Notepad Series - InCTF Internationals 2021 Az3z3l 2021-08-16 Web Exploitation tl;dr Notepad 1 - Use Set-Cookie header to get XSS on the Admin Notepad 1.5 - CRLF on the name parameter of Golang’s Header().Set() method Notepad 2 - Xsleaks using Timing-Allow-Origin header Read More InCTFi CRLF XSS Xsleaks