Skip to main content
INELab Showcase
Back to CTF
M

Mshadow4shell

@Mshadow4shell
Resolving local date…
Global rank
#1
All-time leaderboard
Total points
13,200
Across CTF seasons
Challenges solved
9
Distinct arenas
Captures solved
29
3392h 24m total
Activity

Submission rhythm.

Monthly Captures
01
Submissions

Public captures.

NexaCorp: Zero Credentials
You walk through a door using an identity you forgedCompleted450 pts
NexaCorp: Zero Credentials
The server fetches something internal on your behalfCompleted450 pts
NexaCorp: Zero Credentials
You gave yourself access the system never intended to grantCompleted450 pts
NexaCorp: Zero Credentials
A credential meant for someone else ends up in your handsCompleted450 pts
NexaCorp: Zero Credentials
Something was left exposed that shouldn't be publicCompleted450 pts
VulnCorp
What is the flag obtained from the debug admin panel accessed through secrets leaked in the exposed git commit history?Completed450 pts
Droid-Warden
If you’ve made it through the last door, it’s time to search for the treasure hidden within.Completed450 pts
Droid-Warden
Broken authentication is an invitation to attackers to walk right in. You don’t need to break the front door, it’s already unlocked.Completed450 pts
Droid-Warden
Feeling unwell? A doctor uses an injection. Some systems react similarly when prodded the right way.Completed450 pts
Droid-Warden
User “daniel” seems innocent enough, but not everyone takes security seriously, and he’s no exception.Completed450 pts
Droid-Warden
Look beyond what the app shows you to uncover the first flag.Completed450 pts
Silent Footprint
After successfully escalating privileges on the target, you read /root/flag.txt. Which flag is the final (root) flag?Completed450 pts
Silent Footprint
A hidden host is running a misconfigured service, after exploiting it and gaining access, what is the flag?Completed450 pts
Silent Footprint
While exploring ctf2.playground.ine, you examine the application folder. Which flag is found there?Completed450 pts
Silent Footprint
You've gained access to the host ctf.playground.ine. What is the first flag you discover on that machine?Completed450 pts
Token Takeover
When the mechanism meant to verify trust is deceived, what final secret comes to light?Completed450 pts
Token Takeover
In the subtle art of tampering with token headers, what forbidden message is uncovered?Completed450 pts
Token Takeover
When your token unexpectedly elevates its privileges, what hidden flag is revealed?Completed450 pts
Token Takeover
Some tokens carry secrets that should never be revealed. What hidden truth emerges?Completed450 pts
TravelEndpoint
Data is only as secure as its weakest link. Can you uncover information that shouldn't be accessible?Completed450 pts