Gnome Tea

  Challenge Progession:
Act II
Difficulty:
  Location:
Modern Scandanavian
Gnome Tea
Spill the Tea

Thomas in the Modern Scandanavian Condo tells us about his interactions with the gnomes. They seem to use a secret passphrase when they communicate with each other. They also use a social media app called "Gnome Tea" to gossip amongst themselves. Thomas thinks if we can infiltrate this gnomes-only app, we can discover the secret passphrase.

Gnome Tea App
In the News

If you keep up with the news, another similar app simply called "Tea", suffered a breach. This was due to a poorly secured database/storage settings. Images of government issued ID cards were leaked. Read about it here.

This application may be vulnerable in the same way. Gnome Tea is a Firebase application. Firebase is an application platform run by Google that offers building and hosting applications including backend services like Firestore databases, etc...

Firebase applications load a javascript file that contains some configuration data. When you load up Gnome Tea in your browser, it fetches a javascript file called "index-XXXXXX.js" where the X's are some arbitrary characters. There is a config object in this javascript code that contains data like apiKey, authDomain, projectId, storageBucket among other things. I just searched for the text "apiKey" and found it.

Firebase Config
If you want to copy/paste that text I will post the text version below.
const OP = {
    apiKey: "AIzaSyDvBE5-77eZO8T18EiJ_MwGAYo5j2bqhbk",
    authDomain: "holidayhack2025.firebaseapp.com",
    projectId: "holidayhack2025",
    storageBucket: "holidayhack2025.firebasestorage.app",
    messagingSenderId: "341227752777",
    appId: "1:341227752777:web:7b9017d3d2d83ccf481e98"
}

Exploring Firebase API

The next step is to take this API key and other data and use the Firebase API to see what is available for us to see. I'm not 100% familiar with using these API's so I used a tool I found on Github called firepwn. This tool proved to be valuable at querying the public data available behind Gnome Tea.

To set it up, just clone the repository and launch the src/index.html in a browser. Then add the config details we found in the javascript file.

Firepwn Setup
Click Start and then you can begin querying the Firebase API's for data. There are two areas of Firepwn that are useful here. "Firestore DB Explorer" and "Firebase Storage". We can query any publicly available data from the Firestore DB or any public documents in Firebase storage.
Firepwn Features

Extracting the Documents

In Firepwn, I clicked the Firebase Storage button and selected Execute with the default options. The action here is to "List Files". This will tell me if there are public files/directories.

Public Directories
There are two public directories: gnome-avatars and gnome-documents. I did the File Listing process again only I set the path to gnome-avatars:
Path: gnome-avatars
Gnome Avatars
18 Gnome avatar files were returned. You can download any of these files by copying the path of the file, pasting it as the path, then changing the action to "Download File". It will produce a link to the file that can be downloaded. Notice it produced a link with a valid token.
Downloading File
Click the "OPEN IN NEW TAB" button to view and download the File. I will show this process once, but it is the exact same for downloading any of the other files.
Gnome Avatar Downloaded
There is another directory called "gnome-documents". Lets view and download those files as well. Listing the gnome-documents directory reveals 18 images that are driver's licenses!
Gnome Drivers Licenses
Gnome Licenses Downloaded
I downloaded all the avatars and drivers license images to my machine and moved on to extracting the data. *note If you want to download and inspect these files yourself I will host them here:

gnome-avatars.zip
gnome-documents.zip

Extracting the Database

There are 3 collections noted in that javascript file downloaded from the Gnome Tea app.

Collections
The collections are gnomes, dms, and tea. We can use the Firebase DB Explorer to extract all the data from these 3 collections. Just set the action to "Get" and set the path to the collection name "gnomes". Click execute and it will extract all the records in the collection in JSON format.

As an example here is the first gnome record pulled out:

Record: Professor Pumpernickel
I downloaded all the records from all 3 collections. If you want to browse the files here they are:

gnomes.json
dms.json
tea.json

Being Nosy

Since we are looking for a secret passphrase, I started browsing through the dms and found a conversation between Glitch Mitnick and Barnaby Briefcase.

{
	"document_id": "fHlgFwFTJeRkOFLK9DVj",
	"data": {
	  "lastMessage": "Barnaby... we need to talk about password security. 😅 Please don't share passwords in DMs!",
	  "participants": [
		"l7VS01K9GKV5ir5S8suDcwOFEpp2",
		"LA5w0EskgSbQyFnlp9OrX8Zovu43"
	  ],
	  "messages": [
		{
		  "content": "Hey Glitch, I keep forgetting my password. Can you help me reset it?",
		  "senderName": "Barnaby Briefcase",
		  "senderUid": "l7VS01K9GKV5ir5S8suDcwOFEpp2",
		  "timestamp": {
			"seconds": 1759260052,
			"nanoseconds": 956000000
		  }
		},
		{
		  "content": "Sure thing! What's your current password so I can verify your account?",
		  "timestamp": {
			"seconds": 1759260052,
			"nanoseconds": 956000000
		  },
		  "senderName": "Glitch Mitnick",
		  "senderUid": "LA5w0EskgSbQyFnlp9OrX8Zovu43"
		},
		{
		  "content": "Sorry, I can't give you my password but I can give you a hint. My password is actually the name of my hometown that I grew up in. I actually just visited there back when I signed up with my id to GnomeTea (I took my picture of my id there).",
		  "senderName": "Barnaby Briefcase",
		  "senderUid": "l7VS01K9GKV5ir5S8suDcwOFEpp2",
		  "timestamp": {
			"seconds": 1759260052,
			"nanoseconds": 956000000
		  }
		},
		{
		  "senderName": "Glitch Mitnick",
		  "senderUid": "LA5w0EskgSbQyFnlp9OrX8Zovu43",
		  "timestamp": {
			"seconds": 1759260052,
			"nanoseconds": 957000000
		  },
		  "content": "Barnaby... we need to talk about password security. 😅 Please don't share passwords in DMs!"
		}
	  ],
	  "participantNames": [
		"Barnaby Briefcase",
		"Glitch Mitnick"
	  ],
	  "lastMessageTime": {
		"seconds": 1759260052,
		"nanoseconds": 957000000
	  }
	}
}
It looks like Barnaby needs to reset his password. His current password is the name of his hometown! Not only that, but he explains that when he took the picture of his ID, he was there. We definitely need to check the exif data of that license photo to see if there are GPS coords in there.

I located his license from the files I downloaded from the Firestore bucket and ran it though an exif tool to check the data.

License Image EXIF Data
There are GPS coordinates in there! Acoording to Google Maps, the place at coordinates (-33.46495847505669, 115.91044990491714) is called "Gnomesville".
Gnomesville, Australia

The credentials we need to try in this case is barnabybriefcase@gnomemail.dosis:gnomesville.

Spilling Tea

I was able to login as Barnaby!

Gnome Tea
I know there is an admin dashboard because I saw the endpoint in the javascript file with the config.
admin endpoint
The admin endpoint says Access Denied.
Access Denied
It also says that some javascript flag isn't set. The flag is "window.ADMIN_UID". What is strange is that it tells us what the value should be. I opened up the console and set
window.ADMIN_UID = "3loaihgxP0VwCTKmkHHFLe6FZ4m2"
When I did that the admin page loaded and I got some "secret data" loaded in the console!
Secret Data
Passphrase!
The secret passphrase is in there under "Agent Recognition Protocol". The passphrase is "GigGigglesGiggler". Enter that in your badge to complete the challenge!