Covers Weeks 1–6. Individual, in the sandbox. Flags = points.
✅ This week — what to do
- Before — VM + tools ready; warm up on the Week 7 mock CTF.
- In class — hands-on CTF (
ctf.md); submit flags for points (your flags are per-student). - Rules — sandbox targets only; individual.
Time breakdown: AGENDA.md (../../AGENDA.md).
Format
A timed capture-the-flag with graded challenges across:
- Injection (SQLi / command injection) — this course's own apps, not DVWA.
- XSS (stored only) — this course's own week05 app, not Juice Shop.
- Auth / access control (IDOR, weak JWT forgery).
- Cryptography (crack a weak hash / break an ECB oracle).
Each solved challenge yields a flag; partial credit for documented progress.