CTFのWebにおける⾼難易度問題について
at 魔⼥のお茶会 #7 おふらいん!(2025 冬)
問題集 https://docs.google.com/spreadsheets/d/12nRbFdmwNPBOcD2eitybnVixar-LVFmm_WudrOObVf4/edit?usp=sharing
以下、参照リンクです。
AlpacaHack Round 7 (Web) - disconnection-revenge
https://dimas0305.notion.site/Bypassing-null-Origin-in-4xx-Status-Code-Using-Iframe-disconnection-revenge-Writeup-AlpacaHack-R-14e48583e65d80e6b8d5c53f07905d97
Nowruz 1404 CTF - 🌱
FMCTFの公式Discordより
TSG CTF 2024 - I Have Been Pwned
https://blog.hamayanhamayan.com/entry/2024/12/15/201408#web-I-Have-Been-Pwned
KalmarCTF 2025 - spukhafte Fernwirkung
https://github.com/kalmarunionenctf/kalmarctf/tree/main/2025/web/spukhafte/solution
SEKAI CTF 2024 - Chunky
https://fireshellsecurity.team/sekaictf-frog-waf-and-chunky/#challenge-chunky-16-solves
SECCON CTF 13 Qual - JavaScrypto
https://zenn.dev/ponyopoppo/articles/894c3c2e5a06b6#javascrypto
corCTF 2022 friends
https://x.com/hamayanhamayan/status/1557584112004648961
[1] セキュリティにおける"gadget"とは何なのか?
https://blog.hamayanhamayan.com/entry/2022/09/14/212004
ImaginaryCTF 2023 - Sanitized Revenge
https://github.com/maple3142/My-CTF-Challenges/blob/master/ImaginaryCTF%202023/Sanitized%20Revenge/README.md
SECCON CTF 13 Qual - Double-Parser
https://zenn.dev/tchen/articles/0efc8f9679a818#%E2%9C%85-double-parser-(221pts-17solves)
Flatt Security XSS Challenge - hamayanhamayan問
https://speakerdeck.com/flatt_security/jie-da-jie-shuo-flatt-security-xss-challenge
防衛省サイバーコンテスト2023 - Bypass
https://blog.hamayanhamayan.com/entry/2023/08/06/220606#web-Bypass