Try exploiting the ssti to run arbitrary code and get the flag.

Box: luhack-web-0

Port: 8084

Url: http://100.110.89.151:8084