Web Exploitation CTF Challenges
SQLi, XSS, SSRF, auth bypass & server-side payloads.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
Web exploitation is the discipline that most closely mirrors the work of an application security engineer. Targets are deliberately vulnerable web applications — custom-built for the competition or pulled from well-known public vulnerable labs — and your job is to find the flaw in how the application handles untrusted input, then turn that flaw into access you were never meant to have.
The mental model is consistent across every web challenge: input arrives, gets processed, and something about that process can be bent. A string that reaches a database query unescaped becomes SQL injection. A value reflected into a page without encoding becomes cross-site scripting. A server that fetches a URL you control becomes server-side request forgery. Learning web exploitation means learning to spot those seams and to know which tool tells you what.
Expect these challenges to punish surface-level scanning. A directory brute-force and a stock payload will get you exactly as far as they always do in a real engagement — nowhere. The scoring here rewards reading how the application behaves: noticing that a JSON field is concatenated into a shell command, or that an admin endpoint checks a cookie you can simply set yourself.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Injection flaws
SQL injection across stacked and blind variants, NoSQL injection, command injection and LDAP injection — where unescaped input reaches an interpreter and executes as code.
Cross-site scripting
Reflected, stored and DOM-based XSS, with realistic sinks: search fields, profile inputs, URL fragments and JSON responses reflected straight into client-side JavaScript.
Access control
IDOR through predictable identifiers, broken object-level authorisation, insecure direct object references and privilege escalation from a low-privilege account.
Server-side request forgery
Servers that fetch attacker-supplied URLs — including a cloud metadata endpoint in the final stages — turning an outbound request into a credential theft primitive.
Authentication & session
Weak session handling, predictable password resets, forgeable tokens and login flows that can be bypassed by editing a single request header.
Logic & race conditions
Discount stacking, negative-quantity purchases, race conditions between competing requests and business rules that were never written to be enforced.
Tools you’ll reach for
- Burp Suite Community
- sqlmap
- curl
- ffuf
- wfuzz
- Browser DevTools
- Python requests
- Hashcat / John
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Work through PortSwigger Web Security Academy end to end — it is free, structured, and maps almost one-to-one onto what the category tests.
Set up a local lab with intentionally broken apps: DVWA, Juice Shop and WebGoat. Break them by hand before you try to break a timed challenge.
Learn to read application source. Most web challenges ship a snippet, a config or a comment; the vulnerability is nearly always visible once you know where to look.
Get fast at reading Burp output — repeater, intruder and the request/response diff are where the actual work happens.
Memorise the handful of payloads that matter: a boolean SQLi test, a basic reflected-XSS tag, an SSRF probe, and a JWT `alg: none` variant.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
Web Exploitation is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.