diff options
| author | Gabriel Schneider <[email protected]> | 2026-03-26 16:23:24 -0300 |
|---|---|---|
| committer | Gabriel Schneider <[email protected]> | 2026-03-27 13:48:42 -0300 |
| commit | 7c32657002fca2c7e2195d789b1b11e3071d79a2 (patch) | |
| tree | 6ee80577abce9f16251b3b8c642ae290ad8084b7 /trees/blog/archive | |
| parent | c5388feaf9a3bc57070af7c75d03c88bc4fbda4a (diff) | |
| download | 0x4200.cafe-7c32657002fca2c7e2195d789b1b11e3071d79a2.tar.gz 0x4200.cafe-7c32657002fca2c7e2195d789b1b11e3071d79a2.zip | |
Squashed older blog files
Diffstat (limited to 'trees/blog/archive')
| -rw-r--r-- | trees/blog/archive/Getting Hands Dirty with Hacking.md | 181 | ||||
| -rw-r--r-- | trees/blog/archive/hello-2024.md | 30 | ||||
| -rw-r--r-- | trees/blog/archive/umdctf-2024-cmsc430.md | 52 | ||||
| -rw-r--r-- | trees/blog/archive/umdctf-2024-donations-fixed.md | 24 | ||||
| -rw-r--r-- | trees/blog/archive/umdctf-2024-donations.md | 38 |
5 files changed, 325 insertions, 0 deletions
diff --git a/trees/blog/archive/Getting Hands Dirty with Hacking.md b/trees/blog/archive/Getting Hands Dirty with Hacking.md new file mode 100644 index 0000000..3053f58 --- /dev/null +++ b/trees/blog/archive/Getting Hands Dirty with Hacking.md @@ -0,0 +1,181 @@ +--- +title: Getting Hands Dirty with Hacking +date: 2022-11-03 +publish: true +tags: [] +--- + +# Intro & Motivation + +For a a while now I have been thinking about writing this. Earlier I've written +about [getting into +Cybersecurity](https://medium.com/@gabrielschneider100/going-to-cybersecurity-as-a-software-engineer-intern-d416881ab2a2), +I was about a month into my internship and it was much more about my reaction +to: "You're going to Security now, good luck young one". + +Now I'm five months in, and many things have changed. I'm still here (literally +here, I work from home), I'm still an intern, but still, things are very +different. + +So, I'm writing this here because there were many times where I had to stop, +grab a piece of paper and just dump the new things that were clouding my head. +I still wrote almost daily markdown notes on the new things that I was +learning, but still, it's different, sometimes all I need is a blank piece of +paper and a nice pen. The same way I write a lot to myself, it's not enough, +from time to time I feel the need to share what I've learned, so this is it. + + +## Processes & Techniques + +In the start I was: "I want to get really good at hacking, so I'm going to +learn new techniques and get really good at them, SQL Injection, XSS, wait for +me I'm coming after you!". And while there's value to that, by itself, +practicing those techniques wasn't really going to help me that much. I was +trying to turn into a good fighter just by repeatedly punching a punch bag, +it's not going to work just by itself, I'm going to get my ass kicked this way. + + +The thing that was missing in my approach was actually deeper than I expected, +to be a hacker you have to think like one. For a very long time my mind was set +on building things and solving problems, I wanted to make robots, games, and +explore maths; that was basically it. Software Engineering was a straight path +ahead, it's different, but at the end it's just building things and solving +problems. That's not the case with Hacking, at all. + + +To think like a hacker honestly is like listening to your inner devil. When you +come across something, you want to take advantage of it, I want to learn about +it until you know enough to break it. It took a while, but I can feel the +effects of my _self corruption_, this inner evil voice is already talking _all +the fucking time_ in my head. + +On the Internet you see hackers doing stuff with Software and then doing +crazier stuff with Hardware, it didn't made much sense to me how those people +could change domains like that, now it does. It's like coding in Clojure and +then going to embedded C, the mindset is _basically_ the same, it's the +enviroment and the tools for it that changed. + + +## My first Big Project + + +When I started to notice a big improvement in my _Dark Arts_ fighting +techniques was when I stopped to think about my thought process and it write +down. A month ago I was faced with: "You have 4-5 weeks to test those websites +and write a report, good luck pal". I work in a _great_ team, but I felt like +they had put way too much faith in me at the time. For the first week I was +just testing with the techniques that I had learned, I was much better at those +than I was before, but still. + +I had _one_ good finding and that was it. I had a motivation rush after finding +it, but soon it started to feel like I was trying to climb a huge wall with