KOREONE
banner
koreone.bsky.social
KOREONE
@koreone.bsky.social
Into InfoSec, CTFs, SecDevOps, GenAI and Crypto 🤖
CTF Player for Team RootRunners
https://linktr.ee/koreone
Hack The Box – pcalc Challenge Writeup

pcalc is a small PHP calculator packaged with its application source, web-server configuration, and Docker startup script provided....
Hack The Box – pcalc Challenge Writeup
pcalc is a small PHP calculator packaged with its application source, web-server configuration, and Docker startup script provided. A visitor supplies an arithmetic expression through the formula query parameter and sees the calculated value in the page. Source inspection shows that the startup script moves the flag out of the web root and gives it a random filename, while the calculator passes user input to PHP's eval after applying a character blacklist.
kore.one
October 10, 2026 at 7:01 AM
SunshineCTF 2026 – Homemaker Challenge Writeup

Homemaker is a Linux binary exploitation challenge built around a small, custom command protocol. The supplied program presents itself as a domestic automaton and waits for a service key card, but the useful behavior is in its binary packet parser....
SunshineCTF 2026 – Homemaker Challenge Writeup
Homemaker is a Linux binary exploitation challenge built around a small, custom command protocol. The supplied program presents itself as a domestic automaton and waits for a service key card, but the useful behavior is in its binary packet parser. A valid key unlocks commands that update and read back a stack-resident state buffer. The update command has an inclusive loop bound: when the advertised packet body contains 256 data bytes, the loop also copies the following checksum byte.
kore.one
October 9, 2026 at 8:57 AM
H7CTF 2026 Quals – BartBrack Challenge Writeup

BartBrack presents Flux, a business banking interface with a username and password login, a five-digit second factor, and a dashboard for balances, transactions, cards, and statements....
H7CTF 2026 Quals – BartBrack Challenge Writeup
BartBrack presents Flux, a business banking interface with a username and password login, a five-digit second factor, and a dashboard for balances, transactions, cards, and statements. The challenge is a black-box web application: no source archive or challenge files were provided at the start. The application exposes enough behavior through its public JavaScript, GraphQL responses, PHP error messages, and dashboard pages to build an exploit chain.
kore.one
October 8, 2026 at 12:31 PM
WebVerse Pro – Proxy Pursuit Challenge Writeup

Proxy Pursuit is a black-box web challenge set in LoadMesh's operations console. The console displays connection records for a client IP, but it takes that IP from the HTTP X-Forwarded-For header, which a requester can influence....
WebVerse Pro – Proxy Pursuit Challenge Writeup
Proxy Pursuit is a black-box web challenge set in LoadMesh's operations console. The console displays connection records for a client IP, but it takes that IP from the HTTP X-Forwarded-For header, which a requester can influence. The challenge begins with supplied console credentials and an exposed web endpoint; the goal is to find how this lower-trust header reaches the connection query and use that behavior to obtain the flag.
kore.one
October 7, 2026 at 11:59 AM
Hack The Box – Intergalatic Bounty Challenge Writeup

Intergalatic Bounty is a source-assisted web security challenge built from two Express applications: a bounty-management service and a small webmail viewer....
Hack The Box – Intergalatic Bounty Challenge Writeup
Intergalatic Bounty is a source-assisted web security challenge built from two Express applications: a bounty-management service and a small webmail viewer. The principal application uses SQLite through Sequelize, JSON Web Tokens for authentication, Nunjucks for server-side templates, sanitize-html for user-supplied bounty descriptions, Nodemailer for account-verification messages, Needle for server-side HTTP requests, and @christopy/mergedeep when administrators update bounties. The challenge is solved by tracing how attacker-controlled data crosses the boundaries between those components.
kore.one
October 5, 2026 at 1:00 PM
Awarded the badge Completionist from Hack The Box!
labs.hackthebox.com
October 5, 2026 at 9:48 AM
SunshineCTF 2026 – Code Breaker Challenge Writeup

Code Breaker is a stripped, 64-bit Linux service that accepts length-prefixed binary messages. A custom substitution-box stream cipher hides the service's heap-management commands after a short handshake....
SunshineCTF 2026 – Code Breaker Challenge Writeup
Code Breaker is a stripped, 64-bit Linux service that accepts length-prefixed binary messages. A custom substitution-box stream cipher hides the service's heap-management commands after a short handshake. The central flaw is in its clone/delete logic: deleting a slot frees its allocation even when another slot still points to the same allocation. The surviving slot provides both a read and a write into freed memory.
kore.one
October 4, 2026 at 12:36 PM
H7CTF 2026 Quals – Merged Challenge Writeup

