picoCTF 2021
86 challenges with 86 published solutions between them. Solution links go to picoctfsolutions.com, which is the only writeup source this index uses for picoCTF - one worked solution per challenge, rather than an aggregate of other people’s posts.
Every writeup on picoctfsolutions.comCryptography17
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Clouds
1 writeup- custom-cipher
- chosen-plaintext-attack
Compress and Attack
1 writeup- compression-oracle
- aes
Dachshund Attacks
1 writeup- rsa
Double DES
1 writeup- aes
Easy Peasy
1 writeup- otp
It is my Birthday 2
1 writeup- hash-cracking
It's Not My Fault 1
1 writeup- x86-assembly
- decompilation
It's Not My Fault 2
1 writeup- x86-assembly
- decompilation
Mind your Ps and Qs
1 writeup- rsa
Mini RSA
1 writeup- rsa
Mod 26
1 writeup- classical-cipher
- caesar-cipher
New Caesar
1 writeup- custom-cipher
- caesar-cipher
New Vignere
1 writeup- vigenere-cipher
- custom-cipher
No Padding, No Problem
1 writeup- rsa
Pixelated
1 writeup- visual-cryptography
- steganography
Play Nice
1 writeup- custom-cipher
Scrambled: RSA
1 writeup- rsa
Web17
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Bithug
1 writeup- path-traversal
- ssti
Cookies
1 writeup- cookie-manipulation
GET aHEAD
1 writeup- http-headers
It is my Birthday
1 writeup- hash-cracking
More Cookies
1 writeup- flask-session
Most Cookies
1 writeup- flask-session
Scavenger Hunt
1 writeup- source-inspection
Some Assembly Required 1
1 writeup- wasm
- javascript-deobfuscation
Some Assembly Required 2
1 writeup- wasm
- javascript-deobfuscation
Some Assembly Required 3
1 writeup- wasm
- xor
Some Assembly Required 4
1 writeup- wasm
- javascript-deobfuscation
Startup Company
1 writeup- file-upload
- ssti
Super Serial
1 writeup- php-deserialization
Web Gauntlet 2
1 writeup- sql-injection
Web Gauntlet 3
1 writeup- sql-injection
Who are you?
1 writeup- http-headers
X marks the spot
1 writeup- xpath-injection
Binary exploitation16
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Binary Gauntlet 0
1 writeup- buffer-overflow
Binary Gauntlet 1
1 writeup- shellcode
Binary Gauntlet 2
1 writeup- format-string
- shellcode
Binary Gauntlet 3
1 writeup- rop
- format-string
Bizz Fuzz
1 writeup- fuzzing
- buffer-overflow
Cache Me Outside
1 writeup- tcache
- heap-exploitation
Download Horsepower
1 writeup- v8-pwn
- heap-exploitation
filtered-shellcode
1 writeup- shellcode
Here's a LIBC
1 writeup- rop
- ret2libc
Kit Engine
1 writeup- jit-compiler
- heap-exploitation
Stonk Market
1 writeup- format-string
Stonks
1 writeup- format-string
The Office
1 writeup- format-string
- heap-exploitation
Turboflan
1 writeup- v8-pwn
- jit-compiler
Unsubscriptions Are Free
1 writeup- use-after-free
- heap-exploitation
What's your input?
1 writeup- format-string
Reverse engineering16
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
ARMssembly 0
1 writeup- arm-assembly
ARMssembly 1
1 writeup- arm-assembly
ARMssembly 2
1 writeup- arm-assembly
ARMssembly 3
1 writeup- arm-assembly
ARMssembly 4
1 writeup- arm-assembly
Checkpass
1 writeup- binary-analysis
- gdb
crackme-py
1 writeup- python-reversing
Easy as GDB
1 writeup- gdb
- x86-assembly
gogo
1 writeup- binary-analysis
- gdb
keygenme-py
1 writeup- python-reversing
- keygen
Let's get dynamic
1 writeup- frida
Powershelly
1 writeup- powershell
- decompilation
Rolling My Own
1 writeup- custom-cipher
Shop
1 writeup- python-reversing
- integer-overflow
speeds and feeds
1 writeup- gcode
Transformation
1 writeup- encoding
Forensics13
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Disk, disk, sleuth!
1 writeup- disk-forensics
Disk, disk, sleuth! II
1 writeup- disk-forensics
Information
1 writeup- metadata-analysis
MacroHard WeakEdge
1 writeup- steganography
Matryoshka doll
1 writeup- steganography
- file-carving
Milkslap
1 writeup- steganography
- lsb-stego
Surfing the Waves
1 writeup- audio-stego
Trivial Flag Transfer Protocol
1 writeup- pcap-analysis
- steganography
tunn3l v1s10n
1 writeup- image-analysis
- hex-analysis
Very very very Hidden
1 writeup- steganography
Weird File
1 writeup- file-inspection
- file-magic
Wireshark doo dooo do doo...
1 writeup- pcap-analysis
Wireshark twoo twooo two twoo...
1 writeup- pcap-analysis
Misc7
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Magikarp Ground Mission
1 writeup- ssh
- linux-cli
Nice netcat...
1 writeup- netcat
- encoding
Obedient Cat
1 writeup- file-inspection
Python Wrangling
1 writeup- python
- encoding
Static ain't always noise
1 writeup- strings
- file-inspection
Tab, Tab, Attack
1 writeup- linux-cli
- file-inspection
Wave a Flag
1 writeup- binary-execution
- linux-cli