<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Suzu</title><description>OpenBMC security, vulnerability research, binary exploitation, and CTF writeups.</description><link>https://www.suzu.tw/</link><language>zh-TW</language><item><title>《納瓦爾寶典》開始閱讀</title><link>https://www.suzu.tw/books/naval-almanack/</link><guid isPermaLink="true">https://www.suzu.tw/books/naval-almanack/</guid><description>從白手起家到財務自由，矽谷傳奇創投家納瓦爾的投資哲學與人生智慧。</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>思維</category><category>財務</category></item><item><title>【Pwn】AIS3 Pre-Exam 2026 Writeup: blooockchain</title><link>https://www.suzu.tw/posts/2026-05-26-ais3-pre-exam-2026-blooockchain/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-ais3-pre-exam-2026-blooockchain/</guid><description>A pwn writeup for blooockchain, covering raw SHA-256 digests, strncat, an OOB leak, and saved RIP overwrite.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Pwn</category></item><item><title>AIS3 Pre-Exam 2026 Writeups: 前言</title><link>https://www.suzu.tw/posts/2026-05-26-ais3-pre-exam-2026-writeup%E5%89%8D%E8%A8%80/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-ais3-pre-exam-2026-writeup%E5%89%8D%E8%A8%80/</guid><description>AIS3 Pre-Exam 2026 完整解題地圖：整理 Pwn、Web、Reverse、Crypto 與 Misc 題目，並依系列順序連結每篇詳細 Writeup。</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category></item><item><title>【Crypto】AIS3 Pre-Exam 2026 Writeup: EasyFAULT</title><link>https://www.suzu.tw/posts/2026-05-26-cryptoeasyfault/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-cryptoeasyfault/</guid><description>A crypto writeup for EasyFAULT, recovering the hidden RSA structure with lattice-style analysis.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Crypto</category><category>RSA</category><category>Lattice</category></item><item><title>【Crypto】AIS3 Pre-Exam 2026 Writeup: EasyJWT</title><link>https://www.suzu.tw/posts/2026-05-26-cryptoeasyjwt/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-cryptoeasyjwt/</guid><description>A crypto writeup for EasyJWT, focusing on JWT signing, verification, and token forgery.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Crypto</category><category>JWT</category></item><item><title>【Crypto】AIS3 Pre-Exam 2026 Writeup: EasyPAINT</title><link>https://www.suzu.tw/posts/2026-05-26-cryptoeasypaint/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-cryptoeasypaint/</guid><description>A crypto writeup for EasyPAINT, extracting the Nuitka app logic and recovering the cryptographic path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Crypto</category><category>Nuitka</category></item><item><title>【Crypto】AIS3 Pre-Exam 2026 Writeup: EasyWEB</title><link>https://www.suzu.tw/posts/2026-05-26-cryptoeasyweb/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-cryptoeasyweb/</guid><description>A crypto writeup for EasyWEB, analyzing the encrypted cookie/session behavior.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Crypto</category><category>Web</category></item><item><title>【Crypto】AIS3 Pre-Exam 2026 Writeup: EasyZKP</title><link>https://www.suzu.tw/posts/2026-05-26-cryptoeasyzkp/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-cryptoeasyzkp/</guid><description>A crypto writeup for EasyZKP, covering the proof protocol and final forgery.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Crypto</category><category>ZKP</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: ƐSI∀ Sǝɔɹǝʇ Ⅎlɐƃ Sɥod</title><link>https://www.suzu.tw/posts/2026-05-26-misc%C9%9Bsi-s%C7%9D%C9%94%C9%B9%C7%9D%CA%87-%E2%85%8El%C9%90%C6%83-s%C9%A5od/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-misc%C9%9Bsi-s%C7%9D%C9%94%C9%B9%C7%9D%CA%87-%E2%85%8El%C9%90%C6%83-s%C9%A5od/</guid><description>A misc writeup for ƐSI∀ Sǝɔɹǝʇ Ⅎlɐƃ Sɥod, following the hidden host and service clues.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>Web</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: Hacked by Lazarus Group</title><link>https://www.suzu.tw/posts/2026-05-26-mischacked-by-lazarus-group/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-mischacked-by-lazarus-group/</guid><description>A misc writeup for Hacked by Lazarus Group, using proxy/header behavior to reach the flag.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>HTTP Headers</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: Jail</title><link>https://www.suzu.tw/posts/2026-05-26-miscjail/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-miscjail/</guid><description>A misc writeup for Jail, focusing on the Python jail request shape and execution trick.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>Pyjail</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: Jail-Revenge</title><link>https://www.suzu.tw/posts/2026-05-26-miscjail-revenge/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-miscjail-revenge/</guid><description>A misc writeup for Jail-Revenge, abusing the Flask body handling and Python execution path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>Pyjail</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: Kernel0Day</title><link>https://www.suzu.tw/posts/2026-05-26-misckernel0day/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-misckernel0day/</guid><description>A misc writeup for Kernel0Day, from QEMU environment triage to the final privilege path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>Kernel</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: Welcome</title><link>https://www.suzu.tw/posts/2026-05-26-miscwelcome/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-miscwelcome/</guid><description>A misc writeup for Welcome, solving the QR-code based warmup challenge.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>QR Code</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: アッシェンテ！</title><link>https://www.suzu.tw/posts/2026-05-26-misc%E3%82%A2%E3%83%83%E3%82%B7%E3%82%A7%E3%83%B3%E3%83%86-/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-misc%E3%82%A2%E3%83%83%E3%82%B7%E3%82%A7%E3%83%B3%E3%83%86-/</guid><description>A misc writeup for アッシェンテ！, analyzing the Minecraft mod and RNG path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>Minecraft</category></item><item><title>【Misc】AIS3 Pre-Exam 2026 Writeup: 想在雪中來杯下午茶嗎?</title><link>https://www.suzu.tw/posts/2026-05-26-misc%E6%83%B3%E5%9C%A8%E9%9B%AA%E4%B8%AD%E4%BE%86%E6%9D%AF%E4%B8%8B%E5%8D%88%E8%8C%B6%E5%97%8E/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-misc%E6%83%B3%E5%9C%A8%E9%9B%AA%E4%B8%AD%E4%BE%86%E6%9D%AF%E4%B8%8B%E5%8D%88%E8%8C%B6%E5%97%8E/</guid><description>A misc writeup for 想在雪中來杯下午茶嗎?, using OSINT to identify the location.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Misc</category><category>OSINT</category></item><item><title>【Pwn】AIS3 Pre-Exam 2026 Writeup: DG-Server</title><link>https://www.suzu.tw/posts/2026-05-26-pwndg-server/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-pwndg-server/</guid><description>A pwn writeup for DG-Server, from HTTP parser triage to the final exploit path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Pwn</category><category>DNS</category></item><item><title>【Pwn】AIS3 Pre-Exam 2026 Writeup: ooonvifd</title><link>https://www.suzu.tw/posts/2026-05-26-pwnooonvifd/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-pwnooonvifd/</guid><description>A pwn writeup for ooonvifd, focusing on the ONVIF parser bug and exploitation flow.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Pwn</category><category>ONVIF</category><category>Heap</category></item><item><title>【Pwn】AIS3 Pre-Exam 2026 Writeup: std-print</title><link>https://www.suzu.tw/posts/2026-05-26-pwnstd-print/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-pwnstd-print/</guid><description>A pwn writeup for std-print, using the binary symbols, ROP, and flag memory leak path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Pwn</category><category>ROP</category></item><item><title>【Pwn】AIS3 Pre-Exam 2026 Writeup: 特別的愛給特別的你</title><link>https://www.suzu.tw/posts/2026-05-26-pwn%E7%89%B9%E5%88%A5%E7%9A%84%E6%84%9B%E7%B5%A6%E7%89%B9%E5%88%A5%E7%9A%84%E4%BD%A0/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-pwn%E7%89%B9%E5%88%A5%E7%9A%84%E6%84%9B%E7%B5%A6%E7%89%B9%E5%88%A5%E7%9A%84%E4%BD%A0/</guid><description>A pwn writeup for 特別的愛給特別的你, covering the QEMU/raw-disk execution model and exploit path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Pwn</category><category>Kernel</category><category>QEMU</category></item><item><title>【Pwn】AIS3 Pre-Exam 2026 Writeup: 獨屬於你的魔法</title><link>https://www.suzu.tw/posts/2026-05-26-pwn%E7%8D%A8%E5%B1%AC%E6%96%BC%E4%BD%A0%E7%9A%84%E9%AD%94%E6%B3%95/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-pwn%E7%8D%A8%E5%B1%AC%E6%96%BC%E4%BD%A0%E7%9A%84%E9%AD%94%E6%B3%95/</guid><description>A pwn writeup for 獨屬於你的魔法, using one arbitrary write and glibc internals to reach shell.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Pwn</category><category>glibc</category></item><item><title>【Reverse】AIS3 Pre-Exam 2026 Writeup: DG-Server</title><link>https://www.suzu.tw/posts/2026-05-26-reversedg-server/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-reversedg-server/</guid><description>A reverse writeup for DG-Server, covering the custom verifier and DNSSEC-like chain.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Reverse</category><category>DNS</category></item><item><title>【Reverse】AIS3 Pre-Exam 2026 Writeup: lua</title><link>https://www.suzu.tw/posts/2026-05-26-reverselua/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-reverselua/</guid><description>A reverse writeup for the Lua bytecode challenge and its custom opcode mapping.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Reverse</category><category>Lua</category></item><item><title>【Reverse】AIS3 Pre-Exam 2026 Writeup: tetris</title><link>https://www.suzu.tw/posts/2026-05-26-reversetetris/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-reversetetris/</guid><description>A reverse writeup for tetris, analyzing the static ELF and hidden flag path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Reverse</category><category>ELF</category></item><item><title>【Reverse】AIS3 Pre-Exam 2026 Writeup: 哇!金色傳說 &amp; Hidden-in-the-Cloak</title><link>https://www.suzu.tw/posts/2026-05-26-reverse%E5%93%87%E9%87%91%E8%89%B2%E5%82%B3%E8%AA%AAhidden-in-the-cloak/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-reverse%E5%93%87%E9%87%91%E8%89%B2%E5%82%B3%E8%AA%AAhidden-in-the-cloak/</guid><description>A reverse writeup for the Unity challenges 哇!金色傳說 and Hidden-in-the-Cloak.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Reverse</category><category>Unity</category></item><item><title>【Web】AIS3 Pre-Exam 2026 Writeup: Give-Me-Flag</title><link>https://www.suzu.tw/posts/2026-05-26-webgive-me-flag/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-webgive-me-flag/</guid><description>A web writeup for Give-Me-Flag, reversing the .NET service behavior and callback path.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Web</category><category>.NET</category></item><item><title>【Web】AIS3 Pre-Exam 2026 Writeup: Linkedout</title><link>https://www.suzu.tw/posts/2026-05-26-weblinkedout/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-weblinkedout/</guid><description>A web writeup for Linkedout, from file read to the final application exploit chain.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Web</category><category>Flask</category></item><item><title>【Web】AIS3 Pre-Exam 2026 Writeup: Mass-Rapid-Transit</title><link>https://www.suzu.tw/posts/2026-05-26-webmass-rapid-transit/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-webmass-rapid-transit/</guid><description>A web writeup for Mass-Rapid-Transit, covering admin access, payload testing, and the final route.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Web</category><category>XSS</category></item><item><title>【Web】AIS3 Pre-Exam 2026 Writeup: MyGO!!!!! x Ave Mujica 圖庫</title><link>https://www.suzu.tw/posts/2026-05-26-webmygox-ave-mujica%E5%9C%96%E5%BA%AB/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-webmygox-ave-mujica%E5%9C%96%E5%BA%AB/</guid><description>A web writeup for MyGO!!!!! x Ave Mujica 圖庫, chaining SQL injection and file read.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Web</category><category>SQLi</category><category>LFI</category></item><item><title>【Web】AIS3 Pre-Exam 2026 Writeup: PDF-Converter</title><link>https://www.suzu.tw/posts/2026-05-26-webpdf-converter/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-webpdf-converter/</guid><description>A web writeup for PDF-Converter, focusing on PHP, PDF generation, and file-read behavior.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Web</category><category>PHP</category><category>SSRF</category></item><item><title>【Web】AIS3 Pre-Exam 2026 Writeup: Tea-God-Adventure</title><link>https://www.suzu.tw/posts/2026-05-26-webtea-god-adventure/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-26-webtea-god-adventure/</guid><description>A web writeup for Tea-God-Adventure, using prompt injection and internal blackbox probing.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>AIS3</category><category>CTF</category><category>Writeup</category><category>Web</category><category>Prompt Injection</category></item><item><title>OpenBMC Security Part 2: bmcweb Multipart Parser CVEs</title><link>https://www.suzu.tw/posts/2026-05-15-openbmc-bmcweb-multipart-parser-cves/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-15-openbmc-bmcweb-multipart-parser-cves/</guid><description>A practical, slide-backed analysis of CVE-2022-2809 and CVE-2022-3409 in the bmcweb multipart parser.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>OpenBMC</category><category>bmcweb</category><category>CVE</category><category>Parser</category><category>Security</category></item><item><title>OpenBMC Security Part 1: Architecture, Attack Surface, and Lab Setup</title><link>https://www.suzu.tw/posts/2026-05-15-openbmc-security-architecture-and-lab/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-15-openbmc-security-architecture-and-lab/</guid><description>A practical and slide-backed walkthrough of OpenBMC architecture, attack surface, D-Bus, and a QEMU lab setup.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>OpenBMC</category><category>BMC</category><category>Security</category><category>Firmware</category><category>Redfish</category></item><item><title>OpenBMC Security Part 3: slpd-lite and CVE-2024-41660</title><link>https://www.suzu.tw/posts/2026-05-15-openbmc-slpd-lite-cve-2024-41660/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-05-15-openbmc-slpd-lite-cve-2024-41660/</guid><description>A practical, slide-backed analysis of CVE-2024-41660 in OpenBMC slpd-lite, focusing on SLP length fields and memory corruption.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>OpenBMC</category><category>slpd-lite</category><category>CVE</category><category>Memory Corruption</category><category>Security</category></item><item><title>CVE-2024-2961 漏洞分析</title><link>https://www.suzu.tw/posts/2026-01-18-cve-2024-2961-%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2026-01-18-cve-2024-2961-%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/</guid><description>CVE-2024-2961 主要是 glibc 的 iconv 函式，在進行字元轉換時，因為呼叫 Escape Sequence 到輸出時沒有檢查邊界問題，因此可以造成 OOB Write，後續也利用這個 Off by one 來打達成 PHP 的 LFI to RCE 漏洞。</description><pubDate>Sun, 18 Jan 2026 00:00:00 GMT</pubDate><category>CVE</category><category>iconv</category><category>Heap</category><category>Learning</category><category>Research</category></item><item><title>【30天學習新語言-Ruby】Day 7：寫一個簡易字典攻擊器測試弱密碼</title><link>https://www.suzu.tw/posts/2025-08-16-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-7%E5%AF%AB%E4%B8%80%E5%80%8B%E7%B0%A1%E6%98%93%E5%AD%97%E5%85%B8%E6%94%BB%E6%93%8A%E5%99%A8%E6%B8%AC%E8%A9%A6%E5%BC%B1%E5%AF%86%E7%A2%BC/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-16-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-7%E5%AF%AB%E4%B8%80%E5%80%8B%E7%B0%A1%E6%98%93%E5%AD%97%E5%85%B8%E6%94%BB%E6%93%8A%E5%99%A8%E6%B8%AC%E8%A9%A6%E5%BC%B1%E5%AF%86%E7%A2%BC/</guid><description>其實，</description><pubDate>Sat, 16 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>【30天學習新語言-Ruby】Day 6：爬蟲自動搜尋敏感資訊</title><link>https://www.suzu.tw/posts/2025-08-15-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-6%E7%88%AC%E8%9F%B2%E8%87%AA%E5%8B%95%E6%90%9C%E5%B0%8B%E6%95%8F%E6%84%9F%E8%B3%87%E8%A8%8A/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-15-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-6%E7%88%AC%E8%9F%B2%E8%87%AA%E5%8B%95%E6%90%9C%E5%B0%8B%E6%95%8F%E6%84%9F%E8%B3%87%E8%A8%8A/</guid><description>如果去看常見的一些資安事件，</description><pubDate>Fri, 15 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>【30天學習新語言-Ruby】Day 5：基本 HTML 解析找出潛在攻擊點</title><link>https://www.suzu.tw/posts/2025-08-14-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-5%E5%9F%BA%E6%9C%AC-html-%E8%A7%A3%E6%9E%90%E6%89%BE%E5%87%BA%E6%BD%9B%E5%9C%A8%E6%94%BB%E6%93%8A%E9%BB%9E/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-14-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-5%E5%9F%BA%E6%9C%AC-html-%E8%A7%A3%E6%9E%90%E6%89%BE%E5%87%BA%E6%BD%9B%E5%9C%A8%E6%94%BB%E6%93%8A%E9%BB%9E/</guid><description>找到 Web 服務之後，下一步就是分析網頁內容了。</description><pubDate>Thu, 14 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>【30天學習新語言-Ruby】Day 4：使用 HTTP 請求偵測 Web 服務狀態</title><link>https://www.suzu.tw/posts/2025-08-13-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-4%E4%BD%BF%E7%94%A8-http-%E8%AB%8B%E6%B1%82%E5%81%B5%E6%B8%AC-web-%E6%9C%8D%E5%8B%99%E7%8B%80%E6%85%8B/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-13-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-4%E4%BD%BF%E7%94%A8-http-%E8%AB%8B%E6%B1%82%E5%81%B5%E6%B8%AC-web-%E6%9C%8D%E5%8B%99%E7%8B%80%E6%85%8B/</guid><description>在做滲透測試的時候，只知道 port 開著還不夠，</description><pubDate>Wed, 13 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>【30天學習新語言-Ruby】Day 3：Banner Grabbing 抓取服務資訊</title><link>https://www.suzu.tw/posts/2025-08-12-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-3banner-grabbing-%E6%8A%93%E5%8F%96%E6%9C%8D%E5%8B%99%E8%B3%87%E8%A8%8A/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-12-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-3banner-grabbing-%E6%8A%93%E5%8F%96%E6%9C%8D%E5%8B%99%E8%B3%87%E8%A8%8A/</guid><description>在偵查的時候，知道某個 Port 有沒有開還不夠，通常還會去看背後是什麼服務、版本是多少。</description><pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>【30天學習新語言-Ruby】Day 2：用多執行緒加速 Port Scanner Scanner</title><link>https://www.suzu.tw/posts/2025-08-10-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-2%E7%94%A8%E5%A4%9A%E5%9F%B7%E8%A1%8C%E7%B7%92%E5%8A%A0%E9%80%9F-port-scanner/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-10-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-2%E7%94%A8%E5%A4%9A%E5%9F%B7%E8%A1%8C%E7%B7%92%E5%8A%A0%E9%80%9F-port-scanner/</guid><description>在資安方面，很多任務都是 I/O 密集型（例如網路掃描、HTTP 請求），</description><pubDate>Sun, 10 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>【30天學習新語言-Ruby】Day 1：用 Ruby 寫一個簡易 Port Scanner</title><link>https://www.suzu.tw/posts/2025-08-09-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-1%E7%94%A8-ruby-%E5%AF%AB%E4%B8%80%E5%80%8B%E7%B0%A1%E6%98%93-port/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-09-30%E5%A4%A9%E5%AD%B8%E7%BF%92%E6%96%B0%E8%AA%9E%E8%A8%80-rubyday-1%E7%94%A8-ruby-%E5%AF%AB%E4%B8%80%E5%80%8B%E7%B0%A1%E6%98%93-port/</guid><description>先講一下 Ruby 跟其他語言的差別好了，</description><pubDate>Sat, 09 Aug 2025 00:00:00 GMT</pubDate><category>Learning</category><category>Ruby</category><category>30天學Ruby挑戰</category></item><item><title>一些之前的解題資料庫</title><link>https://www.suzu.tw/posts/2025-08-05-%E4%B8%80%E4%BA%9B%E4%B9%8B%E5%89%8D%E7%9A%84%E8%A7%A3%E9%A1%8C%E8%B3%87%E6%96%99%E5%BA%AB/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-08-05-%E4%B8%80%E4%BA%9B%E4%B9%8B%E5%89%8D%E7%9A%84%E8%A7%A3%E9%A1%8C%E8%B3%87%E6%96%99%E5%BA%AB/</guid><description>因為之前習慣放 Notion，有些跨平台的題目比較好整理在一起，所以部分題目也會放在這邊：</description><pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate><category>Writeups</category><category>CTF</category><category>NCKUCTF</category><category>AIS3</category><category>pwnable</category><category>NOPctf</category></item><item><title>From LOL to LOLBAS - Win10/11 Attack</title><link>https://www.suzu.tw/posts/2025-04-30-from-lol-to-lolbas---win10_11-attack/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-04-30-from-lol-to-lolbas---win10_11-attack/</guid><description>目標：</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><category>Research</category><category>Windows</category><category>LOLBAS</category></item><item><title>【網路安全實務與社會實踐】作業三</title><link>https://www.suzu.tw/posts/2025-03-27-%E7%B6%B2%E8%B7%AF%E5%AE%89%E5%85%A8%E5%AF%A6%E5%8B%99%E8%88%87%E7%A4%BE%E6%9C%83%E5%AF%A6%E8%B8%90%E4%BD%9C%E6%A5%AD%E4%B8%89/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-03-27-%E7%B6%B2%E8%B7%AF%E5%AE%89%E5%85%A8%E5%AF%A6%E5%8B%99%E8%88%87%E7%A4%BE%E6%9C%83%E5%AF%A6%E8%B8%90%E4%BD%9C%E6%A5%AD%E4%B8%89/</guid><description>登入頁面的sqli</description><pubDate>Thu, 27 Mar 2025 00:00:00 GMT</pubDate><category>CTF</category><category>Learning</category><category>Writeups</category></item><item><title>【網路安全實務與社會實踐】作業二 Write-up</title><link>https://www.suzu.tw/posts/2025-03-26-%E4%BD%9C%E6%A5%AD%E4%BA%8C-write-up/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-03-26-%E4%BD%9C%E6%A5%AD%E4%BA%8C-write-up/</guid><description>發現這題的path traversal重點在這個區間</description><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><category>CTF</category><category>Learning</category><category>Writeups</category></item><item><title>picoCTF 2025 write-ups</title><link>https://www.suzu.tw/posts/2025-03-11-picoctf-2025-write-ups/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-03-11-picoctf-2025-write-ups/</guid><description>payload: getattr(import(&apos;o&apos;+&apos;s&apos;), &apos;po&apos;+&apos;pen&apos;)(&apos;tac${IFS}&apos;+chr(47)+&apos;fl&apos;).read()</description><pubDate>Tue, 11 Mar 2025 00:00:00 GMT</pubDate><category>Writeups</category><category>CTF</category><category>picoCTF</category></item><item><title>【網路安全實務與社會實踐】作業一 Write-up</title><link>https://www.suzu.tw/posts/2025-03-07-%E7%B6%B2%E8%B7%AF%E5%AE%89%E5%85%A8%E5%AF%A6%E5%8B%99%E8%88%87%E7%A4%BE%E6%9C%83%E5%AF%A6%E8%B8%90%E4%BD%9C%E6%A5%AD%E4%B8%80/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-03-07-%E7%B6%B2%E8%B7%AF%E5%AE%89%E5%85%A8%E5%AF%A6%E5%8B%99%E8%88%87%E7%A4%BE%E6%9C%83%E5%AF%A6%E8%B8%90%E4%BD%9C%E6%A5%AD%E4%B8%80/</guid><description>&gt; 此次 Lab 共為兩題</description><pubDate>Fri, 07 Mar 2025 00:00:00 GMT</pubDate><category>CTF</category><category>Learning</category><category>Writeups</category></item><item><title>PortSwigger SQLi writeup</title><link>https://www.suzu.tw/posts/2025-01-31-portswigger-sqli-writeup/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-01-31-portswigger-sqli-writeup/</guid><description>1. 開始會需要用到 Burp Suite Repeater 來幫忙轉成 URL Encoding 了（而且也比較方便看 response）</description><pubDate>Fri, 31 Jan 2025 00:00:00 GMT</pubDate><category>PortSwigger</category><category>Learning</category><category>Writeups</category></item><item><title>2025 TSCCTF writeup</title><link>https://www.suzu.tw/posts/2025-01-16-2025-tscctf-writeup/</link><guid isPermaLink="true">https://www.suzu.tw/posts/2025-01-16-2025-tscctf-writeup/</guid><description>反白就可以找到flag</description><pubDate>Thu, 16 Jan 2025 00:00:00 GMT</pubDate><category>Writeups</category><category>CTF</category></item></channel></rss>