BSidesSF 2019 CTF
49 challenges with 104 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 25 of them also carry the solution BSidesSF 2019 CTF’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeUncategorised15
The upstream scoreboard did not say, so neither do we.
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md, solution/solve.rb
Published by the organisers in BSidesSF/ctf-2019-release: solutions/goodluks1.md, solutions/goodluks2.md
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md, solution/solution.c
Published by the organisers in BSidesSF/ctf-2019-release: solution/check_net.pl, solution/check.sh
Bruteforce
1 official solutionAlso written up in: NicolaiSoeborg/ctf-writeups
Published by the organisers in BSidesSF/ctf-2019-release: solution/readme.md
Published by the organisers in BSidesSF/ctf-2019-release: solution/readme.md
Dribbles (250pt)
1 official solutionAlso written up in: ctf.harrisongreen.me
Fastflag (150pt)
1 official solutionAlso written up in: ctf.harrisongreen.me
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Pngsvg
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Runit Solve
1 official solutionAlso written up in: tephracore/ctf-writeups
Runitplusplus Solve
1 official solutionAlso written up in: tephracore/ctf-writeups
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Forensics11
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2019-release: solution/readme.md
Also written up in: mzfr/ctf-writeups, 0xmzfr/ctf-writeups
- forensics
- dos
Same technique in picoCTF: Timeline 0, Timeline 1, Sleuthkit Apprentice
Also written up in: mzfr/ctf-writeups, 0xmzfr/ctf-writeups
- luks
- forensics
- johntheripper
- hashcat
Same technique in picoCTF: WPA-ing Out, investigation_encoded_2, FindAndOpen
Also written up in: mzfr/ctf-writeups, 0xmzfr/ctf-writeups
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Also written up in: mzfr/ctf-writeups, 0xmzfr/ctf-writeups
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in BSidesSF/ctf-2019-release: solution/steps.txt
- forensic
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
100 thekey COMPLETE
1 official solutionAlso written up in: Eshaan7/CTFs_datadumps_2019
- luks
- masterkey
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Pgpdata
1 official solutionAlso written up in: Eshaan7/CTFs_datadumps_2019
thekey(Forensics 100)
1 official solutionAlso written up in: imurasheen.hatenablog.com
Reverse engineering6
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Also written up in: quintuplecs/BSidesSF2019
- mobile
- forensics
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in BSidesSF/ctf-2019-release: solution/solution.py
- sse
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Also written up in: NicolaiSoeborg/ctf-writeups, NicolaiSoeborg/ctf-writeups
- mobile
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in BSidesSF/ctf-2019-release: solution/solution.py
- rev
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- blind
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- mobile
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Web5
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: beerpwn/ctf
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Also written up in: beerpwn/ctf
- web
- crypto
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Also written up in: quintuplecs/BSidesSF2019
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Binary exploitation5
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Also written up in: merrychap/ctf-writeups, VoidHack/write-ups, konatabrk/ctf-writeups, Hope0351/CTF-collection, merrychap/ctf-writeups, VoidHack/write-ups, konatabrk/ctf-writeups, Hope0351/CTF-collection
- pwn
- reverse
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2019-release: solution/solution.py
Also written up in: sajjadium/ctf-writeups, sajjadium/ctf-writeups, sajjadium/CTFium, sajjadium/CTFium, sajjadium/ctf-writeups, sajjadium/ctf-writeups, sajjadium/PersianCatsCTF, sajjadium/PersianCatsCTF
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: merrychap/ctf-writeups, konatabrk/ctf-writeups, Hope0351/CTF-collection, merrychap/ctf-writeups, konatabrk/ctf-writeups, Hope0351/CTF-collection
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
Also written up in: quintuplecs/BSidesSF2019
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Misc5
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in BSidesSF/ctf-2019-release: solution/readme.md
Also written up in: mzfr/ctf-writeups, 0xmzfr/ctf-writeups
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
blink(101 Mobile 50)
1 official solutionAlso written up in: imurasheen.hatenablog.com
Track
1 official solutionAlso written up in: aadityapurani.com
- trivia
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Cryptography2
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in BSidesSF/ctf-2019-release: solution/factor/factor_test.go, solution/factor/factor.go, solution/main.go
- crypto
- rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
Published by the organisers in BSidesSF/ctf-2019-release: solution/README.md, solution/Poracle.rb, solution/Solution.rb
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC