Recent notes

  1. writeup

    ZEXOR-v2.0

    Crackme writeup that disables anti-debugging and exploits a nibble-swap bug to recover ZEXOR's license PRNG seed.

  2. article

    Breaking the Handshake: Network Protocol Fuzzing

    Explains stateful network protocol fuzzing, emphasizing message timing, ordering, and multi-step interaction over isolated inputs.

  3. writeup

    Nexus! _

    Crackme writeup for reversing a custom encrypted VM while bypassing anti-debugging and extracting the NexusCore password.

  4. writeup

    Monitors Four

    HTB Monitors Four writeup exploiting PHP loose comparison and Docker Desktop API access to obtain user and root flags.

  5. project

    SIMP Internal Architecture

    Explains the architecture of a Go MITM proxy, including concurrency, programmable filtering, and epoll-based polling.

  6. writeup

    Otternaut Launch

    Sui blockchain writeup assembling launch-capsule objects in order and calling the entrypoint with valid version and safety values.

  7. writeup

    Stretch

    Reverse-engineering writeup that decrypts embedded strings and recovers the expected Stretch license value.

  8. writeup

    Solidity Jail 1

    Solidity Jail writeup showing how to bypass keyword restrictions and use the contract interface to read the flag.

  9. writeup

    Snake

    Reverse-engineering writeup that bypasses a Snake game's premium license check and reconstructs its legacy encryption.

  10. writeup

    Nim Yong Un

    Nim reverse-engineering writeup deriving the launch code from repeated MD5 checks over transformed input characters.

  11. writeup

    dark

    WWCTF pwn writeup using shellcode injection and a vmaskmov side channel to exfiltrate the flag under seccomp.