At the end of this lab, you should be able to:
The university has recovered an old application used for managing student grades
. As with any homework project the documentation is incomplete. You have received only two files and some messages from the administrator:
pass.txt bla.zip
Your goal is to recover the application, start it, authenticate to it and find the forgotten administrative interface.
Act as a patient security tutor, not a solver. Help me understand the concepts and approach, point me to the right tools (bash / python-based), and give me hints and guiding questions — but don't write out the full solution or complete code. Nudge me just enough to keep me trying, and only reveal more if I tell you I'm still stuck.
What is Base64 and how can I decode Base64 data from the Linux command line?
How can I recognize whether a string might still be Base64 encoded?
The administrator left the following message:
I am a security guy, so protected them using Base64. Several times.
You received:
pass.txt
Recover the original information. Decode the Base64 outer layers until you obtain readable information. At the end of this exercise you should have a list of possible passwords.
Save the result as:
passwords.txt
How can I read a text file line by line in Python?
How can Python's zipfile module try a password when extracting a ZIP archive?
The second file provided by the administrator is:
bla.zip
Unfortunately, it is password protected using one of the passwords contained in passwords.txt.
Write a small Python program that:
passwords.txt;bla.zip;Python provides the following module:
import zipfile
You may find the documentation for ZipFile.extractall() useful.
At the end of this exercise you should have a directory containing the recovered grades application.
How can I use the Linux “find” command to locate regular files of exactly 987 bytes?
How can I determine whether a file contains human-readable text from the command line?
You now have the application files but you don't know which file contains the application configuration. The configuration file has all of the following properties:
Find it.
You should discover a server configuration similar to:
[server] host = 0.0.0.0 port = 0
Change the configuration port to 8080 and start the recovered environment:
docker compose up -d --build
Check whether the application is running:
curl http://localhost:8080
The application should now display a login page.
How can I inspect the first bytes of a file on Linux?
What is a file signature or magic number?
What should the beginning of a valid PNG file look like?
The administrator password is in the
static/admin-screenshot.png
Unfortunately, the screenshot appears to have been corrupted while it was being transferred.
Try inspecting the file:
file admin-screenshot.png
Something is wrong with the file header.
A valid PNG file starts with the following bytes:
89 50 4E 47 0D 0A 1A 0A
After repairing the file:
file;Use the credentials to log in to the grades application.
What is binwalk used for when analysing a suspicious file?
How should I interpret this binwalk output?
The administrator remembers that he also provided a admin-backup.hex file dump with the list of app's API endpoints. However, it got mixt into the screenshot file. Look again at:
admin-screenshot.png
The screenshot is not particularly large or detailed, however the file is considerably larger than expected.
Start by running:
binwalk admin-screenshot.png
Remember that filenames and extensions are not always trustworthy.
The file command says “bzip2 compressed data”. Which Linux command can decompress this format?
Using admin-backup.hex you discovered that the administrator apparently had a complicated backup procedure. The file is a hexdump of another file, which has then been compressed and archived several times using different formats.
Reverse the process.
First convert the hexdump back into binary data using xxd.
xxd -r admin-backup.hex > recovered
Then determine what kind of file you have and use the corresponding tool to extract them. At the end you should recover:
web-paths.txt
How can I send an HTTP GET request using Python requests?
How can I read one URL path per line from a text file?
How can I check the HTTP status code returned by requests?
What does HTTP 429 mean and how should a client react to it?
You can now access the grades application and authenticate successfully. However, the administrator remembers that there used to be an older administrative interface. Nobody remembers its URL. Fortunately, web-paths.txt contains a list of possible paths used during development.
Write a Python program that searches for the forgotten endpoint.
Your program should:
web-paths.txt;The administrative interface should provide you with a GIF image.
The server contains a protection mechanism against aggressive automated clients. If more than approximately three requests per second are sent from the same client, the network protection temporarily blocks that client. The block lasts approximately 10 seconds.
A very aggressive script may therefore appear to suddenly stop working. Your program should behave reasonably and deal with this limitation. Maybe some “sleep” can be used.
How does an animated GIF store multiple frames?
Which Linux tools can show or extract individual frames from an animated GIF?
The page contains one final piece of evidence recovered from the old grades application. When you access the page, your browser automatically downloads:
evidence.gif
Open the GIF. Nothing particularly interesting seems to happen. You can stare at it for the next hour if you want. Or you can investigate how animated GIF files actually work. Your goal is to recover the final flag from the GIF.
You may find tools for extracting individual GIF frames useful. For example, ImageMagick can separate an animated GIF into individual images. Inspect the resulting frames.
An animated GIF is not necessarily a single image.
Waiting for the animation to reveal everything may not be the best approach.
Login into Moodle and take the Lab01 quiz.
Please take a minute to fill in the feedback form for this lab.