running Room 12 : Join the game

Virtual environnement to attack can be reached at : ctf12.root-me.org
Time remaining : 02:17:02

Informations

  • Virtual environnement chosen : root-me-spip
  • Description : 
    Attention : this CTF-ATD is linked to the challenge "Root Me, for real"

    At the end of 2021, we were able to authenticate with administrative privileges on the Root-Me backoffice using, among other things, a 0day vulnerability in the SQL engine of SPIP 4.0.0.

    The vulnerability has been corrected in version 4.0.1 of the software. This challenge is a simple SPIP site in vulnerable version. Find the bug in your turn, exploit it, and pass root to recover the flag ! Game duration : 240 min

  • Validation flag is stored in the file /passwd
  • Only registered players for this game can attack the virtual environnement.
  • A tempo prevent game starting to early or too late.
  • Game will start when one player has choosen his virtual environnement and declared himself as ready.

Player's list

World Map


0x0 35 Available rooms

Room Virtual environnement chosen State Attackers count
ctf01 Well-Known running
Time remaining : 03:18:39
1
mire
ctf02 Well-Known running
Time remaining : 03:19:34
1
Rob
ctf03 Docker - Sys-Admin’s Docker running
Time remaining : 03:22:03
1
Bachi
ctf04 Windows - ZeroLogon running
Time remaining : 01:42:43
1
rHACK00n
ctf05 waiting 0
ctf06 waiting 0
ctf07 LAMP security CTF5 running
Time remaining : 03:01:22
2
0xffff, b4n3
ctf08 waiting 0
ctf09 End Droid running
Time remaining : 03:51:09
1
Jamal
ctf10 waiting 0
ctf11 waiting 0
ctf12 root-me-spip running
Time remaining : 02:17:02
1
darkveiderg
ctf13 OpenClassrooms - DVWA running
Time remaining : 02:19:27
1
rob
ctf14 waiting 0
ctf15 Apprenti-Scraper running
Time remaining : 00:00:23
2
val, raaphael273
ctf16 waiting 0
ctf17 waiting 0
ctf18 Windows - sAMAccountName spoofing running
Time remaining : 01:08:27
1
0xSpectra
ctf19 Docker - Talk through me running
Time remaining : 00:46:13
1
Neriss
ctf20 waiting 0
ctf21 waiting 0
ctf22 waiting 0
ctf23 waiting 0
ctf24 waiting 0
ctf25 waiting 0
ctf26 The Ether : EvilScience running
Time remaining : 02:06:54
1
Usurper
ctf27 waiting 0
ctf28 waiting 0
ctf29 waiting 0
ctf30 waiting 0
ctf31 waiting 0
ctf32 waiting 0
ctf33 waiting 0
ctf34 waiting 0
ctf35 waiting 0

CTF Results CTF Results

Pseudo Virtual Environnement Attackers count Time start Environnement compromised in
- Hopital Bozobe 0 3 March 2019 at 23:15 -
- Exploit KB Vulnerable Web App 0 3 March 2019 at 21:47 -
- SamBox v1 1 3 March 2019 at 21:38 -
- Metasploitable 2 3 March 2019 at 21:32 -
SSH Agent Hijacking 1 3 March 2019 at 21:30 0h33