-
Executing a Textbook ret2libc Attack to Pop a Shell
This writeup is also readable on my GitHub repository and team website. It’s been a while since I’ve written a CTF writeup! I’ve been very busy with school and work for the past year or so, and so my writeup authoring skills may be a bit rusty. From 9 July...
-
Excited to Compete at redpwnCTF 2021
My team, IrisSec, will be competing at redpwnCTF 2021. I don’t usually announce these kinds of things on my blog, but I’m particularly excited about this event since I’ve done redpwnCTF in the past before and have high expectations for them. We’re going to be participating in the college division...
-
nya! Devlog 2
Being back home in Merced, I’ve finally been able to get some peace and quiet and work on the daemon I’ve been writing for nya! again. It’s nice to be able to program recreationally in peace and silence again. I’ve gotta check up on the other subteams soon to see...
-
SVG-Based XSS
My team recently competed at WeCTF 2021, a competition organized and hosted by students at the University of California, Santa Barbara. WeCTF was a great competition and I had a great time. One of the things I learned about was SVG-based XSS, an XSS attack vector in which arbitrary JavaScript...
-
Slowly Slipping into Summertime Stresses
I’ve needed to write a personal blog post for a few weeks now. I’ve been visiting my family and hometown these past few weeks and to be honest, it’s been quite hellish. I am very much looking forward to going back to Merced soon – back to my school, my...
-
Starting a New Networking Project
That’s right: I’m starting yet another project! This one was spawned out of necessity for my workplace at UC Merced IT Network and is much more technical and specific than the other projects I’m doing this summer. Over the next uncertain length of time, I’m going to be writing a...
-
nya! Devlog 1
This is the second week working on nya! with my team. By now, I’ve just about finished up the daemon and its respective specifications, and the visualization engine team has finished a few graph generators already. The daemon is still in the midst of heavy testing and tweaking to ensure...
-
nya! Devlog 0
Last week, I mentioned a project I was starting called “nya! - nginx: Your Analytics.” I started work on it this week, but not before recruiting a few of my peers to get a team together for some help. This week was mainly just a lot of orientation and then...
-
Summer Projects
Now that I’m officially on summer break, it’s time to get started on my summer projects! I’ve got a lot planned for this summer. I’m really excited to get started, and many of these projects are things that I’ve been planning to do for a while now but just didn’t...
-
The End of My Second Year
Well, that’s the end of that. Yesterday morning, I finished my last final exam of the spring semester. It’s done. I’ve completed my second year of college. I’m glad it’s over with. I’m going to be spending some time resting and recovering and rallying up my energy and motivation again,...
-
The Fog of Memories
The past is something that’s been on my mind a lot lately. I’ve been reminiscing, remembering, and re-living, and I know that living in the past is not necessarily healthy behavior, but it’s like a sort of defense mechanism for me in my times of need. Some people escape to...
-
The Ugliness of Cancel Culture
I felt compelled to author this in response to recent events taking place at my university, a single case of the much broader dangerous culture shift I’ve observed taking place in my generation. As the title of this post may have given away, I am of course talking about “cancel...
-
Hanging On, Holding On
It’s been quite a busy week! Yesterday I had a quiz for Dynamics and a midterm for Computer Organization, and today I have a midterm coming up for Algorithm Design and Analysis. Tomorrow, I have a project draft due for Statics, and then it’s followed by another project due on...
-
IrisSec Wins the National Cyber League
I’m happy to announce that we’ve just won the National Cyber League, Spring 2021 season! We ranked first place out of 922 teams total. This is the second consecutive season we’ve won first place, and so we’re proud to defend our title. Our team lineup for this event was: [[nope]]...
-
No Post This Week
There will be no post this week. I’m currently going through both tough and busy times, and did not have the time to finish what I was planning on publishing today. Happy trails.
-
Zero-Width Character Steganography
Zero-width character steganography is one of my most favorite steganography techniques due to its genius simplicity. For the uninitiated, steganography is the act of hiding some sort of data, such as a plaintext, in a form of cover data. Zero-width character steganography can embed any form of encodable data into...