AIS3 好厲駭 - 網頁安全:OWASP Top 10 2025
發表於|更新於|Cyber
|總字數:7|閱讀時間:1分鐘|瀏覽量:
文章作者: R3X DJ
版權聲明: 本部落格所有文章除特別聲明外,均採用CC BY-NC-SA 4.0 授權協議。轉載請註明來源 R3X's Blog!
相關推薦

2026-02-27
2026 THJCC CTF Writeup
THJCC 2026 writeups 輕鬆打,學生賽區第23名 Welcome Welcome to THJCC CTF 誰跟你F12,我瞪眼法求Flag THJCC{We1c0m3-tO-tHjcC-c7F_2O26} Reverse Super baby reverse IDA一開就是了 Fllllllag_ch3cker_again? 丟進IDA逆向得到這串 int __fastcall main(int argc, const char **argv, const char **envp) { __int64 v3; // rbx __int64 v4; // rax char v6; // [rsp+Fh] [rbp-E1h] BYREF unsigned __int64 i; // [rsp+10h] [rbp-E0h] __int64 v8; // [rsp+18h] [rbp-D8h] __int64 v9; // [rsp+20h] [rbp-D0h] char *v10; // [rsp+28...

2025-04-20
2025 THJCC CTF Writeup
THJCC 2025 writeups 先上成績: 其實我不需要寫XD太弱了拿不到前10。不過第一次打CTF比賽就拿第22名/133人還滿開心的,希望明年可以挺進高中組前10。 WarmUp Welcome Flag: THJCC{w3lc0m3_70_7hjcc} beep boop beep boop 01010110 01000101 01101000 01001011 01010001 00110000 01001110 00110111 01100010 01101010 01000010 01111001 01100010 01010100 01010010 01110011 01011000 01111010 01001110 01110101 01011001 01111010 01000010 01101011 01001101 01010111 00110100 00110010 01100110 01010001 00111101 00111101 二進位轉ASCII字元後發現是base64,再次解碼即得 Flag: THJCC{n0rm4l_...

2026-09-20
boroCTF 2026 Writeup
Intro Sorry, I didn’t write writeup for all the challenges I solved. So only some of them are in this writeup. This is my second team-up CTF competition, and my teammates are EH, Cgm, and shrimp2845. The competition is held from 2026/6/12 to 2026/6/16, the second weekend after I graduated from high school! This CTF competition did not use dynamic scoring. We got 35th place / 178 teams in the HS Division, and 93rd place / 831 teams of all teams OSINT Satoshi Hunt I found a X account whose ...

2025-05-26
AIS3 Pre-Exam 2025 Writeup
AIS3 Pre-Exam 2025 分數貶值很嚴重耶w 是AI的緣故嗎 第一次打,雖然只有166名,但比賽當下解出了7題還算滿意吧 比賽過程中曾經最高排名:66 更:很幸運的得到了備取資格,雖然沒有成功備上😭可能上天要我先好好準備學測吧w Misc Welcome 這裡不能直接複製,直接複製會變成 AIS3{This_Is_Just_A_Fake_Flag_~~} 所以要自己手動輸入 Flag: AIS3{Welcome_And_Enjoy_The_CTF_!} 原因解釋: 右鍵檢查就可以發現,他用了一些HTML和CSS的技巧 這裡放假的flag 這裡才是真flag 其實另有方法可以直接把flag取出來喔! 在Web Console輸入 [...document.querySelectorAll('.flag > span')].map( (e, i) => window.getComputedStyle(e, '::before').content ).join('').replace(/"/g, '') ...

2026-08-10
AIS3 Junior Writeup
Basic The Fist Flag 在 CTF 中的目標就是找到一串「Flag」,這題是熟悉平台操作使用,直接將整個字串複製貼上即可 Flag: Flag(Thi3_is_the_First_flag) Linux-1 在 Linux 系統 (和 Windows 一樣,是一個作業系統,常見於伺服器) 中,要印出一個檔案的內容可以使用 cat 指令 (對應的 Windows 指令為 type),用法為:cat 檔案名稱。此題的目標是印出 flag (很好猜 Flag 就在 flag 裡)。因此使用 cat flag Flag: FLAG{cat_is_enough_for_the_first_step} Linux-2 解法1 要找出 Flag,我們第一步可以先列出目錄底下有哪些檔案,在 Linux 系統中,我們可以使用 ls 指令列出某個目錄底下的所有內容,用法為:ls 目錄,若未指定目錄,則預設列出目前目錄底下的檔案。執行 ls 之後會輸出以下: app.py notes.txt projects.txt todo.txt welcome.txt 接著我們可以...

2026-07-20
Junior.Crypt.2026 CTF Writeup
前言 我們戰隊組了三隊去玩:RCEs、RCEs-2、owo (因為一隊上限 3 人),結果 RCEs-2 排名比我們前面很多XD Misc Ghost Layers 題目給了一個 svg: 先上網找個 svg-formatter-beautifier 這樣比較好看 然後可以看到 <def> 中的 <g id="s17">: <g id="s17"> <g transform="translate(62.500,454.000) scale(0.009400,-0.009400)" fill="#f8efc9" stroke="#f8efc9" stroke-width="36" stroke-linejoin="round"> <path d="M803 578Q803 728 746.0 818.5Q689 909 596 909Q504 909 447.5 819.0Q391 729 391 578Q391 426 447.5 336.0Q504 246 596 246Q689 246 746....
評論
目錄
- 1. Top 10:2025 List
- 1.1. A01:2025 Broken Access Control
- 1.2. A02:2025 Security Misconfiguration
- 1.3. A03:2025 Software Supply Chain Failures
- 1.4. A04:2025 Cryptographic Failures
- 1.5. A05:2025 Injection
- 1.6. A06:2025 Insecure Design
- 1.7. A07:2025 Authentication Failures
- 1.8. A08:2025 Software or Data Integrity Failures
- 1.9. A09:2025 Security Logging and Alerting Failures
- 1.10. A10:2025 Mishandling of Exceptional Conditions

