<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>https://chrisandoryan.github.io/</id>
  <title>Siahaan.</title>
  <subtitle>Writeups and notes on cyber security and programming by Chrisando Ryan.</subtitle>
  <updated>2026-10-06T00:58:18+07:00</updated>
  <author><name>Chrisando Ryan</name></author>
  <link rel="self" type="application/atom+xml" href="https://chrisandoryan.github.io/feed.xml"/>
  <link rel="alternate" type="text/html" href="https://chrisandoryan.github.io/"/>
  <entry>
    <title>TJCTF2020 - Admin Secrets</title>
    <link href="https://chrisandoryan.github.io/posts/Admin-Secrets/" rel="alternate" type="text/html"/>
    <id>https://chrisandoryan.github.io/posts/Admin-Secrets/</id>
    <published>2020-10-31T10:33:00+07:00</published>
    <updated>2020-10-31T10:33:00+07:00</updated>
    <category term="Web"/>
    <category term="XSS"/>
    <summary>Given a website, where a person can login and register. Both are irrelevant to the challenge, so I will cut the chase. The other feature, the ‘relevant’ feature of the challenge, is a feature that allows user to write a note and even send the note to an admin (evil laugh). It isn’t hurt to think that this might be an XSS challenge, and I did that.</summary>
  </entry>
  <entry>
    <title>Hilltop CTF 2020 - What Is The Deadly Bug Here?</title>
    <link href="https://chrisandoryan.github.io/posts/What-Is-The-Deadly-Bug-Here_/" rel="alternate" type="text/html"/>
    <id>https://chrisandoryan.github.io/posts/What-Is-The-Deadly-Bug-Here_/</id>
    <published>2020-06-09T10:33:00+07:00</published>
    <updated>2020-06-09T10:33:00+07:00</updated>
    <category term="Web"/>
    <category term="Hash length extension"/>
    <category term="Command injection"/>
    <category term="My challenges"/>
    <summary>Given a simple website that looks like this.</summary>
  </entry>
  <entry>
    <title>Hilltop CTF 2020 - Tornado</title>
    <link href="https://chrisandoryan.github.io/posts/Tornado/" rel="alternate" type="text/html"/>
    <id>https://chrisandoryan.github.io/posts/Tornado/</id>
    <published>2020-06-09T10:33:00+07:00</published>
    <updated>2020-06-09T10:33:00+07:00</updated>
    <category term="Web"/>
    <category term="PRNG cracking"/>
    <category term="My challenges"/>
    <summary>Given a website that seems like a file-sharing utility.</summary>
  </entry>
  <entry>
    <title>Hilltop CTF 2020 - Stock Marked</title>
    <link href="https://chrisandoryan.github.io/posts/StockMarked/" rel="alternate" type="text/html"/>
    <id>https://chrisandoryan.github.io/posts/StockMarked/</id>
    <published>2020-06-09T10:33:00+07:00</published>
    <updated>2020-06-09T10:33:00+07:00</updated>
    <category term="Web"/>
    <category term="Deserialization"/>
    <category term="My challenges"/>
    <summary>Given a website that seems like a plain stock trading website.</summary>
  </entry>
  <entry>
    <title>Hilltop CTF 2020 - Memoir</title>
    <link href="https://chrisandoryan.github.io/posts/Memoir/" rel="alternate" type="text/html"/>
    <id>https://chrisandoryan.github.io/posts/Memoir/</id>
    <published>2020-06-09T10:33:00+07:00</published>
    <updated>2020-06-09T10:33:00+07:00</updated>
    <category term="Web"/>
    <category term="SSTI"/>
    <category term="My challenges"/>
    <summary>Given a website where you can enter any URL, the web will visit them and display the response.</summary>
  </entry>
  <entry>
    <title>Hilltop CTF 2020 - Heist To The Port</title>
    <link href="https://chrisandoryan.github.io/posts/Heist-To-The-Port/" rel="alternate" type="text/html"/>
    <id>https://chrisandoryan.github.io/posts/Heist-To-The-Port/</id>
    <published>2020-06-09T10:33:00+07:00</published>
    <updated>2020-06-09T10:33:00+07:00</updated>
    <category term="Web"/>
    <category term="Cookie tampering"/>
    <category term="My challenges"/>
    <summary>Given a plain text website that says see what you don’t. A simple GET request to the website returned 405 Method Not Allowed status, which indicates that the request method is known but not supported to access the resources.</summary>
  </entry>
</feed>
