webmedium

Booty

alfactf

Task: Find hidden objects in a darkened captcha game with 110 objects across 3 levels. Solution: Used API click endpoint as oracle to bruteforce coordinates via grid search with 150 parallel threads.

$ ls tags/ techniques/
API endpoint enumeration via Swagger/OpenAPICoordinate bruteforce via grid searchParallel request optimizationResponse-based oracle attack

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]