WolvSecCTF 2022
14 challenges with 17 published solutions between them. The writeups for this event were found in public repositories. Each link is pinned to the commit it was read from.
Where these writeups liveWeb5
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Java??
2 official solutionsAlso written up in: noflowpls/CTF-Writeup, Dom0nS/ctf
Also written up in: Dom0nS/ctf
Ssrf 101
1 official solutionAlso written up in: Dom0nS/ctf
Ssrf 301
1 official solutionAlso written up in: Dom0nS/ctf
Xss 401
1 official solutionAlso written up in: Dom0nS/ctf
Cryptography3
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
ANYTHING
1 official solutionAlso written up in: dreeSec/WolvSec-CTF-2022-Writeups
Eav Diffie Hellman
1 official solutionAlso written up in: Dom0nS/ctf
RSA Frustration
1 official solutionAlso written up in: dreeSec/WolvSec-CTF-2022-Writeups
Binary exploitation3
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
babyRet
2 official solutionsAlso written up in: Nosiume/CTF-Writeups, Nosiume/CTF-Writeups
String0
2 official solutionsAlso written up in: Nosiume/CTF-Writeups, Nosiume/CTF-Writeups
Also written up in: Nosiume/CTF-Writeups
Uncategorised1
The upstream scoreboard did not say, so neither do we.
Generate One Src Zip
1 official solutionAlso written up in: sambrow/my_ctf_challenges
Forensics1
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Noise
1 official solutionAlso written up in: dreeSec/WolvSec-CTF-2022-Writeups
OSINT1
Answer a question about the real world from public sources. The work is pivoting between identifiers, not exploiting anything.
Where in the world
1 official solutionAlso written up in: dreeSec/WolvSec-CTF-2022-Writeups