Posts

All posts

Page 2

What a CTF on IRC looks like — IRCPuzzles AFPC 2022

Cluelessly staring at a vague hint for hours, relentlessly going down multiple rabbit holes, the joy of finally finding a solution… what’s not to love? After all, this is fairly similar to a regular day in information security. I decided to check out this …

An Image Speaks a Thousand RCEs: The Tale of Reversing an ExifTool CVE

A tweet showing an RCE in ExifTool popped up on my feed; it looked interesting — maybe a little scary. But what good is an RCE on a demo video? I wanted more; I wanted it to pop my calculator.exe, to rm -rf my home directory; heck, it could even Rick Roll me. …

Solving Intigriti Challenge using… Content Injection!

Intigriti releases cool challenges every once in a while, and this was no exception. I love a good challenge. Every time I solve an Intigriti challenge, I learn something new. Motivated by that, I wanted to crack this one too. As usual, there were many …

h1–702 CTF — Web Challenge Write Up

This writeup has since won the H1–702 challenge. Read HackerOne blog here: https://www.hackerone.com/blog/H1-702-CTF-Winners-Announced When you open the challenge link, you’re presented with this: Instructions can be found on the web challenge site: …

Solving the Dog Problem — Google CTF 2018 Quals Write Up

Challenge Description#Cat Chat app popupGetting familiarized#When you open the link, it redirects you to a chat room with a random UUID which is probably the chat room ID. Challenge homepageThis looks like a chat application built with NodeJS where anyone can …