Certmarq is a web application for creating and issuing course certificates. An issuer writes a certificate body containing merge fields, and the application renders a preview on its own server before a certificate is issued....
H7CTF 2026 Quals – Merged Challenge Writeup
Certmarq is a web application for creating and issuing course certificates. An issuer writes a certificate body containing merge fields, and the application renders a preview on its own server before a certificate is issued. In this black-box challenge, that preview feature crosses the critical trust boundary: text supplied by a newly registered user is evaluated as a Jinja template with access to server-side Python objects.
kore.one
October 2, 2026 at 4:13 PM
SunshineCTF 2026 – Groundhog Day Challenge Writeup

Groundhog Day is a black-box web challenge built around a public weather console and a separate, localhost-only archive service....
SunshineCTF 2026 – Groundhog Day Challenge Writeup
Groundhog Day is a black-box web challenge built around a public weather console and a separate, localhost-only archive service. The console displays a newly generated observation for February 2 on every visit, but its real security boundary is the server-side request used to obtain that observation. A leftover feed override lets a visitor choose the destination of that request. The archive service provides a PDF report endpoint and uses an old version of wkhtmltopdf to render supplied HTML.
kore.one
October 1, 2026 at 7:00 AM
H7CTF 2026 Quals – Justified Challenge Writeup

Justified is a black-box web challenge built around an online bookbinder's Instant Cover Proof service. Visitors enter thesis details, and the service typesets a PDF title page and shows the typesetter's log....
H7CTF 2026 Quals – Justified Challenge Writeup
Justified is a black-box web challenge built around an online bookbinder's Instant Cover Proof service. Visitors enter thesis details, and the service typesets a PDF title page and shows the typesetter's log. The title field accepts typesetting commands so that users can enter accented letters and symbols. That convenience becomes the entry point: the submitted title is interpreted as active TeX input, and the PDF engine can execute shell commands.
kore.one
September 30, 2026 at 3:29 PM
SunshineCTF 2026 – Planetary Probe Challenge Writeup

Planetary Probe is a black-box web challenge built around a deliberately sparse search interface. A visitor submits a planet name and receives only one of two results: Signal detected or No signal....
SunshineCTF 2026 – Planetary Probe Challenge Writeup
Planetary Probe is a black-box web challenge built around a deliberately sparse search interface. A visitor submits a planet name and receives only one of two results: Signal detected or No signal. The limited response hides both database values and errors, but it still reveals whether an injected condition succeeded. The path to the flag starts with Boolean-based SQL injection in the…
kore.one
September 28, 2026 at 3:50 PM
PwnSec CTF 2026 – peekaboo Challenge Writeup

peekaboo is a shellcode-sandbox challenge built around information hiding rather than a conventional control-flow hijack. The program reads the flag, encrypts it, stores the Base64 representation in a page whose address is randomized, removes the…
PwnSec CTF 2026 – peekaboo Challenge Writeup
peekaboo is a shellcode-sandbox challenge built around information hiding rather than a conventional control-flow hijack. The program reads the flag, encrypts it, stores the Base64 representation in a page whose address is randomized, removes the plaintext and key material, clears the visible CPU state, installs a restrictive seccomp filter, and finally executes attacker supplied machine code. The shellcode is intentionally allowed to compute, map memory, and write a few bytes from one designated page, but it starts without a pointer to the secret.
kore.one
September 26, 2026 at 9:38 AM
PwnSec CTF 2026 – PHault Challenge Writeup

PHault is a compact web challenge built around an unusual fault-based blind SQL injection oracle. The application openly reveals its PHP source and directly concatenates an attacker-controlled id query parameter into a MariaDB/MySQL statement....
PwnSec CTF 2026 – PHault Challenge Writeup
PHault is a compact web challenge built around an unusual fault-based blind SQL injection oracle. The application openly reveals its PHP source and directly concatenates an attacker-controlled id query parameter into a MariaDB/MySQL statement. At first glance, conventional blind extraction appears to have been deliberately neutralized: SQL errors and successful queries produce the same visible sentence, SQL error reporting is disabled, query results are never printed, and a shutdown handler pads every response to at least two seconds.
kore.one
September 25, 2026 at 7:00 AM