Web - Journal
100 points | 518 solves
Last updated
100 points | 518 solves
Last updated
dear diary, there is no LFI in this app
The provided php file:
It's a simple enough challenge that looks like your typical LFI but like the description says, this is not a LFI challenge.
As it turns out, the assert()
function basically works like an eval()
function and we all know the horrors of eval
. This page on HackTricks explains it all.
It is also worth noting from the provided docker file that the flag file name is appended with random characters which hinted towards getting an RCE.
Final solution:
Flag: ictf{assertion_failed_e3106922feb13b10}