CryptoCat
@cryptocat.me
๐ค 476
๐ฅ 81
๐ 123
Security Researcher ๐ Hacking Content @
https://yt.cryptocat.me
๐
pinned post!
CTF resources ๐บ
loading . . .
GitHub - Crypto-Cat/CTF: CTF chall write-ups, files, scripts etc (trying to be more organised LOL)
CTF chall write-ups, files, scripts etc (trying to be more organised LOL) - GitHub - Crypto-Cat/CTF: CTF chall write-ups, files, scripts etc (trying to be more organised LOL)
https://github.com/Crypto-Cat/CTF
over 2 years ago
0
9
1
My writeup for the "APICrash" challenge from
@yeswehack.bsky.social
๐ฅ
cryptocat.me/blog/ctf/mon...
loading . . .
Race Condition via GraphQL Aliases | YesWeHack 11-25: APICrash | CryptoCat's Blog
YesWeHack Dojo 11-25 writeup: exploiting unsynchronised threaded TinyDB writes via GraphQL aliases to corrupt storage and trigger error-based flag disclosure.
https://cryptocat.me/blog/ctf/monthly/yeswehack/api_crash/
4 days ago
0
0
0
reposted by
CryptoCat
404 Media
10 days ago
At least four videos show what really happened when ICE shot a woman in Minneapolis on Wednesday. DHS has established itself as an agency that cannot be trusted to live in or present reality.
@evystadium.bsky.social
has more. Full story by
@josephcox.bsky.social
:
www.404media.co/dhs-is-lying...
loading . . .
20
1291
440
Happy new year!! ๐ฅณ๐
17 days ago
0
2
0
I've been working hard to move my written content from gitbook over to my own website ๐ทโโ๏ธ It's still a work in progress, but I'm pretty happy with the results so far ๐ ๐
cryptocat.me/blog/
17 days ago
1
2
0
Wishing a very hacky christmas to all the hacker fam! ๐
23 days ago
0
1
0
Video walkthrough for the Hacky Christmas challenge I made for
#NahamCon2025
๐
youtu.be/fs9WeNkUB4M
loading . . .
Manipulating Memory with Cheat Engine - Hacky Christmas [NahamCon 2025 CTF]
YouTube video by CryptoCat
https://youtu.be/fs9WeNkUB4M
29 days ago
0
0
0
The
#NahamCon2025
CTF is over โ Writeups for my challs ๐ ๐ฎ Hacky Christmas โก
book.cryptocat.me/blog/ctf/202...
๐ฅ VulnBank โก
book.cryptocat.me/blog/ctf/202...
๐ฅ Snorex 2K CCTV โก
book.cryptocat.me/blog/ctf/202...
Stay tuned for a video walkthrough of Hacky Christmas ๐ ๐
30 days ago
0
0
0
I made a couple of [easy-med] challenges for
#NahamCon2025
- you've got 24 hours! ๐ ๐ฎ
ctf.nahamcon.com/hubs/hacky-c...
๐ฅ
ctf.nahamcon.com/hubs/vuln-bank
๐ฅ
ctf.nahamcon.com/hubs/snorex-...
Here's a sneak peek at Hacky Christmas ๐ Can you escape the ice box and take out 1 MILLION gingerbread men? ๐
loading . . .
about 1 month ago
0
1
0
I also made some challenges for
#NahamCon2025
, hope you will check them out! ๐
add a skeleton here at some point
about 1 month ago
0
1
0
New stickers ๐ผ
loading . . .
about 1 month ago
1
3
0
New video covering the solution to the Mother Printers challenge I created for
@hackinghub.bsky.social
๐ Tried to make it as beginner friendly as possible as I know many players aren't familiar with rev/pwn ๐
youtu.be/ebNYtX_8lOY
loading . . .
Mother Printers (Print2Own) - Full Exploit Chain Walkthrough [HackingHub]
YouTube video by CryptoCat
https://youtu.be/ebNYtX_8lOY
about 2 months ago
0
1
0
Didn't get chance to solve my "Mothers Printers" challenge on
@hackinghub.bsky.social
? ๐จ Here's the official writeup โก
book.cryptocat.me/blog/ctf/mon...
Prefer video? Stay tuned for a beginner-friendly walkthrough on YT next week โถ
about 2 months ago
1
1
0
Time to drop a couple of hints for my
@hackinghub.bsky.social
challenge! 1๏ธโฃ First flag is on the website (you need to find it before flag 3/4/5) 2๏ธโฃ The chall is inspired by some cool research I read (go find it) Writeups will be published once we hit 10 solves โก
app.hackinghub.io/hubs/mother-...
loading . . .
https://app.hackinghub.io/hubs/mother-printers
2 months ago
0
0
1
Congratulations to Bhavya for being the first to capture all 5 flags on my
@hackinghub.bsky.social
challenge! ๐ฅณ๐ We've released a small patch. If you were stuck on flag 3, please re-download files! Good time to practice your patch-diffing ๐
app.hackinghub.io/hubs/mother-...
2 months ago
0
1
0
So, who's gonna blood my new
@hackinghub.bsky.social
challenge? ๐ผ Challenge ๐
app.hackinghub.io/hubs/mother-...
First 3 solves will earn the "Hacker Cat" role in my discord server โก๏ธ
discord.cryptocat.me
#ctf
#capturetheflag
#ethicalhacking
#cybersecurity
#infosec
#offsec
2 months ago
1
1
1
The "Ultimate Calculator 3000" challenge is over! โณ You can watch the video walkthrough here โก
youtu.be/lRJno96za5A
I'll leave everything online for another week or so ๐
loading . . .
Hidden Product Activation and Serial Keygen - "Ultimate Calculator 3000" [Rev/Web Challenge]
YouTube video by CryptoCat
https://youtu.be/lRJno96za5A
3 months ago
1
0
0
My writeup for the September Dojo challenge on
@yeswehack.bsky.social
- Chainfection โ The challenge combined multiple CVEs, creating a chain of vulnerabilities: SQL injection -> file write + path traversal -> SSTI (RCE) Read the full writeup โก๏ธ
book.cryptocat.me/blog/ctf/mon...
3 months ago
0
0
0
I made a new CTF challenge! It will run until the 30th of October ๐ There's no prizes, but the first 3 solves will earn themselves the "Hacker Cat" rank in my discord server ๐ธ Download "Ultimate Calculator 3000" to get started โก
discord.cryptocat.me
3 months ago
1
1
0
reposted by
CryptoCat
Trend Zero Day Initiative
3 months ago
Recapping Day One of
#Pwn2Own
Ireland 2025. Join
@dustinchilds.bsky.social
(and Maude) as he covers the highlights of the first day of the competition. We awarded $522,500 for 34 unique 0-day bugs, and more is to come.
youtu.be/tiM_StSFvow
loading . . .
Recapping Day One of Pwn2Own Ireland 2025
YouTube video by Trend Zero Day Initiative
https://youtu.be/tiM_StSFvow
0
1
1
reposted by
CryptoCat
Stephen Fewer
3 months ago
We just posted our AttackerKB
@rapid7.com
Analysis for the recent Cisco 0day chain; CVE-2025-20362 and CVE-2025-20333. Full technical root cause analysis of both the auth bypass and buffer overflow are here:
attackerkb.com/topics/Szq5u...
loading . . .
CVE-2025-20362 | AttackerKB
On September 25, 2025, Cisco published advisories for two new vulnerabilities, CVE-2025-20362, and CVE-2025-20333, which are known to be exploited in-the-wild โฆ
https://attackerkb.com/topics/Szq5u0xgUX/cve-2025-20362/rapid7-analysis
1
2
1
New video looking at some interesting printer vulnerabilities, found by
@stephenfewer.bsky.social
(
@rapid7.com
) ๐จ โถ
youtu.be/--SaQKmcyiU
loading . . .