my +bare hands. It as then that I stopped, grabbed a piece of paper, a nice pen, +did some research about the _pentesting process_, read some checklists and +started building my own. The thought process was forming in my head from +working with my peers, from the things that I was learning from the internet, +my head was getting cloudy with it. Writing it down was like making those +clouds rain, condensating them to water and clearing up my mind. + +The project is done now and it was a great success. This kind of _"process +organization"_ was very important to it's success. + + + + +## Things I've learned + +So, Gabriel, you say; what do you have to show to us? You climbed that wall, +wrote some shit in some stone slabs, now share it with us! + +So... I say; beware of the golden calfs out there in Security, there are many! + +The first things that I liked is that **it feels like war**. There are clearly +two sides: We (usually a small team or single person) vs them (A company or a +specific product). Some of the processes we use for hacking are actually used +by military intelligence. Lo and behold these are my commandments: + + +--- + +The fist commandment is: **Information is Key**. + +Let's say there's a Pizza shop which has their own delivery service. They hired +us to test its security. The first thing is that we need to do is to gather +information about it. + +- How does it work? +- Which features does it have? +- Can I order Pizza to my neighbour? +- Do they check if I'm the person I'm claiming to be? + +And then you discover: Oh, if the delivery takes more than 30 minutes the pizza +is free. What happens if I order pizza from somewhere far away? Will they +deliever to me? What if it's not that far away, but I keep making changes to +the order so it takes longer? + +You can also find hidden things this way, i.e. They have lower prices if it's +your birthday, but they only change the price if you ask for it, they keep this +promotion hidden for some reason. Can I fake my ID to always get lower prices? + + +> You need to understand how it's supposed to work, its features and +> functionalities. So you know what to break and exploit. + +--- + +The second commandment is: **Organization is Key** + + +We'll gather a lot of information, it will be needed for writing a report to +our Pizza shop client, to our attacks, and to share it with our team. + +Also, for every domain that we are working there will be lots and lots of +information about the specific tools and processes for it. Better organization +means more efficient tests, the next time you do them, because information is +accessible and searchable. My setup is described +[here](https://gbrls.github.io/blog/current-organizational-structure/). + +Organization is also important to keep track of the tests you've done, the time +you did them, and which tests are still left to do. + +--- + +The third commandment is: **Know your domain** + + +Pizza Delivery Services is a very specific domain. Knowing well your domain +will greatly improve your chances of success in an attack. Think how having +worked on the phone in a Pizza Delivery Service would help you exploit another +Pizza delivery companies. + +--- + +The forth commandment is: **Attack fast and with precision** + + +Many times you'll need to execute an attack as a proof of concept. The attack +should be well planned, precise and fast. + + +Most of the time you'll need to take care to not cause disruption to the +regular services. + +You'll need to be fast to not give enough time for them to +react to it. + + +You'll need to be **very** careful with [PII](https://www.cloudflare.com/en-gb/learning/privacy/what-is-pii/). + +--- + +# Conclusion + +Those commandments are maturing, I'm still very new at this and different +people have different styles. Despite those things, I hope they are helpful. + +Security is very big and exciting. Have fun and take care. + + +# References + +- [The Web Application Hacker's Handbook](https://www.amazon.com.br/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470) diff --git a/trees/blog/archive/hello-2024.md b/trees/blog/archive/hello-2024.md new file mode 100644 index 0000000..a5dcc60 --- /dev/null +++ b/trees/blog/archive/hello-2024.md @@ -0,0 +1,30 @@ +--- +title: "Hello 2024" +date: 2024-05-22T23:31:59-03:00 +draft: false +description: "" +--- + + +With about 40% of the year gone I say hello :) + + +I'm way behind schedule for what I expected to post here this year, so I'm +going to make up for it now. I'm going to try to cover topics in a cartoonish +way like the book "Land of Lisp" by Conrad Barski, one of my favourites in any +topics, it made me completely obsessed with Lisp. + +I