NDH 2015 Weshgrow Writeup
Point = 300
Category = Crypto
By openning the url we redirected to following link:
http://weshgrow.challs.nuitduhack.com/?hmac=ca8473d35a80a5ca4e9f3555c2869f71
As we know HMAC is a cryptographic message for authenticating using a secret key. So this has been made of something.
Also we could find another HMAC in the page source as you can see:
http://weshgrow.challs.nuitduhack.com/admin?hmac=fac0887096a54ac497d968daf4c4fe0b
if you open the /flag address without the purposed HMAC you see redirection to address+"#missinghmac"
.
So this could be HMAC of pages and we should prepare a HMAC for flag
.