Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Cookie Forgery and Command Injection Walkthrough - Feature Unlocked Challenge - CSCTF 2024

CryptoCat via YouTube

Overview

Learn how to exploit web security vulnerabilities through a detailed walkthrough video of the "Feature Unlocked" challenge from CyberSpace CTF 2024. Master advanced techniques including cookie forgery, custom signature generation and verification, and blind command injection to gain unauthorized access to hidden features. Follow along with practical demonstrations of exploiting validation server hijacking via hidden GET parameters, implementing cookie forgery attacks, and executing blind data exfiltration. Gain hands-on experience with web security concepts while exploring the complete solution path from initial source code review through successful exploitation.

Syllabus

Start
Source code review
Cookie forgery
Recreate validation server
Access unlocked feature
Command injection
Blind exfiltration
End

Taught by

CryptoCat

Reviews

Start your review of Cookie Forgery and Command Injection Walkthrough - Feature Unlocked Challenge - CSCTF 2024

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.