Suninatas Wargame Writeup
A collection of Suninatas wargame writeups covering Forensics 14, 15, 18, and Simple Login.
Read full articleTags
A collection of Suninatas wargame writeups covering Forensics 14, 15, 18, and Simple Login.
Read full articleKongju National University Gifted Center pwnable2 challenge — patching a Sleep NOP to print the flag instantly.
Read full articleSolving CSAW 2013 Exploitation 2 (200 points) by sending a buffer and a secret, then overwriting RET with a buffer overflow.
Read full articleWalkthrough of the "alert(1) to win" XSS challenge.
Read full articleA writeup for RITSEC CTF 2021's baby WASM challenge, covering WebAssembly bytecode reversing, the WASM memory model, and flag extraction.
Read full articleWriteups for SUA CTF 2019 challenges in the pwn and reversing categories.
Read full articleWriteups for HackCTF's pwn category: basic BOF, format string bugs, heap exploitation (tcache), RTL chaining, and x64 buffer overflow.
Read full articleWriteups for Reversing.kr's Easy series -- Easy CrackMe, Easy ELF, Easy Keygen, Easy Unpack, and Replace -- solved through static and dynamic analysis.
Read full articleProgressing through the LOB (Lord of Buffer Overflow) wargame: Gate (basic BOF), Iron_golem (partial RELRO bypass), Dark_eyes (NX + ASLR) — tracing the evolution of Linux exploitation techniques.
Read full articleSolving pwnable.kr challenges: ARM PC computation quirks (leg), a GOT overwrite via scanf (passcode), and building a ROP chain (horcruxes).
Read full articleWriteups for the ROP Emporium ret2win (basic ROP control-flow hijacking) and callme (chained function calls with specific arguments) challenges.
Read full articleA shellcode injection writeup for Pwnable.tw's Start challenge, exploiting a stack-based buffer overflow in a minimal 32-bit Linux binary with no NX protection.
Read full articleSolving the Protostar wargame: stack buffer overflows, format string bugs, heap exploitation, and a network challenge.
Read full articleSolving exploit.me's vulnerable service: stack buffer overflows, return address overwrites, shellcode injection, and ROP techniques on x86 Linux.
Read full articleSolutions to picoCTF 2018 pwn and assembly challenges: a buffer overflow series, x86 assembly puzzles, and shellcode execution.
Read full articleSolving DEF CON 23's babycmd: command injection via blacklist bypass on a 64-bit Linux binary, with a shell-escape technique.
Read full articleSolving DEF CON 22 CTF Qualifier's r0pbaby: leaking the shared library base, finding gadgets via PLT/GOT, and building a 64-bit ROP chain to call system().
Read full articleA classic Plaid CTF 2013 challenge: a ret2libc / ROP chain exploit against a 32-bit Linux binary.
Read full article