2024 HuntressCTF - Base-p-

2024-10-08 | #

Summary Author: Izzy Spering That looks like a weird encoding, I wonder what it's based on. Steps Looking at the text file for the challenge I see this: 楈繳籁萰杁癣怯蘲詶歴蝕絪敪ꕘ橃鹲𠁢腂𔕃饋𓁯𒁊鹓湵蝱硦楬驪腉繓鵃舱𒅡繃絎罅陰罌繖𔕱蝔浃虄眵虂𒄰𓉋詘襰ꅥ破ꌴ顂𔑫硳蕈訶𒀹饡鵄腦蔷樸𠁺襐浸椱欱蹌ꍣ鱙癅腏葧𔕇鱋鱸𓁮聊聍ꄸꈴ陉𔕁框ꅔ𔕩𔕃驂虪祑𓅁聨朸聣摸眲葮𖠳鵺穭𒁭豍摮饱恕𓉮詔葉鰸葭楷洳面𔕃𔑒踳𔐸杅𐙥湳橹驳陪楴氹橬𓄱蝔晏稸ꄸ防癓ꉁ𖡩鵱聲ꍆ稸鬶魚𓉯艭𔕬輷茳筋𔑭湰𓄲怸艈恧襺陷项譶ꍑ衮汮蹆杗筌蹙怰晘缸睰脹蹃鹬ꕓ脶湏赑魶繡罢𒉁荶腳ꌳ蕔𔐶橊欹𖥇繋赡𐙂饎罒鵡𒉮腙ꍮ楑恤魌虢昹𒅶效楙衎𔕙ꉨ𓈸𔑭樯筶筚絮𓁗浈豱ꉕ魔魧蕕聘筣鹖樫ꍖ汸湖萰腪轪𓉱艱絍笹艨魚詇腁𒁮陴顮虂癁 The challenge’s name is Base-p-. The -p- reminds me of the all ports commands on nmap which reminded of a challenge last year where I had to use Base65536. Trying that same approach I was able to decode the text another chunk of base64 text.

Continue reading 


2024 HuntressCTF - Myster

2024-10-08 | #

Summary Author: Michael Orlino Someone sent this to me... such enigma, such mystery: rkenr wozec gtrfl obbur bfgma fkgyq ctkvq zeucz hlvwx yyzat zbvns kgyyd sthmi vsifc ovexl zzdqv slyir nwqoj igxuu kdqgr fdbbd njppc mujyy wwcoy Settings as below: 3 Rotor Model Rotor 1: VI, Initial: A, Ring A Rotor 2: I, Initial: Q, Ring A Rotor 3: III, Initial L, Ring A Reflector: UKW B Plugboard: BQ CR DI EJ KW MT OS PX UZ GH Steps This was a new challenge.

Continue reading 


2024 HuntressCTF - Ran Somewhere

2024-10-08 | #

Summary Author: @Spyderwall Thanks for joining the help desk! Here's your first ticket of the day; can you help the client out? Steps This challenge had an .eml file with three attachments. Starting off with the email I was presented with this information. The URL in the signature was point to https://sites.google.com/view/id-10-t/home. Moving on to look at the attachments, I see 4e 6f 74 65.txt which translates to note.txt and the file was a hex encoded message.

Continue reading 


2024 HuntressCTF - System Code

2024-10-08 | #

Summary Author: Truman Kain Follow the white rabbit. NOTE: Bruteforce is permitted for this challenge instance if you feel it is necessary. Steps When starting this challenge we are presented with a red or blue pill. The blue pill to redirect to a matrix screen with a text box. If you input the incorrect value, you’ll receive this error: “Incorrect. You will receive the flag with the correct input.”. At the bottom of the website is a credit link that will take you to the matrix repo.

Continue reading 


2024 HuntressCTF - Malibu

2024-10-04 | #

Summary Author: Truman Kain What do you bring to the beach? NOTE: There are two things to note for this challenge. This service takes a bit more time to start. If you see a Connection refused, please wait a bit more. This service will not immediately respond or prompt you... it is waiting for your input. If you just hit Enter, you will see what it is. Extra tip, once you know what the service is, try connecting in a better way.

Continue reading 