- MonkeHacks
- Posts
- MonkeHacks #80
MonkeHacks #80
Cats, CTBB, H1 LHE
MonkeHacks #80
Slightly late issue again this week because… I have cats now! Woohoo! More on that below.
It’s been a memorable week for me. Sometimes there are weeks where your life takes a new direction, or your existing lifestyle gets a reshuffle, and this week was one of those. It’s really crazy just how different my apartment feels now, now that there are cats living in it too.
Sometimes I wonder why my life isn’t more peaceful, but after a very short time spent reflecting on it, I realise that it’s entirely my own doing, and I wouldn’t have it any other way. I will be cutting down on my longer trips now that I have pets. I can still do 5-6 day trips, as I have friends who can mind the cats, but longer ones are mostly out of question.

Please welcome Meap (closer) and Tora (further).
Weekly Ideas / Notes
Starting with the life stuff - I have cats, at last! I named them Meap and Tora (meap is an alien from the show Phineas and Ferb, and tora means tiger in Japanese; my grandfather was called Torao so this is a kind of tribute to him). They’re 6 months old, so they’re quite mischievous - I haven’t slept very well recently as a result. Having cats has been a longtime goal of mine, and taking care of the two kittens has been incredibly fulfilling so far. It’s actually been a really, really great week - the new Pokémon game was released on the Switch 2, which I was looking forward to for quite a long time, and Joji - formerly known as Filthy Frank - dropped a new single for the first time in 3 years. So all in all - amazing week.
I tried to set up a gate to stop the cats from entering my bedroom (it’s quite high up so I’m not going to allow them access until they’re older and more agile) but they jumped over the gate. I put a second gate on top of the first one, this should work better now. I hope they don’t jump it again, because I had to wake up at 6am to put that damn gate up.
Congratulations gr3pme for becoming a co-host of CTBB! Well deserved, he’s the one writing the Hackernotes for us this whole time.
I scrapped the startup idea I had before and started a new, much better one. I’m working long hours on the MVP. It’s going very well. I’m looking forward to launching it in the near future. I’m about 50% of the way through the development of the MVP right now.
I’ll be taking part in HackerOne’s upcoming LHE in Amsterdam at the start of November. More on that closer to the event date! Busfactor is also going! This is my 5th and likely final LHE of the year. I’m very thankful for the opportunity.
CTBB Episode 144: Busfactor and I are on this week’s episode of the Critical Thinking podcast. Please give it a listen!
Ireland placed 10th in the European Cybersecurity Challenge! I dropped out of the team because of the Mexico LHE, but I’m really glad to see that they crushed it. 10th of ~34 countries is phenomenal for a country as small and as underfunded as Ireland - it’s a night and day difference from when I first joined the squad around 4 years ago. Funnily enough, as I was returning home from Mexico City, I did run into some of the Kalmar CTF players in the airport lounge - some of whom were heading to Warsaw for ECSC at the time.
Reading List
I haven’t read any books in a while, so I really need to get back to it.
Currently:
Fiction:
Solenoid by Mircea Cărtărescu (130/600 pages)
Guards! Guards! by Terry Pratchett
Non-Fiction:
A Random Walk Down Wall Street by Burton Malkiel (150/300 pages)
How The World Made The West by Josephine Crawley Quinn (180/400 pages)
Next on the list:
Fiction: Mort by Terry Pratchett
Non-Fiction: Day Zero to Zero Day by Eugene Lim (SpaceRaccoon)
Resources
3 new posts from the CTBB Research Lab: CTBB Labs produced three interesting but brief articles. Check them out!
Hustle Culture Lied To You: I generally like Matt D’Avella’s videos. In particular, I like this one. In a nutshell: do less, but do the fewer tasks with more intention and focus. And don’t neglect the rest of your life. You will regret it if you only focus on work.
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office: Sam Curry and Shubs hacked the World Poker Tournament with a set of surprisingly simple bugs. Absolutely insane.
CometJacking: How One Click Can Turn Perplexity’s Comet AI Browser Against You: A pretty clever AI bug here. Nice work!
More Than DoS (Progress Telerik UI for ASP.NET AJAX Unsafe Reflection CVE-2025-3600): This is a VERY technical writeup explaining a .NET gadget in Telerik that the Watchtowr team used to get RCE in Sitecore.
OpenECSC - kv-messenger: A really nice web challenge involving CRLF that was part of the OpenECSC CTF.
Finding Critical Bugs in Adobe Experience Manager: Assetnote / SLCyber found several critical bugs in AEM. AEM is everywhere so this is super impressive.