Posts

Showing posts with the label ctf365

CTF365 Security Shepherd Walkthrough - No Spoilers Just Hints

hopefully, lets try to do all of the  CTF365 Security Shepherd  lessons and challenges, and help everybody with all they need but no spoilers. that doens't meant you don't need to do your learning, if i didn't write something, that means (a) learn the topic (b) read instructions. simple way to work through is installing burp-suite CE and make it work with ssl, but i'll try to also teach, where possible, you can use other tools. LESSONS *any lession with a asterisk [*] in its name means that it would have been easier with burp, just altering the request. [need to install cert. etc.] Broken Session Management* the session is managed via cookies, can be changed via Chrome Dev Tools (F12) -> Application tab -> Storage -> Cookies. (maybe you must click the button 1st) Cross-Site Request Forgery after putting a value in the box and submitting, right-click and Inspect-Element the image. you must put a full url i.e. https://..... try put a funny image...