PicoCTF 2022 Web Exploitation

Includes, Insp3ct0r, where are the robots, Power Cookie

Mukilan Baskaran
InfoSec Write-ups

--

Photo by Boitumelo Phetla on Unsplash

Welcome back amazing hackers, after a long time I am boosted again by posting a blog on another interesting jeopardy CTF challenge PicoCTF 2022.

In this write-up, we are going to see some of the web exploitation challenges.

First Challenge Insp3ct0r

The web interface looks like this:

By clue/hints behind this is to inspect Html pages, javascript pages, and finally look into CSS pages.

I found one part of the flag by inspecting index.html

The second part of the flag by inspecting mycss.css

The third part of the flag by inspecting myjs.js

Finally, altogether you got a flag for this challenge.

Where are the robots:

The page looks like this

I navigated to the robots.txt page and found an interesting location.

I poked into the location and finally reached the flag.

Includes:

The web interface looks like this

While viewing the source page I found the first part of the flag.

Then viewing the script.js I found the second part of the flag

Power Cookie

Home page

Click on the continue guest button nothing interesting appears after clicking the button.

This appears after clicking the button.

--

--