<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>dimasc.tf — Blog &amp; Notes</title>
    <description>Security research, CTF writeups, and technical notes by Dimas Maulana.</description>
    <link>https://dimasc.tf/</link>
    <atom:link href="https://dimasc.tf/rss.xml" rel="self" type="application/rss+xml" />
    <language>en</language>
    <managingEditor>noreply@dimasc.tf (Dimas Maulana)</managingEditor>
    <webMaster>noreply@dimasc.tf (Dimas Maulana)</webMaster>
    <generator>Custom RSS Generator</generator>
    <item>
      <title>My-CTF-Challenges — Hard AI Benchmark (4873f89c)</title>
      <link>https://dimasc.tf/notes/my-ctf-challenges-hard-ai-benchmark-4873f89c/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/my-ctf-challenges-hard-ai-benchmark-4873f89c/</guid>
      <description>The initial synchronized set contains three solved, four timed out, and one blocked record. After replacing the two withheld shortcut-affected baselines with repaired revisions, the current eligible s...</description>
      <pubDate>Fri, 11 Sep 2026 00:10:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Rare Web CTF Challenges — 0–2 Solves</title>
      <link>https://dimasc.tf/notes/rare-web-ctf-challenges-0-2-solves/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/rare-web-ctf-challenges-0-2-solves/</guid>
      <description>Checked 10 September 2026. Scope: difficult Web and browser-adjacent challenges for reference and candidate-primitive research.</description>
      <pubDate>Thu, 10 Sep 2026 04:07:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
      <category>Analysis</category>
    </item>
    <item>
      <title>TFC CTF 2026 — Under 20 Solves</title>
      <link>https://dimasc.tf/notes/tfc-ctf-2026-under-20-solves/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/tfc-ctf-2026-under-20-solves/</guid>
      <description>Checked on 7 September 2026 (Asia/Makassar). Filter: strictly fewer than 20 solves, across all 29 challenges. Three challenges qualify; all are WEB.This is a research-status note. No matching solution...</description>
      <pubDate>Mon, 07 Sep 2026 06:33:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
      <category>Analysis</category>
    </item>
    <item>
      <title>Forensics</title>
      <link>https://dimasc.tf/notes/forensics/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/forensics/</guid>
      <description>Flag: SAS{1_d1d_my_f1rst_add_5_when_1_w4s_7}  (submit verbatim — the drawn image has no _ between a and dd_5)Flag: RTRTNI26{43.431, 39.933} — server-validated First Blood, 300 base points + 20 bonus.</description>
      <pubDate>Mon, 08 Jun 2026 00:20:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>https://dimasc.tf/notes/path-traversal/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/path-traversal/</guid>
      <description></description>
      <pubDate>Wed, 08 Apr 2026 04:51:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Pwn</title>
      <link>https://dimasc.tf/notes/pwn/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/pwn/</guid>
      <description></description>
      <pubDate>Mon, 09 Mar 2026 22:29:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Codex</title>
      <link>https://dimasc.tf/notes/codex/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/codex/</guid>
      <description></description>
      <pubDate>Mon, 09 Mar 2026 08:34:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Programming</category>
    </item>
    <item>
      <title>YAML</title>
      <link>https://dimasc.tf/notes/yaml/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/yaml/</guid>
      <description>The vulnerability stems from how YAML aliasing interacts with delayed data mutation.Initially, the validation loop checks conf[&quot;blogs&quot;][0][&quot;name&quot;]. Later in the execution, the code applies a transform...</description>
      <pubDate>Wed, 11 Feb 2026 08:06:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
      <category>Programming</category>
    </item>
    <item>
      <title>PatchStack CTF 2025: End-of-the-year Alliance Capture the Flag</title>
      <link>https://dimasc.tf/posts/patchstack-ctf-2025-end-of-the-year-alliance-captu/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/patchstack-ctf-2025-end-of-the-year-alliance-captu/</guid>
      <description>The challenge involves a WordPress plugin named &quot;AI Trust Score&quot; (located in wp-content/plugins/ai-badbots/ai-badbots.php). This plugin uses AI heuristics to assign a &quot;trust score&quot; to incoming request...</description>
      <pubDate>Sun, 21 Dec 2025 12:21:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>wordpress</category>
      <category>CTF</category>
    </item>
    <item>
      <title>GIT</title>
      <link>https://dimasc.tf/notes/git/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/git/</guid>
      <description>ASIS CTF 2024git log to rce using textconvsolverASIS CTF Final 2024 - gitmails (web)</description>
      <pubDate>Tue, 11 Nov 2025 03:54:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
    </item>
    <item>
      <title>SAML</title>
      <link>https://dimasc.tf/notes/saml/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/saml/</guid>
      <description></description>
      <pubDate>Tue, 11 Nov 2025 00:59:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Unicode</title>
      <link>https://dimasc.tf/notes/unicode/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/unicode/</guid>
      <description>Unicode trick we can input this to get single quote ȧ&gt;&lt;h1&gt;123&lt;/h1&gt;level js library injection because the code uses db to read/write post instead of dbPost.</description>
      <pubDate>Thu, 23 Oct 2025 02:01:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Programming</category>
    </item>
    <item>
      <title>Dangling Markup Attacks</title>
      <link>https://dimasc.tf/notes/dangling-markup-attacks/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/dangling-markup-attacks/</guid>
      <description></description>
      <pubDate>Mon, 20 Oct 2025 02:52:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>CVE</title>
      <link>https://dimasc.tf/notes/cve/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/cve/</guid>
      <description>CVE-2024-51417 is a vulnerability in System.Linq.Dynamic.Core that allows remote access to properties on reflection types and static properties/fields, leading to RCE.</description>
      <pubDate>Wed, 24 Sep 2025 03:54:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
    </item>
    <item>
      <title>Javascript</title>
      <link>https://dimasc.tf/notes/javascript/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/javascript/</guid>
      <description>Bypass forbidden characters in Javascript when special characters are blacklisted.Forbidden Characters:Bypass Method 1: Using instanceof and array syntaxBypass Method 2: Using Symbol.hasInstanceWhen a...</description>
      <pubDate>Fri, 12 Sep 2025 07:36:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
    <item>
      <title>Patchstack Aliance CTF S02E03 - WordCamp Europe</title>
      <link>https://dimasc.tf/posts/patchstack-aliance-ctf-s02e03-wordcamp-europe/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/patchstack-aliance-ctf-s02e03-wordcamp-europe/</guid>
      <description>The endpoint /wp-json/ghostly/v1/login is a custom REST route in the WordPress backend. Here’s the kicker:Here’s the vulnerable PHP handler logic (as reverse-engineered from the behavior):This effecti...</description>
      <pubDate>Sun, 08 Jun 2025 03:29:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>SSRF</title>
      <link>https://dimasc.tf/notes/ssrf/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/ssrf/</guid>
      <description>justctf 2023
https://gist.github.com/TrixterTheTux/99c1da88ebdc7bd3de224ef500f01178https://www.serv-u.com/resources/tutorial/pasv-response-epsv-port-pbsz-rein-ftp-command#:~:text=(p1%20*%20256)%20%2B%...</description>
      <pubDate>Mon, 02 Jun 2025 11:30:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Tutorial</category>
    </item>
    <item>
      <title>CSSLeak</title>
      <link>https://dimasc.tf/notes/cssleak/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/cssleak/</guid>
      <description>paper:
TLDR; Leaking CSS selectors without network exfiltration. I spent a lot of time trying to use crashing payloads but took too long, ended up being able to use the &lt;object&gt; tag to count frames co...</description>
      <pubDate>Mon, 02 Jun 2025 11:27:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
    <item>
      <title>XXE</title>
      <link>https://dimasc.tf/notes/xxe/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/xxe/</guid>
      <description>https://mohemiv.com/all/evil-xml/https://github.com/zeyu2001/My-CTF-Challenges/tree/main/SEETF-2023/ezxxeTETCTF2022- transform2newyear &amp; admin portalthis is the challenge i&apos;ve made with &lt;@268513122740...</description>
      <pubDate>Mon, 02 Jun 2025 11:25:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Latex</title>
      <link>https://dimasc.tf/notes/latex/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/latex/</guid>
      <description>SCTF 2024 By W&amp;M - W&amp;M Team</description>
      <pubDate>Sat, 31 May 2025 04:13:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>ja3</title>
      <link>https://dimasc.tf/notes/ja3/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/ja3/</guid>
      <description>faking ja3 fingerprinthttps://balsnctf.com/challenges#0FA-23Route the runner took: it ruled out smuggling HTTP_SSL_JA3 as a request header from the module source (the add-on registers an explicit $htt...</description>
      <pubDate>Sat, 31 May 2025 04:07:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Electron</title>
      <link>https://dimasc.tf/notes/electron/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/electron/</guid>
      <description>https://github.com/maple3142/My-CTF-Challenges/blob/master/HITCON%20CTF%202023/Harmony/dist/client/electron/preload.tshttps://github.com/maple3142/My-CTF-Challenges/blob/master/HITCON%20CTF%202023/Har...</description>
      <pubDate>Sat, 31 May 2025 04:06:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>HTMX</title>
      <link>https://dimasc.tf/notes/htmx/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/htmx/</guid>
      <description>![[Pasted image 20230620190834.png]]https://htmx.org/attributes/hx-disable/#:~:text=The%20hx%2Ddisable%20attribute%20will,to%20prevent%20malicious%20scripting%20attacks
gpn ctf 2023ctf/2024/linectf/we...</description>
      <pubDate>Sat, 31 May 2025 04:05:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>DOM CLOBERING</title>
      <link>https://dimasc.tf/notes/dom-clobering/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/dom-clobering/</guid>
      <description>this will createtested: firefox v102seccon quals 2023 “blink web”payloadsadly this technique will thor error if we don’t use something like
this to wrap the document objectChallenges - Blue Water CTF...</description>
      <pubDate>Sat, 31 May 2025 04:04:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
    </item>
    <item>
      <title>Client Side Desync Attack</title>
      <link>https://dimasc.tf/notes/client-side-desync-attack/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/client-side-desync-attack/</guid>
      <description>https://mizu.re/post/abusing-client-side-desync-on-werkzeughttps://github.com/zeyu2001/My-CTF-Challenges/tree/main/SEETF-2023/now-you-c-meSetup. 3 services in one net namespace: Node proxy:3000 (rever...</description>
      <pubDate>Sat, 31 May 2025 04:03:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
    </item>
    <item>
      <title>Curl</title>
      <link>https://dimasc.tf/notes/curl/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/curl/</guid>
      <description>we can use like {} below to bypass blacklistin curl we can use -k option without any space to specify a curl
config fileexample in htbctf 2024 challenge percetron
https://trixterthetux.notion.site/HTB...</description>
      <pubDate>Sat, 31 May 2025 04:02:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>C</title>
      <link>https://dimasc.tf/notes/c/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/c/</guid>
      <description></description>
      <pubDate>Sat, 31 May 2025 04:01:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Redis</title>
      <link>https://dimasc.tf/notes/redis/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/redis/</guid>
      <description>redis.Ring does not check what shards you access. redis.Del on several keys will execute only on the shard of the first key, which can lead to an inconsistent state where some keys exist for a deleted...</description>
      <pubDate>Tue, 27 May 2025 06:52:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Puppetter / playwright</title>
      <link>https://dimasc.tf/notes/puppetter-playwright/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/puppetter-playwright/</guid>
      <description>The challenge idea is based on finding this issue: https://github.com/puppeteer/puppeteer/issues/13840Unitended, use window.playwright__binding(&quot;foobar&quot;) for crashing the playwringt and do leak from t...</description>
      <pubDate>Mon, 05 May 2025 06:32:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Python</title>
      <link>https://dimasc.tf/notes/python/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/python/</guid>
      <description>payloadthats make the innerHTML is appended into non iframe tagfun fact yang easy  bisa pakai ipv6 dan itu support scope id seperationhttps://github.com/python/cpython/blob/49fb75c676bd422b03aef9824d1...</description>
      <pubDate>Mon, 28 Apr 2025 09:35:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
    <item>
      <title>Quic</title>
