Hackplayers/hackthebox-writeups

Re-enable Active Machines WU

noraj opened this issue · 1 comments

noraj commented

Machines writeups until 2020 March are protected with the corresponding root flag. But since this date, HTB flags are dynamic and different for every user, so is not possible for us to maintain this kind of system. So from now we will accept only password protected challenges and retired machines (that machine write-ups don't need password).

As far as I understand that means that you don't accept Active Machines WU anymore?

Instead of the root.txt hash it could be the md5sum of the root shadow entry for linux and ntlm Admin entry for Windows.

Eg. in pseudo-code with fictive examples

  • Linux: md5('root:$6$YIFGN9YscCV72BjFtx/tehbc7sQTJp09c5.:18277:0:99999:7:::')
  • Windows: md5('Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c:::')

Thanks but we are not interested anymore in maintaining that. Of course we already considered this option time ago.

What the hack the box staff want to achieve with the dynamic flags system is to avoid the existence of something fixed (not dynamic) to solve the machines... doing this, is to create a fixed string which will shown how to solve the machine. Is exactly what the hack the box staff want to avoid. Doing this we are "killing" the dynamic flag system. They created it for a reason.

Sorry but we will not do it.