bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

Nibbles - Hack The Box

7h3M0nk
2021-02-09
HackTheBox

How to crack Nibbles box without Metasploit.

tl;dr

  • Nibbleblog v4.0.3 Code Execution
  • CVE-2015-6967
Read More
HackTheBox WriteUp Nibbles

Web IDE - DiceCTF 2021

Yadhu Krishna M
2021-02-09
Web Exploitation

tl;dr

  • Unintended Solution: Cookie Path Restriction bypass using pop-up windows + JS Sandbox Escape
  • Intended Solution: Service Workers + JS Sandbox Escape
Read More
XSS DiceCTF JavaScript Sandbox Escape

Build A Better Panel - Dice CTF 2021

Az3z3l
2021-02-09
Web Exploitation

tl;dr

  • Payload: {"widgetName":"constructor","widgetData":"{\"prototype\":{\"srcdoc\":\"<script src='/admin/debug/add_widget?panelid=star7rix&widgetname=test123&widgetdata=%27%29%2C%28%27star7rix%27%2C+%28select+flag+from+flag%29%2C+%27%7B%22type%22%3A%22test123%22%7D%27%29+--'></script>\"}}"}
Read More
XSS Prototype Pollution CSP DiceCTF

Shocker - Hack the Box

7h3M0nk
2021-02-08
HackTheBox

How to crack Shocker box without Metasploit.

tl;dr

  • ShellShocker exploit
  • Apache mod_cgi
Read More
Writeup HackTheBox Shocker

ProxPi Relay Attack

bi0sHardware
2021-02-07
Hardware

tl;dr

In this post, we are going to share our research into PKES systems and the possibility of Relay attacks on such systems.

Read More
Relay Attacks PKES systems Smart Cars

Little Tricks - StarCTF 2021

g4rud4
2021-01-28
Forensics / Disk

tl;dr

  • Decrypt the bitlocker encrypted drive
  • extracting the flag from deleted PDF
Read More
Disk Encryption Bitlocker StarCTF

Favourite Architecture-1 - StarCTF 2021

Pwn-Solo
2021-01-20
Pwn

tl;dr

  • Abusing a stack overflow on a RISC-V binary to then return to shellcode.
Read More
Exploitation Linux StarCTF Shellcode RISC-V

BabyPAC - StarCTF 2021

d4rk_kn1gh7
2021-01-18
Pwn

tl;dr

  • Buffer overflow in AArch64
  • Bypass pointer authentication to leak libc and get shell
Read More
StarCTF ARM ROP PAC

Year In Review 2020

bi0s
2020-12-31
YearInReview

Read More
YearInReview

Diary - Balsn 2020

3agl3
2020-11-17
Pwn

tl;dr

  • Overflow from stdin stucture till main_arena.
  • Create fake fastbin chunks to get overlapping chunk and leak.
  • Overwrite __malloc_hook using fastbin attack.
Read More
Heap Balsn

 Previous 

11 / 19

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.