DownUnderCTF 2020
77 challenges with 259 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 40 of them also carry the solution DownUnderCTF 2020’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeMisc23
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.py
Also written up in: rkm0959/CTFWriteups, alright21/ctf, alright21/ctf, ROFLailXGOD/CTFs, SamIsland/CTF-Writeups, TARS-02/CTF-Writeups
- rot
- caesar
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: ROFLailXGOD/CTFs
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: fr334aks/DownUnderCTF_2020
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: jeanettesa/ctf-writeups, ROFLailXGOD/CTFs, SamIsland/CTF-Writeups, TARS-02/CTF-Writeups
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Also written up in: SamIsland/CTF-Writeups, TARS-02/CTF-Writeups
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: fr334aks/DownUnderCTF_2020, ROFLailXGOD/CTFs, SamIsland/CTF-Writeups, TARS-02/CTF-Writeups
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: ROFLailXGOD/CTFs
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: SamIsland/CTF-Writeups, TARS-02/CTF-Writeups
- morse
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Also written up in: fr334aks/DownUnderCTF_2020
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- misc
- gpg
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in DownUnderCTF/Challenges_2020_Public: solution.md, solution/gcp_enum.sh
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
- discord
- bot
- mongodb
- admin
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup/writeup.md
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in DownUnderCTF/Challenges_2020_Public: solve.js
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
In a pickle 200
2 official solutionsAlso written up in: sarm08/jeopardy-ctf-writeups, sarm08/jeopardy-ctf-writeups
Also written up in: sarm08/jeopardy-ctf-writeups
16 Home Runs 100
1 official solutionAlso written up in: sarm08/jeopardy-ctf-writeups
Also written up in: ROFLailXGOD/CTFs
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md
Binary exploitation11
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/exploit.py
Also written up in: datajerk/ctf-write-ups, fr334aks/DownUnderCTF_2020, ROFLailXGOD/CTFs, datajerk/ctf-write-ups, jakecraige/ctf, fr334aks/DownUnderCTF_2020
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/exploit.py
Also written up in: IRS-Cybersec/ctfdump, datajerk/ctf-write-ups, jakecraige/ctf, Hope0351/CTF-collection, D4mianWayne/PwnLand, fr334aks/DownUnderCTF_2020, ROFLailXGOD/CTFs, datajerk/ctf-write-ups
- pwn
- bof
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/exploit.py, exploit/exploit2.py, exploit/writeup2.md
Also written up in: datajerk/ctf-write-ups, datajerk/ctf-write-ups
- pwn
- format-string
- fsb
- pie
Same technique in picoCTF: PIE TIME 2, Binary Gauntlet 2, Binary Gauntlet 3
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/exploit.py
Also written up in: datajerk/ctf-write-ups, datajerk/ctf-write-ups, hackinglife.tistory.com
- seccomp
- bof
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/exploit.js
Also written up in: WilliamParks/ctf_writeups
- v8
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Echos
3 official solutionsAlso written up in: IRS-Cybersec/ctfdump, Hope0351/CTF-collection, D4mianWayne/PwnLand
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/sol.py
Also written up in: jt00000/ctf.writeup
- realloc
- malloc
- pwn
- heap
Same technique in picoCTF: vr-school, sice_cream, zero_to_hero
Return To What 200
2 official solutionsAlso written up in: sarm08/jeopardy-ctf-writeups, sarm08/jeopardy-ctf-writeups
Return To What Revenge
2 official solutionsAlso written up in: Hope0351/CTF-collection, D4mianWayne/PwnLand
Shell This 100
2 official solutionsAlso written up in: sarm08/jeopardy-ctf-writeups, sarm08/jeopardy-ctf-writeups
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/sol.py
- pwn
- heap
- rust
- uaf
- lifetime
- bug
Same technique in picoCTF: vr-school, sice_cream, zero_to_hero
Cryptography10
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.sage
Also written up in: sandy9999/CTF-WriteUps
- rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.py
Also written up in: ROFLailXGOD/CTFs, jakecraige/ctf
- aes
- padding
Same technique in picoCTF: AES-ABC, Compress and Attack, cryptomaze
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.py
Also written up in: sandy9999/CTF-WriteUps, jakecraige/ctf
- aes-cbc
- crypto
Same technique in picoCTF: AES-ABC, Compress and Attack, cryptomaze
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.py, exploit/writeup.ipynb
