For the first time in my CTF career I saw such a shameless and broad flag sharing 😦 Almost all challenges dropped to minimal points with over 300 teams participating in the scheme! Only a few CTFs even get that number of all teams. That's just mind blowing 🤯
Thanks to @ENOFLAG for organizing another #ENOWARS this weekend, and to all participating teams! It was a lot of fun. And we appreciate all the feedback about our tooling ;)
Recently I played SAS CTF with @BushwhackersCTF and got stuck on client-side task. After I did some quick research on bypassing `Content-Disposition: attachment` for XSS
TL;DR:
- NEL header
- Link header
- Duplicate C-D header (most interesting!)
Writeup: https://t.co/bGz6oXX081
Although our main website has never had any content except silly logo easter egg, and nobody visits it, it will be in different colors for a while. https://t.co/YQNFf32dWG
Thank you to everyone who helped organize and all the people playing for an awesome #ictf2021!
Congrats to @BushwhackersCTF, @saarsec and @We_0wn_Y0u for finishing Top-3!
We've archived the final scoreboard and the game website at https://t.co/gkCnbdlv2X
The cup will begin its journey a little later, however guys from @towerofhanoi have already made it look right. Once more, congratulations to @BushwhackersCTF :)
@saarsec I didn't realize tweets starting with @ go straight to "tweets and replies" instead of main feed, so trying to mitigate this with self-repost :)