Pwn
- A1 Full Pwn
A Windows DC: SMB null session leaked a password-protected Office doc, cracking it gave CMS creds, a C1 CMS .NET deserialization bug gave RCE, and BloodHound pointed at a …
- Betabuf
A protobuf-based auth scheme defeated in three steps, an over-permissive registration, a length-truncating rename, and a score endpoint used as a parsing oracle.
- Gentleman
A User repr formatted attacker-controlled data twice, so a Python format string injected into the username walked the object graph to RCE.
- Password Protected
A dictionary attack against a raw-socket login prompt that did not land.
- duck-cord
An unbounded read into the number buffer overflowed into the adjacent message buffer, letting me pose as the system user.
- Interpreted Arduino I
The flag prints once at boot, before you attach to the serial console, so rebooting while connected catches it.
- Space Jam
A webshell led through sudo find and a SUID cp to the root flag.
- Offline
An SMBv1 host fell to EternalBlue for SYSTEM, then RDP admin for the king server.
- Hogwarts
SQL injection on two portals gave SSH creds, then sudo date and SUID ip to root.