
Hello team Thank you so much for organising the ctf it has helped a lot to learn and improve my knowledge now lets got to solution i have preapred short videos as a refrence for each part and broken down ctf in 8 challenges. So the ctf was broken into: 1. Gathering leaking to gain login credentials 2. Bypassing 1st 2fa 3. SSrf in cookies to getting the unauthorised apk 4. Getting Leaked Secret from apk 5. Accessing new employee account 6. Upgrading account privilages to admin and getting admin credentials 7. Login to Martin account and bypass 2nd 2fa 8. Bypass payment 2fa via CSS Injection via ssrf to get the flag 1.Gathering leaking to gain login credentials {F853363} So first we get that scope of the ctf was *.bountypay.h1ctf.com so ran a quick certspotter search on them gave api.bountypay.h1ctf.com app.bountypay.h1ctf.com software.bountypay.h1ctf.com staff.bountypay.h1ctf.com www.bountypay.h1ctf.com and running dirsearch on them i was able to see that https://app.bountypay.h1ctf.com/ subdomain git directory was exposed now among its git files the important one was /.git/config file which gave me information about this github page https://github.com/bounty-pay-code/request-logger/commit/07e138f46b09e1a702b9df8f1e701db20a38defa#diff-c3692912e7cb4cbcd03da419c135060e upon visting we get another path bp_web_trace.log so final path https://app.bountypay.h1ctf.com/p_web_trace.log were having system logs of brian oliver access which were base64 encoded log files...
SOCIAL SHARE CARD GENERATOR