{"id":64,"date":"2022-07-17T22:05:42","date_gmt":"2022-07-17T22:05:42","guid":{"rendered":"http:\/\/moveax.me\/?p=64"},"modified":"2022-08-31T19:01:18","modified_gmt":"2022-08-31T19:01:18","slug":"nebula-level07-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level07-a-newbies-approach\/","title":{"rendered":"Nebula Level07: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">For the level07 challenge we have some Perl code to analyze. This code is available both on the Virtual Machine and the&nbsp;<a href=\"\">page<\/a>&nbsp;of the challenge.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Perl basics<\/li><li>Webservers<\/li><li>Netcat<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level07<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In this level07, we\u2019ll need to operate a webserver.<br>For that, we\u2019ll use netcat to connect to the webserver. You can see on what port the webserver is listening by looking at the file thttpd.conf under the option \u201cport\u201d.<br>After connecting to the server, you can give him&nbsp;<a href=\"https:\/\/www.w3schools.com\/tags\/ref_httpmethods.asp\">HTTP methods<\/a>, for example GET, if you want to request something from the server.<br>Now, let\u2019s give the server the following command: \u201cGET \/index.cgi?Host=localhost HTTP\/1.1\u201d and on the next line \u201cHost: localhost\u201d. The webserver, will ping the localhost, under flag07 user. So if we use chaining commands once more, we should be able to have the server running commands for us.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/test.png\" alt=\"Test connection\" class=\"wp-image-647\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Ok, but type all of that while testing is boring, so let\u2019s put it in a file redirect it to netcat. Just use the command \u201cnc localhost 7007 &lt; file\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, for me, the next step is to create the SUID program (the same that we used for multiple exercises). Then, I\u2019ll create a simple script to compile the C program and to set the SUID bit. Here\u2019s what my C program looks like.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/nefarious.c.png\" alt=\"nefarious.c\" class=\"wp-image-648\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">And here is my shell script.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/nefarious.sh_.png\" alt=\"nefarious.sh\" class=\"wp-image-649\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now we just need to update the file that we\u2019ll pass to the netcat. Remember that, to send multiple commands at the same time to the shell, we need to use \u201c;\u201d, but we\u2019ll have to code them so that the webserver won\u2019t interpret these characters. To do that, we just need to use the % symbol, followed by the number in hexadecimal that represents that char in the ASCII table. Here\u2019s the file that I\u2019ll pass to the netcat connection. One advice: place all the files in the \/tmp folder, so that you won\u2019t have problems with permissions.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/http_query.png\" alt=\"HTTP Query\" class=\"wp-image-650\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Notice that all the reserved characters were encoded. If you now make the connection to the webserver using netcat, feeding it the file with the HTTP request, you\u2019ll the same output as the first image. But when you look into the \/home\/flag07 folder you can see our moveaxme SUID program.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/files2.png\" alt=\"SUID program for level07\" class=\"wp-image-651\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now, it\u2019s just a matter of running this little program and you\u2019ll have a shell under the flag07 account. After that, just collect the flag.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/result_level07.png\" alt=\"Result of level07\" class=\"wp-image-652\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Solved!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 8\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Input validation and sanitization is something very important regarding not just webservers, but all kinds of applications. So, if the idea of the program was just getting some IP to ping, the program would only allow the dot symbol in the string given by the user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Never trust the input!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Nebula Level 5-9\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/ICeUE6c7SoM?start=170&#038;feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>For the level07 challenge we have some Perl code to analyze. This code is available both on the Virtual Machine and the&nbsp;page&nbsp;of the challenge. What&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level07-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level07: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-64","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/64","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=64"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/64\/revisions"}],"predecessor-version":[{"id":109,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/64\/revisions\/109"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=64"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=64"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=64"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}