•
•
•
•
•
•
•
•
The Ordinary PlayerThe Ordinary Player
HomePosts & WriteupsMembersContests

© 2025 - 2026 The Ordinary Player. All rights reserved.
Website theme & implementation © Rosemary (blog.rosemary.my.id)

Posts & Writeups

The Ordinary Player CTF team writeups, research, and analysis.

Showing 1–6 of 6 entries
Dec 11, 2025•Cyber Security•
...

Advent of Cyber 2025 Day 6-10

Every year, TryHackMe hosts an Advent of Cyber event where they release a new room every day leading up to Christmas. This post will contain my writeups for Advent of Cyber 2025 day 6-10.

By Rosemary • 26 min readRead writeup
Dec 6, 2025•Cyber Security•
...

Advent of Cyber 2025 Day 1-5

Every year, TryHackMe hosts an Advent of Cyber event where they release a new room every day leading up to Christmas. This post will contain my writeups for Advent of Cyber 2025 day 1-5.

By Rosemary • 30 min readRead writeup
Nov 24, 2025•Cyber Security•
...

🔐 SecureAuth™ (Web) - PatriotCTF

This writeup shows how the SecureAuth™ API in PatriotCTF 2025 could be bypassed using a NoSQL injection trick by sending a password field with a MongoDB operator, allowing instant admin access and revealing the flag.

By Rosemary • 2 min readRead writeup
Nov 24, 2025•Cyber Security•
...

Trust Fall (Web) - PatriotCTF

A product-catalog app in PatriotCTF 2025 hid an IDOR vulnerability behind a hard-coded read-only token. By probing the backend API, user data could be accessed simply by changing the ID in the request. Enumerating those IDs eventually revealed the root profile, which exposed the flag and confirmed the app’s missing authorization controls.

By Rosemary • 3 min readRead writeup
Nov 24, 2025•Cyber Security•
...

Vorpal Masters (Web) - PatriotCTF

This writeup reverses a small license binary from PatriotCTF 2025 to recover the valid key CACI-2025-PatriotCTF. By inspecting the format string, strcmp checks, byte-by-byte comparisons, and a simple arithmetic check on the numeric field, the three segments are revealed and assembled into the final license.

By Rosemary • 3 min readRead writeup
Nov 1, 2025•Cyber Security•
...

Timelock (Blockchain) - QnQSec 2025

This writeup explains how the Timelock contract in QnQSec 2025 could be bypassed by abusing ERC-20 allowances. While the timelock blocked direct transfers from the player, it didn’t restrict transferFrom, allowing an attacker to drain the player’s tokens through an approved spender.

By Rosemary • 3 min readRead writeup
The Ordinary PlayerThe Ordinary Player
HomePosts & WriteupsMembersContests

© 2025 - 2026 The Ordinary Player. All rights reserved.
Website theme & implementation © Rosemary (blog.rosemary.my.id)