Writeups
82 CTF writeups across FlagYard, HTB. Categories: blockchain, coding, crypto, forensics, machine, misc, mobile, osint, pwn, rev, web.
Off-Ledger
FlagYardforensicsMediumPCAP of a gateway bleeding via Heartbleed against vault-internal.corp.local. Recover the RSA private key from fragmented PEM material in the leak (factor n from recovered d), de…
Mythical
HTBmachineMediumAssumed-breach mini pro lab with Mythic Apollo on DC01. KeePass backup via rsync yields domjoin; ADCS ESC4→ESC1 produces DA. Forest trust into mythical-eu leads to MSSQL trustwo…
PhantomRing
HTBforensicsVery EasyStatic analysis of a Linux post-exploitation agent using iouring (liburing) for C2 I/O to evade syscall-based EDR. Zip password hacktheblue.
phone book
FlagYardpwnMediumFlagYard PWN medium (150 pts). glibc 2.27 contacts menu with an 8-operation budget, mallocusablesize overflow into the next chunk header, UAF, and signed OOB index. Solved with …
Puppet
HTBmachineMediumHTB/VulnLab mini pro-lab: internal Sliver multiplayer C2, Windows FILE01 foothold → PrintNightmare/UAC SYSTEM → LSA secret for Puppet service account → DC it share SSH key → PM0…
Cobblestone
HTBmachineInsaneFree Insane Linux machine (id 691, maker c1sc0). Web stack is a Minecraft-themed multi-vhost PHP/MySQL site; foothold user is cobble (rbash). Root is Cobbler 3.3.6 XML-RPC auth …
Garfield
HTBmachineHardj.arbuckle → writable SYSVOL scripts + scriptPath on Liz Wilson
Resizer
HTBwebHardHard HTB web challenge: a Flask image resizer with an unsanitized multipart filename. The blacklist only rejects .py/.pyc substrings and refuses to overwrite existing files. The…
TwoMillion
HTBmachineEasyEasy free/retired Linux. Invite API → register → mass-assign admin → VPN generate command injection → .env reuse → CVE-2023-0386 OverlayFS/FUSE root.
Hercules
HTBmachineInsaneInsane Windows AD box (id 778, maker birkk). Chain: LDAP injection on HTTPS portal → description password spray → ASP.NET machineKey path traversal → FormsAuth cookie forge → Ba…
CCTV
HTBmachineEasy1. cctv.htb → Zoneminder /zm — default admin:admin
DevHub
HTBmachineMediumMCPJam Inspector on :6274 allows unauth RCE via CVE-2026-23744 (POST /api/mcp/connect with serverConfig.command). Shell as mcp-dev. Local JupyterLab token is in process cmdline …
Fireflow
HTBmachineMediumDownloaded successfully (free machine has walkthrough access):
Helix
HTBmachineMediumApache NiFi 1.21 on flow.helix.htb allows anonymous write on the REST API. From there:
Kobold
HTBmachineEasyEasy free Linux box. External RCE via MCPJam Inspector CVE-2026-23744 on mcp.kobold.htb, shell as ben. Privilege escalation via docker group membership hidden in /etc/gshadow + …
MakeSense
HTBmachineMediumWordPress agency site with client-side Whisper/AI pipeline. Hardcoded AES-GCM key lets an attacker forge encrypted transcriptions containing XSS; admin bot (walter) views them →…
Nexus
HTBmachineEasy1. Hosts: nexus.htb, git.nexus.htb, billing.nexus.htb
Orion
HTBmachineEasy1. CraftCMS 5.6.16 on http://orion.htb — footer version leak; /admin/login
SmartHire
HTBmachineMediumFlask hiring/ML app registers sklearn models to MLflow (models.smarthire.htb, Basic admin:password). Overwrite pythonmodel.pkl artifact after training (pickle RCE) → code exec a…
celestial order
FlagYardcryptoMediumModified Ed25519: SHA-512 replaced by four concatenated MD5 digests, and nonce hash is H(m || sksuffix) (message prefix). An MD5 collision pair gives identical nonces (same R) f…
CloudyHeist
FlagYardforensicsMediumHIPAA client incident image: AnyDesk remote access exfiltrated stage.zip; recovered staged payload from CloudStore/data (ZIP), Base64 note → XOR 0x11 → flag.
