Find the smallest web exploit that proves the path.
web exploitation
Guides web-heavy CTF work to map the application, confirm its trust boundary, and develop a minimal exploit proof.
When to use it
Use it when a CTF target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract surface.
Give it a web-heavy CTF target; it maps the application, classifies likely bugs, and returns a minimal proof or exploit path.
What you provide
This skill
the challenge web application
Sends exploit requests
pip install sqlmap flask-unsign requests httpx
Installs Python web tooling
ffuf
Installs ffuf from latest source
Python 3 must be available for the tooling and bundled Python script.
The sqlmap package must be installed for the documented SQL injection workflow.
The flask-unsign package must be installed for Flask cookie analysis.
The requests package must be installed for the documented HTTP tooling and exploit examples.