<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on Pwn-la-Chapelle</title><link>https://pwn-la-chapelle.eu/posts/</link><description>Recent content in Posts on Pwn-la-Chapelle</description><generator>Hugo</generator><language>en-US</language><copyright>{year}</copyright><lastBuildDate>Tue, 14 Apr 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://pwn-la-chapelle.eu/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Intro Workshops 2026</title><link>https://pwn-la-chapelle.eu/posts/intro_26ss/</link><pubDate>Tue, 14 Apr 2026 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/intro_26ss/</guid><description>&lt;p>Are you interested in CTFs and Cybersecurity? Do you want to get started, but don&amp;rsquo;t know how?&lt;br>
We are thrilled to announce that we will be hosting a series of introductory workshops this semester!&lt;/p></description></item><item><title>Author Writeup – Haix-La-Chapelle CTF 2025: Ghostbusters</title><link>https://pwn-la-chapelle.eu/posts/hlc2025_ghostbusters/</link><pubDate>Mon, 08 Dec 2025 01:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/hlc2025_ghostbusters/</guid><description>&lt;p>This is a writeup for the challenge &amp;ldquo;Ghostbusters&amp;rdquo; I submitted to Haix-La-Chapelle CTF 2025, which was the first CTF challenge I&amp;rsquo;ve ever created.
I often see Ghostscript used in the wild in various ways in pentests, which is why I wanted to write a challenge about it for quite a while.
If you are interested in this topic, my colleagues and I have also written a &lt;a href="https://blog.redteam-pentesting.de/2023/ghostscript-overview/">blog post about Ghostscript exploiting&lt;/a> and published some useful &lt;a href="https://github.com/RedTeamPentesting/postscript_blog_examples">exploit scripts for attacking Ghotscript&lt;/a>.&lt;/p></description></item><item><title>Writeup - GlacierCTF 2025: typstmk</title><link>https://pwn-la-chapelle.eu/posts/glacierctf2025_typstmk/</link><pubDate>Mon, 24 Nov 2025 21:34:53 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/glacierctf2025_typstmk/</guid><description>&lt;p>A misc challenge by &lt;strong>ecomaikgolf.com&lt;/strong>, solved by &lt;strong>Trayshar&lt;/strong> (with support from &lt;strong>Romern&lt;/strong>, &lt;strong>vincentscode&lt;/strong>)&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>The cutting-edge Typst build tool, now with extra compilations!&lt;/p></description></item><item><title>Haix-la-Chapelle 2025</title><link>https://pwn-la-chapelle.eu/posts/haix_announcement_25/</link><pubDate>Wed, 08 Oct 2025 16:20:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/haix_announcement_25/</guid><description>&lt;p>We are happy to announce that we will be hosting our first ever CTF, Haix-la-Chapelle 2025, on the 29th of November!
It will be a Jeopardy style CTF and will start at 10 am Berlin time, lasting for 24 hours.&lt;/p></description></item><item><title>Writeup – GPN CTF 2025: Honeypot</title><link>https://pwn-la-chapelle.eu/posts/gpn2025_honeypot/</link><pubDate>Mon, 23 Jun 2025 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/gpn2025_honeypot/</guid><description>&lt;p>&lt;em>TLDR: Our commands trigger eBPF syscall hooks which each correspond to a move in a labyrinth. Once we beat the labyrinth, the hook decrypts the flag.&lt;/em>&lt;/p></description></item><item><title>Writeup – GPN CTF 2025: Paranoid</title><link>https://pwn-la-chapelle.eu/posts/gpn2025_paranoid/</link><pubDate>Sun, 22 Jun 2025 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/gpn2025_paranoid/</guid><description>&lt;h2 id="challenge-overview">Challenge Overview&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Name&lt;/strong>: Paranoid&lt;/li>
&lt;li>&lt;strong>Category&lt;/strong>: Crypto&lt;/li>
&lt;li>&lt;strong>Points&lt;/strong>: 383/500&lt;/li>
&lt;li>&lt;strong>Solves&lt;/strong>: 6&lt;/li>
&lt;li>&lt;strong>Author&lt;/strong>: Alkalem&lt;/li>
&lt;li>&lt;strong>Challenge Files&lt;/strong>: &lt;a download="paranoid" href="paranoid.tar.gz">paranoid.tar.gz&lt;/a>&lt;/li>
&lt;li>&lt;strong>Flag Format&lt;/strong>: &lt;code>GPNCTF{…}&lt;/code>&lt;/li>
&lt;/ul>
&lt;p>We are presented with a pseudo-random number generator that implements a linear congruential generator (LCG) with parameters that are themselves randomly generated at program start.&lt;/p></description></item><item><title>Writeup – bi0s CTF 2025: dont_whisper</title><link>https://pwn-la-chapelle.eu/posts/bi0s2025_dontwhisper/</link><pubDate>Mon, 09 Jun 2025 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/bi0s2025_dontwhisper/</guid><description>&lt;h2 id="1-challenge-overview">1. Challenge Overview&lt;/h2>
&lt;blockquote>
&lt;p>many say that neural networks are non deterministic and generating mappings between input and output is non TRIVIAL&lt;/p></description></item><item><title>Intro Workshops 2025</title><link>https://pwn-la-chapelle.eu/posts/intro_25ss/</link><pubDate>Mon, 07 Apr 2025 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/intro_25ss/</guid><description>&lt;p>Are you interested in CTFs and Cybersecurity? Do you want to get started, but don&amp;rsquo;t know how?&lt;br>
