All skills
ljagiello avatar

/ctf-web

@61c2efe
by Lukasz Jagielloljagiello/ctf-skills3.4k stars
393

Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, file upload, request smuggling, OAuth/OIDC, SAML, prototype pollution, and similar web bugs. Do not use it for native binary memory corruption, reverse engineering of standalone executables, disk or memory forensics, or pure cryptanalysis unless the web flaw is still the main path to the flag.

Use this Skill: https://skilld.dev/gh/ljagiello/ctf-skills/ctf-web

This session only. Nothing lands on disk.

auth-and-access-2.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

CTF Web - Auth & Access Control Attacks (Part 2)

2018-era additions: bucket-collision hash auth bypass, Unicode username homograph collision, SRP A=0/A=N bypass, ArangoDB AQL MERGE privilege escalation. For foundational auth/access techniques see auth-and-access.md. For JWT attacks see auth-jwt.md. For OAuth/OIDC/SAML/CI-CD, see auth-infra.md.

Table of Contents


std::unordered_set Bucket Collision Auth Bypass (Hackover 2018)

Pattern: A C++ backend stores credential hashes in std::unordered_set<std::string>. The set's bucket index is derived from only the first bytes of a SHA-512 digest (truncated size_t hash). The lookup loop aborts early after a bounded number of bucket probes (MAX_LOOKUPS = 1000). Flood the set with 1000+ entries that all collide in the same bucket as the root account — the compare for the correct entry never executes and the call returns "found" on an attacker-chosen password.

// Vulnerable shape
std::unordered_set<std::string> users;
auto it = users.find(login_key);           // probes at most MAX_LOOKUPS
if (it != users.end()) { /* accepted */ }
# Flood registration: every entry collides in root's bucket
import requests
for i in range(1100):
    requests.post("http://target/register",
                  data={"name": f"ro{i:04d}", "password": "ot1"})
# Log in as root with an arbitrary password — loop gives up before compare
requests.post("http://target/login", data={"name": "root", "password": "anything"})

Key insight: Hash-table implementations that truncate digests into bucket indices expose a second-preimage surface: the attacker only has to match the bucket, not the full hash. When the data structure also has a bounded probe count (DoS guard), flooding the bucket turns an authentication check into an unconditional accept. Any unordered_map/unordered_set keyed on low-entropy derivations of user input is suspect — watch for std::hash<std::string> implementations that reduce to size_t via XOR-folding.

References: Hackover CTF 2018 — secure-hash, writeup 11502


nodeprep.prepare Homograph Username Collision (HCTF 2018)

Pattern: Registration calls Node's node-xmpp-server nodeprep.prepare(username) which runs RFC-3491/Stringprep normalization. Unicode characters like ᴬ (U+1D2C Modifier Letter Capital A) normalize to ASCII A, then the existing user lookup finds the already-registered admin. Register ᴬdmin with any password, and the lookup returns the real admin row — set a new password via a password-reset flow.

username: \u1D2Cdmin   # ᴬdmin
nodeprep.prepare("ᴬdmin") == "admin"

Key insight: Any pipeline that (1) normalizes usernames before lookup but (2) stores the pre-normalized form separately is vulnerable. Normalize once at write-time and never accept users whose pre-normalized form collides with an existing row. Libraries to audit: nodeprep, icu.normalize, unicodedata.normalize, golang.org/x/text/secure/precis.

References: HCTF 2018 — admin, writeup 12132


SRP A=0, A=N Auth Bypass (OTW Advent 2018)

Pattern: SRP (Secure Remote Password) implementations that do not validate A % N != 0 allow the client to send A = 0 (or A = k*N). The server computes S = (A * v^u)^b mod N = 0, so the session key is H(0) — known to the attacker. Bypass login without knowing the password.

Client: sends A = 0
Server: computes S = 0
Session key: K = H(0)   # attacker knows this

Key insight: SRP, DH, and similar group-based protocols need explicit validation that public values are nontrivial. Spec-compliant SRP rejects A % N == 0; buggy implementations don't. Same attack works for A = N, 2N, ....

References: OverTheWire Advent Bonanza 2018 — writeup 12750


ArangoDB AQL MERGE Injection for Privilege Escalation (P.W.N. CTF 2018)

Pattern: ArangoDB's AQL query language accepts user-supplied fragments that are concatenated into FILTER clauses. Inject ' || 1 == 1 LET newitem = MERGE(u, {'role':'admin'}) RETURN newitem // to turn a login check into an in-memory role upgrade — the server returns the modified user object without touching the real record.

username: x' || 1 == 1 LET newitem = MERGE(u, {'role':'admin'}) RETURN newitem //
password: anything

Key insight: NoSQL databases each have their own injection grammar. AQL's MERGE creates a new document inheriting the found record's fields, bypassing any ACL that only checks persistent storage. Always use parameterised bind variables.

References: P.W.N. CTF 2018 — H!pster Startup, writeup 12067

Source: SKILL.md on GitHub

3 alerts16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive toolkit for web-based CTF challenges, including automated fuzzing scripts and a large catalog of exploitation payloads. It requires downloading external repositories and running installation scripts, and contains numerous prompt injection examples for bypassing AI safety filters.

  • Socket16d

    6 alerts: gptSecurity, gptMalware, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    7/8 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at 61c2efe. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 weeks ago.

Activeupdated 3 weeks ago
metadata
{
  "user-invocable": "false"
}
All 1 allowed tools
Bash Read Write Edit Glob Grep Task WebFetch WebSearch
Other metadata
compatibility
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.

README badge

README badge for ljagiello/ctf-skills/ctf-web