Layment Portal
Original Writeup on seall.dev
When connecting to the instance, we are given this:
$ nc chals.secedu.site 5005
New session started
LOGIN >
Thinking of some usernames from earlier, I think of Layton! We try:
layton
Layton
laypay
lpayden
laytonpayden
layton_payden
LaytonPayden
LPayden
But, its LAYTON that opens the puzzle, greatโฆ
$ nc chals.secedu.site 5005
New session started
LOGIN > LAYTON
Welcome. You may "add" hours to your worksheet here
We can add hours, ok!
> add
You have added an hour. You are now on 4 hours.
If we keep entering add we hit the following: Too many hours entered (35 is the max). Resetting to zero.
OK, letโs open two instances and try to exploit a potential race-condition, we work it up to 35 and then enter two addโs:
> add
You have added an hour. You are now on 37 hours.
SECEDU{st0l3n_funds_h3r3}
Flag: SECEDU{st0l3n_funds_h3r3}
Related Writeups
Brick House
I was going through some old tapes from the '80s and came across a strange recording on one labeled "Basic Programs #1." ...
Don't Touch My Fone
Looks like someone's dialing a phone number, see if you can figure out what it is! The flag format is the decoded phone ...
Look Long and Prosper
In this challenge, youโll need to uncover a hidden secret, but first, you must find the key. The key is hidden in plain ...