<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Web on Th3B0yWh0L1v3d — Security Writeups</title>
    <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/</link>
    <description>Recent content in Web on Th3B0yWh0L1v3d — Security Writeups</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 16 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Beyond the Homepage</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/beyond-the-homepage/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/beyond-the-homepage/</guid>
      <description>Flag hidden in an HTML comment, visible only via browser developer tools or view-source.</description>
    </item>
    <item>
      <title>Boro Senpai 1</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-1/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-1/</guid>
      <description>IDOR / broken access control lets you access another user&amp;rsquo;s flag by changing an ID parameter.</description>
    </item>
    <item>
      <title>Boro Senpai 2</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-2/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-2/</guid>
      <description>Part 2 of the Boro Senpai series: SSRF via Docker internal hostname.</description>
    </item>
    <item>
      <title>Boro Senpai 3</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-3/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-3/</guid>
      <description>Flag or unlock parameter hardcoded in client-side JavaScript.</description>
    </item>
    <item>
      <title>boroGPT</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/borogpt/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/borogpt/</guid>
      <description>Source-map leak reveals JWT secret, forge admin token, then exploit Jinja2 SSTI for RCE.</description>
    </item>
    <item>
      <title>Cracking the Vault</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/cracking-the-vault/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/cracking-the-vault/</guid>
      <description>Password and flag hardcoded in client-side JavaScript — just read the source.</description>
    </item>
    <item>
      <title>dotdotslashflagtxt</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/dotdotslashflagtxt/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/dotdotslashflagtxt/</guid>
      <description>Classic path traversal — the challenge name tells you exactly what to do.</description>
    </item>
    <item>
      <title>Drone Dash</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/drone-dash/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/drone-dash/</guid>
      <description>Node.js prototype pollution via POST /api/flight-profile grants admin access.</description>
    </item>
    <item>
      <title>Kobeni&#39;s Dashboard</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/kobenis-dashboard/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/kobenis-dashboard/</guid>
      <description>Abusing ImageMagick&amp;rsquo;s SVG text: pseudo-coder to read the flag file via server-side image conversion.</description>
    </item>
    <item>
      <title>Neural Sync Portal</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/neural-sync-portal/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/neural-sync-portal/</guid>
      <description>SSRF via Docker internal hostname to reach the metadata service and retrieve the flag.</description>
    </item>
    <item>
      <title>Solarity</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/solarity/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/solarity/</guid>
      <description>Path traversal via /view?file=../flag.txt reads the server-side flag file.</description>
    </item>
  </channel>
</rss>
