Back to regular schedule of CTFs (almost) every weekend
Greetings fleshlings,
Summer is officially over, we have CTFs and the semester ramping up again, so we might also have more students joining us. I added the events for this month into our calendar and here's the breakdown (we always meetup at SBA Research, Floragasse 7, 5th Floor, unless mentioned otherwise):
2026-10-10: FortID CTF. We have no idea what to expect from this one, but the rating on CTFtime seems decent. We are meeting on Saturday from 10:00 onwards.
2026-10-17: Next try for Securinets CTF. In case it gets moved again, there should still be other CTFs to play. This one starts at 11:00 on Saturday, I will most likely be at SBA from 10:00 onwards already.
2026-10-24: HITCON CTF, expect hard challenges. We meet starting from 10:00 on Saturday. Unfortunately there's also Hack.lu CTF running in parallel, maybe we are lucky and Hack.lu CTF gets moved (or we do a little multi track drifting?)
Greetings h4ckers! We are again very late in the month and we haven't been doing much in September (some of us were at ACSC, some of us were at BalCCon), but we do have some important info! Namely we have FAUST CTF coming up this weekend, and it's A/D! 2026-09-26: FAUST CTF, an Attack/Defense CTF. The CTF starts at 14:00 our time, so we will slowly meet around 12:00, finish setting up infra and grab lunch....
Greetings, hopefully everyone has survived the heat so far (or fled Vienna). There is not much happening in August, be on the lookout in Mattermost for spontaneous plans. The next fixed dates are in early September: 2026-09-07: Next monthly meetup Monday, 18:30 at SBA...
Greetings hackers, here's to hoping everyone is enjoying the summer so far with temperatures not (yet) as extreme as June. Safe and enjoyable travel wishes go out to everyone who decided to leave Vienna over the summer (i can't blame you). So what's in store for this month? Well we have our first A/D CTF of the year! 2026-07-18: ENOWARS join us for some Attack/Defense CTF fun, meeting at 13:00 at SBA ideally, CTF starts at...
Pool Party “brrrrrrr” said the Platypus. It’s warm outside the water. “Time for a pool party”, it thinks. It has been a while since it met its fellow platypuses and a pool party is a clever idea to reunite. The Platypus decides to host a webserver to store the plans and figures that nginx is a good fit because it’s fast - almost as fast as the Platypus can use its 40000 electroreceptors on the bill...
Seccomp Hell Some challenges are userland pwns, others are kernel pwn, still others are sandbox escapes. In Seccomp Hell, you can get all three for free <3 Note: Try getting a full root shell for this challenge Dist TL;DR You need to exploit three parts in this challenge userland exploitation backdoor that allows ROP chain that can be used to get arbitray code execution kernel backdoor backdoor that creates CALL GATE in the LDT (local descriptor table) to get kernel mode escalation and write...
KuK Hofhackerei collaboration for DEF CON CTF Qualifiers 2024
Last weekend we grouped up with our esteemed friends from other Austrian CTF teams and participated in this year's DEF CON CTF Qualifiers under the KuK Hofhackerei mantle. The event was again hosted by nautilus.institute. Thanks for many fun challenges. In the end we were able to reach the 21st place. This year we tried a hybrid approach, with teams meeting up in Graz, Linz and Vienna and collaborating through Discord, which worked...
Introduction The service image-galoisry is a flask web server accompanied by a web GUI. On the website, users can create new image galleries, which are safeguarded by a password. Following gallery creation, users have the option to upload images, with each image undergoing encryption with AES. Notably, these galleries, while publicly accessible, only display encrypted files for download. However, should a user possess the password for a specific gallery, they have the option to instruct the...
Write an oldschool keygen for an oldschool login interface.
Google CTF 2022 presented us with oldschool, a typical, as the name suggests, oldschool crackme with an ncurses terminal interface. The goal of the challenge was to write a keygen, which would be able to generate keys for a list of users provided by the CTF organizers. The official and detailed writeup is available here, which goes through the intended solution of manually reverse engineering the key verification algorithm. However, since we are researchers (and most importantly, too lazy to manually...