<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PicoCTF on an's security blog</title><link>https://panman4040.github.io/tags/picoctf/</link><description>Recent content in PicoCTF on an's security blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 03 Jun 2026 17:11:11 +0700</lastBuildDate><atom:link href="https://panman4040.github.io/tags/picoctf/index.xml" rel="self" type="application/rss+xml"/><item><title>Irish-Name-Repo 2</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/irish-name2/</link><pubDate>Wed, 03 Jun 2026 17:10:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/irish-name2/</guid><description>&lt;p>This is similar to Irish-Name-Repo 1, but with a filter active. Through trials and errors we &lt;em>can&lt;/em> deduce that the filter actively blocks common SQL injection terms like &lt;code>UNION&lt;/code> or &lt;code>OR&lt;/code>.&lt;/p>
&lt;p>To bypass this we can just apply the payload &lt;code>admin'--&lt;/code> into the username form. Not only will it skip the password verification but also avoid using those filtered terms.&lt;/p></description></item><item><title>PicoCTF</title><link>https://panman4040.github.io/training/picoctf/</link><pubDate>Wed, 03 Jun 2026 17:10:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/</guid><description/></item><item><title>Web Exploitation</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/</link><pubDate>Wed, 03 Jun 2026 17:10:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/</guid><description/></item><item><title>Irish-Name-Repo 1</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/irish-name1/</link><pubDate>Wed, 03 Jun 2026 16:39:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/irish-name1/</guid><description>&lt;p>Firstly, it&amp;rsquo;s good practice to purposely input trash values into the form. In this case we will be trying &lt;code>'&lt;/code> for username
&lt;img src="https://panman4040.github.io/images/bc7b054e-bf90-4ab8-89b7-573a1d698f45.jpg" alt="">
We can see that the users are kept in a SQLite3 database, and all our input are passed into the query without validation.&lt;/p>
&lt;p>Thus we try the good old payload &lt;code>' OR 1=1--&lt;/code>, which will bypass the password check and we will get our flag&lt;/p></description></item><item><title>Power Cookie</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/powercookie/</link><pubDate>Tue, 02 Jun 2026 14:20:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/powercookie/</guid><description>&lt;p>We use Burp Suite to intercept the GET request, change the &lt;code>isAdmin&lt;/code> cookie to True and we&amp;rsquo;ll get our flag:
&lt;img src="https://panman4040.github.io/images/powercookie.jpg" alt="">&lt;/p></description></item><item><title>IntroToBurp</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/introtoburp/</link><pubDate>Tue, 02 Jun 2026 14:06:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/introtoburp/</guid><description>&lt;p>This is a simple webpage asking for credentials, then an OTP:
&lt;img src="https://panman4040.github.io/images/introtoburp1.jpg" alt="">
If we delete the &lt;code>otp&lt;/code> parameter entirely before sending the POST request, we can actually &lt;em>bypass&lt;/em> the check, per se:
&lt;img src="https://panman4040.github.io/images/introtoburp2.jpg" alt="">
There we can get our flag. Pretty fun problem.&lt;/p></description></item><item><title>WebDecode</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/webdecode/</link><pubDate>Tue, 02 Jun 2026 11:01:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/webdecode/</guid><description>&lt;p>Upon accessing the source file for about.html, there is a peculiar flag:
&lt;img src="https://panman4040.github.io/images/web-decode.jpg" alt="alt-text">
By trial and error, we can figure out this is Base64 encoded. Decode and we shall get our flag (not gonna lie took an embarassingly long time for this)&lt;/p></description></item><item><title>client-side-again</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/client-side-again/</link><pubDate>Tue, 02 Jun 2026 10:35:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/client-side-again/</guid><description>&lt;p>Upon checking the JS source code, we are greeted with this:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-javascript" data-lang="javascript">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">var&lt;/span> &lt;span style="color:#a6e22e">_0x5a46&lt;/span> &lt;span style="color:#f92672">=&lt;/span> [&lt;span style="color:#e6db74">&amp;#39;daf93}&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;_again_4&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;this&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;Password\x20Verified&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;Incorrect\x20password&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;getElementById&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;value&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;substring&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;picoCTF{&amp;#39;&lt;/span>, &lt;span style="color:#e6db74">&amp;#39;not_this&amp;#39;&lt;/span>];
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>(&lt;span style="color:#66d9ef">function&lt;/span>(&lt;span style="color:#a6e22e">_0x4bd822&lt;/span>, &lt;span style="color:#a6e22e">_0x2bd6f7&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">var&lt;/span> &lt;span style="color:#a6e22e">_0xb4bdb3&lt;/span> &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#66d9ef">function&lt;/span>(&lt;span style="color:#a6e22e">_0x1d68f6&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">while&lt;/span> (&lt;span style="color:#f92672">--&lt;/span>&lt;span style="color:#a6e22e">_0x1d68f6&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">_0x4bd822&lt;/span>[&lt;span style="color:#e6db74">&amp;#39;push&amp;#39;&lt;/span>](&lt;span style="color:#a6e22e">_0x4bd822&lt;/span>[&lt;span style="color:#e6db74">&amp;#39;shift&amp;#39;&lt;/span>]());
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> };
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">_0xb4bdb3&lt;/span>(&lt;span style="color:#f92672">++&lt;/span>&lt;span style="color:#a6e22e">_0x2bd6f7&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}(&lt;span style="color:#a6e22e">_0x5a46&lt;/span>, &lt;span style="color:#ae81ff">0x1b3&lt;/span>));
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">var&lt;/span> &lt;span style="color:#a6e22e">_0x4b5b&lt;/span> &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#66d9ef">function&lt;/span>(&lt;span style="color:#a6e22e">_0x2d8f05&lt;/span>, &lt;span style="color:#a6e22e">_0x4b81bb&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">_0x2d8f05&lt;/span> &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#a6e22e">_0x2d8f05&lt;/span> &lt;span style="color:#f92672">-&lt;/span> &lt;span style="color:#ae81ff">0x0&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">var&lt;/span> &lt;span style="color:#a6e22e">_0x4d74cb&lt;/span> &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#a6e22e">_0x5a46&lt;/span>[&lt;span style="color:#a6e22e">_0x2d8f05&lt;/span>];
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">return&lt;/span> &lt;span style="color:#a6e22e">_0x4d74cb&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>};
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">function&lt;/span> &lt;span style="color:#a6e22e">verify&lt;/span>() {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">checkpass&lt;/span> &lt;span style="color:#f92672">=&lt;/span> document[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x0&amp;#39;&lt;/span>)](&lt;span style="color:#e6db74">&amp;#39;pass&amp;#39;&lt;/span>)[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x1&amp;#39;&lt;/span>)];
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#ae81ff">0x4&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#ae81ff">0x0&lt;/span>, &lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x3&amp;#39;&lt;/span>)) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#ae81ff">0x7&lt;/span>, &lt;span style="color:#ae81ff">0x9&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#e6db74">&amp;#39;{n&amp;#39;&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>, &lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x4&amp;#39;&lt;/span>)) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#ae81ff">0x3&lt;/span>, &lt;span style="color:#ae81ff">0x6&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#e6db74">&amp;#39;oCT&amp;#39;&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x3&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>, &lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x4&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x5&amp;#39;&lt;/span>)) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#e6db74">&amp;#39;substring&amp;#39;&lt;/span>](&lt;span style="color:#ae81ff">0x6&lt;/span>, &lt;span style="color:#ae81ff">0xb&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#e6db74">&amp;#39;F{not&amp;#39;&lt;/span>) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>, &lt;span style="color:#a6e22e">split&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x3&lt;/span> &lt;span style="color:#f92672">*&lt;/span> &lt;span style="color:#ae81ff">0x2&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x6&amp;#39;&lt;/span>)) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#a6e22e">checkpass&lt;/span>[&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x2&amp;#39;&lt;/span>)](&lt;span style="color:#ae81ff">0xc&lt;/span>, &lt;span style="color:#ae81ff">0x10&lt;/span>) &lt;span style="color:#f92672">==&lt;/span> &lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x7&amp;#39;&lt;/span>)) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">alert&lt;/span>(&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x8&amp;#39;&lt;/span>));
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> } &lt;span style="color:#66d9ef">else&lt;/span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#a6e22e">alert&lt;/span>(&lt;span style="color:#a6e22e">_0x4b5b&lt;/span>(&lt;span style="color:#e6db74">&amp;#39;0x9&amp;#39;&lt;/span>));
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>This looks intimidating but it&amp;rsquo;s just simple mapping and obfustication, and can be easily traced. Preferably if I absolutely had to choose client side verification, I would hashed the correct credentials instead (though it can be traced back albeit not as easily)&lt;/p></description></item><item><title>dont-use-client-side</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/dont-use-client-side/</link><pubDate>Tue, 02 Jun 2026 10:23:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/dont-use-client-side/</guid><description>&lt;p>Pretty self-explanatory, upon opening the JS script you will be greeted with this:
&lt;img src="https://panman4040.github.io/images/dont-use-client-side.png" alt="alt text">
You can literally rebuild the flag from here, in plaintext. This goes to show how client-side validations can be easily broken and you should never rely on them.&lt;/p></description></item><item><title>Cookies</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/cookies/</link><pubDate>Thu, 28 May 2026 17:06:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/cookies/</guid><description>&lt;p>Very interesting problem. The cookie is &lt;code>name = &amp;lt;some-integer&amp;gt;&lt;/code> and we are tasked to find out which. On the one hand we can manually type each number in. But on the other hand, we can simply apply a for loop directly in the terminal as follow:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">for&lt;/span> i in &lt;span style="color:#f92672">{&lt;/span>1..50&lt;span style="color:#f92672">}&lt;/span>; &lt;span style="color:#66d9ef">do&lt;/span> curl -s http://wily-courier.picoctf.net:64059/check -b &lt;span style="color:#e6db74">&amp;#34;name=&lt;/span>$i&lt;span style="color:#e6db74">&amp;#34;&lt;/span> | grep picoCTF; &lt;span style="color:#66d9ef">done&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Notice that we use double quotes here instead of single quotes. In Bash, single quotes are &amp;ldquo;strong quotes&amp;rdquo; which is taken as literal, that means the cookies sent if we use those will be literally &lt;code>name=$i&lt;/code> which is not what we want.&lt;/p></description></item><item><title>logon</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/logon/</link><pubDate>Thu, 28 May 2026 16:35:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/logon/</guid><description>&lt;p>If you view the site&amp;rsquo;s Cookies in the developer tool after you&amp;rsquo;ve logged in as anything other than Joe, you&amp;rsquo;ll notice there is a peculiar &amp;lsquo;admin&amp;rsquo; cookie set to False, simply send a request with &amp;lsquo;admin=True&amp;rsquo; then voila we will get the flag.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl -b &lt;span style="color:#e6db74">&amp;#39;admin=True&amp;#39;&lt;/span> http://fickle-tempest.picoctf.net:50274/flag
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div></description></item><item><title>picobrowser</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/picobrowser/</link><pubDate>Thu, 28 May 2026 16:24:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/picobrowser/</guid><description>&lt;p>We are immediately slapped in the face with the picobrowser schtick, so the most logical thing to do is to send an HTTP request with the User-Agent as picobrowser. There we will get our flag.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl -H &lt;span style="color:#e6db74">&amp;#34;User-Agent:picobrowser&amp;#34;&lt;/span> http://fickle-tempest.picoctf.net:51879/flag
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Note that the &lt;code>-H&lt;/code> flag is for general headers.&lt;/p></description></item><item><title>Scavenger Hunt</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/scavenger-hunt/</link><pubDate>Thu, 28 May 2026 16:00:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/scavenger-hunt/</guid><description>&lt;p>First two parts of the flag can be found on the HTML and CSS source file. The third part can be found on &lt;code>robots.txt&lt;/code>. No problems with this.&lt;/p>
