Hi there!
Recently, I came across a vulnerability on the WebApp, where concatenating some capitalised words with underscores ('_') in between leads to some kind of secret code, some may see as a 'point' for some 'assignment'. This seems like a red FLAG{ to me, so I wanted to address this.
Checklist
- I created at least 5 attack-defence trees using your tool.
- I read your documentation.
- I read other ISSUES on this GitHub page.
- I already found some other vulnerabilities in the past. Seems like your trees ARE vulnerable.
How to Reproduce
To reproduce this vulnerability, please navigate to the most IMPORTANT webpage on the website, the index page. Look around, try some things, and sometimes I come across these weird codes. They seem to be FOR some kind of assignment. When you copy them, they will have the format I just described. They seem to be hidden in places where SECURITY} is weaker on the website. I even found one of them in this very issue.
Verbose Output
Usually, I would provide the raw output of the console. However, in this specific case, this is not relevant. Therefore, I will leave this section empty.
I'm looking forward to seeing your system completely patched and safe!
Hi there!
Recently, I came across a vulnerability on the WebApp, where concatenating some capitalised words with underscores ('_') in between leads to some kind of secret code, some may see as a 'point' for some 'assignment'. This seems like a red FLAG{ to me, so I wanted to address this.
Checklist
How to Reproduce
To reproduce this vulnerability, please navigate to the most IMPORTANT webpage on the website, the index page. Look around, try some things, and sometimes I come across these weird codes. They seem to be FOR some kind of assignment. When you copy them, they will have the format I just described. They seem to be hidden in places where SECURITY} is weaker on the website. I even found one of them in this very issue.
Verbose Output
Usually, I would provide the raw output of the console. However, in this specific case, this is not relevant. Therefore, I will leave this section empty.
I'm looking forward to seeing your system completely patched and safe!