Code Monkey home page Code Monkey logo

hacker101-ctf's Introduction

Hacker101 CTF

0x00 Overview

Hacker101 CTF is part of HackerOne free online training program. Really a good place to apply all the pen test skills for beginners.

0x01 CTF

Difficulty Name Skills Completion
Trivial A little something to get you started Web 1 / 1
Easy Micro-CMS v1 Web 4 / 4
Moderate Micro-CMS v2 Web 3 / 3
Hard Encrypted Pastebin Web, Crypto 1 / 4
Moderate Photo Gallery Web 3 / 3
Moderate Cody's First Blog Web 3 / 3
Easy Postbook Web 7 / 7
Moderate Ticketastic: Demo Instance Web 0 / 0
Moderate Ticketastic: Live Instance Web 2 / 2
Easy Petshop Pro Web 3 / 3
Hard Model E1337 - Rolling Code Lock Web, Math 1 / 2
Moderate TempImage Web 2 / 2
Easy H1 Thermostat Android 2 / 2
Expert Model E1337 v2 - Hardened Rolling Code Lock Math 0 / 1
Moderate Intentional Exercise Android 1 / 1
Moderate Hello World! Native 1 / 1
Expert Rend Asunder Native 1 / 3
Easy BugDB v1 Web, GraphQL 1 / 1
Easy BugDB v2 Web, GraphQL 1 / 1
Moderate BugDB v3 Web, GraphQL 1 / 1
Moderate Oauthbreaker Android 0 / 2
Moderate Mobile Webdev Android 0 / 2
Moderate XSS Playground by zseano Web 0 / 1
Moderate OSU CTF Web 0 / 1
Moderate Grayhatcon CTF Web 0 / 4
Moderate RTFM Web 0 / 8
Moderate Hackyholidays CTF Web 0 / 12
Moderate Y2FuIHlvdSByZWNvbj8/ Web, Recon 0 / 3

hacker101-ctf's People

Contributors

testert1ng avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

hacker101-ctf's Issues

Micro CMS v2 - Flag 1

I use curl to make a POST request to the edit/2 url ,but it says that the method is not allowed.Does this happen because I am using Windows?

Missing file extension .txt?

Hi!

Thanks a lot for sharing all your documentation.

I read the "Photo Gallery - Flag2" document. In my opinion, there is a little bug in the sections "0x02 Remote Code Execution" and "0x03 FLAG".

The command "id=1 UNION SELECT 'test'--" does not work for me. Running this command results in an HTTP 500 error. If I add a file extension everything works fine. Finally, the command looks like: "id=1 UNION SELECT 'test.txt'--".

petshop pro flag 2

I can't see any link to edit the items in the pet store so I can't change the content which is forwarded to the /cart page. I don't know whether there was an update to this challenge or the web page doesn't render properly. I checked on other browsers so I don't think that's the issue.

image

I did change the 'name' of the item by intercepting the POST request to /checkout from /cart and got XSS on the /checkout page but don't see the flag.

image

Maybe, the XSS needs to pop up on the /cart webpage? Anyways, just wanted to ask if there's another way around this. Btw thank you for creating this repo, great help.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.