Danish CTF player

CTF writeups and other projects

marvin@5y:~

$ whoami

Danish CTF player & Challenge developer

$ contact-info

marv1nh@5y.dk - LinkedIn - GitHub

$

Marvin Hald

I am a Danish CTF player. This site contains my CTF writeups and technical projects.

Web securityLinuxForensicsReverse engineeringCTFs

Experience & education

Experience

Student Assistant · Challenge Developer

Campfire Security · Part-time

Copenhagen, Capital Region of Denmark

  • Cybersecurity
  • Programming

Cyberlandsholdet

De Danske Cybermesterskaber

  • Cybersecurity
  • Teamwork

Education

Nærum Gymnasium

Upper secondary education

Latest writeups

6 articles

01

Corsica - Web Exploitation

The target is a web application running on https://corsica.cfire/. The application has an admin panel at https://corsica.cfire/admin that is protected by authentication.…

Read writeup
02

IOT Gateway - Boot2Root

This challenge is from the DDC Nationals 2026. I did not solve this challenge during the event, however I got really far and had a good idea on what the solution was. I…

Read writeup
03

Photo Album - Web Exploitation

solves: 14 Author: marv1nh The challenge provided a basic photo album web app where users could upload either image files (.jpg, .png, etc.) or a .tar archive containing…

Read writeup
04

Squeaky Clean - Boot2Root

Challenge: Boot2Root (Step 1: Initial Access) Target: http://squeaky-clean.cfire Date: 2026-03-04 --- A Flask web application running SQLite. The attack chain to initial…

Read writeup
05

Bøf-baserede værdipapirer og emails - Forensics

Category: Forensics Points: 557 Solves: 8 Author: marv1nh Junior first blood --- --- --- I started by opening the disk image using Autopsy, a digital forensics platform.…

Read writeup
06

Coding Practices - Web Exploitation

This challenge was part of the DDC Nationals 2026. I unfortunately did not solve this challenge during the event, but here is my writeup from a couple days later. The ch…

Read writeup