Connected
HTBmachineEasyEasy Linux box running FreePBX 16.0.40.7. Unauthenticated SQLi (CVE-2025-57819) in the Endpoint module yields RCE as asterisk. Privilege escalation abuses root sysadminmanager h…
Convergent Cipher
FlagYardcryptoMediumCustom 6-byte block cipher: each 3-byte half is XORed with a key half, inverted in GF(P) with P = 2^24+43, then XORed with SHA256(key):6. Two chosen plaintexts cancel the final …
CU29
FlagYardcryptoMediumRSA-1024 with public exponent e=23 forced to share a factor with φ(n) (so 23 | p−1 or q−1), a small private-related value ee, and a leak (p+q)>>200. Factor via Howgrave–Graham C…
Enigma
HTBmachineEasyEasy Linux box. NFS share leaks webmail creds → Roundcube as kevin/sarah → OpenSTAManager admin password in sarah’s mail → CVE-2025-69212 P7M command injection as www-data → cra…
FastRsa
FlagYardcryptoEasyInteractive RSA challenge: 14 timed rounds print n, m^3 mod n, and (m+1)^3 mod n. Recover m each round with Franklin-Reiter (related messages, e=3, difference 1). After all roun…
FindTheLeak
FlagYardforensicsMediumNTFS-only forensics: recover an attacker staging directory name from $MFT/$J after a short-lived exfil.7z, then decode the directory name (Base64 → Base32) to the flag.
fs
FlagYardpwnHardHard heap note challenge on glibc 2.31 built without tcache. UAF (free without nulling content) plus edit/view length derived from the chunk size field enable an off-by-one size…
HeapYard
FlagYardpwnMediumNote-style heap menu (malloc 0x10 × 4 slots) with UAF: free does not null the pointer. Tcache poison (glibc 2.39 safe-linking) allocates over the global ptr array, hijacks slots…
Klay
FlagYardforensicsHardWindows 10 crash-dump forensics. Suspicious winint.exe (C:\temp\winint.exe) appears to be injector malware (Cobalt Strike–related Defender hits in dump). Process dump of PID 467…
locker
FlagYardrevMediumNo remote instance; pure offline reverse + decrypt.
lunatic
FlagYardrevHardCustom Lua 5.4 interpreter ((((LUnAtic 1.0)))) based on commit c33b1728... with a backdoored luaVequalobj for length-32 tables. The script mutates both tables through 0x1336 equ…
MEfactory
FlagYardforensicsHardSPI flash dump of a synthetic Intel ME-style image. The factory provisioning secret is AES-128-CBC ciphertext stored in a custom ME page; the real 16-byte key lives in another p…
Normal El-Gamal
FlagYardcryptoHardElliptic-curve ElGamal with encrypt/decrypt oracles. Curve parameters are secret, but many curve points leak from ciphertexts and decryption results. Recover p,a,b via GCDs of W…
Paperwork
HTBmachineEasy1. LPD RCE (lp): Port 1515 implements RFC 1179. Control-file job name (J) is concatenated into shell=True → inject ; cmd #. Downloadable server.py documents the sink.
Quadratic CRT
FlagYardcryptoMediumFlag is encoded as x = f·√(-7) in the ring Z√(-7) and reduced modulo two random elements m1, m2. Congruences x ≡ yi (mod mi) expand to a pair of integer CRTs on f, solved with s…
Reactor
HTBmachineEasy1. CVE-2025-55182 (React2Shell) unauthenticated RCE on Next.js 15.0.3 / React 19.0.0 → shell as node
Reader
FlagYardpwnEasyEasy PIE binary with an intentional file-reader and a stack buffer overflow. The path filter blocks any path containing flag, so leak libc via /proc/self/maps, then ret2libc for…
Real Number Generator
FlagYardcryptoHard48-bit seed feeds a Decimal LCG-like map state = (e·state) mod π, then sqrt(|sin+cos|) packed as IEEE-754 doubles for a keystream. Known plaintext The flag is: recovers the fir…
Recon101
FlagYardforensicsHardPCAP of a LAN with ZeroTier noise plus two external TCP sources. The real recon is a 1 Hz SYN-retransmit sweep of port 1433 (MSSQL) from 134.119.216.167 across 32 hosts. Each co…
RegReflector
FlagYardforensicsHardEmployee ran a fake Chrome installer; artifacts include Windows registry hives and user profile data. Hint: comeflywithme / XOR with 0x1f.
