LIVE: WordPress Intrusion | Cybersecurity | Blue Team | AMA
Key Takeaways
The video covers a live cybersecurity demonstration, focusing on WordPress intrusion, Blue Team Labs, and security analysis, with discussions on various tools and techniques such as log analysis, threat hunting, and incident response. It highlights the importance of hands-on experience and foundational skills for security analysts, and explores topics like cloud security, endpoint security, and cybersecurity certifications.
Full Transcript
[Music] Heat. Heat. [Music] Attack the [Music] planet. [Music] Heat. Heat. [Music] Heat. Heat. [Music] Hey. Hey. What's going on everyone? Happy Wednesday. Happy Wednesday, TCM stream day. Uh, how's everyone doing? Oh, hi from Usuzbekistan. Wow. Hello everyone. Hello. We have uh dumb memes as the first comment of the day. So, welcome. Welcome everybody. Hope everyone is having a great uh first half of your week and I hope you have a remaining second half of your week. Um, this is truly the hump day for me. Uh, it's been a very busy week so far. How's everyone doing? Let's get it. Yeah, we're going to have some fun today doing some WordPress log analysis intrusion, but we'll wait a little bit for people to funnel in uh and we'll probably start the challenge uh in about maybe 20 minutes, maybe maybe about half uh half. How's everyone doing? Good morning. Seeing a lot of good mornings. It's just past noon here for me in uh the lovely I was going to say state of Canada. Uh the lovely country of Canada. Hello from Albany, New York. Nice. Nice. Welcome from Morocco. Wow. From Ghana and I saw it from India. We have people from all over the globe today as I'm sure we we usually do. But this is this is awesome. We have folks from Uganda, from Kenya. This is awesome. Someone from Alaska. Cyber Alaskan. That's awesome. Hope you're all doing well. Um, feel free to, uh, you know, shoot some questions in the chat. We're going to do a bit of Q&A and then we'll hop over to, uh, a Blue Team Labs, uh, online room that I was going to do the other week. uh when when I last streamed, but we ran out of time. So, um we're going to we're going to kick that one off today uh around the the WordPress intrusion, but that will come shortly. Um and I'll I'll tell you all where we can find that challenge when the time comes. Lot of locations in chat right now. That's awesome. We have people people from all over the world tuning in for another amazing TCM Wednesday stream. Just while we're waiting for people to come in, I thought I'll mention uh before I forget, uh just a reminder uh we do have uh some some cool stuff coming up uh next month uh in the months following. Uh so in April we have uh the sock uh uh level one live training class uh that I'm hosting uh for the second time around. We did one back in January uh and it turned out really cool. Uh we had a great cohort and uh really um you know baked in a lot of uh uh stuff into those four days uh of class. So um that was a lot of fun. I'm really excited to do that again in April. So, um, yeah, if you haven't taken the SOCK11 course and if you want to kind of go on that track and maybe, uh, go for the, uh, you know, the PSAA exam or just sort of build up those foundational skills, uh, I think the SOC level one live class is a a great way to sort of dive into that and and really come out swinging with a with a ton of um, you know, all those foundations in your tool set. So, um, if you do have sort of the employer budget, I know we're in sort of the the first or second quarter of the year, maybe we're getting close. Um if you do want to sort of uh jump into that, we uh just a reminder there we have that and we also have uh hacking ad live in May. So uh some some interesting exciting live trainings in in in in the works here. Question from Sir Kit here. Uh this is going to sound crazy. Can you be a sock analyst without having to work with Windows? I absolutely hate Windows. Well, um, we don't see eye to eye on that. I love Windows forensics. I think it's some of those artifacts are just the most fun thing to dive into, but uh, to answer your question, it's tough, right? Um, it's already kind of, um, everything is so Windows heavy and Windows based, right? Like most environments, you're going to have some sort of active directory setup. You're going to have Windows systems. you know, sometimes in like, you know, more startup kind of smaller companies, uh, you might be more like MacOSS-based and such. And so maybe there's some some some opportunities there, but I think sort of few and far between. Um, I've never worked in an organization. I've never worked with an organization uh that does not have some sort of um, you know, majority Windows footprint. And so I think it'll be a little bit more tough. uh but um uh you know uh it's just sort of the way it is uh in in environments these days. Uh any idea what the sock do one certification will be called? Yes. So we kind of a few months back we sort of um uh you know took a step back and thought about um how we want to classify certifications and so we sort of landed on a model of you know we'll have different levels right so um it's going to follow the same format but it's going to be sort of that professional level uh certification because the sock 21 is going to be quite a a step up from um sort of the associate level uh that you get with the sock 101 right so um probably uh professional security or professional sock analyst professional I imagine But uh we are pretty um agile here uh with with the way we you know uh name things. We you know we we want to make things the most competitive and the most uh you know the the the naming schemes that that are going to make the most sense uh to what's being tested for. So PAP. Yeah, there you go. Most likely. Um but we we are not there yet. We'll we'll get there soon. Arubius, welcome. Welcome. YouTube is trolling you apparently. Uh, apparently it's showing you my Tik Toks, but it's it's not showing you when I'm live. Good question from Josh. What will the badge look like? So, with the sock 101, we have the porcupine uh with the sort of shield and swords behind it. Um, that was kind of a custom effort. Uh, shout outs to Hiana for putting that one together. I think it's I'm a bit biased, but I think it's our coolest emblem for a course, but not sure, not not decided on what the sock one uh badge or the the animal will look like yet. We kind of want them to be like evolutions. Um, and so I don't know what a porcupine might evolve into, but we'll we'll figure something cool out. uh got a favorite part module E so one course hard to say um maybe memory forensics uh or file system forensics I'm hoping to really have a good deep dive uh into both like NTFS and and also performing memory forensics at a deeper level and and hunting things like uh you know DLL injections and stuff like that. So, uh, most likely some of that deep dive stuff. Uh, the way the course is kind of going to work, and