Cybersecurity Labs (FOR FREE) - Linux Backdoor Analysis

John Hammond · Beginner ·🔐 Cybersecurity ·3y ago

Key Takeaways

The video provides a comprehensive guide to Linux backdoor analysis using various tools such as netcat, bash, and the proc file system, with a focus on cybersecurity and defensive techniques. It also covers the setup of a virtual machine and the use of Docker and Windows Terminal to access a Linux environment.

Full Transcript

there are so many different options for cyber security training but not all of them are at an affordable price tag or accessible and approachable in the way that you like and you like to learn so anti- siphon training associated with black hills information security and all of that family of companies all put together by John strand have an incredible option called pay what you can it's this whole approach to Education and Training and all this cyber security stuff that I for one love it says look we're here to help you whether or not you're getting started in cyber security you're wanting to improve your skills you're trying to train your team antiphon training has a whole lot of awesome curriculum there now what I want to do in this video is regardless of a price tag I want to showcase some of the free resources like free exercises free activities free Labs things that you can play with without any cost for free for fun but before I do I would be remiss not to mention all of the incredible options that come from anti- siphon training whether or not it's live training or on demand training things that you want to catch a whole live webinar for or just catch some videos and be able to take a look at it after the fact whenever you want to learn tons of different courses on purple teaming on Enterprise forensics and response from initial access penetration testing Enterprise security packet decoding regular Expressions anything and at the top of their website there is this option for pay what you can training where you can choose how much you want to pay a couple of these courses are an option for you s course skills like Security operation Center regular Expressions active defense and cyber deception let me click on uh getting started in security with black kills information security and the miter attack framework with a pay you can course you can gain access to their cyber range which is really a meta CF it's a giant capture the flag that you can do whatever the heck you want to do with it but this is one of their Premier courses it says look anyone that's new to information security anyone that wants to dig into cyber security just fire it up of course John strand is a head honcho lead in this thing one incredible fellow a seriously great friend and I respect the hell out of everything that he does and they have one upcoming course April 17th through the 20th so if you want to register for that live training you can go ahead and click on it here and look this is the form that you can fill out cruise through it but it is pay what you can look if you want to pay $25 or like $500 you can absolutely do it run through it here all these options whatever you need to fill out to purchase this thing and and realize hey John what the heck you said pay what you can but here all these options with dollar signs $25 $50 $100 check it out if you look at this for tuition assistance please click here click on this thing new form all that goes away he says would you like to start another registration yes absolutely scroll down uh fill out all the stuff but now that option for Price Tag is gone so let me fill this out super duper quick now take a look all of this 0 you can jump in for free let me hit next nothing else left to do here we can submit and we've got that free pay what you can training there we go registered didn't have to pay a cent didn't have to enter any credit card information didn't have to do anything to slap in some of the info and I've got a confirmation number and I'm ready to rock I'll get a nice little countdown cool this is going to be coming up pretty quick all right now what we can dive into in in this video is getting our hands on some of the virtual machines and labs and exercises that are included in these pay what youou can courses that John strand bless his heart generous as all get out is willing to offer and give to the world completely for free but if you want to take the most out of all this you should work with the virtual machine that's been prepared and provided for you they do suggest hey you can use this in VMware Workstation or you can use Virtual box of course which is free a little bit more accessible if you aren't using vmw workstation player any of these options All In All you have to download the virtual machine itself it's included in a szip archive and they stress look if you're taking the class if you're getting into the fun and action here you should probably download this like right now it takes a little bit to download it's a big big file so click the Go Button I'm going to go Ahad and save it with my virtual machines I'll hit save there and I'll start to see this thing download they do give you instructions as to how you might go and extract this if you don't have seven zip usually in the class that they do live trainings for we'll hand that out in the USB drive but hey you should be able to kind of pull this thing down extract it as needed the username and password for all the virtual machines are just ADHD lowercase no quotes and of course I have a Discord server if you have any questions need support it's all yours hey quick note this is like a 16 GB file to download so seriously download it now I'll include the link in the video description too okay so my virtual machine has finished downloading I'm going to go and right click on this and I'll use szip to extract it to this directory here that should go ahead and carve this out okay and now that that is finishing up I'll go ahead and open this in VMware Workstation I'm going to end up using VMware Workstation however of course you can use VMware Player you you could use Virtual box whatever fits your fancy here inside of VMR workstation I'm going to go ahead and hit open or control U on the keyboard