Writeups
How each challenge was solved, root cause first and then the exploit. Grouped by event.
Category
Event
28 writeups
September 2026 SkillBit Flash CTF
Participant 2-hour flash CTF
5 solves
NxT · solo
5 writeups
- CoilVMSIGTRAP-driven VM rev A stripped x86-64 binary runs its checks entirely inside a SIGTRAP handler, one int3 per input byte, with self-modifying XOR blocks and an rdtsc anti-debug gate. The FNV-1a verification chain inverts cleanly step by step, recovering the input and the decryption key in one forward pass.
- Git Sleuthgit-only shell, 501 haystack files misc A restricted shell only runs git, with `flag`, `grep`, `diff` and `:` all blocklisted. Committing the haystack and diffing blob hashes finds the one odd file among 500 decoys, and `git cat-file -p <hash>` reads it straight by SHA with no blocked syntax.
- TrackMelog poisoning via User-Agent web A PHP log viewer `include`s the access log instead of reading it, and the User-Agent header is logged unsanitized. Poisoning the log with a PHP snippet in the User-Agent, then viewing it through the include, executes it and dumps the runtime-generated flag file.
- Carry OnZIP appended after PNG IEND forensics A checkpoint-layout PNG carries a ZIP archive appended after its IEND chunk, invisible to image viewers but readable by unzip. The extracted memo hides the flag in plain sight, labeled as a diagnostic recovery key.
- Careless Talkplaintext flag in decoy noise rev A watchword-prompt binary never needs to be run or reversed: the flag sits split across two plaintext strings in the data section, buried under dozens of decoy lines that a targeted grep cuts straight through.
TISC 2026
78th of 1,432
7 solves
NxT · solo
7 writeups
- REDACTEDPDF redaction bypass forensics A five-page PDF's black-box redactions never touched the underlying text. pdftotext -layout recovers a Base64 string hidden under a section titled The Flag, decoding straight to the flag.
- My Printer Has a SecretHCCB stego + tracking dots + OSINT osint A printed cover-sheet PNG hides an HCCB-style colour tag (a 36x36 triangle grid pointing to an archive) and a fake tracking-dot pattern (the archive password), then a passive OSINT chain across aucfan, Flickr, a hobby site and a shop finds the seller's username, pants colour, and model number.
- Lion City Layoverfake WASM VM + Fermat RSA rev A Singapore-themed maze hides a fake WebAssembly VM whose validator and interpreter parse different custom sections; duplicating a wasm section bypasses the opcode blocklist to dump a Fermat-weak RSA blob, factored to recover the boarding-pass claim, all while dodging LLM prompt-injection honeypots.
- ZyGPTLSB-sealed LLM weights AI A Qwen3-1.7B fine-tune seals a flag in one MLP tensor's LSBs, keyed by a 5-record live handshake among 69 self-verifying provisioning rows. The model's own recited manual misdirects toward a false reserved-rows subset; brute-forcing all 69-choose-5 combinations against a flip-mask oracle finds the real one.
- Trash TalkGTS Pokemon trash-byte stego rev A Nintendo GTS emulator hides messages in Pokemon nickname trash bytes across two game generations. A Gen 4 Porygon's trash reveals the XOR key for Gen 5 Porygon2 trash (recipient PIDs plus an OT-name instruction to trade a female Buizel), and performing that trade unlocks a hidden Porygon-Z whose trash XORs with its own PID into the flag.
- Provenance Expertforged Rich header forensics A PE32+ binary's Rich header and linker version were forged to claim Visual Studio 2017, but the load-config layout and COFF timestamp (Aug 2026) prove Visual Studio 2022. Repairing every Rich-header build number to the matching VS2022 17.13 build and recomputing the checksum satisfies the grader's provenance check.
- Omnitrixrace condition + dlopen pwn pwn A stripped Rust/tokio service gates a dlopen primitive behind a policy-mask bit no static code path can set. A data race in capability-cache reconcile flips the shared mask, letting a hand-crafted .so slip past content filters and get dlopen'd to run the execute-only flag binary.
