sh4yu

1st place

27100 points


Solves

Challenge Category Value Time
Access Log Sensitive Data Exposure 700
Change Bender's Password Broken Authentication 1000
Login Amy Sensitive Data Exposure 450
Reset Bender's Password Broken Authentication 700
Forged Signed JWT Vulnerable Components 1350
Client-side XSS Protection XSS 450
Repetitive Registration Improper Input Validation 100
Reset Uvogin's Password Sensitive Data Exposure 700
Forged Coupon Cryptographic Issues 1350
Unsigned JWT Vulnerable Components 1000
Exposed Metrics Sensitive Data Exposure 100
Reset Bjoern's Password Broken Authentication 1000
Bjoern's Favorite Pet Broken Authentication 450
CAPTCHA Bypass Broken Anti Automation 450
Multiple Likes Broken Anti Automation 1350
Upload Size Improper Input Validation 450
XXE Data Access XXE 450
Deprecated Interface Security Misconfiguration 250
Vulnerable Library Vulnerable Components 700
Legacy Typosquatting Vulnerable Components 700
Upload Type Improper Input Validation 450
Security Policy Miscellaneous 250
Weird Crypto Cryptographic Issues 250
Visual Geo Stalking Sensitive Data Exposure 250
Meta Geo Stalking Sensitive Data Exposure 250
Steganography Security through Obscurity 700
Mass Dispel Miscellaneous 100
Bonus Payload XSS 100
Password Strength Broken Authentication 250
Nested Easter Egg Cryptographic Issues 700
Forged Review Broken Access Control 450
Forged Feedback Broken Access Control 450
Zero Stars Improper Input Validation 100
Admin Registration Improper Input Validation 450
Retrieve Blueprint Sensitive Data Exposure 1000
HTTP-Header XSS XSS 700
Reflected XSS XSS 250
Five-Star Feedback Broken Access Control 250
Admin Section Broken Access Control 250
Misplaced Signature File Sensitive Data Exposure 700
Easter Egg Broken Access Control 700
Poison Null Byte Improper Input Validation 700
Forgotten Sales Backup Sensitive Data Exposure 700
Forgotten Developer Backup Sensitive Data Exposure 700
Login MC SafeSearch Sensitive Data Exposure 250
Confidential Document Sensitive Data Exposure 100
Reset Jim's Password Broken Authentication 450
View Basket Broken Access Control 250
Privacy Policy Miscellaneous 100
Bully Chatbot Miscellaneous 100
Score Board Miscellaneous 100
DOM XSS XSS 100
Error Handling Security Misconfiguration 100
Login Jim Injection 450
Login Bender Injection 450
Login Admin Injection 250