{"id":46,"date":"2022-07-17T22:02:22","date_gmt":"2022-07-17T22:02:22","guid":{"rendered":"http:\/\/moveax.me\/?p=46"},"modified":"2022-07-18T00:24:19","modified_gmt":"2022-07-18T00:24:19","slug":"nebula-level00","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level00\/","title":{"rendered":"Nebula Level00: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Level00 falls in the category of SUID files which is something that I heard about but never had any practical experience. The goal here is to collect the flag through the&nbsp;<em>getflag<\/em>&nbsp;command.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>find command<\/li><li>Other basic Unix commands<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level00<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The&nbsp;<a href=\"\">instructions<\/a>&nbsp;for level00 state that we need to find a SUID program which run as flag00 account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First things first. A Set User ID (SUID) program is a risky type of file that can run with the privileges of another user, for instance, root. This Linux feature allows to improve security when properly used, but is can also be very nefarious when incorrectly used. Here\u2019s an example of a SUID program.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/level00_suid.png\" alt=\"Ping\" class=\"wp-image-524\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Notice that under the owner permissions, instead of an \u201cx\u201d you have a \u201cs\u201d which means this is a SUID program and will run as root when you execute it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, let\u2019s see how will we going to discover that file.<br><a href=\"https:\/\/linux.die.net\/man\/1\/find\">Find<\/a>&nbsp;command allows you to search for files owned by a specific user, which is accomplished with the \u201c-user\u201d option. But if you try it, you\u2019ll a lot of \u201cPermission denied\u201d, so your command should be something like \u201cfind \/ -user flag00 2&gt;\/dev\/null\u201d. \u201c2&gt;\/dev\/null\u201d means that we\u2019ll redirect the stderr to the null device, which means that you throw out all the lines with errors.<br>After running that command we still have a few files. Let\u2019s narrow it down by filtering for those that have the SUID bit set, using the \u201c-perm\u201d option.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Your final command should be \u201c<strong>find \/ -user flag00 -perm -4000 2&gt;\/dev\/null<\/strong>\u201c.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After running it, you get only two files and if you run the first one, you\u2019ll login in flag00 account. From here, you can just run the getflag command and obtain your trophy of level00.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/level00_solution.png\" alt=\"Nebula level00 solution\" class=\"wp-image-527\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 1\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As one can imagine, the simplest way to prevent vulnerabilities through SUID programs is not writing them in the first place. If for some reason you really need to write this type of programs, make sure you don\u2019t give an interface to the user that allows him to write commands. If you can\u2019t, make sure to sanitize all the input.<br>Always do a proper inventory and account for the SUID programs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Level00 falls in the category of SUID files which is something that I heard about but never had any practical experience. The goal here is&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level00\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level00: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-46","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/46","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=46"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/46\/revisions"}],"predecessor-version":[{"id":104,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/46\/revisions\/104"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=46"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=46"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=46"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}