251109_RootCipherCTF learning record

In the full-stack CTF player program, this article will be continuously updated with recreated learning content

Contact Authors

Discord

Attachments

Release 251109_RootCipherCTF · cvestone/cvestone.github.io · GitHub

EventInfo

image.png

ScoreBoard

My team 0xfun’s rank in this event - top 2:
image.png

crypto

JustTh!s

Desc

Just solve this.

Flag Format: RootCipher{xxxx}

Key Points:


misc

TokyoDrift - User&root

Desc

Tokyo holds hidden secrets buried deep within the panel. Only a true drifter can navigate through the twists and turns to uncover what lies beneath.

You need to perform deeper post-enumeration; linpeas may help you.

Challenge Link: https://thundercipher.tech/room/62

Author: p4nth3r
Level: Medium

Description: The streets of Tokyo never sleep — and neither does this web app.
Start Machine Download Certificate

  • What is the user flag?
  • What is the root flag?

Key Points:


steganography

Nature

Desc

The environment is not just our home; it’s the source of life, and it’s our responsibility to protect it from harm.

Flag Format: RootCipher{xxxx}

Key Points:


Truth

Desc

Truth beyond the image.

Flag Format: RootCipher{xxxx}

Key Points:


Analyse this image, we find something special:

o42>6C2]42F89ED
image.png
decoded from ROT47: @camera.caughts, obviously it looks like an username, by osint way,we get it:
https://www.instagram.com/camera.caughts/

We can also see the metadata Spidey, maybe its a key from somewhere.

forensics

Last Character Standing(√)

Desc

ChatGPT accidentally leaked a flag—but it clipped off the final character. You’re given the almost-complete flag (every character except the last one).

https://chatgpt.com/share/69102a64-f3e0-8004-bb9c-0078aeae0ca

Key Points: GPT osint, markdown syntax


At the first time i tried to use some osint ways, like “Wayback Machine”, even though the old chatgpt shared conversation , maybe will be recorded in it, but didnt find anything.

Finally teammates said we should notice the Desc, the last character is wrong, so just add 1 in the end, because the Desc was edited by markdown syntax,as follows:

1
[https://chatgpt.com/share/69102a64-f3e0-8004-bb9c-0078aeae0ca](https://chatgpt.com/share/69102a64-f3e0-8004-bb9c-0078aeae0ca)

try to use some characters which looks like ), and 1 is suitable, after modified, search it:
https://chatgpt.com/share/69102a64-f3e0-8004-bb9c-0078aeae0ca1:
image.png
RootCipher{FLag_Leaked_In_ChatGpt}
Damn it, it looks like a puzzled chall…i dont like, lmao.

Reveal

Desc

Why can’t I open this file?

Flag Format: RootCipher{xxxx}

Key Points:


Mesmerize

Desc

My phone has been buzzing with a lot of pings from messages and notifications all morning.

Flag Format: RootCipher{xxxx}

Key Points:


osint

The Wheel of Fate

Desc

A moment from the Kurukshetra battlefield has been captured in this image. Some details speak loudly, while others stay quiet, waiting for the observant. What you seek is not just in scripture, but in the ground where the scripture unfolded. Follow what is hidden.

Flag Format: RootCipher{xxxx}

Key Points:


hardware

Nano

Desc

Arduino nano

Flag Format: RootCipher{xxxx}

Key Points:


Firm-Image

Desc

I think there’s something wrong with this firmware; I can’t flash it onto my router.

Flag Format: RootCipher{xxxx}

Key Points:


Communication

Desc

We have intercepted communication between the devices.

Flag Format: RootCipher{xxxx}

Key Points: