DUCTF 2023 - Helpless
Helpless
Helpless is a miscellaneous CTF challenge for Down Under CTF 2023. Challenge drops you directly into a python interactive help prompt and directs you to where the flag is located.
SSHing the provided machine, does drop us into an interactive python help cli. Exiting the interactive cli also exits the SSH connection. Probably will have to use the python interactive in some way to get the flag.
Printing the help page for python “print” works. Doesn’t show any options directly on the bottom. Reminds me of a vimjail challenge from another ctf, where either commands needed to be piped into the initial connection or using less documented features of the cli. Piping in commands via ssh didn’t seem like the appropriate approach. Pressing the “H” key did yield some results..
The “H” key drops into a LESS help page. Slightly part of the name of this challenge, likely on the right trail. Scrolling down the Less help page shows more options.
“:e” lets you examine files. If we have the appropriate permissions for the flag file, that could be the end of this challenge.
And then the flag is revealed. A simple solution to the challenge. Didn’t find this documented too much on the web. The process of finding these commands was fun.