Mr. McFlurry

2nd place

24000 points


Solves

Challenge Category Value Time
Change Bender's Password Broken Authentication 1000
Reflected XSS XSS 250
Forged Coupon Cryptographic Issues 1350
Retrieve Blueprint Sensitive Data Exposure 1000
Password Strength Broken Authentication 250
Reset Bender's Password Broken Authentication 700
Reset Jim's Password Broken Authentication 450
Login Amy Sensitive Data Exposure 450
Reset Uvogin's Password Sensitive Data Exposure 700
Forged Signed JWT Vulnerable Components 1350
Exposed Metrics Sensitive Data Exposure 100
Login Jim Injection 450
Login Bender Injection 450
Reset Bjoern's Password Broken Authentication 1000
Bjoern's Favorite Pet Broken Authentication 450
Security Policy Miscellaneous 250
Misplaced Signature File Sensitive Data Exposure 700
Unsigned JWT Vulnerable Components 1000
Mass Dispel Miscellaneous 100
Vulnerable Library Vulnerable Components 700
Legacy Typosquatting Vulnerable Components 700
CAPTCHA Bypass Broken Anti Automation 450
Nested Easter Egg Cryptographic Issues 700
Weird Crypto Cryptographic Issues 250
Multiple Likes Broken Anti Automation 1350
Forged Feedback Broken Access Control 450
Forged Review Broken Access Control 450
View Basket Broken Access Control 250
Confidential Document Sensitive Data Exposure 100
Deprecated Interface Security Misconfiguration 250
XXE Data Access XXE 450
Upload Type Improper Input Validation 450
Easter Egg Broken Access Control 700
Poison Null Byte Improper Input Validation 700
Forgotten Developer Backup Sensitive Data Exposure 700
Forgotten Sales Backup Sensitive Data Exposure 700
Login MC SafeSearch Sensitive Data Exposure 250
Admin Registration Improper Input Validation 450
Visual Geo Stalking Sensitive Data Exposure 250
Meta Geo Stalking Sensitive Data Exposure 250
Five-Star Feedback Broken Access Control 250
Admin Section Broken Access Control 250
Zero Stars Improper Input Validation 100
Bonus Payload XSS 100
Bully Chatbot Miscellaneous 100
Score Board Miscellaneous 100
Privacy Policy Miscellaneous 100
DOM XSS XSS 100
Login Admin Injection 250
Error Handling Security Misconfiguration 100