redpwnCTF 2019
47 challenges with 99 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 13 of them also carry the solution redpwnCTF 2019’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeMisc14
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Also written up in: wr47h/CTF-Writeups
- misc
- python
- jail
Same technique in picoCTF: PW Crack 2, PW Crack 1, PW Crack 3
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
Also written up in: wr47h/CTF-Writeups, meowmeowxw.gitlab.io
Same technique in picoCTF: PW Crack 3, PW Crack 4, PW Crack 5
Also written up in: wr47h/CTF-Writeups, meowmeowxw.gitlab.io
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.java
Also written up in: unorde.red
- misc
- algo
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in redpwn/redpwnctf-2019-challenges: sol.py
- algo
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- misc
- python
- jail
Same technique in picoCTF: PW Crack 2, PW Crack 1, PW Crack 3
- bash
- misc
Also written up in: harshit-tyhf/CTF-Challenges-Writeups
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Every Encoding Ever
1 writeupSame technique in picoCTF: PW Crack 2, Codebook, convertme.py
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Binary exploitation12
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
Also written up in: beerpwn/ctf
- format-string
- pwn
Same technique in picoCTF: PIE TIME 2, Binary Gauntlet 2, Binary Gauntlet 3
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
- rop
Same technique in picoCTF: lockdown-horses, Guessing Game 1, vr-school
Also written up in: wr47h/CTF-Writeups, meowmeowxw.gitlab.io
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- uaf
- pwn
- tcache
Same technique in picoCTF: vr-school, sice_cream, zero_to_hero
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, vr-school
Published by the organisers in redpwn/redpwnctf-2019-challenges: bin/exploit.c, bin/solve.py
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
- shellcode
- pwn
Same technique in picoCTF: handoff, Binary Gauntlet 2, Kit Engine
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Reverse engineering6
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Also written up in: meowmeowxw.gitlab.io
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Also written up in: meowmeowxw.gitlab.io
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- re
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- re
Same technique in picoCTF: vault-door-1, vault-door-3, vault-door-4
- re
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Forensics6
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
Also written up in: wr47h/CTF-Writeups
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- ocr
- forensics
- scripting
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Published by the organisers in redpwn/redpwnctf-2019-challenges: solve.py
- forensics
Same technique in picoCTF: investigation_encoded_2, investigation_encoded_1, Investigative Reversing 0
Web4
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
- web
- crypto
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
- guessing
Same technique in picoCTF: logon, More Cookies, Cookie Monster Secret Recipe
- web
- crypto
Same technique in picoCTF: Live Art, secure-email-service, No FA
- ssrf#web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Cryptography3
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Also written up in: srixivas/SecurityNuggets, Srinivas11789/SecurityNuggets
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: unorde.red
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Published by the organisers in redpwn/redpwnctf-2019-challenges: solution.py
Steganography1
Find the payload hidden inside a carrier that looks ordinary. Bit planes, appended data, metadata, and audio spectrograms.
- substitution
- stego
- forensics
Same technique in picoCTF: StegoRSA, Glory of the Garden, Investigative Reversing 0
Uncategorised1
The upstream scoreboard did not say, so neither do we.
Also written up in: Hong5489/RedPwnCTF2019