I'm honoured to see my "Advent of Pwn" CTF writeup featured on yesterday's pwn.talk

I'm honoured to see my "Advent of Pwn" CTF writeup featured on yesterday's pwn.talk

βPicture yourself as a digital maestro, orchestrating a symphony of code in a vast digital realm. However, thereβs a twist: you donβt get to pen down your own notes. Instead, you're given a legacy of existing code snippets, scattered across the system. This is the essence of Return Oriented Programming (ROP) exploits!β (pwn.college)
#rop #returnorientedprogramming #pwn #ctf #cybersecurity #pwncollege
What a hell of a challenge!
π Successfully completed Yansanity (Easy)! π
π Successfully completed Yansanity (Hard)! π
Did you ever reverse-engineer a CPU & operating system where you didn't know the instruction opcodes, registers, CPU flags, syscall numbers etc.?
Back to pwn.college for Yellow belt - making progress.
Checking Santa's List Twice (With Python & Assembly!) π π»
Just cleared "Weak 01" of #AdventOfPwn 2025 on pwn.college! π©
The challenge used thousands of addb and subb instructions to obfuscate a 1024-byte check. I used objdump for static analysis and wrote a Python parser to "undo" the math and recover the flag.
Skills: β Reverse Engineering (x86) β Static Analysis β Python Scripting
Full writeup & solver: π https://eeshan-agrawal.medium.com/santas-byte-level-bookkeeping-solving-pwn-college-day-01-757469859b80
Back in the game for my Yellow Belt βοΈ
CTF Writeup: pwn.college - Advent of Pwn 2025
pwn.college is an educational cybersecurity platform by Arizona State University. Their Advent of Pwn 2025 released one challenge per day during December. This writeup documents my solutions for the 2025 edition's 12 challenges, covering binary exploitation, web security, blockchain, VM escapes, and even MS-DOS networking.
https://www.feyrer.de/CTF/CTF-Writeup-pwn.college-AdventOfPwn2025/
1/x
*** Update on my personal CyberSec journey
I havenβt posted a lot recently, which doesnβt mean I was lazy. The last weeks entertained several CTFs (PlatyPwn, Huntress, hack.lu, UniR) and also some fun professional events and great people with a focus on the EU Cyber Resilience Act (project networks, qSkills, and an event I hosted at my employer).
More in comments.
#ctf #cybersecurity #platypwn #huntress #hacklu #eucra #cra #arm64 #angr #tryhackme #thm #adventofcyber #39c3 #pwncollege
For more pwnage: Advent of Pwn