      <link>https://dimasc.tf/notes/quic/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/quic/</guid>
      <description>let me put this challenge clearly for those who didnt got what actually is 0rtt replay attack
so basically in tls 1.3, client sends a clienthello along with some ciphers to use then server acknowledge...</description>
      <pubDate>Mon, 28 Apr 2025 09:10:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Pyjail</title>
      <link>https://dimasc.tf/notes/pyjail/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/pyjail/</guid>
      <description>golfadvancedrestore builtinshttps://github.com/BYU-CSA/BYUCTF-2023/tree/main/builtins-2imaginary-ctf 2023https://peps.python.org/pep-0560/#:~:text=The idea of class_getitem is simple%3A it is,to avoid...</description>
      <pubDate>Tue, 22 Apr 2025 04:03:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Elixir</title>
      <link>https://dimasc.tf/notes/elixir/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/elixir/</guid>
      <description></description>
      <pubDate>Tue, 22 Apr 2025 03:47:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>BUN</title>
      <link>https://dimasc.tf/notes/bun/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/bun/</guid>
      <description>BUN null injection ASIS CTF 2023ASIS CTF 2023for hello again: - find the /src:/[path] hardcoded
endpoint in bun’s debug mode that launches an editor on the system (why
is this enabled by default? wtf?...</description>
      <pubDate>Tue, 08 Apr 2025 14:32:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Programming</category>
    </item>
    <item>
      <title>gRPC</title>
      <link>https://dimasc.tf/notes/grpc/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/grpc/</guid>
      <description>This only works locally because the server behaves differently. There are actually two types of identifiers from the package we send: one for the handler and one for the message type. To create type c...</description>
      <pubDate>Thu, 27 Mar 2025 06:46:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Bypass</title>
      <link>https://dimasc.tf/notes/bypass/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/bypass/</guid>
      <description></description>
      <pubDate>Thu, 27 Mar 2025 03:07:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>ZipSlip</title>
      <link>https://dimasc.tf/notes/zipslip/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/zipslip/</guid>
      <description>vulnerable codewe can do this to gain arbitrary file writevulnerable codetar versiThe unzip logic is defined in the file ZipArchive.java:But oops, it looks like the zip file entries are not sanitised,...</description>
      <pubDate>Thu, 27 Mar 2025 02:39:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Programming</category>
    </item>
    <item>
      <title>Mongo</title>
      <link>https://dimasc.tf/notes/mongo/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/mongo/</guid>
      <description>this mongo db version is vulnerable to log4jhttps://community.progress.com/s/article/blackduck-identified-vulnerability-with-mongodb#:~:text=BlackDuck%20identified%20vulnerability%20log4j%201.2.25%20i...</description>
      <pubDate>Mon, 17 Mar 2025 13:47:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
    </item>
    <item>
      <title>Dompurify</title>
      <link>https://dimasc.tf/notes/dompurify/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/dompurify/</guid>
      <description>https://mizu.re/post/exploring-the-dompurify-library-hunting-for-misconfigurations#beforeSanitizeAttributes-manipulationThe solution for 🌱🌱  is mxss with transferring a style tag in xhtml namespace...</description>
      <pubDate>Mon, 17 Mar 2025 02:53:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
    <item>
      <title>Cache Poisoning / Cache Probing</title>
      <link>https://dimasc.tf/notes/cache-poisoning-cache-probing/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/cache-poisoning-cache-probing/</guid>
      <description>cache poisoning using request smuglingchunky unintended:
GET /{user_id}/.well-known/jwks.json /../../..{post_url}
server thinks its http/0.9 and it caches the response no
transfer-encoding stuff neede...</description>
      <pubDate>Fri, 14 Mar 2025 06:40:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>DNS</title>
      <link>https://dimasc.tf/notes/dns/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/dns/</guid>
      <description>localhost.7chn.me -&gt; 127.0.0.1foobar.n.7chn.me -&gt; your serverworking in selenium==4.27.1https://github.com/DownUnderCTF/Challenges_2023_Public/blob/main/misc/mini-dns-server/solve/solv.pyIt is to brin...</description>
      <pubDate>Thu, 13 Mar 2025 10:33:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Java</title>
      <link>https://dimasc.tf/notes/java/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/java/</guid>
      <description>us-18-Haken-Automated-Discovery-of-Deserialization-Gadget-Chains-wp.pdfcorlang:
use this twice to get your karma &gt; 10disconnect and reconnect${tokenRepo.findAll()[0].value}
to get the flagAt this poin...</description>
      <pubDate>Thu, 13 Mar 2025 00:52:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>SQL</title>
      <link>https://dimasc.tf/notes/sql/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/sql/</guid>
      <description>https://swisskyrepo.github.io/PayloadsAllTheThings/SQL Injection/PostgreSQL Injection/#postgresql-file-writeInstallations running Postgres 9.3 and above have functionality which allows for the superus...</description>
      <pubDate>Wed, 12 Mar 2025 12:02:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Golang</title>
      <link>https://dimasc.tf/notes/golang/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/golang/</guid>
      <description>err is shared between handler calls and therefore, we can race the checkPath call and the err != nil check.https://caddyserver.com/docs/modules/http.handlers.templateshttps://github.com/sohomdatta1/so...</description>
      <pubDate>Wed, 12 Mar 2025 10:26:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Docker</title>
      <link>https://dimasc.tf/notes/docker/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/docker/</guid>
      <description>l3hctf 2024https://s1um4i-official.feishu.cn/docx/QeGGdeyuhoR6kuxCOj8c44wRnne#SfxUd5lMRoxkfCx1G7HcrCTbnobdetailed WU can be see there
https://hust-l3hsec.feishu.cn/docx/MZ8SdwSoPo3cBTxOxbGcuUBun4cln -...</description>
      <pubDate>Wed, 12 Mar 2025 08:22:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Browser</title>
      <link>https://dimasc.tf/notes/browser/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/browser/</guid>
      <description>the challenge use FROM node:16-alpine3.16 which bundle Chrome version 102, and can be used to gain RCE.CTFtime.org / Google Capture The Flag 2025 / Sourceless / WriteupNotice that the bot runs Chromiu...</description>
      <pubDate>Tue, 04 Mar 2025 04:28:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
    </item>
    <item>
      <title>nginx</title>
      <link>https://dimasc.tf/notes/nginx/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/nginx/</guid>
      <description>You can do something like this to do path traversal echo -e “GET
/%2f%2f/%2f%2f/%2f%2f/%2f%2f/%2f%2f/../../../../../../opt/flag.txt
HTTP/1.1: centvps.centaurushook.xyz” | nc centvps.centaurushook.xyz...</description>
      <pubDate>Tue, 04 Mar 2025 04:23:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Wordpress</title>
      <link>https://dimasc.tf/notes/wordpress/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/wordpress/</guid>
      <description>un-authenticated admin endpoint/wp-admin/admin-post.phpwhereis_admin()returnstrueand still recommending EOL PHP 7.4 (https://wordpress.org/download/)WordPress
Plugin Security Testing Cheat Sheet · wps...</description>
      <pubDate>Mon, 24 Feb 2025 10:25:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
    </item>
    <item>
      <title>Patchstack Alliance CTF S02E01 - WordCamp Asia</title>
      <link>https://dimasc.tf/posts/patchstack-alliance-ctf-s02e01-wordcamp-asia/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/patchstack-alliance-ctf-s02e01-wordcamp-asia/</guid>
      <description>Last weekend, I participated in the Patchstack WCUS CTF and solved all the WordPress challenges. Here&apos;s my write-up for each challenge from the Patchstack WCUS CTF 2025.Using Semgrep and my Semgrep cu...</description>
      <pubDate>Sun, 23 Feb 2025 13:15:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>wordpress</category>
      <category>CTF</category>
    </item>
    <item>
      <title>CSP Bypass</title>
      <link>https://dimasc.tf/notes/csp-bypass/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/csp-bypass/</guid>
      <description>To avoid leaking path information cross-origin (as discussed in Egor Homakov’s Using Content-Security-Policy for Evil), the matching algorithm ignores the path component of a source expression if the...</description>
      <pubDate>Sun, 16 Feb 2025 00:52:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
      <category>Programming</category>
    </item>
    <item>
      <title>CSRF</title>
