Mike Lemire
banner
mike-lemire.bsky.social
Mike Lemire
@mike-lemire.bsky.social
info sec and compliance leader. opinions my own.
Reposted by Mike Lemire
How I Found 7 Logical Bugs in the com-olho CTF Feature
How I Found 7 Logical Bugs in the com-olho CTF Feature
Welcome back! You might remember that in the last blog I talked about 7 bugs in a small part of a website  — this blog is about that. And sorry, I don’t have any proof images this time (as always), because the platform com-olho blocked me. Yeah — they just blocked me. All my triage report, upcoming payment was just gone. They don’t respond to emails at all. So be careful if you’re hunting on comolho. Yes, I’m taking the name — because honestly, what worse can they do now? Let me clear a one things. All the 7 bugs covered in these blogs were on their own platform, comolho , and all of them were successfully fixed. Let’s talk about the website in sort. The platform has a CTF program where you can submit flags and earn some points according to level of CTF. You can also create your own CTF and earn points if it’s good enough, they will upload it to their program. 1. Unlimited Points Farming via Replayed Flag Submission — P2 So when we submit a correct flag, we get points and the submit flag option is removed . The bug is that only the input is removed — there is no server-side validation . While submitting a correct flag, I capture the request: POST /api/ctf/submit_answer/128 using Burp. Send this request to Repeater. Now I can submit the same flag infinite times , and each time it will give me points. 2. Race Condition Allows User To Collect Extra Points From Single — P4 I know you might be thinking why this is separated from point 1  — it’s because I found this later. Follow the same process until the request is in Repeater, then right-click and choose extension , and select Turbo Intruder . Choose any script and launch the attack — the points get added multiple times. 3. https://strangerwhite.medium.com/how-i-stumbled-on-a-bug-that-gave-5x-the-rewards-without-any-hacking-tools-002767451f85 Please read this blog first for better understanding of how creating and submitting your own CTF works because all the below bugs are related this. 4. Unlimited Points Earned By Re-submitting CTF Using Draft Manipulation — P2 When you submit your own CTF for review, you normally cannot revert it back to draft  — you can only edit the CTF. Open Burp Suite and intercept the request while submitting a CTF: POST /ctf/123/ Send this request to Repeater and then let the intercepted request go forward (note: this is not the same as the first bug ). The CTF is submitted successfully, and I get points for submitting it. Now i come back to the Repeater tab and modify the request by adding: save_as_draft = true Send the request. The CTF reverts back to draft . I repeated this process again and again, and each time I received points. How did I know save_as_draft was a parameter? Because when I originally submitted the CTF as a draft, this parameter was present in the request. Real request 5. Race Condition Allows Submitting More Than 5 CTF per Months — P3 Because of the huge number of CTF submissions, they decided to limit it to only 5 CTFs per month . I created more than 5 CTFs and saved all of them as  drafts . Open Burp Suite, click on Edit CTF , and in the request i get the CTF ID . Don’t change anything — just save it as a draft. Do the same for all other CTFs to collect their CTF IDs . Now submit a CTF and send this request to Repeater multiple times (5+) . After that, change the CTF IDs in the requests (the ones obtained in step 2). Create a group in Repeater and send all the requests in parallel. 6. Points Awarded For Rejecting CTF via Manipulation request — (don’t remember) So I submitted a CTF and it wasn’t good, so it got rejected. Basically, if a CTF is rejected, all actions should be blocked . But because of this bug, I was still able to submit a flag and get points. I submitted a flag to any CTF just to get the request format and sent it to Repeater. In that request, I changed the CTF ID to my rejected CTF ID (I explained above how to get the ID). I then changed the flag to the correct one — I knew the flag because I created that CTF. Done. I got points for the rejected CTF . Note: If your CTF is approved, others can solve it and submit flags, but you cannot solve your own CTF . And if the CTF is rejected, you should not be able to do anything at all . 7. Allow editing of approved / publicly available CTFs. — P2 Once a CTF is approved, we are not allowed to edit it , but there is no server-side validation in place. This is the most dangerous bug in this blog, because once a CTF is approved, it becomes publicly available and other users can interact with it. I was able to edit an approved CTF . I could upload a virus, add phishing links, or redirect users anywhere. Users would think it’s just a normal CTF and run it to solve, without knowing what’s really inside. I submitted this as P1 , but they changed it to  P2 . I opened Burp Suite and edited any old CTF, captured the request, and sent it to Repeater. Then I changed the CTF ID to an approved CTF ID . I could change anything I wanted, and all those changes became publicly available Done! This blog is a bit different from my other blogs, and it may not be as clear, because I don’t remember everything perfectly and I had to put all the bugs into one post. I also didn’t want to make it too long. So if you don’t understand anything, just mail me and I’ll share the original POC. Got questions? Email me: [email protected] or reach out on Twitter: @StrangeRwhite9 How I Found 7 Logical Bugs in the com-olho CTF Feature was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
infosecwriteups.com
December 30, 2025 at 9:39 AM
Reposted by Mike Lemire
He means you don’t have to apologize for being a racist anymore.
JD Vance: "In the United States of America you don't have to apologize for being white anymore"
December 21, 2025 at 7:22 PM
Reposted by Mike Lemire
Every stop sign we have in #boston should be accompanied by a speed hump - or raised intersection. There is absolutely no reason cars should not be forced to slow down or stop at a stop sign. ATM ppl run them more often than American runs on #dunkin.
Something people need to understand is that choices at *all levels* create dangerous infrastructure. Even something simple like the local DPW striping a road with no bike lane at 12 feet instead of the agreed upon 10 feet creates a more dangerous environment (This is a real example).
results not accidents
December 16, 2025 at 4:44 PM
Does anyone else still open MS Word by typing "winword" in a CMD prompt or search bar?
December 9, 2025 at 2:38 PM
Reposted by Mike Lemire
If the xkcd comic 2347 made today... 😂
November 20, 2025 at 12:59 PM
From downtown Austin to the airport : public transit Vs walking
October 8, 2025 at 6:07 PM
Reposted by Mike Lemire
How to Trace an IP Address (Beginner’s OSINT Guide with Real Example)
How to Trace an IP Address (Beginner’s OSINT Guide with Real Example)
Want to know how to trace an IP address.
infosecwriteups.com
September 25, 2025 at 8:59 AM
Reposted by Mike Lemire
Top 10 Best API Penetration Testing Companies In 2025
Top 10 Best API Penetration Testing Companies In 2025
cybersecuritynews.com
August 30, 2025 at 10:29 AM
Reposted by Mike Lemire
Nice of Nevada to give a man with repeated mental problems a fucking machine gun.
July 29, 2025 at 2:45 PM
Reposted by Mike Lemire
The hearings on Benghazi went on for more than two years. Only four adults died, all of whom took willingly took a dangerous assignment in Libya.