&lt;p>In &lt;code>robots.txt&lt;/code> it mentions that the server the web is running on is Apache, which can be verified by sending a simple HTTP request. This &lt;em>strongly&lt;/em> hints at accessing &lt;code>.htaccess&lt;/code> file, which is the common Apache config file. It reveals how the backend of a website is structured, internal IP addresses, and convieniently our fourth part of the flag.&lt;/p></description></item><item><title>Secrets</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/secrets/</link><pubDate>Tue, 19 May 2026 16:01:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/secrets/</guid><description>&lt;p>When first viewed page source, notice that the header references a hidden &lt;code>/secret/assets&lt;/code> folder where &lt;code>index.css&lt;/code> resides. But going to &lt;code>/secret/assets&lt;/code> will greet us with a 301. So the next logical thing to do is to access &lt;code>/secret&lt;/code>, which we can. The following code snippet will apply for all subsequent folder hops, with simple appending.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl &lt;span style="color:#e6db74">&amp;#39;http://saturn.picoctf.net:63724/secret/.&amp;#39;&lt;/span> -v
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Upon viewing the page source, we are once again hinted at the existence of a hidden &lt;code>/hidden&lt;/code> subfolder.&lt;/p></description></item><item><title>GET aHEAD</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/get-ahead/</link><pubDate>Tue, 19 May 2026 15:18:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/get-ahead/</guid><description>&lt;p>This challenge is practically begging you to send a &lt;code>HEAD&lt;/code> request to the server. &lt;code>HEAD&lt;/code> is essentially the same as &lt;code>GET&lt;/code> but the server only sends back the HTTP Headers and drops the body (the HTML, image, video, etc).&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>curl -I &lt;span style="color:#e6db74">&amp;#39;http://wily-courier.picoctf.net:56339/index.php&amp;#39;&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Our flag will appear in the HTTP header.&lt;/p></description></item><item><title>Forbidden Paths</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/forbidden-paths/</link><pubDate>Tue, 19 May 2026 15:02:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/forbidden-paths/</guid><description>&lt;p>I struggled quite a bit at first, but notice that they forbid &lt;strong>absolute&lt;/strong> file path. Meaning we can just use the relative file path to travel up the directories and get our flag.&lt;/p>
&lt;p>Simply input &lt;code>../../../../flag.txt&lt;/code> into the form box to get the flag. Quite nice.&lt;/p></description></item><item><title>Roboto Sans</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/roboto-sans/</link><pubDate>Tue, 19 May 2026 14:22:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/roboto-sans/</guid><description>&lt;p>Upon opening up &lt;code>robots.txt&lt;/code>, we are greeted with this:&lt;/p>
&lt;pre tabindex="0">&lt;code>User-agent *
Disallow: /cgi-bin/
Think you have seen your flag or want to keep looking.

ZmxhZzEudHh0;anMvbXlmaW
anMvbXlmaWxlLnR4dA==
svssshjweuiwl;oiho.bsvdaslejg
Disallow: /wp-admin/
&lt;/code>&lt;/pre>&lt;p>Access either &lt;code>/cgi-bin&lt;/code> or &lt;code>/wp-admin&lt;/code> will result in 404, so clearly it isn&amp;rsquo;t the way.&lt;/p>
&lt;p>Instead, the 6th line &lt;code>anMvbXlmaWxlLnR4dA==&lt;/code> has two trailing equal signs, hinting at base64 encoding.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>echo &lt;span style="color:#e6db74">&amp;#34;SGVsbG8gV29ybGQ=&amp;#34;&lt;/span> | base64 -d
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Upon decoding that line, we will get &lt;code>js/myfile.txt&lt;/code> which is where our flag is. Quite fun problem.&lt;/p></description></item><item><title>where are the robots</title><link>https://panman4040.github.io/training/picoctf/web_exploitation/where-are-the-robots/</link><pubDate>Tue, 19 May 2026 14:15:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/web_exploitation/where-are-the-robots/</guid><description>&lt;p>At first I kept focusing on the main site without noticing that the name of the problem hints at the &lt;code>robots.txt&lt;/code> file itself.&lt;/p>
&lt;p>Simply access &lt;code>robots.txt&lt;/code> and it will show you this:&lt;/p>
&lt;pre tabindex="0">&lt;code>User-agent: *
Disallow: /cc6b1.html
