<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Th3B0yWh0L1v3d — Security Writeups</title>
    <link>https://th3b0ywh0l1v3d.github.io/</link>
    <description>Recent content on Th3B0yWh0L1v3d — Security Writeups</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 16 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://th3b0ywh0l1v3d.github.io/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A Basic Start</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/a-basic-start/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/a-basic-start/</guid>
      <description>Decoding a multi-layer encoding chain: Base64 followed by Base91.</description>
    </item>
    <item>
      <title>AlphaCode</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/alphacode/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/alphacode/</guid>
      <description>Reverse-engineering a custom esolang stack machine to recover the flag.</description>
    </item>
    <item>
      <title>Amazing</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/amazing/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/amazing/</guid>
      <description>Reversing a Python marshal bytecode maze generator seeded by an LCG to find the escape path.</description>
    </item>
    <item>
      <title>Babel&#39;s Vault</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/babels-vault/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/babels-vault/</guid>
      <description>Finding the flag inside the Library of Babel using a seed and image residual pixel indices.</description>
    </item>
    <item>
      <title>Beyond the Homepage</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/beyond-the-homepage/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/beyond-the-homepage/</guid>
      <description>Flag hidden in an HTML comment, visible only via browser developer tools or view-source.</description>
    </item>
    <item>
      <title>Boro Hero</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/misc/boro-hero/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/misc/boro-hero/</guid>
      <description>OSINT challenge: identify a Freehold High School alum from a blurred music photo — Bruce Springsteen.</description>
    </item>
    <item>
      <title>Boro Senpai 1</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-1/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-1/</guid>
      <description>IDOR / broken access control lets you access another user&amp;rsquo;s flag by changing an ID parameter.</description>
    </item>
    <item>
      <title>Boro Senpai 2</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-2/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-2/</guid>
      <description>Part 2 of the Boro Senpai series: SSRF via Docker internal hostname.</description>
    </item>
    <item>
      <title>Boro Senpai 3</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-3/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/boro-senpai-3/</guid>
      <description>Flag or unlock parameter hardcoded in client-side JavaScript.</description>
    </item>
    <item>
      <title>boroGPT</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/borogpt/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/borogpt/</guid>
      <description>Source-map leak reveals JWT secret, forge admin token, then exploit Jinja2 SSTI for RCE.</description>
    </item>
    <item>
      <title>cat</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/cat/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/cat/</guid>
      <description>Reversing a repeating-key XOR crackme that downloads the flag from catbox.moe.</description>
    </item>
    <item>
      <title>Chicken Dinner</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/chicken-dinner/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/chicken-dinner/</guid>
      <description>Brute-force stack canary byte-by-byte via fork&amp;rsquo;s PID oracle, leak libc with puts, then ORW ROP chain.</description>
    </item>
    <item>
      <title>Coming Together</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/coming-together/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/coming-together/</guid>
      <description>Two&amp;rsquo;s complement INT_MIN negation overflow bypasses an absolute-value check to trigger the win condition.</description>
    </item>
    <item>
      <title>Cracking the Vault</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/cracking-the-vault/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/cracking-the-vault/</guid>
      <description>Password and flag hardcoded in client-side JavaScript — just read the source.</description>
    </item>
    <item>
      <title>Disco Franklin</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/disco-franklin/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/disco-franklin/</guid>
      <description>Decoding ASCII characters from RGB color blocks in a PNG image.</description>
    </item>
    <item>
      <title>dotdotslashflagtxt</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/dotdotslashflagtxt/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/dotdotslashflagtxt/</guid>
      <description>Classic path traversal — the challenge name tells you exactly what to do.</description>
    </item>
    <item>
      <title>Drone Dash</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/drone-dash/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/drone-dash/</guid>
      <description>Node.js prototype pollution via POST /api/flight-profile grants admin access.</description>
    </item>
    <item>
      <title>Et Tu Brute</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/et-tu-brute/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/et-tu-brute/</guid>
      <description>Classic Caesar cipher shifted by +3 conceals the flag.</description>
