Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

CTF secrets revealed: TopLang challenge from SnykCon 2021 explained

Blog post from Snyk

Post Details
Company
Date Published
Author
Michael Aquilina
Word Count
2,987
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

The challenge, "Fetch the Flag" from SnykCon 2021, was a web-based challenge involving an oracle attack using blind SQL injection. The team approached this problem by first investigating the available pages and identifying potential attack vectors. They then tested the vulnerability of the order query string and determined that it was susceptible to a blind SQL injection attack. Using an oracle attack, they were able to extract the login information from the database, including table names, column names, and data. The team then used this information to manipulate the admin panel's cookies and gain access to the admin page, ultimately retrieving the Snyk CTF flag.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 467 104 44 -27%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.