Dojo Logo
pwniiywh
ADMIN

Challenges:

Python3
Dojo #55 - Split Decision## Split Decision Active until : **02th November - 2026** ### IMPORTANT NOTE ⚠️ Due to the large amount of AI-generated spam reports, you must read the `Rules`. If you do not follow the rules, your submission will be rejected and closed as `spam`. --- ### How to submit your report 1. Visit the Dojo program at [https://yeswehack.com/programs/dojo](https://yeswehack.com/programs/dojo) 2. Click on **submit report** 3. Login or create your account 4. Submit your report --- ## Description A diagnostic bundle must pass through a strict gateway before reaching an internal export service. Can you make both layers see what they expect and recover the hidden token? ⚠️ _**Note:** To view the setup code for this challenge, click on settings (**⚙** icon) located at the top over the tab: `INFO`._ ### Rules - Your report must include a proof of concept (PoC) payload. - The report must ONLY include the valid flag as text. Do not add invalid flags at all in the report or images of the flag (a valid flag will trigger a popup window). - ⚠️ Full LLM-based solving is strictly forbidden. AI tools may be used for assistance, but the challenge work and final solution must be your own, using full AI for solving and reporting will result in that the report is closed as "spam".
Last Update: 10/2/2026, 1:25 PM
PHP
Dojo #50 - Bucket Vault## Bucket Vault Active until : **24th April - 2026** #### How to submit your report 1. Visit the Dojo program at [https://yeswehack.com/programs/dojo](https://yeswehack.com/programs/dojo) 2. Click on **submit report** 3. Login or create your account 4. Submit your report --- ## Description Bucket Vault implements a secure file storage system using pre-signed URLs with signatures. Generate time-limited access tokens for files stored in the vault, with built-in signature verification to ensure only authorized requests can retrieve protected content. ⚠️ _**Note:** To view the setup code for this challenge, click on settings (**⚙** icon) located at the top over the tab: `INFO`._ ## Goal **BRUTE FORCE IS NOT ALLOWED!** (_Applies only to the Dojo challenge page itself._) ### A valid solution for the challenge must meet these requirements: - Your report must include a proof of concept (PoC) showing how you obtained the flag - The flag must be included in the report
Last Update: 3/27/2026, 3:41 PM
Python3
XXE #1 - Basic File Read## Basic File Read Try to read the contents of `/tmp/flag.txt` using XML External Entity (XXE) injection.
Last Update: 2/5/2026, 5:42 PM
Python3
XXE #3 - Internal Metadata SSRF## Internal Metadata SSRF A metadata service is running locally on `127.0.0.1:8000`. Use XXE to perform SSRF and retrieve the secret.
Last Update: 2/5/2026, 5:41 PM
Python3
XXE #2 - Config Leak## Config Leak This challenge contains a local DTD file. Exploit it to read `/etc/flag.txt`.
Last Update: 2/5/2026, 5:41 PM
Python3
Dojo #42 - Hex Color Palette# Hex Color Palette Active until : **04th July - 2025** **How to submit your report** * Visit the Dojo program at **https://yeswehack.com/programs/dojo** * Click on **submit report** * Login or create your account * Submit your report --- # Description With this application, you can now display your own hex color palettes and unleash your inner UX designer! Simply upload your own XML files to generate custom palettes. **Can you find the flag?** * ~ The flag can be found in `/tmp/flag.txt` * ~ Note: To view the setup code for this challenge, click on settings (⚙ icon) located at the top over the tab: *INFO*. # Goal **BRUTE FORCE IS NOT ALLOWED!** *(Applies only to the Dojo challenge page itself.)* ### A valid solution for the challenge must meet these requirements: * Your report must include a proof of concept (PoC) showing how you obtained the flag * The flag must be included in the report
Last Update: 6/10/2025, 1:13 PM
PHP
Halloween Special - Spooky Party Invitation# Halloween Special - Spooky Party Invitation Active until: **7th November - 2024** Authors: **Pwnii** ## How to submit your report 1. Visit the Dojo program at [https://yeswehack.com/programs/dojo](https://yeswehack.com/programs/dojo) 2. Click on submit report 3. Login or create your account 4. Submit your report --- ## Description You're invited to our Halloween party – with a spooky twist! Here’s your personal invitation, it seems that you might be able to change the background image on your spooky party invitation card.. ~ The spooky flag can be found in the file: `/tmp/flag.txt` ! ## Goal #### BRUTE FORCE IS NOT ALLOWED! (Applies only to the Dojo challenge page itself.) #### A valid solution for the challenge must meet these requirements: * Your report must include a proof of concept (PoC) showing how you obtained the flag * The flag must be included in the report * We’d really like you to fully understand why the challenge is solved this way.
Last Update: 6/10/2025, 1:13 PM