7 months ago
Public voting is now open
It's your turn to pick the Popular Choice award winner! Browse 'HTS 2k25-Hack The Shield' submission gallery, click on your favorite, and vote. Be sure to spread the word via your social networks, too!
Please note, as per the Devpost terms of service, you may not tamper with the vote process through manual or automated means, or attempt to compensate voters, at risk of disqualification. Find out more about public voting here.
Questions?If you have any questions about the hackathon, please post on the discussion forum.
7 months ago
π₯ ROUND:03 Mini Project: βBuild & Secure a Vulnerable Appβ
β³ Duration: 2 Days π― GoalTeams will build a small web app, intentionally add real bug bounty vulnerabilities, exploit them, and then fix them.
Required Vulnerabilities
Your app must include at least:
-
IDOR
-
Broken Access Control
-
XSS (stored or reflected)
-
Insecure File Upload
Bonus (optional):
-
Weak JWT secret
-
Sensitive data leak
-
CSRF
Required Submission
Teams must submit all of the following:
-
Vulnerable Version (Before Fix) β> the intentionally vulnerable app.
-
Secure Version (After Fix) β> patched & secured app.
-
Bug Bounty Report (Mandatory) β> a professional report including:
-
Bug Title
-
Vulnerability Type (IDOR/XSS/etc.)
-
Severity
-
Steps toβ¦
-
7 months ago
Round 02 Begins π₯ ( Operation: Broken Web )
Operation: Broken WebBlackHaze has breached Rivertownβs Web Command Core and left 4 vulnerable entry points.
Your mission: Exploit them, capture the flags, restore the system.
π¦ IDOR Breach β Access restricted profile & extract token.
Difficulty: β
β
ββ
π© XSS Injection β Trigger redirect using JS payload.
Difficulty: β
β
ββ
π₯ SQLi Bypass β Break login via SQL manipulation.
Difficulty: β
β
β
β
πͺ Admin Takeover β Find & breach hidden admin panel.
Difficulty: β
β
β
β
7 months ago
Round 01 Begins π₯ ( City of Shadows π©)
Rivertown is under Rockyβs control. Your mission: find the 9 hidden flags in the dataset below and submit them with your team info
π Download The Dataset Find 9 Flags: Click Here
β
Everything is safe. Explore, investigate, and capture the flags!
Format:
1. FLAG-01 Β
2. FLAG-02 Β
β¦ Β
9. FLAG-09 Β
Team Name: Β
Members: Β
Email: Β
The city waits. Only you can topple Rocky. Good luck!
