CI / typecheck + build (turbo) (push) Canceled after 0s
- Add extra_fields JSONB column to documents table (migration 0003) - CreateDocInput/UpdateDocInput: extraFields?: Record<string, string> - parseFile: extracts non-standard frontmatter keys as extraFields - stringifyFile: writes extraFields dynamically to YAML frontmatter - toMeta: spreads extraFields from DB row into DocumentMeta - DocForm: '+ Add field' UI for content creators to add any metadata - API routes: splitPayload() separates standard vs custom fields - Doc page: CustomFieldBadges dynamically renders any custom field - Add db:migrate / db:push scripts + deploy workflow migration step - Add CTF writeup template (content/writeups/ctf/template/) - Add sample DEF CON writeup with event/challenge/category/difficulty/points - Add @tailwindcss/typography for table rendering (prose classes) - Add remark-gfm for GitHub Flavored Markdown table parsing
77 lines
1.7 KiB
Markdown
77 lines
1.7 KiB
Markdown
---
|
|
id: ctf-writeup-template
|
|
title: "CTF Writeup Template — How to Structure a Challenge Writeup"
|
|
type: writeup
|
|
tags:
|
|
- ctf
|
|
- template
|
|
- methodology
|
|
status: draft
|
|
author: asep
|
|
created_at: 2026-08-20
|
|
updated_at: 2026-08-20
|
|
---
|
|
|
|
# CTF Writeup Template
|
|
|
|
A consistent writeup structure helps reviewers and future-you reproduce the solve.
|
|
Below is the recommended template. Delete this intro paragraph and fill each
|
|
section.
|
|
|
|
## Challenge Info
|
|
|
|
| Field | Value |
|
|
| ------------ | -------------------- |
|
|
| **Event** | `[Event Name]` |
|
|
| **Challenge**| `[Challenge Name]` |
|
|
| **Category** | `pwn` / `crypto` / `web` / `rev` / `forensics` / `misc` |
|
|
| **Difficulty**| `easy` / `medium` / `hard` |
|
|
| **Points** | `[points at start]` |
|
|
| **Solves** | `[number]` |
|
|
|
|
## Initial Recon
|
|
|
|
What you see when you download the binary/file/URL. File type, basic
|
|
inspection (`file`, `strings`, `checksec`, HTTP headers, etc.).
|
|
|
|
## Approach
|
|
|
|
Describe the high-level idea — what class of vulnerability or attack this
|
|
belongs to.
|
|
|
|
## Step-by-Step Solve
|
|
|
|
Walk through each step with commands and output. Include:
|
|
|
|
- Exact commands you ran
|
|
- Key output (truncated if long, but enough to confirm)
|
|
- Why each step works
|
|
- Tool versions / versions if relevant
|
|
|
|
### 1. Enumerate
|
|
|
|
```
|
|
$ command-here
|
|
output-here
|
|
```
|
|
|
|
### 2. Find the vulnerability
|
|
|
|
Explain what you found and how it maps to the approach.
|
|
|
|
### 3. Craft the exploit
|
|
|
|
Show the exploit script or payload, explain each part.
|
|
|
|
## Flag
|
|
|
|
```
|
|
flag{...}
|
|
```
|
|
|
|
## Summary
|
|
|
|
What you learned, what the intended solution was (if yours differed),
|
|
and any pitfalls you hit along the way (e.g., "tool X version Y breaks
|
|
on Z").
|