UIUCTF 2023 Challenge Writeups (1x rev, 4x crypto, 2x pwn)

  Рет қаралды 1,468

SloppyJoePirates CTF Writeups

SloppyJoePirates CTF Writeups

Күн бұрын

Пікірлер: 12
@SloppyJoePirates
@SloppyJoePirates Жыл бұрын
Correction 1: For zapps-1, it's a hardlink, not a symlink. Thanks @zhuyifei1999!
@perschrijver8884
@perschrijver8884 Жыл бұрын
Congrats on 100 videos! Thanks for another great one :D
@kampet3438
@kampet3438 Жыл бұрын
I really enjoyed "zapping setuid1" as well! Truly a nice challenge :)
@MelarDev
@MelarDev Жыл бұрын
underrated YT channel, keep it up!
@ttrss
@ttrss Жыл бұрын
really interesting approach to the vm challenge
@ap425q
@ap425q Жыл бұрын
Hey could you solve vmwhere2 with the same approach as vm1 it should work right 🤔?
@davemonaco1
@davemonaco1 Жыл бұрын
No, the approach will probably not work for vmwhere2. The reason is that the check in vmwhere2 always processes the whole flag and gathers comparisions in a mask. basically loop over the input and do mask |= input[i]^encrypted[i], if mask is 0 the input is fine. but number of executed instructions will not vary drastically.
@SloppyJoePirates
@SloppyJoePirates Жыл бұрын
(What @davemonaco1 said)
@daniel01045
@daniel01045 Жыл бұрын
hmm my comment got deleted but basically you can massively improve the efficiency of the bruteforce on vmwhere one by just using send instead of sendline and bruting byte by byte. If it hangs then you got the right character, if it terminates, then obviously you got the wrong char. I managed to get the flag this way in about 10 seconds.
@SloppyJoePirates
@SloppyJoePirates Жыл бұрын
Oh interesting, thanks!
@davemonaco1
@davemonaco1 Жыл бұрын
Nice writeups, as always. For Zapping Setuid1: I found that most of the options can be removed. Minimal set is to specify the entry and output: "gcc shell.c -o ld-linux-x86-64.so.2 -e main" worked all fine for me
@SloppyJoePirates
@SloppyJoePirates Жыл бұрын
Hey @davemonaco1! Oh nice, way simpler! Strange, I wonder why I was having issues with stack canaries? Maybe I had multiple things wrong and I just thought it was stack canaries
UIUCTF 2023 Web Challenges
23:32
SloppyJoePirates CTF Writeups
Рет қаралды 1,2 М.
СОБАКА ВЕРНУЛА ТАБАЛАПКИ😱#shorts
00:25
INNA SERG
Рет қаралды 3,5 МЛН
😜 #aminkavitaminka #aminokka #аминкавитаминка
00:14
Аминка Витаминка
Рет қаралды 3 МЛН
Perfect Pitch Challenge? Easy! 🎤😎| Free Fire Official
00:13
Garena Free Fire Global
Рет қаралды 75 МЛН
vsCTF 2023 Challenge Writeups (4x pwn, 1x misc, 1x rev, 1x web)
33:26
SloppyJoePirates CTF Writeups
Рет қаралды 1,7 М.
Why Agent Frameworks Will Fail (and what to use instead)
19:21
Dave Ebbelaar
Рет қаралды 83 М.
BuckeyeCTF 2023 Challege Writeups (5x crypto, 5x misc, 3x pwn,  2x rev, 7x web)
49:18
SloppyJoePirates CTF Writeups
Рет қаралды 2,1 М.
The Only Unbreakable Law
53:25
Molly Rocket
Рет қаралды 336 М.
Security Topics #2: Unicode Normalization Attacks
17:53
SloppyJoePirates CTF Writeups
Рет қаралды 822
Why Are Open Source Alternatives So Bad?
13:06
Eric Murphy
Рет қаралды 671 М.
Vim Tips I Wish I Knew Earlier
23:00
Sebastian Daschner
Рет қаралды 76 М.
All Rust string types explained
22:13
Let's Get Rusty
Рет қаралды 181 М.
NewportBlakeCTF 2023 Writeups (2x algo, 4x crypto, 2x misc, 2x osint, 5x pwn, 1x rev, 4x web)
49:18
СОБАКА ВЕРНУЛА ТАБАЛАПКИ😱#shorts
00:25
INNA SERG
Рет қаралды 3,5 МЛН