Files
mcpedia/content/writeups/ctf/template/writeup-template.md
T
asepharyana c760c3c087
CI / typecheck + build (turbo) (push) Canceled after 0s
feat(core): dynamic custom frontmatter fields for CTF writeup metadata
- Add extra_fields JSONB column to documents table (migration 0003)
- CreateDocInput/UpdateDocInput: extraFields?: Record<string, string>
- parseFile: extracts non-standard frontmatter keys as extraFields
- stringifyFile: writes extraFields dynamically to YAML frontmatter
- toMeta: spreads extraFields from DB row into DocumentMeta
- DocForm: '+ Add field' UI for content creators to add any metadata
- API routes: splitPayload() separates standard vs custom fields
- Doc page: CustomFieldBadges dynamically renders any custom field
- Add db:migrate / db:push scripts + deploy workflow migration step
- Add CTF writeup template (content/writeups/ctf/template/)
- Add sample DEF CON writeup with event/challenge/category/difficulty/points
- Add @tailwindcss/typography for table rendering (prose classes)
- Add remark-gfm for GitHub Flavored Markdown table parsing
2026-08-20 23:18:57 +07:00

1.7 KiB

id, title, type, tags, status, author, created_at, updated_at
id title type tags status author created_at updated_at
ctf-writeup-template CTF Writeup Template — How to Structure a Challenge Writeup writeup
ctf
template
methodology
draft asep 2026-08-20 2026-08-20

CTF Writeup Template

A consistent writeup structure helps reviewers and future-you reproduce the solve. Below is the recommended template. Delete this intro paragraph and fill each section.

Challenge Info

Field Value
Event [Event Name]
Challenge [Challenge Name]
Category pwn / crypto / web / rev / forensics / misc
Difficulty easy / medium / hard
Points [points at start]
Solves [number]

Initial Recon

What you see when you download the binary/file/URL. File type, basic inspection (file, strings, checksec, HTTP headers, etc.).

Approach

Describe the high-level idea — what class of vulnerability or attack this belongs to.

Step-by-Step Solve

Walk through each step with commands and output. Include:

  • Exact commands you ran
  • Key output (truncated if long, but enough to confirm)
  • Why each step works
  • Tool versions / versions if relevant

1. Enumerate

$ command-here
output-here

2. Find the vulnerability

Explain what you found and how it maps to the approach.

3. Craft the exploit

Show the exploit script or payload, explain each part.

Flag

flag{...}

Summary

What you learned, what the intended solution was (if yours differed), and any pitfalls you hit along the way (e.g., "tool X version Y breaks on Z").