Hello ethical hackers! Today I will share with you my capture the flag writeup for H1-2006. It details my process of solving this awesome challenge organized by HackerOne.
Read more on https://thehackerish.com/capture-the-...
Follow us on Twitter: / thehackerish
Listen on Anchor: https://anchor.fm/thehackerish
Listen on Spotify: https://open.spotify.com/show/4Ht8jEb...
Listen on Google Podcasts: https://podcasts.google.com/?feed=aHR...
Listen on Breaker: https://www.breaker.audio/hack-for-fu...
Listen on PocketCasts: https://pca.st/f6ipzls4
Listen on RadioPublic: https://radiopublic.com/hack-for-fun-...
I divided this CTF writeup into several sections, each one marks a milestone in the CTF journey. Every section is further divided into smaller parts to easily describe the vulnerabilities and how I exploited them.
This CTF write-up describes a smooth path. However, the reality was totally different. The write-up doesn’t include rabbit holes I fell for when I was looking for ways to pivot inside the infrastructure. It doesn’t mention the long hours trying to figure out how to solve the Android challenges, and it certainly doesn’t talk about the sleepless nights trying to escalate the privileges, code the scripts and debug everything!
As always, stay curious, keep learning and go find some bugs!