webProeasy

Вокруг света

bug-makers

Task: Flask app reveals flag parts one per unique visitor IP, tracked via signed session cookie. Solution: rotate requests through free HTTP proxies while replaying the session cookie to accumulate IPs and collect all 9 flag parts.

$ ls tags/ techniques/
proxy_rotationsession_cookie_replayip_based_access_control_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups