Skip to content

Instantly share code, notes, and snippets.

View farisv's full-sized avatar
🎸

Fariskhi Vidyan farisv

🎸
  • Singapore
View GitHub Profile
@farisv
farisv / rwctf-5th-dark-portal-writeup.md
Last active March 10, 2026 05:04
Real World CTF 5th (2023): Dark Portal Writeup

Real World CTF 5th (2023): Dark Portal Writeup

I participated in the Real World CTF 5th with new team SKSD and got the 12th place, enough to get the merchandise prize this year. Usually top 12 of Real World CTF got invited to China for final, but this year's competition is online only.

This is the write-up of one of the web challenges, Dark Portal.

Problem

@farisv
farisv / intigriti-challenge-1222.md
Last active January 16, 2023 17:33
Writeup for Intigriti's Challenge 1222

Intigriti's Challenge 1222 (December 2022)

URL: https://challenge-1222.intigriti.io/

Given a web application where users can register, login, create a blog post, and visit other users' blog posts. The criteria of the expected solutions are:

  • Should work on the latest version of Chrome and FireFox.
  • Should execute alert showing the victim's/another user's username..
  • Should leverage a cross site scripting vulnerability on this domain.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should NOT use another challenge on the intigriti.io domain.
### Keybase proof
I hereby claim:
* I am farisv on github.
* I am farisv (https://keybase.io/farisv) on keybase.
* I have a public key whose fingerprint is FE31 79D9 B1B3 5939 8CF2 AF78 DB96 FEF7 9857 E3CC
To claim this, I am signing this object: