Open in app

Sign In

Write

Sign In

Ditto
Ditto

6 Followers

Home

About

May 15, 2022

OSED Prep

My 4 part series after completing OSED training: First 2 parts are merely failed attempts.. Was fooling around with known vulnerable apps and trying to get it myself Last 2 parts are an intentionally vulnerable app made by one of the OSED student at that time. Lets learn Reverse Engineering 1! - HackMD Lets learn Reverse Engineering 1! ###### tags: `reverse engineering`, `windows`, `pwn` I will bhackmd.io

1 min read

1 min read


May 3, 2022

Python Shells in Browser!?

Recently, I chanced upon something cool! Its a python shell running on the Browser. 🤯 The technology behind it is Pyodide and primarily based on WebAssembly/Emscripten. Check out the papers below if you are interested! https://pyodide.org/en/stable/ https://blog.pyodide.org/talks/2022-pyodide-PyConUS.pdf You can even do things like import os and open,read,write files to it! Sounds pretty dangerous but everything is done behind a sandbox (hmmmmm?).

Cool Stuff

1 min read

Cool Stuff

1 min read


Apr 8, 2021

PicoCTF 2021 (Pwn only)

My results: 11/16 completed! Managed to solve Cache Me Outside locally but not on remote. :(

Pico

7 min read

PicoCTF 2021 (Pwn only)
PicoCTF 2021 (Pwn only)
Pico

7 min read


Mar 11, 2021

ZeroPts CTF Pwn

Super awesome, learnt a lot! Still loads to learn, but getting there. StopWatch: Always google suspicious API calls such as alloca. This API allocates memory using the stack frame, allowing user to specially position something (stack canary) to be printed later! …

Pwn

2 min read

ZeroPts CTF Pwn
ZeroPts CTF Pwn
Pwn

2 min read


Feb 19, 2021

McAfee ATR Hax

This CTF is a good experience for people who want to get started in the CTF field. Managed to solved a few challenges and will be uploading my solutions on github. Sadly, I will only doing a write up for the pwn challenge. …

Mcafee

2 min read

McAfee ATR Hax
McAfee ATR Hax
Mcafee

2 min read


Feb 13, 2021

PwnCollege BabyMem

Really enjoyed Challenge 5 on integer overflow and Challenge 15 on brute forcing stack canaries! Challenge 5 was quite realistic as I happened to read a write-up that seems to have the same logic flaw. This was the write-up I was looking at that I find particularly relevant: pwn4fun Spring 2014 - Safari - Part I Back in March this year I entered the pwn4fun hacking contest at CanSecWest […googleprojectzero.blogspot.com

Pwncollege

1 min read

Pwncollege

1 min read


Jan 29, 2021

Adversary Quest 2021 (Continued)

Challenge 2 (Order of 0x20) Install tor and extract these messages from the Deep Dark Web Welcome on board! 259F8D014A44C2BE8FC573EAD944BA63 21BB02BE026D599AA43B7AE224E221CF 00098D47F8FFF3A7DBFF21376FF4EB79 B01B8877012536C10394DF7A943731F8 9117B49349E078809EA2EECE4AA86D84 4E94DF7A265574A379EB17E4E1905DB8 49280BD0040C23C98B05F160905DB849 280B6CB9DFECC6C09A0921314BD94ABF 3049280B5BFD8953CA73C8D1F6D0040C 1B967571354BAAB7992339507BBB59C6 5CDA5335A7D575C970F1C9D0040C23C9 8B08F78D3F40B198659B4CB137DEB437 08EB47FB978EF4EB7919BF3E97EA5F40 9F5CF66370141E345024AC7BB966AEDF 5F870F407BB9666F7C4DC85039CBD819 994515C4459F1B96750716906CB9DF34 5106F58B3448E12B87AFE754C0DD802C 41C25C7AAAFF7900B574FC6867EA35C5 BB4E51542C2D0B5645FB9DB1C6D12C8E F62524A12D5D5E622CD443E02515E7EB 991ACCC0C08CE8783F7E2BAD4B16D758 530C79003E5ED61DFE2BE70F50A6F9CA 288C…

Crowdstrike

3 min read

Adversary Quest 2021 (Continued)
Adversary Quest 2021 (Continued)
Crowdstrike

3 min read


Jan 29, 2021

Adversary Quest 2021

Only had time to do the first 2 RE challenges, was stuck on the Protective Penguin Challenge (Portal). Would appreciate a dm/comment if you manage to finish it. Here goes my write up on the other 2 challenges! Challenge 1: The Proclaimation This challenge is about reversing a boot loader. 1. Install qemu-system, I…

Adversary Quest

2 min read

Adversary Quest 2021
Adversary Quest 2021
Adversary Quest

2 min read


Jan 21, 2021

Challenge 2: Time To Draw

This is my first time looking at a Prototype Pollution Challenge. I guess a recurring theme/lesson is to always go back to basics and start looking at what the user can control. Source code: cddc12346/RandomCTFs Contribute to cddc12346/RandomCTFs development by creating an account on GitHub.github.com With that lesson in mind, lets start looking at what the user can control. Searching for…

Web

3 min read

Challenge 2: Time To Draw
Challenge 2: Time To Draw
Web

3 min read


Jan 19, 2021

BambooFox CTF 2021

This was a great CTF! Tried the web challenges and I think I did better than last time haha. Managed to complete 1 challenge by myself with no hints! It was similar to what I attempted on TetCTF but with a little tweak and different method. …

Bamboofox

3 min read

BambooFox CTF 2021
BambooFox CTF 2021
Bamboofox

3 min read

Ditto

Ditto

6 Followers

Welcome!

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech