XeroExecute Blog

Recent Posts

Rust Tickler 3 - Huntress CTF 2025 Reverse Engineering Writeup

Complete walkthrough of Rust Tickler 3, a multi-stage Rust reverse engineering challenge from Huntress CTF 2025. Covers dynamic analysis, memory extraction, custom PRNG XOR cipher, and AES-256-CBC decryption techniques.

No Limits - Huntress CTF 2025 PWN Challenge Writeup

Complete writeup for “No Limits” PWN challenge from Huntress CTF 2025. Exploit a parent-child process architecture to bypass seccomp restrictions using /proc/pid/mem and GOT hijacking techniques.

TryHackMe: Industrial Intrusion - auth (9005)

A reverse engineering challenge involving XOR decoding and memory comparison to retrieve the flag from a remote industrial gateway.

SwampCTF: You Shall Not Passss

This writeup details the solution to the “You Shall Not Passss” reverse engineering challenge from SwampCTF, involving dynamic analysis with Ghidra and gdb to decrypt the flag, and analysis of shellcode execution.

Try Hack Me Hackfinity Battle CTF

Try Hack Me Hackfinity Battle CTF Writeups

Sqlate IrisCTF 2025 (pwn)

Exploit writeup for the Sqlate challenge from IrisCTF 2025 by lambda, involving a buffer overflow in a custom encoding mechanism to escalate privileges and retrieve the flag.

Huntress 2024

My notes on five challenges from Huntress CTF 2024: Whamazon, Keyboard Junkie, MOVEable, Strange Calc and OceanLocust. The challenges were solved as part of the Dombusters team.