<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Writeups on L3B4nk4</title><link>https://blog.b4nk4.tech/categories/writeup/</link><description>Recent content from L3B4nk4</description><generator>Hugo</generator><language>en-us</language><copyright>All articles on this blog are licensed under the BY-NC-SA license agreement unless otherwise stated. Please indicate the source when reprinting!</copyright><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0200</lastBuildDate><atom:link href="https://blog.b4nk4.tech/categories/writeup/index.xml" rel="self" type="application/rss+xml"/><item><title>Tired of Running</title><link>https://blog.b4nk4.tech/post/tired-of-running/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0200</pubDate><guid>https://blog.b4nk4.tech/post/tired-of-running/</guid><description>
<![CDATA[<h1>Tired of Running</h1><p>Author: L3B4nk4()</p>
        
          A Go web challenge: a uint16 length-wrap in a custom serializer desynchronizes backend parsing, leading to login bypass, osquery table abuse, inline YARA credential leakage, and a final internal request-splitting trick to recover the flag.
        
        <hr><p>Published on 2026-08-09 at <a href='https://blog.b4nk4.tech/'>L3B4nk4</a>, last modified on 2026-08-09</p>]]></description><category>writeup</category></item><item><title>Python Sucks</title><link>https://blog.b4nk4.tech/post/python_sucks/</link><pubDate>Sat, 13 Sep 2025 00:00:00 +0200</pubDate><guid>https://blog.b4nk4.tech/post/python_sucks/</guid><description>
<![CDATA[<h1>Python Sucks</h1><p>Author: L3B4nk4()</p>
        
          A Flask challenge from Connectors CTF: SQL injection leads to admin access, the file viewer turns into arbitrary file read, and the exposed Werkzeug console finishes the box with RCE.
        
        <hr><p>Published on 2025-09-13 at <a href='https://blog.b4nk4.tech/'>L3B4nk4</a>, last modified on 2026-03-26</p>]]></description><category>writeup</category></item><item><title>I Hate PHP</title><link>https://blog.b4nk4.tech/post/i-hate-php/</link><pubDate>Wed, 25 Mar 2026 18:49:31 +0200</pubDate><guid>https://blog.b4nk4.tech/post/i-hate-php/</guid><description>
<![CDATA[<h1>I Hate PHP</h1><p>Author: L3B4nk4()</p>
        
          I Hate PHP looks like a restricted LFI at first, but the bug is stronger than that because the app uses include(). Once I found a writable file under an allowed path, it turned into RCE.
        
        <hr><p>Published on 2026-03-25 at <a href='https://blog.b4nk4.tech/'>L3B4nk4</a>, last modified on 2026-03-25</p>]]></description><category>writeup</category></item><item><title>My name is ayksks</title><link>https://blog.b4nk4.tech/post/my-name-is-ayksks/</link><pubDate>Tue, 09 Dec 2025 15:22:45 +0200</pubDate><guid>https://blog.b4nk4.tech/post/my-name-is-ayksks/</guid><description>
<![CDATA[<h1>My name is ayksks </h1><p>Author: L3B4nk4()</p>
        
          This is the challenge where I achieved second blood: XSS → SSRF → RCE.
        
        <hr><p>Published on 2025-12-09 at <a href='https://blog.b4nk4.tech/'>L3B4nk4</a>, last modified on 2025-12-09</p>]]></description><category>writeup</category></item><item><title>A Very Small Locker</title><link>https://blog.b4nk4.tech/post/a-very-small-locker/</link><pubDate>Sun, 16 Nov 2025 10:45:12 +0200</pubDate><guid>https://blog.b4nk4.tech/post/a-very-small-locker/</guid><description>
<![CDATA[<h1>A Very Small Locker</h1><p>Author: L3B4nk4()</p>
        
          A web challenge with two paths: an unintended NoSQL injection shortcut, and the intended chain of business logic, XSS, and IDOR.
        
        <hr><p>Published on 2025-11-16 at <a href='https://blog.b4nk4.tech/'>L3B4nk4</a>, last modified on 2025-11-16</p>]]></description><category>writeup</category></item></channel></rss>