I'll go ahead and navigate to those virtual machines and where I went ahead and stored this and I'll open up that vmx file now I can open this and that should go ahead and spawn in the virtual machine I'm going to rename this I'm just going to change the settings here go to the options Tab and I'll call this John strand pwic for pay what you can hit okay on that and now we can turn this thing on if it asks whether or not you moved it or copied it I'm going to go ahead and click ion copied it and it might wh and complain that virtualization is not supported on this platform just for a little bit of background knowledge the virtual machine for the pay what youan courses and all of John strand's lectures use some virtualization within virtualization in fact it's using WSL or that windows subsystem for Linux where you have Linux as a virtual machine inside of your Windows Virtual Machine it gets weird but in most cases you will need to probably if you run into this issue reboot and change your bios settings you honestly can just Google like hey your computer's manufacturer and then bios enable virtualization within virtualization there are a couple weird Oddities for every single make and manufacturer but trust me you can track it down and we should be able to go and boot this machine without an issue looks like in my case I need to do that so I'm going to reboot and change those settings and I'll be right back all righty back in Action let's see if I can go ahead and turn this sucker on fingers crossed all right success looks like it's booting without an issue looking good hey just for your awareness I am using an asro or ASRock Creator machine I had to boot into my BIOS and I turned on svm mode made sure that was enabled I also had to go into the advanced configuration settings CPU stuff to turn svio Sr iov whatever setting I don't know computers and turn that on also still wouldn't work I asked Uncle Google brought me to reddits all holy reddits hey they've got all the answers uh looks like this helped me out here BCD edit the command to set hypervisor launch type off and then with the optional features of Windows I would turn off Windows subsystem for Linux and another reboot that end up working for me so hey Kudos and credit to all those folks I'll link that in the description if that helps you just as well with that we are booted up to our machine let me go ahead and hit ADHD as the password and we know for the user ADHD and we can log right in all right I amped up the display settings here so hopefully you can see this a little bit better and we do have a couple uh shortcuts on the desktop for zap you have nmap you have Docker Windows terminal and we should be able to actually open up Windows terminal and then choose you know I also want a new buntu machine because again this is using the windows sub system for Linux so you've actually got Linux as a virtual machine inside of your Windows Virtual machine and we can do a whole lot of super cool fun stuff with that uh let me go and close this out and it bring us to the labs here if I double click on that shortcut you'll note that we'll open up our web browser and this is where John strand in all his glory has shared all of these Labs that you can go through for free literally for free and these are the ones that you might be able to dig into for the introduction to Sock Security operation Center and all those skills that you might gain look at all these things there are so many super duper cool ones and in just a GitHub repository this is nice and easy and that you can just sort of copy and paste like you can press the I believe button see it happen watch the magic and fold for your very eyes so let me go through and showcase this but seriously you can go to this within your web browser right now if you wanted to the intro Labs just right here is exactly what you want to get to uh one thing to note though is that they do have a batch script to be able to pull and clone all this stuff that is worthwhile to do uh so let me go ahead and make sure that we pull and update all of the labs to the latest versions if you minimize your web brows and you go open up your file explorer they should be present if you move into the C directory here we can go and explore what's on the file system they do have a tools directory here along with the atomic red team a bunch of others you do have this lab update script here but there's actually inside of the intro Labs folder a lab update pull a batch script which should be a little bit better for us to use let me go ahead and double click on that you can see it will go ahead and pull down all of the latest Labs with Git and then we're good we're good to go and one other thing that uh John strand recommends is if you actually make sure that Windows updates is off just for the sake of hey things running smoothly in class you don't want to install these updates if you want to go ahead and actually make sure within the advanced options all of these Microsoft Windows updates are off don't let it do it if you want to be super hardcore you can go the windows services and like seriously just go kill and stop the Windows update service let me see do I have that down here yeah Windows update let me just right click stop we could also go into properties here and make that uh disabled there we go we set that startup type to disabled hit apply and okay now that all of that boilerplate stuff is done hey you know let's go ahead and do a lab let me fire up the edge browser that I had where we were looking at the intro Labs navigation that we started with and we could dive into the intro to Sock class and probably take a look at hey just the very first lab for us the Linux CLI Linux command line bear in mind hey this is meant to be a beginner friendly lab so we're going to be going to some Basics here but that's okay for folks that are just getting into this this might be really really cool to get some lay of the land for some the Linux file system and some of the Shady shenanigans that can happen with malware reverse shells back doors all that stuff so in this lab we'll be looking at a back door through the lens of the Linux CLI or the Linux command line interface we'll