hashkitten@hash_kittenAug 28, 2023I've written another set of challenges this year and I'm really happy with how they turned out. Make sure you check out DUCTF this weekend :)DownUnderCTF@DownUnderCTFAug 25, 2023Attention ALL Hackers - We are now ONE WEEK AWAY from DUCTF 4.0! 🔥 Sign-ups are now OPEN! 🔥 play.duc.tfGIF202303190196.2K06.2K
hashkitten@hash_kittenSep 17, 2022I've written some challenges this year. Make sure you check DUCTF out! =)DownUnderCTF@DownUnderCTFSep 16, 2022You all know the drill by now! What are you waiting for! Registration is open at play.duc.tf and only 1 week till the madness starts 🔥🔥🔥GIF10116016
hashkitten@hash_kittenSep 23, 2023Replying to @PortSwiggerRes @avlidienbrunn and @fransrosenIf you additionally don't have {}, you can do "".x=location=name+""1017074490449
hashkitten@hash_kittenMar 21, 2023Replying to @Synacktiv and @_remsio_Very neat and clean writeup =)1015054630463
hashkitten@hash_kittenNov 4, 2022Replying to @intigritiBase64 encode first using php://filter, then prepend 'GIF89a' using github.com/wupco/PHP_INCL… . PHP always recognizes this as a valid image so the check will pass. Full POC: tio.run/##tVRdb4IwFH33…GitHub - wupco/PHP_INCLUDE_TO_SHELL_CHAR_DICTFrom github.com101505
hashkitten@hash_kittenDec 8, 2023Replying to @joaxcar22 chars for an alert with the empty string :)1014040404
hashkitten@hash_kittenOct 19, 2022Replying to @c3l3si4n @marcioalm and 2 othersUnfortunately iconv filter based payloads seem very dependent on the version of the underlying system iconv library101