Homemade CTF Challenge: 03 "Web Hunt"
Skills:
Network Security70%
Key Takeaways
Solves the Homemade CTF Challenge 03 'Web Hunt' using various cybersecurity tools and techniques
Full Transcript
Hello everyone. Welcome back. Uh again, my name is John Hammond and I'm in this video I'm showcasing um some more of those challenges that I put together for a local practice exercise CTF or capture the flag competition uh at my school. And so the next challenge was on web hunt. And the prompt here is it's a website scavenger hunt. And the hint that you can find if you hover over is like gre can be an extremely powerful weapon if you know how to wield the sword. So it is a zip file that you'd end up downloading. And once you actually go ahead and use this, you'll notice that it is a full and complete website with an index of HTML and CSS and images and JS and stuff like that. So the ploy is that they would go ahead and and extract all these files and begin to look at the website with a little index.html. I'll drag this down so you can see it. And it is quite simply a website where hopefully it would fool them to like look around and and and and and do things. What you might want to look at the HTML source or some of the CSS. It's literally the ploy is that it's a website scavenger hunt. But since there are a bunch of files and we want to be able to search through them for a flag. Well, at this point we should know the flag format. So what we can do is we can just search for it, right? So that is in the uh web hunts. So that is four in my case. So in the web page or in the website, what we'd end up doing is grepping in our case for anything that starts with USCGA like looking for the flag identifier, the flag format. But we wouldn't want to do it on like a specific file because we know it's probably not going to be in any of those. But we'll do it recursively. - r and we'll look at in this folder onward. So we find it eventually but that uh that d-r folder or that that uh that argument sorry what that does it reads all files under each directory recursively. So that's how I intended them to solve that challenge rather than having to look for it by hand because I actually stored the flagged in the JavaScript like jQuery file. So no one would look through that on their own like individually. The deploy and the hope was that they would use GP to to find it. So GP can of course find the line but and you can you can just go look for it because it'll be highlighted. But a uh a good ploy I think is to now use more things inside of the I think it's RP or O. I want to be able to get just the All right, there it is. Cool. ro o and the regular expressions you find simply the flag itself. So there we go. Grev can find anything if you know what you're looking for. And that is how I ended up putting that together. So the way that I built that was real easy. All I ended up doing was I was taking that nothinginthebox.com and I wget mirrored that to create that nothinginthebox.com. I think I can go ahead and start to show that and then it will no check certificates. Fine. If I need that argument to go ahead and pull it, that's fine. And then it will start to like mirror and scrape the web page. So that's why it was able to create that folder and all the other stuff. So I'll get rid of that. But once it was downloaded, I'd literally just go into the JavaScript file, see what's in there, and I'd go ahead and insert the flag in in the jQuery file. I'd just edit it in like Sublime Text, and just literally plop it in there wherever it's in the middle of a comment or or after a command. So that way it doesn't interrupt the JavaScript code itself, but it's still hidden in in in the web page. So that was it. just using simply GP to find a file, but knowing to use it on all of the files in the web page. So, that was um Did I copy the flag? I want to make sure I copy the flag. Okay, cool. Yep. We'll go ahead and submit it and get our 100 points and we're just moving right along with some of the symbol challenges that I put together for our local practice CTF exercise and competition. So, I'll see you in the next video.
Original Description
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
GitHub: https://github.com/JohnHammond
Site: http://www.johnhammond.org
Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 35 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
▶
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Network Security
View skill →Related Reads
📰
📰
📰
📰
SQL Injection in AI-Generated Python: How It Ships
Dev.to · CopperSunDev
Casi le Enseñamos a los Bots de Spam Cómo Vencernos
Dev.to AI
How to Verify Telegram Bots Before Integration
Dev.to AI
GHSA-42H9-826W-CGV3: GHSA-42H9-826W-CGV3: Denial of Service via Uncontrolled Recursion in Axios formDataToJSON
Dev.to · CVE Reports
🎓
Tutor Explanation
DeepCamp AI