jaalso@kali:~$ ls -la ctf/

CTF & Box

Platform labs, CTF challenges, and boxes I've solved on PortSwigger, OWASP Juice Shop, and TryHackMe — guided practice targets, separate from my own builds under ~/labs.

// solved
PortSwigger Web Security Academy
18 labs solved · Apprentice + Practitioner
SQL injection · 5
SQLi in WHERE clause — retrieving hidden data apprentice
SQLi allowing login bypass apprentice
Querying DB type & version (MySQL / Microsoft) practitioner
UNION attack — determining number of columns practitioner
UNION attack — finding a column containing text practitioner
UNION attack — retrieving data from other tables practitioner
Path traversal · 4
File path traversal, simple case apprentice
Traversal blocked — absolute path bypass practitioner
Traversal stripped non-recursively practitioner
Traversal stripped with superfluous URL-decode practitioner
Access control · 3
User role controlled by request parameter apprentice
Insecure direct object references (IDOR) apprentice
Authentication bypass via OAuth implicit flow apprentice
XSS · 2
Reflected XSS into HTML context, nothing encoded apprentice
Stored XSS into HTML context, nothing encoded apprentice
Auth · CSRF · File upload · 3
Username enumeration via different responses apprentice
CSRF vulnerability with no defenses apprentice
Remote code execution via web shell upload apprentice
OWASP Juice Shop
10 challenges solved · self-hosted in Docker, attacked through Burp
Injection & access control
Login Admin — SQL injection auth bypass
Login Bender — SQLi, target user ★★
Admin Section — UNION-based SQLi ★★
User Credentials — forced browsing ★★★
View Basket — IDOR ★★
DOM XSS
Bonus Payload — reflected XSS via URL params
Error Handling — provoked server error
Confidential Document — path access
Privacy Policy
TryHackMe
Active Directory rooms completed
Active Directory exploitation
Attacktive Directory — exploiting a vulnerable Domain Controller medium
Exploiting Active Directory — common AD attack techniques medium
Hack The Box
retired boxes land here as I complete them — profile active
Profiles: TryHackMe ↗ · Hack The Box ↗