want to make things which make people be interested and curious about _cool +stuff_ like that book did to me, there could be so much more books like it in +so many different topics. + +I'm also teaching myself how to draw better and it's working! I can confidently +draw better and faster, this makes me really excited to put this skill to use +in a new project. + +I learned a lot of new things and joined a Security CTF team, so there are +topics which I've never covered before. I have an itch to write about those for +a while now. + +"HM1Zb3xmvMc" label="Land of Lisp- The Music Video!" + diff --git a/trees/blog/archive/umdctf-2024-cmsc430.md b/trees/blog/archive/umdctf-2024-cmsc430.md new file mode 100644 index 0000000..33fd708 --- /dev/null +++ b/trees/blog/archive/umdctf-2024-cmsc430.md @@ -0,0 +1,52 @@ +--- +title: "umdctf2024 - cmsc430" +date: 2024-04-28T19:19:27-03:00 +draft: false +description: "" +tags: ["rev", "ctf"] +--- + +### Description + +> This binary was compiled by an hand-crafted, artisan racket compiler, courtesy of UMD's very own CMSC430 class. + +### Reversing + +The attachment was an standard x64 ELF file. After opening it in my +decompiler, and going to the main function, everything seemed pretty +straight. + + + + +Investigating this `sub_17e0` function we see that it has a lot of deep nested conditionals, where in each step it calls `read_byte()` and then compares it to a byte. + + + + +To me this seemed like a pretty easy crack by using symbolic execution to find which input passess all of those conditionals. I tried using a simbolic execution engine inside Binary Ninja, but I never did it before and couldn't make it work. +So I ended up copying those bytes by hand and writing them to a python script to write them to a new file. + +At first this didn't work because I didn't realize that the `read_byte()` function multiples by two the bytes that I reads, so I had to halve them. + +### Flag + +```python3 +a = bytes([0xaa, 0x9a, 0x88, 0x86, 0xa8, 0x8c, 0xf6, 0xe6, 0xd0, 0xde, 0xea, 0xe8, + 0xbe, 0xde, 0xea, 0xe8, 0xbe, 0xe8, 0xde, 0xbe, 0xd4, 0xde, 0xe6, 0xca, + 0xfa]) + +# Added later +b = bytes([x // 2 for x in a]) + +with open('sol.bin', "wb") as file: + file.write(b) + +``` + +```console +└─$ hexdump sol.bin +00000000 55 4d 44 43 54 46 7b 73 68 6f 75 74 5f 6f 75 74 |UMDCTF{shout_out| +00000010 5f 74 6f 5f 6a 6f 73 65 7d |_to_jose}| +00000019 +``` diff --git a/trees/blog/archive/umdctf-2024-donations-fixed.md b/trees/blog/archive/umdctf-2024-donations-fixed.md new file mode 100644 index 0000000..7f8df33 --- /dev/null +++ b/trees/blog/archive/umdctf-2024-donations-fixed.md @@ -0,0 +1,24 @@ +--- +title: "umdctf2024 - Donations Fixed" +date: 2024-04-28T19:18:00-03:00 +draft: false +description: "" +tags: ["web", "ctf"] +--- + + +This is the harder version of [donations](/writeups/umdctf-2024-donations-fixed), it's the same challenge, but you can't donate negative amounts this time. + +After playing with it for a while, I realized that the solution was probably to find a way to donate money to your user, bypassing that Jeff Bezos check. So I tested adding more user id's in the `to` parameter and the money went to them. + +So the solution was to create users, and donate all of their money to a user which will retrieve the flag. + +```http +POST /api/donate HTTP/2
+Host: donations2-api.challs.umdctf.io
+Cookie: session=... +Content-Length: 36
+Content-Type: application/x-www-form-urlencoded
+ +to=lisanalgaib&to=gbrls¤cy=999 +``` diff --git a/trees/blog/archive/umdctf-2024-donations.md b/trees/blog/archive/umdctf-2024-donations.md new file mode 100644 index 0000000..2f7a445 --- /dev/null +++ b/trees/blog/archive/umdctf-2024-donations.md @@ -0,0 +1,38 @@ +--- +title: "umdctf2024 - Donations" +date: 2024-04-28T18:57:47-03:00 +draft: false +description: "" +tags: ["web", "ctf"] +--- + + +After downloading and prettifying the javascript code we see that there's a `/api/flag` and a `/api/donate` endpoints. + +The flag route returns: + +```json +{"detail":"only the wealthy may view the treasure..."} +``` + +After trying some things that didn't work, I went to the donate functionality. +Using the parameters that I found in the javascript I is playing with this funcionality and noticed that you can only donate to a specific user + +```json +{"detail":"you may only donate to Jeff Bezos"} +``` + +And somehow that Jeff Bezos's id is `lisanalgaib` + +The solution was to donate a negative amount and earn that in return. + +```http +POST /api/donate HTTP/2
+Host: donations-api.challs.umdctf.io
+Content-Length: 30
+Cookie: session=... +Content-Type: application/x-www-form-urlencoded
+ +to=lisanalgaib¤cy=-99999 +``` + |
