| The Return of the Grinch |
Information Disclosure |
w31rd0 |
Critical |
2022-02-01 |
| Saving Christmas from Grinchy Gods |
SQL Injection |
akshansh |
Critical |
2022-02-01 |
| ccc ctf |
SQL Injection |
shamollash |
Critical |
2021-06-23 |
| HackerOne’s 100K CTF Writeup |
XML External Entities (XXE) |
rykkard |
Critical |
2021-06-21 |
| 100K CTF's Writeup |
SQL Injection |
dexter0us |
Critical |
2021-06-21 |
| CCC H1 June 2021 CTF Writeup |
XML External Entities (XXE) |
pmnh |
Critical |
2021-06-21 |
| Adam and the Deadly Injections |
Out-of-bounds Read |
akshansh |
Critical |
2021-06-18 |
| ccc.h1ctf.com CTF |
SQL Injection |
erbbysam |
Critical |
2021-06-18 |
| H1-CTF 100k Solution - Congratz on the 100k Rep todayisnew |
SQL Injection |
w31rd0 |
Critical |
2021-06-17 |
| [100K-ctf] Multiple vulnerabilities leading to compromise of Pinger instance. |
None supplied |
nukedx |
No rating |
2021-06-17 |
| Grinchs website takendown with various other exploits |
Improper Restriction of Authentication Attempts |
archerl |
Critical |
2021-03-02 |
| hackyholidays CTF Writeup |
None supplied |
un5h4d0w |
Critical |
2021-03-02 |
| Taking Grinch Down To Save Holidays |
SQL Injection |
akshansh |
Critical |
2021-01-22 |
| Hackyholidays [ h1-ctf] writeup [mission:- stop the grinch ] |
Improper Access Control - Generic |
kunal94 |
Critical |
2021-01-14 |
| CTF Writeup |
SQL Injection |
a_l |
Critical |
2021-01-14 |
| h1-ctf : 12 days of hack holiday writeup |
Information Disclosure |
webhak |
Critical |
2021-01-14 |
| Solution for hackyholiday |
None supplied |
holme |
No rating |
2021-01-12 |
| ctf walkthrough |
Information Disclosure |
rekter0 |
No rating |
2021-01-12 |
| Flags for hackyholidays CTF |
None supplied |
yashrs |
No rating |
2021-01-12 |
| It's just a man on a mission |
None supplied |
thezoomer |
Critical |
2021-01-12 |
| Mission completed. Grinch Networks is down and Christmas saved. |
Uncontrolled Resource Consumption |
yso |
Critical |
2021-01-12 |
| Wholesome Hacky Holidays: A Writeup |
None supplied |
ph0cu5 |
Critical |
2021-01-12 |
| Writeup Hackyholiday CTF |
None supplied |
abdilahrf_ |
Critical |
2021-01-12 |
| Hacky Holidays CTF Writeup |
Uncontrolled Resource Consumption |
w-- |
Critical |
2021-01-12 |
| [hacky-holidays] Grinch network is down |
None supplied |
mzfr |
Critical |
2021-01-12 |
| [hackyholidays] CTF write-up |
None supplied |
rend |
Critical |
2021-01-12 |
| [H1 hackyholidays] CTF Writeup |
Information Disclosure |
macasun |
Critical |
2021-01-12 |
| Hacky Holidays Writeup |
None supplied |
cardinal |
Critical |
2021-01-12 |
| Complete destruction of the Grinch server |
Business Logic Errors |
shamollash |
High |
2021-01-12 |
| Invading Grinch Network and Saving Christmas |
None supplied |
w31rd0 |
Critical |
2021-01-12 |
| Successfully took down the Grinch and saved the holidays from being ruined |
None supplied |
shubhamz007 |
Critical |
2021-01-12 |
| First CTF ever! |
SQL Injection |
eliee |
Critical |
2021-01-12 |
| Hackyholidays CTF writeup |
