BrunnerCTF 2026 - Welcome Aboard (Web)
Summary The Brunnerne Inc. internal wiki sits behind layered infrastructure. Direct access to /wiki/internal/flag (hinted by robots.txt) returns a hard 403 Access is forbidden. from Kestrel. The platf
Search for a command to run...
Series
Writeups from BrunnerCTF 2026, a jeopardy-style CTF by Brunnerne (Denmark) spanning Web, Forensics, Crypto, Pwn, Reverse Engineering, OSINT, and Misc, including the beginner-friendly "Onboarding" track.
Summary The Brunnerne Inc. internal wiki sits behind layered infrastructure. Direct access to /wiki/internal/flag (hinted by robots.txt) returns a hard 403 Access is forbidden. from Kestrel. The platf
Summary A "Brunnerne Hosting" customer portal exposed a legacy reservation import form that fed user-controlled, base64-encoded data into unserialize(). Getting a flag required chaining three independ
Summary The challenge exposes a firmware update service ("Bink ink update tool v1.0.5") running as brunner_operator inside a Debian container, reachable only through a Squid proxy. The tool accepts te
Overview The box ships a mostly-stock WordPress 7.0.0 install on PHP 8.2 / Apache, running on a Debian Trixie base image, packaged as a Docker/Kubernetes challenge deployment. Initial access comes thr
Summary A Flask web app accepts a .tar upload of a "git repository" and runs git status and git log against it to display commit stats. Because the tar is extracted with no validation and real git com
Summary The challenge ships a single file, activating_neurons.py, defining a small nn.Module called BrunsvigerNet. The model has two linear layers, but forward() only runs the input through the first