World Congress 2022 • Jun 15, 2022

Capture the Flag 101

Micah Silverman

Is a widely used package secretly compromising your Node.js runtime? Adopt a "hack yourself" mindset with Capture the Flag exercises to proactively exploit and patch hidden architectural vulnerabilities.

Pause
Mute Enter Fullscreen
#1 about 5 min

Introduction to cloud-native application developer security

How shifting security to developers changes traditional approaches to application safety.

#2 about 3 min

Learning application security through capture the flag events

How complex cross-functional challenges encourage practical learning and out-of-the-box thinking.

#3 about 3 min

Understanding flags and collaborative rules of engagement

Finding alphanumeric solution codes while sharing progress without spoiling the challenge.

#4 about 3 min

Setting up the invisible ink web vulnerability challenge

Gathering provided files and interface hints to start solving the web application security puzzle.

#5 about 2 min

Utilizing basic HTTP verbs for security exploration

Reviewing get, post, and delete methods to understand how data interacts with the RESTful server.

#6 about 6 min

Interacting with payloads and content types using curl

Sending command line requests to test server responses and discover tainted data flows.

#7 about 2 min

Identifying prototype pollution vulnerabilities with scanning tools

Running a security scan against the package configuration to discover prototype pollution flaws.

#8 about 8 min

Exploiting lodash merge functions via prototype pollution

Using practical proof of concepts to inject arbitrary data into JavaScript object prototypes.

Matching moments

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · World Congress 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:41 min

Setting the stage for software security demos

Vandana Verma Sehgal · LIVE

4:35 min

Improving developer education with realistic security training environments

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · World Congress 2024