#general
1 messages ยท Page 8 of 1
up to the challenge author
is there an issue doing these on mac lol
which one
mac is the superior os so of course there would be no problems
^
๐ฎ
run a mac VM on windows
Hmm
rpisec op
I am so jelly at the first places lmao
No, you should probably not pp poopoo.
dang it
lol yeah
!coinflip @vale hamlet be jelly
Yes, you should absolutely @โEpifor#9116 be jelly.
lol
!coinflip pp,poopo
Yes, you should absolutely pp,poopo.
hm
I thought PFS stood for planetary file system
pwning for soju
๐
Almost the end of day1 and I still have only 1 point... Never felt that bad...
Try the baby challenges, like sice sice baby
ah yes, sice sice baby, perfect for beginners ๐
try babier csp
dm me if u want a hint or some feedback on what steps you're trying
I spent hours trying all the xss payload I could think of. I think I need a break to come to it with a fresher mind
Thanks I'll look at it after the break
don't be so hard on yourself mate
it's alright you can do this
live ctfs take time to do anyway
best of luck!
@covert berry I'm in the same boat, first ctf btw. We got this!
That's not the first one for me. But that's the first time I fail that hard :)
But I'm sure I'll find something before the end, and learn a lot reading the writeups
When you're at the bottom, you can only go up
I start to be so so curious about the dice is you thing hahaha
that's the spirit champ.
idk how to troubleshoot ghidra ๐ฆ
not unless a black hole opens on the opposite polar and you get sucked down through earths core :/
just sayin, it always can be worse
!coinflip funny
Yes, you should absolutely funny.
!coinflip 
No, you should probably not <:lemonthink:805962564991057920>.
!coinflip @everyone
Yes, you should absolutely @โeveryone.
python
doing babymix atm and im stuck lol
youre late to the party champ
i tried everything
!fleg
what the fuck is this command
try it in #flag
i did lol
did{gong}
can anyone give me a hint on babymix
what the fuck is this
Capture The Flag, CTF teams, CTF ratings, CTF archive, CTF writeups
challenge authors might post the intended solution on their blogs, too
Can someone publish a writeup for Missing Flavortext now ?
no, that's strictly against the rules ๐ฆ
babymix seems like a pain. im struggling too.
thank you
Ah damn it, didn't see that coming...
yeah i know ive been at it for a while now
Would do ctf but too dumb :) and.... donโt wanna break my skull
breaking my skull is really relatable
other challenges are going to be published? (which category if any?)
any additional challenges will be released in about 3 hours and 20 minutes
thx
misc ๐
o also misc
oh wait

survey
:^)
also don't do this :^)
wtf ethan don't leak the solution
now they'll know that
if you try a random amount of underscores
in a random amount of paths
with dots randomly strewn about
they'll get the flag
obviously
wtf does libc like dynamically update the copyright year when you run it or something
tf is this
its 2021 though ๐ค
nvm i am stupid i forgot the the loader tries to load from library path
./libc.so.6 was correct
๐
exp.cc ๐
90 seconds
reminder: don't be like this ๐
you're causing our monitoring system to ping us for the traffic and it's getting kinda annoying
i get the feeling the ppl doing that aren't seeing your messages
me too ๐
ban
cant you just ip ban them
or work out their username/team name from the ip, and give them a stern talking to?
we haven't started ๐จing yet but probably will if it continues 
are u guys ready for more challs?
Sure, we already completed like ... three!
now that sice sice baby has been blooded, get ready for sice sice adult
true
smh poor infrastructure
โญ

