A Pentester's Guide to CTFs | by panawesome

A Pentester's Guide to CTFs | by panawesome

Source: YouTube · Hack The Box · published Mar 21, 2023 · 29:20

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates how penetration testers can benefit from CTF challenges through a practical web challenge walkthrough, showing real-world vulnerabilities like XSS and IDOR exploits 0:01.

Key Takeaways:
• CTFs provide learning opportunities and hands-on practice for penetration testers to stay current with attack techniques 1:13
• Three types of penetration testing exist: black box (no info), white box (full access), and gray box (some info) which is most common 2:40
• XSS vulnerabilities can lead to session hijacking by stealing cookies through malicious JavaScript 7:47
• IDOR (Insecure Direct Object Reference) vulnerabilities occur when applications trust user input to access objects directly 10:43
• The demonstration shows exploiting stored XSS to steal admin cookies, then using IDOR to reset the admin password 15:58

The video provides a realistic example of how these vulnerabilities appear in actual applications and how they can be chained together to gain unauthorized access.

Sources:

  • 0:01 Introduction to CTF benefits for pen testers
  • 1:13 Learning opportunities in CTFs
  • 2:40 Types of penetration testing
  • 7:47 XSS attacks and session hijacking
  • 10:43 IDOR vulnerability explanation
  • 15:58 XSS payload demonstration

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hi everyone this is Panos from hack the box and we are going to go over one of last year's easy web challenges and this was one of my favorite challenges and we are going to go over how a pen tester would see it sounds like this how a pen tester can benefit from something like this and some of the general pen testing process guidelines why am I doing this presentation is okay a couple things for me I start computer science right I did both my bachelor's and my masters in the Athens University of comics and business I I started being a CTF player with some guys that I learned from University and that led me to nothing my first job being a penetration tester and I was doing that for four years before joining hack the box right now I'm working at the community of hack the box like sever apoca…