RCE by uploading a web.config

TL;DR By uploading a web.config I was able to bypass the blacklist, which blocks files with an executable extension (such as ‘.asp’ and ‘.aspx’). After setting execution rights to ‘.config’ and then adding asp code […] Read More

ICU – Keep An Updated Database Of Your Assets

ICU  Is a tool to constantly keep an updated database with all your assets. It contains the program linked to the domain, the domain status, if the (sub)domain is in scope and more… Why? I […] Read More

Getting stack traces with limited SSRF (ASP.NET)

TL;DR  Most ASP.NET MVC sites have ‘customErrors’ on ‘RemoteOnly’, since this is default, which returns custom error pages outside of localhost (remote). But while on localhost, it returns the full error information including stack trace, […] Read More

How I discovered 1500+ test accounts

TL;DR  By using the search function in the mail with an empty search string, I retrieved all the usernames, for which I then checked if the password is the same as the username. By filtering […] Read More

H1-212 CTF ~ Write-Up
Scroll Up