picoCTF Writeups
28+ challenges solved on picoCTF picoGym. Every writeup documents the vulnerability class, the exploitation methodology, root cause analysis, and mitigations — written for both CTF players and developers who want to understand what they're defending against.
28+Total Writeups
24Web Exploitation
4Forensics
3Difficulty Levels
Web Exploitation
SSTI → RCE · Second-Order SQLi · IDOR · File Upload Bypass · Session Hijacking · Rate Limit Bypass · Credential Stuffing · Client-Side Auth Failures
Easy
Old Session
→
Easy
Dev Backdoor
→
Easy
Announcements — Server-Side Template Injection
→
Easy
File Upload — Unrestricted Upload to RCE
→
Easy
Cookie Monster
→
Easy
Heapdump — Exposed Diagnostic Endpoint
→
Easy
WebDecode — Base64 in HTML Attributes
→
Easy
Bookmarklet — Hardcoded Key in Client-Side JS
→
Easy
Transparent JS — Credentials in Public JavaScript
→
Easy
Inspect HTML — Flag in HTML Comment
→
Easy
On Includes — Flag Split Across CSS and JS
→
Easy
Cookies — Sequential Cookie Enumeration
→
Easy
Scavenger Hunt — Flag Across 5 Server Files
→
Easy
GET aHead — Flag in HTTP Response Headers
→
Easy
Don't Use Client-Side — Flag in JS Verification Logic
→
Easy
Login as Joe — Credential and Auth State in Cookies
→
Easy
Robots — Flag Hidden Behind robots.txt Disallow
→
Medium
byp4ss3d — .htaccess Upload to PHP Execution
→
Medium
Crack the Gate 2 — X-Forwarded-For Rate Limit Bypass
→
Medium
Credential Stuffing — Raw TCP Automation with Python Sockets
→
Medium
Fool the Lockout — IP Rotation via X-Forwarded-For
→
Medium
Hashgate — IDOR via MD5-Hashed Sequential IDs
→
Hard
ORDER ORDER — Second-Order SQL Injection
→
Medium
Secret Box — PostgreSQL INSERT Injection with Dollar-Quoting
→
Forensics
Binary Encoding · Steganography · Metadata Analysis · Multi-Stage Encoding Chains · File Type Recovery · OCR
All writeups are also available on GitHub with the original challenge files.
View on GitHub →