Rating:

#### 1. Leak /etc/passwd file with an LFI
#### 2. Target the gitserver system user and know that there is a git repo inside his home directory
#### 3. Get the commits made to the repo in order to get the flag
Full Writeup: [https://www.sousse.love/post/signstealingsoftware-p2-umdctf/index.html](http://)

Original writeup (https://www.sousse.love/post/signstealingsoftware-p2-umdctf/index.html).