FYP 17059

Han Yu

Supervisor: Dr. S. M. Yiu

A CTF Platform for Cybersecurity Training in HKU

Web Attack Challenge 2
Challenge 2: Direct Modification of URL Console

In this challenge, users are required to collect certain amount of different categories things to get the flags..



When explore button is clicked, users will find one random subject and then use collect button to collect it.

Part 1 of the flag requires users to collect one wool and eleven sticks, while part 2 of the flag requires onw wool, three sticks, 2 dyes and four bricks. Only if all the specified amount of the subjects are collected, the flag can be revealed.






Hackers are expected to directly modify the URL console content, that is the GET HTTP requests, to retrieve required subjects.