DefCamp Quals 2024 — CTF Infrastructure Vulnerability13 October 2024·374 words·2 minsAugustoDefCamp 2024 Infra Kubernetes Gcp Cloud PwnFrom a popped shell to full Kubernetes cluster compromise — exploiting GCP metadata, kubelet credentials, and CSR auto-approval to bypass RBAC.
LA CTF 2024 — Jason Web Token17 February 2024·275 words·2 minsAugusto , RickbonavigoLA CTF 2024 Web Crypto Jwt Type-Juggling PythonAbusing Python’s floating point arithmetic to forge JWT-like tokens — when float(‘inf’) meets type juggling.