Hacker101 CTF — Postbook Walkthrough

📰 Medium · Cybersecurity

Recently, I completed the Hacker101 Postbook challenge, a vulnerable blogging platform designed to demonstrate several common web… Continue reading on Medium »

Published 18 Jun 2026

Full Article

Title: Hacker101 CTF — Postbook Walkthrough

URL Source: https://medium.com/@ucarrcemre/hacker101-ctf-postbook-walkthrough-0fd40a698bba?source=rss------cybersecurity-5

Published Time: 2026-06-18T19:13:38Z

Markdown Content:
# Hacker101 CTF — Postbook Walkthrough | by Ucarcemre | Jun, 2026 | Medium

[Sitemap](https://medium.com/sitemap/sitemap.xml)

[Open in app](https://play.google.com/store/apps/details?id=com.medium.reader&referrer=utm_source%3DmobileNavBar&source=post_page---top_nav_layout_nav-----------------------------------------)

Sign up

[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40ucarrcemre%2Fhacker101-ctf-postbook-walkthrough-0fd40a698bba&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)

[](https://medium.com/?source=post_page---top_nav_layout_nav-----------------------------------------)

Get app

[Write](https://medium.com/m/signin?operation=register&redirect=https%3A%2F%2Fmedium.com%2Fnew-story&source=---top_nav_layout_nav-----------------------new_post_topnav------------------)

[Search](https://medium.com/search?source=post_page---top_nav_layout_nav-----------------------------------------)

Sign up

[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40ucarrcemre%2Fhacker101-ctf-postbook-walkthrough-0fd40a698bba&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)

![Image 1: Unknown user](https://miro.medium.com/v2/resize:fill:32:32/1*dmbNkD5D-u45r44go_cf0g.png)

# Hacker101 CTF — Postbook Walkthrough

[![Image 2: Ucarcemre](https://miro.medium.com/v2/da:true/resize:fill:32:32/0*kuyckkchj2ogTRu1)](https://medium.com/@ucarrcemre?source=post_page---byline--0fd40a698bba---------------------------------------)

[Ucarcemre](https://medium.com/@ucarrcemre?source=post_page---byline--0fd40a698bba---------------------------------------)

Follow

4 min read

·

Just now

[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fvote%2Fp%2F0fd40a698bba&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40ucarrcemre%2Fhacker101-ctf-postbook-walkthrough-0fd40a698bba&user=Ucarcemre&userId=da3d5200df81&source=---header_actions--0fd40a698bba---------------------clap_footer------------------)

1

[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Frepost%2Fp%2F0fd40a698bba&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40ucarrcemre%2Fhacker101-ctf-postbook-walkthrough-0fd40a698bba&user=Ucarcemre&userId=da3d5200df81&source=---header_actions--0fd40a698bba---------------------repost_header------------------)

1

[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fbookmark%2Fp%2F0fd40a698bba&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40ucarrcemre%2Fhacker101-ctf-postbook-walkthrough-0fd40a698bba&source=---header_actions--0fd40a698bba---------------------bookmark_footer------------------)

[Listen](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2Fplans%3Fdimension%3Dpost_audio_button%26postId%3D0fd40a698bba&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40ucarrcemre%2Fhacker101-ctf-postbook-walkthrough-0fd40a698bba&source=---header_actions--0fd40a698bba---------------------post_audio_button------------------)

Share

Press enter or click to view image in full size

![Image 3](https://miro.medium.com/v2/resize:fit:700/1*kqjQSA91qCNOWUhBBOMOLw.png)

Recently, I completed the Hacker101 Postbook challenge, a vulnerable blogging platform designed to demonstrate several common web application security flaws. Throughout the challenge, I encountered weaknesses related to authentication, authorization, hidden client-side parameters, predictable object references, and insecure session management.

This walkthrough explains the methodology I used to identify and exploit each vulnerability.

## Flag 0 — Weak Password Authentication

The first hint provided by the challenge
Read full article → ← Back to Reads