<- HTB CHALLENGES

Web - Total: 67

jscalc
CTF

jscalc

JavaScript. Code injection
OnlyHacks
CTF

OnlyHacks

Cross-Site Scripting. Cookie hijacking
Breaking Bank
CTF

Breaking Bank

Open Redirect. JWKS and JWT forgery. OTP bypass
ProxyAsAService
CTF

ProxyAsAService

Server-Side Request Forgery. localhost bypass. HTTP Request URI
Neonify
CTF

Neonify

CRLF Injection. RegEx bypass. Server-Side Template Injection
TimeKORP
CTF

TimeKORP

Command injection
KORP Terminal
CTF

KORP Terminal

SQL injection. Password hash cracking
Flag Command
CTF

Flag Command

API. Developer tools
wafwaf
CTF

wafwaf

PHP. Time-based SQL injection. WAF bypass
GhostlyTemplates
CTF

GhostlyTemplates

Go. Server-Side Template Injection. Local File Read
PumpkinSpice
CTF

PumpkinSpice

Cross-Site Request Forgery. Remote Code Execution
Spellbound Servants
CTF

Spellbound Servants

Insecure deserialization with pickle
LoveTok
CTF

LoveTok

PHP. Code injection. Remote Code Execution
HauntMart
CTF

HauntMart

Server-Side Request Forgery. IP address bypass
CandyVault
CTF

CandyVault

MongoDB. NoSQL injection
SpookTastic
CTF

SpookTastic

Cross-Site Scripting
0xBOverchunked
CTF

0xBOverchunked

Boolean-based SQL injection. Transfer-Encoding chunked
Saturn
CTF

Saturn

Server-Side Request Forgery. TOCTOU
HTBank
CTF

HTBank

HTTP Parameter Pollution
Percetron
CTF

Percetron

HA-Proxy. HTTP request smuggling via WebSocket. Server-Side Request Forgery. MongoDB Wire Protocol. Gopher Protocol. Cypher injection (neo4j). Command injection. RCE
Testimonial
CTF

Testimonial

Go. gRPC. Client-side verification. Directory traversal. Arbitrary File Write. Server-Side Rendering
emoji voting
CTF

emoji voting

Boolean-based SQLi in ORDER. Automate flag extraction
E.Tree
CTF

E.Tree

XPATH injection. Automate flag extraction
Wild Goose Hunt
CTF

Wild Goose Hunt

MongoDB. NoSQL injection. Automate flag extraction
Watersnake
CTF

Watersnake

Java. CVE. SnakeYAML insecure deserialization
Lazy Ballot
CTF

Lazy Ballot

CouchDB. NoSQL injection. Authentication bypass
Toxic
CTF

Toxic

PHP deserialization. Local File Inclusion. Log Poisoning
CurlAsAService
CTF

CurlAsAService

Parameter injection. Local File Read
Templated
CTF

Templated

Flask. Server-Side Template Injection. RCE
Trapped Source
CTF

Trapped Source

HTML code inspection
AbuseHumanDB
CTF

AbuseHumanDB

Cross-Site Search. Bypass Same-Origin Policy for exfiltration
ExpressionalRebel
CTF

ExpressionalRebel

Server-Side Request Forgery. Regular Expression Denial of Service
TrapTrack
CTF

TrapTrack

Insecure Deserialization in pickle. SSRF in Redis
Spybug
CTF

Spybug

Malicious file upload. SSTI to XSS. CSP bypass
Didactic Octo Paddles
CTF

Didactic Octo Paddles

JWT. Server-Side Template Injection
Orbital
CTF

Orbital

SQL injection. Directory Traversal. Local File Read
Passman
CTF

Passman

GraphQL. IDOR
Kryptos Support
CTF

Kryptos Support

Cross-Site Scripting. Insecure Direct Object Reference
baby breaking grad
CTF

baby breaking grad

JavaScript. Prototype Pollution
baby website rick
CTF

baby website rick

Insecure deserialization with pickle
baby todo or not todo
CTF

baby todo or not todo

Broken Access Control
BatchCraft Potions
CTF

BatchCraft Potions

GraphQL batching attack. OTP and rate limit bypass. JWT. CSP. DOM Clobbering. XSS
The Magic Informer
CTF

The Magic Informer

Directory Traversal. Local File Read. JWT. Broken Access Control. SSRF. Command Injection. RCE
baby WAFfles order
CTF

baby WAFfles order

XML External Entity injection
Cursed Secret Party
CTF

Cursed Secret Party

XSS. CSP bypass
Juggling facts
CTF

Juggling facts

PHP. Type Juggling
Horror Feeds
CTF

Horror Feeds

Stack-based SQL injection
Spookifier
CTF

Spookifier

Server-Side Template Injection
baby nginxatsu
CTF

baby nginxatsu

nginx. Directory listing
Userland City
CTF

Userland City

PHP. Laravel exploit
baby BoneChewerCon
CTF

baby BoneChewerCon

PHP. Laravel Debugger
Letter Dispair
CTF

Letter Dispair

PHP. Remote Code Execution. PHPMailer (CVE)
baby interdimensional internet
CTF

baby interdimensional internet

Code injection. Read remote file
Spiky Tamagotchi
CTF

Spiky Tamagotchi

Authentication bypass. JavaScript code injection
Intergalactic Post
CTF

Intergalactic Post

SQLi in SQLite to RCE in PHP
Red Island
CTF

Red Island

SSRF. Path Traversal. Gopher protocol. Redis RCE
Mutation Lab
CTF

Mutation Lab

SVG file read through image. Forge session cookie
Amidst Us
CTF

Amidst Us

Python. Third-party dependencies. Code Injection. RCE
BlinkerFluids
CTF

BlinkerFluids

Node.js. Third-party dependencies. Code Injection. RCE
baby ninja jinja
CTF

baby ninja jinja

SSTI with limited characters
baby CachedView
CTF

baby CachedView

SSRF using iframe
sanitize
CTF

sanitize

SQL injection. Authentication bypass
baby auth
CTF

baby auth

Session cookies. Authentication bypass
Full Stack Conf
CTF

Full Stack Conf

Cross-Site Scripting
looking glass
CTF

looking glass

Command injection. Remote Code Execution
Gunship
CTF

Gunship

Prototype Pollution. AST Injection
Slippy
CTF

Slippy

TAR Directory Path Traversal. Server-Side Template Injection