cURLing #
To get silver the commands are fairly simple
curl curlingfun:8080
curl -k https://curlingfun:9090
curl -k https://curlingfun:9090 -d 'skip=alabaster'
curl -k https://curlingfun:9090 -H 'Cookie: end=3'
curl -k https://curlingfun:9090 -I
curl -k https://curlingfun:9090 -H 'Stone: Granite'
curl -k https://curlingfun:9090/../../etc/hacks --path-as-is
And i got the silver medal
But how do we get the gold
curl -k -X POST https://curlingfun:9090 -d 'skip=bow' -H 'Cookie: end=10' -H 'Hack: 12ft'
curl -k https://curlingfun:9090/../../etc/button --path-as-is
curl -k -L https://curlingfun:9090/GoodSportsmanship
Frosty Keypad #
We talk to morel and he tells us about a book we need to find
I found the book over to the right
Yep it ends up spelling out S A N T A
Took me a while to figure out how to change santa into numbers and was tryning to use leetspeak and everything but its just old phone number typing
72682
im guessing this is the hint for gold
Found the uv light behind the boxes above the shredder
i think were meant to just brute force it ?
and when we input the silver password we get this
now how do i get a wordlist with all possible combos of numbers
so i just googled
I realised that i need combos like 22222 and i have “2,2,2,2,2” so to fix this in nano i hit replace and replaced “,” with nothing
the password is 22786 lets put that in
Hardware #
Part 1
Morcel gave me “One Thousand Little Teeny Tiny Shredded Pieces of Paper” which when downloaded was a zip file called shreds.zip with loads of images looking like this
I was so confused on what to do until i noticed the hint
Now for the next part 2 we are inside the SLH ( santa’s little helper) machine and we need to grant acess to card 43 but we dont have the passcode so we need to find it