cURLing

 Act I

 The Front Yard

Difficulty:

In the center of The Front Yard is the cURLing challenge. Speak to Bow Ninecandle to get info about this objective. This challenge deals with sending http requests with curl. As Bow mentions, reading the help document will serve you well for this one.

cURLing Terminal

If you have never played Holiday Hack Challenge before, some challenges like this one will be sort of a tutorial followed by a series of tasks. I will lay out each task and what curl command I used to solve it. Click the terminal and say Yes you are ready to begin.

1: Unlike the defined standards of a curling sheet, embedded devices often have web servers on non-standard ports. Use curl to retrieve the web page on host "curlingfun" port 8080. If you need help, run the 'hint' command.

This is the most basic curl command. Simply request the webserver:port and return the output.

  1:
Terminal
curl http://curlingfun:8080

2: Embedded devices often use self-signed certificates, where your browser will not trust the certificate presented. Use curl to retrieve the TLS-protected web page at https://curlingfun:9090/

To tell curl to not verify the SSL certificate, use the "-k" or "--insecure" option.

  2:
Terminal
curl -k https://curlingfun:9090

3: Working with APIs and embedded devices often requires making HTTP POST requests. Use curl to send a request to https://curlingfun:9090/ with the parameter "skip" set to the value "alabaster", declaring Alabaster as the team captain.

Use the "-d" option to specify a request POST data. This will also tell curl to set the HTTP method to POST. You can also manually specify the HTTP method with the "-X" or "--method" option.

  3:
Terminal
curl -k -d "skip=alabaster" https://curlingfun:9090

4: Working with APIs and embedded devices often requires maintaining session state by passing a cookie. Use curl to send a request to https://curlingfun:9090/ with a cookie called "end" with the value "3", indicating we're on the third end of the curling match.

Use the "-b" or "--cookie" option to specify cookie data.

  4:
Terminal
curl -k -b "end=3" https://curlingfun:9090

5: Working with APIs and embedded devices sometimes requires working with raw HTTP headers. Use curl to view the HTTP headers returned by a request to https://curlingfun:9090/

Use the "-i" or "--show-headers" option to display the response headers.

  5:
Terminal
curl -k -i https://curlingfun:9090

6: Working with APIs and embedded devices sometimes requires working with custom HTTP headers. Use curl to send a request to https://curlingfun:9090/ with an HTTP header called "Stone" and the value "Granite".

Use the option "-H" to specify custom header a name and value pair.

  6:
Terminal
curl  -k -H "Stone:Granite" https://curlingfun:9090

7: curl will modify your URL unless you tell it not to. For example, use curl to retrieve the following URL containing special characters: https://curlingfun:9090/../../etc/hacks

Use the "--path-as-is" option. Normally curl squashes or merges them according to standards but with this option set you tell it not to do that.

  7:
Terminal
curl -k --path-as-is https://curlingfun:9090/../../etc/hacks

Completing these 7 tasks completes the Silver challenge for this objective.

Once you complete the Silver challenge, Bow Ninecandle will challenge you to go for gold and complete this challenge only using 3 commands.

You know... rumor has it you can breeze through this with just three commands. Why don’t you give it a whirl?"

To get the full context of the Gold challenge, read the file on the terminal "HARD-MODE.txt".

Prefer to skip ahead without guidance? Use curl to craft a request meeting these requirements:

  • HTTP POST request to https://curlingfun:9090/
  • Parameter "skip" set to "bow"
  • Cookie "end" set to "10"
  • Header "Hack" set to "12ft"

Combine the options learned from the Silver challenge to set the http method to post, specify post data, set a cookie, and set a custom header.

  Hard 1:
Terminal
curl -k -H "Hack:12ft" -b "end=10" -d "skip=bow" https://curlingfun:9090

Success! The terminal response with the next challenge.

Excellent! Now, use curl to access this URL: https://curlingfun:9090/../../etc/button

This is exactly like Task 7 from the Silver challenge.

  Hard 2:
Terminal
curl -k --path-as-is https://curlingfun:9090/../../etc/button

Great! Finally, use curl to access the page that this URL redirects to: https://curlingfun:9090/GoodSportsmanship

Use "-L" flag to enable following redirects on requests that respond with 3XX status codes.

  Hard 3:
Terminal
curl -k -L https://curlingfun:9090/GoodSportsmanship

Excellent work, you have solved hard mode! You may close this terminal once HHC grants your achievement.

The terminal lets us know we completed Hard mode and got the Gold trophy!

 Frosty KeypadWhere to next?Hardware Hacking 101 

Holiday Hack Challenge 2024 Report - Cody Travis <cody@chillaspect.com>