DefCamp Quals 2024 — CTF Infrastructure Vulnerability13 October 2024·374 words·2 minsAugustoDefCamp 2024 Infra Kubernetes Gcp Cloud PwnFrom a popped shell to full Kubernetes cluster compromise — exploiting GCP metadata, kubelet credentials, and CSR auto-approval to bypass RBAC.
Insomni'hack Teaser 2024 — Vaulty20 January 2024·762 words·4 minsCubikMan47Insomni'hack 2024 Pwn Format-String Rop Buffer-OverflowExploiting a format string vulnerability to leak the canary and libc, then ROP to shell via a buffer overflow in a password manager binary.