Nir Hason

Exercise · 2026-0812

ARACHNE

A SOC jump box got compromised at 03:14. Six flags are buried in what it left behind. You get a shell, no network, and no adult supervision.

Six flags Forty commands Zero network calls ~90 minutes, if you are good

Drop into the shell

[ brief ]

before you start

The host below is a lie told by JavaScript in your own tab. There is no server behind it, no database, and nothing it can reach — so nothing you type can hurt this site, and nothing you find here is a real credential. The puzzle is the puzzle. Attacking the page around it is the boring answer to a question nobody asked.

Everything you need is on that filesystem. Start with cat README.txt, then help. If you get genuinely stuck, hint exists — but it will not talk to you until you have put the work in, and it will never hand you a flag.

six flags

Terminal

progress 0 / 6 saved in this browser only
analyst@arachne — /dev/pts/0 — 132×34 sandboxed

Tab completes · ↑ recalls · Ctrl+L clears · pipes and ; work · help lists everything

What is in it

Six flags, six different problems

No guessing, no pixel-hunting, no "click the fourth word". Every stage is a thing that has actually happened to somebody, and every flag names the next place to look — so you can be stuck, but never lost.

01 · recon
What a directory does not tell you the first time you ask it.
02 · log analysis
One request in a hundred and sixty carried the thing you want. Find it with the tools, not with your eyes.
03 · encoding
Three layers deep, and none of them is encryption — which is the entire lesson.
04 · classical crypto
A cipher broken in 1863, still shipping in 2026.
05 · privilege escalation
One line in a sudoers file, one binary, one flag on that binary.
06 · attribution
Two addresses. Only one of them is a person. This is the part that is actually the job.

How it is sandboxed

Nothing here can reach anything

Putting a terminal on your own website is a slightly funny thing to do, so it is worth being precise about what it is and is not.

  1. no backend

    The host is an object, not a machine

    The filesystem, the logs, the mailbox and the sudoers file are all one JavaScript object built when the page loads. Commands are string manipulation over that object. There is nothing to escape into, because there is nothing behind it.

  2. no eval

    Your input is never executed

    The shell parses what you type into tokens and looks the first one up in a table of about forty functions. There is no eval(), no new Function(), and no template that ever receives your text. Output reaches the screen as text nodes, never as markup — so the terminal cannot be talked into becoming an XSS vector.

  3. no egress

    The page cannot make a request

    This site serves Content-Security-Policy: default-src 'none', which includes connect-src. Even if this script tried to call out, the browser would refuse. It does not try: there is no fetch, no XMLHttpRequest and no WebSocket anywhere in it.

  4. no telemetry

    Nobody is watching you solve it

    Your progress lives in localStorage on your own machine and goes nowhere. I have no idea who is playing, how far they got, or what they typed — which is a shame, because I would love to know. Tell me instead: me [at] nirhason [dot] com

The source of the puzzle is, obviously, downloadable — it is a static file on a static site. You can read the answers out of it in about four minutes. You can also look up the last page of a crossword.