I participated in both of these events to some extent, but I didn’t look at every challenge. This post is just a note to briefly record the solutions, without going into too much detail.
As usual, here are the keywords I noted:
- GraphQL batch query + alias
- Python os.path.join absolute path
- Svg XSS, foreignObject
- WebRTC CSP bypass
- Status code xsleak
- DNS rebinding
- nmap command injection
- Ruby rack file upload temporary storage
- buildConstraintViolationWithTemplate EL injection
- Request smuggling
- document.baseURI
- 200/404 status code xsleak