Google CTF 2016: Ernst Echidna
Key Takeaways
The video discusses the Google CTF 2016 challenge Ernst Echidna, presented by John Hammond, covering AI and cybersecurity topics, specifically focusing on Capture The Flag challenges and problem-solving strategies.
Full Transcript
Hey, what's going on everybody? My name is John Hammond and in this video I wanted to bring to you uh one of the easiest solutions to some of the Google capture the flag CTF that uh got started this weekend. It was going on from I think April 29th to May 1st I think. Uh it was their first annual Google CTF. So a lot of people seemed like they were jumping in on it and I was one of them. The challenge I wanted to show you is Ernst Akidna. It was only worth 50 points. wasn't really a big challenge and a lot of people solved it. 737 people were able to get this one. So, it's pretty simple challenge, but I want to just walk you through it and build a a quick get flag script for you. So, uh here we go. Can you hack this website? The robots.ext sure looks interesting. Hm. Okay, let's take a look at this. And uh it says, "Welcome to Strawberry T. Access to the is restricted." Okay. Please register to get access. Whatever. Uh let's check out that robots.ext text that they were hinting at. Robots.ext. And it does not want us to go to the admin page. Okay. Well, what is over there? Let's check that one out. For/admin. And it tells us, oh, we're not logged in. Fine. I guess we will uh go back and now try and log in and register. Okay. So, if we can register for account, it's just it's pretty simple username and password field. There's nothing interesting in here. If you take a look at the source, there's nothing hidden. There's nothing hidden in the old page. There's it's just plain straight HTML. So if we register, I guess we'll just do some stuff. Uh I don't know just to fill stuff out. Let's go for the purpose of explanation. A and B as our username and password. We're registered. Thank you for registering. Unfortunately, there's no content. That's fine. Can we get to our admin page now? That's really all we care about, right? Okay. Sorry. This interface is restricted to administrators only. Well, dang, that's annoying. Thank you for registering. Unfortunately, there's been no content posted on the site. Okay. How's it keeping track of the fact that I am registered and logged in? That's probably done with a cookie, right? So, I mean, you can uh view cookies in Firefox with like cookie manager. It's a cool plugin. Uh if you don't already have it, I totally recommend you grab it because I'm going to use that to take a look at what we have here. I'm going to fire up cookie manager as the actual tool, not the Google search. My bad. And we want to be looking at our website. Ernst Akidna is a challenge that we're looking at right now. And it has a cookie. It has a cookie set for us. MD5 hash looks like, right? Hopefully you guys can see this. I'm sorry if it's too small. I can't really zoom in on this. Okay. So, it's MD5 hash cookie has a value that I'm assuming just based off its name is an MD5 hash. Um, now MD5 is pretty much well known for being pretty weak. So, I wonder if we can hack it. I wonder if we can crack that or find a collision for this uh MD5 hash. So, I just Googled MD5 cracker and md5cracker.org was a good one that I ended up using. Um, so I threw my hash in there and whoa, a lot of people told me that it has the result of just simple A. And that's what we just put in as our username. You see, you remember when we lo when we registered as A as our username and B as our password. So, it looked like all it really did was MD5 hash our username. So, can we have it kind of fool can we fool the web page into thinking that I am the administrator? Let's delete our current cookie. I'll just remove that. Now, if I go to the page, looks like I have to register. Can I log in? Can I register as admin? Okay. Admin account already taken. Oh, well. Okay. Dang. But what's to stop us from like changing our changing our cookie already that we already have? So, if we fire up cookie manager one more time, our MD5 hash, which is currently the MD5 hash of the letter A, our username. Let's actually create our own MD5 hash of the word admin of that admin user. And can we just set this to be it right? Can we set this to be our cookie? Do I have uh All right, I still have it. I still have it up. Good. Let's go into cookie manager. Change the value of our MD5 hash cookie to now the MD5 hash of the the username admin. Save it. Refresh the page. There's nothing new here. But now if I go to admin, hey, that admin page now lets us come on in. And it says, "Hey, congratulations. your token is this flag. Cool. So, we just got the flag, right? We would be we would be able to submit this, but uh some of you guys may know I don't really like just leaving it at that. I'd like to be able to script this or automate getting the flag for us. So, let's go ahead and start to build something that will let us do that. Fire up Sublime Text. Get a new script going. I guess in Google CTF I have a I'll just create a get flag.py script for us. I'll try and zoom in here so you can see it. Get a shebang line going. Let's import re um I'm sorry, a request. And let's import hashlib. So we'll actually use that to MD5 stuff. We'll say username equals admin because that's what we want. MD5 can equal hashlib.m MD5 just to create our MD5 object. Um so MD5.update with username and then um MD5 I guess hash which is what we'll set the value of the cookie can be equal to that MD5 objects hex digest. So once it actually gets the digest of this uh username admin and once it hashes the word admin MD5 hash now we see okay we've successfully hashed MD5 now let's actually make that call let's get a request object open we can just say s equals request session scookies if we if I were to show you that currently it is just an empty cookie jar let's actually update that I'll remove this print statement with a new dictionary for the string MD5 hash. Set it to our MD5 hash that we've actually is actually the hash. Now, if we were to print out S.Cookies, you should be able to see, oh, okay, cool. MD5 hash is actually a cookie in there. That's just fine. So, now we should be able to run s.get on our admin page. If we try and run this and print it out, it does have an error because we need to verify the SSL certificate. I'm going to ignore that. So, we can do that with uh verify equals false. Probably not the best idea, but it does get to what we wanted to. It gets a response to 100. So, let's save that as R. We can print out R.ext. Here we go. Okay, cool. Congratulations. Your token is. And let's just scrape that out with regular expressions. Um, content can equal that. And then what is it that we're trying to find? Re dot re.arch. All right. Matched equals re.arch. Pattern will be CTF. Anything in here. And let's escape these out. And we'll find that in our contents. So, if matched, print matched. What do we get here? Nothing. I might not need to have these. Um, congratulations. your token to CTF. That should totally work. Do I need to like escape my uh asterisk here too? Here. I'll pause this so I can get it right for you. Sorry, guys. All right, I'm dumb. I completely forgot about the fact that I just actually needed to put the inside of the flag like in parenthesis or the actual like whole thing. Okay, my fail. So, yeah, CTF and then the flag format is this curly braces and you can just denote that, hey, I actually want this as part of a found group. So, if I just left it. Okay, now it should work. Cool. Very nice. Uh I don't know how I can hide that uh security warning. Let's do some research and find that. Again, I'm kind of going off off the cuff right now. I probably shouldn't be doing this much research and like doing things that I don't have scripted or at least I don't have prepared, but requests ignore warning. Python requests ignore insecure requests warning. Is there a way to suppress that? Looks like there's just this line. Okay, sure. Stole that off the internet. No big deal. Copy and paste. Copy paste code off stack overflow. That's good. That's good programming practice, right? That's funny. Okay. Sure. Real simple thing just to uh get flag uh let's make this executable. See Google Earns executable chmod plus x get flag.py. Okay. And that that gets our flag for us. Sweet. We're done. I'm I I spent too much time on this problem trying to show you something very very simple, but it was a lot of fun. So, thanks guys. Hope you enjoyed this real simple uh part of Google CTF. Really, really cool CTF. I didn't get a whole lot of challenges, but it was a ton of fun. So, thanks again, guys. See you in a next later video.
Original Description
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
GitHub: https://github.com/JohnHammond
Site: http://www.johnhammond.org
Twitter: https://twitter.com/_johnhammond
Playlist
Uploads from John Hammond · John Hammond · 28 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
▶
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
Related Reads
📰
📰
📰
📰
The Half-Life 2 of AI isn't a smarter chatbot
Dev.to AI
AI in Journalism: The One Writing the News Is No Longer a Reporter
Medium · AI
Why Cursor’s Change-of-Control Clause Became the Model Deadline
Medium · Programming
5 Leadership Behaviors Separating Companies That Win With AI From Companies Just Using It
Medium · AI
🎓
Tutor Explanation
DeepCamp AI