YAPC::Hakodate 2024ã«åå ãã¦ãã¾ãããè¿å¹´ã®YAPCã§ã¯åå ããã ãã§ç»å£ãã¦ããªãã£ãã®ã§ãããä»åã¯ã²ã¹ãã¨ãã¦å¼ãã§ããã ããã®ã§ã40åæ ã§èªåã®ä»äºã«å°ãé¢ä¿ãããããªæè¡ãã¿ã¿ãããªãã®ã話ããã¦ãããã¾ããã speakerdeck.com ã¹ã©â¦
ä¾ãã°ãã®SSHå ¬ééµãæ«å°¾ã«ç§ã®åå(akiym)ãå ¥ã£ã¦ãã¾ãã ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFC90x6FIu8iKzJzvGOYOn2WIrCPTbUYOE+eGi/akiym ãããªãã£ãããsshéµã欲ããã¨æãã¾ãããï¼ ed25519ã®SSHå ¬ééµã®æ§é SSHéµã®å½¢å¼ã«ã¯RSAãDSAãed2â¦
YAPC::Kyotoã¶ãã®YAPCã¨ãããã¨ã§YAPC::Hiroshima 2024ã«åå ãã¦ãã¾ããããä¹ ãã¶ãã®åå è ã®æ¹ã ãéå¶ãã¦ããã ããã¹ã¿ããã®æ¹ã å ±ã ãããã¨ããããã¾ããã å°è±¡ã«æ®ã£ããã¼ã¯ 2024å¹´å¬ã®Perl 5.40ã§ã¯Test2::Suiteãã³ã¢å ¥ãã¨ãããã¨ãèâ¦
以åã«akictfã¨ãã常è¨CTFãå ¬éãã¦ããã®ã§ãããéãããã¨ã«ãªã£ããã£ããã¯ã¡ã³ããã³ã¹ãé¢åã«ãªã£ãããã§ãããå½æã¯2013å¹´ãDockerãåºå§ããé ã§å½ç¶ä½¿ã£ã¦ããããLXCä¸ã§åé¡ã管çãã¦ãã¾ããããããã®VPSä¸ã§åããã¦ãã¦(å¾ã«ãããã®â¦
2023/4/22ã«è¡ãªãããRicerca CTF 2023ã«HackingForSushiã§åå ãã¦ã24ä½ã§ããã ä¸äººãã¼ã ã ãæéããã¾ããªãã£ãã®ã§revå+å¤ãããªãã¤ç¸ãã§è§£ãã¾ãããä¸åº¦ããé£æ度ã§è§£ãã¦ãã¦æ¥½ããã£ãã§ãã 解ããåé¡ nande å¾®å¦ã«éãæ°ããã¤ã¤ããã¨â¦
Firestoreã«ã¯ã¨ãã¥ã¬ã¼ã¿ãç¨æããã¦ãã¦ãæå ã®ç°å¢ã§ãä¼¼ããããªãã®ãåãããããã«ãªã£ã¦ãã¾ããéçºããã«ã¯ããã¯å¿ é ã¨ãã£ãã¨ããã§ãä¾ãã°éçºç°å¢ã®ãã¼ã¿ãæå ã®ç°å¢ã«ã¤ã³ãã¼ããã¦ä½¿ãã¨ãããã¨ããããã¦ãã¾ãã ã¨ãã¥ã¬ã¼ã¿ã«â¦
2023/4/22ã«è¡ãªãããRicerca CTF 2023ã«dodododoã§åå ãã¦ã2ä½ã§ããã dodododoã§ã¯æ®æ®µCTFã«åå ããã¨ãã¯ãGoogle Docsã«ããã¥ã¡ã³ããç¨æãã¦ãããã©ã®åé¡ã解ããã¨ãã¦ããããªã©ã®é²æç¶æ³ãå ±æã§ããããã«ãã¦ãã¾ãã大ãããã®ã¯ãªãã®â¦
SECCON CTF 2022ã®å½å 決åã«ãã¼ã AERO SANITYã§åå ãã¦ã4ä½ã§ããã 以åã¯ãã¼ã dodododoã¨ãã¦åå ãã¦ããã®ã§ããããã¼ã ã¡ã³ãã¼ã®åæ°(1人)ãCTFéå¶å´ã«ãªã£ã¦ãã¾ã£ãã®ã§ãä»åã¯ä¼ç¤¾ã®ååãèªã£ã¦ãã£ã¦ãã¾ããã Heptarchy æ§ã ãªè¨èªã®ãâ¦
ãã®è¨äºã¯ãCTF Advent Calendar 2021ã®4æ¥ç®ã§ãã adventar.org CTFã§åºé¡ãããreversingã®åé¡ã®ã²ã¨ã¤ã«ãç¬èªVMã¨å¼ã°ãããç¬èªã«å®è£ ãããVirtual Machineã®ä¸ã§åããã¤ãã³ã¼ã(ããã°ã©ã )ã®è§£æãè¡ããã®ãããã¾ãã ãã®åé¡ã§ã¯VMèªä½ã®ãâ¦
ã¾ãã¯ããã«ã2021/2æç¹ã§gRPCããµãã¼ãããã¦ããè¨èªã«ã¯Perlã¯å«ã¾ãã¦ããªããå ¬å¼ã«ã¯ãµãã¼ãããã¦ãã¾ããã ç¾æç¹ã§ã¨è¨ã£ããã®ã®å°æ¥çã«ããµãã¼ãããããã¨ããªãã ãããã¨ããPerlã§gRPCãæ±ãã®ã¯è¨ã®éã¨ãããã§ãããã ãã¨ãªããgâ¦
