Structured Attack Security Application via Capture the Flag: Sequential Attack Execution and Capture of the Three Flags
| dc.contributor.author | Bayazıt, Esra Çalık | |
| dc.contributor.author | Araç, Merve | |
| dc.contributor.author | Gücükoğlu, Behlül | |
| dc.contributor.author | Er, Veysel | |
| dc.contributor.author | Öfkeli, Erva | |
| dc.date.accessioned | 2026-08-27T12:36:17Z | |
| dc.date.issued | 2026 | |
| dc.department | FSM Vakıf Üniversitesi, Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümü | |
| dc.department | FSM Vakıf Üniversitesi, Meslek Yüksekokulu, Bilişim Güvenliği Teknolojisi Bölümü | |
| dc.description.abstract | Capture the Flag (CTF), one of the types of penetration testing, is started to be frequently applied in evaluation processes as a method that has recently become increasingly popular in the field of cybersecurity. Within a predefined scenario, it is an evaluation process that simulates a threat actor's attack by capturing a flag representing a computer system or network security. In this study, a framework is presented that provides practical experience of attack techniques having fundamental importance in the field of cybersecurity including privilege escalation, SQL injection, command injection, directory traversal, brute force, and steganography by presenting the steps of a banking system simulation. Additionally, it is aimed to practice privilege escalation, accessing the hidden files and password‑cracking processes using tools such as Hydra/John the Ripper by applying privilege escalation techniques. In this regard, the study aims to offer a guiding model for transforming theoretical knowledge into practical applications within the cybersecurity sector. The process of capturing the three flags targeted within the scenario systematically reveals the operational requirements of vulnerability exploitation. Furthermore, participants’ progress levels are monitored via a tracking script used throughout the CTF application process. In this aspect, the study provides an effective, applicable, and traceable simulation model for training and raising awareness in the field of cybersecurity. | |
| dc.description.abstract | Penetrasyon test türlerinden biri olan Bayrak Yakalama (Capture the Flag- CTF), son dönemlerde siber güvenlik alanında her geçen gün daha popüler hale gelen bir yöntem olarak değerlendirme süreçlerinde sıklıkla uygulanmaya başlanmıştır. Kurulan bir senaryo gereği bir tehdit aktörünün saldırısının bir bilgisayar sistemi veya ağının güvenliğini temsilen bayrağı ele geçirme yoluyla simüle edilen bir değerlendirme sürecidir. Bu çalışmada, bir banka sistemi simülasyonun basamakları sunularak siber güvenlik alanında temel öneme sahip olan privilege escalation, SQL injection, command injection, directory traversal, brute force ve steganography saldırı tekniklerinin uygulamalı olarak deneyimlenmesini sağlayacak bir çerçeve sunulmuştur. Ayrıca privilege escalation teknikleri uygulayarak yetki yükseltmeleri, gizli dosyalara ulaşmaları ve Hydra/John the Ripper gibi araçlarla parola kırma süreçlerinin deneyimlenmesi hedeflenmiştir. Bu doğrultuda çalışma, siber güvenlik sektöründe teorik bilginin pratik uygulamaya dönüştürülmesine yönelik yol gösterici bir model sunmayı amaçlamakta; senaryo kapsamında ele geçirilmesi hedeflenen üç bayrağa erişim süreci ise zafiyet istismarının operasyonel gerekliliklerini sistematik bir biçimde ortaya koymaktadır. Ayrıca, katılımcıların ilerleme düzeyleri CTF uygulaması süreci boyunca kullanılan takip scripti aracılığıyla takip edilmektedir. Bu yönüyle çalışma, siber güvenlik alanında eğitim ve farkındalık oluşturmak için etkili, uygulanabilir ve izlenebilir bir simülasyon modeli ortaya koymaktadır. | |
| dc.identifier.citation | BAYAZIT, Esra Çalık, Merve ARAÇ, Behlül GÜCÜKOĞLU, Veysel ER & Erva ÖFKELİ. "Structured Attack Security Application via Capture the Flag: Sequential Attack Execution and Capture of the Three Flags". Osmaniye Korkut Ata Üniversitesi Fen Bilimleri Enstitüsü Dergisi, 9.2 (2026): 994-1011. | |
| dc.identifier.doi | 10.47495/okufbed.1840420 | |
| dc.identifier.endpage | 1011 | |
| dc.identifier.issue | 2 | |
| dc.identifier.orcid | https://orcid.org/0000-0002-6813-1037 | |
| dc.identifier.orcid | https://orcid.org/0000-0001-8892-3974 | |
| dc.identifier.orcid | https://orcid.org/0009-0000-1372-6116 | |
| dc.identifier.orcid | https://orcid.org/0009-0002-9753-5847 | |
| dc.identifier.orcid | https://orcid.org/0009-0007-2250-4276 | |
| dc.identifier.startpage | 994 | |
| dc.identifier.trdizinid | 1395144 | |
| dc.identifier.uri | https://search.trdizin.gov.tr/tr/yayin/detay/1395144/bayrak-ele-gecirme-yoluyla-yapilandirilmis-saldiri-guvenligi-uygulamasi-ardisik-sirali-saldiri-yurutme-ve-uc-bayragin-ele-gecirilmesi | |
| dc.identifier.uri | https://hdl.handle.net/11352/6254 | |
| dc.identifier.volume | 9 | |
| dc.indekslendigikaynak | TR-Dizin | |
| dc.language.iso | en | |
| dc.publisher | Osmaniye Korkut Ata Üniversitesi | |
| dc.relation.ispartof | Osmaniye Korkut Ata Üniversitesi Fen Bilimleri Enstitüsü Dergisi | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.subject | Capture the Flag (CTF) | |
| dc.subject | Cyber Security | |
| dc.subject | Information Security | |
| dc.subject | Attack | |
| dc.subject | Vulnerability | |
| dc.subject | Bayrak Yakalama | |
| dc.subject | Siber Güvenlik | |
| dc.subject | Bilgi Güvenliği | |
| dc.subject | Saldırı | |
| dc.subject | Zafiyet | |
| dc.title | Structured Attack Security Application via Capture the Flag: Sequential Attack Execution and Capture of the Three Flags | |
| dc.title.alternative | Bayrak Ele Geçirme Yoluyla Yapılandırılmış Saldırı Güvenliği Uygulaması: Ardışık Sıralı Saldırı Yürütme ve Üç Bayrağın Ele Geçirilmesi | |
| dc.type | Article |










