PicoCTF 2024
by not_a_30t - Wednesday March 13, 2024 at 12:11 PM
#11
(Mar 17, 2024, 11:51 PM)kali1337 Wrote: Who was able to set Samsung: TimeStamp: 1970:01:01 00:00:00.001+00:00 (Checking tag 7/7) in task Blast from the past?

I got 6/7 this Samsung tag has been driving me nuts
Reply
#12
(Mar 16, 2024, 08:09 PM)metapreter Wrote: Anyone trade flegs for forensics??????????????????????
I have all except last 2

What are you looking for?
Reply
#13
(Mar 16, 2024, 02:28 PM)not_a_30t Wrote: for verify sha256sum , it is not working for a directory , i even tried ls | grep picoCTF but no result

What can be done for noSql , I tried  {"username":{"$regex":"^admin"},"password":{"$gt":""}}
and saw the src  code , I tried to go directly to /admin abut no flag seen    In the code there is models/users page , where i saw token: { type: String, required: false ,default: "{{Flag}}"}

Seems like there is a user called "joshiriya355@mumbama.com" (seed.ts). There is also some weird parsing going on checking between brackets?
[color=#9cdcfe]email:[/color] [color=#4fc1ff]email[/color].[color=#dcdcaa]startsWith[/color]([color=#ce9178]"{"[/color]) [color=#d4d4d4]&&[/color] [color=#4fc1ff]email[/color].[color=#dcdcaa]endsWith[/color]([color=#ce9178]"}"[/color]) [color=#d4d4d4]?[/color] [color=#9cdcfe]JSON[/color].[color=#dcdcaa]parse[/color]([color=#4fc1ff]email[/color]) [color=#d4d4d4]:[/color] [color=#4fc1ff]email[/color],


Anyone got a hint for Trickster (Web file upload challenge)?
Reply
#14
(Mar 16, 2024, 08:09 PM)metapreter Wrote: Anyone trade flegs for forensics??????????????????????
I have all except last 2

with element i agree

(Mar 14, 2024, 01:41 PM)leadrelic Wrote: Anyone get how to solve sansalpha?

yah solved lets trade with element
Reply
#15
(Mar 18, 2024, 12:40 AM)biZaRRoBaT Wrote:
(Mar 17, 2024, 11:51 PM)kali1337 Wrote: Who was able to set Samsung: TimeStamp: 1970:01:01 00:00:00.001+00:00 (Checking tag 7/7) in task Blast from the past?

I got 6/7 this Samsung tag has been driving me nuts

It seems like it is not writeable. Apparently there was a tool that was able to do it from Samsung itself but I can't find it anymore (not available on the link supplied and on the wayback machine):
Reply
#16
(Mar 18, 2024, 09:05 PM)pwn1 Wrote:
(Mar 16, 2024, 08:09 PM)metapreter Wrote: Anyone trade flegs for forensics??????????????????????
I have all except last 2

with element i agree

(Mar 14, 2024, 01:41 PM)leadrelic Wrote: Anyone get how to solve sansalpha?

yah solved lets trade with element


i got blast from the past...anyone wanna trade for SansAlpha

(Mar 18, 2024, 12:40 AM)biZaRRoBaT Wrote:
(Mar 17, 2024, 11:51 PM)kali1337 Wrote: Who was able to set Samsung: TimeStamp: 1970:01:01 00:00:00.001+00:00 (Checking tag 7/7) in task Blast from the past?

I got 6/7 this Samsung tag has been driving me nuts


trade blast from past for mob psycho and introtoburp...fair offer
Reply
#17
(Mar 19, 2024, 10:47 AM)LU_1F3R Wrote:
(Mar 18, 2024, 09:05 PM)pwn1 Wrote:
(Mar 16, 2024, 08:09 PM)metapreter Wrote: Anyone trade flegs for forensics??????????????????????
I have all except last 2

with element i agree

(Mar 14, 2024, 01:41 PM)leadrelic Wrote: Anyone get how to solve sansalpha?

yah solved lets trade with element


i got blast from the past...anyone wanna trade for SansAlpha

(Mar 18, 2024, 12:40 AM)biZaRRoBaT Wrote:
(Mar 17, 2024, 11:51 PM)kali1337 Wrote: Who was able to set Samsung: TimeStamp: 1970:01:01 00:00:00.001+00:00 (Checking tag 7/7) in task Blast from the past?

I got 6/7 this Samsung tag has been driving me nuts


trade blast from past for mob psycho and introtoburp...fair offer

I got mob psycho but I dont have intotoburp, I do have others though so would still like to trade, let me know
Reply
#18
(Mar 18, 2024, 09:05 PM)pwn1 Wrote:
(Mar 16, 2024, 08:09 PM)metapreter Wrote: Anyone trade flegs for forensics??????????????????????
I have all except last 2

with element i agree

(Mar 14, 2024, 01:41 PM)leadrelic Wrote: Anyone get how to solve sansalpha?

yah solved lets trade with element
 can u give a hint pls or article article
Reply
#19
(Mar 19, 2024, 02:00 PM)mefunman Wrote:
(Mar 19, 2024, 10:47 AM)LU_1F3R Wrote:
(Mar 18, 2024, 09:05 PM)pwn1 Wrote:
(Mar 16, 2024, 08:09 PM)metapreter Wrote: Anyone trade flegs for forensics??????????????????????
I have all except last 2

with element i agree

(Mar 14, 2024, 01:41 PM)leadrelic Wrote: Anyone get how to solve sansalpha?

yah solved lets trade with element


i got blast from the past...anyone wanna trade for SansAlpha

(Mar 18, 2024, 12:40 AM)biZaRRoBaT Wrote:
(Mar 17, 2024, 11:51 PM)kali1337 Wrote: Who was able to set Samsung: TimeStamp: 1970:01:01 00:00:00.001+00:00 (Checking tag 7/7) in task Blast from the past?

I got 6/7 this Samsung tag has been driving me nuts


trade blast from past for mob psycho and introtoburp...fair offer

I got mob psycho but I dont have intotoburp, I do have others though so would still like to trade, let me know

you got sans-alpha?
Reply
#20
(Mar 17, 2024, 11:51 PM)kali1337 Wrote: Who was able to set Samsung: TimeStamp: 1970:01:01 00:00:00.001+00:00 (Checking tag 7/7) in task Blast from the past?

I was able to.  I need help with SansAlpha

(Mar 14, 2024, 06:50 PM)Adith Wrote: i really need to solve No Sql Injection. i did solve first web unminify question. please someone help

Did you solve it ??  if not hit me up and I will help.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 92,000 Yesterday, 06:48 PM
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,985 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,046 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,636 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,284 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)