dotdotslashflagtxt

Classic path traversal — the challenge name tells you exactly what to do.

June 16, 2026 · 1 min · 42 words · Th3B0yWh0L1v3d

Solarity

Path traversal via /view?file=../flag.txt reads the server-side flag file.

June 16, 2026 · 1 min · 39 words · Th3B0yWh0L1v3d

Padelify — TryHackMe

A padel-tournament portal behind a deny-list ModSecurity WAF falls to a three-step chain: a User-Agent header bypass, a stored XSS that steals a moderator bot’s session cookie, and an LFI that leaks admin creds via full per-character URL-encoding.

June 8, 2026 · 18 min · 3660 words · Th3B0yWh0L1v3d

Plant Photographer — TryHackMe

SSRF via a pycurl download endpoint chains into file:// LFI, Werkzeug debug PIN cracking, and full RCE on a Dockerised Flask app.

June 8, 2026 · 4 min · 721 words · Th3B0yWh0L1v3d

Spaetzle — GPN CTF 2026

An MD5-only oracle over arbitrary paths is turned into a full file disclosure using the error-based PHP filter-chain oracle to leak /flag byte-by-byte.

June 6, 2026 · 3 min · 487 words · Th3B0yWh0L1v3d