SANDBOX · AUTHORIZED TESTING ONLY
The Lab.
A small cyber range built into my portfolio. Hunt the six hidden flags, poke around a real shell, and see how this site is secured.
flags 0 / 6 captured
~/ctf
This site is also a capture the flag challenge.
Six flags are hidden across the whole site: the home page, this page, the shell, and a few places in between. They use the format JD{…}. You'll need recon, DevTools, and some curiosity. Submissions are checked in your browser against SHA-256 hashes, so reading the source won't show you the answers.
[scope] This website only, client-side. Please don't test GitHub's infrastructure.
Welcome back, administrator. (Were you, though?)
Access was granted because a cookie said so. Never trust the client.
~/shell
The same shell as the home page, with more room. Type help to get started. You can submit flags here with submit JD{…}.
Starting shell…
~/site-security
A security portfolio should be secure too. Here's how this site is built, including what it can't do.
# How this site is built:
- [✓] Content-Security-Policy: scripts limited to self and 3 pinned CDNs
- [✓] Subresource Integrity (sha384) on every third-party script and stylesheet
- [✓] No inline scripts, no eval, no frameworks, no build step
- [✓] No analytics, no trackers, no third-party cookies
- [✓] RFC 9116 /.well-known/security.txt
- [✓] HTTPS enforced · strict referrer policy · rel="noopener" on external links
- [!] Contact form delivered by EmailJS (third party); the only outside API the home page calls
- [!] One deliberately insecure cookie (it's a CTF challenge)
- [!] GitHub Pages can't send custom headers, so CSP is set by meta tag and frame-ancestors isn't enforced