~ / writeups / firstcontact

First Contact

Hack The Box · Easy · Satellite

Easy Satellite Challenge

Challenge Overview

Field Value
Name First Contact
Category Satellite (orbital mechanics / scripting)
Difficulty Easy (challenge 1 of 9 in the HTB Satellite Exploitation Track)
Event HTB Satellite Exploitation Track
Connection nc 154.57.164.69 32055
Objective Compute a satellite's next visibility window from its TLE + ground-station coordinates

Attack surface summary: An interactive netcat service that, each round, prints a satellite's two-line element (TLE) set and a ground station's (Lat,Long), then asks "When will it be visible next?". The correct answer is the next pass window (rise → set) where the satellite's elevation exceeds a threshold (30°) over the station. Answer every round correctly and the service prints the flag.

Flag

Flag Value
First Contact [REDACTED]

Analysis

Initial reconnaissance of the service:

nc 154.57.164.69 32055
# ...prints a satellite TLE (two lines), a ground-station (Lat,Long), and...
# When will it be visible next?>

Doing this math by hand is impractical for multiple rounds, so the solve is automated:

  1. Parse the TLE and coordinates out of each prompt.
  2. Load them into Skyfield (EarthSatellite + Topos).
  3. Use find_events(..., altitude_degrees=30.0) to locate rise/set events over the next 24h.
  4. Format each rise→set pair as YYYY-MM-DDTHH:MM:SSZ windows and send them back.
  5. Loop with pwntools until the service dumps the flag.
pip install skyfield pwntools

Attack Chain

1. Recon the service

nc 154.57.164.69 32055
# -> noticed it asks "When will it be visible next?" and supplies a TLE + (Lat,Long)

2. Automate the satellite pass calculation

The solver (full script in solve.py) parses the TLE lines and coordinates with regex, then:

satellite     = EarthSatellite(line1, line2, f"SAT_{round_num}", ts)
ground_station = Topos(latitude_degrees=lat, longitude_degrees=lon)

t, events = satellite.find_events(ground_station, t0, t1, altitude_degrees=30.0)
# event == 0 -> satellite rises above 30°
# event == 2 -> satellite sets below 30°

Each rise/set pair is grouped into a "<rise> <set>" window and sent back:

2024-10-02T14:23:11Z 2024-10-02T14:28:44Z

3. Read the flag

After all rounds are answered, the connection stays open and the service prints the flag:

[REDACTED]

Techniques Demonstrated

  1. Interactive netcat service reconnaissance — manual nc to understand the challenge protocol.
  2. Automated protocol interaction — pwntools remote() loop that reads prompts and answers programmatically.
  3. Orbital mechanics / pass prediction — Skyfield (SGP4) to compute satellite visibility windows above a 30° elevation mask.
  4. TLE parsing — regex extraction of two-line element sets and ground-station coordinates.

Tools Used

nc (netcat), Python 3, pwntools, skyfield.

← all writeups