Skip to content

Latest commit

 

History

History
60 lines (36 loc) · 1.8 KB

index.md

File metadata and controls

60 lines (36 loc) · 1.8 KB

Welcome to Secured Monitorr Challenge [Bonus Box]

I guess monitoring the server doesnt cause a harm .. right?

Instructions

  1. To open the challenge you need to paste all the 3 flags in the correct order.

  2. After getting the IP donot share it with other players.

  3. The box might go down due to severe load. In that case we might add new box or instance.

  4. Donot share the flag.

  5. Donot harm the box / the testing environment by installing something!

  6. If you want to reset the box drop a mail at [email protected] along with your username.

  7. Donot delete any files which is pre-loaded in the system.

  8. Start with the following piece of code.

  9. Even though its an AWS instance you cannot get aws-metadata / or IAM / Security details. If you get by somehow please do drop me a mail along with the POC.

Code Snippet

<html>
  <!-- CSRF POC -- Generated By @dark_haxor -->
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="https://ctf.sudoflaws.in/ip_giver.php" method="POST">
      <input type="hidden" name="fname1" value="sudoflaws{Flag of challenge SpaceWhite}" />
      <input type="hidden" name="fname2" value="sudoflaws{Flag of challenge Kennywizard}" />
      <input type="hidden" name="fname3" value="sudoflaws{Flag of challenge AlienTech}" />
      
    <!-- No spaces in between flags ..please do eliminate those spaces -->
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

Box Credits:

https://twitter.com/dark_haxor

Donate me:

IF you really liked the box feel free to donate 🙂

Bitcoin 1PgyTpKQ4AcUGVuSJSq5fLXvLjVeputL1g

Stellar GAT62OFZ3LUOTSNKKPSB2J6JBW4XU4G2FUKFVTV3U2PPNRSTAQ6XS7V3

Etherium 0x0CF6EC165D27E1cf65a1360d4D6bCb4233dEd36B

USD Digital 0x0CF6EC165D27E1cf65a1360d4D6bCb4233dEd36B