- IrisCTF
- web:
- lamenote: 'XS leak' using
CSP restriction
andhistory.length
.
- lamenote: 'XS leak' using
- web:
- Akasec
- web:
- HackerNickname:
JacksonInject
,curl globbing
andJava Class Instance
oforg.springframework.context.support.FileSystemXmlApplicationContext
.
- HackerNickname:
- web:
- GreyCTF
- web
- CSS exfiltration
- web
- OpenECSC
- web (all): writeup
- JustCTF
- web (backslash):
nginx njs
andproxy pass
. - web (PocketBase): ¿mutation?
XSS
.
- web (backslash):
- NahamCon
- pwn:
- pwn_weird_cookie:
Custom Canary Exfiltration
andret2libc
.
- pwn_weird_cookie:
- pwn:
- ProjectSekai
- rev:
- AzusawaGachaWorld:
Proxying
the connections from the binary (game) to the endpoint.
- AzusawaGachaWorld:
- web:
- ScannerService: Bypass for
Command Injection
in Nmap params. - Frog-WAF:
SSTI
inJava
(buildConstraintViolationWithTemplate
).Character Bypass
using[]
andgetSize()
. - GolfJail:
WebRTC CSP Bypass
andXSS
.
- ScannerService: Bypass for
- rev:
- Random
- web:
- Mizu's chall:
DOM Clobbering
.
- Mizu's chall:
- web: