Posts

Showing posts with the label hack the box

Hack the Box - Emdee Five For Life Challenge - Walkthrough

Image
Introduction Today we're going to be doing a CTF challenge walkthrough of the Emdee Five for Life challenge hosted at https://app.hackthebox.eu/challenges/67 . Emdee five for life is a cryptography and scripting challenge. For this walkthrough, we'll be using a Kali Linux virtual machine as our attacking system. After starting the challenge instance, we find that the associated URL is http://139.59.178.146:30204/ . The challenge's description is as follows: CHALLENGE DESCRIPTION Can you encrypt fast enough? Initial Enumeration From the challenge name and description, we can guess that MD5 encryption will play a part in completing the challenge. Let's visit the challenge URL : http://139.59.178.146:30204/  We can copy the string, then use the MD5sum command to return a MD5 -encrypted version of the string: echo -n "dc4YGQyrs6q9BsIAituO" | md5sum Then we copy the output of the command and submit it to the web form, which results in this: We kn...

Hack the Box - MarketDump Challenge - Walkthrough

Image
Introduction Today we're going to be doing a CTF challenge walkthrough of the MarketDump challenge hosted at https://app.hackthebox.eu/challenges/66 . For this walkthrough, we'll be using a Kali Linux virtual machine as our attacking system. The challenge's description is as follows: CHALLENGE DESCRIPTION We have got informed that a hacker managed to get into our internal network after pivoiting through the web platform that runs in public internet. He managed to bypass our small product stocks logging platform and then he got our costumer database file. We believe that only one of our costumers was targeted. Can you find out who the customer was? Initial Information and Clues The downloaded file that accompanies this challenge is a file named MarketDump.zip , which is password protected (password = hackthebox ). After unzipping the file, we find that the file in question is called MarketDump.pcapng , which we can analyze using Wireshark . But before we open the file in ...

Hack the Box - Nest - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Nest machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Nest machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.100.97 Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.100.97 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p445,4386 10.129.100.97 There seems to be an unusual service running on port 4386.  Let's check it out using Netcat : netcat -C 10.129.100.97 4386 After some research, we can't find any info on this service, so we assume it's a custom network app.  Specifically, accessing the service using Netcat requires the -C switch to work, since the app requires the Carriage Return t...