bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

Ancient House - InCTF Internationals 2021

Pwn-Solo
2021-08-15
Pwn

tl;dr

  • Jemalloc heap challenge
  • A buggy implementation of strncat in merge allows for an overwrite onto the next region
Read More
InCTFi Exploitation Linux Heap Jemalloc

Vuln Drive - InCTF Internationals 2021

Rohit
2021-08-15
Web

tl;dr

  • /source to get the source
  • Access local host from dev_test using SSRF
  • SQLI to get the flag path a nd LFI to get the flag
Read More
InCTFi SSRF LFI SQLI

DeadlyFastGraph - InCTF Internationals 2021

d4rk_kn1gh7
2021-08-15
Pwn

tl;dr

  • Arbitrary type confusion in DFG JIT
  • Bug eliminates a single CheckStructure node
Read More
InCTFi Exploitation Browser Safari

Json Analyser - InCTF Internationals 2021

1nt3rc3pt0r
2021-08-15
Web Exploitation

tl;dr

  • Json_Interoperability - /verify_roles?role=supersuperuseruser\ud800","name":"admin
  • Prototype_Pollution - {"constructor":{"prototype":{"test":"123"}}} in config-handler
Read More
InCTFi Prototype_Pollution Json_Interoperability

MD-Notes - InCTF Internationals 2021

Yadhu Krishna M
2021-08-14
Web Exploitation

tl;dr

  • Leak admin’s hash using wildcard target origin in postMessage or by calculating sha256('').
  • Create an XSS payload to read /api/flag and send it to attacker server.
Read More
InCTFi XSS JavaScript

Billu_Box_1 - VulnHub VM Challenge

01_susil
2021-08-10
Pentest / VulnHub

tl;dr

  • LFI(Local File Inclusion) Using Hackbar plugin.
Read More
WriteUp Vulnhub Billu Box 1

unknowndevice64 - Vulnhub VM Challenge

47Suriya
2021-08-10
Pentest / Vulnhub

tl;dr

  • Steghide
  • Restricted Shell
Read More
Write up Vulnhub VM Challenge unknowndevice64

Nullbyte - VulnHub VM Challenge

01_susil
2021-08-10
Pentest / VulnHub

tl;dr

  • Reading meta data using Exiftool.
  • Using sqlmap to get Password hash.
Read More
WriteUp Vulnhub Nullbyte

Stapler1 - Vulnhub VM Challenge

47Suriya
2021-08-10
Pentest / Vulnhub

tl;dr

  • Local File Inclusion
Read More
Write up Vulnhub VM Challenge Stapler 1

LazySysAdmin_1.0 - VulnHub VM Challenge

susil_01
2021-08-10
Pentest / Vulnhub

tl;dr

  • smb enumeration using smbclient.
Read More
WriteUp Vulnhub LazySysAdmin_1.0

 Previous 

8 / 19

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.