Published onFebruary 22, 2024Intigriti Valentines challenge 0224 writeupwriteupXSSbug-bountyCTFcookie-manipulationJWTAchieving sensitive data leak via XSS
Published onJanuary 14, 2024Intigriti challenge 0124 writeupwriteupprototype-pollutionXSSbug-bountyCTFDOM-clobberingAchieving arbitrary javascript execution via prototype pollution
Published onDecember 20, 2023Intigriti challenge 1223 writeupwriteupregexpenetration-testingbug-bountyReDoSRCECTFExposing the hidden flag via catastrophic backtracking in the regex expression
Published onNovember 6, 2023Intigriti challenge 1023 writeupwriteupxsspenetration-testingbug-bountyLFIRFICTFExposing the hidden flag via improper sanitization of HTML and Chrome developer protocol
Published onSeptember 28, 2023Intigriti challenge 0923 writeupwriteupsqlipenetration-testingbug-bountyCTFExposing the hidden flag via improper handling of query parameters and blacklisting