Posts

Showing posts with the label cryptography

TryHackMe - Hashing - Crypto 101 - Walkthrough

Introduction Today we're going to be doing a walkthrough for the Hashing - Crypto 101 room hosted at https://tryhackme.com/room/ hashingcrypto101 . For this walkthrough, we'll be using one virtual machine (VMs), the TryHackMe AttackBox, as our attacking machine. Task 1 - Key Terms Questions: Is base64 encryption or encoding? Answer can be found in this article: https://en.wikipedia.org/wiki/Base64 Task 2 - What is a hash function? Questions What is the output size in bytes of the MD5 hash function? Refer to this article for the answer (keep in mind that 1 byte = 8 bits): https://en.wikipedia.org/wiki/MD5 Can you avoid hash collisions? (Yea/Nay) Answer contained in Task description If you have an 8 bit hash output, how many possible hashes are there? The formula for determining the possible number of hashes for a hashing algorithm is 2 ^ (bit output). Therefore, the answer is 2 ^ 8. Task 3 - Uses for hashing Questions Crack the hash "d0199f51d2728db6011945145a1b607a" ...

NahamCon2021 CTF - Esab64 - Writeup

Image
Introduction Today we're doing a CTF writeup for the esab64 challenge from the NahamCon2021 CTF. esab64 is a cryptography challenge and after we started the challenge we downloaded the associated file and read it:  cat esab64 With a filename that includes the number 64 in it, we would suspect that it's base64 encoded, but just to make sure, we'll check the number of characters in the string. If it's a multiple of 4, then we can try using base64 decode on it: wc esab64 52 is a multiple of 4, so let's try the base64 decode: base64 -d esab64 That's not an answer, but looking closer at the filename, esab is the word base reversed. So let's rev the file, and pipe it into base64 decode: rev esab64 | base64 -d We're definitely on the right track, because we see galf , the reverse of flag , in the output. Now let's do the same thing as before, but pipe an extra rev at the end: rev esab64 | base64 -d | rev Summary The f...

Hack the Box - Brainfuck - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Brainfuck machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Brainfuck machine as the victim system.  After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.96.96. Scanning and Enumeration We'll start by scanning for open ports with Nmap: sudo nmap -T4 -p- 10.129.96.96 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -T4 -p22,25,110,143,443 10.129.96.96 Seeing that there's an HTTPS service open, we'll use Nmap scripts to enumerate the SSL certificate: nmap --script=ssl* -p443 10.129.96.96 We see three URLs associated with the certificate, so we'll add those URLs to our /etc/hosts file so that those addresses resolve properly in our web browser: sudo gedit /etc/hosts Now we can navigate to ...