This is an old revision of the document!
At the end of this lab, you should be able to:
The university has recovered an old application used for managing student grades. As with any homework project the documentation is incomplete. You have received only two files and some messages from the administrator:
pass.txt bla.zip
Your goal is to recover the application, start it, authenticate to it and find the forgotten administrative interface.
Act as a patient security tutor, not a solver. Help me understand the concepts and approach, point me to the right tools (bash / python-based), and give me hints and guiding questions — but don't write out the full solution or complete code. Nudge me just enough to keep me trying, and only reveal more if I tell you I'm still stuck.
The administrator left the following message:
I am a security guy, so protected them using Base64. Several times.
You received:
pass.txt
Recover the original information. Decode the Base64 outer layers until you obtain readable information. At the end of this exercise you should have a list of possible passwords.
Save the result as:
passwords.txt
The second file provided by the administrator is:
bla.zip
Unfortunately, it is password protected using one of the passwords contained in passwords.txt.
Write a small Python program that:
passwords.txt;bla.zip;Python provides the following module:
import zipfile
You may find the documentation for ZipFile.extractall() useful.
At the end of this exercise you should have a directory containing the recovered grades application.
You now have the application files but you don't know which file contains the application configuration. The configuration file has all of the following properties:
Find it.
You should discover a server configuration similar to:
[server] host = 0.0.0.0 port = 0
Change the configuration port to 8080 and start the recovered environment:
docker compose up -d --build
Check whether the application is running:
curl http://localhost:8080
If everything worked, you should receive a response from the grades application.
You can also open:
http://localhost:8080
in your browser.
The application should now display a login page.
The application works, but you do not know the administrator password.
Fortunately, the administrator remembers something:
I took a screenshot of the admin interface that contained the login information.
The recovered application files contain:
admin-screenshot.png
Unfortunately, the screenshot appears to have been corrupted while it was being transferred.
Try inspecting the file:
file admin-screenshot.png
Then inspect the first bytes:
xxd admin-screenshot.png | head
Something is wrong with the file header.
A valid PNG file starts with the following bytes:
89 50 4E 47 0D 0A 1A 0A
Use a hex editor to repair the corrupted bytes:
hexedit admin-screenshot.png
After repairing the file:
file;Use the credentials to log in to the grades application.
Before continuing, look again at:
admin-screenshot.png
The screenshot is not particularly large or detailed.
However:
ls -lh admin-screenshot.png
shows that the file is considerably larger than expected.
Maybe the screenshot contains more than an image.
For this exercise you will use a new tool:
binwalk
Start by running:
binwalk admin-screenshot.png
Study the output.
If Binwalk detects additional content, try extracting it:
binwalk -e admin-screenshot.png
Inspect the extracted files.
Remember that filenames and extensions are not always trustworthy.
Use:
file <filename>
when you are unsure what a file actually contains.
Your goal is to recover:
admin-backup.hex
The file recovered from the screenshot is:
admin-backup.hex
The administrator apparently had a complicated backup procedure.
The file is a hexdump of another file, which has then been compressed and archived several times using different formats.
Reverse the process.
First convert the hexdump back into binary data:
xxd -r admin-backup.hex > recovered
Then determine what kind of file you have:
file recovered
Depending on the output, you may need tools such as:
gzip bzip2 tar mv file
After every step, ask the system what the resulting file actually is:
file <filename>
Continue until there are no more compression or archive layers.
At the end you should recover:
web-paths.txt
Do not delete this file.
You will need it for the final challenge.
You can now access the grades application and authenticate successfully.
However, the administrator remembers that there used to be an older administrative interface.
It is no longer linked anywhere in the application.
Nobody remembers its URL.
It may have been something like:
/admin /old-admin /maintenance /internal
Fortunately, web-paths.txt contains a list of possible paths used during development.
Write a Python program that searches for the forgotten endpoint.
Your program should:
web-paths.txt;You may use:
import requests
For example:
response = requests.get(url) print(response.status_code)
A normal missing page returns:
404 Not Found
You are looking for something different.
The server contains a protection mechanism against aggressive automated clients.
If more than approximately three requests per second are sent from the same client, the network protection temporarily blocks that client.
The block lasts approximately 10 seconds.
A very aggressive script may therefore appear to suddenly stop working.
Your program should behave reasonably and deal with this limitation.
Useful Python functionality includes:
import time time.sleep(...)
You may also want to handle request errors rather than immediately terminating the program.
When you discover the forgotten administrative endpoint:
ISC{...}
Please take a minute to fill in the feedback form for this lab.