Hacking The Davinci Code: WebDAV Cybersecurity

Hacking The Davinci Code: WebDAV Cybersecurity

Source: YouTube · John Hammond · published May 29, 2024 · 16:20

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates solving "The Da Vinci Code" web CTF challenge by exploiting WebDAV vulnerabilities in a Flask application to access the hidden flag 2:27-2:53.

Key Takeaways:
• The challenge involves a deliberately broken Flask website with WebDAV vulnerabilities 2:12-2:15
• Using curl with PROPFIND method reveals the directory structure including a secret folder with flag.txt 4:19-5:18
• Finding a backup source file (app.py.db.backup) in the static directory reveals MOVE method capability 10:17-11:21
• The solution uses WebDAV MOVE method to transfer flag.txt from the secret directory to the accessible static directory 13:05-15:36

This creative CTF challenge demonstrates how WebDAV methods in web applications can be exploited to move files and access protected content.

Sources:

  • 2:12-2:15 Intentionally broken website as part of the challenge
  • 2:27-2:53 Explanation of WebDAV vulnerability
  • 4:19-5:18 Using PROPFIND to discover directory structure
  • 8:17-8:43 Discovery of flag.txt in secret directory
  • 10:17-11:21 Finding backup source code revealing MOVE capability
  • 13:05-15:36 Moving flag.txt to static directory to access it

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

this captur the flag challenge is called The Da Vinci Code it's a medium challenge in the web category that I made I created this for the ncon capture the flag competition and the description is uh someone made a da Vinci Code fan page but they spelled it wrong and it looks like the website seems broken this is a Deployable per instance hey you can go ahead and spin up the task we'll click the start button here to make that available for us but I will be running this locally and I'll walk you through it and I'll tell you what this challenge is and how we put it together so I am running this challenge locally I've just spun up the docker container on Local Host Port 5000 but we're presented with this website for The Da Vinci Code uncover and unravel the secrets hidden in the works of Da Vin…