Challenge Overview
| Field | Value |
|---|---|
| Name | Flag Command |
| Category | Web |
| Difficulty | Very Easy |
| Event | Cyber Apocalypse 2024 |
| Type | Black-box web app — terminal-style "Dimensional Escape Quest" text adventure |
| Vulnerability | Sensitive information disclosure via unprotected /api/options endpoint |
Attack surface summary: A browser game that presents a terminal prompt and a branching text adventure. The flag is gated behind a secret command that is only revealed by the backend /api/options endpoint and triggered via POST /api/monitor.
Flag
| Flag | Value |
|---|---|
| Flag Command | [REDACTED] |
Analysis
Opening the app shows a terminal prompt (>> start). Intercepting traffic (Burp Suite / mitmproxy) exposes the client-side JS and one key API endpoint:
/static/terminal/js/main.js/static/terminal/js/game.js/static/terminal/js/commands.jsGET /api/options
Source review of main.js shows the win path: if the player's currentCommand equals the secret option returned by the backend, the app POSTs it to /api/monitor as JSON {"command": currentCommand} — which returns the flag.
The unprotected GET /api/options endpoint leaks the hidden secret command:
curl -s http://<ip>:<port>/api/options
# { "allPossibleCommands": { "...story options..." },
# "secret": "Blip-blop, in a pickle with a hiccup! Shmiggity-shmack" }
Attack Chain
1. Map the application
Open the web app, note the terminal prompt, and start the game with start. Enumerate the loaded assets via the Network tab / proxy history.
2. Review client-side JavaScript
Trace main.js → game.js → commands.js. main.js imports playerWon() (which prints the GAME_WON string), but the trigger condition lives in the option-check that POSTs a secret command.
3. Pull the secret from /api/options
curl -s http://<ip>:<port>/api/options
# ... "secret": "Blip-blop, in a pickle with a hiccup! Shmiggity-shmack" ...
4. Submit the secret to /api/monitor
curl -s -X POST http://<ip>:<port>/api/monitor \
-H "Content-Type: application/json" \
-d '{"command":"Blip-blop, in a pickle with a hiccup! Shmiggity-shmack"}'
# {"message": "[REDACTED]"}
Techniques Demonstrated
- Client-side JavaScript source review — traced the win logic across
main.js/game.js/commands.js. - HTTP traffic / API endpoint mapping — discovered
/api/optionsand/api/monitorfrom the app's own requests. - Sensitive information disclosure — unprotected
/api/optionsleaks a hidden "secret" command that unlocks the flag.
Tools Used
Browser DevTools / Burp Suite (or mitmproxy), curl.