Files
mcpedia/content/writeups/ctf/template/writeup-template.md
T
asepharyana c760c3c087
CI / typecheck + build (turbo) (push) Canceled after 0s
feat(core): dynamic custom frontmatter fields for CTF writeup metadata
- Add extra_fields JSONB column to documents table (migration 0003)
- CreateDocInput/UpdateDocInput: extraFields?: Record<string, string>
- parseFile: extracts non-standard frontmatter keys as extraFields
- stringifyFile: writes extraFields dynamically to YAML frontmatter
- toMeta: spreads extraFields from DB row into DocumentMeta
- DocForm: '+ Add field' UI for content creators to add any metadata
- API routes: splitPayload() separates standard vs custom fields
- Doc page: CustomFieldBadges dynamically renders any custom field
- Add db:migrate / db:push scripts + deploy workflow migration step
- Add CTF writeup template (content/writeups/ctf/template/)
- Add sample DEF CON writeup with event/challenge/category/difficulty/points
- Add @tailwindcss/typography for table rendering (prose classes)
- Add remark-gfm for GitHub Flavored Markdown table parsing
2026-08-20 23:18:57 +07:00

77 lines
1.7 KiB
Markdown

---
id: ctf-writeup-template
title: "CTF Writeup Template — How to Structure a Challenge Writeup"
type: writeup
tags:
- ctf
- template
- methodology
status: draft
author: asep
created_at: 2026-08-20
updated_at: 2026-08-20
---
# CTF Writeup Template
A consistent writeup structure helps reviewers and future-you reproduce the solve.
Below is the recommended template. Delete this intro paragraph and fill each
section.
## Challenge Info
| Field | Value |
| ------------ | -------------------- |
| **Event** | `[Event Name]` |
| **Challenge**| `[Challenge Name]` |
| **Category** | `pwn` / `crypto` / `web` / `rev` / `forensics` / `misc` |
| **Difficulty**| `easy` / `medium` / `hard` |
| **Points** | `[points at start]` |
| **Solves** | `[number]` |
## Initial Recon
What you see when you download the binary/file/URL. File type, basic
inspection (`file`, `strings`, `checksec`, HTTP headers, etc.).
## Approach
Describe the high-level idea — what class of vulnerability or attack this
belongs to.
## Step-by-Step Solve
Walk through each step with commands and output. Include:
- Exact commands you ran
- Key output (truncated if long, but enough to confirm)
- Why each step works
- Tool versions / versions if relevant
### 1. Enumerate
```
$ command-here
output-here
```
### 2. Find the vulnerability
Explain what you found and how it maps to the approach.
### 3. Craft the exploit
Show the exploit script or payload, explain each part.
## Flag
```
flag{...}
```
## Summary
What you learned, what the intended solution was (if yours differed),
and any pitfalls you hit along the way (e.g., "tool X version Y breaks
on Z").