Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Pwnable|Web Security|Cryptography CTF-style challenges

NotificationsYou must be signed in to change notification settings

l4wio/CTF-challenges-by-me

Repository files navigation

These are CTF-style challenges I've made. Hope you enjoyed ✌

Highlight

Tips: Like reading book, don't read the last pages first. Let's enjoy them for a day at least before checking writeup/sol. I've put a lot of my work in each one.

I'm going to describe my highlight challenges, which I like mostly. Also point out the interesting points of them.

Web

NameLanguageSummaryRatingLevelDescribe yet ?
prisonbreakseason2PythonPython Jail⭐⭐⭐⭐💀💀💀✔️
XYZBANKPHPMySQL type casting⭐⭐💀💀✔️
XYZTemplatePHP/JavascriptJavascript/XSS⭐⭐💀💀
cryptowwwPHPHash extension / urldecode trick, HTTP Parameter Pollution⭐⭐💀💀✔️
curl_story_part_1PHPSSRF /w CRLF Injection (it was 0day)⭐⭐⭐⭐💀💀✔️
luckygamePHPMySQLi /w session variable + php type juggling⭐⭐⭐⭐💀💀💀✔️
simplehttpRubyRuby RCE /wWEBrick::Log.new⭐⭐⭐⭐💀💀💀✔️
tower4PythonFormat injection⭐⭐⭐⭐💀💀✔️
lixiPHPPHP syntax trick⭐⭐⭐💀💀✔️
LoginMeNodeJSRegExp injection, MongoDB⭐⭐⭐💀✔️
h4x0rs.clubPHP/JSCSPstrict-dynamic, XSS, iframe in the middle, postMessage totop⭐⭐⭐⭐💀💀💀✔️
h4x0rs.spacePHP/JSCSP, Persistent XSS, AppCache, ServiceWorker⭐⭐⭐⭐💀💀💀✔️
h4x0rs.datePHP/JSCSP, cache,<meta> Referrer override⭐⭐⭐💀💀✔️

Pwnable

NameSummaryRatingLevelDescribe yet ?
anotherarenaHeap on anothermain_arena (threads)⭐⭐⭐💀✔️
c0ffeeRace condition, with 1-byte overwrite, nearly impossible to exploit⭐⭐⭐⭐💀💀💀
pokedexUninitialized memory -> Heap overflow⭐⭐⭐💀💀✔️
rapgeniusUninitialized memory -> Use-After-Free +_IO_FILE abusing (_IO_read_* &&_IO_write_*)⭐⭐⭐💀💀✔️
castleCombine many of bugs: uninitliazed memory + stack overflow + heap overflow to defeat stack cookie eventually⭐⭐⭐⭐💀💀💀
House-of-CardsOld school pwnable, overwritingENV⭐⭐⭐⭐💀💀✔️
h4x0rs.club pt3Old school pwnable, Fake MySQL server, MySQL LOCAL INFILE⭐⭐⭐⭐⭐💀💀💀✔️

Footer

Final round SVATTT 2016 Introduction page

Twitter: @l4wio

...Dành cả tuổi thanh xuân để suy nghĩ đề CTF.

Updating...

About

Pwnable|Web Security|Cryptography CTF-style challenges

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

[8]ページ先頭

©2009-2025 Movatter.jp