/images/ghost.png

Cryptax

This website is personal and does not represent my employer

Blog

Capture The Evidence v2 (2026)

Capture The Evidence v2 - June 2026 French gendarmerie 🇫🇷 organized a special CTF called “Capture The Evidence” from June 5 to June 15, 2026. I participated for the first time, with a team of 4 called Eternal Green. The name of our team is a play on words based on Eternal Blue, the organizing team where blue is the color of the gendarmerie, and Green in our case in reference to the (famous?

Auvergn'hack 2026

Back from Auvergn’hack 2026 Auvergn’hack is a recent, local security conference in Clermont Ferrand (France). It is rather small: a single day and a single track, but it was a great discovery with an excellent ratio of interesting talks. Yes, when you’re a “senior” with “20+ years of experience” (a kinder way of saying you’re old), you’ve already seen quite a lot. You don’t say it too often not to sound old and grumpy, but you are often disappointed with talks because they tell a story so similar to one you’ve already heard in the past.

CTFs and AI

CTFs and Artificial Intelligence. Post Ph0wn 2026 Thoughts. Update May 26, 2026: Link to feedback from NorthSec CTF Update May 19, 2026: Re-phrased first paragraph. In particular, replaced the title “Myth #1 CTF players hate AI [..]” with “CTF players hate AI [..]: True or False?” because I found my title was too biaised. It did not express fairly enough the reality. Added a paragraph on my (current) opinion. Added references to foreman, Kabir and Sthack CTF My opinion, in short The “problem” of AI in CTFs is very complex, with pros and cons…

More blog posts →

Write-ups

CTE v2 (2026) - Le Vault

CTE v2 (2026) - Le Vault This challenge begins with some OSINT where we need to find a program protected by password. This program is used by Melanie’s friend, Samir Taleb. NB. These are fake identities used all along “Capture The Evidence” v2. Then, we’ll need to provide the author’s name of this challenge as flag. The tags of the challenge suggest there’s a part with OSINT (first part) and a part with Reverse (second part).

CTE v2 (2026) - Toujours en Vente

CTE v2 (2026) - Toujours en Vente This is a reverse engineering challenge created by Miaou for Capture The Evidence (CTE) in June 2026. We are given a binary broker_tool, and we need to find a URL to flag, e.g https://u.rl/path. Reconnaissance The binary is an ELF x86-64, not stripped. We run it: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 =================================== B U S I N E S S P O R T A L =================================== Welcome, valued partner.

Auvergn'hack 2026: Crypto challenge

Auvergn’hack 2026 CTF: Crypto - Saki There was a crypto challenge at Auvergn’hack. I can’t remember exactly the title (I think it was “Saki” or something). I did not preserve the description either, but the only important files that were provided were: an encrypted message (message.txt): 1 {"h": "g1oatFTHSYsUH377iZQSuesUM/t+pFXRrwCrNW8v8Lw=", "n": "WQq7B4XEueM=", "m": "2gFQlO5+YZFnqaar7QEGpu3/f/2WdbJEWPnVjNuNs2dXyHUi7/8="} a verification file (v.txt), with a single word: Monkey a Python script (script.py) to encrypt or decrypt messages Goal: we need to decrypt message.

More write-ups →