Another Secure Store Note - LINE CTF 2023 ma1f0y 2023-03-28 Web tl;dr Leak csrf token bypassing document.domain visiting /profile/ will not change the nonce Leak nonce using dangling markup in firefox Add XSS payload using the csrf to get the flag Read More LINECTF2023