ProxyAsAService: identify the broken request handling, prove control, and use it to recover the flag.
Htb
373 postsPursue the Tracks
Pursue the Tracks: isolate the relevant artifact, decode the evidence, and extract the flag.
Questionnaire
Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.
Rhome
Shamir's Secret
Space Pirate Going Deeper
Space Pirate Going Deeper: build the exploit primitive, stabilize the payload, and use it to read the flag.
Terrorfryer
Terrorfryer: reverse the validation logic, model the transform, and recover the accepted input.
Wizard's Diary
Wizard's Diary: calculate the overflow offset, redirect control flow, and land a reliable flag read.
Writing on the Wall
Writing on the Wall: build the exploit primitive, stabilize the payload, and use it to read the flag.
YALM
AbuseHumanDB
AbuseHumanDB: identify the broken request handling, prove control, and use it to recover the flag.
Ancored
Ancored: inspect the Android app, trace the validation path, and recover the flag.
Computational Recruting
Computational Recruting: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Crushing
Crushing: reverse the validation logic, model the transform, and recover the accepted input.
Easy Phish
Easy Phish: correlate the public clues, pivot through the evidence, and identify the final answer.
Entity
Entity: build the exploit primitive, stabilize the payload, and use it to read the flag.
Foggy Intrusion
Foggy Intrusion: isolate the relevant artifact, decode the evidence, and extract the flag.
Fuel Crisis
Fuel Crisis: shape the prompt path, bypass the model guard, and recover the target output.
Golfer
Golfer: trace the binary, isolate the validation routine, and invert it to recover the flag.
Graverobber
Graverobber: trace the binary, isolate the validation routine, and invert it to recover the flag.
Illumination
Illumination: isolate the relevant artifact, decode the evidence, and extract the flag.
Infiltration
Infiltration: correlate the public clues, pivot through the evidence, and identify the final answer.
Override
Override: decode the captured signal, map the bitstream, and recover the flag.
Perfect Synchronization
Perfect Synchronization: recover the Vigenere key from the ciphertext, decrypt the message, and verify the flag.
Pixel Audio
Pixel Audio: build the exploit primitive, stabilize the payload, and use it to read the flag.
Potion Master
Potion Master: recover the XOR transform from the binary and invert it to reveal the flag.
Prision Pipeline
Prision Pipeline: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.
Quantum Conundrum
Quantum Conundrum: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.