# qualifier (blogs) — RSS Amplifier

Recent posts from the 3 feeds in the RSS Amplifier directory that cover qualifier.

Page: <https://rssamplifier.com/topics/qualifier/blogs>  
Feed: <https://rssamplifier.com/topics/qualifier/blogs.md>

---

## [Partizan Belgrade outclass Tobol Kostanay in UEFA Conference League qualifiers](https://www.tanjug.rs/english/sports/271933/partizan-belgrade-outclass-tobol-kostanay-in-uefa-conference-league-qualifiers/vest)

_2026-08-07 · tanjug.rs - Sports_

## [Kecmanovic defeated in Montreal Masters second round](https://www.tanjug.rs/english/sports/271632/kecmanovic-defeated-in-montreal-masters-second-round/vest)

_2026-08-06 · tanjug.rs - Sports_

## [Red Star lose to Hapoel Be'er Sheva away in UEFA Champions League qualifiers](https://www.tanjug.rs/english/sports/271318/red-star-lose-to-hapoel-beer-sheva-away-in-uefa-champions-league-qualifiers/vest)

_2026-08-05 · tanjug.rs - Sports_

## [Kecmanovic through to Montreal Masters second round](https://www.tanjug.rs/english/sports/271043/kecmanovic-through-to-montreal-masters-second-round/vest)

_2026-08-04 · tanjug.rs - Sports_

## [Partizan learn of their potential opponent in UEFA Conference League playoff round](https://www.tanjug.rs/english/sports/270837/partizan-learn-of-their-potential-opponent-in-uefa-conference-league-playoff-round/vest)

_2026-08-03 · tanjug.rs - Sports_

## [If they beat Hapoel Be'er Sheva, Red Star will face Aarhus or Sabah in UCL playoff](https://www.tanjug.rs/english/sports/270775/if-they-beat-hapoel-beer-sheva-red-star-will-face-aarhus-or-sabah-in-ucl-playoff/vest)

_2026-08-03 · tanjug.rs - Sports_

## [Vojvodina, Zeleznicar knocked out of UEFA Conference League qualifiers, Partizan march on](https://www.tanjug.rs/english/sports/270117/vojvodina-zeleznicar-knocked-out-of-uefa-conference-league-qualifiers-partizan-march-on/vest)

_2026-07-31 · tanjug.rs - Sports_

## [Djokovic confirms he will play at Cincinnati Masters](https://www.tanjug.rs/english/sports/269943/djokovic-confirms-he-will-play-at-cincinnati-masters/vest)

_2026-07-30 · tanjug.rs - Sports_

## [Red Star Belgrade demolish Larne again in UEFA Champions League qualifiers](https://www.tanjug.rs/english/sports/269798/red-star-belgrade-demolish-larne-again-in-uefa-champions-league-qualifiers/vest)

_2026-07-30 · tanjug.rs - Sports_

## [Djokovic to play at Riyadh exhibition tournament](https://www.tanjug.rs/english/sports/269488/djokovic-to-play-at-riyadh-exhibition-tournament/vest)

_2026-07-29 · tanjug.rs - Sports_

## [Unlimited Mobile Internet, One V-SIM (Sponsored)](https://crawlproof.com/a/B07ZR7CNTpAU)

_2026-07-29 · **Sponsored**_

Automatically switches across T-Mobile, AT&T and Verizon; no throttling, no contract.

## [Breaking Git(Hub) and Authentik at Plfanzen CTF](https://blog.gk.wtf/posts/plfanzen/)

_2026-05-11 · gk.wtf_

Writeups for the challenges I solved during Plfanzen CTF

## [swiss hacking challenge 2026 qualifier - bedrockbank](https://blog.gk.wtf/shc26/rev_bedrockbank/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories rev Description Bedrock Bank & Trust is the most secure financial institution in all of Bedrock! Their new stone-tablet vault app uses &ldquo;pterodactyl-grade&rdquo; account key protection. Unfortunately Dino forgot his password 😭 Can you help recover it?

## [swiss hacking challenge 2026 qualifier - brachiosaurus](https://blog.gk.wtf/shc26/web_brachiosaurus/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories web Description Gresslyosaurus, the local post officer has unfortunately lost access to the service managing the delivery of letters (the dino swears that he typed the password correctly, he tried it twice). Additionally, it seems that some messages have re-appeared! Please help him to sort this situation out and find the messages that still need to be delivered.

