Janith Deshan
COL --:--:--

SANDBOX · AUTHORIZED TESTING ONLY

The Lab.

A small cyber range built into my portfolio. Hunt the six hidden flags, poke around a real shell, and see how this site is secured.

flags 0 / 6 captured

drag to spin · simulated traffic
01

~/ctf

./capture --flags

This site is also a capture the flag challenge.

Six flags are hidden across the whole site: the home page, this page, the shell, and a few places in between. They use the format JD{…}. You'll need recon, DevTools, and some curiosity. Submissions are checked in your browser against SHA-256 hashes, so reading the source won't show you the answers.

[scope] This website only, client-side. Please don't test GitHub's infrastructure.

0 / 6 captured

    02

    ~/shell

    /bin/jdsh

    The same shell as the home page, with more room. Type help to get started. You can submit flags here with submit JD{…}.

    guest@jd: ~ focus `

    Starting shell…

    try:
    03

    ~/site-security

    cat /etc/site-security.conf

    A security portfolio should be secure too. Here's how this site is built, including what it can't do.

    /etc/site-security.confself-audit

    # How this site is built:

    • [✓] Content-Security-Policy: scripts limited to self and 3 pinned CDNs
    • [✓] Subresource Integrity (sha384) on every third-party script and stylesheet
    • [✓] No inline scripts, no eval, no frameworks, no build step
    • [✓] No analytics, no trackers, no third-party cookies
    • [✓] RFC 9116 /.well-known/security.txt
    • [✓] HTTPS enforced · strict referrer policy · rel="noopener" on external links
    • [!] Contact form delivered by EmailJS (third party); the only outside API the home page calls
    • [!] One deliberately insecure cookie (it's a CTF challenge)
    • [!] GitHub Pages can't send custom headers, so CSP is set by meta tag and frame-ancestors isn't enforced