boroGPT

Source-map leak reveals JWT secret, forge admin token, then exploit Jinja2 SSTI for RCE.

June 16, 2026 · 1 min · 99 words · Th3B0yWh0L1v3d

Chakravyuh Defense — DalCTF 2026

A defensive web CTF where you patch the vulnerable source and the grader attacks your build: Secure the Login is fixed with parameterized queries, and Render & Plunder is sealed by binding SSTI input as render context plus adding an object-level authorization check to kill the IDOR.

June 7, 2026 · 13 min · 2615 words · Th3B0yWh0L1v3d

La Casa de Papel (Secure Comms) — Zer0d4yh31st CTF

A Flask/Jinja2 app renders user-supplied names directly into a template, enabling SSTI that dumps os.environ to leak the flag stored as an environment variable.

June 6, 2026 · 2 min · 214 words · Th3B0yWh0L1v3d