17 writeups published·Skilled Writer·Since 2025
Knowledge flows through your words!
- 2026THJCC 2026 Summer — Official Writeup· Updated: Aug 16· CTF, THJCC, Forensics, WriteUpOfficial THJCC 2026 Summer writeup for NoNo, a log-analysis forensics challenge where 500 lines of loud fake-CVE noise hide one real lead: a single request to an internal vhost for a look-alike secret path.
- THJCC 2026 Summer — 官方解題· Updated: Aug 16· CTF, THJCC, Forensics, WriteUp· 中文THJCC 2026 Summer NoNo 官方解題。一條 log 分析鑑識題,500 行 log 全是假的 CVE 攻擊雜訊,真正的線索只有一筆打到內部 vhost 的請求。
- HITCON CTF 2025 — Writeup· Updated: Aug 5· CTF, HITCON CTF, Misc, WriteUpHITCON CTF 2025 misc writeup for Git Playground: a chroot jail that hands you a real git repo plus arbitrary file writes, so overwriting core.pager in .git/config turns git log into flag disclosure through the shell.
- CCCTF 2026 — Writeup· Updated: Aug 5· CCCTF, CTF, WriteUpCCCTF 2026 writeup covering the challenges I solved across Web, Crypto, Misc, and Reverse: a flag hidden before a Rick Roll redirect, a weak Flask secret key, a nested field-selector IDOR, XOR key reuse, JPEG-comment stego, a ZIP appended to a PNG, and a Windows keygen.
- picoCTF 2026 — Writeup· Updated: Aug 5· CTF, picoCTF, WriteUpA picoCTF writeup covering 11 challenges across Web, Cryptography, Forensics, and Reverse Engineering: IDOR via MD5, SQLi to hash cracking, a Flask session OTP leak, LFSR-AES, Diffie-Hellman key reuse, an RSA key hidden in JPEG metadata, bitstream and git-history forensics, XOR unpacking, and a Heartbleed-style heap over-read.
- AWDT 2026 — Writeup· Updated: Aug 5· CTF, AWDT, Attack-With-Defense, WriteUpFull attack-and-defense writeups for AWDT 2026: prototype pollution, XXE, SSRF-to-Redis, Phar deserialization, JWT forgery, Nginx off-by-slash traversal, sandbox escape RCE, ML data poisoning, an async TOCTOU race, stored XSS, and a seccomp ORW pwn, each with the minimal patch.
- Secso CTF 2026 Writeup· Updated: Jul 5· Secso, Writeup, CTF, Crypto, Web, MiscWriteup for Secso CTF 2026 challenges, covering RSA common factor attack, SQL injection to arbitrary file read, vmsplice TOCTOU commit-reveal break, /proc cmdline secret leak, and DOM clobbering cookie exfiltration.
- No Hack No CTF 2026 — Official Writeup· Updated: Jul 5· CTF, No Hack No CTF, Forensics, WriteUpFull writeup for No Hack No CTF 2026 Kira-Notes computer forensics challenge. Browser forensics, disk image recovery, password reconstruction, and archive extraction.
- PolyU PUCTF 2026 - 一場唔愉快嘅經歷· Updated: Jun 8· PUCTF, CTF關於 PUCTF 2026 嘅參賽感受同埋對主辦方處理手法嘅遺憾。
- SekaiCTF 2025 Writeup· Updated: May 17· SekaiCTF, Writeup, CTFWriteup for SekaiCTF 2025 web exploitation challenges, covering LFI vulnerability exploitation and Docker container filesystem analysis in the My Flask App challenge.
- HKCERT CTF 2025 — Writeup· Updated: Aug 5· CTF, HKCERT CTF, Web Exploitation, Cryptography, Reverse EngineeringMy HKCERT CTF 2025 writeups: renderme web RCE and privesc, plus crypto (cruel_rsa, EC Fun, Loss N, Bivariate copper, Triple Key Cipher), a pickle jail, reverse (easyjar SM4, findkey), and a PHP POP-chain web bug.
- THJCC CTF 2026 — Official Writeup· Updated: Jun 8· CTF, THJCC CTF 2026, WriteUpTHJCC CTF 2026 official writeup, Complete solutions for these challenges! By UmmIt Kin.
- 2025TryHackMe - Anonymous· Updated: Jul 7· TryHackMe · Challenge · MediumFTP anonymous login, writable scripts, and env privilege escalation.
- TryHackMe - GitLab CVE-2023-7028· Updated: Jul 7· TryHackMe · Learn · MediumPassword reset account takeover vulnerability in GitLab.
- TryHackMe - Multi-Factor Authentication· Updated: Jul 7· TryHackMe · Learn · EasyBypassing auto-logout and brute-forcing a hardcoded OTP.
- No Hack No CTF 2025 — Official Writeup· Updated: Jun 8· CTF, No Hack No CTF, WriteUpFull writeup for No Hack No CTF 2025 Crackme and gitgit challenges. Learn how to solve these challenges step by step.
- Bronco CTF 2025 Writeup· Updated: Jul 27· Bronco CTF, 2025, Writeup, CTFWriteup for Bronco CTF 2025, covering reverse engineering, web, and miscellaneous challenges including Break the Battalion, Inspector Requestor, Mary's Lamb is a Little Phreak, and Rahhh-Sh.