Differences

This shows you the differences between two versions of the page.

Link to this comparison view

isc:labs:new:01 [2026/10/04 15:34]
mihai.chiroiu created
isc:labs:new:01 [2026/10/04 22:39] (current)
mihai.chiroiu [Scenario]
Line 15: Line 15:
 ===== Scenario ===== ===== Scenario =====
  
-The university has recovered an old application used for managing student grades.+The university has recovered an old {{:​isc:​labs:​lab01_intro_new.zip|application}} used for managing student grades ​
  
-Unfortunately,​ the administrator who maintained the application is unavailable and the documentation is incomplete. +. As with any <​del>​homework</​del>​ project ​the documentation is incomplete. You have received only two files and some messages ​from the administrator:​
- +
-You have received only two files from the administrator:​+
  
 <​code>​ <​code>​
Line 28: Line 26:
 Your goal is to recover the application,​ start it, authenticate to it and find the forgotten administrative interface. Your goal is to recover the application,​ start it, authenticate to it and find the forgotten administrative interface.
  
-Each exercise continues from the previous one.+===== AI/LLM agents prompt =====
  
-===== Using an LLM ===== +{{page>:isc:​agents&​nofooter&​noeditbutton&​noheader}} ​
- +
-You are encouraged to use an LLM during this lab, but use it as a **technical assistant**,​ not as a CTF solver. +
- +
-Good questions include: +
- +
-<code> +
-How can I use find to locate a file of exactly 987 bytes? +
- +
-What does this output from the file command mean? +
- +
-What is the header of a PNG file? +
- +
-What does this Python exception mean? +
- +
-How can I add a delay between HTTP requests in Python? +
-</​code>​ +
- +
-Do **not** paste the complete lab, upload the archive or ask: +
- +
-<​code>​ +
-Solve this exercise for me. +
- +
-Here is the entire lab. Give me all the flags. +
-</​code>​+
  
-Try to formulate a small question about the specific problem you are currently trying to solve.+===== 01. [1p] Serious Security =====
  
-===== Useful Tools =====+<note tip> 
 +**Ask your agent**
  
-  * ''​man''​ +> What is Base64 and how can I decode Base64 data from the Linux command line? 
-  * ''​find''​ +> How can I recognize whether a string might still be Base64 encoded?
-  * ''​file''​ +
-  * ''​base64''​ +
-  * ''​xxd''​ +
-  * ''​hexedit''​ +
-  * ''​unzip''​ +
-  * ''​binwalk''​ +
-  * ''​gzip''​ +
-  * ''​bzip2''​ +
-  * ''​tar''​ +
-  * Python +
-  * ''​requests''​ +
-  * ''​curl''​ +
-  * Docker / Docker Compose+
  
-===== 01. Serious Security =====+</​note>​
  
 The administrator left the following message: The administrator left the following message:
  
-> I am a serious ​security guy, so obviously I did not leave the passwords in plaintext. I protected them using Base64. Several times.+> I am a security guy, so protected them using Base64. Several times.
  
 You received: You received:
Line 88: Line 50:
 </​code>​ </​code>​
  
-Determine how the contents were encoded and recover ​the original information. +Recover ​the original information. ​Decode ​the Base64 outer layers ​until you obtain readable information. At the end of this exercise you should have a **list of possible passwords**.
- +
-You may find the following commands useful: +
- +
-<code bash> +
-cat pass.txt +
-base64 -d +
-</​code>​ +
- +
-One decoding operation might not be enough. +
- +
-Continue ​until you obtain readable information. +
- +
-At the end of this exercise you should have a **list of possible passwords**.+
  
 Save the result as: Save the result as:
Line 109: Line 58:
 </​code>​ </​code>​
  
-You will need it in the next exercise.+===== 02. [1p] Zip it good =====
  
-===== 02. Zip it good =====+<note tip> 
 +**Ask your agent** 
 + 
 +> How can I read a text file line by line in Python? 
 +> How can Python'​s zipfile module try a password when extracting a ZIP archive? 
 + 
 +</​note>​
  
 The second file provided by the administrator is: The second file provided by the administrator is:
Line 119: Line 74:
 </​code>​ </​code>​
  
-Unfortunately,​ it is password protected. +Unfortunately,​ it is password protected ​using one of the passwords contained in ''​passwords.txt''​.
- +
-Fortunately,​ the administrator appears to have used one of the passwords contained in ''​passwords.txt''​. +
- +
-Your task is to find the correct password and extract the archive. +
- +
-You could try every password manually, but that would be boring.+
  
 Write a small Python program that: Write a small Python program that:
Line 144: Line 93:
 At the end of this exercise you should have a directory containing the recovered grades application. At the end of this exercise you should have a directory containing the recovered grades application.
  
-===== 03. Find the configuration =====+===== 03. [1p] Find the configuration =====
  
-You now have the application files.+<note tip> 
 +**Ask your agent**
  
-Unfortunately, ​the administrator does not remember which file contains the application configuration.+> How can I use the Linux "​find"​ command to locate regular files of exactly 987 bytes? 
 +> How can I determine whether a file contains ​human-readable text from the command line?
  
-Somewhere inside ​the extracted directory there is a file with **all** of the following properties:+</​note>​ 
 + 
 +You now have the application files but you don't know which file contains the application configuration. The configuration file has **all** of the following properties:
  
   * human-readable;​   * human-readable;​
Line 157: Line 110:
  
 Find it. Find it.
- 
-Useful commands include: 
- 
-<code bash> 
-find 
-file 
-ls 
-stat 
-</​code>​ 
- 
-Do not manually inspect every file. 
- 
-Once you find the correct file, inspect its contents. 
  
 You should discover a server configuration similar to: You should discover a server configuration similar to:
Line 179: Line 119:
 </​code>​ </​code>​
  
-The configured ​port is invalid for this application. +Change the configuration ​port to **8080** and start the recovered environment:​
- +
-Change it to: +
- +
-<code ini> +
-port = 8080 +
-</​code>​ +
- +
-Now start the recovered environment:​+
  
 <code bash> <code bash>
Line 198: Line 130:
 curl http://​localhost:​8080 curl http://​localhost:​8080
 </​code>​ </​code>​
- 
-If everything worked, you should receive a response from the grades application. 
- 
-You can also open: 
- 
-<​code>​ 
-http://​localhost:​8080 
-</​code>​ 
- 
-in your browser. 
  
 The application should now display a login page. The application should now display a login page.
  
-===== 04. The corrupted screenshot =====+===== 04. [1p] The corrupted screenshot =====
  
-The application works, but you do not know the administrator password.+<note tip> 
 +**Ask your agent**
  
-Fortunately, ​the administrator remembers something:+> How can I inspect ​the first bytes of a file on Linux? 
 +> What is a file signature or magic number? 
 +> What should the beginning of a valid PNG file look like? 
 +</​note>​
  
-> I took a screenshot of the admin interface that contained the login information. +The administrator password is in the 
- +
-The recovered application files contain:+
  
 <​code>​ <​code>​
-admin-screenshot.png+static/admin-screenshot.png
 </​code>​ </​code>​
  
Line 231: Line 155:
 <code bash> <code bash>
 file admin-screenshot.png file admin-screenshot.png
-</​code>​ 
- 
-Then inspect the first bytes: 
- 
-<code bash> 
-xxd admin-screenshot.png | head 
 </​code>​ </​code>​
  
Line 245: Line 163:
 <​code>​ <​code>​
 89 50 4E 47 0D 0A 1A 0A 89 50 4E 47 0D 0A 1A 0A
-</​code>​ 
- 
-Use a hex editor to repair the corrupted bytes: 
- 
-<code bash> 
-hexedit admin-screenshot.png 
 </​code>​ </​code>​
  
Line 261: Line 173:
 Use the credentials to log in to the grades application. Use the credentials to log in to the grades application.
  
-===== 05. There is something strange about this screenshot =====+===== 05. [1p] There is something strange about this screenshot =====
  
-Before continuing, look again at:+<note tip> 
 +**Ask your agent** 
 + 
 +> What is binwalk used for when analysing a suspicious file? 
 +> How should I interpret this binwalk output? 
 +</​note>​ 
 + 
 +The administrator remembers that he also provided a admin-backup.hex file dump with the list of app's API endpoints. However, it got mixt into the screenshot file. Look again at:
  
 <​code>​ <​code>​
Line 269: Line 188:
 </​code>​ </​code>​
  
-The screenshot is not particularly large or detailed. +The screenshot is not particularly large or detailed, however ​the file is considerably larger than expected.
- +
-However: +
- +
-<code bash> +
-ls -lh admin-screenshot.png +
-</​code>​ +
- +
-shows that the file is considerably larger than expected. +
- +
-Maybe the screenshot contains more than an image. +
- +
-For this exercise you will use a new tool: +
- +
-<code bash> +
-binwalk +
-</​code>​+
  
 Start by running: Start by running:
Line 292: Line 195:
 binwalk admin-screenshot.png binwalk admin-screenshot.png
 </​code>​ </​code>​
- 
-Study the output. 
- 
-If Binwalk detects additional content, try extracting it: 
- 
-<code bash> 
-binwalk -e admin-screenshot.png 
-</​code>​ 
- 
-Inspect the extracted files. 
  
