Web - Server

Saturday 10 November 2018, 16:02  #1
PHP eval
Jurgen
  • 1 posts

Heya,

I must be missing something... how many ways are there to run a PHP command whithout using a-zA-Z? Or am I looking in the wrong direction?

Sunday 11 November 2018, 12:45  #2
PHP eval
Th1b4ud
  • 1636 posts

There is lots of way to bypass the filter. Search on google :)

Monday 7 January 2019, 14:12  #3
PHP eval
Anonymous

Hi, i was read the .passwd file, and it have a string with [Ech0 : spoil], which looks like a flag

But when i submitted it => error, please check

Thursday 13 August 2020, 18:59  #4
PHP eval
nico
  • 1 posts

Hi,

me too. I have read the file but i cannot validate the level.

I have used this website to understand how to by pass regex filter and send some code to execute : [Th1b4ud : spoil]

i have copy the result directly in the input field to vaidate the level but it don’t work. Have i missing anything ?

Thank you