Police Leakage

Description

We made our website dynamic now, You can easily navigate between pages!

Solution

Police Leakage.png

Navigation happens with /?page=report.php.

To view source use /?src

We have LFI, but with few restrictions being /etc, php: and flag in filename.

/proc/self/cmdline returns php-fpm: pool www

If flag is located at /flag.txt we can't read it because of blacklist.

Blacklist for php is not case sensitive so it can be easily bypassed, /etc can be included with php filters like:

https://book.hacktricks.wiki/en/pentesting-web/file-inclusion/index.htmlarrow-up-right

php_filter_chain_generatorarrow-up-right can be used to chain filters for RCE

circle-check

Last updated