webProhard
Personal Blog
uoftctf2026
A Node.js/Express web application with user registration, login, blog posts, and magic links for passwordless login. An admin bot (Puppeteer) visits reported URLs after logging in as admin. The `/flag` endpoint is only accessible to admin users.
$ ls tags/ techniques/
autosave_xss_bypassmagic_link_session_leakcookie_swap_attack
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][free]review— pingCTF
- [web][Pro]YOFA 1.0— bug-makers
- [web][Pro]Object Master— hackerlab
- [web][Pro]YOFA 2.0— bug-makers
- [web][Pro]Lab 293 — CloudNest — Reflected XSS in Login Callback Label— hackadvisor