
h1-ctf: 12 Days of Hacky Holidays This is my writeup for 12 Days of Hacky Holidays. The report is written such that beginners to CTFs will be able to learn the tricks of the trade. The Mission: The Grinch has gone hi-tech this year with the intention of ruining the holidays ?We need you to infiltrate his network and take him down! Check out all the details on https://hackerone.com/h1-ctf to learn more! Contents I laid out all the days here with their title and vulnerability. For more information about the vulnerability types, https://portswigger.net/web-security/all-materials is a great resource. Day | Title | Vulnerability --- | --- | --- 1 | robots.txt | Information Disclosure 2 | DOM Flag | Information Disclosure 3 | People Rater | Insecure Direct Object Reference (IDOR) 4 | Swag Shop | Insecure Direct Object Reference (IDOR) 5 | Secure Login | Password Bruteforcing 6 | My Diary | Business Logic Vulnerability 7 | Hate Mail Generator | Server Side Template Injection (SSTI) 8 | Grinch Forum | Open Source Intelligence (OSINT) 9 | Evil Quiz | SQL Injection 10 | Sign Up Manager | Business Logic Vulnerability 11 | Recon Server | SQL Injection / Server Side Request Forgery (SSRF) 12 | Attack Box | Hash Cracking / DNS Rebinding --- Day 1 Let's jump right in and see what the Grinch is up to: {F1134432} Well, that's not very inviting! A usual place to look for URL paths of note is the robots.txt file. Accessing it at https://hackyholidays.h1ctf.com/robots.txt returned:...
SOCIAL SHARE CARD GENERATOR