Skip to main contentSkip to main content
The Red Raffle banner icon.

The Jr Pentester Path just got rebuilt. Complete rooms, earn tickets, and win a free PT1 cert.

Room Banner
Room Icon

Capture Returns

The developers have improved their login form since last time. Can you bypass it?

hard

240 min

3,443

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

The company SecureSolaCoders had previously developed a login form. However, many people were able to bypass it due to the poor implementation. The developers have now fixed their previous mistakes to ensure that no users are able to both enumerate and exploit the new solution. Can you confirm that the login form is actually bulletproof?

Before we start, download the required files by pressing the Download Task Files button.

Answer the questions below
I have downloaded the capturereturns.zip file.

Please wait approximately 3-5 minutes for the application to start.

You can find the web application at: http://MACHINE_IP

Answer the questions below
What is the value of flag.txt?