OWASP Top 10 - baby nginxatsu

This website allow us to generate nginx config:

Once you generate the config file they give you a link to the config file:
http://138.68.134.163:32143/config/51

Let’s see what is in the storage directory.
We have a bunch of config file and a tar.gz file:

Download it:

Open it with sqlite3:

Show the users:

Now let’s enter the hashes in https://crackstation.net/

nginxatsu-adm-01@makelarid.es:adminadmin1
Now you can log in with the creds and get the flag.