Differences

This shows you the differences between two versions of the page.

Link to this comparison view

isc:labs:new:01 [2026/10/04 16:34]
mihai.chiroiu [02. Zip it good]
isc:labs:new:01 [2026/10/04 22:39] (current)
mihai.chiroiu [Scenario]
Line 15: Line 15:
 ===== Scenario ===== ===== Scenario =====
  
-The university has recovered an old application used for managing student grades. As with any <​del>​homework</​del>​ project the documentation is incomplete. You have received only two files and some messages from the administrator:​+The university has recovered an old {{:​isc:​labs:​lab01_intro_new.zip|application}} used for managing student grades ​ 
 + 
 +. As with any <​del>​homework</​del>​ project the documentation is incomplete. You have received only two files and some messages from the administrator:​
  
 <​code>​ <​code>​
Line 29: Line 31:
  
 ===== 01. [1p] Serious Security ===== ===== 01. [1p] Serious Security =====
 +
 +<note tip>
 +**Ask your agent**
 +
 +> What is Base64 and how can I decode Base64 data from the Linux command line?
 +> How can I recognize whether a string might still be Base64 encoded?
 +
 +</​note>​
  
 The administrator left the following message: The administrator left the following message:
Line 49: Line 59:
  
 ===== 02. [1p] Zip it good ===== ===== 02. [1p] Zip it good =====
 +
 +<note tip>
 +**Ask your agent**
 +
 +> How can I read a text file line by line in Python?
 +> How can Python'​s zipfile module try a password when extracting a ZIP archive?
 +
 +</​note>​
  
 The second file provided by the administrator is: The second file provided by the administrator is:
Line 75: Line 93:
 At the end of this exercise you should have a directory containing the recovered grades application. At the end of this exercise you should have a directory containing the recovered grades application.
  
-===== 03. Find the configuration =====+===== 03. [1p] Find the configuration =====
  
-You now have the application files.+<note tip> 
 +**Ask your agent**
  
-Unfortunately, ​the administrator does not remember which file contains the application configuration.+> How can I use the Linux "​find"​ command to locate regular files of exactly 987 bytes? 
 +> How can I determine whether a file contains ​human-readable text from the command line?
  
-Somewhere inside ​the extracted directory there is a file with **all** of the following properties:+</​note>​ 
 + 
 +You now have the application files but you don't know which file contains the application configuration. The configuration file has **all** of the following properties:
  
   * human-readable;​   * human-readable;​
Line 88: Line 110:
  
 Find it. Find it.
- 
-Useful commands include: 
- 
-<code bash> 
-find 
-file 
-ls 
-stat 
-</​code>​ 
- 
-Do not manually inspect every file. 
- 
-Once you find the correct file, inspect its contents. 
  
 You should discover a server configuration similar to: You should discover a server configuration similar to:
Line 110: Line 119:
 </​code>​ </​code>​
  
-The configured ​port is invalid for this application. +Change the configuration ​port to **8080** and start the recovered environment:​
- +
-Change it to: +
- +
-<code ini> +
-port = 8080 +
-</​code>​ +
- +
-Now start the recovered environment:​+
  
 <code bash> <code bash>
Line 129: Line 130:
 curl http://​localhost:​8080 curl http://​localhost:​8080
 </​code>​ </​code>​
- 
-If everything worked, you should receive a response from the grades application. 
- 
-You can also open: 
- 
-<​code>​ 
-http://​localhost:​8080 
-</​code>​ 
- 
-in your browser. 
  
 The application should now display a login page. The application should now display a login page.
  
-===== 04. The corrupted screenshot =====+===== 04. [1p] The corrupted screenshot =====
  
-The application works, but you do not know the administrator password.+<note tip> 
 +**Ask your agent**
  
-Fortunately, ​the administrator remembers something:+> How can I inspect ​the first bytes of a file on Linux? 
 +> What is a file signature or magic number? 
 +> What should the beginning of a valid PNG file look like? 
 +</​note>​
  
-> I took a screenshot of the admin interface that contained the login information. +The administrator password is in the 
- +
-The recovered application files contain:+
  
 <​code>​ <​code>​
-admin-screenshot.png+static/admin-screenshot.png
 </​code>​ </​code>​
  
