Nahamcon CTF 2023
Table of Contents
Nahamcon CTF 2023
I was the only one on my team.
Read the rules
a link to the rules and found in view-scorce
line 273 flag{90bc54705794a62015369fd8e86e557b}
Rules
We don’t want to have to enforce restrictions on you, but there are a few things we would like to politely ask you not to do:
- Please do not attack the competition infrastructure or other players. The challenges are your targets. That’s it.
- You do not need to use automated scanners like
sqlmap
, DirBuster,nmap
, Metasploit,nikto
or others. Please do not use them against the challenges. - Please do not brute-force flags.
- Please do not share flags with other players, or explicitly and deliberately cheat.
- Please do not blatantly ask for hints. The proper to way to ask for help is to explain what you have tried and showcase_(in a direct message)_ what errors or output you may have.
Flag Format
Flags for this competition will follow the format: flag\{[0-9a-f]{32}\}
. That means a flag{}
wrapper with what looks like an MD5 hash inside the curly braces. If you look closely, you can even find a flag on this page!
Support
For admin support in the case of any technical issues, please join the NahamSec
Discord server: https://discord.gg/nahamsec-598608711186907146.
You should find a #ctf-general
channel in the NahamCon 2023 category and direct your questions there. When your question requires discussing a specific challenge, please direct message one of the challenge authors as noted in the challenge description.
Ctrl + U
...Fast Hands
Author: @JohnHammond#6971
You can capture the flag, but you gotta be fast!
Press the Start
button on the top-right to begin this challenge.
Connect with:
- http://challenge.nahamcon.com:31565 Please allow up to 30 seconds for the challenge to become available.
Description
This challenge had a button that when you click it it would open a new tab and then immediately disrepair, I tried to use inspect in the web browser but found it was much easier to use burp to find that this was in the body of the web page
in the body of the page found `