I'm not ready to stop talking about Epstein a week after Bondi won't release the files when it protects people who will continue to victimize children.
July 16, 2025 at 12:18 PM
Disappointed the @nytimes.com should know only Congress can declare war.
June 22, 2025 at 1:06 AM
Reposted by Mike Lemire
Hegseth should be removed for this comment alone.

The deployment of US troops against our own citizens should be an unquestionable boundary we never cross.
HIRONO: If a court says this deployment of troops into our cities is not legal, would you follow that court's order?

HEGSETH: I don't believe district courts should be determining national security policy. If it goes to the Supreme Court, we'll see.
June 18, 2025 at 3:06 PM
I guess I don't need my DivX software and serial numbers any longer. There is another tech I got behind which the rest of the world did not.
May 29, 2025 at 11:06 PM
Reposted by Mike Lemire
Assessing Third-Party Vendor Risks – CISO Best Practices
Assessing Third-Party Vendor Risks - CISO Best Practices
cybersecuritynews.com
April 28, 2025 at 11:45 AM
Reposted by Mike Lemire
Security Metrics Every CISO Needs to Report to the Board in 2025
Security Metrics Every CISO Needs to Report to the Board in 2025
cybersecuritynews.com
April 22, 2025 at 2:22 PM
Reposted by Mike Lemire
Digital Forensics In 2025: How CSOs Can Lead Effective Investigations
Digital Forensics In 2025: How CSOs Can Lead Effective Investigations
cybersecuritynews.com
April 21, 2025 at 7:07 PM
Reposted by Mike Lemire
Due process matters. Freedom matters.
Mass. leaders join rally in support of detained Tufts student - The Boston Globe
Rümeysa Öztürk was apprehended by masked immigration agents on a Somerville street last week.
www.bostonglobe.com
April 2, 2025 at 12:58 PM
$TSLA is half what it was a few months ago but even at this level it still looks hella overvalued
March 17, 2025 at 4:28 PM
Reposted by Mike Lemire
Cloud Storage: The Not-So-Safe Haven for Sensitive Data – Ransomware Alert!

Ransomware in cloud storage? You bet! 66% of cloud buckets are vulnerable. Learn how to outsmart cybercriminals with these top cloud security tips.
thenimblenerd.com?p=1039999
Cloud Storage: The Not-So-Safe Haven for Sensitive Data – Ransomware Alert!
Sensitive data lurks in 66% of cloud storage buckets, making them prime targets for ransomware attacks. According to the SANS Institute, these attacks can exploit cloud providers' security controls. To combat this, understanding cloud security, blocking unsupported encryption, enabling backups, and balancing security costs are key. Remember, the cloud won't save you, but you can save yourself!
thenimblenerd.com
March 17, 2025 at 12:07 PM
Reposted by Mike Lemire
15 Best Patch Management Tools In 2025
15 Best Patch Management Tools In 2025
cybersecuritynews.com
March 6, 2025 at 7:30 AM
Reposted by Mike Lemire
In a blistering statement, the American Bar Association describes "attacks on constitutionally protected birthright citizenship, the dismantling of USAID and the attempts to criminalize" diversity initiatives as "wide-scale affronts to the rule of law itself."

https://buff.ly/4bb7dqp
February 10, 2025 at 8:29 PM
RSS feeds, its a crying shame they are not still widely used, can it come back? joeyehand.com/blog/2025/01...
I Ditched the Algorithm for RSS—and You Should Too - Joey's Hoard of StuffRSS feed iconRSS feed icon
Joey Einerhand's Portfolio and tech blog.
joeyehand.com
January 16, 2025 at 8:59 PM
Last night I dreamt I had a very nice dual cassette deck. I realize I regret selling mine in the 90s, thinking it was time to go digital, not realizing they would never make good ones again and how much I'd miss the look, feel and mechanics of them.
December 6, 2024 at 2:41 PM