Posts

Showing posts with the label ctf writeup

Hack the Box - MarketDump Challenge - Walkthrough

Image
Introduction Today we're going to be doing a CTF challenge walkthrough of the MarketDump challenge hosted at https://app.hackthebox.eu/challenges/66 . For this walkthrough, we'll be using a Kali Linux virtual machine as our attacking system. The challenge's description is as follows: CHALLENGE DESCRIPTION We have got informed that a hacker managed to get into our internal network after pivoiting through the web platform that runs in public internet. He managed to bypass our small product stocks logging platform and then he got our costumer database file. We believe that only one of our costumers was targeted. Can you find out who the customer was? Initial Information and Clues The downloaded file that accompanies this challenge is a file named MarketDump.zip , which is password protected (password = hackthebox ). After unzipping the file, we find that the file in question is called MarketDump.pcapng , which we can analyze using Wireshark . But before we open the file in ...

NahamCon2021 CTF - Shoelaces - Writeup

Image
Introduction Today we're doing a CTF writeup for the Shoelaces challenge from the NahamCon2021 CTF. Shoelaces is (ostensibly) a steganography challenge and after we started the challenge we downloaded our file: And now to run strings on the file to see if there's any interesting text in the image info: strings -8 shoelaces.jpg Summary After downloading the image file, we ran the Strings command to check if there was any relevant text in the image file, and were thus able to access our objective flag string. Finish

NahamCon2021 CTF - Esab64 - Writeup

Image
Introduction Today we're doing a CTF writeup for the esab64 challenge from the NahamCon2021 CTF. esab64 is a cryptography challenge and after we started the challenge we downloaded the associated file and read it:  cat esab64 With a filename that includes the number 64 in it, we would suspect that it's base64 encoded, but just to make sure, we'll check the number of characters in the string. If it's a multiple of 4, then we can try using base64 decode on it: wc esab64 52 is a multiple of 4, so let's try the base64 decode: base64 -d esab64 That's not an answer, but looking closer at the filename, esab is the word base reversed. So let's rev the file, and pipe it into base64 decode: rev esab64 | base64 -d We're definitely on the right track, because we see galf , the reverse of flag , in the output. Now let's do the same thing as before, but pipe an extra rev at the end: rev esab64 | base64 -d | rev Summary The f...

NahamCon2021 CTF - Buzz - Writeup

Image
Introduction Today we're doing a CTF writeup for the Buzz challenge from the NahamCon2021 CTF. Buzz is a file compression challenge and after we started the challenge we downloaded the associated file we checked what kind of file it was: file buzz Seems to be a compressed file, but no specific type is identified. We try decompressing it with Gzip , a common compression program: gzip -d buzz Gzip won't interact with any files that don't have the .gz file extension, so let's add it: mv buzz buzz.gz Now let's try again: gzip -d buzz Seems to have worked. Let's check the buzz file's type again: file buzz It worked. Let's read the file: cat buzz Summary The downloaded file appeared to be compressed upon inspection. Upon renaming the file to add a common file-compression extension, we were able to decompress the file and read it, accessing the objective flag string. Finish

NahamCon2021 CTF - Pollex - Writeup

Image
Introduction Today we're doing a CTF writeup for the Pollex challenge from the NahamCon2021 CTF. Pollex is a steganography challenge and after we started the challenge we downloaded the associated file we checked what kind of file it was:  file pollex This looks like a regular jpg file. Let's check its exif info with Exiftool : The output from the Exiftool tells us that there's an embedded thumbnail in the file, also the thumbnail is embedded as binary data. We can extract embedded binary thumbnail data from images using Exiftool by supplying the following command: exiftool -b -a -preview:all -W /home/kali/walks/ctf/nahamcon2021/%f_%t%-c.%s pollex The file that was created is named pollex_ThumbnailImage.jpg.  Let's view it now: xdg-open pollex_ThumbnailImage.jpg Summary After downloading the file, we used Exiftool to analyze it, discovering that there was a thumbnail embedded in the image. Using Exiftool, we extracted the thumbnail and viewed it, revealed our ob...

NahamCon0212 CTF - Sensible - Writeup

Image
Introduction Today we're doing a CTF writeup for the Sensible challenge from the NahamCon2021 CTF. Sensible is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge:  First, we authenticate into the system using leo's credentials which we captured in a previous challenge: ssh -p 30010 leo@challenge.nahamcon.com input password: constelleorising After some enumeration, we find that there is an interesting file in the /opt/playbooks directory: cd /opt/playbooks ls This file, and the /playbooks directory's presence on the system points to this system running the Ansible configuration management program. We will try to confirm this: which ansible This implies that Ansible is indeed installed on this system. Let's take a look at the getinfo.yaml file: cat getinfo.yaml We see that there is a hash for the Ansible vault here. We can crack this hash after converting it into a format that John the Ripper...

Nahamcon2021 CTF - Banking On It - Writeup

Image
Introduction Today we're doing a CTF writeup for the Banking On It challenge from the NahamCon2021 CTF. Banking On It is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge: First, we login to the server as the gus user, using an SSH private key captured from a previous challenge: ssh -i guskey.txt -p 31608 gus@challenge.nahamcon.com First, let's see if our user has any special sudo privileges: sudo -l Our user can run the SETENV command as root without a password when using the bank program in the /opt/banking/ directory. That means that if we're able to create a malicious shared object (.so) file, we can use the SETENV LD_PRELOAD command to activate the malicious .so file and elevate our privileges. First, let's see if there's a compiler on the system we can use to compile our .so file. which gcc That being confirmed, we move to a publicly writable directory and create our malicious...

Nahamcon2021 CTF - Internal - Writeup

Image
Introduction Today we're doing a CTF writeup for the Internal challenge from the NahamCon2021 CTF. Internal is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge: The first thing we do is log in to the system as the orion user using captured SSH credentials we obtained from a a previous challenge: ssh -p 30718 orion@challenge.nahamcon.com input password: stars4love4life While enumerating running processes, we find some interesting stuff: ps -aux The root user is running MySQL as well as a Bash script that references MySQL . Let's take a look at that Bash script: cat /create_mysql_admin_user.sh The information in the script indicates that the root account in MySQL is setup without a password. Let's login to MySQL as root now: mysql -uroot -p input a blank password Using MySQL as the root user, we can read any files in the system that we are aware of. Because the common location of the flag.tx...