Roasted Vault
FlagYardforensicsHardPCAP of AS-REP roasting against CORP.LOCAL service accounts. Crackable passwords are built from wiki AD password-policy templates + LDAP attributes. Decrypted vault-sync AES-GCM…
Silentium
HTBmachineEasy1. Vhost staging.silentium.htb → Flowise 3.0.5
SM
FlagYardforensicsMediumMemory dump after Office social-engineering: malicious Word macro splits the flag into two VirtualAlloc buffers (FlagY{ + MD5 + }). Reconstruct by carving VBA source (or both re…
Sole of ROP
FlagYardpwnEasyTiny static ELF: buffer overflow, NX on, only pop rax; ret and syscall gadgets plus embedded /bin/dash. Challenge text hints at signals → SROP (sigreturn-oriented programming) t…
Unstable
FlagYardcryptoMedium1. Connect to instance; collect n1, ct1, ct2, n2, ct3, ct4.
verifiable delay
FlagYardcryptoMediumWesolowski-style VDF over an RSA modulus. The server computes y = g^(2^(2^256)) mod n with the trapdoor phi(n) and asks for a different claim h plus a Fiat–Shamir Wesolowski pro…
Winter is coming
FlagYardrevHard32-bit ELF password checker that mmaps seven XOR-encrypted shellcode stages and runs each against a slice of the 39-byte input. Recover each stage's transform, invert it, then r…
ZoomHeist
FlagYardforensicsMediumWindows user-profile triage of a Zoom malvertising victim. Firefox history shows a visit to a GitHub Pages clone (flagyardctf.github.io) that spoofed Zoom; the fake site’s flag.…
Fishy HTTP
HTBforensicsEasyC2 over HTTP where commands are smuggled in HTML structure (tag-to-hex mapping → binary) and command output is returned as base64 encoded via first-letter-of-word encoding in PO…
Partial Encryption
HTBrevEasyWindows x64 PE that stores multiple shellcode blobs in .data, each encrypted with a partial AES (AESKEYGENASSIST + AESDECLAST only) keyed by the 16-byte broadcast of the block i…
TrueSecrets
HTBforensicsEasyWindows 7 memory dump of an APT-related investigation. A TrueCrypt container (development.tc) holds C2 agent source and DES-encrypted session logs. The TrueCrypt passphrase is r…
Honor Among Thieves
HTBblockchaineasyThe challenge contract stores the encrypted flag and hash in private storage, but the real leak is the public blockchain history. Rival transactions already called talk(bytes32)…
Token to Wonderland
HTBblockchaineasyThe custom ERC20-like SilverCoin contract was compiled for Solidity ^0.7.0, where integer arithmetic does not automatically revert on underflow. Its transfer() path checked from…
Baby Time Capsule
HTBcryptoVery EasyRSA with exponent e=5 and the same plaintext encrypted under 5 different moduli. Solved via Hastad's broadcast attack (CRT + integer 5th root).
Behind the Scenes
HTBrevA "Very Easy" reverse engineering challenge where the binary uses ud2 (undefined opcode) instructions with a SIGILL signal handler as an anti-decompilation trick. The password i…
Ether Tag
HTBmiscVery EasyAn ICS/SCADA challenge where we connected to an EtherNet/IP controller and read the value of the "FLAG" tag to retrieve the flag.
Flagportation
HTBwebVery EasyThe flag is transmitted via quantum teleportation through a QuTiP-based terminal (QTT). By applying the standard Bob-side correction gates based on Alice's measurement results, …
Global Hyperlink Zone
HTBwebVery EasyA Qiskit-based quantum circuit challenge where you must construct a 5-qubit gate sequence that produces specific measurement correlations across qubits to "initialize the hyperl…
Lucky Dice
HTBmiscVery EasyA speed-based dice game where we had to compute the round winner (highest dice sum) for 100 rounds with only 0.3 seconds to answer each round. Solved by pre-computing the winner…
Magical Palindrome
HTBwebVery EasyA Hono/Node.js web app that asks for a palindrome string of at least 1000 characters. A nginx clientmaxbodysize of 75 bytes prevents sending a long string directly. The vulnerab…
RSAisEasy
HTBcryptoEasyRSA challenge with two moduli sharing a common prime q, and a leaked linear combination that reveals the shared factor via GCD.
Simple Encryptor
HTBrevVery EasyA ransomware-style challenge where a custom encryptor binary encrypts a flag file using srand(time(NULL)) seeded PRNG. The seed is written to the output file, making decryption …
Social Media Investigation Hub
HTBosintVery EasyA cross-platform OSINT investigation into the TechReviewer2024 account across three simulated social media platforms (ChirpNet, ConnectPro, ForumHub). The investigation reveals …
The Last Dance
HTBcryptoVery EasyA stream-cipher keystream reuse attack. The challenge encrypts both a known message and the FLAG with the same ChaCha20 key+nonce, allowing the FLAG to be recovered by XORing th…
The Puppet Master
HTBosintVery EasyA progressive OSINT web quiz that challenges the investigator to identify a military vehicle shown in a banner image on the NZDF (New Zealand Defence Force) website, then answer…
The Suspicious Domain
HTBosintVery EasyWHOIS investigation of the domain alexmorgan-reviews.net — linked to the TechReviewer2024 / Alex Morgan fake review operation from the previous challenge. The domain was registe…
Chaogen
HTBcodinghardA multi-quadrant cellular automaton challenge. A square N×N petri dish (N multiple of 4) is divided into 4 equal quadrants, each governed by one of four unknown rule-sets in B/S…
FlagCommand
HTBmiscA web-based terminal adventure game ("Dimensional Escape Quest") hides a secret command in its API. Reading the JavaScript source reveals a /api/options endpoint that returns al…
Like a Glove
HTBmisceasyWord analogy puzzle using GloVe Twitter 25-dimensional embeddings. Each line is "Like A is to B, C is to ?", encoding a standard word analogy A:B :: C:D. The formula vec(D) ≈ ve…
PINsmith
HTBcodingeasyA coding challenge where we must generate all possible PIN combinations matching a known partial pattern, respecting a "no adjacent repeats" policy. The pattern contains known d…
Uplink
HTBcodinginsaneA tree DP problem involving minimizing the time to transfer data from each node to the root. Each node can "jump" directly to any ancestor (not just the parent), and each jump c…
LMAy
FlagYardwebeasyA "Docker Compose validator" web app parsed user-supplied YAML with yaml.load using an unsafe loader (FullLoader/UnsafeLoader) instead of yaml.safeload. This allows !!python/obj…
nooter
FlagYardwebeasyA Flask note-taking app has a SQL injection in the INSERT statement used to save notes. The backend formats the query as a Python string (VALUES(?,'%s') % note) before executing…
OhMyPatch
FlagYardwebeasyA Flask user-management app exposes a JSON Patch endpoint (PATCH /patch) that applies user-supplied operations to the users list and persists the result. The endpoint is also re…
SecureArchive
FlagYardwebeasyA PHP archive storage app has a "View File" feature backed by include($GET'file'). It also stores uploaded archives as hash-named files under uploads/. The server has an openbas…
TechShop
FlagYardwebeasyA shop app leaked two "admin only" endpoints in an HTML comment, neither of which enforced authorization. Editing a product description (broken access control) plus a Jinja2 ser…
Arno
FlagYardmobileUnity IL2CPP Android game reverse engineering challenge from FlagYard. The APK com.Z4ki.Arno is a Unity-based Android game with native IL2CPP code.
Logger
FlagYardpwnHeap exploitation challenge on FlagYard (tcp.flagyard.com:14808). The binary has a logger service with write/tofile/delete/print operations. Uses a patched binary with pwntools …
Baby Frame
HTBmiscA recently recovered experimental spacecraft broadcasting under spacecraft ID 12 has entered visibility range. Ground telemetry suggests that one onboard diagnostic application …
Crypto CTF
FlagYardcryptoThe server provides three operations on a fresh 1024-bit RSA key per connection:
NOSJ
FlagYardwebNOSJ is an e-commerce challenge with two roles: Seller (can generate buyer invitations) and Buyer (needs a valid invitation to open the store and get the flag). Sellers must be …