Earlier this month, Sam Curry and I found one of our first exploitable ORM injection vulnerabilities that we’ve seen in the wild and leveraged it to steal cryptocurrency from an online game. We found an upcoming “pay-to-spawn” shooter, a battle royale game where you have to put up some amount of crypto to spawn and the winner takes all. Sadly for us, the game was not fully released and it’s in…
Challenge Name Solves Fidler 3574 Garbage 1506 Wednesday 1146 Report 1019 TKApp 953 Codeit 817 RE Crowd 712 Aardvark 661 crackinstaller 508 Break 357 Rabbithole 260 Before we get into the writeup, neither did i think i would complete Flare-on this year nor did i think i would do a write up. So i did not take any notes during the 6 weeks and had to write everything from memory and saved files i had…
Challenge Name Category Solves Points Just a Normal CTF Web 116 100 login_page Web 23 200 Just a Normal CTF Category: Web | Solves: 116 | Points: 100 This challenge was pretty straight forward. Upon opening the challenge we are greeted with an all too familiar ctfd instance. After a quick look around i didnt see anything that would indicate that this was not a real ctfd instance, one interesting…
Through multiple vulnerabilites in the web apps and the mobile app i was able to recover Marten’s account and pay all the hackers! Thus completing the CTF. The first thing i did was check certificate transparency logs for certs issued to the domains in scope. This gave me: software.bountypay.h1ctf.com staff.bountypay.h1ctf.com api.bountypay.h1ctf.com app.bountypay.h1ctf.com bountypay.h1ctf.com A…