📌 Info

This lab contains a vulnerable image upload function. Certain file extensions are blacklisted, but this defense can be bypassed using a classic obfuscation technique.


🎯 Goal


🔑 Credentials

You can log in to your own account using:

wiener:peter


📝 Steps

1. Initial Attempts


2. Null Byte Injection