<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ctf-Writeup on krash.dev</title><link>https://krash.dev/tags/ctf-writeup/</link><description>Recent content in Ctf-Writeup on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/ctf-writeup/rss.xml" rel="self" type="application/rss+xml"/><item><title>Anonymous Challenge Write-Up: WinjaCTF c0c0n 2021</title><link>https://krash.dev/posts/winja-anonymous-challenge-writeup/</link><pubDate>Mon, 15 Nov 2021 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/winja-anonymous-challenge-writeup/</guid><description>&lt;p&gt;WinjaCTF at c0c0n [2021]: I developed an easy challenge - called &amp;ldquo;Anonymous&amp;rdquo; - the challenge was based upon browser forensics.&lt;/p&gt;
&lt;h2 id="tldr"&gt;TL;DR&lt;a class="heading-anchor" href="#tldr" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Intended Way&lt;/strong&gt; - Download the zip &amp;gt; Extract it &amp;gt; Navigate the Linux directory structure &amp;gt; To find a directory called &lt;code&gt;.config&lt;/code&gt; &amp;gt; google-chrome &amp;gt; Default &amp;gt; Open the History File in SQL Browser &amp;gt; Search for URLs and upon up the URL to get a file with the name - formatted like flag.&lt;/p&gt;</description></item><item><title>Bug Bounty Summit CTF Writeup</title><link>https://krash.dev/posts/bug-bounty-summit-ctf-writeup/</link><pubDate>Mon, 02 Nov 2020 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/bug-bounty-summit-ctf-writeup/</guid><description>&lt;p&gt;&lt;em&gt;The CTF is live on Hacker101 as Grayhatcon CTF – &lt;a href="https://ctf.hacker101.com/ctf" target="_blank" rel="noopener noreferrer"&gt;Hacker101 CTF&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The CTF was built upon real vulnerabilities found during bug bounties. It had four flags – 250 points each.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Objective&lt;/strong&gt; - Hackerone&amp;rsquo;s Username and Password database has been leaked and put on an auction. Our task was to delete the auction listing before anyone buys it.&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;We were given an IP, which resolved to a web application. On performing some basic information gathering, I found out some stuff.&lt;/p&gt;</description></item></channel></rss>