← All labs
MasterRemote code execution

Argument injection into a called binary

100 points · about 180 minutes · flag format DC{...}
InjectionServer-Side Requests

Brief

Remote code execution is the top of the ladder: making the server run code you chose. It usually arrives through something more modest — an upload that lands somewhere executable, a template that evaluates input, a deserialization gadget, an injection that reaches a shell — escalated until the process does your bidding.

This lab: Argument injection into a called binary. Turn a foothold into commands running on the server itself.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Chain a foothold into command execution on the server, and prove it by reading something only the server's own process can. Capture the flag from the host.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.