hardwareeasy-medium
Утёнок в тумане (Duckling in the Fog)
duckerz
Task: MQTT broker with anonymous access but ACL-restricted topics; hints in announcements reveal username and secret topic path. Solution: Enumerate topics anonymously, extract username from hints, brute-force password, authenticate to access retained message with flag.
$ ls tags/ techniques/
mqtt_wildcard_enumerationmqtt_acl_analysismqtt_password_bruteforcemqtt_retained_message_extraction
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]