Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Fetch the Flag CTF 2022 writeup: Treasure Trove

Blog post from Snyk

Post Details
Company
Date Published
Author
Luke Watts
Word Count
572
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Fetch the Flag CTF 2022 Treasure Trove challenge involved reverse engineering and exploiting a swashbuckle.js endpoint to extract a license key from a website. The challenge required teams to use browser console commands to invoke the `validate` method on the `window` object, which returned an integer that was used to verify the license key. The code used a series of checks to validate the input characters and calculate their sum, before posting it to an API endpoint if the value matched 1800. Teams were able to solve this challenge without engaging with the obfuscator codebase, using browser console commands to bypass the encryption and extract the flag.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.