Slide 3 and slide 8: permission, scope, and the fence you put up first.
Written authorization This target exists to be attacked, and whoever operates this host has authorized you to test it for the duration of the session. That, and nothing else, is what makes this legal. The same application on anyone else's machine would not be yours to touch.
The fence
Target
Decision
https://www.ctfanz.in/
IN SCOPE - the whole Village Keep app
/api/*
IN SCOPE
/neighbour-village
OUT OF SCOPE - different owner, do not test
The host OS, your own laptop
OUT OF SCOPE
Any real internet host
OUT OF SCOPE
Code of honour (slide 18)
No written permission, no raid.
Stay inside scope, every single time.
Do no harm: no data deletion, no denial of service.
Found something critical? Stop and tell the client now.
Guard client data like your own treasure.
Burp setup, mirroring slides 7 and 8. Proxy > Open browser. Click around once. Target > Site map, right-click https://www.ctfanz.in > Add to scope > Yes. Then Proxy > HTTP history > filter bar > Show only in-scope items.