https://portswigger.net/research/top-10-web-hacking-techniques?fbclid=IwY2xjawPZEIhleHRuA2FlbQIxMABicmlkETFUQ0tlVEhDNHhSQlZiUTlKc3J0YwZhcHBfaWQQMjIyMDM5MTc4ODIwMDg5MgABHqH2a7japNsgZVrGMKcvg3IO_JG9XWfifevwCXGiH0VUsuSE2Z1TStLc5WT-_aem_3u-f1v-2hCfbcD-5_EzSkQ

Unrealistic-1 - uofctf2025

<aside> 💡

resp.headers["Content-Security-Policy"] = "default-src 'none'; img-src http: https:; style-src 'self';"

we can use image-src

</aside>

Unrealistic-2 - uofctf2025

<aside> 💡

DNS REBINDING SETUP. https://www.intruder.io/research/we-hacked-ourselves-with-dns-rebinding

https://www.intruder.io/research/split-second-dns-rebinding-in-chrome-and-safari

</aside>