HIDDEN SOURCE CODE (PicoCTF 2022 #13 'inspect-html')
Key Takeaways
The video demonstrates how to solve the 'inspect-html' challenge from PicoCTF 2022 by inspecting the HTML source code of a webpage to find a hidden flag, using tools like curl and grep to automate the process.
Full Transcript
ladies and gentlemen welcome back to another youtube video showcasing the pico ctf 2022 capture the flag in the last video we got to dig through some html css javascript the beginning fundamentals foundations for web exploitation that we might continue on and do forward and we finally finished 12 challenges and cracked our way through the first page of the pico ctf game so now we're moving on and doing some more fun stuff and uh let's get to it over here in my cali virtual machine of course i'm navigating the pico ctf webpage and we're cruising onward to another web exploitation challenge called inspect html might be kind of another symbol simple similar one as the last challenge it says can you get the flag go to this website and see what you can discover a-okay ooh on his his dice i don't know what that is i don't know what any of this is and i i don't want to read it so i'm i'm not going to um but look i mentioned previously hey it's cool to see what this web page is showing us what it's willing to give us outright but i want to dig into the cool stuff i want to dig into the internals i want to see how it's made and put together i want to look at the source code best way to do that right click and view page source and there we okay that is that challenge there is our flag so look i mentioned in the previous video you you know comments in scripting languages programming languages markup languages etc um we saw it in pico sorry in python with the octothorpe with that hashtag or pound symbol we also just as well saw it in python well no i just said that we saw it in jscript dude i'm falling apart i saw it in javascript right with the two forward slashes just the same way we saw it in the c programming language you also saw in css the cascading style sheets forward slash and the asterisks and c does that just as well for multi-line or multi-block comments now html html uses these greater than and less than symbols to denote an element right for for markup with an exclamation point and two hyphens to note the beginning and ending of the comment it's not going to be rendered out on the page of course we didn't see that when we were just looking at how the web browser presented to us but it's still going to be included and something that we can see as a client and user receiving this html page and content maybe sometimes there's some spooky secrets i don't know shenanigans that might be included in there in this case hey it's our flag and that's that like can i even should i is it even worth making a directory for this thing hey we'll do it just for the i don't know completion's sake we could probably like legit solve this we'll write a get flag script here let's use curl to download this webpage and let's grep again taco e pico ctf with the flag format just like that using curl rather than wget to be able to download and see the source page curl will need us to remain silent we attack s there and then grep of course will want to remove the color with tactec color equals none my face in the way no i'm good i'm in the clear that's it we can save that there's our get flag script there is our flag.text and we can finish that challenge wow a lot of good learning coming from that one uh i hope you guys had fun one of the other things like man should i even upload this but hey we had some fun i hope you enjoyed and i'll let you get back to it everybody i love you i'll see you in the next video
Original Description
Help the channel grow with a Like, Comment, & Subscribe!
❤️ Support ➡ https://jh.live/patreon ↔ https://jh.live/paypal ↔ https://jh.live/buymeacoffee
Check out the affiliates below for more free or discounted learning!
🖥️ Zero-Point Security ➡ Certified Red Team Operator https://jh.live/crto
💻Zero-Point Security ➡ C2 Development with C# https://jh.live/c2dev
👨🏻💻7aSecurity ➡ Hacking Courses & Pentesting https://jh.live/7asecurity
📗Humble Bundle ➡ https://jh.live/humblebundle
🐶Snyk ➡ https://jh.live/snyk
🌎Follow me! ➡ https://jh.live/discord ↔ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/instagram ↔ https://jh.live/tiktok
📧Contact me! (I may be very slow to respond or completely unable to)
🤝Sponsorship Inquiries ➡ https://jh.live/sponsorship
🚩 CTF Hosting Requests ➡ https://jh.live/ctf
🎤 Speaking Requests ➡ https://jh.live/speaking
💥 Malware Submission ➡ https://jh.live/malware
❓ Everything Else ➡ https://jh.live/etc
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
Related Reads
📰
📰
📰
📰
How to Group and Batch Vulnerability Fixes to Save Engineering Time
Dev.to · InstaSLA
10 Skills Every Cyber Security Professional Needs in 2026
Medium · Cybersecurity
Ugroza: Turning OSINT into Actionable Threat Intelligence
Medium · AI
Ugroza: Turning OSINT into Actionable Threat Intelligence
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI