<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>hur01</title><description>CTF and wargame write-ups: reverse engineering, exploitation, cryptography, blockchain internals and hardware side-channels.</description><link>https://hur01.pages.dev/</link><item><title>AgilePaste 3</title><link>https://hur01.pages.dev/ctf/nns-ctf/agilepaste-3/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/agilepaste-3/</guid><description>Differential handling of duplicate Erlang ETF map keys — a term that never passed validation reaches the client&apos;s JSON encoder</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>bloatware.js</title><link>https://hur01.pages.dev/ctf/nns-ctf/bloatware-js/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/bloatware-js/</guid><description>Next.js resume-data-cache blobs are base64 → inflate → JSON.parse with no integrity check, and the client Flight decoder&apos;s synchronous reference walk has no guards at all.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Clean Sweep</title><link>https://hur01.pages.dev/ctf/nns-ctf/clean-sweep/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/clean-sweep/</guid><description>ECOVACS DEEBOT T9 firmware 1.4.9 — `reqDo`&apos;s JSON command dispatcher builds a string with `sprintf` and hands it to `popen()`</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>dont-worry</title><link>https://hur01.pages.dev/ctf/nns-ctf/dont-worry/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/dont-worry/</guid><description>CSP bypass via path traversal in the Prism autoloader&apos;s `data-dependencies`, chained with `No-Vary-Search` cache-key confusion to replay the bot&apos;s authenticated response</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Count on me!</title><link>https://hur01.pages.dev/ctf/nns-ctf/count-on-me/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/count-on-me/</guid><description>`vb.htm?checkupdate=&lt;url&gt;` reflects the server-side fetch body verbatim — response-reflected SSRF (the SSID injection and `update.cgi` crash were dead ends)</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Dot Matrix</title><link>https://hur01.pages.dev/ctf/nns-ctf/dot-matrix/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/dot-matrix/</guid><description>Parse the I2C capture → map registers to LEDs → rebuild frames → fix the row order → recover the true scroll period</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Downhill</title><link>https://hur01.pages.dev/ctf/nns-ctf/downhill/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/downhill/</guid><description>Hidden-parallelepiped attack on a 2003 signature scheme — recover `f` with covariance plus FFT-augmented 4th-moment gradient descent</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>dyslexic</title><link>https://hur01.pages.dev/ctf/nns-ctf/dyslexic/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/dyslexic/</guid><description>`vboxsf` is a client filesystem — the guest trusts the host&apos;s SHFL RPC responses without validating them</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Embedded encryptor</title><link>https://hur01.pages.dev/ctf/nns-ctf/embedded-encryptor/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/embedded-encryptor/</guid><description>Locate the encryption in the power trace, align per-block, recover the key with CPA (last two bytes handled separately)</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Flag Pointer Register</title><link>https://hur01.pages.dev/ctf/nns-ctf/flag-pointer-register/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/flag-pointer-register/</guid><description>PE32+ — the decoder always runs, the result pointer just never reaches RDX. Replay the 8-byte-key XOR instead</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>happy</title><link>https://hur01.pages.dev/ctf/nns-ctf/happy/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/happy/</guid><description>`--frozen-intrinsics` freezes only the ECMAScript intrinsics — Node core prototypes such as `EventEmitter.prototype` are left alone</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>1up clank bro</title><link>https://hur01.pages.dev/ctf/nns-ctf/1up-clank-bro/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/1up-clank-bro/</guid><description>Ladybird LibJS inline-cache type confusion after a GC sweep → unchecked heap OOB R/W → native function table hijack for RCE</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>File Monster</title><link>https://hur01.pages.dev/ctf/nns-ctf/file-monster/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/file-monster/</guid><description>Uploads are written verbatim to `/tmp/&lt;name&gt;` on the shared MongoDB container → CVE-2026-13078 / SERVER-128832</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Ein milljón bjóra</title><link>https://hur01.pages.dev/ctf/nns-ctf/ein-milljon-bjora/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/ein-milljon-bjora/</guid><description>`Exif.ReadLocation()` returns a raw `JsonElement`, giving a zero-byte write; steer the classifier to inflate the approved count</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>No Strings Attached</title><link>https://hur01.pages.dev/ctf/nns-ctf/no-strings-attached/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/no-strings-attached/</guid><description>Recover the 56 bytes of `secret` (0x404040) XORed against a glibc-style LCG keystream</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Min Beste Venn</title><link>https://hur01.pages.dev/ctf/nns-ctf/min-beste-venn/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/min-beste-venn/</guid><description>1,135 HTTP HEAD requests, all 404 — the information is in the shape of the **request paths**, not the responses</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Open Secret</title><link>https://hur01.pages.dev/ctf/nns-ctf/open-secret/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/open-secret/</guid><description>Static ELF using raw syscalls only, so there are no libc calls for ltrace to catch</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Omniscient</title><link>https://hur01.pages.dev/ctf/nns-ctf/omniscient/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/omniscient/</guid><description>`SetApConfig` base64-wraps every input except the `ts` field added in the X5 → command injection into `popen()`</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Patch Tuesday</title><link>https://hur01.pages.dev/ctf/nns-ctf/patch-tuesday/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/patch-tuesday/</guid><description>Runtime opcode patch (`jz` → `jnz`)</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Purgatory</title><link>https://hur01.pages.dev/ctf/nns-ctf/purgatory/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/purgatory/</guid><description>Erlang hot code loading — the worker&apos;s local calls stay pinned to old.beam, but the fully-qualified `Mod:Fun` call is late-bound and lands in new.beam</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>jailnet</title><link>https://hur01.pages.dev/ctf/nns-ctf/jailnet/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/jailnet/</guid><description>The Janet compiler runs outside the sandbox it is compiling for, and nothing verifies the bytecode it emits.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>perchance</title><link>https://hur01.pages.dev/ctf/nns-ctf/perchance/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/perchance/</guid><description>Missing trailing slash in a `startsWith` check (userinfo bypass), then a hardcoded extension UUID and an origin-less postMessage handler to steal `activateOn`</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Raymarine Navigation</title><link>https://hur01.pages.dev/ctf/nns-ctf/raymarine-navigation/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/raymarine-navigation/</guid><description>LightHouse 4.11.133 (0day) — command injection in a CGI binary</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Scratch Space</title><link>https://hur01.pages.dev/ctf/nns-ctf/scratch-space/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/scratch-space/</guid><description>Decoded into an mmap&apos;d scratch page and then wiped — reconstruct the pre-wipe state</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>silent</title><link>https://hur01.pages.dev/ctf/nns-ctf/silent/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/silent/</guid><description>pyjail — reach `object` without `__class__`, then build an arbitrary-getattr primitive without spelling a single name</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The Builder</title><link>https://hur01.pages.dev/ctf/nns-ctf/the-builder/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/the-builder/</guid><description>The page tag is `sha256(content)[:12]`, so it is predictable, and the registry accepts anonymous pushes → smuggle in `ONBUILD COPY --from=theme /flag.txt`</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The Temple</title><link>https://hur01.pages.dev/ctf/nns-ctf/the-temple/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/the-temple/</guid><description>TempleOS — print to the terminal after `MountIDEAuto`, and decode the 8x8 glyphs from the noVNC canvas pixels instead of reading them by eye</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Time Lock</title><link>https://hur01.pages.dev/ctf/nns-ctf/time-lock/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/time-lock/</guid><description>Lie to `time()` with `LD_PRELOAD` to pass the time gate</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Self-service</title><link>https://hur01.pages.dev/ctf/nns-ctf/self-service/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/self-service/</guid><description>Abuse LDAP attribute-driven group &quot;provisioning&quot; → reset `ops`&apos;s password → pivot</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Triangle Platform</title><link>https://hur01.pages.dev/ctf/nns-ctf/triangle-platform/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/triangle-platform/</guid><description>Start from tenant-a&apos;s `console` ServiceAccount and escape through Kyverno&apos;s YAML handling</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>small-guy</title><link>https://hur01.pages.dev/ctf/nns-ctf/small-guy/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/small-guy/</guid><description>All 256 rounds of the checker live in .eh_frame; the C++ unwinder is the VM, and it consumes its key one frame late.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Sleepy CPU</title><link>https://hur01.pages.dev/ctf/nns-ctf/sleepy-cpu/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/sleepy-cpu/</guid><description>The length of each sleep interval is the flag byte - a power side-channel you can read with a threshold.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate></item><item><title>NNS International Lounge</title><link>https://hur01.pages.dev/ctf/nns-ctf/nns-international-lounge/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/nns-international-lounge/</guid><description>A hardcoded HMAC key plus one unvalidated field, compounded by a one-time bonus escape hatch.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>littlefs</title><link>https://hur01.pages.dev/ctf/nns-ctf/littlefs/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/littlefs/</guid><description>Driving a discontinued Saleae app headlessly through its socket API to open an undocumented capture format.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Keyboard</title><link>https://hur01.pages.dev/ctf/nns-ctf/keyboard/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/keyboard/</guid><description>Decoding USB Low-Speed off the raw wire, then replaying every keystroke - including the edits that build the real flag.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Hardware accelerated flag checker 2</title><link>https://hur01.pages.dev/ctf/nns-ctf/hardware-accelerated-flag-checker-2/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/hardware-accelerated-flag-checker-2/</guid><description>Extracting a netlist back out of a fabricatable SKY130 layout with no PDK installed.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate></item><item><title>sea of theft — Flag of Yore</title><link>https://hur01.pages.dev/ctf/defcamp/sea-of-theft/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/sea-of-theft/</guid><description>An unused sprite renders to a screenshot of the game in dev mode, and the version string in those pixels names a release the bucket never cleaned up.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>ratatouille</title><link>https://hur01.pages.dev/ctf/defcamp/ratatouille/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/ratatouille/</guid><description>A 70-byte .recipe section holds the flag, and the nine anti-analysis environment checks are not a defence — they are the key material.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>hollowdex</title><link>https://hur01.pages.dev/ctf/defcamp/hollowdex/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/hollowdex/</guid><description>JNI_OnLoad rewrites verifyFlag&apos;s bytecode through /proc/self/mem at load time; the shipped dex is a decoy hiding a 3-round Feistel.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>bitdebit2</title><link>https://hur01.pages.dev/ctf/defcamp/bitdebit2/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/bitdebit2/</guid><description>One bit flip into IO_list_all, a seccomp filter that never checks the arch, and a flag read out through connection-drop timing.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>arbitrary-funds-sweep</title><link>https://hur01.pages.dev/ctf/defcamp/arbitrary-funds-sweep/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/arbitrary-funds-sweep/</guid><description>The vault trusts an un-aliased L1 address that was never deployed on L2, and the same permissionless CREATE2 factory exists on both chains.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>legacy</title><link>https://hur01.pages.dev/ctf/defcamp/legacy/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/legacy/</guid><description>Python 2 parses a 2 MB integer literal in quadratic time, so the backup overruns its timeout and the SIGQUIT trap gcores the root password into /tmp.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>aethergate</title><link>https://hur01.pages.dev/ctf/defcamp/aethergate/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/aethergate/</guid><description>Endpoints are validated per list element but stored space-joined and split again into argv, so one space injects curl options and file:// reads /dev/vdb as root.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>prime calc</title><link>https://hur01.pages.dev/ctf/k17/prime-calc/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/prime-calc/</guid><description>Downloading and re-uploading a DMTCP checkpoint is a memory read/write primitive; one 36-byte path swap makes the worker read /flag instead of its config.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>big-win</title><link>https://hur01.pages.dev/ctf/k17/big-win/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/big-win/</guid><description>A loop that exits on != and can increment twice per pass never terminates, and its own counter is reachable through the array it bounds.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>make-a-wish</title><link>https://hur01.pages.dev/ctf/k17/make-a-wish/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/make-a-wish/</guid><description>A signed modulo on the array index makes free() take a stack pointer, and tcache never checks that a chunk lives on the heap.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>huge binary 1</title><link>https://hur01.pages.dev/ctf/k17/huge-binary-1/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/huge-binary-1/</guid><description>An unchecked stack index leaks libc and printf is called twice, so one GOT overwrite turns the second call into system(&quot;/bin/sh&quot;).</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>ihyh</title><link>https://hur01.pages.dev/ctf/k17/ihyh/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/ihyh/</guid><description>fclose() without NULLing the global FILE * lets a 464-byte note become the FILE struct, turning fflush into write(2) and fwrite into system().</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>huge binary 2</title><link>https://hur01.pages.dev/ctf/k17/huge-binary-2/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/huge-binary-2/</guid><description>One byte of leak per run, so the first job is a loop: a single %hhn on a page-aligned libc address makes main call itself forever.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>not-json</title><link>https://hur01.pages.dev/ctf/k17/not-json/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/not-json/</guid><description>Two loops sharing one buffer compose: the key loop&apos;s overflow breaks the canary and the description loop&apos;s terminator repairs it, then one byte of saved RBP pivots the frame.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>solstice-9</title><link>https://hur01.pages.dev/ctf/defcamp/solstice-9/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/defcamp/solstice-9/</guid><description>Three bench captures each hide the real component next to a more attractive decoy; assembling the 96-byte fixture and inverting boarddiag&apos;s lane routing yields the Ed25519 private key.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>spot</title><link>https://hur01.pages.dev/ctf/k17/spot/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/spot/</guid><description>The commitment is counted with FIONREAD but never read until after the reveal, and splice() puts a page reference in the pipe rather than bytes.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>waf</title><link>https://hur01.pages.dev/ctf/k17/waf/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/waf/</guid><description>The anti-ROP memset zeroes everything after the first NUL — and since we choose both the NUL position and the length, it becomes the tool that writes the chain.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>java notes</title><link>https://hur01.pages.dev/ctf/k17/java-notes/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/k17/java-notes/</guid><description>commons-collections 3.2.1 on the classpath and an unfiltered readObject(), so CC6 gives blind RCE exfiltrated with curl&apos;s --data-binary.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Death Ops</title><link>https://hur01.pages.dev/ctf/pwnsec/death-ops/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/death-ops/</guid><description>96 bytes of alphanumeric loader out of a seccomp jail, then a kernel LPE built on a char device that allows exactly two arbitrary writes.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Gap Gap</title><link>https://hur01.pages.dev/ctf/pwnsec/gap-gap/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/gap-gap/</guid><description>p-1 and q-1 share a 600-bit prime, which turns 30 redacted digits of d into a Coppersmith root modulo an unknown divisor of N-1.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Freal World Manipulation</title><link>https://hur01.pages.dev/ctf/pwnsec/freal-world-manipulation/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/freal-world-manipulation/</guid><description>An IEEE754 overflow blows the index limit open, and the mincore() bounds check becomes the oracle that defeats 1 GB of brk randomisation.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>peekaboo</title><link>https://hur01.pages.dev/ctf/pwnsec/peekaboo/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/peekaboo/</guid><description>seccomp allows 8-byte writes from one page only, so the ciphertext is found by mmap binary search and the 24-bit srand seed does the rest.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>pickle</title><link>https://hur01.pages.dev/ctf/pwnsec/pickle/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/pickle/</guid><description>Every string written as \uXXXX slips past a byte-level blocklist, and the check that should have stopped REDUCE throws inside its own try.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>ycc</title><link>https://hur01.pages.dev/ctf/pwnsec/ycc/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/ycc/</guid><description>The sandbox flags are airtight; the bug is that emit_dot splices an unescaped key into the generated C, so a map lookup breaks out into system().</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Zigerions</title><link>https://hur01.pages.dev/ctf/pwnsec/zigerions/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/zigerions/</guid><description>A VMProtect-packed dropper chain whose final payload is an unrunnable ELF carrying an AES key next to its own ciphertext.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>pwnsec-support</title><link>https://hur01.pages.dev/ctf/pwnsec/pwnsec-support/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/pwnsec-support/</guid><description>SQLi into a bespoke register VM, then a 4-byte arbitrary write turned into an arbitrary read by type-confusing a Lua table slot.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>PHault</title><link>https://hur01.pages.dev/ctf/pwnsec/phault/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/pwnsec/phault/</guid><description>Identical responses and padded timing close every usual channel, so the oracle becomes PHP&apos;s memory_limit: a 34 MB row makes the page fatal.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Hardware accelerated flag checker 1</title><link>https://hur01.pages.dev/ctf/nns-ctf/hardware-accelerated-flag-checker-1/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/hardware-accelerated-flag-checker-1/</guid><description>Writing a gate-level simulator for an anonymous Yosys netlist and walking its KMP-style automaton.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Cheese</title><link>https://hur01.pages.dev/ctf/nns-ctf/cheese/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/cheese/</guid><description>Reproducing a lockdown browser&apos;s integrity headers from its config file alone, without ever installing it.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Light-Weight Encryption</title><link>https://hur01.pages.dev/ctf/nns-ctf/light-weight-encryption/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/light-weight-encryption/</guid><description>Publishing the whole LWE relation lets any kernel vector cancel the secret, reducing the break to a scalar trapdoor.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Impossible</title><link>https://hur01.pages.dev/ctf/nns-ctf/impossible/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/impossible/</guid><description>Leaked ceremony toxic waste turns Groth16 into a rubber stamp for any public statement at all.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate></item><item><title>From Nothing</title><link>https://hur01.pages.dev/ctf/nns-ctf/from-nothing/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/from-nothing/</guid><description>Recovering a withheld Mumford v-polynomial, then the Jacobian&apos;s order via complex multiplication instead of point counting.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Crypto Party 2</title><link>https://hur01.pages.dev/ctf/nns-ctf/crypto-party-2/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/crypto-party-2/</guid><description>A UUID4 used as an ECDSA nonce has ~106 unpredictable bits, recovered with a 168-dimension lattice.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate></item><item><title>RLP Golf</title><link>https://hur01.pages.dev/ctf/nns-ctf/rlp-golf/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/rlp-golf/</guid><description>Hand-written Yul assembling canonical RLP with mstore8 headers and calldatacopy bodies, scored purely on gas.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Void</title><link>https://hur01.pages.dev/ctf/nns-ctf/void/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/void/</guid><description>An off-by-one in Cairo&apos;s circuit failure-guarantee lets a STARK prove that an invertible element has no inverse.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Fork</title><link>https://hur01.pages.dev/ctf/nns-ctf/fork/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/fork/</guid><description>A Move VM module cache that lives outside Block-STM&apos;s tracked read-set, raced into a permanent chain fork.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CERN</title><link>https://hur01.pages.dev/ctf/nns-ctf/cern/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/cern/</guid><description>Two Aztec functions share a 4-byte selector, so redirecting a callback to the contract itself mints its private notes to me.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Block Rehearsal</title><link>https://hur01.pages.dev/ctf/nns-ctf/block-rehearsal/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/block-rehearsal/</guid><description>Crashing a Mina validator through a zip_exn that fires before any proof is ever verified.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Bank of NNS</title><link>https://hur01.pages.dev/ctf/nns-ctf/bank-of-nns/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/bank-of-nns/</guid><description>A permutation-cycle bug in kimchi&apos;s connect_64bit leaves a range-check limb entirely unconstrained.</description><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Reverse Grand Prix</title><link>https://hur01.pages.dev/ctf/nns-ctf/reverse-grand-prix/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/reverse-grand-prix/</guid><description>Zero-cost AST nodes defeat solc&apos;s inliner size heuristic, compressing a 157-second compile bomb into 637 bytes.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Glomma River Trading</title><link>https://hur01.pages.dev/ctf/nns-ctf/glomma-river-trading/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/glomma-river-trading/</guid><description>A perp market that reads its mark price straight off the thin AMM pool you are free to trade against.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate></item><item><title>eu261</title><link>https://hur01.pages.dev/ctf/nns-ctf/eu261/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/nns-ctf/eu261/</guid><description>A textbook checks-effects-interactions violation, reentered 16 times to drain a compensation fund to exactly zero.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate></item><item><title>basic_heap_overflow</title><link>https://hur01.pages.dev/writeups/dreamhack/basic-heap-overflow/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/basic-heap-overflow/</guid><description>No PIE fixes the address of get_shell, so a 28-byte heap overflow is enough to redirect execution.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Buffer Overflow Practice</title><link>https://hur01.pages.dev/concepts/exploitation/buffer-overflow-practice/</link><guid isPermaLink="true">https://hur01.pages.dev/concepts/exploitation/buffer-overflow-practice/</guid><description>Working through a full stack-overflow methodology on VulnServer: spiking, fuzzing, offset, bad characters, module, shellcode.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Launching Calculator with a Buffer Overflow</title><link>https://hur01.pages.dev/concepts/exploitation/launching-calculator-with-a-buffer-overflow/</link><guid isPermaLink="true">https://hur01.pages.dev/concepts/exploitation/launching-calculator-with-a-buffer-overflow/</guid><description>Reproducing a Windows buffer overflow end to end, using mona.py to find the offset and land a payload.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>awesome-basics</title><link>https://hur01.pages.dev/writeups/dreamhack/awesome-basics/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/awesome-basics/</guid><description>A textbook stack overflow: an 80-byte buffer read with 0x80, overwriting RIP to jump into shellcode.