Recently, there were several CTF challenges that were quite good, such as SECCON and HITCON, but unfortunately, I was traveling abroad at that time and was too lazy to write complete writeups after returning. Originally, I was even too lazy to take notes, but once time passed, it became difficult to find related information, so I decided to write a brief summary.
In addition, I will also briefly mention several challenges that I think I should have taken notes on before, but for some reason, I did not.
Keywords:
- Node.js prototype pollution gadget to RCE (Balsn CTF 2022 - 2linenodejs)
- Obtaining the original value of a JS proxy (corCTF 2022 - sbxcalc)
- Cache of browser back behavior (SECCON CTF 2022 - spanote)
- Using SVG to create synchronous XSS (HITCON CTF 2022)
- Reading data from shadow DOM (HITCON CTF 2022)