QuickScan: trace the binary, isolate the validation routine, and invert it to recover the flag.
Htb
373 postsRaceCar
RaceCar: use the format-string bug for a leak or write, then redirect execution to the flag path.
Sp00ky Theme
Sp00ky Theme: isolate the relevant artifact, decode the evidence, and extract the flag.
VHDLock
VHDLock: decode the captured signal, map the bitstream, and recover the flag.
The Last Frontier
The Last Frontier: decode the captured signal, map the bitstream, and recover the flag.
El Mundo
El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
El Pipo
El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.
RsaCtfTool
RsaCtfTool: abuse the AES misuse, derive the missing key material, and decrypt the flag.
LinkVortex
LinkVortex: use CVE-2023-40028 where it fits the service, gain a shell, and escalate to root.
Bizness
Bizness: use CVE-2023-49070 and CVE-2023-51467 where it fits the service, gain a shell, and escalate to root.
Inject
Inject: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Unrested
Unrested: use CVE-2024-36467 and CVE-2024-42327 where it fits the service, gain a shell, and escalate to root.
Vintage
Vintage: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Kernel Adventures 2
Kernel Adventures 2: build the shellcode path, control execution, and read the flag.
ScreenCrack
Touch
Bag Secured
Bag Secured: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Intrusion
Intrusion: decode the captured signal, map the bitstream, and recover the flag.
MultiDigilingual
MultiDigilingual: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Addition
Addition: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
C.O.P
C.O.P: exploit the SQL injection, extract the needed data, and reach the flag.
CandyVault
CandyVault: model the crypto leak, recover the missing secret, and decrypt the flag.
Cursed Stale Policy
Cursed Stale Policy: abuse websocket to cross the web trust boundary and recover the flag.
DLLAMA
DLLAMA: abuse unsafe deserialization to cross the trust boundary and reach the flag.
Execute
Fishy HTTP
Gunship
Gunship: identify the broken request handling, prove control, and use it to recover the flag.
Jscalc
Jscalc: use path traversal to escape the intended read path and recover the flag.