corCTF 2024
46 challenges with 71 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 5 of them also carry the solution corCTF 2024’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeWeb11
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Also written up in: strellic/my-ctf-challenges, byf1sh/CTF-WriteUps
Also written up in: siunam321/CTF-Writeups, byf1sh/CTF-WriteUps
Adminbot Test
1 official solutionAlso written up in: strellic/my-ctf-challenges
Axios.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
Can.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
- csp
- web
- extension
Same technique in picoCTF: Live Art, secure-email-service, No FA
erm UNFINISHED
1 official solutionAlso written up in: Hope0351/CTF-collection
Also written up in: strellic/my-ctf-challenges
- ssti
- chess
- stockfish
Rock Paper Scissors
1 official solutionAlso written up in: siunam321/CTF-Writeups
rock paper scissors UNFINISHED
1 official solutionAlso written up in: Hope0351/CTF-collection
Uncategorised9
The upstream scoreboard did not say, so neither do we.
Portswigger Labs Cross Origin Resource Sharing
2 official solutionsAlso written up in: siunam321.github.io, siunam321.github.io
Anglerfish
1 official solutionAlso written up in: tvdat20004/CTF_write-up
Chall Setup
1 official solutionAlso written up in: a-p-n/CTF-solutions
Corctf Dev
1 official solutionAlso written up in: cor.team
Also written up in: fireshellsecurity.team
Digest Me
1 official solutionAlso written up in: maplebacon.org
Its Just a Dos Bug Bro Leaking Flags from Filesystem with Spectre v1
1 official solutionAlso written up in: www.willsroot.io
Also written up in: ph0wn/writeups
Trojan Turtles A KVM Escape Exploit from the L2 Guest to the L1 Hypervisor
1 official solutionAlso written up in: www.willsroot.io
Misc7
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in Crusaders-of-Rust/corctf-2024-public-challenge-repo: solution.py
Also written up in: Hope0351/CTF-collection, Hope0351/CTF-collection, Hope0351/CTF-collection
Also written up in: strellic/my-ctf-challenges, strellic/my-ctf-challenges
Chessboard 1.0.0.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
Jquery.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
Socket.Io.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
Sweetalert2.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
Touch Grass 2
1 official solutionAlso written up in: Hope0351/CTF-collection
Cryptography5
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Exchange
5 official solutionsAlso written up in: Hope0351/CTF-collection, Hope0351/CTF-collection, Hope0351/CTF-collection, Hope0351/CTF-collection, rekter0/ctf
Published by the organisers in Crusaders-of-Rust/corctf-2024-public-challenge-repo: solve.sage
Also written up in: tvdat20004/CTF_write-up, tvdat20004/CTF_write-up, tranminhprvt01/CTF-writeups, tranminhprvt01/CTF-writeups
Also written up in: tvdat20004/CTF_write-up, tranminhprvt01/CTF-writeups, tranminhprvt01/CTF-writeups
- algebra
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in Crusaders-of-Rust/corctf-2024-public-challenge-repo: sol.py
- quantum-error-correction
- quantum
- crypto
- qiskit
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Exploit
1 official solutionAlso written up in: napwnli/napwnli_writeups
Reverse engineering5
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Also written up in: strellic/my-ctf-challenges, tvdat20004/CTF_write-up, a-p-n/CTF-solutions, napwnli/napwnli_writeups, tranminhprvt01/CTF-writeups
Published by the organisers in Crusaders-of-Rust/corctf-2024-public-challenge-repo: solve/src/main.rs
Also written up in: strellic/my-ctf-challenges, nnub.es
- minecraft
- rev
- game-hacking
- rust
- game
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- game-hacking
- rev
- minecraft
- game
- rust
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Also written up in: strellic/my-ctf-challenges
Forensics5
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Also written up in: Hope0351/CTF-collection, Hope0351/CTF-collection, cor.team
- pcap
- forensics
Same technique in picoCTF: FindAndOpen, Ph4nt0m 1ntrud3r, WebNet0
Also written up in: cor.team
- forensics
- windows
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Decrypted Message
1 official solutionAlso written up in: Hope0351/CTF-collection
infiltration UNFINISHED
1 official solutionAlso written up in: Hope0351/CTF-collection
Published by the organisers in Crusaders-of-Rust/corctf-2024-public-challenge-repo: solve.py
Binary exploitation4
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Also written up in: miraicantsleep/ctf-writeups
- format-string
- pwn
Same technique in picoCTF: PIE TIME 2, Binary Gauntlet 2, Binary Gauntlet 3
- cve
- sqlite
- pwn
- 1day
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- micro-architecture
- side-channel
- entrybleed
- kernel
- pwn
- spectre
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- hypervisor
- pwn
- nested-kvm-escape
- kvm
- hypervisor-escape
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz