niktay: CTF writeups and tutorials

Featured

A double free, a leaked system(), and a detour through fastbins to reach __free_hook.

Read the writeup
Figure 1: a 0x20 heap chunk on amd64, with its fd field circled0x20fdFig. 1 · 0x20 chunk, amd64
  1. Chonk Shortage

    CTF.SG CTF 2022 · pwn

    Leaking libc through an oversized mmap chunk, then a format-string bug redirects a writable libc GOT entry to system to get a shell.

  2. House of Sice

    HSCTF 8 · pwn

    A double free, a leaked system(), and a detour through fastbins to reach __free_hook.

  3. BabyRE

    zh3r0 CTF 2021 · reversing

    Recognizing the per-8-byte bit shuffle as a matrix transpose and inverting it in Python to turn the comparison constant back into the flag.

  4. The Vault

    zh3r0 CTF 2021 · misc

    Extracting PICO-8 code hidden in a cartridge PNG's color-channel LSBs, then reimplementing its Lua check in Python to recover the password.

  5. Epic Game

    ICHSA CTF 2021 · pwn

    Abusing an snprintf return-value bug to wrap a write into the GOT and point memset at system, using the game's leaked luck stat as a libc address.

  6. Freeless

    SECCON Beginners 2021 · pwn

    With no free available, a top-chunk overflow forces sysmalloc to free memory, enabling a libc leak and tcache poisoning of __free_hook.

Show 27 earlier postsHide 27 earlier posts2017–2021
  1. masterc

    3kCTF 2021 · pwn

    Overwriting a thread's master canary in its TCB via an unbounded gets, then ROP-ing to a shell after leaking a PIE address through scanf.

  2. crypto warmup

    3kCTF 2021 · crypto

    Mapping every three-character block to the number the provided encoder outputs, then reversing the lookup over the given numbers.

  3. babycrypto1

    LINECTF 2021 · crypto

    Forging an AES-CBC command block with the server's encryption oracle, encrypting the show command under the previous block as its IV.

  4. babycrypto2

    LINECTF 2021 · crypto

    Flipping bits in the IV that the server prepends to AES-CBC ciphertext, so the first block decrypts to show instead of test.

  5. PWNkemon

    ALLES CTF 2020 · other

    Decoding a Game Boy link-cable capture as SPI in Saleae Logic, then converting the bytes with a Pokémon character table to read the flag.

  6. i-wanna-find-the-flag

    redpwnCTF 2020 · reversing

    Extracting the GameMaker data.win from the game executable and opening it in UndertaleModTool to read the flag from its winner room.

  7. Skywriting

    redpwnCTF 2020 · pwn

    A read without a NUL terminator leaks stack values; a later overflow restores the canary and selects a libc one-gadget return target.

  8. Finches in a Pie

    RACTF 2020 · pwn

    A format-string leak defeats the canary and PIE, then a buffer overflow redirects execution to a built-in flag-printing function.

  9. Got It

    HSCTF 7 · pwn

    A scrambled GOT turns the binary's scanf into printf, and the resulting format-string write redirects a GOT entry to a one-gadget shell.

  10. pwnagotchi

    HSCTF 7 · pwn

    A gets overflow with no canary leaks puts to fingerprint libc, then ROPs through the eat and zzz helpers to reach a one-gadget shell.

  11. Captain Hook

    Sharky CTF 2020 · pwn

    A format-string bug leaks the stack canary and libc, then a buffer overflow in the edit handler drives a ROP chain to a one-gadget shell.

  12. give_away_1

    Sharky CTF 2020 · pwn

    A 32-bit buffer overflow and a leaked system address drive a ret2libc call that runs /bin/sh via a string found in the provided libc.

  13. give_away_2

    Sharky CTF 2020 · pwn

    A PIE binary that leaks main to beat ASLR, then leaks libc via printf's GOT entry before ROP-ing into a one-gadget shell.

  14. z3robotwaves

    Sharky CTF 2020 · reversing

    Modeling the many constraints of a check_flag routine as an SMT problem and solving them with Z3 to recover the password.

  15. Honey, Help!

    CyBRICS Quals 2019 · misc

    Mapping garbled terminal symbols back to letters with a chosen-plaintext attack to recover the flag.

  16. ProCTF

    CyBRICS Quals 2019 · misc

    An SSH login that drops into a Prolog interpreter, where shell() spawns a shell to read the flag.

  17. Warmup

    CyBRICS Quals 2019 · other

    Using curl to read the page served before its redirect, then base64-decoding its contents to recover the flag.

  18. Zakukozh

    CyBRICS Quals 2019 · crypto

    Brute-forcing the keys of an affine cipher over all 256 byte values and keeping the decryption that produces a valid PNG of the flag.

  19. [PoP:Rev] Reverse Engineering x86 ELF: 0x1

    reversing

    How a function's prologue, return value, and epilogue look in disassembly, through a program that only returns 0.

  20. [PoP:Rev] Reverse Engineering x86 ELF: 0x2

    reversing

    How local variables and function calls look in disassembly, through a program that adds three integers from user input.

  21. [PoP:Rev] Reverse Engineering x86 ELF: 0x3

    reversing

    How conditionals look in disassembly, through a program that tells whether its input is more than, less than, or equal to 10.

  22. [PoP:Rev] Reverse Engineering x86 ELF: 0x4

    reversing

    How loops look in disassembly, through a program that prints the length of its input.

  23. [PoP:Rev] Reverse Engineering x86 ELF: 0x5

    reversing

    How structs look in disassembly, through a program that reads a name and age into a struct and prints them.

  24. rev_rev_rev

    Tokyo Westerns CTF 2017 · reversing

    Reversing a 32-bit ELF that reverses its input, transforms it with bitwise operations, and NOTs it, then brute-forcing the flag one character at a time.

  25. 2017, Dating in Singapore

    HITB GSEC 2017 · misc

    Reading a string of digits as twelve months of days and tracing them out on the 2017 calendar.

  26. Prime

    HITB GSEC 2017 · other

    Decompiling an APK whose prime check also accepts squares of primes, which makes the flag π(10¹⁶) + π(10⁸).

  27. Simple Transfer

    HITB GSEC 2017 · misc

    Recovering a PDF sent over NFS from a packet capture, then converting it to HTML with pdftohtml to reveal the flag.