Freemarker

Command execution with constraints

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

Taking example on the training payload Command execution, you have to find a way to execute the same payload but without ., ) and ( .

Goal: Execute the id shell command

Hints

Solution

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result