Skip to main content
Room Icon

Overflow The Jackpot CTF

THM Defcon CTF Event

medium

45 min

2,010

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Score updated
Score updated

What is a CTF?

A Capture the Flag event is a competition where you will have to solve cybersecurity challenges in diverse areas of knowledge. The challenges are completely practical and will allow you to put your skills to the test. Each challenge has one or more flags you'll need to retrieve to score points.

A flag is a string of text hidden in each challenge that will serve as proof that you've achieved the expected goal. Flags for this competition will follow the following format:

THM{I_R3@d_Th3_Rul3s_aNd_ACKnowledge_Th3M}

Where are the challenges?

The competition will run from August 6th to August 9th. The challenges will be made available in this room when the competition starts.

While you wait for the competition, feel free to try the challenges from our catalogue to practice! 

Read the rules of the CTF! 

We’d love to say that everything is permitted during the CTF, but to keep it fair and fun, please follow these rules:

  1. Do not attack TryHackMe's infrastructure.
  2. Do not attack other users' machines; only use your IP and/or the target machines' IP.
  3. Don’t share flags with other players / teams.
  4. Do not brute force flags on the TryHackMe platform.

If you have questions or need support, our staff and volunteers will be at Village to help.

Answer the questions below

Submit the Welcome + Rules flag.

 
B1t Recovery
 
 
🎰 30 PTS
🔐 Crypto
Very Easy
> BRIEFING
A dealer at the back tables kept a private ledger locked away, scrambled before he vanished into the crowd. Security swept the floor after the fact and pulled a single scrambled file off his terminal, nothing else.
The lock looks solid at a glance, but the house never spends more than it has to. See if you can shake the ledger loose and read what he was hiding.
🎰 THE TABLE
Attachments
> TASKS
Download the attached file
Analyze how the ledger was scrambled
Recover the original contents
Submit the flag
📰 VEGAS TIMES
Word around the pit is the dealer's lock only ever used a handful of bytes to scramble the whole ledger, and every one of his files started the exact same way. If you already know how a message begins, you know more about its lock than you think.
[ CRYPTO ] [ PYTHON ] [ CYBERCHEF ]
Answer the questions below

What is the flag?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine - Task 3
Status:Off
 
Lost Fortune Included
 
 
🎰 60 PTS
🌐 Web
Easy
> BRIEFING
The house always keeps a back room, and this one never quite closed its doors. Somewhere behind the neon and the noise sits a forgotten terminal, still quietly serving up files to anyone who knows how to ask nicely.
Word on the floor is the old system trusts its visitors a little too much. Find the door, learn its language, and see what the dealer never meant to hand over.
🎰 THE TABLE
Connection
://MACHINE_IP
> TASKS
Connect to the
Access the Web Application
Exploit the Application
Submit the flag
📰 VEGAS TIMES
Locals say the old terminal at the edge of town isn't picky about what it shows you, only about how you ask. Regulars warn that the usual tricks don't land here, this one rewards patience and experimentation more than muscle memory. Approach it like a black box, try more than the obvious, and pay attention to what the app quietly tells you back.
[ WEB ] [ ] [ BLACK BOX ] [ BURPSUITE ]
Answer the questions below

What is the flag?

 
Casino Heist
 
 
🎰 90 PTS
🕵️ Forensics
Medium
> BRIEFING
Security noticed a quiet machine on the back office network acting strangely late one night. Before anyone could pull the plug, something had already come and gone, and whatever it grabbed on the way out went straight over the wire.
The full capture from that night has been pulled for review. Somewhere in that traffic is the getaway car itself, and if you look close enough, it left the keys sitting right there on the dashboard.
🎰 THE TABLE
Attachments
> TASKS
Download the packet capture
Identify what was pulled onto the network
Recover the secret it left behind
Use it to unlock what was taken
Submit the flag
📰 VEGAS TIMES
Word is whoever built the getaway car in a hurry, and never bothered hiding the parts under the hood. Pull it apart, and the lock they used to hide the loot might just be sitting in plain sight inside it.
[ FORENSICS ] [ ] [ NETWORK ] [ REVERSE ENGINEERING ]
Answer the questions below

What is the flag?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine - Task 5
Status:Off

Challenge Summary

The TSS team worked an incident at the Cascadia Ski and Resort Collective, a three-property hospitality group sharing one IT backbone, and produced a full report of the attack. The activity is consistent with POWDER WOLF, an eCrime cluster known for using stolen remote access credentials against hospitality infrastructure. 

Critically, the intrusion ran the full kill chain and was only caught at the staging step, before anything encrypted, surfaced by the CSIRT investigation rather than any alert.

Mission Parameters

  1. Read and understand the attack chain at the incident report stored at \threat-intel in the DaC site.
  2. Identify the problems and why the detections from the CSIRT analyst are not working.
  3. Research and understand the attacker's technique before applying the fixes.
  4. Understand the customer's environment particularities before applying the fixes.
  5. Tune and merge the detections in the DaC application.

Lab Access

Your colleagues on the CSIRT team have collected the logs from the time of the attack and set them up in a Splunk instance connected to the TSS Detection Engineering team's Detection-as-Code (DaC) application. The application is a GitHub-style site that runs multiple checks and validations before deploying a detection rule. If you are not familiar with the DaC concept, we strongly recommend taking a look at the AI & Automation in Detection Engineering room, which provides you with a clear explanation of this concept.

Inside the application, you will see the README.md file under the Code tab. This file contains details on how the pipeline works and an explanation of what DaC is. The application also has an App Instructions button that interactively guides you:

Screenshot showing where to click for app instructions.

Start the lab by clicking the Start Machine button below. You will then have access to both the Splunk instance and the Detection-as-Code interface. Please wait 4-5 minutes for the platform to launch.

To access the Detection-as-Code interface, please follow this link:

To access the instance, please follow this link:

Target Machine card placeholder
Answer the questions below

What is the PR#1 flag?

What is the PR#2 flag?

What is the PR#3 flag?

What is the PR#4 flag?

What is the PR#5 flag?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine - Task 6
Status:Off
 
Agent P
 
 
🎰 120 PTS
🖥️ Boot2root
Hard
> BRIEFING
Something on Heinz's machine keeps phoning home. A host inside "A hosts of sorts!" is beaconing out on a schedule nobody authorized, and the team that owns it swears everything's fine.
It isn't. Someone's already inside, quietly holding root and running the show through their own tooling. Get a foothold, work out who's really in control, and take it back from them before they notice you looking.
🎰 THE TABLE
Connection
://MACHINE_IP
Flag Format
EVILINC{...}
> TASKS
Get a foothold on the web application
Escalate to a low-privileged user
Escalate to the internal operator account
Take back control from what's already inside
Submit the flags
📰 VEGAS TIMES
Sources say the front door isn't as current as it looks. Once you're past it, keep an eye on what's talking to itself on the inside, not everything that accepts your input is as careful about what it does with it. And whatever's already running the show left more evidence behind than it thinks.
[ BOOT2ROOT ] [ WORDPRESS ] [ PRIVESC ] [ REVERSE ENGINEERING ]
Answer the questions below

What is the user flag?

What is the operator flag?

What is the root flag?