saarCTF 2023
6 challenges with 5 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 6 of them also carry the solution saarCTF 2023’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeUncategorised3
The upstream scoreboard did not say, so neither do we.
Published by the organisers in saarsec/saarctf-2023: exploits/exploit_bad_randomness.py, exploits/exploit_login_different_username.py, exploits/exploit_login_strcmp.py, exploits/exploit_ntp_cmdi.py, exploits/php_mt19937.py
Also written up in: cybersp3ck.github.io
Published by the organisers in saarsec/saarctf-2023: exploits/exploit_firefighter.py, exploits/exploit_get.py, exploits/exploit_tracking_commands.py, exploits/unintended-exploits.txt
Published by the organisers in saarsec/saarctf-2023: exploits/README.md, exploits/exploit_machine.py
Cryptography1
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in saarsec/saarctf-2023: exploits/exploit_mc_board.py, exploits/exploit_task.py, exploits/telecommunication_nogamelib.py
- serialization
- object-pascal
- inconsistencies
- crypto
- csharp
- c++
- python
Same technique in picoCTF: Sequences, C3, It's Not My Fault 2
Web1
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Published by the organisers in saarsec/saarctf-2023: exploits/exploit_read_db.py, exploits/exploit_timestamp.py
Also written up in: hydr0nium/ctf_writeups
- xml
- python
- django
Same technique in picoCTF: Live Art, secure-email-service, No FA
Misc1
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in saarsec/saarctf-2023: exploits/exploit_private.py, exploits/exploit_public.py
- compiler
- bytecode
- type-confusion
- stack
Same technique in picoCTF: PW Crack 2, Permissions, Specialer