TG:HACK CTF 2020 - Web

6 minute read

TG:HACK CTF 2020 has been very interesting and intellectually challenging. It made me bang my head on the desk repeatedly in the hopes of numbing the pain of not being able to solve some of the challenges. In the end, I managed to figure out all but the two of the hardest challenges. My writeups are intended to cover the whole process of solving a challenge, so if you don’t want a detailed explanation, just scroll to the payloads.

CySA+ Tips and Tricks (CS0-001)

10 minute read

Less than a year after passing the Security+, I can finally proudly say that I passed CySA+ as well. I set my sights on this exam the same day I passed the Security+ and I focused on studying for it extensively over the past two months. I passed it with 845 out of 900 and was really surprised at how well it went despite the fact that CompTIA recommends you to have 3-4 years of technical experience minimum. I’ve got 0. I have no IT or Security work experience, but what I do have is determination and the will to succeed. If such an underqualified 20 year old could pass this exam thanks to those two things, you can as well. The purpose of this blogpost is to share some of the things I found helpful during my studies for it. I explored a diverse range of study materials and I will tell you which ones worked for me and which ones didn’t.

Security+ Tips and Tricks

8 minute read

Security+ is an industry standard certfication that is very popular and held in high regard. CompTIA recommends you to have an Network+ level of knowledge combined with two years of IT administration experience with a focus in Security before you go for this exam, but that is nothing more than a recommendation. You can easily pass this exam with no IT work experience and without a Network+ behind you. I did and so can you. I initially passed this exam in December of 2018, but over time i realized that my tips and tricks were too surface-level, so i rewrote my blogpost entirely with extra information for you. I hope you find it at least remotely useful.

NeverLAN CTF 2019 - Web

15 minute read

Today NeverLAN CTF concluded with my team being somewhere in the top 1/4 out of 1600+ teams. I have learned a bunch about SQL and JavaScript, so to me it was time well spent. I spent most of it on Web Application challenges, as those seem to be the thing that interests me most and i would like to explain how they are all solved. Since this CTF was aimed at middle schoolers, that will be the level that i will explain the solutions on. The writeups will go as a narrative, with me explaining concepts as the challenges go. One of the challenges requires that you use Kali Linux, as it is an operating system created for those who test and implement network and computer security and it is good if you learn it. These writeups assume a certain level of computer knowledge and as much as i would like to, i can’t explain everything, as this article would become endless. Some of the stuff is linked for you to read up on in different sources, some of it you can google. With that said, let’s begin.

FireShell CTF 2019 - Bad Injections

4 minute read

Today FireShell CTF 2019 wrapped up and ended. I had fun and i learned a lot. Coming into the ctf, i was expecting something a little more complicated than trivial, however it proved to be quite a challenge for my first ever serious ctf attempt. I decided to take on the most solved Web Application challenge called “Bad Injections”. With the help of my amazing friends and fellow contenders i came close to solving it, but ran out of energy at 2AM, 2 hours away from the end of the ctf.