Skip to content

01 / The reading desk

Blog.

Security research, CTF writeups, and things I’ve learned along the way.

16 published articles

Browse the archive

Latest from the desk

PatchStack CTF 2025: End-of-the-year Alliance Capture the Flag

The challenge involves a WordPress plugin named "AI Trust Score" (located in wp-content/plugins/ai-badbots/ai-badbots.php). This plugin uses AI heuristics to assign a "trust score" to incoming request...

More from the archive

15 articles

Patchstack Aliance CTF S02E03 - WordCamp Europe

The endpoint /wp-json/ghostly/v1/login is a custom REST route in the WordPress backend. Here’s the kicker:Here’s the vulnerable PHP handler logic (as reverse-engineered from the behavior):This effecti...

CTF

Patchstack Alliance CTF S01E01

In the recent Patchstack Alliance CTF S01E01, I am thrilled to share that I earned 2nd place and successfully solved all the challenges presented. Below is my detailed write-up of each challenge:In th...

wordpressCTF

Patchstack WCUS CTF Writeup 2024

Last weekend, I participated in the Patchstack WCUS CTF and solved all the WordPress challenges. Here's my write-up for each challenge from the Patchstack WCUS CTF 2024.My area have some kind of dynas...

CTF

Wiki World

Can you alpha test out our newest note-taking website? (If you find anything, please report it to us using nc cha.hackpack.club 8702)Also unrelatedly, our website admin is really fond of the wiki-wor...

SecurityWeb

X Et Et

solver.py index.htmlThere are several steps to achieve RCE:Those are the steps required to work on this challenge. For the rest, you can refer to the solve script above to see the execution flow.After...

CTFWeb

Spurdo Enbinling

Spurdo decided to develop a web game while he was solo leveling. But due to lack of skill, spurdo developed a game that cannot be completed by anyone sane enough. And because of that he decided to inv...

Web

Looking for something shorter?

My notebook is where quick references and works in progress live.

Open the notebook