Aragog

@macw141 said:

@owodelta said:
found the OWASP thing mentioned here, but have no idea on how to use it.
PM please

This is indeed a tricky one. When I got a nudge, everything became simple, till root. The key thing is how to submit the payload.

I figured out what happens with the content of the files (what happens if you submit it and what is returned).
but can not get an idea how to move that a step forward.
i need that moment of enlightment