JavaScript Sandboxes: Antipattern Review

Because the internet runs on JavaScript, and JavaScript is famously known as a language held together with paper clips and rubber bands, the topic of proper sandboxing and safe JS execution became a pretty popular discussion in the security community. I wanted to explore some small and common gotchas that I’ve seen in recent times regarding JS sandboxes, including and based off of a real-world example I saw at work. ...

Jul 24, 2026 · 2507 words · Vie

DEFCON 33: Retrospective

1 CTF. 2 full days of hacking. 3 teams. 4 victories. When we won last year, our hat-trick, we were the first in DEF CON’S history to do it. 3 consecutive victories, 8x3 (24) black badges awarded in 3 total years. I think it was safe to say that a reputation formed around us and naturally, speculation. PPP and The Duck already had their own reputations so it’s not like the secrets and rumors and awe towards MMM came out of nowhere. However, it’s not like MMM was the only team that did well enough to have a reputation in the CTF community. ...

Aug 11, 2025 · 2594 words · Vie

DEF CON 32 Retrospective, end of the year recap

In 2009, a group students at the Carnegie Mellon University formed a computer security club known as the Plaid Parliament of Pwning, abbreviated to PPP, to participate in Capture the Flag contests. The team saw numerous successes throughout their tenure, and many of the CMU folks with their roots in PPP went on to succeed professionally in cybersecurity-related careers. 2 such members went on to co-create Theori.io, a leading platform of security solutions covering everything from security education to audits and consulting. Their presence exists in both South Korea and USA, and they have their own CTF team, The Duck, that dominates leaderboards whenever they play. ...

Dec 29, 2024 · 4242 words · Vie

DUCTF 2024: Prisoner Processor

DUCTF 2024 has concluded this summer, and I decided to take a look at it with Maple Bacon and solve a few challenges. This is specifically a writeup for “Prisoner-Processor”, the hardest web challenge available. My teammate Angus and I solved this together. It was a great challenge and ventured into alot of interesting things about Bun and TypeScript, so kudos to the authors for making such an interesting challenge! ...

Jul 7, 2024 · 2263 words · Vie

A case for documentation

I am aware that the main target audience of my tiny blog are CTF players looking for my writeups and other like-minded security researchers exploring topics I like. But my 2024 resolution was to relive and unite my artistic persona that I spent most of my teen years curating, and marrying that to the security career life I live now. Part of my fine arts training involved a good deal of literature. I wanted to write some random stuff really badly, and this post came out of that desire, I understand it’s out of left field especially given the content of my other work here. If people like this I’d be happy to intersperse more of this into my usual stuff of writeups and security research. ...

Jan 6, 2024 · 1648 words · Vie

MAPLECTF 2023: JUJUTSU KAISEN

MapleCTF’s 2nd annual CTF was held at the same time as Hackceler8 preparation week, so for a brief couple of days in Japan I was busy helping organize 2 ctfs at once, which I don’t recommend. This year, I decided to spice things up with my chals, my vie chals, by incorporating a fun prize for whichever team manages to solve all of my challenges.I had 3 challenges: JaVieScript, Blade Runner, and Jujutsu Kaisen. The first 2 I won’t detail writeups as they’re beginner-friendly and there already exist plenty of writeups for them. The latter one I will detail an author writeup for. ...

Oct 10, 2023 · 2490 words · Vie

DEFCON 31: Retrospective

Beginning Back in October of 2019, I was attending my 3rd/4th? year at UBC, where I tried to play in a beginner-friendly CTF known as “CSAW 2019” with UBC’s team: Maple Bacon. Particularly, I tried out a challenge called Unagi, which, having spent an eternity on, I managed to solve after hours of wrangling with the problem. To be completely frank, I solved the challenge after googling “XML vulnerability” and trying out payloads - really, just, throwing payloads and modifying them to tailor the challenge - until one stuck and I got the flag. I was happy, but I also thought, “what the hell did I achieve? what did the payload do? What did I learn?” and I couldn’t come up with an answer I was satisfied with. I really just googled information about XML vulenrabilities, found an XXE payload, and threw it hoping to see if something would change (I didn’t even know what XXE stood for). Granted, I still needed to modify the payload. Unagi required more effort than just a copy-paste. But overall, my first experience was largely juvenile and I was still as naive as I was pre CSAW 2019. ...

Aug 31, 2023 · 2001 words · Vie

PBCTF 2023 : JAZZY x VIE CHALS

I was a guest challenge writer for perfect blue’s CTF held mid February. We play-tested each others chals :P MAKIMA Challenge Description Makima simps check in here I’m actually a Power stan. I just needed an excuse for people to look at my Makima drawing. TL;DR Hide php in image, making a PHP/image polyglot X-Accel-Header redirection through CDN to reach internal .php files and access /uploads/your_img.png/lol.php to execute PHP The important parts The default.conf, which is the config used for the nginx proxy server, has an RCE vulnerability: ...

Feb 21, 2023 · 1936 words · Vie

MapleCTF 2022 : Vie's challenges

MapleCTF 2022 ran this year to great success, which is fantastic given the tight timeframe we were operating on shortly after coming back from DEFCON 30. We held a beginner-friendly, UBC-local version back in January, so our endgame for this version was to make more creative and harder challenges that people hopefully enjoyed. I wrote 3 web challenges for this CTF: honksay, Viene Library and Art Gallery, the latter 2 I will detail here. I hope you enjoyed them if you played! ...

Sep 1, 2022 · 2260 words · Vie

DEFCON 30: Retrospective

Man. My team, Maple Bacon, collaborated with CMU’s CTF team PPP and Theori.io’s CTF team The Duck, forming Maple Mallard Magistrates as a merger to participate in DEF CON finals. The Beginning Discussions about the merge had occurred earlier in the year - I triangulate it to a month or so before I found myself in Athens, Greece attending ICC. This is important to mention as I heard many people speculate about the existence of MMM and whether or not it was formed as a response to something. The answer is no, the reasoning was very simple: we wanted to play together! Unfortunately, there wasn’t much of a complex reason, we simply had a desire to team up and have fun in Vegas. ...

Aug 16, 2022 · 2361 words · Vie