#KalmarCTF
GG everyone who played #KalmarCTF 2025!

Writeups for my two challs:

MonoDOOM: jonathke.github.io/monoDOOM
A chal based on a sick sidechannel attack by @damienrobert.bsky.social !

Not-so-complex multiplication: jonathke.github.io/not-so-complex
An easy chal based on complex multiplication.
Jonathan Komada Eriksen - Notes
jonathke.github.io
March 9, 2025 at 5:24 PM
#𝗞𝗮𝗹𝗺𝗮𝗿𝗖𝗧𝗙 𝟮𝟬𝟮𝟱 𝗶𝘀 𝗷𝘂𝘀𝘁 𝗮𝗿𝗼𝘂𝗻𝗱 𝘁𝗵𝗲 𝗰𝗼𝗿𝗻𝗲𝗿 - 𝗰𝗼𝗺𝗲 𝗰𝗼𝗺𝗽𝗲𝘁𝗲 𝘄𝗶𝘁𝗵 𝘁𝗵𝗲 𝗯𝗲𝘀𝘁 𝗰𝗼𝗺𝗽𝗲𝘁𝗶𝘁𝗶𝘃𝗲 𝗵𝗮𝗰𝗸𝗲𝗿𝘀 𝗳𝗿𝗼𝗺 𝗮𝗿𝗼𝘂𝗻𝗱 𝘁𝗵𝗲 𝘄𝗼𝗿𝗹𝗱 𝗮𝗻𝗱 𝘄𝗶𝗻 𝗴𝗿𝗲𝗮𝘁 𝗽𝗿𝗶𝘇𝗲𝘀! (6x IDAPro from @hex-rays.bsky.social) Mark your calendars for March 7th - 9th, 2025, and gear up for a 48-hour showdown of skill, and pure #CTF & #hacking grit.
March 1, 2025 at 9:40 PM
Writeup of the crypto-challenge MonoDOOM ETERNAL from #KalmarCTF - A follow up from last-years MonoDOOM challenge, this time with botched side-channel protection!

jonathke.github.io/monoDOOM-ETE...
March 30, 2026 at 9:49 AM
KalmarCTF 2025 is a wrap! Congrats to the winning teams!

🥇 - organizers
🥈 - Blue Water
🥉 - Tower of Hanoi
4️⃣ - r3kapig
5️⃣ - about:blankets
6️⃣ - The Flat Network Society

A big thanks to our sponsors hex-rays and Zellic! See you all next year! 🚩
March 9, 2025 at 6:52 PM
#KalmarCTF is currently well underway - and we’re once again featuring prizes sponsored by @hex-rays.bsky.social and Zellic !

Come play along by visiting kalmarc.tf
March 28, 2026 at 12:11 AM
Using SonarQube to solve a CTF challenge? Done! ✅

Learn how we detected a 0-day vulnerability during #KalmarCTF, making us first to solve the challenge! From Zip Slip to RCE, using lazy class loading:

www.sonarsource.com/blog/code-se...

#appsec #CTF #vulnerability
www.sonarsource.com
September 16, 2025 at 3:38 PM
KalmarCTF 2026 has finished! Congratulations to the winning teams!

🥇- sarrus
🥈- FMC
🥉- rasmusfaber

And to the top teams on the human scoreboard!

🥇- mhackeroni
🥈- The Flat Network Society
🥉- P3ak

Another huge thanks to our sponsors @hex-rays.bsky.social and Zellic!
March 29, 2026 at 9:39 PM
KalmarCTFとpicoCTFの問題を見てみるか
March 16, 2024 at 1:25 AM
If you like CTF competitors, this is the one to compete in. Go go go.