challs are up now ๐
24hrs is halfway?
yep
sick
Admins, I think my ip has been blocked, can someone help me?
I swear I will stop fuzzing! ๐
dm with ip
lmao
lmao
lmao
fool, you broke the chain
hm?
whoever solves adult csp first gets 100000000 pandaman ยฎ๏ธ pandapoints โข๏ธ
did someone put one of those discord cache windows defender triggering things in here
Rob should offer a 3d printed trophy for first blooder of adult csp
@lean chasm lol
very hard to moderate vc
,snipe
o that means i owe pernicious 3 virtual cookies
not if i steal those cookies from u
better watch out i'm bringing the grandma that bakes those cookies
; p
will challenge authors be posting solutions/writeups when the ctf is over?
up to authors
thanks
also .
.
this is a hacking server
:blobskid:
if you are not ready for hacking we suggest you do the leave
hacking more like "let's set off everyone's AV just to piss them off"
who was that
nice one
:thonk:
discord critical vuln ๐ฑ ๐ฑ ๐ฑ
@sage musk ik LMFAO that's the joke 
wao


what do u think ab cpanel?
zer0pts in first again ๐
rust wasm :dab:
xxddd
hi
dang who pulled the skid move
if anyone wants an explanation of why that skid move worked,
https://twitter.com/0x0elliot/status/1347877064360136705?s=20
just found out that if put mildly malicious looking code to the tail of an image and send it over discord, it will get cached and make windows defender panic and give a false alarm and why is this so fucking cool?
yeah it's ok, it's not really skid even
it's just like
a bit annoying
ยฏ_(ใ)_/ยฏ
i mean, everything is really working as intended
not if you have linux ๐
"i have linux, it's impossible for me to get a virus"
but that's not a virus sir
that's just a vbs script appended to the tail of an image which doesn't execute at all
yeah i know
just triggers your windows defender. it's harmless.
yeah i know mate
yez
๐คก
but i'm saying that it's good protocol in general to keep malicious code off your main computer
indeed
someone put a miner on my jupyter instance, but they were slightly more clever
they made a hidden dir in /tmp
and named the file "python"
rather than just fucking downloading xmrig plonk right in the middle of the home dir
i am not familiar with jupyter
come back? lol
yeah
scripts
scrape shodan
ill delete your ip form the list, but this is what it looks like
mhm
some guy connected from an AWS instance, and the AWS instance also hosted his rรฉsumรฉ
opsec 100
lol why would you do that
also i know most people are perfectly capable of absolutely destroying my measly AWS instance, even without perms
please do not do so
bitcoinz
i lack context because i haven't visited that link, but poggers on you champ
lmao
@ whoever was asking for cookies
thanks kind sir
alright cya need to prep for gunnhacks, wish me luck setting up picoctf platform
you hosting a CTF?
uh
why not just use CTFd? it's so much simpler?
picoctf shell ๐คค
i kind of asked for this didn't i 
lol
wait so picoCTF gives players a shell too that you want to use in your CTFs right
that's so cool
those carnegie mellon nerds
ok but you kinda need infinity money to run picoctf platform
it's a like less than 24 hr ctf
shell server mad expensive
wait
because its always very laggy
we'll have netcat obviously as well
and that one ctf has also had the shell server result in unintended cheese 
gunnhacks is a "mini ctf" aka it's for people who mainly
- don't really know a programming language
- don't have a lincox installation or vm
- will mald if they need to spend more than half an hour on a challenge
yes it did
lol yea

that's pretty nice
yea uh
yeah, all flags leeked
that's so cool
ppl are dumb
needed to ALL be changed
12h downtime
:pepega:
oh yeah all the flags got leeked
:pepega:
there is: lfi rce via /tmp in php
ppl sticking flags in /tmp
also the mysql one
tldr shell server = /tmp abuse
12h downtime

team still maxes in 1.5 days
ok rob
tooting my own horn a little
can I toot ur horn
wait
reminds me of that one time this one french CTF team clapped a CTF
"ctfd is reliable" 
until ctfd dead
rctf doesn't have individual accounts
minute 2
what are the bad things you guys noticed about it?
uh
people dont know how to host it
lol
in the first 5 min
hm
our rctf instance is massively underutilized
I've actually used both ctfd and rctf for my club in the past
google is telling us to downsize it :^)
I would say they are pretty equal in configuration complexity
ig editing yaml isn't for everyone
I used to run our club's ctf platform on the school's shared hosting service
ctfd was actually unusably slow
google forms ๐ค
yea rctf is severely lacking in the admin ui department
we're working on itโข๏ธ
we have the user members thing that you saw in redpwnctf
yeah i have noticed how CTFd is slow. but while testing it never died yet
yea and this
I guess the whole concept of team limit relies on honour system anyway
when there's a ctfd the team is always
- redpwn
- BrownieInMotion
lol
why dont you just use your own account
is type a separate password to join the team
really that difficult
less friction for ppl to hop onto the ctf
if you can just copy-paste creds from a channel
instead of going through registration flow
there doesnt need to be less friction

idt you understand how 50+ member ctf teams work
main issue w/ ctfd comes when hosting big events
๐
redpwn exposed!!!??!???!/1??!!11
it's extremely difficult to make sure everything works with large number of requests
redpwn more like kraftheinzberkshirehathawayconglomerate
๐ You do not have the required permissions to run this command
rip
bean is where you bean someone
lol
our legendary logo ;-;

@stone nacelle qpwoeirut are you going to learn pwn for picoctf
๐ฎ
lol
no im not
then we dont need to harvest another pwn person

how is gunnhacks goiing
i will not
lemonthink sticker
lol
as we don't want malding
@stone nacelle did you already make a smol e
smh this is a public server
although anybody who would do dicectf is already too advanced
presumably
tfw literally 
lmao
unless we were to buy krusty burgers and disguise them as our own cooking ๐ค
delightfully devilish
chop0
tfw I thought this was a bug
i am so confused
then I looked at the axis scale
i just saw something in watermark as a service

but replace krusty burgers with dicectf, and cooking with ctf challenges
๐
tldr don't bruteforce please our computers get unhappy and when our computers get unhappy we get unhappy 
no sir i saw something else
mostly from the uh 100+GB of logs we've collected
lol

default nginx log 
who is the admin for watermark as a service
yeah
dm me
dang sniped
i did a challenge yesterday, but today have been working on ghunnhax
chalenges
fizzbuzz helo
chop0 isn't helping his teammates smh
i think it was intended but i was taken aback because of the striking familiarity with something

those events sort of feel
sometimes lmao
yeah
hmm at redpwn we were floating around the idea of writing some shell server software btw
with fully isolated user shells running in docker
mm
running on one big dedi box bc roaming home directories is hard 
lmao
nsjail is great for fresh sandbox per conn but
shell server needs persistent environments per user
:/
we could just run rob's pwn docker as the image btw
rob had wanted to put this in the web category btw
"it has a website so it's web"
too bad gink axed that idea
good ginky
gating adult csp behind babier csp smh
tfw no challenge dependencies in rctf
tbh that's probably something we should do eventually
along with a tag system
anyone down for copying justctf's scoreboard
why is there no functioning website dang it
admin for waas
dm me
Have all challs been released?
yes
we will be releasing a survey tho
all challs which affect ranking have been released already
you have to solve level 5 properly to get the flag :^)
That level is a nightmare ๐
you could brute force it, but you'd have to try at least 3 different combinations of the symbols
for legal reasons I must say that I am joking and also have not solved it
๐
Hi! Admin for babyrop?
๐
aadmin for watermark as a service? ๐ค
dm
Where do I go to learn how to complete these challenges as I have been unable to solve any . Of these I code Java and c
hello
Hello
Hello
where are you from ๏ผ
will the challenges still be accessible after the end of the ctf?
picoCTF or overthewire are good places to start i think
@amber wind UHC when
never

any admin for babymix?
mge me again ๐
I uninstalled tf2 cause it's way too chonky
josh's new pfp makes me very uncomfortable
same
yes later today silly
ew csa
almost at 1k
wtf
noleek
caboose?
kunai lets you pull risky stabs
TRUE
gink i just sent a lot of ss
also hi gink how are you
also it makes it way easier to surf explosives
but

haskell moment
aplet 
!clean until 808009973036089345
โ Deleted 7 messages!

