Skip to content
RAYZHED
  • HomeAccueil
  • BlogBlog
  • ProjectsProjets
  • ToolsOutils
  • AboutÀ propos
/
/home/rayzhed/blog

// Blog

PostsArticles

Security research · hardware · tools · writeupsRecherche sécu · hardware · outils · writeups

CTF 13 JUN 2026

P'Hack 2026 / Ça vient et ça s'en va

Network forensics. PCAP analysis of an NTLM relay attack: identifying the coercion CVE, the two relay negotiate packets and extracting the NTLM challenge nonce.

forensics · network · wireshark 2 min →2 min →
CTF 13 JUN 2026

P'Hack 2026 / Screenshot - www-data

Web pentest walkthrough, flag 1/3. IDOR on a user API, hardcoded temp password, path traversal to PHP source disclosure, legacy extension bypass for webshell upload and RCE.

pentest · web · idor 2 min →2 min →
CTF 30 MAY 2026

InterIUT 2026 / Am I Root Now?

Realistic PWN walkthrough. Broken environment, four chained privilege escalations: zip, tar, PYTHONPATH hijack and vim SUID, all the way to root.

pwn · linux · privesc 5 min →5 min →
CTF 28 JAN 2026

HackDay 2026 / Ringbearer

Forensics challenge walkthrough. Windows registry dumps, hash cracking and chained credential extraction to reach the flag hidden inside a 7-zip archive.

forensics · windows · registry 3 min →3 min →
© 2026 Rayzhed rayzhed@gmail.com