PlaidCTF 2014

This was a challenging, but incredibly fun CTF. The 'Gnu E Ducks' (no hyphens allowed!) placed 71st out of 800-something teams. Here is the collection of writeups for the challenges we solved:

  • twenty  : primitive crypto
  • mtpox  : hash-length extension, sqli
  • ezhp  : memory corruption, heap overflow
  • kpop  : php object serialization
  • reeekeeeeee  : django session serialization, language security