Capture the flag (CTF)

n00bz CTF Challenge #2: Practical Website Hacking

Infosec Institute
June 23, 2015 by
Infosec Institute

In the second edition of our n00bs CTF Labs, we've created 13 small challenges to test your web app hacking skills. The challenges are based on common vulnerabilities (XXS, code injection, inadequate redirect functions ect.) as well as older and less frequently seen vulnerabilities such as Data Validation; Parameter Delimiter. Each level has a bounty of $100, you just need to find the flag and post your solutions online to to be entered in the contest. There are no limits to the number of entries you can submit, but entrants are only eligible to win the bounty for up to 3 levels.

As you can see in the screenshot below, switching levels is as easy as clicking the orange levels button in the top left hand corner of the screen.

What should you learn next?

What should you learn next?

From SOC Analyst to Secure Coder to Security Manager — our team of experts has 12 free training plans to help you hit your goals. Get your free copy now.

ctf1

If you find yourself stuck on a level you can always click the Get a Hint button for additional information and the type of vulnerability you will be solving for is located in the bottom left corner of the page.

ctf2

Vulnerabilities that are in a green font are on the OWASP's top 10 list while those in red are not.

ctf3

You can access the second edition of our CTF Challenge by CLICKING HERE and additional information regarding the bounty submission requirements can be found here.

Happy Hunting!

Resources

What should you learn next?

What should you learn next?

From SOC Analyst to Secure Coder to Security Manager — our team of experts has 12 free training plans to help you hit your goals. Get your free copy now.

There are many articles in our library that can help with the challenges, here are 8 particularly useful ones:

Infosec Institute
Infosec Institute

Infosec’s mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber safe at work and home. More than 70% of the Fortune 500 have relied on Infosec Skills to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ’s security awareness training.