Step-by-step CTF challenge writeups, written by the community.
Bypass an overly naive SQL injection filter to get past a login form.
Find a flag hidden in three pieces across the HTML source, a JS file, and a CSS file.
Detect and extract a ZIP file hidden inside a PNG image with binwalk. An introduction to steganography.
Manipulating HTTP cookies to enumerate hidden values and capture the flag. Technique: IDOR via a sequential cookie.
Share your CTF solutions with the community. Join the Discord and post in #writeups.
Join CTFdojo Discord