Hello I am Arsalan. Offensive Security Engineer, I blog about Cyber security, CTF writeup, Programming, Blockchain and more about tech. born and raised in indonesia, currently living in indonesia
as you can see, we have to guess the correct input according to
these output, so i manually collect all the data, and create a
script to solve automatically
run the script, and we got our flag
Flag:
hacktoday{tebak_tebak_berhadiah_flag_1kEb44t}
Hard Rock casino
Description:
play smart and win
nc chall.codepwnda.id 14021
Solve:
Service Source code
according to the source code, our chance to win is depends on random()
so i create a simple script to solve it:
you can use volatility to find the right profile, so we can digging more into it
according to the description, i assume our flag is stored inside recent command,then i use cmdscan to get the flag
Flag:
hacktoday{yOUv3folll0wed_My_c0mm4ND_f3ry_w3LL}
Stegosaurus
Description:
omething creepy is hiding here.
format flag: “hacktoday{flag}”, tiap kata dipisahkan oleh “_”
Solve:
use stegsnow to extract the hidden data
download the image, and use stegsolve.jar to get the flag
Flag:
hacktoday{ez_point_yow}
Nothosaurus
Description:
#007
Solve:
there is a zip header inside okay file, so i assume this is the
zip file, so i create a simple script to join the file
after the file extracted, there is 2 file inside it broken.jpg and cute.jpg
so we have to compare each file and dump the difference between two file
FLAG:
hacktoday{broken_image}
Harta Karun
Description:
Seorang penggemar harta akhirnya insaf setelah menonton drama pengingat dosa, ia pun mengadakan sebuah sayembara untuk menemukan harta yang telah ia simpan di suatu tempat. Para peserta hanya diberikan gambar peta untuk menemukan Location dari harta tersebut. Apakah kamu yang menjadi juara?
Solve:
extract with foremost, and join the file
Flag:
hacktoday{di_bawah_kasur}
Daun Singkong
Description:
tanam-tanam ubi tak perlu dibajak.
Solve:
Extract daunsinkong.zip i found .DS_Store inside the archive
i use https://labs.internetwache.org/ds_store/. to extract all the information
brute the flag.7z using .DS_Store information, password: pertanianindonesiakanlebihbaikjikapetaninyatidakmainctf