CachedWeb: chain SSRF with path control to reach the internal target and read the flag.
Web
43 postsDark Runes
Amidst Us
Amidst Us: find the command execution path, trigger it cleanly, and read the flag.
baby sql
baby sql: exploit the SQL injection, extract the needed data, and reach the flag.
Letter Dispair
Letter Dispair: find the command execution path, trigger it cleanly, and read the flag.
OnlyHacks
OnlyHacks: use the client-side injection path to steal the needed proof and recover the flag.
Console
Console: abuse php to cross the web trust boundary and recover the flag.
pcalc
pcalc: identify the broken request handling, prove control, and use it to recover the flag.
sanitize
sanitize: exploit the SQL injection, extract the needed data, and reach the flag.
Interstellar
Under Construction
Under Construction: exploit the SQL injection, extract the needed data, and reach the flag.
CDNio
Jailbreak
Jailbreak: identify the broken request handling, prove control, and use it to recover the flag.
ApacheBlaze
ApacheBlaze: identify the broken request handling, prove control, and use it to recover the flag.
Breathtaking View
DoxPit
Insomnia
NextPath
No Threshold
No Threshold: identify the broken request handling, prove control, and use it to recover the flag.
PDFy
Pentest Notes
POP Restaurant
ProxyAsAService
ProxyAsAService: identify the broken request handling, prove control, and use it to recover the flag.
AbuseHumanDB
AbuseHumanDB: identify the broken request handling, prove control, and use it to recover the flag.
ScreenCrack
C.O.P
C.O.P: exploit the SQL injection, extract the needed data, and reach the flag.
Cursed Stale Policy
Cursed Stale Policy: abuse websocket to cross the web trust boundary and recover the flag.
DLLAMA
DLLAMA: abuse unsafe deserialization to cross the trust boundary and reach the flag.