nullcon HackIM 2020
33 challenges with 84 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 19 of them also carry the solution nullcon HackIM 2020’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeBinary exploitation8
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: LJP-TW/CTF, ironore15/ctf, epicleet/write-ups
- pwn
- heap-overflow
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in nullcon/hackim-2020: README.md, sol/sploit.py
Also written up in: smallkirby/pwn-writeups, HexRabbit/CTF-writeup, epicleet/write-ups
- _libc_start_main
- formatstring
- pwn
Same technique in picoCTF: PIE TIME 2, Binary Gauntlet 2, Binary Gauntlet 3
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: smallkirby/pwn-writeups, 10secTW/ctf-writeup
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: ironore15/ctf, epicleet/write-ups
- pwn
- crypto
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: HexRabbit/CTF-writeup
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in nullcon/hackim-2020: solution/cookie.py, solution/solve.py
Published by the organisers in nullcon/hackim-2020: README.md
Published by the organisers in nullcon/hackim-2020: README.md
Uncategorised8
The upstream scoreboard did not say, so neither do we.
Also written up in: jt00000/ctf.writeup
Ghost Zh
1 official solutionAlso written up in: 10secTW/ctf-writeup
Meekboi En
1 official solutionAlso written up in: 10secTW/ctf-writeup
Meekboi Zh
1 official solutionAlso written up in: 10secTW/ctf-writeup
Returminator En
1 official solutionAlso written up in: 10secTW/ctf-writeup
Returminator Zh
1 official solutionAlso written up in: 10secTW/ctf-writeup
Year3000 En
1 official solutionAlso written up in: 10secTW/ctf-writeup
Year3000 Zh
1 official solutionAlso written up in: 10secTW/ctf-writeup
Cryptography7
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Also written up in: death-of-rats/CTF, ironore15/ctf, death-of-rats/CTF
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: pcw109550/write-up, death-of-rats/CTF, pcw109550/write-up, death-of-rats/CTF
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in nullcon/hackim-2020: README.md, solve.py
Also written up in: ironore15/ctf
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in nullcon/hackim-2020: README.md, solve.py
Also written up in: jt00000/ctf.writeup, epicleet/write-ups
Published by the organisers in nullcon/hackim-2020: README.md, solve.py
Server
2 official solutionsAlso written up in: ironore15/ctf, KinoVir/ctf-wps
Also written up in: devploit/ctf-writeups
- game
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Reverse engineering4
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Published by the organisers in nullcon/hackim-2020: README.md, solution/addrs.txt, solution/disass.txt, solution/solution.py, solution/solve_z3.py
Also written up in: ironore15/ctf, epicleet/write-ups
- reverse
- engineering
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in nullcon/hackim-2020: README.md, solution/solve.py
Also written up in: 10secTW/ctf-writeup, epicleet/write-ups
- reverse
- engineering
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in nullcon/hackim-2020: README.md
Published by the organisers in nullcon/hackim-2020: README.md
Misc4
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in nullcon/hackim-2020: README.md, solve.py
Also written up in: datajerk/ctf-write-ups
- programming
- images
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: TeamUnderdawgs/CTF-Docs
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: TeamUnderdawgs/CTF-Docs
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- game
- modding
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Web2
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: TeamUnderdawgs/CTF-Docs
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in nullcon/hackim-2020: README.md
Also written up in: TeamUnderdawgs/CTF-Docs
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA