Kalmarunionen
open-menu closeme
News icon
2026 - KalmarCTF 2026 Wrap-Up 🎉 2026 - KalmarCTF is back for its 4th year! 2026 - WE WON SECCON CTF FINALS 2026 IN JAPAN 🇯🇵🏆 2026 - Kalmarunionen finishes #2 in the world on CTFtime 2025 2025 - Four Weeks of Wins: Kalmarunionen Takes 1st Place at Hack.lu CTF! 🏆 2025 - Kalmarunionen Wins Google Hackceler8 in Mexico City 🏆🇲🇽 2025 - We did it: Kalmarunionen just won ASIS CTF - our 4th ASIS WIN! 2025 - 2nd at GoogleCTF, Mid-Season World #1 - and a visit from the Minister! 2025 - Triple CTF Weekend 2025 - KalmarCTF 2025 - Kalmarunionen is now officially the #1 competitive hacking team in the world! 2024 - Chaos Communication Congress (38C3) HXP CTF 2024 - SECCON CTF 2024 - Cybersecurity Awareness Month 2024 - Google CTF 2024 - Aim for DEFCON Glory - Call for sponsors 2024 - Kalmar CTF 2024 - Real World CTF
Writeups icon
ASIS CTF - xtr BambooFox CTF: The Vault BSidesSF 2021: Log 'em All De Danske Cybermesterskaber: 80s Commitments De Danske Cybermesterskaber: Kuuuurveen FaustCTF 2021 - Attack & Defense - thelostbottle Hack.lu CTF - Nodenb LKVM Escape MidnightSun Quals: kgbfskfsb MidnightSun Quals: Revver Pwn2win - Hackus Qiling Sandbox Escape Real World CTF 4th: Secured Java SekaiCTF 2023 - Leakless Note Sudo Exploit Writeup Union CTF 2021: Cr0wnAir
Become a member
Sponsors
About
  • Qiling Sandbox Escape

    calendar January 24, 2022 · 11 min read · clone-and-pwn qiling sandbox-escape  ·
    Share on: twitter facebook linkedin copy

    Writeup by: Oliver Lyak (ly4k)

    Solved by: Zopazz, Oliver Lyak (ly4k)

    <img
      loading="lazy"
      decoding="async"
      alt="Challenge description"
      
        class="image_figure image_internal image_unprocessed" …</picture></figure></p>
    

    Read More
  • Real World CTF 4th: Secured Java

    calendar January 23, 2022 · 4 min read  ·
    Share on: twitter facebook linkedin copy

    Writeup by: Nicolai Søborg

    Solved by: Nicolai Søborg, Rasmus Have

    This year we managed to land a 13 place, again! (which is really a shame as top 12 gets swag …)

    The challenge is a single python file that allows you to “run untrusted Java in a safe way”.

    The code boils down to:

    1. you upload two files: …

    Read More
  • LKVM Escape

    calendar December 17, 2021 · 18 min read · web race-conditions  ·
    Share on: twitter facebook linkedin copy

    Writeup by: Zanderdk | linkedin

    Solved by: ZZZ | linkedin, N00byedge | linkedin

    Indie VMM - HXP 2021

    In this challenge we are given a root access to a linux machine running in the linux tools hypervisor and the goal is to escape out of the hypervisor to access the flag file on the host system. During this challenge we …


    Read More
  • Hack.lu CTF - Nodenb

    calendar October 30, 2021 · 11 min read · web race-conditions  ·
    Share on: twitter facebook linkedin copy

    Writeup by: andyandpandy

    Solved by: andyandpandy, Hako

    Writeup

    The challenge has a race condition vulnerability, where you can delete your user and rapidly after send another request for the flag, which is successful when timed correctly.

    Description

    Web challenge

    Challenge author: pspaul/SonarSource

    To keep track of …


    Read More
  • Pwn2win - Hackus

    calendar June 18, 2021 · 4 min read  ·
    Share on: twitter facebook linkedin copy

    Writeup by: andyandpandy

    Solved by: andyandpandy, eskildsen, 2by4

    Writeup

    This is most likely an unintended solution.

    TL;DR: Create a note with two iframes. First iframe gets /s/secret-note, second gets from evil.com, which returns a html page where another iframe is loaded based on an 0-day CVE-2021-39175 in a …


    Read More
  • FaustCTF 2021 - Attack & Defense - thelostbottle

    calendar June 13, 2021 · 8 min read · attack-defense game python misc  ·
    Share on: twitter facebook linkedin copy

    Writeup author: Bawstaws

    The Lost Bottle is the most awesome pirate game. It is about a young pirate, that lost her favorite bottle of old rum. She is now doomed to drink ordinary rum until she finds her bottle.

