Three nginx servers, each with a classic configuration mistake: a CRLF injection through $uri in a redirect, an alias traversal from a location without a trailing slash, and an add_header in a location that drops the server's security headers.
Pas commencéDockercommit 287d01dx86_64 · aarch64Secret
Exploit the three nginx misconfigurations: inject a header, read files outside the alias, and lose the security headers.
Le brief de ce lab se trouve dans son dépôt.