<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Stellar Vector Blog</title><link>https://blog.stellarvector.be/</link><description>Recent content on Stellar Vector Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 01 Mar 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.stellarvector.be/index.xml" rel="self" type="application/rss+xml"/><item><title>sightseeing-in-ghent</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/sightseeing-in-ghent/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/sightseeing-in-ghent/</guid><description>OSINT adventure in Ghent requiring landmark identification, Google Maps investigation, and decoding a hidden sequence from a YouTube video soundtrack.</description></item><item><title>GateCrash</title><link>https://blog.stellarvector.be/writeups/2023/hackthebox-university-ctf-brains-bytes/gatecrash/</link><pubDate>Mon, 11 Dec 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/hackthebox-university-ctf-brains-bytes/gatecrash/</guid><description>Deep dive into Nim-specific CRLF injection (CVE-2020-15693). Shows how to inject JSON payloads into headers to bypass frontend filters and achieve SQL injection.</description></item><item><title>mayday-mayday</title><link>https://blog.stellarvector.be/writeups/2023/hackthebox-university-ctf-brains-bytes/mayday-mayday/</link><pubDate>Mon, 11 Dec 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/hackthebox-university-ctf-brains-bytes/mayday-mayday/</guid><description>Advanced RSA attack exploiting MSB leaks from CRT exponents. Uses the Coppersmith method and lattice-based reduction to factor large moduli.</description></item><item><title>PhantomFeed</title><link>https://blog.stellarvector.be/writeups/2023/hackthebox-university-ctf-brains-bytes/phantomfeed/</link><pubDate>Sun, 10 Dec 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/hackthebox-university-ctf-brains-bytes/phantomfeed/</guid><description>Multi-stage web exploitation involving a ReDoS-powered race condition, OAuth2-based XSS for token theft, and a final RCE via HTML2PDF font abuse.</description></item><item><title>keysharer</title><link>https://blog.stellarvector.be/writeups/2023/lakectf/keysharer/</link><pubDate>Mon, 06 Nov 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/lakectf/keysharer/</guid><description>High-level Cryptography solve demonstrating the Invalid Curve Attack. Explains how to recover a secret key by sending points from curves with lower orders.</description></item><item><title>Encoding Challenges</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/encoding-challenges/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/encoding-challenges/</guid><description>Step-by-step guide to reversing complex data encodings. Covers nested Base64/Base16 loops and a custom bit-shifting &amp;lsquo;magic shuffle&amp;rsquo; algorithm.</description></item><item><title>RSA Challenges</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/rsa-challenges/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/rsa-challenges/</guid><description>Comprehensive walkthrough of three RSA challenges from CTF101, covering basic decryption, factoring using online tools, and exploiting totient multiples from leaked private exponents.</description></item><item><title>Substitution Ciphers</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/substitution-ciphers/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/substitution-ciphers/</guid><description>Classic cryptography overview featuring Caesar and Vigenere Ciphers. Demonstrates single-byte XOR bruteforcing and frequency analysis for multi-key XOR decryption.</description></item><item><title>sightseeing</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/sightseeing/</link><pubDate>Sun, 15 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/sightseeing/</guid><description>OSINT challenge solve involving Leuven landmark recognition, Google Maps review scouting, and a creative hex-to-ASCII video transcription puzzle.</description></item><item><title>poster-thief-1</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/poster-thief-1/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/poster-thief-1/</guid><description>Introduction to the security.txt standard (RFC 9116). Shows how to locate and use a site&amp;rsquo;s security policy to find hidden contact information and flags.</description></item><item><title>poster-thief-2</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/poster-thief-2/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/poster-thief-2/</guid><description>Detailed exploration of Path Traversal vulnerabilities. Explains how to bypass non-recursive traversal filters by nesting sequences to reach sensitive system files.</description></item><item><title>poster-thief-3</title><link>https://blog.stellarvector.be/writeups/2023/ctf101/poster-thief-3/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/ctf101/poster-thief-3/</guid><description>Hands-on tutorial on manipulating HTTP headers using curl. Demonstrates how to bypass server-side checks for User-Agent, Referer, and custom headers.</description></item><item><title>apbq-rsa-1</title><link>https://blog.stellarvector.be/writeups/2023/downunderctf/apbq-rsa-1/</link><pubDate>Thu, 07 Sep 2023 00:00:00 +0000</pubDate><guid>https://blog.stellarvector.be/writeups/2023/downunderctf/apbq-rsa-1/</guid><description>RSA factoring challenge using specific linear combination hints. Employs a brute-force GCD attack on coprime hint coefficients to recover the private key.</description></item></channel></rss>