Line 162: Line 155:
 <code bash> <code bash>
 file admin-screenshot.png file admin-screenshot.png
-</​code>​ 
- 
-Then inspect the first bytes: 
- 
-<code bash> 
-xxd admin-screenshot.png | head 
 </​code>​ </​code>​
  
Line 176: Line 163:
 <​code>​ <​code>​
 89 50 4E 47 0D 0A 1A 0A 89 50 4E 47 0D 0A 1A 0A
-</​code>​ 
- 
-Use a hex editor to repair the corrupted bytes: 
- 
-<code bash> 
-hexedit admin-screenshot.png 
 </​code>​ </​code>​
  
Line 192: Line 173:
 Use the credentials to log in to the grades application. Use the credentials to log in to the grades application.
  
-===== 05. There is something strange about this screenshot =====+===== 05. [1p] There is something strange about this screenshot =====
  
-Before continuing, look again at:+<note tip> 
 +**Ask your agent** 
 + 
 +> What is binwalk used for when analysing a suspicious file? 
 +> How should I interpret this binwalk output? 
 +</​note>​ 
 + 
 +The administrator remembers that he also provided a admin-backup.hex file dump with the list of app's API endpoints. However, it got mixt into the screenshot file. Look again at:
  
 <​code>​ <​code>​
Line 200: Line 188:
 </​code>​ </​code>​
  
-The screenshot is not particularly large or detailed. +The screenshot is not particularly large or detailed, however ​the file is considerably larger than expected.
- +
-However: +
- +
-<code bash> +
-ls -lh admin-screenshot.png +
-</​code>​ +
- +
-shows that the file is considerably larger than expected. +
- +
-Maybe the screenshot contains more than an image. +
- +
-For this exercise you will use a new tool: +
- +
-<code bash> +
-binwalk +
-</​code>​+
  
 Start by running: Start by running:
Line 223: Line 195:
 binwalk admin-screenshot.png binwalk admin-screenshot.png
 </​code>​ </​code>​
- 
-Study the output. 
- 
-If Binwalk detects additional content, try extracting it: 
- 
-<code bash> 
-binwalk -e admin-screenshot.png 
-</​code>​ 
- 
-Inspect the extracted files. 
  
 Remember that filenames and extensions are not always trustworthy. Remember that filenames and extensions are not always trustworthy.
  
-Use:+===== 06. [1p] The great file squeeze =====
  
-<code bash> +<note tip> 
-file <​filename>​ +**Ask your agent**
-</​code>​+
  
-when you are unsure what a file actually contains.+> The file command says "bzip2 compressed data". Which Linux command can decompress this format?
  
-Your goal is to recover:+</​note>​
  
-<​code>​ +Using admin-backup.hex ​you discovered that the administrator apparently had a complicated backup procedure. The file is a **hexdump of another file**, which has then been compressed and archived several times using different formats.
-admin-backup.hex +
-</​code>​+
  
-===== 06. The great file squeeze =====+Reverse the process. 
  
-The file recovered from the screenshot is: +First convert the hexdump back into binary data using xxd. 
- +
-<​code>​ +
-admin-backup.hex +
-</​code>​ +
- +
-The administrator apparently had a complicated backup procedure. +
- +
-The file is a **hexdump of another file**, which has then been compressed and archived several times using different formats. +
- +
-Reverse the process. +
- +
-First convert the hexdump back into binary data:+
  
 <code bash> <code bash>
Line 270: Line 217:
 </​code>​ </​code>​
  
-Then determine what kind of file you have: +Then determine what kind of file you have and use the corresponding tool to extract them. At the end you should recover:
- +
-<code bash> +
-file recovered +
-</​code>​ +
- +
-Depending on the output, you may need tools such as: +
- +
-<code bash> +
-gzip +
-bzip2 +
-tar +
-mv +
-file +
-</​code>​ +
- +
-After every step, ask the system what the resulting file actually is: +
- +
-<code bash> +
-file <​filename>​ +
-</​code>​ +
- +
-Continue until there are no more compression or archive layers. +
- +
-At the end you should recover:+
  
 <​code>​ <​code>​
 web-paths.txt web-paths.txt
 </​code>​ </​code>​
 +===== [1p] 07. Where did the admin page go? =====
  
