Goal
Capture Flag1 at /etc/flag1
using lfi.
Steps
After spinning up the VM, I've opened the /challenges/chall1.php
to see that POST
param is used to include file contents into the web application.
I've opened Postman app (provided by THMs AttackBox) and called the PHP script with file
request parameter:
Flag
F1x3d-iNpu7-f0rrn