$ cd sections/csaw26
CSAW26
CSAW CTF 2026 · September 2026
- event
- CSAW CTF 2026
- writeups
- 12
- site
- ctf.csaw.io ↗
CSAW CTF 2026 qualification round. Twelve challenges solved across pwn, reverse engineering, web, crypto, forensics and misc — each writeup carries the original challenge files and my solve scripts.
crypto — 1
forensics — 2
Breach: Zero Day
Three answers buried in 2.7 MB of Windows security logs, a packet capture and a memory dump — most of it synthetic filler with a fingerprint that gives it away.
Ghost in the Machine
Every packet in the capture is byte-identical. The message is in the gaps between them, and the source ports spell out the XOR key.
misc — 1
pwn — 3
Saint Vespers and the Copper Choir
A struct with a name buffer sitting directly under a called function pointer. Overwrite what you write to, on glibc 2.35 with the hooks gone.
Hells Bells
A use-after-free that leaves the pointer in the slot table: unsorted-bin libc leak, then tcache poisoning into __free_hook on glibc 2.31.
Diamond Dogs
Two object types drawn from the same heap, both freed without clearing their slot — type confusion turns a dangling dog into an arbitrary call.
rev — 1
web — 4
Low Tide
A five-stage SCADA proxy chain: deobfuscate a gateway address, forge a time-derived token, walk a virtual filesystem, authenticate to a chat bridge, then issue a control command...
Golf Heist
Rotor settings leaked in 418 response headers, fed through a three-rotor Enigma to a passphrase — then the proxy trusts a role header it should never have read.
CSALE
A Flask storefront solved black-box after the source release was pulled — unauthenticated account enumeration, an unthrottled 4-digit PIN, and a two-layer decoy built to eat you...
CSALE Revenge
The correctly deployed CSALE. Byte-identical source, but this time the intended path works: a signed 32-bit integer overflow in the checkout maths.