gamepwnmedium

LightningFast

hackthebox

Task: Get 1,000,000 points in a Unity IL2CPP game to buy the flag. Solution: Discover a hidden /endpoints API that returns dynamic getter/setter endpoint names, use the setter to directly set the score to 1,000,000 via HTTP POST, then call /buyflag to retrieve the flag.

$ ls tags/ techniques/
traffic_captureendpoint_discoveryapi_manipulation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]