60 notes to explore
My-CTF-Challenges — Hard AI Benchmark (4873f89c)
The initial synchronized set contains three solved, four timed out, and one blocked record. After replacing the two withheld shortcut-affected baselines with repaired revisions, the current eligible s...
Rare Web CTF Challenges — 0–2 Solves
Checked 10 September 2026. Scope: difficult Web and browser-adjacent challenges for reference and candidate-primitive research.
TFC CTF 2026 — Under 20 Solves
Checked on 7 September 2026 (Asia/Makassar). Filter: strictly fewer than 20 solves, across all 29 challenges. Three challenges qualify; all are WEB.This is a research-status note. No matching solution...
Forensics
Flag: SAS{1_d1d_my_f1rst_add_5_when_1_w4s_7} (submit verbatim — the drawn image has no _ between a and dd_5)Flag: RTRTNI26{43.431, 39.933} — server-validated First Blood, 300 base points + 20 bonus.
YAML
The vulnerability stems from how YAML aliasing interacts with delayed data mutation.Initially, the validation loop checks conf["blogs"][0]["name"]. Later in the execution, the code applies a transform...
Unicode
Unicode trick we can input this to get single quote ȧ><h1>123</h1>level js library injection because the code uses db to read/write post instead of dbPost.
CVE
CVE-2024-51417 is a vulnerability in System.Linq.Dynamic.Core that allows remote access to properties on reflection types and static properties/fields, leading to RCE.
Javascript
Bypass forbidden characters in Javascript when special characters are blacklisted.Forbidden Characters:Bypass Method 1: Using instanceof and array syntaxBypass Method 2: Using Symbol.hasInstanceWhen a...
SSRF
justctf 2023 https://gist.github.com/TrixterTheTux/99c1da88ebdc7bd3de224ef500f01178https://www.serv-u.com/resources/tutorial/pasv-response-epsv-port-pbsz-rein-ftp-command#:~:text=(p1%20*%20256)%20%2B%...
CSSLeak
paper: TLDR; Leaking CSS selectors without network exfiltration. I spent a lot of time trying to use crashing payloads but took too long, ended up being able to use the <object> tag to count frames co...
XXE
https://mohemiv.com/all/evil-xml/https://github.com/zeyu2001/My-CTF-Challenges/tree/main/SEETF-2023/ezxxeTETCTF2022- transform2newyear & admin portalthis is the challenge i've made with <@268513122740...
ja3
faking ja3 fingerprinthttps://balsnctf.com/challenges#0FA-23Route the runner took: it ruled out smuggling HTTP_SSL_JA3 as a request header from the module source (the add-on registers an explicit $htt...
Electron
https://github.com/maple3142/My-CTF-Challenges/blob/master/HITCON%20CTF%202023/Harmony/dist/client/electron/preload.tshttps://github.com/maple3142/My-CTF-Challenges/blob/master/HITCON%20CTF%202023/Har...
HTMX
![[Pasted image 20230620190834.png]]https://htmx.org/attributes/hx-disable/#:~:text=The%20hx%2Ddisable%20attribute%20will,to%20prevent%20malicious%20scripting%20attacks gpn ctf 2023ctf/2024/linectf/we...
DOM CLOBERING
this will createtested: firefox v102seccon quals 2023 “blink web”payloadsadly this technique will thor error if we don’t use something like this to wrap the document objectChallenges - Blue Water CTF...
Client Side Desync Attack
https://mizu.re/post/abusing-client-side-desync-on-werkzeughttps://github.com/zeyu2001/My-CTF-Challenges/tree/main/SEETF-2023/now-you-c-meSetup. 3 services in one net namespace: Node proxy:3000 (rever...
Curl
we can use like {} below to bypass blacklistin curl we can use -k option without any space to specify a curl config fileexample in htbctf 2024 challenge percetron https://trixterthetux.notion.site/HTB...
Redis
redis.Ring does not check what shards you access. redis.Del on several keys will execute only on the shard of the first key, which can lead to an inconsistent state where some keys exist for a deleted...
Puppetter / playwright
The challenge idea is based on finding this issue: https://github.com/puppeteer/puppeteer/issues/13840Unitended, use window.playwright__binding("foobar") for crashing the playwringt and do leak from t...
Python
payloadthats make the innerHTML is appended into non iframe tagfun fact yang easy bisa pakai ipv6 dan itu support scope id seperationhttps://github.com/python/cpython/blob/49fb75c676bd422b03aef9824d1...
Quic
let me put this challenge clearly for those who didnt got what actually is 0rtt replay attack so basically in tls 1.3, client sends a clienthello along with some ciphers to use then server acknowledge...
Pyjail
golfadvancedrestore builtinshttps://github.com/BYU-CSA/BYUCTF-2023/tree/main/builtins-2imaginary-ctf 2023https://peps.python.org/pep-0560/#:~:text=The idea of class_getitem is simple%3A it is,to avoid...
BUN
Overall verdict: FAIL — the valid clean attempt solved in 23m44s, before the 60-minute resistance threshold.BUN null injection ASIS CTF 2023ASIS CTF 2023for hello again: - find the /src:/[path] hardco...
gRPC
This only works locally because the server behaves differently. There are actually two types of identifiers from the package we send: one for the handler and one for the message type. To create type c...
