CTF - Penetration testing basic

Job ID: 33038850

Budget: $30 – $250 USD

I have received first round of interview for the post of Graduate Penetration Tester and they have invited me to really basic CTF challenge to participate and solve it. There will be 2 basic web app ctf and 1 Infrastructure ctf. Also there will be basic 13 question regarding which is mentioned at the end of this description. please read the following description really carefully.
Here is sample email I have got:

For the challenge, you will have 2 hours in which to solve as many of the CTF challenges as you can (there are 3 in total; 2 Web App and 1 Infrastructure). At the end of the 2-hour timeslot window, you will need to complete the questionnaire contained within this email below (please note, you will need to submit any flags found via the questionnaire so please either screenshot or note down any flags you find). The flags look like this (this is just an example):

Flag(If_U_f1nD_D0M_l0Ok_4_SqL)


Please note, all challenges will reset 60 minutes into your 2 hour timeslot - this is by design and will enable you to try other methods of securing the flag should an initial attempt have been unsuccessful. Additionally, these challenges are intended to be solved through manual penetration methods (the use of automated tools will be detected, and there are protections in place within the Web Apps; please note, however, you can run a scan for the Inf as the port is not provided). For the Web Apps, you can use Burpsuite Intercept, Repeater and so forth (just not fully automated tools).

----------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Questions

Web App 1: What was the ‘main’ vulnerability on the target application?
Web App 1: What payload did you use to exploit the vulnerability? This can be any payload used to find or exploit the issue – it doesn’t have to be the one used to obtain the flag.
Web App 1: In 2 or 3 bullet points, how should a customer remediate this issue?
Web App 1: What was the flag?

Web App 2: What was the ‘main’ vulnerability on the target application?
Web App 2: What payload did you use to exploit the vulnerability? This can be any payload used to find or exploit the issue – it doesn’t have to be the one used to obtain the flag.
Web App 2: In 2 or 3 bullet points, how should a customer remediate this issue?
Web App 2: What was the flag?

Inf 1: What was the entry point? (port number/service)
Inf 1: Whose account did you compromise?
Inf 1: What was that person’s password?
Inf 1: How did you escalate privileges? Which command(s) were used?
Inf 1: What was the flag?

Thanks
Related categories: Linux Penetration Testing