      <link>https://dimasc.tf/notes/csrf/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/csrf/</guid>
      <description>teknik solve lain untuk adminplz, pakai dns rebinding attack untuk
bypass same-origin-policy(for adminplz) Thanks for the 0.0.0.0 tip. That worked for me! I host
this page locally:and then submit a UR...</description>
      <pubDate>Fri, 14 Feb 2025 14:04:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Bash</title>
      <link>https://dimasc.tf/notes/bash/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/bash/</guid>
      <description>there’s some strange behaviour in bash version 5.0.3(1)-release (in
version 5.2.26 doesn’t work) where array such as this will execute
header_namethis is vulnerable too from kalmarctf 2024this works t...</description>
      <pubDate>Mon, 10 Feb 2025 13:01:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>SSTI</title>
      <link>https://dimasc.tf/notes/ssti/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/ssti/</guid>
      <description>**Using MRO and subclasses to access subprocess.Popen:**This accesses the base object class via MRO, gets all subclasses, and uses index 399 (subprocess.Popen) to execute shell commands.AI writeup (co...</description>
      <pubDate>Mon, 10 Feb 2025 11:41:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>XSLeak</title>
      <link>https://dimasc.tf/notes/xsleak/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/xsleak/</guid>
      <description>for ad-note I had a solution that was too slow but still interesting. By setting the attribute name=NAME, all ad iframes get the the name NAME, and reading on the window reference .NAME would return t...</description>
      <pubDate>Mon, 10 Feb 2025 11:29:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>React / NextJS / Svelte</title>
      <link>https://dimasc.tf/notes/react-nextjs-svelte/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/react-nextjs-svelte/</guid>
      <description>You can  only read valid json file exampleall you need is a file with //#sourceMappingURL= in it, and then the file you want to exfilitrate (it must be valid json though, which is why the dockerfile w...</description>
      <pubDate>Mon, 10 Feb 2025 08:58:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
    <item>
      <title>Leak</title>
      <link>https://dimasc.tf/notes/leak/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/leak/</guid>
      <description>https://gist.github.com/tyage/3bb2b730c67b363a26b45699ca34b22ahttps://hackmd.io/@r2dev2/S1P0RYHYke#WebNot sure if anyone else used this trick From the xs leak via cpu
microarchitectual attack dream (e...</description>
      <pubDate>Mon, 10 Feb 2025 06:43:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>Node / JS</title>
      <link>https://dimasc.tf/notes/node-js/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/node-js/</guid>
      <description>https://hackerone.com/reports/2819573Referensi dari sini:https://stackoverflow.com/questions/35949554/invoking-a-function-without-parenthesesCheck jawaban nomer 7https://github.com/daffainfo/ctf-write...</description>
      <pubDate>Mon, 10 Feb 2025 06:43:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>Crypto Web</title>
      <link>https://dimasc.tf/notes/crypto-web/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/crypto-web/</guid>
      <description>pingCTF 20231753CTF ## ZerodayUntitled example program from TAMUCTF 2024exploittamuctf-2024/web/cracked at master · tamuctf/tamuctf-2024 (github.com)l34k CTF 2024AKASEC CTF 2024 | Rusty RoadsolverWrit...</description>
      <pubDate>Sun, 09 Feb 2025 22:53:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>PHP</title>
      <link>https://dimasc.tf/notes/php/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/php/</guid>
      <description>Proxy / WAF Protections Bypass | hacktricksNginx FPM configuration:CopyNginx is configured to block access to /admin.php but it&apos;s possible to bypass this by accessing /admin.php/index.php.Copytl;dr ab...</description>
      <pubDate>Sun, 09 Feb 2025 07:57:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
    </item>
    <item>
      <title>XSS</title>
      <link>https://dimasc.tf/notes/xss/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/xss/</guid>
      <description>localhost.7chn.me -&gt; 127.0.0.1foobar.n.7chn.me -&gt; your serveri was definitely wrong. The A=&gt;B-&gt;A (we abuse this relationship to cache our payload and trigger XSS) is strictly considered same site (htt...</description>
      <pubDate>Sat, 08 Feb 2025 18:30:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
    </item>
    <item>
