All Writeups

Comprehensive collection of CTF challenges, solutions, and insights.


Filter by tag:

DEADROP Web 6 - weather.control.deadrop

A three-stage vulnerability chain - SQL injection to bypass authentication, IDOR to steal an admin API key from another operator's report, then command injection via the weather query endpoint to achieve RCE and read the flag.

DEADROP Web 5 - drone_registry.gov

Exploiting a Server-Side Request Forgery vulnerability in an operator location verification endpoint to access an internal AWS-style metadata service and exfiltrate IAM credentials containing the flag.

DEADROP Web 4 - leaks.secure-drop.deadrop

Bypassing Content-Security-Policy via inline event handlers to execute stored XSS against an admin bot, exfiltrating the admin session token via a built-in capture endpoint.

DEADROP Web 3 - budget.internal.deadrop

Exploiting a Server-Side Template Injection vulnerability in an expense report submission form to extract a flag from the Flask application config via Jinja2's built-in config context variable.

DEADROP Web 2 - agent_portal.classified

Bypassing JWT signature verification by exploiting the alg:none algorithm confusion vulnerability to escalate from asset to handler clearance.

DEADROP Web 1 - surveillance.archive.gov

Exploiting a UNION-based SQL injection in a fake government FOIA portal to extract a flag from a hidden table that the query was never meant to reach.