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Sigreturn-Oriented Programming (SROP)</title><link>https://hur01.pages.dev/writeups/dreamhack/sigreturn-oriented-programming-srop/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/sigreturn-oriented-programming-srop/</guid><description>Notes on SROP: forging a sigcontext frame so a single sigreturn sets every register at once.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>cherry</title><link>https://hur01.pages.dev/writeups/dreamhack/cherry/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/cherry/</guid><description>strncmp only checks the first six bytes, so the rest of the overflow is free to reach the return address.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>mmapped</title><link>https://hur01.pages.dev/writeups/dreamhack/mmapped/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/mmapped/</guid><description>Overflow the length argument to mprotect so the real flag page is never protected before it is written out.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>validator</title><link>https://hur01.pages.dev/writeups/dreamhack/validator/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/validator/</guid><description>NX disabled and a writable GOT, so the shellcode is written directly into the GOT and jumped to.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>off_by_one_000</title><link>https://hur01.pages.dev/writeups/dreamhack/off-by-one-000/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/off-by-one-000/</guid><description>A single byte past the end of the buffer is enough to shift the saved frame pointer and take control.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>ssp_000</title><link>https://hur01.pages.dev/writeups/dreamhack/ssp-000/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/ssp-000/</guid><description>Stack canary present, so the exploit reads it out first and writes it back in place during the overflow.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>memory_leakage</title><link>https://hur01.pages.dev/writeups/dreamhack/memory-leakage/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/memory-leakage/</guid><description>A struct read back without clearing it first leaks adjacent heap memory field by field.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>basic_exploitation_003</title><link>https://hur01.pages.dev/writeups/dreamhack/basic-exploitation-003/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/basic-exploitation-003/</guid><description>A 32-bit binary with no canary and no PIE, exploited by overflowing into the return address.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Exploit Tech: __environ</title><link>https://hur01.pages.dev/writeups/dreamhack/exploit-tech-environ/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/exploit-tech-environ/</guid><description>Full RELRO and PIE, so the stack address is leaked through the environ pointer in libc instead.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>hook</title><link>https://hur01.pages.dev/writeups/dreamhack/hook/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/hook/</guid><description>The binary is linked with -z norelro, leaving the init/fini arrays writable and hijackable.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>sint</title><link>https://hur01.pages.dev/writeups/dreamhack/sint/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/sint/</guid><description>A signed comparison lets a negative length through, which then becomes a huge unsigned size in the copy.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Return to Library (RTL)</title><link>https://hur01.pages.dev/writeups/dreamhack/return-to-library-rtl/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/return-to-library-rtl/</guid><description>NX blocks shellcode, so the return address goes to a libc function instead. PIE is off, so the offsets hold.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Return to Shellcode</title><link>https://hur01.pages.dev/writeups/dreamhack/return-to-shellcode/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/return-to-shellcode/</guid><description>A canary blocks a direct return overwrite, but the stack is executable, so the shellcode goes there.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>oneshot</title><link>https://hur01.pages.dev/writeups/dreamhack/oneshot/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/oneshot/</guid><description>46 bytes into a 16-byte buffer, with a leaked stdout address turning a one-gadget into a working shell.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Reversing Basic Challenge #6</title><link>https://hur01.pages.dev/writeups/dreamhack/reversing-basic-challenge-6/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/reversing-basic-challenge-6/</guid><description>Static analysis in IDA of a routine that checks user input character by character.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>send_sig</title><link>https://hur01.pages.dev/writeups/dreamhack/send-sig/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/send-sig/</guid><description>The program forwards a signal number straight to the kernel; the exploit is choosing the right one.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>cmd_center</title><link>https://hur01.pages.dev/writeups/dreamhack/cmd-center/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/cmd-center/</guid><description>A 24-byte name buffer read with 100 bytes, overflowing into the command string passed to system().</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>basic_exploitation_002</title><link>https://hur01.pages.dev/writeups/dreamhack/basic-exploitation-002/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/basic-exploitation-002/</guid><description>printf(buf) instead of printf(&quot;%s&quot;, buf) - a format string bug turned into a GOT overwrite.