nsatchison

>>> from user import place
# 17th

>>> from user import score
# 8900 points

Solves

Challenge Category Value Time
Decrypt Hidden Commit Challenge Group 3 400
Remote Code Execution (RCE) via File Upload Group 9 400
Command Injection Group 4 400
Path Traversal Group 4 200
Parameter Pollution Group 4 200
Challenge 3 - Medium Group 6 200
Challenge 5 – Hard Group 6 400
Easy 1 Group 7 100
Medium 1 Group 7 200
IDOR Challenge Group 3 200
Decoder Challenge Group 3 100
Challenge 4 – Medium Group 6 200
Challenge 2 – Easy Group 6 100
SQL Injection Challenge Group 3 100
Weak JWT Secret Group 9 200
SQL Injection (SQLi) Group 9 200
Insecure Direct Object Reference (IDOR) Group 9 100
SQL Injection Group 10 200
Cross-Site Scripting (XSS) Group 10 200
Weak Password Group 10 100
Open Redirect Group 10 100
2nd Challenge Group 8 100
5th Challenge Group 8 400
3rd Challenge Group 8 200
Challenge 2: (Easy) Group 5 100
Challenge 5: (Easy) Group 5 100
JSON API Injection Group 4 100
Search Functionality Group 4 100
JaSON Bourne's Secure Login (Medium) Group 1 200
Deven Biehler’s XSS-Attack (Easy) Group 1 100
Brute-Force Side-Channel Attack (Hard) Group 1 400
Client-side information leakage (Medium) Group 1 200
SQL Injection Challenge (Easy) Group 1 100
Filter Evader W8 100
SQLI HW3 100
XSS HW3 100
The Hidden Layer W6 100
IDOR HW3 100
Insecure File Upload HW3 100
Broken Access Control HW3 100
Silent Intrusion W6 100
Challenge_0 HW2 100
Challenge_1 HW2 100
Challenge_2 HW2 100
XSS W5 100
Challenge_4 HW2 100
Cross Origin Chaos W5 100
Challenge_3 HW2 100
Bypass 2FA W3 100
Pathfinder W2 100
JavaScript Analysis W2 100
HTTP Auth Bypass W2 100
Elevated Access W2 100
Header Hunters W2 100
I told you not to look here! W1 100
Decode and Conquer(0) W1 100
Decode and Conquer(1) W1 100
Flag Within W1 100