I solved two web challenges: required notes
and required notes revenge
. Although the intened solution is XS-Leak, I found RCE solution even for the revenge challenge!
- CTFtime:
- An author solution for required notes:
- https://gist.github.com/Ze-Pacifist/9bcd1072a62bbc5850322878b21bc8c8
- It uses a leak technique described in https://infosec.zeyu2001.com/2023/from-xs-leaks-to-ss-leaks.