SSL PROXY image
DDC   DDC2025-REGIONALS   web  

SSL PROXY

Sorry for lack of pictures. Forgot to grab them.
The challenge consists of a website advertising a proxy service. The page allows you to submit a URL.
Considering this is a CTF challenge in a scoped network, the goal is probably related to a service running on the machine.

Testing with localhost shows the following:
awesome image

This can be bypassed by changing the IP to decimal:
awesome image

Using the command parameter shown in the above screenshot, code can be ran, getting the flag:
awesome image

DDC{wh1tel1sts_ar3_c00l}