Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Fetch the Flag CTF 2022 writeup: Not So Smart Fridge

Blog post from Snyk

Post Details
Company
Date Published
Author
Antonio Gomes
Word Count
1,026
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

The challenge "Not So Smart Fridge" from Fetch the Flag CTF 2022 starts with a warm welcome and a description of the Smart Fridge Ultra SFU-3000, but its actual capabilities are disappointing. The fridge's firmware is pistache/0.0.3.20220107, which has a known path traversal vulnerability. By exploiting this vulnerability, the flag can be accessed through accessing a specific folder path on the fridge's web application, which points to the currently running process, allowing the download of the pistache binary. The binary is then reverse engineered using Ghidra, and an analysis of the decompiled code reveals that the flag is hidden in a method named checkFlag, with a specific length constraint. By analyzing the method's logic and constraints, the flag can be reconstructed.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.