CSAW CTF Qualification Round 2019
64 challenges with 194 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 16 of them also carry the solution CSAW CTF Qualification Round 2019’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeUncategorised33
The upstream scoreboard did not say, so neither do we.
Baby Boi 50
6 official solutionsAlso written up in: jacopotediosi/CTF-Writeups, jacopotediosi/Writeups, perfectblue/ctf-writeups, jacopotediosi/CTF-Writeups, jacopotediosi/Writeups, rollsafe/ctf-writeups
Dudeweedlmao
4 official solutionsAlso written up in: perfectblue/ctf-writeups, perfectblue/ctf-writeups, rollsafe/ctf-writeups, rollsafe/ctf-writeups
Also written up in: perfectblue/ctf-writeups, Merricx/ctf-writeups, rollsafe/ctf-writeups
BabyCSP 50
2 official solutionsAlso written up in: jacopotediosi/CTF-Writeups, jacopotediosi/Writeups
Brillouin 500
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Buyifi 500
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Byte Me 50
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Callsite 100
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Chal Visitor
2 official solutionsAlso written up in: jacopotediosi/CTF-Writeups, jacopotediosi/Writeups
Chosen Plaintext
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Count On Me 100
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Des 2 Bites 200
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Fault Box 400
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Gibberish 200
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Halfpike 500
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Jquery
2 official solutionsAlso written up in: jacopotediosi/CTF-Writeups, jacopotediosi/Writeups
Also written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Popping Caps 300
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Popping Caps2 350
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Secure file storage 300
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Timelie 150
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Tvm 400
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Unagi 200
2 official solutionsAlso written up in: jacopotediosi/CTF-Writeups, jacopotediosi/Writeups
Wizkid 350
2 official solutionsAlso written up in: perfectblue/ctf-writeups, rollsafe/ctf-writeups
Curves
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Custom
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Custom Bruter
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Custom1
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Fault
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Novotney
1 official solutionAlso written up in: alex-bellon/ctf-writeups
Sassy
1 official solutionAlso written up in: aadityapurani/My-CTF-Solutions
Server
1 official solutionAlso written up in: Merricx/ctf-writeups
Travller
1 official solutionAlso written up in: farazsth98/CTF
Binary exploitation10
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solver.py
Also written up in: farazsth98/CTF, bootplug/writeups, meowmeowxw.gitlab.io, cesena.github.io
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solver.py
Also written up in: farazsth98/CTF, meowmeowxw.gitlab.io, cesena.github.io
- fmtstr
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solver.py
Also written up in: farazsth98/CTF, faraz.faith
- srop
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solve.py
Also written up in: bootplug/writeups
- pwn
- tcache
- tcache_perthread_struct
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solve.py
- pwnable
- tcache
- heap
Same technique in picoCTF: vr-school, sice_cream, zero_to_hero
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solver.py
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: sol.py
Also written up in: bootplug/writeups
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: rpis.ec
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Assemble
1 official solutionAlso written up in: bootplug/writeups
Also written up in: bootplug/writeups
Web9
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solver.sh
Also written up in: jiafuei/ctf-writeups, cesena.github.io
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: w181496/CTF, bootplug/writeups, bootplug/writeups
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: cesena.github.io
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: sol.py
Also written up in: terjanq/Flag-Capture, terjanq/Flag-Capture
- web
- template-injection
- nodejs
Same technique in picoCTF: Live Art, secure-email-service, No FA
Babycsp (Web 50)
1 official solutionAlso written up in: 0xiso.hatenablog.com
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: exploit_cleaned.py
Secure File Storage (web 300)
1 official solutionAlso written up in: 0xiso.hatenablog.com
Unagi (Web 200)
1 official solutionAlso written up in: 0xiso.hatenablog.com
Cryptography7
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: README.md, solver.py
Also written up in: jiafuei/ctf-writeups, jiafuei/ctf-writeups, Merricx/ctf-writeups, meowmeowxw.gitlab.io, cesena.github.io
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: README.md, solver.py
Also written up in: Merricx/ctf-writeups
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solve.py
Also written up in: alex-bellon/ctf-writeups, Merricx/ctf-writeups
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solve.py
Also written up in: Merricx/ctf-writeups
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: Merricx/ctf-writeups
- crypto
- des
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: README.md, solver.py
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Reverse engineering5
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Also written up in: bannsecurity.com, meowmeowxw.gitlab.io, cesena.github.io
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- reverse
- engineering
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- reversing
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in osirislab/CSAW-CTF-2019-Quals: solver.py
- reversing
- ghc
- haskell
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200