October 2, 2026
PicoCTF Writeup: picobrowser
Welcome back, hackers! Today we’re solving “picobrowser”, a Web Exploitation challenge from picoCTF where the goal is to convince the…

By SoBatista
2 min read
Welcome back, hackers! Today we're solving "picobrowser", a Web Exploitation challenge from picoCTF where the goal is to convince the website that we are using a very specific browser.
This one is pretty simple once we understand the clue the website gives us.
And it is a good example of why we should never blindly trust information that comes from the client.
Challenge Overview
- Event: picoCTF 2019
- Challenge Name: picobrowser
- Category: Web Exploitation
- Difficulty: Medium
Challenge Description
This website can be rendered only by picobrowser, go and catch the flag!
Hint 1: You don't need to download a new web browser
Step 1: Opening the Website
First I launched the instance and that gave me a URL.
I clicked on it and I was presented with a very simple website.
The website had a big green button that said: Flag
Of course that was the first thing I clicked on. However, instead of getting the flag I got this:
This gave a very pretty good clue. It showed this:
Mozilla/5.0 (X11; Linux x86_64; rv:156.0) Gecko/20100101 Firefox/156.0Mozilla/5.0 (X11; Linux x86_64; rv:156.0) Gecko/20100101 Firefox/156.0And this is the User-Agent being sent by the browser.
The User-Agent is basically a string that tells the web server what kind of client is making the request. In my case the request was coming from Firefox running on Linux.
Now, I saw that it also said:
You're not picobrowser!
So I thought that this was the answer.
Step 2: Intercepting the Request
At this point, I clicked the Flag button again.
But this time, I intercepted the request with Burp Suite.
Inside the request, we can see the User-Agent header:
This matches exactly what the website showed us in the error message.
Step 3: Changing the User-Agent
The next logic step was change the User-Agent to:
User-Agent: picobrowserUser-Agent: picobrowserThen I sent the modified request.
And this time, instead of receiving the error message, the response contained the flag.
Final Thoughts
This was a small challenge, but I liked how direct the clue was.
The application literally showed us the User-Agent it was seeing, which immediately pointed us toward the part of the request we needed to inspect.
Once we intercepted the request with Burp Suite, the solution became very straightforward:
- Find the User-Agent
- Change it to picobrowser
- Send the request
- Get the flag.
Simple challenge, but a nice introduction to HTTP headers and request manipulation.
Happy hacking, and I'll see you in the next write-up!
**Cheers, **SoBatista