be using a large number of different basic commands to get a better understanding of what a back door is and what it does we'll be using three different Ubuntu terminals the first will be the first will be where we run the back door the second will be where we connect to it the third is where we'll be running our analysis so let's get started by open up a terminal as an administrator I'm going to hit the Windows key I'll type in terminal and I'll hit control shift and enter to open that up as an admin there we go now that that's open let me get back to it and it says look if you want to open up a Ubuntu command prompt that is where we'll use our little drop down we can do that just as well here's Ubuntu another control shift 3 if you're a keyboard junkie now we want to become root we want to become the super user so what we will do is pseudo or super user do su to switch user and then a hyphen to denote look I don't want to be any specific user to switch into I just want to become root the absolute administrator the ruler of all the Linux domain let me hit pseudo Su hyphen and now you need to enter the password again that is ADHD if you aren't familiar with Linux it's just not going to display what you're typing the keys don't show up even with like asterisks or stars or whatever you just have to trust that you're typing correctly hopefully it's okay to do it's only four letters I'll enter and now you can see I am root note The Prompt has changed with a little #no longer than the dollar sign we've got our octo Thorp here and that denotes that we are root if I run the who Ami command that validates that now we have a root prompt we want to do this because we're going to have a back door running as root and then a connection from a different user account on the system first we need to create an fifo back pipe or a first in first out sort of different file everything in Linux is a file even those weird network devices or whatever I don't know manual human interface devices like your mouse and keyboard all that can be treated and understood as a file within Linux so let me go ahead and create this to make nod whatever Back pipe as a type of device here and then p p is the pipe that we want to refer to but back pipe will be the name of the file let's go ahead and copy this again super duper easy switch back I'll paste that in you can use the right click on your keyboard now if I LS you can see there is our back pipe file looks like we had another honey Port Dosh file in the current directory that's okay all we care about is our back pipe and now we can start the back door what we do is some special syntax here where we denote we're going to run the bash command we're going to take input from a file descriptor now this is a weird thing you can think of a couple of different ways that you interact with your computer through different streams right you have a input stream like what you type on the keyboard or as you move your mouse and that is a standard input stream that has a numerical identifier zero just what you're typing in hey consider it zero as just a number you could have standard output like the stuff that's displayed on your computer screen info that returns back to you when you run commands in the command line that's standard output and that number is one there's also standard error which is like number two that's another output stream but specifically designated for errors and stuff that goes wrong you don't have to worry about it right now but just for the press the I believe button zero is our input and one is our output so take a look at what we're doing here we're running bash with standard input being read in with like a little less than redirector from our back pipe piped into to take some of the standard output and standard input into another application netcat netcat is going to listen on Port 2222 or quad 2 where standard output you can see that number one there is going to go funneled back into the back pipe so kind of weird right but bear with me that is going to act as our back door that's just the syntax the semantic sugar let me go ahead and copy this one more time I'll paste it into our Command Prompt here once I hit enter now there's no output nothing is happening but on Port 22222 a lot of Tut tws we are going to have a back door or sort of like a bind shell like it's literally waiting and listening for connections on Port 2222 that it will actually allow you to enter commands and run code the description explains this just as well but now we want to open up another Ubuntu terminal that is where we'll go ahead and connect to work with our back door open up another Ubuntu terminal they recommend that you use if config I'm going to say look hey if config is deprecated it's not what you should be using in today's modern day and age we want to try and use the command IP now IP with other parameters or arguments or subcommands you could use Adder to list addresses and in fact you want to show them with another sub command IP Adder show now that will enter in display our same interface eth zero the important one here with the inet or IP address actual address 17218 111125 that is our host that's our IP address to our Linux machine so I'm going to go ahead and copy that and now it suggests that we try to connect to our back door let's use netcat to connect to that IP address on Port 22222 remember your IP address will be different as ours is we end in what 250 yeah so let me go ahead and netcat to that IP address at that port 2222 hit enter and now there's nothing happening on the screen but if I actually type in the who am I command just as I did earlier remember that root output is what we saw a moment ago I can LS to list stuff in the current directory I can say PWD to see hey what is my present working directory I can run the ID command I can go ahead and touch a file now if I list that out there's that file because we are interacting with this machine because of our back door and through our back door they go ahead and validate the exact same way and you have a simple Linux back door as rout now we can open up another ubun terminal and start our analysis we have one where we created the back door we have one that