This is the second part exploring DVWA. For the first part, click here. In this post, we will see vulnerabilities for: File inclusion File upload Captcha SQL File inclusion This happens in dynamic pages with PHP as a result of a fault in the programming of the page. This is...

Damn Vulnerable Web App DVWA is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to...

UMDCTF 2020 is hosted by the University of Maryland Cyber Security Club. Date: Saturday, April 18th 2020, 10:00 AM EDT - Sunday April 19th 2020, 10:00 AM EDT. Misc Oh hi nyan: Googling matt2r2, we find the flag here https://www.reddit.com/user/matt2r2/comments/g23kk6/colors/ MemeCTF: “I wish I was better at OSINT :( 9012389aad4eb9be53d225c4bbe72098ebdb37b97a52893171ff1bce0d40f383”....

Hackpack is an educational CTF that aims to complement security courses at North Carolina State University. Date: vie, 17 abr. 2020, 17:00 UTC — mar, 28 abr. 2020, 03:59 UTC Web Cookie Forge. When we log in, a cookie named session appears (this is the JWT). In the Flagship Loyalty...

Houseplant CTF is a capture the flag made with the new RiceTeaCatPanda developers. Date: vie, 24 abr. 2020, 19:00 UTC — dom, 26 abr. 2020, 19:00 UTC Begginers [1-9]: These challenges are cryptographic problems, so we have to use these types of encoding: Base64 Hexadecimal Octal Caesar Morse A1Z26 Atbash...