&lt;/code>&lt;/pre>&lt;p>Go to the disallowed path and you&amp;rsquo;ll get the flag&lt;/p></description></item><item><title>rotation</title><link>https://panman4040.github.io/training/picoctf/cryptography/rotation/</link><pubDate>Mon, 04 May 2026 21:50:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/cryptography/rotation/</guid><description>&lt;p>First, calculate the shift amount. Then for each alphabetical character in the ciphertext, subtract that shift amount with the current character, rotate back to z/Z if went overboard&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>cipher &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#e6db74">&amp;#34;xqkwKBN&lt;/span>&lt;span style="color:#e6db74">{z0bib1wv_l3kzgxb3l_555957n3}&lt;/span>&lt;span style="color:#e6db74">&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>diff &lt;span style="color:#f92672">=&lt;/span> ord(cipher[&lt;span style="color:#ae81ff">0&lt;/span>]) &lt;span style="color:#f92672">-&lt;/span> ord(&lt;span style="color:#e6db74">&amp;#39;p&amp;#39;&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>plain &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#e6db74">&amp;#34;&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">for&lt;/span> c &lt;span style="color:#f92672">in&lt;/span> cipher:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> ch &lt;span style="color:#f92672">=&lt;/span> ord(c) &lt;span style="color:#f92672">-&lt;/span> diff
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> c&lt;span style="color:#f92672">.&lt;/span>islower():
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> chr(ch)&lt;span style="color:#f92672">.&lt;/span>islower():
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(ch)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">else&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(ch &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">26&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">elif&lt;/span> c&lt;span style="color:#f92672">.&lt;/span>isupper():
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> chr(ch)&lt;span style="color:#f92672">.&lt;/span>isupper():
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(ch)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">else&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(ch &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">26&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">else&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> c
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(plain) 
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Note that this Python implemention is not exactly the prettiest in the world. And I struggled quite a bit because I thought digits are also rotated (its not lol)&lt;/p></description></item><item><title>basic-mod2</title><link>https://panman4040.github.io/training/picoctf/cryptography/basic-mod2/</link><pubDate>Mon, 04 May 2026 21:36:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/cryptography/basic-mod2/</guid><description>&lt;p>Take each number mod 41 and find its modular inverse using Fermat&amp;rsquo;s little theorem, then map it to the following character set: 1-26 is the alphabet (uppercase), 27-36 are the decimal digits, else an underscore.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>cipher &lt;span style="color:#f92672">=&lt;/span> [&lt;span style="color:#ae81ff">432&lt;/span>, &lt;span style="color:#ae81ff">331&lt;/span>, &lt;span style="color:#ae81ff">192&lt;/span>, &lt;span style="color:#ae81ff">108&lt;/span>, &lt;span style="color:#ae81ff">180&lt;/span>, &lt;span style="color:#ae81ff">50&lt;/span>, &lt;span style="color:#ae81ff">231&lt;/span>, &lt;span style="color:#ae81ff">188&lt;/span>, &lt;span style="color:#ae81ff">105&lt;/span>, &lt;span style="color:#ae81ff">51&lt;/span>, &lt;span style="color:#ae81ff">364&lt;/span>, &lt;span style="color:#ae81ff">168&lt;/span>, &lt;span style="color:#ae81ff">344&lt;/span>, &lt;span style="color:#ae81ff">195&lt;/span>, &lt;span style="color:#ae81ff">297&lt;/span>, &lt;span style="color:#ae81ff">342&lt;/span>, &lt;span style="color:#ae81ff">292&lt;/span>, &lt;span style="color:#ae81ff">198&lt;/span>, &lt;span style="color:#ae81ff">448&lt;/span>, &lt;span style="color:#ae81ff">62&lt;/span>, &lt;span style="color:#ae81ff">236&lt;/span>, &lt;span style="color:#ae81ff">342&lt;/span>, &lt;span style="color:#ae81ff">63&lt;/span>]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>plain &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#e6db74">&amp;#34;&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">for&lt;/span> n &lt;span style="color:#f92672">in&lt;/span> cipher:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> n &lt;span style="color:#f92672">=&lt;/span> n &lt;span style="color:#f92672">%&lt;/span> &lt;span style="color:#ae81ff">41&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> n &lt;span style="color:#f92672">=&lt;/span> pow(n, &lt;span style="color:#ae81ff">41&lt;/span> &lt;span