The Last Frontier: decode the captured signal, map the bitstream, and recover the flag.
Challenge
318 postsEl Mundo
El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
El Pipo
El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
RsaCtfTool
RsaCtfTool: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Kernel Adventures 2
Kernel Adventures 2: build the shellcode path, control execution, and read the flag.
ScreenCrack
Touch
Bag Secured
Bag Secured: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Intrusion
Intrusion: decode the captured signal, map the bitstream, and recover the flag.
MultiDigilingual
MultiDigilingual: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Addition
Addition: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
C.O.P
C.O.P: exploit the SQL injection, extract the needed data, and reach the flag.
CandyVault
CandyVault: model the crypto leak, recover the missing secret, and decrypt the flag.
Cursed Stale Policy
Cursed Stale Policy: abuse websocket to cross the web trust boundary and recover the flag.
DLLAMA
DLLAMA: abuse unsafe deserialization to cross the trust boundary and reach the flag.
Execute
Fishy HTTP
Gunship
Gunship: identify the broken request handling, prove control, and use it to recover the flag.
Jscalc
Jscalc: use path traversal to escape the intended read path and recover the flag.
Juggling facts
Juggling facts: identify the broken request handling, prove control, and use it to recover the flag.
KORP Terminal
KORP Terminal: exploit the SQL injection, extract the needed data, and reach the flag.
MinMax
MinMax: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
misDIRection
misDIRection: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Neonify
Neonify: identify the broken request handling, prove control, and use it to recover the flag.
Nothing Without A Cost
Nothing Without A Cost: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Oddly Even
Oddly Even: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Optimus Prime
Optimus Prime: model the crypto leak, recover the missing secret, and decrypt the flag.
PetPet Rcbee
PetPet Rcbee: abuse file-upload to cross the web trust boundary and recover the flag.