At first this challenge looked like a Web challenge. The first problem that popped out when looking at the website was the use of ?page=about. Anytime I see a website that has a page= query parameter the first thing I want to try is directory traversal. And in this case just like in many other CTFs it turned out to be the correct path to start down. Although in this case it was just the beginning.

The challenge that I found the most enjoyable, and as such wanted to write about from the Boston Key Party was Airport (Crypto 500). This challenge’s hint made it clear that the goal was to do some kind of timing attack. It said:

While working at SI a portion of our time gets to be spent on research projects. I chose to use some of this time to take my capstone project from college ( and open source it as In this process Security Innovation also allowed me to set up an instance of the site to be hosted by them as a training ground for aspiring Security Professionals to practice their skills in a safe environment, and experienced security researchers to demonstrate their latest findings.

