Beyond the Homepage
Flag hidden in an HTML comment, visible only via browser developer tools or view-source.
No writeups match your filter.
Flag hidden in an HTML comment, visible only via browser developer tools or view-source.
IDOR / broken access control lets you access another user’s flag by changing an ID parameter.
Part 2 of the Boro Senpai series: SSRF via Docker internal hostname.
Flag or unlock parameter hardcoded in client-side JavaScript.
Source-map leak reveals JWT secret, forge admin token, then exploit Jinja2 SSTI for RCE.
Password and flag hardcoded in client-side JavaScript — just read the source.
Classic path traversal — the challenge name tells you exactly what to do.
Node.js prototype pollution via POST /api/flight-profile grants admin access.
Abusing ImageMagick’s SVG text: pseudo-coder to read the flag file via server-side image conversion.
SSRF via Docker internal hostname to reach the metadata service and retrieve the flag.