Squ1rrel Web Goosemon I’d rather die than use a password manager. In other news, can anyone help me remember the login info for my account? The flag for this challenge is the account password.
Squ1rrel Web Key Server Well, my application is finally making it big – and I’ve heard that once you get over 10 users, using kubernetes is basically a must. Come check out my microservices!
Squ1rrel Web JSON Store Have you ever wanted to store some JSON data really quickly? Have we got the solution for you!
Nitectf Web un(documented)-js-api DOM clobbering, domain takeovers, shared process slowdowns, and CSS exfiltration, oh my!
Wreckctf Web password-3 A quick but interesting proof-of-concept demonstrating that security by obscurity does not and will never work. Even if you don’t show reflected feedback from SQL commands, your database is still not safe.
Sekaictf Web Bottle Poem For this web challenge, we had to utilize two different exploits to get the flag – and one of them wasn’t a web exploit!
Sekaictf Web Issues: Another JWT Challenge Oh, JWTs. A well-intentioned standard, for sure – but my god, the number of implementation mistakes you can make.