Writeups
  • Writeups
  • 2020 Writeups
    • Angstrom
      • Git Good
      • Secret Agents
      • windows of opportunity
      • Califrobnication
      • Patcherman
      • Just Rust
      • No canary
      • WS3
      • Confused Streaming
      • Reasonably Secure Algorithm
      • Defund's Crypt
      • Low-kee
      • Discrete Superlog
      • Wacko Images
      • Shifter
      • Xmas Still Stands
      • Noisy
      • Canary
      • Inputter
      • clam clam clam
      • PSK
      • Taking Off
      • Consolation
      • Wooosh
      • Signal_of_hope
      • One Time Bad
      • Revving up
    • bsidesBOS
      • Binary Exploitation
        • Patches
        • Sea Shells
      • Cryptography
        • Alice and Bob
        • Exodia
        • Fancy Caesar
        • Flag-SP Network
        • Maelstrom
      • Forensics
        • Amnesia
        • Mercury
        • Mobility
        • Patchwork Quilt
        • Spy Cam
      • Misc
        • Tea-mix
        • Swipe
      • Scripting
        • Flushed Revenge
        • Reggae
        • Robot Takeover
      • Steg
        • Dimension 0
        • Saving The World
        • Secret Romance
      • Warmup
        • Give Up
        • Kiddie Pool
        • Play The Harp
        • Where's The Body
        • Baseball
        • Ez Bake Oven
        • Y2K
      • Web
        • Clown Show
        • Yet Another Micro-story Library
    • Crypto CTF
      • Amsterdam
      • One Line Crypto
      • Trailing Bits
      • Gambler
    • Covid19 CTF
      • Sql db 3
      • Web 1 (Something Derpy? Idk)
      • ECB is the best CB
      • Db 2
      • Scouting
    • FWordCTF
      • Pwn
        • Welcome Pwner
        • One Piece Remake
        • Numbers
      • Misc
        • Secret Array
        • Twis Twis Litlle Star
      • Web
        • JAILOO WARMUP
      • Rev
        • Tornado
        • XO
        • Beginner Rev
        • Fibo
      • Crypto
        • Randomness
        • One Part!
        • BDBG
        • Weird RSA
      • OSINT
        • Identity Fraud
      • Bash
        • CapiCapi - bash
      • Forensics
        • NULL
    • Google
      • Reversing
        • Beginner
      • Hardware
        • Basics
      • Crypto
        • Chunk Norris
        • Sharky - Crypto
      • Sandbox
        • Writeonly
    • Hacktivity Con
      • Binary Exploitation
        • Pancakes
        • Statics and Dynamics
        • Space Force
          • Space Force - Binary Exploitation
        • Bullseye
      • Scripting
        • Misdirection
        • Rescue Mission
        • Hashbrown Casserole
        • Flushed
        • Tootsie Pop
      • Crypto
        • OFBuscated
        • Tyrannosaurus Rex
        • Perfect XOR
        • Bon Apettit
        • A E S T H E T I C
      • Steg
        • Cold War
        • substitute face
        • Vencryption
      • Mobile
        • Mobile One
      • Web
        • Lightweight Contact Book
        • Bite
        • Ladybug
      • Forensics
        • Domo Arigato
      • Warm Up
        • Hexgedit
        • Caesar Mirror
        • Internet Cattos
      • Misc
        • Private Investigator
    • Houseplant
      • 11
      • Deep Lyrics
      • Adventure Revisited
      • CH₃COOH
      • Rivest Shamir Adleman
      • Zip-a-dee-doo-dah
      • Pie Generator
      • Ez
      • Groovin and Cubin
      • QR Generator
      • Half
      • Tough
      • Beginner Writeups
      • Spilled Milk
      • Fire-place
      • Survey Writeup: Houseplant 2020
      • Sizzle
      • Post-Homework Death
      • Rainbow vomit
      • Lemon
      • I dont like needles
      • Pz
      • Music Lab
      • Ezoterik
      • Parasite
      • Catography
      • Selfhost all the things!
      • Satan's jigsaw
    • HSCTF
      • Web
        • Broken Tokens
      • Binary Exploitation
        • Pwnagotchi
        • Boredom
      • Reverse Engineering
        • Ice Cream Bytes
        • AP lab: Comp Sci Principles
        • AP Lab: English Language
      • Forensics
        • Meta Mountain
      • Misc
        • My First Calculator
    • NahamConCTF
      • pwn
        • Syrup
        • Conveyor Belt
        • Dangerous
      • Misc
        • Alkatraz
        • Fake File
        • Trapped
        • Awkward
      • Web
        • Official business
        • Localghost
        • Agent-95
        • PHPPhoneBook
        • Time Keeper
      • Osint
        • Tron
      • Crypto
        • Homecooked
        • raspberry
        • docxor
        • Twinning
      • Scripting
        • rotten: caesars
        • Merriam
        • Gnomes
      • poggers
    • Plaid
      • File-system-based strcmp go brrrr
    • RACTF
      • Misc
        • Teleport
        • NS.mov
        • ST.mov
        • Pearl pearl pearl
        • Discord
        • BR.mov
        • Emojasm 2
        • Spentalkux
        • EmojASM
        • Reading Between The Lines
        • Mad CTF Disease
      • OSINT
        • Tree Man
        • Brick by Brick
        • Remote Retreat
        • Suspended Belief
        • Dead Man
        • RAirways
      • Pwn
        • Finches in a Pie
        • Finches in a stack
        • Solved in a flash
        • Puffer Overflow
          • Puffer Overflow
        • Not Really AI
        • A Flash Of Inspiration
          • A Flash of Inspiration
        • Medea
        • Eccentric Encryption Engima
        • Snakes and Ladders
      • Web
        • Entrypoint
        • Admin Attack
        • Collide
        • Baiting
        • Vandalism
        • Quarantine
        • Quarantine - Hidden Information
        • Getting Admin
        • Finding Server Information
        • Insert Witty Name
      • Forensics
        • Access Granted
        • Cut Short
        • Dimensionless Loading
        • Peculiar Packet Capture
        • Disk Forensics Fun
        • A Monster Issue
        • A Musical Mix Up
        • Cheap Facades
      • Crypto
        • B007l3G CRYP70
        • Access=0000
        • B007L36 CRYP70... 4641N
        • Mysterious Masquerading Message.md
        • Really Simple Algorithm
        • Really Speedy Algorithm
        • Really Secret Algorithm
        • 0x Series
        • Really Small Algorithm
    • Redpwn CTF
      • Crypto
        • worst-pw-manager
        • 4k-rsa
        • pseudo-key
        • 12 Shades of Redpwn
        • priminity
        • base646464
        • Alien Transmissions v2
        • itsy bitsy
        • seekrypt
      • Web
        • Panda Facts
        • Static Static Hosting
        • Tux Fanpage
        • Anti textbook
        • Inspector-General
        • Login
        • Static Pastebin
      • Pwn
        • The Library
        • Coffer Overflow
        • Secret Flag
        • Dead Canary
        • Skywriting
      • Rev
        • SmArT-Solver
          • SmArT-Solver
        • Ropes
        • Aall
        • Bubbly
      • Misc
        • CaaSino
        • uglybash
        • Albatross
    • rgbCTF
      • misc
        • ye olde prng
        • Penguins
        • Picking Up The Pieces
        • Differences
        • hallo
        • Adventure
        • insert witty algorithm name here
      • rev|pwn
        • ARM 1
        • LYCH King
        • Time Machine
        • Object Oriented Programming
        • Soda Pop Bop
        • Too Slow
        • sadistic rev 2
        • Advanced Reversing Mechanics 2
        • Sadistic Reversing 1
      • ZTC
        • Ralphie
        • Peepdis
        • Vaporwave1
        • icanhaz
        • vaporwave 3
        • Vaporwave 2
      • web
        • tictactoe
        • type racer
        • keen eye
        • Countdown
        • imitation crab
      • forensics:osint
        • PI 1- Magic in the air
        • Pi 2
        • robins reddit password
        • Space Transmission
        • Insanity Check
      • beginner
        • Joke check
        • A Basic Challenge
        • Pieces
        • Quirky resolution
        • Shoob
        • Name A More Iconic Band
        • fine day
      • crypto
        • Grab your Jisho
        • Shakespeare Play, Lost (and found!)
        • (rgbctf/crypto/e.md)
        • I Love Rainbows
        • Adequate Encryption Standard
        • Occasionally Tested Protocol
        • rubikcbc
        • N-AES
    • Sharky
      • Give away 2
      • Give away 1
      • Give away 0
      • Romance Dawn
      • The hare and the tortoise
    • TJCTF
      • Circus
      • Forensics
        • Cookie Monster
        • Gamer F
        • Ling ling
        • Rap God
        • Hexillology
      • Misc
        • arabfunny
        • TTW
        • Timed
        • Gamer M
        • Zipped up
        • Discord
        • Censorship
        • Jarvis
        • Slicer
      • Reasonably Secure Algorithm
      • Login sequel
      • Seashells
      • Admin secrets
      • Web
        • Sarah Palin Fanpage
        • Circus
        • Login sequel
        • Weak Password
        • Moar Horse 4
        • Gamer W
        • File Viewer
        • Admin secrets
      • Gamer R
      • El primo
      • Crypto
        • home rolled
        • rgbsa
        • difficult decryption
        • Reasonably Secure Algorithm
        • Is this Crypto
        • Titanic
      • Reversing
        • comprehensive2
        • Forwarding
        • Gym
        • ASMR
        • Gamer R
      • Gamer M
      • Sarah Palin Fanpage
      • Zipped up
      • Is this Crypto
      • Pwn
        • OSRS
        • Stop
        • Seashells
        • Cookie Library
        • Tinder
        • El primo
      • Discord
      • Congenial Octo Couscous
      • Titanic
      • Gamer F
      • Censorship
      • Jarvis
      • OSRS
      • Moar Horse 4
      • Weak Password
      • Stop
      • Ling ling
      • Slicer
      • Cookie Library
      • Cookie Monster
      • comprehensive2
      • home rolled
      • Rap God
      • difficult decryption
      • Forwarding
      • rgbsa
      • Gym
      • arabfunny
      • Tinder
      • Timed
      • Gamer W
      • TTW
      • ASMR
      • File Viewer
      • Hexillology
    • Tokyo Westerns CTF
      • sqrt
      • easy-hash
      • Nothing much to see
      • Twin D
    • Zh3r0 CTF
      • Misc
        • Rainbow Hex
        • Find the Covid19 Vaccine
        • Welcome To Phase 2md
        • Welcome To Phase 1
        • Analyse me
        • snakes everywhere
      • Forensics
        • Run Forrest Run
        • PreDestination
        • Snow
          • Snow.md
        • Hidden Music
        • is it a troll???
        • Soundless
        • PreDestination
        • UnRemovable
        • Katycat
        • LSB Fun
        • Good Ol' IE
      • pwn
        • Command1
        • Free flag
        • Help
      • Crypto
        • We are related
        • Dozen Bases
        • Uncipher Me
        • NASA
        • RSA Warmup-Really Small Algorithm
      • Web
        • Web Warmup
        • Google Source Code
      • OSINT
        • NASA
      • Prenote: As all of these challenges were similar, we decided to combine these under one page.
  • 2021 Writeups
    • Union CTF
      • Antistatic
      • Cr0wn Air
      • Human Server
      • Mordell Primes
      • Neo-classical
      • Nutty
      • Why is a raven
Powered by GitBook
On this page