connects to it and now a third one for analysis let me hop back over there create a new ubun terminal and let's again run as rout so pseudo Su switch user to The Hyphen enter the password and now we're root now we want to be root because looking at network connection and process information systemwide requires that root access basically it's hard to do your job as a sock analyst without this administrator privilege so let's start by looking at network connections with lsof Or List open files when you list open files you can use the TAC I flag to look at open internet connections when you use Tac P you're actually asking lsof this command don't try and guess what service and Port it's on just give us the port number I just want to see what Port is actually being open for this open file so let's use lsof Tac I Tac capital P and now take a look we actually have TCP service running on any interface that's star on 2222 the port number for our back door you can see that it is listening and that is a little bit peculiar we can see netcat is the command running that even the process ID and the user that invoked it the file descriptor all the stuff that could be super helpful for our analysis because especially that process ID number might allow us to dig into it a little bit further if you didn't want to use the capital P argument to list open ports you can use the lowercase p switch to denote anything associated with that process ID in our case we know that that is 231 so let's use lsof Tac lowercase p 231 now we'll drill down into specifically that netcat command and take a look we can actually see this is the current working directory that it's in it's in/ root we can see the file that it might be working with that fifo or first in first out back pipe note that that's specifically the file that it's using and the ipv4 address the information the port that it's listening on or even the connection that's coming from that's super duper helpful now other things that you might be able to do are look at these other running processes we know this netc cap process is running but what else is being ran and invoked so you can use the PS command to be able to do that we'll use the Au switch a for all processes used sort of by user n x to include the processes using a teletype terminal like a real interactive shell let me go ahead and run PS Au and check it out there is our netcat Command that we saw just a moment ago and there is our rout running on that process ID 231 for our netcat listener I think we can actually use PS elf and that we'll try to list these out in a sort of like tree like structure where you can see sort of a branch one child process after the parent process note hey this is the original pseudo Su command that we ran and starting to invoke bash and then start to listen on Port 222 two lots of twos now finally let's go navigate into the proc directory this is something super specific and special Linux and that it's a directory inside of Linux that does not exist on the physical hard drive like it's not in your file system but it is something in memory it's something that Linux uses and allows us to see data associated with various processes that are running that are active in memory this can be super duper useful because it allows us to dig into that memory to see what might be happening if you change directory into slpr and the process ID remember ours is 231 now inside of this directory we have a whole lot of different interesting stuff to dig into you actually have the executable that's kind of being ran Within in memory you actually have the current working directory as even like a Sim link if I try to do LS tacla we could actually see what that CWD refers to it's pointing towards that SL root directory where we know that this thing started from and the executable is even going to netcat it knows that it's /bin netcat do openbsd just one of the netcat variants you could dig into the memory you could see what things are mapped you can see what files have been accessed you can even see the command line that it was invoked with tons of cool stuff in of the proc directory but they recommend inside this lab even running the strings command to take a look at what you might be able to pull out of the running executable let's run strings. exe and if I scroll through this you could even see like the help output like literally the usage to run the netcat command and now you got a pretty clear indicator like a good Smoking Gun that look if you put on your blinders and you didn't know that you would were manually running this back door say you switch perspective to the analyst to look through this now you know exactly how this back door was created because you were able to find and carve out and literally dig through using the proc file system and everything that you've learned on Linux command line to note that's netcat and that's how they crafted this executable and back door and that is the very very first lab that you could cruise through for free as part of the introduction to sock or Security operation Center course all from John Strand and anti- siphon training and all this incredible pay what you can if you really really like want to make this thing free like you can it's it's up to you wanting to take on that learning and want to go on this journey so I hope that's kind of cool I hope that's kind of fun look this was just the tip of the iceberg and I was trying to speedrun through the lab because this video is already long enough as it is setting up the virtual machine getting into the class I hope it's just cool and opens a whole new wide world for you to have things to play with have things to learn from cruise through a couple of these Labs I hope I can make a couple more videos on this and uh I just love that look it's in it's in GitHub you can copy and paste you can make this super duper easy and gain a whole lot of exposure to new tech new technology new software new solutions to things that you might not have seen before so uh I hope that was fun I hope you enjoy this video please do all those YouTube algorithm things like comment subscribe and I've been talking way too fast for way too long I'll see you in the next video

