[TCP1PCTF 2023] Unsecure

TCP1PCTF was organized by Indonesian and it was opened to anyone. The challenge is solely focus on exploiting deserialization vulnerability and how to chain the gadget to get code execution.

October 17, 2023 Â· 4 min

[TCP1PCTF 2023] PDFIFY

TCP1PCTF was organized by Indonesian and it was opened to anyone. For this challenge specifically, it was really good. I do need to read the source code as well as chaining multiple vulnerabilities such as SQL Injection, SSRF and Insecure Deserialization to get RCE.

October 17, 2023 Â· 12 min

[WargamesMY 2022] MostFriendlyApp

This is a web challenge related to TOTP and some bruteforce operation.

December 26, 2022 Â· 3 min

[WargamesMY 2022] C0mmand33r

This is a boot2root challenge, related to basic OS injection, some real world related account takeover and basic privilages escalation.

December 26, 2022 Â· 9 min