web50 : RFC 7230 :: EKOPARTY CTF 2016
Key Takeaways
Solves EKOPARTY CTF 2016 web50 RFC 7230 challenge using web protocol exploitation techniques
Full Transcript
Hello everybody and welcome back to another video. Uh my name is John Hammond and I'm showcasing some more of the really simple and small challenges from the Echo Party or Eco Party CTF for 2016. I honestly still don't know how to pronounce the name of the CTF. I prefer Echo Party, but whatever. Uh I want to show off web 50. I again I haven't solved a whole lot of challenges. Um and these are all the simple ones and the small ones that I have, but I want to showcase them and and give them to you. So this one is asking to uh get get just the basic information from the server and the CTFchopart.org. Uh the challenge title is RFC7230. We could if we wanted to Google that and figure out what it is. You can see I have visited this page already. And it looks like it's just a simple page or RFC defining what the hypertext transfer protocol or HTTP is. So, I read through this and it didn't particularly give me a whole lot of uh of of hints and a and a good lead anywhere, but I I continued to move on and I actually tried to throw some simple like reconnaissance and web application uh testing stuff like tools at the URL and I actually ended up doing it with Nikto. But I we're trying to keep like a list of the tools that we end up using. So, I want to show that to you. It should be public. So, USGA tools and there's a list of some stuff that I try to archive. Um, and one of them that we have on there is NATO, but it's under the reconnaissance uh utility. Uh, and the same thing with Netcraft, which apparently a friend of mine solved this challenge by using Netcraft. So, I'll showcase that too. But you can use neto a terminal here and you can specify the host-H and we'll specify htt echo party and you'll see immediately it finds some information and in our case okay the server area that that that information field is does have our flag in it echo this is my great server. So super easy again you just kind of take advantage of using the tool and doing some simple reconnaissance on the on the web server on the web page. Um but again we could do that with Netcraft just like uh I had noted in our archive of tools here and a friend of mine told me that he solved it this way. So you can supply the URL that you want to give it and it can do a little bit of scanning eventually in the SSSL sorry SSL portion it does find oh the server here the flag again you can see the flag format echo this is my great server so you would go ahead and be able to submit that get your 50 points and you'd be rolling but wanted to showcase it to you simple stuff I just use the neto tool and netcraft it does some good reconnaissance and finds what we need in our case the lag. So, all righty. Thanks again for watching, guys. I hope to show you some more stuff. Again, simple, but I want to showcase it off to you uh in a later video. Talk to you soon.
Original Description
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
GitHub: https://github.com/JohnHammond
Site: http://www.johnhammond.org
Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 41 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
▶
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Network Security
View skill →Related AI Lessons
⚡
⚡
⚡
⚡
Apple rushed to squash 29 bugs because AI is supercharging hackers - update ASAP
ZDNet
The Augean Stables: Cleaning The Overlooked Cybersecurity Blind Spots For PQC Readiness
Forbes Innovation
API-RTA Exam Walkthrough — Passed | CyberWarFare Labs
Medium · Cybersecurity
Ethical Hacking Step-by-Step (Part 3)
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI