k4ndar3c
12
Place20850
Points529
Challenges39
Compromissions
94%
App - Script
865 Points31 / 33
- o Bash - System 1
- o sudo - faiblesse de configuration
- o Bash - System 2
- o LaTeX - Input
- o Powershell - Command injection
- o AppArmor - Jail Introduction
- o Bash - unquoted expression injection
- o Docker - I am groot
- o Perl - Command injection
- o Powershell - SecureString
- o Bash - cron
- o LaTeX - Execution de commandes
- o Python - input()
- o R : exécution de code
- o Powershell - Basic jail
- o Python - pickle
- o Bash - quoted expression injection
- o Docker - Sys-Admin’s Docker
- o Shared Objects hijacking
- o SSH - Agent Hijacking
- x AppArmor - Jail Medium
- o Bash - race condition
- o Docker - Talk through me
- o Python - format string
- o Python - PyJail 1
- o PHP - Jail
- o Python - PyJail 2
- o Python - Jail - Exec
- o Javascript - Jail
- o Python - Jail - Garbage collector
- o Bash - Shells restreints
- o Python - Eval Is Evil
- x Deep learning - Modèle malveillant
87%
App - Système
5890 Points81 / 93
- o ELF x86 - Stack buffer overflow basic 1
- o ELF x64 - Basic heap overflow
- o ELF x86 - Stack buffer overflow basic 2
- o PE32 - Stack buffer overflow basic
- o ELF x86 - Format string bug basic 1
- o ELF x64 - Stack buffer overflow - basic
- o ELF x86 - Format string bug basic 2
- o ELF x86 - Race condition
- o ELF ARM - Stack buffer overflow - basic
- o ELF MIPS - Stack buffer overflow - No NX
- o ELF x64 - Double free
- o ELF x86 - Stack buffer overflow basic 3
- o ELF x86 - Use After Free - basic
- o ELF ARM - Stack Spraying
- o ELF x64 - Stack buffer overflow - PIE
- o ELF x86 - BSS buffer overflow
- o ELF x86 - Stack buffer overflow basic 4
- o ELF x86 - Stack buffer overflow basic 6
- o ELF x86 - Format String Bug Basic 3
- o PE32 - Stack buffer overflow avancé
- o ELF ARM - Basic ROP
- o ELF MIPS - Basic ROP
- o ELF RISC-V - Intro - let’s do the ROP
- o ELF x64 - Stack buffer overflow - Stack pivot
- o ELF x86 - Stack buffer overflow - C++ vtables
- o PE32+ Format string bug
- o ELF x64 - Logic bug
- x ELF x86 - Bug Hunting - Plusieurs problèmes
- o ELF x86 - Stack buffer and integer overflow
- o ELF x86 - Stack buffer overflow - ret2dl_resolve
- o ELF x86 - Stack buffer overflow basic 5
- o ELF x64 - Stack buffer overflow - avancé
- o ELF MIPS - Format String Glitch
- o ELF x64 - Heap Filling
- o ELF x86 - Information leakage with Stack Smashing Protector
- o ELF x64 - File Structure Hacking
- o ELF ARM - Race condition
- x ELF x64 - Browser exploit - Intro
- o ELF x64 - Buggy VM
- o ELF x64 - Heap Safe-Linking Bypass
- o ELF x64 - ret2dl_init
- o ELF x86 - Out of bounds attack - French Paradox
- o ELF x86 - Remote BSS buffer overflow
- o ELF x86 - Remote Format String bug
- o PE32+ Basic ROP
- o ELF x64 - Remote heap buffer overflow - tcache
- o ELF x86 - Blind remote format string bug
- x LinKern ARM - syscall vulnérable
- o LinKern x86 - Buffer overflow basic 1
- o ELF x64 - Sigreturn Oriented Programming
- o LinKern x86 - Null pointer dereference
- o ELF x64 - Syscall chaining
- o LinKern x64 - Race condition
- x ELF ARM - Shellcode alphanumérique
- o ELF MIPS - URLEncoded Format String bug
- o ELF x64 - Blind SROP
- x ELF x64 - Heap Hop
- o ELF x86 - Hardened binary 1
- o ELF x86 - Hardened binary 2
- o ELF x86 - Hardened binary 3
- o ELF x86 - Hardened binary 4
- x LinKern MIPSel - Vulnerable ioctl
- o LinKern x64 - code réentrant
- o ELF ARM - Heap format string bug
- o ELF ARM - Format String bug
- o ELF ARM - Use After Free
- o ELF x64 - FILE structure hijacking
- o ELF x64 - Heap feng-shui
- o ELF x64 - Off-by-one bug
- o ELF x86 - Hardened binary 5
- x LinKern ARM - Stack Overflow
- o LinKern x86 - basic ROP
- o ELF ARM - Heap Off-by-One
- x ELF x64 - Advanced blind format string exploitation
- o ELF x64 - Remote Heap buffer overflow 1
- o ELF x86 - Hardened binary 6
- o ELF x86 - Hardened binary 7
- o ELF x86 - Remote stack buffer overflow - Hardened
- o LinKern x64 - RowHammer
- o LinKern x64 - SLUB off-by-one
- o ELF ARM - Heap buffer overflow - Wilderness
- o ELF ARM - Heap Overflow
- o ELF ARM64 - Heap Underflow
- o ELF x64 - Seccomp Whitelist
- o ELF x86 - Blind ROP
- o LinKern x64 - Memory exploration
- x WinKern x64 - Stack buffer overflow avancé - ROP
- x WinKern x64 - Use After Free
- o ELF x64 - Remote Heap buffer overflow 2
- o ELF x64 - Advanced Heap Exploitation - Heap Leakless & Fortified
- o ELF x64 - Blind ROP
- x ELF x64 - Browser exploit - BitString
- x ELF ARM64 - Multithreading
89%
Cracking
2015 Points59 / 66
- o ELF x86 - 0 protection
- o ELF x86 - Basique
- o PE x86 - 0 protection
- o ELF C++ - 0 protection
- o Godot - 0 protection
- o PE DotNet - 0 protection
- o APK - Introduction
- o ELF MIPS - Basic Crackme
- o ELF x64 - Golang basique
- o ELF x86 - Fake Instructions
- o ELF x86 - Ptrace
- o Godot - Bytecode
- o WASM - Introduction
- o APK - Flutter Debug
- o ELF ARM - Basic Crackme
- o ELF x64 - Basic KeygenMe
- o Gestion de sauvegarde sous Unity3D
- o Godot - Mono
- o PE DotNet - Basic Anti-Debug
- o PE DotNet - Basic Crackme
- o PYC - ByteCode
- o ELF x86 - Pas de points d’arrêt logiciels
- o Lua - Bytecode
- o MachO x64 - keygenme or not
- o ELF ARM - crackme 1337
- o ELF x86 - CrackPass
- o ELF x86 - ExploitMe
- o ELF x86 - Random Crackme
- o GB - Basic GameBoy crackme
- o PDF - Javascript
- o PE x86 - Xor Madness
- o Powershell DeObfuscation
- o ELF ARM - Crypted
- o ELF x64 - Automatisation du crackme
- o Godot - Modèle 3D
- x NRO ARM - Switch homebrew
- o PE x86 - SEHVEH
- o APK - Anti-debug
- o APK - Insomni’Droid
- o ELF x64 - Rust backdoor
- o ELF x64 - Rust Crackme
- o PE x64 - UEFI Secure Boot
- o APK - Root My Droid
- o ELF x64 - Nanomites - Introduction
- o ELF x86 - Anti-debug
- o PE DotNet - KeygenMe
- o PE x64 - Bazar dans les tables
- o PE x86 - AutoPE
- o PYC - Self Modifying (Byte)Code
- o PYC - Snakeygen
- o ELF x86 - KeygenMe
- x HackerMan
- x Unity - Mono - Basic Game Hacking
- o WASM - Trouvez le PNJ
- o Bash - VM
- o ELF x64 - KeyGenMe
- o ELF x64 - Anti-debug et equations
- x Unity - IL2CPP - Basic Game Hacking
- o ELF x64 - Nanomites
- o ELF x86 - Packed
- o PE x86 - RunPE
- o ELF x86 - VM
- o ELF x64 - Hidden Control Flow
- x Ringgit
- x Voracious Nanomites
- x White-Box Cryptography #2
86%
Cryptanalyse
1710 Points60 / 70
- o Encodage - ASCII
- o Encodage - UU
- o Hash - DCC
- o Hash - DCC2
- o Hash - LM
- o Hash - Message Digest 5
- o Hash - NT
- o Hash - SHA-2
- o Chiffrement par décalage
- o CISCO - Salted Password
- o Décomposition pixelisée
- o ELF64 - Chiffrement avec le PID
- o Fichier - PKZIP
- o Substitution monoalphabétique - César
- o Circular Bit Shift
- o Clair connu - XOR
- o Code - Pseudo Random Number Generator
- o Encodage - Codebook
- o Fichier - PKZIP 2
- o File - Insecure storage 1
- o Substitution polyalphabétique - Vigenère
- o Système - Android lock pattern
- o Transposition - Rail Fence
- o AES - CBC - Bit-Flipping Attack
- o AES - ECB
- o AES - ECB - Copy Paste
- o LFSR - Clair connu
- o RSA - Factorisation
- o RSA - Oracle de déchiffrement
- o Service - Timing attack
- o Substitution monoalphabétique - Polybe
- o Twisted secret
- o Vecteur d’initialisation
- o Chiffre de Hill
- o GEDEFU
- o OTP - Erreur d’implémentation
- o RSA - Clé privée corrompue 1
- o RSA - Fractions continues
- o RSA - Modules communs
- o Service - Hash length extension attack
- o Shamir Secret Sharing - Introduction
- o AES - 4 tours
- o ECDSA - Introduction
- o RSA - Padding
- o RSA - Signature
- x Shamir Secret Sharing - Traitor
- o AES128 - CTR
- o PHP - mt_rand
- o Problème du logarithme discret
- o RSA - Clé privée corrompue 2
- o RSA - Clé privée corrompue 3
- o RSA - Multiples destinataires
- o AES - Attaque par fautes #1
- x FEAL - Cryptanalyse différentielle
- o Machine Enigma
- x Side Channel - AES : CPA
- o ECDHE
- o RSA - H-rabin
- o RSA - Lee cooper
- o Service - CBC Padding
- x Side Channel - AES : premier round
- o Substitution polyalphabétique - Masque jetable
- o White-Box Cryptography
- x AES - Variante affaiblie
- x Shamir Secret Sharing - Reduction
- x Hash - SHA-3
- o AES - Attaque par fautes #2
- x Shamir Secret Sharing - Irreductible ?
- x AES-PMAC
- x ECDSA - Erreur d’implémentation
93%
Forensic
1455 Points41 / 44
- o Fichier supprimé
- o Capture moi ça
- o Command & Control - niveau 2
- o MasterKee
- o Oh My Grub
- o Docker layers
- o Windows - LDAP User KerbeRoastable
- o Windows - NTDS Extraction de secrets
- o Analyse de logs - attaque web
- o Command & Control - niveau 5
- o Supply chain attack - Docker
- o Trouvez le chat
- o Vilain petit canard
- o Windows - LDAP User ASRepRoastable
- o Active Directory - GPO
- o Command & Control - niveau 3
- o Exfiltration DNS
- o Open My Vault
- o Web3 - Mets ton masque - Etape 1
- o C2 Mythic
- o Command & Control - niveau 4
- o Entretien à l’ANSSI
- o Keylogger maison
- o macOS - Keychain
- o Macro Word malveillante
- o Ransomware Android
- o Supply chain attack - Python
- o Exfiltration air-gap
- o iOS - Introduction
- x The Artist
- o Multi-devices
- o Command & Control - niveau 6
- o Find me
- o Rootkit - Cold case
- o Second entretien à l’ANSSI
- o Web3 - Mets ton masque - Etape 2
- o Find me again
- o Find me back
- o Find me on Android
- o Zeus Bot
- o Try again
- o The Lost Case - Investigation Mobile
- x Remote Support
- x Try again 2
93%
Programmation
870 Points27 / 29
- o TCP - Retour au collège
- o TCP - Chaîne encodée
- o TCP - La roue romaine
- o TCP - Uncompress Me
- o CAPTCHA me if you can
- o Deep Learning - Introduction
- o Ethereum - Tutoreum
- o Suite mathématique
- o ELF x64 - Shellcoding - Sheep warmup
- o Ethereum - tx.origin
- o Solveur de polynômes du second degré
- o Ethereum - Takeover
- o Multiples encodages
- o Apprenti Scraper
- o ARM - Shellcoding - Egg hunter
- o Ethereum - Bunker
- o Ethereum - NotSoPriv8
- x Adversarial Attack - GAN
- o Deep Learning - Captcha
- o ELF x64 - Shellcoding - Polymorphism
- o Ethereum - Architecte
- o Ethereum - Reentrancy
- o Quick Response Code
- o WinKern x64 - shellcoding : vol de token
- o Ethereum - BadStack
- o ELF x64 - Sandbox shellcoding
- o Ethereum - King of the EVM
- o ELF x86 - Shellcoding - Alphanumeric
- x Adversarial Attack - Prison Break
77%
Réaliste
2320 Points46 / 60
- o Eh oui, parfois
- o End Droid
- o Windows - KerbeRoast
- o ComCyber - Challenge
- o P0wn3d
- o Windows - ASRepRoast
- o Windows - Group Policy Preferences Passwords
- o The h@ckers l4b
- o Windows - ZeroLogon
- o Néonazi à l’intérieur
- o Windows - krbtgt history
- o Windows - sAMAccountName spoofing
- o Mersenne with 2
- o Bash/Awk - parsing netstat
- o Breaking Root-Me like it’s 2020
- o PyRat Enchères
- o Root them
- o IPBX - call me maybe
- o Marabout
- o Root-We
- o Starbug Bounty
- o Ultra Upload
- o Well-known
- o A bittersweet shellfony
- o Bash - System Disaster
- o Django unchained
- o Imagick
- o MALab
- x SSHocker
- o Web TV
- o DasBox1 : du Rififi chez les hommes-lézards
- o SamBox v2
- o SamCMS
- x BBQ Factory - First Flirt
- o Extractor
- x Getting root Over it !
- x reCOINier
- o Texode
- x BBQ Factory - Back To The Grill
- x Dans ton Kube
- o DjangocatZ
- o Red Pills
- o Root Me, for real
- o SamBox v1
- o SAP Pentest 007
- o Crypto Secure
- o Hôpital Bozobe
- x SamBox v3
- o ARM FTP Box
- x Bohemian RhapC2
- x I’m a Bl4ck H4t
- o SAP Pentest 000
- x Texode Back
- o Bluebox 2 - Pentest
- x Nodeful
- x Matrix terminal
- o Bluebox - Pentest
- o C comme C-curisé
- x Highway to shell
- x SamBox v4
91%
Réseau
705 Points30 / 33
- o FTP - Authentification
- o TELNET - authentification
- o ETHERNET - trame
- o Kerberos - Authentification
- o NTLM - Authentification
- o Authentification twitter
- o Bluetooth - Fichier inconnu
- o CISCO - mot de passe
- o DNS - transfert de zone
- o IP - Time To Live
- o LDAP - null bind
- o OSPF - Authentification
- o POP - APOP
- o RF - AM Transmission
- o Extraction de données
- o RF - FM Transmission
- o RF - Key Fixed Code
- o SIP - Authentification
- o ETHERNET - Transmission altérée
- o Trafic Global System for Mobile communications
- o HTTP - DNS Rebinding
- o SSL - échange HTTP
- o Netfilter - erreurs courantes
- o SNMP - Authentification
- o Wired Equivalent Privacy
- o Charge ICMP
- o ARP Spoofing - Écoute active
- o XMPP - Authentification
- x RF - Transmission satellite
- o WPA2 - Enterprise
- o ARP Spoofing - L’homme du milieu
- x RF - Bande L
- x WPA3 - SAE
96%
Stéganographie
465 Points22 / 23
- o EXIF - Metadata
- o Point à la ligne
- o Steganomobile
- o Twitter Secret Messages
- o TXT - George et Alfred
- o WAV - Analyse de bruit
- o Poem from Space
- o Points jaunes
- o EXIF - Miniature
- o Mimic - Dummy sight
- o WAV - Analyse spectrale
- o APNG - Just A PNG
- o Crypt-art
- o ELF x64 - Duality
- o PDF - Embedded
- o Genius ID
- o Kitty spy
- o PNG - Least Significant Bit
- o PNG - Pixel Indicator Technique
- o PNG - Pixel Value Differencing
- o Angecryption
- o Base Jumper
- x Hide and seek
93%
Web - Client
1625 Points39 / 42
- o HTML - boutons désactivés
- o Javascript - Authentification
- o Javascript - Source
- o Javascript - Authentification 2
- o Javascript - Obfuscation 1
- o Javascript - Obfuscation 2
- o Javascript - Native code
- o Javascript - Webpack
- o Javascript - Obfuscation 3
- o XSS - Stockée 1
- o AST - Deobfuscation
- o CSP Bypass - Inline code
- o CSP Bypass - Nonce 2
- o CSRF - 0 protection
- o Web Socket - 0 protection
- o XSS DOM Based - Introduction
- o Flash - Authentification
- o XSS DOM Based - AngularJS
- o XSS DOM Based - Eval
- o CSP Bypass - Dangling markup
- o CSP Bypass - JSONP