dwai
im worrying

!clean until 808012258713403402
โ Deleted 13 messages!
wtmooooooooo
pure gink
we live in a society
๐๏ธ โ๏ธ
๐ฐ
the funniest thing is
wait no I'll say it in the pwn channel
:c
yooo mslc op
@neon matrix prize for blood on survey?
you get free gink points
is @harsh abyss 's love and respect still on the table
that's for him to decide
no prizes
๐
I did not have enough time to take part of the CTF but if someone post ร writeup (after the end aswell) I am interested ( and Good Luck for THE
end of the CTF !)
admin for dice-is-you?
@loud vessel
potential prize for first one to blood survey
Reallly going for those in depth, well thought out survey responses there ๐
survey speedrun
don't worry, it doesn't affect tiebreaker or anything
the challenge exists purely so that more people see it
Where is my one point for the survey?
And btw, you forgot to include the rating for the sanity check challenge, which was excellent
In challenge rev/Guess the Vuln I am getting error: ./handler: 2: ./handler: Syntax error: newline unexpected (expecting ")") while opening http://localhost:31337/
Can some tell me how they solved the JavaScript ones please when the contest is over
any idea, If I am doing something wrong?
dm @amber wind
and writeups will hopefully be posted after the competition
just wanted to know if I am on right path?
are you publishing official writeups after the ctf ends?
if you're referring to a specific challenge, dm the author about it
depends on the challenge. some authors will be publishing official writeup/solution
thanks got it working
will there be a writeup channel?
after ctf ends yes
look at the solves count
Can someone post a url for me into the writeup channel when the ctf is over?
I will be asleep by then
(someone who has completed babier csp preferably)
you can just post it later there's no rush
lmfao
Wish I got a chance to look at more of them
welp is adult csp gonna get solved 
you know if we extended the ctf by 24 hours that means we can release another batch of challenges
i FINALLY completed babier
pb are obviously hoarding it
you can always do them afterwards as long as our infra people aren't mean ๐
ok xnu hacker

gnu hurd pwn when
windows kernel when 
ios kernel when 
just leave challs up until you have -200 balance in your account
if we take down admin bots it can probably run for a long time
dont lemonthink me
this is absolutely not related to personal experiences
idk I haven't seen cloud functions on our billing report
i forgot to shut off the instances @unique sail
ginkoid went from admeme bot at $30/day to ???/day
honest mistake
ginkoid gets kickbacks after shilling for google for so long

rgbctf platform ๐ โ
pepeg

the commonwealth
bad
vexctf is gnu hurd except ctf platform
:(

rgbctf platform is gnu hurd except ctf platform
@ pepsipu





now i just get dependabot requests

somehow bAse has adopted rgbctf2, which was probably a mistake, and he should probably remove it from his github
since its java EE
or something
somehow it was transferre

please dont make rgbctf 2
is this
@unique sail
what reunion
chop0 and you
what
what
whyyyyy
no ive stayed in contact with chop this whole time


most epic malding
if rgb2 then i'll have to do infra so aaza

was worth the two 1 votes on ctftime given by penguin
lmao



redpwn writeup for one of the challs:
"SSTV."
water under the bridge
we did writeups for rgbctf?
I remember writing up jisho
hahahahahahaha


thinking abt it
who can find the hackmd
i would make rgbctf2
it was so funny
no
yes
admeme bot is entirely free
please dont
please no
but it was pretty epic
next time you are gonna hide the flag in an emote you add halfway during the ctf
we're going to hide the flag on my desktop
why do you think I added 
you found it
rob doesn't know because i wrote up soda lol
thonk
Using the not-great documentation of the nearly-featureless LaserLang langauge
I was hurt by this :sadtownloaf:
tfw
#This is the end goal of the operations. This was not actually included in the shared object with the encryption function.
#There is no knowing what these numbers actually meant, but we assumed it was the desired output if we were able
#to input the flag into the provided program. However, we could not even do that, as no executable was provided.
ok it's owner write only now
except maybe pepsipus
didn't rob do soda pop bop
you were having way too much fun with these for them to just be "for completion only"
dunno i didn't rly feel like doing guess
almost as bad as the recent shadowctf

also smh if you're gonna have algo at least make it not "haha copy/paste dijkstra/floodfill go brrr"
the worst part about rgb was that I never got the jam
imagine doing algo
i did it afterwards
i proposed the cheese solution tho
since i had just finished studysim
and it was similar


what squares were you missing
Why is the admin bot so expensive?
you cant have blind pwn if you dont have pwn

aaa i was so against these algo challs but at that point it was already such a fucking mess i just gave up
good plan
fill it out
This is amazing ๐

we definetily get those 5 bonus points XD
fake flags :pepega:
anyway let me in the winrars when sadtownloaf
you did
infra did not get hacked, but people decided to ddos it >:( and it was like 3 AM
๐ค
so i just threw more instances behind the load balancer
willwam845 should be admin next year
:blobreach:
nah im good
and then i accidentally deleted the main instance for ctfx bc i didnt label it
but then
digitalocean
was retardd
stay tuned in 40 daysโข๏ธ
alternatively ip ban ppl ๐
bro that was the worst afternoon of my life
was 3 AM, someone was using some booter and i honestly couldn't be bothered
imagine not having
no one else knew how to use DO
i was so fucking tired, and EVERY NIGHT
lol the blur
is this rgbctf?
yeah

yeah
yea hi
did you include my "alright cunts lets go"
in the song
in the end
or just the ai-generated inspirational quote
no i did not put that lmao
you know
the end end end product of that
was
A little lo-fi to keep you warm and cosy during these cold winter months... :) Headphones definitely recommended for maximum ambience. This is my first time trying to make lo-fi, but I think it turned out pretty well...
Background by Amitai Angor AA VFX: https://www.youtube.com/dvdangor2011
i'm going to call this the one good thing that came out of rgbctf

Dice CTF more like nice CTF
called it
perfectly guessed
all challenges solved ๐
op
literally called it 
pb literally hoarding
pee bee
now rob doesn't need to be sad :)
now we finally know everything is solvable
lmao
problem can be solved and not solvable
yeah they just guessed the flag ๐
truee
dice{gang}
no leek plox
so how is everyone doing?
tired
do not
turn to the pwn side
you will have to deal with poortho and his notorious glibc pwns
^
that sounds scary
stay at the misc side
poortho put me out of a job ๐
Solve pyjails and guess flags
stick to kmh and his pyjails
yeah maybe crypto in not that bad in the end
Would it be possible to train an AI to guess flags
Give it a flag and a challenge name
And an author
false
create an AI that tries all iacr paper links
create an AI that uses GPT-3 to write its own IACR paper
backdoor the next amazing crypto challengeโข๏ธ
Maybe this would be useful for crypto
Given a paper, write code that does what is spoken about in the paper
yours sound better
crypto papers without implementation should be banned
@amber wind does escortum do a good job of screenshots
idk I never used it
hm i want a screen recorder with no ui
obs!
terminal recorder
asciinema?
i want maim but for recordings
draw a box / click a region to start
keybind to stop
quicktime player can do that
blinkenlights
quicktime player is bloated though
wtf
wtf
no nsfw pls
wtf
i cant wait to find out how to solve survey
Same
Reminder delivery:
To: @glossy marsh
Scheduled: Thu Feb 4 23:47:21 2021 (3 days ago)
Jump Link: #general message
Reminder:```
complain about dicectf on ctftime
wtmoo




