running Room 5 : Join the game

Virtual environnement to attack can be reached at : ctf05.root-me.org
Time remaining : 03:34:17

Informations

  • Virtual environnement chosen : root-me-spip
  • Description : 
    Attention : this CTF-ATD is linked to the challenge "Root Me, for real"

    At the end of 2021, we were able to authenticate with administrative privileges on the Root-Me backoffice using, among other things, a 0day vulnerability in the SQL engine of SPIP 4.0.0.

    The vulnerability has been corrected in version 4.0.1 of the software. This challenge is a simple SPIP site in vulnerable version. Find the bug in your turn, exploit it, and pass root to recover the flag ! Game duration : 240 min

  • Validation flag is stored in the file /passwd
  • Only registered players for this game can attack the virtual environnement.
  • A tempo prevent game starting to early or too late.
  • Game will start when one player has choosen his virtual environnement and declared himself as ready.

Player's list

World Map


0x0 35 Available rooms

Room Virtual environnement chosen State Attackers count
ctf01 LAMP security CTF5 running
Time remaining : 02:49:14
1
Strat0S
ctf02 waiting 0
ctf03 Sambox v4 running
Time remaining : 00:42:17
2
cpt_mustard, zipherle
ctf04 Relative Path Overwrite running
Time remaining : 01:01:51
1
Drost
ctf05 root-me-spip running
Time remaining : 03:34:17
1
LecCorentin
ctf06 Apprenti-Scraper running
Time remaining : 03:14:49
1
AZAOWEN
ctf07 SSRF Box running
Time remaining : 03:57:20
1
zecter310
ctf08 Websocket - 0 protection running
Time remaining : 01:02:20
1
Duc
ctf09 ARM FTP box running
Time remaining : 02:23:52
1
cezame
ctf10 Docker - Sys-Admin’s Docker running
Time remaining : 03:23:02
1
Id3m
ctf11 waiting 0
ctf12 Shared Objects Hijacking running
Time remaining : 00:17:55
1
Incinscible
ctf13 waiting 0
ctf14 waiting 0
ctf15 waiting 0
ctf16 waiting 0
ctf17 waiting 0
ctf18 waiting 0
ctf19 waiting 0
ctf20 waiting 0
ctf21 waiting 0
ctf22 waiting 0
ctf23 waiting 0
ctf24 waiting 0
ctf25 waiting 0
ctf26 waiting 0
ctf27 waiting 0
ctf28 waiting 0
ctf29 waiting 0
ctf30 waiting 0
ctf31 waiting 0
ctf32 waiting 0
ctf33 waiting 0
ctf34 waiting 0
ctf35 waiting 0

CTF Results CTF Results

Pseudo Virtual Environnement Attackers count Time start Environnement compromised in
- SSH Agent Hijacking 1 3 March 2019 at 12:26 -
- BSCorp - Unix 1 3 March 2019 at 13:24 -
- LAMP security CTF5 0 3 March 2019 at 01:12 -
- FristiLeaks 1.3 0 3 March 2019 at 02:10 -
dali SamBox v2 1 3 March 2019 at 00:39 0h57