Breaking Web Application: Busting Makes Me Feel Good


Link


The Reasoning

Let’s call a spade a spade, and all other gardening tools by their appropriate names for that matter, web applications are still the dominant form of application in development today. Mobile and AI are quickly on the rise but Web Apps are still king. So, to make it in cybersecurity you have to be able to know how to secure them. This comes from both ends in both defending them and attacking them so you know your defenses worked. This can add value to the company you work for, in the form of pentests, and external companies, in the form of bug bounties. Plus, I hear you get internet points (you probably thought IP stood for Internet Protocol) for posting about your coolest findings.


The Learning Path, Part 1

So, a couple of friends and myself started a study group and we were going to burn through all three HTB certs (CDSA, CPTS, and CBBH at the time) and share notes, what we learned, attack cheat sheets, etc. I diligently toiled my way through the entire CBBH Learning Path and like a good study group partner pasted my status to my co-workers, including cool commands and things I learned that I thought were interesting. In my mind, we were building our own little mini-HackTricks and going to dominate the exam with our monster OneNote/Obsidian/Confluence/favorite note-taking app. I get to the finish line, everyone else gave up. No one else even over 50%. I had a decision to make about the exam. But, with the wind deflated and imposter syndrome gnawing at me, decided to shelve it. Never let your success be dependent on others. The exam is a solitary effort so it didn’t matter if I had my friends or not, but I let it matter…for reasons.


Learning Path, Part 2

At some point, the Hack The Box wizards deemed the Certified Bug Bounty Hunter to be no more. The CBBH had been rechristened Certified Web Exploitation Specialist (CWES). And with this rebrand, it also included more modules that I had to complete. The video game completionist in me started to show here. I wasn’t even sure if I was going to take the exam but I saw 77% in my previously finished learning path and determined that this shall not stand. Then, I immediately paused whatever I was doing at the time and switched over to rock out the extra modules to bring me back to that sweet 100%.


The Exam Experience

This was a surprisingly frustrating certification exam. You work hard to find a vulnerability. Then, that is only part of the equation, as you still have to work to be able to read the flag. Plus, you gain RCE but never really have to pop a full shell as you can read the flag from web app command execution. So, you don’t even get that great dopamine hit from getting your initial foothold shell. And let’s all be honest with ourselves, that dopamine hit is why we are all in cybersecurity. The helping people and securing the internet will forever only be secondary outcomes of our need to chase the warm and fuzzies from popping shells. Don’t lie.


The Wait

The wait is always the absolute worst part of the HTB certification process. I don’t really know what new I can say about it since this is my third HTB certification post now. You are looking at 3 to 4 weeks of wait time to get your results back. And, yes, I am one of those people who sit there and constantly refresh hoping for an update…for 3 to 4 weeks. The anxiety is slightly mitigated since I know how many points that I have. I also took other HTB certifications so I roughly know what guidelines they are looking for in the report. I am reasonably certain that I passed. The anxiety isn’t too high. The waiting is still hard though. And since you are reading this post, my intuition was correct and I actually did pass so there you go.


What’s next

So, I have CISSP penciled in for my next “project.” This is the best credential for the resume as it is the most widely recognized certification in the cybersecurity industry. But, since I am red team heavy, might shift that to the Certified Red Team Operator (CRTO) by Zero Point Security. Fully lean into where my career journey is taking me. Plus, I struggle with CISSP study (see CISSP Study). Now, to definitely and conclusively answer the question, what’s next. The survey says, I don’t know.


Lessons Learned

The biggest benefit to taking this class for me is reigniting the pentesting juices so I am firing on all cylinders. I have worked in Blue Team for the last year or so (and focused on their certs (looking at you PMRP and CDSA)). Needless to say, there was some ring rust to shake off so I can get back in the ring and take another swing. The first big takeaway is methodology tightening. I was able to tighten up my processes and redevelop my Audit Program so I am fighting fit for the next company that hires me. The second benefit is a refresh to the exploits, namely what they are and what they look like in a live environment. That way I can recognize them from a blue or red context. Finally, reporting was a huge win. Say what you want about it being more boring than the hacking part, but if you can’t communicate your findings effectively you are not much benefit to the devs you are trying to help. Suck it up and create the best report you can.


Reflections

My biggest takeaway: Remember your objective. It’s going to sound repetitive at this point but I think it is important. Take a look at the information you have available and always think what can I do with this. We are ultimately fixated on the flag since this is a CTF but take a step back and acknowledge what you have access to and what you can do with it. I guess this is a long-winded way to say enumeration is your friend. When you are down and troubled and need a helping hand. You have enumeration. Read everything and understand all functionalities available to you. If you are still stuck, enumerate some more. Eventually, you will find a functionality that screams, or at least whispers, “look at me.” Add it to the attack pipeline and continue to chain until you hit that RCE.

What helped me most:

Breathe. Remember where you are and what you have access to and where you can go. And breathe again.


Similar Content:

  • Coming Soon!

Feel free to reach out if you took it too! I would love to know your experience.