2017from the authors’ own sites
Bugs Bunny CTF
4 challenges with 4 published solutions between them. The writeups for this event were found on the authors’ own sites.
Where these writeups liveWeb2
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Solve it with:JWT decoder and signature verifierJWT alg=none bypass generatorWeb attack payload catalogJWT secret brute forceLearn: Sessions, tokens and access control
Also written up in: kinyabitch.wordpress.com
LQI X 140
1 official solutionAlso written up in: kinyabitch.wordpress.com
Reverse engineering2
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Solve it with:Strings extractor for binaries and blobsWebAssembly disassemblerJava .class disassemblerPython .pyc bytecode disassemblerLearn: Binary exploitation
Rev100
1 official solutionAlso written up in: kinyabitch.wordpress.com
Rev75
1 official solutionAlso written up in: kinyabitch.wordpress.com