<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>niktay</title><description>CTF writeups on binary exploitation, reverse engineering, and cryptography, and a tutorial series on reverse engineering x86 ELF binaries.</description><link>https://blog.niktay.dev/</link><language>en</language><item><title>Chonk Shortage · CTF.SG CTF 2022</title><link>https://blog.niktay.dev/writing/ctfsg-ctf-2022-chonk-shortage/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/ctfsg-ctf-2022-chonk-shortage/</guid><description>Leaking libc through an oversized mmap chunk, then a format-string bug redirects a writable libc GOT entry to system to get a shell.</description><pubDate>Sun, 13 Mar 2022 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>glibc</category><category>heap</category></item><item><title>House of Sice · HSCTF 8</title><link>https://blog.niktay.dev/writing/hsctf-8-2021-house-of-sice/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/hsctf-8-2021-house-of-sice/</guid><description>A double free, a leaked system(), and a detour through fastbins to reach __free_hook.</description><pubDate>Sun, 20 Jun 2021 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>glibc</category><category>heap</category></item><item><title>BabyRE · zh3r0 CTF 2021</title><link>https://blog.niktay.dev/writing/zh3r0-ctf-2021-babyre/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/zh3r0-ctf-2021-babyre/</guid><description>Recognizing the per-8-byte bit shuffle as a matrix transpose and inverting it in Python to turn the comparison constant back into the flag.</description><pubDate>Mon, 07 Jun 2021 00:00:00 GMT</pubDate><category>Reversing</category><category>x86-64</category></item><item><title>The Vault · zh3r0 CTF 2021</title><link>https://blog.niktay.dev/writing/zh3r0-ctf-2021-the-vault/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/zh3r0-ctf-2021-the-vault/</guid><description>Extracting PICO-8 code hidden in a cartridge PNG&apos;s color-channel LSBs, then reimplementing its Lua check in Python to recover the password.</description><pubDate>Mon, 07 Jun 2021 00:00:00 GMT</pubDate><category>Misc</category><category>games</category><category>steganography</category></item><item><title>Epic Game · ICHSA CTF 2021</title><link>https://blog.niktay.dev/writing/ichsa-ctf-2021-epic-game/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/ichsa-ctf-2021-epic-game/</guid><description>Abusing an snprintf return-value bug to wrap a write into the GOT and point memset at system, using the game&apos;s leaked luck stat as a libc address.</description><pubDate>Thu, 03 Jun 2021 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>games</category></item><item><title>Freeless · SECCON Beginners 2021</title><link>https://blog.niktay.dev/writing/seccon-beginners-2021-freeless/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/seccon-beginners-2021-freeless/</guid><description>With no free available, a top-chunk overflow forces sysmalloc to free memory, enabling a libc leak and tcache poisoning of __free_hook.</description><pubDate>Mon, 24 May 2021 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>heap</category></item><item><title>masterc · 3kCTF 2021</title><link>https://blog.niktay.dev/writing/3kctf21-masterc/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/3kctf21-masterc/</guid><description>Overwriting a thread&apos;s master canary in its TCB via an unbounded gets, then ROP-ing to a shell after leaking a PIE address through scanf.</description><pubDate>Thu, 20 May 2021 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category></item><item><title>crypto warmup · 3kCTF 2021</title><link>https://blog.niktay.dev/writing/3kctf21-crypto-warmup/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/3kctf21-crypto-warmup/</guid><description>Mapping every three-character block to the number the provided encoder outputs, then reversing the lookup over the given numbers.</description><pubDate>Mon, 17 May 2021 00:00:00 GMT</pubDate><category>Crypto</category><category>python</category></item><item><title>babycrypto1 · LINECTF 2021</title><link>https://blog.niktay.dev/writing/linectf21-babycrypto1/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/linectf21-babycrypto1/</guid><description>Forging an AES-CBC command block with the server&apos;s encryption oracle, encrypting the show command under the previous block as its IV.</description><pubDate>Sun, 21 Mar 2021 00:00:00 GMT</pubDate><category>Crypto</category><category>AES</category><category>python</category></item><item><title>babycrypto2 · LINECTF 2021</title><link>https://blog.niktay.dev/writing/linectf21-babycrypto2/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/linectf21-babycrypto2/</guid><description>Flipping bits in the IV that the server prepends to AES-CBC ciphertext, so the first block decrypts to show instead of test.</description><pubDate>Sun, 21 Mar 2021 00:00:00 GMT</pubDate><category>Crypto</category><category>AES</category><category>python</category></item><item><title>PWNkemon · ALLES CTF 2020</title><link>https://blog.niktay.dev/writing/allesctf20-pwnkemon/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/allesctf20-pwnkemon/</guid><description>Decoding a Game Boy link-cable capture as SPI in Saleae Logic, then converting the bytes with a Pokémon character table to read the flag.