    </item>
    <item>
      <title>Franklin</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/franklin/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/franklin/</guid>
      <description>Recovering the flag from TrueType GSUB ligature substitution rules.</description>
    </item>
    <item>
      <title>George Orwell</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/george-orwell/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/george-orwell/</guid>
      <description>Decompiling a compiled AutoHotkey executable to extract the flag.</description>
    </item>
    <item>
      <title>Hidden But Definitely Not</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/hidden-but-definitely-not/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/hidden-but-definitely-not/</guid>
      <description>Recovering a flag hidden via stack-string construction and XOR obfuscation.</description>
    </item>
    <item>
      <title>Kobeni&#39;s Dashboard</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/kobenis-dashboard/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/kobenis-dashboard/</guid>
      <description>Abusing ImageMagick&amp;rsquo;s SVG text: pseudo-coder to read the flag file via server-side image conversion.</description>
    </item>
    <item>
      <title>Mania</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/mania/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/mania/</guid>
      <description>Use-after-free on a tcache chunk to overwrite a function pointer and call win().</description>
    </item>
    <item>
      <title>Nature&#39;s Takeover</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/misc/natures-takeover/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/misc/natures-takeover/</guid>
      <description>Identify the abandoned ship overgrown with vegetation from an OSINT image — SS Ayrfield.</description>
    </item>
    <item>
      <title>Neural Sync Portal</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/neural-sync-portal/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/neural-sync-portal/</guid>
      <description>SSRF via Docker internal hostname to reach the metadata service and retrieve the flag.</description>
    </item>
    <item>
      <title>New to the Format</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/new-to-the-format/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/pwning/new-to-the-format/</guid>
      <description>Blind format-string exploit with ASLR off: leak stack address then use %n + call rax to redirect execution.</description>
    </item>
    <item>
      <title>Next Challenge (VULNBOT)</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/misc/next-challenge/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/misc/next-challenge/</guid>
      <description>Reverse-psychology logic puzzle: telling the bot the flag IS the answer gets you the flag.</description>
    </item>
    <item>
      <title>Not the Flag</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/not-the-flag/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/crypto/not-the-flag/</guid>
      <description>Apply bitwise NOT to a hex string to reveal the flag.</description>
    </item>
    <item>
      <title>Not Your Time</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/not-your-time/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/not-your-time/</guid>
      <description>Crackme that stores the bitwise NOT of the flag bytes; invert them to get the flag.</description>
    </item>
    <item>
      <title>Perfectly Destructive File</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/perfectly-destructive-file/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/reversing/perfectly-destructive-file/</guid>
      <description>Extracting a flag hidden inside a PDF stream using FlateDecode and base64.</description>
    </item>
    <item>
      <title>Solarity</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/solarity/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/boroctf-2026/web/solarity/</guid>
      <description>Path traversal via /view?file=../flag.txt reads the server-side flag file.</description>
    </item>
    <item>
      <title>Flip Dat Bit — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/flip-dat-bit/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/flip-dat-bit/</guid>
      <description>A TCP service hands you the AES-CBC ciphertext of your own input and asks you to return a ciphertext that decrypts to contain admin credentials — solved with a single-byte XOR flip.</description>
    </item>
    <item>
      <title>Intermediate Nmap — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/intermediate-nmap/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/intermediate-nmap/</guid>
      <description>A full-range nmap scan uncovers a port 31337 service broadcasting SSH credentials in plaintext — connecting the dots between -sV output and an SSH login to grab the flag.</description>
    </item>
    <item>
      <title>Reset — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/reset/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/reset/</guid>
      <description>Anonymous SMB leaks a default onboarding password; AS-REP roasting cracks TABATHA_BRITT; a three-link BloodHound ACL chain of forced password resets leads to DARLA_WINTERS, whose constrained delegation with protocol transition lets us impersonate Administrator via S4U2Self/S4U2Proxy for a full domain dump.</description>
    </item>
    <item>
      <title>El Bandito — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/el-bandito/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/el-bandito/</guid>
      <description>An exposed Spring Boot Actuator plus an nginx /.;/ path-ACL bypass leaks admin creds and the first flag; an HTTP/2 H2.CL desync then captures an internal bot&amp;rsquo;s request, stealing its flag cookie.</description>
