Profile

Shadow


CloudSek CTF round-2

By Sh1dO0w December 16, 2025 Posted in CTF

Hey, I’m Sh1d00w

def sh1d00w():
    """CTF Player / Penetration tester / Red Teamer"""
    Stats = {
        "ctf Rank": "60",
        "ctf name": "sh1d00w",
        "ctf round": "2"
    }
    for k, v in Stats.items():
        print(f"{k:>9}: {v}")

sh1d00w()

I am back with the round 2 of CloudSekCtf

Challenge 1: Boot Sequence

Category: Web

Description: The Orbital Boot Sequence has stalled mid-launch. Can you restart the relay and seize control before the fleet drifts off-course? Submit the root flag for the win.

Challenge Instance : http://15.206.47.5:8443/

DNS diagram
#### Initial Recon

First i map the site and Observe:

DNS diagram
DNS diagram
DNS diagram

Step 1 : How i gain admin privileges

{
"alg": "HS256",
"typ": "JWT"
}
{
  "sub": "flightoperator",
  "role": "operator",
  "iat": 1765687759,
  "exp": 1765688959
}
┌──(kali㉿kali)-[~]
└─$ nano key.txt         

┌──(kali㉿kali)-[~]
└─$ john key.txt --format=HMAC-SHA256 --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (HMAC-SHA256 [password is key, SHA256 256/256 AVX2 8x])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
butterfly        (?)     
1g 0:00:00:00 DONE (2025-12-14 01:10) 50.00g/s 409600p/s 409600c/s 409600C/s 123456..whitetiger
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
DNS diagram
DNS diagram
DNS diagram

Step 2: Checksum Reversal (Client-Side Trust Issue)

Step 3: Identifying Server-Side Template Injection (SSTI)

DNS diagram
DNS diagram
DNS diagram

The CTF was really fun!
The challenge were simple but a bit tricky, and the flow felt smooth.
Thank you for organizing such a wonderful CTF!


You Might Also Like