ãã®è¨äºã¯ãã¯ã¦ãªã¨ã³ã¸ã㢠Advent Calendarã®15æ¥ç®ã§ãã qiita.com OpenSSLã«ä¾åãã¦ããã¢ã¸ã¥ã¼ã«ãã¤ã³ã¹ãã¼ã«ãããã¨æã£ãã¨ãã«ã©ã¤ãã©ãªãè¦ã¤ãããªãã¦å°ããã¨ãããã¾ãã ä¾ãã°macOSä¸ã§homebrewã使ã£ã¦OpenSSLãã¤ã³ã¹ãã¼ã«ããå ´â¦
attack and deferenceå½¢å¼ã®CTFã«ãªã³ã©ã¤ã³ã§åå ãããdodododoã¯19ä½ã sshã§ãããµã¼ãã1å°ä¸ãããã¦ãããã§8ã¤ã®ãµã¼ãã¹ãæ£ããåããã¤ã¤ãæ»æã¨é²å¾¡ãè¡ãã flagã¯éå¶ãããµã¼ãã¹ãæ£ããåãã¦ãããã©ããã®ç¢ºèªã¨ä¸ç·ã«éããã¦ãããä¾â¦
speakerdeck.com æè¿ã®ä¾¿å©Perlæ å ±ã好ããªã¢ã¸ã¥ã¼ã«ã®è©±ããã¾ããã ãã¼ã¯å¿åããã¨ãã«ã¯è©±ãããã£ãç´°ãã話é¡ãããã¤ããã£ãã®ã§ããã20åã§ã¯åã¾ããªãã£ãã®ãããã¯ã©ã¹ãã«ããã¯ã©ã¹ãã¼ããããªãã¼ã¿ãType::Tinyã®è©±ã«ãªãã¾ããã â¦
speakerdeck.com ãã¼ã¯ã®å 容ã¯Test2ã®å°å ¥ãã便å©æ å ±ãç´¹ä»ããããã¾ãããå°ãã§ãTest2使ã人ãå¢ããã¨ããã§ããã ã¹ã©ã¤ãä¸ã«ã触ãã¦ãã¾ãããåºæ¬çã«ã¯Test2ã«ç§»è¡ããã«ããã£ã¦ã¯Test2::Plugin::UTF8ã使ãããã«ããã°å¤§ä¸å¤«ããªã¨æãã¾â¦
æ ªå¼ä¼ç¤¾ã¯ã¦ãªã«å ¥ç¤¾ãã¾ããæ ªå¼ä¼ç¤¾ã¯ã¦ãªã«å ¥ç¤¾ãã¾ãã - hitode909ã®æ¥è¨
ä»å¹´ãid:nanuyokakinuããã«ããå¹´è³ç¶CTFãéå¬ããã¦ããã®ã§åå ããï¼ reversingåé¡ãå ¨é¨ã§3åï¼ãã¹ã¦è§£ãã¨æå¾ã®ãã©ã°ã«Amazonã®ã®ããå¸ãæ¸ãã¦ããï¼ãå¹´çãè²°ããï¼ä»å¹´ã¯ãªãã¨0x1337åï¼ãããã¨ããããã¾ãã :) nanuyokakinu.hatenabloâ¦
ãã®è¨äºã¯ï¼CTF Advent Calendar 2016ã®1æ¥ç®ã§ãï¼ www.adventar.org CTFãã¬ã¤ã¤ã¼ãããã®ï¼æ¥ã ã®éé¬ã¯æ¬ ããã¾ããï¼ éå»åã解ãã¦ããï¼ç«¶æä¸ã«çã®å®åãçºæ®ãããã¨ãã§ããã®ã§ãï¼ ã¨ãããã¨ã§ï¼bata_24ãããå ¬éãã¦ããpwn challenges lâ¦
ãã¾ãã¡ãã³ã¨ããè¨ãæ¹ãåãããªãããã©ï¼ã¤ã¾ãã¯ãããããã¨ï¼ [ { id => 1, value => 'foo', }, { id => 2, value => 'bar', }, ] ãã®ãããªãã¼ã¿æ§é ããã£ãã¨ãã«ï¼ä»¥ä¸ã®ããã«idãkeyã¨ãã¦ããã·ã¥ã«ãããï¼ { 1 => { id => 1, value => 'â¦
greeting Host : pwn2.chal.ctf.westerns.tokyo Port : 16317 greeting Note: DoSæ»æã«å¯¾ãã対çã®çºï¼åºåã131072æåã«å¶éããã¦ãã¾ãï¼ mainé¢æ°ã®ã¿ã®ã·ã³ãã«ãªãã¤ããªï¼FSBããããï¼ãã®å¾ããã«returnãããã1度ããå®è¡ã§ããªãããã«è¦ããâ¦
Go Sandbox (Pwning, 150) We found a sandbox written in Go. It looks pretty solid, but there must be a bug somewhere. All you need to do for us is to execute ./get_flag IP: gobox.hackable.software:1337 Download Golangã®ã½ã¼ã¹ã³ã¼ããå®è¡ãâ¦
ãã¼ã dodododoã§åå ãã¦ã29109ptã§åªåãã¾ããã ãã¼ã æ§æã¯akiym, xrekkusu, lrks, hiromuã®4人ãåæ ã¯ãæ»æçakiymã¨lrksãé²å¾¡çxrekkusuã¨hiromuã ä»åã®SECCON Intercollegeã¯å¦çéå®ã¨ãããã¨ã§ãé常ã®æ±ºåã¨ã¯éããAttack & Defenseã«ã¼â¦
