webPromedium
Booty
alfactf
Task: Find hidden objects in a darkened captcha game with 110 objects across 3 levels. Solution: Used API click endpoint as oracle to bruteforce coordinates via grid search with 150 parallel threads.
$ ls tags/ techniques/
API endpoint enumeration via Swagger/OpenAPICoordinate bruteforce via grid searchParallel request optimizationResponse-based oracle attack
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Throttle— alfactf
- [web][Pro]Mermaid— alfactf
- [web][Pro]YouTroopers— alfactf
- [web][Pro]Torrent— alfactf
- [infra][Pro]SecretShell— alfactf