Burp Suite User Forum

Create new post

Academy Mystery Labs - File upload challenges are missing /home/carlos/secret

Chris | Last updated: Mar 16, 2022 01:29PM UTC

I have noticed that all of the Mystery challenges for file upload vulnerabilities do not have the required '/home/carlos/secret' file. This makes it impossible to submit the solution. Steps to reproduce: 1) https://portswigger.net/web-security/all-labs 2) In Mystery Labs: Select any level, Select File Upload Vulnerabilities 3) Solve the challenge, and observe there is no file /home/carlos/secret in the container Running 'ls -alR /home' show shows the contents of /home/carlos /home/elmer and /home/peter, none of them contain a secret file. Is anyone else seeing this issue or can confirm?

Adrian | Last updated: Mar 16, 2022 03:01PM UTC

I can confirm it, happened to me too. I've also checked it with 'ls -al' command and the directories were empty.

Liam, PortSwigger Agent | Last updated: Mar 16, 2022 03:41PM UTC

Chris, Adrian, thanks for these reports. We'll investigate and update this thread ASAP.

Liam, PortSwigger Agent | Last updated: Mar 16, 2022 08:19PM UTC

We have replicated this issue. We'll keep you updated. Thanks!

YASSIN | Last updated: Oct 28, 2022 07:56AM UTC

I confirm this also

Liam, PortSwigger Agent | Last updated: Oct 28, 2022 01:09PM UTC

Thanks, Mohammad. We'll look into this again.

Liam, PortSwigger Agent | Last updated: Nov 16, 2022 02:46PM UTC

Hi Mohammad. We've checked this issue, and we think everything is working as expected. Could you provide some more detail about the problem you are facing?

Warren | Last updated: Jan 08, 2024 06:12AM UTC

Hello I have a slightly different problem. I have obtained the secret but when uploading it on the lab it says it is not correct.

Dominyque, PortSwigger Agent | Last updated: Jan 08, 2024 01:28PM UTC

Hi Warren Can you please send us some screenshots of the steps you are taking so we can better advise? You can send these screenshots to support@portswigger.net if you wish.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.