saarCTF 2020
11 challenges with 8 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 7 of them also carry the solution saarCTF 2020’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeUncategorised10
The upstream scoreboard did not say, so neither do we.
Published by the organisers in saarsec/saarctf-2020: exploits/algebraOpt.py, exploits/cryptostuff.py, exploits/exploit_caesar.py, exploits/exploit_otp.py, exploits/exploit_plain.py, exploits/exploit_rsaSmallFactor.py, exploits/exploit_rsaWiener.py, exploits/exploit_schwenk.py
Published by the organisers in saarsec/saarctf-2020: exploits/exploitchangepw.py, exploits/exploitdirectfileaccess_alias.py, exploits/exploitdirectfileaccess.py, exploits/exploitloginbackdoor.py, exploits/exploitRCE.py, exploits/saarlendar.py, exploits/utils.py
Published by the organisers in saarsec/saarctf-2020: exploits/common.py, exploits/exploit-leak-key.py, exploits/exploit-rc-points.py, exploits/exploit-rc-share.py
Published by the organisers in saarsec/saarctf-2020: exploits/exploit_datalog.py, exploits/exploit_errorlog.py, exploits/exploit_handshake.md, exploits/utils.py
Published by the organisers in saarsec/saarctf-2020: exploits/exploit_login.py, exploits/exploit_nextmenu.py, exploits/test_exploit.php
Published by the organisers in saarsec/saarctf-2020: exploits/exploit_cmd.py, exploits/exploit_key.py
Attack Shit
1 official solutionAlso written up in: dobsonj/ctf
Schlossberg Main
1 official solutionAlso written up in: mephi42/ctf
Schlossberg Main2
1 official solutionAlso written up in: mephi42/ctf
Setup
1 official solutionAlso written up in: LetzPwn/ctf-writeups
Binary exploitation1
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Published by the organisers in saarsec/saarctf-2020: exploits/README.md, exploits/exploit_array_casts.py, exploits/exploit_double_link.py, exploits/exploit_imports.py, exploits/exploit_main_params.py, exploits/exploit_uninitialized_arrays.py
Also written up in: mephi42/ctf, abiondo.me
- ppc
- pwn
- llvm
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz