Sunday, June 14, 2020

Hacker101 CTF: A little something to get you started

Hacker101 is one of the best when it comes to bug bounty. With the intent to brush up my skills to become a good bug bounty hunter, I have started Capture the Flag (CTF) from Hacker101. In its learning path, the very first challenge we get is

  • A little something to get you started

When you click Go, you get to the following page

At first, it feels like there is nothing to do here. Trust me. I felt the same. No any buttons to click and no any things to do. Just the text "Welcome to level 0. Enjoy your stay."


So, I began to play around, honestly! I started with manipulating given URL: http://35.190.155.168/bf06d4167c
i.e. changing bf06d4167c values to random number. And then adding some stuff to this URL bf06d4167c/abc etc. I know this was not a smart move. Just gave it a try. 


Since, nothing seemed to work, then, I clicked on Developer Tool.

Even here nothing will be obvious in the first look. Again some play around. I saw background-image mentioned in the body section, but nothing can be seen there. So, i searched for background.png in the url itself as: http://35.190.155.168/bf06d4167c/background.png

Voila! there is the flag.



14 comments:

  1. Excellent blog! I read your blog and it’s really impressive that you mainly stress the quality management word. Thank for sharing this blog. This type of blogs is always appreciated.iso-27001-lead-auditor-training

    ReplyDelete
  2. Thanks you for sharing this unique useful information content with us. Really awesome work.. ISO 9001 Lead Auditor Course Saudi

    ReplyDelete
  3. Thanks for given detail information to me. keep posting like this. iso-14001

    ReplyDelete
  4. FULLZ AVAILABLE WITH HIGH CREDIT SCORES 700+
    (Spammed From Credit Bureau of USA)

    =>Contact 24/7<=

    Telegram> @killhacks
    ICQ> 752822040

    FRESHLY SPAMMED
    VALID INFO WITH VALID DL EXPIRIES

    *All info included*
    NAME+SSN+DOB+DL+DL-STATE+ADDRESS
    Employee & Bank details included

    CC & CVV'S ONLY USA AVAILABLE

    $1 for SSN+DOB
    $2 for SSN+DOB+DL
    $5 for High credit fullz 700+
    (bulk order negotiable)
    *Payment in all crypto currencies will be accepted

    ->You can buy few for testing
    ->Invalid or wrong info will be replaced
    ->Serious buyers needed for long term

    PLEASE DON'T ASK ANYTHING FOR FREE

    TOOLS & TUTORIALS AVAILABLE FOR SPAMMING, HACKING & CARDING

    (Carding, spamming, hacking, scam page, Cash outs, dumps cash outs)

    Ethical Hacking Tools & Tutorials
    Kali linux
    Facebook & Google hacking
    SQL Injector
    Bitcoin flasher
    Keylogger & Keystroke Logger
    Premium Accounts (Netflix, coinbase, FedEx, Pornhub, etc)
    Paypal Logins
    Bitcoin Cracker
    SMTP Linux Root
    DUMPS with pins track 1 and 2
    Smtp's, Safe Socks, rdp's, VPN, Viruses
    Cpanel
    Php mailer
    Server I.P's & Proxies
    HQ Emails Combo

    *If you need a valid vendor it's very prime chance, you'll never be disappointed*

    CONTACT 24/7
    Telegram> @killhacks
    ICQ> 752822040

    ReplyDelete
  5. Nice blog sir, it is very informative blog post post.

    Now you can also easy to manage theirs document. PDF Signer Software

    ReplyDelete
  6. QUALITY SSN DOB DL HIGH CREDIT SCORES Leads
    Tutorials & E-Books For Ethical Hacking
    Tools For Everything You Need

    I'm On Telegram = @killhacks & I C Q = 752822040

    Stuff for Learning purpose
    (Spamming, Ethical Hacking, LINUX, Programming, etc. )

    Deals in all kind of Tools, Tutorials, E-books, Leads/Fullz/Pros
    Availability 24/7
    FASTEST DELIVERY

    Build Your Own Business with proper guide
    Always glad to serve

    GOOD LUCK
    Here I'm:
    I C Q = 752822040
    Tele-gram = @killhacks

    ReplyDelete

  7. It is very useful and knowledgeable. Therefore, I would like to thank you for the efforts you have made in writing this article.

