At RWPL in SECCON 13, held on March 1, 2025, I contributed a self-made challenge, “RWPL Flowers,” as sub-content for the workshop and ran it hands-on on the day.
Event
| Event | RWPL in SECCON 13 |
| Date | March 1, 2025 |
| Venue | Asakusabashi Hulic Hall & Conference, Room 2, Tokyo |
RWPL is an event where participants split into small teams and experience either the offensive side (penetration testing) or the defensive side (SOC). See the connpass event page for details.
The challenge: “RWPL Flowers”
A two-stage CTF-style exercise spanning web and binary exploitation. The core of the walkthrough was source-code leakage via LFI, leading to RCE.
- Web part (user). Use LFI (local file inclusion) to leak the application’s source code, then turn that into RCE (remote code execution) to capture the first flag.
- Binary part (root). The target binary has a stack buffer overflow that gives control of RIP. For the hands-on, a PoC that crashes with RIP =
0x42424242was already placed on the server, and participants only had to redirect execution to thewin()function — escalating privileges and capturing the second flag.
Participants were given the distribution files and worked through it themselves, with hints along the way.
Solution video
I’ve published a walkthrough of the intended solution. Play it from the thumbnail below.