All Writeups
Comprehensive collection of CTF challenges, solutions, and insights.
Raptor Weekly 6 - 3lectric Igloo - Web
Three flags across a penguin colony web app. Source recon, IDOR enumeration, OS command injection through a diagnostic ping utility, and AES-CBC decryption using keys leaked from the process environment.
Raptor Weekly 2 - ECHELON Web 1 - 1.1 ; OPEN CHANNEL
Chaining HTML comment enumeration to a disallowed robots.txt entry, pivoting through an exposed staging endpoint to recover an operator username, and extracting the portal password from a JSON debug response behind a custom request header.
WHAMazon! Web 4 - The Archives
Chaining prior recon from robots.txt with API endpoint fuzzing and a missing-result anomaly to discover a path traversal vulnerability in an image file server.
WHAMazon! Web 2 - Employee of the Month
Combining GitHub OSINT with API endpoint discovery to find hardcoded admin credentials left in a public seed script.
WHAMazon! Web 1 - The Forgotten Protocol
Leveraging a publicly accessible robots.txt to discover exposed internal API endpoints and retrieve a leaked maintenance key.