squ1rrel

The Vanderbilt University CTF Club

  • Home
  • About
  • Team
  • CTFTime
Image
Squ1rrel Web

Portrait

It’s like DeviantArt, but with a report button to keep it less Deviant.

Image Kyle Burgess 4 min read
Image
Squ1rrel Web

Go Getter

There’s a joke to be made here about Python eating the GOpher. I’ll cook on it and get back to you.

Image Kyle Burgess 3 min read
Image
Squ1rrel Web

Acorn Clicker

Click acorns. Buy squirrels. Profit.

Image Kyle Burgess 3 min read
Image
Csaw Forensics

Zip Zip Zip

A ZIP within a ZIP within a ZIP within a ZIP…

Image David Huang 4 min read
Image
Csaw Misc

Russian Jet Tracking

Last Friday night, the little me who aspired to be like those hackers in movies finally had her dreams come true. Or, girl tracks Russian planes.

Image Rachel Koh 3 min read
Image
Csaw Pwn

mini-golfing

Leaky stacks with printf: format string basics

Image Patrick Dobranowski 4 min read
Image
Csaw Web

Lost Pyramid

The only way to avoid SSTIs is to use protection.

Image Kyle Burgess 5 min read
Image
Csaw Web

BucketWars

The hardest challenge for a CTFer to solve is how to lose their versionity.

Image Kyle Burgess 2 min read
Image
Squ1rrel Web

Goosemon

I’d rather die than use a password manager. In other news, can anyone help me remember the login info for my account? The flag for this challenge is the account password.

Image Kyle Burgess 5 min read
Image
Squ1rrel Web

Personal Website

Check out my personal website! I have a blog!

Image Nisala 4 min read
Image
Squ1rrel Web

Mutex Lock

just solved distributed systems

Image Nisala 4 min read
Image
Squ1rrel Web

Key Server

Well, my application is finally making it big – and I’ve heard that once you get over 10 users, using kubernetes is basically a must. Come check out my microservices!

Image Nisala 2 min read
Image
Squ1rrel Web

JSON Store

Have you ever wanted to store some JSON data really quickly? Have we got the solution for you!

Image Nisala 3 min read
Image
Blackhatmea Pwn

babysbx

Shellcode sandboxes make for a fun little game.

Image Patrick Dobranowski 17 min read
Image
Patriotctf Forensics

Unsupported Format 2

Just a silly little forensics challenge.

Image Sam Sliman 1 min read
Image
Sekaictf Rev

Guardians of the Kernel

Kernel can be a scary word. That’s alright though because we have an SMT solver on our team.

Image Patrick Dobranowski 11 min read
Image
Patriotctf Web

Flower Shop

Bad news: pay-to-win made it to CTFs. Good news: we paid first.

Image Nisala 2 min read
Image
Sekaictf Algo

Gluttonous Sheep

This sheep needs to chill out with the apples, I’m sure there’s plenty to go around.

Image Abi Kothapalli 11 min read
Image
Sekaictf Web

Vulnerability Scanner

Scanner? Buddy!

Image Nisala 3 min read
Image
Kitctfctf Rev

protector

This was a cool reversing challenge where I wrote a GDB script to undo obfuscated operations to get the flag.

Image Akash 7 min read
Image
Htb Crypto

AESWCM

Cryptography transcends wizardry.

Image Holden Turner 16 min read
Image
Kitctfctf Misc

Grep it? CodeQL it!

CodeQL: a surprisingly handy tool! Just need to read the instructions more carefully next time…

Image Zi Teoh 6 min read
Image
Kitctfctf Web

Etherpad 1 & 2

LDAP me up, bro.

Image Kyle Burgess 6 min read
Image
Nitectf Misc

The Boys

Miscellaneous sure is one way to describe it.

Image Sam Sliman 2 min read
Image
Xmas Misc

Blocker, Cookie Market, & Bread Bank

Blockchain: a new way to program… and a new way to write vulnerable code.

Image David Perez 15 min read
Image
Nitectf Web

un(documented)-js-api

DOM clobbering, domain takeovers, shared process slowdowns, and CSS exfiltration, oh my!

Image Nisala 8 min read
Image
Kitctfctf Crypto

Prime Guesser 1 & 2

Who needs math when you can just guess?

Image Holden Turner 56 min read
Image
Nitectf Forensics

Revisiting Classics

Paging Nick Gebo - Get Your Ass In Here

Image Sam Sliman 1 min read
Image
Buckeyectf Misc

frog-universe

Welcome to Frog Universe!

Image Aryan Garg 33 min read
Image
Buckeyectf Crypto

bonce

This challenge gives us two files, output.txt and bonce.py.

Image Evelyn 4 min read
Image
Buckeyectf Pwn

stack duck

I love ducks, so I was a little saddened to see that this duck was a canary in disguise. Still a birb though!

Image Patrick Dobranowski 13 min read
Image
Buckeyectf Crypto

SSSHIT

A crypto challenge that boils down to “3x - 3a + b = c”.

Image Sam Alws 6 min read
Image
Buckeyectf Misc

spelunk

All of these challenges are too hard for me. Wait… is that Minecraft???

Image Maya 5 min read
Image
Buckeyectf Crypto

powerball

I like free money. Crypto and lottery in the same sentence? Say less.

Image Aadi Bajpai 6 min read
Image
Buckeyectf Misc

nile & andes

Despite having worked in smart contract security, I have never actually performed an attack before – until now. Let’s take a look at some not-so-smart contracts, shall we?

Image Ben Siraphob 11 min read
Image
Buckeyectf Rev

cap

This litty challenge was highkey bussin bruh, on god, no cap fr fr. Sheeesh.

Image Abi Kothapalli 18 min read
Image
Hacklu Crypto

Linear Starter

Every delicious meal needs a starter and I have great news for you: This one is even linear!

Image Zi Teoh 4 min read
Image
Buckeyectf Rev

intel does what amd'ont

This was the first time I reversed a binary with obfuscated code!

Image Akash 12 min read
Image
Buckeyectf Rev

crispyr

Rust is wonderful to write, but reversing it is quite the challenge.

Image Akash 8 min read
Image
Buckeyectf Misc

devil

I can sorta do CTF problems – but deep down, I’m a DevOps guy.

Image Nisala 7 min read
Image
Bluehensctf Misc

Rick and Morty - One Time Pad - Esoteric Languages

Memes as an internet subculture, World War era encryption schemes, and program states as stacks of dynamically sized integers, oh my! How do they all connect?

Image Patrick Dobranowski 20 min read
Image
Buckeyectf Web

goober

How on earth do SVGs have so many security vulnerabilities?

Image Nisala 3 min read
Image
Bluehensctf Misc

Wordles with Dads

Another variation of Wordle, just like my previous writeup on Vocaloid Heardle.

Image squ1rrel team 11 min read
Sekaictf Misc

Sus

Someone sent this file to me, claiming he got it from a SEKAI where the palette is not colorful but purple. I had no idea what he was talking about – I only

Image Evelyn 2 min read
Image
Sekaictf Forensics

Broken Converter & flag Mono

A two-part CTF challenge!

Image Aryan Garg 5 min read
Image
Bluehensctf Pwn

Intro to PWN 1-3

This was my first time doing a CTF, so I literally had no idea what was going on the whole time. But I do think I learned a good bit from just observing

Image squ1rrel team 6 min read
Image
Bluehensctf Misc

CryptoDuck!

Digital circuits and Python: low-level meets high-level in the solution to this oddball of a challenge.

Image squ1rrel team 4 min read
Image
Wreckctf Web

password-3

A quick but interesting proof-of-concept demonstrating that security by obscurity does not and will never work. Even if you don’t show reflected feedback from SQL commands, your database is still not safe.

Image Patrick Dobranowski 5 min read
Image
Sekaictf Web

Bottle Poem

For this web challenge, we had to utilize two different exploits to get the flag – and one of them wasn’t a web exploit!

Image Akash 5 min read
Image
Bluehensctf Forensics

The Quantum Realm

Forensics! Stego! Look, they even gave us an image! You know the drill.

Image squ1rrel team 2 min read
Bluehensctf Web

Firefun!

I love Firebase. So this really was the perfect challenge for me.

Image Nisala 4 min read
Sekaictf Web

Issues: Another JWT Challenge

Oh, JWTs. A well-intentioned standard, for sure – but my god, the number of implementation mistakes you can make.

Image Nisala 4 min read
Sekaictf Crypto

Secure Image Encryption!

One of the more solvable challenges… completed in the silliest way possible.

Image Kyle Burgess 7 min read
Image
Sekaictf Misc

Vocaloid Heardle

Well, it’s just too usual to hide a flag in stegano, database, cipher, or server. What if we decide to sing it out instead?

Image Zi Teoh 8 min read
Sekaictf Misc

Matryoshka

ANSI escape codes. Race conditions in PNG parsing. Digital COVID-19 vaccination records. De-noising audio files and the NATO phonetic alphabet. The only thing linking all of them? A race to solve a CTF

Image Ben Siraphob 9 min read
squ1rrel © 2025
Latest Posts Twitter
Advertisement
Advertisement