Capture The Talent: Detonation

g1@g1-infosec:~

CTF: Capture The Talent, 19/02/2022

Challenge name: Detonation

Challenge category: Web

On this challenge we are faced with a somewhat cryptic description and an IP address:

Challenge description

If we access that IP address on a browser we see this:

It’s cool indeed!

My first thought is to analyze the site with the Developer Tools. In Firefox and Chrome you can access this by hitting F12.
Not much is revealed until we check the Storage tab and we look at the cookie provided by the site:

That encoding looks familiar..

I think I recognize the Value of this cookie as a good candidate for a base64 encoded string. I proceed to visit Base64Decode and attempt to decode the string. We obtain this curious text:

Potential flag?

This looks promising! It could be a flag although it lacks the CTT{} formatting of this event’s flags. But, unsurprisingly, this string is rejected as the flag. Try harder!

Well here we are talking about space and a huge flying rock. I would call that an asteroid. What if we input asteroid as our cookie value? Will we ‘denotate’ the challenge? *wink*

First we encode the string asteroid using Base64Encode to obtain this:

Base64 encoded ‘asteroid’

We change the Value of our cookie so it looks like this:

Ready for a blast off?

We reload the page and.. eureka!
What a blast!

Flag found!

Special thanks to Capture The Talent for the initiative and the great fun!