Although it’s been almost two months, I’m still going to take some notes. Last year, I was electrocuted badly. I thought it would be better this year since it’s been a year, but I still got electrocuted.
Keywords:
- SSRF mongoDB via telnet protocol
- jetty cookie parser
- ASI (Automatic Semicolon Insertion)
- VM sandbox escape via Proxy
- process.binding
- Browser’s XSLT + XXE
First, let me post the official repo, which contains the code and answers: https://github.com/dicegang/dicectf-2023-challenges