{"id":84,"date":"2022-07-17T22:10:43","date_gmt":"2022-07-17T22:10:43","guid":{"rendered":"http:\/\/moveax.me\/?p=84"},"modified":"2022-07-17T22:14:55","modified_gmt":"2022-07-17T22:14:55","slug":"nebula-level12-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level12-a-newbies-approach\/","title":{"rendered":"Nebula Level12: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Level12 shows again the problem of input sanitization, demonstrated on one small Lua program. As usual, let\u2019s try to obtain a shell under flag12 account.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Lua programming language<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level12<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">First time using Lua, here. I knew about this programming language, but never had the opportunity to try it, although, it was (is \ud83d\ude42 ) on my TODO list.<br>So, we have a small program listening on port 50001. When you connect to it, it will ask for a password, hash it and try to match it against a hard coded hash.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/Overview.png\" alt=\"Overview\" class=\"wp-image-731\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><br>In order to calculate the hash, the program resort on the popen function, which will run a shell command. I\u2019m going to solve this one quickly, using the trick applied in the&nbsp;<a href=\"nebula-level11\">last exercise<\/a>. I\u2019ll place the SUID program and its compiler in the \/tmp directory and make the program compile it.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/commands.png\" alt=\"commands\" class=\"wp-image-732\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In this last image, I make use of chaining commands. The reason is because the command being executed will be \u201cecho&nbsp;<em>password<\/em>&nbsp;| sha1sum\u201d, so I fed something to the echo and ended that command with \u201c;\u201d separator,&nbsp; in order to execute more commands. I made the flag12.lua execute my bash script that compiles the SUID program and I commented the rest of the original command, using the \u201c#\u201d symbol. The result of this execution can be found on the next image.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/suid-1.png\" alt=\"SUID\" class=\"wp-image-734\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now, we just need to execute this program, which is owned by flag12 and will run under the flag12 account, instead of level12.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/06\/result_level1.png\" alt=\"Result level12\" class=\"wp-image-733\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">There you go!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 13\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once again, we can see the nefarious outcomes of passing input directly from a user to a program, without sanitization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From what I read, there are some implementations of SHA1 in Lua, but in any case, if you want to make a system call in order to compute the hash, ensure that no negative outcome will rise and, most important, test it!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Nebula Level 10-14\" width=\"500\" height=\"375\" src=\"https:\/\/www.youtube.com\/embed\/xGOqq_6blPo?start=314&#038;feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Further Reading<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"http:\/\/seclists.org\/fulldisclosure\/2014\/May\/128\">Lua Web Application Security Vulnerabilities<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Level12 shows again the problem of input sanitization, demonstrated on one small Lua program. As usual, let\u2019s try to obtain a shell under flag12 account.&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level12-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level12: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-84","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/84","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=84"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/84\/revisions"}],"predecessor-version":[{"id":90,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/84\/revisions\/90"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=84"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=84"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=84"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}