-Do not delete this file.+<note tip> 
 +**Ask your agent**
  
-You will need it for the final challenge. +> How can I send an HTTP GET request using Python requests? 
- +> How can I read one URL path per line from a text file? 
-===== 07. Where did the admin page go? ===== +> How can I check the HTTP status code returned by requests? 
- +> What does HTTP 429 mean and how should a client react to it? 
-You can now access the grades application ​and authenticate successfully. +</note>
- +
-However, the administrator remembers that there used to be an **older administrative interface**. +
- +
-It is no longer linked anywhere in the application. +
- +
-Nobody remembers its URL. +
- +
-It may have been something like: +
- +
-<code> +
-/admin +
-/​old-admin +
-/​maintenance +
-/internal +
-</code>+
  
-Fortunately,​ ''​web-paths.txt''​ contains a list of possible paths used during development.+You can now access the grades application and authenticate successfully. However, the administrator remembers that there used to be an **older administrative interface**. Nobody remembers its URL. Fortunately,​ ''​web-paths.txt''​ contains a list of possible paths used during development.
  
 Write a Python program that searches for the forgotten endpoint. Write a Python program that searches for the forgotten endpoint.
Line 334: Line 244:
   - display interesting results.   - display interesting results.
  
-You may use:+The **administrative interface** should provide you with a GIF image. 
 +<​note>​
  
-<code python>​ +The server contains a protection mechanism against aggressive automated clients. If more than approximately **three ​requests ​per second** are sent from the same client, the network protection temporarily blocks that client. The block lasts approximately **10 seconds**.
-import ​requests +
-</​code>​+
  
-For example:+A very aggressive script may therefore appear to suddenly stop working. Your program should behave reasonably and deal with this limitation. Maybe some "​sleep"​ can be used. 
 +</​note> ​
  
-<code python>​ +===== 08. [1p] Waiting for eternity =====
-response ​= requests.get(url) +
-print(response.status_code) +
-</​code>​+
  
-A normal missing ​page returns:+<note tip> 
 +**Ask your agent** 
 + 
 +> How does an animated GIF store multiple frames? 
 +> Which Linux tools can show or extract individual frames from an animated GIF? 
 +</​note>​ 
 + 
 +The page contains one final piece of evidence recovered from the old grades application. When you access the page, your browser automatically downloads:
  
 <​code>​ <​code>​
-404 Not Found+evidence.gif
 </​code>​ </​code>​
  
-You are looking ​for something different.+Open the GIF. Nothing particularly interesting seems to happen. ​You can stare at it for the next hour if you want. Or you can investigate how animated GIF files actually work. Your goal is to recover the final flag from the GIF.
  
-==== One more problem ​====+You may find tools for extracting individual GIF frames useful. For example, ImageMagick can separate an animated GIF into individual images. Inspect the resulting frames.  
 +==== Hint ====
  
-The server contains ​a protection mechanism against aggressive automated clients.+An animated GIF is not necessarily ​a single image.
  
-If more than approximately **three requests per second** are sent from the same client, ​the network protection temporarily blocks that client.+Waiting for the animation to reveal everything may not be the best approach.
  
-The block lasts approximately **10 seconds**.+===== [1p] Moodle quiz =====
  
-A very aggressive script may therefore appear to suddenly stop working. +Login into Moodle ​and take the Lab01 quiz.
- +
-Your program should behave reasonably ​and deal with this limitation. +
- +
-Useful Python functionality includes: +
- +
-<code python>​ +
-import time +
- +
-time.sleep(...) +
-</​code>​ +
- +
-You may also want to handle request errors rather than immediately terminating ​the program. +
- +
-When you discover the forgotten administrative endpoint: +
- +
-  - open it; +
-  - authenticate using the credentials recovered earlier; +
-  - retrieve the final flag. +
- +
-<​code>​ +
-ISC{...} +
-</​code>​+
  
-===== Feedback =====+===== [1p] Feedback =====
  
 {{page>:​isc:​lab-feedback&​nofooter&​noeditbutton}} {{page>:​isc:​lab-feedback&​nofooter&​noeditbutton}}
isc/labs/new/01.1791120878.txt.gz · Last modified: 2026/10/04 16:34 by mihai.chiroiu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0