$ cat writeup.md…
$ cat writeup.md…
ringzer0ctf
Task: an SSH ticketing service authenticates a hex token with a SHA1(secret||token) secret-prefix MAC and only grants the flag to username=admin. Solution: SHA1 length-extension attack appending &username=admin so last-value-wins query parsing resolves to admin, brute-forcing the unknown secret length (13) to forge a valid signature without the secret.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar