The CTF is over but the challenges are still online!
Announcements
Hint: Our appsec team just told me that there are some dangerous bugs in receive_sharing_intent and shared_preferences 😱.
We released one last Challenge
New pwn challenge:
Range of Motion. This is the last challenge we will release this year.
Have fun playing the last ~24h 🎈
Some of you have already noticed that you will need to get code execution despite the presence of -no-shell-escape
. Maybe try taking a look at what actually happens when you build the LaTeX project using latexmk
...
Regarding all unsolved challenges from the first release cycle:
- Web: EquipTracker, GymTok, Bench Press
- Pwn: Ancient Monkey
- Mobile: Fleeting Inspirations
- Misc: Locker Zone, FDA
If you have made significant progress in any of those challenges, please open a ticket and tell us about it.
We may release hints on those challenges.
Happy lifting!
This challenge has two identical remote instances, in case port 25 is blocked in your network
nc pushgainpull.club 25
nc pushgainpull.club 2525
New challenges released!
- REGenerating EXperience (rev)
- Mutant (cloud)
- Pay To Gym (crypto)
- ARMDAY (full-body workout)
The challenge was built with numpy version 1.26.4. Unfortunately the encoder is broken with numpy version 2.0 and later.