webProeasy

Маскарад (Masquerade)

bug-makers

Task: Express.js app splits flag into 5 parts, each revealed by a new unique User-Agent within the same session. Solution: Reuse the connect.sid session cookie while changing the User-Agent header across 5 requests to collect all flag parts.

$ ls tags/ techniques/
session_cookie_reuse_with_different_user_agentsexpress_session_state_trackingmulti_part_flag_collection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups