Padelify — TryHackMe

A padel-tournament portal behind a deny-list ModSecurity WAF falls to a three-step chain: a User-Agent header bypass, a stored XSS that steals a moderator bot’s session cookie, and an LFI that leaks admin creds via full per-character URL-encoding.

June 8, 2026 · 18 min · 3660 words · Th3B0yWh0L1v3d

Baby Web — DalCTF 2026

A static HTML page stuffed with a movie transcript hides the flag in a paragraph marked hidden=“true” — invisible in the browser but right there in the page source.

June 6, 2026 · 3 min · 595 words · Th3B0yWh0L1v3d