4 ms·
Its a classic alright but being a classic just a warning to everyone some of it does require going back in time a little bit like dealing with a 16bit binary.
by 0x0539 11y ago
Its a classic alright but being a classic just a warning to everyone some of it does require going back in time a little bit like dealing with a 16bit binary.
If this type stuff interests any of you but is too hard, give mine a try ( 0x0539.net ). It is not intended to be a significant challenge, instead all the stages focus on introducing some basic concept related to offensive security. Its mostly aimed at some young teens that have expressed an interest in learning that stuff rather so the target is very introductory.
I update the site every so often with new sets of challenges and rotate through former sets if someone requests it. The current one I ran for a bit in 2013 and then brought it back earlier this year and plan to cycle in a new binary exploitation focused one in December.
- busterarm 11y agoI've gotten so far as finding the first secret and turning that into something viewable so I can read the two word question. Not quite sure what to do with the stuff that's left over yet though.
- noobie 11y agoThere are 10 types of people.. ;)
- rhubarbcustard 11y agoI've got past this bit and got the deciphered output but am hopelessly stuck on the next bit. Any clues?
- busterarm 11y agoSure, that gives me an address, but the host isn't reachable. I played around with it and found a login page that might be similar but _no clues_ as to how to gain access. Feel like I'm missing an intermediate step here.
- 0x0539 11y agoOh sorry, that is a side-effect from bringing it back the domain was slightly different. As for the login page, sometimes the way in is not through the front door.
- nint22 11y agoI really enjoy these puzzles, but I'm also stuck at the login page. Even poking around, and ignoring that the subdomain isn't working, I don't see anything else. Have any suggestions?
- 0x0539 11y agoEverything you need to figure it out is on the login page. Consider how hackernews works, there is the login page but that is not the only means to authenticating. You don't after all have to type your user/pass out for every page request.
- nint22 11y agoThanks for the tip! I'll be attacking this again tonight, I think I have an idea now that you mention auth. By the way, some subdomains are public (not sure if part of the game), like source.0x0539.com, oxidized etc. Awesome work, thanks for the fun! Edit: Just got past login, what an awesome puzzle. That being said, I hate that it looks like I have a run an executable from your site. Seems dangerous, so now I have to spend the time getting a VM setup.
- 0x0539 11y agoYou don't have to run the executable. You can, but the problem is absolutely doable without running it (static reversing). As for the subdomains, you can safely ignore them. There are a number of them most are not primarily mine. I just give some friends free hosting(or point subdomains to their boxes) And yea there are random subdomains that are not part of it. Most of the subdomains are not even mine (I give free hosting to friends). The only subdomain that was part of it was clcs.0x0539.net but thats no longer the case.
- rhubarbcustard 11y agoThis is fun! Can we sign up anywhere to get an email when you do updates?