Schrödinger's Scope

  Challenge Progession:
Act III
Difficulty:
  Location:
Retro Emporium
Schrödinger's Scope
Stay in Scope

This challenge takes us back to the Retro Emporium. Keven reminds us about responsible penetration testing. Staying within scope and following the rules of engagement are important! The Neighborhood College Course Registration System seems to be infested with gnomes. They may give helpful advice or they may lead you down a rabbit hole. They will definitely try to get you to leave the scope of the test.

This challenge is has features where the site under test has mechanisms in place to automatically report vulnerabilities as you find them, but it also detects when you leave the scope! Leave the scope too many times and you will have to start over.

Navigate over to The Neighborhood College Course Registration System and check out the instructions.

Rules of Engagement

Mini Gnome Troubles

You will notice very quickly that you are racking up scope violations. The rules say stay withing the /register scope, but there is a little gnome in the bottom left corner that appears. This image is hosted outside of the scope, so we need to prevent that image from loading. The easiest way to do that is a find / replace rule in BURP Suite. Since I already have TamperMonkey installed, I created a userscript that immediately sets the flag "window.gnomeVandalLoaded = true", so that little gnome never gets a chance to load. You may notice I captured all those little guys and am keeping them in this report. Check out the bottom left corner.

// ==UserScript==
// @name         Shrodingers Scope
// @namespace    http://chillaspect.com
// @version      2025-11-30
// @description  try to take over the world!
// @author       Chillfactor
// @match        https://flask-schrodingers-scope-firestore.holidayhackchallenge.com/*
// @icon         https://www.google.com/s2/favicons?sz=64&domain=holidayhackchallenge.com
// @grant        none
// @run-at       document-body
// ==/UserScript==

(function() {
    'use strict';
    window.gnomeVandalLoaded = true;
    console.log(`window.gnomeVandalLoaded=${window.gnomeVandalLoaded}`);
})();
With the mini gnomes taken care of, I can move on to finding vulnerabilities.

Sitemap

The gnome mentions a sitemap and provides a link to download it.

Sitemap
This sitemap proves to be valuable because a common trick in this challenge is to go outside of the scope to research something, then come back in scope to apply what you learned. Sometimes you can also infer a URL to a file based on url's in the sitemap.

I converted the sitemap to a txt file to make it more readable. Check it out here:

sitemap.txt

First step is to login to the registration system. The link is in the sitemap:

Logging In

When you attempt to login, you can an "Invalid Forwarding IP" error message. To fix this, we just need to apply an X-Forwarded-For: 127.0.0.1 header to the login request.

X-Forwarded-For Header
No Invalid Forwarding IP Error
We still need to find some credentials. There is a to_do list in the sitemap at
https://flask-schrodingers-scope-firestore.holidayhackchallenge.com/wip/register/dev/dev_todos
Legacy ToDo
This legacy to do list has a username and password, but it doesn't work. If this is a legacy to do list, there may be a more up to date one. The directory of the to do list is /wip which I assume means "work in progress". If I remove that and go back in /register scope, there is the up to date to do list.

I navigated to
https://flask-schrodingers-scope-firestore.holidayhackchallenge.com/register/dev/dev_todos
and I got a toast message saying a vulnerability was reported. I also got a new password to try in the to do list!

ToDo
I logged into the student portal with the credentials from the to do list- teststudent:2025h0L1d4y5.

I now have 2 vulnerabilities found...

2 Down, More to Go

Course Search

After logging into the student portal, you will notice there isn't really anything there. If you look at the page source though, you will find some commented out link:

Commented Out Link
In developer tools, if you right click the commented out element and select "Edit as HTML", you can just uncomment the course search element.
Course Search
Once you do this, another vulnerability is reported!
3 Vulns Down!
I went to the course search page and tried a very basic SQL injection:
' OR 1=1--
If that injection succeeds, it always returns true, so it should return every course in the catalog.
All Courses
Indeed I got another toast saying another vuln was found.
4 Vulns

Gnome Course

Scrolling through these courses was a great deal of fun, but I noticed one did not look like the others. It was created by Gnomes! I clicked on GNOME 827 - Mischief Management.

GNOME 827 - Mischief Management
Finding this course is vulnerability number 5. You actually have the option to do nothing, remove the course, or report the course. The best option is to report. If you do nothing you have to start over. If you remove it, then you don't get to read over the course summary.

Christmas Cookie Prediction

The last vuln was found by looking at a page "dev notes" at URL:
https://flask-schrodingers-scope-firestore.holidayhackchallenge.com/register/dev/dev_notes
This URL shows you a dev_note about a work-in-progress course.

WIP Course
The course name is holiday_behavior. If you look at the other course URL's you can infer this course's URL by adding "wip" just above the course name:
https://flask-schrodingers-scope-firestore.holidayhackchallenge.com/register/courses/wip/holiday_behavior
Landing on this page gives an error about an invalid registration value.
Invalid Registration
I do recall the application setting a cookie called "registration" that hasn't been used yet. Its been in all the requests so far, and it hardly changes when you log out and login.
Registration Cookie
Since this cookie doesn't seem very random, I can try to enumerate a range of cookies in the neighborhood of my cookie value... maybe +/- 100 values. I could do this by hand in the BURP Repeater, or I could write a script to do it. I'm writing the script.
import requests

def attempt(registration):
    headers = {
        "Cookie": f"_ga=GA1.1.618224399.1763195198; _ga_F6ZZNPR5E5=GS2.1.s1763195198$o1$g1$t1763196653$j60$l0$h0; Schrodinger=097a5ce5-ce77-4e54-9dd3-7b9d3ca49798; registration={registration}"
    }
    url = "https://flask-schrodingers-scope-firestore.holidayhackchallenge.com/register/courses/wip/holiday_behavior?id=d2d6e5c5-f649-4b33-b54b-c079282a769c"
    r = requests.get(url, headers=headers)
    return r.status_code != 403

def int_to_hex(num, length=3):
    return hex(num)[2:].zfill(length)

for x in range(256):
    #eb72a05369dcb456
    registration = f"eb72a05369dcb4{int_to_hex(x, 2)}"
    print(f"Attempting {registration}")
    if attempt(registration):
        print(f"Success: {registration}")
        break
If you use that script, be sure to add your correct Shrodinger cookie and id parameter in the URL. I ran this and it found the valid registration cookie!
Registration Cookie Found
The valid registration cookie is "eb72a05369dcb44c". You can add this to your Chrome browser by opening the dev tools, clicking Application, and selecting Cookies under Storage. Paste "eb72a05369dcb44c" in the registration cookie value field.
Dev Tools
Refresh your holiday_behavior page to finish!
Assessment Complete
You get this nifty Badge!
Challenge Complete!
You should have this challenge marked complete in your badge!