CTF WriteUps
Solved CTFs
TryHackMe — Silver Platter
Enumerated exposed services, leveraged weak file permissions and a misconfigured web app to obtain a foothold, then escalated via a writable service script.
View on GitHubTryHackMe — Advent of Cyber 2024
Daily challenge summaries including methodology, key commands, and flags. Focus on practical techniques across web, forensics, and basic cryptography.
View on GitHubTryHackMe — API Wizards Breach
Mapped endpoints with documentation fuzzing, exploited authentication flaws and parameter tampering to extract sensitive data. Mitigations and secure patterns provided.
View on GitHubTryHackMe — Publisher
Abused a CMS plugin upload to achieve code execution, pivoted to system access, and captured flags. Includes enumeration checklists and detection notes.
View on GitHubTryHackMe — MR Robot CTF
Discovered WordPress creds via dictionary attack, reused credentials for lateral movement, and escalated via vulnerable service binaries.
View on GitHubTryHackMe — Lo‑Fi
Identified hidden endpoints and weak access controls, chained minor logic issues to extract secrets and escalate access.
View on GitHubTryHackMe — The Sticker Shop
Abused insecure direct object references and weak session handling to access protected resources. Includes remediation guidelines.
View on GitHubTryHackMe — Pickle Rick
Enumerated web app for credentials, leveraged sudo misconfigurations to root the host. Clear, step-by-step methodology with commands.
View on GitHub