Original Description

https://jh.live/pwyc || Jump into Pay What You Can training -- at whatever cost makes sense for you! https://jh.live/pwyc Download the PWYC VM: https://www.antisyphontraining.com/john-strand-training-lab-download-instructions/ Reddit Instructions for nested virtualization: https://www.reddit.com/r/vmware/comments/k7hd4z/virtualized_amdvrvi_is_not_supported_on_this/ John Strand's Intro Labs Github: https://github.com/strandjs/IntroLabs 🔥 YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe! 🙏 SUPPORT THE CHANNEL ➡ https://jh.live/patreon 🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor 🌎 FOLLOW ME EVERYWHERE ➡ https://jh.live/discord ↔ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/instagram ↔ https://jh.live/tiktok 💥 SEND ME MALWARE ➡ https://jh.live/malware
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 0 of 60

← Previous Next →
1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
28 Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
38 Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

This video provides a step-by-step guide to setting up a virtual machine and analyzing Linux backdoors using various tools such as netcat, bash, and the proc file system. It covers the setup of a virtual machine, the use of Docker and Windows Terminal to access a Linux environment, and the analysis of backdoors using Linux CLI and other tools.

Key Takeaways
  1. Download and extract the virtual machine
  2. Set up the virtual machine using VMware Workstation or Virtualbox
  3. Enable virtualization within virtualization in the BIOS settings
  4. Access the Linux environment using Docker and Windows Terminal
  5. Analyze the backdoor using netcat, bash, and the proc file system
💡 The use of the proc file system and Linux CLI can provide valuable insights into the analysis of Linux backdoors

Related Reads

Up next
NordVPN Coupon Code 2026 | Exclusive Discount + 4 FREE Months
Tutorial Stack
Watch →