Hacking
is the finest art.
CTF challenges Write-ups, vulnerability research, and offensive security techniques. All write-ups include full methodology, not just the flag.
Recent Write-ups
View all →Solstice 9
Rebuilding a device fixture from flash storage and bus captures to sign a maintenance request.
Power with Errors
Recovering fifteen XOR keys from noisy matrix powers using commutators and lattice reduction.
Kanji
Tracing an IRC botnet through a large packet capture to identify its bots, victim, and flood attacks.
Gnome Breaker
Fixing a keyring extraction error, cracking the login password, and recovering the secret stored inside.
Arbitrary Funds Sweep
Recreating an L1 contract at the same address on L2 to take ownership of a five-ETH vault.
aethergate
Using a telemetry URL validation bug to overwrite an init script and retrieve the router flag.
oBfsC4t10n
Recovering a payload split across an Excel picture, UserForm, and worksheet cell, then decoding VBA and XOR-obfuscated shellcode.
FishyHTTP
Analyzing a bundled .NET executable and decoding commands hidden in HTML tags and command output disguised as words in HTTP traffic.
PartialEncryption
Reversing a Windows PE that decrypts small runtime code chunks with AES-NI before validating the flag byte by byte.
ARMs Race
Automating a 50-level ARM emulation challenge by decoding ARM instructions and recovering the final value of r0.
RedTrails
Analyzing a multi-stage attack through Redis exploitation, reverse shell deployment and AES-256-CBC decryption.
Snakecode
Extracting layered Python bytecode obfuscation through base64 decoding, zlib decompression, and marshal deserialization.