webProhard

Torrent

alfactf

Task: React SPA torrent tracker with search functionality. Solution: UNION-based SQL injection in PostgreSQL to extract session tokens, authentication bypass with stolen admin token, download protected torrent file, extract flag from video frames.

$ ls tags/ techniques/
UNION-based SQL Injection in PostgreSQLSession token extraction via SQLiAuthentication bypass with stolen tokenBitTorrent file download and parsingVideo frame extraction for flag recovery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups