webProhard

Personal Blog

uoftctf2026

A Node.js/Express web application with user registration, login, blog posts, and magic links for passwordless login. An admin bot (Puppeteer) visits reported URLs after logging in as admin. The `/flag` endpoint is only accessible to admin users.

$ ls tags/ techniques/
autosave_xss_bypassmagic_link_session_leakcookie_swap_attack

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups