tl;dr
- Analysing Google keep mobile artifacts.
tl;dr
tl;dr
cflag.tl;dr
tl;dr
/gettoken%3fcreditcard=mmm&promocode=FREEWAF to get the token.{"name":"' union select flag, 1, 1, 1 from flag -- -", "name":"x"} to get the flag.tl;dr
__malloc_hook to one_gadgettl;dr
; secure; samesite=none to cookie. Now, <script src="https://jason.2021.chall.actf.co/flags?callback=load"></script> would retrieve the flag. tl;dr
tl;dr
tl;dr
tl;dr