webhard

board_of_secrets

miptctf

Task: Task board app with file uploads and admin bot. Solution: Exploited relative path script injection by uploading malicious JS as attachment, then tricking admin bot to visit crafted URL that loads the attachment as script.js, exfiltrating /api/secret via image beacon.

$ ls tags/ techniques/
relative_path_script_injectioncontent_type_bypassadmin_bot_exploitationimage_beacon_exfiltration

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]