Challenge Author: LT ‘SYREAL’ JONES
Category: Web Exploitation
Difficulty: Easy
Description
Can you get the flag?
Process / Notes
- Start the challenge instance
- Details on the “include/copy/import” directive that contains a second file inserted into the first file
- Check the source
- There’s a button to say hello at the bottom
- Knowing to check the linked files in the source this time, checking the style.css…
- That contained half the flag!
- The script that looks like it gets run when you press the button had a comment containing the other half of the flag.
10 minutes 29 seconds to complete
Hints
Core Lessons
- Understand how to use the web inspector
- Understand how to examine embedded files