Improper Restriction of Authentication Attempts |
xehle |
None |
2021-01-12 |
| 12 Days of Hacky Holidays write-up, but as a text-based RPG? |
Uncontrolled Resource Consumption |
dee-see |
None |
2021-01-11 |
| How The Hackers Saved Christmas |
Information Disclosure |
nytr0gen |
Critical |
2021-01-11 |
| Hacky Holidays CTF Writeup |
Server-Side Request Forgery (SSRF) |
rykkard |
Critical |
2021-01-11 |
| HackyHolidays 2020 Full Write-up: Information Disclosure of 12 Flags |
Information Disclosure |
liamg |
Critical |
2021-01-11 |
| [h1ctf-Grinch Networks] MrR3b00t Saving the Christmas |
None supplied |
d3f4u17 |
Critical |
2021-01-11 |
| h1 hacky holidays CTF solution |
Buffer Over-read |
erbbysam |
Critical |
2021-01-11 |
| H1 Hackyholidays CTF - The Grinch was defeated |
None supplied |
val_brux |
Critical |
2021-01-11 |
| Infiltrating into Grinch-Networks and saving Christmas! |
Server-Side Request Forgery (SSRF) |
castilho |
Critical |
2021-01-11 |
| A Visit from The Grinch ~ 'Twas the night before Hackmas... |
Improper Access Control - Generic |
bendtheory |
Critical |
2021-01-11 |
| Grinch Networks compromised! |
None supplied |
zonduu |
Critical |
2021-01-11 |
| Grinch-Networks taken down - hacky holidays CTF |
Improper Restriction of Authentication Attempts |
pirateducky |
Critical |
2021-01-11 |
| Writeup Submission |
None supplied |
h3x0ne |
High |
2021-01-11 |
| HackyHolidays H1 CTF Writeup |
None supplied |
mava |
No rating |
2021-01-11 |
| [ Hacky Holidays CTF ] Completely taken down the Grinch Networks |
Server-Side Request Forgery (SSRF) |
ht0x0 |
Critical |
2021-01-11 |
| 12 Days of CTF Walkthroughs |
Server-Side Request Forgery (SSRF) |
meraxes |
Critical |
2021-01-11 |
| [h1-ctf] 12 Days of Adventure to stop Grinch from ruining Christmas |
None supplied |
sudi |
No rating |
2021-01-11 |
| [CTF] I've DDoSed Grinch Network |
Uncontrolled Resource Consumption |
jeti |
Critical |
2021-01-11 |
| Stopping Grinch to ruin XMas! |
None supplied |
nukedx |
No rating |
2021-01-11 |
| [h1-2006 2020] Bounty payments are done ! |
Server-Side Request Forgery (SSRF) |
louzogh |
Critical |
2020-09-14 |
| [h1-2006 2020] Bounty payments are done ! |
Server-Side Request Forgery (SSRF) |
louzogh |
Critical |
2020-09-14 |
| @shakedko H1-2006 CTF writeup |
None supplied |
shakedko |
Critical |
2020-07-06 |
| [h1-2006 CTF] Multiple vulnerabilities leading to account takeover and two-factor authentication bypass allows to send pending bounty payments |
None supplied |
kapytein |
Critical |
2020-07-06 |
| [H1-2006 2020] CTF Writeup |
None supplied |
yashrs |
No rating |
2020-07-06 |
| [H1-2006 2020] Got the flag |
Buffer Underflow |
s1r1u5 |
Critical |
2020-06-25 |
| [H1-2006 2020] CTF Writeup |
Server-Side Request Forgery (SSRF) |
leoastorga_g |
Critical |
2020-06-23 |
| [H1-2006 2020] Bypassing access control checks by modifying the URL, internal application state, or the HTML page, or using a custom API attack tool |
Privilege Escalation |
bcobain23 |
Critical |
2020-06-22 |
| [H1-2006 2020] CTF Writeup |
