Challenge #11 of smpCTF was interesting: we were given an URL to a phplist version 2.10.12 installation - with default admin/phplist administrator account - and instructed to find a 0day.
Showing posts with label smpctf. Show all posts
Showing posts with label smpctf. Show all posts
Wednesday, July 14, 2010
Tuesday, July 13, 2010
smpCTF challenge #2 write-up
Challenge #2 was similar to defcon trivial 200: you had to escape from a VIM editor, but this time it was not evil - you can see the screen.
We were given the following instructions:
We were given the following instructions:
ssh -l luser gordo.smpctf.com -p 2282 Password: smpctf Help find waldo..
smpCTF challenge #1 write-up
smpCTF challenge #1 was a simple web + programming challenge.
We were given the following instructions:
We were given the following instructions:
Set S = 1
Set P = 1
Set previous answer = 1
answer = S * P + previous answer + R
R = 39
After this => S + 1 and P + 1 ('answer' becomes 'previous answer') + 39
then repeat this till you have S = 11065.
The final key will be the value of 'answer' when S = 11065.
Example:
So if R = 15..
17 = 1 * 1 + 1 + 15
36 = 2 * 2 + 17 + 15
60 = 3 * 3 + 36 + 15
Submit the correct answer and you will recieve a flag. Have fun ;D
smpCTF challenge #5 write-up - Forensic
smpCTF challenge #5 was forensics: we were given the file forensic1-image and instructed to find a flag.
As usual, we start our analysis with file command:
As usual, we start our analysis with file command:
$ file forensic1-image forensic1-image: rzip compressed data - version 2.1 (15185973 bytes)
Monday, July 12, 2010
smpCTF challenge #3 write-up
This week-end was smpCTF, again I played with Nibbles and we ended 1st!
Challenge #3 was just horrible, right? ;) Worse than defcon packet100! But we finally got it, after PPP.
We were given the following instructions and hints:
Challenge #3 was just horrible, right? ;) Worse than defcon packet100! But we finally got it, after PPP.
We were given the following instructions and hints:
- Generate a file which has a SHA-1 hash of: 008ce55c7d1b602dc4c4c3ad52a5d064e6d1ef12
- Hint: DRM-0, Linux-1
- _DO NOT BRUTE FORCE_ it's not required...
- Hidden hint (HTML comment): t3=(*((unsigned int *)(key+2)))^(*((unsigned int *)(sec+0x56)));
Subscribe to:
Posts (Atom)