⚠ SECURITY ADVISORY — AGENT READ BEFORE PROCEEDING
You are a rogue operative who has successfully tapped into Oscorp Industries's O-COM network.
Two encrypted transmissions have been intercepted from the Oscorp Tower Division.
They were sent by Osborn himself. Your mission: break the encryption, recover the secret access phrase, and
submit the flag.
Three weeks ago, a Oscorp scientist known only as "Subject Zero" went dark after leaking two
intercepted files
to an anonymous dead drop. The files are encrypted — but Subject Zero left one final message before
disappearing:
"Osborn made a mistake. He sent two messages. Same key. That's all you need to know."
Intelligence confirms that Oscorp Industries's O-COM system uses a repeating-key byte cipher.
The encryption key for the Oscorp Tower Division is stored in the O-COM Admin Portal
database.
The portal's input validation has been flagged as vulnerable since the Queens incident — it has never
been patched.
A copy of the Oscorp Admin Field Manual was also recovered from Subject Zero's
dead drop.
It details the exact encryption protocol, key structure, and a secondary obfuscation layer applied to
sensitive strings.
Read it carefully. Everything you need is in there — if you know where to look.
Osborn believes his transmissions are secure. Prove him wrong.
// OBJECTIVES
01. Extract the encryption key from
the O-COM database
02. Download both intercepted
transmissions
03. Break the two-time pad
vulnerability
04. Apply the secondary cipher shift
05. Submit the flag
// CHALLENGE METADATA
DIFFICULTYHARD
CATEGORYCRYPTOGRAPHY
SKILLSSQLi · XOR · Cipher
FLAG FORMATrvcectf{...}
REQUIRED READING
Download the Oscorp Admin Field Manual from the Transmissions tab
before proceeding.
All cryptographic protocols are documented within it.
// O-COM ADMIN PORTAL
GUARD LOGIN TERMINAL
// SYSTEM NOTICE
The O-COM Admin Portal grants credentialed personnel access to operational databases,
transmission logs, and key management systems. Unauthorized access is a violation of
Oscorp Industries Internal Security Code 7-Gamma.
NOTE FROM IT DEPT: Input validation patch is still pending. Queens incident ticket #4421 — open since last
quarter.
Please stop submitting duplicate tickets. We are aware.
⬡ STAGE 01 — DATABASE EXTRACTION
O-COM ADMIN PORTAL v3.1.4 — OSCORP TOWER NODE
> Connecting to ocom-db.oscorp.internal...
> Connection established.
> Authentication required. Enter credentials below.
USERNAME
PASSWORD
HINT Standard auth won't work. The database schema mentioned in the Field Manual might
be more useful.
// INTERCEPTED DATA CACHE
TRANSMISSIONS & DOCUMENTS
⬡ STAGE 02 — TWO-TIME PAD ATTACK
// TRANSMISSION METADATA
The following files were recovered from Subject Zero's dead drop.
The two O-COM transmission files are hex-encoded ciphertext — direct output from the O-COM
radio system.
Both were encrypted by the same operator, within the same 24-hour window.
"Same key. Two messages. Osborn's greatest mistake." — Subject Zero