Zh3r0 CTF
57 challenges with 130 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not.
Full task list on CTFtimeCryptography18
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Also written up in: itsecgary/CTFs, Kumo0x1/Zh3r0_2020_CTF, deut-erium/WriteUps
- cryptography
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: itsecgary/CTFs, deut-erium/WriteUps
- crypto
- cryptography-rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
Also written up in: itsecgary/CTFs, deut-erium/WriteUps
- crypto
- cryptography-rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
Also written up in: TheWinRaRs/Writeups, deut-erium/WriteUps
- crypto
- rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
- cryptography-rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
Uncipher me
2 official solutionsAlso written up in: TheWinRaRs/Writeups, deut-erium/WriteUps
2020 06 18 zh3r0 2020 Analyze Me
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 18 zh3r0 2020 Double Fish
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 18 zh3r0 2020 Hastads Message
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 18 zh3r0 2020 Mix
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 18 zh3r0 2020 RSA warmup
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 18 zh3r0 2020 Uncipher Me
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 18 zh3r0 2020 We Are Related
1 official solutionAlso written up in: deut-erium/WriteUps
2020 06 19 Zh3r0 2020 Gboad Maddy
1 official solutionAlso written up in: deut-erium/WriteUps
Analyze me
1 official solutionAlso written up in: deut-erium/WriteUps
Decrypt
1 official solutionAlso written up in: andregri/CTF-writeups
Double fish
1 official solutionAlso written up in: deut-erium/WriteUps
Dozen Bases
1 official solutionAlso written up in: TheWinRaRs/Writeups
Misc13
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
help
1 writeupAlso written up in: TheWinRaRs/Writeups
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Rainbow Hex
1 writeupAlso written up in: TheWinRaRs/Writeups
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- python
- bytecode
- reverseengineering
Same technique in picoCTF: PW Crack 2, PW Crack 1, PW Crack 3
Subset of Hacking Machines
2 writeups- tryhackme
- linux
- enumeration
Same technique in picoCTF: Permissions, Specialer, plumbing
Tears
2 writeupsSame technique in picoCTF: PW Crack 2, Permissions, Specialer
- binaryexploit
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Find The Covid19 Vaccine
1 official solutionAlso written up in: TheWinRaRs/Writeups
- tryhackme
- scanning
- linux
Same technique in picoCTF: Permissions, Specialer, plumbing
- tryhackme
- scanning
- linux
Same technique in picoCTF: Permissions, Specialer, plumbing
- tryhackme
- scanning
- linux
Same technique in picoCTF: Permissions, Specialer, plumbing
- tryhackme
- scanning
- linux
Same technique in picoCTF: Permissions, Specialer, plumbing
Knock knock
1 writeup- portknocking
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
VOID
1 writeup- wav
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Forensics6
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Also written up in: itsecgary/CTFs, TheWinRaRs/Writeups
- forensic+crypto
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Also written up in: TheWinRaRs/Writeups
- forensic
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Also written up in: TheWinRaRs/Writeups, TheWinRaRs/Writeups
- forensic
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
Also written up in: TheWinRaRs/Writeups
- forensic
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- forensic
- forensics
Same technique in picoCTF: investigation_encoded_2, FindAndOpen, Ph4nt0m 1ntrud3r
- audio
- forensics
- stego
Same technique in picoCTF: Glory of the Garden, Investigative Reversing 0, Investigative Reversing 1
Web5
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Google Source Code
3 writeupsAlso written up in: TheWinRaRs/Writeups
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Discord
3 official solutionsAlso written up in: fr4gment/CTF-Writeups, fr4gment/Zh3r0-CTF-2020, trott4425/CTF-Writeups
Also written up in: itsecgary/CTFs
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
- robots
- esoteric-language
- web
- directorylisting
Same technique in picoCTF: Live Art, secure-email-service, No FA
Uncategorised5
The upstream scoreboard did not say, so neither do we.
Flag Series
1 official solutionAlso written up in: TheWinRaRs/Writeups
Also written up in: itsecgary/CTFs
Master
1 official solutionAlso written up in: skyf0l/CTF
Ultrarsa
1 official solutionAlso written up in: joshdabosh/writeups
Warmup
1 official solutionAlso written up in: itsecgary/CTFs
Steganography4
Find the payload hidden inside a carrier that looks ordinary. Bit planes, appended data, metadata, and audio spectrograms.
Also written up in: TheWinRaRs/Writeups
- steganography
- forensics
Same technique in picoCTF: StegoRSA, Glory of the Garden, Investigative Reversing 0
Also written up in: itsecgary/CTFs
- steganography
- forensics
Same technique in picoCTF: What Lies Within, Milkslap, flags are stepic
Also written up in: TheWinRaRs/Writeups
- steganography
- forensics
Same technique in picoCTF: StegoRSA, Glory of the Garden, Investigative Reversing 0
- steganography
- master
Same technique in picoCTF: StegoRSA, Glory of the Garden, Investigative Reversing 0
Binary exploitation3
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Also written up in: itsecgary/CTFs, TheWinRaRs/Writeups, itsecgary/CTFs
- alignment
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: itsecgary/CTFs, TheWinRaRs/Writeups
- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
armpw
1 writeup- pwn
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Reverse engineering2
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Also written up in: andregri/CTF-writeups, TheWinRaRs/Writeups
- python
- rev
- crypto
Same technique in picoCTF: keygenme-py, Shop, patchme.py
- rev
- z3
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
OSINT1
Answer a question about the real world from public sources. The work is pivoting between identifiers, not exploiting anything.
Also written up in: TheWinRaRs/Writeups, TheWinRaRs/Writeups
- osint
Same technique in picoCTF: CVE-XXXX-XXXX