Description
People keep trying to trick my players with imitation flags. I want to make sure they get the real thing! I’m going to provide the SHA-256 hash and a decrypt script to help you know that my flags are legitimate.
Steps Taken
- ssh into the machine
- ls the directory
- run `sha256sum files/* | grep
- run `./decrypt.sh files/
- Flag: picoCTF{trust_but_verify_e018b574}