Overview

This was an easy web challenge that involved a XSS(Cross-site scripting) attack. The set up was a web application that allowed users to register an account to log in and post notes. Additionally, there was an admin bot page in which the admin bot would visit the page url we gave it. Looking through the source code, I found that the flag was set as the cookie of the admin bot. So the goal was to craft a XSS attack to steal its cookie.

Overview

The set up of this challenge was a simple calculator that allowed users to perform easy calculations, such as subtraction and multiplication, through the formula url parameter. It had a command injection vulnerability that allowed attackers to inject arbitrary commands on the host system to extract sensitive information.

Approach

There was nothing much interesting in the frontend of the web page, so I turned to the source code and found the vulnerability immediately. The web application was using eval() to take in user input as a string and then executing it through echo. Whenever eval() is used in an application to take in an input it should always set off an alarm. There are numerous articles online explaining the danger of eval(). In this case, even though the author used a seemingly secure way, regular expression, to sanitize the user input before passing it into eval(), there were still ways to bypass the filter. Here is a screenshot of the source code:

Description of challenge: There’s a hidden flag on Jelly’s page, but the creator hasn’t made her page public yet. Can you find a way to access her page and capture the flag?

Overview

From the initial inspection, it seemed that the access to one of the Virtual Youtubers’ page was restricted when clicking on her picture. However, there existed a broken access control vulnerability that allowed direct access to the web page by simply changing the url to an endpoint.

Overview

The setting of this web page was a custom name converter that converted a user input into “AWASCII”. Due to improper user input sanitization, a command injection vulnerability present in the application allowed execution of arbitrary command code.

Approach

When I first opened up the web page, I noticed that there was a place for user input. I examined the source code main.py and found that the flask application was using python’s subprocess module to start the python script awafier.py that took the user input as an argument. After checking the documentation of the python module, it appeared that the library will not implicitly choose to call a system shell unless it’s invoked via shell=True. In this challenge, this was invoked explicitly as shown in the screenshot of the source code.

Overview

This was a good beginner challenge that involved a Server-Side Template Injection vulnerability in the Flask application’s Jinja2 template engine. This vulnerability allowed access to read the contents of the applicatoin’s config object, which was where the flag for this challenge was located.

Approach

When I first opened up the web page, I was presented with a form input. I tested the level of input sanitization with a mathematical expression in double curly braces: {{2*2}}, which prints the contents in between to the template output. To better see the response from the browser, I sent my request using Burpsuite and got a positive indication of a Server-Side Template Injection vulnerability.

Overview

This was the second part of the same application, which also involved the Server-Side Template Injection Vulnerability. However, this time the flag was in the file flag.txt in the application directory, which can be accessed through remote code execution using the request object.

Approach

To achieve remote code execution, the goal was to import the os module, which can be found in request’s __builtins__ method via the __globals__ attribute.

This is my first time being a CTF author and organizer for UMassCTF. I decided to make a beginner challenge that teaches basic skills in web exploitation.

Challenge Description

You just got invited to Spongebob’s birthday! But he’s decided to test your friendship with a series of challenges before granting you with the ticket of entrance. Can you prove that you’re truly his friend and earn your entrance to this holesome birthday party?