None supplied |
un5h4d0w |
Critical |
2020-06-22 |
| [H1-2006 2020] Multiple vulnerabilities allow to leak sensitive information |
Improper Access Control - Generic |
zoczus |
No rating |
2020-06-22 |
| [H1-2006 2020] From multiple vulnerabilities to complete ATO on any customer account and staff admin |
Violation of Secure Design Principles |
rreiss |
Critical |
2020-06-22 |
| [H1-2006] CTF Writeup |
Improper Access Control - Generic |
nirvana_msu |
Critical |
2020-06-19 |
| [h1-2006 CTF] Payments for May have been processed! |
Information Disclosure |
vakzz |
Critical |
2020-06-19 |
| [H1-2006 2020] The Story of Making Bounty Hunters Happy |
Improper Access Control - Generic |
w31rd0 |
No rating |
2020-06-19 |
| [h1-2006 2020] Writeup h12006 CTF |
Privilege Escalation |
0xxl |
High |
2020-06-19 |
| [h1-2006 2020] CTF Walkthrough |
Server-Side Request Forgery (SSRF) |
meraxes |
Critical |
2020-06-18 |
| [H1-2006 2020] Connecting the dots to send hackers their Bug Bounty |
Code Injection |
akshansh |
Critical |
2020-06-18 |
| [H1-2006 2020] Writeup |
Improper Access Control - Generic |
njbooher |
No rating |
2020-06-18 |
| [H1-2006 2020] Multiple vulnerabilities leading account takeover |
Privilege Escalation |
nukedx |
Critical |
2020-06-18 |
| [H1-2006 2020] 36 hours of brain cycles utilized on solving a neat puzzle |
None supplied |
0xatul |
No rating |
2020-06-18 |
| [H1-2006 2020] CTF Writeup! |
None supplied |
sw33tlie |
Critical |
2020-06-18 |
| [H1-2006 2020] In-depth resolution of the h1-2006 CTF |
Improper Access Control - Generic |
enzyro |
Critical |
2020-06-18 |
| [H1-2006 2020] I successfully solved it! |
None supplied |
zeroxyele |
Critical |
2020-06-18 |
| [H1-2006 2020] How I solved my first H1 CTF |
Violation of Secure Design Principles |
cr33pb0y |
Critical |
2020-06-18 |
| [H1-2006 2020] Multiple vulnerabilities lead to CEO account takeover and paid bounties |
Improper Authentication - Generic |
fersingb |
Critical |
2020-06-18 |
| [H1-2006 2020] CTF writeup |
None supplied |
0xbeefed |
No rating |
2020-06-18 |
| [H1-2006 2020] "Swiss Cheese" design style leads to helping Mårten Mickos pay poor hackers |
Execution with Unnecessary Privileges |
al-madjus |
No rating |
2020-06-18 |
| [H1-2006 2020] CTF |
Violation of Secure Design Principles |
jeti |
Critical |
2020-06-18 |
| [H1-2006 2020] H1-CTF writeup |
None supplied |
smaury |
None |
2020-06-18 |
| [H1-2006 2020] Solution for the h1-2006 CTF challenge |
Privilege Escalation |
thehackerish |
High |
2020-06-18 |
| [h1-2006 2020] Chained vulnerabilities lead to account takeover |
Insecure Storage of Sensitive Information |
kanytu |
Critical |
2020-06-18 |
| [H1-2006 2020] Includes 1 free content discovery |
Improper Restriction of Authentication Attempts |
osintopsec |
Critical |
2020-06-18 |
| [H1-2006 2020] CTF write-up |
Server-Side Request Forgery (SSRF) |
counterbreach |
Critical |
2020-06-18 |
| [H1-2006 2020] Exploiting multiple vulnerabilities to get hacker's payment ensured |
Improper Privilege Management |
hecsv17 |
