CHALLENGES 2017



!! If you have some write-ups for the challenges, feel free to send it to us via the contact form and we will add it here to our website. !!

Thank you very much for writing some write-ups:

  • Stefano Vetrini
  • Daniele Linguaglossa

Qualifying Challenges

Every participant needed to solve at least one qualifying challenges. They can be downloaded from here.

Main Event Challenges

One flag per challenge!
Standard Flag-format: AHE17{<FLAG>}
There are also challenges with a different flag format. Please check the Description.

There are also some challenges that can not be solved after the event, they were only available for local hackers.

Challenge Difficulty Description Write-Up
Native
AES-Decrypt 400 It’s right in front of you, just decrypt it!
Token-Generator 500 If you enter a flag in the app it will validate if it is the correct flag. To find the correct flag, which the validator will accept, just reverse the app. Attention: Token format is AHE17-THEFLAG
Exploiting
Time Is Ticking 100 Only for local hackers during the event. NONE
Communication
Mr. President What Is The Gold Code 200 Only for local hackers during the event. NONE
Flying-Dutchman 300 This challenge includes an app and a server. The token is stored on the server, various hints are hidden in both, app and server.
Use HTTP GET requests to find the hints on the server. Only GET requests are required to solve this challenge!Requires a server.
NONE
Hardware
Give Me All Your Money (Money Safe Challenge) 250 Only for local hackers during the event. NONE
Look Outside (Intel Edison Board Challenge) 150 Only for local hackers during the event. NONE
Reversing
Flag-Validator 150 If you enter a flag in the app it will validate if it is the correct flag. To find the correct flag, which the validator will accept, just reverse the app.

If you find the correct flag, please put the flag for submission into AHE17{THEFLAG} .

Crypto
You Can Hide – But You Cannot Run 250 Something is going on inside this app, don’t know what its doing. I have the feeling a secret message is transmitted somehow, somewhere… can you help me find the secret message?
Base64 Cracker 150 Only for local hackers during the event. NONE
Crack-Me
Why Should I Pay? 200 This app is useluss without premium, but why would you pay for something if you can get it for free?
Misc
Esoteric 300 So much Brainfuck… seems like there is more than you see! Please take a look at me!
Scam the Client 250 Only for local hackers during the event. NONE