Skip to content

CVE Workflow For World-Class Web CTF ​

High-level CVE work is not "run PoC and hope". Treat it as fingerprint -> applicability -> adaptation -> proof.

Authoritative Feeds ​

  • NVD CVE API 2.0: https://services.nvd.nist.gov/rest/json/cves/2.0
  • FIRST EPSS API: https://api.first.org/data/v1/epss
  • CISA KEV catalog / GitHub mirror: https://github.com/cisagov/kev-data
  • GitHub Global Security Advisories API: https://docs.github.com/rest/security-advisories/global-advisories

Workflow ​

  1. Fingerprint product and version
    • Headers, HTML comments, assets, source maps, lockfiles, package manifests.
    • Error pages and stack traces.
    • Static paths and default favicon hashes.
  2. Map to ecosystem
    • npm, PyPI, Maven, Composer, RubyGems, Go, Docker image, appliance.
  3. Enrich candidate CVEs
    • scripts/ctf-website/cve_lookup.py CVE-YYYY-NNNN
    • Check EPSS, KEV, CVSS, CWE, references, affected versions.
  4. Applicability proof
    • Does challenge expose the vulnerable route/config?
    • Are preconditions met: auth, role, parser, feature flag, default plugin?
  5. Exploit adaptation
    • Convert public PoC to minimal request sequence.
    • Remove noisy/destructive behavior.
    • Add flag extraction and evidence logging.
  6. Replay from clean state
    • Fresh session.
    • Minimal dependencies.
    • Save request/response and exploit script.

Runnable Baseline ​

powershell
python scripts/ctf-website/cve_lookup.py CVE-2024-0001 --out exports/ctf-website/case/cve.json
python scripts/ctf-website/cve_graph.py --help
python scripts/ctf-website/cve_chain_planner.py --help

Replace the example CVE with the fingerprinted candidate and preserve the JSON output as evidence.

Common CVE Classes In Web CTF ​

ClassExamples Of SurfacesWhat To Prove
RCE via template/parserOGNL, Spring, Struts, Freemarker, VelocityExpression evaluation reaches command/file primitive
DeserializationJava/PHP/.NET/Python/RubySigned/encrypted blob bypass or gadget present
Path traversal/file readFramework static serving, archive extractionRead flag path or config secret
SSRFPDF render, webhook, image fetch, metadata clientInternal service response or callback
Auth bypassOAuth/JWT/framework middlewarePrivileged endpoint reachable
Prototype pollutionNode config merge, template renderPolluted property reaches security decision
XXEXML upload/API/SOAPFile read or SSRF

Evidence Standard ​

  • Product/version evidence.
  • CVE enrichment report path.
  • Affected version/precondition evidence.
  • Minimal exploit script.
  • Flag extraction output.

Sources ​

This workflow is wired to the authoritative sources above. Re-check live API docs when extending the script because CVE feeds evolve.

MCP 工具映射 ​

AI Agent 可调用以下 MCP 工具自动完成或加速上述攻击步骤:

攻击步骤MCP 工具说明
CVE 知识检索kb_router按 CVE 信号搜索知识库相关技术
漏洞验证探测http_probeHTTP GET 探测验证 CVE 影响

GPL-3.0 · 仅供授权环境下的学习与防御性研究使用