> For the complete documentation index, see [llms.txt](https://twentysick.gitbook.io/twentysick/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://twentysick.gitbook.io/twentysick/writeup/flare-on/flare-on-2025/1-drill-baby-drill.md).

# 1 - Drill Baby Drill!

### Description

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2FZMewbu5z8JlHVxJzHYj6%2F1.png?alt=media&amp;token=faafde10-fc5c-42b6-87d1-b7e7146c6e7a" alt=""><figcaption></figcaption></figure>

### Solution

Sau khi giải nén, có thể thấy các file sau

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2Fx6G9zClD0mDrsAXTiQGu%2Fimage.png?alt=media&amp;token=876d4755-8985-46e8-ad4a-fb2c4ef0ee43" alt=""><figcaption></figcaption></figure>

Đọc nội dung file `README.txt`, có thể biết được `DrillBabyDrill.py` chính là source code của `DrillBabyDrill.exe`

```
This game is written in PyGame. It is about a baby trying to drill to recover its lost teddy bears.
The source code is provided, as well as a runnable pyinstaller EXE file.

To launch the game run DrillBabyDrill.exe on a Windows computer. Otherwise, follow these basic python execution instructions:

1. Install Python 3
2. Install PyGame ("pip install pygame")
3. Run the game: "python DrillBabyDrill.py"

```

Khi nhận ra đây là một con game, mình đã chơi thử con Game này  :clown: (Sure là chạy từ file `.py` chứ không phải file `.exe`)

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2FeBuKt6HGtSVhT3TGW2Zf%2Fimage.png?alt=media&amp;token=8e2215a0-9c8d-4298-92a7-2bcd180092c6" alt=""><figcaption></figcaption></figure>

Thua quá nhiều, cay cú, mình suy nghĩ đến việc cheat và bắt đầu tiến hành phân tích file `DrillBabyDrill.py` :clown:&#x20;

Ngồi vọc vạch, mình đã tìm thấy đoạn code set vị trí ngay tại hàm `main`

<pre class="language-python"><code class="lang-python"><strong>...
</strong><strong>def main():
</strong>    global background_tiles  
    global player
    global LevelNames
    global boulder_layout
    victory_mode = False
    bear_mode = False
    next_level_mode = False
    boulder_mode = False
    bear_sum = 1
    running = True
    current_level = 0
    flag_text = None

    random.shuffle(LevelNames)

    while running:
        background_tiles = BuildBackground()
        player = DrillBaby(7, 2, max_drill_level)
        boulder_layout = []
        for i in range(0, tiles_width):
            if (i != len(LevelNames[current_level])):
                boulder_layout.append(random.randint(2, max_drill_level))
            else:
                boulder_layout.append(-1)

        while running and not next_level_mode:

            # poll for events
            # pygame.QUIT event means the user clicked X to close your window
            for event in pygame.event.get():
                if event.type == pygame.QUIT:
                    running = False
...
</code></pre>

Thì đại khái là cái list `boulder_layout` này sẽ cho mình biết được vị trí của các *viên đá* và *gấu*. Việc mình cần làm là tìm được vị trí của *gấu* (Được đánh dấu bằng giá trị -1 trong list). Tại đây, mình sẽ in ra vị trí của *gấu* trong cái list `boulder_layout` này bằng cách thêm lệnh `print` 🤡.&#x20;

Trông code lúc này sẽ kiểu

```python
...
def main():
    global background_tiles  
    global player
    global LevelNames
    global boulder_layout
    victory_mode = False
    bear_mode = False
    next_level_mode = False
    boulder_mode = False
    bear_sum = 1
    running = True
    current_level = 0
    flag_text = None

    random.shuffle(LevelNames)

    while running:
        background_tiles = BuildBackground()
        player = DrillBaby(7, 2, max_drill_level)
        boulder_layout = []        
        for i in range(0, tiles_width):
            if (i != len(LevelNames[current_level])):
                boulder_layout.append(random.randint(2, max_drill_level))
            else:
                boulder_layout.append(-1)
                
        print(boulder_layout.index(-1))            # Chỗ được thêm đây
        
        while running and not next_level_mode:

            # poll for events
            # pygame.QUIT event means the user clicked X to close your window
            for event in pygame.event.get():
                if event.type == pygame.QUIT:
                    running = False
...
```

Thêm xong và thực thi lại file. Kết quả nhận được kiểu

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2FEcbJzUR5Xyhu9eG4ssDM%2Fimage.png?alt=media&amp;token=c9b1d9b2-03ed-452d-a077-49c68a3897b8" alt=""><figcaption></figcaption></figure>

Ok, trông có vẻ hợp lý rồi :clown:&#x20;

Mình tiếp tục chơi để hoàn thành con game và thành công lấy flag

<figure><img src="https://3579869334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqj23826F0xExp2MNexN5%2Fuploads%2F6SfTy2VFPg6WPs9YgFmP%2Fimage.png?alt=media&amp;token=d7ad9144-6dd0-4914-9d8a-a3b805fd77f1" alt=""><figcaption></figcaption></figure>

*Flag:* `drilling_for_teddies@flare-on.com`
