Published on10 février 20240xL4ughctf 2024 - Wordpress 10xL4ughctf-2024LumyForensicsPCAPWordpress forensics Ips and versions
Published on10 février 20240xL4ughctf 2024 - Wordpress 20xL4ughctf-2024LumyForensicsPCAPWordpress forensics bruteforce username, passwords and method used
Published on10 février 20240xL4ughctf 2024 - Wordpress 30xL4ughctf-2024LumyForensicsPCAPWordpress forensics tools used by attacker and CVE associated
Published on29 octobre 2023BlueHensCTF 2023 – Python Jail / HarderBlueHensCTF-2023LumyMiscPyjailPython Jail
Published on1 octobre 2023BuckeyeCTF 2023 – StrayBuckeyeCTF-2023LumyWebLFIHTTP parameter pollution attack leading to LFI
Published on1 octobre 2023BuckeyeCTF 2023 – Text Adventure APIBuckeyeCTF-2023LumyWebDeserializationPickle deserialization exploitation
Published on1 octobre 2023BuckeyeCTF 2023 – area51BuckeyeCTF-2023LumyWebSQLBlind NoSQL injection on MongoDB
Published on10 septembre 2023PatriotCTF 2023 – FlowerShopPatriotCTF-2023LumyWebPRNGmt_rand vulnerability
Published on10 septembre 2023PatriotCTF 2023 – PickYourStarterPatriotCTF-2023LumyWebSSTISSTI in Web pokemon starter pick challenge
Published on3 septembre 2023DownUnderCTF 2023 – DownunderflowDownUnderCTF-2023LumyPwnUnderflow exploit
Published on3 septembre 2023DownUnderCTF 2023 – FaradayDownUnderCTF-2023LumyOSINTTrack a target based on a phone number
Published on3 septembre 2023DownUnderCTF 2023 – Randomly chosenDownUnderCTF-2023LumyCryptoRandom seed but with low value that can be bruteforced
Published on27 août 2023SEKAI CTF 2023 – Azusawa's Gacha WorldSEKAICTF-2023LumyReverseUnity3DUnity3D Gacha Game system : Solved using DNSpy, Cheatengine and Wireshark as no server side verification
Published on2 août 2023OSCP Buffer overflow guideLumyOSCPBufferoverflowExploit example of a bufferoverflow on the OSCP exam
Published on29 juillet 2023BYUCTF 2023 – PBKDF2BYUCTF-2023LumyForensicsCryptoZipExploit zip with ascci SHA 1 representation
Published on29 juillet 2023BYUCTF 2023 – a-z0-9BYUCTF-2023LumyJailPython jail with blacklist containg all letters + "." Unicode and octal is key
Published on29 juillet 2023BYUCTF 2023 – abcdefghijklmBYUCTF-2023LumyJailPython jail with blacklist containg all letters + "." Unicode and octal is key
Published on29 juillet 2023BYUCTF 2023 – Builtins 1BYUCTF-2023LumyJailPython jail with no builtins, using os._wrap_close to get the flag
Published on29 juillet 2023BYUCTF 2023 – Builtins 2BYUCTF-2023LumyJailPython jail with no builtins, "__" filters and size limitation. Unicode and _frozen_importlib_external.FileLoader was the solution
Published on29 juillet 2023BYUCTF 2023 – KCPasswordBYUCTF-2023LumyForensicsCryptoMacOSExploit MacOS autologon feature
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 1BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 2BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 3BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 4BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023BYUCTF 2023 – urmombotnetdotnet - 5BYUCTF-2023LumyWebStacktracesGetting secrets through stacktraces with flask
Published on29 juillet 2023ImaginaryCTF 2023 – WebImaginaryCTF-2023LumyForensicsBrowserDataBrowser data exploit
Published on29 juillet 2023n00bzCTF 2023 – Crack & Crackn00bzCTF-2023LumyForensicsZipPDFBruteforce cracking of zip and pdf file
Published on29 juillet 2023n00bzCTF 2023 – Google Form 2n00bzCTF-2023LumyMiscGoogle-formGoogle form misconfiguration permitting to see previous responses
Published on29 juillet 2023n00bzCTF 2023 – Pyjail 1n00bzCTF-2023LumyJailPython jail with a huge blacklist. If we can't bypass the blacklist, let's delete the blacklist using pop
Published on29 juillet 2023TFCCTF 2023 – ListTFCCTF-2023LumyForensicsPCAPPCAP capture with RCE on the system through webshell
Published on29 juillet 2023TFCCTF 2023 – MCTEENXTFCCTF-2023LumyForensicsZipAn encrypted zip file, with partial knowledge of a file content
Published on29 juillet 2023TFCCTF 2023 – My first calculatorTFCCTF-2023LumyMiscJailPython jail with blacklist containg all letters + "." Unicode and octal is key
Published on29 juillet 2023TFCCTF 2023 – My third calculatorTFCCTF-2023LumyMiscJailPython jail with blacklist containg all letters + "." + cmd restrictions. Unicode and octal is key
Published on29 juillet 2023TFCCTF 2023 – PassTFCCTF-2023LumyReverseChar by Char password comparison. Bruteforce and reverse solutions
Published on29 juillet 2023TFCCTF 2023 – Some TrafficTFCCTF-2023LumyForensicsSteganographyPCAPExfiltration of sensible data using steganography upon network
Published on29 juillet 2023TJCTF 2023 – Back to the pastTJCTF-2023LumyWebJWTChanging algorithm from RS256 to HS256, bypassing signature process