New new blog
Posted on January 3, 2025
(Last modified on June 17, 2026)
|
1 min
Launched an updated version of the website. The previous version was version 5 which used custom HTML along with Hugo Go generated HTML. The transition to Version 5 happened in 2018.
Version 6
I’ve recently been encourgaed to go back to blogging and felt it was time to move to pure Hugo. Hence, the birth of version 6. Version 6 is purely Hugo Go generated and used the BeautifulHugo theme.
Previous posts were also migrated over from version 5 of the blogs section which were initially deployed using Google Blogger. Version 6 is a huge jump from the last post about 5-years ago.
[Read More]CTFlearn Easy
Posted on August 17, 2020
(Last modified on June 17, 2026)
|
16 min
Sorted all challenges by difficult so that I could attempt and learn from the easier ones.
Easy
Misc
Practice Flag - 20pts
Try inputting the flag: flag{CTFLearn_is_awesome}
- Submitted:
CTFLearn{CTFLearn_is_awesome}
Wikipedia - 30pts
Not much to go off here, but it’s all you need: Wikipedia and 128.125.52.138.
- Navigated to wikipedia site
https://www.wikipedia.org/ - Searched for
128.125.52.138 and found page on Flag. Searched within page for CTF and found reference to CTF flgs - Submitted:
CTFlearn{cNi76bV2IVERlh97hP}
QR Code - 30pts
Do you remember something known as QR Code? Simple. Here for you : https://mega.nz/#!eGYlFa5Z!8mbiqg3kosk93qJCP-DBxIilHH2rf7iIVY-kpwyrx-0
[Read More]UQ Cyber Squad 0x03 Shells
Posted on March 29, 2020
(Last modified on June 17, 2026)
|
6 min
Introduction
0x03 Shells session presented by the UQ Cyber Squad. Access via OpenVPN connection. OpenVPN configuration bundle provided during the workshop.
Challenge 1 - Family Binding Time - 10pts
Let’s bind together at 192.168.57.11:8297
nc 192.168.57.11 8297
id
uid=1002(user) gid=1002(user) groups=1002(user)
pwd
/home/user
ls -las
total 60
4 drwxr-xr-x 3 user user 4096 Mar 27 06:02 .
4 drwxr-xr-x 4 root root 4096 Mar 24 02:13 ..
4 -rw------- 1 user user 1584 Mar 26 01:26 .bash_history
4 -rw------- 1 user user 105 Mar 26 00:50 .lesshst
4 -rw------- 1 user user 5 Mar 24 03:38 .python_history
4 drwxr-xr-x 2 user user 4096 Mar 26 00:59 .ssh
8 -rw------- 1 user user 5066 Mar 27 06:01 .viminfo
4 -r-xr-xr-x 1 root user 892 Mar 27 06:02 init_shell.py
20 -rwsr-xr-x 1 richard root 16728 Mar 26 00:54 read_secret_message
4 -rw-r--r-- 1 user user 24 Mar 24 02:14 user.txt
cat user.txt
flag{n1c3_b0nd1ng_t1m3}
Challenge 2 - shhhhhhhh - 20pts
How do I ssshhhhh? How do I know how to?
[Read More]Over the Wire - Wargames - Bandit
Posted on March 22, 2020
(Last modified on June 17, 2026)
|
52 min
Introduction
Details about the challenges may be found at https://overthewire.org/wargames/bandit/. The game is played over SSH over port 2220 so firewalls may need to be adjusted to allow outbound traffic to connect to the game. The game has 34 levels. The levels are chained, so that to get to the next level you need to complete/finish/beat the previous level.
WARNING: These are my own notes and contain actual flags.
Bandit Level 0
Level Goal
The goal of this level is for you to log into the game using SSH. The host to which you need to connect is bandit.labs.overthewire.org, on port 2220. The username is bandit0 and the password is bandit0. Once logged in, go to the Level 1 page to find out how to beat Level 1.
