OpenECSC 2024 Final Round — Slurm21 September 2024·322 words·2 minsValOpenECSC 2024 Web Mongodb Path-Traversal Hash-OracleExploiting a race condition in database writes and a checksum oracle to brute-force a secret file character by character.