{"id":74,"date":"2022-07-17T22:08:46","date_gmt":"2022-07-17T22:08:46","guid":{"rendered":"http:\/\/moveax.me\/?p=74"},"modified":"2022-08-31T19:02:03","modified_gmt":"2022-08-31T19:02:03","slug":"nebula-level17-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level17-a-newbies-approach\/","title":{"rendered":"Nebula Level17: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On level17 we have a python script listening on port 10007. In order to solve this challenge we\u2019ll have to connect to this port and provide some input.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Python<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level17<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Looking at the code, we can identify one module, known to be vulnerable. On top of that, it accepts input from the user, so it\u2019s probably a good place to start testing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before we actually start doing something, take a look at the documentation of&nbsp;<a href=\"https:\/\/docs.python.org\/2\/library\/pickle.html\">pickle<\/a>&nbsp;module. It allows to serialize and de-serialize Python structures.<br>Let\u2019s run an example.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/example_py.png\" alt=\"Example\" class=\"wp-image-807\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">If we execute this python script, it\u2019ll produce a file, pickled.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/files.png\" alt=\"Files\" class=\"wp-image-808\"\/><\/figure>\n<\/div>\n\n\n<figure class=\"wp-block-image\" id=\"attachment_809\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/pickled.png\" alt=\"pickled\" class=\"wp-image-809\"\/><figcaption>Contents of pickled<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Now, let\u2019s feed the main python script this file.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/test_example.png\" alt=\"Test\" class=\"wp-image-810\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This pickle module was new for me, so I did some research and end up finding a BlackHat&nbsp;<a href=\"https:\/\/www.slideshare.net\/sensepost\/sour-pickles\">presentation<\/a>&nbsp;by Marco Slaviero. I\u2019ll use his technique to solve challenge level17.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Like the&nbsp;<a href=\"nebula-level16\/\">previous<\/a>&nbsp;exercise, I\u2019ll take advantage of this vulnerability to compile a SUID program. Let\u2019s take a peek my pickled file.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/exploit.png\" alt=\"pickled_malicious\" class=\"wp-image-811\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Simple. Now it\u2019s just a matter of feeding this file to the program running on port 10007. For this, use&nbsp;<code>nc 127.0.0.1 10007 &lt; pickled<\/code>. Exit and list the files under&nbsp;<code>\/home\/flag17<\/code>, where you\u2019ll see the following files.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/files_flag17.png\" alt=\"Files_flag17\" class=\"wp-image-812\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Run the SUID program and collect the flag&nbsp;<img decoding=\"async\" alt=\"\ud83d\ude42\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/13.0.0\/svg\/1f642.svg\"><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/result_level17.png\" alt=\"Result level17\" class=\"wp-image-813\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">One more, two left.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 18\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The easiest way to solve this problem is not using pickle at all. But I believe that in some cases this will be a half measure, because the main problem is the source of the data. So, as suggested in the previous articles, always sanitize input, don\u2019t trust any source.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/www.youtube.com\/watch?v=tC7e9jySIk4=02m56s\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Further Reading<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/lincolnloop.com\/blog\/playing-pickle-security\/\">Playing with Pickle Security<\/a><\/li><li><a href=\"https:\/\/sensepost.com\/blog\/2011\/blackhat-2011-presentation\/\">BlackHat 2011 Presentation<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>On level17 we have a python script listening on port 10007. In order to solve this challenge we\u2019ll have to connect to this port and&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level17-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level17: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-74","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/74","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=74"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/74\/revisions"}],"predecessor-version":[{"id":120,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/74\/revisions\/120"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=74"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=74"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=74"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}