webProeasy
Mermaid
alfactf
Task: JavaScript web game with server-side API for tracking flag letter collection. Solution: Bypassed game logic by directly calling API endpoints (next-letter → collect-letter) without actually playing, exploiting missing server-side validation.
$ ls tags/ techniques/
API endpoint enumeration from client JSGame logic bypass via direct API callsServer-side validation absence exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Сила воли (Willpower)— duckerz
- [web][Pro]Booty— alfactf
- [web][Pro]Web-полигон (Web Polygon)— duckerz
- [web][Pro]Tsunami— alfactf
- [web][Pro]Throttle— alfactf