Skip to content

CTF-Archives/HKCERTCTF2025Quals

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 

Repository files navigation

HKCERT CTF 2025 (Qualifying Round)

附件在 Releases 下载

Binary Exploitation

link start!

爆裂流星!!!! Burst meteor!!!!

a_strange_rop

二十以內的加法對小學生來說有點難了,對高中生來說有點簡單了,對大學生來說剛剛好!!! 誒,所以全對以後的獎勵呢??? Adding up to 20 is a bit difficult for elementary school students, a bit simple for high school students, and just right for college students!!! Hey, so what about future rewards???

childcode

"Some"body once claimed "the father of 4", but I have been hunting for the true number behind binary. Finally, I see the pattern. "syscall" is 0f05 (15, 5). '\n' is 10. "ret" is 0xc3 (195). These vital instructions are all multiples of 5. Therefore, 5 is the master of binary, and I have named the code "the child of 5". Do you have what it takes? Show me your childcode.

compress

smaller

filesystem

這是個能夠讀取文件的程序,來看看有沒有你想要的文件吧o( ̄▽ ̄)ブ。 This is a program that can read files. Let's see if there are any files you want o( ̄▽ ̄)ブ.

filesystem-revenge

這是個能夠讀取文件的程序,來看看有沒有你想要的文件吧o( ̄▽ ̄)ブ。 This is a program that can read files. Let's see if there are any files you want o( ̄▽ ̄)ブ.

nofile

衰了,唔單文件冇佐,伺服器的shell也連不上了,只剩下一個服務還在運行。 Decline, not only files are missing, but also the server's shell I can't connect anymore, only one service is still running.

piano

piano, pianissimo, pianississimo
The challenge environment will execute the following command to set up a restricted execution context: /chroot --userspec=1000:1000 /home/ctf /run.sh

#!/bin/sh
./qjs ./tmp.js

stop

You'd better stop and leave right now.

Cryptography

Bivariate copper

那麼問題來了,什麼是copper? So the question is, what is copper?

ComCompleXX

我最近開始迷上數學了,但這題看起來真的很複複複雜,你能幫我嗎? I've recently become obsessed with math, but this problem seems really comcomplexx. Can you help me?

EC Fun

密碼學很簡單!祝你玩得開心! Crypto is so EC! May you have fun!

LWECC

Easy ECC...and LWE maybe

Loss N

沒有那個n,我照樣可以解出flag。 Even without that n, I can still solve the flag.

POC

Easy AES Challenge

Triple Key Cipher

我實現了一個使用三個密鑰的分組密碼算法。 I implemented a block cipher algorithm that uses three keys.

Try E

e這麼大...何意味? E is so big... what does it mean?

cruel_rsa

cute rsa? oh nonono, so cruel

Miscellaneous

Chimedal's goddess

Chimedal帶上了99朵玫瑰,決定向心心念念的女神表白,可女神卻給了他一張小紙條,上面是一段奇奇怪怪的資訊,如果Chimedal能破解這段資訊的話,女神就答應跟他在一起。作為Chimedal最好的朋友的你,能否幫Chimedal抱得美人歸呢? 請注意:flag需要添加flag{}后提交,flag包含下劃綫“_”和空格“ ” Chimedal brought 99 roses, determined to confess to the goddess he had been longing for. However, the goddess gave him a small note containing a strange message. If Chimedal could decipher this message, she would agree to be with him. As Chimedal's best friend, can you help him win the heart of his beloved? Please note: The flag needs to be submitted after adding flag{} and the flag contains underscore (_) and space ( )

Deleted

Despite taking the fastest action, the suspect still noticed us and cleared the evidence from the computer before we arrived. Please help us find as many useful clues as possible. Attachment password:==###HkCert2025###== Note:

  1. Answer all of question with UTC+8 timezone.
  2. When you need to work with the registry, please be careful not to overwrite your machine's registry. You can also perform the analysis in a virtual machine. The attachment link is as follows: https://drive.google.com/file/d/1DM14noGC5YdBb4gGmPX41gM4MLlvoYZS/view?usp=sharing MD5 hash of attachment.zip: 7f559bb45323d512cf65c384009b4f31

Easy_Base

新人,學院給了你一套能殺死龍王的武器,但上面的文字好像有點看不清啊(flag格式為:flag{xx_xx}) Newcomer, the academy has given you a set of weapons capable of killing the Dragon King, but the text on them seems a bit hard to read (flag format: flag{xx_xx})

LOVE

看起來我的模型有過擬合的情況。你能幫我看看嗎? It seems like my model is overfitting. Can you take a look for me?

Little Wish

Oh, the music stopped! Alright everyone — clap along and follow my lead! We'll keep it going together!

Personal Health Assistant

Healx has developed a personal health assistant app and has decided to hire a senior AI safety expert to test the app before its launch.

Protocol

Try to Talk With Private Protocol

Questionnaire

問卷連結/Questionnaire Link: https://forms.hkcert.org/hkcertctf2025-evaluation Please note that there should be no spaces in the submitted flag.The flag format is ctf2025{}

Suspicious File

We captured a suspicious file transmitted through a covert channel, analyzed it and found out the secrets. The flag format is hkcert25{}

busbus

A device has been implanted with a backdoor, attempting to trigger it and leak sensitive information.

easyJail

Very easy pickle jail,go ahead !

Reverse Engineering

JN

怎麽有的函數看不到 Why can't some functions be seen

Wm

Have you heard of wasm

abc

bc文件是什麽 bc What is the file

box

Hello, I found a box. Could you open it

easydriver

一個簡單的驅動。 A simple driver. 注:

  • flag提交格式:flag{youget}
  • 如果系統出現藍屏,請確保自身環境純淨,本驅動不會對系統進行任何破壞性操作,盡請放心。
  • 解題推薦使用64位Win10 - Win11 22H2的虛擬機系統。 Note:
  • flag Submission format: flag{youget}
  • If the system shows a blue screen, please ensure that your environment is pure. This driver will not perform any destructive operations on the system, so please rest assured.
  • Recommended use of 64 bit for problem-solving Win10 - Win11 22H2 The virtual machine system.

easyjar

Reverse engineering a simple algorithm

easyre

Reverse a simple algorithm

eert

開始考察數據結構 Start investigating data structures

ezc

隨機密鑰怎麽辦? What about the random key? flag提交格式:flag{youget} flag Submission format: flag{youget}

findkey

鑰匙找不到了 I can't find the key

onebyone

需要解密哦 We need to decrypt it

Web Exploitation

BabyUpload

“This is a simple file upload service. The administrator said, ‘I hate the letter “P”. Anything containing “P” is not allowed in!’”

Dam Breach

“The magnificent CloudBeaver stands guard over the torrent of data.”

Labyrinth

Welcome to the labyrinth of serialization. There are no familiar Roman roads or spring gardens here—only high walls all around. Find the hidden ‘tracking’ path, and only then can you break free from the maze.

easy-lua

A Lua online executor

ezjs

Come and try some code auditing!

insph

We've developed an advanced AI data processing system that can intelligently process data from any URL. The system is already deployed on a server; can you find the hidden flag within it?

nettool

Let’s do a code audit.

newrule

Bill Jobs developed an intelligent login system, but there is a vulnerability in one of the Header headers for the login. Can you help him find the vulnerability? This is a beneficial behavior for the body.

r

object reference and pointer reference

react

The developer jumped on the trend and used the latest Next.js 15 to build the application.

renderme

“I wrote a simple page to render your name.”

About

第六届“香港网安夺旗赛2025”(HKCERT CTF)

Resources

Stars

Watchers

Forks

Packages

 
 
 

Contributors