</description><pubDate>Mon, 07 Sep 2020 00:00:00 GMT</pubDate><category>Other</category><category>hardware</category><category>games</category></item><item><title>i-wanna-find-the-flag · redpwnCTF 2020</title><link>https://blog.niktay.dev/writing/redpwnctf20-i-wanna-find-the-flag/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/redpwnctf20-i-wanna-find-the-flag/</guid><description>Extracting the GameMaker data.win from the game executable and opening it in UndertaleModTool to read the flag from its winner room.</description><pubDate>Fri, 26 Jun 2020 00:00:00 GMT</pubDate><category>Reversing</category><category>windows</category><category>games</category></item><item><title>Skywriting · redpwnCTF 2020</title><link>https://blog.niktay.dev/writing/redpwnctf20-skywriting/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/redpwnctf20-skywriting/</guid><description>A read without a NUL terminator leaks stack values; a later overflow restores the canary and selects a libc one-gadget return target.</description><pubDate>Fri, 26 Jun 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category></item><item><title>Finches in a Pie · RACTF 2020</title><link>https://blog.niktay.dev/writing/ractf-finches-in-a-pie/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/ractf-finches-in-a-pie/</guid><description>A format-string leak defeats the canary and PIE, then a buffer overflow redirects execution to a built-in flag-printing function.</description><pubDate>Thu, 11 Jun 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86</category></item><item><title>Got It · HSCTF 7</title><link>https://blog.niktay.dev/writing/hsctf-got-it/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/hsctf-got-it/</guid><description>A scrambled GOT turns the binary&apos;s scanf into printf, and the resulting format-string write redirects a GOT entry to a one-gadget shell.</description><pubDate>Sun, 07 Jun 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category></item><item><title>pwnagotchi · HSCTF 7</title><link>https://blog.niktay.dev/writing/hsctf-pwnagotchi/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/hsctf-pwnagotchi/</guid><description>A gets overflow with no canary leaks puts to fingerprint libc, then ROPs through the eat and zzz helpers to reach a one-gadget shell.</description><pubDate>Sat, 06 Jun 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>glibc</category></item><item><title>Captain Hook · Sharky CTF 2020</title><link>https://blog.niktay.dev/writing/sharky-ctf-captain-hook/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/sharky-ctf-captain-hook/</guid><description>A format-string bug leaks the stack canary and libc, then a buffer overflow in the edit handler drives a ROP chain to a one-gadget shell.</description><pubDate>Tue, 12 May 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>glibc</category></item><item><title>give_away_1 · Sharky CTF 2020</title><link>https://blog.niktay.dev/writing/sharky-ctf-give-away-one/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/sharky-ctf-give-away-one/</guid><description>A 32-bit buffer overflow and a leaked system address drive a ret2libc call that runs /bin/sh via a string found in the provided libc.</description><pubDate>Tue, 12 May 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86</category><category>glibc</category></item><item><title>give_away_2 · Sharky CTF 2020</title><link>https://blog.niktay.dev/writing/sharky-ctf-give-away-two/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/sharky-ctf-give-away-two/</guid><description>A PIE binary that leaks main to beat ASLR, then leaks libc via printf&apos;s GOT entry before ROP-ing into a one-gadget shell.</description><pubDate>Tue, 12 May 2020 00:00:00 GMT</pubDate><category>Pwn</category><category>x86-64</category><category>glibc</category></item><item><title>ｚ３ｒｏｂｏｔｗａｖｅｓ · Sharky CTF 2020</title><link>https://blog.niktay.dev/writing/sharky-ctf-z3robotwaves/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/sharky-ctf-z3robotwaves/</guid><description>Modeling the many constraints of a check_flag routine as an SMT problem and solving them with Z3 to recover the password.</description><pubDate>Tue, 12 May 2020 00:00:00 GMT</pubDate><category>Reversing</category><category>x86-64</category><category>Z3</category></item><item><title>Honey, Help! · CyBRICS Quals 2019</title><link>https://blog.niktay.dev/writing/cybrics-2019-honey-help-misc/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/cybrics-2019-honey-help-misc/</guid><description>Mapping garbled terminal symbols back to letters with a chosen-plaintext attack to recover the flag.</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate><category>Misc</category><category>steganography</category></item><item><title>ProCTF · CyBRICS Quals 2019</title><link>https://blog.niktay.dev/writing/cybrics-2019-proctf-ctb/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/cybrics-2019-proctf-ctb/</guid><description>An SSH login that drops into a Prolog interpreter, where shell() spawns a shell to read the flag.