
DreamHack - Are you admin? Web Challenge Write-up
Hmm... You look suspicious. Are you admin?

Hmm... You look suspicious. Are you admin?

Understand the basics of LLM Prompt Injection attacks.

A patched issue for Exercise: Relative Path Overwrite.

Dream built a web crawling site. Find vulnerabilities on crawling sites and earn flags!

Dream has started development as a Tomcat server. Find vulnerabilities in services and obtain flags. The flag is /flag on the path.

Exercise: This is an exercise in Relative Path Overwrite.

Log in as an administrator to earn flags! The flag format is DH{...}

Analyze the given code and logs to find answers that correspond to the given questions.

This is an exercise in Client Side Template Injection.

Flags can be obtained by writing CSP according to the conditions required by the question.