chelos@blep:~$ no cookies · no trackers · no js required to read (=^・ω・^=)

ねこカフェ · open late · rain all night

blep.fi

ブレップ

chelos · ctf & on-chain investigation · lofi

blep.fm stereo · lofi
ch 1/5 ■ standby

Fluid

instrumental hip-hop · lofi beats
somafm · relayed, your IP stays here
scroll

$ whoami ฅ^•ﻌ•^ฅ blep!

chelos

ctf enthusiast by night, on-chain investigator by obsession. i pop web & reversing challenges for fun, then follow the money through eth transactions the same way — one hop, one trace, one rabbit hole at a time. headphones on, rain outside, debugger open.

#ctf#web#reversing#ethereum#on-chain forensics#opsec

$ cat ~/.flag_hunting ctf

jeopardy ctfs for the thrill of the 3am "wait… what if" moment. every solve gets a writeup so the next person gets there faster.

  • › web — auth bypasses, injections, logic bugs
  • › reversing — binaries, crackmes, obfuscated js
  • › writeups — tctt · stdio · secplayground

$ cast run --trace on-chain

the ledger never forgets. tracing exploits, scams and drained wallets across ethereum — tx by tx, until the funds stop moving.

  • › tracing — fund flows, bridges, mixers, cex deposits
  • › forensics — exploit tx traces & contract decompilation
  • › tooling — foundry · etherscan · block explorers · graphs

contact

github
chanios
medium
@chanios
email

tuta ↔ tuta mail is end-to-end encrypted. from anywhere else, assume it isn't — keep secrets out of plaintext.

$ ls ~/writeups

all on medium →
  1. · 1 min read

    Secplayground Cybersplash 2025 — Shopez

    เนื่องจาก medium บล็อกคำบางคำไม่สามารถลงได้ผมจะแก้ใว้ดังนี้ __ proto __ -> Tralalero Tralala Chef Crabracadabra -> (() => {});return proces s.mainModule.require(\”child _ process\”).ex ecSy nc(\”cat…

    #secplayground#cybersplash2025#ctf-writeup#ctf [private mirror]
  2. · 2 min read

    Secplayground Xmas 2024 — Bookclub

    ในข้อนี้นะครับเราจะได้เว็บที่มีช่อง input ผมลองไปลองมาเหมือนต้องแทนช่องว่างเป็นตัวอื่นแต่ผมก็ไม่ได้ทำต่อเพราะหลังจาก inject แล้วก็ทำอะไรไม่ได้ แต่เมื่อลองกด Hint You can Command Injection via SQL…

    #ctf#ctf-writeup#secplayground#secplaygroundbloodyxmas [private mirror]
  3. · 1 min read

    STDiO 2024 Reverse Me writeup

    ข้อนี้นะครับเป็นข้อที่ดูเหมือนจะยากเพราะเราไม่รู้ว่าไฟล์ .so คืออะไรแล้วยังมีแค่ 0 solves แต่ว่าเราโดน summon ให้มาทำ จัดไปครับพี่ President bankD .so ก็คือ shared library…

    #stdio2024#stdio-ctf [private mirror]
  4. · 1 min read

    STDiO 2023 - Rolling Farm writeup

    STDiO 2023 Rolling Farm writeup 🍎 สำหรับ Rolling Farm หมวดหมู่ Web ข้อนี้นะครับ เราจะได้เว็บมาเว็บนึงที่จะให้เราไปเก็บ Apple Simulator ครับซึ่งเว็บต้องการให้เราเก็บ Apple 56 ลูกเพื่อที่จะเอาไปซื้อ…

    #writeup#stdio2023#beginner#stdio-ctf [private mirror]
  5. · 1 min read

    TCTT 2023 — xfill writeup

    ในโจทย์ข้อนี้นะครับเราจะได้ไฟล์ xfil.pcapng มานะครับให้เรานำไปเปิดใน wireshark เลย เราจะเห็นมี packet ที่ request dns query รัวๆ แล้วเห็นข้อความที่เป็น hex แปลกๆ ส่งออกไป ให้เรา apply filter…

    #ctf-writeup#cybersecurity [private mirror]
  6. · 1 min read

    TCTT 2023 — MitM writeup ⛓️

    สำหรับโจทย์ในข้อนี้เราก็จะได้ไฟล์ Networking-MitM.pcap มานะครับขั้นแรกเราเข้า wireshark แล้วเราจะเจอ packet ที่มีคนพยายาม auth อะไรสักอย่างให้เราหา packet ที่ auth success แล้ว follow ข้อมูลนั้น…

    #cybersecurity [private mirror]
  7. · 1 min read

    TCTT 2023 — Nebula writeup

    🌌 สำหรับ Nebula หมวดหมู่ forensic ข้อนี้นะครับ ไฟล์โจทย์จะเป็น Nebula.mp4 ตามรูปโดยไม่มี Description อะไรมาอธิบายเลยขั้นแรกเลยเราต้องเปิด text editor ที่ดีที่สุดในโลกกันเลยนะครับ notepad.exe…

  • cookies: 0
  • trackers: 0
  • 3rd-party requests: 0
  • csp: strict
  • referrer: none
  • radio: relayed

blep.fi — brewed with sveltekit + tailwind, coffee and too many rabbit holes. served from a single origin (=^‥^=) security.txt