{"id":76,"date":"2022-07-17T22:09:05","date_gmt":"2022-07-17T22:09:05","guid":{"rendered":"http:\/\/moveax.me\/?p=76"},"modified":"2022-08-31T19:02:06","modified_gmt":"2022-08-31T19:02:06","slug":"nebula-level16-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level16-a-newbies-approach\/","title":{"rendered":"Nebula Level16: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Just like&nbsp;<a href=\"nebula-level07\/\">level07<\/a>, level16 has a Perl&nbsp;<a href=\"\">script<\/a>&nbsp;that we need to analyze and has also a vulnerability as expected: input not sanitized. Let\u2019s exploit it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Perl<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level16<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As stated in the main page of this challenge, level16 has a script running on port 1616. We can see that the script is composed by two subroutines, login and htmlz. Also, it\u2019s possible to understand from this script that the username will be converted to all uppercase and everything after a space will be stripped away.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We can exploit the program by taking advantage from the line 14, where a shell command is executed. I\u2019m going to exploit the challenge in the same way that I did for level07, I\u2019ll make this Perl script compile a SUID program so I can get a shell under flag16 account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You should know the SUID code by now\u2026<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/SUID.png\" alt=\"SUID\" class=\"wp-image-793\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">To compile this C code, we must pass a tiny shell program which performs this task.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/COMP.png\" alt=\"Compiler\" class=\"wp-image-794\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">I\u2019m keeping all the files in \/tmp directory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, to start exploiting this exercise you can either use&nbsp;<a href=\"https:\/\/linux.die.net\/man\/1\/curl\">curl<\/a>&nbsp;or netcat. You can even use a file where you write your commands and then redirect the content to one of these commands. I\u2019ll use netcat in my examples.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, connect to the program is as simple as entering the command&nbsp;<em>nc 127.0.0.1 1616<\/em>. After this, the prompt will be waiting for input. Because line 11 will convert every letter to uppercase, our shell script that will compile our SUID program needs to have an uppercase name. But now the location of that file is a problem\u2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So our command to inject will be&nbsp;<code>`\/*\/COMP`<\/code>. As level07, we\u2019ll have to encode this command in hexadecimal, where the command will become&nbsp;<em>%60%2f%2a%2f%43%4f%4d%50<\/em>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our final command will be&nbsp;<em>GET \/index.cgi?username=%60%2f%2a%2f%43%4f%4d%50%60<\/em>. Here it is.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/executing.png\" alt=\"Execution\" class=\"wp-image-796\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now, it\u2019s just a matter of running the SUID.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/result_level16.png\" alt=\"Result Level16\" class=\"wp-image-797\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Done! 3 challenges left.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 17\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Same as&nbsp;<a href=\"nebula-level07\/\">level07<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/www.youtube.com\/watch?v=tC7e9jySIk4=01m45s\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Further Reading<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-1885\/Perl.html\">Perl: Security Vulnerabilities<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Just like&nbsp;level07, level16 has a Perl&nbsp;script&nbsp;that we need to analyze and has also a vulnerability as expected: input not sanitized. Let\u2019s exploit it. What you\u2019ll&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level16-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level16: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-76","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/76","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=76"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/76\/revisions"}],"predecessor-version":[{"id":121,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/76\/revisions\/121"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=76"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=76"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=76"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}