    </item>
    <item>
      <title>HeartBleed — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/heartbleed/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/heartbleed/</guid>
      <description>A vulnerable nginx server exposes OpenSSL&amp;rsquo;s Heartbleed bug (CVE-2014-0160), allowing unauthenticated heap memory disclosure that leaks a plaintext HTTP POST body — and the flag — straight out of an active SSL session.</description>
    </item>
    <item>
      <title>Padelify — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/padelify/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/padelify/</guid>
      <description>A padel-tournament portal behind a deny-list ModSecurity WAF falls to a three-step chain: a User-Agent header bypass, a stored XSS that steals a moderator bot&amp;rsquo;s session cookie, and an LFI that leaks admin creds via full per-character URL-encoding.</description>
    </item>
    <item>
      <title>Plant Photographer — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/plant-photographer/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/plant-photographer/</guid>
      <description>SSRF via a pycurl download endpoint chains into file:// LFI, Werkzeug debug PIN cracking, and full RCE on a Dockerised Flask app.</description>
    </item>
    <item>
      <title>Robots — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/robots/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/robots/</guid>
      <description>XSS in a registration form exfiltrates the admin&amp;rsquo;s session cookie; RFI via the admin URL-tester gives www-data code execution; double-MD5 cracking yields SSH access, and a sudo apache2 logging trick writes a root SSH key.</description>
    </item>
    <item>
      <title>Bandaids Help me Heal — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/pwning/bandaids-help-me-heal/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/pwning/bandaids-help-me-heal/</guid>
      <description>A &amp;lsquo;pwn&amp;rsquo; binary with no input is really a static-reversing puzzle: a fake usleep loop would take days and a fake integrity check always passes, so reading the constants and undoing a single-byte XOR yields the flag without ever waiting.</description>
    </item>
    <item>
      <title>Bouncer — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/bouncer/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/bouncer/</guid>
      <description>A read-only anonymous FTP gateway turns out to be a Redis health-check proxy; abusing the PORT command for an FTP bounce plus a newline-smuggled RETR inline command yields a bidirectional Redis relay that scans the subnet and reads the flag.</description>
    </item>
    <item>
      <title>Card Trick — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/misc/card-trick/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/misc/card-trick/</guid>
      <description>A trivia/OSINT puzzle: identify Valve&amp;rsquo;s unreleased game Deadlock and the hero Wraith, then read the shipped ability data (Card Trick) from the community API to get the suit order, max-level stat modifiers, and card-charge count for the flag.</description>
    </item>
    <item>
      <title>Chakravyuh Defense — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/chakravyuh-defense/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/chakravyuh-defense/</guid>
      <description>A defensive web CTF where you patch the vulnerable source and the grader attacks your build: Secure the Login is fixed with parameterized queries, and Render &amp;amp; Plunder is sealed by binding SSTI input as render context plus adding an object-level authorization check to kill the IDOR.</description>
    </item>
    <item>
      <title>Connected — HackTheBox</title>
      <link>https://th3b0ywh0l1v3d.github.io/htb/connected/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/htb/connected/</guid>
      <description>A Hard Linux machine running FreePBX — full writeup locked until the box retires.</description>
    </item>
    <item>
      <title>Fun With RSA — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/fun-with-rsa/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/fun-with-rsa/</guid>
      <description>A homemade RSA-CRT signer leaks a correct and a faulted signature of the same message; gcd(s − spz, n) factors n (the Bellcore attack), while the trivial shortcut just recovers the message via s^e mod n — and the XOR &amp;lsquo;protection&amp;rsquo; undoes itself.</description>
    </item>
    <item>
      <title>ICEMAN — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/iceman/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/iceman/</guid>
      <description>A GraphQL vault chains a crackable HS256 JWT secret (the challenge name) for tier escalation with broken object-level authorization — the unreleased album is hidden from album(id) but leaks through the label→artists→albums path.</description>
    </item>
    <item>
      <title>Lost My Flag Printer — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/misc/lost-my-flag-printer/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/misc/lost-my-flag-printer/</guid>
      <description>A setuid helper pins an eBPF flag-printer into a world-accessible PROG_ARRAY then chmod 000s the program pin; loading an unprivileged socket-filter that bpf_tail_calls index 0 runs the root-loaded printer and fills the readable flag map.</description>
    </item>
    <item>
      <title>Password Vault — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/pwning/password-vault/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/pwning/password-vault/</guid>