Was this helpful?

Export as PDF
  1. 2020 Writeups
  2. TJCTF
  3. Misc

Discord

This challenge was definitely one of the harder ones in the CTF, mainly because of it's deceiving point value, at only 5 points. The description doesn't provide any information at all, which was very strange, and the fact that the challenge was categorized as "Misc" also made it very confusing, as should the challenge not be OSINT if nothing at all is provided?

This ended up taking a very long time to figure out. Perhaps the title would give a bigger hint? It mentions Discord, which is a common text and voice messaging service used by gamers.

I myself, am not a gamer, so I wasn't too keen on the idea of registering at discord.com, but if I was going to get 5 points for it, I was going to do it nonetheless.

Registering however, was a challenge in itself.

The difficulty lies in that you have to put personal information in, but wait... Do I really trust a site like discord with my personal details?

Were these 5 points really worth it? I asked myself.

"Yes. Yes they are. We must beat our rivals Pwn to 0xE4!".

And so, reluctantly, I filled in my details, and added 2 Factor Authentication for safety.

These 5 points were going to be so worth it.

However, how was I to get into the server where the flag was?

I would need an invite link. But where was I to get that?

Well, I started by trying to OSINT the challenge creators, in the hopes that they would have left something in their social medias, but it ended up with no results, to my sadness.

I looked for minutes, hours, days for this link, but nothing showed up.

Eventually, I gave up and decided to come back to this challenge another day. I decided to look at other challenges.

What about that circle one? Or the difficult decryption one?

But still, there was a feeling in my heart.

A feeling that meant I would HAVE to get those 5 points.

After all, it could mean the difference between winning and losing...

One morning, while scrolling through the challenges, I noticed something rather interesting.

There was a logo that looked oddly familiar amongst the email, Facebook and Twitter logos.

At once I recognised what it was.

IT WAS THE DISCORD LOGO! Hovering over it, I saw it redirected to a discord.gg link.

Perhaps this was it?

Perhaps this was the link to join the discord?? With my right hand sweating and shivering, I moved my mouse towards the icon, and clicked.

For a moment... There was silence.

Nothing could be heard, except for the faint sound of rickrolls in the background, and the weird audio for arabfunny.

Suddenly, I was greeted with a page. "evanyeyeye invited you to join TJCTF".

This was it. Those 5 points were going to be mine, and we would crush Pwn to 0xE4 like twigs.

However, it turns out this was again, still not enough. The security of the server was set to very high, and I needed to pass a captcha.

"No problem!", I thought. "I can just use my OCR script!".

However, despite trying over 2 times to try and get the OCR script to work, I never managed to do it, and time was running out.

There were only 95 hours left in the CTF.

This needed to be quick.

We were running out of time.

This was an emergency.

Immediately I recruited help from our team's Asian, PotatoK. He was able to read the letters and numbers and so, after a long while of waiting, we got access to the server! Those 5 points were finally going to be ours! However, once again, due to the delicate crafting of this challenge by the creator, KyleForkBomb(who even is that guy), we were stopped in our tracks once again. "How many parts does this challenge have?", I thought to myself. I decided to go back to the challenge page, and luckily enough, there was a relevant hint!

"Type ?flag in chat"

So I proceeded to type in "?flag in chat", in the hopes that it would give me the flag, but after 5 seconds of me typing "?flag in chat" into notepad, it was clear that this was going nowhere. So, I kept on pushing. I found a shortcut for typing it as well, by simply CTRL-C to copy and CTRL-V to paste. However, even after a further 7 seconds of typing it, no flag was there. Where was this flag, and why was it so difficult just for 5 measly points? I had to beat Pwn to 0xE4. I had to.

After a few more seconds of trying to type "?flag into chat" into my notepad window, I decided to try and take the hint from another perspective. I decided to read the hint once more.

"Type ?flag in chat"

Ever since we discovered the hint, we had always interpreted it as 'Type "?flag i n chat"'. But what if it was meaning something else? For example, it could have meant 'Type "?flag" in chat'.

Now everything made sense.

The pain of trying to find the Discord link. The captcha which I had to get PotatoK to solve. The registering for the Discord account. It all made sense now. All the suffering we went through.

With palms still sweating, I slowly typed "?flag" into the #general chat.

There was no one else around as far as I could tell. I was going to crush Pwn to 0xE4.

I was going to get these points.

I was close, I could feel it.

I could definitely taste the flag.

I felt so close.

Once I typed "?flag" in chat, there was silence yet again.

I could feel the sense once again, just like when I clicked on the discord link.

A few seconds passed.

Then, I saw my message get deleted? Who could have done this? Was it the evil mind of the challenge creator? Was it... no... it couldn't be... Pwn to 0xE4???

Could they have done this in order to get the flag and the points before us?

This was a disaster.

We needed those points.

This was turning into a nightmare, and there were only 94 hours left in the CTF.

We needed a plan to take them down, and fast. We quickly retreated back to the Jackbox server in order to discuss.

This had to be done quick.

We would need to act fast.

Our plan was simple. We would just need to type the command, and the get output before Pwn to 0xE4 would have a chance to intervene.

Using my new techniques I learnt from Truly Terrible Why, and also the CTRL-C CTRL-V technique from earlier, I was set to get this flag. This was going to work.

I was going to get this flag, get those 5 points, and crush Pwn to 0xE4.

I could taste victory already, and those CTFTime points would definitely be ours.

We were almost ready to execute the plan.

This would be it.

The flag would be ours.

Those 5 points we worked so hard for.

Registering the account, finding the link, getting past the captcha, using the hint. All the pain and suffering would finally pay off.

We were ready to take on Pwn to 0xE4.

We waited for the perfect moment to strike, but we had to be extra careful, as we did not expect them last time...

The plan was in action! I pasted the command carefully, but swiftly, and awaited the response...

Yet again... silence...

Until...

We were able to retrieve a message link...

It appears this takes us to the announcements channel, which I scrolled through a couple times, but couldn't find anything of use.

Where was this flag, and why was this challenge only worth 5 points???

Then... something caught my eye...

It appeared to be... an image... with some text on it. The words looked familliar... especially the "tjctf" part...

Suddenly, I realised what this was.

This was the flag!! The very thing that took almost 2 minutes to find was right in front of us!!

I had to get PotatoK once again to read it for me, but we finally found the flag after a lot of sweat, pain, and effort.

Swiftly I wrote the flag down, and copied it into the flag box.

"Correct!" it read, and those 5 points were finally ours.

We would go on to get defeated by Pwn to 0xE4, as they solved Naughty, meaning that these 5 points made all the difference.

Thank you for making this one of the most difficult CTF challenges I have ever solved, and even though it was only worth 5 points, they were more than satisfying to get.

Flag: tjctf{circles_was_a_bad_challenge}

-@Willwam845

PreviousZipped upNextCensorship

Last updated 4 years ago

Was this helpful?

https://discordapp.com/channels/426043976957820940/467040678820446209/713526612158840843