Three nginx servers, each with a classic configuration mistake: a CRLF injection through $uri in a redirect, an alias traversal from a location without a trailing slash, and an add_header in a location that drops the server's security headers.
Not startedDockercommit 287d01dx86_64 · aarch64Secret
Exploit the three nginx misconfigurations: inject a header, read files outside the alias, and lose the security headers.
The brief for this lab lives in its repository.