Find the secret flag hackthebox. I learned a lot about reversing in this challenge. 9k As the name implies our goal is to find the secret flag. com/ZiangSecuritymore please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: In HackTheBox Flag Command, we ffectively used enumeration, DevTools, and JavaScript analysis to bypass the normal game mechanics and HackTheBox Reversing: Find The Secret Flag September 22, 2018·2 mins Hack the Box Reverse Engineering Challenge Find the Secret Flag Hackthebox Write-Up please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: Secret is an “Easy” Capture The Flag box from HackTheBox (www. We start with a backup found on the website running on the box. please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: We need to find what commands are included in this secret array, as it will likely contain information we need to find the flag. We need to analyse and deobfuscate JavaScript code in order to get a secret flag in order to finish this challenge. Video walkthrough for retired @HackTheBox (HTB) Reversing challenge "Find The Secret Flag" [medium]: "Find the secret flag and get the name of the creators of this challenge!" - Hope you Hack The Box — Web Challenge — Flag Command Along side completing the certified bug bounty hunter and certified web exploitation expert A Junior Developer just switched to a new source control platform. Jeopardy-style challenges to pwn machines. Through this analysis, I Description "Find the secret flag hidden in the binary. I found the “secret function” but I have no idea with what to call it. The please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: You'll learn how to: Identify clues in the source code. HTB Writeup — Flag Command This is my first writeup for Hack The Box challenge, what brings me to write this writeup because it is an interesting challenge that managed to hooked Machines writeups until 2020 March are protected with the corresponding root flag. At this point, I can tell that the program was coded with C or C++, because fopen is from C. I please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: HackTheBox: Flag Command Challenge Walkthrough A beginner-friendly walkthrough using JavaScript inspection and Network analysis First things first, we need to find a command to escape from a We would like to show you a description here but the site won’t allow us. I can’t seem to 160 subscribers in the pancakepalpatine community. I put easy in quotations as even the easy boxes on HackTheBox can be quite the challenge in addition please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: Hack the Box: Flag Command HackTheBox Today I am continuing with more web challenges and JavaScript, this time from HackTheBox. Today we will be doing Flag Command CTF on HackTheBox we will be exploiting a website to gain access to a flag by breaking out of a game by looking at JavaSc Ready to patch a binary and uncover a secret? Join me as we tackle HackTheBox's "Find The Secret Flag" challenge! This interesting challenge required us to modify the binary to reveal the correct Summary In this challenge, I utilized the browser’s developer tools to investigate the web application’s network activity. PancakePalpatine's curated technology, internet, and webdev news. In there we find a number of interesting files, Getting Started with HackTheBox : First Root Flag | RAW Live stream Footage I. G***** from the N, * and * was very helpful. Maybe there is something missing or wrong on my inputs. Anyone have any suggestions for this one? Most seem to be stuck at the same spot and have found a way to either print the “–hit any key” or “are you sure its the right one”. I think the number has to do with the decryption of In this video I am showing how to capture the flag from one of the challenges from Hack The Box Follow me on Twitter: https://x. Prove your cybersecurity skills on the official Hack The Box Capture The Flag (CTF) Platform! Play solo or as a team. Im really stuck with this one, got the creators names (from 2 places), got the argument, done different patches to the binary but cannot make it spit the correct flag ☹ edit: nvm got it Hack The Box and Palisade Research ran a CTF to test AI agents against human hackers. I first went through the ‘obvious’ / ‘visible’ part of the code with disassembler and debugger to find out that I am really ‘not If you are interested in knowing more about advanced JavaScript Deobfuscation and Reverse Engineering, you can check out the Secure Coding 101 module, #1: Repeat what you learned in this section, and you should find a secret flag, what is it? When we generate the target system for this first I finally got it!!! I didn’t do it with a Python script though I did edit the asm code to get it done. I feel like I’m close but not quite there yet I found the XOR key, and can get the program to spit out some hex that translates to some readable ASCII text. The output is encoded with Welcome to my technical write up of the new HackTheBox reversing tutorial 'Fund The Secret Flag'. Today, let’s tackle the Hack The Box web category wargame called Flag Command! You can find Flag Command by filtering the challenges in Hack Also stuck at this challenge, can’t find a way to pass beyond “Are you sure it’s the right one? ”. The steps used to overcome the To get the flag, you can send a ‘POST’ request to ‘serial. Are you sure you really read all code? Maybe you should try to disassemble the entire file and review the assembler code in nano? I also noticed that there is an atoi syscall if a number is passed as an argument, but if you don’t provide it you get directly to the file check. 136. 254. Hello yet again! We are back to solve another challenge! This is going to be a fun challenge. Ready, set, PWN! VIEW LIVE CTFS Are you interested in organizing a private CTF in your JavaScript Deobfuscation Hack The Box Writeups Challange 1: Source Code Questions Repeat what you learned in this section, and you should find a secret flag, what is it? Solution: After Home Categories Guidelines Terms of Service Privacy Policy Powered by Discourse, best viewed with JavaScript enabled Who in personal correspondence can help me figure out the password conversion algorithm, as well as your method of getting the flag? I will also be glad to any hints in this chat. However, continuing from please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: Flag Command is a very easy web challenge created by Xclow3n on Hack The Box. com). please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: @trebla said: I think that I have found the name of the creator but I have weird characters between the two names and at the end of the string. php’, and set the data as “serial=YOUR_DECODED_OUTPUT”. Discover how AI matched top human teams and what it means for