Movatterモバイル変換


[0]ホーム

URL:


Skip to content
DEV Community
Log in Create account

DEV Community

DaNeil C
DaNeil C

Posted on • Edited on

     

Hacker101 CTF - BugDB v1

  • CTF Name: BugDB v1
  • Resource: Hacker101 CTF
  • Difficulty: Easy
  • Number of Flags: 1

Note::: NO, I won't be posting my found FLAGS, but I will be posting the methods I used.


Flag0

  • Hint:
    1. What can you see? What can you not see?
    2. What data types are involved?
    3. Have you tried querying different endpoints?
  • Acquired By:
    • This was a big odd of a hint so I started out just looking at the super blank page and looking at its code.Alt Text
    • Now that I've looked over it all I will poke around at the GraphQL tool that it is.Alt Text
    • With this CTF the left side of the page is the query and the right side is the output. This required knowing what queries GraphQL will accept soooo let's try some things.Alt TextAlt Text
    • Now I need to find the specific pattern to get alllllll of the information. Time to try some more thingsAlt Text
    • After some research and adding lots of things to the query I was able to get all the information to show up.Alt TextIf you look in the bugs of the second node ID there is a "text" field that has the flag.Alt Text

Thoughts/Learned

I have not played around with graphQL much so this was an interesting CTF to get me to research it more. I am looking forward to the second on and seeing how this will change.
I don'treally know what I learned outside of more about GraphQL as this environment was set up for this.


Happy Hacking

Please Note that I am still learning and if something that I have stated is incorrect please let me know. I would love to learn more about what I may not understand fully.

Top comments(0)

Subscribe
pic
Create template

Templates let you quickly answer FAQs or store snippets for re-use.

Dismiss

Are you sure you want to hide this comment? It will become hidden in your post, but will still be visible via the comment'spermalink.

For further actions, you may consider blocking this person and/orreporting abuse

I write to better educate myself as I go through CTFs and Bug Bounties. If anything I have written is incorrect, please let me know and send me a link to an article to read to better educate myself.
  • Location
    Seattle
  • Education
    Information Technology BA and Software Engineering Bootcamp Grad
  • Work
    Security Engineer/Researcher Performing Responsible Disclosure
  • Joined

More fromDaNeil C

DEV Community

We're a place where coders share, stay up-to-date and grow their careers.

Log in Create account

[8]ページ先頭

©2009-2025 Movatter.jp