ONE LIBRARY / MANY THREADS
Find your next rabbit hole.
Projects, research writeups, and field notes. Search titles, summaries, and topics.
Your saved reading ↗85 results to explore
- Projects
CTF-XSS-BOT
Craft engaging XSS challenges effortlessly with CTF-XSS-BOT. This template simplifies setting up an environment for Capture The Flag competitions.
Explore the project ↗ - Projects
VWA-Wazuh (Mini Lab SOC)
An application consisting of several vulnerable web applications that are integrated with Wazuh.
Explore the project ↗ - Projects
Dockerized Wordpress Debug Setup
A Dockerized WordPress development environment with two configurations, one using Nginx and the other using Apache. Includes Xdebug for debugging.
Explore the project ↗ - Projects
CTF Challenge Difficulty Calculator
A Next.js program designed to assess the difficulty of a Capture The Flag (CTF) challenge more efficiently.
Explore the project ↗ - Projects
CTFIFY
A command-line tool designed to simplify the process of downloading and managing Capture The Flag (CTF) challenges.
Explore the project ↗ - Projects
CTF Assistant
Discord bot for managing CTF written in Bun programming language.
Explore the project ↗ - Projects
Paradigmctf BlockChain Infra Extended
Setup from Paradigm CTF blockchain challenges with new features, including a web interface and additional challenge setup.
Explore the project ↗ - Projects
TCP1P Theme
The TCP1P Theme is a CTFd theme built based on the CTFd core-beta theme.
Explore the project ↗ - Projects
Cyber-Security-Learning-Resources
Material untuk belajar Cyber Security.
Explore the project ↗ - Blog posts
PatchStack CTF 2025: End-of-the-year Alliance Capture the Flag
The challenge involves a WordPress plugin named "AI Trust Score" (located in wp-content/plugins/ai-badbots/ai-badbots.php). This plugin uses AI heuristics…
Start reading ↗ - Blog posts
Patchstack Aliance CTF S02E03 - WordCamp Europe
The endpoint /wp-json/ghostly/v1/login is a custom REST route in the WordPress backend. Here’s the kicker:Here’s the vulnerable PHP handler logic (as…
Start reading ↗ - Blog posts
Patchstack Alliance CTF S02E01 - WordCamp Asia
Last weekend, I participated in the Patchstack WCUS CTF and solved all the WordPress challenges. Here's my write-up for each challenge from the Patchstack…
Start reading ↗ - Blog posts
Read the file with lxml.etree that Vulnerable to XXE, include the local DTD, and generate an error to read the Flag: Cyber Jawara National 2025 Quals SVG Validator
A simple SVG validator.In order to gain Arbitrary File Read, we will exploit the XXE vulnerability in the lxml.etree. We must introduce an error in the XML…
Start reading ↗ - Blog posts
Exploiting DOM Clobbering and Using Trigram CSS Leak to Expose Nonce: Freedom Notes - Cyber Jawara National 2025 Quals Writeup
Make your notes has freedom, a freedom from sanitizerIn this challenge, we will exploit two vulnerabilities to gain XSS. The first is DOM Clobbering in the…
Start reading ↗ - Blog posts
Bypassing null Origin in 4xx Status Code Using Iframe | disconnection-revenge Writeup | AlpacaHack Round 7 (Web)
Unfortunately, I solved this challenge only 30 minutes after the CTF ended. Here is my write-up about the challenge.This is a fixed challenge of…
Start reading ↗ - Blog posts
Patchstack Alliance CTF S01E01
In the recent Patchstack Alliance CTF S01E01, I am thrilled to share that I earned 2nd place and successfully solved all the challenges presented. Below is…
Start reading ↗ - Blog posts
Tot Musica (Web) Unitended Solution - Cyber Jawara International
Someone just recently making a new website, find the full name of the author.Please solve it in locally first!BOT: the Flag With This Format: CJ{[a-z0-9\s]}
Start reading ↗ - Blog posts
Patchstack WCUS CTF Writeup 2024
Last weekend, I participated in the Patchstack WCUS CTF and solved all the WordPress challenges. Here's my write-up for each challenge from the Patchstack…
Start reading ↗