      <description>A password-manager heap challenge: free() without nulling the pointer gives a use-after-free, tcache hands the freed Login chunk back via set_password, and overwriting the struct&amp;rsquo;s leading function pointer redirects an indirect call to the leftover read_master_key win function.</description>
    </item>
    <item>
      <title>Slot Machine — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/pwning/slot-machine/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/pwning/slot-machine/</guid>
      <description>A textbook ret2win: gets() into a 32-byte stack buffer with no canary and no PIE lets us overwrite the saved return address with jackpot(); the only twist is closing stdin to force the menu loop&amp;rsquo;s EOF break so the corrupted return fires.</description>
    </item>
    <item>
      <title>someone said steg? — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/misc/someone-said-steg/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/misc/someone-said-steg/</guid>
      <description>A 16-frame APNG hides one flag character per frame in the top-left pixel of each frame&amp;rsquo;s decompressed scanline data; every standard stego avenue is a dead end, so decompressing all 16 fdAT/IDAT streams and reading byte 4 of each yields the flag.</description>
    </item>
    <item>
      <title>Spoiled Cheese Pull — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/forensics/spoiled-cheese-pull/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/forensics/spoiled-cheese-pull/</guid>
      <description>A &amp;lsquo;PNG&amp;rsquo; that file() calls a broken JPEG is a PNG with a forged signature and vandalized chunk names; repairing the header reveals an rMQR (rectangular Micro QR) barcode that ZXing decodes to the flag.</description>
    </item>
    <item>
      <title>All&#39;s Fair in Love and CTFs — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/alls-fair/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/alls-fair/</guid>
      <description>The title &amp;lsquo;All&amp;rsquo;s Fair&amp;rsquo; points at the Playfair cipher; the grid image is the standard 5×5 key square with even columns blanked, and the ciphertext decrypts to ANYTHINGFORTHEFLAG.</description>
    </item>
    <item>
      <title>Angry Shamir — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/angry-shamir/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/angry-shamir/</guid>
      <description>An RSA modulus that looks 2054-bit-strong is actually 67 × q — a tiny prime factor makes it trivially factorable (FactorDB / trial division), reconstructing the private key and decrypting the flag.</description>
    </item>
    <item>
      <title>Baby Android — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/baby-android/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/baby-android/</guid>
      <description>A single APK whose UI claims there&amp;rsquo;s nothing to see — the flag is split into three pieces hidden in a MainActivity field, a string resource, and a Compose theme getter.</description>
    </item>
    <item>
      <title>Baby Web — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/baby-web/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/baby-web/</guid>
      <description>A static HTML page stuffed with a movie transcript hides the flag in a paragraph marked hidden=&amp;ldquo;true&amp;rdquo; — invisible in the browser but right there in the page source.</description>
    </item>
    <item>
      <title>Bit Miner — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/bit-miner/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/bit-miner/</guid>
      <description>An idle/clicker TCP game whose shop checks affordability against a stale cached balance but deducts from a fresh re-read; racing two sessions as the same user underflows an unsigned long to ~1.8e19 bits and buys the flag.</description>
    </item>
    <item>
      <title>Cat GIFs — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/cat-gifs/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/cat-gifs/</guid>
      <description>A PHP upload app re-encodes every GIF through PHP-GD as sanitization but never validates the filename — a payload smuggled inside the GIF color palette survives the re-encode, yielding a GIF/PHP polyglot webshell and RCE.</description>
    </item>
    <item>
      <title>Compression isn&#39;t encryption — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/compression-isnt-encryption/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/compression-isnt-encryption/</guid>
      <description>A 192-bit Huffman stream and a frequency table; the textbook min-heap decode looks perfect (wrapped in dalctf{}, zero leftover bits) yet is wrong — matching the encoder&amp;rsquo;s tie-break policy recovers the real flag.</description>
    </item>
    <item>
      <title>DEAD VAULT — Zer0d4yh31st CTF</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/zer0d4yh31st/web/dead-vault/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/zer0d4yh31st/web/dead-vault/</guid>
      <description>A Money Heist–themed Flask app hides a flag split into three fragments behind a server-side URL fetcher, bypassed with a DNS-based SSRF to reach the internal API and a privileged file-read endpoint.</description>
    </item>
    <item>
      <title>Do You Know The Way? — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/do-you-know-the-way/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/do-you-know-the-way/</guid>
      <description>A UPX-packed, unstripped crackme lays its 44-byte check out as 44 independent per-character functions; emulating each with Unicorn brute-forces the flag one byte at a time, sidestepping a rand()-based anti-dynamic trap.</description>
    </item>
    <item>
      <title>Espresso — HackTheBox Hardware</title>
      <link>https://th3b0ywh0l1v3d.github.io/htb/espresso/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/htb/espresso/</guid>