</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate><category>Misc</category><category>prolog</category></item><item><title>Warmup · CyBRICS Quals 2019</title><link>https://blog.niktay.dev/writing/cybrics-2019-warmup-web/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/cybrics-2019-warmup-web/</guid><description>Using curl to read the page served before its redirect, then base64-decoding its contents to recover the flag.</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate><category>Other</category><category>web</category></item><item><title>Zakukozh · CyBRICS Quals 2019</title><link>https://blog.niktay.dev/writing/cybrics-2019-zakukozh-cyber/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/cybrics-2019-zakukozh-cyber/</guid><description>Brute-forcing the keys of an affine cipher over all 256 byte values and keeping the decryption that produces a valid PNG of the flag.</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate><category>Crypto</category><category>affine cipher</category></item><item><title>[PoP:Rev] Reverse Engineering x86 ELF: 0x1</title><link>https://blog.niktay.dev/writing/pop-rev-x86elf-1/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/pop-rev-x86elf-1/</guid><description>How a function&apos;s prologue, return value, and epilogue look in disassembly, through a program that only returns 0.</description><pubDate>Sun, 25 Feb 2018 00:00:00 GMT</pubDate><category>Reversing</category><category>x86</category><category>assembly</category></item><item><title>[PoP:Rev] Reverse Engineering x86 ELF: 0x2</title><link>https://blog.niktay.dev/writing/pop-rev-x86elf-2/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/pop-rev-x86elf-2/</guid><description>How local variables and function calls look in disassembly, through a program that adds three integers from user input.</description><pubDate>Sun, 25 Feb 2018 00:00:00 GMT</pubDate><category>Reversing</category><category>x86</category><category>assembly</category></item><item><title>[PoP:Rev] Reverse Engineering x86 ELF: 0x3</title><link>https://blog.niktay.dev/writing/pop-rev-x86elf-3/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/pop-rev-x86elf-3/</guid><description>How conditionals look in disassembly, through a program that tells whether its input is more than, less than, or equal to 10.</description><pubDate>Sun, 25 Feb 2018 00:00:00 GMT</pubDate><category>Reversing</category><category>x86</category><category>assembly</category></item><item><title>[PoP:Rev] Reverse Engineering x86 ELF: 0x4</title><link>https://blog.niktay.dev/writing/pop-rev-x86elf-4/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/pop-rev-x86elf-4/</guid><description>How loops look in disassembly, through a program that prints the length of its input.</description><pubDate>Sun, 25 Feb 2018 00:00:00 GMT</pubDate><category>Reversing</category><category>x86</category><category>assembly</category></item><item><title>[PoP:Rev] Reverse Engineering x86 ELF: 0x5</title><link>https://blog.niktay.dev/writing/pop-rev-x86elf-5/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/pop-rev-x86elf-5/</guid><description>How structs look in disassembly, through a program that reads a name and age into a struct and prints them.</description><pubDate>Sun, 25 Feb 2018 00:00:00 GMT</pubDate><category>Reversing</category><category>x86</category><category>assembly</category></item><item><title>rev_rev_rev · Tokyo Westerns CTF 2017</title><link>https://blog.niktay.dev/writing/tokyowesterns-2017-rev-rev-rev-reverse/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/tokyowesterns-2017-rev-rev-rev-reverse/</guid><description>Reversing a 32-bit ELF that reverses its input, transforms it with bitwise operations, and NOTs it, then brute-forcing the flag one character at a time.</description><pubDate>Mon, 04 Sep 2017 00:00:00 GMT</pubDate><category>Reversing</category><category>x86</category></item><item><title>2017, Dating in Singapore · HITB GSEC 2017</title><link>https://blog.niktay.dev/writing/hitb-gsec-2017-2017-dating-in-singapore-misc/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/hitb-gsec-2017-2017-dating-in-singapore-misc/</guid><description>Reading a string of digits as twelve months of days and tracing them out on the 2017 calendar.</description><pubDate>Mon, 28 Aug 2017 00:00:00 GMT</pubDate><category>Misc</category><category>puzzles</category></item><item><title>Prime · HITB GSEC 2017</title><link>https://blog.niktay.dev/writing/hitb-gsec-2017-prime/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/hitb-gsec-2017-prime/</guid><description>Decompiling an APK whose prime check also accepts squares of primes, which makes the flag π(10¹⁶) + π(10⁸).</description><pubDate>Mon, 28 Aug 2017 00:00:00 GMT</pubDate><category>Other</category><category>android</category></item><item><title>Simple Transfer · HITB GSEC 2017</title><link>https://blog.niktay.dev/writing/hitb-gsec-2017-simple-transfer-misc/</link><guid isPermaLink="true">https://blog.niktay.dev/writing/hitb-gsec-2017-simple-transfer-misc/</guid><description>Recovering a PDF sent over NFS from a packet capture, then converting it to HTML with pdftohtml to reveal the flag.</description><pubDate>Sun, 27 Aug 2017 00:00:00 GMT</pubDate><category>Misc</category><category>forensics</category></item></channel></rss>