We are thrilled to announce that we will be hosting five introductory workshops this semester!&lt;/p></description></item><item><title>Deutsche Hacking Meisterschaft 2024</title><link>https://pwn-la-chapelle.eu/posts/dhm_2024/</link><pubDate>Thu, 18 Jul 2024 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/dhm_2024/</guid><description>&lt;p>From July 10th to July 12th, we had the chance to participate in the first edition of the &lt;a href="https://hacking-meisterschaft.de/">Deutsche Hacking Meisterschaft (DHM)&lt;/a> in Bonn. This is the joint finals of the &lt;a href="https://cybersecurityrumble.de">Cyber Security Rumble&lt;/a> and the &lt;a href="https://cscg.de">Cyber Security Challenge Germany&lt;/a>.&lt;/p></description></item><item><title>Writeup - Deutsche Hacking Meisterschaft 2024: Parse my Postgres</title><link>https://pwn-la-chapelle.eu/posts/dhm2024_parsemypostgres/</link><pubDate>Tue, 16 Jul 2024 12:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/dhm2024_parsemypostgres/</guid><description>&lt;p>A web challenge by &lt;strong>0x4D5A&lt;/strong>, solved by &lt;strong>Vincent&lt;/strong>, &lt;strong>Sven&lt;/strong> and &lt;strong>Trayshar&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>Ever found an 0-day in a 20k stars GitHub project? You can do now! A recent security advisory of the &lt;a href="https://github.com/parse-community/parse-server/">Parse Server&lt;/a> disclosed a critical SQL injection vulnerability. The mitigation:&lt;/p></description></item><item><title>Writeup - Deutsche Hacking Meisterschaft 2024: Cute Big Cats</title><link>https://pwn-la-chapelle.eu/posts/dhm2024_cutebigcats/</link><pubDate>Tue, 16 Jul 2024 08:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/dhm2024_cutebigcats/</guid><description>&lt;p>A crypto challenge by &lt;strong>0x4D5A&lt;/strong> and &lt;strong>Rugo&lt;/strong>, solved by &lt;strong>Euph0r14&lt;/strong> and &lt;strong>Trayshar&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>Who doesn&amp;rsquo;t love Cute Big Cats? But the most beloved cat is the &amp;ldquo;flag cat&amp;rdquo;, only visibile to the admin user. Go grab it!&lt;/p></description></item><item><title>Writeup - Cyber Security Rumble 2024: Conspiracy Social</title><link>https://pwn-la-chapelle.eu/posts/csr2024_conspiracysocial/</link><pubDate>Sat, 18 May 2024 16:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/csr2024_conspiracysocial/</guid><description>&lt;p>A web challenge by &lt;strong>lukas&lt;/strong>, solved by &lt;strong>Euph0r14, Danptr, Vincent&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>Always wanted to start your own Conspiracy but got overwhelmed managing all the secret handshakes and passwords with your fellow conspirators? Then Conspiracy Social is the solution you&amp;rsquo;re looking for. We take all the hassle out of managing secret handshakes. With us you can always be sure that your conversation partner is who he pretends to be.&lt;/p></description></item><item><title>Writeup - Cyber Security Rumble 2024: MyFirstPythonSite</title><link>https://pwn-la-chapelle.eu/posts/csr2024_myfirstpythonsite/</link><pubDate>Sun, 12 May 2024 13:00:00 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/csr2024_myfirstpythonsite/</guid><description>&lt;p>A web challenge by &lt;strong>lukas2511&lt;/strong>, solved by &lt;strong>Euph0r14, Danptr, Svido, nikgame33&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>I&amp;rsquo;ve heard PHP is insecure, so I started writing my first website in Python instead!&lt;/p></description></item><item><title>Writeup - UMDCTF 2024: TripleDES</title><link>https://pwn-la-chapelle.eu/posts/umdctf2024_tripledes/</link><pubDate>Fri, 03 May 2024 21:16:23 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/umdctf2024_tripledes/</guid><description>&lt;p>A crypto challenge by &lt;strong>clam&lt;/strong>, solved by &lt;strong>Trayshar&lt;/strong> and &lt;strong>Euph0r14&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>Before the Kwisatz Haderach, the Bene Gesserit used this oracle to predict the future.&lt;/p></description></item><item><title>Writeup - UMDCTF 2024: PaddingOracle</title><link>https://pwn-la-chapelle.eu/posts/umdctf2024_paddingoracle/</link><pubDate>Fri, 03 May 2024 19:16:23 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/umdctf2024_paddingoracle/</guid><description>&lt;p>A crypto challenge by &lt;strong>lily&lt;/strong>, solved by &lt;strong>Trayshar&lt;/strong> and &lt;strong>Euph0r14&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>The Baron used AES128-CBC with PKCS#7 to hide the flag. Can you recover the flag using his padding oracle?&lt;/p></description></item><item><title>Writeup - DamCTF 2024: Tarrible Storage</title><link>https://pwn-la-chapelle.eu/posts/damctf2024_tarrible/</link><pubDate>Sun, 28 Apr 2024 07:34:53 +0000</pubDate><guid>https://pwn-la-chapelle.eu/posts/damctf2024_tarrible/</guid><description>&lt;p>A web challenge by &lt;strong>M1ll_0n&lt;/strong>, solved by &lt;strong>Trayshar&lt;/strong>&lt;/p>
&lt;h2 id="challenge">Challenge&lt;/h2>
&lt;blockquote>
&lt;p>Move over google drive, there&amp;rsquo;s a new file storage service in town: &lt;code>http://tarrible-storage.chals.kekoam.xyz&lt;/code>&lt;/p></description></item></channel></rss>