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>mistake</title><link>https://hur01.pages.dev/writeups/pwnable-kr/mistake/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/pwnable-kr/mistake/</guid><description>Operator precedence: the result of the comparison lands in fd instead of the file descriptor from open().</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>random</title><link>https://hur01.pages.dev/writeups/pwnable-kr/random/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/pwnable-kr/random/</guid><description>rand() is never seeded, so it returns the same value every run and the password is a fixed constant.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>bof</title><link>https://hur01.pages.dev/writeups/pwnable-kr/bof/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/pwnable-kr/bof/</guid><description>A stack canary blocks the naive overflow, so the write has to be placed around it rather than through it.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>collision</title><link>https://hur01.pages.dev/writeups/pwnable-kr/collision/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/pwnable-kr/collision/</guid><description>Twenty input bytes are read as five ints and summed; any five values adding to 0x21DD09EC pass the check.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>fd</title><link>https://hur01.pages.dev/writeups/pwnable-kr/fd/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/pwnable-kr/fd/</guid><description>atoi(argv[1]) - 0x1234 becomes a file descriptor, so passing 4660 makes the program read from stdin.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>PEPassword</title><link>https://hur01.pages.dev/writeups/reversing-kr/pepassword/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/pepassword/</guid><description>A packed PE unpacked first, then the password-check and decryption paths traced in the original binary.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>SimpleVM</title><link>https://hur01.pages.dev/writeups/reversing-kr/simplevm/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/simplevm/</guid><description>A tiny bytecode VM validating the key; solving it means understanding the instruction set and running it backwards.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Direct3D FPS</title><link>https://hur01.pages.dev/writeups/reversing-kr/direct3d-fps/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/direct3d-fps/</guid><description>A Direct3D game where the win condition is reached by patching the check rather than playing it.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>WindowKernel</title><link>https://hur01.pages.dev/writeups/reversing-kr/windowkernel/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/windowkernel/</guid><description>A Windows kernel driver reading the keyboard port directly, communicating over IOCTL rather than user-mode input.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AutoHotkey2</title><link>https://hur01.pages.dev/writeups/reversing-kr/autohotkey2/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/autohotkey2/</guid><description>UPX-packed and reporting &quot;exe corrupt&quot;; the CRC routine has to be debugged in the original, not the unpacked, file.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>x64 Lotto</title><link>https://hur01.pages.dev/writeups/reversing-kr/x64-lotto/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/x64-lotto/</guid><description>A lottery check decompiled in IDA, where the comparison can be satisfied without guessing the numbers.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AutoHotkey1</title><link>https://hur01.pages.dev/writeups/reversing-kr/autohotkey1/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/autohotkey1/</guid><description>An AutoHotkey-compiled binary: recovering the DecryptKey and the EXE key, then combining them into the AuthKey.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>HateIntel</title><link>https://hur01.pages.dev/writeups/reversing-kr/hateintel/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/hateintel/</guid><description>The binary is for a non-Intel architecture and will not run, so the whole solve is static analysis in IDA.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Flash Encrypt</title><link>https://hur01.pages.dev/writeups/reversing-kr/flash-encrypt/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/flash-encrypt/</guid><description>A SWF file observed dynamically by embedding it in a page, rather than decompiling the ActionScript.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Easy Unpack</title><link>https://hur01.pages.dev/writeups/reversing-kr/easy-unpack/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/easy-unpack/</guid><description>Finding the original entry point of a packed binary and dumping it once the unpacking stub has run.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>ImagePcr</title><link>https://hur01.pages.dev/writeups/reversing-kr/imagepcr/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/imagepcr/</guid><description>The program compares a drawing against a bitmap held in its resources; the flag is the image it expects.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Multiplication</title><link>https://hur01.pages.dev/writeups/reversing-kr/multiplication/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/multiplication/</guid><description>A Java jar with an anti-decompiler trick that breaks JD-GUI, read with CFR instead. The bug is a long overflow.