    Flags: 2531.00

    Tags: rev, misc, game

    Introduction

    After discovering that this is a game challenge I …


    Read More
  • De Danske Cybermesterskaber: Kuuuurveen

    calendar May 9, 2021 · 3 min read · Crypto  ·
    Share on: twitter facebook linkedin copy

    Writeup by: ChrRaz

    We are given the following challenge description. A client and a server have been communicating the flag over an encrypted channel.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    
    Der er en Kuuuuuuuuuuuuuuurveeeeeee, er den ikke smuk?
    En client og en server kommunikere over en krypteret kommunikationskanal. Se …

    Read More
  • De Danske Cybermesterskaber: 80s Commitments

    calendar May 9, 2021 · 5 min read · Crypto  ·
    Share on: twitter facebook linkedin copy

    Writeup by: ChrRaz

    When opening http://80s-commitments.hkn we are greeted with the following page:

    <img
      loading="lazy"
      decoding="async"
      alt="The main page"
      
        class="image_figure image_internal image_unprocessed" …</picture></figure></p></!--></!-->
    

    Read More
  • BSidesSF 2021: Log ’em All

    calendar March 20, 2021 · 14 min read · c++ use-after-free  ·
    Share on: twitter facebook linkedin copy

    Challenge Description (967 points)

    Play to win and log ’em all! Once you’ve seen all 151 Asciimon, talk to Professor Jack for the flag. We’ve included some data for the first couple rooms, you’ll have to figure out the rest yourself!

    nc -v logemall-a2db138b.challenges.bsidessf.net 666

    (author: …


    Read More
  • Union CTF 2021: Cr0wnAir

    calendar February 25, 2021 · 3 min read  ·
    Share on: twitter facebook linkedin copy

    Writeup by: Nicolai Søborg

    TL;DR - bypassing a filter to generate two JWTs (RS256). Finding e and N from the two signatures and forge an arbitrary JWT (HS256).

    Step 1: Getting two RS256 signatures

    To get a signature we need to bypass a filter validated by jpv (“JSON Pattern Validator”).

    This package has a …


    Read More
    • ««
    • «
    • 1
    • 2
    • 3
    • »
    • »»

Recent Posts

  • 2026 - KalmarCTF 2026 Wrap-Up 🎉
  • 2026 - KalmarCTF is back for its 4th year!
  • 2026 - WE WON SECCON CTF FINALS 2026 IN JAPAN 🇯🇵🏆
  • 2026 - Kalmarunionen finishes #2 in the world on CTFtime 2025
  • 2025 - Four Weeks of Wins: Kalmarunionen Takes 1st Place at Hack.lu CTF! 🏆
  • 2025 - Kalmarunionen Wins Google Hackceler8 in Mexico City 🏆🇲🇽
  • 2025 - We did it: Kalmarunionen just won ASIS CTF - our 4th ASIS WIN!
  • 2025 - 2nd at GoogleCTF, Mid-Season World #1 - and a visit from the Minister!

Categories

NEWS 18 WRITEUPS 17 DDC 2021 2 MIDNIGHTSUN 2 BSIDESSF 2021 CTF 1 FAUST CTF 2021 1 HACK.LU CTF 1 HXP 1 REAL CVE 1 REAL WORLD CTF 1 SEKAICTF 2023 1

Tags

LINKEDIN 18 CRYPTO 8 2024 7 NEWS 5 WEB 5 HACKING 4 KALMARCTF 4 RACE-CONDITIONS 3 2026 2 CTFTIME 2 GOOGLECTF 2 JOURNEY 2 REV 2 SECCONCTF 2 XSS 2 38C3 1 ADVANCED WEB 1 ASIS 1 ATTACK-DEFENSE 1 BREAKTHESYNTAXCTF 1 C++ 1 CLONE-AND-PWN 1 CTF 1 CYBERSECURITYAWARENESSMONTH 1 DAMCTF 1 GAME 1 GOOGLE CTF 1 HACKCELER8 1 HACKLU 1 HXPCTF 1 JAPAN 1 MEXICO 1 MIDNIGHT SUN 1 MISC 1 PLAIDCTF 1 PWN 1 PYTHON 1 QILING 1 RCE 1 REAL WORLD CTF 1 REAL-WORLD 1 SANDBOX-ESCAPE 1 SANDIEGOCTF 1 SUDO 1 SUNDHEDSKORT 1 UMDCTF 1 USE-AFTER-FREE 1 XS-SEARCH 1 Z3 1

Sponsor Highlight

Kalmarunionen is proudly sponsored by:

  • Dubex
  • JN Data
  • ICSRange
  • CyberSkillsDK
  • Industriens Fond
Kalmarunionen

Copyright 2020-  KALMARUNIONEN. All Rights Reserved

to-top