At the end of this lab, you should be able to:
* use basic Linux commands during a security investigation; * use Python to automate repetitive tasks; * inspect and repair files based on their format; * identify hidden or embedded content; * interact programmatically with a web application; * use a new security analysis tool; * relate practical security problems to the concepts discussed during the first lecture.
The university has recovered an old application used for managing student grades.
Unfortunately, the administrator who maintained the application is unavailable and the documentation is incomplete.
You have received only two files from the administrator:
pass.txt bla.zip
Your goal is to recover the application, start it, authenticate to it and find the forgotten administrative interface.
Each exercise continues from the previous one.
You are encouraged to use an LLM during this lab, but use it as a technical assistant, not as a CTF solver.
Good questions include:
How can I use find to locate a file of exactly 987 bytes? What does this output from the file command mean? What is the header of a PNG file? What does this Python exception mean? How can I add a delay between HTTP requests in Python? Do not paste the complete lab, upload the archive or ask: <code> Solve this exercise for me. Here is the entire lab. Give me all the flags. Try to formulate a small question about the specific problem you are currently trying to solve. ===== Useful Tools ===== * ‘‘man’’ * ‘‘find’’ * ‘‘file’’ * ‘‘base64’’ * ‘‘xxd’’ * ‘‘hexedit’’ * ‘‘unzip’’ * ‘‘binwalk’’ * ‘‘gzip’’ * ‘‘bzip2’’ * ‘‘tar’’ * Python * ‘‘requests’’ * ‘‘curl’’ * Docker / Docker Compose ===== 01. Serious Security ===== The administrator left the following message: I am a serious security guy, so obviously I did not leave the passwords in plaintext. I protected them using Base64. Several times. You received: <code> pass.txt
Determine how the contents were encoded and recover the original information.
You may find the following commands useful:
cat pass.txt base64 -d
One decoding operation might not be enough.
Continue until you obtain readable information.
At the end of this exercise you should have a list of possible passwords.
Save the result as:
passwords.txt
You will need it in the next exercise.
The second file provided by the administrator is:
bla.zip
Unfortunately, it is password protected.
Fortunately, the administrator appears to have used one of the passwords contained in ‘‘passwords.txt’’.
Your task is to find the correct password and extract the archive.
You could try every password manually, but that would be boring.
Write a small Python program that:
* reads the passwords from ‘‘passwords.txt’’; * tries each password against ‘‘bla.zip’’; * stops when the correct password is found; * extracts the archive.
Python provides the following module:
import zipfile
You may find the documentation for ‘‘ZipFile.extractall()’’ useful.
At the end of this exercise you should have a directory containing the recovered grades application.
You now have the application files.
Unfortunately, the administrator does not remember which file contains the application configuration.
Somewhere inside the extracted directory there is a file with all of the following properties:
* human-readable; * exactly 987 bytes in size; * not executable.
Find it.
Useful commands include:
find file ls stat
Do not manually inspect every file.
Once you find the correct file, inspect its contents.
You should discover a server configuration similar to:
[server] host = 0.0.0.0 port = 0
The configured port is invalid for this application.
Change it to:
port = 8080
Now start the recovered environment:
docker compose up -d --build
Check whether the application is running:
curl http://localhost:8080
If everything worked, you should receive a response from the grades application.
You can also open:
http://localhost:8080
in your browser.
The application should now display a login page.
The application works, but you do not know the administrator password.
Fortunately, the administrator remembers something:
I took a screenshot of the admin interface that contained the login information.
The recovered application files contain:
admin-screenshot.png
Unfortunately, the screenshot appears to have been corrupted while it was being transferred.
Try inspecting the file:
file admin-screenshot.png
Then inspect the first bytes:
xxd admin-screenshot.png | head
Something is wrong with the file header.
A valid PNG file starts with the following bytes:
89 50 4E 47 0D 0A 1A 0A
Use a hex editor to repair the corrupted bytes:
hexedit admin-screenshot.png
After repairing the file:
* verify it again using ‘‘file’’; * open the screenshot; * recover the administrator username and password.
Use the credentials to log in to the grades application.
Before continuing, look again at:
admin-screenshot.png
The screenshot is not particularly large or detailed.
However:
ls -lh admin-screenshot.png
shows that the file is considerably larger than expected.
Maybe the screenshot contains more than an image.
For this exercise you will use a new tool:
binwalk
Start by running:
binwalk admin-screenshot.png
Study the output.
If Binwalk detects additional content, try extracting it:
binwalk -e admin-screenshot.png
Inspect the extracted files.
Remember that filenames and extensions are not always trustworthy.
Use:
file <filename>
when you are unsure what a file actually contains.
Your goal is to recover:
admin-backup.hex
The file recovered from the screenshot is:
admin-backup.hex
The administrator apparently had a complicated backup procedure.
The file is a hexdump of another file, which has then been compressed and archived several times using different formats.
Reverse the process.
First convert the hexdump back into binary data:
xxd -r admin-backup.hex > recovered
Then determine what kind of file you have:
file recovered
Depending on the output, you may need tools such as:
gzip bzip2 tar mv file
After every step, ask the system what the resulting file actually is:
file <filename>
Continue until there are no more compression or archive layers.
At the end you should recover:
web-paths.txt
Do not delete this file.
You will need it for the final challenge.
You can now access the grades application and authenticate successfully.
However, the administrator remembers that there used to be an older administrative interface.
It is no longer linked anywhere in the application.
Nobody remembers its URL.
It may have been something like:
/admin /old-admin /maintenance /internal
Fortunately, ‘‘web-paths.txt’’ contains a list of possible paths used during development.
Write a Python program that searches for the forgotten endpoint.
Your program should:
* read candidate paths from ‘‘web-paths.txt’’; * request each path from the web application; * inspect the HTTP status code; * display interesting results.
You may use:
import requests
For example:
response = requests.get(url) print(response.status_code)
A normal missing page returns:
404 Not Found
You are looking for something different.
The server contains a protection mechanism against aggressive automated clients.
If more than approximately three requests per second are sent from the same client, the network protection temporarily blocks that client.
The block lasts approximately 10 seconds.
A very aggressive script may therefore appear to suddenly stop working.
Your program should behave reasonably and deal with this limitation.
Useful Python functionality includes:
import time time.sleep(…) You may also want to handle request errors rather than immediately terminating the program. When you discover the forgotten administrative endpoint: * open it; * authenticate using the credentials recovered earlier; * retrieve the final flag. <code> ISC{...}
Answer the following questions based on what you did during the lab.
The administrator stored the password list using Base64.
Which property of the CIA triad was the administrator presumably trying to protect?
* A. Integrity * B. Availability * C. Authentication * D. Confidentiality
The ZIP archive was protected by a password, but the password could be found using a short wordlist.
What was the weakest link?
* A. The ZIP filename * B. The weak password * C. The size of the ZIP archive * D. The operating system
The application could not start because the configuration contained an incorrect port number.
Which CIA property was most directly affected when legitimate users could not use the application?
* A. Confidentiality * B. Authentication * C. Integrity * D. Availability
The administrator password was visible inside a screenshot.
Which CIA property was most directly affected?
* A. Confidentiality * B. Integrity * C. Availability * D. Non-repudiation
Sensitive information was hidden inside an image and later discovered using Binwalk.
Which statement is most accurate?
* A. Hiding information guarantees confidentiality. * B. File extensions prevent unauthorized access. * C. Hiding information is not a replacement for proper confidentiality controls. * D. Binwalk provides encryption.
The recovered backup contained several layers of hexadecimal encoding, compression and archives.
Does this represent defence in depth?
* A. Yes. Every additional file layer is automatically a security control. * B. Yes. Compression guarantees confidentiality. * C. No. Defence in depth requires meaningful and preferably independent security controls. * D. No. Defence in depth can only be used for networks.
The old administrator page was not linked from the application, but it could still be discovered by fuzzing possible paths.
What should actually protect an administrative endpoint?
* A. An unusual URL * B. Proper authentication and authorization * C. A longer HTML page * D. A different filename extension
Please take a minute to fill in the feedback form for this lab.