Random idea : We can use XSS to exfiltrate passwords by abusing password managers autofill functionality. What we can do is inject a fake login page which gets filled up by a password manager like @LastPass , and our xss can steal them.
@s3cur3_1337 yes, changing the base leads to the repetition of a number which can be stripped off to reveal the flag. @StructHack solved it by doing frequency analysis in paper.
Can you find the flag from this?
Flag format : mrcb{....}
I wrote this challenge with one-liner JS
้้เฆเฆ้ฃ้้้ เฆ้้้้เฆเฆ้้เฆ้ ้้้้้้้้ ้้้ฅ
@dntverif@nullenc0de readme asks you to run as ./gofuzz.py however, there is a shebang missing in the source code. Try adding shebang and see if the problem resolves?
@pablos@samykamkar Looks like the link to the @samykamkar site is wrong there. It should have been https://t.co/kcX5Rz8xA8 . Gonna listen to the podcast soon :)
We've wrapped up our fifth onsite @hackthebox_eu meetup Nepal. It was organized in collaboration with women in cybersecurity for the women's cyber empowerment. We solved a Windows machine to get them started with CTF. Thanks @hackthebox_eu , and my team mates @maskop9@tnirmalz.
We've wrapped up fourth @hackthebox_eu meetup Nepal. It was an onsite event hosted for the college students. There were around 100+ participants and it was so overwhelming. We solved a medium level box named "interface". Looking forward to upcoming events. Keep hacking !
Excited to share my recent talk on WordPress Application Security at WordCamp Nepal! Check out the video to learn about tips and tricks to keep your WordPress site secure.
Disclaimer: It's in Nepali language but you can go through the slide.
https://t.co/PGQJw7RUa5