MAPLECTF 2023: JUJUTSU KAISEN

MapleCTF’s 2nd annual CTF was held at the same time as Hackceler8 preparation week, so for a brief couple of days in Japan I was busy helping organize 2 ctfs at once, which I don’t recommend. This year, I decided to spice things up with my chals, my vie chals, by incorporating a fun prize for whichever team manages to solve all of my challenges.I had 3 challenges: JaVieScript, Blade Runner, and Jujutsu Kaisen. The first 2 I won’t detail writeups as they’re beginner-friendly and there already exist plenty of writeups for them. The latter one I will detail an author writeup for. ...

Oct 10, 2023 · 2490 words · Vie

PBCTF 2023 : JAZZY x VIE CHALS

I was a guest challenge writer for perfect blue’s CTF held mid February. We play-tested each others chals :P MAKIMA Challenge Description Makima simps check in here I’m actually a Power stan. I just needed an excuse for people to look at my Makima drawing. TL;DR Hide php in image, making a PHP/image polyglot X-Accel-Header redirection through CDN to reach internal .php files and access /uploads/your_img.png/lol.php to execute PHP The important parts The default.conf, which is the config used for the nginx proxy server, has an RCE vulnerability: ...

Feb 21, 2023 · 1936 words · Vie

ASIS Quals 2021: Lovely Nonce

Lovely Nonces is a challenge from ASIS Quals 2021, involving interesting CSP bypasses and stylesheet leaks. My teammate Ming and I solved this challenge together, and a copy of the writeup (with the index.html file used in the exploit) can be found in the UBC CTF blog. TL;DR CSS attribute selectors for a stylesheet leak of the CSP nonce combined with XSS. Recon The CSP is implemented via a meta-tag in the DOM, and not through response header as is usually the common practise. It’s just one directive, script-src, with the randomly generated nonce value, which we can try to retrieve. ...

Oct 24, 2021 · 785 words · Vie