
First of all, thanks for the awesome CTF. I enjoyed it very much :) Summary The CTF was about helping HackerOne's beloved CEO, @martenmickos, to approve May bug bounty payments after he has lost his login details for BountyPay. It all started with this tweet: {F860982} And as you all know, I had to help him since ~~ItTakesACrowd~~! Ohh sorry.. That's not our motto here, but TogetherWeHitHarder is! ;) Let's start by saying that Marten can relax, I paid it all. I've sacrificed a few sleepless nights just for him to sleep well. ? {F859739} Flag: ^FLAG^736c635d8842751b8aafa556154eb9f3$FLAG$ In this report, I'll try to focus more on my way of thinking, rather than on the technical implementation so others will be able to learn what I've learned and use it to hit harder and make our world a safer place. CTF Walkthrough Recon I've started the challenge by performing two basic recon steps: - Subdomain enumeration with subfinder (subfinder -d bountypay.h1ctf.com). This revealed the following subdomains: bash app.bountypay.h1ctf.com www.bountypay.h1ctf.com bountypay.h1ctf.com software.bountypay.h1ctf.com staff.bountypay.h1ctf.com api.bountypay.h1ctf.com Directories/files enumeration with ffuf and SecLists which found a .git/HEAD file in app.bountypay.h1ctf.com. ffuf -w ./SecLists/Discovery/Web-Content/common.txt -u "https://app.bountypay.h1ctf.com/FUZZ" -ac {F859753} In short, that means that we may be able to retrieve more information about the code in this application and maybe...
SOCIAL SHARE CARD GENERATOR