      <description>An ESP32 firmware reversing challenge — full writeup locked until the challenge retires.</description>
    </item>
    <item>
      <title>Expensey Eats — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/expensey-eats/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/expensey-eats/</guid>
      <description>An alg:none JWT forgery grants admin, UNION-based SQLi reveals a hidden $99,999 vault dish, and a broken-authorization order flow lets the admin buy it for free — the flag arrives in a one-time Flask flash message.</description>
    </item>
    <item>
      <title>Haskell2 — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/haskell2/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/reversing/haskell2/</guid>
      <description>A stripped compiler for an invented language is reverse-engineered from its error strings and codegen templates; the recovered grammar exposes an intended read file primitive that simply prints flag.txt — no exploit required.</description>
    </item>
    <item>
      <title>Heart Part 7 — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/heart-part-7/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/heart-part-7/</guid>
      <description>A Kendrick-themed Flask app chains UNION-based SQLi to leak admin creds, an admin panel exposes an internal cipher microservice, and a Heartbleed-style over-read bleeds the AES-256 master key from heap memory to decrypt the flag.</description>
    </item>
    <item>
      <title>La Casa de Papel (Secure Comms) — Zer0d4yh31st CTF</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/zer0d4yh31st/web/la-casa-de-papel/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/zer0d4yh31st/web/la-casa-de-papel/</guid>
      <description>A Flask/Jinja2 app renders user-supplied names directly into a template, enabling SSTI that dumps os.environ to leak the flag stored as an environment variable.</description>
    </item>
    <item>
      <title>LCG Seed Squared — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/lcg-seed-squared/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/lcg-seed-squared/</guid>
      <description>A homemade LCG-as-cipher multiplies each flag byte by a deterministic state independent of the plaintext — the known DalCTF{ prefix recovers one state, and replaying the generator divides out the rest. The lost seed is a red herring.</description>
    </item>
    <item>
      <title>Playing with Pointers — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/playing-with-pointers/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/crypto/playing-with-pointers/</guid>
      <description>A C program squares each flag byte as a float, then a &amp;lsquo;forgotten&amp;rsquo; Quake-style &lt;em&gt;(long&lt;/em&gt;)&amp;amp;y type-pun prints the raw IEEE-754 bits as integers; reversing bits→float→sqrt→char recovers the flag.</description>
    </item>
    <item>
      <title>SecretPickle — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/secretpickle/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/secretpickle/</guid>
      <description>A Pyodide client serializes requests with pickle obfuscated by a hardcoded XOR key, letting the server pickle.loads attacker data for unauthenticated root RCE, then hooking the live handler to capture the adminbot&amp;rsquo;s plaintext login password.</description>
    </item>
    <item>
      <title>Secure Secretpickle — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/secure-secretpickle/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/secure-secretpickle/</guid>
      <description>The hardened secretpickle runs pickle.loads in a write-only seccomp sandbox, but the adminbot action visits an attacker URL with no scheme check and returns a screenshot, so file:///flag.txt renders the flag into the image.</description>
    </item>
    <item>
      <title>SecureForm Admin — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/secureform-admin/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/web/secureform-admin/</guid>
      <description>A 4-digit PIN with no rate limiting falls to brute force, the dashboard&amp;rsquo;s ORDER BY sort is blind-SQL-injectable, and the home-made sanitizer only strips &amp;lsquo;&amp;lt;&amp;rsquo; — so boolean extraction with &amp;lsquo;&amp;gt;&amp;rsquo; dumps the secrets table.</description>
    </item>
    <item>
      <title>Simple Food Notifications — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/simple-food-notifications/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/simple-food-notifications/</guid>
      <description>A Flask meal-notification SSRF whose is_global filter is defeated by abusing urllib3&amp;rsquo;s retry-driven DNS re-resolution — a global IP that hangs on port 80 (8.8.8.8) outlasts dnsmasq&amp;rsquo;s 2s cache, so the retry re-resolves to 127.0.0.1 and reaches the localhost-only /vip-meal.</description>
    </item>
    <item>
      <title>Spaetzle — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/spaetzle/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/spaetzle/</guid>
      <description>An MD5-only oracle over arbitrary paths is turned into a full file disclosure using the error-based PHP filter-chain oracle to leak /flag byte-by-byte.</description>
    </item>
    <item>
      <title>Tiny Web — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/tiny-web/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/tiny-web/</guid>
      <description>A one-line Node server lets you inject a rel=stylesheet entry into the Link response header, which Firefox applies to the flag-bearing page, enabling CSS attribute-selector exfiltration of the cookie.</description>
    </item>
    <item>
      <title>Warmer Up — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/forensics/warmer-up/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/forensics/warmer-up/</guid>
