squ1rrel
  • Home
  • About
  • Team
  • CTFTime

web

Writeups on web challenges.

Squ1rrel Web

Portrait

It’s like DeviantArt, but with a report button to keep it less Deviant.

Kyle Burgess 4 min read
Squ1rrel Web

Go Getter

There’s a joke to be made here about Python eating the GOpher. I’ll cook on it and get back to you.

Kyle Burgess 3 min read
Squ1rrel Web

Acorn Clicker

Click acorns. Buy squirrels. Profit.

Kyle Burgess 3 min read
Csaw Web

Lost Pyramid

The only way to avoid SSTIs is to use protection.

Kyle Burgess 5 min read
Csaw Web

BucketWars

The hardest challenge for a CTFer to solve is how to lose their versionity.

Kyle Burgess 2 min read
Squ1rrel Web

Goosemon

I’d rather die than use a password manager. In other news, can anyone help me remember the login info for my account? The flag for this challenge is the account password.

Kyle Burgess 5 min read
Squ1rrel Web

Personal Website

Check out my personal website! I have a blog!

Nisala 4 min read
Squ1rrel Web

Mutex Lock

just solved distributed systems

Nisala 4 min read
Squ1rrel Web

Key Server

Well, my application is finally making it big – and I’ve heard that once you get over 10 users, using kubernetes is basically a must. Come check out my microservices!

Nisala 2 min read
Squ1rrel Web

JSON Store

Have you ever wanted to store some JSON data really quickly? Have we got the solution for you!

Nisala 3 min read
Patriotctf Web

Flower Shop

Bad news: pay-to-win made it to CTFs. Good news: we paid first.

Nisala 2 min read
Sekaictf Web

Vulnerability Scanner

Scanner? Buddy!

Nisala 3 min read
Kitctfctf Web

Etherpad 1 & 2

LDAP me up, bro.

Kyle Burgess 6 min read
Nitectf Web

un(documented)-js-api

DOM clobbering, domain takeovers, shared process slowdowns, and CSS exfiltration, oh my!

Nisala 8 min read
Buckeyectf Web

goober

How on earth do SVGs have so many security vulnerabilities?

Nisala 3 min read
Wreckctf Web

password-3

A quick but interesting proof-of-concept demonstrating that security by obscurity does not and will never work. Even if you don’t show reflected feedback from SQL commands, your database is still not safe.

Patrick Dobranowski 5 min read
Sekaictf Web

Bottle Poem

For this web challenge, we had to utilize two different exploits to get the flag – and one of them wasn’t a web exploit!

Akash 5 min read
Bluehensctf Web

Firefun!

I love Firebase. So this really was the perfect challenge for me.

Nisala 4 min read
Sekaictf Web

Issues: Another JWT Challenge

Oh, JWTs. A well-intentioned standard, for sure – but my god, the number of implementation mistakes you can make.

Nisala 4 min read
squ1rrel © 2025
Latest Posts Twitter