AlpacaHack Logo

Challenges

Sign InSign Up

Rows:

CHALLENGEAUTHORS

SOLVES

(CURRENT)

SOLVE RATE

(AT CONTEST TIME)

Welcome
Misc

admin

858

solves

-

AlpacaHack Round 2 (Web)

366

solves

Top 28%

= 84/300 users

echo
Pwn

AlpacaHack Round 1 (Pwn)

240

solves

Top 32%

= 56/174 users

qrime
Crypto

AlpacaHack Round 3 (Crypto)

177

solves

Top 38%

= 91/239 users

AlpacaHack Round 7 (Web)

172

solves

Top 15%

= 71/458 users

CakeCTF 2023

148

solves

Top 33%

= 246/729 teams

AlpacaHack Round 6 (Pwn)

138

solves

Top 28%

= 57/197 users

AlpacaHack Round 8 (Rev)

112

solves

Top 19%

= 61/316 users

RTACTF 2023 Spring

107

solves

-

AlpacaHack Round 6 (Pwn)

104

solves

Top 20%

= 41/197 users

AlpacaHack Round 4 (Rev)

91

solves

Top 15%

= 42/279 users

AlpacaHack Round 3 (Crypto)

87

solves

Top 17%

= 42/239 users

AlpacaHack Round 1 (Pwn)

86

solves

Top 15%

= 27/174 users

AlpacaHack Round 7 (Web)

83

solves

Top 9%

= 42/458 users

CaaS
Web

AlpacaHack Round 2 (Web)

63

solves

Top 4%

= 13/300 users

AlpacaHack Round 3 (Crypto)

59

solves

Top 12%

= 30/239 users

AlpacaHack Round 2 (Web)

58

solves

Top 3%

= 10/300 users

XOR-CBC
Crypto

RTACTF 2023 Spring

57

solves

-

AlpacaHack Round 10 (Pwn)

57

solves

Top 42%

= 40/95 users

RTACTF 2023 Spring

56

solves

-

Rows:

🍪

SECCON CTF 13 決勝観戦CTF
161 solves
WebBeginner

Author:

ある条件を満たすとフラグが得られるようです

import Fastify from "fastify";
import fastifyCookie from "@fastify/cookie";

const fastify = Fastify();
fastify.register(fastifyCookie);

fastify.get("/", async (req, reply) => {
  reply.setCookie('admin', 'false', { path: '/', httpOnly: true });
  if (req.cookies.admin === "true")
    reply.header("X-Flag", process.env.FLAG);
  return "can you get the flag?";
});

fastify.listen({ port: process.env.PORT, host: "0.0.0.0" });

*完全なソースコードは以下からダウンロード可能です。

cookie.tar.gz
descriptionsolveswriteups