maybe I'm hopefully not overpromising things here or giving too much away, but, um, the the main overarching theme of so one is going to be sort of changing altitude and and, um, being able to scope out incidents in the enterprise at scale and then sort of work our way down and down a sort of funnel uh, and and, you know, really deep dive in a handful of systems that we might be interested in during an incident. And so it's going to have that sort of at scale, you know, how can we um, you know, maybe threat hunt or how can we, uh, respond to incidents and collect, uh, artifacts that we need at scale on, you know, hundreds or maybe thousands of systems. And then once we find, you know, a system of interest or maybe a few, uh, how do we then deep dive, uh, really into that system and and and, you know, uncover some uh, very advanced detections or very advanced attacks uh, in that regard. So, um yeah, we will see what ends up being my favorite module in stock 111. It was definitely the uh uh endpoint security module. Uh cuz again, we do sort of that live instant response stuff. Uh and and really a bit of yeah, I guess you could say live instant response and really understanding the endpoint. Uh that's sort of where my brain likes to live. I just used the Dier Stevens tool. Nice. Which one? He's got like hundreds of tools and they're all extremely awesome. Um, but yeah, that's awesome to see. We use a lot in uh we use a lot of his his uh tool suite in sock 101 and sock 2011 respectively. Armadillo armor. Yeah, I kind of thought about that. Like uh we just like beef up the the animal a bit and make them look a lot more tough. Uh, do you like building courses or do you like uh hands-on doing the work? Uh, I would say I prefer doing the work. Uh, that's really where um, you know, my skill set shines and where I really actually learn while I'm working. Um, but it is nice to sort of distill um, all of that knowledge sort of into a nice package like a course or a training, right? So um it is really like I feel super privileged to be in sort of both scenarios where I can do the practitioner side and do consulting and then also sort of you know uh package that together for thousands of students to enjoy. What's the rough estimate on the amount of time it takes to develop a full course? That's a good question. Uh really depends. Um, and uh I certainly haven't developed as many courses as uh uh uh Heath or um Alex or or even Andrew Bellini. So I'm kind of the least seasoned uh course developer, I guess you could say, uh in the academy, but Sock 2011 is definitely taking a lot longer than uh sock 101. um mostly just because of all of the amount of uh you know labbing and uh simulations I need to do to collect artifacts and a lot of research goes into some of those more advanced techniques as well. So, um, yeah, it can vary, uh, it can vary pretty wildly, I found. I like your questions today, circuit. Uh, what's the difference between, uh, DFIR, digital forensics, instant response, and sockwork? A lot of people assume it's the same. Uh, can you sort of break it down? Yeah. um you know you're going to see different definitions all over but um they are you know they have a lot of similarities right um if we think of like our standards you know sock analyst kind of thing um usually you have different stages or different um you know levels right you might have uh sort of a triage analyst they call it or like a level one uh maybe analyst that's again doing sort of that initial alert or alarm uh triage right so um as alerts come in you know they're do they're performing like a little bit of a highle disposition on you know the legitimacy you know whether it's a false positive or not and also like understanding the scope right is it um something that could be affecting a single endpoint that maybe is not internet connected or versus you know um uh you know something that that that fired off on on a ton of endpoints right so again performing that initial um scoping of an incident to sort of event uh prevent sort of this whack-a-ole approach where you know you patch one system and then you know uh five more uh sort of spring up. So um but when you start getting into sort of these higher tiers in the sock right these maybe level two or level three um and again every organization's different right everyone's going to have different teams and different uh structures and priorities but typically you know when we get to that those higher tiers in the sock uh there's more of a focus on uh performing that actual remediation right particularly with a level two analyst um is what I've seen um in in most organizations I've either worked with or seen uh But again, that's sort of performing the instant response, you know, maybe leading the teams or working with the incident response teams if there's not a dedicated IR team, right? Maybe it's sort of an ad hoc kind of thing. Um, but again, performing that uh you know, um most parts remediation, right? If we think about where the the triage analyst lives, mostly around that detection stage, uh you know, someone on the incident response side might uh you know, be more focused on the later stages of that model, right? uh the actual analysis response right capabilities. Um uh forensics is really interesting because it can sort of be again that specialized uh sort of thing but it can live pretty much anywhere in that model, right? Uh we might be performing forensics to help scope an incident. We might be collecting uh forensic artifacts to help out with uh uh you know a response effort, right? So, um they can vary widely, but uh again, usually uh these skill sets are a little bit more specialized as you start getting into uh defer or DFIR, but uh there's always a ton of paths that you can go down. Uh is consulting in blue side of security a thing? Yeah, definitely. Um incident response consulting. Yeah. uh um you know we have sort of this concept of retainers right um so if your organization doesn't have sort of an internal uh instant response component or um maybe sort of an ability right you can sort of maybe outsource that out uh to like sort of external parties uh same kind of deal with forensics as well um so there's definitely uh space in in sort of the blue team field for consulting uh for example maybe um you know incident takes place and you're sort of um uh you know directed or or or brought in to sort of again scope out the incident and and work on it uh and work within the internal sock uh with the actual members of the organization as well from an outside perspective. So um yeah there's consulting all around Uh how is blue team uh different in the cloud or is it pretty much the same thing? Uh there's definitely differences right um as we start moving towards the cloud sort of the perimeter a little bit shifts from uh sort of these uh perimeter detections and sort of you know we think about securing the perimeter versus in the cloud a lot of it is focused on identity and access management right so uh a lot of the same principles still apply right the same sort of hardening efforts that we that we have the same sort of tiered model of access role-based access stuff like that uh that we have in the enterprise uh but a lot of that um sort of gets shifted um and the sort of perimeter uh it really relies on identity and so um you know similarities but um definitely a different kind of beast um uh once you start working with cloud environments uh you can also have things like active directory in the cloud right so um uh a lot of our same you know foundations and principles still apply um from a defense perspective whether we're dealing with you know virtualized machines uh in the enterprise versus you know somewhere uh on on Azure servers seeing a few like road map kind of questions. I don't always have the best like one-sizefits-all answer for for road maps, right? Um really just depends on where you're starting from and and the sort of direction you want to go. Uh but for a security analyst role, it's it's it's it's tough. like um uh practical experience in my opinion is is king. Um and sort of having things that you can either blog about or uh talk about in interviews rather than just you know checking some boxes here and there. Um and so again I I would uh just focus on getting that hands-on experience maybe building out a lab. Um you know try hackme is a pretty good resource for working with some of these tools right in a sort of lab environment if you can't uh build things up locally. Um but uh I don't really have specific recommendations on like um you know certifications that you need to check the box, right? Because it's different everywhere you go. It's different globally. Obviously, I have a little bit of bias. I think the um the socket one course is really going to get you uh a very good head start and build out all of those um foundational skills that you need. But again, it's not the only training out there. It's not the only course. It's not the only uh certification, right? Um, and so, uh, I don't have a single recommendation for you other than, uh, you know, maybe figure out where you want to be in a few years from now and sort of work your way up, uh, to, uh, you know, some of the the bridges you might need to cross. So, I would say look at, you know, the, uh, some some job postings of of places you might want to work at or like positions that you might want to be, uh, within the next year or so. Uh, and just look at the requirements, right? Um, again, sometimes the requirements are are not very helpful, right? it might be asking for uh you know a CISSP uh for a triage security analyst role right which just doesn't make sense but you know look at sort of the patterns as you start to look at more um job postings right it's kind of like being a sock analyst itself right is sort of looking for patterns and and sort of doing that aggregation to see you know hey I keep seeing you know these skills pop up right I I keep seeing uh you know uh folks want some someone with uh Splunk experience right so maybe you uh go install the the enterprise trial version of Splunk and start ingesting data and working with that, right? So, um, that's why it's hard to give a roadmap because again, it's just entirely dependent on where the jobs are and what what what they're asking for. Um, and so that's always been my advice. That's always what I've done is I just, you know, research a position that I'm interested in, uh, in the next, you know, few months or so or a year. Uh, and then just write out requirements, right? Sort of build out my to-do list uh, in that way. I know some people have different advice. Some people go about things differently. That's just how I done it and that's the only way that I can uh really uh discuss from a personal uh sort of perspective anecdotally, right? Uh did you go from AZ900 straight to A500? Um I think so. So, I don't know if I went straight to it, but I definitely got 900 first because uh I remember back in the day, I don't know if they still do this. Uh Microsoft has uh every few months they do like a training kind of week or something uh where you can sign up uh and they're going to do like a live uh class on these sort of a 900, you know, Azure fundamentals uh things that you need to know. Um kind of in this live format that you need to attend, right? You sign up for it. Um they check your attendance or whatever. But after those few days, I forget how long it actually is. Uh they'll actually send you a voucher for uh taking the A900. So that's why I got that. It was just sort of like a free thing. I was like, "Hey, why not?" Um and then from there, um uh at the time the the uh position I was working in, we were uh sort of doing a lot more Azure focused stuff. Uh they needed sort of a cloud security engineer type person uh to fill. And so I sort of took it the initiative to um you know go for the AC a500 that Azure security engineer role uh or certification and sort of build out my skills that way and and end up doing a lot of cloud stuff there. So um again that's kind of kind of similar to my answer before is like just what are the requirements either in your role or a role that you want to take uh and can you fill those in some way right um can you uh you know take some training that's relevant or can you um you know uh that's always been my sort of goal uh is just you know figure out where the gaps are and sort of try to fill them become a more valuable uh analyst or engineer first time viewer. How's everyone doing? Welcome. Welcome. Thank you for joining, Rick. Uh, what do you think about job postings for sock tier one positions including auditing for various frameworks on top of alert triage investigation? Yeah, honestly my hot take I don't know if it's a hot take but a lot of like these um entry level analyst positions for some reason or another are just getting ridiculous. um you know there's certain like set of skills that um in my mind uh a tier one analyst should have or should work towards um before they can sort of move their way up in in the sock, right? Um and for some reason companies like to put in the most random things on on these these job postings. Uh maybe they have a specific requirement uh and they're they're not actually trying to fill in like a a traditional T1 analyst. They want someone that can wear many hats, right? Um, I've been there before and so it's definitely a thing. But, you know, um, it it can be a little bit difficult. I think, um, you know, even just a few years ago, a lot of these job postings made a lot more sense. Uh, they weren't asking for certifications that require 5 years of experience to even take uh um to get an entry- level job. So, um, it's tough. Yeah. like especially if you do it the way I do it where you're just looking at positions and sort of trying to pick out the patterns uh for things that you might want to uh pick up or you know uh build up in your resume it's you can start going down rabbit holes which is a little bit tough but that's why I say like a good uh blue team oriented course um is going to fill in a lot of those gaps for you and really um uh you know give you a solid skill set that's going to apply to many of these job postings, right? you're never going to you're never going to have every requirement, right? Or every bullet point on a job posting. Apply anyways, right? Um I've never fit the bill 100% on any of the jobs that I've applied to. And so, um yeah, it's a it's it's kind of like a chess game, you can say. Uh when is so 21 going to be released? Question of the day. Um I don't have uh an exact release date and I don't want to give one because things happen and um like I was saying earlier this course is just has been a monster uh to sort of um scope and sort of uh uh get direction in because um you know it could really go in so many different directions. I could I could keep developing this course for the next 5 years and I still it still wouldn't be in my mind um complete. Right. So um uh we are thinking you know in the next uh you know month or so right so uh or maybe a month or two so uh I don't want to give an exact date for that reason uh just because things happen uh things can even happen during uh QA processes right so maybe I need to go back and rebuild some labs or something so um no exact date but relatively in the near future um and definitely before the summer is what I can Uh you say sock 21 is more dfir. Yep. It's uh really focused on incident response threat hunting at scale uh and uh some deep dive forensics as well. I think uh are really the most valuable um things to to to sort of help you move up uh in a role like um assuming you know the sock one is more geared towards maybe that that triage or tier one analyst. Well, if you want to go down instant response specializations or even just work up to a tier two or tier three or get into digital forensics, right, or threat hunting, um these are the the sort of skills you need to uh detect more advanced threats, right? And also perform many of these things at scale, right? So uh in sock 101 we work with a lot of uh you know tools and technologies and and different methodologies on how we can apply different tools to uh you know say looking at uh network data or looking at endpoint telemetry right um but how do we do that at scale right how can we during an incident how can we collect artifacts and uh uh you know related evidence from hundreds of systems uh that we can then use to sort of parse down and find things of interest in kind of like a threat hunting way right so it really converges uh in my mind those three pillars uh which are the most going to be the most valuable uh skills that you'll take in any um kind of role that you want to end up in. Right. All right. I will introduce the challenge for today. We are just at um uh half time here uh or half past. So let me flip this on and I will give you the link here. Uh so if we go to uh Blue Team Labs online uh blue team Lababs.online uh if you go to the challenges section you'll need to uh sort of register if you're not in but this was uh we're going to do Whoops. I need to sign in here. We're going to do um one of the rooms that I meant to do the other week but uh we were doing a different one and we sort of ran out of time. Uh so what we're going to do is filter for the free rooms that are retired. should be uh let's focus it. I can't remember. No, there's no hard ones. Uh so we have to do medium and it's this log analysis one. This compromised WordPress uh system here. So I'll get started on that in a second. I don't think it should take too long. Um hopefully we can wrap this up relatively quickly and then of course we'll do some more Q&A uh for any questions that uh are cued in the meantime. All right, let me make sure I'm all set up here. I already have the zip file, but let's kick this one off, shall we? So, the scenario here, pretty short. Uh, one of our WordPress sites has been compromised, but we're currently unsure how. The primary hypothesis is that an installed plugin was vulnerable to remote code execution vulnerability, which gave an attacker access to the underlying operating system of the server. So, uh, pretty common kind of, uh, vulnerability or exploit here with WordPress plugins, right? Um, you know, sometimes, uh, if you ever done, uh, you know, some CTS before, uh, that are WordPress based, uh, you're typically, you know, guessing credentials, getting into the sort of backend or administrator dashboard of a WordPress site. Um, and then from there, you know, you basically own the keys to the kingdom. Uh, if there are no u, you know, security restrictions in place, you can pretty much arbitrarily upload a plugin that um, you know, you can just upload a a reverse shell plugin, right? Uh, these things exist or a web shell plugin, right? Um, and so that's a common thing that we see um sometimes with um some of these uh CMS style sites that are vulnerable to these kind of things. Uh oh yeah, the link should be in chat there for Blue Team Labs online. All right. And so to basically start off the challenge, we of course need access to that log file uh which we can download just by clicking on download file there. I should already have it on this machine from last time. And we just need to unzip it. And so, uh, let's unzip that with the password. Need to provide the password of btllo. Oops. If I can type. Uh, and then it's called btllo_wordpress.zip. So, let's inflate that access.log file. It seems to be the only thing we get here. There we go. and we should be able to get started. Uh, let me full screen this. And, uh, looks like we're going to be dealing with some manual uh, log analysis, which I really enjoy doing. It's kind of therapeutic for me uh, to really just sort of dig into um, you know, these sort of lined log files here. Uh, especially when it's like Apache or EngineX logs. Just kind of fun thing to do. Of course, we could we could take a log file from something like a web server and upload it into, you know, Elastic Search or Splunk or something and sort of do things that way. Obviously, a more much more powerful tool set than doing things in the command line. But sometimes we don't have the option, right? Sometimes we need to um just quickly cut up something or uh you know transform or manipulate data uh in the command line. Uh maybe if we're remoting into a system or again if we just don't have that sort of graphic uh interface option. But it's also applicable uh you know a lot of these things that you can even see here uh you know these different uh bash shell kind of commands uh you know the grab sorts unique um you know cutting up things uh using said or a right a lot of these are going to come in handy when you're dealing with almost any kind of uh you know uh data or output in the command line right um you know whether we're uh pulling back you know some some volatility data right if we're doing some memory analysis in the command line um you know how can we sort format the results that we're getting and and sort of do uh some hunts on uh you know suspicious process ids, right? Or or image names, right? Um so a lot of the stuff is going that we we're probably going to cover today is going to be really applicable for a number of different uh you know facets or uh uh uh skills, right? And so we have this access.log file uh and again we're going to do this in the command line. I want to see how long uh you know how many lines this file is. Uh so we know we sort of get an idea of what we're working with, right? We could just run something like ls- a or ll here um to list out sort of the the the size of the file itself, which can give us a bit of indication, but I just want to count the lines at this point. And so I'm going to do uh WL for um uh Whoops. And then provide access.log. Whoops. It's word count, not WL. There we go. And and L here is just the argument to count, you know, hey, I only want the lines, right? If we were to just do uh word count by itself, we're going to get, you know, line count uh uh uh word count, like the actual, you know, string of a word and then the actual character count itself. And so in this case, looks like we only have 2,000 lines, which is really not a lot. Um, so it's most likely this log file was already condensed somehow or uh sort of uh maybe um temporally uh sort of extracted out so we're only looking at a subset of data, right? Because 2,000 lines is not a ton to work with. So with that, it's probably going to be um it's going to make our lives a lot easier, right? So this is why you always want to sort of um cut down data and filter it as you need to. And so, uh, to start out, you know, we could sort of start jumping into the file and and manipulating it however we want. Uh, but to start us off, I'm going to go off this first question here of identify the URI of the admin login panel that the attacker gain access to. Uh, include the token. Right? So, include the token is interesting. Um, because if we're, you know, if this is a standard kind of uh, you know, Apache log file, right? Let me just cut out one of these few of these lines here. Um, we don't have a ton to go off of where a token might be, right? Uh, it's most likely going to be some sort of URL parameter cuz again, we're not really getting like body information that's, you know, in a post request, for example. Uh, we're just sort of seeing, uh, the, you know, the full URI uh, that was accessed. Uh, and some other things like, you know, we'll get the user agent, maybe a refer page, of course, the IP address, timestamp, stuff like that. Uh so there's a set uh you know set number of columns or fields that we can actually extract from these files and so that's only as much as we have to work with right and so in this case we're looking to identify what the uh admin login panel is that the attacker gain access to. And so of course we can do this a number of different ways. um you know the way you do this or the way you prefer to do it is probably different than the way uh I might do it in this example um because there's just so many different ways you can do this kind of thing right so what we can do is just cat out that access log file obviously we're going to print out 2,000 individual lines or events sort of to the screen here so what we can do uh is sort of GP out uh for things of interest right so I can pipe that output over to GP and then maybe we can look for something like the word admin Right? Uh if this is an admin login panel, uh it looks like it's looking for a PHP file, which is pretty common with WordPress. Uh so we could even do something like, you know, I want to grap out for just PHP files, right? So just PHP. We of course have to escape out the dot there with a backslash. Um so if we do that, we should cut our uh results pretty significantly, right? And in this case, I think I can already see the answer here with the token. Uh so again uh just doing something very quick like that can really cut things down and help us out. So now we're just pulling back again those PHP files but that might not be enough, right? Uh we might want to do some more uh cutting up of this file, right? So I can pipe that output now over to the cut command. We can specify a delimiter to cut by. Right? So if you look at that output of the file, each field or column is sort of separate at space. And so we can set the space character as sort of our delimter. Say, hey, you know, every time there's a space, uh, treat that as a different field or a different sequence in sort of, uh, if you think about maybe like a CSV file, right? Sort of comma delimited. In this case, we're sort of space delimited here. And in this case, I know that um, and so what I want to do is pull back the uh, um, the UR uh, URL that was accessed or like the page that was accessed like the, you know, admin.php for example. And I know that's in these standard Apache logs, that's going to be seven as the field number uh just from experience and doing this kind of thing a lot. Uh but for example, one is going to be the IP addresses, right? So that's going to print out just the IP addresses or that first field in the file. And so you know uh if you didn't know what you're really working with, you could just sort of trial uh you know uh trial by error. just uh keeps going up until you reach seven, which yeah, as you can see here, is going to be just pulling back the uh unique or not unique yet, but uh just pulling back all of the different uh URIs or URL uh routes that were accessed, right? And we can see some interesting things. We have again the sort of WordPress login page here. Looks like uh we have some uh uploads here with a freak.php. I think that might come in handy. Uh so again like it's like the third command we kind of ran and we're already uh getting a good grasp on some things of interest that we might want to check uh inside of this file, right? Um of course we're not we're not really um putting a timeline together in our heads yet, but we are seeing some things that you know, hey, let me know let me let me uh write this down and and return to it later on, right? If I don't find anything else. But we again we can take this a step further. You can see we're getting a lot of duplicate results. And so we can do some more fun things. Yep, there you go. So we have teraflops way ahead of me, moving at a mile a minute. You called it. Yep. We're going to pipe this over to unique. And that's going to say, hey, you know, every time we have um uh you know, some of these lines that are um connected here, I only want a sort of single aggregated version, right? And before we do that, I'm actually going to run the sort command. What that's going to do is make sure that every single duplicate entry is sort of stacked on top of each other, right? Because for example, before we were just doing it based on the actual timestamp or the chronological order in which these files were or log files were written, right? So someone could access this login file, access a different page, and then access the login file again, and it's not going to be stacked, right? So by sorting the the results that we're getting, we're making sure that every single instance of login.php PHP is stacked up and then we can pipe that over to unique and that's going to just really cut down on a lot of the noise. We're still getting quite a bit because uh you know WordPress is a pretty noisy uh kind of CMS, right? So we have all of these different includes that are requested, these different JavaScript files, right? But we always have ways to clean that up too. Uh I'm going to append the C argument here um to just count up all of those unique entries, right? So you can see uh it's giving us that aggregation now, right? So this specific URL was accessed 10 times, right? Opposed to this one which was only one time. And so finally we can pipe that over to one more uh sort command uh and append the NR here to basically say, you know, give me the top uh values in sort of that um descending order. And I want to count them by the number that is next to each line, right? So I want to figure out, you know, hey, what is the most uh access file and and move downwards? So, when we do that, we're going to see a lot of ones here for all of these unique uh sort of uh you know, one-time events. And so, I'm interested in what was accessed more than once, obviously. Um because if an attacker is accessing a an admin page or a dashboard, probably not going to just access it once. Uh we might typically see uh quite a few more, right? Uh so, I'm going to pipe that over to head command to say, you know, hey, I only want to pull back a certain amount of the top values. And for example with the n uh parameter here I can just say I want to pull back the top five. And doing that you know really cleaned up a ton of noise here. And as you can see in first place we have uh you know this login page here with 135 uh hits. Right. So in doing just some of these basic uh you know bash sort of syntax commands here we were able to take a 2000line file which again is not a ton but the same methodology applies and we're able to cut that down into some things of interest right so this admin login page uh again in this case we're seeing that freak.php PHP uh page as well that doesn't look too normal, right? It looks a little bit anomalous. So again, something we might want to write down and return to later. But in this case, I think this is uh what we should be looking for here because it also has the uh ITEC HP token, whatever that means uh for admin login. There we go. So that was answered correctly. We identified the admin login page that the attacker gained access to. How do we know that the attacker actually gained access? Right? We were kind of inferring just because it was, you know, hey, the the top sort of page that was accessed. But now that we have this URL, we can use this as a pivot point to uh investigate things further, right? We can now say, you know, hey, um what IP addresses were accessing this page, right? because now we're we're only getting the URLs which is very helpful for um you know doing that statistical sort of analysis but it's not super contextual in terms of you know who is accessing and when uh and you know with what user agents right and so what we can do is sort of take that um string there and use that as our sort of GP uh pivot point here right so I can just do GP I can fill in um WP login might need to escape some of this stuff uh we'll see if that works and then access.log. There we go. So now we're just pulling back the results. Should be 135 of them if you remember. Um that relate to uh just that page that was accessed, right? And so now what we can do uh because we we know that uh in this case from our question that the attacker accessed this page. Now what we can do is sort of do the same thing uh we can cut based on those uh delimiters of spaces. And this time I just want to pull back the IP addresses. So, now that we've done that, same kind of deal that we just did, right? We can clean that up. We can sort them. Uh, we can pipe it over to unique- C to count that up the results. And then one more sort command there to say, you know, hey, let me uh uh order them by uh the the the top values sort of thing. And doing that, there we go. Looks like we get some interesting results here. Uh it looks like we have maybe an error result that was in in uh the the log itself. So we can kind of ignore that. But we are seeing some of the top IP addresses now that were hitting that login page, right? So again, we might want to document some of these, right? Um looks like we have quite a few here. Um which is interesting. And so that's how we can sort of start to use what we find uh in order to pivot and and look off of uh additional uh IPs or entries, right? And so again, we still don't know which one the attacker might be here, but we know the attacker is somewhere in this list, right? So whether it be we start correlating this with other events or, you know, start doing reputation checks on these IPs to see, you know, hey, were they involved in any uh you know, nefarious activity in the in the past, right? um or were they part of are they associated with any uh you know active malware going on right so there's a ton that we can do but in this case um this question really sticks out to me too so we can sort of jump over to this next question which is I think going to help us narrow down what IP uh is of interest here so this question is can you find the two tools that the attacker used and so again you know might be thinking how the heck are we going to figure out what tools an attacker used uh just from this you know garbled mess of logs right and the way you know we can figure that out is you know just think about what again what fields do we have access to right so if I just take one of these so I'm just going to grab the first line here we have a you know we only have a a strict set of fields that we have to work with because we were only given this access log file right it's not like we can hop on the endpoint and maybe look at uh you know the the memory uh dump or you know the file system right to figure out what tools were used. And so in my opinion the only two uh really indicators that that can stick out here for us that might be useful are things like the actual URL that was accessed. Right? So maybe if a specific tool like a hacking tool that was used um you know has a a specific signature or fingerprint that it maybe like uploads a a file with a particular name uh on the system right that might be a giveaway. Uh if it's something you know maybe attackers running some sort of directory busting attack. Uh we might see you know a ton of just different directories uh all being attempted to to be accessed from the same IP address. And we might see a ton of 404s when uh you know certain