Challenge Category

Web Exploitation CTF Challenges

SQLi, XSS, SSRF, auth bypass & server-side payloads.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

Web exploitation is the discipline that most closely mirrors the work of an application security engineer. Targets are deliberately vulnerable web applications — custom-built for the competition or pulled from well-known public vulnerable labs — and your job is to find the flaw in how the application handles untrusted input, then turn that flaw into access you were never meant to have.

The mental model is consistent across every web challenge: input arrives, gets processed, and something about that process can be bent. A string that reaches a database query unescaped becomes SQL injection. A value reflected into a page without encoding becomes cross-site scripting. A server that fetches a URL you control becomes server-side request forgery. Learning web exploitation means learning to spot those seams and to know which tool tells you what.

Expect these challenges to punish surface-level scanning. A directory brute-force and a stock payload will get you exactly as far as they always do in a real engagement — nowhere. The scoring here rewards reading how the application behaves: noticing that a JSON field is concatenated into a shell command, or that an admin endpoint checks a cookie you can simply set yourself.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Injection flaws

SQL injection across stacked and blind variants, NoSQL injection, command injection and LDAP injection — where unescaped input reaches an interpreter and executes as code.

Cross-site scripting

Reflected, stored and DOM-based XSS, with realistic sinks: search fields, profile inputs, URL fragments and JSON responses reflected straight into client-side JavaScript.

Access control

IDOR through predictable identifiers, broken object-level authorisation, insecure direct object references and privilege escalation from a low-privilege account.

Server-side request forgery

Servers that fetch attacker-supplied URLs — including a cloud metadata endpoint in the final stages — turning an outbound request into a credential theft primitive.

Authentication & session

Weak session handling, predictable password resets, forgeable tokens and login flows that can be bypassed by editing a single request header.

Logic & race conditions

Discount stacking, negative-quantity purchases, race conditions between competing requests and business rules that were never written to be enforced.

Tools you’ll reach for

  • Burp Suite Community
  • sqlmap
  • curl
  • ffuf
  • wfuzz
  • Browser DevTools
  • Python requests
  • Hashcat / John

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Work through PortSwigger Web Security Academy end to end — it is free, structured, and maps almost one-to-one onto what the category tests.

  2. Set up a local lab with intentionally broken apps: DVWA, Juice Shop and WebGoat. Break them by hand before you try to break a timed challenge.

  3. Learn to read application source. Most web challenges ship a snippet, a config or a comment; the vulnerability is nearly always visible once you know where to look.

  4. Get fast at reading Burp output — repeater, intruder and the request/response diff are where the actual work happens.

  5. Memorise the handful of payloads that matter: a boolean SQLi test, a basic reflected-XSS tag, an SSRF probe, and a JWT `alg: none` variant.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

Web Exploitation is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.