Scavenger Hung (picoCTF 39)

Challenge Author: MADSTACKS

Category: Web Exploitation

Difficulty: Easy

Description

There is some interesting information hidden around this site. Can you find it?

Process / Notes

  1. Open site
  2. Two tabs - how and what
  3. How = liking the website; what = html, css, JS were used to make the site
  4. Examine the source code
  5. First part of the flag in some <!-> text toward the bottom
  6. Remembering to check the embedded css and JS, will check those at the top
  7. Another part of the flag in the css
  8. Seemingly nothing of note in the JS
  9. Inspector to see about running the JS
  10. No wait, the clue is “how can I keep google from indexing my website?” - the robots.txt!
  11. Adding ‘/robots.txt’ to the url got me the third part of the flag
  12. Next hint is that it’s an apache server
  13. Reading how to interact with an apache server and nothing’s coming of it
  14. At 18:40 looking up what to do next in the challenge
  15. add ‘/.htaccess’ to the url! Definitely wouldn’t have figured that out by chance
  16. Next clue is about making websites on their mac because they can store a lot of information
  17. Checking the storage in the inspector
  18. Nothing there
  19. From the walk-through, it’s actually under another url change to ‘/.DS_Store’
  20. That contained the last part of the flag

22 minutes 23 seconds to complete

Hints

Core Lessons

  1. Understand how to access the page source and the embedded css and JS
  2. Understand various endings to urls including /robots.txt, /.htaccess, and /.DS_Store