files or or directories were not found. The other thing here uh that is usually very interesting to us is the user agent right uh so what actual system uh and software and operating system was making that connection right um uh you know for example if I curl a web page I'm not going to see you know this string here of Mosilla 5.0 So, uh, you know, I'm going to see the curl utility, right? And a lot of tools, uh, not even just sort of living off the land binaries, but a lot of, um, you know, common enumeration tools or scanning tools have their own unique, um, user agents, right? Because they're sort of built in or baked in to how the tool works. And oftent times you can change this uh, in sort of a configuration setting or maybe an argument that you append. But a lot of times, you know, attackers are lazy. Uh, they they don't change the default values, right? So we can sometimes uh identify uh some interesting activity through user agents. In other cases uh you know maybe an attacker uh misspells something in a user agent, right? Maybe instead of Mosilla, they accidentally type it with one L. And so that can be another thing that once we start aggregating user agents, we can identify interesting tactics, right? Um or if in the sort of command and control uh scenario, maybe an attacker is purposely setting their user agent to something specific so they can filter out any you know network traffic that does not contain that user agent. Right? So there's legitimate use cases and also legitimate malicious use cases as well. Right? So in this case uh we already know how to sort of cut these logs up. Right? So we're going to do that. But in this this time we're going to do it based on the user agent because I think that's going to be our tell here in terms of you know hey what tools were used because if nap was used to scan we might see end mapap in this user agent string. If uh Ghostbuster for example was used to uh sort of enumerate directories or files, well we might see Ghostbuster in here as well or Hydra for example, right? And so uh same kind of deal, right? We can uh cut up. This time I want to cut up based on these uh quotation marks, right? Because uh I want to grab everything within these quotation marks. And it looks like we have a few, right? The URL request itself, the sort of request string has its own sort of quotation marks. uh you know the referer code here has its own and so what we need to do is basically um comment that out or sort of um allow us to use that quotation marks uh character. Uh so we need to use a backslash there. And then what we can do now is sort of uh you know start working our way up the different fields that we might want to grab to make sure that we're grabbing just this string. And I don't know off the top of my head what it is. Uh is it five? Nope. So, if I start with one here, we're just going to grab sort of the timestamp values. Uh, two looks like it's going to be that request string, right? So, that's not exactly what we're looking for at this point in time. Uh, three is the the um I guess in between the request string and refer, right? So, it's kind of it's it's just trial and error at this point. Um, was it five or six? Yeah, so it's six. Okay, let me go back there and try six. And now we're just pulling back the user agent strings. All right. So, same kind of deal. Now, we can cut this up and filter it to our liking to get rid of all these duplicate results. So, we can then focus on, you know, hey, what is um you know, either what are what are the top values or what are the rare values, right? What what only appears once, which is um usually more interesting to us from a user agent perspective, right? Because typically, you know, we have certain user agents in our environment that map to like, you know, hey, I'm running Firefox or I'm running Chrome or uh, you know, Microsoft Edge, uh, god forbid, but, you know, we have a a sort of subset of us and strings, we might have different versions, right? But if we see anything rare or anything that, you know, is only appearing once or twice in the logs, uh, again, get in that threat hunting sort of mindset. That's what we want to look into. So, uh, same kind of thing. We can uh sort out the results uh and then do the unique command to you know count up the results and then one more sort uh what not snort one more sort command to say hey let's uh get those in reverse order based on the number. All right we're getting looks like a bunch of errors which is not fun. Uh these aren't errors like in our command line. These are actually just lines in the file. So, it looks like for some reason or another um the Apache server or whatever it was uh was locking a bunch of errors which kind of just really gets some noise which is a bit annoying. So, we can clean that up a bit. I'll just run our same command. I'll do gp tac v there uh to say, you know, hey, let's pull back everything not uh matching whatever string we provide. In this case, I'm just going to search for the word error because I want to sort of ignore all of those. And there we go. That looks a bit better. We're still seeing some weird uh results here and there, which again, if we really wanted to, we could cut up some more, but I think we can kind of work with this, right? Um, so again, we have a lot of what seemingly look legitimate here, right? We have a lot a ton of sort of Firefox user agent strings. Uh, some Safari as well that you can see. If you're ever unsure, you can actually parse these strings on a a website, right? Uh, actually, I can demonstrate that. Might as well. So, I'm just going to cop copy this string here. hop over to the browser and just type in uh parse user agent and we should be able to uh we should be able to uh find a site that can do this for us. What is my browser.com is a good example here. And so I can just paste that in and uh parse in that user agent string and then it will give us this information and start breaking down. Wow, this site has a ton of advertisements. Yikes. But maybe you can see the point here. Uh it's breaking down things like the software version for us, right? Uh so we can see it's running Firefox, uh the software version, right? Uh the layout engine, stuff like that. Uh we can get some information about, you know, hey, this was most likely a Linux system that was accessing this, which can be a little interesting to us. But basically, that's sort of how we can make sense of those strings uh if they do seem a little uh uh you know, overbearing. But as you scroll down, in this case again, I'm looking for more of the unique or the rare uh user agents that might not fit in. So we can see Python requests. That's immediately interesting to me. Uh that would mean someone, you know, is using the Python request module uh to make a connection to this website, right? So oftent times you see that in uh exploit scripts, right? That are running maybe Python scripts. But I do see some interesting ones here. um WP scan, WordPress