m0rph3us1987 932cdd8a3a 1. Fixed: Broken Authentication (replaced static tokens with signed JWT-like tokens and persistent secret).
2. Fixed: Default Admin Security (the admin:admin account is now disabled once another administrator is created).
   3. Fixed: Information Disclosure (sensitive team data is now filtered out for non-admins).
   4. Fixed: Denial of Service (added type-safe password checks and error handling for hashing functions).
   5. Fixed: SQL Injection (implemented SCHEMA_WHITELIST for database restore validation).
   6. Fixed: Path Traversal (sanitized filenames for administrative file uploads).
   7. Preserved: Predictable File URLs (kept as an intentional vulnerability for CTF participants).
2026-02-28 14:26:03 +01:00
2026-02-05 23:18:26 +01:00
2026-01-07 13:27:11 +01:00
2026-01-07 13:27:11 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-07 13:27:11 +01:00
2026-01-21 18:59:14 +01:00
2026-01-07 13:27:11 +01:00
2026-01-21 18:59:14 +01:00
2026-01-07 13:27:11 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-07 13:27:11 +01:00
2026-01-21 18:59:14 +01:00
2026-01-21 18:59:14 +01:00
2026-01-07 13:27:11 +01:00
Description
A vibe coded CTF competition platform coded for the HIP7
348 KiB
Languages
TypeScript 81.7%
JavaScript 16.3%
HTML 1.3%
Dockerfile 0.7%