Web Reversing XSS LFI RCE Linux Mobile
+825 points

AndroCat

Fullpwn machine on a Linux environment with Android APK to reverse engineer and exploit the API through XSS and PDF generation. Then escalate privileges with a SSTI and a NodeJS CVE

Web Scripting XSS RCE
+400 points

Phantom Feed

One of my favorite hard web challenges I've done, combining many different small vulnerabilities into a chain that leads to Remote Code Execution by stealing tokens from a bot and using SSTI

Web SQL Injection RCE
+325 points

Nexus Void

Medium C# web challenge with some secrets leftover in compilation artifacts, and a chain of SQL Injection with JSON Deserialization to achieve RCE

Scripting Crypto
+625 points

MSS + MSS Revenge

Cryptography challenge creatively using CRT to single out the key that decrypts the flag. The original had an unintended solution after which a patched "MSS Revenge" was created

Forensics Reversing Crypto Hardware
+325 points

ZombieNet

Forensics challenge with a lot of Reverse Engineering, extracting files from a router firmware image and then decrypting obfuscated binaries