Posted onEdited onInctfDisqus: Word count in article: Reading time ≈NaN:aN
Challenge
The following is a batch script authentication system. Your goal here
is to get the batch script to authenticate you by inputting a password
into the field. For this extbasic, your goal is to circumvent
authentication altogether. Decrypting the password is for
extbasic11.
关卡给出一个 Windows batch
认证脚本,要求输入内容使脚本认证通过。本关的目标是绕过认证。
@ECHO OFF SETLOCAL ENABLEDELAYEDEXPANSION SET PRIME=2 3 5 7 11 13 17 19 23 29 31 37 41 43 47 53 59 61 67 71 73 79 83 89 97 101 SET CHARS=a b c d e f g h i j k l m n o p q r s t u v w x y z SET PASSWORDVALUE=1 SET INPUT= SET /P INPUT=Insert password: IF "%INPUT%"=="" "%~0" ECHO Authenticating... :OVERLOOP SET CURRENTPOSITION=0 :SUBLOOP IF /I "!INPUT:~%CHARACTERPOSITION%,1!"=="!CHARS:~%CURRENTPOSITION%,1!" SET /A PASSWORDVALUE*=!PRIME:~%CURRENTPOSITION%,3! SET /A CURRENTPOSITION+=3 IF NOT %CURRENTPOSITION%==78 GOTO :SUBLOOP SET /A CHARACTERPOSITION+=1 IF NOT "!INPUT:~%CHARACTERPOSITION%,1!"=="" GOTO :OVERLOOP :END ENDLOCAL&IF NOT %PASSWORDVALUE%==1065435274 GOTO :ACCESSDENIED ECHO You have been authenticated. Welcome aboard! GOTO :SILENTPAUSE :ACCESSDENIED ECHO Access denied! :SILENTPAUSE PAUSE > NUL
Posted onEdited onInctfDisqus: Word count in article: Reading time ≈NaN:aN
Challenge
Captain Kirk has coded this Perl script for all his fellow-captains
to automate their logging. This way they don't have to record their logs
on tape, but they can type them in and archive them. But this log only
seems to log one log?! It automatically deletes all previous logs! Fix
the script for him, so they can keep their logs again! Captain Kirk
给同僚写了一个自动记日志的 Perl 脚本,但每次只留下一条日志,
之前的全被删掉;把它修好,让日志能留存下来。
#!/usr/bin/perl # Captain Kirk has coded this Perl script for all his fellow-captains # to automate their logging. # This way they don't have to record their logs on tape, but they can type them in # and archive them. But this log only seems to log one log?! # It automatically deletes all previous logs! Fix the script for him, # so they can keep their logs again! print'> Hello Captain ' . $ENV{'USER'} . '.' . "\n"; open(STARTREKLOG, '>/var/log/startrek'); print'> Please enter your log data here, end with a "." on a single line.' . "\n"; my$LogText; print'> '; while (<STDIN>) { unless ($_ne'.' . "\n") { last; } $LogText .= $_; print'> '; } print'> Log is being saved to /var/log/startrek' . "\n"; $DateTime = localtime(); print STARTREKLOG ' -- START OF LOG -- ' . "\n"; print STARTREKLOG 'Date/Time: ' . $DateTime . "\n"; print STARTREKLOG 'Log : ' . $LogText; print STARTREKLOG ' -- END OF LOG -- ' . "\n"; die('> Log saved! Now exiting.' . "\n");
Posted onEdited onInctfDisqus: Word count in article: Reading time ≈NaN:aN
Challenge
Bill Gates wrote a Perl script that grants access to the company
records; it has a security flaw that lets everyone in. Fix the flaw.