Print Scan Hacks: Understanding the 8 CVEs Impacting Brother Printers
YouTube video by CryptoCat
https://youtu.be/--SaQKmcyiU
4 months ago
1
1
0
One week until
@bsidesbelfast.bsky.social
, Who's going? ๐ As always, I've got stickers - come say hi! ๐
4 months ago
0
3
1
Video walkthrough for the "Fancy Login Form" web challenge from the
@why2025.bsky.social
CTF ๐ฉ Learn how to exfiltrate data via CSS injection โก๏ธ
youtu.be/jUjlj2z5jJk
loading . . .
5 months ago
0
0
0
Played the
@why2025.bsky.social
CTF over the weekend ๐ Here's some web challenge writeups ๐
book.cryptocat.me/ctf-writeups...
loading . . .
Web | CTF Writeups
https://book.cryptocat.me/ctf-writeups/2025/why/web
5 months ago
0
1
1
Famous beef noodle soup (broth simmering continously for over 50 years!) in one of my all time favourite cities - Bangkok! ๐น๐ญ Any hackers here wanna hang out, hmu ๐ค
7 months ago
0
1
1
I've done a lot of awesome hacker meetups but this one was next level! So nice to meet brutecat, dreyand and IDlSSEVERYTHING๐ฅ These guys have some crazy skills (and stories), hope to meet again in the future ๐
7 months ago
1
1
0
I'll be in Singapore this weekend! I know there's lots of cool hackers there so hmu if you wanna get some coffee/food/drinks ๐ฅฐ
7 months ago
0
2
1
Finally back in
#KualaLumpur
๐ Meeting some of my favourite Malaysian hackers for food/drinks tomorrow night. If you wanna join, let me know! ๐ฅฐ
7 months ago
1
0
0
๐
7 months ago
0
1
0
My OSWE review, tips/tricks.. general ramblings ๐๐
youtu.be/IK4t-i5lDEs
loading . . .
Offensive Security Web Expert (OSWE) Review + Tips/Tricks [OffSec]
YouTube video by CryptoCat
https://youtu.be/IK4t-i5lDEs
8 months ago
0
0
0
Just finished my OSWE exam ๐ Today I write up the report.. while watching
#NahamCon
๐
8 months ago
0
2
0
reposted by
CryptoCat
Johan Carlsson
8 months ago
Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall
joaxcar.com/blog/2025/05...
loading . . .
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson
https://joaxcar.com/blog/2025/05/20/confetti-solution-to-my-intigriti-may-xss-challenge/
1
19
6
reposted by
CryptoCat
Jorian
8 months ago
The legendary
@joaxcar.bsky.social
made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below:
jorianwoltjer.com/blog/p/hacki...
loading . . .
Intigriti May XSS Challenge (0525) | Jorian Woltjer
A challenge by @joaxcar with a small but complex XSS chain, hitting DOM Clobbering with a race condition and abusing a cool URL parsing quirk in JavaScript.
https://jorianwoltjer.com/blog/p/hacking/intigriti-xss-challenge/0525
2
12
7
Heading back to SE-Asia next month.. Any hackers wanna hang out? ๐ Join my discord to keep up with the travel plans / arrange meetups:
cryptocat.me/discord
๐
#cybersecurity
#ethicalhacking
#infosec
#bugbounty
#ctf
#asia
8 months ago
0
1
0
reposted by
CryptoCat
James Kettle
8 months ago
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at
#BHUSA
! This is going to be epic, check out the abstract for a teaser โ
2
38
19
Video walkthrough for the web challenges from Tsuku CTF ๐
youtu.be/qGd4d0zmhy8
loading . . .
Tsuku CTF Web Challenge Walkthroughs (2025)
YouTube video by CryptoCat
https://youtu.be/qGd4d0zmhy8
9 months ago
1
1
0
reposted by
CryptoCat
Nicolas Grรฉgoire
9 months ago
We already know that any Web server listening on the loopback interface is a security risk, because it may be accessed by a browser or its extensions. But the impact may be way bigger if this Web server is a MCP server ๐ฑ
blog.extensiontotal.com/trust-me-im-...
loading . . .
Trust Me, Iโm Local: Chrome Extensions, MCP, and the Sandbox Escape
Letโs talk about MCPs. Youโve probably heard of them, and maybe youโve read the security risks associated with them. Sure, they soundโฆ
https://blog.extensiontotal.com/trust-me-im-local-chrome-extensions-mcp-and-the-sandbox-escape-1875a0ee4823
0
26
2
Have YOU joined my discord server yet? Click the link below and let's talk about hacking stuff ๐
discord.cryptocat.me
9 months ago
0
0
0
Added a video walkthrough for the web challenges from the recent CTF@CIT ๐
youtu.be/ZBdApaw0r0M
#capturetheflag
#ctf
#websecurity
#bugbounty
#cybersecurity
#ethicalhacking
#infosec
loading . . .
CTF@CIT Web Challenge Walkthroughs
YouTube video by CryptoCat
https://youtu.be/ZBdApaw0r0M
9 months ago
0
0
0
Made writeups for the web challs featured in the CTF@CIT competition this weekend ๐ฉ 1) SQL injection 2) Git repo dumping 3) Local file read with basic filter bypass 4) Flask session cookie tampering + SSTI 5) Credential reuse / HTTP method tampering
book.cryptocat.me/ctf-writeups...
9 months ago
0
0
1
Video for the HackDonalds Challenge by
@intigriti.com
๐
youtu.be/KwD_TKZr0YY
loading . . .
Next.js Middleware Auth Bypass (CVE-2025-29927) and Local File Read via XXE - HackDonalds Challenge
YouTube video by Intigriti
https://youtu.be/KwD_TKZr0YY?si=Anj3agAZrOTHi4kc
9 months ago
0
2
1
My YouTube channel has reached a new milestone; 3 million views! ๐ฅณ๐ Next up - 50k subscribers! Help me get there ๐ฅบ
yt.cryptocat.me
9 months ago
0
5
0
Who wants a bonus
@intigriti.com
challenge? Easier than usual ๐ First blood + best writeup win a โฌ50 swag voucher ๐ Find the flag before 15/04/25 ๐
hackdonalds.intigriti.io
loading . . .
HackDonalds
๐ Welcome to the most exploitable fast food chain on the net.
https://hackdonalds.intigriti.io
9 months ago
1
3
1
London ๐ฌ๐ง๐๐จ
10 months ago
0
3
0
reposted by
CryptoCat
Intigriti
10 months ago
Check out the walkthrough for the fourth (and currently final)
@portswigger.net
lab on NoSQL injection by
@cryptocat.me
๐ผ
youtu.be/aSXlmJ3lN4o
loading . . .
Exploiting NoSQL Operator Injection to Extract Unknown Fields
YouTube video by Intigriti
https://youtu.be/aSXlmJ3lN4o
1
3
1
Almost 600 hackers at ZeroDays CTF in
#Dublin
this year!! ๐
#ZeroDays
#CTF
#CaptureTheFlag
#CyberSecurity
#EthicalHacking
#InfoSec
#BugBounty
#Ireland
10 months ago
0
6
1
As promised, I've updated my YouTube playlist with a walkthrough for the new API testing module in
@digi.ninja
's Damn Vulnerable Web Application (DVWA) ๐
www.youtube.com/watch?v=c_6R...
loading . . .
18 - API Security (low/med/high) - Damn Vulnerable Web Application (DVWA)
YouTube video by CryptoCat
https://www.youtube.com/watch?v=c_6RaCekH40
10 months ago
0
0
0
Met so many cool hackers over the past few days in Kuala Lumpur! ๐
10 months ago
0
2
0
reposted by
CryptoCat
Lennaert89
10 months ago
Attending the amazing
@1ns0mn1h4ck.bsky.social
to represent
@intigriti.com
today! Hit me up if you want to chat. I've got stickers and invite codes to hand out ๐.
0
6
2
New
@portswigger.net
video released over on the
@intigriti.com
channel! ๐
youtu.be/mVYu_3b_dOE
loading . . .
Exploiting Syntax Injection to Extract Data
YouTube video by Intigriti
https://youtu.be/mVYu_3b_dOE
10 months ago
1
3
1
Load more
feeds!
log in