💥Presenting the champions of p3rf3ctr00t CTF 2025! 🔥
🥇 1st Place — 0xfun
🥈 2nd Place — Al_Qabilah
🥉 3rd Place — Escadron
Congratulations to these outstanding teams for an incredible performance!
Thanks to all our sponsors and creators👏👏
💯💯P3rf3ctr00t CTF 2025 has officially come to an end🎉🎉. It was a great success. GG to everyone that participated and congrats to the winners.🎉🎉
UNTIL NEXT TIME👏👏
Also kudos to the support for 48 hrs of consistency😁😁
🗣️🗣️The wait is almost over! P3rf3ctr00t CTF 2025 is around the corner — bigger, tougher, and more thrilling than ever.🎉
Gear up to test your skills, push your limits, and prove your dominance in the cybersecurity arena.🔥🔥
💥 Coming soon…
Thanks to all our partners🙏🙏
Congrats again!!!🎉🎉, to the team @p3rf3ctr00t for bringing another one home . Led by @alvin_kidwiz we won the @SafaricomPLC PwnZone ctf. We are really umatched at this level😂😂. GG to all those legends who participated👍🏾👍🏾.
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
LINUX USERS ARE NOT HACKERS!
🚀 Kicking Off My Web3 Learning Journey Series!
I've received many questions about how I transitioned into Web3 Security. So, I’ve decided to share my exact learning journey, step by step.
This isn’t meant to be the ultimate guide. There are plenty of great resources out there (many probably better). But this is what genuinely worked for me, and I hope it’ll help in your own journey.
💣Pre-auth RCE in under 10 minutes. This vuln survived years of audits because it looked innocuous: forgotten service, commented code, and an obscure serializer. Humans skim past that, but AI doesn’t blink. 🤖
Plot twist: the FlexNetOperationsService was commented out in the config. Was this another dead end?🤔Well... the .svc file was still deployed. In IIS, that means the service was still live! Hacktron built a quick SOAP payload, fired it, and got a Windows directory listing back.
⚠️Then it landed on one weird serializer: NetDataContractSerializer. It turns out that this serializer embeds .NET metadata. Translation? It lets attackers sneak in full .NET objects if you’re not careful! The serializer lived inside a WCF service called FlexNetOperationsService.
Enter Hacktron — our AI security engineer. We gave it the decompiled .NET code and said: "Find pre-auth deserialization flaws". It tore through thousands of files in minutes. First stop: every .Deserialize() call it could see. Most were boring JSON converters with safe defaults.
Apple once ran this software. Multiple security firms poked at it. No one spotted the bug.
Here's a thread of how we found CVE-2025-5086 in Delmia Apriso... 👇🧵