bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

Pawn - Angstrom CTF 2021

d4rk_kn1gh7
2021-04-08
Pwn

tl;dr

  • UAF in chess game, overwrite __malloc_hook to one_gadget
Read More
Linux Heap AngstromCTF

Jason - Angstrom CTF 2021

Az3z3l
2021-04-08
Web Exploitation

tl;dr

  • Intended: Append ; secure; samesite=none to cookie. Now, <script src="https://jason.2021.chall.actf.co/flags?callback=load"></script> would retrieve the flag.
  • Unintended: Append .actf.co as domain to cookie using CSRF -> Setup a xss payload in reaction.py challenge -> Log in to this using CSRF -> Payload in Reaction.py exfiltrates document.cookie
Read More
AngstromCTF XSS CSRF Cookies

Mantis - Hack The Box

7h3M0nk
2021-03-31
HackTheBox

tl;dr

  • Kerberos Exploitation
  • MS MySQL Server
  • MS14-068
  • GoldenTicket
Read More
Writeup HackTheBox Mantis Goldenticket

Bounty - Hack The Box

7h3M0nk
2021-03-27
HackTheBox

tl;dr

  • RCE by uploading web.config
  • Windows IIS 7.5
  • MS10-059: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege
Read More
HackTheBox WriteUp Bounty

KarDi Bee X - Securinets Quals 2021

g4rud4
2021-03-22
Forensics / Memory

tl;dr

  • File recovery from the memory dump
  • Environment variables analysis.
  • RAR and Zip password cracking.
  • Cracking Windows user password hash.
  • Extracting Keepass Master Password from keystrokes of logged data.
Read More
Volatility Windows Memory Analysis Securinets Quals

Be My Guest - UTCTF21

g4rud4
2021-03-15
Forensics / Network

tl;dr

  • Retrieving the flag from Samba SMB workgroup guest.
Read More
UTCTF SMB

Hack Bob's Box - UTCTF21

g4rud4
2021-03-15
Forensics / Network

tl;dr

  • Anonymous login to FTP server.
  • Retrieve SSH login username and password from Firefox History
Read More
UTCTF FTP Firefox History

Cronos - Hack The Box

7h3M0nk
2021-03-03
HackTheBox

tl;dr

  • SQL Injection
  • Linpeas Priv-Esc
Read More
HackTheBox Write up Linux Box Cronos

dummyper - AeroCTF 2021

fug1t1v3
2021-02-28
Reversing / Linux

tl;dr

  • The dump has some encrypted functions
  • The encrypted bytes are being xorred with a 32 byte key
  • Find the xor_key in the dump
  • Use xor_key offset to find the offset of AES_key and iv
  • AES_CBC decrypt to find flag
Read More
Linux Reversing AES_CBC AeroCTF

Beep - Hack The Box

7h3M0nk
2021-02-28
HackTheBox

tl;dr

  • Shellshock
  • Local File Inclusion
Read More
HackTheBox Write up Beep Linux Box

 Previous 

10 / 19

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.