Linux Hacking: strings & ltrace: Leviathan: OverTheWire (Levels 0-1)
Skills:
Tool Use & Function Calling80%
Key Takeaways
Uses strings and ltrace to solve Leviathan Levels 0-1 on OverTheWire
Full Transcript
hello what is going on everybody my name is John Hammond and welcome back to the YouTube video of mine and in this video and the next couple I'm gonna try and get into the Leviathan war game on over the wire then online war gaming website so we just finished up bandit in a previous series so now I want to move into Leviathan it's kind of at least seemingly the next or quote-unquote one of the suggested next games to play there's a little bit of description as to what the game is not terribly difficult on the rating scale doesn't require any knowledge of programming just a little bit of common sense and some knowledge about basic Unix commands some of these are kind of clever and you may not have been used to that syntax or seen them before so that's why I wanted to showcase them and you'll see in the webinar face that all of the levels level one all the way through level seven here at level six I guess I don't know they don't have any information so we're probably just gonna be only in the terminal the entire time no real need to have this web browser so I'm gonna hop over to the terminal and you can see that I have changed my theme a little bit just to hopefully attract some I don't know maybe some others that might see these blue and green not blue what the heck black and green hacker stuff in the thumbnail and I don't know maybe get some more viewers that way I don't know just low-hanging fruit to get the script kiddies so let's make a connection to the war game Leviathan it's uh it says here in the description of the of the war game the username is Leviathan zero as usual same with how it was for bandit zero and the password is the life in zero for just this first level make sure we use that as our username and the hostname remember we're using the Newport is 2223 for this war game for Leviathan and once we can make connection it will want to ask for the password let's start to use that SSH past setup that we had before so I'll create a file for this user and put the password in there and I actually learned from a comment and the last series for bandit that the command substitution in bash is normally I had learned it through backticks however that's really old and it's pretty much deprecated so the more common style that has superseded is to use a dollar sign like you would for kind of variables but replace their surround your command in single you know parentheses so that will do the same thing and it's at least more proper or at least more common these days so I'm just gonna copy pasted that'll come in because I'm lazy and now we are connected eventually okay cool so you can see logo here over the wire and we are in so let's see what we got nothing by default in the home directory so let's list out all things backup is a different looking directory that we aren't usually seen before it's hidden because of that period there so there's a bookmarks out HTML in here let's just see what that is and it's a lot of HTML holy crap super gross stuff knowing that we want to have a password let's just try and grep for password in this and we get a hit okay cool looks like password for life and one is this thing okay kind of a cheap hack whatever but that got us a password let's put this in our leviathan1 file and now let's modify our connection line to move to a life on one so all we did for that one was just find the file it was hidden hidden directory and then grep through it for just a string password because that we know that's all we wanted to find was the password for the next level that's how these war games work so now we're gonna Leviathan one and what is this thing check password what wrong password good bye alright so it's probably asking for a kind of string in what this password may be so I'm going to run strings on it on that file on that binary to see what else might be in here right what other plaintext and readable strings might be present in the binary there's the prompt there's probably the show command it'll execute once we get it correct and doesn't look like it's doing anything else or anything that we can really see in here so let's look at some other tools el tres is a good one for simple command-line binary like reconnaissance I need the dot in the forward slash here to actually run the binary cuz el trace will follow along with it so it looks like it's gonna run printf and then the gate character for our input so hello I enter and we can see that okay it runs get character a couple times and then string compare STR compare hell so the first three letters of I guess what I entered and then the word sex okay I suppose that is the password so let's try and run with that input and we get a dollar sign we get a bash prompt well not so much bash maybe just a regular shell as we saw in the string up there just bin SH so Who am I I'm Leviathan - now cool that means I can cat out the password for the next level by one Leviathan - and this directory here etc life and pass is just noted in the little in the prompts that okay you can look in the let's enter live life and pass folder for the various password levels so okay that is the token to get us to the next level let's break out of this put this in a Leviathan two files so we can save it for later and now we can move into Leviathan 2 for the next war game cool alright ah that's all for now I just want to get you guys your feet wet with the game and get us set up so I'll see you in the next video when we tackle the next level - thank you guys so much for watching I hope you're enjoying this series and please may if you want to like comment subscribe do what you got to do alright see you later
Original Description
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
GitHub: https://github.com/JohnHammond
Site: http://www.johnhammond.org
Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Tool Use & Function Calling
View skill →Related Reads
📰
📰
📰
📰
Virus MAYUNDO à l’UNIKIN : Quand mon propre PC s’est fait piéger (et comment sauver vos fichiers)
Medium · Cybersecurity
The Frontline of Modern Cyber Defense
Medium · Cybersecurity
Why Proactive Threat Hunting Matters in Managed Cybersecurity
Medium · Cybersecurity
I Tracked Myself Using AI — What I Found Kept Me Up All Night
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI