This BoT can speak, can you ask him the flag? https://telegram.me/csictf_brobot/
I opened the Telegram App in my mobile and started a conversation with the bot. I tested out all available commands and understood that the bot is a text2voice bot which will convert whatever text we give into an equivalent voice file. We get a github link for the bot's source code when we type
So, I went ahead and checked the source code of the bot.
def send_voice_msg(update, context):
We see that the text we give is appended with the echo command and is run and converted to its equivalent audio file using espeak. Since the input is not sanitized, we can make echo execute whatever command we want. Trying
'$(cat flag.txt)' give us the following voice file with the flag.