Posts by Emil Lerner
IPPS write-up (FAUST CTF 2020)
We’ve recently participated in Faust 2020 as part of MoreBushSmokedWhackers team and took the first place. We were first to solve the IPPS service (which was also the first blood of the game as a whole). This blog post covers the service itself, the vulnerabilities and the exploitation details.
Master of PHP writeup (Real World CTF 2019)
GoogleCTF 2019 GPhotos writeup
The challenge is an image storage service implemented as a PHP script. The source can be retrieved via a hidden link on the main page. The script is running inside Apache.