scan. It's a very common uh uh WordPress scanning or enumeration kind of uh utility, right? If I just do a search for WP scan, again, if you don't know any of these uh user agents, you can just do a search for what you're finding, right? Um so, in this case, we can see WP scan uh is used to again find vulnerabilities or or um uh you know, different uh uh configuration misconfigurations within WordPress sites. Right now, it looks like we have one request, which is interesting from WP scan. This is a little interesting. I think this was maybe cleaned up for the challenge purpose because if you're running WP scan against a WordPress site, you're going to have tons of uh uh requests, right? It's a pretty noisy uh kind of utility. Same with SQL Map, right? So, if you're looking for SQL injection or you're looking to automate uh SQL injection and detection, uh SQL map is a pretty popular choice. Again, seeing one request here is a little interesting. Um, typically you would have a bunch. Uh, but in this case, yeah, looks like we've identified both these tools here, right? So, these are pretty common um tools. If you ever done like CTFs, you you'll probably see a lot of these pretty often, but even in the wild, we see things like SQL Map all the time. Uh, WPS scan as well for WordPr
Original Description
Sponsor a Video: https://www.tcm.rocks/Sponsors
Pentests & Security Consulting: https://tcm-sec.com
Get Trained: https://academy.tcm-sec.com
Get Certified: https://certifications.tcm-sec.com
Merch: https://merch.tcm-sec.com
📱Social Media📱
___________________________________________
X: https://x.com/TCMSecurity
Twitch: https://www.twitch.tv/thecybermentor
Instagram: https://www.instagram.com/tcmsecurity/
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/
TikTok: https://www.tiktok.com/@tcmsecurity
Discord: https://discord.gg/tcm
Facebook: https://www.facebook.com/tcmsecure
💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:
https://www.patreon.com/thecybermentor
Support the stream (one-time): https://streamlabs.com/thecybermentor
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: https://amzn.to/31GN7iX
The Hacker Playbook 3: https://amzn.to/34XkIY2
Hacking: The Art of Exploitation: https://amzn.to/2VchDyL
The Web Application Hacker's Handbook: https://amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: https://amzn.to/2V9srOe
Social Engineering: The Science of Human Hacking: https://amzn.to/31HAmVx
Linux Basics for Hackers: https://amzn.to/34WvcXP
Python Crash Course, 2nd Edition: https://amzn.to/30gINu0
Violent Python: https://amzn.to/2QoGoJn
Black Hat Python: https://amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:https://amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: https://amzn.to/30d1UW1
EVGA 2080TI: https://amzn.to/30d2lj7
MSI Z390 MotherBoard: https://amzn.to/30eu5TL
Intel 9700K: https://amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: https://amzn.to/2M638Zb
Razer Nommo Chroma Speakers: https://amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: https://amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: https://amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: https://amzn.to/31MOgpu
My Recording Equipment:
Panasonic G85 4K C
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from The Cyber Mentor · The Cyber Mentor · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Buffer Overflows Made Easy - Part 1: Introduction
The Cyber Mentor
Buffer Overflows Made Easy - Part 2: Spiking
The Cyber Mentor
Buffer Overflows Made Easy - Part 3: Fuzzing
The Cyber Mentor
Buffer Overflows Made Easy - Part 4: Finding the Offset
The Cyber Mentor
Buffer Overflows Made Easy - Part 5: Overwriting the EIP
The Cyber Mentor
Buffer Overflows Made Easy - Part 6: Finding Bad Characters
The Cyber Mentor
Buffer Overflows Made Easy - Part 7: Finding the Right Module
The Cyber Mentor
Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
The Cyber Mentor
HackTheBox - Sunday Walkthrough (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
The Cyber Mentor
HackTheBox - Fighter Walkthrough (Re-Up)
The Cyber Mentor
Beginner Linux for Ethical Hackers - Navigating the File System
The Cyber Mentor
Beginner Linux for Ethical Hackers - Users and Privileges
The Cyber Mentor
Beginner Linux for Ethical Hackers - Common Network Commands
The Cyber Mentor
Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
The Cyber Mentor
Beginner Linux for Ethical Hackers - Controlling Kali Services
The Cyber Mentor
Beginner Linux for Ethical Hackers - Scripting with Bash
The Cyber Mentor
Beginner Linux for Ethical Hackers - Installing and Updating Tools
The Cyber Mentor
Cracking Linux Password Hashes with Hashcat
The Cyber Mentor
Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
The Cyber Mentor
Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
The Cyber Mentor
New Zero to Hero Pentest Course, New Website, and 2K Subs?!
The Cyber Mentor
Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
The Cyber Mentor
Zero to Hero Pentesting: Episode 2 - Python 101
The Cyber Mentor
Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
The Cyber Mentor
Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
The Cyber Mentor
Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
The Cyber Mentor
Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
The Cyber Mentor
Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
The Cyber Mentor
Installing Windows Server 2016 on VMWare in 5 Minutes
The Cyber Mentor
Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
The Cyber Mentor
A Day in the Life of an Ethical Hacker / Penetration Tester
The Cyber Mentor
Active Directory Exploitation - LLMNR/NBT-NS Poisoning
The Cyber Mentor
Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
The Cyber Mentor
Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
The Cyber Mentor
Writing a Pentest Report
The Cyber Mentor
Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
The Cyber Mentor
The Complete Linux for Ethical Hackers Course for 2019
The Cyber Mentor
Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
The Cyber Mentor
Popping a Shell with SMB Relay and Empire
The Cyber Mentor
Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 2 - Lame
The Cyber Mentor
Pentesting for n00bs: Episode 3 - Blue
The Cyber Mentor
Web App Testing: Episode 1 - Enumeration
The Cyber Mentor
Pentesting for n00bs: Episode 4 - Devel
The Cyber Mentor
Pentesting for n00bs: Episode 5 - Jerry
The Cyber Mentor
Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
The Cyber Mentor
Pentesting for n00bs: Episode 6 - Nibbles
The Cyber Mentor
Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
The Cyber Mentor
How NOT to Approach a Cybersecurity Mentor
The Cyber Mentor
Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
The Cyber Mentor
Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 9 - Grandpa
The Cyber Mentor
Top 5 Internal Pentesting Methods
The Cyber Mentor
More on: Security Basics
View skill →
🎓
Tutor Explanation
DeepCamp AI