Intro

Sorry, I didn’t write writeup for all the challenges I solved. So only some of them are in this writeup.
This is my second team-up CTF competition, and my teammates are EH, Cgm, and shrimp2845.
The competition is held from 2026/6/12 to 2026/6/16, the second weekend after I graduated from high school!

This CTF competition did not use dynamic scoring.

image
We got 35th place / 178 teams in the HS Division, and 93rd place / 831 teams of all teams

OSINT

Satoshi Hunt

image
I found a X account whose ID is @SatoshiNakamuda, and in his latest post he mentioned the highest point of Japan.
image
Go found out the highest point in Japan, it is Mount Fuji. So the flag is: boroCTF{Mount_Fuji}

Third Time’s the Charm

image
Just google it!
image
Flag: boroCTF{Nightmare_Eclipse}

Forensics

Billie Eilish

image
Extracted using binwalk, we will get an encrypted zip file.
Use black magic to find out the password is “badguy”, the most famous song of Billie Eilish.
Unzip the file and get this photo.
eilish
Flag: boroCTF{im_a_good_guy}

Looking through Windows

image
We had a .vhd file.
First use foremost to extract it, then we can get an encrypted zip. Use john the ripper and rockyou.txt to brute force the password. The password is “forget92936281”.
Finally, open the flag.txt file in the zip.
Flag: boroCTF{f!l3_f0r3nsics_FTW!!}

Listen Close

image
Super easy, just view the spectrum.
image
Flag: boroCTF{Sp3c^R0}

Misc

AI Slop

image
slop
We can observed that there were Gemini’s logo at the bottom right, so the flag is: boroCTF{gemini}

Distortion

image
Logo
By the sentance “The owner gave me money!”, we can guess it is the logo of their sponsor. So go to the home page of boroCTF, and found there was a sponsor called “Kite Army”.
image
Flag: boroCTF{Kite_Army}

Nature’s Delight

image
weirdtag
Search by Image, and we can find out that the barcode corresponds to a 16.9 ounce bottle of watar from “Poland Spring” brand.
Flag: boroCTF{Poland_Spring}

64 is life

image
image
Given sixty-four file, and their file names are the base64 encoding of numbers 1 to 64. We can decode the file name to find the correct order of the file, and connect them one by one. We used the following script:

import os
import base64

chunks_dir = "./ctf_chunks"
output_file = "recovery"

file_pieces = {} # the dictionary used to store the correct file order

for filename in os.listdir(chunks_dir):
	idx = int(base64.b64decode(filename.encode()))
	file_path = os.path.join(chunks_dir, filename)
	with open(file_path, "rb") as f:
		file_pieces[idx] = f.read()

combined_date = b""
for i in range(1,65):
	combined_date += file_pieces[i]

print(combined_date.decode())

and got the following output:

Y40m40940y40b40040N40U40R40n40t40z40M40X40h40040e40V40940m40M40H40V40y40X40240I40z40Y40X40V40040e40X40040=4040404040404040404040404040404040404040404040404040404040

remove all the 40, we’ll get

Ym9ybNURntzMXheV9mMHVyX2IzYXVeX=

Just decode it again.
Flag: boroCTF{s1xty_f0ur_b3auty}

File File Crocodile

image
It gave us a png file.
image
Using HxD, I found extra bytes after the IEND chunk, which should be the final chunk of a PNG file.
Notice that AE 42 60 82 are still part of the png file (it is the CRC value of the IEND block), so we copy the following bytes and save it to a new file.

46 43 03 04 0A 00 09 00 00 00 EF 5E C8 5C 5F 19 E0 53 39 00 00 00 2D 00 00 00 08 00 1C 00 66 6C 61 67 2E 74 78 74 55 54 09 00 03 F2 E5 26 6A F2 E5 26 6A 75 78 0B 00 01 04 E8 03 00 00 04 E8 03 00 00 B0 B6 F8 4C 06 1D D2 97 38 0B D9 99 5F 7B 7C C5 F3 47 16 E9 5A E7 76 E8 EC 32 44 FC B6 04 54 8F 84 7A 2A 76 F7 79 F7 7D 31 4E 4E BB 08 E0 6A CB 97 36 5F 1D 99 D5 6B 88 4C 50 4B 07 08 5F 19 E0 53 39 00 00 00 2D 00 00 00 46 43 01 02 1E 03 0A 00 09 00 00 00 EF 5E C8 5C 5F 19 E0 53 39 00 00 00 2D 00 00 00 08 00 18 00 00 00 00 00 01 00 00 00 FF 81 00 00 00 00 66 6C 61 67 2E 74 78 74 55 54 05 00 03 F2 E5 26 6A 75 78 0B 00 01 04 E8 03 00 00 04 E8 03 00 00 46 43 05 06 00 00 00 00 01 00 01 00 4E 00 00 00 8B 00 00 00 00 00

Because the file was corrupted, we couldn’t open it. However, I notice there was 50 4B(PK) in the file, so I guess this was a zip file. I replace all the 46 43(FC) with 50 4B(PK) and obtain an encrypted zip file.
In the challenge discription, there exist the following sentence:

Interrogating him didn't work as the only word he seemed to know was "croc".

So we can guess (Actually Gemini guessed it lol) the password is sheer “croc”.

Flag: boroCTF{n3v3r_sm1l3_4t_4_p0lygl0t_cr0c0d1l3}

Why wasn’t this in the Forensics catogory?

Web

Beyond the Homepage

image
image
View Source then you can find the Flag.

Flag: boroCTF{d3v3l0peR_t001s}

Cracking the Vault

image
Again, just ctrl+U view the source code.

lol the infra was taken down so I can’t reproduce it

dotdotslashflagtxt

image
Literally. As the name of challenge.

again I can’t reproduce it :(

Drone Dash

image
I just don’t know. I just click the botton and free flag appeared lol.