{"id":52,"date":"2022-07-17T22:04:02","date_gmt":"2022-07-17T22:04:02","guid":{"rendered":"http:\/\/moveax.me\/?p=52"},"modified":"2022-08-31T19:01:49","modified_gmt":"2022-08-31T19:01:49","slug":"nebula-level01-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level01-a-newbies-approach\/","title":{"rendered":"Nebula Level01: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Still under the SUID programs category, level01 makes use of another trick in order to be solved, the manipulation of environment variables.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Use ln command<\/li><li>Environment Variables<\/li><li>Other basic Unix commands<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level01<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If we analyze the code of level01 program, one of the first things that I notice is the use of a C function, system, and although it&nbsp;<em>doesn\u2019t<\/em>&nbsp;receive input from the user, it\u2019s still exploitable. Time to run the flag01 program.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/flag01_run.png\" alt=\"Flag01\" class=\"wp-image-547\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This output is (obviously) caused by the system function, more specifically by the \u201c<em>echo and now what?\u201d<\/em>. But how about the \u201c\/usr\/bin\/env\u201d? Imagine that you have multiple programs in your system called&nbsp;<em>echo<\/em>. Which one will be executed? The answer is the first one that appears in the PATH variable. This is ensured by the \u201c\/usr\/bin\/env\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To find out where the&nbsp;<em>echo<\/em>&nbsp;is located, run the command \u201cwhich echo\u201d.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/which.png\" alt=\"which\" class=\"wp-image-548\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Then, cross-reference the path resultant with the paths in the PATH variable.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/path.png\" alt=\"path\" class=\"wp-image-549\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Notice the folder that contains the echo program, it\u2019s almost the last one. If we were able to put an echo program in some other folder that appears before \/bin, that would be the one that would run. But we don\u2019t have write permissions on any of those\u2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the solution is to append to the beginning, a location where we actually can write, \/home\/level01.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/printenv.png\" alt=\"printenv\" class=\"wp-image-551\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now, my goal is to get a shell, so I\u2019ll create a little C program called echo.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/echo.png\" alt=\"echo.c\" class=\"wp-image-553\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">I compile the program using the command \u201cgcc -o echo echo.c\u201d and now I have a little program that gives me a shell.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before I run the flag01 let\u2019s recap. We have a program called flag01 that will call the first echo program it finds in the environment variable PATH. The first entry in this variable is \/home\/level01, inserted by us, and this folder contains an echo program written also by us, which will give us a shell.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s check the current user, run the program and get the flag.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/solution.png\" alt=\"Solution of level01\" class=\"wp-image-554\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Another solution, and if you didn\u2019t want a shell, would be with symbolic links. Once more, we can add \/home\/level01 to the PATH and in this folder, place a symbolic link called echo which points to \/bin\/getflag. So, when you run the flag01 program, the following happens\u2026<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/another_solution.png\" alt=\"Another Solution for level01\" class=\"wp-image-563\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 2\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Same advice as&nbsp;<a href=\"nebula-level00\/\">level00<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">https:\/\/youtube.com\/watch?v=hxjN-xASoaw%3Fstart%3D54%26feature%3Doembed<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Further Reading<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.cyberciti.biz\/faq\/set-environment-variable-unix\/\">UNIX: Set Environment Variable<\/a><\/li><li><a href=\"https:\/\/www.nixtutor.com\/freebsd\/understanding-symbolic-links\/\">Understanding Symbolic Links<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Still under the SUID programs category, level01 makes use of another trick in order to be solved, the manipulation of environment variables. What you\u2019ll need&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level01-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level01: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-52","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/52","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=52"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/52\/revisions"}],"predecessor-version":[{"id":117,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/52\/revisions\/117"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=52"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=52"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=52"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}