webhard

Board of Secrets Revenge

miptctf

Task: Web app with admin bot where /api/secret is censored by proxy. Solution: Used relative path script injection for XSS, extracted ETag header containing SHA1 hash of original response, brute-forced the flag from the hash.

$ ls tags/ techniques/
relative_path_script_injectionetag_hash_leaksha1_bruteforceresponse_header_exfiltrationproxy_censorship_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]