Web exploitation challenges from the COlicyber practice track.
A Too Small Reminder — Session ID Enumeration
Register, log in, notice the session_id cookie is a small integer. Brute-force integers upward from 30 until the admin session is hit and the flag appears.