@KalmarunionenDM https://infosec.exchange/@KalmarunionenDM/114089379574048710
Kalmarunionen (@KalmarunionenDM@infosec.exchange)
Attached: 1 image 𝗞𝗮𝗹𝗺𝗮𝗿𝗖𝗧𝗙 𝟮𝟬𝟮𝟱 𝗶𝘀 𝗷𝘂𝘀𝘁 𝗮𝗿𝗼𝘂𝗻𝗱 𝘁𝗵𝗲 𝗰𝗼𝗿𝗻𝗲𝗿 - 𝗰𝗼𝗺𝗲 𝗰𝗼𝗺𝗽𝗲𝘁𝗲 𝘄𝗶𝘁𝗵 𝘁𝗵𝗲 𝗯𝗲𝘀𝘁 𝗰𝗼𝗺𝗽𝗲𝘁𝗶𝘁𝗶𝘃𝗲 𝗵𝗮𝗰𝗸𝗲𝗿𝘀 𝗳𝗿𝗼𝗺 𝗮𝗿𝗼𝘂𝗻𝗱 𝘁𝗵𝗲 𝘄𝗼𝗿𝗹𝗱 𝗮𝗻𝗱 𝘄𝗶𝗻 𝗴𝗿𝗲𝗮𝘁 𝗽𝗿𝗶𝘇𝗲𝘀! The #KalmarCTF 2025 is on the horizon, and Kalmarunionen is ready to raise the bar once again. Mark your calendars for March 7th - 9th, 2025, and gear up for a 48-hour showdown of skill, and pure CTF grit. 𝐇𝐞𝐫𝐞’s 𝐰𝐡𝐚𝐭’s 𝐢𝐧 𝐬𝐭𝐨𝐫𝐞: With a generous nod to @HexRaysSA for making the coveted #IDAPro licenses possible, we promise an unforgettable event brimming with complex challenges in binary exploitation, reverse engineering, and other classic #CTF categories. 🥇 First Place: 3x IDA Pro Named Licenses* with 2 Decompilers each 🥈 Second Place: 2x IDA Pro Licenses* with 2 Decompilers each 🥉 Third Place: 1x IDA Pro License* with 2 Decompilers Why join hashtag #KalmarCTF 2025? - Test yourself against top global teams and except some fun and original challenges - Immerse yourself in a thriving community of passionate CTF players and hackers. If you’re ready to push your limits, claim your glory, and maybe take home some serious #HexRays loot, head over to KalmarC.TF for all the details. REassemble your dream team, and lets see who takes all home the licenses this year. #hacking #cybersecurity #CTF
infosec.exchange
March 1, 2025 at 10:11 PM
KalmarCTF 2026 – EvilBabyKalmarCTF Challenge Writeup

This challenge presents a scenario where we are given admin access to a CTFd instance. A bot (the "scraper") runs inside the infrastructure and automatically scrapes the CTFd instance every 30 seconds using JohnHammond/ctfd-download, a Python…
KalmarCTF 2026 – EvilBabyKalmarCTF Challenge Writeup
This challenge presents a scenario where we are given admin access to a CTFd instance. A bot (the "scraper") runs inside the infrastructure and automatically scrapes the CTFd instance every 30 seconds using JohnHammond/ctfd-download, a Python tool for downloading CTFd challenge data. The challenge involves exploiting a path traversal vulnerability combined with a URL fragment injection in an older version of this scraper tool to achieve arbitrary file write on the scraper's filesystem, ultimately leading to Python module hijacking and remote code execution on the scraper container, which holds the flag at…
kore.one
April 9, 2026 at 4:06 PM
KalmarCTF 2026 – Aros-25 Challenge Writeup

Aros-25 is a reverse engineering and exploitation challenge featuring a custom virtual machine (VM) implemented as an ARM32 binary. The challenge presents competitors with a stripped, obfuscated ARM executable that implements a simple bytecode…
KalmarCTF 2026 – Aros-25 Challenge Writeup
Aros-25 is a reverse engineering and exploitation challenge featuring a custom virtual machine (VM) implemented as an ARM32 binary. The challenge presents competitors with a stripped, obfuscated ARM executable that implements a simple bytecode interpreter. Players must reverse engineer the VM's instruction set, understand its memory model, identify security constraints, and ultimately craft a payload that reads the flag file from the remote server.
kore.one
April 7, 2026 at 6:18 PM
With under 48 hours till we kick off with #KalmarCTF 2025, we are happy to announce that Zellic is joining as a sponsor this year, as well as an updated prize pool!
Come compete with the best competitive hackers from around the world!

Registrations are now open at kalmarc.tf !
March 5, 2025 at 11:08 PM