Hack the Box: Illumination

Challenge Lab: Forensics

Difficulty: Easy

“A Junior Developer just switched to a new source control platform. Can you find the secret token?”

Zip Password: hackthebox

Start out by downloading and unzipping the provided file. You will notice that there is a hidden .git folder:

This directory should hold all the history of changes from the Junior Developer in the log portion:

Let’s focus on the one where the tokens were removed:

See the token? It looks like it is encoded with Base64. Let’s decode it:

You can either decode it in the command line like this:

Or use something like CyberChef:

Happy Hacking! ❤




CTF Writeups to facilitate cyber education.

Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

Software Defined Solution in the context of I/O stress with Networking Fault Injection

From LA Fashion Designer to NY Programmer

Jebot, a Traditional Indonesian Game

Website and Server Monitoring with Buddy’s Recurrently Executed Pipelines

Senior Java developer Interview Questions series 5 (Core Java 8, Spring)

Simple way to create kubernetes cluster locally using kind.

Twig : PHP Template engine

Implementing E2E tests for the Login and Registration workflows of RefApp 3.x

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store


CTF Writeups to facilitate cyber education.

More from Medium

TryHackMe - Cyborg

Proving Grounds Meathead walkthrough

Undefeatable Monster

Why I recommend Hackthebox