- CTFtime: https://ctftime.org/event/2217/
- 445 solves / 105 points
Just cheat.
Just cheat.
I solved all web and some misc challenges. This gist shows my solvers for two hard web challenges: quickstyle and biscuit-of-totality.
I solved two web challenges: required notes and required notes revenge. Although the intened solution is XS-Leak, I found RCE solution even for the revenge challenge!
I expect that the intended solution is to prepare a server that returns a crafted Content-Type header. However, I solved this challenge without preparing the server :)
🚨 I uploaded files to my repository: https://github.com/arkark/my-ctf-challenges/tree/main/challenges/202409_IERAE_CTF_2024/web/leakleakleak
You can download challenge files from: leakleakleak.tar.gz