CTF Advent Calendar 2015 - Adventar 16æ¥ç® CTFãããã¨å¯ç£ç©ã¨ãã¦ä¸æ岩ã®ã¹ã¯ãªãããã§ããããã¾ããããã¤ã便å©ãã¼ã«ãå ¬éãã¦ããã®ã§ãããã§ç´¹ä»ãã¾ãã å人çã«ã¯å°å³ã«ä¾¿å©ã¨æã£ã¦ããã®ã§ãããä¸äººåããããããªãã®ã§ã¯ãªãããã§ãâ¦
This is my short writeup for John's shuffle. John is completely drunk and unable to protect his poor stack.. Fortunately he can still count on his terrific shuffling skills. Connect to shuffle.polictf.it:80 This is pwnable challenge worth â¦
The Perl Jam - Exploiting a 20 Year-old Vulnerability ããPerlãæ®æ®µããæ¸ãã¦ãã人ã«ã¨ã£ã¦ã¯å¸¸èã§ã¯ããããããã§ã¯ãªã人ã®ããã«æ¸ãã¦ããã ãªã¹ãã¨é å Perlã«ãããããªã¹ããã¨ã¯ä½ãã¨ããã®ã確èªãã¦ãããã¾ããPerlã«ã¯ã³ã³ããã¹ãâ¦
ãã¼ã dodododoã§åå ãæè¿ã¯ããèªå(@akiym)ã¨ãã£ãã(@xrekkusu)ã®2人ã§åå ãã¦ããã çµæã¯7ä½ãfinalsã®åå 権ãè²°ãããããããä¼å ´ã¯ã¹ãã¤ã³ã§ãããã交éè²»ã¯ã§ãªãã®ã§ç ´æ£ã¨ãããã¨ã«ãåé¡ã¯éå§æã«ãã¹ã¦ãªã¼ãã³ãããå½¢ã«ãªã£ã¦ããâ¦
loginpage1 (web 10)running at ctf.katsudon.org:5002 #!/usr/bin/env perl use Mojolicious::Lite; app->secrets([$ENV{FLAG}]); get '/' => sub { my $self = shift; return $self->render('index', user => $self->session->{user}, flag => $ENV{FLAG},â¦
SECCON 2014 ãªã³ã©ã¤ã³äºé¸(æ¥æ¬èª)ã«dodododoã¨ãã¦åå ããã2302ç¹ã§5ä½ãã¨ããããå ¨å½å¤§ä¼ã®åºå ´æ¨©ã¯ç²å¾ã§ãã(ä¸ä½8ä½ã¾ã§)ããã¼ã ã¡ã³ãã¼ã«ããwriteup: http://xrekkusu.hatenablog.jp/entry/2014/07/19/220129 以ä¸ãèªåã解ããåé¡ã®writeuâ¦
blacklist (web 10)running at ctf.katsudon.org:5001 use Mojolicious::Lite; use DBI; # enjoy~ my $BLACKLIST_CHAR = qr/['"`=]/; my $BLACKLIST_WORD = qr/select|insert|update|from|where|order|union|information_schema/; my $dbh = DBI->connect('dâ¦
ã²ã¼ã ãä½ããã¨æãç«ã£ãã¯ãããã®ã®ãä½ããå§ããã°ãããã ããâ¦ãcocos2d-xã§ã¹ããã²ã¼ã ãä½ãï¼Unityã§3Dããªããªã®ã²ã¼ã ãä½ãï¼ãã¾ãã¡ããã¨ãã¾ããããããã§ãããªãã ãè¤éãããã®ã§ãã ãããªããªãã«ããã¿ãªãªã®ããã¡ãã³ã³ã®ã²â¦
10guess (crypto 10)running at ctf.katsudon.org:5555 package main import ( "bufio" cr "crypto/rand" "crypto/rsa" "fmt" "log" "math/big" "math/rand" "net" "strconv" ) var seed int64 = ????? func handleConnection(conn net.Conn) { log.Printf("â¦