Rating:

# ▼▼▼Dance(Web:150) 58/605=9.6%▼▼▼
**This writeup is written by [@kazkiti_ctf](https://twitter.com/kazkiti_ctf)**

```
https://dance.wpictf.xyz
by binam
```

---

```
GET / HTTP/1.1
Host: dance.wpictf.xyz
```

```
HTTP/1.1 302 FOUND
Server: nginx/1.13.12
Date: Tue, 17 Apr 2018 00:17:58 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 309
Connection: keep-alive
Location: https://www.youtube.com/watch?v=dQw4w9WgXcQ#t=0m09s
Set-Cookie: flag=E1KSn2SSktOcG2AeV3WdUQAoj24fm19xVGmomMSoH3SuHEAuG2WxHDuSIF5wIGW9MZx=; Path=/
Set-Cookie: Julius C.="got good dance moves."; Path=/
Strict-Transport-Security: max-age=31536000

<title>Redirecting...</title>
<h1>Redirecting...</h1>

You should be redirected automatically to target URL: https://www.youtube.com/watch?v=dQw4w9WgXcQ#t=0m09s. If not click the link.
```

Set-Cookie: flag=E1KSn2SSktOcG2AeV3WdUQAoj24fm19xVGmomMSoH3SuHEAuG2WxHDuSIF5wIGW9MZx=; Path=/

Set-Cookie: Julius C.="got good dance moves."; Path=/

`Julius C.` is Hint. → Julius Caesar. → Caesar cipher

---

flag=`E1KSn2SSktOcG2AeV3WdUQAoj24fm19xVGmomMSoH3SuHEAuG2WxHDuSIF5wIGW9MZx=`

↓To shift the letters

```
F1LTo2TTluPdH2BfW3XeVRBpk24gn19yWHnpnNTpI3TvIFBvH2XyIEvTJG5xJHX9NAy=
G1MUp2UUmvQeI2CgX3YfWSCql24ho19zXIoqoOUqJ3UwJGCwI2YzJFwUKH5yKIY9OBz=
H1NVq2VVnwRfJ2DhY3ZgXTDrm24ip19aYJprpPVrK3VxKHDxJ2ZaKGxVLI5zLJZ9PCa=
I1OWr2WWoxSgK2EiZ3AhYUEsn24jq19bZKqsqQWsL3WyLIEyK2AbLHyWMJ5aMKA9QDb=
J1PXs2XXpyThL2FjA3BiZVFto24kr19cALrtrRXtM3XzMJFzL2BcMIzXNK5bNLB9REc=
K1QYt2YYqzUiM2GkB3CjAWGup24ls19dBMsusSYuN3YaNKGaM2CdNJaYOL5cOMC9SFd=
L1RZu2ZZraVjN2HlC3DkBXHvq24mt19eCNtvtTZvO3ZbOLHbN2DeOKbZPM5dPND9TGe=
M1SAv2AAsbWkO2ImD3ElCYIwr24nu19fDOuwuUAwP3AcPMIcO2EfPLcAQN5eQOE9UHf=
N1TBw2BBtcXlP2JnE3FmDZJxs24ov19gEPvxvVBxQ3BdQNJdP2FgQMdBRO5fRPF9VIg=
O1UCx2CCudYmQ2KoF3GnEAKyt24pw19hFQwywWCyR3CeROKeQ2GhRNeCSP5gSQG9WJh=
P1VDy2DDveZnR2LpG3HoFBLzu24qx19iGRxzxXDzS3DfSPLfR2HiSOfDTQ5hTRH9XKi=
Q1WEz2EEwfAoS2MqH3IpGCMav24ry19jHSyayYEaT3EgTQMgS2IjTPgEUR5iUSI9YLj=
R1XFa2FFxgBpT2NrI3JqHDNbw24sz19kITzbzZFbU3FhURNhT2JkUQhFVS5jVTJ9ZMk=
S1YGb2GGyhCqU2OsJ3KrIEOcx24ta19lJUacaAGcV3GiVSOiU2KlVRiGWT5kWUK9ANl=
T1ZHc2HHziDrV2PtK3LsJFPdy24ub19mKVbdbBHdW3HjWTPjV2LmWSjHXU5lXVL9BOm=
U1AId2IIajEsW2QuL3MtKGQez24vc19nLWcecCIeX3IkXUQkW2MnXTkIYV5mYWM9CPn=
V1BJe2JJbkFtX2RvM3NuLHRfa24wd19oMXdfdDJfY3JlYVRlX2NoYUlJZW5nZXN9DQo=
W1CKf2KKclGuY2SwN3OvMISgb24xe19pNYegeEKgZ3KmZWSmY2OpZVmKAX5oAYO9ERp=
X1DLg2LLdmHvZ2TxO3PwNJThc24yf19qOZfhfFLhA3LnAXTnZ2PqAWnLBY5pBZP9FSq=
Y1EMh2MMenIwA2UyP3QxOKUid24zg19rPAgigGMiB3MoBYUoA2QrBXoMCZ5qCAQ9GTr=
Z1FNi2NNfoJxB2VzQ3RyPLVje24ah19sQBhjhHNjC3NpCZVpB2RsCYpNDA5rDBR9HUs=
A1GOj2OOgpKyC2WaR3SzQMWkf24bi19tRCikiIOkD3OqDAWqC2StDZqOEB5sECS9IVt=
B1HPk2PPhqLzD2XbS3TaRNXlg24cj19uSDjljJPlE3PrEBXrD2TuEArPFC5tFDT9JWu=
C1IQl2QQirMaE2YcT3UbSOYmh24dk19vTEkmkKQmF3QsFCYsE2UvFBsQGD5uGEU9KXv=
D1JRm2RRjsNbF2ZdU3VcTPZni24el19wUFlnlLRnG3RtGDZtF2VwGCtRHE5vHFV9LYw=
```

---

flag format is `WPI{`

When `WPI{` is encoded with base64, it becomes `V1BJewo=`.

---

V1BJe2JJbkFtX2RvM3NuLHRfa24wd19oMXdfdDJfY3JlYVRlX2NoYUlJZW5nZXN9DQo=

↓Decode with base64

`WPI{bInAm_do3sn,t_kn0w_h1w_t2_creaTe_chaIIenges}`