
# Tar Analyzer
*Defenit CTF 2020 - Web 278*

*Writeup by Payload as ToEatSushi*

## Problem

Our developer built simple web server for analyzing tar file and extracting online. He said server is super safe. Is it?

## Unintended way

It's defenitely solved by unintended way.

## Exploitation
1. Make a symlink that points `/flag.txt`
2. Archive it to `.tar`
3. Upload and read.


Original writeup (https://github.com/mdsnins/ctf-writeups/blob/master/2020/Defenit%20CTF/Tar%20Analyzer/tar_analyzer.md).