Media Summary: Grab RSA private key from JPEG comment and decrypt a file with it. The following Python program connects to the server, gets the hex bytes of an executable, disassembled it and looks for where the ... A website used the hash of the userid number as the URL of their page. The following Python code tries a bunch to find the ...

Pico2026 Stegorsa - Detailed Analysis & Overview

Grab RSA private key from JPEG comment and decrypt a file with it. The following Python program connects to the server, gets the hex bytes of an executable, disassembled it and looks for where the ... A website used the hash of the userid number as the URL of their page. The following Python code tries a bunch to find the ... Brute force an XOR encrypted file with single byte key. Uses crackstation to find unsalted sha-256 hashed password for admin. Then decodes Flask session token to get the OTP code. Use sudo nano to edit the sudoers file to give yourself additional sudo permissions.

Use pwntools to read symbols from ELF file and send function addresses to server. Call an etherium contract using Foundry cast and trigger an integer overflow by depositing 2^256-1. Uses LLDB, Ghidra and CyberChef to reverse engineer a binary that decodes the password at runtime.

Photo Gallery

pico2026 stegorsa
PicoCTF StegoRSA
pico2026 autorev1
pico2026 gatekeeper
pico2026 hashgate
pico2026 Shared Secrets
pico2026 No FA
pico2026 absolute nano
pico2026 bytemancy3
pico2026 ksecrets
pico2026 Smart Overflow
pico2026 north south
Sponsored
View Detailed Profile
pico2026 stegorsa

pico2026 stegorsa

Grab RSA private key from JPEG comment and decrypt a file with it.

PicoCTF StegoRSA

PicoCTF StegoRSA

PicoCTF

pico2026 autorev1

pico2026 autorev1

The following Python program connects to the server, gets the hex bytes of an executable, disassembled it and looks for where the ...

pico2026 gatekeeper

pico2026 gatekeeper

Simple reverse engineering with Ghidra.

pico2026 hashgate

pico2026 hashgate

A website used the hash of the userid number as the URL of their page. The following Python code tries a bunch to find the ...

Sponsored
pico2026 Shared Secrets

pico2026 Shared Secrets

Brute force an XOR encrypted file with single byte key.

pico2026 No FA

pico2026 No FA

Uses crackstation to find unsalted sha-256 hashed password for admin. Then decodes Flask session token to get the OTP code.

pico2026 absolute nano

pico2026 absolute nano

Use sudo nano to edit the sudoers file to give yourself additional sudo permissions.

pico2026 bytemancy3

pico2026 bytemancy3

Use pwntools to read symbols from ELF file and send function addresses to server.

pico2026 ksecrets

pico2026 ksecrets

Use kubectl to view Kubernetes secrets.

pico2026 Smart Overflow

pico2026 Smart Overflow

Call an etherium contract using Foundry cast and trigger an integer overflow by depositing 2^256-1.

pico2026 north south

pico2026 north south

Access a website from Iceland!

pico2026 Bypass Me

pico2026 Bypass Me

Uses LLDB, Ghidra and CyberChef to reverse engineer a binary that decodes the password at runtime.