This is an old revision of the document!
At the end of this lab, you should be able to:
The university has recovered an old application used for managing student grades. As with any homework project the documentation is incomplete. You have received only two files from the administrator:
pass.txt bla.zip
Your goal is to recover the application, start it, authenticate to it and find the forgotten administrative interface.
Act as a patient security tutor, not a solver. Help me understand the concepts and approach, point me to the right tools (bash / python-based), and give me hints and guiding questions — but don't write out the full solution or complete code. Nudge me just enough to keep me trying, and only reveal more if I tell you I'm still stuck.
The administrator left the following message:
I am a serious security guy, so obviously I did not leave the passwords in plaintext. I protected them using Base64. Several times.
You received:
pass.txt
Recover the original information. Decode the Base64 outer layers until you obtain readable information. At the end of this exercise you should have a list of possible passwords.
Save the result as:
passwords.txt
The second file provided by the administrator is:
bla.zip
Unfortunately, it is password protected.
Fortunately, the administrator appears to have used one of the passwords contained in passwords.txt.
Your task is to find the correct password and extract the archive.
You could try every password manually, but that would be boring.
Write a small Python program that:
passwords.txt;bla.zip;Python provides the following module:
import zipfile
You may find the documentation for ZipFile.extractall() useful.
At the end of this exercise you should have a directory containing the recovered grades application.
You now have the application files.
Unfortunately, the administrator does not remember which file contains the application configuration.
Somewhere inside the extracted directory there is a file with all of the following properties:
Find it.
Useful commands include:
find file ls stat
Do not manually inspect every file.
Once you find the correct file, inspect its contents.
You should discover a server configuration similar to:
[server] host = 0.0.0.0 port = 0
The configured port is invalid for this application.
Change it to:
port = 8080
Now start the recovered environment:
docker compose up -d --build
Check whether the application is running:
curl http://localhost:8080
If everything worked, you should receive a response from the grades application.
You can also open:
http://localhost:8080
in your browser.
The application should now display a login page.
The application works, but you do not know the administrator password.
Fortunately, the administrator remembers something:
I took a screenshot of the admin interface that contained the login information.
The recovered application files contain:
admin-screenshot.png
Unfortunately, the screenshot appears to have been corrupted while it was being transferred.
Try inspecting the file:
file admin-screenshot.png
Then inspect the first bytes:
xxd admin-screenshot.png | head
Something is wrong with the file header.
A valid PNG file starts with the following bytes:
89 50 4E 47 0D 0A 1A 0A
Use a hex editor to repair the corrupted bytes:
hexedit admin-screenshot.png
After repairing the file:
file;Use the credentials to log in to the grades application.
Before continuing, look again at:
admin-screenshot.png
The screenshot is not particularly large or detailed.
However:
ls -lh admin-screenshot.png
shows that the file is considerably larger than expected.
Maybe the screenshot contains more than an image.
For this exercise you will use a new tool:
binwalk
Start by running:
binwalk admin-screenshot.png
Study the output.
If Binwalk detects additional content, try extracting it:
binwalk -e admin-screenshot.png
Inspect the extracted files.
Remember that filenames and extensions are not always trustworthy.
Use:
file <filename>
when you are unsure what a file actually contains.
Your goal is to recover:
admin-backup.hex
The file recovered from the screenshot is:
admin-backup.hex
The administrator apparently had a complicated backup procedure.
The file is a hexdump of another file, which has then been compressed and archived several times using different formats.
Reverse the process.
First convert the hexdump back into binary data:
xxd -r admin-backup.hex > recovered
Then determine what kind of file you have:
file recovered
Depending on the output, you may need tools such as:
gzip bzip2 tar mv file
After every step, ask the system what the resulting file actually is:
file <filename>
Continue until there are no more compression or archive layers.
At the end you should recover:
web-paths.txt
Do not delete this file.
You will need it for the final challenge.
You can now access the grades application and authenticate successfully.
However, the administrator remembers that there used to be an older administrative interface.
It is no longer linked anywhere in the application.
Nobody remembers its URL.
It may have been something like:
/admin /old-admin /maintenance /internal
Fortunately, web-paths.txt contains a list of possible paths used during development.
Write a Python program that searches for the forgotten endpoint.
Your program should:
web-paths.txt;You may use:
import requests
For example:
response = requests.get(url) print(response.status_code)
A normal missing page returns:
404 Not Found
You are looking for something different.
The server contains a protection mechanism against aggressive automated clients.
If more than approximately three requests per second are sent from the same client, the network protection temporarily blocks that client.
The block lasts approximately 10 seconds.
A very aggressive script may therefore appear to suddenly stop working.
Your program should behave reasonably and deal with this limitation.
Useful Python functionality includes:
import time time.sleep(...)
You may also want to handle request errors rather than immediately terminating the program.
When you discover the forgotten administrative endpoint:
ISC{...}
Please take a minute to fill in the feedback form for this lab.