webeasy

Mermaid

alfactf

Task: JavaScript web game with server-side API for tracking flag letter collection. Solution: Bypassed game logic by directly calling API endpoints (next-letter → collect-letter) without actually playing, exploiting missing server-side validation.

$ ls tags/ techniques/
API endpoint enumeration from client JSGame logic bypass via direct API callsServer-side validation absence exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]