2019from public repositories
BSidesCo 2019
19 challenges with 19 published solutions between them. CTFtime has no listing for this event at all, so nothing built on CTFtime can show what it was made of. These writeups were found in public repositories instead. Each link is pinned to the commit it was read from.
Where these writeups liveWeb9
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Solve it with:JWT decoder and signature verifierJWT alg=none bypass generatorWeb attack payload catalogJWT secret brute forceLearn: Web attacks and session tokens
8.Buscadordesecretos
1 official solution9.PDF
1 official solutionBugBounty1
1 official solutionBugBounty2
1 official solutionBugBounty3
1 official solutionBugBounty4
1 official solutionBugBounty5
1 official solutionBugBounty6
1 official solutionBugBounty7
1 official solution
Uncategorised6
The upstream scoreboard did not say, so neither do we.
2.Exorcismo2
1 official solution3.Exorcismo3
1 official solution4.Irreversible
1 official solution5.Colision
1 official solution7.RobandoSecretosAntiguos2
1 official solution8.Diffieredelmanual
1 official solution
Binary exploitation4
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Solve it with:ROP gadget finderShellcode assembler and libraryCyclic pattern generator and offset finderFormat string exploit builderLearn: Binary exploitation
1.Fugas
1 official solution2.Incontinencia
1 official solution3.MagiaMagia
1 official solution4.Banderas
1 official solution