[Read More]UQ Cyber Squad 0x01 Intro to Linux, Machines, and Networking
Posted on March 20, 2020
(Last modified on June 17, 2026)
|
23 min
Introduction
Found the UQ Cyber Squad site at https://cybersquad.uqcloud.net/index.html. Signed up for their CTF on https://ctf.uqcloud.net/
0x01 Introduction to Linux
This was identical to the QUT Whitehats Week 2 for challenges 1 through to 8. The writeup was already done at https://kush.com.fj/blog/posts/2020-02-28_qut_wh_wk2/.
No place like index.html - 10pts
There’s no clues or hints for this but it was pretty obvious.
- Navigated to
https://cybersquad.uqcloud.net/index.html - Manually reviewed the page source and searched for
flag - Found flag on line #30 of the source
- Submitted: flag{w0ah_n1c3_f1nd}
Machines
The machines challenges were named machines because they provided virtual machines for a traditional boot-to-root.
[Read More]QUT Whitehats CTF Week_3
Posted on March 13, 2020
(Last modified on June 17, 2026)
|
8 min
Week_3
WARNING: Like all my CTF notes, this contains spoilers.
3x01 - 10pts
https://crypto.qutwhitehats.club/ch1
For simplicity sake, to be able to easily attempt this weeks challenges, please navigate to: https://www.katacoda.com/0xollie/scenarios/0x01 sign up/sign in and click onto the terminal.
INPUT: apt install httpie -y wait approx 1 minute for it to install.
obtain ciphertext by running the following command: http get https://crypto.qutwhitehats.club/ch1
To input an answer run the following command: http post https://crypto.qutwhitehats.club/ch1 answer=“answerhere”
[Read More]QUT Whitehats CTF Week_2
Posted on March 6, 2020
(Last modified on June 17, 2026)
|
4 min
Week_2
I spent a good 10 minutes trying to figure out the challenges before reaching for help. Eventually was told that the challenge location was “on the end of our slide deck is a link to katacode, thats where Olliver is doing his Challenges https://www.katacoda.com/0xollie/scenarios/0x01"
Signed up for Katacoda and nativated to the URL.
WARNING: Like all my CTF notes, this contains spoilers.
Challenge 1 - Normal files - 10pts
These are just regular files
flag syntax: flag{insert_flag_here}
[Read More]QUT Whitehats CTF Week_1
Posted on February 28, 2020
(Last modified on June 17, 2026)
|
2 min
Week_1
WARNING: Like all my CTF notes, this contains spoilers.
How_2_Flag - 0 pts
For our CTF challenges this year we will be using the format: flag-{example_flag} Please note that all flags are case-sensitive!
- Submitted:
flag-{example_flag}
Have you joined our discord server yet? https://discord.gg/kRbcVnP
- Joined discordapp
- Clicked on Add a server
- Used the URL in the challenge
- Checked #flag channel
- Submitted:
flag-{welcome_1337_haxor}
Our website - https://qutwhitehats.club is a vast treasure trove of information. Have a look and see if you can find the hidden flag!
[Read More]AWSN Cadet CTF
Posted on February 21, 2020
(Last modified on June 17, 2026)
|
4 min
Introduction
I was fortunate enough at attend an Australian Women in Security Networ (AWSN) session. Following the session there was a beginner level capture the flag (CTF) hosted off http://149.28.182.32:8000. These are my notes from the CTF. Additional things to note are, firstly, that for the Web challenges, challenge 4 is called flag5, and challenge 5 references flag4. Secondly, the submission for the Cryptography password challenge expects the flag in the format flag{flag_value}. Finally, the notes below contain spoilers, and actual flags submitted.
[Read More]GPG Better than Zip Encryption
Posted on March 30, 2019
(Last modified on June 17, 2026)
|
4 min
Is GPG/OpenPGP really Better than Zip ?
I attended a local conference yesterday (2019-03-29) and during one of the talks a senior analyst from one of the world’s first CERT said that the preference was to use GPG for symmetric key encryption of files to transfer confidential information to their clients over zip. The reason presented was that zip did not provide the desired level of confidentiality and integrity. This comment got me thinking as I had thought that zip used AES for encryption, so now I am awake at 0100hrs in the morning and curious to understand the encryption used in zip.
[Read More]