Village KeepKeepStore roomMy ordersWar roomWatch towerProfileScopeScoreboardLog in

Rules of engagement

Slide 3 and slide 8: permission, scope, and the fence you put up first.

Written authorization
This target exists to be attacked, and whoever operates this host has authorized you to test it for the duration of the session. That, and nothing else, is what makes this legal. The same application on anyone else's machine would not be yours to touch.

The fence

TargetDecision
https://ctfanz.in/IN SCOPE - the whole Village Keep app
/api/*IN SCOPE
/neighbour-villageOUT OF SCOPE - different owner, do not test
The host OS, your own laptopOUT OF SCOPE
Any real internet hostOUT OF SCOPE

Code of honour (slide 18)

  1. No written permission, no raid.
  2. Stay inside scope, every single time.
  3. Do no harm: no data deletion, no denial of service.
  4. Found something critical? Stop and tell the client now.
  5. Guard client data like your own treasure.
Burp setup, mirroring slides 7 and 8.
Proxy > Open browser. Click around once. Target > Site map, right-click https://ctfanz.in > Add to scope > Yes. Then Proxy > HTTP history > filter bar > Show only in-scope items.