$volatility timeliner --output=body --output-file=timeliner.txt --profile=<profile> --filename=<ram_dump> && volatility mftparser --output=body --output-file=mftparser.txt --profile=<profile> --filename=<ram_dump> && volatility shellbags --output=body --output-file=shellbags.txt --profile=<profile> --filename=<ram_dump>$cat timeliner.txt mftparser.txt shellbags.txt > timeline.txt$mactime -b timeline.txt -d > mactime.txt
# Volatility timeline
# sysdig: System-level exploration tool
Installing #curl -s https://s3.amazonaws.com/download.draios.com/stable/install-sysdig | sudo bashListing chisels #sysdig -clListing fields to filter #sysdig -lUsing a chisel #sysdig -c topprocs_cpuWriting events to file #sysdig -z -w tracefile.scap.gzReading events from file and use a chisel #sysdig -z -r tracefile.scap.gz -c topprocs_cpuFiltering events for a specific process #sysdig proc.name=sshdFiltering events for a specific file #sysdig fd.name=/var/log/auth.logFiltering events for files that contain /etc #sysdig fd.name contains /etc#sysdig evt.args contains /bin/ls#sysdig fd.ip=1.2.3.4#sysdig fd.l4proto=udpFormating the output #sysdig -p '%evt.arg.path' 'evt.type=chdir and user.name=root'Information about all chisels #sysdig -cl | grep -P '^\w' | awk '{print $1}' | grep -v -e Category -e Use | xargs -L 1 sysdig -iInteresting chisels #sysdig -c topprocs_cpu#sysdig -c echo_fds -s 2000 -A proc.name=httpd#sysdig -c echo_fds -s 2000 -A fd.port=80 and evt.buffer contains GET#sysdig -c spy_file 'RW /var/log/syslog'#sysdig -c spy_logs#sysdig -c spy_syslog#sysdig -c spy_ip 1.2.3.4#sysdig -c spy_port 443#sysdig -c topconns#sysdig -c topprocs_net#sysdig -c spy_users 0|1#sysdig -c lsof#sysdig -c netstat#sysdig -c ps#sysdig -c topfiles_bytes proc.name contains tar#sysdig -c list_login_shells ncat#sysdig -c spy_users proc.loginshellid=1234#sysdig -c stdin -c stdout proc.name=cat
Reference
https://github.com/draios/sysdig/wiki
Labels:
sysdig
# SimpleHTTPSServer with letsencrypt certificate
#apt-get update#apt-get install software-properties-common#add-apt-repository ppa:certbot/certbot#apt-get update#mkdir webserver#cd webserver#apt-get install certbot#mkdir www#certbot certonly --webroot -w $PWD/www -d mydomain.org -d www.mydomain.org#cp /etc/letsencrypt/live/mydomain.org/privkey.pem .#cp /etc/letsencrypt/live/mydomain.org/fullchain.pem .#cat privkey.pem fullchain.pem > cert.pem#cat https-server.py#python https-server.py eth0
Labels:
certbot,
certificate,
https,
letsencrypt,
python,
simplehttpsserver
# HITCON CTF 2017 Quals: Sakura - Reversing
#cat sakura.py#python sakura.pyIn [1]:sakura = Popen([fn], stdin = PIPE, stdout = PIPE)In [2]:flag = sakura.communicate(input = dump)[0]In [3]:print flag
# Pwn2Win 2k17: Baby Regex - Misc
# cat regexbaby_034fa13e17660024b26b6f570aa6b66bba446e2f837c052f012225190387bafa.txt
#ipython>import re>data = open('regexbaby_034fa13e17660024b26b6f570aa6b66bba446e2f837c052f012225190387bafa.txt').read()>def check(regex):...print len(regex)...print re.findall(regex, data)# "from "Drivin" until the end of phrase, without using any letter, single quotes or wildcards, and capturing "Drivin'" in a group, and "blue." in another", with max. "16" chars: >check('(.{7}).+-(.{5})$')# "(BONUS) What's the name of the big american television channel (current days) that matchs with this regex: .(.)\1", with max. "x" chars: # "FLY until... Fly", without wildcards or the word "fly" and using backreference", with max. "14" chars: # "<knowing the truth. >, without using "line break"", with max. "8" chars: >check('<[^>]+>')# "All "Open's", without using that word or [Ope-], and no more than one point", with max. "11" chars: >check('(?i)(oPEn)')# "the follow words: "unfolds", "within" (just one time), "makes", "inclines" and "shows" (just one time), without using hyphen, a sequence of letters (two or more) or the words itself", with max. "38" chars: >check('(?:\s\S{2}d|t)\s([^F]\w{3,7}[n!s])\s')# "Chips" and "code.", and it is only allowed the letter "c" (insensitive)", with max. "15" chars: >check(' .{32} (.{5})\n')# Type the regex that capture: "the only word that repeat itself in the same word, using a group called "a" (and use it!), and the group expression must have a maximum of 3 chars, without using wildcards, plus signal, the word itself or letters different than [Pa]", with max. "16" chars: >check('(?P<a>..a)(?P=a)')
#cat baby_regex.py#python baby_regex.py
References
https://www.regexpal.com
https://www.debuggex.com
# GynvaelEN mission 018
# curl 'http://gynvael.coldwind.pl/c3459750a432b7449b5619e967e4b82d90cfc971_mission018/admin.php?password1=240610708&password2=10932435112'
#curl 'http://gynvael.coldwind.pl/c3459750a432b7449b5619e967e4b82d90cfc971_mission018/superadmin.php'_:)
Source
https://www.youtube.com/watch?v=adHOlKKbFXM (2:00:22)
References
https://www.whitehatsec.com/blog/magic-hashes/
# GynvaelEN mission 017
zeros = '\x00'*32
base64.b64encode(zeros)
'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA='
Cookie: mission017session=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
ivencrypted.encode('hex') = '927a00302d2e13896de885ece9f3445d2de83b880d2043a6ecc6e8bbb0a831dc'
result = ''
new = '{"access_level":"admin"}'
for i in range(len(new)):
result += chr(ord(new[i]) ^ ord(ivencrypted[i]))
base64.b64encode(result) == 6VhhU05LYPoyhOCajJ9mZw+JX+VkTmHb
Cookie: mission017session=6VhhU05LYPoyhOCajJ9mZw%2BJX%2BVkTmHb
Decrypted cookie data: {"access_level":"admin"}
Flag: HMAC? What do you mean "HMAC"?Source
https://www.youtube.com/watch?v=9xGgZUMNl2Y (2:05:00)
References
https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation
# GynvaelEN mission 016
Wav to image using RX-SSTV
Slow-scan TV is a method to transmit an image over radio using frequency modulation.
This is the partial message that contains the image:
? ? R O N D I Y M A U Z ? ? ? B C K P ? ? ? V W X Y DHXDMW BQLF KDYNV
Manual decryption
Y D = I A HX = ?? DM = AY W B = ? P QL = ?? F K = ? ? DY = IM NV = RX I A??AY? P??? ?AIRX ---> I ALWAYS PLAY FAIRX
Source
https://www.youtube.com/watch?v=locDS3uHv_E (2:03:00)
References
https://en.wikipedia.org/wiki/Slow-scan_television
Labels:
challenge,
crypto,
gynvael,
sstv,
steganography
# EkoParty CTF 2017: OnTheWire (300) - Misc
Introduction
We have sniffed some bytes of a transmission. What does it say?
51 91 51 31 51 71 112 31 51 123 91 71 95 127 121 51 112 95 121 121 91 71 112 126 112 112 95 79 121 121 95 51 91 71 112 123 121 126 112 91 112 109 91 71 95 51 121 48 112 121 112 126 95 78 121 51 112 123 112 61
Hint
You will see the flag in a lcd display
Solution
#cat onthewire.py#python onthewire.py
Reference
https://en.wikichip.org/wiki/seven-segment_display/representing_letters
# GynvaelEN mission 015
#cat mission_15.py#python mission_15.py
Source
https://www.youtube.com/watch?v=BQRX3owv2JI (1:57:30)
Labels:
bruteforce,
challenge,
crypto,
gynvael,
steganography
# GynvaelEN mission 014
#cat mission_14.py#python mission_14.py
Source
https://www.youtube.com/watch?v=rhsH-snYkIc (1:55:36)
# GynvaelEN mission 013
#cat parser.py#tshark -nr session.pcapng -T fields -e data -qz follow,tcp,raw,3|tail -n +7| tr -d '=\r\n\t'|less|xxd -r -p > follow_tcp_stream3#python parser.py follow_tcp_stream3 vfile#ls 2f*#cat 2f70726f632f353937392f6d617073.bin#python parser.py follow_tcp_stream3 memory 55555555#r2 55555555.bin[0x00000000]>s 0x00004831[0x00004831]>pd 44[0x00004831]>s 0x4909[0x00004909]>pd 58#ipythonIn [1]:table = [0x8e, 0x32, 0x2f, 0x39, 0xea, 0x2d, 0x27, 0x39, 0xea, 0x27, 0xea, 0x88, 0x25, 0x94, 0x3b, 0x30, 0x39, 0x2f, 0x29, 0x39, 0xea, 0x2e, 0x27, 0x39, 0x31, 0xea, 0x8f, 0xea, 0x5d, 0x2b, 0x5b, 0x39, 0x39, 0xf0]...:r = ''...:for e in table:...:r += chr(((((e - 0x63) ^ 0x5a) - 0x63) ^ 0x5a) & 0xff)...:print r...:
Source
https://www.youtube.com/watch?v=7zTtVYjjquA (1:58:10)
Reference
https://sourceware.org/gdb/onlinedocs/gdb/Remote-Protocol.html
# GynvaelEN mission 012
#curl -s http://www.computer-engineering.org/ps2keyboard/scancodes2.html | tr [:upper:] [:lower:] > scan_codes.html#for i in 12 1b 1c 23 24 29 2c 2d 31 32 35 41 42 43 44 49 4d 52 58 59; do result=`cat scan_codes.html | grep '<tt>' | grep -m1 -B1 "<tt>$i</tt>" | sed 's/<[^>]*>//g' | tr -d ' '| tr -d '\r'`; key=`echo "$result" | tail -n1`; value=`echo "$result" | head -n1`; echo "0x$key: '$value',"; done#cat keylogger.py#python keylogger.py
Source
https://www.youtube.com/watch?v=4Xo_FAx6P0A (1:51:20)
Done in collaboration
https://atorralba.github.io/
Labels:
challenge,
gynvael,
keyboard,
keylogger,
scan_codes
# GynvaelEN mission 011
#cat mission_11-firmware.txt#cat mission_11.py#python mission_11.py
Source
https://www.youtube.com/watch?v=s5gOW-N9AAo (1:46:20)
# GynvaelEN mission 010
#cat mission_10.py#python mission_10.py
Source
https://www.youtube.com/watch?v=Vs8PLpHCoNY (1:45:30)
# GynvaelEN mission 009
#cat mission_09.py#python mission_09.py
Source
https://www.youtube.com/watch?v=7RotbY17tKk (1:47:55)
Reference
https://en.wikipedia.org/wiki/COFF
# Decrypt Wildfly/Jboss vault passwords
#cat standalone.xml#cat vaultbreaker.py#python vaultbreaker.py 3y28rCZlcKR vault 12438567 50 vault.store vault.dat
Reference
https://developer.jboss.org/wiki/JBossAS7SecuringPasswords
Done in collaboration
https://atorralba.github.io/
# GynvaelEN mission 008
#cat mission_08.py#python mission_08.py
Source
https://www.youtube.com/watch?v=OAk23u9b-88 (1:50:10)
# GynvaelEN mission 007
#cat parser.py#python parser.py report.zip#cat generate_zipfiles.py#python generate_zipfiles.py report.zip
Source
https://www.youtube.com/watch?v=z9hfkajoAvc (1:25:15)
References
https://en.wikipedia.org/wiki/Zip_(file_format)
https://pkware.cachefly.net/webdocs/casestudies/APPNOTE.TXT (4.4.5)
https://github.com/corkami/pics/blob/master/binary/zip101/zip101.pdf
# An XOR alternative
#cat xor_alternative.py#python xor_alternative.py o SECRET 1234#python xor_alternative.py d c+=c=+ch=cc= 1234
Reference
https://isc.sans.edu/forums/diary/Obfuscating+without+XOR/22544/
Labels:
obfuscation,
xor
Subscribe to:
Posts (Atom)