Writeup of the SSTI (day 2) based challenges for the Comsec Xmas CTF.
$ find . --tag CUEH
-
-
Xmas CTF Day 2 Dev Notes
-rw-r--r--- DanG xmasctfAn introduction to SSTI and design notes on template injection for the Comsec Xmas CTF
-
On Demand, per user Docker shells
-rw-r--r--- DanG teachingExperiments with Spawning Docker Containers on demand over an SSH connection.
-
Docker for teaching EH
-rw-r--r--- DanG teachingThoughts on using docker for teaching PenTesting, and an introduction to a Linux Trainer
-
An update on the XSS Trainer
-rw-r--r--- DanG ctfAn Update to the XSS trainer, Now with added Server side checks
-
Detecting JS Alerts In Wargames
-rw-r--r--- DanG ctfTurning Alerts generated by XSS into a game, for fun and grades.
-
CLI basics wargame
-rw-r--r--- DanG teachingLearning through doing. A "wargame" to build basic Linux Skills