Challenge Name: Ping-Pong

Author :L0xm1

Challenge Description

A simple ping service .Is it vulnerable?


When you visit the challenge link ,we are welcomed with "Enter the hostname to ping Example: /ping?"

When we visit the /ping endpoint with ?address={hostname to ping}and give /ping? ,we get the ping response of

Here if we give /ping?|ls we can get the contents in the directory i.e ( flag.txt templates)

When we try /ping?|cat flag.txt it throws out an error Not Allowed which indicates cat is blacklisted.

We can use head,more,tail etc to read the flag.

When we give /ping?|head flag.txt we get the flag.

