webProhard

Biba and Boba

miptctf

Task: Two Rust services where user input is compressed with a secret signature using gzip. Solution: CRIME/BREACH compression oracle attack - binary search for compression threshold to leak SECRET digit by digit, then forge valid bincode packet.

$ ls tags/ techniques/
compression_oraclecrime_breach_attackbinary_search_oraclebincode_forgery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups