CVE Workflow For World-Class Web CTF
High-level CVE work is not "run PoC and hope". Treat it as fingerprint -> applicability -> adaptation -> proof.
Authoritative Feeds
- NVD CVE API 2.0:
https://services.nvd.nist.gov/rest/json/cves/2.0 - FIRST EPSS API:
https://api.first.org/data/v1/epss - CISA KEV catalog / GitHub mirror:
https://github.com/cisagov/kev-data - GitHub Global Security Advisories API:
https://docs.github.com/rest/security-advisories/global-advisories
Workflow
- Fingerprint product and version
- Headers, HTML comments, assets, source maps, lockfiles, package manifests.
- Error pages and stack traces.
- Static paths and default favicon hashes.
- Map to ecosystem
- npm, PyPI, Maven, Composer, RubyGems, Go, Docker image, appliance.
- Enrich candidate CVEs
scripts/ctf-website/cve_lookup.py CVE-YYYY-NNNN- Check EPSS, KEV, CVSS, CWE, references, affected versions.
- Applicability proof
- Does challenge expose the vulnerable route/config?
- Are preconditions met: auth, role, parser, feature flag, default plugin?
- Exploit adaptation
- Convert public PoC to minimal request sequence.
- Remove noisy/destructive behavior.
- Add flag extraction and evidence logging.
- Replay from clean state
- Fresh session.
- Minimal dependencies.
- Save request/response and exploit script.
Runnable Baseline
powershell
python scripts/ctf-website/cve_lookup.py CVE-2024-0001 --out exports/ctf-website/case/cve.json
python scripts/ctf-website/cve_graph.py --help
python scripts/ctf-website/cve_chain_planner.py --helpReplace the example CVE with the fingerprinted candidate and preserve the JSON output as evidence.
Common CVE Classes In Web CTF
| Class | Examples Of Surfaces | What To Prove |
|---|---|---|
| RCE via template/parser | OGNL, Spring, Struts, Freemarker, Velocity | Expression evaluation reaches command/file primitive |
| Deserialization | Java/PHP/.NET/Python/Ruby | Signed/encrypted blob bypass or gadget present |
| Path traversal/file read | Framework static serving, archive extraction | Read flag path or config secret |
| SSRF | PDF render, webhook, image fetch, metadata client | Internal service response or callback |
| Auth bypass | OAuth/JWT/framework middleware | Privileged endpoint reachable |
| Prototype pollution | Node config merge, template render | Polluted property reaches security decision |
| XXE | XML upload/API/SOAP | File read or SSRF |
Evidence Standard
- Product/version evidence.
- CVE enrichment report path.
- Affected version/precondition evidence.
- Minimal exploit script.
- Flag extraction output.
Sources
This workflow is wired to the authoritative sources above. Re-check live API docs when extending the script because CVE feeds evolve.
MCP 工具映射
AI Agent 可调用以下 MCP 工具自动完成或加速上述攻击步骤:
| 攻击步骤 | MCP 工具 | 说明 |
|---|---|---|
| CVE 知识检索 | kb_router | 按 CVE 信号搜索知识库相关技术 |
| 漏洞验证探测 | http_probe | HTTP GET 探测验证 CVE 影响 |