<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Php :: X3ric Blog</title><link>https://x3ric.com/blog/tags/php/</link><description>CTF notes, systems work, and writeups.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Jun 2026 21:41:13 +0200</lastBuildDate><atom:link href="https://x3ric.com/blog/tags/php/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox Phoenix Pipeline Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Phoenix-Pipeline-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Phoenix-Pipeline-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Letter Dispair Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Letter-Dispair-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Letter-Dispair-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>rce</category><category>php</category><category>cve-2016-10045</category><description>Letter Dispair: find the command execution path, trigger it cleanly, and read the flag.</description></item><item><title>HackTheBox Console Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Console-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Console-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Console: abuse php to cross the web trust boundary and recover the flag.</description></item><item><title>HackTheBox Interstellar Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Interstellar-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Interstellar-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><category>ssrf</category><category>rce</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Insomnia Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Insomnia-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Insomnia-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox PDFy Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-PDFy-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PDFy-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox POP Restaurant Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-POP-Restaurant-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-POP-Restaurant-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox ScreenCrack Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ScreenCrack-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ScreenCrack-Challenge/</guid><pubDate>Tue, 03 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>ssrf</category><category>rce</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Toxic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Toxic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Toxic-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>deserialization</category><category>rce</category><category>php</category><description>Toxic: abuse unsafe deserialization to cross the trust boundary and reach the flag.</description></item><item><title>HackTheBox Feedback Flux Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Feedback-Flux-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Feedback-Flux-Challenge/</guid><pubDate>Sat, 02 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>xss</category><category>php</category><description>Feedback Flux: use the client-side injection path to steal the needed proof and recover the flag.</description></item></channel></rss>