Ended up using makemime which showed the data in base64. Good enough! Interestingly enough though the ORME.flag showed permission denied... I'll have to go back to that one later.
I think one of the binaries probably has a privilege escalation vulnerability. Looking with la -al you can see the last modified dates, there's a couple of interesting ones
Same. As far as I can tell, none of the usual restricted shell escape tricks work, so you just have to search through all the binaries on the system until you find one you can abuse to print the file contents, and that seems like more of a time sink than it's worth.
Use iconv.
LOL; I used split in the temp directory to create files of a single byte each and ran md5sum on them.
That's quite a bit more straightforward :)
Well I spent an hour trying out as many commands as possible before giving up. Then came across this comment: https://news.ycombinator.com/item?id=20252612 and went through his Twitch recordings to see if he could get past this stage. That is how I learnt about iconv. :)
Hehe. I kinda love this though :P
shuf also works (its in /usr/bin) -- this took me a ~long~ time to figure out
env /bin/busybox strings README.flag
Nice one! Was wondering if there would be a way to call BusyBox with one of the missing binaries.
i ended up using fold.
theres also has to be a way to read the ORME.flag by modifying the file permissions but i haven't figured that one out yet.
Yeah I went through all of the non-deleted commands and fold ended up being the one I found too. The beginning instruction says some levels have multiple flags, so I'm guessing ORME.flag is the hardmode flag.
I bypassed the shell by executing the binary straight from the loader so I was able to do a chmod +r and cat to get it.