Linux Hacking: strings & ltrace: Leviathan: OverTheWire (Levels 0-1)

John Hammond · Intermediate ·🔐 Cybersecurity ·8y ago

Key Takeaways

Uses strings and ltrace to solve Leviathan Levels 0-1 on OverTheWire

Full Transcript

hello what is going on everybody my name is John Hammond and welcome back to the YouTube video of mine and in this video and the next couple I'm gonna try and get into the Leviathan war game on over the wire then online war gaming website so we just finished up bandit in a previous series so now I want to move into Leviathan it's kind of at least seemingly the next or quote-unquote one of the suggested next games to play there's a little bit of description as to what the game is not terribly difficult on the rating scale doesn't require any knowledge of programming just a little bit of common sense and some knowledge about basic Unix commands some of these are kind of clever and you may not have been used to that syntax or seen them before so that's why I wanted to showcase them and you'll see in the webinar face that all of the levels level one all the way through level seven here at level six I guess I don't know they don't have any information so we're probably just gonna be only in the terminal the entire time no real need to have this web browser so I'm gonna hop over to the terminal and you can see that I have changed my theme a little bit just to hopefully attract some I don't know maybe some others that might see these blue and green not blue what the heck black and green hacker stuff in the thumbnail and I don't know maybe get some more viewers that way I don't know just low-hanging fruit to get the script kiddies so let's make a connection to the war game Leviathan it's uh it says here in the description of the of the war game the username is Leviathan zero as usual same with how it was for bandit zero and the password is the life in zero for just this first level make sure we use that as our username and the hostname remember we're using the Newport is 2223 for this war game for Leviathan and once we can make connection it will want to ask for the password let's start to use that SSH past setup that we had before so I'll create a file for this user and put the password in there and I actually learned from a comment and the last series for bandit that the command substitution in bash is normally I had learned it through backticks however that's really old and it's pretty much deprecated so the more common style that has superseded is to use a dollar sign like you would for kind of variables but replace their surround your command in single you know parentheses so that will do the same thing and it's at least more proper or at least more common these days so I'm just gonna copy pasted that'll come in because I'm lazy and now we are connected eventually okay cool so you can see logo here over the wire and we are in so let's see what we got nothing by default in the home directory so let's list out all things backup is a different looking directory that we aren't usually seen before it's hidden because of that period there so there's a bookmarks out HTML in here let's just see what that is and it's a lot of HTML holy crap super gross stuff knowing that we want to have a password let's just try and grep for password in this and we get a hit okay cool looks like password for life and one is this thing okay kind of a cheap hack whatever but that got us a password let's put this in our leviathan1 file and now let's modify our connection line to move to a life on one so all we did for that one was just find the file it was hidden hidden directory and then grep through it for just a string password because that we know that's all we wanted to find was the password for the next level that's how these war games work so now we're gonna Leviathan one and what is this thing check password what wrong password good bye alright so it's probably asking for a kind of string in what this password may be so I'm going to run strings on it on that file on that binary to see what else might be in here right what other plaintext and readable strings might be present in the binary there's the prompt there's probably the show command it'll execute once we get it correct and doesn't look like it's doing anything else or anything that we can really see in here so let's look at some other tools el tres is a good one for simple command-line binary like reconnaissance I need the dot in the forward slash here to actually run the binary cuz el trace will follow along with it so it looks like it's gonna run printf and then the gate character for our input so hello I enter and we can see that okay it runs get character a couple times and then string compare STR compare hell so the first three letters of I guess what I entered and then the word sex okay I suppose that is the password so let's try and run with that input and we get a dollar sign we get a bash prompt well not so much bash maybe just a regular shell as we saw in the string up there just bin SH so Who am I I'm Leviathan - now cool that means I can cat out the password for the next level by one Leviathan - and this directory here etc life and pass is just noted in the little in the prompts that okay you can look in the let's enter live life and pass folder for the various password levels so okay that is the token to get us to the next level let's break out of this put this in a Leviathan two files so we can save it for later and now we can move into Leviathan 2 for the next war game cool alright ah that's all for now I just want to get you guys your feet wet with the game and get us set up so I'll see you in the next video when we tackle the next level - thank you guys so much for watching I hope you're enjoying this series and please may if you want to like comment subscribe do what you got to do alright see you later

Original Description

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010 E-mail: johnhammond010@gmail.com PayPal: http://paypal.me/johnhammond010 GitHub: https://github.com/JohnHammond Site: http://www.johnhammond.org Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 0 of 60

← Previous Next →
1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
28 Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
38 Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

Related Reads

📰
Virus MAYUNDO à l’UNIKIN : Quand mon propre PC s’est fait piéger (et comment sauver vos fichiers)
Learn how to protect your files from viruses spread through USB drives and recover your data if infected
Medium · Cybersecurity
📰
The Frontline of Modern Cyber Defense
Learn how cyberattacks often start with harmless-looking events like phishing emails or malicious URLs and why a multi-step approach is crucial for modern cyber defense
Medium · Cybersecurity
📰
Why Proactive Threat Hunting Matters in Managed Cybersecurity
Proactive threat hunting is crucial in managed cybersecurity to detect and respond to threats before they cause harm, rather than just reacting to alerts
Medium · Cybersecurity
📰
I Tracked Myself Using AI — What I Found Kept Me Up All Night
A person used AI to track themselves and found sensitive information in 40 minutes, highlighting cybersecurity concerns
Medium · Cybersecurity
Up next
NordVPN Coupon Code 2026 | Exclusive Discount + 4 FREE Months
Tutorial Stack
Watch →