Bill Gates 写了个 Perl
脚本,用来校验访问者有没有权限读取公司记录;这段脚本存在安全缺陷,任何人都能拿到记录。要求把缺陷修掉。
1 2 3 4 5 6 7 8
#!/usr/bin/perl chomp ( my$User = `/usr/bin/whoami` ) ; print"Checking your access level...\n" ; if ( $User == 'BillGates' ) { print"Authorized! Here are the company records:\n" . `cat /home/BillGates/CompanyRecords.db` ; die ( "Closing...\n" ) ; } die ( "You're not authorized!\n" ) ;
Solution
脚本的逻辑很短:用反引号执行 /usr/bin/whoami
拿到当前用户名存进 $User,然后只有一个 if
决定是否读取
/home/BillGates/CompanyRecords.db。要修好缺陷,改动点必然落在这个比较上;其它行(chomp、print、die)都只是输出,不参与授权判断。
#!/usr/bin/perl # Local reproduction of the ExtBasic 8 flaw (run against our own Perl, no # network). A non-privileged user name stands in for the whoami output. use strict; use warnings;
my$User = "some_user"; # what `/usr/bin/whoami` would return
Posted onEdited onInctfDisqus: Word count in article: Reading time ≈NaN:aN
Challenge
修正一个 PHP 页面里同时带有 bug
和漏洞的那一行,提交修正后的整行。
关卡页给出的是一段数据录入代码,要求:There is only one line that has a vuln, correct it. The output does not have to be valid XHTML and assume that a mysql connection has been made already. There is a bug as well as a vuln. You MUST fix both.
#!/usr/bin/env python3 """HackThisSite Extended Basic 7 (playit) live solver. The level prints a tiny PHP page and asks for the one line that carries both a bug and a vulnerability: <form name="grezvahfvfnjuvavatovgpu" action="<?=$_SERVER['PHP_SELF']?>" method="get"> * vuln: ``$_SERVER['PHP_SELF']`` is echoed raw into the ``action`` attribute, so a path like ``/x.php/"><script>alert(1)</script>`` is reflected as markup and becomes XSS. ``htmlspecialchars()`` fixes it. * bug: the form submits with ``method="get"`` while the handler only reads ``$_POST['data']``, so the INSERT never runs. ``method="post"`` fixes it. The corrected line is posted to ``/missions/extbasic/template.php`` together with the per-load ``formkey`` and ``lvl``. A ``Referer`` pointing at the level page is mandatory, otherwise the endpoint answers ``Invalid Referer`` and the attempt does not count. The session cookie comes from ``HTS_COOKIE`` and is never persisted. """ import os import re import urllib.parse import urllib.request
UA = ("Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) " "Chrome/131.0.0.0 Safari/537.36") BASE = "https://www.hackthissite.org" LEVEL = BASE + "/missions/playit/extbasic/7/" TEMPLATE = BASE + "/missions/extbasic/template.php" CK = os.environ["HTS_COOKIE"]
Posted onEdited onInctfDisqus: Word count in article: Reading time ≈NaN:aN
Challenge
This site is run by a new sysadmin who does not know much about web
configuration. The script is located at http://moo.com/moo.php Attempt
to make the script think you are authed by entering the correct URI.
进入正确的 URI,让脚本以为你已经通过认证。
如果 $passed 只是一个普通的未定义局部变量,第二个
if
恒为假,这题无从下手。题面第一句正是钥匙:new sysadmin who does not know much about web configuration,一个不懂
Web 配置的管理员,对应的就是最典型的一项 PHP
配置错误:register_globals = On。
PROGRAM = "\n".join([ "BEGIN notr.eal", "CREATE int AS 2", "DESTROY int AS 0", "ANS var AS Create + TO", "out TO", ])
defvalue_of(expr, env): total = 0 for term in expr.split("+"): term = term.strip() if re.fullmatch(r"\d+", term): total += int(term) else: total += env.get(term.lower(), 0) return total
defrun(source): env = {} answer = None for line in source.splitlines(): parts = line.split() ifnot parts or parts[0] == "BEGIN": continue if parts[0] == "out": print("out %s -> %s" % (parts[1], answer)) continue name, declared_type, _as = parts[0], parts[1], parts[2] expr = " ".join(parts[3:]) answer = value_of(expr, env) env[name.lower()] = answer print("%-8s %-4s AS %-14s => %d" % (name, declared_type, expr, answer)) return answer
if __name__ == "__main__": print(run(PROGRAM))
运行输出
1 2 3 4 5
CREATE int AS 2 => 2 DESTROY int AS 0 => 0 ANS var AS Create + TO => 2 out TO -> 2 2
Posted onInctfDisqus: Word count in article: Reading time ≈NaN:aN
Challenge
You have this function, provide the value which must be POST-ed as
filename to obtain the desired results: Get the source code of
hackthissite.org/index.php