Phonebook: identify the broken request handling, prove control, and use it to recover the flag.
Challenge
318 postsPrying Eyes
Prying Eyes: use path traversal to escape the intended read path and recover the flag.
Replacement
Replacement: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Reversal
Reversal: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
SpookTastic
SpookTastic: use the client-side injection path to steal the needed proof and recover the flag.
TimeKORP
TimeKORP: use path traversal to escape the intended read path and recover the flag.
Toxic
Toxic: abuse unsafe deserialization to cross the trust boundary and reach the flag.
Trapped Source
Trapped Source: identify the broken request handling, prove control, and use it to recover the flag.
Weather App
Weather App: use SSRF to reach the hidden service or file path and pull the flag.
Ancient Encodings
Ancient Encodings: model the crypto leak, recover the missing secret, and decrypt the flag.
Dont't Panic
Dont't Panic: trace the binary, isolate the validation routine, and invert it to recover the flag.
El Teteo
El Teteo: build the shellcode path, control execution, and read the flag.
FF Jump Street
FF Jump Street: decode the captured signal, map the bitstream, and recover the flag.
Flippin Bank
Flippin Bank: reconstruct the generator state, derive the AES material, and decrypt the final ciphertext.
Gonna Lift Em All
Gonna Lift Em All: reconstruct the PRNG state from the leak, replay it, and recover the flag.
Hacky Bird
Hacky Bird: inspect the game logic, control the relevant state, and recover the flag.
Mathematricks
Mathematricks: build the exploit primitive, stabilize the payload, and use it to read the flag.
Que Onda
Que Onda: build the exploit primitive, stabilize the payload, and use it to read the flag.
Regularity
Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.
SpellBrewery
SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.
yoU ART
yoU ART: decode the captured signal, map the bitstream, and recover the flag.
WayBack
Binary Basis
Binary Basis: model the crypto leak, recover the missing secret, and decrypt the flag.
Brevi Moduli
Brevi Moduli: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.
Hybrid Unifier
Hybrid Unifier: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Inizialization
Inizialization: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Read Before You Sign
Read Before You Sign: model the crypto leak, recover the missing secret, and decrypt the flag.
Sekur Julius
Sekur Julius: reconstruct the PRNG state from the leak, replay it, and recover the flag.