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CSHOP</title><link>https://hur01.pages.dev/writeups/reversing-kr/cshop/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/cshop/</guid><description>A .NET binary that no debugger would open, read instead as IL through a .NET decompiler.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Ransomware</title><link>https://hur01.pages.dev/writeups/reversing-kr/ransomware/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/ransomware/</guid><description>Broken output until the code page is fixed, then recovering the key the sample uses to encrypt and restore files.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Easy ELF</title><link>https://hur01.pages.dev/writeups/reversing-kr/easy-elf/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/easy-elf/</guid><description>A small Linux ELF that XORs input against a fixed table before comparing it to the stored password.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Replace</title><link>https://hur01.pages.dev/writeups/reversing-kr/replace/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/replace/</guid><description>Patching the compare instruction so any input is accepted, which reveals the stored password.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Position</title><link>https://hur01.pages.dev/writeups/reversing-kr/position/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/position/</guid><description>The serial depends on the position of each character of the name, so the keygen has to invert that mapping.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Music Player</title><link>https://hur01.pages.dev/writeups/reversing-kr/music-player/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/music-player/</guid><description>Timing check in a media player: the program has to believe the track played to the end.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Easy Keygen</title><link>https://hur01.pages.dev/writeups/reversing-kr/easy-keygen/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/easy-keygen/</guid><description>Reversing the serial routine and reimplementing it as a keygen that produces a valid serial for any name.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Easy Crack Me</title><link>https://hur01.pages.dev/writeups/reversing-kr/easy-crack-me/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/reversing-kr/easy-crack-me/</guid><description>Breakpointing the comparison in x32dbg and reading the expected password out one character at a time.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Crypto/Oops</title><link>https://hur01.pages.dev/ctf/script-ctf/crypto-oops/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/crypto-oops/</guid><description>I am from the future! I accidentally forgot to link chall.zip!</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Bonus 1, 2 &amp; 3</title><link>https://hur01.pages.dev/ctf/script-ctf/osint-bonus-1-2-3/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/osint-bonus-1-2-3/</guid><description>All three challenges were solved through passive investigation of public profiles and repositories connected to the fictional “newbie” character.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>misc golf</title><link>https://hur01.pages.dev/ctf/script-ctf/misc-golf/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/misc-golf/</guid><description>Produce a number spiral while staying within a strict rendered pixel-width limit.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>FaaS 1.5</title><link>https://hur01.pages.dev/ctf/script-ctf/pwn-faas-1-5/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/pwn-faas-1-5/</guid><description>The service fetched a user-supplied host with curl and displayed the page title.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>pwn faas 2</title><link>https://hur01.pages.dev/ctf/script-ctf/pwn-faas-2/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/pwn-faas-2/</guid><description>The service takes a host, validates it, and passes it to curl.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Leaks</title><link>https://hur01.pages.dev/ctf/script-ctf/pwn-leaks/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/pwn-leaks/</guid><description>The service passed user input directly to printf, creating a format-string vulnerability.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Diabolical</title><link>https://hur01.pages.dev/ctf/script-ctf/rev-diabolical/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/rev-diabolical/</guid><description>The challenge presented a large, statically linked, stripped Go executable.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>web wpm game2</title><link>https://hur01.pages.dev/ctf/script-ctf/web-wpm-game2/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/web-wpm-game2/</guid><description>Recover the flag through a constrained server-side expression.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Rev/MeowvelousShop</title><link>https://hur01.pages.dev/ctf/script-ctf/rev-meowvelous-shop/</link><guid isPermaLink="true">https://hur01.pages.dev/ctf/script-ctf/rev-meowvelous-shop/</guid><description>Analyze a custom virtual machine and uncover the hidden flag path.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>tcache_dup</title><link>https://hur01.pages.dev/writeups/dreamhack/tcache-dup/</link><guid isPermaLink="true">https://hur01.pages.dev/writeups/dreamhack/tcache-dup/</guid><description>A double free puts the same chunk in the tcache list twice, so a later malloc hands back a pointer we control.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>