webeasy
Mermaid
alfactf
Task: JavaScript web game with server-side API for tracking flag letter collection. Solution: Bypassed game logic by directly calling API endpoints (next-letter → collect-letter) without actually playing, exploiting missing server-side validation.
$ ls tags/ techniques/
API endpoint enumeration from client JSGame logic bypass via direct API callsServer-side validation absence exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]