This introductory challenge teaches the most basic reflex in offensive security: read a program's help before using it. By connecting to the remote binary and typing ./flag --help, the flag is displayed directly.
- Platform: picoGym
- Category: General Skills / Misc
- Points: 50 pts
- Difficulty: Beginner
- Technique: Reading a program's help (--help)
Challenge description
The prompt provides a connection command to a remote shell:
nc saturn.picoctf.net 54981
Once connected, we land in a minimal Linux environment with a binary named flag available. No other hint is given — that's precisely the point of the challenge: learning to explore on your own.
Step 1 — Connect
We open a terminal and connect with netcat to the given host and port:
$ nc saturn.picoctf.net 54981
The connection is established and a plain shell prompt appears, with no particular welcome message.
Step 2 — Explore
We list the contents of the current directory to see what's available:
$ ls
flag
Just one file: an executable named flag. No source code, no further hint in the prompt — we need to interact with the binary directly to understand what it does.
Step 3 — Read the help
Facing an unknown binary, the very first reflex (even before launching a disassembler or debugger) is to check whether it offers built-in help, via --help or -h:
$ ./flag --help
The program immediately responds by printing its usage — and the flag is included directly in the message:
Usage: flag [options]
This program prints the flag and exits.
picoCTF{***************************}
Full netcat session
$ nc saturn.picoctf.net 54981
$ ls
flag
$ ./flag --help
Usage: flag [options]
This program prints the flag and exits.
picoCTF{***************************}
🚩 picoCTF{ flag intentionally hidden }
The flag is deliberately hidden — follow the method, you've earned it. 💪
Key takeaways
This challenge may seem trivial, but it teaches an essential habit: before diving into a complex analysis (disassembly, reverse engineering, fuzzing…), always check the most obvious options of an unknown binary or command.
-
--helpand-hare often the first thing to try when facing an unknown binary - A lot of useful information (usage, hidden options, versions, even hints or educational secrets) can be found in help messages before even starting a deeper analysis
- In pentesting as in CTFs, enumeration always starts with the simplest means before bringing out the heavy artillery
Originally published on CTFdojo — join the CTFdojo Discord to discuss writeups and get notified about new ones.
Top comments (0)