Published on27 octobre 2023BlueHensCTF 2023 - Best Bathroom on CampusBlueHensCTF-2023ChocapikkWebFirebaseInformation-DisclosureExploiting an incorrectly configured Firebase database to reveal hidden data.
Published on1 octobre 2023BuckeyeCTF 2023 – StrayBuckeyeCTF-2023LumyWebLFIHTTP parameter pollution attack leading to LFI
Published on1 octobre 2023BuckeyeCTF 2023 – Text Adventure APIBuckeyeCTF-2023LumyWebDeserializationPickle deserialization exploitation
Published on1 octobre 2023BuckeyeCTF 2023 – area51BuckeyeCTF-2023LumyWebSQLBlind NoSQL injection on MongoDB
Published on10 septembre 2023PatriotCTF 2023 – FlowerShopPatriotCTF-2023LumyWebPRNGmt_rand vulnerability
Published on10 septembre 2023PatriotCTF 2023 – PickYourStarterPatriotCTF-2023LumyWebSSTISSTI in Web pokemon starter pick challenge
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 1BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 2BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 3BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 4BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 5BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023TJCTF 2023 – Back to the pastTJCTF-2023LumyWebJWTChanging algorithm from RS256 to HS256, bypassing signature process