Week 19 · ctf

Final — Capstone CTF Tournament (Week 19)

← all weeks · readme · slides

Final — Capstone CTF Tournament (Week 19)

Course: Software Security (KOSEN69) · Covers: the whole term Time: 150 min · Total: 150 pts · Team-based · leaderboard · Sandbox only (ethics policy applies).

Submit per challenge: the flag (or noted proof), the payload/command, and a one-line mitigation. Difficulty rises with points. (The graded project demo is scored separately — see the Week 19 worksheet rubric.)

#TitleTopic / targetPts
1Boolean BypassSQLi login (week04)10
2Shell Outcommand injection (week04)15
3Persistent Popstored XSS (week05)10
4Not Your ObjectIDOR (week06)10
5Token Smithforge JWT to admin (week06)15
6Raid the APIBOLA + mass assignment (week10)15
7Smashstack overflow → win() ret2win (week11)20
8Fuzz Firstcrash the binary with a fuzzer (week11)10
9Bad Dependencyfind the vulnerable dep / unsigned image (week12)10
10Misconfig Huntexposed secret / *:* IAM / root Dockerfile (week13)15
11Jailbreak the Botprompt injection → leak the secret (week14)10
12Indirect Hitindirect injection / output XSS (week14)10

Submission table

#Flag / proofPayload or commandMitigation
1–12

Rules: attack only provided targets; one submission per team per challenge; document method. First-blood bonus at instructor's discretion.