Kaspersky CTF 2026
69th Asia regional league
736 points
9 solves
NxT · ITE College West
9 writeups
- SlopGateQEMU escape pwn 182 pts The hardened SlopGate PCI device is a decoy. The serial console still drops to the QEMU monitor, and `migrate "exec:..."` runs a command on the host.
- LumberjackML / OOB read AI 89 pts An ONNX-to-native compiler never bounds-checks `feature_idx`. A negative index reads the `FLAG` env pointer off the stack, one float at a time, through a tree-classifier oracle.
- chroot-bronzechroot escape misc 77 pts Root inside a bare chroot. Ship an ELF with `printf` octal escapes, run it via `ld.so` to dodge the missing `+x`, then the classic `chroot`/`chdir("..")` walk-out.
- awasmsafeWASM + Electron rev 74 pts The password check is a WASM RC4 whose key is derived from the page's own source and CSP hash, gated behind ~56 anti-Node fingerprint checks. Run the real Electron renderer, then solve the RC4 algebraically.
- chroot-silversandbox escape misc 64 pts `SOCAT_PPID=1` gives it away: the jailer lives outside the jail. Build a musl PIE, upload it with all-3-digit octal `printf`, run via the musl loader, and escape through a saved root fd.
- Sudokryptcustom cipher crypto 50 pts The Feistel and sudoku layers are keyless and publicly invertible. Two design leaks recover both secret permutations, and a shared block counter exposes the spectral keystream as a degree-56 linear recurrence.
- Shiny Sweetie Curveelliptic curve crypto 50 pts A fresh random curve every round, only x-coordinates leaked. X-only addition identities plus a resultant-and-GCD trick recover the secret prime, then `a`, `b`, and the step point.
- biblockerSIGSEGV "TPM" rev 50 pts The "Trusted Potato Module" is a SIGSEGV handler that hands back AES key material derived from the fault address via XTEA. Re-implement the CRC and XTEA statically. The key is `target_key XOR mask`.
- CensoredHNP / lattice crypto 50 pts Each Schnorr signature ships a "diagnostic" blob whose XOR masks are computable from public data. Unmask it for ~16 bits of nonce per signature, then solve the Hidden Number Problem by lattice reduction.
TFC CTF 26
162nd of 1,027 teams
77.08 CTFtime weight
7 solves
NxT · solo
7 writeups
- Discord Shenanigans V6acrostic in #announcements misc 340 pts The pre-event announcement is an acrostic. First letters spell LCASTLE, and the opening words "Less than" tell you to drop the leading L. The hidden word is CASTLE.
- MATH OR METH?hidden row in a lattice crypto 298 pts One row of a small-entry matrix is the flag's base-33 digits, and only `h = a A mod p` is published. Two LLL passes recover the hidden row lattice, and one vector decodes to printable text.
- RULESread the rules page misc 128 pts The flag-format section of the site rules page uses a real flag as its example. Visiting the page marks the challenge solved.
- CER FRUMOSMT19937 state recovery crypto 625 partial Mersenne Twister outputs over-determine the 19968-bit state. Model the twist and temper in Z3, add the leaked bits as constraints, then read off the two words that seed the AES key and IV.
- 1+1approximate GCD crypto Ten samples `x_i = p * q_i + r_i` share the secret `p` (the flag) with small noise `r_i`. A Howgrave-Graham AGCD lattice with the right scale recovers `q_0`, and `p = x_0 / q_0`.
- mida lying binary-search oracle crypto A 30-character password behind a comparison oracle that answers truthfully only while your submitted state matches a hidden mood. One provably-safe probe detects the mood flip; char-by-char search contains the damage.
- FISHING NOT PHISHINGvessel tracking via AIS osint Reverse image search identifies the trawler STEAUA DE MARE 1. Global Fishing Watch gives the September 2023 voyage from Constanta, the first fishing event, and the coordinates for a haversine distance.
No writeups match these filters.
Solve scripts and challenge archives aren't published here. Ask in Discord.