Good morning everyone, I’m trying to perform the exercise on second-order LFIs, the code provided is the same as the one proposed as an example in the explanation, but when I try to do the necessary steps I don’t get the contents of the flag file.
The steps are very simple:
I rename one of the files to ‘flag’
I rename the user to ‘../admin’
I select the new flag file and I should get the contents, but this is not the case
I went up the file system up to 7 levels, but I got nothing, I also tried to rename the user /home/admin but again nothing to do.
Maybe the filename isn’t ‘flag’, I’m pretty much at a standstill. Do you have suggestions? Where am I doing wrong?
Here’s the hint: it’s related to admin, and you need to figure out how to access it. Everything is located in the same directory. Don’t complicate things by going to the root directory; there’s nothing there.