Welcome!

By registering with us, you'll be able to discuss, share and private message with other members of our community.

SignUp Now!
  • Guest, before posting your code please take these rules into consideration:
    • It is required to use our BBCode feature to display your code. While within the editor click < / > or >_ and place your code within the BB Code prompt. This helps others with finding a solution by making it easier to read and easier to copy.
    • You can also use markdown to share your code. When using markdown your code will be automatically converted to BBCode. For help with markdown check out the markdown guide.
    • Don't share a wall of code. All we want is the problem area, the code related to your issue.


    To learn more about how to use our BBCode feature, please click here.

    Thank you, Code Forum.

PHP CTF Help

zed

New Coder
I'm new to programming, and I'm sorry if this is a really obvious question, which I think it is. I'm participating in a beginner CTF event, and I managed to find the following PHP code for a website:
PHP:
$firstChar = $_POST['filename'][0];

if (strcmp($firstChar, '/') == 0) {
    echo "Not Authorized";
} else {
    if (file_exists($_POST['filename'])) {

        $file = fopen($_POST['filename'], 'r');

        while (!feof($file)) {
            $line = fgets($file);
            echo $line.
            "
            ";
        }

        fclose($file);
    } else {
        echo "File does not exist";
    }
}

The way to get the flag is to input a valid filename into a HTML input on the website. Does anyone know a vulnerability which would allow me to insert '/flag.txt', which is where the flag is?
 

New Threads

Latest posts

Buy us a coffee!

Back
Top Bottom