Reflection & Review
Pre-Midterm · Weeks 1–6
Goal today
- Consolidate Weeks 1–6
- 🎯 Security Jeopardy team quiz-show
- 🧪 Mock CTF in the midterm format
- Build your one-page cheat sheet
Map of the half
🎯 Security Jeopardy
Categories × point values:
| Threat Modeling | Tooling | Crypto | Injection | XSS | Auth |
|---|
🧪 Mock CTF
Same format as Week 9, 6 challenges, ~150 min:
- Injection (SQLi / command)
- XSS (stored only — reflected/DOM aren't in this mock)
- Auth / IDOR / JWT
- Crypto (crack a hash — the ECB oracle is a Week 3 lab task, not part of this mock)
No surprises on exam day.
Common mistakes to avoid
- Confusing encoding vs encryption vs hashing
- "Validated input" ≠ safe → still parameterize
- Authentication without authorization
- Trusting client-side checks
Deliverable
A one-page cheat sheet (your own) — may be allowed in the exam at instructor's discretion.
Midterm next week
Wk 8 = written · Wk 9 = hands-on CTF · covers Weeks 1–6