squ1rrel

The Vanderbilt University CTF Club

  • Home
  • About
  • Team
  • CTFTime
Squ1rrel Web

Portrait

It’s like DeviantArt, but with a report button to keep it less Deviant.

Kyle Burgess 4 min read
Squ1rrel Web

Go Getter

There’s a joke to be made here about Python eating the GOpher. I’ll cook on it and get back to you.

Kyle Burgess 3 min read
Squ1rrel Web

Acorn Clicker

Click acorns. Buy squirrels. Profit.

Kyle Burgess 3 min read
Csaw Forensics

Zip Zip Zip

A ZIP within a ZIP within a ZIP within a ZIP…

David Huang 4 min read
Csaw Misc

Russian Jet Tracking

Last Friday night, the little me who aspired to be like those hackers in movies finally had her dreams come true. Or, girl tracks Russian planes.

Rachel Koh 3 min read
Csaw Pwn

mini-golfing

Leaky stacks with printf: format string basics

Patrick Dobranowski 4 min read
Csaw Web

Lost Pyramid

The only way to avoid SSTIs is to use protection.

Kyle Burgess 5 min read
Csaw Web

BucketWars

The hardest challenge for a CTFer to solve is how to lose their versionity.

Kyle Burgess 2 min read
Squ1rrel Web

Goosemon

I’d rather die than use a password manager. In other news, can anyone help me remember the login info for my account? The flag for this challenge is the account password.

Kyle Burgess 5 min read
Squ1rrel Web

Personal Website

Check out my personal website! I have a blog!

Nisala 4 min read
Squ1rrel Web

Mutex Lock

just solved distributed systems

Nisala 4 min read
Squ1rrel Web

Key Server

Well, my application is finally making it big – and I’ve heard that once you get over 10 users, using kubernetes is basically a must. Come check out my microservices!

Nisala 2 min read
Squ1rrel Web

JSON Store

Have you ever wanted to store some JSON data really quickly? Have we got the solution for you!

Nisala 3 min read
Blackhatmea Pwn

babysbx

Shellcode sandboxes make for a fun little game.

Patrick Dobranowski 17 min read
Patriotctf Forensics

Unsupported Format 2

Just a silly little forensics challenge.

Sam Sliman 1 min read
Sekaictf Rev

Guardians of the Kernel

Kernel can be a scary word. That’s alright though because we have an SMT solver on our team.

Patrick Dobranowski 11 min read
Patriotctf Web

Flower Shop

Bad news: pay-to-win made it to CTFs. Good news: we paid first.

Nisala 2 min read
Sekaictf Algo

Gluttonous Sheep

This sheep needs to chill out with the apples, I’m sure there’s plenty to go around.

Abi Kothapalli 11 min read
Sekaictf Web

Vulnerability Scanner

Scanner? Buddy!

Nisala 3 min read
Kitctfctf Rev

protector

This was a cool reversing challenge where I wrote a GDB script to undo obfuscated operations to get the flag.

Akash 7 min read
Htb Crypto

AESWCM

Cryptography transcends wizardry.

Holden Turner 16 min read
Kitctfctf Misc

Grep it? CodeQL it!

CodeQL: a surprisingly handy tool! Just need to read the instructions more carefully next time…

Zi Teoh 6 min read
Kitctfctf Web

Etherpad 1 & 2

LDAP me up, bro.

Kyle Burgess 6 min read
Nitectf Misc

The Boys

Miscellaneous sure is one way to describe it.

Sam Sliman 2 min read
Xmas Misc

Blocker, Cookie Market, & Bread Bank

Blockchain: a new way to program… and a new way to write vulnerable code.

David Perez 15 min read
Nitectf Web

un(documented)-js-api

DOM clobbering, domain takeovers, shared process slowdowns, and CSS exfiltration, oh my!

Nisala 8 min read
Kitctfctf Crypto

Prime Guesser 1 & 2

Who needs math when you can just guess?

Holden Turner 56 min read
Nitectf Forensics

Revisiting Classics

Paging Nick Gebo - Get Your Ass In Here

Sam Sliman 1 min read
Buckeyectf Misc

frog-universe

Welcome to Frog Universe!

Aryan Garg 33 min read
Buckeyectf Crypto

bonce

This challenge gives us two files, output.txt and bonce.py.

