tag

Web

43 posts
web

CachedWeb

CachedWeb: chain SSRF with path control to reach the internal target and read the flag.

web

Amidst Us

Amidst Us: find the command execution path, trigger it cleanly, and read the flag.

web

baby sql

baby sql: exploit the SQL injection, extract the needed data, and reach the flag.

web

Letter Dispair

Letter Dispair: find the command execution path, trigger it cleanly, and read the flag.

web

OnlyHacks

OnlyHacks: use the client-side injection path to steal the needed proof and recover the flag.

web

Console

Console: abuse php to cross the web trust boundary and recover the flag.

web

pcalc

pcalc: identify the broken request handling, prove control, and use it to recover the flag.

web

sanitize

sanitize: exploit the SQL injection, extract the needed data, and reach the flag.

web

Under Construction

Under Construction: exploit the SQL injection, extract the needed data, and reach the flag.

web

Jailbreak

Jailbreak: identify the broken request handling, prove control, and use it to recover the flag.

web

ApacheBlaze

ApacheBlaze: identify the broken request handling, prove control, and use it to recover the flag.

web

No Threshold

No Threshold: identify the broken request handling, prove control, and use it to recover the flag.

web

ProxyAsAService

ProxyAsAService: identify the broken request handling, prove control, and use it to recover the flag.

web

AbuseHumanDB

AbuseHumanDB: identify the broken request handling, prove control, and use it to recover the flag.

web

C.O.P

C.O.P: exploit the SQL injection, extract the needed data, and reach the flag.

web

DLLAMA

DLLAMA: abuse unsafe deserialization to cross the trust boundary and reach the flag.