Web - Server

samedi 10 novembre 2018, 16:02  #1
PHP eval
Jurgen
  • 1 posts

Heya,

I must be missing something... how many ways are there to run a PHP command whithout using a-zA-Z ? Or am I looking in the wrong direction ?

dimanche 11 novembre 2018, 12:45  #2
PHP eval
Th1b4ud
  • 1636 posts

There is lots of way to bypass the filter. Search on google :)

lundi 7 janvier 2019, 14:12  #3
PHP eval
Anonyme

Hi, i was read the .passwd file, and it have a string with [Ech0 : spoil], which looks like a flag

But when i submitted it => error, please check

jeudi 13 août 2020, 18:59  #4
PHP eval
nico
  • 1 posts

Hi,

me too. I have read the file but i cannot validate the level.

I have used this website to understand how to by pass regex filter and send some code to execute : [Th1b4ud : spoil]

i have copy the result directly in the input field to vaidate the level but it don’t work. Have i missing anything ?

Thank you