Skip to content

h4tt/H4TT-3.0

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

sreencast

Hack All The Things Round 3.0

crypto

Author: Forest Anderson

wcrx{vk_kl_silk3}

Author: Forest Anderson

Some thing that my big brother is too hard to read, so I change it up a little. 7oLE1AHC4nb8kiaEeaqDuit44S3CCp

Author: Dave Petrasovic

2225086084306530724665

format: flag{deciphered_text_lower-case_with_underscores_for_spaces}

Author: Matt Penny

We got word that Evilcorp is trying out a new authentication mechanism. It's pretty new and untested so I doubt it's secure. See if you can break it.

Author: Dave Petrasovic

f{shm-nc3lc440t-1ra4rdrh1p}g3--34-h

Author: Dave Petrasovic

EEMEMEMEMEEEEEEEEMMEEMEMMEMEMMEMEMMEMEMMEEEEMEEEEEEEEMEEMMEMEMMEE

format: FLAG{UPPERCASE-WITH-DASHES-FOR-SPACE}

Author: Dave Petrasovic

LxrXLsgmbyStKmHsSjAujmAzn41kLlXFSIPkKmHsSjAujlWJnkc5n4AmK4A4Mtg6TJbC

Author: Matt Penny

We obtained access to EvilCorp's debug tools for product keys. See if you can decipher their internal representation.

Author: Matt Penny

You must complete part 1 first.

Now that we know how EvilCorp's license keys are structured, we need to to create a key licensed to the user "evilcorp" that we can use to avoid detection. Don't forget to verify it with the debug tools!

Author: Clayton Smith and Forest Anderson

One of our FSociety agents was undercover in Estonia in 2017. We haven't heard from him since, and we thought he was KIA. However, we've recently recieved a file with their identity card. Clearly the agent is trying to give us some information, but what is it?

evilcorp

Author: Francisco Trindade

You've received a link to Evil Corps website through an anonymous email. Try and see what you can find.

Author: Francisco Trindade

Looks like the Evil Corp mole has given us an encrypted file, see if you can't decrypt it.

Author: Francisco Trindade

Looks like the leaked memo might reveal some security vulnerabilities on the login form. See if you can't gain access.

Author: Francisco Trindade

Looks like some file is readable that shouldn't be. Go find it.

Author: Francisco Trindade

We need to see what's in /tmp. Try and gain access to those files.

Author: Francisco Trindade

The mole seems to have given us a way to get the last bit of info in /root. See if you can't get access to it.

forensics

Author: Forest Anderson

Flag format flag{WORDS_UPPER_CASE}

Author: Dave Petrasovic

We found this Nickleback album on a disgruntled employee's computer. Are they hiding anything?

Author: Matt Langois

What a sublime day!

Author: Dave Petrasovic

Author: Griffin

You find yourself in a room with a strip of paper being fed out of a wall and a flashing light. After a time, it stops. On the tape is a sequence of bits traced out. The start and end are smudged. What could they mean? ...1111111111111111111111100000111111101101011111110010000001001110011011110010110000100000011101000110100001101001011100110010000001101001011100110010000001101110011011110111010000100000011000010111001101100011011010010110100100101110001000001110100000010111110110110010000111101011011011111111100110110110001111111010101101100001111110001101001110110001111111101100011111111011000111010100110110001111111100000001110110111111101100001100100100000010000000000000000000000000000... flag format: flag(UPPER_CASE)

Author: Forest Anderson

I've encrypted this image with a super secret password! You'll never get it open! Fine, I'll give you some information. The image is 1000x1000 and stored in Raw full-byte PPM goodness. You still need more info? Ok, here is the command I used: openssl enc -aes-128-ecb -nosalt -pass REDACTED -in tux.ppm -out image.enc

misc

Author: Matt Penny

We intercepted a secret file, but how can anything fit in 24K?!

phys

Author: Forest Anderson

Pick the basic locks 1-3

Author: Forest Anderson

Pick the basic locks 3-6

Author: Forest Anderson

Pick the next 2 locks

Author: Forest Anderson

Pick the last 2 locks

Author: Forest Anderson

You're almost out, time to just get out of some cuffs

pwn

Author: Matt Langois

We managed to get restricted access to a box!

nc evilcorp.h4tt.ca 9005

P.S. We managed to get the source to the binary, see the attached file.

Author: Matt Penny

We got into the Evilcorp CEO's family computer. Looks like something important was left lying around.

Author: Matt Penny

The Evilcorp CEO is onto our trick from last time. See if you can extract more secrets.

recon

Author: Forest Anderson

What's wrong with CSIS? Can you get the name of this episode? Flag format flag{NAME_UPPER_NO_SYMBOLS}

Author: Forest Anderson

What street does this kitty live on? The flag is in the form flag{STREET_UPPER_CASE}

Author: Dave Petrasovic

Author: Forest Anderson

I'm waiting for a bus right now! Can you figure out what city I'm in? The flag is in the form flag{CITY_UPPER_CASE}

Author: Dave Petrasovic

The following video files were recovered from the storage device in a Tesla Model 3

rev

Author: Matt Langois

Who needs x86 when you have MIPS?

Author: Sean Maher

Can you hear the elves sending out packages?

Author: Sean Maher

The flag is somewhere in the binary. Can you find it?

Author: Sean Maher

Dynamic analysis just got a lot harder. Can you beat the oods?

Author: Sean Maher

I lost my flag! Can you help me find it?

stego

Author: Matt Langois

We've recieved an image of two evilcorp members in a video call. Take a look for any hidden messages

Author: Dave Petrasovic

Definition: https://www.youtube.com/watch?v=YTkuJ4vRQZM Format: flag{example-flag}, lower case, dashes in place of spaces.

Author: Matt Penny

We found this strange file but have no idea what's inside it, or even what it is.

web

Author: Francisco Trindade

I think the developers at evilcorp left something accidentally

Author: Forest Anderson

You're looking pretty good today, but maybe a bit off center?

Author: Francisco Trindade

Evil Corp threw up an interesting report generator

Author: Francisco Trindade

Can you catch it?

Author: Francisco Trindade

Evil Corp posted something interesting that needs some deciphering

Author: Francisco Trindade

Follow the Rabbit Hole

Author: Dave Petrasovic

Author: Matt Penny

It looks like EvilCorp runs personalized web portals for employees to access the contents of their corporate phones. We've got access to one of them - I wonder if there are any secrets in there.

Author: Francisco Trindade

Morpheus has an interesting decision for you Neo.