Generated by All in One SEO v4.8.9, this is an llms.txt file, used by LLMs to index the site. # Alsavaudomila ## Sitemaps - [XML Sitemap](https://alsavaudomila.com/sitemap.xml): Contains all public & indexable URLs for this website. ## 投稿 - [Local Authority picoCTF Writeup](https://alsavaudomila.com/local-authority-picoctf-writeup/) - picoCTF Local Authority: password found in client-side JavaScript. Burp Suite and DevTools walkthrough — plus why JS auth is always transparent to the user. - [Inspect HTML picoCTF Writeup](https://alsavaudomila.com/inspect-html-picoctf-writeup/) - picoCTF Inspect HTML: the flag is in an HTML comment — invisible on screen, visible in DevTools. Source inspection walkthrough with curl, Ctrl+U, and the Elements tab. - [Wireshark doo dooo do doo picoCTF Writeup](https://alsavaudomila.com/wireshark-doo-dooo-do-doo-picoctf-writeup/) - ROT13-encoded flag in HTTP traffic. Wireshark doo dooo do doo picoCTF walkthrough: filter, Follow TCP Stream, and decode in one command. - [Crack the Gate 1 picoCTF Writeup](https://alsavaudomila.com/crack-the-gate-1-picoctf-writeup-2/) - Crack the Gate 1 picoCTF writeup: ROT13-encoded HTML comment reveals a debug header that bypasses login. Python decode + Burp Suite Repeater walkthrough. - [Log Hunt picoCTF Writeup](https://alsavaudomila.com/log-hunt-picoctf-writeup/) - picoCTF Log Hunt hides a flag across FLAGPART entries in a server log — with duplicate entries as a trap. Full solve: strings, grep, deduplication, and why sk1lls_ appears twice. - [Riddle Registry picoCTF Writeup](https://alsavaudomila.com/riddle-registry-picoctf-writeup/) - picoCTF Riddle Registry hides the flag in Base64 inside a PDF's Author metadata field — not behind the redacted text. Full solve: pdfinfo, Base64 decode, and why redaction removal was the wrong first move. - [Flag in Flame picoCTF Writeup](https://alsavaudomila.com/flag-in-flame-picoctf-writeup/) - picoCTF Flag in Flame chains two encodings: Base64 hides a PNG; the PNG shows the flag as hex. Solve walkthrough and encoding identification reference. - [CTF Forensics Tools: The Ultimate Guide for Beginners](https://alsavaudomila.com/ctf-forensics-tools/) - A field guide to CTF forensics tools built from 20+ picoCTF challenges. Covers which tool to reach for first by file type — disk images, audio, PNG, ZIP, PCAP — and the specific mistakes that cost the most time. - [RED | picoCTF](https://alsavaudomila.com/red-picoctf-writeup/) - picoCTF RED hides the flag in LSB steganography, with the method spelled in a metadata poem. Walkthrough: exiftool, zsteg install errors, Base64 decode. - [Includes picoCTF Writeup](https://alsavaudomila.com/includes-picoctf-writeup/) - picoCTF Includes hides the flag across a CSS and a JS file. Walkthrough: finding both halves, the BurpSuite mistake, and the 2of2 notation that saves you. - [Ph4nt0m 1ntrud3r picoCTF Writeup](https://alsavaudomila.com/ph4nt0m-1ntrud3r-picoctf-writeup/) - picoCTF Ph4nt0m 1ntrud3r: the flag fragments arrive in the wrong order on purpose. Full walkthrough of sorting Base64 payloads by microsecond timestamp and why Follow TCP Stream misleads you. - [CTF Audio Challenges: A Practical SoX Combat Guide](https://alsavaudomila.com/sox-in-ctf-how-to-analyze-and-manipulate-audio-files/) - SoX's rough frequency stat exposes Morse code in seconds — before you open any GUI. TJCTF 2024 beep-boop-robot solved: identifying the 1000 Hz carrier, ruling out DTMF, decoding timing patterns. - [binwalk in CTF: Spot False Positives Fast](https://alsavaudomila.com/binwalk-in-ctf-how-to-analyze-binaries-and-extract-hidden-files/) - binwalk's TIFF false positive inside PNG files catches most first-timers. Full walkthrough of picoCTF Matryoshka Doll: 4-layer extraction, ICC profile signatures, and when to ignore binwalk hits. - [steghide in CTF: How to Hide and Extract Data from Images](https://alsavaudomila.com/steghide-in-ctf-how-to-hide-and-extract-data-from-files/) - steghide's identical error for wrong passphrase vs. no data trips up every CTF newcomer. Walk through the picoCTF "Hidden in Plainsight" challenge, Stegseek brute-force, and how DCT embedding actually works. - [dd in CTF: Disk Imaging Extraction and Common Challenge Patterns](https://alsavaudomila.com/dd-in-ctf-disk-imaging-extraction-and-common-challenge-patterns/) - dd in CTF disk forensics: real picoCTF Disk, disk, sleuth! II walkthrough with fdisk partition extraction, actual flag recovery, and when filesystem tools fail you. - [Audacity CTF: Audio Forensics](https://alsavaudomila.com/audacity-in-ctf-audio-forensics-techniques-and-common-challenge-patterns/) - Audacity audio forensics for CTF: waveform vs spectrogram decision, 9 hidden data patterns, and real command outputs from a picoCTF Morse Code challenge. - [Analyzing ZIP Encryption: When to Act](https://alsavaudomila.com/zip2john-in-ctf-extracting-zip-passwords-and-common-challenge-patterns/) - ZipCrypto vs AES-256 ZIP cracking in CTF: real TJCTF challenge walkthrough, zip2john workflow, and when to switch from wordlists to bkcrack known-plaintext attack. - [strings Command in CTF: Hidden Data Guide](https://alsavaudomila.com/strings-command-in-ctf-how-to-extract-hidden-data-from-binaries/) - strings finds readable text in any binary or disk image. Real picoCTF examples, key options (-n, -e l, -t x), and how to avoid submitting a fake flag. - [Crack the Power picoCTF Writeup](https://alsavaudomila.com/crack-the-power/) - My RSA loop exited at i=1, revealing wrapping never occurred. picoCTF Crack the Power: digit count diagnostic, gmpy2.iroot, small exponent risks. - [zbarimg: QR Decoding in CTF](https://alsavaudomila.com/zbarimg-in-ctf-qr-barcode-decoding-techniques-and-common-challenge-patterns/) - Four ways zbarimg silently fails in CTF — and how to fix each. ImageMagick commands for inverted colors and low resolution, plus a diagnostic workflow. - [Scan Surprise picoCTF Writeup](https://alsavaudomila.com/scan-surprise-picoctf-writeup/) - zbarimg decoded picoCTF Scan Surprise in one command — after 25 minutes debugging pyzbar. Writeup with QR failure modes and CTF pattern guide. - [pngcheck in CTF: How to Analyze and Repair PNG Files](https://alsavaudomila.com/pngcheck-in-ctf-how-to-analyze-and-repair-png-files/) - 🔍 pngcheck CTF Tutorial: How to Analyze Corrupted PNG Files and Find Hidden Chunks Searching for "pngcheck CTF" or "how to fix corrupted PNG forensics" usually returns tool documentation or terse Writeups that skip the thinking. This article is different: it's a walkthrough of how I actually use pngcheck in CTF PNG forensics challenges — - [DISKO 1 picoCTF Writeup](https://alsavaudomila.com/disko-1-picoctf-writeup/) - picoCTF DISKO 1 — why mounting, binwalk, and Sleuth Kit all come up empty, and how strings reads raw FAT16 sectors to find the flag in two seconds. - [Hidden in Plainsight picoCTF Writeup](https://alsavaudomila.com/hidden-in-plainsight-picoctf-writeup/) - picoCTF Hidden in Plainsight solved: passphrase hidden as double base64 in the JPEG comment field. Covers file metadata analysis, steghide info, and flag extraction. - [Mini RSA picoCTF Writeup](https://alsavaudomila.com/mini-rsa-picoctf-writeup/) - How I finally solved picoCTF Mini RSA: three cube root failures, the gmpy2 k-iteration fix, and why floating-point silently corrupts big-integer roots. - [Corrupted File picoCTF Writeup](https://alsavaudomila.com/corrupted-file-picoctf-writeup/) - picoCTF 2019 Corrupted File: JPEG header broken by two bytes. Full hex repair walkthrough, 20 minutes of failed attempts, and how magic byte spoofing is abused in real-world attacks. - [fdisk in CTF: Partition Analysis and Common Challenge Patterns](https://alsavaudomila.com/fdisk-in-ctf-partition-analysis-and-common-challenge-patterns/) - Learn how to use the fdisk command for CTF forensics. Identify partitions, calculate offsets for dd, and find hidden data in disk images. - [FFmpeg for CTF Forensics](https://alsavaudomila.com/ffmpeg-in-ctf-how-to-analyze-and-manipulate-audio-video-files/) - Use FFmpeg for CTF video forensics: find hidden frames, decode metadata, extract audio for Audacity, and repair broken media files. Patterns from real challenges. ## Pages - [alsavaudomila Writeup](https://alsavaudomila.com/) - ctf writeup page - [About](https://alsavaudomila.com/about/) - I'm a security engineer based in Japan. I run this site as a space to document what I learn from CTF challenges — not just the solutions, but the reasoning behind them. How It Started My interest in security started with iPhone jailbreaking. Taking apart a locked system to understand how it works — and - [privacy-policy](https://alsavaudomila.com/privacy-policy/) - Purpose of Use of Personal Information This blog may request personal information such as your name and email address when you contact us or leave comments on articles.The personal information collected will be used only for responding to inquiries and providing necessary information via email, and will not be used for any other purpose. About - [Contact](https://alsavaudomila.com/contact/) - mail rudy00candygmail.com X(twitter) rudy_candy_ discord rudy_candy ## My Templates - [デフォルトキット](https://alsavaudomila.com/?elementor_library=デフォルトキット) ## Categories - [picoCTF-Forensics-Easy](https://alsavaudomila.com/category/picoctf-forensics-easy/) - [picoCTF-Web Exploitation-Easy](https://alsavaudomila.com/category/picoctf-web-exploitation-easy/) - [picoCTF-Cryptography-Medium](https://alsavaudomila.com/category/picoctf-cryptography-medium/) - [picoCTF-Forensics-Medium](https://alsavaudomila.com/category/picoctf-forensics-medium/) - [picoCTF-General Skills-Easy](https://alsavaudomila.com/category/picoctf-general-skills-easy/) - [tools](https://alsavaudomila.com/category/tools/) ## Tags - [exiftool](https://alsavaudomila.com/tag/exiftool/) - [Base64](https://alsavaudomila.com/tag/base64/) - [ROT13](https://alsavaudomila.com/tag/rot13/) - [Burp Suite](https://alsavaudomila.com/tag/burp-suite/) - [RSA](https://alsavaudomila.com/tag/rsa/) - [file](https://alsavaudomila.com/tag/file/) - [strings](https://alsavaudomila.com/tag/strings/) - [grep](https://alsavaudomila.com/tag/grep/) - [HEX](https://alsavaudomila.com/tag/hex/) - [PNG](https://alsavaudomila.com/tag/png/) - [steghide](https://alsavaudomila.com/tag/steghide/) - [Low Public Exponent Attack](https://alsavaudomila.com/tag/low-public-exponent-attack/) - [Wireshark](https://alsavaudomila.com/tag/wireshark/) - [zsteg](https://alsavaudomila.com/tag/zsteg/) - [pdfinfo](https://alsavaudomila.com/tag/pdfinfo/) - [QR code](https://alsavaudomila.com/tag/qr-code/) - [zbarimg](https://alsavaudomila.com/tag/zbarimg/) - [PDF](https://alsavaudomila.com/tag/pdf/) - [Substitution cipher](https://alsavaudomila.com/tag/substitution-cipher/) - [hexdump](https://alsavaudomila.com/tag/hexdump/) - [jpg](https://alsavaudomila.com/tag/jpg/) - [jiff](https://alsavaudomila.com/tag/jiff/) - [binwalk](https://alsavaudomila.com/tag/binwalk/) - [hexedit](https://alsavaudomila.com/tag/hexedit/) - [pngcheck](https://alsavaudomila.com/tag/pngcheck/) - [sox](https://alsavaudomila.com/tag/sox/) - [ffmpeg](https://alsavaudomila.com/tag/ffmpeg/) - [dd](https://alsavaudomila.com/tag/dd/) - [fdisk](https://alsavaudomila.com/tag/fdisk/) - [zip2john](https://alsavaudomila.com/tag/zip2john/) - [audacity](https://alsavaudomila.com/tag/audacity/)