## [swiss hacking challenge 2026 qualifier - buffer-overflow-intro](https://blog.gk.wtf/shc26/pwn_buffer-overflow-intro/)

_2026-05-01 · gk.wtf_

Difficulty baby Categories pwn Description This program asks for a password. There&rsquo;s a variable called is\_admin that needs to equal 0xdeadbeef to get the flag. The program uses gets(), which is vulnerable to buffer overflow. Access: Connect to the binary with ncat --ssl \[host\] \[port\] or use pwntools.

## [swiss hacking challenge 2026 qualifier - canopysaurus](https://blog.gk.wtf/shc26/pwn_canopysaurus/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories pwn Description Something&rsquo;s wrong with the brontosaurus powering Fred&rsquo;s car. The Dino Control Unit (DCU) is acting up, and the mechanics at the Bedrock Motor Pool can&rsquo;t figure it out. Can you find the reset code for the DCU and help Fred get back on the road? Author Kiwi Attachments canopysaurus.tar.gz Service Challenge has a remote instance. LLM…

## [swiss hacking challenge 2026 qualifier - connivance](https://blog.gk.wtf/shc26/rev_connivance/)

_2026-05-01 · gk.wtf_

Difficulty hard Categories rev Description Bad guys like to obfuscate their code. This challenge implements a part of the DRM behind Tinfoil , a homebrew application that enables pirated games on the Nintendo Switch. Good luck! Author Yannik Attachments connivance.tar.gz LLM Usage I used ChatGPT to guess function signatures and structs. Also, the code for tracing of the compare opcode (at the end)…

## [swiss hacking challenge 2026 qualifier - dino-configurator](https://blog.gk.wtf/shc26/rev_dino-configurator/)

_2026-05-01 · gk.wtf_

Difficulty easy Categories rev Description Feel like you have been transported back in time by looking at this lovely .NET WinForms application. Note: This challenge only runs on windows. Author NoRelect Attachments dino-configurator.tar.gz Solution It&rsquo;s a .NET reversing challenge.

## [swiss hacking challenge 2026 qualifier - dino-test-bank](https://blog.gk.wtf/shc26/web_dino-test-bank/)

_2026-05-01 · gk.wtf_

Difficulty easy Categories web Description Dino Bank has setup a test server so e-banking is going to be less painful when going prod! Author Tobias 'floyd' Ospelt Service Challenge has a remote instance. Overview The challenge initially presents us with a login page, which we can bypass by reading the source code:

## [swiss hacking challenge 2026 qualifier - dino-vault](https://blog.gk.wtf/shc26/crypto_dino-vault/)

_2026-05-01 · gk.wtf_

Difficulty easy Categories crypto Description Do you have a park with dinosaurs of your own? Then make sure back your dinos up regularly! You never know when the next mass extinction event will happen, so better safe than sorry. We encrypt all your dinosaur data so that you need not worry that anyone is able to copy your designs. Our encrypted designs are uploaded as well for anyone to verify that…

## [swiss hacking challenge 2026 qualifier - dinodata](https://blog.gk.wtf/shc26/web_dinodata/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories web Description DinOData gives developers instant access to rich, structured dinosaur data through a fast, modern interface. Build educational apps, research tools, or games with reliable prehistoric data at your fingertips. Author NoRelect Service Challenge has a remote instance. Overview The challenge serves a swagger UI allowing us to call a lot of different API…

## [Anthony Ettinger on LinkedIn (Sponsored)](https://crawlproof.com/a/Wx1fB9SPja0v)

_2026-04-30 · **Sponsored**_

Public LinkedIn profile at linkedin.com/in/anthonyettinger.

## [swiss hacking challenge 2026 qualifier - fossildash](https://blog.gk.wtf/shc26/web_fossildash/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories web Description The Dinosaur Research Network just launched FossilDash , a collaborative platform where researchers share fossil discoveries. Access requires a valid researcher certificate. Can you find a way to dig up the flag?

