hardwareProeasy-medium
Утёнок в тумане (Duckling in the Fog)
duckerz
Task: MQTT broker with anonymous access but ACL-restricted topics; hints in announcements reveal username and secret topic path. Solution: Enumerate topics anonymously, extract username from hints, brute-force password, authenticate to access retained message with flag.
$ ls tags/ techniques/
mqtt_wildcard_enumerationmqtt_acl_analysismqtt_password_bruteforcemqtt_retained_message_extraction
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [hardware][Pro]Умный офис (Smart Office)— duckerz
- [web][Pro]Космический терминал (Cosmic Terminal)— duckerz
- [stego][Pro]Фотокарточки (Photo Cards)— duckerz
- [reverse][Pro]129 (Утка)— duckerz
- [forensics][Pro]Мим— duckerz