Tags: html lfi 

Rating: 5.0

**Catergory** - Web | **Points** - 100

## Description:
We are creating a new web-site for our restaurant. Can you check if it is secure enough?

### Solution:
Upon visiting the site, checking the source of the home page reveals:

So we know we might be facing an LFI to try and access 'apache access' or the 'error log'.

Now, clicking one the navigation links shows us the structure of the URL
Maybe ``?page=home`` is vulnerable to LFI?

It sure is, visiting ``http://bonappetit.stillhackinganyway.nl/?page=.htaccess`` it reveals the following:
<FilesMatch "\.(htaccess|htpasswd|sqlite|db)$">
Order Allow,Deny
Deny from all

<FilesMatch "\.phps$">
Order Allow,Deny
Allow from all

<FilesMatch "suP3r_S3kr1t_Fl4G">
Order Allow,Deny
Deny from all

# disable directory browsing
Options -Indexes
Hmm, no flag but we do see ``suP3r_S3kr1t_Fl4G``, let's try accessing that file.

Yep, that file reveals the flag :)

Original writeup (https://github.com/notdls/ctf-write-ups/tree/master/SHA2017/web/Bon%20Appetit).
RegardlessAug. 7, 2017, 2:01 a.m.

How do you go about accessing the file suP3r_S3kr1t_Fl4G?

Thank you for the writeup!