Writeups
A collection of some writeups written by TJCSC
Andrew Liu
Haix-la-Chapelle 2025 - PDFBill (Misc)
11/30/2025 — 9 min readAutomating UUID hoarding to break the Cloud Bill Insurance credit limit and buy the premium voucher.Andrew Liu
PatriotCTF 2025 - Waldo's Night Out (OSINT)
11/30/2025 — 3 min readTriangulating Sterling, Reston, and Tysons for the multi-part Waldo's Night Out challengeAnsh Agrawal
LakeCTF 2025 - Attack of the Clones (Crypto)
11/28/2025 — 7 min readCrypto walkthrough for Attack of the ClonesAnsh Agrawal
LakeCTF 2025 - Ez Part (Crypto)
11/28/2025 — 8 min readCrypto walkthrough for Ez PartAnsh Agrawal
LakeCTF 2025 - Gamblecore (Web)
11/28/2025 — 5 min readWeb walkthrough for GamblecoreAnsh Agrawal
LakeCTF 2025 - Guess Flag (Crypto)
11/28/2025 — 4 min readCrypto walkthrough for Guess FlagAnsh Agrawal
LakeCTF 2025 - Quantum vernam (Crypto)
11/28/2025 — 5 min readCrypto walkthrough for Quantum vernamAnsh Agrawal
LakeCTF 2025 - Revenge of the Sith (Crypto)
11/28/2025 — 6 min readCrypto walkthrough for Revenge of the SithAnsh Agrawal
LakeCTF 2025 - The Phantom Menace (Crypto)
11/28/2025 — 4 min readCrypto walkthrough for The Phantom MenaceAndrew Liu
PatriotCTF 2025 - Where's Legally Distinct Waldo Four (OSINT)
11/27/2025 — 1 min readOSINT walkthrough for the fourth Waldo challengeAndrew Liu
PatriotCTF 2025 - Where's Legally Distinct Waldo One (OSINT)
11/27/2025 — 2 min readOSINT walkthrough for the first Waldo challengeAndrew Liu
PatriotCTF 2025 - Where's Legally Distinct Waldo Three (OSINT)
11/27/2025 — 1 min readOSINT walkthrough for the third Waldo challengeAndrew Liu
PatriotCTF 2025 - Where's Legally Distinct Waldo Two (OSINT)
11/27/2025 — 1 min readOSINT walkthrough for the second Waldo challengeBrian Ho
picoGym - SideChannel
3/1/2024 — 5 min readTiming-based side channel attack on an pin-checker programBrian Ho
picoGym - Specialer
2/20/2024 — 3 min readReading files in a sandboxed environmentDarin Mao
ASIS CTF Finals 2021 - cuuurl
1/7/2022 — 5 min readArbitrary curl to RCEDarin Mao
TetCTF 2022 - ezflag 2
1/7/2022 — 9 min readSimple ROP through a socketDarin Mao
TetCTF 2022 - magicbox
1/7/2022 — 17 min readReversing a NOR machineDarin Mao
redpwnCTF 2021 - devnull-as-a-service (pwn)
7/12/2021 — 14 min readret2dlresolve on 64-bit binaries with huge pagesDarin Mao
redpwnCTF 2021 - gelcode-2 (pwn)
7/12/2021 — 6 min readShellcode golfingDarin Mao
picoMini by redpwn 2021 - Darin's Challenges
6/21/2021 — 18 min readAuthor writeups for picoMini by redpwnDiana Lin
picoMini by redpwn 2021 - notepad (web)
5/12/2021 — 5 min readWriteup for notepad (web)Diana Lin
picoMini by redpwn 2021 - not-crypto (rev)
5/12/2021 — 2 min readWriteup for not-crypto (rev)Anna Hsu
picoMini by redpwn 2021 - advanced-potion-making (forensics)
5/11/2021 — 3 min readFixing a corrupt PNG fileAnna Hsu
picoMini by redpwn 2021 - login (web)
5/11/2021 — 2 min readClient side login seems like a bad ideaDarin Mao
ångstromCTF 2021 - Jar/Snake/Ekans
4/15/2021 — 16 min readExploiting heavily restricted pickle deserializationDarin Mao
ångstromCTF 2021 - wallstreet (pwn)
4/15/2021 — 5 min readAn unusual trick for format string exploitationDarin Mao and Daniel Wang
picoCTF 2021 - BitHug (web)
4/5/2021 — 5 min readExploiting SSRF in a complex web applicationDarin Mao
picoCTF 2021 - Stonk Market (pwn)
3/31/2021 — 7 min readTricky format string exploitationDarin Mao
picoCTF 2021 - Bizz Fuzz (pwn)
3/30/2021 — 7 min readAutomated analysis of a large binaryDarin Mao
justCTF 2020 - Pinata (pwn)
1/30/2021 — 18 min readBlind exploitation of nginx from justCTF 2020Darin Mao, Saigautam Bonam, and Autin Mitra
TJCSC Winter Contest 2020
12/16/2020 — 23 min readSolutions to selected problems from the 2020 Winter ContestDarin Mao and Stephen Huan
NACTF 2020
11/4/2020 — 14 min readRequired writeups for winning teams.Darin Mao
CSAW CTF 2020 Qualifier - blox (rev/pwn)
11/3/2020 — 13 min readThis was a two-part series from the 2020 CSAW CTF Qualifier involving a small Tetris-like game.Darin Mao
DamCTF 2020 - guess (pwn)
10/12/2020 — 3 min readThis is my writeup for the challenge "guess" in the pwn category from OSUSEC's DamCTF 2020.Darin Mao
CSAW RED 2020 Qualifier (crypto)
9/29/2020 — 3 min readSolutions for crypto challenges from the CSAW RED 2020 Qualification Round.Darin Mao
CSAW RED 2020 Qualifier (rev)
9/29/2020 — 17 min readSolutions for rev challenges from the CSAW RED 2020 Qualification Round.Darin Mao
CSAW RED 2020 Qualifier (misc)
9/29/2020 — 13 min readSolutions for misc challenges from the CSAW RED 2020 Qualification Round.Darin Mao
CSAW RED 2020 Qualifier (web)
9/29/2020 — 3 min readSolutions for web challenges from the CSAW RED 2020 Qualification Round.Darin Mao