πŸ“Œ Info

This lab contains a vulnerable image upload function. Certain file extensions are blacklisted, but this defense can be bypassed due to a fundamental flaw in the configuration of this blacklist.


🎯 Goal


πŸ”‘ Credentials

You can log in to your own account using:

wiener:peter

πŸ’‘ Hint

You need to upload two different files to solve this lab.


πŸ“ Steps

1. Understanding the Blacklist