 Remember that filenames and extensions are not always trustworthy. Remember that filenames and extensions are not always trustworthy.
  
-Use:+===== 06. [1p] The great file squeeze =====
  
-<code bash> +<note tip> 
-file <​filename>​ +**Ask your agent**
-</​code>​+
  
-when you are unsure what a file actually contains.+> The file command says "bzip2 compressed data". Which Linux command can decompress this format?
  
-Your goal is to recover:+</​note>​
  
-<​code>​ +Using admin-backup.hex ​you discovered that the administrator apparently had a complicated backup procedure. The file is a **hexdump of another file**, which has then been compressed and archived several times using different formats.
-admin-backup.hex +
-</​code>​+
  
-===== 06. The great file squeeze =====+Reverse the process. 
  
-The file recovered from the screenshot is: +First convert the hexdump back into binary data using xxd. 
- +
-<​code>​ +
-admin-backup.hex +
-</​code>​ +
- +
-The administrator apparently had a complicated backup procedure. +
- +
-The file is a **hexdump of another file**, which has then been compressed and archived several times using different formats. +
- +
-Reverse the process. +
- +
-First convert the hexdump back into binary data:+
  
 <code bash> <code bash>
Line 339: Line 217:
 </​code>​ </​code>​
  
-Then determine what kind of file you have: +Then determine what kind of file you have and use the corresponding tool to extract them. At the end you should recover:
- +
-<code bash> +
-file recovered +
-</​code>​ +
- +
-Depending on the output, you may need tools such as: +
- +
-<code bash> +
-gzip +
-bzip2 +
-tar +
-mv +
-file +
-</​code>​ +
- +
-After every step, ask the system what the resulting file actually is: +
- +
-<code bash> +
-file <​filename>​ +
-</​code>​ +
- +
-Continue until there are no more compression or archive layers. +
- +
-At the end you should recover:+
  
 <​code>​ <​code>​
 web-paths.txt web-paths.txt
 </​code>​ </​code>​
 +===== [1p] 07. Where did the admin page go? =====
  
-Do not delete this file.+<note tip> 
 +**Ask your agent**
  
-You will need it for the final challenge.+> How can I send an HTTP GET request using Python requests? 
 +> How can I read one URL path per line from a text file? 
 +> How can I check the HTTP status code returned by requests? 
 +> What does HTTP 429 mean and how should a client react to it? 
 +</​note>​
  
-===== 07. Where did the admin page go? ===== +You can now access the grades application and authenticate successfully. However, the administrator remembers that there used to be an **older administrative interface**. Nobody remembers its URL. Fortunately,​ ''​web-paths.txt''​ contains a list of possible paths used during development.
- +
-You can now access the grades application and authenticate successfully. +
- +
-However, the administrator remembers that there used to be an **older administrative interface**. +
- +
-It is no longer linked anywhere in the application. +
- +
-Nobody remembers its URL. +
- +
-It may have been something like: +
- +
-<​code>​ +
-/admin +
-/​old-admin +
-/​maintenance +
-/internal +
-</​code>​ +
- +
-Fortunately,​ ''​web-paths.txt''​ contains a list of possible paths used during development.+
  
 Write a Python program that searches for the forgotten endpoint. Write a Python program that searches for the forgotten endpoint.
Line 403: Line 244:
   - display interesting results.   - display interesting results.
  
-You may use:+The **administrative interface** should provide you with a GIF image. 
 +<​note>​
  
-<code python>​ +The server contains a protection mechanism against aggressive automated clients. If more than approximately **three ​requests ​per second** are sent from the same client, the network protection temporarily blocks that client. The block lasts approximately **10 seconds**.
-import ​requests +
-</​code>​+
  
-For example:+A very aggressive script may therefore appear to suddenly stop working. Your program should behave reasonably and deal with this limitation. Maybe some "​sleep"​ can be used. 
 +</​note> ​
  
-<code python>​ +===== 08. [1p] Waiting for eternity =====
-response ​= requests.get(url) +
-print(response.status_code) +
-</​code>​+
  
-A normal missing page returns:+<note tip> 
 +**Ask your agent**
  
-<code> +> How does an animated GIF store multiple frames? 
-404 Not Found +> Which Linux tools can show or extract individual frames from an animated GIF? 
-</code>+</note>
  
-You are looking for something different. +The page contains ​one final piece of evidence recovered ​from the old grades application. When you access ​the page, your browser automatically downloads:
- +
-==== One more problem ==== +
- +
-The server ​contains ​a protection mechanism against aggressive automated clients. +
- +
-If more than approximately **three requests per second** are sent from the same client, the network protection temporarily blocks that client. +
- +
-The block lasts approximately **10 seconds**. +
- +
-A very aggressive script may therefore appear to suddenly stop working. +
- +
-Your program should behave reasonably and deal with this limitation. +
- +
-Useful Python functionality includes: +
- +
-<code python>​ +
-import time +
- +
-time.sleep(...) +
-</​code>​ +
- +
-You may also want to handle request errors rather than immediately terminating the program. +
- +
-When you discover ​the forgotten administrative endpoint: +
- +
-  - open it; +
-  - authenticate using the credentials recovered earlier; +
-  - retrieve the final flag.+
  
 <​code>​ <​code>​
-ISC{...}+evidence.gif
 </​code>​ </​code>​
  
-===== End-of-Lab Quiz ===== +Open the GIF. Nothing particularly interesting seems to happen. You can stare at it for the next hour if you want. Or you can investigate how animated GIF files actually work. Your goal is to recover ​the final flag from the GIF.
- +
-Answer ​the following questions based on what you did during the lab. +
- +
-==== Q1 ==== +
- +
-The administrator stored the password list using Base64. +
- +
-Which property of the CIA triad was the administrator presumably trying ​to protect? +
- +
-  * A. Integrity +
-  * B. Availability +
-  * C. Authentication +
-  * D. Confidentiality +
- +
-==== Q2 ==== +
- +
-The ZIP archive was protected by a password, but the password could be found using a short wordlist. +
- +
-What was the weakest link? +
- +
-  * A. The ZIP filename +
-  * B. The weak password +
-  * C. The size of the ZIP archive +
-  * D. The operating system +
- +
-==== Q3 ==== +
- +
-The application could not start because ​the configuration contained an incorrect port number. +
- +
-Which CIA property was most directly affected when legitimate users could not use the application?​ +
- +
-  * A. Confidentiality +
-  * B. Authentication +
-  * C. Integrity +
-  * D. Availability +
- +
-==== Q4 ==== +
- +
-The administrator password was visible inside a screenshot. +
- +
-Which CIA property was most directly affected? +
- +
-  * A. Confidentiality +
-  * B. Integrity +
-  * C. Availability +
-  * D. Non-repudiation +
- +
-==== Q5 ==== +
- +
-Sensitive information was hidden inside an image and later discovered using Binwalk. +
- +
-Which statement is most accurate? +
- +
-  * A. Hiding information guarantees confidentiality. +
-  * B. File extensions prevent unauthorized access. +
-  * C. Hiding information is not a replacement for proper confidentiality controls. +
-  * D. Binwalk provides encryption. +
- +
-==== Q6 ==== +
- +
-The recovered backup contained several layers of hexadecimal encoding, compression and archives. +
- +
-Does this represent defence in depth?+
  
-  * A. Yes. Every additional file layer is automatically a security control. +You may find tools for extracting individual GIF frames useful. For example, ImageMagick can separate an animated GIF into individual images. Inspect the resulting frames.  
-  * B. Yes. Compression guarantees confidentiality. +==== Hint ====
-  * C. No. Defence in depth requires meaningful and preferably independent security controls. +
-  * D. No. Defence in depth can only be used for networks.+
  
-==== Q7 ====+An animated GIF is not necessarily a single image.
  
-The old administrator page was not linked from the application,​ but it could still be discovered by fuzzing possible paths.+Waiting for the animation to reveal everything may not be the best approach.
  
-What should actually protect an administrative endpoint?+===== [1p] Moodle quiz =====
  
-  * A. An unusual URL +Login into Moodle ​and take the Lab01 quiz.
-  * B. Proper authentication ​and authorization +
-  * C. A longer HTML page +
-  * D. A different filename extension+
  
-===== Feedback =====+===== [1p] Feedback =====
  
 {{page>:​isc:​lab-feedback&​nofooter&​noeditbutton}} {{page>:​isc:​lab-feedback&​nofooter&​noeditbutton}}
isc/labs/new/01.1791117271.txt.gz · Last modified: 2026/10/04 15:34 by mihai.chiroiu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0