CTF Community | Hints
Open in Telegram
This channel has been created to share some of the good stuff in solving the CTF challenges. Our try will be to put writeup to some of the CTF challenges.
Show moreThe country is not specifiedEducation99 541
1 254
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
MazeWalker
MazeWalker’s goal is to reduce malware analysis time by automating runtime data collection and better visualization eventually helping a researcher to concentrate on static analysis and less on its dynamic part.
https://github.com/0xPhoeniX/MazeWalker
#re #ida #malware
@ctfplay
PhpSploit is a remote control framework, aiming to provide a stealth interactive shell-like connection over HTTP between client and web server. It is a post-exploitation tool capable to maintain access to a compromised web server for privilege escalation purposes.
https://github.com/nil0x42/phpsploit
#Web
#Pentest
@ctfplay
API Security Testing
Part-One
https://medium.com/datadriveninvestor/api-security-testing-part-1-b0fc38228b93
Part-Two
https://medium.com/@saumyaprakashrana_51250/api-security-testing-part-2-67ae9fb9c12
#API
#Pentest
#Web
@ctfplay
Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.
https://github.com/aaronhnatiw/race-the-web
#Web
#Api
@ctfplay
Practical Approaches for Testing and Breaking JWT Authentication
https://mazinahmed.net/blog/breaking-jwt/
#Web
#Article
@ctfplay
Malware Analysis — Tools And Resources
https://medium.com/@NasreddineBencherchali/malware-analysis-tools-and-resources-16eb17666886
#Malware
#Article
@ctfplay
#Ghidra Processor for the Play Station 2's Emotion Engine MIPS based CPU
https://github.com/beardypig/ghidra-emotionengine
#Reverse
@ctfplay
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner :
https://github.com/nccgroup/tracy
#Tools
#Web
#Pentest
@ctfplay
OWASP-Nettacker/readme.md at master · ZDResearch/OWASP-Nettacker
https://github.com/zdresearch/OWASP-Nettacker/blob/master/readme.md
#Pentest
#Tools
@ctfplay
PEpper
An open source script to perform malware static analysis on Portable Executable
https://github.com/Th3Hurrican3/PEpper
#Malware
#Re
#Tools
@ctfplay
5000 Android Apps samples in four categories Adware, Ransomeware, Scareware and SMS Malware in 42 families
If you are working on Android malware detection and characterization, pls find our new dataset CICInvesAndMAl2019 which includes 5000 samples in four categories Adware, Ransomeware, Scareware and SMS Malware in 42 families.
To present the real behaviors of the Android malware in this dataset we used real cell phones instead of on emulators and followed different activation functions such as sending SMS, Calling, Interacting with malware sample, shutting down the cell phone to activate malware and passed the dormitory phase. Also, we captured malware activities immediately after installing, during interaction with, and after restarting the cellphone and interacting again.
http://205.174.165.80/CICDataset/CICInvesAndMal2019/
#Malware
#Android
@ctfplay
Deserialization Bugs in the Wild
A totally unscientific analysis of deserialization vulns found in the wild
https://medium.com/@vickieli/deserialization-bugs-in-the-wild-fe37149a7ee1
#Web
#Article
#Deserialization
@ctfplay
radare2 & Frida in OWASP Mobile Security Testing Guide
https://github.com/radareorg/r2con2019/blob/master/talks/r2_and_frida_owasp_mstg/r2_and_frida_in_the_OWASP_MSTG_Carlos_Holguera.pdf
#Mobile
#Frida
#R2
@ctfplay
- Malware Analysis 101
- Basic Static Analysis
https://medium.com/bugbountywriteup/malware-analysis-101-basic-static-analysis-db59119bc00a
#malware
@ctfplay
DefCon DFIR CTF 2019 WriteUp
https://medium.com/@ozan.unal/defcon-dfir-ctf-2019-writeup-38f168eda56b
#CTF
#Defcon
@ctfplay
