logo
CryptoCat's Blog
2025 Bug Bounty Writeups
Initializing search
    • Home
    • CTF Writeups
      • Monthly Challenges
          • 11-25: APICrash
          • 10-25: Ghost Whisper
          • 09-25: Chainfection
          • 08-25: Hardware Monitor
          • 07-25: CCTV Manager
          • 06-25: Hex Color Palette
          • 04-25: HackDonalds
          • 08-24: SafeNotes
          • 01-24: Repo Woes
          • 04-23: We Like To Sell Bricks
          • 11-25: Mother Printers
          • 10-25: Ultimate Calculator 3000
          • 12-24: Summar-AI-ze
      • 2025
            • Hacky Christmas
            • VulnBank
            • Snorex 2K CCTV
            • Malayo
            • Secure Exam Browser
            • Bait and Switch
            • Nulle
            • Nimrod
            • Comparing
            • Weird App
            • Stacked
            • LLM Hacking (levels 1-5)
            • Shoe Shop
            • Planets
            • Buster
            • Why2025 CTF Time
            • Why2025 Planner
            • Fancy Login Form
            • Press Me If U Can
            • SNAD
            • Infinite Queue
            • TMCB
            • Method in the Madness
            • No Sequel
            • Advanced Screening
            • My First CTF
            • My Second CTF
            • My Third CTF
            • The Mission
            • len_len
            • Flash
            • YAMLwaf
            • Breaking Authentication
            • Commit & Order: Version Control Unit
            • How I Parsed your JSON
            • Mr. Chatbot
            • Keeping Up with the Credentials
      • 2024
            • BabyFlow
            • In Plain Sight
            • IrrORversible
            • Layers
            • Rigged Slot Machine 1
            • Bug Squash 1
            • Bug Squash 2
            • Secure Bank
            • Biocorp
            • Cat Club
            • Pizza Paradise
            • SafeNotes 2.0
            • Quick Recovery
            • Triage Bot 2
            • Floormat Sale
            • Retro2Win
            • Rigged Slot Machine 2
            • UAP
            • Schrodinger's Pad
            • Cold Storage
            • No Comment
            • Trackdown
            • Trackdown 2
            • CTF Mind Tricks
            • Hoarded Flag
            • Password Management
            • Playing on the Backcourts
            • Log Me In
            • Lost Pyramid
            • BucketWars
            • Feature Unlocked
            • Fare Evasion
            • Log Action
            • Bad Worker
            • PoW
            • One Day One Letter
            • Upload
            • Flag Command
            • TimeKORP
            • KORP Terminal
            • Labyrinth Linguist
            • Locktalk
            • SerialFlow
            • Testimonial
      • 2023
            • Dark Secrets
            • Triage Bot
            • Photographs
            • Floormat Store
            • Bug Report Repo
            • My Music
            • Blank
            • IDORiot
            • Inspection
            • Login
            • Perfect Picture
            • Roks
            • Write-Flag-Where
            • Last Hope
            • Mysterious Learnings
            • Perfect Synchronization
            • Getting Started
            • Labyrinth
            • Pandora's Box
            • Void
            • Cave System
            • Hunting License
            • Needle in a Haystack
            • Shattered Tablet
            • She Sells Sea Shells
            • Azusawa's Gacha World
            • Sanity
            • Waiting an Eternity
            • Hidden Figures
            • Marmalade 5
            • Obligatory
            • Star Wars
            • Stickers
            • Leek
      • 2022
            • ASE
            • Links 1
            • Links 2
            • Links 3
            • Open Doors
            • 4mats
            • Easy Overflow
            • BabyReeee
            • Super-Secure-Requests-Forwarder
            • Hellbound
            • Really Obnoxious Problem
            • Wah
            • Whats My Name
            • Where Am I
            • Crumbs
            • Xtra Salty Sardines
            • Baby Steps
            • Flaskmetal Alchemist
            • Hacker Ts
            • Two for One
            • Side Channel
            • Buffer Overflow 1
            • Buffer Overflow 2
            • Buffer Overflow 3
            • Flag Leak
            • Function Overwrite
            • ROPfu
            • RPS
            • Stack Cache
            • Wine
            • X-Sixty-What
            • Wizardlike
            • Noted
            • Vader
            • Flag in Space
            • Bird
            • Cake
            • Easy Register
            • Search Engine
            • Interview Opportunity
      • 2021
            • Unsubscriptions Are Free
            • Fibinary
            • Chainblock
            • Meet Me Halfway
            • Xmas Spirit
            • Minimelfistic
            • Mr. Snowy
            • Naughty List
            • Sleigh
            • Infiltration
            • Intercept
            • Badseed
            • Twizzty Buzzinezz
            • Context
            • Hotel
            • Air Supplies
            • Injection Shot
            • Library
            • Recruitment
            • Knock Knock
            • Split
            • A Kind of Magic
            • Tweety Birb
            • Zoom2Win
            • Retcheck
            • The Library
            • Yabo
            • Availability
            • Alien Math
            • Password Checker
            • Checker
            • Cute Invoice
            • Mineslazer
            • Injection Traffic
            • Power Snacks
            • Deleted Flag
            • Engine Control
            • Skylark
            • Phasestream
            • Alien Camp
            • Build Yourself In
            • Controller
            • System Drop
            • Blitzprop
            • E-Tree
            • Wild Goose Hunt
            • Sanity Checks
            • Secure Login
            • Sticky Stacks
            • Tranquil
            • Free Flags
            • Jailbreak
            • Jar
    • Bug Bounty
      • 10-25: IDOR Leads to Mass PII Exposure in Healthcare App
    • Vuln Research
      • CVE Analysis
        • CVE-2025-31344: giflib Heap-based Buffer Overflow
        • CVE-2025-24813: Tomcat DefaultServlet Partial PUT
        • CVE-2025-54376: Hoverfly WebSocket Auth Bypass
      • Novel Research

    2025 Bug Bounty Writeups

    • 10-25: IDOR + Mass PII Exposure in a Healthcare App
    January 6, 2026