webhard
Board of Secrets Revenge
miptctf
Task: Web app with admin bot where /api/secret is censored by proxy. Solution: Used relative path script injection for XSS, extracted ETag header containing SHA1 hash of original response, brute-forced the flag from the hash.
$ ls tags/ techniques/
sha1file_uploadxssnginxexpressadmin_botheadless_chromeaiohttpproxy_bypassetagrelative_path_injection
relative_path_script_injectionetag_hash_leaksha1_bruteforceresponse_header_exfiltrationproxy_censorship_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]