INS’HACK :: 2019 :: Neurovision Misc 206 pts Writeup

Challenge details. Category Points Solves Difficulty Misc 206 20 Hard 1. Challenge description We found this strange file from an AI Startup. Maybe it contains sensitive information…Neurovision files 2. SOLUTION #1 We are given an HDF5 file named neurovision-2d327377b559adb7fc04e0c3ee5c950c, executing the file command will tell us its an HDF5 file. file neurovision-2d327377b559adb7fc04e0c3ee5c950c # outputs neurovision-2d327377b559adb7fc04e0c3ee5c950c: Hierarchical Data Format (version 5) data For More on HDF5 structure HERE
Read more →

INShAck 2019 :: You Shall Not Pass :: Forensics 330 Writeup

Challenge details. Category Points Solves Forensics 330 11 1. Challenge description One of my friends is a show-off and I don’t like that.Help me find the backdoor he just boasted about! :DYou’ll find an image of his USB key here.And one last thing, my friend owns you-shall-not-pass.ctf.insecurity-insa.fr. 2. Solution 2.1 Data Extraction Part By extracting the compressed file that was given to us, we find a raw image of an NTFS filesystem, you can verify that using the file command on linux.
Read more →

AngstromCTF 2019 | No SEQUELS and No SEQUELS 2 Web Writeup

This blog post contains the writeup for two challenges (No SEQUELS & No SEQUELS 2), because they are related. So let’s start with No SEQUELS first. 1. No SEQUELS 1 Category: Web Points: 50 1.2 Challenge Description The prequels sucked, and the sequels aren’t much better, but at least we always have the original trilogy. Hint said : MongoDB is a safer alternative to SQL, right?
Read more →

AngstromCTF 2019 Secret Sheep Society | CTF Writeup

Challenge details Category Points Solves Crypto 120 98 TL;DR Spotting the weakness (AES with CBC Mode). Get token. Flipping specific bytes in session json (turn false to true ). manipulate token with flipped bytes. Send manipulated token to page. Get the flag. Challenge Description The sheep are up to no good. They have a web portal for their secret society, which we have the source for.
Read more →

Hacklab ESGI 2019 | Rookie Web100 Writeup

Challenge Description Category Points Solves web 100 18 This is the URL for the challenge. URL:http://ctf.hacklab-esgi.org:8082/ So, as soon as we visit the given URL, we get a simple web page saying Website Checker and the title saying super curling (this gonna be fun!!). we notice that there is one input in the page, whatever you give as input gets passed to curl as a parameter.
Read more →