L3AK25: Writeup for Web/Window-of-Opportunity

Exploits window.opener with SOP disabled to bypass CSRF protections and read sensitive data from the admin’s tab via DOM access.

July 14, 2025 · 10 min · hxuu

L3AK25: Writeup for Web/Notorious-Note

A prototype pollution vulnerability in a custom parser enables bypassing sanitize-html, allowing an XSS via <iframe onload>. Exploitation relies on unsafe object property checks and inherited config values.

July 14, 2025 · 8 min · hxuu

L3AK25: Writeup for Web/Flag-L3ak

The application is vulnerable to a side-channel attack known as XS-Search, a subclass of XS-Leaks. By observing differences in server responses based on 3-character search queries, we reconstructed the flag one character at a time.

July 14, 2025 · 5 min · hxuu