Critical |
2020-06-18 |
| [H1-2006 2020] ^FLAG^736c635d8842751b8aafa556154eb9f3$FLAG$ |
None supplied |
pirateducky |
Critical |
2020-06-18 |
| [H1-2006 2020] CTF Writeup |
Server-Side Request Forgery (SSRF) |
0xcaptainfreak |
Critical |
2020-06-18 |
| h1-ctf writeup , finally paid the payments by chaining multiple bugs |
Information Disclosure |
d1r3wolf |
Critical |
2020-06-18 |
| [H1-2006 2020] H1-2006 CTF Writeup |
Information Disclosure |
nytr0gen |
Critical |
2020-06-18 |
| [H1-2006 2020] I successfully solved it! |
None supplied |
zeroxyele |
Critical |
2020-06-18 |
| [H1-2006 2020] Flag for H1-CTF |
None supplied |
batee5a |
No rating |
2020-06-18 |
| [H1-2006 2020] [Multiple Vulnerability] CTF Writeup - @abdilahrf_ |
None supplied |
abdilahrf_ |
Critical |
2020-06-18 |
| [H1-2006 2020] CTF write-up |
Privilege Escalation |
diegobernal |
Critical |
2020-06-18 |
| [h1-2006 2020] Write up for H1-2006 CTF |
None supplied |
zer0ttl |
Critical |
2020-06-18 |
| [H1-2006 2020] CTF Writeup |
None supplied |
hipotermia |
Critical |
2020-06-18 |
| [H1-2006 2020] Bounty Pay CTF challenge |
Improper Access Control - Generic |
0xfd |
Critical |
2020-06-18 |
| [H1-2006 2020] I made the CEO's bounty payment! |
None supplied |
bugra |
Critical |
2020-06-18 |
| [h1-415 2020] SSRF in a headless chrome with remote debugging leads to sensible information leak |
Server-Side Request Forgery (SSRF) |
d1r3wolf |
Critical |
2020-02-04 |
| [h1-415 2020] Spent a week and failed at solving the last step. |
Improper Access Control - Generic |
s1r1u5 |
Critical |
2020-02-04 |
| [h1-415 2020] Multiple vulnerabilities leading to leaking of secret user files |
Server-Side Request Forgery (SSRF) |
nukedx |
Critical |
2020-02-03 |
| [h1-415 2020] My writeup on how to retrieve the special secret document |
Improper Authentication - Generic |
blaklis |
Critical |
2020-02-03 |
| [h1-415 2020] @_bayotop h1-415-ctf writeup |
Privilege Escalation |
bayotop |
Critical |
2020-02-03 |
| [h1-415 2020] H1-415 CTF Writeup by W-- |
Security Through Obscurity |
w-- |
Critical |
2020-02-03 |
| [h1-415 2020] Chain of vulnerabilities leading to account takeover and unauthorized access of sensitive internal resources |
Server-Side Request Forgery (SSRF) |
checkm50 |
Critical |
2020-02-03 |
| [h1-415 2020] finally |
Improper Authentication - Generic |
003random |
High |
2020-02-03 |
| [h1-415 2020] h1ctf{y3s_1m_c0sm1c_n0w} |
Improper Access Control - Generic |
pirateducky |
Critical |
2020-02-03 |
| [h1-415 2020] Multiple chained vulnerabilities lead to leaking secret document |
None supplied |
nytr0gen |
Critical |
2020-02-03 |
| [h1-415 2020] I got the flag |
Improper Access Control - Generic |
jllis |
Critical |
2020-02-03 |
| [h1-415 2020] I found Joberts missing file! |
Violation of Secure Design Principles |
p4fg |
No rating |
2020-02-03 |
| [h1-415 2020] Solution for h1415's CTF challenge |
None supplied |
herrera |
None |
2020-02-03 |
| [H1-415 2020] CTF Writeup |
Server-Side Request Forgery (SSRF) |
manoelt |
Critical |
2020-02-03 |