LakeCTF 2026 Challenge Author Writeups

LakeCTF Challenge: Modulato Bombo

It's the challenge made to force myself to dev hfsdr
Meant to be easy challenge to explore RF Side Channel Attacks

Solve path

  1. See the bomb
  2. Use the custom SDR board to sniff the pwm signals
  3. Enter the pin for flag (in the wrong flag format lmao, my bad)

The concept is that high frequency wired signals emit RF waves for side channel attacks.

It was fun deving for this challenge, not just hfsdr but learning how to handle tx though pwn. To make it easier, I intentionally removed the need for GNURadio, and let the pwm frequency be inaccurate (rp2350 pwm peripheral is not as exact as the fpga, but the fpga one is not too reliable somehow, in hindsight I could prob test more and make it work for more learning)

Some infra issues is they needed briefing. And I was rushing around so sometimes they dismantled the bomb😢

I think the concept of the chall was interesting and I tuned it more to be easy, and that's exactly what I got, 8 solves
Quite satisfied for my scope

Pasted image 20261008181701.png

Side point
for architectural considerations

  1. I used a GreyMecha RP2350 for PWM
  2. The FPGA controlled the keypad LOL, no diodes because no time
  1. For the lolz, the GreyMecha controlled the OLED and key circuitry and PWM, the hack&roll badge is connected to the pwm signal (to check its on), and a servo threatening greycat

mostly vibe coded, but needed to debug some FPGA stuff manually (inout in yosys lmao)

LakeCTF Challenge: Beyond Root

I got this challenge from the DEFCON SG Badge meeting, when Sprite_Tm suggested SPIFFS on the DEFCON SG1 badge, but said it didn't support directories (so some funny stuff could be done)

Solve path:

  1. On Web portal OSINT Camera image to museum bolo
  2. Inject the path into the form to read /config.json and get the WiFi credentials
  3. Go to Museum Bolo, login, and nmap for the Camera
  4. Access the SPIFFS shell, notice the file system and hint, and access the flag at /../flag.txt

The infra was a mess, I think my phone's hot-spot couldn't support all the connections, and people were spamming XSS payload, but it got better in the end.

People generally liked the onsite part, but the shell/ file directory path was divisive, some were ok and liked it, some thought it was stupid, dm but don't think people had too bad of an opinion

I was aiming for easy/medium and I kinda got that, 6/10 solves, tho was a bit sad couldn't be harder (I had ideas but I was too tired to cook)

Pasted image 20261008181930.png