CODEGATE 2012 – Vuln 400

We were presented with a web-page containing a number of functions. After clicking around for a bit it was clear the goal is to login to the board as ‘Baron zzingzzing’.

The access to the board is protected using a ‘certificate’. The site offers the possibility to obtain a certificate for ‘citizen’ but will only allow access to the board as baron, king or queen.

