[THM] Lo-Fi Writeup
[THM] Lo-Fi Writeup
CX3300x00 Challenge Info
Obviously, it’s an LFI vuln. The web application can read the local file to response the different page.
0x01 Reconnaissance
We can found that the file can be read by such as page=file:///etc/passwd
.
0x02 Exploit
Use the file:///flag.txt
to read the flag.txt
in the root path.
0x03 Pwned
Comment
Privacy policy
✅ No need to delete blank lines, comment directly for the best display