M
Mshadow4shell
@Mshadow4shell
Resolving local date…
Global rank
#1
All-time leaderboard
Total points
13,200
Across CTF seasons
Challenges solved
9
Distinct arenas
Captures solved
29
3392h 24m total
Activity
Submission rhythm.
Monthly captures
Monthly Captures
Submissions
Public captures.
- NexaCorp: Zero CredentialsYou walk through a door using an identity you forged450 ptsCompleted
- NexaCorp: Zero CredentialsThe server fetches something internal on your behalf450 ptsCompleted
- NexaCorp: Zero CredentialsYou gave yourself access the system never intended to grant450 ptsCompleted
- NexaCorp: Zero CredentialsA credential meant for someone else ends up in your hands450 ptsCompleted
- NexaCorp: Zero CredentialsSomething was left exposed that shouldn't be public450 ptsCompleted
- VulnCorpWhat is the flag obtained from the debug admin panel accessed through secrets leaked in the exposed git commit history?450 ptsCompleted
- Droid-WardenIf you’ve made it through the last door, it’s time to search for the treasure hidden within.450 ptsCompleted
- Droid-WardenBroken authentication is an invitation to attackers to walk right in. You don’t need to break the front door, it’s already unlocked.450 ptsCompleted
- Droid-WardenFeeling unwell? A doctor uses an injection. Some systems react similarly when prodded the right way.450 ptsCompleted
- Droid-WardenUser “daniel” seems innocent enough, but not everyone takes security seriously, and he’s no exception.450 ptsCompleted
- Droid-WardenLook beyond what the app shows you to uncover the first flag.450 ptsCompleted
- Silent FootprintAfter successfully escalating privileges on the target, you read /root/flag.txt. Which flag is the final (root) flag?450 ptsCompleted
- Silent FootprintA hidden host is running a misconfigured service, after exploiting it and gaining access, what is the flag?450 ptsCompleted
- Silent FootprintWhile exploring ctf2.playground.ine, you examine the application folder. Which flag is found there?450 ptsCompleted
- Silent FootprintYou've gained access to the host ctf.playground.ine. What is the first flag you discover on that machine?450 ptsCompleted
- Token TakeoverWhen the mechanism meant to verify trust is deceived, what final secret comes to light?450 ptsCompleted
- Token TakeoverIn the subtle art of tampering with token headers, what forbidden message is uncovered?450 ptsCompleted
- Token TakeoverWhen your token unexpectedly elevates its privileges, what hidden flag is revealed?450 ptsCompleted
- Token TakeoverSome tokens carry secrets that should never be revealed. What hidden truth emerges?450 ptsCompleted
- TravelEndpointData is only as secure as its weakest link. Can you uncover information that shouldn't be accessible?450 ptsCompleted