Site cover image

Site icon image vicevirus’ Blog

Yo, welcome to my blog! I write tech stuff and play CTFs for fun. (still a noob)

Post title icon Wargames.my WGMY 2024 Web Write-up

Featured image of the post

Wargames.my 2024 Web Writeup - Writeup on some of the web challenges in WGMY 2024. Twig php argc_argv template injection, kubernetes auth vault reading, vulnerable Wordpress plugin leading to LFI/LFR, OpenRASP bypass by loading custom/external class

Post title icon BackdoorCTF'24 Writeup

Featured image of the post

BackdoorCTF'24 Writeup - Some of the web challenges. Prompt injection, DOM Clobber, CSS Injection through font-face.

🔎 spatie/browsershot ≤ 5.0.0: Improper Input Validation Leading to Local File Read (LFR) CVE-2024-21544

Featured image of the post

Improper Input Validation in spatie/browsershot ≤ 5.0.0. CVE-2024-21544

Post title icon ASEAN Cyber Shield 2024 Prelim and Finals Write-up

Featured image of the post

ASEAN CYBER SHIELD HACKING CONTEST 2024 - Prelim & Finals Write-up of challenges that I managed to solve

Post title icon Battle of Hackers 2024 (BOH/IBOH 2024) Local Category - Web Writeup

Featured image of the post

BOH/IBOH 2024 - All Web challenges writeup. Bunch of web stuff

Post title icon Siber Siaga I-Hack 2024 Semi-Final Attack Defense CTF Write-up

Featured image of the post

A&D CTF in Malaysia. Solutions and methods of persistence.

Post title icon Siber Siaga I-Hack 2024 Qualifier Write-up

Featured image of the post

All web solutions except for Pinger. LIttle bit of RE, DFIR and Malware.

Post title icon Hacktheon Sejong 2024 Finals Web Write-up

Featured image of the post

Reversing WASM, React compiled code and exploring through Django

Post title icon Wani CTF 2024 Web Write-up

Featured image of the post

<meta> tag redirect to XSS and hijacking timeserver by hosting your own

Post title icon Codegate CTF 2024 Preliminary master_of_calculator Write-up

Featured image of the post

Bypassing Ruby filters to execute command injection