mischard

Phantom 2

tamuctf

Task: GitHub repo with phantom/orphaned commit, no API leaks to discover SHA. Solution: Brute force 4-char hex SHA prefixes via GitHub web interface, then extract flag via Git Data API tree/blob traversal.

$ ls tags/ techniques/
github_phantom_commit_recoverygit_tree_traversalsha_prefix_brute_forcegithub_web_interface_enumerationasync_http_rate_limiting

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]