Overpass3 - Hosting 📅 Mar 11, 2021 · ☕ 9 min read · ✍️ M4t35Z dirfuzz --> backup --> gpg --> creds --> ftp --> pw reuse --> nfs
LaunchR 📅 Nov 1, 2020 · ☕ 4 min read · ✍️ M4t35Z IDOR discloses userid of other users. SSTI discloses SECRET_KEY which was same as the jwt secret. With this, I changed my userid to admin.
PlayerTwo 📅 Jul 1, 2020 · ☕ 14 min read · ✍️ M4t35Z My writteup about the insane PlayerTwo machine. I got access to the root flag on an unintended way. There is NO heap exploitation in this writeup!