Tag Generator: SHHC20
In the Wrapping Room beside Noel Boetie is the tag generator.

Talking with Holly, she states its not behaving appropriately.


Noel mentioned the file upload wasn't acting correctly, so I started there by trying to upload a txt file. This produced an error output.

From there, I started interacting with the tag generator and watching the endpoints that were accessed through Chrome Dev tools.

Poke Endpoints

I started with some blind curl queries to the endpoints. Quickly I stumbled on the app dumping all the environment variables. Yikes!

curl https://tag-generator.kringlecastle.com/image?id=foo