      <title>Read the file with lxml.etree that Vulnerable to XXE, include the local DTD, and generate an error to read the Flag: Cyber Jawara National 2025 Quals SVG Validator</title>
      <link>https://dimasc.tf/posts/read-the-file-with-lxml-etree-that-vulnerable-to-x/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/read-the-file-with-lxml-etree-that-vulnerable-to-x/</guid>
      <description>A simple SVG validator.In order to gain Arbitrary File Read, we will exploit the XXE vulnerability in the lxml.etree. We must introduce an error in the XML since we cannot read the flag information di...</description>
      <pubDate>Sun, 12 Jan 2025 10:59:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>XXE</category>
      <category>Security</category>
    </item>
    <item>
      <title>Exploiting DOM Clobbering and Using Trigram CSS Leak to Expose Nonce: Freedom Notes - Cyber Jawara National 2025 Quals Writeup</title>
      <link>https://dimasc.tf/posts/exploiting-dom-clobbering-and-using-trigram-css-le/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/exploiting-dom-clobbering-and-using-trigram-css-le/</guid>
      <description>Make your notes has freedom, a freedom from sanitizerIn this challenge, we will exploit two vulnerabilities to gain XSS. The first is DOM Clobbering in the sanitize function in the index.html file, wh...</description>
      <pubDate>Sun, 12 Jan 2025 09:28:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Domclobering</category>
      <category>CSS Leak</category>
      <category>CTF</category>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>Bypassing null Origin in 4xx Status Code Using Iframe | disconnection-revenge Writeup | AlpacaHack Round 7 (Web)</title>
      <link>https://dimasc.tf/posts/bypassing-null-origin-in-4xx-status-code-using-ifr/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/bypassing-null-origin-in-4xx-status-code-using-ifr/</guid>
      <description>Unfortunately, I solved this challenge only 30 minutes after the CTF ended. Here is my write-up about the challenge.This is a fixed challenge of disconnection.In this challenge, we are given source co...</description>
      <pubDate>Sat, 30 Nov 2024 11:42:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>XSS</category>
      <category>CTF</category>
      <category>Security</category>
      <category>Web</category>
      <category>Programming</category>
    </item>
    <item>
      <title>Patchstack Alliance CTF S01E01</title>
      <link>https://dimasc.tf/posts/patchstack-alliance-ctf-s01e01/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/patchstack-alliance-ctf-s01e01/</guid>
      <description>In the recent Patchstack Alliance CTF S01E01, I am thrilled to share that I earned 2nd place and successfully solved all the challenges presented. Below is my detailed write-up of each challenge:In th...</description>
      <pubDate>Sun, 24 Nov 2024 01:13:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>wordpress</category>
      <category>CTF</category>
    </item>
    <item>
      <title>Tot Musica (Web) Unitended Solution - Cyber Jawara International</title>
      <link>https://dimasc.tf/posts/tot-musica-web-unitended-solution-cyber-jawara-int/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/tot-musica-web-unitended-solution-cyber-jawara-int/</guid>
      <description>Someone just recently making a new website, find the full name of the author.Please solve it in locally first!BOT: http://152.42.183.87:8182/Submit the Flag With This Format: CJ{[a-z0-9\s]}http://152....</description>
      <pubDate>Mon, 28 Oct 2024 07:37:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
    <item>
      <title>Apache</title>
      <link>https://dimasc.tf/notes/apache/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/apache/</guid>
      <description>SCTF havefunSCTF 2024 By W&amp;M - W&amp;M Team (wm-team.cn)How it works. With mod_negotiation and AddHandler type-map .var (or Options +MultiViews), Apache treats certain files as type-maps: a plain-text map...</description>
      <pubDate>Sat, 19 Oct 2024 11:50:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Patchstack WCUS CTF Writeup 2024</title>
      <link>https://dimasc.tf/posts/patchstack-wcus-ctf-writeup-2024/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/patchstack-wcus-ctf-writeup-2024/</guid>
      <description>Last weekend, I participated in the Patchstack WCUS CTF and solved all the WordPress challenges. Here&apos;s my write-up for each challenge from the Patchstack WCUS CTF 2024.My area have some kind of dynas...</description>
