Final — Capstone CTF Tournament (Week 19)
← all weeks · readme · slides
Final — Capstone CTF Tournament (Week 19)
Course: Software Security (KOSEN69) · Covers: the whole term Time: 150 min · Total: 150 pts · Team-based · leaderboard · Sandbox only (ethics policy applies).
Submit per challenge: the flag (or noted proof), the payload/command, and a one-line mitigation. Difficulty rises with points. (The graded project demo is scored separately — see the Week 19 worksheet rubric.)
| # | Title | Topic / target | Pts |
|---|---|---|---|
| 1 | Boolean Bypass | SQLi login (week04) | 10 |
| 2 | Shell Out | command injection (week04) | 15 |
| 3 | Persistent Pop | stored XSS (week05) | 10 |
| 4 | Not Your Object | IDOR (week06) | 10 |
| 5 | Token Smith | forge JWT to admin (week06) | 15 |
| 6 | Raid the API | BOLA + mass assignment (week10) | 15 |
| 7 | Smash | stack overflow → win() ret2win (week11) | 20 |
| 8 | Fuzz First | crash the binary with a fuzzer (week11) | 10 |
| 9 | Bad Dependency | find the vulnerable dep / unsigned image (week12) | 10 |
| 10 | Misconfig Hunt | exposed secret / *:* IAM / root Dockerfile (week13) | 15 |
| 11 | Jailbreak the Bot | prompt injection → leak the secret (week14) | 10 |
| 12 | Indirect Hit | indirect injection / output XSS (week14) | 10 |
Submission table
| # | Flag / proof | Payload or command | Mitigation |
|---|---|---|---|
| 1–12 |
Rules: attack only provided targets; one submission per team per challenge; document method. First-blood bonus at instructor's discretion.