SunshineCTF 2018
39 challenges with 63 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 15 of them also carry the solution SunshineCTF 2018’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeBinary exploitation10
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Also written up in: phieulang1993/ctf-writeups, antihorsey/ctf-writeups
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: phieulang1993/ctf-writeups
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: phieulang1993/ctf-writeups
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: phieulang1993/ctf-writeups
- pwn
Same technique in picoCTF: vr-school, sice_cream, zero_to_hero
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Web8
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
- web
- php
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
- php
- x-forwarded-for
Same technique in picoCTF: Live Art, secure-email-service, No FA
- header
- web
- accept
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
- curl
- null-byte-poisoning
Same technique in picoCTF: Live Art, secure-email-service, No FA
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Forensics8
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
- pcap
- dns
- wireshark
Same technique in picoCTF: FindAndOpen, Ph4nt0m 1ntrud3r, WebNet0
Also written up in: DancingSimpletons/writeups
- forensics
- git
Same technique in picoCTF: Forensics Git 0, Forensics Git 1, Forensics Git 2
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
- forensics
- fax
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Reverse engineering4
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
- reverse
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- reverse_engineering
- paint3d
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- reverse
- engineering
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: README.md
Misc3
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Also written up in: SouthCoded/Silverboyz_Writeups
- crpyto
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Published by the organisers in SunshineCTF/SunshineCTF-2018-Public: solution.py
- scripting
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Uncategorised3
The upstream scoreboard did not say, so neither do we.
Phishy
1 official solutionAlso written up in: antihorsey/ctf-writeups
Also written up in: viktoredstrom/CTF
Visionary Writeup
1 official solutionAlso written up in: SouthCoded/Silverboyz_Writeups
Cryptography2
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Also written up in: antihorsey/ctf-writeups
- json
- scripting
- math
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
- enigma
- cryptography
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Steganography1
Find the payload hidden inside a carrier that looks ordinary. Bit planes, appended data, metadata, and audio spectrograms.
Also written up in: DancingSimpletons/writeups
- steganography
- forensics
Same technique in picoCTF: StegoRSA, Glory of the Garden, Investigative Reversing 0