Sudo ltrace | Ryan's CTF [15] Strings wont help you

John Hammond · Intermediate ·🔐 Cybersecurity ·7y ago

Key Takeaways

Uses sudo ltrace to crack a password in a Ryan's CTF challenge

Full Transcript

this challenge from Ryan Nicholson's cap from flag competition is called strings won't help you for 100 points in the extreme category it says determine the password that the program asks for and receive the flag recover the flag so it gives us a show that we can connect to credentials to login with CTF 9 and challenge 9 if we check in our home directory we have a file program ok we still don't have the file command whatever let's run the program and it says cat root md5 hash permission denied that's weird enter the password for the flag please sub nope try again I was originally weirded out by why we're getting a permission denied notion thing here for root md5 if I check out this program it's not a set UID binary so it's very strange but it's owned by root and everyone can run it but I'm not able to open up this file that's in the root home directory so I checked out what I can run with sudo or with root privileges and it says these user may run the following commands no password competitor program ok we see that here and L Trace that was really weird so I figured all right let's sudo L trace and the program and this will show us ok what is it which is actually trying to happen here looks like it tries to read this file md5 hash and it gets this md5 hash cool it enters the password for the flag as we input it so please sub and then it tries to oh it uses some bash code to determine the md5 sum of that get the actual hash and it tries to compare that you can see strcmp with the hash that it read out of md5 hash so all we need is to figure out what this hash is originally what the real plane tax is from that write like that should be our goal here because please sub is not the correct password but whatever yields this hash is the correct password so let's go ahead and try and crack this I'll google it or a crack station whatever we need to do to actually I don't need command-line I just need the actual thing whatever we need to do to crack this hash let's paste it in here run through that stupid CAPTCHA and the hash is supposedly Big Bang one okay so back to our program here now we can run program again we'll have to sudo it because so we can read that proper hash file and then we'll enter Big Bang three one and it says okay sweet that was the flag that's here's what you need a foo material I that wasn't a set UID binary I thought that was kind of strange but I was going to use L trace and s trace to begin with so it's an interesting thing that those our noted in sudo that we would be able to run them so always always at least when you're in a shell try and run that basic enumeration sudo attack l lista well you can run without a password or anything also in the system you might have access to that's kind of a cool thing to note for a capture flag competitions and this one was just a simple okay reverse this hash pretty much what we did like in the beginner section hey I want to give a special shout out and some love the people that are willing to support me on patreon you guys are phenomenal I'm gonna do it I'm gonna run through hero Spencer Clark L Horowitz so hey Attila I'm sorry always put your name or Gaddafi and religious world's bastion of Harwich and Rob Timothy County Jacob hr1 FL Thomas for Rob Dacus JT ton Maurice contour oh it's Ben's Queenie William woodcomb Justin man Kim Bono pixel richard smith you guys are phenomenal hey $1 a month on patreon will give you a special shout-out just like this at the end of every video where I can butcher your name along with everyone else's $5 a month on patreon will give you early access to every video that I create before it's uploaded onto YouTube and if you did like this video please do press that like button maybe leave me a comment if you're willing to subscribe join us on discord linked to the server is in the description and you would be awesome if I could see some support on patreon you're the best guys see you soon

Original Description

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010 E-mail: johnhammond010@gmail.com PayPal: http://paypal.me/johnhammond010 GitHub: https://github.com/JohnHammond Site: http://www.johnhammond.org Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 0 of 60

← Previous Next →
1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
28 Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
38 Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

Related Reads

📰
Your HIPAA Posture, in Version Control
Improve your HIPAA posture by managing infrastructure and evidence in version control, ensuring compliance and security
Medium · Cybersecurity
📰
What is gobuster?
Learn about Gobuster, a command line tool for discovering hidden files and directories in cybersecurity, and how to use it for penetration testing
Medium · Programming
📰
Web3 Development Surges Amidst Critical Supply Chain Malware Threats and Bearish Sentiment
Web3 development faces critical supply chain malware threats, including IronWorm, which steals wallet keys and cloud credentials, amidst bearish market sentiment
Dev.to AI
📰
Lab: SQL injection UNION attack, retrieving multiple values in a single column
Learn to perform SQL injection UNION attacks to retrieve multiple values in a single column, enhancing your cybersecurity skills
Medium · Cybersecurity
Up next
How To Delete Your Data From The Internet | Privacy Bee Review & Tutorial 2026
Tutorial Stack
Watch →