minaminao

1.3K posts

minaminao banner
minaminao

minaminao

@vinami

security researcher, 🦙@AlpacaHack, ja:@2llr

เข้าร่วม Mart 2016
564 กำลังติดตาม2.2K ผู้ติดตาม
minaminao
minaminao@vinami·
@rian_tkb これは絶対書いたほうが良く、追記しました(競技ではないのでヒントの追加は許されてほしい) こういう感想、めちゃくちゃありがたいです……
日本語
1
0
2
416
りあん
りあん@rian_tkb·
今日の daily alpacahack、client-side 問題を解いたことないせいで(というよりかは docker と dns が何もわからないせいで)めちゃくちゃな勘違いをしていた、こういうのこそ初心者向けヒントに書いておいてほしいが、単に自分がアホすぎるだけかも
日本語
1
1
6
2K
minaminao รีทวีตแล้ว
AlpacaHack
AlpacaHack@AlpacaHack·
We've launched Daily AlpacaHack, our daily CTF challenge 🎄 Beginner-friendly challenges every day: • New problems on weekdays • Selected problems from external CTFs on weekends Now fully available in English! alpacahack.com/daily?lang=en
AlpacaHack tweet media
English
0
8
59
3.7K
minaminao
minaminao@vinami·
@tko919_ @rsk0315_h4x 横からすみません。フラグ提出フォームにplaceholderがあり、そこにフラグフォーマットは明示されています。確かにCTFをやっていないと気づきにくいので問題文に注意書きしておくべきでしたね……(一応printableな文字列になることは間違いないのでprefixがわからなくても解くことはできます)
minaminao tweet media
日本語
0
0
2
182
TKO
TKO@tko919_·
@rsk0315_h4x TSG LIVEの過去問であることしか明記されていないように見えるんですが、prefixが固定であることはコンテストページに行かないと分からなくないですか?(CTFの不文律を何も知らないので適当なことを言っています)
日本語
1
0
1
323
TKO
TKO@tko919_·
daily alpacahackのsize limitのwriteupを読んだが、prefixが分かっていないと解きようがなくないか
日本語
1
0
1
677
minaminao รีทวีตแล้ว
jinu
jinu@lj1nu·
I participated in ICC 2025. ICC is a CTF where teams compete by continent, with both Jeopardy-style and Attack & Defense CTFs. I wanted to share a fun story from the A&D, where I tried exploit other teams internal tools. Thanks to the organizers and players @icctokyo2025
jinu tweet media
English
1
7
69
5.5K
Chovid99
Chovid99@Chovid99·
Thanks for the memories @icctokyo2025. I enjoyed the event a lot, probably one of the best and most fun CTFs so far. The pwn challenges’ quality was top notch. Huge thanks to the ASEAN team for giving me the chance to represent, and huge thanks to the ICC organizers ❤️
Chovid99 tweet media
English
1
0
86
2.7K
minaminao
minaminao@vinami·
Last week, I enjoyed COMPFEST and got two first bloods. First time using Huff "2", and the new builtins made building contracts easier. Also played JailCTF, not blockchain but really one of my favorites CTFs
English
0
0
5
644
minaminao
minaminao@vinami·
pushed the challs for hitcon, 07ctf, and cbc github.com/minaminao/my-c… tried making a rev one on EVM that could easily be solved using a symbolic execution engine like hevm, but it ended up with 0 solves😭 hevm is now highly compatible with Foundry, the experience was quite good
minaminao tweet media
English
1
1
38
3K
minaminao รีทวีตแล้ว
DeFiHackLabs
DeFiHackLabs@DeFiHackLabs·
HITCON CTF 2025 Date: UTC 08/22 14:00 ~ 08/24 14:00 ctf2025.hitcon.org Thanks to @vinami from DeFiHackLabs for creating the web3 challenges for HITCON.
English
0
2
11
2.2K
minaminao รีทวีตแล้ว
Asian Cyber Security Challenge (ACSC)
🎯 ACSC 2025 Registration is OPEN! 🕛 Start: Aug 16 (Sat) 12:00 noon 🕛 End: Aug 17 (Sun) 12:00 noon 🔗 Register now: docs.google.com/forms/d/e/1FAI… 🌐 Official site: acsc.asia 🎮 The game is open to ALL players. 🌍 Finalists will be selected from ACSC member countries for #ICCTokyo2025 — but everyone’s welcome to join and play! #ctf #acsc_ctf #icctokyo2025 #cybersecurity
Asian Cyber Security Challenge (ACSC) tweet media
English
2
31
62
35.4K
minaminao
minaminao@vinami·
Long time no post — I've been casually running a CTF platform for individual players called @AlpacaHack for the past year. This weekend, we're hosting a new 6-hour Crypto round. Feel free to give it a try! alpacahack.com/ctfs/round-13
minaminao tweet media
English
0
1
13
1.1K
minaminao รีทวีตแล้ว
maple3142
maple3142@maple3142·
Finally completed the writeup for my challenge (ffmac) in AlpacaHack Round 9 (Crypto) github.com/maple3142/My-C…
English
1
4
23
3.5K
minaminao
minaminao@vinami·
@duncancmt it seems like there is no problem if you can specify salt to the factory contract, but are there any cases where it breaks? I think it would be like the create2 factory contract
English
1
0
3
41
Duncan Townsend
Duncan Townsend@duncancmt·
@vinami @real_philogy This seems Bad. Doesn't this mean that factory contracts that CREATE from calldata won't work after EOF? Seems like that breaks a lot of important use cases that rely on deterministic, permissionless deployment of trusted contracts to predictable addresses across all chains.
English
1
0
1
112
minaminao
minaminao@vinami·
Do you know that calling the function in the following EOF contract results in a revert? This is definitely a potential pitfall ... 🙃
minaminao tweet media
English
5
1
41
4.9K
minaminao
minaminao@vinami·
@plotchy yeah that’s right the extra sstore cost is consumed though 😢
English
0
0
1
61
plotchy🔅
plotchy🔅@plotchy·
@vinami easiest would be to sstore an accumulator
English
1
0
2
157
minaminao
minaminao@vinami·
I created a challenge at SECCON CTF that explored EVM Object Format (EOF)🧩 It revealed two emerging pitfalls: Contract Recreation Failures and Call Return Mishandling. It was tough—only 2 teams solved. Give it a try to deepen your understanding of EOF: github.com/minaminao/my-c…
minaminao tweet media
English
3
8
84
9.2K
minaminao
minaminao@vinami·
@real_philogy we must specify a salt 😢 so I think compilers should enforce the inclusion of a salt the current Solidity PoC doesn’t do so …
English
2
0
2
286
philogy
philogy@real_philogy·
@vinami seems like a bug, this should work in EOF
English
1
0
3
343