    WS-C3650-24PS-E
    WS-C3650-24TD-L
    WS-C3650-24PD-S

    ReplyDelete
  8. NAME|SSN|DOB|DL|ADDRESS|EMAIL|PHONENUMBER|WORKHISTORY|ACCOUNTDETAILS
    Fresh Fullz & Fresh Spammed

    CCNUMBER|MM|YYYY|CVV|NAME|SSN|DOB|ADDRESS|EMAIL|PHONENUMBER
    CC fullz with CVV

    High Credit Scores Pros 700+
    EIN Business Fullz

    ICQ 752822040
    WA/TG +92 317 272 1122
    TG @leadsupplier
    Skype/Wickr @peeterhacks

    Spamming All fresh Tools & Tutorials
    Hacking Stuff
    Carding Methods & Cashout Methods
    Loan Methods
    SMTP's/RDP's/SHELLS/Brutes/C-panels
    Key-Loggers/Kali-Linux Full Package
    Courses for D**K/D**P Web
    SQLi Injector
    Combos/I.P's/Proxies
    Logs/HQ Emails

    ICQ/TG @killhacks
    WA +92 317 272 1122
    exploit.tools4u at gmail dot com

    ReplyDelete
  9. Hey, that's not the end of the challenge. The flag is actually hexencoded. Decoding it gives a binary file and I am trying hard to solve the binary file puzzle. If you think that the flag is the end of ctf then how to get the point of solving that? Do you got the point?

    ReplyDelete
  10. Hey Guys!!
    I found a genuine man on YouTube with the channel name "toolz store". He's selling 100% working spamming tools like SMTP, cpanel's, RDP and many more best spamming tools. I tried one of its tools and its gave me working and accurate result. I must say you should try their tools once.
    I have their contacts;
    His TeLeGraM = @cpanelmaster
    His I.c.Q = @cpanelmaster
    He also have a site named = https://toolz.store

    ReplyDelete
  11. Buy Fullz, Leads, Database
    Get Highly Exclusive, Freshly Spammed, Legit Leads
    Verified and Updated 2025

    Stuff Listed Below
    ============================
    +USA SSN DL front back with Selfie
    +Passport Photos
    +USA SSN INFO
    +Canada SIN
    +UK NIN
    +UK Fullz
    +USA Fullz
    +Canada Fullz
    +Business owner leads
    +Payday loan leads
    +Sweepstakes & gambling Leads
    +Casinos database
    +Home owners leads
    +Employee leads
    +USA Bank leads
    +Personal detail info
    +Email combos
    +Mortgage leads
    +Crypto database
    +Forex database
    +Stock Market Trader leads
    +Education Leads
    +Auto insurance Leads
    +Phone Number & Email leads
    and many other stuff

    All info provided are valid, fresh and not sold before
    Replacement for any wrong and invalid info
    You can buy a few for testing
    Stuff will be delivered after payment proof
    Payment only in crypto
    Available 24/7
    Contact us for the deals & discounts
    ==============================
    Whats App : +1..605..846..1870
    TG : @ Lead_pro20
    Email : datastreemer (at the rate) gmail (dot) com
    Contact us and make good money

    ReplyDelete
  12. This comment has been removed by the author.

    ReplyDelete

  13. BIG DEALS $$$$

    USA DATABASE-FULLZ-LEADS ( updated upto 2025 - All info is verified & guaranteed )
    ***********************************************************************************
    We'Offering SSN DL USA/UK/CA/AUS/EU/ASIAN/INTER CC/CVV FULLZ INFO, Valid Non-VBV Bin Fullz CCV...
    We guarantee that Our INFOS 100% firsthand and extremely fresh because we update them weekly and monthly.
    Fresh stuff available here only
    BIG discount on bulk
    Invalid & useless info will be replaced

    #USA--#UK--#CANADA STUFF
    *************************
    -SSN DOB DL Address
    -SSN DOB DL Address Phone email
    -Real DL|ID Front Back with Selfie & SSN
    -High Credit scores Pros 700+
    -Young Age fullz 2010 & above
    -Old Age fullz 1960 & below
    -Passport Photos with Selfie
    -Fresh Sweepstakes & Payday Leads
    -KYC & Tax Return Stuff
    -W2 Forms with DL front Back
    -Cars Database with Registration Numbers
    -Work Travel Visa with SSN Photos
    -CC with CVV with billing address
    -Dumps with Pin Track 101 & 202
    -Business EiN Pros FullZ
    -UK Real DL Scan Front back with Selfie
    -UK Passport Photos with Selfie
    -Bulk UK Fullz
    -UK young & Old age Fullz
    -UK CC with CVV fullz
    -High Credit Scores UK fullz Pros
    -UK phone numbers & emails Leads

    TOOLS:
    Spamming Tools & tutorials
    Web-mailers -Bulk Email Sender
    Scampage tools and tutorials
    Carding Tools & Tutorials
    *******************************
    Payment Method
    * USDT * ETH * BTC* PAYPAL
    ***************************

    #FULLZ #SINFULLZ#REALDLSCAN #YoungAgeFullz #Fullzseller #CANADAFULLZ
    #FULLZCANADA #SellerSINDOB #ShopSINDOB#BusinessFullzCanada #CanadaPros
    #CanadaLeads#HighCSPRos #HighCreditFullz #Fullzseller #UKFULLZ #FULLZUK

    "Let's explore opportunities for a mutually beneficial, long-term partnership.

    *********************************
    Contact us :
    Telegram: @Albertz101
    Gmail: albertartemis6@gmail.com

    **********************************

    ReplyDelete