2018found by harvest
HITB-XCTF GSEC CTF 2018 Final
1 challenge with 1 published solution between them. No writeups were ever filed against this event's listing, so its solutions were found in public repositories instead. Each link is pinned to the commit it was read from.
The event listingWeb1
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Solve it with:JWT decoder and signature verifierJWT alg=none bypass generatorWeb attack payload catalogJWT secret brute forceLearn: Sessions, tokens and access control
Xctf 2018 Finals Web
1 official solutionAlso written up in: ReAbout/ctf-writeup