CachedWeb: chain SSRF with path control to reach the internal target and read the flag.
codelocked
CachedWeb: chain SSRF with path control to reach the internal target and read the flag.
LicenseGenerator: recover the XOR transform from the binary and invert it to reveal the flag.
SatelliteHijack: trace the binary, isolate the validation routine, and invert it to recover the flag.
400Curves: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.
A Nightmare On Math Street: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Amidst Us: find the command execution path, trigger it cleanly, and read the flag.
baby sql: exploit the SQL injection, extract the needed data, and reach the flag.
Letter Dispair: find the command execution path, trigger it cleanly, and read the flag.