Party Cat0%

CTF

HTTP Desync i XS-Leak mitjançant Range Oracle

29/06/26

HTTP Desync i XS-Leak mitjançant Range Oracle

Final | SekaiCTF 2026

Com la discrepància JSON-JavaScript condueix a RCE (Lodash)

26/01/26

Com la discrepància JSON-JavaScript condueix a RCE (Lodash)

Redacció oficial: gap | 0xL4ugh v5

Next.js DNS Rebinding, Python CRLF i pdfkit Injection

25/01/26

Next.js DNS Rebinding, Python CRLF i pdfkit Injection

Redacció oficial: pdf.exe | 0xL4ugh v5

Injecció DQL i ALGUN atac

10/11/25

Injecció DQL i ALGUN atac

Repte SMS v2 | CyCTF 2025

SROP, Stack Pivot i FSOP

09/11/25

SROP, Stack Pivot i FSOP

Reptes Pwn | CyCTF 2025

Injecció de comandaments de Linux

24/09/25

Injecció de comandaments de Linux

Redacció oficial: Mushroom Hates Letters | Finals IEEE 2025

CSP Bypass mitjançant XSS

20/09/25

CSP Bypass mitjançant XSS

Escrit oficial: rebutjat | IEEE 2025

Encadenant 6 errors a RCE

18/09/25

Encadenant 6 errors a RCE

Redacció oficial: Full Stack Disaster | ConnectorsCTF 2025

Exfiltració de dades mitjançant DNS

18/09/25

Exfiltració de dades mitjançant DNS

Redacció oficial: cat flag.png | ConnectorsCTF 2025

Injecció SQL i explotació JWT

13/09/25

Injecció SQL i explotació JWT

Redacció oficial: la promoció | ConnectorsCTF 2025

Injecció d'ordres mitjançant la revisió de fonts

12/09/25

Injecció d'ordres mitjançant la revisió de fonts

Redacció oficial: Banderes a l'aire | ConnectorsCTF 2025

Injecció SQL i exposició a Git

03/08/25

Injecció SQL i exposició a Git

Camí invisible | ASC Cyber ​​WarGames

React Router Trucs & Source Review

20/04/25

React Router Trucs & Source Review

Reptes web | b01lersCTF 2025

SSRF, GraphQL i engany de memòria cau

03/03/25

SSRF, GraphQL i engany de memòria cau

7 reptes web | Fawazeer Cyber ​​2025

API Race Conditions i Wireshark

01/03/25

API Race Conditions i Wireshark

Metodologia Tutorial | ApoorvCTF 2025

JWT Alg Confusió i condició de carrera

20/02/25

JWT Alg Confusió i condició de carrera

Bypass 2FA | NextGen Defense CTF 2025

Falsificació JWK i bypass OTP

16/12/24

Falsificació JWK i bypass OTP

Trencant banc | HTB University CTF 2024

Injecció SQL mitjançant cadenes de filtres PHP

03/11/24

Injecció SQL mitjançant cadenes de filtres PHP

SMS Challenge | CyCTF 2024

Injecció de comandaments

03/11/24

Injecció de comandaments

Màquina expenedora | CyCTF 2024

Sol·licitud de contraban, SSRF i Git

05/10/24

Sol·licitud de contraban, SSRF i Git

Col·lecció Web Challenge | Ferro CTF 2024

Explotació de versions de bucket S3

12/09/24

Explotació de versions de bucket S3

BucketWars | CSAW CTF 2024