Evelyn 4 min read
Buckeyectf Pwn

stack duck

I love ducks, so I was a little saddened to see that this duck was a canary in disguise. Still a birb though!

Patrick Dobranowski 13 min read
Buckeyectf Crypto

SSSHIT

A crypto challenge that boils down to “3x - 3a + b = c”.

Sam Alws 6 min read
Buckeyectf Misc

spelunk

All of these challenges are too hard for me. Wait… is that Minecraft???

Maya 5 min read
Buckeyectf Crypto

powerball

I like free money. Crypto and lottery in the same sentence? Say less.

Aadi Bajpai 6 min read
Buckeyectf Misc

nile & andes

Despite having worked in smart contract security, I have never actually performed an attack before – until now. Let’s take a look at some not-so-smart contracts, shall we?

Ben Siraphob 11 min read
Buckeyectf Rev

cap

This litty challenge was highkey bussin bruh, on god, no cap fr fr. Sheeesh.

Abi Kothapalli 18 min read
Hacklu Crypto

Linear Starter

Every delicious meal needs a starter and I have great news for you: This one is even linear!

Zi Teoh 4 min read
Buckeyectf Rev

intel does what amd'ont

This was the first time I reversed a binary with obfuscated code!

Akash 12 min read
Buckeyectf Rev

crispyr

Rust is wonderful to write, but reversing it is quite the challenge.

Akash 8 min read
Buckeyectf Misc

devil

I can sorta do CTF problems – but deep down, I’m a DevOps guy.

Nisala 7 min read
Bluehensctf Misc

Rick and Morty - One Time Pad - Esoteric Languages

Memes as an internet subculture, World War era encryption schemes, and program states as stacks of dynamically sized integers, oh my! How do they all connect?

Patrick Dobranowski 20 min read
Buckeyectf Web

goober

How on earth do SVGs have so many security vulnerabilities?

Nisala 3 min read
Bluehensctf Misc

Wordles with Dads

Another variation of Wordle, just like my previous writeup on Vocaloid Heardle.

squ1rrel team 11 min read
Sekaictf Misc

Sus

Someone sent this file to me, claiming he got it from a SEKAI where the palette is not colorful but purple. I had no idea what he was talking about – I only

Evelyn 2 min read
Sekaictf Forensics

Broken Converter & flag Mono

A two-part CTF challenge!

Aryan Garg 5 min read
Bluehensctf Pwn

Intro to PWN 1-3

This was my first time doing a CTF, so I literally had no idea what was going on the whole time. But I do think I learned a good bit from just observing

squ1rrel team 6 min read
Bluehensctf Misc

CryptoDuck!

Digital circuits and Python: low-level meets high-level in the solution to this oddball of a challenge.

squ1rrel team 4 min read
Wreckctf Web

password-3

A quick but interesting proof-of-concept demonstrating that security by obscurity does not and will never work. Even if you don’t show reflected feedback from SQL commands, your database is still not safe.

Patrick Dobranowski 5 min read
Sekaictf Web

Bottle Poem

For this web challenge, we had to utilize two different exploits to get the flag – and one of them wasn’t a web exploit!

Akash 5 min read
Bluehensctf Forensics

The Quantum Realm

Forensics! Stego! Look, they even gave us an image! You know the drill.

squ1rrel team 2 min read
Bluehensctf Web

Firefun!

I love Firebase. So this really was the perfect challenge for me.

Nisala 4 min read
Sekaictf Web

Issues: Another JWT Challenge

Oh, JWTs. A well-intentioned standard, for sure – but my god, the number of implementation mistakes you can make.

Nisala 4 min read
Sekaictf Crypto

Secure Image Encryption!

One of the more solvable challenges… completed in the silliest way possible.

Kyle Burgess 7 min read
Sekaictf Misc

Vocaloid Heardle

Well, it’s just too usual to hide a flag in stegano, database, cipher, or server. What if we decide to sing it out instead?

Zi Teoh 8 min read
Sekaictf Misc

Matryoshka

ANSI escape codes. Race conditions in PNG parsing. Digital COVID-19 vaccination records. De-noising audio files and the NATO phonetic alphabet. The only thing linking all of them? A race to solve a CTF

Ben Siraphob 9 min read
squ1rrel © 2025
Latest Posts Twitter