CSAW CTF Qualification Round 2017
38 challenges with 188 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 15 of them also carry the solution CSAW CTF Qualification Round 2017’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeBinary exploitation10
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: README.md
Also written up in: VulnHub/ctf-writeups, vulnhub/ctf-writeups, 0ops/ctfs, briansp8210/CTF-writeup, integeruser/on-pwning, willtuna/CTF-writeup, sajjadium/ctf-writeups, sajjadium/CTFium
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: README.md
Also written up in: VulnHub/ctf-writeups, vulnhub/ctf-writeups, briansp8210/CTF-writeup, integeruser/on-pwning, willtuna/CTF-writeup, 0ops/ctfs, briansp8210/CTF-writeup, posgnu/ctfs
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: README.md
Also written up in: 0ops/ctfs, briansp8210/CTF-writeup, integeruser/on-pwning, willtuna/CTF-writeup, briansp8210/CTF-writeup, toomanybananas/ctf_solutions, willtuna/CTF-writeup
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: briansp8210/CTF-writeup, integeruser/on-pwning, willtuna/CTF-writeup, briansp8210/CTF-writeup, toomanybananas/ctf_solutions, willtuna/CTF-writeup
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solution.pdf, sol.py
Also written up in: integeruser/on-pwning
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solution/exploit.py
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Pwn500
2 official solutionsAlso written up in: ByteBandits/writeups, Hope0351/CTF-collection
Sudhackar
2 official solutionsAlso written up in: ByteBandits/writeups, Hope0351/CTF-collection
CSAW2017 pwn true
1 official solutionAlso written up in: mfakbar127/CTF-Writeup
Web7
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Also written up in: duykham.blogspot.fr
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: qwaz/solved-hacking-problem
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
- lfi
- nodejs
Also written up in: duykham.blogspot.fr
- sqli
- runtime.js
- web
Same technique in picoCTF: Irish-Name-Repo 3, Startup Company, More SQLi
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solver/BeanSolve.java, solver/n.txt, solver/PasswordMatch.java
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solver/target/surefire-reports/solver.AppTest.txt
Reverse engineering5
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solve.py
Also written up in: TechSecCTF/writeups, TechSecCTF/writeups
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: README.md
Also written up in: posgnu/ctfs, toomanybananas/ctf_solutions
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solve.py
Also written up in: rossgibb/ctf
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solver.py
Misc5
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solver.py
- python
- misc
Same technique in picoCTF: PW Crack 2, PW Crack 1, PW Crack 3
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solver.py
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
CSAW2017 misc cvv
1 official solutionAlso written up in: mfakbar127/CTF-Writeup
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- misc
- csaw
- cvv
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Uncategorised5
The upstream scoreboard did not say, so neither do we.
Realism Rev400
2 official solutionsAlso written up in: maroueneboubakri.blogspot.fr, maroueneboubakri.blogspot.com
Tablez
2 official solutionsAlso written up in: posgnu/ctfs, posgnu/ctfs
Babycrypto
1 official solutionAlso written up in: pietroferretti/ctf
Decrypt
1 official solutionAlso written up in: pietroferretti/ctf
SCV (100pt)
1 official solutionAlso written up in: ctf.harrisongreen.me
Cryptography4
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solver.py
Also written up in: oalieno/CTF, OAlienO/CTF, viz-prakash/CTF, oalieno/CTF, OAlienO/CTF
- xor
- crypto
- cryptography
Same technique in picoCTF: Custom encryption, XtraORdinary, It's Not My Fault 2
Published by the organisers in osirislab/CSAW-CTF-2017-Quals: solve_baby_crypt.py
Also written up in: ashutosh1206/Crypto-CTF-Writeups, Hope0351/CTF-collection, viz-prakash/CTF, ashutosh1206/Crypto-CTF-Writeups, Hope0351/CTF-collection
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: qwaz/solved-hacking-problem, oalieno/CTF, oalieno/CTF, OAlienO/CTF, OAlienO/CTF, qwaz/solved-hacking-problem, oalieno/CTF, OAlienO/CTF
- crypto
Same technique in picoCTF: Custom encryption, XtraORdinary, It's Not My Fault 2
Cipher
1 official solutionAlso written up in: viz-prakash/CTF
Forensics2
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
- pcap
- forensics
Same technique in picoCTF: FindAndOpen, Ph4nt0m 1ntrud3r, WebNet0
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r