OSIRIS Blog
  • Home
  • About
Sign in Subscribe

CSAW CTF 2014 VM

Vaughn Valle (8bitrosso)

Vaughn Valle (8bitrosso)

Oct 14, 2014

A few weeks ago the CSAW CTF was run from NYU-Poly and over 2500 teams registered to play.

We’re releasing most of the CSAW CTF challenges in a VM for those who were not competing to download and try on their own.

CSAW Quals 2014 VM - MD5: abc2fd91edc1b4f60a88a4183ce4fbe6

Credentials:

Username: user

Password: user

Read more

Bugcrowd Student Finale CTF 2025 Writeup:  MadDog Memorial

Bugcrowd Student Finale CTF 2025 Writeup: MadDog Memorial

Here, I had to find a way to get the admin flag from a memorial website. The site assigns regular visitors random usernames, but the flag is restricted to admins only. I needed to figure out how to trick the system into believing I was the administrator.

By j3rry Nov 25, 2025
Bugcrowd Student Finale CTF 2025 Writeup:  Predictable

Bugcrowd Student Finale CTF 2025 Writeup: Predictable

In this chal, I was given a compromising an admin account on a website. I had to figure out how password reset tokens were generated and create a valid one to hijack the account. The hint suggested that the tokens were generated using predictable patterns based on timestamps and email addresses.

By j3rry Nov 25, 2025
CrateCTF 2025 Writeup: Fiats och Shamirs Skyltsmedja

CrateCTF 2025 Writeup: Fiats och Shamirs Skyltsmedja

In this challenge, we visited a "Sign Smith" shop that used a fancy cryptographic protocol to verify customers. Our goal was to forge a signature to prove we were allowed to pick up the flag, even though the shop refused to sign any message containing the word "flag."

By j3rry Nov 25, 2025
CrateCTF 2025 Writeup: Evenemang

CrateCTF 2025 Writeup: Evenemang

The is a forensics challenge where a user accidentally ran a mal program hidden among 1000 other numbered programs (1.exe to 1000.exe) in a folder on their desktop. Instead of manually checking each program, they ran all of them and captured the system logs to analyze which one behaved suspiciously.

By j3rry Nov 25, 2025
OSIRIS Blog
  • Sign up
Powered by Ghost

Join our newsletter!

Subscribe to stay up to date on OSIRIS events and secrets 👀