webProeasy

Mermaid

alfactf

Task: JavaScript web game with server-side API for tracking flag letter collection. Solution: Bypassed game logic by directly calling API endpoints (next-letter → collect-letter) without actually playing, exploiting missing server-side validation.

$ ls tags/ techniques/
API endpoint enumeration from client JSGame logic bypass via direct API callsServer-side validation absence exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups