{"id":66,"date":"2022-07-17T22:05:58","date_gmt":"2022-07-17T22:05:58","guid":{"rendered":"http:\/\/moveax.me\/?p=66"},"modified":"2022-08-31T19:01:22","modified_gmt":"2022-08-31T19:01:22","slug":"nebula-level08-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level08-a-newbies-approach\/","title":{"rendered":"Nebula Level08: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In this challenge, we will need to analyze a pcap file in order to discover the password to flag08 account. Level08 will make us use some very useful tools, like Wireshark or tcpdump. I\u2019ll use Wireshark because I more acquainted with it, but you can use any other tool of network traffic analysis. Actually, I\u2019ve been using tcpdump on daily basis, but I think I don\u2019t yet have the skills to solve the level08 challenge.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Wireshark<\/li><li>Basic Unix Commands<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level08<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For level08 challenge, we have a pcap file under the \/home\/flag08 folder. If you want to analyze the file inside the virtual machine, it\u2019s probably better to use tcpdump, but I advise you to extract the file to some environment where you have access to Wireshark.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, when you fire up Wireshark, you can notice two things right away. First, all the communication is done through TCP and second, the only parties involved in this connection are 59.233.235.218 and 59.233.235.223. You can start by analyzing all the data in every single TCP packet, but it\u2019s better if you make use of Wireshark capabilities, and reconstruct the entire communication in a more friendly way. To do so, right click in one packet and select \u201cFollow TCP Stream\u201d.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/wireshark.png\" alt=\"wireshark\" class=\"wp-image-664\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">When you do this, a small window pops up, with the data of all packets assembled, so you can understand what is going on.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/wireshark-1.png\" alt=\"data\" class=\"wp-image-666\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The red packets are the ones that the client sent and in blue those that the server sent. Notice that at the bottom of the window, you can see that the data is presented as ASCII.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every time that Wireshark can\u2019t print a character, it will replace that character with a dot, that\u2019s why you see a password like \u201cbackdoor\u202600Rm8.ate\u201d. To understand what the dots are, we can analyze all the data in the packets OR\u2026 we can display the data as \u201cHex Dump\u201d (Work smarter, not harder\u2026).<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/data_hex_dump.png\" alt=\"Hex Dump Data\" class=\"wp-image-667\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In the middle column, you can see the ASCII codes that represents mostly letters. Also, all the dots (except the last one) represent the \u201c7F\u201d ASCII code which is the \u201cDEL\u201d character. The last dot is the \u201cCR\u201d, carriage return, which basically means the enter key was pressed. This, means that every time one dot pops up, a character of the password was deleted. This makes our password be \u201cbackd00Rmate\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s try to login in flag08 account and get the flag to level08 challenge.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/solution-2.png\" alt=\"Level08 solution\" class=\"wp-image-668\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">We did it!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 9\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">I think that the first solution that comes to me is not using this kind of applications, I mean, whose data is transferred as clear text (aka unencrypted) through the wire.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One good example here, is the Telnet protocol which sends everything in clear text. I think is now safe to say that the majority of admins (or people in general) prefer to use SSH, which does not sent unencrypted traffic and is much more robust when compared to Telnet.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Nebula Level 5-9\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/ICeUE6c7SoM?start=334&#038;feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Further Reading<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/medium.com\/@weblab_tech\/encrypted-client-server-communication-protection-of-privacy-and-integrity-with-aes-and-rsa-in-c7b180fe614e\">Encrypted client-server communication<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>In this challenge, we will need to analyze a pcap file in order to discover the password to flag08 account. Level08 will make us use&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level08-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level08: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-66","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/66","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"predecessor-version":[{"id":110,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/66\/revisions\/110"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}