- o CSRF - contournement de jeton
- o XSS - Volatile
- o CSP Bypass - Dangling markup 2
- o CSP Bypass - Nonce
- o CSS - Exfiltration
- o Javascript - Obfuscation 4
- x Relative Path Overwrite
- o XSS - Stockée 2
- o XSS DOM Based - Filters Bypass
- o Self XSS - DOM Secrets
- x CSPT - The Ruler
- o DOM Clobbering
- o Javascript - Obfuscation 6
- o Self XSS - Race Condition
- o Browser - bfcache / disk cache
- o HTTP Response Splitting
- o Javascript - Obfuscation 5
- o XS Leaks
- o XSS - Stored - contournement de filtres
- o XSS - DOM Based
- x Same Origin Method Execution
97%
Web - Serveur
2930 Points93 / 96
- o HTML - Code source
- o HTTP - Contournement de filtrage IP
- o HTTP - Open redirect
- o HTTP - User-agent
- o Mot de passe faible
- o PHP - Injection de commande
- o API - Broken Access
- o Fichier de sauvegarde
- o HTTP - Directory indexing
- o HTTP - Headers
- o HTTP - POST
- o HTTP - Redirection invalide
- o HTTP - Verb tampering
- o Install files
- o Nginx - Alias Misconfiguration
- x Nginx - Root Location Misconfiguration
- o API - Mass Assignment
- o CRLF
- o File upload - Double extensions
- o File upload - Type MIME
- o Flask - Unsecure session
- o GraphQL - Introspection
- o HTTP - Cookies
- o Insecure Code Management
- o JWT - Introduction
- o XSS - Server Side
- o Directory traversal
- o File upload - Null byte
- o JWT - Jeton révoqué
- o JWT - Secret faible
- o JWT - Unsecure File Signature
- o PHP - assert()
- o PHP - Configuration Apache
- o PHP - Filters
- o PHP - Register globals
- o PHP - Remote Xdebug
- o Python - Server-side Template Injection Introduction
- o File upload - ZIP
- o Flask - Development server
- o GraphQL - Injection
- o Injection de commande - Contournement de filtre
- o Java - Server-side Template Injection
- o JWT - Clé publique
- o JWT - Header Injection
- o Local File Inclusion
- o Local File Inclusion - Double encoding
- x Nginx - SSRF Misconfiguration
- o Node - Eval
- o PHP - Loose Comparison
- o PHP - preg_replace()
- o PHP - Type juggling
- o Remote File Inclusion
- o SQL injection - Authentification
- o SQL injection - Authentification - GBK
- o SQL injection - String
- o XSLT - Exécution de code
- o Elixir - EEx
- o JWT - Unsecure Key Handling
- o LDAP injection - Authentification
- o Node - Serialize
- o NoSQL injection - Authentification
- o PHP - Path Truncation
- o PHP - Sérialisation
- o SQL injection - Numérique
- o SQL Injection - Routed
- o SQL Truncation
- o XML External Entity
- o XPath injection - Authentification
- o Yaml - Deserialization
- o API - Broken Access 2
- o GraphQL - Backend injection
- o GraphQL - Mutation
- o Java - Spring Boot
- o Local File Inclusion - Wrappers
- o PHP - Eval
- o PHP - Eval - Contournement de filtres avancés
- o SQL injection - Error
- o SQL injection - Insert
- o SQL injection - Lecture de fichiers
- o XPath injection - String
- o File upload - Polyglot
- o NodeJS - Prototype Pollution Bypass
- o NoSQL injection - En aveugle
- o SQL injection - Time based
- o Java - Custom gadget deserialisation
- o NodeJS - vm escape
- o Server Side Request Forgery
- o SQL injection - En aveugle
- o LDAP injection - En aveugle
- o PHP - Unserialize overflow
- o PHP - Unserialize Pop Chain
- o SQL Injection - Second Order
- x Python dotenv
- o Python - SSTI contournement de filtres en aveugle
- o XPath injection - En aveugle
- o SQL injection - Contournement de filtres