Author thumbnail

LiveOverflow

CTF video write-ups

202,559 views
50 items
Last updated on Mar 24, 2022
public playlist
Let’s play a game: what is the deadly bug here?
12:54
Bash injection without letters or numbers - 33c3ctf hohoho (misc 350)
11:09
Failing easy local file inclusion challenge - mindreader (misc) Google CTF 2017
6:50
Blind GQL injection and optimised binary search - A7 ~ Gee cue elle (misc) Google CTF 2017
14:25
Using z3 to find a password and reverse obfuscated JavaScript - Fsec2017 CTF
10:33
TROOPERS 17 - PacketWars solved with an iPhone
5:04
Global variable Buffer Overflow to leak memory - 34C3 CTF readme_revenge (pwn)
16:13
Python code audit of a firmware update - 34C3 CTF software_update (crypto) part 1/2
12:48
Linear independence and GF(2) - 34C3 CTF software_update (crypto) part 2/2
14:27
Reverse Engineering and identifying Bugs - BKPCTF cookbook (pwn 6) part 1
26:49
Leaking Heap and Libc address - BKPCTF cookbook (pwn 6) part 2
25:48
Arbitrary write with House of Force (heap exploit) - BKPCTF cookbook (pwn 6) part 3
19:38
pwnable.kr - Levels: fd, collision, bof, flag
21:32
Live Hacking - EFF-CTF 2016 - Level 0-4 (Enigma Conference)
18:59
ROP with a very small stack - 32C3CTF teufel (pwnable 200)
31:39
Abusing the exception handler to leak flag - 32C3CTF readme (pwnable 200)
30:36
Live Hacking - Internetwache CTF 2016 - web50, web60, web80
9:15
Live Hacking - Internetwache CTF 2016 - crypto60, crypto70, crypto90
27:34
Reverse Engineering with Binary Ninja and gdb a key checking algorithm - TUMCTF 2016 Zwiebel part 1
9:25
Scripting radare2 with python for dynamic analysis - TUMCTF 2016 Zwiebel part 2
10:28
Live Hacking - Internetwache CTF 2016 - exp50, exp70, exp80
16:56
Simple reversing challenge and gaming the system - BruCON CTF part 1
6:28
int0x80 from DualCore lent me his lockpicking set and I'm a horse - BruCON CTF part 2
8:33
MD5 Length Extension and Blind SQL Injection - BruCON CTF part 3
10:30
Format String to dump binary and gain RCE - 33c3ctf ESPR (pwn 150)
13:25
PHP include and bypass SSRF protection with two DNS A records - 33c3ctf list0r (web 400)
9:03
[Live] A basic Heap Feng Shui intro - 33c3ctf babyfengshui (pwn 150)
2:19:48
Solving a JavaScript crackme: JS SAFE 2.0 (web) - Google CTF 2018
15:01
†: Some things I got wrong with JS Safe 2.0 - Google CTF 2018
5:30
Basic Windows Reversing and Attacking Weak Crypto - FLARE-On 2018
13:18
Analysing a Collection of Windows Binaries and Embedded Resources - FLARE-On 2018
12:04
Ethereum Smart Contract Hacking - Real World CTF 2018
19:34
Jump Oriented Programming: Ethereum Smart Contract #2 - Real World CTF 2018
19:21
XS-Search abusing the Chrome XSS Auditor - filemanager 35c3ctf
13:16
Analysing a Firefox Malware browserassist.dll - FLARE-On 2018
16:26
Ethereum Smart Contract Backdoored Using Malicious Constructor
8:38
GitLab 11.4.7 Remote Code Execution - Real World CTF 2018
14:03
Speedrun Hacking Buffer Overflow - speedrun-001 DC27
10:57
Minetest Circuit Challenge - Google CTF 2019 Qualifier
13:53
Zero-day vulnerability in Bash - Suidbash Google CTF Finals 2019 (pwn)
15:54
FPGA simulated on a GPU - GPURTL Google CTF Finals 2019 (reversing)
43:03
XSS a Paste Service - Pasteurize (web) Google CTF 2020
11:46
XSS on the Wrong Domain T_T - Tech Support (web) Google CTF 2020
13:40
Failed DOM Clobbering Research - All The Little Things 1/2 (web) Google CTF 2020
10:21
Chaining Script Gadgets to Full XSS - All The Little Things 2/2 (web) Google CTF 2020
13:46
can you hack this screenshot service?? - CSCG 2021
22:48
Design Flaw in Security Product - ALLES! CTF 2021
12:28
Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022
21:49
Finding 0day in Apache APISIX During CTF (CVE-2022-24112)
12:41
I've been Hacking for 10 Years! (Stripe CTF Speedrun)
28:58