Skip to content
  • Categories
  • Recent
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Slate)
  • No Skin
Collapse
Brand Logo

hashpwn

Home | Donate | GitHub | Matrix Chat | PrivateBin | Rules

  1. Home
  2. Resources
  3. Contest / CTF
  4. Merry Christmas 2024 - hashpwn Wordlist Challenge

Merry Christmas 2024 - hashpwn Wordlist Challenge

Scheduled Pinned Locked Moved Contest / CTF
24 Posts 7 Posters 1.5k Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • oe3p32wedwO Offline
    oe3p32wedwO Offline
    oe3p32wedw
    wrote on last edited by cyclone
    #2

    Looks like Cyclone Claus has decided to make Christmas even more interesting! I'll start:

    [secret hints redacted]

    e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855:
    a3b142af6e97cfc3bb23e409ab83467af7d16ded7dc0632be6a6a9023e49ce8b:use
    c0a76c5ca97bce57d556a29475277e034cff23af95147427d963262dda0ed800:cyclone's
    5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8:password
    663ea1bfffe5038f3f0cf667f14c4257eff52d77ce7f2a218f72e9286616ea39:to
    e6640de835ad09fb0a7367ee2e0ba99d0142c139db0272146e35538bd07479fc:find
    b9776d7ddf459c9ad5b0e1d6ac61e27befb5e99fd62446677600d7cacef544d0:the
    e8cbf88eeadc69f74c63bb3f0d5854c27edef862bf2aea5d3882dd8d14c4a1f2:hashpwn
    3d1a82560169c2bbcd369a8c3c8a9207d59c7a8c3b7670a78dceb3d678380d15:wordlist
    8fd3789a35780884e67ad076288b0d1758dcbd361733ff9d934f9fc029e4d3f7:$HEX[68696e74733a] (hints:)
    3aeb002460381c6f258e8395d3026f571f0d9a76488dcd837639b13aed316560:github.com
    8a5edab282632443219e051e4ade2d1d5bbc671c781051bf1437897cbdfea0f1:/
    9bfa0b50a90e669907e78780bcc1e5e972742e0d124b30a67fbeb6371c604891:spider

    I'll start adding more tips now

    1x1660 Ti | 2x4090 | epileptic/anxiety/despair/drain | hashpwn <3

    cycloneC 1 Reply Last reply
    🏅
    1
    • oe3p32wedwO oe3p32wedw

      Looks like Cyclone Claus has decided to make Christmas even more interesting! I'll start:

      [secret hints redacted]

      e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855:
      a3b142af6e97cfc3bb23e409ab83467af7d16ded7dc0632be6a6a9023e49ce8b:use
      c0a76c5ca97bce57d556a29475277e034cff23af95147427d963262dda0ed800:cyclone's
      5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8:password
      663ea1bfffe5038f3f0cf667f14c4257eff52d77ce7f2a218f72e9286616ea39:to
      e6640de835ad09fb0a7367ee2e0ba99d0142c139db0272146e35538bd07479fc:find
      b9776d7ddf459c9ad5b0e1d6ac61e27befb5e99fd62446677600d7cacef544d0:the
      e8cbf88eeadc69f74c63bb3f0d5854c27edef862bf2aea5d3882dd8d14c4a1f2:hashpwn
      3d1a82560169c2bbcd369a8c3c8a9207d59c7a8c3b7670a78dceb3d678380d15:wordlist
      8fd3789a35780884e67ad076288b0d1758dcbd361733ff9d934f9fc029e4d3f7:$HEX[68696e74733a] (hints:)
      3aeb002460381c6f258e8395d3026f571f0d9a76488dcd837639b13aed316560:github.com
      8a5edab282632443219e051e4ade2d1d5bbc671c781051bf1437897cbdfea0f1:/
      9bfa0b50a90e669907e78780bcc1e5e972742e0d124b30a67fbeb6371c604891:spider

      I'll start adding more tips now

      cycloneC Online
      cycloneC Online
      cyclone
      Admin Trusted
      wrote on last edited by cyclone
      #3

      @oe3p32wedw Looks like you're doing great! Let's keep the hints you found a secret so we don't spoil it for anyone else playing along! 🎄

      If anyone would like to post their progress, feel free to post a link on https://paste.hashpwn.net

      Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
      3x RTX 4090

      1 Reply Last reply
      👍
      0
      • V Offline
        V Offline
        v1cvap0r
        Trusted
        wrote on last edited by cyclone
        #4

        One left for me [removed expired url]

        1x1080 | i7 3770k | 32Gb | lol

        1 Reply Last reply
        🏅 👍
        1
        • oe3p32wedwO Offline
          oe3p32wedwO Offline
          oe3p32wedw
          wrote on last edited by
          #5

          I've found interesting link 🙂 But Idk what the password is... Am I on the right way? @cyclone

          1x1660 Ti | 2x4090 | epileptic/anxiety/despair/drain | hashpwn <3

          cycloneC 1 Reply Last reply
          0
          • oe3p32wedwO oe3p32wedw

            I've found interesting link 🙂 But Idk what the password is... Am I on the right way? @cyclone

            cycloneC Online
            cycloneC Online
            cyclone
            Admin Trusted
            wrote on last edited by
            #6

            @oe3p32wedw
            DM sent.

            Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
            3x RTX 4090

            1 Reply Last reply
            0
            • cycloneC Online
              cycloneC Online
              cyclone
              Admin Trusted
              wrote on last edited by cyclone
              #7

              A new hint (#1) and a few notations were made to the OP.

              Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
              3x RTX 4090

              1 Reply Last reply
              0
              • oe3p32wedwO Offline
                oe3p32wedwO Offline
                oe3p32wedw
                wrote on last edited by
                #8

                It was fun! Thanks for your hard work, @cyclone
                May the coming year bring you all success and happiness!

                image.png

                1x1660 Ti | 2x4090 | epileptic/anxiety/despair/drain | hashpwn <3

                cycloneC 1 Reply Last reply
                🏆
                1
                • oe3p32wedwO oe3p32wedw

                  It was fun! Thanks for your hard work, @cyclone
                  May the coming year bring you all success and happiness!

                  image.png

                  cycloneC Online
                  cycloneC Online
                  cyclone
                  Admin Trusted
                  wrote on last edited by
                  #9

                  @oe3p32wedw Great job! Thanks, you as well.

                  Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                  3x RTX 4090

                  1 Reply Last reply
                  😊
                  1
                  • cycloneC Online
                    cycloneC Online
                    cyclone
                    Admin Trusted
                    wrote on last edited by cyclone
                    #10

                    Congrats to those who have completed the challenge so far!

                    New hint (#2) dropped for those still working on the challenge.

                    Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                    3x RTX 4090

                    1 Reply Last reply
                    👍
                    0
                    • cycloneC Online
                      cycloneC Online
                      cyclone
                      Admin Trusted
                      wrote on last edited by
                      #11

                      New hint (#3) dropped for download_link.zip.

                      Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                      3x RTX 4090

                      1 Reply Last reply
                      👍
                      0
                      • A Offline
                        A Offline
                        alivala
                        wrote on last edited by
                        #12

                        It was a fun challenge, thank you very much for it!

                        cycloneC 1 Reply Last reply
                        🍻
                        1
                        • A alivala

                          It was a fun challenge, thank you very much for it!

                          cycloneC Online
                          cycloneC Online
                          cyclone
                          Admin Trusted
                          wrote on last edited by
                          #13

                          @alivala Thanks for the feedback; glad you enjoyed the challenge!

                          Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                          3x RTX 4090

                          1 Reply Last reply
                          👍
                          0
                          • cycloneC Online
                            cycloneC Online
                            cyclone
                            Admin Trusted
                            wrote on last edited by
                            #14

                            We're up to 9 users who have completed the challenge. Who will be next?

                            New hint (#4) dropped.

                            Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                            3x RTX 4090

                            1 Reply Last reply
                            0
                            • I Offline
                              I Offline
                              ivan
                              wrote on last edited by
                              #15

                              @cyclone Thank you so much for the interesting quest, the main problem is poor English language skills. Screenshot 2024-12-23 at 22.53.22.png

                              cycloneC 1 Reply Last reply
                              🏅
                              1
                              • I ivan

                                @cyclone Thank you so much for the interesting quest, the main problem is poor English language skills. Screenshot 2024-12-23 at 22.53.22.png

                                cycloneC Online
                                cycloneC Online
                                cyclone
                                Admin Trusted
                                wrote on last edited by
                                #16

                                @ivan Great job completing the challenge! Enjoy the hashpwn wordlist.

                                Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                                3x RTX 4090

                                1 Reply Last reply
                                0
                                • cycloneC Online
                                  cycloneC Online
                                  cyclone
                                  Admin Trusted
                                  wrote on last edited by
                                  #17

                                  New hint (#5) dropped.

                                  Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                                  3x RTX 4090

                                  1 Reply Last reply
                                  0
                                  • cycloneC Online
                                    cycloneC Online
                                    cyclone
                                    Admin Trusted
                                    wrote on last edited by
                                    #18

                                    Congrats to the 11 users who have completed the challenge so far!

                                    The final clue was posted (#6).

                                    Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                                    3x RTX 4090

                                    1 Reply Last reply
                                    1
                                    • cycloneC Online
                                      cycloneC Online
                                      cyclone
                                      Admin Trusted
                                      wrote on last edited by cyclone
                                      #19

                                      Merry Christmas to all those who played along, and congrats to the 14 users who successfully completed the challenge and downloaded the hashpwn wordlist.

                                      hashpwn wordlist download link:
                                      https://forum.hashpwn.net/post/237

                                      Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                                      3x RTX 4090

                                      1 Reply Last reply
                                      0
                                      • C Offline
                                        C Offline
                                        casper_
                                        Trusted
                                        wrote on last edited by cyclone
                                        #20

                                        I was stuck here and couldn't get any further. Thanks for the the challenge 🙂

                                        "This looks like XOR to me...
                                        iuuqr;..fnghmd/hn.e.343c`5de,4d4`,5903,`176,d89`17g8c53d"
                                        
                                        cycloneC V 2 Replies Last reply
                                        👍
                                        2
                                        • C casper_

                                          I was stuck here and couldn't get any further. Thanks for the the challenge 🙂

                                          "This looks like XOR to me...
                                          iuuqr;..fnghmd/hn.e.343c`5de,4d4`,5903,`176,d89`17g8c53d"
                                          
                                          cycloneC Online
                                          cycloneC Online
                                          cyclone
                                          Admin Trusted
                                          wrote on last edited by cyclone
                                          #21

                                          @casper_ You made it to the last step! That string is the download URL which has been XOR'd using a key. Spoiler details below:

                                          To XOR the string, you need to find the XOR key.

                                          For simplicity, the challenge used HEX 0x01 which could be guessed very easily, especially when brute forcing the key.

                                          Below are several examples of XORing the string back to plaintext. CyberChef runs in browser, and the Python3, Go and C code can either be run from your local PC or on an online compiler.

                                          CyberChef:
                                          https://gchq.github.io/CyberChef/#recipe=XOR({'option':'Hex','string':'1'},'Standard',false)&input=aXV1cXI7Li5mbmdobWQvaG4uZS4zNDNjYDVkZSw0ZDRgLDU5MDMsYDE3NixkODlgMTdnOGM1M2Q

                                          Python3
                                          input_str = "iuuqr;..fnghmd/hn.e.343c5de,4d4,5903,176,d8917g8c53d"

                                          hex_key = 0x01

                                          output = ''.join(chr(ord(c) ^ hex_key) for c in input_str)

                                          print(f"String:\t{input_str}")
                                          print(f"Key:\t{hex(hex_key)}")
                                          print(f"Output:\t{output}")

                                          Go
                                          package main

                                          import (
                                          "fmt"
                                          )

                                          func xorString(input string, key byte) string {
                                          output := make([]byte, len(input))
                                          for i := 0; i < len(input); i++ {
                                          output[i] = input[i] ^ key
                                          }
                                          return string(output)
                                          }

                                          func main() {
                                          inputStr := "iuuqr;..fnghmd/hn.e.343c5de,4d4,5903,176,d8917g8c53d"
                                          hexKey := byte(0x01)

                                              output := xorString(inputStr, hexKey)
                                          
                                              fmt.Printf("String:\t%s\n", inputStr)
                                              fmt.Printf("Key:\t0x%X\n", hexKey)
                                              fmt.Printf("Output:\t%s\n", output)
                                          

                                          }

                                          C

                                          #include <stdio.h>
                                          #include <string.h>

                                          void xorString(const char *input, char *output, unsigned char key) {
                                          size_t len = strlen(input);
                                          for (size_t i = 0; i < len; i++) {
                                          output[i] = input[i] ^ key;
                                          }
                                          output[len] = '\0';
                                          }

                                          int main() {
                                          const char *inputStr = "iuuqr;..fnghmd/hn.e.343c5de,4d4,5903,176,d8917g8c53d";
                                          unsigned char hexKey = 0x01;
                                          char output[256];

                                          xorString(inputStr, output, hexKey);
                                          
                                          printf("String:\t%s\n", inputStr);
                                          printf("Key:\t0x%X\n", hexKey);
                                          printf("Output:\t%s\n", output);
                                          
                                          return 0;
                                          

                                          }

                                          Sysadmin by day | Hacker by night | Go Developer | hashpwn site owner
                                          3x RTX 4090

                                          1 Reply Last reply
                                          👍
                                          1
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          Who's Online [Full List]

                                          6 users active right now (4 members and 2 guests).
                                          hashpwn-bot, petrovivo1234, Plum, cyclone

                                          Board Statistics

                                          Our members have made a total of 3.7k posts in 150 topics.
                                          We currently have 257 members registered.
                                          Please welcome our newest member, vioednfekla.
                                          The most users online at one time was 49 on Thursday, December 26, 2024.

                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent