NahamCon CTF 2022: Web Challenge Walkthroughs

  Рет қаралды 7,961

CryptoCat

CryptoCat

Күн бұрын

Пікірлер: 48
@MantisSTS
@MantisSTS 2 жыл бұрын
Another awesome video dude! Really great "writeup" of all the challenges!
@_CryptoCat
@_CryptoCat 2 жыл бұрын
🙏🥰
@migo369
@migo369 2 жыл бұрын
Awesome man! Really enjoy your videos, keep it up.
@_CryptoCat
@_CryptoCat 2 жыл бұрын
thanks mate 💜
@ca7986
@ca7986 2 жыл бұрын
Amazing walkthrough
@_CryptoCat
@_CryptoCat 2 жыл бұрын
ty 🙏🥰
@jonathanhoyos8191
@jonathanhoyos8191 2 жыл бұрын
I did enjoy. Keep posting more interesting CTF-Web challenges solutions :D
@_CryptoCat
@_CryptoCat 2 жыл бұрын
thanks mate 🙏🥰
@khalilbouzidi8432
@khalilbouzidi8432 2 жыл бұрын
Thank you for sharing very informative, hope to see some buffer overflows
@_CryptoCat
@_CryptoCat 2 жыл бұрын
Thanks mate 🥰 No pwn challs from this CTF but there's *a lot* already on the channel 😉
@khalilbouzidi8432
@khalilbouzidi8432 2 жыл бұрын
​ @CryptoCat ​ yes already did watch them (good content === new subscriber :D), i did know this channel when i was trying to do babysteps challenge, still couldn't solve it 🙃
@_CryptoCat
@_CryptoCat 2 жыл бұрын
@@khalilbouzidi8432 there was a few ways to solve babysteps, i just used ret2libc which comes up a lot in CTFs although this was 32-bit, which is less common: github.com/Crypto-Cat/CTF/blob/main/ctf_events/nahamcon_22/pwn/babysteps.py
@khalilbouzidi8432
@khalilbouzidi8432 2 жыл бұрын
@@_CryptoCat I'm trying to learn more about pwn so thanks for the guidance
@sahilpawar5152
@sahilpawar5152 2 жыл бұрын
Man I had seen a challenge similar to the last one in some CTF but I couldn't solve it and weeks later, I forgot name of the CTF so I couldn't search for its writeup 😅. But now I found challenge similar to it. Thanks man really appreciate your efforts ❤️.
@_CryptoCat
@_CryptoCat 2 жыл бұрын
thank you 🙏🥰
@SuperSohaizai
@SuperSohaizai 2 жыл бұрын
Just when I want to search for write ups, I found this. Perfect timing. Couldn't join the event at that time so will make use of this, thanks! Edit: was going to try dirbuster of some sort, but it is not allowed apparently, at least according to the rules
@_CryptoCat
@_CryptoCat 2 жыл бұрын
Yeh, that's typically the case with CTFs, no automated tools. They normally say that due to the infrastructure though. I think it makes a lot less sense as a rule when each player has their own instance. I guess the challenges are designed to be solved without brute force though 😅
@SuperSohaizai
@SuperSohaizai 2 жыл бұрын
@@_CryptoCat yeah I agree with that part. Brute forcing kinda take the beauty out of it to be honest, even though it does make it harder. Not gonna lie, dirb was always on my mind when I was attempting, and have to keep reminding myself haha. Thanks again for the video!
@_CryptoCat
@_CryptoCat 2 жыл бұрын
@@SuperSohaizai It really wasn't needed here, I just thought I'd include it in because it's one of the first things you'd do on a HTB machine, or in a real pentest. Knowing my luck people will do in CTF events now and get suspended for breaking rules: "😮 but I learnt it from CryptoCat?!" 🤣 Thank you! 🙏🥰
@jorgevilla6523
@jorgevilla6523 2 жыл бұрын
great video thanks
@_CryptoCat
@_CryptoCat 2 жыл бұрын
💜
@nuridincersaygili
@nuridincersaygili 2 жыл бұрын
excellent! anything for babyrsa?
@_CryptoCat
@_CryptoCat 2 жыл бұрын
nope! i normally avoid crypto 😁
@vancaotran7547
@vancaotran7547 2 жыл бұрын
when will you have the pwnable video of nahamcon CTF ? I'm really looking forward to it
@_CryptoCat
@_CryptoCat 2 жыл бұрын
never 😆 it was a great CTF but I don't have time to cover all challenges, especially when there's multiple competitions every week. I typically either: a) pick a category b) solve easy-ish challs from multiple category c) pick 1-2 hard challenges angstrom CTF video is coming later today though, containing a few pwn challs 😉
@BaNguyen-xt9bg
@BaNguyen-xt9bg 2 жыл бұрын
I wait for pwn sir!
@_CryptoCat
@_CryptoCat 2 жыл бұрын
No pwn this time! I solved a couple of the easier ones but they were very similar to videos I've made before.
@sudoer92
@sudoer92 2 жыл бұрын
Nice video i learned alot, did you win the ctf ?
@_CryptoCat
@_CryptoCat 2 жыл бұрын
thanks mate 🥰 i definitely didnt win haha, just did a few challenges 😁
@0xgodson119
@0xgodson119 2 жыл бұрын
🤩
@_CryptoCat
@_CryptoCat 2 жыл бұрын
nandri 🙏🥰
@rehanmumtaz5972
@rehanmumtaz5972 2 жыл бұрын
Can u share the presentation link?
@_CryptoCat
@_CryptoCat 2 жыл бұрын
From the conference? Which presentation? I think they'll be uploaded to kzbin.info
@rehanmumtaz5972
@rehanmumtaz5972 2 жыл бұрын
@@_CryptoCat i think you open the presentation while solving hacker T's challenge... may be its of defcon i guess
@_CryptoCat
@_CryptoCat 2 жыл бұрын
@@rehanmumtaz5972 oooooo I know what you mean! here it is: docs.google.com/presentation/d/1JdIjHHPsFSgLbaJcHmMkE904jmwPM4xdhEuwhy2ebvo/htmlpresent
@rehanmumtaz5972
@rehanmumtaz5972 2 жыл бұрын
@@_CryptoCat Thanks for sharing btw great explanation of these web challenges ! 💓
@_CryptoCat
@_CryptoCat 2 жыл бұрын
@@rehanmumtaz5972 💜
@kaizensky3399
@kaizensky3399 2 жыл бұрын
Did you forget to add Deafcon?
@_CryptoCat
@_CryptoCat 2 жыл бұрын
nah haha a teammate solved it and i didn't have all that much time. I was just going to pick 1 hard chall.. then couldn't solve any and did a few web instead 😂 I struggled enough with some of the xss ones bc im a n00b 😆
@seif-allahhomrani2169
@seif-allahhomrani2169 2 жыл бұрын
@@_CryptoCat it's cool that u mention ur failures and ur successes bro !!
@tlouik
@tlouik 2 жыл бұрын
@@_CryptoCat no, you're pro D:
@IlmuGuru
@IlmuGuru 2 жыл бұрын
Auto subscribe , dont take down this vidio
@_CryptoCat
@_CryptoCat 2 жыл бұрын
ty 🥰 i wasn't planning to take down the video but youtube censors be warned!! 😀
@IlmuGuru
@IlmuGuru 2 жыл бұрын
@@_CryptoCat Calm down I've saved it in the gallery🤣
@MrFontaineInc
@MrFontaineInc 2 жыл бұрын
I definitely need to brush up on Regex. Personnel stumped me and it was so simple.
@_CryptoCat
@_CryptoCat 2 жыл бұрын
that one was cool! don't see it much in ctfs 😊
@nogoodhacker6944
@nogoodhacker6944 2 жыл бұрын
how were you able to guess the flag would be at /var/www/flag.txt on extravagant xml injection 6:12 ?? BTW awesome !
@_CryptoCat
@_CryptoCat 2 жыл бұрын
thanks 🥰 3:19 it said the flag was at /var/www so just had to guess filename, either "flag" or "flag.txt" 😁
Angstrom CTF 2022 - Challenge Walkthroughs
1:18:40
CryptoCat
Рет қаралды 7 М.
路飞做的坏事被拆穿了 #路飞#海贼王
00:41
路飞与唐舞桐
Рет қаралды 26 МЛН
coco在求救? #小丑 #天使 #shorts
00:29
好人小丑
Рет қаралды 103 МЛН
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 21 МЛН
LA CTF 2024: Web Challenge Walkthroughs (1-4)
19:56
CryptoCat
Рет қаралды 3,5 М.
NahamCon CTF 2023: Web Challenge Walkthroughs
26:09
CryptoCat
Рет қаралды 13 М.
Angstrom CTF 2021 - Web Challenge Walkthroughs
36:05
CryptoCat
Рет қаралды 8 М.
I've been challenged to a CSS BATTLE by Web Dev Simplified
42:22
Kevin Powell
Рет қаралды 955 М.
BAD RANSOMWARE - HackTheBox Business CTF
22:01
John Hammond
Рет қаралды 52 М.
Solving a Hard Google CTF challenge - "Paste-tastic!"
26:26
PwnFunction
Рет қаралды 93 М.
RECOVERING FILES with Autopsy (PicoCTF 2022 #47 'operation-oni')
14:00
路飞做的坏事被拆穿了 #路飞#海贼王
00:41
路飞与唐舞桐
Рет қаралды 26 МЛН