Web Exploitation
Web exploitation covers a wide range of attacks against websites and web APIs. You'll learn to inspect client-side code, manipulate cookies and sessions, inject malicious SQL queries, and abuse server-side rendering. These techniques map directly to real-world vulnerabilities tracked in the OWASP Top 10.
Guides for this path
Read these alongside the challenges below. The first one orients you; the rest go deeper on the techniques each step needs.
- The picoCTF Web Exploitation Roadmap: Recon to RCEWeb exploitation roadmap: how to learn web hacking in order, a difficulty-tiered path classifying every bug by where your input lands, with technique guides.
- Web Recon for CTF: robots.txt, Page Source, DevTools, and Hidden EndpointsYour first web CTF recon playbook: view-source, DevTools, robots.txt, exposed .git, directory brute-forcing with ffuf and gobuster, cookies, and when to open Burp.
- Cookie and JWT Attacks for CTF Web Challenges (picoCTF Guide)Cookie and JWT attacks for CTF: session hijacking, base64 cookies, Flask signed sessions, JWT alg:none and confusion, and Burp interception, plus picoCTF links.
- SQL Injection for CTF: From Authentication Bypass to Data ExtractionSQL injection for CTF: authentication bypass, UNION-based extraction, blind SQLi, NoSQL injection, and sqlmap automation, with picoCTF challenge links.
- Server-Side Template Injection for CTF: Detection, Gadgets, and Filter BypassSubmit {{7*7}} to a form. If the page shows 49, you have SSTI. Here is how to go from that one test to full server compromise, and why the fix is one line of code.
- Command Injection for CTF: From Ping Boxes to Blind ExfilCommand injection for CTF: shell metacharacters, in-band reads, blind time and OOB tricks, filter bypass with IFS and globs, and the picoCTF Ping Cmd solve.
- Step 01
Source Code and Developer Tools
Browser developer tools are the first weapon in a web hacker's arsenal. Flags can hide in HTML comments, JavaScript source files, or CSS. The Includes and Inspect HTML challenges are classics that teach you to never trust that what you see in the browser is the whole picture.
- Step 02
Cookies and Session Manipulation
HTTP is stateless, so web applications use cookies to remember who you are between requests. Cookies are just text, and if an application trusts them without validation, you can forge admin tokens, manipulate user roles, or hijack sessions. Always check what data sits in your browser's cookie jar.
- Step 03
Enumeration and Hidden Endpoints
Web applications often expose more than the developer intended. A robots.txt can point you to hidden admin paths, JS files may reference internal APIs, and directory traversal can leak restricted files. The head-dump challenge is a great example of information leakage through an unprotected endpoint.
- Step 04
SQL Injection
SQL injection is one of the oldest and most prevalent web vulnerabilities. When user input is concatenated directly into a database query, an attacker can escape the intended context and execute arbitrary SQL. These challenges cover both classic SQL injection and the NoSQL variant in MongoDB.
- Step 05
Server-Side Injection
Server-Side Template Injection (SSTI) occurs when user input is embedded directly into a template engine like Jinja2 or Twig. Unlike reflected XSS, SSTI runs on the server and can lead to remote code execution. Understanding template syntax is key to spotting where evaluation happens.