OpenECSC 2024 Final Round — Slurm21 September 2024·322 words·2 minsValOpenECSC 2024 Web Mongodb Path-Traversal Hash-OracleExploiting a race condition in database writes and a checksum oracle to brute-force a secret file character by character.
LA CTF 2024 — Jason Web Token17 February 2024·275 words·2 minsAugusto , RickbonavigoLA CTF 2024 Web Crypto Jwt Type-Juggling PythonAbusing Python’s floating point arithmetic to forge JWT-like tokens — when float(‘inf’) meets type juggling.