Skip to main content

HashingJobApp Beginner picoMini 2022 Solution

Respond to a server's hashing challenges quickly and correctly to earn the flag.

Published: April 2, 2026Updated: August 13, 2026

Description

The server asks you to compute the MD5 hash of a word several times. Answer each prompt correctly to get the flag.

Remote

Connect to the server with netcat.

bash
nc saturn.picoctf.net <PORT>

Solution

Want to try it yourself first?

The guided walkthrough reveals hints one step at a time.

Walk me through it
  1. Step 1Connect and read the prompt
    Observation
    The description says the server asks you to compute an MD5 hash. So connect with netcat first and read the whole prompt carefully before computing anything.
    Connect with netcat. The server asks you to MD5-hash the text between quotes, excluding the quotes themselves. Read the word it gives you.
    bash
    nc saturn.picoctf.net <PORT>
    What didn't work first

    Tried: Sending a response immediately without reading the full prompt first

    The server sends a multi-line prompt carrying both the instruction and the quoted word. Reply before reading to the end and you hash the wrong token, or miss it entirely, and the server rejects the answer. Read the complete output before computing and replying.

    Learn more

    MD5 (Message Digest 5) is a cryptographic hash function that produces a fixed 128-bit (32 hex character) digest from any input. Hash functions are deterministic - the same input always produces the same output - and designed to be one-way: you cannot reverse a hash to recover the original input.

    The server sends the prompt: please md5 hash the text between quotes excluding the quotes. The quoted word changes each time.

  2. Step 2Compute the MD5 hash and reply
    Observation
    The prompt asks for the MD5 hash of a specific quoted word. Use echo -n with md5sum so no trailing newline changes the digest, then paste back only the 32-character hex output.
    In a separate terminal, run md5sum with the word (using echo -n to avoid hashing the newline). Copy the resulting 32-character hex digest and paste it back into the netcat session. Repeat for each round.
    bash
    echo -n 'computers' | md5sum

    Expected output

    524164822d03894ee68052e183e7ea36  -
    What didn't work first

    Tried: Running 'echo computers | md5sum' without the -n flag

    Without -n, echo appends a newline before piping to md5sum, so you hash 'computers\n' rather than 'computers'. The digest is completely different and the server rejects it every time. Always include -n: 'echo -n computers | md5sum'.

    Tried: Pasting the full md5sum output ('524164822d03894ee68052e183e7ea36 -') into the netcat session

    md5sum prints the 32-character digest followed by two spaces and a dash, which stands for stdin. The server wants only the digest, so pasting those trailing characters gets the answer rejected. Copy just the first 32 characters.

    Learn more

    echo -n prints the string without appending a newline character. Hashing computers\n produces a completely different digest than hashing computers, so the -n flag is essential. On macOS, use md5 -s computers instead.

    The server repeats the challenge several times before printing the flag. Each round, copy the word from the netcat output, compute its MD5 in the other terminal, then paste the hex digest back. The server closes the connection after a few seconds of inactivity, so work quickly. If the manual approach is too slow, write a short Python script using the hashlib and socket modules (or pwntools) to automate reading each word, computing its MD5, and sending the reply.

    While MD5 is fast and widely supported, it is cryptographically broken for security purposes - collision attacks have been demonstrated. Modern systems use SHA-256 or SHA-3 instead. MD5 still appears in CTFs and legacy systems, so recognizing it is an important skill.

Interactive tools
  • Hash IdentifierIdentify unknown hash types by length and prefix. Covers MD5, SHA-1, SHA-256, SHA-512, bcrypt, NTLM, and more.
  • Checksum CalculatorCompute CRC32, MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes for text or uploaded files. Verify against known hashes.

Flag

Reveal flag

picoCTF{4ppl1c4710n_r3c31v3d_...}

echo -n is required to suppress the trailing newline - hashing a word with a newline attached produces a completely different MD5 than the server expects.

Key takeaway

Cryptographic hash functions map arbitrary input to a fixed-length digest: deterministic, one-way, and extremely sensitive to change, since one extra newline produces an entirely different hash. MD5 was once standard for integrity checks and password storage, but collision attacks demonstrated in 2004 and 2008 ruled it out for anything security-critical. Modern systems use SHA-256 or SHA-3 for integrity, and bcrypt, scrypt, or Argon2 for passwords, where the computational cost deliberately slows brute-force cracking.

Related reading

Useful tools for General Skills

Where to go next