>/Categories $


Learn With Me - Public-key Cryptography

The Discrete Logarithm Problem Now that you understand modular arithmetic, we can move on to its applications. In the previous post, we discussed how to perform modular computations. Now, it's time to learn how these computations are used in cryptography. Calculating the remainder in an equation...

Learn With Me - Modular Arithmetics

What is Modular Arithmetic? Usually, when you want to perform division, you do something like: $$ \frac{3}{5} = 1,(6) \Rightarrow 1\frac{2}{3} $$ But there are some cases when you only need the remainder. $$ \frac{\text{Dividend}}{\text{Divisor}} = \text{Quotient} + \text{Remainder} $$ Where...


Side Channel Attacks - Basics

What is that? Have you ever heard of a side-channel attack? Maybe not, but you might have heard of the "Pentagon Pizza Index." The idea is somewhat similar. A side-channel attack allows you to gather information indirectly by observing correlated signals rather than the target data itself, just...

How To Sign Up And Login

Requirements To create an account, you'll need the Authenticator app or any other that supports TOTP (time-based one-time passwords), since I don't want to store this kind of information in my database. :) What's next? Once you have it, go to the sign-up page and check if the nickname you want...


Mw302r - Security Research - My First Cve

Router research Apart from participating in CTFs, in the meantime I wanted to practise my other hands-on skills and try to work on some real devices. In order to do that I visited a local electronics store and bought the cheapest device I could find. In this case it was router MW302R shown in the...

Sword Of Secrets - 0x3 Postern

Third task - Postern Now it's time for the 3rd task, and this one was much more challenging than the previous one. From the previous task, we learned that the data for this challenge is located at memory address 0x30000, and just like in both previous tasks we also get an error message displayed. ...


Ones-and-zeros

What is this task even about? I started this challenge by taking a look at Discord, as part of my team had already begun working on it. My first glance at the provided charts led me to think -> 2 charts are probably UART or I2C to be decoded. Identifying protocol A quick look at the provided...

Talking-printer

Who called this 'guessy'? This task wasn't very 'guessy' for me because as soon as I opened the included audio recording, I recognized those distinctive sounds. Not long ago, a clip titled "Two AI Agents Start Talking in a Different Language with Each Other" was viral online, with news sites...


Re:1 Building An Android Lab For Ctf Competitions

Introduction Quite a few of my posts focus on solving challenges involving reverse engineering of mobile applications from CTF competitions. Although in one of my previous posts I briefly described how to approach this topic, I'd like to cover it more extensively here, highlighting particularly...

Brød & Co.

First Part Look at the files After downloading and unzipping the archive there’s only one APK inside, so I launched it on an Android emulator and also opened the APK in JADX-GUI for static analysis. Not much to see in the UI at first glance. There’s a discount code field that’s likely the...


Kashi2024 Catseabank

Let's play Ok, so we run the provided game and see some NPC. Let's talk to him: Oh, looks like he won't talk to us unless we pay him. Luckily, there was a bank next to him—great! Unfortunately, this bank has only 1000 cash, but it's not a problem as long as we are hackers... ...

1337up Live 2024 Phish Market Order Management

First Part Look at the files │>PHISH_MARKET │ docker-compose.yml │ start.sh │ ├───market │ Dockerfile │ market │ wait-for-it.sh │ └───mysql Dockerfile init-db.sql As you may have noticed, there are 2 Docker containers: one with a MySQL database and another...


Web

Session Slip

Session Slip Over the past weekend I was casually playing some CTFs. This time I participated in Athena CTF and tried to solve a few of the Web challenges. One of them was labeled medium, though in my opinion it sat closer to easy, but it chains three distinct bugs, so the label is defensible....

Database Reincursion

First Part Recon To be honest we don't have much to see there. It's simple login form shown on the screenshot below: And we don't have any credentials attached to this task so I assumed it's a SQLi kind of a task and tried some basic payloads as input. It turns out this site has...


X