capture-the-flag

Encoded-Deception

#web

I forgot to save screenshots for this and the challange site is now offline: https://encoded-deception.aws.jerseyctf.com/

Part 1 of the flag

View the page source and look at the source code for the JavaScript file

The first part is encoded as base64 in a variable named secretMessage or something like that.

Part 2 of the flag

Look at the console output for the response from a .php file, the second part is also encoded as base64

Use an online tool to decode both parts.