Web Challenges

Aliens Make Me Wanna Curl

Description

We are expecting communications from an artificial intelligence device called MU-TH-UR 6000, referred to as mother by the crew. We disabled the login page and implemented a different method of authentication. The username is mother and the password is ovomorph. To ensure security, only mothers specific browser is allowed.

Author: Exiden

https://spooky-aliens-make-me-wanna-curl-web.chals.io/flagarrow-up-right

Solution

If you visit website it says: No auth!. From description we already have auth so lets send basic auth header.

TLDR version: send Authentication token with username:password as Base64. More about Basic Autharrow-up-right.

$ echo -n 'mother:ovomorph' | base64
bW90aGVyOm92b21vcnBo

$ curl -H 'Authorization: Basic bW90aGVyOm92b21vcnBo' https://spooky-aliens-make-me-wanna-curl-web.chals.io/flag
Incorrect Device!

For correct device change User-Agentarrow-up-right to given device in description.

$ curl -H 'Authorization: Basic bW90aGVyOm92b21vcnBo' -H 'User-Agent: MU-TH-UR 6000' https://spooky-aliens-make-me-wanna-curl-web.chals.io/flag
NICC{dOnt_d3pEnD_On_h3AdeRs_4_s3eCu1ty}
circle-check

Note

Forgot that curl supports authentication Lol... -u/--user username:password https://everything.curl.dev/http/autharrow-up-right

Ghosts in the Code

Description

Some student here spun up a site where people are submitting their stories about all of the spooky stuff on campus!

This site is clearly haunted... or, at the very least, cursed.

https://niccgetsspooky.xyzarrow-up-right

Flag Format: NICC{w0rds_may_c0nta1n_nums_and_chars!?} - but there are no apostrophes, commas, for colons

Author: Cyb0rgSw0rdarrow-up-right

Solution

Part 1 (/js/scary.js):

Part 3 (/js/scary.js):

Part 2 (/css/bootstraps.css):

Part 4 (HTML):

Part 6 (HTML):

Part 5 (Cookies):

circle-check

Jasons Baking Services

Description

Hey intern! We were able to swipe Jasons application from Github, see if you can find anything useful in the code that will allow you to exploit the real application.

(Be ready to be flash-banged, the web-app is all white!)

Author: Exiden

Challenge: https://spooky-jason-bakeshop-web.chals.io/arrow-up-right Source: jasons-bakeshop-src.ziparrow-up-right

Solution

The vulnariblity is in the given source. You can find config.env:

SECRET is a variable which will be used by application to sign/verify JWT tokens, if this secret is known anyone can forge any kind of tokens.

1. Register 2. Login 3. Copy token

chevron-rightExamplehashtag

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJuYW1lIjoiV295QWciLCJhdXRob3JpemVkIjp0cnVlLCJhZG1pbiI6ZmFsc2UsImlhdCI6MTY5ODU5Nzg3MiwiZXhwIjoxNjk4NTk4MTcyfQ.gpTZ_CkKSbDhn8fP2k-v9iIHFkClLhn0k4cvm2CCWQA

4\. Go to 5\. In `VERIFY SIGNATURE` paste the token (and dont check `secret base64 encoded`, because it's not, in most cases it is)

jasons-baking-services-1
circle-check

Dig Up Their Bones

Description

That blog seems suspicious and I bet that there's more to it than meets the eye.

See if you can dig up anything about the owner of the site?

You'll know what you're looking for once you find it.

https://niccgetsspooky.xyzarrow-up-right

Author: Cyb0rgSw0rdarrow-up-right

Solution

Since we already checked almost every source file on webserver there must be something else. Dig in the challenge name is hint for dig - DNS lookup utilityarrow-up-right

I used Dig (DNS lookup) - Google Apps Toolboxarrow-up-right to search every record and TXT record had the flag.

circle-exclamation

"SpookyCTF2023FLAG=NICC{gh0sts_ar3_h4rd_2_f1nd}"

circle-check

Note

On Windows you can use nslookup:

Space Intruders

Description

Our space ship was hacked a few days ago. We have made sure to improve our security posture by changing all default credentials. We made sure to stop invalid logins by limiting username input to a length of 3 including an equals, legacy software is a pain but it should be secure now.

Author: Exiden

https://spooky-space-intruder-web.chals.io/arrow-up-right

Solution

Credit:

space-intruders-1

Hacktricks: NoSQL - Basic Authentication Bypassarrow-up-right

circle-info

To my knowledge $exists worked because other filters got picked up by WAF.

circle-check
triangle-exclamation

Last updated