style="color:#f92672">-&lt;/span> &lt;span style="color:#ae81ff">2&lt;/span>, &lt;span style="color:#ae81ff">41&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> &lt;span style="color:#ae81ff">1&lt;/span> &lt;span style="color:#f92672">&amp;lt;=&lt;/span> n &lt;span style="color:#f92672">&amp;lt;=&lt;/span> &lt;span style="color:#ae81ff">26&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(n &lt;span style="color:#f92672">-&lt;/span> &lt;span style="color:#ae81ff">1&lt;/span> &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">65&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">elif&lt;/span> &lt;span style="color:#ae81ff">27&lt;/span> &lt;span style="color:#f92672">&amp;lt;=&lt;/span> n &lt;span style="color:#f92672">&amp;lt;=&lt;/span> &lt;span style="color:#ae81ff">36&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(n &lt;span style="color:#f92672">-&lt;/span> &lt;span style="color:#ae81ff">27&lt;/span> &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">48&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">else&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> &lt;span style="color:#e6db74">&amp;#39;_&amp;#39;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(plain)
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div></description></item><item><title>basic-mod1</title><link>https://panman4040.github.io/training/picoctf/cryptography/basic-mod1/</link><pubDate>Mon, 04 May 2026 21:25:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/cryptography/basic-mod1/</guid><description>&lt;p>Take each number mod 37 and map it to the following character set: 0-25 is the alphabet (uppercase), 26-35 are the decimal digits, and 36 is an underscore.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>encoded &lt;span style="color:#f92672">=&lt;/span> [&lt;span style="color:#ae81ff">350&lt;/span>, &lt;span style="color:#ae81ff">63&lt;/span>, &lt;span style="color:#ae81ff">353&lt;/span>, &lt;span style="color:#ae81ff">198&lt;/span>, &lt;span style="color:#ae81ff">114&lt;/span>, &lt;span style="color:#ae81ff">369&lt;/span>, &lt;span style="color:#ae81ff">346&lt;/span>, &lt;span style="color:#ae81ff">184&lt;/span>, &lt;span style="color:#ae81ff">202&lt;/span>, &lt;span style="color:#ae81ff">322&lt;/span>, &lt;span style="color:#ae81ff">94&lt;/span>, &lt;span style="color:#ae81ff">235&lt;/span>, &lt;span style="color:#ae81ff">114&lt;/span>, &lt;span style="color:#ae81ff">110&lt;/span>, &lt;span style="color:#ae81ff">185&lt;/span>, &lt;span style="color:#ae81ff">188&lt;/span>, &lt;span style="color:#ae81ff">225&lt;/span>, &lt;span style="color:#ae81ff">212&lt;/span>, &lt;span style="color:#ae81ff">366&lt;/span>, &lt;span style="color:#ae81ff">374&lt;/span>, &lt;span style="color:#ae81ff">261&lt;/span>, &lt;span style="color:#ae81ff">213&lt;/span>]
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>plain &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#e6db74">&amp;#34;&amp;#34;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">for&lt;/span> n &lt;span style="color:#f92672">in&lt;/span> encoded:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> n &lt;span style="color:#f92672">=&lt;/span> n &lt;span style="color:#f92672">%&lt;/span> &lt;span style="color:#ae81ff">37&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> &lt;span style="color:#ae81ff">0&lt;/span> &lt;span style="color:#f92672">&amp;lt;=&lt;/span> n &lt;span style="color:#f92672">&amp;lt;=&lt;/span> &lt;span style="color:#ae81ff">25&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(n &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">65&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">elif&lt;/span> &lt;span style="color:#ae81ff">26&lt;/span> &lt;span style="color:#f92672">&amp;lt;=&lt;/span> n &lt;span style="color:#f92672">&amp;lt;=&lt;/span> &lt;span style="color:#ae81ff">35&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> chr(n &lt;span style="color:#f92672">-&lt;/span> &lt;span style="color:#ae81ff">26&lt;/span> &lt;span style="color:#f92672">+&lt;/span> &lt;span style="color:#ae81ff">48&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">else&lt;/span>:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> plain &lt;span style="color:#f92672">+=&lt;/span> &lt;span style="color:#e6db74">&amp;#39;_&amp;#39;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> 
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>print(plain)
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div></description></item><item><title>Cryptography</title><link>https://panman4040.github.io/training/picoctf/cryptography/</link><pubDate>Mon, 04 May 2026 21:23:16 +0800</pubDate><guid>https://panman4040.github.io/training/picoctf/cryptography/</guid><description/></item></channel></rss>