boroCTF 2026 Writeup
Intro
Sorry, I didn’t write writeup for all the challenges I solved. So only some of them are in this writeup.
This is my second team-up CTF competition, and my teammates are EH, Cgm, and shrimp2845.
The competition is held from 2026/6/12 to 2026/6/16, the second weekend after I graduated from high school!
This CTF competition did not use dynamic scoring.

We got 35th place / 178 teams in the HS Division, and 93rd place / 831 teams of all teams
OSINT
Satoshi Hunt

I found a X account whose ID is @SatoshiNakamuda, and in his latest post he mentioned the highest point of Japan.

Go found out the highest point in Japan, it is Mount Fuji. So the flag is: boroCTF{Mount_Fuji}
Third Time’s the Charm

Just google it!

Flag: boroCTF{Nightmare_Eclipse}
Forensics
Billie Eilish

Extracted using binwalk, we will get an encrypted zip file.
Use black magic to find out the password is “badguy”, the most famous song of Billie Eilish.
Unzip the file and get this photo.

Flag: boroCTF{im_a_good_guy}
Looking through Windows

We had a .vhd file.
First use foremost to extract it, then we can get an encrypted zip. Use john the ripper and rockyou.txt to brute force the password. The password is “forget92936281”.
Finally, open the flag.txt file in the zip.
Flag: boroCTF{f!l3_f0r3nsics_FTW!!}
Listen Close

Super easy, just view the spectrum.

Flag: boroCTF{Sp3c^R0}
Misc
AI Slop


We can observed that there were Gemini’s logo at the bottom right, so the flag is: boroCTF{gemini}
Distortion


By the sentance “The owner gave me money!”, we can guess it is the logo of their sponsor. So go to the home page of boroCTF, and found there was a sponsor called “Kite Army”.

Flag: boroCTF{Kite_Army}
Nature’s Delight


Search by Image, and we can find out that the barcode corresponds to a 16.9 ounce bottle of watar from “Poland Spring” brand.
Flag: boroCTF{Poland_Spring}
64 is life


Given sixty-four file, and their file names are the base64 encoding of numbers 1 to 64. We can decode the file name to find the correct order of the file, and connect them one by one. We used the following script:
import os
import base64
chunks_dir = "./ctf_chunks"
output_file = "recovery"
file_pieces = {} # the dictionary used to store the correct file order
for filename in os.listdir(chunks_dir):
idx = int(base64.b64decode(filename.encode()))
file_path = os.path.join(chunks_dir, filename)
with open(file_path, "rb") as f:
file_pieces[idx] = f.read()
combined_date = b""
for i in range(1,65):
combined_date += file_pieces[i]
print(combined_date.decode())
and got the following output:
Y40m40940y40b40040N40U40R40n40t40z40M40X40h40040e40V40940m40M40H40V40y40X40240I40z40Y40X40V40040e40X40040=4040404040404040404040404040404040404040404040404040404040
remove all the 40, we’ll get
Ym9ybNURntzMXheV9mMHVyX2IzYXVeX=
Just decode it again.
Flag: boroCTF{s1xty_f0ur_b3auty}
File File Crocodile

It gave us a png file.

Using HxD, I found extra bytes after the IEND chunk, which should be the final chunk of a PNG file.
Notice that AE 42 60 82 are still part of the png file (it is the CRC value of the IEND block), so we copy the following bytes and save it to a new file.
46 43 03 04 0A 00 09 00 00 00 EF 5E C8 5C 5F 19 E0 53 39 00 00 00 2D 00 00 00 08 00 1C 00 66 6C 61 67 2E 74 78 74 55 54 09 00 03 F2 E5 26 6A F2 E5 26 6A 75 78 0B 00 01 04 E8 03 00 00 04 E8 03 00 00 B0 B6 F8 4C 06 1D D2 97 38 0B D9 99 5F 7B 7C C5 F3 47 16 E9 5A E7 76 E8 EC 32 44 FC B6 04 54 8F 84 7A 2A 76 F7 79 F7 7D 31 4E 4E BB 08 E0 6A CB 97 36 5F 1D 99 D5 6B 88 4C 50 4B 07 08 5F 19 E0 53 39 00 00 00 2D 00 00 00 46 43 01 02 1E 03 0A 00 09 00 00 00 EF 5E C8 5C 5F 19 E0 53 39 00 00 00 2D 00 00 00 08 00 18 00 00 00 00 00 01 00 00 00 FF 81 00 00 00 00 66 6C 61 67 2E 74 78 74 55 54 05 00 03 F2 E5 26 6A 75 78 0B 00 01 04 E8 03 00 00 04 E8 03 00 00 46 43 05 06 00 00 00 00 01 00 01 00 4E 00 00 00 8B 00 00 00 00 00
Because the file was corrupted, we couldn’t open it. However, I notice there was 50 4B(PK) in the file, so I guess this was a zip file. I replace all the 46 43(FC) with 50 4B(PK) and obtain an encrypted zip file.
In the challenge discription, there exist the following sentence:
Interrogating him didn't work as the only word he seemed to know was "croc".
So we can guess (Actually Gemini guessed it lol) the password is sheer “croc”.
Flag: boroCTF{n3v3r_sm1l3_4t_4_p0lygl0t_cr0c0d1l3}
Why wasn’t this in the Forensics catogory?
Web
Beyond the Homepage


View Source then you can find the Flag.
Flag: boroCTF{d3v3l0peR_t001s}
Cracking the Vault

Again, just ctrl+U view the source code.
lol the infra was taken down so I can’t reproduce it
dotdotslashflagtxt

Literally. As the name of challenge.
again I can’t reproduce it :(
Drone Dash

I just don’t know. I just click the botton and free flag appeared lol.





