Description
The upload script removes all /<\?|php/. So you can not run php.
You can only upload file whose name is captured by the regexp /^[a-zA-Z0-9]+\.[a-zA-Z0-9]+$/.
 [MMA 2015] [Web – Uploader] Write Up
 [MMA 2015] [Web – Uploader] Write UpThe upload script removes all /<\?|php/. So you can not run php.
You can only upload file whose name is captured by the regexp /^[a-zA-Z0-9]+\.[a-zA-Z0-9]+$/.
 [MMA 2015] [Web – Login as Admin] Write Up
 [MMA 2015] [Web – Login as Admin] Write UpLogin as admin and retrieve the flag.
The flag is the admin’s password.
You can use test:test.
 [MMA 2015] [Misc – MQAAAA] Write Up
 [MMA 2015] [Misc – MQAAAA] Write Up [MMA 2015] [Stegano – Nagoya Castle] Write Up
 [MMA 2015] [Stegano – Nagoya Castle] Write Up [MMA 2015] [Web – Login as Admin] Write Up
 [MMA 2015] [Web – Login as Admin] Write Up