标杆比赛,一个不会,任重道远,加油。。。
Pwn
Sstation Escape
1 | My treasure is yours for the taking, But you'll have to find it first. I left everything I own in host. |
文件下载不下来
Engine for Neophytes
1 | I've heard that @tsuro will precipitate the culmination of intricacy for browser exploitation in CTF games with some choreographed and elaborated bugs in the short run. Thus, here is an excellent opportunity for novices to originate and scrutinize your foolproof exploit for this painless bug. |
The Pwnable Link
1 | Hey guys, we've brought you the real IoT hacking challenge. You can find a home camera in the cabinet beside the table. Please hack it with the latest firmware under default configurations (except that the web admin password will be modified). This challenge requires you to demo the exploit on the stage. The demonstration needs to meet the requirements as below: |
router
1 | There are many ways to manage a router, and I choose SNMP. |
OBC Box
1 | Is OBD Box Safe? There is a real car on the stage which has an OBD Box installed. This OBD Box will connect to its server and this server has the ability to control the car using the OBD Port. |
KitKot
1 | Please don't get lost in the ACG site. Try remotely compromise it and show us your Calculator on the stage |
frawler
1 | Well, it turns out that the time machine we used to pwn suanjike is not a realworld thing :( Let's try something from the future without time traveling. |
文件下载不下来
Web
The Return of One Line PHP Challenge
1 | What happens if I turn off session.upload? This challenge is almost identical to HITCON CTF 2018's challenge One Line PHP Challenge (Tribute to 🍊). Plz read the docker file and show me your shell. |
有dockfile,可以做
Magic Tunnel
1 | Must be a submarine to cross the English Channel? |
The Last Guardian
1 | You need to host a webpage. By open it using our latest safari on macOS, can you run the following JavaScript code in browser under the specified domain? |
flaglab
1 | You might need a 0 day |
Rmi
1 | Remote Method Invocation? No, it's Remote Calculator Invocation. |