Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.
Htb
373 postsSpellBrewery
SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.
yoU ART
yoU ART: decode the captured signal, map the bitstream, and recover the flag.
BlockBlock
Ghost
WayBack
Administrator
Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Binary Basis
Binary Basis: model the crypto leak, recover the missing secret, and decrypt the flag.
Brevi Moduli
Brevi Moduli: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.
Hybrid Unifier
Hybrid Unifier: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Inizialization
Inizialization: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Read Before You Sign
Read Before You Sign: model the crypto leak, recover the missing secret, and decrypt the flag.
Sekur Julius
Sekur Julius: reconstruct the PRNG state from the leak, replay it, and recover the flag.
SPG
SPG: reconstruct the generator state, derive the AES material, and decrypt the final ciphertext.
Sugar Free Candies
Sugar Free Candies: model the crypto leak, recover the missing secret, and decrypt the flag.
Certified
Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Feedback Flux
Feedback Flux: use the client-side injection path to steal the needed proof and recover the flag.
Blazorized
Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Epsilon
Epsilon: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Secure Singning
Secure Singning: derive the XOR key stream, invert the transform, and recover the flag.
Shattered Tablet
Shattered Tablet: trace the binary, isolate the validation routine, and invert it to recover the flag.
Mist
Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Axlle
Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Bypass
Beep
Beep: use CVE-2012-4869 where it fits the service, gain a shell, and escalate to root.
MagicGardens
MagicGardens: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.