Chika

>>> from user import place
# 18th

>>> from user import score
# 8700 points

Solves

Challenge Category Value Time
The Hidden Layer W6 100
Remote Code Execution (RCE) via File Upload Group 9 400
Weak JWT Secret Group 9 200
SQL Injection (SQLi) Group 9 200
Decoder Challenge Group 3 100
Cross-Site Scripting (XSS) Group 9 100
Insecure Direct Object Reference (IDOR) Group 9 100
Challenge 1: (Hard) Group 5 400
4th Challenge Group 8 200
1st Challenge Group 8 100
5th Challenge Group 8 400
3rd Challenge Group 8 200
SQL Injection Challenge Group 3 100
Weak Password Group 10 100
SQL Injection Group 10 200
Cross-Site Scripting (XSS) Group 10 200
2nd Challenge Group 8 100
Easy 2 Group 7 100
Medium 2 Group 7 200
Medium 1 Group 7 200
Path Traversal Group 4 200
Command Injection Group 4 400
Parameter Pollution Group 4 200
Search Functionality Group 4 100
JSON API Injection Group 4 100
Deven Biehler’s XSS-Attack (Easy) Group 1 100
JaSON Bourne's Secure Login (Medium) Group 1 200
SQL Injection Challenge (Easy) Group 1 100
Challenge 5 – Hard Group 6 400
Challenge 4 – Medium Group 6 200
Challenge 3 - Medium Group 6 200
Challenge 2 – Easy Group 6 100
Challenge 1 – Easy Group 6 100
Filter Evader W8 100
XSSInsider W8 100
Bank Heist: CSRF Exploit W8 100
SQLI HW3 100
XSS HW3 100
Broken Access Control HW3 100
Insecure File Upload HW3 100
IDOR HW3 100
Challenge_4 HW2 100
Silent Intrusion W6 100
Challenge_1 HW2 100
Challenge_2 HW2 100
XSS W5 100
Challenge_0 HW2 100
Cross Origin Chaos W5 100
Challenge_3 HW2 100
Bypass 2FA W3 100
Pathfinder W2 100
JavaScript Analysis W2 100
Elevated Access W2 100
HTTP Auth Bypass W2 100
Header Hunters W2 100
I told you not to look here! W1 100
Decode and Conquer(1) W1 100
Decode and Conquer(0) W1 100
Flag Within W1 100