      <description>The challenge file is the CTF&amp;rsquo;s own rules PDF — the flag sits in plain text as the last line; pdftotext reveals it, after ruling out post-EOF carving and active content.</description>
    </item>
    <item>
      <title>Warmerer Up — DalCTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/forensics/warmerer-up/</link>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/dalctf-2026/forensics/warmerer-up/</guid>
      <description>A 4.9 MB rules PDF hides 360 fake 1×1 image XObjects holding base64 chunks that reassemble into an encrypted ZIP; the password is hidden in the rules text, inside is a Singularity .sif whose squashfs holds the flag.</description>
    </item>
    <item>
      <title>COMpetition — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/crypto/competition/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/crypto/competition/</guid>
      <description>A commit-reveal rock-paper-scissors whose non-binding sha256(r1 + message + r2) commitment lets you open one hash to any winning move and sweep all 100 rounds.</description>
    </item>
    <item>
      <title>Double Fried — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/misc/double-fried/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/misc/double-fried/</guid>
      <description>A pcap leaks a flag one character per syslog packet in scrambled order, and sorting by each packet&amp;rsquo;s Message ID field reassembles the flag.</description>
    </item>
    <item>
      <title>Easy DSA — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/crypto/easy-dsa/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/crypto/easy-dsa/</guid>
      <description>A P-521 ECDSA oracle derives its nonce from an MD5-based uuid3, so an MD5 collision forces nonce reuse, leaks the private key, and lets us forge a signature for the flag.</description>
    </item>
    <item>
      <title>Fancy Food Notifications — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/fancy-food-notifications/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/fancy-food-notifications/</guid>
      <description>Chaining a weak RNG seed (258 possible HMAC keys), an SSRF token leak, a urlparse vs urllib3 parser differential, and a URL-userinfo Basic-auth override to forge a VIP JWT and reach /vip-meal as localhost.</description>
    </item>
    <item>
      <title>Königsberg Delivery Problem — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/reversing/konigsberg-delivery-problem/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/reversing/konigsberg-delivery-problem/</guid>
      <description>Reversing a 250-state control-flow-flattened automaton whose success check requires visiting every state — i.e. finding a Hamiltonian path through the transition graph.</description>
    </item>
    <item>
      <title>Leftover Leftovers — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/reversing/leftover-leftovers/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/reversing/leftover-leftovers/</guid>
      <description>A two-stage Java AOT-cache app whose integrity hash covers bytecode and pointers but not the archived heap — patching the pre-resolved heap String redirects the image directory and reads /flag.</description>
    </item>
    <item>
      <title>Leftovers — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/reversing/leftovers/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/reversing/leftovers/</guid>
      <description>Reversing a Javalin app whose real password validator lives in an AOT/CDS cache that overrides the jar — dumping the loaded class with the HotSpot Serviceability Agent unlocks a file-read to /flag.</description>
    </item>
    <item>
      <title>Paradise Nut — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/misc/paradise-nut/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/misc/paradise-nut/</guid>
      <description>Abusing pnut-sh&amp;rsquo;s C-to-shell codegen, where a C local named REPLY aliases the tainted shell $REPLY from gets() and detonates command execution via bash arithmetic to run the setuid nl on /flag.</description>
    </item>
    <item>
      <title>Recipe for Disaster — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/pwning/recipe-for-disaster/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/pwning/recipe-for-disaster/</guid>
      <description>A food-ordering binary reads chef notes with gets() into a buffer sitting in front of an int price field, letting an overflow set a negative price that makes the order total negative and prints /flag.</description>
    </item>
    <item>
      <title>Restaurant Builder — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/restaurant-builder/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/web/restaurant-builder/</guid>
      <description>A FastAPI app builds Pydantic models from user-supplied field definitions, where each string value is eval()ed as a forward-reference annotation, yielding arbitrary code execution and flag exfiltration via the JSON schema.</description>
    </item>
    <item>
      <title>Volatile Component — GPN CTF 2026</title>
      <link>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/misc/volatile-component/</link>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/ctf/gpn-ctf-2026/misc/volatile-component/</guid>
      <description>Exploiting a GitHub Actions workflow that interpolates an untrusted issue body into a run block, gaining RCE to dump the FLAG secret from the Runner.Worker process memory and exfiltrating it as hex to bypass log masking.</description>
    </item>
    <item>
      <title>About</title>
      <link>https://th3b0ywh0l1v3d.github.io/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/about/</guid>
      <description>about</description>
    </item>
  </channel>
</rss>
