RESEARCHNODE / FIELD NOTES

Writeups.

Full technical notes from challenges solved by the team.

8 WRITEUPS

aiscrimination dctf 2026 writeup

DefCamp D-CTF Aiscrimination writeup covering CSS injection, server-side @import processing, path traversal through resolved theme paths, and arbitrary file read to retrieve the flag.

webcss-injectionlfi
READ MORE

bitdebit2 dctf 2026 writeup

DefCamp D-CTF BitDebit² writeup covering a single-bit arbitrary flip, FSOP and JOP through glibc FILE structures, setcontext-based code execution, and a seccomp ABI bypass to recover the flag.

reverse
READ MORE

arbitrary funds sweep dctf 2026 writeup

DefCamp D-CTF Arbitrary Funds Sweep writeup covering CREATE2 address reuse across L1 and L2, reproducing the owner contract at the expected address, and draining the vault through the deployed Saylor contract.

blockchain
READ MORE

legacy dctf 2026 writeup

DefCamp D-CTF Legacy writeup covering a localhost-only root note service, unsafe raw note uploads, a Python 2 JSON parsing DoS, cron-triggered gcore memory dumps, root password recovery from process memory, and final privilege escalation via SUID su.

privesclinux
READ MORE

sea of theft dctf 2026 writeup

DefCamp D-CTF Sea of Theft: Pirate.io writeup covering WASM reverse engineering, hidden asset extraction, an exposed old dev release, and a client-trust bug that lets players bypass movement restrictions to obtain all three flags.

webgame
READ MORE

defcamp supply dctf 2026 writeup

DefCamp D-CTF Supply writeup covering a race condition in the daily credit redemption system, bypassing the credit limit with concurrent requests from multiple IPs, purchasing the Zero Day Debugger, and exploiting command injection to retrieve the flag.

webcommand-injectionrace-conditions
READ MORE

coreweb dctf 2026 writeup

DefCamp D-CTF CoreWeb writeup covering Chromium version disclosure, exploitation of CVE-2025-0291, reverse shell access, and retrieving the flag from the challenge container.

webrcessrfcve
READ MORE

dungeon dctf 2026 writeup

DefCamp D-CTF Dungeon writeup: Drupal 10 JSON:API SQL injection, PostgreSQL file read with pg_read_file, admin login token forgery, and remote code execution through a custom ArcaneLoad module.

websqli
READ MORE