Forum Discussion
Serial Maze Support Group
Have you been burned by the serial maze?
Welcome!
This is a safe space to air out all your serial maze comments, challenges, and anything else.
π
23 Replies
- GusC
Bronze III
Is there another lab we can reference or redo that will assist with the coordinates component?
- DG
Bronze III
Sabrina mentioned in another post. "I would recommend having a look at the Browser Developer Tools: Console and JavaScript Execution lab, as there is some overlap in the tasks. We don't have an offensive lab on Python pickles, but you may find Python: Insecure Deserialization useful, including the further reading linked at the end. Good luck!"
In the Insecure Deserialization it mentions "The developers of a GPS fitness tracking application unfortunately implemented the feature to upload jogging routes vulnerable to insecure deserialization attacks, since they decided to use the insecure pickle format. Your task is to remediate this vulnerability using the more secure JSON format."
So maybe this can be of help.- Nneka_AN
Silver I
Thank you, DG!
- SamDickison
Community Manager
SabrinaKayaciβ might be able to advise you on that.
- autom8on
Silver I
:-)
- sabil10
Bronze II
I'm stuck on serial maze, found one endpoint, it says "What a pickle... You need the secret to continue." not sure how to proceed from here
- Nneka_AN
Silver I
Hi sabil10β
I see you have also been burned by the maze. Welcome to the support group π
Hopefully, autom8onβ, domel44β, or jamesstammersβ might be able to provide some assistance.
Alternatively, if you read through the thread on this page, you might be able to pick up some clues to help. π€©
- SamDickison
Community Manager
π Niiiiice π
- Nneka_AN
Silver I
π€© Wow!! Well done autom8on Steve! π
This gives hope to others in the support group π
When will you be holding the serial maze masterclass? π
- Nneka_AN
Silver I
π
Despite finding the π₯ (Thanks to autom8on for the prompt in the right direction), I'm stumped on how to get to the endpoint π©
Any more clues from the kind immersers that have already conquered this maze? π- domel44
Bronze II
itsdangerous
token > secret_key > π₯ > answer- sabil10
Bronze II
I'm stuck...
tried deserialization on both move/submit endpoint.. unable to exploit.
tried rockyou and both endpoint token .. failed..
found one endpoint 2257 .. which is asking for secret.. but don't see any parameter to brute force..
I'm stuck... would appreciate any hints
TIA
- SamDickison
Community Manager
Something about pickles? π₯π₯π₯
- Nneka_AN
Silver I
I'm side-eyeing every single pickle to see if they contain secrets π£