Category: Flagvent 2025

Dive into the 2025 Flagvent CTF challenges, part of the annual festive security event.

Posts

Showing 24 posts in this category.

Flagvent 2025: Day 25

Flagvent 202540
Providing CTF feedback unlocks a prize page, where a spinning Christmas tree asset hides the flag in plain sight.

Flagvent 2025: Day 24

Flagvent 202530
Learn how xortool statistically analyses a multi-byte XOR cipher to recover a 24-byte key and reveal the plain text.

Flagvent 2025: Day 23

Flagvent 202530
Find out how to transform MusicXML measures into a 25×25 QR code grid hiding a secret CTF flag.

Flagvent 2025: Day 22

Flagvent 202510
Uncover how DNA encoding works and decode it with a simple base-to-binary mapping, turning 4-letter chunks into ASCII.

Flagvent 2025: Hidden 4

Flagvent 202520
Explore how whitespace-based steganography in an HTML can hide secret messages!

Flagvent 2025: Day 21

Flagvent 202530
Abuse UUIDv7 timestamp ordering to predict cursor pagination, letting you jump to the earliest entries on Santa’s Nice List and recover a shiny flag.

Flagvent 2025: Day 20

Flagvent 202520
SantaOS got intercepted! Decode a VCD signal with UART, crack a Pigpen key, and break AES-256-CBC to unwrap the hidden message.

Flagvent 2025: Day 19

Flagvent 202540
Learn how to hijack BGP with FRRouting (vtysh) and reroute traffic via longest-prefix match to steal a brainrot flag.

Flagvent 2025: Day 18

Flagvent 202530
Explore how a web server can be exploited in two phases: first, a User-Agent SQL injection (MySQL updatexml) to enumerate and dump the database; then an @everyone chat logic trick to reveal the remaining flag fragment.

Flagvent 2025: Day 17

Flagvent 202520
Learn how a Tail-Breach Compression Oracle Attack can leak secrets via Content-Length, using only HEAD requests and gzip-enabled responses.

Flagvent 2025: Hidden 3

Flagvent 202520
Sneaky Elves hide the flag in a Docker image manifest label, discovered by checking the referenced ghcr.io challenge image.

Flagvent 2025: Day 14

Flagvent 202540
Break a custom linear hash and invert HMAC leaks to recover RNG seeds and grab the flag.

Flagvent 2025: Day 13

Flagvent 202520
Learn how to exploit Kubernetes debug output to leak a Vault token, escalate to admin, and mint a k8s JWT with elevated privileges to access cluster-scoped secrets.

Flagvent 2025: Hidden 2

Flagvent 202520
Discover FV25.H2 Santa’s Secret Tree by spotting extra data appended to an image file, then decoding it to reveal the hidden flag.

Flagvent 2025: Day 10

Flagvent 202540
Exploit a D-Link ShareCenter RCE, drop a PHP web shell, then use a cron tar wildcard injection to escalate privileges to the santa user.

Flagvent 2025: Day 9

Flagvent 202530
Optimise Elf survival probabilities to 1 on the Quantum Transformer Operator website. Experiment with operators, craft a valid input, and retrieve the daily CTF flag.

Flagvent 2025: Day 7

Flagvent 202520
Explore how modem audio was decoded into ASCII with minimodem, leading us to a hidden webpage concealing the flag.

Flagvent 2025: Hidden 1

Flagvent 202520
A hidden flag is found in Day 6 Santa's Wishlist by decoding hex in package.json to ASCII to reveal it.

Flagvent 2025: Day 6

Flagvent 202530
Explore how a window.name XSS exploit was used to steal a flag stored in localStorage

Flagvent 2025: Day 5

Flagvent 202520
Learn how APNG frames can hide data in the blue channel's LSB and how each frame can contain a secret ASCII character.

Flagvent 2025: Day 4

Flagvent 202520
Discover how a corrupted MP4 was repaired and analysed to reveal a hidden SSTV audio signal that decodes into an image containing a secret flag.

Flagvent 2025: Day 3

Flagvent 202520
Automating a symlink maze in a Linux CTF challenge using sudo-permitted commands to walk a symlink chain.

Flagvent 2025: Day 2

Flagvent 202520
Learn how to crack a gyat-themed CTF by converting gyat code to Python and reversing XOR logic to recover the original password.

Flagvent 2025: Day 1

Flagvent 202540
Reconstruct QR code puzzle pieces decorating a Christmas tree to uncover the secret flag message.