Also written up in: rkm0959/CTFWriteups, sandy9999/CTF-WriteUps
- aes
Same technique in picoCTF: AES-ABC, Compress and Attack, cryptomaze
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.sage, exploit/writeup.ipynb
Also written up in: ROFLailXGOD/CTFs, sandy9999/CTF-WriteUps, ROFLailXGOD/CTFs
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.sage, exploit/writeup.ipynb
- coppersmith
- factoring
- goldwasser-micali
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.sage, exploit/writeup.ipynb
- biased-nonce
- ecc
- ecdsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Server
4 official solutionsAlso written up in: sajjadium/ctf-archives, jakecraige/ctf, ROFLailXGOD/CTFs, vakzz/ctfs
- xor
- crypto
Same technique in picoCTF: Custom encryption, XtraORdinary, It's Not My Fault 2
Ecb Chaining
1 official solutionAlso written up in: ROFLailXGOD/CTFs
Web9
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Also written up in: bootplug/writeups
- cloud
- cloud-pivot
- discord
- secretmanager
- google-cloud
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in DownUnderCTF/Challenges_2020_Public: solution.md
- web
Same technique in picoCTF: logon, More Cookies, Cookie Monster Secret Recipe
Published by the organisers in DownUnderCTF/Challenges_2020_Public: README.md, chal/solve/server.py
Published by the organisers in DownUnderCTF/Challenges_2020_Public: README.md, solve/solve.py
Published by the organisers in DownUnderCTF/Challenges_2020_Public: WRITEUP.md
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/solve.py
- cloud
- gcp
- google-cloud
Same technique in picoCTF: Live Art, secure-email-service, No FA
Leggos 100
1 official solutionAlso written up in: sarm08/jeopardy-ctf-writeups
Published by the organisers in DownUnderCTF/Challenges_2020_Public: README.md
Uncategorised8
The upstream scoreboard did not say, so neither do we.
REHOST
8 official solutionsAlso written up in: pwncollege/ctf-archive, pwncollege/ctf-archive, pwncollege/ctf-archive, pwncollege/ctf-archive, pwncollege/ctf-archive, pwncollege/ctf-archive, pwncollege/ctf-archive, pwncollege/ctf-archive
Also written up in: vakzz/ctfs, vakzz/ctfs, vakzz/ctfs
Echo Server
2 official solutionsAlso written up in: fr334aks/DownUnderCTF_2020, fr334aks/DownUnderCTF_2020
Badmin
1 official solutionAlso written up in: fr334aks/DownUnderCTF_2020
Also written up in: ducdatdau/Writeups
Exploit2
1 official solutionAlso written up in: datajerk/ctf-write-ups
Ret2watr
1 official solutionAlso written up in: jt00000/ctf.writeup
Return Revenge
1 official solutionAlso written up in: IRS-Cybersec/ctfdump
Forensics7
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Published by the organisers in DownUnderCTF/Challenges_2020_Public: solution/writeup.txt, solution/creation/clean_file.py, solution/creation/create_challenge.sh, solution/creation/national_anthem.txt, solution/creation/out.txt, solution/creation/secret_message.txt, solution/creation/WSencoder.py, solution/WSdecoder.py
- forensics
- stegcracker
- steghide
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in DownUnderCTF/Challenges_2020_Public: WRITEUP.md
Also written up in: fr334aks/DownUnderCTF_2020
- forensics
- steghide
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
On the spectrum 100
1 official solutionAlso written up in: sarm08/jeopardy-ctf-writeups
Published by the organisers in DownUnderCTF/Challenges_2020_Public: Sneaky_writeup.pdf
Spot the Difference 327
1 official solutionAlso written up in: sarm08/jeopardy-ctf-writeups
OSINT7
Answer a question about the real world from public sources. The work is pivoting between identifiers, not exploiting anything.
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Also written up in: fr334aks/DownUnderCTF_2020
- osint
Same technique in picoCTF: CVE-XXXX-XXXX
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
- osint
Same technique in picoCTF: CVE-XXXX-XXXX
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
- osint
Same technique in picoCTF: CVE-XXXX-XXXX
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Published by the organisers in DownUnderCTF/Challenges_2020_Public: writeup.md
Steganography1
Find the payload hidden inside a carrier that looks ordinary. Bit planes, appended data, metadata, and audio spectrograms.
Published by the organisers in DownUnderCTF/Challenges_2020_Public: exploit/writeup.md, exploit/exploit.sage, exploit/writeup.ipynb
- lcg
- truncated-lcg
- lll
Same technique in picoCTF: What Lies Within, Milkslap, flags are stepic
Reverse engineering1
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Formatting 100
1 official solutionAlso written up in: sarm08/jeopardy-ctf-writeups