Orel's Avatar

Orel

@orelg

My information security blog: www.thesecuritywind.com

16
Followers
121
Following
10
Posts
29.11.2024
Joined
Posts Following

Latest posts by Orel @orelg

Preview
1753CTF 2025 Writeups This time I couldn't invest a lot of time, but I still solved some easy challenges.1753CTF 2025 was different from those I participated in the past, in a way that the interaction with the platform (su...

My last writeups for three easy challenges from 1753CTF.
Simple broken access control, Unicode normalization and bcrypt input truncation.

www.thesecuritywind.com/post/1753ctf...

14.04.2025 22:02 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Sounds unfair to me, as it was exploitable. The only issue was in their web app. Correct me if I'm wrong

07.03.2025 21:23 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Nice flow! What was the reason they considered it as out of scope?

07.03.2025 10:15 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Which ones do think might be suitable?

27.12.2024 16:48 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

๐Ÿ˜†

21.12.2024 12:48 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I guess it's less tested than other types of vulnerabilities, so I'm just curious.

16.12.2024 18:31 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Very interesting. How common do you think prototype pollution is in JavaScript web applications?

16.12.2024 18:28 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Post image

A small code-golf web challenge (free research from you, for me), how short can you make a "fetch content and execute it inline".

There is a CSP in a meta tag.
Goal: get the content from the file hack.js and have it inserted in the page. like in the image

joaxcar.com/xss/self.html

12.12.2024 13:00 ๐Ÿ‘ 36 ๐Ÿ” 7 ๐Ÿ’ฌ 5 ๐Ÿ“Œ 3

The Silent Sea

11.12.2024 00:27 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Amazing, good luck!

07.12.2024 13:08 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
World Wide CTF 2024 World Wide Email Search Writeup (Web) I think this was the first time I was part of one of the first teams to solve a hard challenge in a big CTF. We were the third team to solve it (it ended with 7 solves out of ~580 teams). Sagiv and I worked together on this challenge and it was enriching and fun, especially because I tried a lot of different things along the way and learned new things.The solution to this challenge might seem a bit straightforward or easy but I think what made it a hard challenge were the subtle hints and limite

Here's a link to my latest blog post!
www.thesecuritywind.com/post/world-w...

02.12.2024 15:49 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0