๐ฏ JustCTF 2025 - 37h of top-tier online jeopardy CTF action!
๐๏ธ Starts Aug 2, 0600 UTC
๐ฐ $8,628 prize pool + IDA Pro licenses + swag
Big thanks to our sponsors!
@trailofbits@osec_io@HexRaysSA@zellic_io
https://t.co/YfVp7gaL9A | https://t.co/7N7YdKK9HP
#CTF#CyberSecurity
We are happy to remind that thanks to our sponsors, Trail of Bits & OtterSec, justCTF2024 teaser is coming. Save the date: 15.06.2024 8:00 UTC. Teaser is online event, and later we will host an offline finals. Registration is open. See more -> https://t.co/KmTzI7sNyN #ctf
With 12h more of hacking (and A LOT of reports to be processed, so it's all subject to change), we're 3rd as a team ๐ต๐ฑ of the H1 Ambassador World Cup qualis
Plus individually, we occupy 2 out of top 3 spots for bounties with DrBrix absolutely killing it in the 1st
I'm so happy!
A while ago I created a challenge for #justCTF23 where players needed to blindly exfiltrate data from MongoDB. Here is my payload which triggers DNS resolution. As far as I know, this is a new technique when having SSRF to Mongo without the ability to read the response ๐๐ฅ #CTF
thanks to mine and @haqpl $ 50k report @github with its @npmjs are improving the security for all ๐
"we received a report... of a vulnerability that would allow an attacker to publish new versions of any npm package..." ๐ฅ
#npm#bugbounty#infosec
an update on recent security incidents across the registry as well as a look into our ongoing investments in maintaining the security of the registry (including 2FA requirements) โฌ๏ธ https://t.co/IlB8Qf6HAM