Lightlines
By ljagiello

ctf-web

ljagiello

Find the smallest web exploit that proves the path.

web exploitation

What it does

Guides web-heavy CTF work to map the application, confirm its trust boundary, and develop a minimal exploit proof.

When to use it

Use it when a CTF target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract surface.

How to use it

Give it a web-heavy CTF target; it maps the application, classifies likely bugs, and returns a minimal proof or exploit path.

What you provide

  • the CTF web target

Access · 3

This skill

the challenge web application

Write

Sends exploit requests

pip install sqlmap flask-unsign requests httpx

Execute

Installs Python web tooling

ffuf

Execute

Installs ffuf from latest source

What you need · 8

Python 3 must be available for the tooling and bundled Python script.

The sqlmap package must be installed for the documented SQL injection workflow.

The flask-unsign package must be installed for Flask cookie analysis.

The requests package must be installed for the documented HTTP tooling and exploit examples.


About this skill

Visibility
Public
Repository
ljagiello/ctf-skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
24