SCS

Description

SCS [Web]

We uncovered a code repository and it appears to be where ARIA is storing mission-critical code. We need to break in!

https://uscybercombine-s4-scs.chals.io/arrow-up-right

Solution

SCS

Uploaded files are placed in /uploads directory

SCS-2

The technology used is PHP

SCS-1

The frontend restricts using special characters:

But making direct request to backend it's bypassed:

SCS-3

Upload shell:

It works:SCS-4

After some enumeration we find location of real flag.txtSCS-5

circle-check

Last updated