tl;dr
- Using Prototype pollution vulnerablity in fast-json-patch pollute value in outputFunctionName
- Get a shell as the flag can only be obtained using binary file
tl;dr
tl;dr
/gettoken%3fcreditcard=mmm&promocode=FREEWAF
to get the token.{"name":"' union select flag, 1, 1, 1 from flag -- -", "name":"x"}
to get the flag.tl;dr
__malloc_hook
to one_gadget
tl;dr
; secure; samesite=none
to cookie. Now, <script src="https://jason.2021.chall.actf.co/flags?callback=load"></script>
would retrieve the flag. tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr