# CTF_100_Writeup_Stage_1 - TryHackMe

Hello Everyone,  Let’s start with the writeup. So, There is a room on TryHackMe called CTF100 which is created by Deskel ( an amazing user of TryHackMe). This room contains total 100 flags, which are divided in different stages. Every stage have different methodologies , technologies and tools to get the flags. The themes of room is based on telent, cipher, encode and esolang. Let’s get started with solution.

![](https://i.imgur.com/8aFjxXW.png align="left")

Follow along with this writeup, and deploy your own instance of CTF100! [https://tryhackme.com/room/ctf100](https://tryhackme.com/room/ctf100)

Task 1-1: Flag1

Start scanning the ip\_address with the help of nmap.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-10-15.png align="left")

It is showing that port 3333 is open. Let’s dig on port 3333.

> $ telnet *&lt;ip\_address&gt;* 3333

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-20-55.png align="left")

It will ask you for you address. Enter your address according to your tunnel ip.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-21-10.png align="left")

Woah.. We just get the first flag, and terminal also showing that 5 more ports are open now. Time to perform another scan using nmap.

> Flag1: you\_got\_a\_message

Task 1-2: Flag2

Do the nmap scan using below mention command.

> $ nmap -v -T5 -p3000-4000 -Pn 10.10.42.75

So, we find the all 5 open ports. Let’s sart to dig on it.

> $ telnet &lt;ip\_address&gt; 3343

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-30-28.png align="left")

It is showing some enciphered text. Decipher text using ROT13.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-32-39.png align="left")

Enter the text to capture the flag and note the number, it will be use in upcoming steps.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-35-06.png align="left")

> Flag2: qt8pm59jh5r49uqdwfw2

Task 1-3: Flag3

Let’s dig on next port.

> $ telnet &lt;ip\_address&gt; 3353

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-37-36.png align="left")

It is again a enciphered text. This is a ceaser cipher, decipher it.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-39-44.png align="left")

Keep rotating until you not get meaningful text.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-41-00.png align="left")

> Flag3: 5wdtc7jzk33qjauh5gxm

Task 1-4: Flag4

Let’s check a new port for a new flag. Repeat the same telnet process but change the port number.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-42-26.png align="left")

Now, where is the key?.. he is trying to make you fool bcoz key is **where**…hahaha

This is vignere cipher, decode it using the key and grab the flag.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-44-59.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-45-30.png align="left")

> Flag4: sm8jvu8jxu7dz6s7qmsp

Task 1-5: Flag5

Next port.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-48-36.png align="left")

It is morse code. Use a morse code translator to decode it and grab the flag.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-51-04.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-53-28.png align="left")

> Flag5: 2p3363hrava9fbq296ca

Task 1-6: Flag6

Next port.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-54-56.png align="left")

It is hex. Try to decode hex to ASCII.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-56-11.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-12-23-56-42.png align="left")

> Flag6: skuj9359mqdm6sv8d8z6

Task 1-7: Flag7

Remember the number with each flag? Collected all 5 numbers are

```yaml
8989 7431 5667 9332 3331
```

This sequence of these ports, open up port 9999. Enter these numbers on it.( The reason is port knocking)

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-18-14.png align="left")

Something hapen… Time to perform a scan using nmap.

> $ nmap  -v -T5  -p4000-4999  -Pn &lt;ip\_address&gt;

![](https://blog.tryhackme.com/content/images/2019/11/image.png align="left")

A new open port. Let’s check it.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-25-01.png align="left")

**Do not trust anything it said.** Maybe it is trying to fool you. Just press enter, it will show you something.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-28-18.png align="left")

PORT PORT …. Means there are 5 more open ports. Time to scan again.

> Flag7: zmht7gg3q3ft7cmc942n

Task 1-8: Flag8

> $ nmap -v -Pn -T5 -p4000-4999 &lt;ip\_address&gt;

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-34-27.png align="left")

Let’s check on each port. 5 more challenges are ready to solve.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-43-48.png align="left")

It is base64 text. Decode it.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-45-57.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-46-28.png align="left")

Save the number. It will be gonna help again.

> Flag8: dmm32qvfkfwm6yjnw46k

Task 1-9: Flag9

Same Process. Check the next port.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-47-55.png align="left")

It is base32.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-49-06.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-49-28-1.png align="left")

> Flag9: fuf8mx74nph26f69mr97

Task 1-10: Flag10

Now, check port 4003. It seems like butter now ..right? Easy and simple… just go with flow and be ready for try harder level….hahhaha

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-53-19.png align="left")

This is base58 which is also look like base64. Decode [base58](https://www.browserling.com/tools/base58-decode)

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-54-17.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-55-05.png align="left")

> Flag10: hud9bm8yc37md5b7t7mn

Task 1-11: Flag11

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-00-56-17.png align="left")

This is base85 looking like unreadable to us. Decode the [base85](https://cryptii.com/pipes/ascii85-encoding).

![](https://blog.tryhackme.com/content/images/2019/11/image-3.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-4.png align="left")

> Flag11: 4xm43r2wajrsrbm4775d

Task 1-12: Flag12

port 4005… what do you have?

![](https://blog.tryhackme.com/content/images/2019/11/image-5.png align="left")

This is also unreadable and it is base91. [Decode](https://www.dcode.fr/base-91-encoding) it.

![](https://blog.tryhackme.com/content/images/2019/11/image-6.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-7.png align="left")

> Flag12: qtfvbd7gbvyg9gww5jwj

Task 1-13: Flag13

Similar to Flag 1-7, collect all 5 numbers and open new ports using port knocking on port 9999.

According to flag, 5 numbers are

```yaml
10113 10415 21033 35555 25637
```

But it is wrong sequence, reverse the order.

```yaml
25637 35555 21033 10415 10113
```

Repeat same process, use port 9999 to open new ports.

![](https://blog.tryhackme.com/content/images/2019/11/image-8.png align="left")

Something happen. Time to perform a new scan.

> $ nmap  -v   -T5   -Pn   -p-6000-6999  &lt;ip\_address&gt;

![](https://blog.tryhackme.com/content/images/2019/11/image-9.png align="left")

Voilaaa…. Port 6000 is open. Let’s check on this port.

![](https://blog.tryhackme.com/content/images/2019/11/image-10.png align="left")

5 more open ports means 5 new flags…

> Flag13: aehg24vwn5yyc8jz4tv5

Task 1-14: Flag14

Perform a new scan to identify 5 new ports.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-01-12-11.png align="left")

5 new open ports. Let’s dig on each one to find the flags.

![](https://blog.tryhackme.com/content/images/2019/11/Screenshot-from-2019-11-13-01-13-06.png align="left")

Remember something…sounds like pika pika pikachu…yes it is pikachu language. Actually, this is an esolang. [Decode](https://www.dcode.fr/pikalang-language) it.

![](https://blog.tryhackme.com/content/images/2019/11/image-11.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-12.png align="left")

> Flag14: k2phhw85emq3v4njj5g6

Task 1-15:Flag 15

Let’s check port 6020. What is it say?

![](https://blog.tryhackme.com/content/images/2019/11/image-13.png align="left")

This is not simple binary language. This is another esolang which is binaryfuck. Let’s [decode](https://www.dcode.fr/binaryfuck-language) it.

![](https://blog.tryhackme.com/content/images/2019/11/image-14.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-15.png align="left")

> Flag15: qtfvbd7gbvyg9gww5jwj

Task 1-16: Flag16

Check port 6030…

![](https://blog.tryhackme.com/content/images/2019/11/image-16.png align="left")

This is spoon esolang. Let’s [decode](https://www.dcode.fr/spoon-language) it.

![](https://blog.tryhackme.com/content/images/2019/11/image-17.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-18.png align="left")

> Flag16: ckjug6sj88xuajfku72h

Task 1-17: Flag17

Let’s check port 6040…

![](https://blog.tryhackme.com/content/images/2019/11/image-24.png align="left")

Looking like brainfuck…but is reversefuck language.

![](https://blog.tryhackme.com/content/images/2019/11/image-25.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-26.png align="left")

> Flag17: x4xhrqx3ywzyx2jmgc5j

Task 1-18: Flag18

port port port hahhaha… it is last port to check 6050.(hope so xD)

![](https://blog.tryhackme.com/content/images/2019/11/image-27.png align="left")

This is alphuck language.

![](https://blog.tryhackme.com/content/images/2019/11/image-28.png align="left")

![](https://blog.tryhackme.com/content/images/2019/11/image-29.png align="left")

> Flag18: kr2t9qcgt4ht9h6j5ydp

Task 1-19: Flag19

Collect all the 5 ports? yes…we did. This is port knocking for stage 2.

The sequence is

```yaml
31031 50010 7968 20010 6100
```

Use these numbers to open ports in stage 2.

![](https://blog.tryhackme.com/content/images/2019/11/image-30.png align="left")

> Ports: 31031 50010 7968 20010 6100

So, It was the writeup for stage1. For Stage2 and more, writeup will coming soon. Stay tuned and wait for writeups. Byee byee.
