Quan
1st place
581 points
Awards
Hint 21
hints
Hint for 3.1 File architecture
-2
Hint 18
hints
Hint for 2.4 Address - Main function
-2
Solves
| Challenge | Category | Value | Time |
| 8 - Adresa JMP ESP gadgetu | Zkouška | 10 | |
| 7 - Obsah tajné funkce | Zkouška | 10 | |
| 6 - Kontrola nad EIP registrem | Zkouška | 10 | |
| 5 - Hodnota EIP registru při pádu | Zkouška | 10 | |
| 4 - Získání Offsetu | Zkouška | 10 | |
| 10 - Konstrukce finálního payloadu | Zkouška | 5 | |
| 9 - Little Endian | Zkouška | 5 | |
| 3 - Bezpečnostní mechanismy | Zkouška | 5 | |
| 2 - Hledání v textových řetězcích | Zkouška | 5 | |
| 1 - Identifikace souboru a architektury | Zkouška | 5 | |
| 12 Pa$$w0rD | MA Fundamentals #1 | 5 | |
| 11 MITRE | MA Fundamentals #1 | 5 | |
| 10 D1r_p4tH | MA Fundamentals #1 | 5 | |
| 9 IP_$ddr3sSeS | MA Fundamentals #1 | 5 | |
| 1.4 Bad Chars | 1 - Buffer_Overflow | 5 | |
| 2 - Needle | Extra 6 (Forensics) | 20 | |
| 1 - Secret token | Extra 6 (Forensics) | 10 | |
| 1 - Suspicious Activity | Extra 9 (Network) | 20 | |
| 4.10 EDX Register | 4 - ROP | 10 | |
| 4.9 ECX Register | 4 - ROP | 10 | |
| 4.8 EBX Register | 4 - ROP | 10 | |
| 4.7 EAX Register #2 | 4 - ROP | 10 | |
| 4.6 EAX Register #1 | 4 - ROP | 10 | |
| 4.5 WriteWhatWhere Address Gadget | 4 - ROP | 10 | |
| 4.4 SysInterupt EAX value | 4 - ROP | 10 | |
| 4.3 Little endianness | 4 - ROP | 10 | |
| 4.2 Address of .bss section | 4 - ROP | 10 | |
| 4.1 Offset | 4 - ROP | 10 | |
| 3.8 Register to pass 3rd argument | 3 - Arguments_64 | 10 | |
| 3.7 Third flag argument | 3 - Arguments_64 | 10 | |
| 3.6 Second flag argument | 3 - Arguments_64 | 10 | |
| 3.5 First flag argument | 3 - Arguments_64 | 10 | |
| 3.4 Address length (x64) | 3 - Arguments_64 | 10 | |
| 3.3 Address - Flag function | 3 - Arguments_64 | 10 | |
| 3.2 Offset | 3 - Arguments_64 | 10 | |
| 3.1 File architecture | 3 - Arguments_64 | 10 | |
| 14 H4cker_Cr3ds - FINAL BO$$ | MA Fundamentals #2 | 15 | |
| 13 User_Cr3ds | MA Fundamentals #2 | 5 | |
| 11 FileEeEeEeEe | MA Fundamentals #2 | 5 | |
| 12 PosledniVecere | MA Fundamentals #2 | 5 | |
| 10 C2_Domain | MA Fundamentals #2 | 5 | |
| 9 (R3)pr0duCtiOn | MA Fundamentals #2 | 5 | |
| 8 G1tHub R4po #2 | MA Fundamentals #2 | 5 | |
| 7 G1tHub R4po | MA Fundamentals #2 | 5 | |
| 6 V3rsioN^^ | MA Fundamentals #2 | 5 | |
| 5 KolikJazykuUmisOToMinJsiBigosem | MA Fundamentals #2 | 5 | |
| 4 DataIsLoveDataIsLife | MA Fundamentals #2 | 5 | |
| 8 CMDL3T | MA Fundamentals #1 | 5 | |
| 7 Sh3LL | MA Fundamentals #1 | 5 | |
| 6 EnCrYpt10n_M3th0d | MA Fundamentals #1 | 5 | |
| 3 F1rst?Sub | MA Fundamentals #2 | 5 | |
| 2 Sha-256_H4Sh | MA Fundamentals #2 | 5 | |
| 1 Danger.zip | MA Fundamentals #2 | 5 | |
| 0.3 - Intro | 0 - Intro | 5 | |
| 2.6 Arguments | 2 - Arguments_32 | 10 | |
| 2.5 Little endianness | 2 - Arguments_32 | 10 | |
| 2.4 Address - Main function | 2 - Arguments_32 | 10 | |
| 2.3 Address - Flag function | 2 - Arguments_32 | 10 | |
| 2.2 Offset | 2 - Arguments_32 | 10 | |
| 1.7 NOP | 1 - Buffer_Overflow | 10 | |
| 2.1 File NX status | 2 - Arguments_32 | 10 | |
| 1.6 Little endianness | 1 - Buffer_Overflow | 10 | |
| 1.5 Address for jmp esp gadget | 1 - Buffer_Overflow | 10 | |
| 1.3 Overwrite the EIP register | 1 - Buffer_Overflow | 10 | |
| 1.2 Offset | 1 - Buffer_Overflow | 10 | |
| 1.1 File Type | 1 - Buffer_Overflow | 10 | |
| 5 0ff$3T | MA Fundamentals #1 | 5 | |
| 4 0r1g1nal_Fil3n4m3 | MA Fundamentals #1 | 5 | |
| 3 C0de_S1z3 | MA Fundamentals #1 | 5 | |
| 2 Created_Date | MA Fundamentals #1 | 5 | |
| 1 SHAsum | MA Fundamentals #1 | 5 | |
| 0.2 - Intro | 0 - Intro | 5 | |
| 0.1 - Intro | 0 - Intro | 5 |