Published on10 septembre 2023PatriotCTF 2023 – PickYourStarterPatriotCTF-2023LumyWebSSTISSTI in Web pokemon starter pick challenge
Published on3 septembre 2023DownUnderCTF 2023 – DownunderflowDownUnderCTF-2023LumyPwnUnderflow exploit
Published on3 septembre 2023DownUnderCTF 2023 – FaradayDownUnderCTF-2023LumyOSINTTrack a target based on a phone number
Published on3 septembre 2023DownUnderCTF 2023 – Randomly chosenDownUnderCTF-2023LumyCryptoRandom seed but with low value that can be bruteforced
Published on27 août 2023SEKAI CTF 2023 – Azusawa's Gacha WorldSEKAICTF-2023LumyReverseUnity3DUnity3D Gacha Game system : Solved using DNSpy, Cheatengine and Wireshark as no server side verification
Published on2 août 2023OSCP Buffer overflow guideLumyOSCPBufferoverflowExploit example of a bufferoverflow on the OSCP exam
Published on29 juillet 2023BYUCTF 2023 – PBKDF2BYUCTF-2023LumyForensicsCryptoZipExploit zip with ascci SHA 1 representation
Published on29 juillet 2023BYUCTF 2023 – a-z0-9BYUCTF-2023LumyJailPython jail with blacklist containg all letters + "." Unicode and octal is key
Published on29 juillet 2023BYUCTF 2023 – abcdefghijklmBYUCTF-2023LumyJailPython jail with blacklist containg all letters + "." Unicode and octal is key
Published on29 juillet 2023BYUCTF 2023 – Builtins 1BYUCTF-2023LumyJailPython jail with no builtins, using os._wrap_close to get the flag
Published on29 juillet 2023BYUCTF 2023 – Builtins 2BYUCTF-2023LumyJailPython jail with no builtins, "__" filters and size limitation. Unicode and _frozen_importlib_external.FileLoader was the solution
Published on29 juillet 2023BYUCTF 2023 – KCPasswordBYUCTF-2023LumyForensicsCryptoMacOSExploit MacOS autologon feature
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 1BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 2BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 3BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask