Structured Attack Security Application via Capture the Flag: Sequential Attack Execution and Capture of the Three Flags

dc.contributor.authorBayazıt, Esra Çalık
dc.contributor.authorAraç, Merve
dc.contributor.authorGücükoğlu, Behlül
dc.contributor.authorEr, Veysel
dc.contributor.authorÖfkeli, Erva
dc.date.accessioned2026-08-27T12:36:17Z
dc.date.issued2026
dc.departmentFSM Vakıf Üniversitesi, Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümü
dc.departmentFSM Vakıf Üniversitesi, Meslek Yüksekokulu, Bilişim Güvenliği Teknolojisi Bölümü
dc.description.abstractCapture the Flag (CTF), one of the types of penetration testing, is started to be frequently applied in evaluation processes as a method that has recently become increasingly popular in the field of cybersecurity. Within a predefined scenario, it is an evaluation process that simulates a threat actor's attack by capturing a flag representing a computer system or network security. In this study, a framework is presented that provides practical experience of attack techniques having fundamental importance in the field of cybersecurity including privilege escalation, SQL injection, command injection, directory traversal, brute force, and steganography by presenting the steps of a banking system simulation. Additionally, it is aimed to practice privilege escalation, accessing the hidden files and password‑cracking processes using tools such as Hydra/John the Ripper by applying privilege escalation techniques. In this regard, the study aims to offer a guiding model for transforming theoretical knowledge into practical applications within the cybersecurity sector. The process of capturing the three flags targeted within the scenario systematically reveals the operational requirements of vulnerability exploitation. Furthermore, participants’ progress levels are monitored via a tracking script used throughout the CTF application process. In this aspect, the study provides an effective, applicable, and traceable simulation model for training and raising awareness in the field of cybersecurity.
dc.description.abstractPenetrasyon test türlerinden biri olan Bayrak Yakalama (Capture the Flag- CTF), son dönemlerde siber güvenlik alanında her geçen gün daha popüler hale gelen bir yöntem olarak değerlendirme süreçlerinde sıklıkla uygulanmaya başlanmıştır. Kurulan bir senaryo gereği bir tehdit aktörünün saldırısının bir bilgisayar sistemi veya ağının güvenliğini temsilen bayrağı ele geçirme yoluyla simüle edilen bir değerlendirme sürecidir. Bu çalışmada, bir banka sistemi simülasyonun basamakları sunularak siber güvenlik alanında temel öneme sahip olan privilege escalation, SQL injection, command injection, directory traversal, brute force ve steganography saldırı tekniklerinin uygulamalı olarak deneyimlenmesini sağlayacak bir çerçeve sunulmuştur. Ayrıca privilege escalation teknikleri uygulayarak yetki yükseltmeleri, gizli dosyalara ulaşmaları ve Hydra/John the Ripper gibi araçlarla parola kırma süreçlerinin deneyimlenmesi hedeflenmiştir. Bu doğrultuda çalışma, siber güvenlik sektöründe teorik bilginin pratik uygulamaya dönüştürülmesine yönelik yol gösterici bir model sunmayı amaçlamakta; senaryo kapsamında ele geçirilmesi hedeflenen üç bayrağa erişim süreci ise zafiyet istismarının operasyonel gerekliliklerini sistematik bir biçimde ortaya koymaktadır. Ayrıca, katılımcıların ilerleme düzeyleri CTF uygulaması süreci boyunca kullanılan takip scripti aracılığıyla takip edilmektedir. Bu yönüyle çalışma, siber güvenlik alanında eğitim ve farkındalık oluşturmak için etkili, uygulanabilir ve izlenebilir bir simülasyon modeli ortaya koymaktadır.
dc.identifier.citationBAYAZIT, Esra Çalık, Merve ARAÇ, Behlül GÜCÜKOĞLU, Veysel ER & Erva ÖFKELİ. "Structured Attack Security Application via Capture the Flag: Sequential Attack Execution and Capture of the Three Flags". Osmaniye Korkut Ata Üniversitesi Fen Bilimleri Enstitüsü Dergisi, 9.2 (2026): 994-1011.
dc.identifier.doi10.47495/okufbed.1840420
dc.identifier.endpage1011
dc.identifier.issue2
dc.identifier.orcidhttps://orcid.org/0000-0002-6813-1037
dc.identifier.orcidhttps://orcid.org/0000-0001-8892-3974
dc.identifier.orcidhttps://orcid.org/0009-0000-1372-6116
dc.identifier.orcidhttps://orcid.org/0009-0002-9753-5847
dc.identifier.orcidhttps://orcid.org/0009-0007-2250-4276
dc.identifier.startpage994
dc.identifier.trdizinid1395144
dc.identifier.urihttps://search.trdizin.gov.tr/tr/yayin/detay/1395144/bayrak-ele-gecirme-yoluyla-yapilandirilmis-saldiri-guvenligi-uygulamasi-ardisik-sirali-saldiri-yurutme-ve-uc-bayragin-ele-gecirilmesi
dc.identifier.urihttps://hdl.handle.net/11352/6254
dc.identifier.volume9
dc.indekslendigikaynakTR-Dizin
dc.language.isoen
dc.publisherOsmaniye Korkut Ata Üniversitesi
dc.relation.ispartofOsmaniye Korkut Ata Üniversitesi Fen Bilimleri Enstitüsü Dergisi
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.subjectCapture the Flag (CTF)
dc.subjectCyber Security
dc.subjectInformation Security
dc.subjectAttack
dc.subjectVulnerability
dc.subjectBayrak Yakalama
dc.subjectSiber Güvenlik
dc.subjectBilgi Güvenliği
dc.subjectSaldırı
dc.subjectZafiyet
dc.titleStructured Attack Security Application via Capture the Flag: Sequential Attack Execution and Capture of the Three Flags
dc.title.alternativeBayrak Ele Geçirme Yoluyla Yapılandırılmış Saldırı Güvenliği Uygulaması: Ardışık Sıralı Saldırı Yürütme ve Üç Bayrağın Ele Geçirilmesi
dc.typeArticle

Dosyalar

Orijinal paket

Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
Bayazıt.pdf
Boyut:
830.12 KB
Biçim:
Adobe Portable Document Format

Lisans paketi

Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
license.txt
Boyut:
1.17 KB
Biçim:
Item-specific license agreed upon to submission
Açıklama: