tag

Web

43 posts
web

Gunship

Gunship: identify the broken request handling, prove control, and use it to recover the flag.

web

Jscalc

Jscalc: use path traversal to escape the intended read path and recover the flag.

web

Juggling facts

Juggling facts: identify the broken request handling, prove control, and use it to recover the flag.

web

KORP Terminal

KORP Terminal: exploit the SQL injection, extract the needed data, and reach the flag.

web

Neonify

Neonify: identify the broken request handling, prove control, and use it to recover the flag.

web

PetPet Rcbee

PetPet Rcbee: abuse file-upload to cross the web trust boundary and recover the flag.

web

Phonebook

Phonebook: identify the broken request handling, prove control, and use it to recover the flag.

web

Prying Eyes

Prying Eyes: use path traversal to escape the intended read path and recover the flag.

web

SpookTastic

SpookTastic: use the client-side injection path to steal the needed proof and recover the flag.

web

TimeKORP

TimeKORP: use path traversal to escape the intended read path and recover the flag.

web

Toxic

Toxic: abuse unsafe deserialization to cross the trust boundary and reach the flag.

web

Trapped Source

Trapped Source: identify the broken request handling, prove control, and use it to recover the flag.

web

Weather App

Weather App: use SSRF to reach the hidden service or file path and pull the flag.

web

Feedback Flux

Feedback Flux: use the client-side injection path to steal the needed proof and recover the flag.

web

SQHell

SQHell: exploit the SQL injection, extract the needed data, and reach the flag.