THB CTF Team Qualification : Challenge #01

THB CTF Team Qualification : Challenge #01


πŸ“œ Rules of Engagement

βœ… Black-box no source code provided, application access only

βœ… In scope: the web application only

❌ Out of scope: host OS, Docker engine, or any infrastructure outside the

web app itself (this is a web challenge, not an OS pwn/pivot exercise)

βœ… Automated scanners are allowed, but won't get you the whole way this

challenge tests manual analysis and business-logic reasoning

🏁 Flag format: THB{...}

πŸ“ A flag alone is not enough for TCTQ scoring

You must also submit a written report covering:

Initial Analysis : what you observed about the app on first pass

Attack Surface Enumeration : endpoints, parameters, and client-side

assets you reviewed

Hypothesis : what you suspected was wrong, and why

Exploitation : the exact steps/requests used to escalate privilege

Root Cause : the underlying flaw, explained in your own words

Evidence : requests/responses demonstrating the exploit

Mitigation : how you'd fix it if you were the developer

Reports are scored on methodology, clarity, and depth of root-cause

understanding : not just whether you found the flag.

Report Page