- Solves: 6
You want to book a hotel?
nc 188.40.18.93 1234
- Solves: 5
Draw some nice images
- Solves: 6
1) Pwn cfy 2) nc 127.0.0.1 3314
- Solves: 3
We proudly present you our totally awesome and hip data scanning service: Fyltr
A demo is available at $ nc 188.40.18.88 1031
You can conveniently write your filters in code and because they are compiled, it's also blazingly fast! And since Fyltr is written in Erlang, nobody will be able to own our servers, keeping your data secure.
- Solves: 12
Where do you want to go (today)?
nc 188.40.18.71 1234
- Solves: 3
Enter the trilogy: pwn this phone. Please use only the qemu provided.
Remote instance requires proof of work: nc 188.40.18.78 1024
creds:
- mobile/mobile
- root/root (local image only)
Connect locally via telnet to localhost:10023 after qemu booted completely.
- Solves: 1
Root the phone.
Hint: Baseband processors do not have memory protections Note: You need to solve Nokia 1337 first.
- Solves: 15
Test your x86_64 shellcode here but dont escape the sandbox please...
nc 188.40.18.84 1234
- Solves: 2
To play it, connect to our server via:
socat -,raw,echo=0 TCP:188.40.18.92:2001
Have fun!
- Solves: 4
Sorting as a Service!
nc 188.40.18.75 1234
- Solves: 5
Say hello to 188.40.18.83:7872
Flag matches [0-9a-f]+
- Solves: 53
We implemented aes in hardware and saved a lot of memory. Feel free to use our online aes encryption service to secure your data.
nc 188.40.18.66 2786
- Solves: 21
I have seen the admin logging in with these credentials:
admin
Sup3r&sEc\_/re_p@$$w()rd
9ae684ca583214d33905000000000000fd635dded0bbb40e162da79fba55ae32
somehow, i cannot login... btw. what does otp mean?
- Solves: 72
In a world, where everybody and their mom rolls out their own crypto implemented PHP, Joe plays it safe with Standard Crypto.
http://188.40.18.87:5144/
- Solves: 38
Ever imagined compiled stack based perl?
It could look like this, but maybe this one is even worse, so we start with an easy one.
Try to find the flag in this binary, but don't forget to run
objdump -h bor_ey
- Solves: 5
-
Note: This is a last minute entry and we haven't broken this ourselves. Don't expect any support. You can probably spend lots of time on this and not get anywhere. The risk is yours, you have been warned.
- Solves: 1
Merkel is under surveillance. Merkel will receive confidential SMS once in a minute or so. Maybe the NSA left something useful.
Note: You need to solve Nokia 1337 first!
- Solves: 8
Hope you have enough time for this to finish flag calculation...
- Solves: 65
- Solves: 5
bindshell running on 188.40.18.81:1024
- Solves: 49
Seems like somebody got pwned http://188.40.18.67
- Solves: 6
Time to pwn back, look for the malware on the compromised host!
You must solve Rick first to be able to solve this challenge.
- Hints:
The goal is to retrieve credentials for C&C IRC channel from memory, do this by pwning the service on port 1337
Some people asked for the firewall rules on Roll:
*filter
:INPUT DROP [56:3360]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [997:167700]
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1234 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -m limit --limit 1/sec --limit-burst 1 -j ACCEPT
-A INPUT -p udp -j ACCEPT
-A INPUT -p icmp -j ACCEPT
COMMIT
Debug build with more or less useful output available at the location of the old binary
- Solves: 1
We scratched this file from a harddrive that fell from a Gnu. It may contain a secret... FILE
- Solves: 2
This is the circuit of a safe lock. Get the key to open it! http://188.40.18.86/safelock/
It's neither about webtronics nor ngspice. Disregard bugs in both.
If you want to write spice code directly, use something like this
cat test.cir | curl --data-binary '@-' http://188.40.18.86/safelock/contest_spice/spice.cgi
- Hints:
when you handbuild your SPICE code: keep in mind that the first line is special and should be a comment, otherwise it is ignored.
The web interface does fully work with Chrome. Use Firefox.
- Solves: 226
5CHAN? never heard of this image board, but they have exactly what we need, the picture we're looking for is not for public, so can you get it?
- Solves: 24
It's some devilish community public portal, we're pretty sure there's something else out there, a private portal maby, we'd like to know the secret behind it
- Solves: 86
Check out our cool webserver. It is really fast because it is implemented in C. For security we use the versatility of ruby.
Get the source at: /31c3ctf.aachen.ccc.de/uploads/http.tar.bz2
Some example sites hosted with our webserver:
- Solves: 11
These guys have ripped off our designs and using them in their web pages builder, we'd Haxx them, dont worry we'll give you decent points for it
- Solves: 101
PHP is nasty crappy sometimes, just pwn it