Hintru Propina ENES Convierte writeups en labs guiados
Usando key compartida — 3/3 labs, 30/30 evaluaciones restantes hoy configurar ▾

Usa tu propia API key de Anthropic para evitar límites y pagar solo por lo que uses. Consíguela en console.anthropic.com/settings/keys. La key vive solo en tu sesión — nunca se escribe a disco ni se registra.

Generar nuevo lab

Pega la URL de un writeup (HTB, bug bounty, artículo de Medium) o el texto plano. Las capturas del writeup se envían al modelo de visión de Claude para extraer payloads visibles en capturas de Burp.

Consejo: si pegas texto Y agregas la URL, las imágenes se extraen igual desde la URL.

Labs existentes (7)

EN medium CTF challenge XXE XML External Entity in-band exfiltration JS bundle recon API enumeration DTD injection arbitrary file read

Tanuki is a flashcard web app with an XML-based deck export and a JSON-driven restore endpoint. The server secretly round-trips your JSON through an XML template with DTD processing enabled — giving you a path to read arbitrary files off the server without any out-of-band channel. Your goal is to exfiltrate the flag at /app/flag.txt entirely in-band.

0/7 · 2026-05-19 16:49:18 Abrir → ·
EN hard CTF challenge Web Cache Poisoning XSS Header Injection Stored XSS CSRF Bot Exploitation Exfiltration

MesaNet is a Black Mesa Transit rail broadcast panel running on Bugforge's lab infrastructure. The application caches API responses and reflects a custom header value directly into HTML, creating a chained attack path: poison the cache with a script injected via a custom header, then trick a bot into viewing the poisoned page — causing it to exfiltrate its private notes (and the flag) to an attacker-controlled webhook.

0/7 · 2026-05-01 15:14:35 fuente ↗ · Abrir → ·
EN hard CTF challenge Stored XSS XSS bot CSRF confused deputy innerHTML sink headless browser session hijack API abuse

The MesaNet Portal hosts a "Rail Broadcasts" application accessible through a JSON gateway API. A low-privilege operator account can interact with several broadcast endpoints, but a confidential note owned by a privileged automated user sits just out of reach. The challenge requires chaining the broadcast creation pipeline with the automated oversight system to escalate access without ever touching the privileged session directly.

0/8 · 2026-04-30 09:58:55 fuente ↗ · Abrir → ·
EN easy CTF challenge GraphQL Introspection Broken Access Control Information Disclosure API Security

The Breach challenge on WebVerse Labs exposes a GraphQL API backing a notes application. The notes are visible in the UI, but a GraphQL schema often has surfaces the front-end never touches. Map what's really there, and find a way to reach the flag.

0/4 · 2026-04-18 22:50:09 fuente ↗ · Abrir → ·
EN medium CTF challenge BAC Broken Access Control HTTP Verb Tampering IDOR Authorization Bypass Burp Suite

Ottergram is a social-media-style web application on Bugforge.io where users browse otter photos. The attack chain is two-stage: first, find functionality you shouldn't be able to reach. Then, find a way past the gate that's supposed to stop you.

0/5 · 2026-04-18 16:26:52 fuente ↗ · Abrir → ·
EN easy bug bounty writeup Open Redirect SSRF parameter injection URL manipulation phishing recon

A phishing/spam email promotes a 'free partnership tool' at start.avail.zone. The invite URL passes a domain through a query parameter — what does the server actually do with it? Investigate the request flow and find an abuse path that could turn this 'invite' into something nastier.

0/5 · 2026-04-15 14:57:14 Abrir → ·
EN easy CTF challenge Business Logic JSON Array Injection Coupon Abuse Parameter Tampering Burp Suite

A pizza-ordering web application on Bugforge gives registered users a single-use discount code. The flag goes to whoever can apply more discount than they should — the fix is one HTTP request away, but you'll need to think carefully about how the server interprets the input you send.

0/4 · 2026-04-12 10:12:47 fuente ↗ · Abrir → ·

¿Te gusta Hintru? Buy me a coffee ☕ ☕