Flag Command
Writeup for Flag Command (Web) - HackTheBox Cyber Apocalypse CTF (2024) π
Video Walkthrough
Description
Embark on the "Dimensional Escape Quest" where you wake up in a mysterious forest maze that's not quite of this world. Navigate singing squirrels, mischievous nymphs, and grumpy wizards in a whimsical labyrinth that may lead to otherworldly surprises. Will you conquer the enchanted maze or find yourself lost in a different dimension of magical challenges? The journey unfolds in this mystical escape!
Solution
We load the webpage and find a terminal, enter a random string.
'hi' command not found. For a list of commands, type 'help'OK, let's do it.
>> help
start Start the game
clear Clear the game screen
audio Toggle audio on/off
restart Restart the game
info Show info about the gameIf we start the game, we can select one of 4 options. I choose to HEAD NORTH.
We get another 4 options. At this point, let's check the web traffic in burp. There's a call to /api/options and in it are some possible commands. Notice we have a secret option.
Let's send the secret message and receive the flag!
Note: I didn't actually solve it like this. Instead I checked the JS before playing the game and saw this function.
Subsequently, I made a GET request to this endpoint and discovered the secret option π
Flag: HTB{D3v3l0p3r_t00l5_4r3_b35t_wh4t_y0u_Th1nk??!}
Last updated
