Posts

Showing posts with the label buffer overflow

TryHackMe - Brainstorm - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the Brainstorm room hosted at https://tryhackme.com/room/ brainstorm . For this walkthrough, we'll be using two virtual machines (VMs), a Kali Linux VM as our attacking machine, and the deployed Windows Brainstorm client as the the victim machine. Task 1 - Deploy Machine and Scan Network Questions: Deploy the machine No answer needed How many ports are open? First, we're going to add the IP address of the Brainstorm machine to our attacking machine's / etc/hosts file. In the current version of Kali,we need switch to Root before doing so: As Root: echo “10.10.100.56 brainstorm.thm” >> /etc/hosts At the time of our examination of the network, there were a number of machines live in the network, and the number of open ports on those systems does not match the answer for this question. Neither does the number of open ports on the brainstorm.thm machine. In the end, we brute forced the answer. Task 2 - A...

NahamCon2021 CTF - Ret2basic - Writeup

Image
Introduction Today we're doing a CTF writeup for the Ret2basic challenge from the NahamCon2021 CTF. Ret2basic is a binary exploit challenge, and after we start the challenge we received a string we can use to interact with the challenge: We also have to download the binary file associated with the challenge so we can enumerate it. After we download the file, we chmod it to make it executable, then start it up: chmod +x ret2basic ./ret2basic Now, in another terminal, we start up edb : edb Then from the file tab, we Attach , then select our running ret2basic process. Now we want to identify the functions in the binary. From the Plugins tab, we select SymbolViewer : In this list, we can see all of the functions the ret2basic binary calls, as well as their associated memory address. One in particular catches our eye: This is most likely the function and memory address we want to instruct the RIP register to go to after we find the correct offset buffer to control it. Before we f...