      <pubDate>Sat, 21 Sep 2024 09:43:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Arbitrary File Inclusion Leading to RCE in Genie.jl - IncludeMe [idekCTF 2024]</title>
      <link>https://dimasc.tf/posts/arbitrary-file-inclusion-leading-to-rce-in-genie-j/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/arbitrary-file-inclusion-leading-to-rce-in-genie-j/</guid>
      <description>In idekCTF 2024, I played with the P1G SEKAI team and secured 1st place out of 1,068 teams! I solved a challenge named &quot;Included me&quot; and got the first blood on that challenge.another minimalist, front...</description>
      <pubDate>Mon, 19 Aug 2024 00:24:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>TLS</title>
      <link>https://dimasc.tf/notes/tls/</link>
      <guid isPermaLink="true">https://dimasc.tf/notes/tls/</guid>
      <description>https://github.com/southball/ctf-writeups/tree/main/Wani-CTF-2024/web/tls_spec Basicaly forensic+web</description>
      <pubDate>Sun, 23 Jun 2024 22:35:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
    </item>
    <item>
      <title>Exploiting Race Condition To Gain Infinity Wealth - m0leCon CTF 2023 - goldinospizza2 </title>
      <link>https://dimasc.tf/posts/exploiting-race-condition-to-gain-infinity-wealth-/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/exploiting-race-condition-to-gain-infinity-wealth-/</guid>
      <description>In the m0leCon CTF 2023, I participated with team TCP1P and successfully solved several web challenges.In this article, I will provide a write-up about an intriguing challenge named &quot;goldinospizza2.&quot;...</description>
      <pubDate>Tue, 30 Apr 2024 23:21:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>Zero-Day XSS Found in Open Source JS Library for CTF Solution - UIUCTF 2023 - peanut-xss Writeup</title>
      <link>https://dimasc.tf/posts/zero-day-xss-found-in-open-source-js-library-for-c/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/zero-day-xss-found-in-open-source-js-library-for-c/</guid>
      <description>This week, I participated in UIUCTF 2023 with the TCP1P team and successfully solved multiple challenges. One of the challenges I tackled was called &quot;peanut-xss&quot;.In this challenge, our goal was to exp...</description>
      <pubDate>Tue, 30 Apr 2024 23:16:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
    </item>
    <item>
      <title>Exploiting the Latest Render Engine in Node (EJS) - SEETF 2023 - Express JavaScript Write-up</title>
      <link>https://dimasc.tf/posts/exploiting-the-latest-render-engine-in-node-ejs-se/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/exploiting-the-latest-render-engine-in-node-ejs-se/</guid>
      <description>During SEETF 2023, I participated as a member of the TCP1P team and successfully solved several web challenges.In this article, I will provide a write-up for a specific challenge called &quot;Express JavaS...</description>
      <pubDate>Tue, 30 Apr 2024 23:10:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>Wiki World</title>
      <link>https://dimasc.tf/posts/wiki-world/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/wiki-world/</guid>
      <description>Can you alpha test out our newest note-taking website? (If you find anything, please report it to us using  nc cha.hackpack.club 8702)Also unrelatedly, our website admin is really fond of the wiki-wor...</description>
      <pubDate>Tue, 30 Apr 2024 23:01:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Security</category>
      <category>Web</category>
    </item>
    <item>
      <title>X Et Et</title>
      <link>https://dimasc.tf/posts/x-et-et/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/x-et-et/</guid>
      <description>solver.py
index.htmlThere are several steps to achieve RCE:Those are the steps required to work on this challenge. For the rest, you can refer to the solve script above to see the execution flow.After...</description>
      <pubDate>Tue, 30 Apr 2024 22:46:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>CTF</category>
      <category>Web</category>
    </item>
    <item>
      <title>Spurdo Enbinling</title>
      <link>https://dimasc.tf/posts/spurdo-enbinling/</link>
      <guid isPermaLink="true">https://dimasc.tf/posts/spurdo-enbinling/</guid>
      <description>Spurdo decided to develop a web game while he was solo leveling. But due to lack of skill, spurdo developed a game that cannot be completed by anyone sane enough. And because of that he decided to inv...</description>
      <pubDate>Tue, 30 Apr 2024 11:47:00 GMT</pubDate>
      <author>noreply@dimasc.tf (Dimas Maulana)</author>
      <category>Web</category>
    </item>
  </channel>
</rss>