webProhard
After Image
srdnlen
Task: read a flag from an internal MJPEG camera stream not accessible from outside, using a Playwright Firefox bot with 75s timeout. Solution: PHP session file injection for XSS, then DNS rebinding via rbndr.us with iptables TCP RST blocking to force DNS re-resolution after 60s Firefox cache expiry, exfiltrate MJPEG frame via shared session.
$ ls tags/ techniques/
dns_rebinding_via_tcp_rstphp_session_file_injectionsession_fixation_via_urliptables_tcp_rst_blockingdns_cache_eviction_floodingmjpeg_stream_exfiltration
π
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Photo Storageβ miptctf
- [web][Pro]Ecler 2β spbctf
- [crypto][Pro]Firewallβ uoftctf2026
- [web][Pro]Lab 307 β CrewHub β File Upload RCE via Polyglot JPG/PHPβ hackadvisor
- [forensics][Pro]ΠΠΈΠΌβ duckerz