THB CTF Team Qualification : Challenge #01
π Rules of Engagement
β Black-box no source code provided, application access only
β In scope: the web application only
β Out of scope: host OS, Docker engine, or any infrastructure outside the
web app itself (this is a web challenge, not an OS pwn/pivot exercise)
β Automated scanners are allowed, but won't get you the whole way this
challenge tests manual analysis and business-logic reasoning
π Flag format: THB{...}
π A flag alone is not enough for TCTQ scoring
You must also submit a written report covering:
Initial Analysis : what you observed about the app on first pass
Attack Surface Enumeration : endpoints, parameters, and client-side
assets you reviewed
Hypothesis : what you suspected was wrong, and why
Exploitation : the exact steps/requests used to escalate privilege
Root Cause : the underlying flaw, explained in your own words
Evidence : requests/responses demonstrating the exploit
Mitigation : how you'd fix it if you were the developer
Reports are scored on methodology, clarity, and depth of root-cause
understanding : not just whether you found the flag.