├── 2017 Christmas
├── .gitkeep
├── babyCPP
└── babyCPP.cpp
├── HITCON
├── ragnarok
│ ├── .gitkeep
│ ├── libc.so.6
│ ├── libvtv.so.0
│ ├── ragnarok.bin
│ ├── ragnarok.py
│ └── ragnarok.cc
├── Start
│ ├── start.py
│ ├── README.md
│ └── start.rb
└── babyfs
│ ├── babyfs.py
│ └── README.md
├── SECCON
├── video_player
│ ├── .gitkeep
│ └── video.py
└── vm_no_fun
│ ├── .gitkeep
│ └── inception.py
├── secuinside-2017
├── .gitkeep
├── ChildHeap
│ ├── .gitkeep
│ └── child.py
├── IdolMaster
│ ├── .gitkeep
│ └── idol.py
├── Very Very Chart
│ ├── .gitkeep
│ └── chart.py
└── Very Very Very
│ ├── .gitkeep
│ ├── vvv
│ └── vvv.py
├── 2017 Codegate Finals
└── VM
│ ├── .gitkeep
│ ├── VM
│ └── VM.py
├── 2017 Whitehat Contest
└── bank
│ ├── .gitkeep
│ ├── bank
│ └── bank.py
├── 2018 AceBear CTF
├── Comic Store
│ ├── .gitkeep
│ └── comic.py
├── easy heap
│ ├── .gitkeep
│ └── easy.py
└── lol game
│ ├── .gitkeep
│ └── lol.py
├── 2018 Codegate Quals
├── 7amebox1
│ ├── .gitkeep
│ ├── 7amebox1.zip
│ ├── 7amebox1.py
│ └── disassembler.py
├── SuperFTP
│ ├── .gitkeep
│ ├── SuperFTP.py
│ └── README.md
├── babyRSA
│ ├── .gitkeep
│ ├── README.md
│ └── RSAbaby.py
├── baskin
│ ├── .gitkeep
│ ├── README.md
│ └── baskin.py
└── SuperMarimo
│ ├── .gitkeep
│ ├── README.md
│ └── SuperMarimo.py
├── 2018 TokyoWesterns CTF
├── crypto
│ ├── .gitkeep
│ └── mix.py
└── pwnable
│ ├── .gitkeep
│ ├── gc.py
│ └── neighbor.py
├── Codeblue CTF
├── nonamestill
│ ├── README.md
│ ├── noname
│ └── noname-first.py
└── Secret Mailer Service
│ ├── README.md
│ ├── mailer
│ └── mailer.py
├── Codegate 2017 Quals
├── hunting
│ ├── .gitkeep
│ ├── hunting
│ └── hunting.py
└── dartmaster
│ ├── .gitkeep
│ └── dartmaster.py
├── 2018 Insomni-hack teaser
└── sapeloshop
│ ├── .gitkeep
│ ├── sapeloshop
│ ├── libc-2.23.so
│ ├── footer.html
│ ├── order.html
│ ├── header.html
│ ├── sapeloshop.py
│ └── index.html
├── README.md
├── 2019 PCTF
├── cppp
│ └── solve.py
├── Splaid Birch
│ └── solve.py
└── Suffarring
│ └── solve.py
├── mix.py
└── LICENSE
/2017 Christmas/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/HITCON/ragnarok/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/SECCON/video_player/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/SECCON/vm_no_fun/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/secuinside-2017/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2017 Codegate Finals/VM/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2017 Whitehat Contest/bank/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 AceBear CTF/Comic Store/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 AceBear CTF/easy heap/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 AceBear CTF/lol game/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/7amebox1/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/SuperFTP/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/babyRSA/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/baskin/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 TokyoWesterns CTF/crypto/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/Codeblue CTF/nonamestill/README.md:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/Codegate 2017 Quals/hunting/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/secuinside-2017/ChildHeap/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/secuinside-2017/IdolMaster/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/SuperMarimo/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 TokyoWesterns CTF/pwnable/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/Codegate 2017 Quals/dartmaster/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/secuinside-2017/Very Very Chart/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/secuinside-2017/Very Very Very/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/2018 Insomni-hack teaser/sapeloshop/.gitkeep:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/Codeblue CTF/Secret Mailer Service/README.md:
--------------------------------------------------------------------------------
1 |
2 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # CTF
2 | Write-up for Hardcore Pwnable&CryptoGraphy
3 |
--------------------------------------------------------------------------------
/2017 Christmas/babyCPP:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/2017 Christmas/babyCPP
--------------------------------------------------------------------------------
/HITCON/ragnarok/libc.so.6:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/HITCON/ragnarok/libc.so.6
--------------------------------------------------------------------------------
/2017 Codegate Finals/VM/VM:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/2017 Codegate Finals/VM/VM
--------------------------------------------------------------------------------
/HITCON/ragnarok/libvtv.so.0:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/HITCON/ragnarok/libvtv.so.0
--------------------------------------------------------------------------------
/HITCON/ragnarok/ragnarok.bin:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/HITCON/ragnarok/ragnarok.bin
--------------------------------------------------------------------------------
/2017 Whitehat Contest/bank/bank:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/2017 Whitehat Contest/bank/bank
--------------------------------------------------------------------------------
/Codeblue CTF/nonamestill/noname:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/Codeblue CTF/nonamestill/noname
--------------------------------------------------------------------------------
/Codegate 2017 Quals/hunting/hunting:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/Codegate 2017 Quals/hunting/hunting
--------------------------------------------------------------------------------
/secuinside-2017/Very Very Very/vvv:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/secuinside-2017/Very Very Very/vvv
--------------------------------------------------------------------------------
/2018 Codegate Quals/7amebox1/7amebox1.zip:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/2018 Codegate Quals/7amebox1/7amebox1.zip
--------------------------------------------------------------------------------
/Codeblue CTF/Secret Mailer Service/mailer:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/Codeblue CTF/Secret Mailer Service/mailer
--------------------------------------------------------------------------------
/2018 Insomni-hack teaser/sapeloshop/sapeloshop:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/2018 Insomni-hack teaser/sapeloshop/sapeloshop
--------------------------------------------------------------------------------
/2018 Insomni-hack teaser/sapeloshop/libc-2.23.so:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/mathboy7/CTF/HEAD/2018 Insomni-hack teaser/sapeloshop/libc-2.23.so
--------------------------------------------------------------------------------
/HITCON/Start/start.py:
--------------------------------------------------------------------------------
1 | from pwn import *
2 |
3 | r = remote("54.65.72.116", 31337)
4 |
5 | print r.recvuntil("> ")
6 | d = open("start.rb").read()
7 | r.send(d)
8 |
9 | r.interactive()
10 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/SuperMarimo/README.md:
--------------------------------------------------------------------------------
1 | There is heap overflow vulnerability in Edit menu.
2 | We can modify string pointer of profile pointer to GOT and leak libc, overwrite GOT to one_shot gadget.
3 | easy XD
4 |
--------------------------------------------------------------------------------
/2018 Codegate Quals/baskin/README.md:
--------------------------------------------------------------------------------
1 | There is stack buffer overflow vulnerability in your_turn() function.
2 | Problem kindly provides some gadgets to make life easy.
3 | Use write() function to leak libc address.
4 | Change control flow to main() again, call system("/bin/sh").
5 |
--------------------------------------------------------------------------------
/HITCON/Start/README.md:
--------------------------------------------------------------------------------
1 | Start - Pwn 132 (165 Teams Solved)
2 | -------------
3 | ### Description
4 | Have you tried pwntools-ruby?
5 | nc 54.65.72.116 31337
6 | (link to binary)
7 |
8 | ### Solution
9 | Binary has simple buffer overflow vulnerability.
10 |
11 | We have to write exploit code with pwntools-ruby and send to server.
12 |
13 | Details are in my exploit code. (start.py, start.rb)
14 |
--------------------------------------------------------------------------------
/2018 Insomni-hack teaser/sapeloshop/footer.html:
--------------------------------------------------------------------------------
1 |
2 |