ad3n๐Ÿ’€kali:~$
  • ๐Ÿ HOME
    • ๐ŸšฉCTF WRITEUPS
      • CURTIN MALAYSIA CTF 2023
        • Web - General
        • Web - SQLi
        • Pwn & Reverse
      • HTB UNIVERSITY CTF 2023
        • Reverse Engineering
      • Wargames.MY 2023 CTF
        • Web
      • osu!gaming CTF 2024
        • Forensic
      • WolvCTF 2024
        • Web
      • TexSAW CTF 2024
        • Web
      • ACSC 2024 CTF
        • Web
      • NahamCon CTF 2024
        • Forensic
      • UCC CTF 2024
        • Boot2root
    • โœ๏ธNOTES
      • Web Exploitation ๐Ÿ•ธ๏ธ
  • ๐Ÿ”CATEGORIES
  • ๐Ÿ™ŒABOUT
Powered by GitBook
On this page
  1. HOME
  2. CTF WRITEUPS
  3. WolvCTF 2024

Web

Last updated 1 year ago

  • Bean Cafe

The web page asked for verification to be able to receive the flag, which need to submit two "identical images"(same md5 values) but different type of image. Since we deal with images, to evaluate the images that are different by using md5 value to compare between the images.

Flag: wctf{new_ai_old_algorithm}

Exploring the web seem does not found ways to exploit and retrieved the flag. Thus, need to focus on how to make two different images has the same md5 value. After a few research we can make it happen by changing the metadata same as the other image and this vulnerability called md5 collisions when use for security-related hashes. Since it takes too long to copy each metadata, I found this page which give link to google drive of two different images with same md5 value. Submit these two images got the flag we wanted.

๐Ÿ 
๐Ÿšฉ
reddit