Simple introduction to SQL Injections
Irish-Name-Repo 1
Power Cookie
IntroToBurp
Simple introduction to using Burp Suite to intercept requests
WebDecode
Simple source checking
client-side-again
Simple client-side (obfusticated) JS script sniffing
dont-use-client-side
Simple client-side JS script sniffing
Cookies
Simple cookie manipulation, with a touch of syntax
logon
Simple cookies manipulation
picobrowser
Simple header manipulation
Scavenger Hunt
Pretty frustrating but interesting source checking challenge
Secrets
Jumping through a trillion folder jumps
GET aHEAD
Sending an HTTP HEAD request
Forbidden Paths
I struggled quite a bit at first, but notice that they forbid absolute file path. Meaning we can just use the relative file path to travel up the directories and get our flag.
Simply input ../../../../flag.txt into the form box to get the flag. Quite nice.
Roboto Sans
robots.txt with a twist
where are the robots
Introduces robots.txt