Played N0PS CTF last week-end.
This is my write-up, with images.

#android #writeup #CTF #native #java #reverse #jeb #decompiler

1/4

This weekend's GreyCatCTF had an interesting "Reverse 101" challenge in the "EZPZ" category. In "nc" a number of questions were asked on the binary, and the most interesting one was what a certain function did (RC4 encrypt) and what input is required to get the flag.

Besides ghidra & gdb, angr was very helpful here to get the plaintext for the RC4 encryption. See pictures for details.

#greycat #ctf #cybersecurity #angr #reverseengineering #rc4 #decrypt #ezpz #writeup #notawriteup #lazy

Wohoo...
My poem in the English language has been published!

A big thank you to Paper Boat and The Alipore Post for organizing such a delightful event. It was a rare and cherished opportunity to stretch my literary muscles in English, especially through poetry. The experience was not only exhilarating but also incredibly soothing, stirring up a beautiful sense of nostalgia.

#poem #nostalgia #writeup #summer #literature

Spent some time at BUYCTF yesterday, scored some flags, some not. Learned a lot, and had even more fun. Here is a writeup from my notes:

http://www.feyrer.de/redir/BYUCTF2025-Writeup.html

#ctf #cybersecurity #writeup #byuctf #2025 #rev #osint #forensics #osint #pwn #nopwn

I noticed a (minor but abusable) data leak in the RMM/PSA tool Atera a while ago, reported it and it's now fixed. I think it's somewhat interesting so I wrote it up.

https://fyr.io/post/atera-leaked-their-customers-to-mailinator

Tldr: if you tested your SMTP settings, it used a public mailbox on mailinator, allowing anyone to watch for (and respond to, if you're so inclined) mail. Phishing opportunity!

#infosec #atera #privacy #dataleak #mailinator #writeup #phishing #netsec

Scraps from mid May-ish to 2025-06-18

A bunch of scrappy notes from mid May-ish to 2025-06-18

Ontu uncle says he once saw it,
hanging from that fig tree branch, just above the water.
No one ever doubts uncle.

Rupu says the fish
the one they call love
isn’t really anything at all.
If you believe in it, it exists.
If you don’t, it fades away.

From afar, love looks magical.
But the closer you get, the more it slips away, like mist.
That’s why no one dares approach a heart too full.

Do you know the kind of peace that comes
from simply believing it’s real?

#writeup #surreal #book #read

Jamie Hendrix Magazine interview - Collectors Realm 3

Jamie Hendrix Manshots interview from Manshots in April, 1995

Collectors Realm 3 - Vintage gay porn, Jack Drago, and Bob's Guys
Writeup: TryHackMe Billing

Billing Difficulty: easy Platform: web, linux Gain a shell, find the way and escalate your privileges! Note: Bruteforcing is out of scope for this room. Answer the questions below What is user.txt? What is root.txt? In this room I practiced exploiting CVEs and privilege escalation. Vulnerabilities explored: Command injection Sudoers misconfiguration Information gathering User flag: getting reverse shell via command injection Root flag: privilege escalation with fail2ban-client Information gathering As usual, first step, running a port scan:

aviskase
CVE-2025–21333 Windows heap-based buffer overflow analysis

CVE-2025–21333 is a vulnerability detected by Microsoft as actively exploited by threat actors. Microsoft patched the vulnerability on January 14th, 2024 with KB5050021 (for Windows 11 23H2/22H2)…

Medium