<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>adrianjunge.de</title>
    <link>https://adrianjunge.de/</link>
    <atom:link href="https://adrianjunge.de/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Latest blog posts and CTF writeups from Adrian Junge.</description>
    <language>en</language>
    <pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate>
    <lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>Climbing Stairs from Two Angles</title>
      <category>Blog post</category>
      <description>
        <![CDATA[LeetCode's Climbing Stairs problem looks like a simple dynamic-programming challenge, but a closer look connects Fibonacci numbers, binomial coefficients, and Pascal's triangle.]]>
      </description>
      <link>https://adrianjunge.de/blog/climbing-stairs</link>
      <guid>https://adrianjunge.de/blog/climbing-stairs</guid>
      <pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Teaching AI to hack Joomla so I can skip my homework</title>
      <category>Blog post</category>
      <description>
        <![CDATA[How a manual SQLi hunt turned into an AI-assisted Joomla audit, two assigned CVEs, and a surprisingly valid way to pass a university lab.]]>
      </description>
      <link>https://adrianjunge.de/blog/joomla-sqli</link>
      <guid>https://adrianjunge.de/blog/joomla-sqli</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Scanwich Station</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[A table-side QR reader for hungry guests and suspicious menus. One special order can make the scanner serve more than dinner.]]>
      </description>
      <link>https://adrianjunge.de/ctf/gpnctf/Scanwich%20Station</link>
      <guid>https://adrianjunge.de/ctf/gpnctf/Scanwich%20Station</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Funny Java Strings?</title>
      <category>Blog post</category>
      <description>
        <![CDATA[Java Strings are immutable, interned, optimized, and surprisingly easy to misunderstand when secrets are involved. This post digs into String pooling, reflection, Base64 copies, library APIs, and why heap dumps are bad news for secrets.]]>
      </description>
      <link>https://adrianjunge.de/blog/java-strings</link>
      <guid>https://adrianjunge.de/blog/java-strings</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>xmalloc</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[All of our slot machines switched from using the very insecure libc heap implementation to something much more secure internally. Surely this new heap implementation is unbreakable :D]]>
      </description>
      <link>https://adrianjunge.de/ctf/kitctf/xmalloc</link>
      <guid>https://adrianjunge.de/ctf/kitctf/xmalloc</guid>
      <pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>HTB CPTS</title>
      <category>Blog post</category>
      <description>
        <![CDATA[My experience completing the Hack The Box Certified Penetration Testing Specialist (HTB CPTS) certification. I share the journey, rough timeline, exam tips, and tools that helped me succeed.]]>
      </description>
      <link>https://adrianjunge.de/blog/htb-cpts</link>
      <guid>https://adrianjunge.de/blog/htb-cpts</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>My Flask App</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[A small Flask application from an easy SekaiCTF web challenge.]]>
      </description>
      <link>https://adrianjunge.de/ctf/sekaictf/My%20Flask%20App</link>
      <guid>https://adrianjunge.de/ctf/sekaictf/My%20Flask%20App</guid>
      <pubDate>Thu, 11 Sep 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Fancy Web</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[The Ministry of Information and Communications Technology of Konoha has recently launched their new official website. While it appears to be a standard government portal showcasing public services and announcements, our intelligence sources have indicated that this WordPress-based website contains hidden information that could expose corruption and human rights violations. The website features a unique table processing system that displays various government data, but our analysts suspect that the developers have hidden sensitive information within the table structures themselves. The site's administrators are known for their sophisticated obfuscation techniques, making it difficult to distinguish between legitimate public data and concealed evidence. Your mission is to investigate this website and uncover the hidden information by looking beyond the surface-level content and examining how the tables are processed and displayed - the truth might be hidden, waiting for someone with the right skills to reveal it.]]>
      </description>
      <link>https://adrianjunge.de/ctf/sekaictf/Fancy%20Web</link>
      <guid>https://adrianjunge.de/ctf/sekaictf/Fancy%20Web</guid>
      <pubDate>Sat, 06 Sep 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Smile at me</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[My hard web challenge for GPNCTF 2025.]]>
      </description>
      <link>https://adrianjunge.de/ctf/gpnctf/Smile%20at%20me</link>
      <guid>https://adrianjunge.de/ctf/gpnctf/Smile%20at%20me</guid>
      <pubDate>Thu, 21 Aug 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Leaf</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[I always think leaf ~= tea. Please allow remote to have some time to boot the browser.]]>
      </description>
      <link>https://adrianjunge.de/ctf/smileyctf/Leaf</link>
      <guid>https://adrianjunge.de/ctf/smileyctf/Leaf</guid>
      <pubDate>Mon, 09 Jun 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Everyone loves canteen food</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[Welcome to the canteen's online menu, where you can check out the daily specials and their prices. But is everything as appetizing as it seems?]]>
