root@z2r:~/blog/tags#grep -r "ctf-writeup" ./posts

<Tag: ctf-writeup />

Found 15 posts with this tag.

CTF WRITEUPSSATELLITE

HTB - First Contact

HackTheBoxEasy

In this Hack The Box challenge, I had to act as a backup pass prediction system for a ground station. By parsing Two-Line Element (TLE) sets and calculating satellite passes above 30 degrees of elevation using Python's `skyfield` library, I wrote an automated solver to determine upcoming visibility windows, overcome strict timing checks, and retrieve the flag.

August 27, 20266 min read
CTF WRITEUPSWEB

WebVerse Pro | Labs - BowBuy

WebVerse ProEasy

A premium archery store whose new-member '\$300 welcome credit' is applied at checkout through a check-then-act race. The redeem endpoint reads a one-time flag, pauses to 'authorize', then adds the credit and sets the flag — so concurrent redeems all pass the check and each adds \$300. By stacking the credit past an item's price and placing the order, the confirmation page renders the flag as a gift.

August 23, 20265 min read
CTF WRITEUPSWEB

WebVerse Pro | Challenge - VelvetRope

WebVerse ProEasy

I found that Gilt & Grain's Members Portal authenticated against an unescaped LDAP filter, letting me bypass login entirely with a wildcard payload that matched any directory entry instead of verifying real credentials. The bug came down to the app treating "a matching record was found" as proof of a correct password, rather than performing an actual LDAP bind to check it.

August 17, 20265 min read
CTF WRITEUPSFORENSICS

THM - After Hours

TryHackMeMedium

A hunt through a resort's offline WMI repository that traces a fileless backdoor from a "clean" event-log binding down through Base64-and-UTF16-encoded PowerShell, a reflectively-loaded .NET payload hidden in a custom Win32_HardwareTelemetry class, and a quietly planted net user backdoor account.

August 8, 202613 min read
CTF WRITEUPSACTIVE DIRECTORY

HackSmarter - MartiniAD

HackSmarterEasy

MartiniAD is an Easy-difficulty Active Directory lab hosted by HackSmarter. The domain `DRY.MARTINI.BARS` is fronted by a single Domain Controller (`DC01`) that permits unauthenticated SMB null/guest sessions. This allows enumeration of a non-default share containing plaintext credentials for a low-privileged domain user. Those credentials are used to Kerberoast a service account, whose cracked password grants a foothold via WinRM. Password reuse between the service account and a linked human Tier-0 admin account (which sits in Domain Admins) then provides full domain compromise, culminating in a DCSync attack to extract the KRBTGT hash.

August 6, 202610 min read
CTF WRITEUPSACTIVE DIRECTORY

HackSmarter - ShadowGate

HackSmarterEasy

Compromising the ShadowGate Active Directory lab through a chained attack path — from AS-REP roasting and ACL abuse via Shadow Credentials, to coercing the Domain Controller with PetitPotam and relaying its authentication into a certificate-based DCSync — culminating in full domain compromise via the krbtgt hash.

August 6, 20268 min read
CTF WRITEUPSBOOT2ROOT

HackSmarter - SysAdmins

HackSmarterMedium

In this HackSmarter SysAdmins lab, I chained anonymous FTP disclosure, OSINT, SNMPv3 username and credential reuse, and a critical sudo privilege escalation (CVE-2025-32463) to move from initial access to full root compromise.

August 6, 202611 min read
CTF WRITEUPSCLOUD

HackSmarter - Rotation

HackSmarterMedium

This is a Medium AWS Challenge Lab, it is an IAM privilege escalation via access key rotation abuse.

August 6, 20268 min read
CTF WRITEUPSCRYPTO

HTB - The Ashen Field

HackTheBoxEasy

Exploit a standard implementation of the Hidden Field Equations protocol via Groebner Basis

August 5, 20266 min read
CTF WRITEUPSCRYPTO

HTB - False Witness

HackTheBoxEasy

Predictable hash function that results in breaking the decisional problem by enumerating all group elements.

August 5, 20267 min read
CTF WRITEUPSCRYPTO

HTB - Fractured Seal

HackTheBoxEasy

Recover RSA private key given leaked information from PEM file using Coppersmith's small roots

August 5, 20266 min read
CTF WRITEUPSHARDWARE

HTB - Thermal Receipt

HackTheBoxEasy

Connect to PRET PJL mode, enumerate device files, recover the latest journal receipt, follow the NVRAM reference, and read NVRAM to recover the flag.

August 5, 20265 min read
CTF WRITEUPSAI/LLM

THM - BankGPT

TryHackMeEasy

This writeup demonstrates how to bypass a banking AI's security guardrails by chaining context manipulation and audit pretexting to ultimately extract hidden API keys through a subtle "Leakage in Refusal" vulnerability.

August 5, 20265 min read
CTF WRITEUPSBLOCKCHAIN

HTB - Caldrin's Day Away

HackTheBoxEasy

This writeup details how to drain an ERC-4626-style vault in HTB's "Caldrin's Day Away" challenge by leveraging a massive flash loan to manipulate an AMM reserve, feeding the poisoned data through a flawed oracle to artificially inflate the vault's share price.

August 4, 202610 min read
CTF WRITEUPSCLOUD

HTB - Bought Riot

HackTheBoxMedium

In this medium-difficulty Cloud challenge, you must trace the origins and financial backing of a malicious rumor to stop a framed Stormbound captain from being wrongfully stripped of their crucial guard post.

August 4, 20264 min read