Baby BoneChewerCon writeup

Baby BoneChewerCon writeup

Challenge name: Baby BoneChewerCon

Difficulty: Easy

Category: Web

Challenge Scenario: Due to heavy workload for the upcoming baby BoneChewerCon event, the website is under maintenance and it errors out, but the debugger is still enabled in production!! I think the devil is enticing us to go and check out the secret key.

Link: https://app.hackthebox.com/challenges/baby%2520BoneChewerCon?tab=play_challenge

Machine IP: 154.57.164.79:31408

Navigated to the site.

When I tried to register with just a ‘test’ it brought me to this.

Scrolling down I found APP_KEY with the flag.

GG

Leave a comment