FYP 17059

Han Yu

Supervisor: Dr. S. M. Yiu

A CTF Platform for Cybersecurity Training in HKU

Web Attack Challenge 1
Challenge 1: Web page source code modification

In this challenge, three different stage are involved and participants have to conquer all the three problems to get the flag.



Stage 1: Inspect the page source code

Directly modify the source code of the website




Stage 2: Decode and change session value

First Run function in javascript to decode the cypher string

Then modify the session value based on the paintext




Stage 3: Change user agaent

Find the new user agaent and send cooresponding HTTP request to the server







Addtional Functionality

A timmer used only for users' preference

It will only refresh itself when all cookies at this site are deleted