#ctf-writeup
My #writeup for hxp 38C3 #ctf @hxp@infosec.exchange - alcoholic variety (#crypto hard) affine.group/writeup/2024... (#EllipticCurves)
hxp 38C3 CTF 2024 - alcoholic_variety (crypto)
affine.group
December 30, 2024 at 10:16 AM
Godzill'hack reached the 160th/984 place at the OsuCTF 2024!

Special thanks to Ishra it was his first CTF,
@r0stm.bsky.social, @samxp.bsky.social

Congratz to every players!

You can find our WriteUp bellow 👇

v0lk3n.github.io/writeup/Osu!...

#CTF #OsuCTF2024 #Crypto #forensics #OSINT
March 5, 2024 at 7:50 PM
An explosive writeup this month, as the August @bellingcat.com challenge was focused on the identification of explosive ordinance. You can read my solutions to Hidden Hazards here ediscoverychannel.com/2025/09/01/bellingcat-challenge-august-2025hidden-hazards/ #CTF #Bellingcat #OSINT #ExplosiveStuff
Bellingcat Challenge – August 2025(Hidden Hazards)
By Dr Tristan Jenkinson Introduction The August Bellingcat Challenges were all related to the identification of explosive ordinance. Key amongst the resources to consider were the article previousl…
ediscoverychannel.com
September 1, 2025 at 9:10 AM
My new favorite CTF tip!

If you’re stuck on a box, find a writeup and feed the solution to an llm. Use the instructions of “Do not tell me the answer under any circumstances, but guide me as I ask questions.”

You’ll think critically and make progress without feeling like you cheated.

#CTF #GenAI
September 19, 2025 at 1:26 AM
BabyRF Writeup - L3ak CTF 2026
bosio.space/src/en/artic...
BabyRF — b0510
BabyRF CTF Writeup
bosio.space
August 7, 2026 at 8:57 PM
Had a fun XSS gadget chain with antoniusblock on a real world target, he made an awesome writeup:
blog.antoniusblock.net/posts/dom-cl...
A CTF-Style XSS Chain in the Wild: DOM Clobbering, Gadgets, and CSP Bypass
A bug bounty target that unexpectedly felt like a CTF. What began as simple recon turned into a nice chain of discoveries that ultimately led to a valid XSS
blog.antoniusblock.net
February 1, 2026 at 9:31 AM
I made a shorter writeup for the CatGPT challenge during hxp CTF at 39C3!
It featured a cool combination of JavaScript injections to escape our context and fix the remaining syntax. Check it out:
jorianwoltjer.com/blog/p/ctf/h...
hxpCTF 2025 - CatGPT | Jorian Woltjer
The hardest web challenge during 39C3's hxp CTF. Auditing RegExes in a PHP library to uncover small gadgets that allow escaping and fixing a JavaScript context.
jorianwoltjer.com
January 5, 2026 at 9:39 AM
New CTF writeup. Needle in a Haystack.

nerdymark.com/vibe-coding-...
nerdymark.com
Complete technical writeup of the Cloud Security CTF #4: 'Needle in a Haystack' challenge featuring client-side validation bypass and API exploitation
nerdymark.com
October 7, 2025 at 7:08 PM
📝 New Blog Post: 🔐 State of Affairs CTF Challenge Writeup
🔐 State of Affairs CTF Challenge Writeup
Complete technical writeup of the 'State of Affairs' Terraform state poisoning CTF challenge. Learn how misconfigured TF_DATA_DIR, race conditions, and malicious provider injection can lead to remote code execution. A deep dive into Terraform supply chain security risks.
nerdymark.com
January 6, 2026 at 5:19 PM
Exploiting musl libc heap allocator (Useful writeup for beginners)
(DEFCON 2021 CTF qualifications - mooosl)

blog.kylebot.net/2021/05/08/D...

#exploit #infosec
December 26, 2023 at 10:35 AM
I made a hard @intigriti.com XSS challenge this July 😅
But, it involves some very interesting Mutation XSS & DOM Clobbering fun combined with a CSP Bypass using the powerful SocketIO gadget.
Everything's explained in my writeup below!
jorianwoltjer.com/blog/p/ctf/i...
Intigriti July XSS Challenge (0725) | Jorian Woltjer
My author's writeup of the July 2025 challenge. Perform Mutation XSS to DOM Clobber an change the insertion point into an iframe, then bypass the CSP using a new useful Socket.IO gadget
jorianwoltjer.com
July 19, 2025 at 4:18 PM
And big kudos, credit where credit is due, all props to @keltecc from the @C4TBuTS4D CTF team for sharing their writeup on CTFtime!
December 5, 2024 at 2:00 PM
Last week was the final week of the December Challenge from Bellingcat. My write up for week four (including the geolocation of a cat!) can be found here. Congratulations to the Bellingcat team for putting together such a great challenge! #OSINT #CTF #Geolocation #Cats #AI #Investigation
Bellingcat Challenge – Week 4 Writeup
By Dr Tristan Jenkinson Introduction This month Bellingcat are running a series of OSINT challenges, each week a new set of five challenges is posted for that week. The “Natural Wonders” series fin…
ediscoverychannel.com
December 30, 2024 at 3:35 PM
During #x3ctf, I discovered an unintended solution that turned out to be a pretty cool generic technique. It allows you to detect the result of a selector during CSS Injection, bypassing any CSP restricting external requests!
Check out the writeup below:
jorianwoltjer.com/blog/p/ctf/x...
Post: x3CTF - blogdog (+ new CSS Injection XS-Leak!) | Jorian Woltjer
A "hard web xssbot" challenge about a fun browser quirk with the is= attribute to perform CSS Injection. Bypass the strict CSP with an unintended new technique to XS-Leak a selector's result by detect...
jorianwoltjer.com
January 26, 2025 at 9:14 PM
Just got back from #AppSecIL2025!
Ended up 4th place in the #CTF 🎉

Solved 12/15 challenges alone - Android pwn, JS sandbox escapes, cache poisoning, XSS bypasses. The usual suspects: SQLi, LDAP injection, XXE.
Had a blast!
Looking forward to the next one.

Writeup: taltechtreks.com/2025/06/04/a...
AppSec IL 2025 CTF - Writeup
A writeup on all challenges I solved in the 2025 OWASP CTF
taltechtreks.com
June 6, 2025 at 11:48 AM
The last Intigriti challenge by @0xblackbird was a fun combination of SSRF to RCE using a surprisingly exploitable pitfall in NextJS middleware.
Check out my writeup below:
jorianwoltjer.com/blog/p/ctf/i...
Intigriti August RCE Challenge (0825) | Jorian Woltjer
A challenge to achieve RCE through SSRF by @0xblackbird, involving an interesting NextJS middleware pitfall. We build a clean proxy for it and find some extra vulnerabilities along the way.
jorianwoltjer.com
August 27, 2025 at 3:00 PM
見てる。おもしろい。CTF 参加はしんどいけど(作問側の)writeupはやっぱり読んでて楽しい / Speculation-Rulesを利用したXS-Leaks - SECCON CTF 13 Author's Writeup ( Tanuki Udon ) - Satoooonの物置 satoooon1024.hatenablog.com/entry/2024/1...
Speculation-Rulesを利用したXS-Leaks - SECCON CTF 13 Author's Writeup ( Tanuki Udon ) - Satoooonの物置
EN この記事はCTF Advent Calender 2024の二日目の記事です。 昨日の記事は小池さんのCTFの問題の作り方でした。実はまだよく読んでない(は?)のですが、作問の記事なんていくらあっても嬉しいですね。 この記事では、SECCON CTF 13で出題したTanuki Udonという問題の想定解の解説をします。 TL;DR 次のような条件を満たすときに、Speculation Ru...
satoooon1024.hatenablog.com
December 2, 2024 at 8:43 AM
AIにWriteUpを参考にしてもらいつつCTF解いてもらうのいいかも
April 30, 2025 at 11:25 AM
Thank you to everyone who participated in the @defcon.bsky.social HHV CTF. The challenge page has been updated with winners, files, and a writeup dchhv.org/challenges/d...
Thank you also to our supporter, JLC PCB jlcpcb.com who helped make our CTF possible!
#DEFCON33
DC33 Challenge
We make our own use for things
dchhv.org
August 21, 2025 at 4:29 AM
わいわい
AWS特化のCTFが超楽しかった!【Security-JAWS / writeup】
zenn.dev
September 10, 2023 at 12:14 PM