rootđź’€senseicat:~#

Hack. Eat. Sleep. Repeat!!!


Project maintained by SENSEiXENUS Hosted on GitHub Pages — Theme by mattgraham

CTF: PATRIOTCTF


image



WEB


Giraffe-notes

image

Exploitation

image


Impersonate

image

Source Code review


Exploitation

image

image

image


DOMDOM

TAGS: Host Header Injection SSRF XXE

image


Source Code Review

image

image


Explaining route check

image

if request.method == 'POST':
        url = request.form['url']
        url_parsed = urllib.parse.urlparse(url).netloc

XML External Entity

image


Bypassing the filters

image

image


Exploitation

image

image

image


CRYPTO


BIGGER IS BETTER

image


image


Misc


Really Only Echo

image



Bypassing the filters

image

image


THANKS FOR READING!!!!