bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

MultiStorage - InCTF Internationals 2021

3agl3
2021-08-18
Pwn

tl;dr

  • Race condition to change the type.
  • Leak using uninitialized memory and get rip with overflow.
Read More
InCTFi Exploitation Heap Kernel

Baby Glob - InCTF Internationals 2021

Cyb0rG
2021-08-17
Pwn

tl;dr

  • Heap Overflow in glob function while handling Tilde operator.
  • Abuse null byte overflow to gain RCE.
Read More
InCTFi Exploitation Heap CVE-2017-15804

Kqueue - InCTF Internationals 2021

Cyb0rG
2021-08-17
Pwn

tl;dr

  • Use the integer overflow to trigger a kernel heap overflow.
  • Use the heap overflow to overwrite tty structure function pointers to get code execution.
Read More
InCTFi Exploitation Linux Kernel Kernel Heap

Heist Ends - InCTF Internationals 2021

g4rud4
2021-08-16
Forensics / Android

tl;dr

  • Extract creation timestamp of a note from Google Keep Notes.
  • Finding location, date & time from Slack Messages.
  • Extract no. of tasks completed and created from Google Tasks.
  • Finding secret code from Google Docs cache.
  • Extract first opened timestamp of a Game.
Read More
InCTFi Android ALEAPP

Heist Continues - InCTF Internationals 2021

g4rud4
2021-08-16
Forensics / Windows

tl;dr

  • Extract User ID and Workspace ID of the Slack workspace participating.
  • Extract the first & last 3 characters of text from the Anydesk Remote connected PC’s thumbnail wallpaper.
  • Extract the type of filesystem of the USBs connected to the system.
  • Extracting active duration of Voice Modulator application used by parsing Windows Activity timeline.
Read More
InCTFi USB Slack Windows Activity timeline Anydesk

Heist - InCTF Internationals 2021

g4rud4
2021-08-16
Forensics / Windows

tl;dr

  • Finding default browser and the top visited website.
  • Extract timestamp, ID, Hostname of the TeamViewer FileTransfer session.
Read More
InCTFi Browser Forensics TeamViewer

Ermittlung - InCTF Internationals 2021

g4rud4
2021-08-16
Forensics / Memory

tl;dr

  • Finding Chat application
  • Extract unread message count from NTUSER.dat.
  • Extract the last executed timestamp of the chat application.
  • Extract the Version of the chat application.
Read More
InCTFi Volatility Windows Memory Analysis

Notepad Series - InCTF Internationals 2021

Az3z3l
2021-08-16
Web Exploitation

tl;dr

  • Notepad 1 - Use Set-Cookie header to get XSS on the Admin
  • Notepad 1.5 - CRLF on the name parameter of Golang’s Header().Set() method
  • Notepad 2 - Xsleaks using Timing-Allow-Origin header
Read More
InCTFi CRLF XSS Xsleaks

Ancient House - InCTF Internationals 2021

Pwn-Solo
2021-08-15
Pwn

tl;dr

  • Jemalloc heap challenge
  • A buggy implementation of strncat in merge allows for an overwrite onto the next region
Read More
InCTFi Exploitation Linux Heap Jemalloc

Vuln Drive - InCTF Internationals 2021

Rohit
2021-08-15
Web

tl;dr

  • /source to get the source
  • Access local host from dev_test using SSRF
  • SQLI to get the flag path a nd LFI to get the flag
Read More
InCTFi SSRF LFI SQLI

 Previous 

7 / 19

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.