0CTF/TCTF 2020 Quals

For the next CTF, I joined the We_0wn_Y0u team from Vienna, and we had a lot of fun! 0CTF/TCTF was on June 27-28. We managed to solve 5 challenges and took 36th place. Below are the solutions to the hardest challenges: Web / easyphp [59 pts, 175 solved]Misc / Cloud Computing [211 pts, 42 solved]Misc

Fun on the aircraft

What can you do on a flight? Well, you can take a nap or read an onboard magazine. One of not so obvious options is to connect to internal aircraft Wi-Fi and check which resources you can access without paying anything. On one of the latest flights, I clicked here and there and found API endpoint, which looks like this: https://www.airline-flynet.com/fapi/flightData (airline name was changed, just in case). On this endpoint, we have quite a lot of interesting data in JSON format. The most exciting thing about this data is the fact it is available only when you’re onboard, and is not available from the “everyday” internet.