The Finaps team took part in the
P0wn Party Hackathon hosted by The S-Unit, and they came out on top! Among the 40 participating teams, the Finaps team found the most vulnerabilities in the "capture the flag" prepared Mendix apps.
The event was not just about building applications in a short period of time. Instead, the focus was on tearing them apart and finding security flaws. With the knowledge gained from some of the workshops, the team started exploring the Mendix client API and used JavaScript to manipulate database entries and discovered flaws in XPath access rules to obtain the flags hidden in the application.