picoCTF Writeups

28+ challenges solved on picoCTF picoGym. Every writeup documents the vulnerability class, the exploitation methodology, root cause analysis, and mitigations — written for both CTF players and developers who want to understand what they're defending against.

28+Total Writeups
24Web Exploitation
4Forensics
3Difficulty Levels

Web Exploitation

SSTI → RCE · Second-Order SQLi · IDOR · File Upload Bypass · Session Hijacking · Rate Limit Bypass · Credential Stuffing · Client-Side Auth Failures

View all 24 →

Forensics

Binary Encoding · Steganography · Metadata Analysis · Multi-Stage Encoding Chains · File Type Recovery · OCR

View all 4 →

All writeups are also available on GitHub with the original challenge files.

View on GitHub →