Hello! We’ve just launched a new wargame site called damn vulnerable web!
It consists only of web challenges, primarily designed for intermediate to advanced players rather than beginners.
We hope this wargame helps more people gain deeper and broader knowledge in web hacking :)
For now, we’re planning to accept only 300 users initially for open beta testing and capacity checks.
Starting from this tweet, we’ll gradually increase the number of allowed sign-ups each week. Your interest and support will be a huge help to our future activities
We’ll do our best to deliver even better work going forward. Thank you!
Wargame site: https://t.co/9iER5IGfSP
Join our Discord: https://t.co/gWTx9jUvtT
We’ve published a new article! This is a full writeup of the web challenges from the SECCON 14 Qual round. It has been written in detail so that readers can understand the core concepts and techniques even if they did not attempt the challenges themselves.
We would like to express our sincere gratitude to the researchers @Predic02 , @masamunee2003 , @ElleuchX1 , and @ irogir for their hard work on this writeup.
To everyone reading this, we wish you a very happy New Year 2026! We’re planning to release something new that we’ve been preparing between January and February, so please stay tuned and show lots of interest : )
What a fierce competition! A massive shoutout to our Top 3 for their god-tier skills:
🥇 no rev/pwn no life - Unstoppable!
🥈 Kalmarunionen - Legendary performance.
🥉 RubiyaLab - Simply brilliant.
Thank you to every team who accepted the challenge.
#ASISCTF
This weekend, I participated in @cykorctf under the name of @ everyone and placed 6th.
And my teammate succeeded in first-blood and everyone injection was successfully performed! 🩸
We have successfully published our third research!
This research focuses on diving deep into the Spring framework. Spring is an important framework used by many companies. However, since the Spring framework doesn't frequently appear in challenges, we expect many people are unfamiliar with it
Through this research, we conducted an in-depth study of the Spring framework centered on case studies - what the Spring framework is and what actual bug cases have occurred.
We hope it receives a lot of interest! : )
We have published a new article! You can check out the research in both Korean and English versions below :)
This article is not research, but a complete writeup of the web challenges from the CODEGATE 2025 final round. We have organized it in as much detail as possible so that you can understand the core concepts even without code comprehension of the challenges
We will show more activities going forward. Please show us lots of interest and look forward to it! We deeply appreciate @goldleo01 and @Predic02 for their hard work in writing the writeup
Our Bootkitty team will announcing "A Stealthy Bootkit-Rootkit Against Modern Operating Systems" soon at USENIX WOOT25.
Stay tuned for upcoming presentation.
Credit:
@B1ack3at, @jihoonab151, HyunA Seo, @Iranu96, @wh1te4ever, Jinho Jung, Hyungjoon Koo.
https://t.co/NCyfnqqqXv
We have successfully published our second research!
This research focuses on various XSLeaks techniques through real case studies. It explains why XSLeaks are dangerous in the real world and how XSLeaks techniques can be utilized in challenges such as CTFs.
This is a series research consisting of 3 parts! We hope it will attract a lot of interest :)
Upstream HTTP/1.1 is inherently insecure and consistently exposes millions of websites to hostile takeover.
Six years after we exposed the threat of HTTP desync attacks, there's still no end in sight.
On August 6, at Black Hat USA, James Kettle from PortSwigger Research will reveal new classes of desync attack that enabled him to compromise multiple CDNs and kick off the desync endgame.
Follow @PortSwigger for the full reveal!
More info 👇
https://t.co/kr6SR4JOw3