## [swiss hacking challenge 2026 qualifier - grafasaurus](https://blog.gk.wtf/shc26/misc_grafasaurus/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories misc Description Visualizing trends in species, eras, and discoveries of dinosaurs? No better tool for the job than Grafana. Author NoRelect Service Challenge has a remote instance. Solution We get unauthenticated access to a grafana instance. There&rsquo;s a swagger ui at /swagger and I wrote a script to brute force all paths methods as an unauthenticated user:

## [swiss hacking challenge 2026 qualifier - juraforum](https://blog.gk.wtf/shc26/web_juraforum/)

_2026-05-01 · gk.wtf_

Difficulty hard Categories web Description The Swiss Jurassic Research Institute just launched JuraForum , an internal discussion board for paleontologists to share findings from the Jura mountains. Can you dig up something they didn&rsquo;t expect? RAWWWR! Author 0x90 Attachments juraforum.tar.gz Service Challenge has a remote instance. Solution (unintended) The challenge uses the markdown2…

## [swiss hacking challenge 2026 qualifier - lumon](https://blog.gk.wtf/shc26/rev_lumon/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories rev Description The work is mysterious and important. socat file:$(tty),rawer tcp:$HOST $PORT Author fitfrost4 Attachments lumon.tar.gz Service Challenge has a remote instance. Overview We have a very pretty TUI to &ldquo;refine&rdquo; numbers:

## [swiss hacking challenge 2026 qualifier - meow](https://blog.gk.wtf/shc26/misc_meow/)

_2026-05-01 · gk.wtf_

Difficulty leet Categories misc Description Like a powerful, dark storm, I will make my presence known to the world. Like a seeping mist, I will creep into the dogs&rsquo; center of power, and make them quake in fear at the very mention of my name!

## [swiss hacking challenge 2026 qualifier - password-checker](https://blog.gk.wtf/shc26/rev_password-checker/)

_2026-05-01 · gk.wtf_

Difficulty baby Categories rev Description This program asks for a password. If you enter the correct password, it grants you access. Figure out what password the program expects by looking at its code. Author xnull Service Challenge has a remote instance. Solution When using a disassembler (here r2ghidra), we can see the flag:

## [swiss hacking challenge 2026 qualifier - pcap-analysis](https://blog.gk.wtf/shc26/misc_pcap-analysis/)

_2026-05-01 · gk.wtf_

Difficulty baby Categories misc Description We captured network traffic from a user logging into a website. The credentials were sent over unencrypted HTTP. Analyze the packet capture and extract the password. Author xnull Service Challenge has a remote instance. Solution We can use tshark to dump the HTTP traffic by following the stream:

## [swiss hacking challenge 2026 qualifier - plumberhub](https://blog.gk.wtf/shc26/misc_plumberhub/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories misc Description Got a leaky drain? Give us a call! Connect using telnet $HOST $PORT flag is in $FLAG Author Popax21 Attachments plumberhub.tar.gz Service Challenge has a remote instance. Overview The challenge consists of multiple rust files:

## [swiss hacking challenge 2026 qualifier - punkhash](https://blog.gk.wtf/shc26/crypto_punkhash/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories crypto Description Look at this punky hash I found. Can you crack it? Author berndoJ Attachments punkhash.tar.gz LLM Usage I used ChatGPT in the browser to get to the general idea of LLL and the CVP approach. The exploit was written by myself. Solution The challenge itself has a really small source code:

## [swiss hacking challenge 2026 qualifier - sql-injection-basics](https://blog.gk.wtf/shc26/web_sql-injection-basics/)

_2026-05-01 · gk.wtf_

Difficulty baby Categories web Description You discovered a login page for a company database system. The credentials are unknown, but you need to gain access to retrieve sensitive information. Find a way to bypass the authentication and log in. Author xnull Service Challenge has a remote instance. Solution On the login page, we use the following credentials to get a login as admin:

## [Generate Viral Hot Takes (Sponsored)](https://crawlproof.com/a/LpGLzbfGqXYU)

_2026-04-30 · **Sponsored**_

Get platform-optimized hot takes and rebuttals to spark debate and engagement

## [swiss hacking challenge 2026 qualifier - stackosaurus](https://blog.gk.wtf/shc26/pwn_stackosaurus/)

_2026-05-01 · gk.wtf_

Difficulty easy Categories pwn Description Jurassic Stack Park recently upgraded their containment management terminals. We managed to pull a copy of the binary off one of the kiosks near the T-Rex enclosure. Author 0x90 Attachments stackosaurus.tar.gz Service Challenge has a remote instance. Overview We&rsquo;re dealing with a 32-bit binary:

## [swiss hacking challenge 2026 qualifier - stegosaurus](https://blog.gk.wtf/shc26/misc_stegosaurus/)

_2026-05-01 · gk.wtf_

Difficulty medium Categories misc Description In 1337 BC. the stegosaurus was known to write malware, infect company servers and extort them. Your task is to&hellip; AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA he&rsquo;s here. I didn&rsquo;t pay the ransom! Now he&rsquo;s coming for my spaghetti

## [swiss hacking challenge 2026 qualifier - weak random](https://blog.gk.wtf/shc26/crypto_weak-random/)

_2026-05-01 · gk.wtf_

Difficulty baby Categories crypto Description This authentication system generates a random token for access. The token is different each time you load the page. Can you predict what token the system will generate? Author xnull Service Challenge has a remote instance. Scenario We need to supply a 6-digit code and get the timestamp used for a seed.

## [swiss hacking challenge 2026 qualifier – writeups](https://blog.gk.wtf/posts/shc-2026/)

_2026-05-01 · gk.wtf_

My writeups for the SHC 2026 Qualifier

## [Endolum CTF - broken-access-control](https://blog.gk.wtf/endolumctf/web_broken-access-control/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : web Author : xnull Description : ### Employee Portal You found an employee portal for a company. Regular users can register and access their dashboard, but there's an admin panel that contains sensitive information. Your goal is to access the admin panel at \`/admin\` and retrieve the flag. Solution We can just change the role cookie to admin after registration:

## [Endolum CTF - buffer-overflow-intro](https://blog.gk.wtf/endolumctf/pwn_buffer-overflow-intro/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : pwn Author : xnull Description : ### Buffer Overflow Introduction This program asks for a password. There's a variable called is\_admin that needs to equal 0xdeadbeef to get the flag. The program uses gets(), which is vulnerable to buffer overflow. \*\*Access:\*\* Connect to the binary with \`ncat --ssl \[host\] \[port\]\` or use pwntools. The web interface provides educational…

## [Endolum CTF - caesar-cipher](https://blog.gk.wtf/endolumctf/crypto_caesar-cipher/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : crypto Author : xnull Description : ### Intercepted Message We intercepted an encrypted message that uses a Caesar cipher (also known as a shift cipher). In this cipher, each letter is shifted by a fixed number of positions in the alphabet. Solution We are presented with the string RAQYZ{pnrfne\_jnf\_abg\_irel\_frpher\_9s2n} . We can simply transform this with chepy : \>\>\>…

## [Endolum CTF - command-injection](https://blog.gk.wtf/endolumctf/web_command-injection/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : web Author : xnull Description : ### Network Diagnostic Tool This web tool lets you ping any server to check if it's reachable. The tool runs the ping command on the server and shows you the output. The flag is stored in \`/flag.txt\` on the server. Solution We can just get the flag with simple command injection in the ping functionality:

## [Endolum CTF - disassembly-intro](https://blog.gk.wtf/endolumctf/rev_disassembly-intro/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : rev Author : xnull Description : ### Flag Checker This program builds a flag internally and checks if your input matches it. You can see how the flag is constructed by looking at the program's code. Solution We just open up the program in our favorite disassembler and look at the main function: int64\_t main () { char var\_48 ; \_\_builtin\_strncpy ( & var\_48 ,…

## [Endolum CTF - ecb-mode-detection](https://blog.gk.wtf/endolumctf/crypto_ecb-mode-detection/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : crypto Author : xnull Description : ### Encrypted Session System This web application stores your session data in an encrypted cookie. When you visit the site, you get a cookie that marks you as a regular user. Only users with admin privileges can see the flag. The cookie is encrypted using AES encryption, but the implementation might have a weakness you can exploit.…

## [Endolum CTF - file-signature-analysis](https://blog.gk.wtf/endolumctf/forensics_file-signature-analysis/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : forensics Author : xnull Description : ### Suspicious File We recovered a file from a compromised system. It has a .txt extension, but something seems off about it. Download the file and determine its real type to view the contents. Solution Based on the header of the file, we can see it&rsquo;s a PNG file: �PNG  ��� We can just look at it and get the flag.

## [Endolum CTF - format-string-basics](https://blog.gk.wtf/endolumctf/pwn_format-string-basics/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : pwn Author : xnull Description : ### Format String Vulnerability This program echoes back whatever you type. The flag is stored in memory on the stack. Can you leak it using a format string vulnerability? \*\*Access:\*\* Connect to the binary with \`ncat --ssl \[host\] \[port\]\` or use pwntools. The web interface provides educational content and downloadable source code.…

## [Endolum CTF - hash-length-extension](https://blog.gk.wtf/endolumctf/crypto_hash-length-extension/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : crypto Author : xnull Description : ### Signed API This API uses MD5 signatures to authenticate requests. You have a valid signature for 'user=guest', but you need admin access. The signature is created as MD5(secret + data), where the secret is unknown to you. \*\*Hint:\*\* The server expects data as a hex string. It does \`bytes.fromhex(data)\` to decode it. Don't convert…

## [Endolum CTF - integer-overflow](https://blog.gk.wtf/endolumctf/pwn_integer-overflow/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : pwn Author : xnull Description : ### Integer Overflow Shop This shop sells flags for 1000 coins each. You only have 500 coins in your wallet. Can you exploit an integer overflow to buy the flag anyway? \*\*Access:\*\* Connect to the binary with \`ncat --ssl \[host\] \[port\]\` or use pwntools. Solution We can use the max. signed 64-bit integer divided by the cost (…

## [Endolum CTF - metadata-extraction](https://blog.gk.wtf/endolumctf/forensics_metadata-extraction/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : forensics Author : xnull Description : ### Vacation Photo Someone sent you a vacation photo with a hidden message. The image looks normal, but there's more to it than meets the eye. Find the secret message hidden in the file. Solution The flag is stored in EXIF data; this data is plaintext anyways, so instead of (as intended) running exiftool , we can just pipe it into…

## [Endolum CTF - password-checker](https://blog.gk.wtf/endolumctf/rev_password-checker/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : rev Author : xnull Description : ### Secure Password Vault This program asks for a password. If you enter the correct password, it grants you access. Figure out what password the program expects by looking at its code. Solution Again, when using a disassembler (here r2ghidra), we can see the flag: ulong sym . check\_password ( char \* arg1 ) { int64\_t iVar1 ; ulong uVar2…

## [Endolum CTF - path-traversal](https://blog.gk.wtf/endolumctf/web_path-traversal/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : web Author : xnull Description : ### Documentation Viewer This application lets you view company documentation files. The docs are stored in a specific directory on the server. The flag is stored in \`/flag.txt\` on the server filesystem. Solution The challenge is self-explanatory, we can just visit https://\<uuid\>.ctf.endolum.io:1337/view?file=../../../flag.txt to get the…

## [Endolum CTF - pcap-analysis](https://blog.gk.wtf/endolumctf/forensics_pcap-analysis/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : forensics Author : xnull Description : ### Network Traffic Capture We captured network traffic from a user logging into a website. The credentials were sent over unencrypted HTTP. Analyze the packet capture and extract the password. Solution We can use tshark to dump the HTTP traffic by following the stream: # tshark -r capture.pcap -z follow,http,ascii,0 1 0.000000…

## [Endolum CTF - sql-injection-basics](https://blog.gk.wtf/endolumctf/web_sql-injection-basics/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : web Author : xnull Description : ### Company Database Login You discovered a login page for a company database system. The credentials are unknown, but you need to gain access to retrieve sensitive information. Find a way to bypass the authentication and log in. Solution On the login page, we use the following credentials to get a login as admin:

## [Endolum CTF - steganography-basics](https://blog.gk.wtf/endolumctf/forensics_steganography-basics/)

_2026-02-01 · gk.wtf_

Difficulty: easy Category : forensics Author : xnull Description : ### Hidden Message in Image Someone sent you a cute cat picture, but they claim there's a secret message hidden inside it. The image looks completely normal. Can you find what's hidden? Solution After downloading the image, we can run zsteg on it: $ zsteg cat.png b1,r,lsb,xy .. text: 'ENDLM{h1dd3n\_1n\_pl41n\_s1ght\_8a7c}'…

