Mostrando entradas con la etiqueta ctf. Mostrar todas las entradas
Mostrando entradas con la etiqueta ctf. Mostrar todas las entradas

lunes, 14 de abril de 2014

Write-up: PlaidCTF 2014 - Heartbleed - Misc - 10 pts

El reto presentado tiene que ver con la vulnerabilidad presentada la semana pasada.

El enunciado decía lo siguiente:

Back up now! Hopefully for good.
Our hearts are bleeding. But instead of bleeding password bytes, they're bleeding flags. Please recover our flags so we don't bleed to death before we can update to 1.0.1-g. Site is up at https://54.82.147.138:45373

Lo que hice fue utilizar este PoC público para este bug:

python hb-test.py 54.82.147.138 -p 45373 > hb-response.txt

Parte del output es el siguiente:




 El flag es:flag{hey_guise_we_made_a_heartbleed}

domingo, 3 de marzo de 2013

Codegate 2013 - Misc 100 Write up

This weekend, two CTF competition were held: Codegate 2013 & Nullcon 2013 BattleUnderground. I was playing with my teammates Francisco and Archie.
 
This level was pretty easy, it was related to the movie "The Net" from 1995 with Sandra Bullock.

I just downloaded the subtitles of the movie and then I looked for words like "contraseña" (my subtitles were in Spanish), "login", etc; and this is what I found:

01:31:10,654 --> 01:31:13,121
<i>''Contraseña:/natoar23ae''</i>

The flag was: natoar23ae