Tags: bazaar web 

Rating: 5.0

# STEM CTF Cyber Challenge 2019 – My First Blog

* **Category:** Web
* **Points:** 150

## Challenge

> I wish canonical would release a blog platform, they make everything so easy to use and it just works!

## Solution

The owner of the blog is a fan of Canonical and its products. As you can see in the blog, he is fan of [Bazaar](http://bazaar.canonical.com/en/), the version control system of Canonical.

Trying to connect to `` will give an `HTTP 403 Forbidden` error, so the folder should exist.

Connecting to `` will reveal the existence of a Bazaar repository folder.

Furthermore, connecting to ``, will reveal the last revision.

1 bzr_lover-20181206184825-790ppqxy6l69f581

So Bazaar must be installed and a `bzr` repostitory must be created in order to craft the `.bzr` directory and then recreate the website files.

$ mkdir ctf-bzr
$ cd ctf-bzr/
$ bzr init
$ echo 'foo' > foo.txt
$ bzr add
$ bzr commit
$ rm foo.txt

The `last-revision` can be downloaded to replace the existing one.

$ cd .bzr/branch
$ rm last-revision
$ wget

The `dirstate` file can be downloaded to replace the existing one.

$ cd ../checkout
$ rm dirstate
$ wget

The `pack-names` file can be downloaded replacing the existing one.

$ cd ../repository
$ rm pack-names
$ wget

Using `bzr check` command will trigger an error that will reveal the name of the missing files.

$ cd ../../
$ bzr check

The name is: `ctf-bzr/.bzr/repository/indices/c325a543411b3717bd63b6cc879e3d50.rix`, so all missing files can be downloaded.

$ cd .bzr/repository/indices/
$ rm *.*
$ wget
$ wget
$ wget
$ wget
$ wget
$ cd ../packs
$ rm *.pack
$ wget

Then the status of the repo could be checked.

$ bzr status

The command `bzr revert` will recreate the file.

<title>My Blog</title>
<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css" integrity="sha384-Gn5384xqQ1aoWXA+058RXPxPg6fy4IWvTNh0E263XmFcJlSAwiGgFAW/dAiS6JXm"

<div class="container">
<div class="jumbotron">
<h1 class="display-4">My Blog</h1>

Just a spot for me to talk about how much I love Canonical

<h1>I love Canonical</h1>

As someone who is just getting started with Linux, I love Canonical. They build the easiest to use Linux distribution I can find, and they build so many useful tools. So far I'v
e tried out

  • Juju - The worlds best configuration management tool!

  • Bazaar - The worlds best version control!

  • Ubuntu - The worlds best OS!

  • Launchpad - GitHub? Gross!

<h1>Learning PHP</h1>

I recently learned about PHP and I can't stop switching everything over to it. In fact, this blog is now powered by PHP, I think! I changed the file extension at least, and adde
d a little PHP code below here. That should pretty much do it right? I have the PHP code commented out for now since I can't seem to get it to work right. I'll have to look into it later.


It will contain the flag.


Original writeup (https://github.com/m3ssap0/CTF-Writeups/blob/master/STEM%20CTF%20Cyber%20Challenge%202019/My%20First%20Blog/README.md).