f4zzie

f4zzie

Offensive Security · Binary Exploitation · Reverse Engineering

picoCTF writeups documenting the full method behind each solve — the reasoning, the commands, and the verification. 37 challenges across 5 categories.

// unsorted
picoCTF - General Skills ABSOLUTE NANO

picoCTF Absolute Nano writeup using GTFOBins nano technique with sudo privileges to escalate access and read the flag file.

picoCTF - Blockchain Access_Control Writeup

picoCTF Access Control writeup exploiting an unprotected owner-setter function in a Solidity smart contract to claim ownership and reveal the flag.

picoCTF - Reverse Engineering Add/On Trap Writeup

picoCTF Add On Trap writeup analyzing a binary with anti-debugging traps and reversing the validation to extract the correct flag.

picoCTF - Reverse Engineering Autorev 1 Writeup

picoCTF AutoRev 1 writeup using automated reverse engineering tools like angr or Z3 to solve constraint-based flag validation.

picoCTF - Reverse Engineering Binary Instrumentation 3 (bin-ins3.zip) Writeup

picoCTF Binary Instrumentation 3 writeup using dynamic binary instrumentation tools like Frida or Pin to trace and solve the challenge.

picoCTF - Reverse Engineering Binary Instrumentation 4 (bin-ins4.zip) Writeup

picoCTF Binary Instrumentation 4 writeup applying advanced instrumentation techniques to hook functions and extract the flag at runtime.

picoCTF - Reverse Engineering Bypass Me Writeup

picoCTF Bypass Me writeup patching or reversing binary validation logic to bypass authentication checks and reveal the flag.

picoCTF - General Skills bytemancy 2

picoCTF Bytemancy 2 writeup sending raw bytes to a network service using pwntools to satisfy binary protocol requirements and retrieve the flag.

picoCTF - General Skills bytemancy 3

picoCTF Bytemancy 3 writeup using objdump disassembly and pwntools p32 packing to reconstruct data from binary sections and extract the flag.

picoCTF - Web Exploitation Credential Stuffing

picoCTF Credential Stuffing writeup using leaked credential databases to automate login attempts and gain unauthorized access to the target application.

picoCTF - Binary Exploitation Echo Escape 1 Writeup

picoCTF Echo Escape 1 writeup leveraging format string bugs in an echo service to read sensitive memory and extract the flag.

picoCTF - Binary Exploitation Echo Escape 2 Writeup

picoCTF Echo Escape 2 writeup using format string vulnerabilities to leak and overwrite memory for shell access.

picoCTF - General Skills Failure Failure

picoCTF Failure Failure writeup exploiting HAProxy failover behavior by exhausting rate limits to trigger backend routing to the flag server.

picoCTF - Web Exploitation Fool the Lockout

picoCTF Fool the Lockout writeup bypassing a rate-limiting lockout mechanism to brute-force credentials and access the protected endpoint.

picoCTF - Blockchain Front_Running Writeup

picoCTF Front Running writeup monitoring the mempool for pending transactions, extracting the plaintext solution, and front-running with higher gas price.

picoCTF - Reverse Engineering Gatekeeper Reverse Engineering Writeup

picoCTF Gatekeeper writeup reversing a gatekeeper binary with multiple validation stages to find the correct input sequence for the flag.

picoCTF - Web Exploitation Hashgate

picoCTF Hashgate writeup exploiting an IDOR vulnerability where user IDs are hashed with MD5, allowing access to other users accounts by predicting hash values.

picoCTF - Binary Exploitation Heap Havoc Writeup

picoCTF Heap Havoc writeup exploiting heap memory management flaws including use-after-free or heap overflow to gain code execution.

picoCTF - Reverse Engineering Hidden Cipher 1 Writeup

picoCTF Hidden Cipher 1 writeup reversing an encryption algorithm to decode the hidden flag from ciphertext output.

picoCTF - Reverse Engineering Hidden Cipher 2 Writeup

picoCTF Hidden Cipher 2 writeup tackling a more complex cipher implementation requiring deeper static analysis to reverse the encoding.

picoCTF - Reverse Engineering JITFP Writeup

picoCTF JITFP writeup reversing a just-in-time compiled program, analyzing dynamically generated code to understand flag computation.

picoCTF - General Skills MY GIT

picoCTF My Git writeup forging a Git commit identity to bypass repository validation checks and retrieve the flag.

picoCTF - Web Exploitation No FA

picoCTF No FA writeup exploiting Flask session cookie vulnerabilities to leak OTP codes and crack passwords for authentication bypass.

picoCTF - Binary Exploitation offset-cycle Writeup

picoCTF Offset Cycle writeup solving a binary exploitation challenge involving cyclic offset calculation and return address control.

picoCTF - Binary Exploitation offset-cycleV2 Writeup

picoCTF Offset Cycle V2 writeup building on the first version with additional protections requiring more advanced exploitation techniques.

picoCTF - General Skills Password Profiler Writeup

picoCTF Password Profiler writeup using CUPP to generate a custom wordlist from OSINT data and cracking a SHA-1 hash to recover the password.

picoCTF - Binary Exploitation Pizza Router Writeup

picoCTF Pizza Router writeup exploiting a routing application through buffer overflow or command injection to capture the flag.

picoCTF - General Skills Printer Shares

picoCTF Printer Shares writeup enumerating SMB shares to discover and access hidden printer share files containing the flag.

picoCTF - General Skills Printer Shares 3

picoCTF Printer Shares 3 writeup discovering a writable cron job script on a printer share and exploiting it for remote code execution to capture the flag.

picoCTF - Binary Exploitation Quizploit Writeup

picoCTF Quizploit writeup exploiting a quiz application through buffer overflow to redirect execution and capture the flag.

picoCTF - Blockchain Reentrance Writeup

picoCTF Reentrance writeup deploying an attacker contract to exploit the classic reentrancy vulnerability and drain the bank contract to zero.

picoCTF - Web Exploitation Secret Box

picoCTF Secret Box writeup exploiting SQL injection to forge authentication tokens and access the secret content containing the flag.

picoCTF - Reverse Engineering Secure Password Database Writeup

picoCTF Secure Password Database writeup reversing a password database application to extract stored credentials and recover the flag.

picoCTF - Reverse Engineering Silent Stream Writeup

picoCTF Silent Stream writeup recovering hidden data from a binary that outputs the flag through non-obvious channels or side effects.

picoCTF - Blockchain Smart_Overflow Writeup

picoCTF Smart Overflow writeup triggering a uint256 integer overflow in unchecked Solidity arithmetic to satisfy the flag reveal condition.

picoCTF - Web Exploitation Sql Map1

picoCTF SQL Map 1 writeup using sqlmap to automate SQL injection attacks and extract password hashes, then cracking them with MD5 lookup.

picoCTF - Binary Exploitation tea-cash Writeup

picoCTF Tea-Cash writeup exploiting a virtual currency application through integer overflow or logic flaws to gain unauthorized funds.