BSides San Francisco CTF
50 challenges with 112 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 28 of them also carry the solution BSides San Francisco CTF’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeWeb8
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: thund3rblog.wordpress.com
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in BSidesSF/ctf-2017-release: solution/solve3.py
Also written up in: pogTeam/writeups
20p Zumbo1
1 official solutionAlso written up in: thund3rblog.wordpress.com
Easyauth 30p
1 official solutionAlso written up in: thund3rblog.wordpress.com
Binary exploitation8
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in BSidesSF/ctf-2017-release: solution/command_set.txt, solution/run_raw/run_raw.c, solution/shellcode/shellcode.asm, solution/shellcode/shellcode2.asm, solution/shellcode/shellcode3.asm, solution/sploit.rb
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2017-release: solution/sploit.rb
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
Reverse engineering8
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- android
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- re
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- re
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
Forensics8
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
Also written up in: pogTeam/writeups
- forensic
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md, solution/extract_code.rb, solution/run_raw_code.c
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- network
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
Misc8
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
zumbo 1 & 2 & 3
8 writeupsSame technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: pogTeam/writeups
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in BSidesSF/ctf-2017-release: solution/solution.txt
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- trivia
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- ppc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
20 NOP
1 official solutionAlso written up in: KevOrr/ctf-writeups
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
Zumbo1&2
1 writeupSame technique in picoCTF: PW Crack 2, Permissions, Specialer
Cryptography6
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in BSidesSF/ctf-2017-release: solution/DelphiSolution.rb, solution/LICENSE.txt, solution/Poracle.rb
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in BSidesSF/ctf-2017-release: solution/README.md
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in BSidesSF/ctf-2017-release: solution/solution.txt
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in BSidesSF/ctf-2017-release: solution/solve.py
Uncategorised4
The upstream scoreboard did not say, so neither do we.
Ancient Hop Grain Juice
1 official solutionAlso written up in: pogTeam/writeups
Let s play a game
1 official solutionAlso written up in: pogTeam/writeups
Quote
1 official solutionAlso written up in: pogTeam/writeups
The Right Cipher
1 official solutionAlso written up in: pogTeam/writeups