bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

ReAL-File-System - bi0sCTF 2024

5h4rrK
2024-03-12
Forensics

Full detailed writeup for ReAL-File-System which is centered around ReFS Log Analysis.

tl;dr

  • Disk Forensics
  • Resilient File System
  • Log Analysis
Read More
bi0sCTF2024 Resilient File System File System Analysis Log Analysis File System Forensics ReFS

verboten - bi0sCTF 2024

sp3p3x
jl_24
2024-03-08
Forensics

tl;dr

  • Registry Hives analysis
  • Analyse Chrome browser artifacts
  • Analyse Slack artifacts
  • Analyse AnyDesk artifacts
  • Analyse artifacts for evidence of execution
  • Analyse clipboard artifacts
Read More
Incident Response USB Slack Windows Activity timeline bi0sCTFs AnyDesk prefetch Chrome

Image Gallery - bi0sCTF 2024

ma1f0y
2024-03-06
Web

tl;dr

Image gallery 1

  • Get xss by uploading index.html in public dir
  • Use bf cache to get the flag.

Image gallery 2

  • Slice files.js using nginx partial caching.
  • Use Subresource Integrity to load the right script
  • Use DOM clobbering and Cache probing to leak the flag uuid
Read More
bi0sCTF2024

Batman Investigation I - Like Father Like Son - bi0sCTF 2024

Azr43lKn1ght
2024-03-05
Forensics

Full solution of Batman Investigation II - Gotham Underground Corruption from bi0sctf 2024

tl;dr

  • Challenge 1 of Batman Investigation series
  • Memory Forensics - WinDBG Dump Debugging - Malware Analysis - Incident Response - Threat Hunting
Read More
bi0sCTF Memory Forensics Incident Response Malware Analysis WinDBG Dump Debugging Threat Hunting

baeBPF - bi0sCTF 2024

Chee-tzu
2024-03-03
RE

tl;dr

  • Analysis of eBPF assembly
  • Simple optimization
Read More
bi0sCTF eBPF

t0y-b0x - bi0sCTF 2024

the.m3chanic
Sans
2024-03-03
RE, Crypto

tl;dr

  • Binary obfuscation with hidden anti-debug checks
  • Linear Cryptanalysis (AES with linearly dependent SBOX)
Read More
bi0sCTF Anti-debug AES

beehive - bi0sCTF 2024

the.m3chanic
2024-03-02
RE

tl;dr

  • Custom hook to syscall 0x31337 using eBPF
  • Check on the argument passed to syscall to verify correct/incorrect key
Read More
bi0sCTF eBPF

കുട്ടി Notes - bi0sCTF 2024

Lu513n
2024-02-29
Web

tl;dr

  • DOM Clobbering to Redirect to another page
  • Increasing Content using SQL Injection giving the same column multiple times
  • Connection-Pool XS-Leaks to measure the time for the page to load
  • Leak the flag character by character using the above techniques
Read More
bi0sCTF DOM Clobbering XS-Leaks

kowaiiVm - bi0sCTF 2024

k1R4
2024-02-28
Pwn

tl;dr

  • The VM takes a custom binary as input
  • Binary contains function table, code and bss sections
  • Code can overlap with bss and be modified at runtime
  • The JIT compiler assumes that a function is safe since it ran many times
  • Functions modified right before JIT bypass security checks
Read More
bi0sCTF Exploitation VM JIT

virtio-note - bi0sCTF 2024

k1R4
2024-02-28
Pwn

tl;dr

  • The patch adds a vulnerable virtio device
  • The device accesses pointers without bound check
  • Abuse OOB pointer access to setup arb r/w primitive
  • Craft open,read,write ropchain on heap
  • Overwrite virtqueue handler with stack pivoting gadget
Read More
bi0sCTF Exploitation QEMU VM-Escape

 Previous 

2 / 19

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.