<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>security on CHERIEF Yassine</title>
    
    
    
    <link>https://omega-coder.github.io/tags/security/</link>
    <description>Recent content in security on CHERIEF Yassine</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>Yassine CHERIEF</copyright>
    <lastBuildDate>Wed, 24 Apr 2019 00:00:00 +0000</lastBuildDate>
    
	<atom:link href="https://omega-coder.github.io/tags/security/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>AngstromCTF 2019 Secret Sheep Society | CTF Writeup</title>
      <link>https://omega-coder.github.io/posts/angstromctf-2019-secret-sheep-society-writeup-crypto/</link>
      <pubDate>Wed, 24 Apr 2019 00:00:00 +0000</pubDate>
      
      <guid>https://omega-coder.github.io/posts/angstromctf-2019-secret-sheep-society-writeup-crypto/</guid>
      <description>
        
          
          
          
        
        
        
          Challenge details    Category Points Solves     Crypto 120 98    TL;DR  Spotting the weakness (AES with CBC Mode). Get token. Flipping specific bytes in session json (turn false to true ). manipulate token with flipped bytes. Send manipulated token to page. Get the flag.  Challenge Description  The sheep are up to no good. They have a web portal for their secret society, which we have the source for.
          
        
        </description>
    </item>
    
    <item>
      <title>Hacklab ESGI 2019 |  Rookie Web100 Writeup</title>
      <link>https://omega-coder.github.io/posts/hacklab-esgi-2019-rookie-web-writeup/</link>
      <pubDate>Mon, 08 Apr 2019 10:59:30 +0200</pubDate>
      
      <guid>https://omega-coder.github.io/posts/hacklab-esgi-2019-rookie-web-writeup/</guid>
      <description>
        
          
          
          
        
        
        
          Challenge Description    Category Points Solves     web 100 18    This is the URL for the challenge.
URL:http://ctf.hacklab-esgi.org:8082/
So, as soon as we visit the given URL, we get a simple web page saying Website Checker and the title saying super curling (this gonna be fun!!). we notice that there is one input in the page, whatever you give as input gets passed to curl as a parameter.
          
        
        </description>
    </item>
    
    <item>
      <title>Securinets CTF 2k19 Lost Flag Writeup</title>
      <link>https://omega-coder.github.io/posts/securinets-ctf-2019-lost-flag-writeup/</link>
      <pubDate>Tue, 26 Mar 2019 17:37:37 +0200</pubDate>
      
      <guid>https://omega-coder.github.io/posts/securinets-ctf-2019-lost-flag-writeup/</guid>
      <description>
        
          
          
          
        
        
        
          Description    Category Points Solves     Forensics 994 19    Description : Help me get back my flag !
URL: https://web8.ctfsecurinets.com/
After visiting the link above, we get a login page.We can login using admin/admin, but unfortunately the flag is deleted.
Then I started searching in the website for any other infos, but with no success. the admin of the challenge (Tr&#39;GFx) said that bruteforcing directories is enough to solve the challenge, so I used dirsearch.
          
        
        </description>
    </item>
    
  </channel>
</rss>