ZipSlip
vulnerable codewe can do this to gain arbitrary file writevulnerable codetar versiThe unzip logic is defined in the file ZipArchive.java:But oops, it looks like the zip file entries are not sanitised,...
Mongo
this mongo db version is vulnerable to log4jhttps://community.progress.com/s/article/blackduck-identified-vulnerability-with-mongodb#:~:text=BlackDuck%20identified%20vulnerability%20log4j%201.2.25%20i...
Dompurify
https://mizu.re/post/exploring-the-dompurify-library-hunting-for-misconfigurations#beforeSanitizeAttributes-manipulationThe solution for 🌱🌱 is mxss with transferring a style tag in xhtml namespace...
Cache Poisoning / Cache Probing
cache poisoning using request smuglingchunky unintended: GET /{user_id}/.well-known/jwks.json /../../..{post_url} server thinks its http/0.9 and it caches the response no transfer-encoding stuff neede...
DNS
localhost.7chn.me -> 127.0.0.1foobar.n.7chn.me -> your serverworking in selenium==4.27.1https://github.com/DownUnderCTF/Challenges_2023_Public/blob/main/misc/mini-dns-server/solve/solv.pyIt is to brin...
Java
us-18-Haken-Automated-Discovery-of-Deserialization-Gadget-Chains-wp.pdfcorlang: use this twice to get your karma > 10disconnect and reconnect${tokenRepo.findAll()[0].value} to get the flagAt this poin...
SQL
https://swisskyrepo.github.io/PayloadsAllTheThings/SQL Injection/PostgreSQL Injection/#postgresql-file-writeInstallations running Postgres 9.3 and above have functionality which allows for the superus...
Golang
err is shared between handler calls and therefore, we can race the checkPath call and the err != nil check.https://caddyserver.com/docs/modules/http.handlers.templateshttps://github.com/sohomdatta1/so...
Docker
l3hctf 2024https://s1um4i-official.feishu.cn/docx/QeGGdeyuhoR6kuxCOj8c44wRnne#SfxUd5lMRoxkfCx1G7HcrCTbnobdetailed WU can be see there https://hust-l3hsec.feishu.cn/docx/MZ8SdwSoPo3cBTxOxbGcuUBun4cln -...
Browser
the challenge use FROM node:16-alpine3.16 which bundle Chrome version 102, and can be used to gain RCE.CTFtime.org / Google Capture The Flag 2025 / Sourceless / WriteupNotice that the bot runs Chromiu...
nginx
You can do something like this to do path traversal echo -e “GET /%2f%2f/%2f%2f/%2f%2f/%2f%2f/%2f%2f/../../../../../../opt/flag.txt HTTP/1.1: centvps.centaurushook.xyz” | nc centvps.centaurushook.xyz...
Wordpress
un-authenticated admin endpoint/wp-admin/admin-post.phpwhereis_admin()returnstrueand still recommending EOL PHP 7.4 (https://wordpress.org/download/)WordPress Plugin Security Testing Cheat Sheet · wps...
CSP Bypass
To avoid leaking path information cross-origin (as discussed in Egor Homakov’s Using Content-Security-Policy for Evil), the matching algorithm ignores the path component of a source expression if the...
CSRF
teknik solve lain untuk adminplz, pakai dns rebinding attack untuk bypass same-origin-policy(for adminplz) Thanks for the 0.0.0.0 tip. That worked for me! I host this page locally:and then submit a UR...
Bash
there’s some strange behaviour in bash version 5.0.3(1)-release (in version 5.2.26 doesn’t work) where array such as this will execute header_namethis is vulnerable too from kalmarctf 2024this works t...
SSTI
**Using MRO and subclasses to access subprocess.Popen:**This accesses the base object class via MRO, gets all subclasses, and uses index 399 (subprocess.Popen) to execute shell commands.AI writeup (co...
XSLeak
for ad-note I had a solution that was too slow but still interesting. By setting the attribute name=NAME, all ad iframes get the the name NAME, and reading on the window reference .NAME would return t...
React / NextJS / Svelte
You can only read valid json file exampleall you need is a file with //#sourceMappingURL= in it, and then the file you want to exfilitrate (it must be valid json though, which is why the dockerfile w...
Leak
https://gist.github.com/tyage/3bb2b730c67b363a26b45699ca34b22ahttps://hackmd.io/@r2dev2/S1P0RYHYke#WebNot sure if anyone else used this trick From the xs leak via cpu microarchitectual attack dream (e...
Node / JS
https://hackerone.com/reports/2819573Referensi dari sini:https://stackoverflow.com/questions/35949554/invoking-a-function-without-parenthesesCheck jawaban nomer 7https://github.com/daffainfo/ctf-write...
Crypto Web
pingCTF 20231753CTF ## ZerodayUntitled example program from TAMUCTF 2024exploittamuctf-2024/web/cracked at master · tamuctf/tamuctf-2024 (github.com)l34k CTF 2024AKASEC CTF 2024 | Rusty RoadsolverWrit...
PHP
Proxy / WAF Protections Bypass | hacktricksNginx FPM configuration:CopyNginx is configured to block access to /admin.php but it's possible to bypass this by accessing /admin.php/index.php.Copytl;dr ab...
XSS
localhost.7chn.me -> 127.0.0.1foobar.n.7chn.me -> your serveri was definitely wrong. The A=>B->A (we abuse this relationship to cache our payload and trigger XSS) is strictly considered same site (htt...