Forum Discussion
QuickSloth
Bronze III
3 months agoConfused in "Threat Modeling Fundamentals; SQL Injection and Server-Side Template Injection"
In the section File Download there is a question on the quiz which asks "What is the value in /etc/flag.txt?" $> ls /etc Tells me that there is no file named flag.txt Am I looking in the wrong pla...
KieranRowley
Community Manager
3 months agoHi QuickSloth I have taken a look but I can't work out which lab you are referring to, please can you clarify the lab name?
- QuickSloth3 months ago
Bronze III
Does this help?
- netcat3 months ago
Silver III
The value is on the target system in /etc/flag.txt - not on the local system.
The target system has a vulnerability, maybe to spawn a shell allowing you to download the file, or a vulnerability in the database allowing to either read and display or to download the file.- QuickSloth3 months ago
Bronze III
Thanks