Official accounts
Recon - any bash explode related social media account, all official accounts are @bashexplode (all accounts are linked at the bottom of this page)
[Nothing before 2022 and nothing after 2023 will be relevant]
[root@home:~]# bash explodeCTF / The album is the challenge
Every song title is a hint. Follow the sound through recon, music theory, audio analysis, and a small portion of network penetration testing.
01 / Briefing
bash explode's album 'CTF' is a capture the flag challenge. Every song title on the album is a hint to the challenge. This CTF consists of passive OSINT Recon, Music Theory, Audio Analysis, and a small portion of Network Penetration Testing.
To participate you should purchase the album on bandcamp* (I gotta get this thing on a torrent). You can also scrape the audio or whatever on any streaming platform, but the compression might screw up some of the challenges*
The only challenge that deals with active penetration testing is related to a database where you will find the credentials via recon. Do your best not to do any other active pentesting activity.
02 / Original scope
Recon - any bash explode related social media account, all official accounts are @bashexplode (all accounts are linked at the bottom of this page)
[Nothing before 2022 and nothing after 2023 will be relevant]
Music Theory/Audio Analysis - the tracks on the album
Compression might screw up some of the challenges. Use the original audio where available.
Penetration testing (you'll find creds somewhere, don't brute force it, if you break a server that's a bummer for everyone)
bashexplode.com*.mp3.zip*.wav.zip*.explode.shTrack 1 / Phase cancellation(I hope the SC compression doesn't destroy it. Click "...More" > "Download File")
Download resource03 / Results
04 / Elsewhere