Web Exploitation
Auth bypasses, SSRF, injection, request smuggling — the modern app attack surface.
// PES University — Electronic City Campus
The OSI model stops at seven. The most exploitable layer is the one operating the keyboard — and that is the one we train.
Layer8 is the cybersecurity club at PES University, ECC. We run weekly CTFs, break and build across web, crypto, reversing and pwn, and turn curiosity into capability.
Every member picks a lane and goes deep, then cross-trains on the rest during weekly sessions.
Auth bypasses, SSRF, injection, request smuggling — the modern app attack surface.
Stack and heap corruption, ROP, format strings, exploit dev against real binaries.
Static and dynamic analysis, unpacking, patching, and reading assembly for sport.
Padding oracles, weak PRNGs, RSA math, and the classic 'never roll your own'.
Disk and memory images, packet captures, log timelines, artifact recovery.
Data hidden in pixels, audio and metadata — spot it, extract it, carve it out.
People, infrastructure and leaks — what the open internet already knows about a target.
Protocol abuse, pivoting, traffic analysis and defending the wire.
Beginner-friendly challenges, a live scoreboard, and writeups afterwards. Show up with a laptop and a browser — we handle the rest.