mischard

EvilBabyKalmarCTF

kalmarctf

Task: Scraper bot runs ctfd-download every 30s, flag at /flag.txt on scraper container. Solution: Chain CTFd RCE to serve raw Python via plugin/template, then exploit markdown image path traversal to hijack tqdm import.

$ ls tags/ techniques/
python_import_hijackingmarkdown_image_path_traversalflask_plugin_injectionjinja2_template_raw_output

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]