Advanced, Rootable, Timed

dejavault / 0.0.0.0

5: Flags (app, 2:system, env, root)
1: Service
5,400 pts
Avg. headshot: 50,675 minutes

50%

Level 12 / Master PenTester

neufdeux / 111th Place

2: Flags found
1: Service discovered
1,150 pts

Sometimes the smallest things can lead to the craziest of rides... Upload the right image type and the path for OpenMediaVault will be revealed to you.

There are many ways you can escalate don't be afraid to try out new things.

To start the challenge connect to http://10.0.40.28:1337/. Your timer starts from the first time you connect to the service.

1 Writeup by:

Activity Stream

Latest activity on the platform

neufdeux Got the ETSCTF username flag from the /etc/passwd file of dejavault for 650 points, 32 months ago
neufdeux Gained access to data stored in environmental variables of dejavault for 450 points, 32 months ago
neufdeux Discovered a web service on target dejavault for 50 points, 32 months ago