Cyber Apocalypse 2022 - Red Island (Web: 325 points)

2022-05-19

For this web challenge we'll chain together multiple vulnerabilities, starting from a simple SSRF and resulting in RCE through a Redis service.

SSRF Redis RCE

Pico CTF 2022 - Noted (Web: 500 points)

2022-03-27

To solve this challenge we need to make use of stored cross-site scripting (XSS) as well as server-side request forgery (SSRF) whilst taking advantage of an automated user in the form of a headless chrome browser.

XSS Same Origin Policy JavaScript