Git Product home page Git Product logo

blinky-keys / business-ctf-2024 Goto Github PK

View Code? Open in Web Editor NEW

This project forked from hackthebox/business-ctf-2024

0.0 0.0 0.0 214.47 MB

Official writeups for Business CTF 2024: The Vault Of Hope

Shell 1.43% JavaScript 47.71% Ruby 10.64% Python 8.00% C 0.99% PHP 0.64% VHDL 0.10% Go 2.15% Assembly 0.08% Rust 0.05% TypeScript 13.21% CSS 6.53% VCL 0.05% Nix 0.01% Hack 0.09% Makefile 0.47% HTML 5.37% Vue 0.87% Dockerfile 0.86% EJS 0.75%

business-ctf-2024's Introduction

HTB

Category Name Objective Difficulty [⭐⭐⭐⭐⭐]
Reversing FlagCasino Reversing a rand based flag checker
Reversing SnappedShut Reversing a backdoored v8 snapshot ⭐⭐
Reversing Don't Panic Reversing the use of Rust unwind catching ⭐⭐
Reversing TunnelMadness Solving a 3D maze embedded in a binary ⭐⭐⭐
Reversing SatelliteHijack Reversing a multi-layered ifunc based backdoor ⭐⭐⭐⭐
Crypto eXciting Outpost Recon Recover XOR key given known plaintext
Crypto Living with Elegance Solve decisional problem based on LWE outputs ⭐⭐
Crypto Bloom Bloom Obtain the key derived from BBS outputs and then SSS ⭐⭐
Crypto Not that random Identify fake outputs from a custom vulnerable HMAC ⭐⭐⭐
Crypto Blessed Crack EC-PRNG with LLL + Cheat custom ZKP + Rogue Key Attack ⭐⭐⭐⭐
Blockchain Recruitment Interact with the infrastructure and solve the challenge by satisfying transaction constraints.
Blockchain NotADemocraticElection Common signature forgery attack. ⭐⭐
Blockchain MetaVault Self verification of smart contracts and how "secrets" can sometimes be hidden in the metadata. ⭐⭐
Blockchain Brokenswap Steal funds from a DEX ⭐⭐⭐
Cloud Scurried
Cloud MetaRooted ⭐⭐
Cloud Protrude ⭐⭐
Cloud CloudOfSmoke ⭐⭐⭐
Cloud Asceticism ⭐⭐⭐⭐⭐
Coding Computational Recruiting Sort based on parsed data computed with formulas
Coding Bag Secured Implement an algorithm to solve the knapsack problem ⭐⭐
Coding Dynamic Paths Implement a dynamic programming algorithm to solve the minimum path sum problem ⭐⭐
Coding Branching Tactics Traverse a tree efficiently using binary lifting ⭐⭐⭐
Coding Nothing Without A Cost DP with an optimized divide and conquer approach ⭐⭐⭐⭐
Forensics Caving PowerShell event log analysis
Forensics Silicon Data Sleuthing OpenWRT firmware analysis ⭐⭐
Forensics Tangled Heist LDAP network traffic analysis ⭐⭐
Forensics Mitigation XZ Backdoor detection and mitigation ⭐⭐⭐
Forensics Counter Defensive Kovter based registry persistence analysis and Telegram evidence dump ⭐⭐⭐⭐
Hardware It's Oops PM VHDL backdoor
Hardware Say Cheese! Camera firmware backdoor ⭐⭐
Hardware Six Five O Two Flashing 6502 CPU ⭐⭐⭐
Misc Aptitude Test Connect to a socket via nc and send answers
Misc Chrono Mind LM context injection with path-traversal, LM code completion RCE. ⭐⭐
Misc Hidden Path Analyse a JavaScript file to find a backdoor using invisible characters and use the backdoor for RCE ⭐⭐
Misc Locked Away Simple PyJail, clearing blacklist ⭐⭐
Misc Super-Duper Pwn vm2 bypass js bot ⭐⭐
Misc Prison Pipeline SSRF exfiltrate private NPM registry token, RCE via supply-chain attack ⭐⭐⭐
Misc Zephyr git and sqlite recon ⭐⭐⭐
Pwn Regularity ret2reg to run custom shellcode
Pwn Abyss Abusing lack of null-byte termination ⭐⭐
Pwn No Gadgets Buffer overflow with missing gadgets, complicating leaking and exploitation ⭐⭐
Pwn Insidious Cache side-channel attack to leak flag location ⭐⭐⭐
Pwn Pyrrhus V8 UAF ⭐⭐⭐⭐
Web Jailbreak XXE
Web Blueprint Heist wkhtmltopdf exploit -> LFI -> GraphQL SQLi -> regex bypass -> RCE ⭐⭐⭐
Web HTB Proxy DNS re-binding => HTTP smuggling => command injection ⭐⭐⭐
Web Magicom register_argc_argv manipulation -> DOMXPath PHAR deserialization -> config injection -> command injection ⭐⭐⭐
Web OmniWatch CRLF injection -> header injection -> cache poisoning -> CSRF -> LFI + SQLi -> beat JWT protection ⭐⭐⭐⭐
Web SOS or SSO? VueJS XSS -> OpenID IdP manipulation -> SQLi ⭐⭐⭐⭐

business-ctf-2024's People

Contributors

makelariss avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.