AI Engineer - Learn how to integrate AI into software applications
Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
This video walkthrough demonstrates solutions for five web challenges from the 2025 CIT@CTF competition, covering essential cybersecurity techniques. Learn how to exploit SQL injection vulnerabilities to bypass authentication, extract sensitive information from git repository history using git-dumper, perform local file reads by bypassing basic filters, manipulate Flask session cookies for server-side template injection (SSTI) attacks, and leverage credential reuse combined with HTTP method tampering. The 17-minute tutorial includes practical demonstrations with accompanying writeups available on the creator's website, making it ideal for CTF participants and cybersecurity enthusiasts looking to enhance their web exploitation skills. The content is organized into clear sections with timestamps for easy navigation through each challenge solution.
Syllabus
0:00 Intro
0:06 Breaking authentication SQLi
2:20 Commit & Order: Version Control Unit git dumping / history
4:25 How I Parsed your JSON local file read with basic filter
7:30 Mr. Chatbot flask session tampering and SSTI
14:40 Keeping Up with the Credentials reused credentials and HTTP verb tampering
16:20 Conclusion
Taught by
CryptoCat