A pwn writeup for blooockchain, covering raw SHA-256 digests, strncat, an OOB leak, and saved RIP overwrite.
Topic: #CTF
A collection of 36 posts about CTF.
AIS3 Pre-Exam 2026 完整解題地圖:整理 Pwn、Web、Reverse、Crypto 與 Misc 題目,並依系列順序連結每篇詳細 Writeup。
A crypto writeup for EasyFAULT, recovering the hidden RSA structure with lattice-style analysis.
A crypto writeup for EasyJWT, focusing on JWT signing, verification, and token forgery.
A crypto writeup for EasyPAINT, extracting the Nuitka app logic and recovering the cryptographic path.
A crypto writeup for EasyWEB, analyzing the encrypted cookie/session behavior.
A crypto writeup for EasyZKP, covering the proof protocol and final forgery.
A misc writeup for ƐSI∀ Sǝɔɹǝʇ Ⅎlɐƃ Sɥod, following the hidden host and service clues.
A misc writeup for Hacked by Lazarus Group, using proxy/header behavior to reach the flag.
A misc writeup for Jail, focusing on the Python jail request shape and execution trick.
A misc writeup for Jail-Revenge, abusing the Flask body handling and Python execution path.
A misc writeup for Kernel0Day, from QEMU environment triage to the final privilege path.
A misc writeup for Welcome, solving the QR-code based warmup challenge.
A misc writeup for アッシェンテ!, analyzing the Minecraft mod and RNG path.
A misc writeup for 想在雪中來杯下午茶嗎?, using OSINT to identify the location.
A pwn writeup for DG-Server, from HTTP parser triage to the final exploit path.
A pwn writeup for ooonvifd, focusing on the ONVIF parser bug and exploitation flow.
A pwn writeup for std-print, using the binary symbols, ROP, and flag memory leak path.
A pwn writeup for 特別的愛給特別的你, covering the QEMU/raw-disk execution model and exploit path.
A pwn writeup for 獨屬於你的魔法, using one arbitrary write and glibc internals to reach shell.
A reverse writeup for DG-Server, covering the custom verifier and DNSSEC-like chain.
A reverse writeup for the Lua bytecode challenge and its custom opcode mapping.
A reverse writeup for tetris, analyzing the static ELF and hidden flag path.
A reverse writeup for the Unity challenges 哇!金色傳說 and Hidden-in-the-Cloak.
A web writeup for Give-Me-Flag, reversing the .NET service behavior and callback path.
A web writeup for Linkedout, from file read to the final application exploit chain.
A web writeup for Mass-Rapid-Transit, covering admin access, payload testing, and the final route.
A web writeup for MyGO!!!!! x Ave Mujica 圖庫, chaining SQL injection and file read.
A web writeup for PDF-Converter, focusing on PHP, PDF generation, and file-read behavior.
A web writeup for Tea-God-Adventure, using prompt injection and internal blackbox probing.
payload: getattr(import('o'+'s'), 'po'+'pen')('tac${IFS}'+chr(47)+'fl').read()