~/write-ups/writeup-3a17d93542

Web Application Penetration Testing CTF 2

Imported from Notion: Web Application Penetration Testing CTF 2

target:: Notion MEDIUM date:: 2026.07.26 notion

Nos dan las siguientes pistas:

  • Task 1: Identify a vulnerability in the ‘About CTF’ page.

  • Task 2: Exploit the login page vulnerability.

  • Task 3: Exploit the search functionality to discover hidden users.

  • Task 4: Leverage user profile enumeration to extract sensitive data.


Empezamos como siempre lanzando un nmap

nmap -p- target​.ine.local -oA all_ports
Notion image
Notion image

Ahora vamos a lanzar un nmap al puerto **80 **para detectar version y posibles vulnerabilidades:

nmap -p80 -sV -sC target​.ine.local -oA http_scan
Notion image
Notion image

No vemos version ni nada interesante.

Vamos a ver que hay en http://target.ine.local

Notion image
Notion image

Vemos un panel Login, podemos intentar SQLi con Burp Suite pero la pista uno dice una vulnerabilidad en about a si que vamos a ver que hay en about

Notion image
Notion image

Vemos que la url es http://target.ine.local/about-ctf?total_flags=4

Y cambiando el numero de la url cambia el output, vamos a ver el codigo fuente para ver que hay detrás.

Hacemos click derecho sobre la web y clickamos en View Page Source

Notion image
Notion image

Tenemos en el codigo fuente la primera flag en un comentario.

Notion image
Notion image

Flag 1: 84014c8c8afa4b2697c30618f8a4116b

Vemos que es una funcion ev​al() donde podemos inyectar codigo malicioso JS facilmente.

Vamos a probar un XSS, pondremos en lugar del 4 esto:

<script>alert("PWNED BY XSS")</script>
Notion image
Notion image

PWNED! Tenemos XSS.

La pista numero 2 nos habla sobre el panel login, nos abrimos Burp Suite y activamos FoxyProxy.

Ponemos valores cualquiera en email y password

Notion image
Notion image

Click derecho y lo mandamos al intruder.

Notion image
Notion image

Añadimos payload en el campo email

Nos creamos payload.txt con el contenido de https://github.com/payload-box/sql-injection-payload-list#sql-injection-auth-bypass-payloads

Y lo añadimos en la pestaña payload de Burp Suite

Notion image
Notion image

Clickamos en Load… y seleccionamos nuestro payload.txt

Y lanzamos con Start Attack

Vamos a fijarnos en Status Code y Length

Notion image
Notion image

Vemos varios con status code 302, probemos directamente en la web.

Notion image
Notion image

Clickamos en Log in.

Notion image
Notion image

Flag 2: 1a8f4d91e19345fca6a51697a7fd8d01

La pista 3 habla sobre el buscador, a si que veamos que hay en Search User

Notion image
Notion image

Probemos una SQLi

' or '1'='1'--
Notion image
Notion image

Flag 3: 0fda002fde8e4ad08ffc1179c2af2f46

Ahora vamos a probar ids de los usuarios en http://target.ine.local/profile/<ID>

http://target.ine.local/profile/576786

Notion image
Notion image

Flag 4: 46d086942aa34d1980e4f4e35e2f75a1


- EOF -

<< back_to_index