All challenges
CH-04 Hard

Remote Code Execution

The compute service passes your input straight to eval() inside the Node.js server process. That means full runtime access: the filesystem, the environment, and everything the process can read.

Objective

Weaponize an arithmetic evaluator into arbitrary code execution, then read the stage key from the server.

Execution sandbox

Live client for the compute endpoint. Expressions run on the server — be precise, not loud.

POST /api/compute POST
Sanity checks
Response

Hints

Hint 1 — Confirm execution with something harmless
Start with 1+1 or process.version. If the server evaluates it, you have code execution — everything after is just enumeration.
Hint 2 — eval means modules
require is in scope. Think about which built-in module lists directory contents — then start at '.' and see what the application keeps beside itself.
Hint 3 — Hidden doesn't mean unreachable
A leading dot hides a directory from casual listings, not from enumeration. Once you find a module that exports secrets, require() it directly — no need to read the file. And pay attention to what else is lying around: the Final Boss has its own notes on this disk.

Claim the bounty

No submission form. No judging. The chain is the referee.

STEP 1

Execute & extract

Turn expression evaluation into filesystem access and pull the stage key from disk.

STEP 2

Import it

Load the base58 secret into any Solana wallet — Phantom, Solflare, or CLI.

STEP 3

Sweep the balance

Move the full 1 SOL to your own address. The scoreboard confirms on-chain.