Coder Social home page Coder Social logo

testert1ng / hacker101-ctf Goto Github PK

View Code? Open in Web Editor NEW
473.0 20.0 117.0 8.46 MB

Hacker101 CTF Writeup

Home Page: https://hacker101.testerting.science

Batchfile 0.33% PHP 0.27% Python 47.11% Java 16.56% C 35.73%
ctf ctf-writeups hackerone hacker101 penetration-testing hacking security pentest

hacker101-ctf's Issues

petshop pro flag 2

I can't see any link to edit the items in the pet store so I can't change the content which is forwarded to the /cart page. I don't know whether there was an update to this challenge or the web page doesn't render properly. I checked on other browsers so I don't think that's the issue.

image

I did change the 'name' of the item by intercepting the POST request to /checkout from /cart and got XSS on the /checkout page but don't see the flag.

image

Maybe, the XSS needs to pop up on the /cart webpage? Anyways, just wanted to ask if there's another way around this. Btw thank you for creating this repo, great help.

Micro CMS v2 - Flag 1

I use curl to make a POST request to the edit/2 url ,but it says that the method is not allowed.Does this happen because I am using Windows?

Missing file extension .txt?

Hi!

Thanks a lot for sharing all your documentation.

I read the "Photo Gallery - Flag2" document. In my opinion, there is a little bug in the sections "0x02 Remote Code Execution" and "0x03 FLAG".

The command "id=1 UNION SELECT 'test'--" does not work for me. Running this command results in an HTTP 500 error. If I add a file extension everything works fine. Finally, the command looks like: "id=1 UNION SELECT 'test.txt'--".

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.