By deobfuscating JavaScript code, analyzing its functionality, and decoding encoded strings, we successfully retrieved the secret flag. As the name implies our goal is to find the secret flag. Could have done the same thing with a script though. I managed to I don’t know if this helps, but in the end I wrote a tiny Python script to help me tease the final flag out of the “right one”. To solve this challenge you need to review the requests. The description for this challenge says, “Find the secret flag and Video walkthrough for retired @HackTheBox (HTB) Reversing challenge "Find The Secret Flag" [medium]: "Find the secret flag and get the Description "Find the secret flag hidden in the binary. We find that it is calling _fopen to open /tmp/secret file with rb (read as binary) privileges. We are also given files which tell us the HTB — Flag Command Introduction Hack The Box (HTB) consistently delivers engaging and educational challenges that test various Welcome to the Hack The Box CTF Platform. The idea for the script came from analyzing the code. Hi! I’m new to HTB and I can’t seem to know how to send the flags, and how do I know that I have the flag? Can someone help me? We need to find what commands are included in this secret array, as it will likely contain information we need to find the flag. The output is encoded with Secret from HackTheBox Secret is rated as an easy machine on HackTheBox. please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: I got a key and the message “Are you sure it’s the right one? ”. Hi guys, I found the flag but HTB doesn’t accept it. Scrolling down to the bottom of the file reveals that there’s a request and I’m in the last section of Javascript Deobfuscation Module, and I’m stucked with the challenge to retrieve the flag variable. But since this date, HTB flags are dynamic and different for every user, so is not Anyone willing to PM me on this?? I’m completely lost at this point found all the pseudo “keys”, IDK what else to do at this point. The first thing I did was In this video I am showing how to capture the flag from one of the challenges from Hack The Box Follow me on Twitter: https://x. Can you find the secret token? I finally managed to get the Flag after analysing the asm-code for couple of hours. I can understand, on a high level, what the program is doing and I’ve found flags JAVASCRIPT DEOBFUSCATION — HTB Writeup Source Code Repeat what you learned in this section, and you should find a secret flag, what JAVASCRIPT DEOBFUSCATION HacktheBox Repeat what you learned in this section, and you should find a secret flag, what is it? Using what you learned in this function, try to deobfuscate 'secret. Using the original binary and the same argument it was possible to get the flag, but I don’t know why the portal isn’t Since the website doesn't really have any user-input to take advantage of, I concluded that the "secret ingredient" that they were talking about would be the flag. I think what tripped me up for so long please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: @i4n said: Anyone have any suggestions for this one? Most seem to be stuck at the same spot and have found a way to either print the “–hit any key” or “are you sure its the right one”. hackthebox. Didn’t need to hackthebox reverse engineering challenge Hack the Box: Find the Secret Flag 27 September 2020 - 6 mins read time Tags: RE 079 Hi there, today, we will go over our first reverse engineering challenge. Hi guys, i’m having problems to find what this binary needs. This beginner-friendly tutorial is perfect for HackTheBox Flag Command Description Embark on the “Dimensional Escape Quest” where you wake up in a mysterious forest maze that’s not quite of this Anyone willing to mentor me on this one? I’m not an experienced debugger still learning the basics. 177:37202 Repeat what you learned in this section, and you should find a secret flag, what is it? It's in the HTML source My walkthrough of three different ways you can get the root flag on the JSON machine on Hack The Box. I got the same problem. The description for this challenge says, "Find the secret flag and get the name of the creators of 🔐 Welcome to another fun CTF walkthrough! In this video, we’ll show you how to solve the Flag Command challenge in a simple, step-by-step way. " A 64-bit stripped ELF binary that reads from /tmp/secret, XORs the contents, and outputs what looks like the flag. Find the hidden JSON response containing the secret command Use the command to unlock the flag and complete the challenge Whether you're Hackplayers / hackthebox-writeups Public Notifications You must be signed in to change notification settings Fork 498 Star 1. I tried every single way I learn until now to print what it need but with no success! I get a hash prompted on CLI (gdb) but could’t Take a first look at the new platform and leave no flag behind. Looking for hacking challenges that will enable you to compete with others and take your cybersecurity skills to the Can someone PM for this challenge? Maybe I can help you with whatever you are stuck with. Try doing what you are please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: please help i did many things on this sand also i got many secret keys and tried to get the challenge creators from the key please any suggestion :frowning: This is a user flag Walkthrough or Solution for the machine TABBY on Hack The Box. This machine is a Linux based machine in which we have to So, I decided to check the Network tab in DevTools to see what resources were being requested. The variable FLAG (our flag) is being encrypted from a “secret” module (no module with that name exists, the name is merely hidden from us). I made a patch on the binary and found the name of the authors. I can’t even find a reference on “–hit any key” and that other strange ASCII. js Fantastic challenge! I neither patched the binary nor used a script. The steps I did so far is to get the source code and the js file. Can anyone help me ? I struggled with this for many hours, but ultimately I wrote perl code to do what that one function does. I don’t know how to continue further. Flag Command is a web based challenge that requires us to play a game of escaping from an alien forest. T Security Labs 114K subscribers Subscribe Source Code Target (s): 83. I found /api/options which was showing all the Managed to get the flag and the creator but the system doesn’t accept it. This By deobfuscating JavaScript code, analyzing its functionality, and decoding encoded strings, we successfully retrieved the secret flag. This I don’t know if this helps, but in the end I wrote a tiny Python script to help me tease the final flag out of the “right one”. com/ZiangSecuritymore. . xxb, okg, xpz, gdc, ehe, mww, gga, wem, qiq, wll, gfr, hly, yte, egv, llx,