web
Challenges
Renderer

Introducing Renderer! A free-to-use app to render your images!

Read a "secret" file that's stored in a directory that Flask automatically exposes via static file serving.
Storing secrets in the static/ directory (which Flask serves publicly)
Not implementing proper access control

scriptCTF{my_c00k135_4r3_n0t_s4f3!_edd23d3198a4}
Wizard Gallery

The council's top priority is to protect the flag, no matter the cost. Oh hey look, it's a photo gallery. What could go wrong?
Last updated