Chain: recon β weak crypto β accesshardnot started
Combine Track A + B + C: recon leaks a config endpoint containing a Caesar-encrypted admin key; decrypt it and use it to authenticate to the protected endpoint for the flag.
loading simulatorβ¦
1. *Recon:/robots.txt β /backup/config.txt leaks admin_key_enc (a Caesar-shifted string) and notes shift=7. Why:* exposed backups leak secrets.
2. *Crypto: Caesar-decrypt the key with shift 7 (page/solve.py). Why:* classical ciphers are trivially reversible.
3. *Access:* send the decrypted key as ?key= to /vault; it returns the flag.
Lesson: leaked + weakly-protected secrets collapse the whole chain.