hardwareeasy-medium

Утёнок в тумане (Duckling in the Fog)

duckerz

Task: MQTT broker with anonymous access but ACL-restricted topics; hints in announcements reveal username and secret topic path. Solution: Enumerate topics anonymously, extract username from hints, brute-force password, authenticate to access retained message with flag.

$ ls tags/ techniques/
mqtt_wildcard_enumerationmqtt_acl_analysismqtt_password_bruteforcemqtt_retained_message_extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]