safe-password

Catégorie: Osint Difficulté: medium Flag: CTF{fdc852bc63a266c8c38db64bef90d62d53ddeef00aa85df7b941ac780b3d75d8}

Challenge

file-archive
1KB
circle-info

Description


Another breach in the company... Haven't they learned anything? It's frustrating to witness the same mistake repeatedly. After all, it's not rocket science to implement basic cybersecurity measures like using non-pwned passwords.It looks like one has been seen more than 80 times before.

Can you help me find that one?

Flag format: CTF{sha256(password)}

Explications

C’est de l’OSINT, donc on regarde les sites proposant de savoir si le mot de passe à fuité

Ici le site attendu c’était https://haveibeenpwned.com/Passwordsarrow-up-right

Pour éviter de renter tous les passwords à la main, on peut scripter la recherche


Script de résolution

Mis à jour