HACKR.GG
LabsShipFast — Command Injection Hunt
Command InjectionMedium

ShipFast — Command Injection Hunt

ShipFast has three features — only one calls a shell command. Identify the injectable endpoint, confirm with a timing probe, and extract both flags from /app/secrets/.

Tools:commixcurl
↗ View walkthrough
// Machine control
Checking session...
// Submit flag