      </description>
      <link>https://adrianjunge.de/ctf/cscg/Everyone%20loves%20canteen%20food</link>
      <guid>https://adrianjunge.de/ctf/cscg/Everyone%20loves%20canteen%20food</guid>
      <pubDate>Fri, 09 May 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>vidplow</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[We recently stumbled upon an exposed SVN server of a large multimedia corporation, containing some of their backend application and internal tooling code. However, the access keys seem to not be the ones used in production - the real ones should fetch us quite a high price though, if we manage to get our hands on them that is. Just one problem - the tech stack seems to be really obscure, and no one on our team seems to have any clue what the heck is going on. Can you take a look, and maybe find some vulnerabilities in this thing?]]>
      </description>
      <link>https://adrianjunge.de/ctf/cscg/vidplow</link>
      <guid>https://adrianjunge.de/ctf/cscg/vidplow</guid>
      <pubDate>Sat, 03 May 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>KDF dream</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[We've managed to insert ourselves into a secure channel between two covert agents, however we overplayed our hand and they have become suspicious that their channel is compromised. Realising that there is no way to restablish trust over the compromised network, Alice called for them to carry out a NIST Certified KDF protocol to generate a symmetric OTP, and then for them to use this to encrypt a physical message at a dead drop location. We want to control the message she leaves, can you influence their conversation to control what Bob reads at the dead drop?]]>
      </description>
      <link>https://adrianjunge.de/ctf/cscg/KDF%20dream</link>
      <guid>https://adrianjunge.de/ctf/cscg/KDF%20dream</guid>
      <pubDate>Fri, 02 May 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Air smeller</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[I found this website where you can rate the smell of the air, after purification. Do you know a good purifier, maybe you can recommend some purifier to the people.]]>
      </description>
      <link>https://adrianjunge.de/ctf/cscg/Air%20smeller</link>
      <guid>https://adrianjunge.de/ctf/cscg/Air%20smeller</guid>
      <pubDate>Thu, 01 May 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Fantastic Doom</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[Doctor Doom, the monarch of Latveria has made many doombots. You working with the Fantastic 4 have to access doombot machine and foil his plans of releasing doombots.]]>
      </description>
      <link>https://adrianjunge.de/ctf/ehax/Fantastic%20Doom</link>
      <guid>https://adrianjunge.de/ctf/ehax/Fantastic%20Doom</guid>
      <pubDate>Thu, 24 Apr 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Cash Memo</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[I have a really hard time managing my cash, am afraid someone might steal my memos...]]>
      </description>
      <link>https://adrianjunge.de/ctf/ehax/Cash%20Memo</link>
      <guid>https://adrianjunge.de/ctf/ehax/Cash%20Memo</guid>
      <pubDate>Thu, 17 Apr 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Tar boom</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[Within the Louvre Museum's intranet, there is a service that allows trusted users to upload .tar files and view their content. However, this service has been exploited by a hacker. He was able to retrieve crucial information about the Louvre's security, hidden within the flag.txt.]]>
      </description>
      <link>https://adrianjunge.de/ctf/dvctf/Tar%20boom</link>
      <guid>https://adrianjunge.de/ctf/dvctf/Tar%20boom</guid>
      <pubDate>Thu, 27 Mar 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Gamedev</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[You've heard of rogue-likes, but have you heard of heap-likes?]]>
      </description>
      <link>https://adrianjunge.de/ctf/lactf/Gamedev</link>
      <guid>https://adrianjunge.de/ctf/lactf/Gamedev</guid>
      <pubDate>Sat, 15 Feb 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>A Minecraft Movie</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[I...AM STEVE!]]>
      </description>
      <link>https://adrianjunge.de/ctf/umdctf/A%20Minecraft%20Movie</link>
      <guid>https://adrianjunge.de/ctf/umdctf/A%20Minecraft%20Movie</guid>
      <pubDate>Tue, 04 Feb 2025 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>CORS Playground</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[An easy FCSC web challenge centered on browser cross-origin policies.]]>
      </description>
      <link>https://adrianjunge.de/ctf/fcsc/CORS%20Playground</link>
      <guid>https://adrianjunge.de/ctf/fcsc/CORS%20Playground</guid>
      <pubDate>Sat, 07 Sep 2024 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Hoster</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[You gained access to a Linux server. Can you also gain privileges?]]>
      </description>
      <link>https://adrianjunge.de/ctf/cscg/Hoster</link>
      <guid>https://adrianjunge.de/ctf/cscg/Hoster</guid>
      <pubDate>Thu, 23 May 2024 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
    <item>
      <title>Photoeditor</title>
      <category>CTF writeup</category>
      <description>
        <![CDATA[A medium CSCG web challenge built around ASP.NET Core and dynamic application behavior.]]>
      </description>
      <link>https://adrianjunge.de/ctf/cscg/Photoeditor</link>
      <guid>https://adrianjunge.de/ctf/cscg/Photoeditor</guid>
      <pubDate>Fri, 17 May 2024 00:00:00 +0000</pubDate>
      <dc:creator>Adrian Junge</dc:creator>
    </item>
  </channel>
</rss>
