Multiflora_Rose
// SECURITY PORTFOLIO
Multiflora_Rose
Cybersecurity / CTF / Research
A personal space for security research, CTF writeups, and technical notes about understanding how systems work.
- Focus
- Security
- Output
- Posts
- Language
- EN / 繁中
- Identity
- halliana
// RESEARCH
Recent posts
Web·2026-08-31
COMPFEST CTF 2026 Writeup: Egg
A WordPress 7.0 pre-auth RCE chain, from a WAF bypass and SQL injection to a temporary admin and command execution.
Web·2026-08-23
BrunnerCTF 2026 Writeup: Technical Debt
Chaining SAML signature wrapping, ASP.NET MVC mass assignment, and Mono BinaryFormatter deserialization into RCE.
Web·2026-08-09
LIT CTF 2026 Writeup: no way out
A client-side Google Forms routing bypass for LIT CTF 2026's no way out.
$ ./achievements.sh
Selected CTF results
$ ./best-result.sh
Best 2026 result
#1
PolyU FYP CTF 2026
2026 · Team: Ghostcat
Writeup contest: 2nd
#1
Hack for a Change 2026 May: UN SDG 1
2026 · Team: hello world has been taken
#1
PolyU FYP CTF 2026
2026 · Team: Ghostcat
Writeup contest: 2nd
#1
Hack for a Change 2026 May: UN SDG 1
2026 · Team: hello world has been taken
#4
CUHK CTF 2025
2025 · Team: hello world has been taken
#6
PolyU x NuttyShell Cybersecurity CTF 2026
2026 · Team: hello world has been taken
Writeup contest: 3rd
#6
Sieberrsec CTF 7.0
2026 · Team: hello world has been taken
#11
Kali Team - CTF 26
2026 · Team: idktheflag
// ABOUT
Multiflora_Rose
Security research, CTF writeups, and notes written with a preference for clear evidence and reproducible reasoning. Team leader of hello world has been taken.
Read about Multiflora_Rose →













