Info - Hack.lu CTF 2025
Hack.lu CTF 2025 - Organized by FluxFingers, the CTF team of Ruhr University Bochum
Hack.βlu CTF registration is open! Win great prizes from our sponsors:
π― 3x @offensivecon.bsky.social tickets by Binary Gecko
π΅οΈ 6x @burpsuite.bsky.social
π₯· 6x @binary.ninja
π¦ 80 months HackTheBox VIP+
πΈ $1000 by Zellic
π©πͺ DHM quals
flu.xxx
16.10.2025 10:44
π 3
π 2
π¬ 1
π 0
Hej!
We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17.
Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox.
All information on flu.xxx
08.10.2025 15:04
π 4
π 3
π¬ 0
π 0
Unrelated question: Why does it say NO GLYPH at the end of each line when viewing your post in the Bluesky app? I saw this with multiple of your posts already π€
08.10.2025 01:44
π 0
π 0
π¬ 0
π 0
Looks like some Linux eBPF vulnerabilities presented at this year's Black Hat are made-up AI slop
www.openwall.com/lists/oss-se...
30.09.2025 15:16
π 82
π 20
π¬ 4
π 7
Last weekend, we took 1st place at #idekCTF and qualified for the #MaltaCTF finals!
Congrats to all the other teams, and thanks to the organizers β the CTF was a lot of fun!
05.08.2025 21:19
π 3
π 1
π¬ 0
π 0
We secured 3rd place at ENOWARS CTF - top team in the DACH region and now qualified for DHM (German Hacking Championship)!
Huge congrats to all participants and thanks to the organizers for an awesome CTF! π
19.07.2025 21:46
π 9
π 1
π¬ 0
π 0
2. should be the issue. I think innerText decides HTML entities, like < to <, which is then assigned to innerHTML.
14.07.2025 05:15
π 1
π 0
π¬ 1
π 0
Looks fine to me. Is there a pitfall with basename()?
21.05.2025 12:46
π 0
π 0
π¬ 1
π 0
"this case has been assessed as low severity and does not meet MSRCβs bar for immediate servicing due to RCE is no longer possible without extensive user interaction (i.e., accepting a save prompt to a location controlled by an attacker)"
We love to see it π«
15.05.2025 10:13
π 2
π 0
π¬ 0
π 0
It's actually free to register with a (burner) email and read the article, you don't have to pay.
05.05.2025 07:30
π 0
π 0
π¬ 0
π 0
Kiwi Farms - Wikipedia
ErgΓ€nzung zur Kiwi π₯: Es kΓΆnnte eine Anspielung auf das Kiwi Farms Forum sein, welches hauptsΓ€chlich aus extremen, organisierten harassment von trans Personen bestand.
en.m.wikipedia.org/wiki/Kiwi_Fa...
28.03.2025 11:02
π 0
π 0
π¬ 0
π 0
And here's the second part of my old JumpServer journey I presented at Insomni'hack24. After getting authenticated last week, this time we're abusing multiple design flaws to get RCE and escape the Docker container on the JumpServer host.
27.03.2025 05:11
π 2
π 0
π¬ 0
π 0
Surveillance contractors not choosing overly edgy sounding company names challenge (impossible)
24.03.2025 13:46
π 12
π 0
π¬ 0
π 0
Beanies sold out π«
21.03.2025 18:03
π 0
π 0
π¬ 0
π 0
I nominate @sonarresearch.bsky.social, now finally on bluesky :)
21.03.2025 00:26
π 2
π 0
π¬ 1
π 0
The Sonar research team just published a blog about my old JumpServer vulns I presented at Insomni'hack24. Check it out for some microservice shenanigans and stay tuned for part two that covers auth->RCE next week.
20.03.2025 16:21
π 2
π 0
π¬ 0
π 0
SAML roulette: the hacker always wins
Introduction In this post, weβll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study.
portswigger.net/research/sam...
18.03.2025 14:57
π 53
π 23
π¬ 0
π 4
The call expression check looks at the name of the variable, but not the runtime value of the called function, assuming that it is safe if named calc* We can abuse this to call the function constructor directly and not through calcCall which would block it
calcCall(calcPrint.constructor('alert(1)'))
11.03.2025 10:10
π 3
π 0
π¬ 0
π 0
The code tries to shadow all globals with local variables, but uses Object.keys to enumerate over window. Object.keys does not include non-enumerable properties, which includes globalThis. This leaves globalThis intact for us to use
11.03.2025 01:43
π 5
π 0
π¬ 1
π 0
You can use globalThis to get access to all globals again and call arbitrary global functions with the help of calcCall. Then just send innerText of the whole site to your server with fetch :)
10.03.2025 22:00
π 0
π 0
π¬ 1
π 0
Wow, thanks for 2nd place! Didn't expect this, maybe it's my sign to finally write it down in text form and tackle all the follow-up ideas π
06.02.2025 09:18
π 8
π 1
π¬ 1
π 0
CCC | 5-Punkte-Plan fΓΌr d(on't)-trust
Der Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen fΓΌr Informationsfreiheit und TechnikfolgenabschΓ€tzung.
D-Trust mΓΆchte gern von der eigenen Verantwortung fΓΌr ein groΓes Datenleck ablenken. Der CCC erklΓ€rt die HintergrΓΌnde und fordert Konsequenzen. (ja, es war mal wieder 1 von uns lol sorry)
www.ccc.de/de/updates/2...
24.01.2025 16:47
π 59
π 22
π¬ 4
π 0
They only fixed a bug that made it easier to abuse this caching info. The bug was with Cloudflare Workers and allowed to run a Cloudflare Worker at a specific data center. From there, the cache state could be retrieved.
The cache info can still be retrieved now using a VPN close to a CF datacenter
21.01.2025 16:53
π 3
π 0
π¬ 0
π 0
The voting form says that it closes on the first of February? π
21.01.2025 10:52
π 0
π 0
π¬ 1
π 0