My goal is to share the knowledge I have as I continue learning cybersecurity. For those who are unfamiliar, Capture The Flags (better known as CTFs) are games where hackers have to find bugs and solve puzzles to find "flags," bits of data that tell the system you've completed a challenge. Hackerone is hosting an event in New York this december and ran a CTF as a secondary way to get an invite to the event. Playing with the cart a bit, we see that the cart/checkout conversation is a url encoded json. Hacker101 is a free class for web security. The challenge description was minimal: I'm selling very valuable stuff for a reasonable amount of money (for me at least). I switch the page id to 7, refresh the page and get the third flag: The last place to test is the page body. Viewing the source code, I find the flag: Thank you for reading. Since the page content is controllable, then if there is XSS, as shown in the figure. I coded one last script to automate the entire process: [+] Contents of h1-ctf: 1. So, I’m beginning now. I am Isaac, a software developer, and cybersecurity enthusiast. Easy and straightforward shopping. #XSS #CTF #bugbounty #hacked Finding attacker-controllable input When dealing with XSS challenges the very first step is to find some attacker-controllable input that can be used as a vector to exploit the actual XSS. This is my writeup for the $50M CTF by HackerOne.This was my first proper CTF and I don’t have much experience in the bug bounty world either so everything was new from the beginning to … Last month, we announced the winner of the Fall semester Watch_Dogs® 2 CTF challenge and taught you how to solve Level 1 of the CTF, Miss Marple.. The initial judgment page should be based on the number after the address bar to query and display the page, then there may be injection, add a quote after the number to try. The CTF serves as the official coursework for the class. I've been programming in Python for 6 years and C++ for 2, I have basic networking knowledge and will soon be working towards getting my Network+, and I lead a CTF at my school, but none of it makes me feel prepared or capable for the profession I want to go into. Click on the image to see the code executed successfully, Then look at the page source to get the flag. The Hacker101 CTF – or Capture the Flag – is a game where you hack through levels to find bits of data called flags. I try replaying it but changing the costs so the kittens are free. The payload executes successfully but there is no flag displayed. Whether you're a programmer with an interest in bug bounties or a seasoned security professional, Hacker101 has something to teach you. At this point, I successfully got all the Flags. The CTF is located here: Boom, Flag0. Page 7 responds with a 403 forbidden error while others respond with 404. I first visit the 'create a new page' link. So I try to retrieve pages between 2 and 12. CTF stands for Capture The Flag, a style of hacking event where you have one goal: hack in and find the flag. After the test, it was found that the